sr.exe

SlickRun

Eric Lawrence

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘SlickRun’.
Publisher:
Bayden Systems  (signed by Eric Lawrence)

Product:
SlickRun

Description:
SlickRun Command Line Utility

Version:
4.3.2.1

MD5:
c033384167961683a945de4f334dfeaf

SHA-1:
76b70d617a0e1d904587e4d2bc70f588f5323d5a

SHA-256:
8d4fcc083e45a6f8f7d2cfa96e56198b7fd4316666d977c0b25c368b74c60d31

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:37:57 PM UTC  (today)

File size:
4 MB (4,210,320 bytes)

Product version:
4.3.2.1

Copyright:
©2015 Eric Lawrence

Original file name:
sr.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\slickrun\sr.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/22/2015 7:00:00 PM

Valid to:
1/31/2018 7:00:00 AM

Subject:
CN=Eric Lawrence, O=Eric Lawrence, L=Austin, S=Texas, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0E7A7FDB64012964951C890FFCF23C10

File PE Metadata
Compilation timestamp:
12/17/2015 4:06:36 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:lXEublhYElk1t3sR0KC9PliBYEiNaxBLSJdSAMCAGOm1eQPyy/DCB3ht:ZEusElk1t3sRO9iYTaxNSzPA7mPPZ0

Entry address:
0x36F590

Entry point:
55, 48, 83, EC, 20, 48, 8B, EC, 90, 48, 8D, 0D, B8, 29, FF, FF, E8, 5B, 71, CA, FF, 48, 8B, 05, 04, 89, 04, 00, 48, 8B, 08, E8, EC, 60, F9, FF, 48, 8B, 05, F5, 88, 04, 00, 48, 8B, 08, 48, 33, D2, E8, BA, 8D, F9, FF, 48, 8B, 05, E3, 88, 04, 00, 48, 8B, 08, 48, 8D, 15, B5, 00, 00, 00, E8, 14, 58, F9, FF, E8, 8F, 28, FF, FF, 84, C0, 75, 64, 48, 8B, 0D, F4, 7F, FE, FF, B2, 01, E8, 8D, 96, FE, FF, 48, 8B, 0D, 3E, 8E, 04, 00, 48, 89, 01, 48, 8B, 05, AC, 88, 04, 00, 48, 8B, 08, 48, 8B, 15, 32, CB, FE, FF, 4C, 8B...
 
[+]

Entropy:
5.8475

Code size:
3.4 MB (3,598,336 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SlickRun

Command:
"C:\Program Files\slickrun\sr.exe"


Scan sr.exe - Powered by Reason Core Security