cexpert_tray.exe

Tray Icon For CryptoExpert

InterCrypto

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘cryptoexpert’.
Publisher:
InterCrypto Ltd  (signed by InterCrypto)

Product:
Tray Icon For CryptoExpert

Version:
8, 31, 13519, 4577

MD5:
9d3b30ba24e69eea7019bb07e86b99df

SHA-1:
3f567a5d09755f028ecb59929ff822a28f356858

SHA-256:
19e2c83172f80f06600bd12813c9b82ce9cd5e89b53dc1efbd59c2d2423fd398

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:18:17 AM UTC  (today)

File size:
598.3 KB (612,688 bytes)

Product version:
1.0.0.1

Copyright:
InterCrypto Ltd

Original file name:
CryptoExpertTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cryptoexpert 8\cexpert_tray.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2012 11:00:00 AM

Valid to:
2/21/2014 10:59:59 AM

Subject:
CN=InterCrypto, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=InterCrypto, L=Penza, S=Penza, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3F2A6FBFFD191BD50D54806F4A73BA5B

File PE Metadata
Compilation timestamp:
12/19/2013 7:47:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:41Fbjl+sUk1bQs1Uvvq6xGJOpqAurVWAuf3:SFf8sUk1bQEUK0GkpQDU

Entry address:
0x1000

Entry point:
68, 01, 90, 49, 00, E8, 01, 00, 00, 00, C3, C3, 4E, 8D, A7, 33, B3, B0, 0F, 4F, A9, ED, E9, 9E, 62, 30, 84, FF, 66, 53, 82, 84, E6, 89, 9B, 01, 8A, 95, 20, 18, 5B, 48, 53, 28, 1B, 33, C6, 8E, DD, F5, 95, 1D, 76, 84, 48, E5, 6E, F2, DE, 7F, 72, 13, 03, C3, 5E, D3, 5E, 99, 12, BB, 53, E5, 97, 19, 58, 62, 76, 0F, F1, 62, FE, 98, 8B, AD, 2A, B6, 5C, CE, 6E, 18, 82, DF, 52, E7, EC, 99, 28, C4, 29, 20, 88, A2, 6F, 33, C3, D7, 6C, BB, F1, 7F, 78, DE, CE, 76, 2A, 5B, CF, 04, 69, 62, 91, 8B, D2, C4, 02, BC, 95, 1A...
 
[+]

Entropy:
7.8273

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
436 KB (446,464 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cryptoexpert

Command:
"C:\Program Files\cryptoexpert 8\cexpert_tray.exe"


Scan cexpert_tray.exe - Powered by Reason Core Security