unins000.exe

  • File Path: C:\Program Files (x86)\WinSCP\unins000.exe
  • Description: Setup/Uninstall
  • Comments: This installation was built with Inno Setup.

Hashes

Type Hash
MD5 2662BB94D77F4859FCEAE4EE80E98127
SHA1 7F934976E364CE4EC4A43985D8E9F198DE8E2487
SHA256 3A299A5666724BED608D34EF47B9B99DFC6867CB6DD0D1B6998F4D01B4F1E0C8
SHA384 4814ECFB59068DF51E18BB78395A5F1EC79DF05A2445E5203FE08055BA6BA8DB2AE5C1FD9C14E83637D1FAF647CD52BE
SHA512 19C038AF48D454E97EDF888ED35BCC0065E8868E4DB1668B280F3758F9FA3ED74170925BF5928ADE8CB68DC4533AE084474A8DD11D20B61C1FDEAD662241EC19
SSDEEP 49152:xEA9P+bz2cHPcUb6HSb4SOEMkBeH7nQckO6bAGx7jXTV1IMgK/sdZvaKBaJhg33m:V92bz2Eb6pd7B6bAGx7DI3333W
IMP 9825B4C9A35EB9A5C5E347CB9CA988EE
PESHA1 E653BA4D62BFA830739C410C521B04E894C5FFBB
PE256 9D0A312EF2F0532256FB5DAE90DF94CBB4C8E9DCDC9C460856579BA658730745

Runtime Data

Child Processes:

_iu14D2N.tmp

Open Handles:

Path Type
(R-D) C:\Windows\System32\en-US\kernel32.dll.mui File
(R-D) C:\Windows\System32\en-US\KernelBase.dll.mui File
(R-D) C:\Windows\System32\en-US\netmsg.dll.mui File
(R-D) C:\Windows\SysWOW64\en-US\user32.dll.mui File
(RW-) C:\Program Files (x86)\NVDA\lib\2021.2 File
(RW-) C:\Windows File
(RW-) C:\Windows\SysWOW64 File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984 File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\Windows\Theme449731986 Section
\Windows\Theme1396518710 Section

Loaded Modules:

Path
C:\Program Files (x86)\WinSCP\unins000.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 0232466DC95B40EC9D21D9329ABFCD5D
  • Thumbprint: FB845245CFBB0EE97E76C775348CAA31D74BEC4C
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=Martin Prikryl, O=Martin Prikryl, L=Prague, C=CZ, SERIALNUMBER=87331519, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=CZ

File Metadata

  • Original Filename: WinSCP-5.19.4-Setup.exe
  • Product Name: WinSCP
  • Company Name: Martin Prikryl
  • File Version: 51.1052.0.0
  • Product Version: 5.19.4
  • Language: Language Neutral
  • Legal Copyright: (c) 2000-2021 Martin Prikryl
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/3a299a5666724bed608d34ef47b9b99dfc6867cb6dd0d1b6998f4d01b4f1e0c8/detection

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\WinSCP\unins000.exe 36

MIT License. Copyright (c) 2020-2021 Strontic.