Defprof.exe

Defprof

ForensiT Limited

Publisher:
ForensiT Limited  (signed and verified)

Product:
Defprof

Description:
Set Default Profile

Version:
1.2.0.0

MD5:
dd82abc694d133fc7119b1fcafef1bde

SHA-1:
302b46a8945b575ca41bc6c7740ab1b5db87cb46

SHA-256:
c9e921fc2657872806ff35bb546de318a2bc9b6bce2ef638c5bb5b5c55a0c844

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:28:55 AM UTC  (today)

File size:
76.3 KB (78,104 bytes)

Product version:
1.2.0.0

Copyright:
Copyright (C) ForensiT 2010-2011

Original file name:
Defprof.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Windows\System32\defprof.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/24/2009 8:00:00 PM

Valid to:
5/14/2012 7:59:59 PM

Subject:
CN=ForensiT Limited, OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ForensiT Limited, L=Chatham, S=Kent, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47FDFF90411A6950291B54D9846B7CF8

File PE Metadata
Compilation timestamp:
1/9/2011 9:45:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
1536:TYc92A9Ed+vqZCNgt/ntWfJxj1HkfzM5qvj3zzm7gGx:TYc60yCNgCRxnej3zzm7R

Entry address:
0x39C8

Entry point:
E8, B0, 32, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, D4, 0C, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 72, 34, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, EF, 0C, 00, 00, 59, 85, C0, 74, E6, C9, C3, F6, 05, 58, 1F, 41, 00, 01, BF, 4C, 1F, 41, 00, BE, 20, C2, 40, 00, 75, 2C, 83, 0D, 58, 1F, 41, 00, 01, 6A, 01, 8D, 45, FC, 50, 8B, CF, C7, 45, FC, 28, C2, 40, 00, E8, 0A, 08, 00, 00, 68, A4, B2, 40, 00, 89, 35, 4C, 1F, 41, 00, E8, FA, 33, 00, 00, 59, 57, 8D, 4D, F0, E8, DF...
 
[+]

Entropy:
6.1492

Code size:
41 KB (41,984 bytes)

Scan Defprof.exe - Powered by Reason Core Security