PhotoScape.EXE

PhotoScape

This is a setup program which is used to install the application. The file has been seen being downloaded from dc342.4shared.com and multiple other hosts.
Product:
PhotoScape

Version:
1, 0, 0, 1295

MD5:
8f32c91eb5cb44fba7705534ae304dea

SHA-1:
a80e0efb3096aaac1fe7ce9cd81a3972172ebf47

SHA-256:
a760ce9c1730bd65fc969f3ef76f81d1f2e6868ff1dd22b633352f66628f5117

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 11:43:53 PM UTC  (a few moments ago)

File size:
6.3 MB (6,651,392 bytes)

Product version:
1, 0, 0, 1295

Copyright:
Copyright (C) 2005

Original file name:
PhotoScape.EXE

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\Program Files\photoscape\photoscape.exe

File PE Metadata
Compilation timestamp:
5/24/2010 3:01:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:phIJpD6yHlXacEcfsTKfwkE4a4ZTJkYBagdG/517FLUUZ4V/tAxLZVf4XlTsKZGK:ormSKcoKfwD4tPjCwhClDkSw2oE7Yb

Entry address:
0x2C239E

Entry point:
E8, D2, 07, 00, 00, E9, 36, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47, 8B, 54, 24, 10, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 14, 89, 54, 24, 10, 8B, 44, 24, 1C, 0B, C0, 7D, 14, 47, 8B, 54, 24, 18...
 
[+]

Code size:
3.4 MB (3,569,152 bytes)

The file PhotoScape.EXE has been discovered within the following program.

PhotoScape  by Mooii Tech
PhotoScape is a graphics editing program, developed by MOOII Tech. The basic concept of PhotoScape is 'easy and fun', so that allows users to easily edit photographs taken from their digital cameras or even mobile phones.
www.photoscape.org
9% remove it
 
Powered by Should I Remove It?

The file PhotoScape.EXE has been seen being distributed by the following 4 URLs.

http://dc342.4shared.com/download/.../PhotoScape.exe

Scan PhotoScape.EXE - Powered by Reason Core Security