MTAppDwn.exe

MTAppDwn

Medical Information Technology, Inc.

It runs as a separate (within the context of its own process) windows Service named “MEDITECH Application Manager”. This file is installed with multiple programs including MEDITECH MyOffice and MEDITECH Alert Server.
Publisher:
MEDITECH  (signed by Medical Information Technology, Inc.)

Product:
MTAppDwn

Description:
MEDITECH MTAppDwn x86

Version:
1.0.0.64

MD5:
a5d99e1dffa22e8a0c17c1ba02e49dd0

SHA-1:
ede52b6a8af2b15983e9ab06f14904b58f85fcbf

SHA-256:
0ea245eb975b68925f390c046695791889cf5b12563606235d9890931f963313

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/23/2024 9:06:02 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.137.240

File size:
347.6 KB (355,992 bytes)

Product version:
1.0.0.64

Copyright:
Copyright © 2013

Original file name:
MTAppDwn.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\meditech\mtappdwn.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/28/2011 8:00:00 PM

Valid to:
10/1/2013 7:59:59 PM

Subject:
CN="Medical Information Technology, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Medical Information Technology, Inc.", L=Westwood, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3D790A315071581E53B74065FBF61C69

File PE Metadata
Compilation timestamp:
9/12/2013 5:48:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:fZ04GCAZWPEUEJMmPn80FKX3rgpz5hrEaTl3WflaMv:K4HAhv80F23rgpz5hr9AlaMv

Entry address:
0x3CEA

Entry point:
55, 8B, EC, 83, EC, 60, 56, 57, 53, 55, E8, B7, D4, FF, FF, E8, AC, 59, 03, 00, A3, 9C, 47, 45, 00, A3, A8, 47, 45, 00, E8, 15, 5A, 03, 00, 8B, F0, 68, 98, D8, 45, 00, 56, E8, F8, 13, 00, 00, E8, C1, 2D, 00, 00, E8, 12, 32, 00, 00, BE, 98, D8, 45, 00, 0F, B6, 06, 8D, 76, 01, 3C, 22, 75, 0C, 0F, B6, 06, 8D, 76, 01, 3C, 22, 75, F6, EB, 0A, 0F, B6, 06, 8D, 76, 01, 3C, 20, 77, F6, 0F, B6, 06, 8D, 76, 01, 3C, 20, 74, F6, 4E, 89, 35, 10, F0, 45, 00, C7, 05, 6C, D4, 45, 00, 00, 00, 00, 00, 83, F8, FF, 74, 19, 0F...
 
[+]

Entropy:
6.4820

Developed / compiled with:
Microsoft Visual C++

Code size:
265 KB (271,360 bytes)

Service
Display name:
MEDITECH Application Manager

Service name:
MTAppManager

Description:
MEDITECH Application Management Service Facilitates running the MEDITECH client software on Microsoft Windows Vista and Microsoft Windows Server 2008 operating systems. If this service is stopped, th

Type:
Win32OwnProcess


The file MTAppDwn.exe has been discovered within the following programs.

MEDITECH Alert Server  by Medical Information Technology, Inc.
About 7% of users remove it
MEDITECH core  by Medical Information Technology, Inc.
About 8% of users remove it
MEDITECH FS\BOH55_L MTAD  by Medical Information Technology, Inc.
About 4% of users remove it
MEDITECH FS\CEU55_L MTAD  by Medical Information Technology, Inc.
About 5% of users remove it
MEDITECH FS\GVILIVE MTAD  by Medical Information Technology, Inc.
About 6% of users remove it
MEDITECH FS\PAISMM_L MTAD  by Medical Information Technology, Inc.
About 4% of users remove it
MEDITECH FS\RWI566_T MTAD  by Medical Information Technology, Inc.
About 7% of users remove it
MEDITECH MagicCS  by Medical Information Technology, Inc.
About 1% of users remove it
MEDITECH MagicCS Connect  by Medical Information Technology, Inc.
About 4% of users remove it
MEDITECH MyOffice  by Medical Information Technology, Inc.
About 5% of users remove it
 
Latest 20 of 11 programs
Powered by Should I Remove It?

Scan MTAppDwn.exe - Powered by Reason Core Security