ib_tray.exe

IBackup

Pro Softnet Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘IBackup Tray’.
Publisher:
Prosoftnet  (signed by Pro Softnet Corporation)

Product:
IBackup

Description:
Meshi Backup Services Tray

Version:
11.0.0.0

MD5:
087fc47039af4984cc23e6803de51b78

SHA-1:
10d76865e7644f0f2bd8bc7e59fefff6ddd93e75

SHA-256:
75c3b7247f417d3cff9c366618f4de86a19619e188feb8ff09c5282ab1d730a3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 12:04:14 AM UTC  (today)

File size:
2 MB (2,142,248 bytes)

Product version:
11.0.0.0

Copyright:
Copyright © Prosoftnet 2013

Original file name:
ib_tray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\meshibackupserviceswindows\ib_tray.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/14/2014 2:00:00 AM

Valid to:
2/15/2016 1:59:59 AM

Subject:
CN=Pro Softnet Corporation, OU=IT, O=Pro Softnet Corporation, L=Calabasas, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
68A7A5C7BD2B769D46DD66EE575B8C68

File PE Metadata
Compilation timestamp:
12/1/2015 2:38:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x1E8D1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3566

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.9 MB (1,994,240 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
IBackup Tray

Command:
"C:\Program Files\meshibackupserviceswindows\ib_tray.exe" min


Scan ib_tray.exe - Powered by Reason Core Security