charityengine.exe

BOINC client

University of California, Berkeley

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘boincmgr’.
Publisher:
Charity Engine  (signed by University of California, Berkeley)

Product:
BOINC client

Description:
Charity Engine for Windows

Version:
7.0.80

MD5:
39c036e709f390c7a6ad6d14a29b0292

SHA-1:
fdeaac6964c6a3dde1f6d682376fa34084b039a6

SHA-256:
c845553d3e477c8958ea746eb7a217958271c47bb34c9a144e5031be0de3748c

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 3:39:51 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
3.7 MB (3,835,991 bytes)

Product version:
7.0.80

Copyright:
© 2003-2013 University of California

Original file name:
progressthruprocessors.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\boinc\charityengine.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/7/2013 4:00:00 PM

Valid to:
1/4/2015 3:59:59 PM

Subject:
CN="University of California, Berkeley", OU=SPACE SCIENCES LABORATORY, O="University of California, Berkeley", L=Berkeley, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7A3A0B81EFB73737F878809989C13B50

File PE Metadata
Compilation timestamp:
3/7/2014 11:52:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0xB5814

Entry point:
E9, BF, FB, 09, 00, E9, 39, FD, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 20, 56, 73, 00, 89, 0D, 1C, 56, 73, 00, 89, 15, 18, 56, 73, 00, 89, 1D, 14, 56, 73, 00, 89, 35, 10, 56, 73, 00, 89, 3D, 0C, 56, 73, 00, 66, 8C, 15, 38, 56, 73, 00, 66, 8C, 0D, 2C, 56, 73, 00, 66, 8C, 1D, 08, 56, 73, 00, 66, 8C, 05, 04, 56, 73, 00, 66, 8C, 25, 00, 56, 73, 00, 66, 8C, 2D, FC, 55, 73, 00, 9C, 8F, 05, 30, 56, 73, 00, 8B, 45, 00, A3, 24, 56, 73, 00, 8B, 45, 04, A3, 28, 56, 73, 00, 8D, 45, 08, A3, 34, 56, 73, 00, 8B...
 
[+]

Entropy:
6.1829

Packer / compiler:
Xtreme-Protector v1.05

Code size:
2.2 MB (2,281,472 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
boincmgr

Command:
"C:\Program Files\boinc\charityengine.exe" \a \s


Scan charityengine.exe - Powered by Reason Core Security