cwtray.exe

Alta

ContentWatch Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘cwcptray’.
Publisher:
ContentWatch, Inc.  (signed by ContentWatch Inc)

Product:
Alta

Description:
cwtray.exe

Version:
2.7.0.201

MD5:
6cbdc66d9854cb619c0d8dc20143ce53

SHA-1:
962a400b8c3d75a6ed09231c0b8e9453187283d5

SHA-256:
04a48ea8fad8523981b8421c097aa85b498c566f8536346529c04fd8717c0c14

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 6:48:30 PM UTC  (today)

File size:
411.3 KB (421,136 bytes)

Product version:
2.7.0.201

Copyright:
(C) ContentWatch, Inc. 2006-2008. All rights reserved.

Original file name:
cwtray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\contentwatch\internet protection\cwtray.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/13/2008 7:00:00 PM

Valid to:
2/13/2009 6:59:59 PM

Subject:
CN=ContentWatch Inc, O=ContentWatch Inc, STREET=32369 Orton Circle, L=Salt Lake City, S=Utah, PostalCode=84119, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2ACC8CA7B67CC8D9232261EC3B77696D

File PE Metadata
Compilation timestamp:
11/6/2008 3:33:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:MgKsH9bQR6ux7/+a03JjraHIXfgJs8AS5Eb3ufef+KElclROa4hkAq5yBzIzacFD:MgKsH9bQvx7y3I5Eb+fVlCiwnCg

Entry address:
0x36FF0

Entry point:
E8, 9F, 06, 00, 00, E9, 35, FD, FF, FF, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, FF, 25, D0, B1, 43, 00, FF, 25, CC, B1, 43, 00, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, AA, FF, FF, FF, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 94, FF, FF, FF, FF, 25, B0, B1...
 
[+]

Code size:
230 KB (235,520 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cwcptray

Command:
C:\Program Files\contentwatch\internet protection\cwtray.exe


Scan cwtray.exe - Powered by Reason Core Security