uiwinmgr.exe

Trend Micro, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Trend Micro Titanium’.
Publisher:
Trend Micro, Inc.  (signed and verified)

MD5:
c8228a259db3e7a8a42d991eb1c4530f

SHA-1:
02728309f32c797777779293234192c918aba0da

SHA-256:
9685e514a1c0cda0ad7245f9338b2ce964ffc079125767d4eeb0c8ee81ac4d61

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 5:36:14 PM UTC  (today)

File size:
1.1 MB (1,111,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\trend micro\titanium\uiframework\uiwinmgr.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/31/2011 9:00:00 AM

Valid to:
2/17/2012 8:59:59 AM

Subject:
CN="Trend Micro, Inc.", OU=RD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
24E3D70B86ED54D0B22C3450B960984E

File PE Metadata
Compilation timestamp:
10/8/2011 9:51:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x6FB93

Entry point:
FA, FE, 74, 14, 8B, C2, C1, F8, 05, 83, E2, 1F, C1, E2, 06, 03, 14, 85, 58, BD, 4A, 00, EB, 05, BA, 30, 9C, 4A, 00, F6, 42, 24, 80, 74, 16, E8, 89, 13, 00, 00, C7, 00, 16, 00, 00, 00, E8, 9F, B1, FF, FF, 83, CF, FF, 89, 7D, E4, 85, FF, 75, 1B, FF, 4E, 04, 78, 0A, 8B, 06, 0F, B6, 38, 40, 89, 06, EB, 09, 56, E8, 06, B5, 00, 00, 59, 8B, F8, 89, 7D, E4, C7, 45, FC, FE, FF, FF, FF, E8, 0E, 00, 00, 00, 8B, C7, E8, 67, 49, 00, 00, C3, 8B, 75, 08, 8B, 7D, E4, 56, E8, 86, E0, FF, FF, 59, C3, 55, 8B, EC, 83, 7D, 08...
 
[+]

Entropy:
6.5079

Code size:
492 KB (503,808 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Trend Micro Titanium

Command:
C:\Program Files\trend micro\titanium\uiframework\uiwinmgr.exe -set silent "1" splashurl ""


Scan uiwinmgr.exe - Powered by Reason Core Security