VBoxTray.exe

Oracle VM VirtualBox Guest Additions

Sun Microsystems, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VBoxTray’.
Publisher:
Oracle Corporation  (signed by Sun Microsystems, Inc.)

Product:
Oracle VM VirtualBox Guest Additions

Description:
VirtualBox Guest Additions Tray Application

Version:
4.0.0.69151

MD5:
249f51c881f14153329e0b0b0d5ad387

SHA-1:
9b23ccf11625e857a3e13d50e70c745b3883b368

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:32:10 AM UTC  (today)

File size:
886.5 KB (907,792 bytes)

Product version:
4.0.0.r69151

Copyright:
Copyright (C) 2009-2010 Oracle Corporation

Original file name:
VBoxTray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\vboxtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2008 2:00:00 AM

Valid to:
6/12/2011 1:59:59 AM

Subject:
CN="Sun Microsystems, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sun Microsystems, Inc.", L=Menlo Park, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
693A64818C1E086B1B15AEE63FA054A2

File PE Metadata
Compilation timestamp:
12/22/2010 3:05:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:Y/lU6MwgReLC5IO4E9FsCnFWXBKsHKZycUodbZWUykxzdxTlabQYtCAZ7cIkKq0:IUrRg40E9DnFWuZycUo5ZWUrldx5Xex

Entry address:
0x53B3

Entry point:
6A, 60, 68, B0, 0B, 43, 00, E8, 35, 12, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, B5, FE, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 18, 02, 43, 00, 8B, 4E, 10, 89, 0D, DC, C0, 4A, 00, 8B, 46, 04, A3, E8, C0, 4A, 00, 8B, 56, 08, 89, 15, EC, C0, 4A, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, E0, C0, 4A, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, E0, C0, 4A, 00, C1, E0, 08, 03, C2, A3, E4, C0, 4A, 00, 33, F6, 56, 8B, 3D, 0C, 02, 43, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
188 KB (192,512 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VBoxTray

Command:
C:\Windows\System32\vboxtray.exe