sleek bill.exe

Intelligent IT

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SleekBillNot’. This is installed with Sleek Bill.
Publisher:
Intelligent IT  (signed and verified)

MD5:
eb7ccadb720a4db5e8eeeaf1ff5133a0

SHA-1:
560f39d2bb6fbe74cf566d8eab4f3680e3cacdee

SHA-256:
bd75684ccdb34fd6b9783555bdc2a28dc5cd782c34c4ee6c89f0f1c5252a723b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:24:12 PM UTC  (today)

File size:
1.7 MB (1,805,216 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/25/2014 6:00:00 AM

Valid to:
2/26/2015 5:59:59 AM

Subject:
CN=Intelligent IT, O=Intelligent IT, L=Sibiu, S=Sibiu, C=RO

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7D61902703177DAFEAB3E52E454E7E48

File PE Metadata
Compilation timestamp:
7/18/2014 5:58:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
49152:ZIieUKzAuUMp16M/hFyda3wsfWzC2cyUGUqIsoN:ZIietVU86o+zYff

Entry address:
0x1290

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 9C, 12, 41, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, DC, 12, 41, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, C4, 12, 41, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, BA, 80, 00, 00, 00, 89, E5, 57, 31, C0, 8D, BD, E8, FE, FF, FF, 56, 53, 81, EC, 1C, 01, 00, 00, 89, 54, 24, 08, 89, 44, 24, 04, 89, 3C, 24, E8, B7, 3F, 00, 00, 89, 7C, 24, 04, C7, 04, 24, 18, 00, 00, 00, E8, 07, 0B, 00, 00, 85, C0, 0F, 84, 7C, 00, 00...
 
[+]

Entropy:
7.8902

Packer / compiler:
MingWin32

Code size:
18 KB (18,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SleekBillNot

Command:
"C:\sleek bill\sleek bill.exe" \n


The file sleek bill.exe has been discovered within the following program.

Sleek Bill  by Intelligent IT
www.sleekbill.com
About 4% of users remove it
 
Powered by Should I Remove It?

Scan sleek bill.exe - Powered by Reason Core Security