copytransmanager.exe

CopyTrans Manager

WindSolutions LLC

Publisher:
WindSolutions  (signed by WindSolutions LLC)

Product:
CopyTrans Manager

Version:
0.8.6.6

MD5:
7d13118abcda2856071a5dc756cd2aa0

SHA-1:
3e771fb2caa58bfd989706943dc1b36a5f51d5a9

SHA-256:
060a59adf101f86285aa7117c1e08ba7e6139cafb8088f0494a77a0c8cdb15ea

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/16/2024 7:56:30 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
22354

Dr.Web
Trojan.Packed.191
9.0.1.014

File size:
3.4 MB (3,537,688 bytes)

Product version:
1.0.0.0

Copyright:
WindSolutions

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\copytransmanager.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/27/2009 2:19:18 PM

Valid to:
5/28/2011 7:54:47 AM

Subject:
CN=WindSolutions LLC, OU=Development, O=WindSolutions LLC, L=Geneva, S=VD, C=CH

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
6A2DC8C96041ED2977F679AB181ECC3B

File PE Metadata
Compilation timestamp:
9/28/2009 8:33:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
49152:j8FoeAZSf82oqhzunZGuny/JfAB1lO4tbWx30crzqmpSZAwpSzog8sb:wcO82PuZ9nEpArMOby3A3pm8U

Entry address:
0x1000

Entry point:
EB, 06, 68, 2E, A8, 00, 00, C3, 9C, 60, E8, 02, 00, 00, 00, 33, C0, 8B, C4, 83, C0, 04, 93, 8B, E3, 8B, 5B, FC, 81, EB, 3F, 90, 40, 00, 61, 9D, E9, E7, 71, 3B, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Packer / compiler:
PECompact v1.4x+

Scan copytransmanager.exe - Powered by Reason Core Security