loadtray.EXE

Load Tray

Xi'an Saming Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘multitray’.
Publisher:
Xi'an Saming Technology Co., Ltd.  (signed and verified)

Product:
Load Tray

Version:
1, 0, 0, 4778

MD5:
6c81b648980a53956e4b5bdddb8c5a4e

SHA-1:
fed631e5014b82f65336133f4ab681abc1efc0e0

SHA-256:
5322258aa70d062b1359f21ac58ceeee0171c1e9dc43029534115fb0a5322505

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/26/2024 1:56:29 AM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Worm.AMCB
4.6.5.141

McAfee
Trojan.Artemis!6C81B648980A
18.0.204.0

File size:
30.8 KB (31,512 bytes)

Product version:
1, 0, 0, 4778

Copyright:
CopyRight (C) 1998-2007

Original file name:
loadtray.EXE

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\lenovo\multirecover\loadtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/14/2006 4:00:00 PM

Valid to:
12/15/2007 3:59:59 PM

Subject:
CN="Xi'an Saming Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Saming Technology Co., Ltd.", S=Shannxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2DF6A0EA04EE7275B1E694FD226923AA

File PE Metadata
Compilation timestamp:
3/13/2007 10:47:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:P3X5S9v5dNnXFaXsspxeGgP1oy0DsiIFg89GEYwYL/CldolMzMjGwP7gM8sOzz+p:PXA9W8se1KDsCAGEYNLCcg1sOxb506jS

Entry address:
0x1A90

Entry point:
55, 8B, EC, 6A, FF, 68, 50, 24, 40, 00, 68, 20, 1C, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, B4, 21, 40, 00, 59, 83, 0D, 6C, 31, 40, 00, FF, 83, 0D, 70, 31, 40, 00, FF, FF, 15, B8, 21, 40, 00, 8B, 0D, 60, 31, 40, 00, 89, 08, FF, 15, BC, 21, 40, 00, 8B, 0D, 5C, 31, 40, 00, 89, 08, A1, C0, 21, 40, 00, 8B, 00, A3, 68, 31, 40, 00, E8, 4E, 01, 00, 00, 39, 1D, 70, 30, 40, 00, 75, 0C, 68, 4A, 1C, 40, 00, FF, 15, C4, 21...
 
[+]

Entropy:
4.2744

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
4 KB (4,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
multitray

Command:
C:\Program Files\lenovo\multirecover\loadtray.exe


Scan loadtray.EXE - Powered by Reason Core Security