pastray.exe

Print Audit Secure

PJLM Software Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Print Audit Secure Notifier’.
Publisher:
PJLM Software Inc.  (signed and verified)

Product:
Print Audit Secure

Description:
Print Audit Secure Notifier

Version:
1.2.3.4811

MD5:
7d99a904962eb92add9e8923ae10ed5e

SHA-1:
8211acb1a375292455cd9d111b101ab47907701a

SHA-256:
61805ff3937285dd9417c3966fd5fc18e0dca146f787427f526379c86df1ba67

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:54:10 PM UTC  (today)

File size:
341.8 KB (350,024 bytes)

Product version:
1.2.3.4811

Copyright:
Copyright (C) 2011-2013

Original file name:
pastray.exe

File type:
Executable application (Win64 EXE)

Language:
English (Canada)

Common path:
C:\Program Files\print audit\print audit secure client\pastray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/30/2012 7:00:00 PM

Valid to:
9/7/2015 6:59:59 PM

Subject:
CN=PJLM Software Inc., OU=Print Audit Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PJLM Software Inc., L=Calgary, S=Alberta, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5CCB50ADE9E1CC9B0B689DCD8A41F8B0

File PE Metadata
Compilation timestamp:
8/18/2014 5:18:37 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:+yf8bFnEpiQJntNNQnTO9qWZJg0T+oJ7A1mt0CV:aJEn4C9fv/n

Entry address:
0x1997C

Entry point:
48, 83, EC, 28, E8, 63, 52, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 8B, C4, 48, 89, 58, 08, 48, 89, 68, 10, 48, 89, 70, 18, 48, 89, 78, 20, 41, 54, 48, 83, EC, 20, 4D, 8B, 51, 38, 48, 8B, F2, 4D, 8B, E0, 41, 8B, 02, 48, 8B, E9, 49, 8B, D1, 48, 03, C0, 48, 8B, CE, 49, 8B, F9, 49, 8D, 5C, C2, 04, 4C, 8B, C3, E8, CA, 52, 00, 00, 44, 8B, 1B, 44, 8B, 55, 04, 41, 8B, C3, 41, 83, E3, 02, BA, 01, 00, 00, 00, 23, C2, 41, 80, E2, 66, 44, 0F, 44, D8, 45, 85, DB, 74, 13, 4C, 8B, CF, 4D, 8B, C4, 48, 8B...
 
[+]

Entropy:
5.7688

Code size:
156.5 KB (160,256 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Print Audit Secure Notifier

Command:
C:\Program Files\print audit\print audit secure client\pastray.exe


Scan pastray.exe - Powered by Reason Core Security