× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 4e95b33787820ef9f3f955852058eb74f1056b5f10504849c1e7428731273fbf
File name: cfw_installer.exe
Detection ratio: 0 / 56
Analysis date: 2016-03-23 09:27:57 UTC ( 1 year, 6 months ago )
Antivirus Result Update
Ad-Aware 20160323
AegisLab 20160323
Yandex 20160316
AhnLab-V3 20160323
Alibaba 20160323
ALYac 20160323
Antiy-AVL 20160323
Arcabit 20160323
Avast 20160323
AVG 20160322
Avira (no cloud) 20160323
AVware 20160323
Baidu 20160322
Baidu-International 20160322
BitDefender 20160323
Bkav 20160322
ByteHero 20160323
CAT-QuickHeal 20160323
ClamAV 20160319
CMC 20160322
Comodo 20160323
Cyren 20160323
DrWeb 20160323
Emsisoft 20160323
ESET-NOD32 20160323
F-Prot 20160323
F-Secure 20160323
Fortinet 20160323
GData 20160323
Ikarus 20160323
Jiangmin 20160323
K7AntiVirus 20160323
K7GW 20160323
Kaspersky 20160323
Malwarebytes 20160323
McAfee 20160323
McAfee-GW-Edition 20160323
Microsoft 20160323
eScan 20160323
NANO-Antivirus 20160323
nProtect 20160322
Panda 20160322
Qihoo-360 20160323
Rising 20160323
Sophos AV 20160323
SUPERAntiSpyware 20160323
Symantec 20160323
Tencent 20160323
TheHacker 20160321
TrendMicro 20160323
TrendMicro-HouseCall 20160323
VBA32 20160323
VIPRE 20160323
ViRobot 20160323
Zillya 20160322
Zoner 20160323
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright
2005-2016 COMODO. All rights reserved.

Product COMODO Internet Security
File version 8, 2, 0, 4978
Description COMODO Internet Security
Signature verification Signed file, verified signature
Signing date 9:26 PM 3/21/2016
Signers
[+] Comodo Security Solutions
Status Valid
Issuer COMODO Code Signing CA 2
Valid from 1:00 AM 1/4/2016
Valid to 12:59 AM 1/1/2017
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint F89A37FB24B0417D93BFB760B12121F5A358F9D9
Serial number 47 4B F5 DF D0 39 5C A9 26 B2 F2 36 7E 46 DC E8
[+] COMODO Code Signing CA 2
Status Valid
Issuer UTN-USERFirst-Object
Valid from 1:00 AM 8/24/2011
Valid to 11:48 AM 5/30/2020
Valid usage Code Signing
Algorithm sha1RSA
Thumbprint B64771392538D1EB7A9281998791C14AFD0C5035
Serial number 10 70 9D 4F F5 54 08 D7 30 60 01 D8 EA 91 75 BB
[+] UTN-USERFirst-Object
Status Valid
Issuer AddTrust External CA Root
Valid from 9:09 AM 6/7/2005
Valid to 11:48 AM 5/30/2020
Valid usage All
Algorithm sha1RSA
Thumbprint 8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA
Serial number 42 1A F2 94 09 84 19 1F 52 0A 4B C6 24 26 A7 4B
[+] The USERTrust Network?
Status Valid
Issuer AddTrust External CA Root
Valid from 11:48 AM 5/30/2000
Valid to 11:48 AM 5/30/2020
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha1RSA
Thumbprint 02FAF3E291435468607857694DF5E45B68851868
Serial number 01
Counter signers
[+] COMODO SHA-1 Time Stamping Signer
Status Valid
Issuer UTN-USERFirst-Object
Valid from 1:00 AM 12/31/2015
Valid to 7:40 PM 7/9/2019
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 03A5B14663EB12023091B84A6D6A68BC871DE66B
Serial number 16 88 F0 39 25 5E 63 8E 69 14 39 07 E6 33 0B
[+] UTN-USERFirst-Object
Status Valid
Issuer AddTrust External CA Root
Valid from 9:09 AM 6/7/2005
Valid to 11:48 AM 5/30/2020
Valid usage All
Algorithm sha1RSA
Thumbrint 8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA
Serial number 42 1A F2 94 09 84 19 1F 52 0A 4B C6 24 26 A7 4B
[+] The USERTrust Network?
Status Valid
Issuer AddTrust External CA Root
Valid from 11:48 AM 5/30/2000
Valid to 11:48 AM 5/30/2020
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha1RSA
Thumbrint 02FAF3E291435468607857694DF5E45B68851868
Serial number 01
Packers identified
F-PROT Unicode, appended, NSIS, UTF-8, UPX, 7Z
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-02-18 14:47:52
Entry Point 0x0001D0F6
Number of sections 5
PE sections
Overlays
MD5 baa5678e2d8962a556772a0b7815ef4b
File type data
Offset 1732608
Size 226855856
Entropy 8.00
PE imports
FreeSid
AllocateAndInitializeSid
CheckTokenMembership
GetDeviceCaps
GetCurrentObject
DeleteDC
CreateFontIndirectW
SelectObject
CreateCompatibleBitmap
GetObjectW
SetStretchBltMode
CreateCompatibleDC
DeleteObject
StretchBlt
SetThreadLocale
GetStdHandle
GetDriveTypeW
WaitForSingleObject
LockResource
CreateJobObjectW
EncodePointer
GetFileAttributesW
SetInformationJobObject
GetLocalTime
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
UnhandledExceptionFilter
LoadLibraryExW
FreeEnvironmentStringsW
GetLocaleInfoW
SetStdHandle
FindResourceExA
WideCharToMultiByte
LoadLibraryW
WriteFile
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
SetEvent
LocalFree
FormatMessageW
ResumeThread
InitializeCriticalSection
OutputDebugStringW
FindClose
TlsGetValue
SetFileAttributesW
GetEnvironmentVariableW
SetLastError
GetUserDefaultUILanguage
LoadResource
RemoveDirectoryW
IsDebuggerPresent
ExitProcess
GetModuleFileNameA
lstrcmpiW
SetProcessWorkingSetSize
GetSystemDefaultUILanguage
GetSystemDefaultLCID
InterlockedDecrement
MultiByteToWideChar
SetFilePointerEx
CreateThread
SetEnvironmentVariableW
GetSystemDirectoryW
GetExitCodeThread
SetUnhandledExceptionFilter
MulDiv
IsProcessorFeaturePresent
GetFileInformationByHandle
GetSystemDirectoryA
DecodePointer
TerminateProcess
GetVersion
GetModuleHandleExW
SetCurrentDirectoryW
GlobalAlloc
GetDiskFreeSpaceExW
SetEndOfFile
GetCurrentThreadId
LeaveCriticalSection
WriteConsoleW
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
TerminateThread
lstrcmpiA
GetVersionExW
GetExitCodeProcess
QueryPerformanceCounter
TlsAlloc
FlushFileBuffers
LoadLibraryA
RtlUnwind
ExitThread
GetFileSize
GetStartupInfoW
CreateDirectoryW
DeleteFileW
WaitForMultipleObjects
GetProcessHeap
AssignProcessToJobObject
lstrcpyW
GetModuleFileNameW
ExpandEnvironmentStringsW
FindNextFileW
ResetEvent
FindFirstFileW
lstrcmpW
GetProcAddress
CreateEventW
CreateFileW
GetFileType
TlsSetValue
HeapAlloc
InterlockedIncrement
GetLastError
SystemTimeToFileTime
LCMapStringW
lstrlenA
GlobalFree
GetConsoleCP
GetEnvironmentStringsW
lstrlenW
CreateProcessW
GetQueuedCompletionStatus
SizeofResource
CompareFileTime
GetCurrentProcessId
CreateIoCompletionPort
SetFileTime
GetCommandLineW
GetCPInfo
HeapSize
GetCommandLineA
SuspendThread
RaiseException
TlsFree
SetFilePointer
ReadFile
CloseHandle
GetACP
GetModuleHandleW
IsValidCodePage
GetTempPathW
VirtualFree
Sleep
IsBadReadPtr
VirtualAlloc
GetOEMCP
SysAllocStringLen
SysFreeString
VariantClear
OleLoadPicture
SysAllocString
SHBrowseForFolderW
ShellExecuteW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
SHGetSpecialFolderPathW
SHGetMalloc
SetFocus
GetParent
EndDialog
SystemParametersInfoW
DefWindowProcW
KillTimer
GetMessageW
ScreenToClient
ShowWindow
MessageBeep
SetWindowPos
GetClassNameA
wvsprintfW
GetSystemMetrics
SetWindowLongW
IsWindow
GetMenu
GetWindowRect
EnableWindow
UnhookWindowsHookEx
CharUpperW
MessageBoxA
LoadIconW
GetWindowDC
GetWindow
GetSysColor
DispatchMessageW
GetDC
GetKeyState
ReleaseDC
SendMessageW
GetWindowLongW
DrawIconEx
DestroyWindow
GetClientRect
SetTimer
GetDlgItem
DrawTextW
CallWindowProcW
EnableMenuItem
ClientToScreen
CallNextHookEx
wsprintfA
CreateWindowExA
LoadImageW
DialogBoxIndirectParamW
SetWindowTextW
GetWindowTextW
SetWindowsHookExW
GetSystemMenu
GetWindowTextLengthW
CreateWindowExW
wsprintfW
CopyImage
PtInRect
CreateStreamOnHGlobal
CoCreateInstance
CoInitialize
Number of PE resources by type
RT_ICON 42
RT_GROUP_ICON 2
RT_MANIFEST 1
RT_VERSION 1
Number of PE resources by language
RUSSIAN 22
UKRAINIAN DEFAULT 21
ENGLISH US 3
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
5.1

LinkerVersion
11.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
8.2.0.4978

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

CharacterSet
Windows, Latin1

InitializedDataSize
1587200

EntryPoint
0x1d0f6

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
8, 2, 0, 4978

TimeStamp
2016:02:18 15:47:52+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
8, 2, 0, 4978

FileDescription
COMODO Internet Security

OSVersion
5.1

FileOS
Win32

LegalCopyright
2005-2016 COMODO. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
COMODO

CodeSize
144384

ProductName
COMODO Internet Security

ProductVersionNumber
8.2.0.4978

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 37b5b221402a14cd72dbac876f10cbf7
SHA1 c65ebbae96db2b69f1f61a6545e06885ab605042
SHA256 4e95b33787820ef9f3f955852058eb74f1056b5f10504849c1e7428731273fbf
ssdeep
6291456:1we9RX42nTsoWtB5itndGPcuR8egQHTM/Ue4Q:1X5nTUWdeF5HTMV

authentihash 57143bae0c3b08eebf349839b2bf3b51789f04012d9a39cd382a03a70e5f3520
imphash cb2f8861ae9e888fc248b97ed817726f
File size 218.0 MB ( 228588464 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Generic Win/DOS Executable (50.0%)
DOS Executable Generic (49.9%)
Tags
nsis peexe upx signed overlay

VirusTotal metadata
First submission 2016-03-23 09:27:57 UTC ( 1 year, 6 months ago )
Last submission 2016-03-23 09:27:57 UTC ( 1 year, 6 months ago )
File names cmd_fw_installer_6113_c7.exe
cfw_installer.exe
cmd_fw_installer_6113_c7.exe
cmd_fw_installer_6113_c7.exe
cfw_installer_6106_53(1).exe
cmd_fw_installer_6113_c7.exe
4E95B33787820EF9F3F955852058EB74F1056B5F10504849C1E7428731273FBF.exe
4E95B33787820EF9F3F955852058EB74F1056B5F10504849C1E7428731273FBF.exe
cmd_fw_installer_6113_c7.exe
cmd_fw_installer.exe
cfw_installer_6106_53.exe
cfw_installer.exe
cfw_installer_6106_53.exe
cfw_installer_6106_53.exe
cmd_fw_installer(1).exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!