AcroTray.exe

AcroTray - Adobe Acrobat Distiller helper application.

Adobe Systems, Incorporated

The executable AcroTray.exe has been detected as malware by 9 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Acrobat Assistant 8.0’.
Publisher:
Adobe Systems Inc.  (signed by Adobe Systems, Incorporated)

Product:
AcroTray - Adobe Acrobat Distiller helper application.

Description:
AcroTray

Version:
10.1.16.13"

MD5:
61241d0c374a9f69d78277e73a8baa2a

SHA-1:
dcfd621962813dde6419a2aca81a1b385f918a72

SHA-256:
3d59e25d37c9add189c430aacaab2b4524d8dac7980fa24f5e620e969765736b

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/25/2024 8:22:19 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160327-1

AVG
Win32/Floxif.A
2015.0.4542

Dr.Web
Win32.FloodFix.7
9.0.1.05190

Emsisoft Anti-Malware
Win32.Floxif
11.5.0.6191

ESET NOD32
Win32/Floxif.H virus
7.0.302.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.96

Kaspersky
Virus.Win32.Pioneer
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.217.955.0

File size:
897.3 KB (918,871 bytes)

Product version:
10.1.16.13"

Copyright:
Copyright © Adobe Systems Inc. 1992-2012

Original file name:
AcroTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\adobe\acrobat 10.0\acrobat\acrotray.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
6/4/2015 12:00:00 AM

Valid to:
5/7/2017 11:59:59 PM

Subject:
CN="Adobe Systems, Incorporated", OU=AcrobatX, O="Adobe Systems, Incorporated", L=San Jose, S=California, C=US, SERIALNUMBER=2748129, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
772C5535FC3A40E39F632C599AB6631D

File PE Metadata
Compilation timestamp:
9/24/2015 9:18:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:5jgoP9kHcmf9m4fr9tW3B54SS5TTrcOL7Z3HSUbOiRfNUR/TiFS3BYHBjvrEH7o:rhiZ8M4Q7pHSUbOKXqGFrEH7o

Entry address:
0x49144

Entry point:
E9, FA, 4F, 04, 00, E9, 79, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 78, 4B, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 78, 4B, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.1974

Packer / compiler:
Xtreme-Protector v1.05

Code size:
602 KB (616,448 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Acrobat Assistant 8.0

Command:
"C:\Program Files\adobe\acrobat 10.0\acrobat\acrotray.exe"


Remove AcroTray.exe - Powered by Reason Core Security