FRTask.EXE

timeback Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FRTask’.
Publisher:
TIMEBACK  (signed by timeback Co., Ltd)

Product:
TimeBack

Description:
TimeBack Task Moudle

Version:
3, 2, 0, 38

MD5:
311891718d10bf266e74203793f392d0

SHA-1:
e0f9ce4f158efc279e49dab366df13cb352d5cf5

SHA-256:
9ecda58bf1838835fb2f1f72886139641320fa90469972748ef81abd3df919ce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 5:03:42 PM UTC  (today)

File size:
175.3 KB (179,512 bytes)

Product version:
3, 2, 0, 38

Copyright:
Copyright TIMEBACK. All Rights Reserved.

Original file name:
FRTask.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\scmate\scmate basic\frtask.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
11/26/2014 9:00:00 AM

Valid to:
12/20/2015 8:59:59 AM

Subject:
CN="timeback Co., Ltd", O="timeback Co., Ltd", L=Geumcheon-gu, S=Seoul, C=KR, SERIALNUMBER=110111-2871518, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=KR

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
535AD65E7AC6BD526B3628F72E50B79A

File PE Metadata
Compilation timestamp:
12/10/2014 5:06:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:OyKnVq4L8uf2TLmydkTrptEYMH7Ix/QTHZYm1Ssx0dgFwwne:OyOq4LPfq5dkTrpMH7IxCZd1bmgFwv

Entry address:
0xB3E2

Entry point:
55, 8B, EC, 6A, FF, 68, B8, CC, 40, 00, 68, 08, B7, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, AC, C3, 40, 00, 59, 83, 0D, E0, 10, 41, 00, FF, 83, 0D, E4, 10, 41, 00, FF, FF, 15, A8, C3, 40, 00, 8B, 0D, D4, 10, 41, 00, 89, 08, FF, 15, A4, C3, 40, 00, 8B, 0D, D0, 10, 41, 00, 89, 08, A1, A0, C3, 40, 00, 8B, 00, A3, DC, 10, 41, 00, E8, B4, 02, 00, 00, 39, 1D, 18, 08, 41, 00, 75, 0C, 68, 04, B7, 40, 00, FF, 15...
 
[+]

Entropy:
5.9403

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
44 KB (45,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FRTask

Command:
C:\Program Files\scmate\scmate basic\frtask.exe


Scan FRTask.EXE - Powered by Reason Core Security