iceEngine.exe

ComnsoBackup Engine

Comnso Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘iceBackup Autorun’.
Publisher:
Comnso Inc.  (signed and verified)

Product:
ComnsoBackup Engine

Version:
2.05.0204

MD5:
f98a9358853bd423a36da2d1c28944ba

SHA-1:
f06090ecf5a3d3d5017f56304a86d13215f66b2e

SHA-256:
304de7e445116d9acf1e928be5a1f55d963b29ba1b3ca7a987787778e555d17d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/11/2024 2:09:20 AM UTC  (today)

File size:
269.5 KB (275,968 bytes)

Product version:
2.05.0204

Copyright:
Comnso Inc. http://www.comnso.com

Original file name:
iceEngine.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\Program Files\comnso\comnsobackup\iceengine.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
4/27/2008 11:24:42 PM

Valid to:
4/27/2009 11:24:42 PM

Subject:
CN=Comnso Inc., OU=Software Development Department, O=Comnso Inc., L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
76DAF63CF79BB6FF5357001FB6247F6A

File PE Metadata
Compilation timestamp:
2/22/2009 11:24:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:LP2vTJeI5SJHFIw8qo1NmWjfeTYbRNRIHKxQ//+QmbYRkn:LP2vTU+SJlIwY1Nm8fz5Iqx6twv

Entry address:
0x6850

Entry point:
B8, 90, C8, 50, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 5F, F7, 7C, 52, 44, 42, 0D, 66, 83, 7B, C1, A2, D6, F8, B5, FB, 5C, 6B, 7A, F4, FD, FC, 6C, 8D, 53, 79, 31, FF, 0C, B8, 99, 06, B8, FF, 66, 86, B4, FD, A1, 57, 35, 10, E4, 0A, 05, 9C, 30, CB, 89, 85, 2D, 79, 9E, B9, F9, 6C, C0, 55, AC, 21, 01, F6, 97, C5, 96, 02, 26, 63, 8B, 08, EA, 63, 95, 8A, 5D, 08, 2D, 69, 73, 69, A4, D6, A7, 2E, B6, 8E, A4, 1B, 11, 5E, 50, AF, 34...
 
[+]

Entropy:
7.9881

Packer / compiler:
PECompact v2

Code size:
1 MB (1,064,960 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
iceBackup Autorun

Command:
C:\Program Files\comnso\comnsobackup\iceengine.exe \boot


Scan iceEngine.exe - Powered by Reason Core Security