pctsgui.exe

PC Tools Security Component

PC Tools Labs

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ISTray’.
Publisher:
PC Tools  (signed by PC Tools Labs)

Product:
PC Tools Security Component

Version:
9.0.0.888

MD5:
8403616dda91c52dfce55f0647fdab27

SHA-1:
eb0c0b696a670058bfb88239679e8b8b09477ed7

SHA-256:
0482c3894c2586e28a218ac758faff0cb9067ca1432f3779619287e1e6331470

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:14:16 PM UTC  (today)

File size:
2.4 MB (2,547,592 bytes)

Product version:
9.0

Copyright:
Copyright © 2011 PC Tools. All rights reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\turbo-x internet security\pctsgui.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/18/2008 2:00:00 AM

Valid to:
12/13/2011 1:59:59 AM

Subject:
CN=PC Tools Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PC Tools Labs, L=Melbourne, S=Victoria, C=AU

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
31CF207043019D53D84DFA6EC371B74A

File PE Metadata
Compilation timestamp:
12/8/2011 5:24:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1433B0

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 14, 04, 54, 00, E8, 11, E2, EB, FF, 8B, 1D, 14, 63, 55, 00, 8B, 03, 83, 78, 30, 00, 75, 07, 8B, 03, E8, 90, DB, F0, FF, 8B, 0D, 58, FA, 54, 00, 8B, 09, B2, 01, A1, E4, 65, 53, 00, E8, 04, 33, FF, FF, A3, E0, 1C, 55, 00, 33, C0, 55, 68, 88, 35, 54, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, 5D, 35, 54, 00, 64, FF, 30, 64, 89, 20, 33, C0, E8, 58, F2, F8, FF, A1, E0, 1C, 55, 00, E8, 9A, CC, FF, FF, 84, C0, 75, 12, 33, C0, 5A, 59, 59, 64, 89, 10, E8, A9, DD, EB, FF, E9...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,316,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ISTray

Command:
"C:\Program Files\turbo-x internet security\pctsgui.exe" \hidegui


Scan pctsgui.exe - Powered by Reason Core Security