MDRAW32p.OCX

MetaDraw OLE Custom Control

Bennet-Tec Information Systems, Inc

It runs as a Windows kernel mode device driver named “catchme”.
Publisher:
Bennet-Tec Information Systems, Inc.  (signed by Bennet-Tec Information Systems, Inc)

Product:
MetaDraw OLE Custom Control

Description:
MetaDraw Pro Custom Control (32-bit version)

Version:
2.5.015

MD5:
ca9d8d68f5ead58de6ae388914bf4ebc

SHA-1:
0651ad157ea572cd10ccf3e79e5c11253fd78c21

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:37:48 AM UTC  (today)

File size:
493.8 KB (505,664 bytes)

Product version:
2.5

Copyright:
Copyright (c) 1995-97, Bennet-Tec Information Systems, Inc.

Original file name:
MDRAW32p.OCX

File type:
OLE control extension (Win32 OCX)

Language:
English (United States)

Common path:
C:\Program Files\common files\geo shared\mdraw32p.ocx

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/16/2000 1:00:00 AM

Valid to:
2/16/2001 12:59:59 AM

Subject:
CN="Bennet-Tec Information Systems, Inc", L=Jericho, S=New York, C=US, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU="www.verisign.com/repository/RPA Incorp. by Ref.,LIAB.LTD(c)98", OU=VeriSign Commercial Software Publishers CA, O="VeriSign, Inc.", L=Internet

Issuer:
OU=VeriSign Commercial Software Publishers CA, O="VeriSign, Inc.", L=Internet

Serial number:
7220DE92F8CC36DB0A2686D92977D988

Registration
CLSIDs:
{32308000-644D-A583-AD61-00403333EC93}, {32308021-644D-A583-AD61-00403333EC93}, {32308022-644D-A583-AD61-00403333EC93}, {32308023-644D-A583-AD61-00403333EC93}, {32308024-644D-A583-AD61-00403333EC93}, {32308025-644D-A583-AD61-00403333EC93}

ProgIDs:
MDRAW.MDrawCtrl.2, MDRAW.AutoPicture

COM registered:
Yes

File PE Metadata
Compilation timestamp:
4/14/2000 1:53:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
12288:om+ieKbg3VQsR1FhQ6KOrpGGWe4M4LwHHXkzyKSULZXEwjYWVqw:oo5bSQEHhQ8pGGvx4LcXkOWVqw

Entry address:
0x4C550

Entry point:
53, 55, 56, 8B, 74, 24, 14, 85, F6, 57, B8, 01, 00, 00, 00, 75, 13, 8B, 0D, 8C, 09, 06, 10, 85, C9, 75, 09, 33, C0, 5F, 5E, 5D, 5B, C2, 0C, 00, 8B, 7C, 24, 1C, 8B, 5C, 24, 14, 83, FE, 01, 74, 05, 83, FE, 02, 75, 28, 8B, 0D, F8, EC, 05, 10, 85, C9, 74, 05, 57, 56, 53, FF, D1, 85, C0, 74, 0C, 57, 56, 53, E8, DF, FE, FF, FF, 85, C0, 75, 09, 33, C0, 5F, 5E, 5D, 5B, C2, 0C, 00, 57, 56, 53, E8, 8D, FA, FF, FF, 83, FE, 01, 8B, E8, 75, 0C, 85, ED, 75, 08, 57, 50, 53, E8, B7, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
318.5 KB (326,144 bytes)

Driver
Display name:
catchme

Type:
Kernel device driver (KernelDriver)

Group:
Base


The file MDRAW32p.OCX has been discovered within the following program.

Datastream  by Thomson Reuters
extranet.datastream.com/index.htm
About 4% of users remove it
 
Powered by Should I Remove It?

Scan MDRAW32p.OCX - Powered by Reason Core Security