slideshow.exe

Photo Slideshow Creator

AMS Software

This is a setup and installation application. The file has been seen being downloaded from dw.id.uptodown.com and multiple other hosts.
Publisher:
AMS Software   (signed by AMS Software)

Product:
Photo Slideshow Creator

Description:
Photo Slideshow Creator Setup

MD5:
375185e48512c7bf59ca748fa9ce7361

SHA-1:
0ac9a236d7aa06a144a4946e2ccb76f8769c410b

SHA-256:
a632e74d8919b5553575a2edda0bad7f341dbec0edf581cd44f12c4b1d448ed7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 5:35:23 PM UTC  (today)

File size:
57.6 MB (60,411,976 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/1/2013 1:00:00 AM

Valid to:
8/24/2015 12:59:59 AM

Subject:
CN=AMS Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AMS Software, L=Yaroslavl, S=Yaroslavskaya oblast, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
531579134817451A78A49643FA819E4F

File PE Metadata
Compilation timestamp:
1/30/2013 3:21:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1572864:0W1sRQG2a+VFZCylocHi3oPS9ed1XQdi9OdR1Qq7P0Tm7rm7l:Ls2lVFZCd13oPS9MCi9+fhWorA

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file slideshow.exe has been seen being distributed by the following 12 URLs.

http://dw.id.uptodown.com/dl/1442043386/.../photo-slideshow-creator-4-31-en-win.exe

http://gsf-cf.softonic.com/0ac/9a2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=322472&instance=softonic_es&type=PROGRAM&Expires=1448510573&Signature=F-gOxYBX06OtTIzGXUDQsq0uIgvqVUvNQOhjkU45xI3Izcn4nFtpxxjxxf5x61y8EHDZS6NQCUIin4uEPcprHoaowMIiwu9w9QLYE7J7MF-B8rGYzfspunh1yv~VtI3L9aH1tqzkkldjGVACu3j8fqXD-AiKmEN3TpIRFL115m0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Slideshow.exe

http://dw.uptodown.com/dwn/cVDz-cZiZJjJr0rdb8K0KG75NIUghvc1SSwSTdKZNJ5rUISQ0GMw0oVJ69gzIbQukkkE5vtgkqxi3eQxYgjlcJL_EcpdG9Fwp-qVBn7wBKw6lvzqpfQHRsadhTkCItpd/WUSvKC8YmzMpmrtu28qWeVGIUbbhmcsKg5YonCrkftNK-6zQ0wt_EAVgSAzQ-nCMX6liOX-HkBjvmTUBa2-3-UgJVxkKZzWoYAj1VDBkP7sLWIWOL-aRJUaGPt4mXSCu/UOueoI-5luvWn6tU7EOnSln4GeSG_ygx29hz1XHVW-xOiQnnGO9Qr7yIEBhPpdjMqd3kX75WPuDrYW-tAIYY-UFF9fB1v2wV-XUjF6ymOIZ_DwFZhwMh_-1otF0F41_0/.../

http://gsf-cf.softonic.com/0ac/9a2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=322472&instance=softonic_es&type=PROGRAM&Expires=1473668672&Signature=XITBS5FNqwNq5C-hkHuONJ-JbEEvk4xipJQyKqQQNbRK5IJ5u3iGm2Oxx-XLS72HnNxhL3Aqb4xIa88dAl~x0mVKC5dfpCbmV71DXPx~cy-xKXwKmQ8Xvfnr~kzBXPrUUP0zzjf0L2On4rasoWw9PZLeAiefdiIUiF1gik3sk-Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Slideshow.exe

http://gsf-cf.softonic.com/0ac/9a2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=322472&instance=softonic_es&type=PROGRAM&Expires=1437300414&Signature=dfd6LfBe0BAcKq5678iQnPYNZg9iIt0mo0oLhYaMvnUImVCw87rO~CWqsiZ12FxFqljLXyK62bWmHwqPb4-ITfJFrPIx8ILxfk6FLNTiRwBhi4uipvlTnaewtVXHpBj76lsJzxjl5pGT0jZ0BCrcrBY6YqqCsKjVfFOYWwkEurg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=Slideshow.exe

https://dw.uptodown.com/dwn/tPtBMhfweX6tQo-GJedeB_tfftAmAT6rCGT02lT_rw5A4g5nuHO9UTXk3jNOt4fC0WRtfSrBRRRRo5y7Bk1MwkgEVJVh3jAtdsDB3-lyXHLzpwFx6uhaZ1m11RcYyrK8/ddkokdaxnRGB11lsSEDc4lLvjmKhEWuyenOOJ11S2fJycWLuZ-XsWFZbKHy1AO8sNubM1IJ6QsFdq5ax7x5QTytqBRYBoU6VmaiV04jYi22KMPtxK8ez4Xn46R7cHvgW/FI-WOR-Q3cIHn0AIKoySy-ppUmoVrRDSJuaUyojfFTSLLFDM7QnE72QZJ3521vfUV1iETorDE50jFUl5BT7n7LH0UPULsmIRRY1Zkz3dojvDNWEZSpi6wo1jlUsdK6cV/.../

https://dw.uptodown.com/dwn/CCkEqWVTim--wBglYu-rmmCkZA0FTvKMHaBGkKUvlg0k90gCu0UQ7zrYtSrNZXDe13bn6RElOY82QkR5egWt9KVcIA2rpjOp0uq_823jexcgcNvsf5xdD0cneUkg32xJ/RFlgm_n3l9Eeln65YXGEJhlOLvnNBnHjvZGFkIbWD49wzpKJ4vdtC63QxCcKjZ-qWb0e6RAhm7e6u-EzsFYTkotkZEK8undWoBZrIYy2jcXB4Xxs317Ehlac4JF5xlgN/-5WK9LFHt9N877ab8qlBkPgknD_1dLzAKpEjUtHM-4KP2Ktp2FfgxkNYGMyh8jyArY0WToXOLSBB7Lale00ywC3VlvtNyTph3wx8id-cnlwtuq4hYXYaVXmUaaxGjNi6/.../

https://dw.uptodown.com/dwn/7CItuvXziaDq9k7XCERz2zb_Yg1tsjtOa2DhzXzCJjn8Bj7CcX03FCdUXYGMHJjrQkaL_c6QRu9GL478pKSJEVsM2du6-GDOg_qhot7YkhKFGXm9BIYttkpqTLsuYMez/exElidLlvSq7oF-ESs-it7pIuSPCMEuEMdMPoUFSMoj3QwC_7iLl_LHiQay0L9SPpPXjs2Fnpuwz6lYlqiYuQ31NQMhFWPHqtMq3MQ2ADR2KE3KpuZ1cUjDAw87kx16u/fbd46NpZdIbhWEd1y7zPEX-tcNbcNQ78SnWbcOI88WTbgnf5sO6sM374Eth76jdLneCcQxxu_qAl4e5xIXYTlIksyzmFtkZZQxak4NbTuB8wVks8XtjcGDxiraKn_1Qs/.../

https://dw.uptodown.com/dwn/sT4_XluYy8S0hA4JYh-gSX53NaJMiFV8VEVFpmFu9-lLChBxfQZBxHkjAtiR6hqSj3Q14bZobkdUBJIzhNL0jMS9PvzCoKT4waL163oNiOn7qUCKK4eJvA4j9K2K5yEP/1fcTrv2zyWd7BFDhNJO5o54xzPWPlZlzzXJ_KFh_Mv5V7n7wFBi2kqAMRkk0ItIeFv_cfaD68p0zlIAj_qrB4SrmXS7hW9JeC0kApDD28rsDagae9vx5x7lPF805BvYN/gFgUm4NVrbiF2Sw11urU-ucKrBLG76JNmjP_X6MF2uLc4SHgPEY8N6c2L1wI49wX5pnu8tC47Gkh45fOpFsFmDw_7JnjEW-VORtVOEaDML1kKmvJZkXGJxe-YYCGig63/.../

Scan slideshow.exe - Powered by Reason Core Security