wintray.exe

AKADO Wintray

AKADO Wintray

The application wintray.exe by AKADO Wintray has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
АКАДО-Екатеринбург  (signed by AKADO Wintray)

Product:
AKADO Wintray

Version:
8.0.0.59

MD5:
11c945a5d482bbeff4cb91b75d66e4a8

SHA-1:
5a59cf1d6afad3d912effccb319aa35480ee03a8

SHA-256:
86253da1046c609f2bf7e08c54d16a8b7a2b0b6d6292932d512073c39b7d779a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 9:31:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AKADOWintray (M)
16.2.28.9

File size:
6 MB (6,288,256 bytes)

Product version:
1.0.0.0

Copyright:
АКАДО-Екатеринбург

Original file name:
wintray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\akado\akado wintray\wintray.exe

Digital Signature
Signed by:

Authority:
AKADO Wintray Root CA

Valid from:
10/4/2011 3:07:29 PM

Valid to:
1/1/2040 4:59:59 AM

Subject:
CN=AKADO Wintray, E=wintray@akado-ural.ru

Issuer:
CN=AKADO Wintray Root CA, E=wintray@akado-ural.ru

Serial number:
F4E1175BDF1FD29A4F1D882740649F12

File PE Metadata
Compilation timestamp:
11/28/2011 10:21:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
98304:m+VRmLt1HXy8H6ZocWJm1JZMFtuQmCKi7ik+7NEAXB3NsO:m+VRmL3HXBH6ecWA17QxmtkiRJOO

Entry address:
0x205C

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, 9C, 70, 8A, 00, A1, 8F, 70, 8A, 00, C1, E0, 02, A3, 93, 70, 8A, 00, 52, 6A, 00, E8, 47, 33, 4A, 00, 8B, D0, E8, DE, 38, 49, 00, 5A, E8, BC, 34, 49, 00, E8, C7, 3D, 49, 00, 6A, 00, E8, 18, 50, 49, 00, 59, 68, 38, 70, 8A, 00, 6A, 00, E8, 21, 33, 4A, 00, A3, 97, 70, 8A, 00, 6A, 00, E9, 8F, E5, 49, 00, E9, 4A, 50, 49, 00, 33, C0, A0, 81, 70, 8A, 00, C3, A1, 97, 70, 8A, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, 6C, 02, 00, 00, 0B, C9...
 
[+]

Code size:
4.6 MB (4,874,240 bytes)

Remove wintray.exe - Powered by Reason Core Security