daymate.exe

DayMate

Crystal Office Systems

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DayMate’.
Publisher:
Crystal Office Systems  (signed and verified)

Product:
DayMate

Version:
6.5.5.0

MD5:
e4d8bcba1d5180a17a2401b99f67829e

SHA-1:
13271bb24409511b05426c562e3b45c7a970af11

SHA-256:
38175217cf044d4a4fa8b823b2f5da088e78a242910f1be1c8aa9ff51cb3f1b5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:08:47 AM UTC  (today)

File size:
5.9 MB (6,185,568 bytes)

Product version:
6.55

Copyright:
© 1999-2012 Crystal Office Systems

Original file name:
daymate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\crystal office\daymate\daymate.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/7/2012 4:00:00 PM

Valid to:
2/7/2014 3:59:59 PM

Subject:
CN=Crystal Office Systems, O=Crystal Office Systems, STREET="Kantemirovskaya street, 53-1-51", L=Moscow, S=RU, PostalCode=115477, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
641A324A34F2B894BA79BC39CE01E16A

File PE Metadata
Compilation timestamp:
5/19/2012 12:55:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
98304:iDA5xv2EdVt7LbTztPn+G8hiwCqDa2uKIOVvd+UG4qoz0gqilw4OU7Z3:df9dVxHTztZ8hDCqDNuK5Vlqoz5qilw6

Entry address:
0x1000

Entry point:
68, 01, D0, 47, 01, E8, 01, 00, 00, 00, C3, C3, 75, BA, 04, 48, 32, 3D, 43, A7, A5, A5, 95, 67, B8, F9, E7, 3E, 48, CF, 6A, 38, 30, 6D, D8, AA, 51, E5, BB, C2, 32, D8, 52, F0, D3, 56, 61, 45, 88, 13, 45, 40, 47, 1F, 92, 06, 88, 1A, 54, 4F, 3A, 68, DE, 13, EF, 3A, 1A, 1F, 3E, 1C, 62, 7A, F7, 3A, DC, 09, 15, 53, B4, E5, EB, E5, 71, 91, FB, 86, 26, EC, 9C, 96, 82, EC, 41, 49, D9, 4C, 98, A0, B1, 55, 83, 5F, 0C, 87, 98, 2C, 57, 77, C7, 23, 52, A4, D0, EB, 1F, 81, 6D, 90, 6E, BF, 89, C4, 9A, 13, 3D, 8A, 3A, C2...
 
[+]

Entropy:
7.9664

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
7.9 MB (8,290,304 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DayMate

Command:
C:\Program Files\crystal office\daymate\daymate.exe


Scan daymate.exe - Powered by Reason Core Security