dqrschdl.exe

Digora for Windows DICOM

PaloDEx Group Oy

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DQRSCHEd’.
Publisher:
SOREDEX  (signed by PaloDEx Group Oy)

Product:
Digora for Windows DICOM

Description:
DICOM Query Retrieve Scheduler

Version:
2.6.101.190

MD5:
5d54d3cf28f1d950f11c3ac9cacd8ae9

SHA-1:
726c290e30e449d7f59b8310e89ec3b2881ade34

SHA-256:
c3124c53118f69495be9ab1102a88e310bc227dc973b08512e11eb5833a60470

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 3:10:05 PM UTC  (today)

File size:
49.2 KB (50,424 bytes)

Product version:
2.6.101.190

Copyright:
Copyright (C) 2007 SOREDEX

Original file name:
QRSchdl.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\soredex\dfw 2.9\dqrschdl.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/25/2008 5:30:00 AM

Valid to:
4/6/2009 5:29:59 AM

Subject:
CN=PaloDEx Group Oy, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PaloDEx Group Oy, L=Tuusula, S=Uusimaa, C=FI

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29EBF74EE4A37C3B3369261B3E404924

File PE Metadata
Compilation timestamp:
3/25/2009 2:15:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
768:1pTtZoa/28bhAl08RK7Y/2lbOH7vwhDhiJzxqAhBL2b+:uohKDE7Y/2lbsDwhQJzxPBi+

Entry address:
0x415D

Entry point:
6A, 70, 68, 68, 5D, 40, 00, E8, 13, 03, 00, 00, 33, DB, 53, 8B, 3D, 38, 50, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 4C, 53, 40, 00, 59, 83, 0D, 50, 71, 40, 00, FF, 83, 0D, 54, 71...
 
[+]

Entropy:
5.5624

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
14.5 KB (14,848 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DQRSCHEd

Command:
C:\Program Files\soredex\dfw 2.9\dqrschdl.exe


Scan dqrschdl.exe - Powered by Reason Core Security