dmstatus.exe

Waters ICS Deployment Manager

Waters Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘rundm’.
Publisher:
Waters Corporation  (signed and verified)

Product:
Waters ICS Deployment Manager

Version:
3.0.122.1

MD5:
e4b2209f3dfdf87d9c53490ce3e0dce0

SHA-1:
19d22d268d93f6fa897efb5e36d1ed335f12ee7d

SHA-256:
3bae46ca7e0e646c046045faf4cacea2aa4913e776ff12d85859e91fa5b2d625

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:35:16 PM UTC  (today)

File size:
686.4 KB (702,824 bytes)

Product version:
3.0.122.1

Copyright:
Copyright © 2009-2011 Waters Corporation. All rights reserved.

Original file name:
DM.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\waters\ics\dm\dmstatus.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/1/2009 1:00:00 AM

Valid to:
6/21/2012 12:59:59 AM

Subject:
CN=Waters Corporation, OU=Informatics, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Waters Corporation, L=Milford, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
612A1E0DA422D380BB02E8E27E128E49

File PE Metadata
Compilation timestamp:
2/1/2012 9:47:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:QF8irbxgmZYuBpkn+Fb8b+FpvYV0aiNo50CsksbMz:aY4pk+Fb8b+FpvYV0aIoWMz

Entry address:
0xAA5FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.9133

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
674 KB (690,176 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
rundm

Command:
"C:\Program Files\waters\ics\dm\dmstatus.exe" \c


Scan dmstatus.exe - Powered by Reason Core Security