macrotoolworks.exe

Macro Toolworks family member

Pitrinec Petr

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘macroToolworks’.
Publisher:
Pitrinec Software  (signed by Pitrinec Petr)

Product:
Macro Toolworks family member

Version:
7, 0, 0, 0

MD5:
07bbb90935c30500178cc3179f3a6570

SHA-1:
fc9e7e5af6b489a31faf0675a779cecf37ed5710

SHA-256:
dc9314b1c31ba48812208696b98aa8a024b33f1a7995769ad6dbb68fb129b4bb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 3:53:45 PM UTC  (today)

File size:
6.4 MB (6,718,424 bytes)

Product version:
7, 0, 0, 0

Copyright:
Copyright © 2000-2014

Original file name:
_prog.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\macrotoolworks\macrotoolworks.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/21/2015 4:14:36 AM

Valid to:
11/27/2017 10:29:47 AM

Subject:
E=support@pitrinec.com, CN=Pitrinec Petr, O=Pitrinec Petr, L=Cerveni Kostelec, S=Hradec Kralove, C=CZ

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211CC446CDC8FD0E58BFE93FDB976AC1F8

File PE Metadata
Compilation timestamp:
1/16/2017 7:14:26 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x45BADD

Entry point:
E8, 37, 09, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, 6A, 00, FF, 15, 4C, C5, 8C, 00, FF, 75, 08, FF, 15, C8, C3, 8C, 00, 68, 09, 04, 00, C0, FF, 15, 24, C5, 8C, 00, 50, FF, 15, EC, C4, 8C, 00, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 55, 0A, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 98, D1, A5, 00, 89, 0D, 94, D1, A5, 00, 89, 15, 90, D1, A5, 00, 89, 1D, 8C, D1, A5, 00, 89, 35, 88, D1, A5, 00, 89, 3D, 84, D1, A5, 00, 66, 8C, 15, B0, D1, A5, 00, 66, 8C, 0D, A4, D1, A5, 00, 66, 8C, 1D, 80...
 
[+]

Entropy:
6.5636

Code size:
4.8 MB (5,025,280 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
macroToolworks

Command:
"C:\users\{user}\appdata\roaming\macrotoolworks\macrotoolworks.exe"


Scan macrotoolworks.exe - Powered by Reason Core Security