greg.exe

Global Registration

Acer Incorporated

It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. This is installed with multiple programs including eMachines Registration and Acer Registration.
Publisher:
Acer Incorporated  (signed and verified)

Product:
Global Registration

Version:
1.2.3005.0

MD5:
c234bc05ef8320abbf1aa04b95886e16

SHA-1:
4498138b99f430676f2d7fb2fdc3ac2e2a5294f0

SHA-256:
e22a2a7805cabfcd0a1b5640860639860f7624c7166f60e4b432f61f210ff12c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 3:42:02 PM UTC  (today)

File size:
2.7 MB (2,846,240 bytes)

Product version:
1.02.3005

Copyright:
Copyright (C) Acer Incorporated 2009

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\packard bell\registration\greg.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/25/2007 1:00:00 AM

Valid to:
9/15/2010 12:59:59 AM

Subject:
CN=Acer Incorporated, OU=OS Certification Dept., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Acer Incorporated, L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0AD996A1A9B17F3D94C61B4C7B2236E4

File PE Metadata
Compilation timestamp:
8/14/2009 8:16:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:D7nsRJEaY9RLeO9Gg2b814daTJHu/TH2GZB:DyJzY9oO9VX14dKHuLTZB

Entry address:
0x201D44

Entry point:
55, 8B, EC, B9, A0, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 8C, E6, 5F, 00, E8, 08, 78, E0, FF, 33, C0, 55, 68, BC, 56, 60, 00, 64, FF, 30, 64, 89, 20, C6, 05, BC, 8B, 63, 00, 00, A1, F8, 08, 63, 00, C6, 00, 00, A1, C4, 08, 63, 00, 0F, B6, 00, 8B, 15, B4, 08, 63, 00, 88, 02, C6, 05, C8, 8B, 63, 00, 00, 6A, 00, E8, 85, 82, E0, FF, A1, 80, 0E, 63, 00, 8B, 00, E8, 99, 46, E0, FF, 50, 6A, 00, 6A, 00, E8, FB, 7E, E0, FF, E8, 4E, 80, E0, FF, 3D, B7, 00, 00, 00, 75, 57, 68, D0, 56, 60, 00, 68, 24...
 
[+]

Entropy:
6.7448

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,120,192 bytes)

Scheduled Task
Task name:
Packard Bell Registration Data Sending

Trigger:
Daily (Runs daily at 15:00)


The file greg.exe has been discovered within the following programs.

Acer Registration  by Acer Incorporated
Acer Registration is a program that is pre-installed with Acer laptops. If the laptop has not yet been registered with Acer it will periodically popup and promt the user to register. It runs as a scheduled task or service (depending on the version).
www.acer.com
54% remove it
eMachines Registration  by Acer Incorporated
eMachines Registration is a popup window that prompts the user to register their new eMachine PC if they have not done so already. The program is preinstalled with most new eMachine PCs.
www.emachines.com
19% remove it
Gateway Registration  by Gateway Incorporated
Gateway Registration is a popup window that prompts the user to register their new Gateway PC if they have not done so already. The program is preinstalled with most new Gateway PCs.
www.gateway.com
24% remove it
Packard Bell Registration  by Packard Bell
The Packard Bell Registration program is included by default with most new Packard Bell computers.
www.packardbell.com
26% remove it
 
Powered by Should I Remove It?