TortoiseHgOverlayServer.exe

TortoiseHg

Steve Borho Open Source Developer

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TortoiseHgOverlayIconServer’.
Publisher:
Steve Borho Open Source Developer  (signed and verified)

Product:
TortoiseHg

Description:
TortoiseHg Overlay Icon Server

Version:
2.1.3

MD5:
534c94180374829d88fa98458799eb60

SHA-1:
e281309d849bfc87bcf4a5016957a1defc0169e0

SHA-256:
b95d2586967f6c715c783a555892598436c37a930e409f6d23434364b59773f0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 4:22:47 AM UTC  (today)

File size:
51.5 KB (52,688 bytes)

Product version:
2.1.3

Copyright:
Copyright (C) 2010 Steve Borho and others

Original file name:
TortoiseHgOverlayServer.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
2/13/2011 4:15:26 AM

Valid to:
2/14/2012 4:15:26 AM

Subject:
E=steve@borho.org, CN=Steve Borho Open Source Developer, OU=Open Source Developer, O=Open Source Developer, C=US

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
07358B

File PE Metadata
Compilation timestamp:
11/10/2008 3:10:52 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:Qr6aAEhHgdCeNw2zS/DAK+YVhD/k7xe41bAyimvgrMJ4f7o4zG:XaAEFexW/DFDVhLk7xe4Rimvq7o4q

Entry address:
0x33D4

Entry point:
48, 83, EC, 28, E8, 87, 02, 00, 00, 48, 83, C4, 28, E9, FE, FC, FF, FF, CC, CC, 48, 83, EC, 28, 48, 8B, 01, 81, 38, 63, 73, 6D, E0, 75, 2B, 83, 78, 18, 04, 75, 25, 8B, 40, 20, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 06, E8, F7, 02, 00, 00, CC, 33, C0, 48, 83, C4, 28, C3, CC, CC, CC, 48, 83, EC, 28, 48, 8D, 0D, B1, FF, FF, FF, FF, 15, E3, 0B, 00, 00, 33, C0, 48, 83, C4, 28, C3, FF, 25, 86, 0D, 00, 00, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B...
 
[+]

Entropy:
5.5979

Code size:
10 KB (10,240 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TortoiseHgOverlayIconServer

Command:
C:\mydownloads\tortoisehg\tortoisehgoverlayserver.exe


Scan TortoiseHgOverlayServer.exe - Powered by Reason Core Security