loadtray.EXE

loadtray

Xi'an SAMING Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘loadtray’.
Publisher:
Xi'an SAMING Technology Co., Ltd.  (signed and verified)

Product:
loadtray

Version:
1, 0, 0, 1

MD5:
c9d6da1a76a442bbd5c766adc21d3710

SHA-1:
1686f807db0ee49ea9a183b99d673261c6f5fa73

SHA-256:
5d088a826aa7631354a741ed551d69936347bd1d2e7929c16769f36bd559665f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 2:27:19 PM UTC  (today)

File size:
49.9 KB (51,048 bytes)

Product version:
1, 0, 0, 1

Copyright:
CopyRight (C) 1998-2012

Original file name:
loadtray.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\netmanager\program\client\loadtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/12/2011 8:00:00 AM

Valid to:
2/10/2013 7:59:59 AM

Subject:
CN="Xi'an SAMING Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an SAMING Technology Co., Ltd.", L=Xi’an, S=ShanXi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2BAC6A302511CC2311CB1B53D07337EC

File PE Metadata
Compilation timestamp:
4/12/2012 1:21:34 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:50BmJzoN03jbe83+GOIwBu2hg12gMDcmqS2gDpBfg8dc0w7QScdYJLM81meMxN:59PbV+Gaq2ggcmqSjDnf9c0rILj8

Entry address:
0x2F90

Entry point:
55, 8B, EC, 6A, FF, 68, 50, 4A, 40, 00, 68, 20, 31, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, D8, 43, 40, 00, 59, 83, 0D, C8, 65, 40, 00, FF, 83, 0D, CC, 65, 40, 00, FF, FF, 15, DC, 43, 40, 00, 8B, 0D, AC, 65, 40, 00, 89, 08, FF, 15, E0, 43, 40, 00, 8B, 0D, A8, 65, 40, 00, 89, 08, A1, E4, 43, 40, 00, 8B, 00, A3, C4, 65, 40, 00, E8, 4E, 01, 00, 00, 39, 1D, E0, 61, 40, 00, 75, 0C, 68, 4A, 31, 40, 00, FF, 15, E8, 43...
 
[+]

Entropy:
4.3383

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
loadtray

Command:
"C:\Program Files\netmanager\program\client\loadtray.exe"


Scan loadtray.EXE - Powered by Reason Core Security