launch wallpaper.exe

Alexey Veresov

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PUSH Wallpaper’.
Publisher:
Alexey Veresov  (signed and verified)

MD5:
392036db58c886d9ea4c408ec86ff6e6

SHA-1:
a159347dd1606af72002098e0c6f52cfe46ea7ad

SHA-256:
22c9dc655fe890aa8f286e7a5ea85f633220cc663891e97b1fc81f06b27471d1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:20:56 AM UTC  (today)

File size:
497.5 KB (509,402 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\push entertainment\video wallpaper\launch wallpaper.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
4/19/2010 1:00:00 AM

Valid to:
4/19/2012 12:59:59 AM

Subject:
CN=Alexey Veresov, O=Alexey Veresov, STREET="Pochaevskaya st, 22a-13", L=Vladimir, S=Vladimir, PostalCode=600007, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
39836D1C6D4C4DD56DCE61CBB52BD31D

File PE Metadata
Compilation timestamp:
5/27/2010 9:12:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1270

Entry point:
E8, F7, 16, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, AD, 40, 00, 89, 0D, 54, AD, 40, 00, 89, 15, 50, AD, 40, 00, 89, 1D, 4C, AD, 40, 00, 89, 35, 48, AD, 40, 00, 89, 3D, 44, AD, 40, 00, 66, 8C, 15, 70, AD, 40, 00, 66, 8C, 0D, 64, AD, 40, 00, 66, 8C, 1D, 40, AD, 40, 00, 66, 8C, 05, 3C, AD, 40, 00, 66, 8C, 25, 38, AD, 40, 00, 66, 8C, 2D, 34, AD, 40, 00, 9C, 8F, 05, 68, AD, 40, 00, 8B, 45, 00, A3, 5C, AD, 40, 00, 8B, 45, 04, A3, 60, AD, 40, 00, 8D, 45, 08, A3, 6C, AD, 40...
 
[+]

Entropy:
5.0405

Code size:
25 KB (25,600 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PUSH Wallpaper

Command:
C:\Program Files\push entertainment\video wallpaper\launch wallpaper.exe s


Scan launch wallpaper.exe - Powered by Reason Core Security