zftpcopy.exe

Z-FTPCopyII

Andreas Baumann

Publisher:
Z-Software Manufaktur Ltd.  (signed by Andreas Baumann)

Product:
Z-FTPCopyII

Version:
3.07.0004

MD5:
4eb49a84ded9481b48e80d71f9707940

SHA-1:
f58b884608a10a0d65779bbadccda74a4099eec3

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/15/2024 11:34:37 AM UTC  (today)

Scan engine
Detection
Engine version

Quick Heal
(Suspicious) - DNAScan
11.14.11.00

File size:
807.9 KB (827,272 bytes)

Product version:
3.07.0004

Copyright:
© A.Baumann 2006 - 20010

Original file name:
zftpcopy.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\z-dbackup\zftpcopy.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/8/2010 1:00:00 AM

Valid to:
2/20/2011 12:59:59 AM

Subject:
CN=Andreas Baumann, OU=SECURE APPLICATION DEVELOPMENT, O=Andreas Baumann, L=Berlin, S=Berlin, C=DE

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
7C65C550EF3872A3BEFFAE18C4180614

File PE Metadata
Compilation timestamp:
3/21/2010 5:08:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:tB9e7do0MShAlNoGtf8mNk41vc6V0oc6V0:tB9mo0MT+C8c3vc6V0oc6V0

Entry address:
0x5D1C

Entry point:
B8, 34, 3E, 6A, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 60, 37, 21, B9, 54, 9E, 68, D4, BB, 64, F5, AD, 94, BA, 29, 3C, F9, D5, 74, AC, DE, 5E, 8A, 1B, 08, BC, CC, BA, 02, CE, 45, 29, B0, 97, 33, 25, 7F, B4, 81, 19, 34, E9, 2C, 53, D8, 80, 61, 55, AB, 0E, 12, F5, 94, 7C, 33, 22, DA, E6, 59, 29, 98, 26, 43, 93, 5D, 47, 55, C5, 35, FF, 29, BD, 6D, D4, A8, EC, E9, 5A, 44, 65, C1, 91, 2D, B5, A8, FC, 41, 1E, DF, 4F, 2B, C5, 0C...
 
[+]

Packer / compiler:
PECompact v2

Code size:
1.5 MB (1,597,440 bytes)

Scan zftpcopy.exe - Powered by Reason Core Security