Memopal.exe

Memopal

Memopal SRL

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Memopal’. This is installed with Memopal.
Publisher:
memopal.com  (signed by Memopal SRL)

Product:
Memopal

Description:
Memopal Client

Version:
1.0.0.0

MD5:
68803a918def99b236d765b893150d8d

SHA-1:
1bc7ed94923ebd5ac0900232cb60ae06d71fa364

SHA-256:
9cdd6991918cf719f30ca0fec94294382f33cdeaf7ef3745fb5a925476b8d6e0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:21:12 AM UTC  (today)

File size:
1.7 MB (1,814,808 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
Memopal.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\memopal\memopal.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/10/2011 12:36:21 PM

Valid to:
2/11/2012 12:36:19 PM

Subject:
CN=Memopal SRL, O=Memopal SRL, L=Rome, S=RM, C=IT

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012E10B4940F

File PE Metadata
Compilation timestamp:
4/12/2011 7:22:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:vFFiL6xP9cKcxcCCaBaJ929ej6Ng9Cblow8nK7q647/hDKzldHA39frn1N8CtmVR:ZFjcxc7aU929emNtl98Kf41DKzYNDT0R

Entry address:
0x187E6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5705

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.5 MB (1,597,440 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Memopal

Command:
C:\Program Files\memopal\memopal.exe


The file Memopal.exe has been discovered within the following program.

Memopal  by Memopal
Publisher's description - “Memopal automatically backs up your computer and puts all your files online for safe storage, so that you no longer have to worry about the possibility of losing important data.”
www.memopal.com
25% remove it
 
Powered by Should I Remove It?

Scan Memopal.exe - Powered by Reason Core Security