PRunOnce.exe

Panasonic Run Once

Matsushita Electric Industrial Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PRunOnce’.
Publisher:

Product:
Panasonic Run Once

Version:
2, 0, 10, 0

MD5:
484520d1f2972305f089b34f1e74bc68

SHA-1:
578d82216abe38c343fa8bd7afa56d775912f322

SHA-256:
878f34684d9d8ae239e45ec5c6a0f125740893766e066a02c071e20892662a2f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 1:02:54 AM UTC  (today)

File size:
157.6 KB (161,424 bytes)

Product version:
V2.00L10 M00

Copyright:
Copyright (C) 2003-2006 Matsushita Electric Industrial Co., Ltd.

Trademarks:
Panasonic

Original file name:
PRunOnce.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/1/2005 9:00:00 AM

Valid to:
12/2/2006 8:59:59 AM

Subject:
CN="Matsushita Electric Industrial Co., Ltd.", OU="IT Products Division, Panasonic AVC Networks Company", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Matsushita Electric Industrial Co., Ltd.", L="1-10-12 Yagumohigashimachi, Moriguchi", S=Osaka, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0E75139B043B2CC614EE81CA86F721D2

File PE Metadata
Compilation timestamp:
11/30/2006 12:49:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:pOXhfHOZlRRDySVzWb2JT3VFaCtS6FJ2gYtvF06:Oh2RRDyS5Wb2JbVLNFJkF

Entry address:
0xBDD0

Entry point:
E8, 1D, 52, 00, 00, E9, 16, FE, FF, FF, 6A, 0C, 68, 28, 13, 42, 00, E8, 46, 09, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, F0, 86, 42, 00, 77, 22, 6A, 04, E8, 00, 54, 00, 00, 59, 83, 65, FC, 00, 56, E8, 42, 5C, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 52, 09, 00, 00, C3, 6A, 04, E8, FD, 52, 00, 00, 59, C3, 55, 8B, 6C, 24, 08, 83, FD, E0, 0F, 87, 9F, 00, 00, 00, 53, 8B, 1D, 94, C0, 41, 00, 56, 57, 33, F6, 39, 35, 74, 73, 42, 00, 8B, FD, 75, 18, E8, FD, 47, 00...
 
[+]

Entropy:
6.3711

Code size:
108 KB (110,592 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PRunOnce

Command:
C:\util\prunonce\prunonce.exe


Scan PRunOnce.exe - Powered by Reason Core Security