boinctray.exe

BOINC client

University of California, Berkeley

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘boinctray’. This is installed with BOINC.
Publisher:
Space Sciences Laboratory  (signed by University of California, Berkeley)

Product:
BOINC client

Description:
BOINC System Tray for Windows

Version:
7.0.44

MD5:
8d852ac2cfe7831643832e0bd590a385

SHA-1:
ecf4a6a9c0e2d80387e2082900eaac52f9f48d8e

SHA-256:
4a0b2842b4f2cb4f6266d1882ad7c58f810efb81e3204103a58064c2445e994b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 3:11:00 AM UTC  (today)

File size:
70.3 KB (71,976 bytes)

Product version:
7.0.44

Copyright:
© 2003-2013 University of California

Original file name:
boinctray.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\boinc\boinctray.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/7/2013 7:00:00 PM

Valid to:
1/4/2015 6:59:59 PM

Subject:
CN="University of California, Berkeley", OU=SPACE SCIENCES LABORATORY, O="University of California, Berkeley", L=Berkeley, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7A3A0B81EFB73737F878809989C13B50

File PE Metadata
Compilation timestamp:
1/8/2013 2:32:39 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:fzQMfuQMB+6Kd5WTVAiXltbzJraK5VXxsjLP1OiGhjWl/fsq:fMMmQMgf5WTVAQlZJrdbXxsj5OiGBWlt

Entry address:
0x1820

Entry point:
48, 83, EC, 28, E8, 37, 04, 00, 00, 48, 83, C4, 28, E9, BE, FC, FF, FF, FF, 25, 68, 9C, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 5C, 24, 10, 44, 89, 44, 24, 18, 48, 89, 4C, 24, 08, 56, 57, 41, 54, 48, 83, EC, 40, 49, 8B, F1, 41, 8B, F8, 4C, 8B, E2, 48, 8B, D9, 83, EF, 01, 89, 7C, 24, 70, 78, 0F, 49, 2B, DC, 48, 89, 5C, 24, 60, 48, 8B, CB, FF, D6, EB, E8, EB, 00, 48, 8B, 5C, 24, 68, 48, 83, C4, 40, 41, 5C, 5F, 5E, C3, CC, CC, CC, CC, CC, 40, 55, 48, 83, EC, 20, 48, 8B, EA, 48, 89, 4D, 38, 48, 89, 4D...
 
[+]

Entropy:
6.1488

Code size:
36.5 KB (37,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
boinctray

Command:
"C:\Program Files\boinc\boinctray.exe"


The file boinctray.exe has been discovered within the following program.

BOINC  by Space Sciences Laboratory, U.C. Berkeley
boinc.berkeley.edu
6% remove it
 
Powered by Should I Remove It?

Scan boinctray.exe - Powered by Reason Core Security