CompanionLink.exe

CompanionLink

CompanionLink Software Inc

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CompanionLink’.
Publisher:
CompanionLink Software, Inc.  (signed by CompanionLink Software Inc)

Product:
CompanionLink

Description:
CompanionLink MFC Application

Version:
7.0.0.0

MD5:
a37e8b438f43e4859a95be64e65278b5

SHA-1:
a8c9fc61d8475ac1d4d4d7e96f2d6743711b5c12

SHA-256:
ee6c155a7c9830395a09e195b46871e0c6d28123068f6b5167c45c1d891b7491

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/25/2024 3:23:55 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16913

File size:
28.8 MB (30,219,560 bytes)

Product version:
7.0.0.0

Copyright:
Copyright (C) 1996-2015 by CompanionLink Software, Inc. All Rights Reserved

Trademarks:
CompanionLink(R) is a registered trademark of CompanionLink Software, Inc. All Rights Reserved

Original file name:
CompanionLink.Exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\companionlink\companionlink.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
8/18/2015 8:00:00 PM

Valid to:
4/28/2016 7:59:59 PM

Subject:
CN=CompanionLink Software Inc, OU=ADMINISTRATION, O=CompanionLink Software Inc, L=Lake Oswego, S=Oregon, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
72F687F119931CD754F7BE6119501F28

File PE Metadata
Compilation timestamp:
2/15/2016 2:11:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
393216:jvHjR9j96Y58K4x0EigOwmukdcNqpQS4zNc/rArsPQMvdF3:XRGYS8iOwMcRhOMIn

Entry address:
0xB48776

Entry point:
E8, B0, 15, 00, 00, E9, 4E, FE, FF, FF, 55, 8B, EC, A1, 84, A8, 4F, 01, 8B, C8, 33, 45, 08, 83, E1, 1F, D3, C8, 5D, C3, 55, 8B, EC, A1, 84, A8, 4F, 01, 83, E0, 1F, 6A, 20, 59, 2B, C8, 8B, 45, 08, D3, C8, 33, 05, 84, A8, 4F, 01, 5D, C3, 55, 8B, EC, 8B, 45, 08, 8B, 4D, 0C, D3, C8, 5D, C3, 55, 8B, EC, 8B, 45, 08, 56, 8B, 48, 3C, 03, C8, 0F, B7, 41, 14, 8D, 51, 18, 03, D0, 0F, B7, 41, 06, 6B, F0, 28, 03, F2, 3B, D6, 74, 19, 8B, 4D, 0C, 3B, 4A, 0C, 72, 0A, 8B, 42, 08, 03, 42, 0C, 3B, C8, 72, 0C, 83, C2, 28, 3B...
 
[+]

Entropy:
6.1171

Code size:
13.7 MB (14,364,672 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CompanionLink

Command:
"C:\Program Files\companionlink\companionlink.exe" -icon


Scan CompanionLink.exe - Powered by Reason Core Security