sparetray.exe

Spare Backup

Spare Backup, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Spare Backup’.
Publisher:
Spare Backup, Inc.  (signed and verified)

Product:
Spare Backup

Version:
5.0.0.1242

MD5:
d2864c3546494602e16d4508853d3daf

SHA-1:
f587c97e374d6a4d5c68fb30592428f95bbec327

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:57:56 PM UTC  (today)

File size:
1.1 MB (1,103,624 bytes)

Product version:
5.0.0.1242

Copyright:
(c) 2006, Spare Backup, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\spare backup\sparetray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2009 12:00:00 AM

Valid to:
3/9/2011 11:59:59 PM

Subject:
CN="Spare Backup, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spare Backup, Inc.", L=Palm Desert, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
45D7F6DF92CD426ED3D7294EC168E14E

File PE Metadata
Compilation timestamp:
5/17/2009 7:17:08 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1B262

Entry point:
E8, 6D, AA, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 57, 56, E8, FC, B5, FF, FF, 33, FF, 59, 3B, F7, 75, 1D, E8, DA, 2E, 00, 00, 57, 57, 57, 57, 57, C7, 00, 16, 00, 00, 00, E8, 6C, B9, FF, FF, 83, C4, 14, 83, C8, FF, EB, 3A, 39, 7D, 0C, 74, DE, C7, 45, EC, 49, 00, 00, 00, 89, 75, E8, 89, 75, E0, 3D, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF, 7F, EB, 05, 03, C0, 89, 45, E4, FF, 75, 14, 8D, 45, E0, FF, 75, 10, FF, 75, 0C, 50, FF, 55, 08, 83, C4, 10, 5F, C9, C3, 8B, FF, 55, 8B, EC, 56...
 
[+]

Entropy:
6.8496

Code size:
256 KB (262,144 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Spare Backup

Command:
"C:\Program Files\spare backup\sparetray.exe" \silent


Scan sparetray.exe - Powered by Reason Core Security