SUPERRAMTRAY.EXE

SuperRam

PGWARE LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SuperRam’.
Publisher:
PGWARE LLC  (signed and verified)

Product:
SuperRam

Description:
SuperRam Tray Applet

Version:
6.0.0.0

MD5:
0d509d9b45cd960382ec9e3f38fa74b8

SHA-1:
bbf3ba076f76a962334977141c611bcb84c3a600

SHA-256:
e451721e5c94673ede9922894bffa4cfd95da1973e1d14eab7e9a3bae0f1dd0f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:46:11 AM UTC  (today)

File size:
1.6 MB (1,700,040 bytes)

Product version:
6.0.0.0

Copyright:
Copyright © 2001-2010 PGWARE LLC

Original file name:
SUPERRAMTRAY.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pgware\superram\superramtray.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
7/16/2008 7:00:00 AM

Valid to:
8/15/2010 6:59:59 AM

Subject:
CN=PGWARE LLC, OU=SECURE APPLICATION DEVELOPMENT, O=PGWARE LLC, L=Norman, S=Oklahoma, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
154769D6AC36E9E67991AAB61B629FA4

File PE Metadata
Compilation timestamp:
3/8/2010 4:08:16 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:FbYF5fFVP9L5muymB2SyVONhbQ7CTJWJXg0yEvo0wLzU:SNHZASfNbWC0yEvoNnU

Entry address:
0x12E38C

Entry point:
55, 8B, EC, B9, 05, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, B8, A4, 58, 52, 00, E8, 72, BE, ED, FF, 33, C0, 55, 68, F3, E4, 52, 00, 64, FF, 30, 64, 89, 20, 33, D2, 33, C0, E8, C7, 4B, FF, FF, 84, C0, 75, 36, E8, C6, 53, FF, FF, 83, F8, 05, 7F, 2C, 8D, 55, E8, 33, C0, E8, E7, 61, ED, FF, 8B, 45, E8, 8D, 55, EC, E8, 7C, 51, EE, FF, 8D, 45, EC, BA, 0C, E5, 52, 00, E8, 53, 8A, ED, FF, 8B, 45, EC, 33, D2, E8, 2D, D1, F8, FF, BB, 02, 00, 00, 80, B8, 10, 94, 53, 00, BA, 44, E5, 52, 00, E8, 29, 86, ED, FF, 8D...
 
[+]

Entropy:
6.4803

Developed / compiled with:
Microsoft Visual C++

Code size:
1.2 MB (1,231,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SuperRam

Command:
"C:\Program Files\pgware\superram\superramtray.exe" \start


Scan SUPERRAMTRAY.EXE - Powered by Reason Core Security