fsviewersetup35.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from filehippo.com and multiple other hosts.
MD5:
456d479d838d5c1eff324b095e1d58a6

SHA-1:
99eaee217923c0bc4cfae8a08048dea97cac0377

SHA-256:
94c014399443c624526473df8c84b0a2924bdb8bfdeadaf39182b6c5c3d7320e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 1:06:03 PM UTC  (today)

File size:
4.1 MB (4,261,270 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\fsviewersetup35.exe

File PE Metadata
Compilation timestamp:
1/13/2007 1:26:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Hw/8u5ylhW7/as1q3HpXLIbybhNgy3edJ+NsFlOHD4Sv:HhPz0/agwYybhCy3qZFY0g

Entry address:
0x3161

Entry point:
81, EC, 7C, 01, 00, 00, 53, 55, 56, 33, F6, 57, 89, 74, 24, 18, BD, 40, 92, 40, 00, C6, 44, 24, 10, 20, FF, 15, 30, 70, 40, 00, 56, FF, 15, 70, 72, 40, 00, A3, F0, F4, 42, 00, 56, 8D, 44, 24, 30, 68, 60, 01, 00, 00, 50, 56, 68, 60, 98, 42, 00, FF, 15, 58, 71, 40, 00, 68, 30, 92, 40, 00, 68, 40, EC, 42, 00, E8, 28, 28, 00, 00, BB, 00, 64, 43, 00, 53, 68, 00, 04, 00, 00, FF, 15, B4, 70, 40, 00, E8, 64, FF, FF, FF, 85, C0, 75, 24, 68, FB, 03, 00, 00, 53, FF, 15, B0, 70, 40, 00, 68, 28, 92, 40, 00, 53, E8, 13...
 
[+]

Entropy:
7.9986

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file fsviewersetup35.exe has been discovered within the following program.

FastStone Image Viewer 4.6  by FastStone Soft
FastStone Image Viewer is an image viewer and organizer for Microsoft Windows, provided free of charge for personal and educational use.
www.faststone.org
10% remove it
 
Powered by Should I Remove It?

The file fsviewersetup35.exe has been seen being distributed by the following 3 URLs.

http://filehippo.com/download/file/.../

Scan fsviewersetup35.exe - Powered by Reason Core Security