grabillatray.exe

DevXSoftware

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Grabilla’.
Publisher:
DevXSoftware  (signed and verified)

MD5:
4cf481ad249db71e5f51d3914d2f6240

SHA-1:
1454de1bcf7a02092215f576924236021b62fb7f

SHA-256:
9dda4c51ea9b0d2acc7f43ade64c50a6663cb21b7e50e0bef3d9b680e408ec10

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/31/2024 4:48:49 AM UTC  (today)

File size:
1.1 MB (1,168,312 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\grabilla\grabillatray.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/9/2014 8:00:00 PM

Valid to:
6/10/2015 7:59:59 PM

Subject:
CN=DevXSoftware, OU=DevXSoftware, O=DevXSoftware, STREET="#615 - 938 Howe St", L=Vancouver, S=BC, PostalCode=V6Z 1N9, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A81EEBF917EAC5AADF05D2F6D1768967

File PE Metadata
Compilation timestamp:
10/1/2014 8:00:07 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:nenVXN0cOtwkV0Wm75wdYFuEsXY7iCGZ5PKlPCdUJ/Tlcnds43mI/KRa:CXOntwkV0D7SETsI7BEKlPtTlGtV

Entry address:
0x26832

Entry point:
E8, 51, 05, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 30, 9B, 4E, 00, 89, 0D, 2C, 9B, 4E, 00, 89, 15, 28, 9B, 4E, 00, 89, 1D, 24, 9B, 4E, 00, 89, 35, 20, 9B, 4E, 00, 89, 3D, 1C, 9B, 4E, 00, 66, 8C, 15, 48, 9B, 4E, 00, 66, 8C, 0D, 3C, 9B, 4E, 00, 66, 8C, 1D, 18, 9B, 4E, 00, 66, 8C, 05, 14, 9B, 4E, 00, 66, 8C, 25, 10, 9B, 4E, 00, 66, 8C, 2D, 0C, 9B, 4E, 00, 9C, 8F, 05, 40, 9B, 4E, 00, 8B, 45, 00, A3, 34, 9B, 4E, 00, 8B, 45, 04, A3, 38, 9B, 4E, 00, 8D, 45, 08, A3, 44, 9B, 4E...
 
[+]

Entropy:
7.4974

Code size:
171.5 KB (175,616 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Grabilla

Command:
C:\users\{user}\appdata\local\grabilla\grabillatray.exe


The file grabillatray.exe has been discovered within the following program.

Grabilla  by grabilla.com
Publisher's description - “Grabilla is simple and fast screenshot capture application. You can grab screenshots or record desktop actions video with voice comments and instantly upload it to our image hosting server - then share your special link! You can capture animated gifs up to 10 seconds.”
grabilla.uservoice.com
12% remove it
 
Powered by Should I Remove It?

Scan grabillatray.exe - Powered by Reason Core Security