iceEngine.exe

ComnsoBackup Engine

Comnso Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘iceBackup Autorun’.
Publisher:
Comnso Inc.  (signed and verified)

Product:
ComnsoBackup Engine

Version:
2.05.0345

MD5:
a868d1e61a8f564a5dffee0cefba90e7

SHA-1:
733ce6a3be1ca7ef2ad3e836647fabfc013f8d63

SHA-256:
827563b21d6f9599c4350c0d77cb7da879791a818e02f031fc9e6207aba13840

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:48:41 PM UTC  (a few moments ago)

File size:
1 MB (1,089,872 bytes)

Product version:
2.05.0345

Copyright:
Comnso Inc. http://www.comnso.com

Original file name:
iceEngine.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Common path:
C:\Program Files\comnso\comnsobackup\iceengine.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/15/2010 1:00:00 AM

Valid to:
6/15/2011 1:59:59 AM

Subject:
CN=Comnso Inc., O=Comnso Inc., L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
4973DC29EF5D0107C436CC94D1D2C71F

File PE Metadata
Compilation timestamp:
4/22/2010 4:13:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:rTZSSXHnxmeJAYQ2Ts420e51KH7pWVvpcQ:RSSXHnxmeJU2DSpJ

Entry address:
0x6924

Entry point:
68, 08, 6B, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, F7, A3, 8E, D1, B8, 53, 03, 43, 93, FD, 0A, DA, CA, 89, 93, 50, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 69, 63, 65, 45, 6E, 67, 69, 6E, 65, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 0C, 00, 08, CC, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 9C, CE, 40, 00, DC, 70, 50, 00, 01, 00, 00, 00, B0, 69, 40, 00, 01, 00, 20, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
1 MB (1,073,152 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
iceBackup Autorun

Command:
C:\Program Files\comnso\comnsobackup\iceengine.exe \boot


Scan iceEngine.exe - Powered by Reason Core Security