imtray.exe

Dartware, LLC

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘IMTray’.
Publisher:
Dartware, LLC  (signed and verified)

MD5:
a0cef1b2c1d60c5b65f3eb26c0cff531

SHA-1:
6c99af4f7f779a064ce781fec08065d2872af771

SHA-256:
ac5f5ccd5e2d38d50f90432559282ba209468a157ccb2ea625d15d13e5b88cc8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:50:18 PM UTC  (today)

File size:
251.7 KB (257,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\intermapper\imtray.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/12/2010 12:00:00 AM

Valid to:
3/11/2013 11:59:59 PM

Subject:
CN="Dartware, LLC", O="Dartware, LLC", STREET=66-7 Benning Street, L=West Lebanon, S=NH, PostalCode=03784, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0AA8EB38FD4AF399720BF52FDADDA500

File PE Metadata
Compilation timestamp:
4/15/2010 5:28:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:sksKIhm6JwtjGVsdscgGta6yyxPLiaK6PQuNZOFJLbpAKZ+n5tlv4Mx7sLHI3p:skHQtDOtPL9NQFJLbp7+DF4Mx7s83

Entry address:
0x8D6C

Entry point:
E8, 67, B7, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, A3, 48, 44, 43, 00, C3, 55, 8D, AC, 24, 58, FD, FF, FF, 81, EC, 28, 03, 00, 00, A1, 10, 20, 43, 00, 33, C5, 89, 85, A4, 02, 00, 00, 56, 89, 85, 88, 00, 00, 00, 89, 8D, 84, 00, 00, 00, 89, 95, 80, 00, 00, 00, 89, 5D, 7C, 89, 75, 78, 89, 7D, 74, 66, 8C, 95, A0, 00, 00, 00, 66, 8C, 8D, 94, 00, 00, 00, 66, 8C, 5D, 70, 66, 8C, 45, 6C, 66, 8C, 65, 68, 66, 8C, 6D, 64, 9C, 8F, 85, 98, 00, 00, 00, 8B, B5, AC, 02, 00, 00, 8D, 85, AC, 02, 00, 00, 89, 85, 9C, 00...
 
[+]

Code size:
164 KB (167,936 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
IMTray

Command:
"C:\Program Files\intermapper\imtray.exe"


Scan imtray.exe - Powered by Reason Core Security