ClinckSupport.exe

iCafe Manager

Ideacts Innovations Pvt Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Clinck v3’.
Publisher:
Ideacts Innovations Pvt. Ltd.  (signed by Ideacts Innovations Pvt Ltd)

Product:
iCafe Manager

Description:
Clinck System Bootstrap Application.

Version:
1.0.0.1

MD5:
e7824a9b1ff1f2f4174e5e5c492d176b

SHA-1:
1978d329ddec95f17a986f8fdf76b4c66119507a

SHA-256:
fd72ba5e6b9484cb18ccf2f7be01be9bd97dc6474c141921898f88ee68f1d721

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
9/21/2024 12:07:25 AM UTC  (today)

File size:
209.9 KB (214,912 bytes)

Product version:
1.0.0.1

Copyright:
© Ideacts Innovations Pvt. Ltd. All rights reserved.

Original file name:
ClinckSupport.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\admin\clincksupport.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/4/2011 2:00:00 AM

Valid to:
9/3/2012 1:59:59 AM

Subject:
CN=Ideacts Innovations Pvt Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ideacts Innovations Pvt Ltd, L=Pune, S=Maharashtra, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F78A337BBCEC44683F94EB8F96D69

File PE Metadata
Compilation timestamp:
5/22/2012 12:07:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:iGDL95tzKMF/5YSmvUWyWXYwCdMOODEd5h25wvWYZL:iAxzKMF7yqODEdou

Entry address:
0xB96B

Entry point:
E8, C4, 03, 00, 00, E9, 36, FD, FF, FF, 3B, 0D, 44, E0, 41, 00, 75, 02, F3, C3, E9, 44, 04, 00, 00, 53, 8A, 5C, 24, 08, F6, C3, 02, 56, 8B, F1, 74, 24, 57, 68, FC, BE, 40, 00, 8D, 7E, FC, FF, 37, 6A, 0C, 56, E8, 3E, 01, 00, 00, F6, C3, 01, 74, 07, 57, E8, 61, F8, FF, FF, 59, 8B, C7, 5F, EB, 13, E8, 42, 05, 00, 00, F6, C3, 01, 74, 07, 56, E8, 4B, F8, FF, FF, 59, 8B, C6, 5E, 5B, C2, 04, 00, 6A, 14, 68, B8, 87, 41, 00, E8, B3, 02, 00, 00, FF, 35, 54, EC, 41, 00, 8B, 35, 28, 07, 41, 00, FF, D6, 59, 89, 45, E4...
 
[+]

Entropy:
6.1498

Code size:
60 KB (61,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Clinck v3

Command:
C:\users\admin\clincksupport.exe


Scan ClinckSupport.exe - Powered by Reason Core Security