F101Tray.exe

Fortres 101

Fortres Grand Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘F101Tray’.
Publisher:
Fortres Grand Corporation  (signed and verified)

Product:
Fortres 101

Description:
Fortres 101 Tray Application

Version:
6.0.2223.4

MD5:
8950e8a5c620da6023643a428d95e290

SHA-1:
83dab2c4d7b6a8e0685488d03d85310f97a05a6d

SHA-256:
977045317b631417ee60233f4c39e8a06f4691a7b6741f85d37ac8099be345f5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 12:51:29 AM UTC  (today)

File size:
187.3 KB (191,816 bytes)

Product version:
6.0.2223.4

Copyright:
Copyright © 2008-2011 Fortres Grand Corporation

Original file name:
F101Tray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\fortres grand\fortres 101 6.5\f101tray.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/19/2010 9:47:44 AM

Valid to:
3/19/2013 9:47:39 AM

Subject:
E=trust@fortresgrand.com, CN=Fortres Grand Corporation, O=Fortres Grand Corporation, L=Plymouth, S=IN, C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012776E5F367

File PE Metadata
Compilation timestamp:
11/20/2012 11:54:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:3VmR2Bn2pBjyKdj7pmyIdC+rPwVLk0qkw9y50f:3VmkR2pPB7pzI

Entry address:
0x4D50

Entry point:
E8, A9, 38, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 0A, 6A, 00, FF, 75, 08, E8, 59, 3B, 00, 00, 83, C4, 0C, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 30, 2C, 41, 00, 00, 75, 18, E8, 13, 30, 00, 00, 6A, 1E, E8, 5D, 2E, 00, 00, 68, FF, 00, 00, 00, E8, 5B, FB, FF, FF, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 30, 2C, 41, 00, FF, 15, BC, D0, 40, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 34, 2C, 41, 00, 74, 0D, 53, E8, 3B, 28...
 
[+]

Entropy:
5.9789

Code size:
46 KB (47,104 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
F101Tray

Command:
"C:\Program Files\fortres grand\fortres 101 6.5\f101tray.exe"


Scan F101Tray.exe - Powered by Reason Core Security