PPINUPDT.EXE

Protector Plus for Windows

Proland Software Private Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Protector Plus InstaUpdate’.
Publisher:
Proland Software  (signed by Proland Software Private Limited)

Product:
Protector Plus for Windows

Version:
8, 0, 79, 4

MD5:
d179f0f301e8d94ecc32729a452f155f

SHA-1:
c591cfa9bfe8cacd5b7360045598a7634b266600

SHA-256:
b59f48565032fb2ca016afe7227c74089fc8a56f7194ee1518737704314fde24

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 5:57:37 AM UTC  (today)

File size:
2.1 MB (2,193,736 bytes)

Product version:
8, 0, 79, 4

Copyright:
(c) Proland Software, 1991 - 2014

Trademarks:
Protector Plus

Original file name:
PPINUPDT.EXE

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/29/2014 4:00:00 AM

Valid to:
4/29/2015 3:59:59 AM

Subject:
CN=Proland Software Private Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Proland Software Private Limited, L=Bangalore, S=India, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5A8768E56756AAEE2A0A28540265B0E4

File PE Metadata
Compilation timestamp:
1/27/2014 9:47:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:SzUhiUvEHkHYeE1tH5OLO0dpy/Q6GQeU1pbGxewZwJ0ii2JA:S8Tv9YNcLO0dpy465HXGxewgRi2JA

Entry address:
0x38B5A

Entry point:
55, 8B, EC, 6A, FF, 68, 80, 96, 45, 00, 68, A8, 76, 43, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, FC, 52, 45, 00, 33, D2, 8A, D4, 89, 15, 10, 21, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 0C, 21, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 08, 21, 48, 00, C1, E8, 10, A3, 04, 21, 48, 00, 6A, 01, E8, 41, 2B, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 82, 50, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
336 KB (344,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Protector Plus InstaUpdate

Command:
C:\protec~1\ppinupdt.exe


Scan PPINUPDT.EXE - Powered by Reason Core Security