tigoanalizadorimt.exe

NxRay

Swiss Mobility Solutions SA

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Tigo Analizador IMT’.
Publisher:
Swiss Mobility Solutions  (signed by Swiss Mobility Solutions SA)

Product:
NxRay

Description:
NxRay Monitor

Version:
1.4.37.12504

MD5:
4a02051137d486498216abdf34e6843b

SHA-1:
41872003f20f45302ea1423b7e78e849c238eff0

SHA-256:
e298749c52a2751224aa2ea06788104fe24dc234c2f508ef50fbfb098b9abdd9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:53:38 PM UTC  (today)

File size:
4.3 MB (4,533,480 bytes)

Product version:
1.4.37.12504

Copyright:
Copyright (C) 2009-2011 Swiss Mobility Solutions

Original file name:
TigoAnalizadorIMT

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\swiss mobility solutions\tigo analizador imt\tigoanalizadorimt.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/25/2010 2:11:26 PM

Valid to:
3/25/2012 2:11:23 PM

Subject:
CN=Swiss Mobility Solutions SA, O=Swiss Mobility Solutions SA, C=CH

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012796D7D26B

File PE Metadata
Compilation timestamp:
5/3/2011 1:27:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:ERD0Npjd86MBqW/Vw/R2Z7J0fbF2+PznIiryDPR0hZo1feTzwG4wF8:DK6YB7ZKbFtPciWPRMyK8

Entry address:
0x1096B

Entry point:
E8, BC, 32, 00, 00, E9, 78, FE, FF, FF, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00, C7, 00, 90, 8E, 74, 00, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 57, 8B, F9, C7, 07, 90, 8E, 74, 00, 8B, 03, 85, C0, 74, 26, 50, E8, AB, 34, 00, 00, 8B, F0, 46, 56, E8, CB, 33, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 12, FF, 33, 56, 50, E8, 02, 33, 00, 00, 83, C4, 0C, EB, 04, 83, 67, 04, 00, C7, 47, 08, 01, 00, 00, 00, 8B, C7, 5F, 5E, 5B, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 8B, C1, 8B, 4D, 08, C7, 00, 90, 8E, 74, 00, 8B, 09...
 
[+]

Code size:
3.3 MB (3,432,448 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Tigo Analizador IMT

Command:
"C:\Program Files\swiss mobility solutions\tigo analizador imt\tigoanalizadorimt.exe"


Scan tigoanalizadorimt.exe - Powered by Reason Core Security