CAUSTray.exe

CAUSTray

Curriculum Advantage, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘CAUSTrayApp’. This is installed with Classworks Auto Update Service.
Publisher:
Curriculum Advantage  (signed by Curriculum Advantage, Inc.)

Product:
CAUSTray

Version:
1.0.0.0

MD5:
a6238d0ebc9629bda06a6f9e7c2526d8

SHA-1:
17b15ed21b1231addd04d4d89efe6df54385e179

SHA-256:
225c7df16c8a2f8f54fbc87f4d555468efa98be5aea6bcc11ad83077e17842bf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:10:57 PM UTC  (today)

File size:
317.9 KB (325,496 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Curriculum Advantage 2010

Original file name:
CAUSTray.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\curriculum advantage\classworks auto update service\caustray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/7/2009 8:00:00 PM

Valid to:
5/19/2012 7:59:59 PM

Subject:
CN="Curriculum Advantage, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Curriculum Advantage, Inc.", L=Duluth, S=Georgia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F6600E095AEB703D83963195239DAAE

File PE Metadata
Compilation timestamp:
6/28/2010 4:08:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:Q56UGGmg5bnQANLlRRbgEgamD/PTlftoupM9vS4Hj5VF:SGGt5bXLlRRTgaWzlWupM93jHF

Entry address:
0x49B7E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6008

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
288 KB (294,912 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CAUSTrayApp

Command:
"C:\Program Files\curriculum advantage\classworks auto update service\caustray.exe"


The file CAUSTray.exe has been discovered within the following program.

Classworks Auto Update Service  by Curriculum Advantage
http;//www.Classworks.com
About 6% of users remove it
 
Powered by Should I Remove It?

Scan CAUSTray.exe - Powered by Reason Core Security