TcSysUI.exe

BECKHOFF TwinCAT System

Beckhoff Automation GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TcSysUI’.
Publisher:
Beckhoff Automation GmbH  (signed and verified)

Product:
BECKHOFF TwinCAT System

Description:
User interface program for TwinCAT System Service

Version:
2.11.0.7

MD5:
6d24c15ce31cd4e27eb6f71efaa556e0

SHA-1:
4953f34b6709309efc94128c277f23c90e82b959

SHA-256:
fa4cbdc7193374b4e699f3843654ffccb40f0d05e73343007a8d1e99419ea1cd

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 12:14:43 PM UTC  (today)

File size:
337.7 KB (345,784 bytes)

Product version:
2,11,2017,0

Copyright:
(c) BECKHOFF Automation 2007-2010. All rights reserved.

Original file name:
TcSysUI.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/4/2008 11:18:43 PM

Valid to:
2/4/2011 11:18:43 PM

Subject:
E=info@beckhoff.de, CN=Beckhoff Automation GmbH, O=Beckhoff Automation GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000117E53E07D1

File PE Metadata
Compilation timestamp:
9/28/2010 12:25:05 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:dPjoIjbmi0EL5nd2havBEOtgl0v/YJGcT8WASxNrlmhkz+:dEYCi0CVBEOtgqoJGFK8

Entry address:
0x4CE7

Entry point:
E8, DC, 03, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 00, A6, 41, 00, 89, 0D, FC, A5, 41, 00, 89, 15, F8, A5, 41, 00, 89, 1D, F4, A5, 41, 00, 89, 35, F0, A5, 41, 00, 89, 3D, EC, A5, 41, 00, 66, 8C, 15, 18, A6, 41, 00, 66, 8C, 0D, 0C, A6, 41, 00, 66, 8C, 1D, E8, A5, 41, 00, 66, 8C, 05, E4, A5, 41, 00, 66, 8C, 25, E0, A5, 41, 00, 66, 8C, 2D, DC, A5, 41, 00, 9C, 8F, 05, 10, A6, 41, 00, 8B, 45, 00, A3, 04, A6, 41, 00, 8B, 45, 04, A3, 08, A6, 41, 00, 8D, 45, 08, A3, 14, A6, 41...
 
[+]

Entropy:
5.4235

Code size:
69.5 KB (71,168 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TcSysUI

Command:
C:\twincat\tcsysui.exe


Scan TcSysUI.exe - Powered by Reason Core Security