pomoc.exe

PcHelpWare

uvnc bvba

This is a setup program which is used to install the application. The file has been seen being downloaded from www.piib.org.pl.
Publisher:
uvnc  (signed by uvnc bvba)

Product:
PcHelpWare

Description:
PCHelpWareV2

Version:
pchelpwareV2

MD5:
23a31649db70876a488d1bc9509beab3

SHA-1:
46da8a8ddf6b11ba15c22d4191d678b062b6109b

SHA-256:
fc85fe055f6e8a794bdbdd360e3e336dc41f7c947b0e17a99c2190cf23a1cb57

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 5:41:42 AM UTC  (today)

File size:
647.5 KB (663,068 bytes)

Product version:
pchelpwareV2

Copyright:
Copyright (c) 2012 uvnc

Original file name:
PCHelpWareV2.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pomoc.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/18/2011 5:15:46 PM

Valid to:
3/18/2014 5:15:42 PM

Subject:
CN=uvnc bvba, O=uvnc bvba, L=Antwerpen, S=Antwerpen, C=BE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012ECA04F7A4

File PE Metadata
Compilation timestamp:
1/3/2012 12:45:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:fA3N8SbGzV5w3YzqvajqxwixpAXHhaYhBIVo6bk7JfZ/ix5B0u4w:fAd8kGR23AJjqxwfXH8GNfZq5cw

Entry address:
0x13D81

Entry point:
E8, EE, 29, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, A0, 07, 42, 00, E8, 39, FC, FF, FF, 6A, 0E, E8, EB, 2B, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 4C, 3C, 42, 00, BA, 48, 3C, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 5B, F8, FF, FF, 59, FF, 76, 04, E8, 52, F8, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 28, FC, FF, FF, C3, 8B, D0, EB, C5, 6A, 0E, E8, B7, 2A, 00, 00, 59, C3, CC, CC, CC, CC, CC, 8B...
 
[+]

Code size:
100 KB (102,400 bytes)

The file pomoc.exe has been seen being distributed by the following URL.

Scan pomoc.exe - Powered by Reason Core Security