OrbTray.exe

Orb

Orb Networks, Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Orb’.
Publisher:
Orb Networks  (signed by Orb Networks, Inc.)

Product:
Orb

Version:
2, 2008, 513, 1830

MD5:
6aac938fc2375c4145581ce3eae5b886

SHA-1:
f868c83f1a948e2bd90eea52e611022631cef049

SHA-256:
5dc08a10b8e6e5d049e4b270fbeb7a563423f6f42b9e10fa3d8277460e8742d8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 2:47:14 PM UTC  (today)

File size:
498.5 KB (510,416 bytes)

Product version:
2, 2008, 513, 1830

Copyright:
Copyright © 2002-2007

Original file name:
OrbTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\orb networks\orb\bin\orbtray.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
5/4/2007 5:00:00 AM

Valid to:
5/17/2009 4:59:59 AM

Subject:
CN="Orb Networks, Inc.", OU=SECURE APPLICATION DEVELOPMENT, O="Orb Networks, Inc.", L=Emeryville, S=California, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
6AE949B1490AD9FD03E24D84F404CB7F

File PE Metadata
Compilation timestamp:
5/14/2008 6:29:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:m2FBaXvQSKuBCJQxGEhsie3VatoV47295YNwpypL7ygLPyZ7GpgyZkzCjORN9eb5:HFBaXYgDxGAeFg75w2Zk6bUe

Entry address:
0x39DDF

Entry point:
E8, B2, 03, 00, 00, E9, 36, FD, FF, FF, CC, CC, CC, 68, CA, 99, 43, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, E0, FF, 44, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, B0, 3E, 45, 00, 89, 0D, AC, 3E, 45, 00, 89, 15, A8, 3E, 45, 00...
 
[+]

Entropy:
6.3556

Code size:
244 KB (249,856 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Orb

Command:
"C:\Program Files\orb networks\orb\bin\orbtray.exe" \background


Scan OrbTray.exe - Powered by Reason Core Security