RooArr.exe

Room Arranger

Jan Adamec

This is installed with Room Arranger.
Publisher:
Jan Adamec  (signed and verified)

Product:
Room Arranger

Version:
7.0.5.289

MD5:
b7c93cedbc0f4efd88a120943b2dc6f0

SHA-1:
e7923f4344c9d2c8617c3847701113ebac64cfd5

SHA-256:
981d40058f87e2ce8194ce5272597579a56808ccfcc4afaf67142871d192cc80

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 3:27:57 PM UTC  (today)

File size:
5.3 MB (5,522,488 bytes)

Product version:
7.0.5

Original file name:
RooArr.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\room arranger\rooarr.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/11/2012 3:00:00 AM

Valid to:
6/12/2015 2:59:59 AM

Subject:
CN=Jan Adamec, O=Jan Adamec, STREET=Na vysine 2076/3, L=Praha 4, S=-, PostalCode=14300, C=CZ

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
40B6FCE015FA82D0BA2AF300BDDB6972

File PE Metadata
Compilation timestamp:
8/31/2012 12:49:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
98304:9RXhdhxzlyAkuFSCwzrixL0g2RuA2IVh1GFpQ2QeLK8RP0futdMLBqd3/:HXhxRcu0OxL0dRb2CsFp/0futdMWv

Entry address:
0x1978

Entry point:
EB, 10, 66, 62, 3A, 43, 2B, 2B, 48, 4F, 4F, 4B, 90, E9, AC, 80, 80, 00, A1, 9F, 80, 80, 00, C1, E0, 02, A3, A3, 80, 80, 00, 52, 6A, 00, E8, 85, 51, 40, 00, 8B, D0, E8, E2, 21, 3F, 00, 5A, E8, 20, 21, 3F, 00, E8, 33, 23, 3F, 00, 6A, 00, E8, 90, 41, 3F, 00, 59, 68, 48, 80, 80, 00, 6A, 00, E8, 5F, 51, 40, 00, A3, A7, 80, 80, 00, 6A, 00, E9, C7, 01, 40, 00, E9, C2, 41, 3F, 00, 33, C0, A0, 91, 80, 80, 00, C3, A1, A7, 80, 80, 00, C3, 60, BB, 00, 50, B0, BC, 53, 68, AD, 0B, 00, 00, C3, B9, EC, 00, 00, 00, 0B, C9...
 
[+]

Entropy:
6.4282

Code size:
4 MB (4,222,976 bytes)

The file RooArr.exe has been discovered within the following program.

Room Arranger  by Jan Adamec
www.roomarranger.com
About 2% of users remove it
 
Powered by Should I Remove It?

Scan RooArr.exe - Powered by Reason Core Security