XactPAY.exe

XactPAY_Service

Hartford Fire Insurance

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘xactpay’. This is installed with XactPAY Upload Utility.
Publisher:
The Hartford  (signed by Hartford Fire Insurance)

Product:
XactPAY_Service

Version:
1.0.0.0

MD5:
c49282300947eeb67699d4cf50b20d39

SHA-1:
25f442348e11cb2faa2ca7d9b5e55834eb608312

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 8:07:06 AM UTC  (today)

File size:
161.4 KB (165,232 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © The Hartford 2006

Original file name:
XactPAY.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\hartford fire insurance\xactpay upload utility\xactpay.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/14/2009 8:00:00 PM

Valid to:
7/29/2010 7:59:59 PM

Subject:
CN=Hartford Fire Insurance, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Payroll Alliances, O=Hartford Fire Insurance, L=Farmington, S=Connecticut, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3E2F16A51A410644380A89B45BFF9CCE

File PE Metadata
Compilation timestamp:
6/24/2010 5:40:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:2PFaXHd6hbxiSy59kEVj1+npFaXHd6hbxiSy59kEVj1+nm+PpmxXC7XA7XmCzPZG:kOQOePt7XA7XmwP6vZJ/PlhJN3dI4

Entry address:
0x2438E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.4326

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
140 KB (143,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
xactpay

Command:
C:\Program Files\hartford fire insurance\xactpay upload utility\xactpay.exe


The file XactPAY.exe has been discovered within the following program.

XactPAY Upload Utility  by Hartford Fire Insurance
www.xactpay.com/qbooks
About 9% of users remove it
 
Powered by Should I Remove It?

Scan XactPAY.exe - Powered by Reason Core Security