easynoter.exe

ART PLUS D.O.O.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘C:_USERS_MDBOB_000_PROGRAMS_ART PLUS_EASYNOTER4_EASYNOTER.EXE’.
Publisher:
Art Plus Marketing & Publishing  (signed by ART PLUS D.O.O.)

Description:
Art Plus EasyNoter PRO

Version:
4.2.9.794

MD5:
3bb666774d2d0cc4bcaaaec78f996bec

SHA-1:
dce16ee21c583dcaf3c176a8ad4b8fa0e0f5dd64

SHA-256:
7eca83c49b2e9be6cbb1a36e34651ebdc9b44f452c70ba8a3b96bbeb34f950be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 3:24:41 PM UTC  (today)

File size:
4.6 MB (4,798,112 bytes)

Product version:
4.2

Copyright:
Copyright © 1999-2014 Art Plus

Original file name:
easynoter.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\mdbob_000\programs\art plus\easynoter4\easynoter.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/18/2014 12:00:00 PM

Valid to:
7/18/2016 11:59:59 AM

Subject:
CN=ART PLUS D.O.O., O=ART PLUS D.O.O., STREET=Kapelska 5, L=Zagreb, S=HR, PostalCode=10000, C=HR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
026E9F820E8FEE940C0768BDAA6C2B50

File PE Metadata
Compilation timestamp:
12/18/2014 9:09:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:bhFfOw4l1voPjkxSSQ3QJFJtxHyqkgX0qbSgmA8/CqGkhF3uxh5qTlPXnvCh/POC:bhFmw4DbhtsqkpWd8/ykhF3TXAPOC

Entry address:
0x3C3C38

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, B8, E0, 27, 7B, 00, E8, 40, 9E, C4, FF, 8B, 1D, 1C, 1A, 7D, 00, 33, C0, 55, 68, 6C, 3F, 7C, 00, 64, FF, 30, 64, 89, 20, 8B, 03, E8, 75, 02, E1, FF, 8B, 03, C6, 40, 67, 00, 8B, 03, BA, 88, 3F, 7C, 00, E8, 13, FC, E0, FF, 8D, 55, E4, 8B, 03, E8, 85, 0B, E1, FF, 8B, 45, E4, 8D, 55, E8, E8, EE, B4, E1, FF, 8B, 45, E8, 8D, 55, EC, E8, 57, D8, C5, FF, 8B, 45, EC, E8, DF, 02, E5, FF, 84, C0, 0F, 84, 61, 02, 00, 00, B8, CC, 3F, 7C, 00, E8, DD...
 
[+]

Entropy:
6.5408

Developed / compiled with:
Microsoft Visual C++

Code size:
3.8 MB (3,942,400 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
C:_USERS_MDBOB_000_PROGRAMS_ART PLUS_EASYNOTER4_EASYNOTER.EXE

Command:
"C:\users\mdbob_000\programs\art plus\easynoter4\easynoter.exe" \a \a


Scan easynoter.exe - Powered by Reason Core Security