traymonitor.exe

Media Codecs Interactive LLC

The application traymonitor.exe by Media Codecs Interactive has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AutoLoader’. It is also typically executed from the user's temporary directory.
Publisher:
Media Codecs Interactive LLC  (signed and verified)

MD5:
2714f642313d87241db9d427ef63fddc

SHA-1:
f3dce76bba37d404752f98c27b5df745eff226c0

SHA-256:
7f6b8c52f185f54972404b7726658803ba21ec7843b334fbc452065122b7dc64

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 11:27:39 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MediaCodecsInteractive (M)
15.12.23.22

File size:
895.2 KB (916,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\traymonitor.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/24/2012 8:00:00 PM

Valid to:
9/25/2013 7:59:59 PM

Subject:
CN=Media Codecs Interactive LLC, O=Media Codecs Interactive LLC, STREET="2711 Centerville Road, Suite 400", L=Wilmington, S=Delaware, PostalCode=19808, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00867CA4C0DF8218799B766CDBCF75747F

File PE Metadata
Compilation timestamp:
5/16/2013 2:44:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:hxQ7G7/dkemK207sERe0rKOABtietPc1BB:heUpbPoB3m

Entry address:
0x1E6000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, F0, 0C, 00, 2D, 7F, CF, 09, 10, 05, 74, CF, 09, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, DE, 36, 54, 16, 68, 45, 62, 55, 59, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 84, BF, FA, 48, 95, 51, CF, 6B, 08, A6, DF, 2E, E3, C2...
 
[+]

Entropy:
7.8061  (probably packed)

Code size:
27.5 KB (28,160 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AutoLoader

Command:
"C:\users\{user}\appdata\local\temp\traymonitor.exe"


Remove traymonitor.exe - Powered by Reason Core Security