tomb.dll

Ocster GmbH & Co. KG

This is installed with Ocster Backup: Freeware Windows Edition.
Publisher:
Ocster GmbH & Co. KG  (signed and verified)

MD5:
d909f9f35d3f0893c4efa72f1d0b2e1d

SHA-1:
38e5bfe7c350900d863564d4906047566955d9cd

SHA-256:
51ff22e2b274c2e1e9acf54f1147bf4473510d2e8fe08a9423fc223586f712c3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 11:27:38 PM UTC  (a few moments ago)

File size:
335.3 KB (343,384 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bin\tomb.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/2/2013 6:00:09 PM

Valid to:
10/17/2014 4:38:36 PM

Subject:
CN=Ocster GmbH & Co. KG, O=Ocster GmbH & Co. KG, L=Oldenburg, S=Niedersachsen, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11213A7C56EB9DEF6CC4C01357C4C19260F5

File PE Metadata
Compilation timestamp:
9/24/2013 8:42:44 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x2361C

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, AF, 03, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 8B, FE, FF, FF, CC, FF, 25, 90, 8C, 00, 00, FF, 25, 92, 8C, 00, 00, FF, 25, 94, 8C, 00, 00, FF, 25, 96, 8C, 00, 00, FF, 25, 98, 8C, 00, 00, FF, 25, 9A, 8C, 00, 00, FF, 25, A4, 8C, 00, 00, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41, 83, E3, F8, 41, F6, 00, 04, 4C...
 
[+]

Code size:
171.5 KB (175,616 bytes)

The file tomb.dll has been discovered within the following program.

Ocster Backup: Freeware Windows Edition  by Ocster GmbH & Co. KG
Publisher's description - “This is a great backup software that was designed from the start to work fully automatic. You simply specify what you want backed up and when and then the software takes care of the rest.”
www.ocster.com/ocster-backup-freeware
23% remove it
 
Powered by Should I Remove It?

Scan tomb.dll - Powered by Reason Core Security