TortoiseHgOverlayServer.exe

TortoiseHg

Steve Borho Open Source Developer

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TortoiseHgOverlayIconServer’.
Publisher:
Steve Borho Open Source Developer  (signed and verified)

Product:
TortoiseHg

Description:
TortoiseHg Overlay Icon Server

Version:
2.2.1

MD5:
afaba4ab72b061f1dbf98303e91ebc35

SHA-1:
c5165c88f27295a49aac6742993ee32bd03c8986

SHA-256:
70a47bd79cc7a00f460bc88ffe26092f1f8bd95e875840c283989ca2bf41b4ab

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:02:07 AM UTC  (today)

File size:
46 KB (47,056 bytes)

Product version:
2.2.1

Copyright:
Copyright (C) 2010 Steve Borho and others

Original file name:
TortoiseHgOverlayServer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
2/13/2011 1:45:26 AM

Valid to:
2/14/2012 1:45:26 AM

Subject:
E=steve@borho.org, CN=Steve Borho Open Source Developer, OU=Open Source Developer, O=Open Source Developer, C=US

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
07358B

File PE Metadata
Compilation timestamp:
11/10/2008 12:40:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:5yq82Ud7/zfkn8I+KlYMeJS/DAK+YV5/44t+310qim+zAMJ4f5o4II:wq824Lfkgc/DFDVi4t+Fim+c5o4n

Entry address:
0x2C61

Entry point:
E8, 72, 03, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, C7, 03, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 6B, 2C, 40, 00, FF, 15, 20, 40, 40, 00, 33, C0, C3, CC, FF, 25, 10, 41, 40, 00, 6A, 14, 68, 30, 42, 40, 00, E8, 5E, 02, 00, 00, FF, 35, A0, 66, 40, 00, 8B, 35, B0, 40, 40, 00, FF, D6, 59, 89, 45, E4, 83...
 
[+]

Code size:
8.5 KB (8,704 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TortoiseHgOverlayIconServer

Command:
C:\replog\tortoise\tortoisehgoverlayserver.exe


Scan TortoiseHgOverlayServer.exe - Powered by Reason Core Security