SUPERRAM.EXE

SuperRam

PGWARE LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SuperRam’.
Publisher:
PGWARE LLC  (signed and verified)

Product:
SuperRam

Version:
5.0.0.1

MD5:
4c58cf820054d96bd9e9e6c52c8f895e

SHA-1:
98105ba16d2b0c3ad6fe27e44f0b70480448413b

SHA-256:
acc343bc9b9946bcfc08a5c9e06e205e03575920726c3c60476972784e0afde7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 2:37:29 AM UTC  (today)

File size:
379.7 KB (388,832 bytes)

Product version:
5.0.0.1

Copyright:
Copyright © 2001-2007 PGWARE LLC

Original file name:
SUPERRAM.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\superram\superram.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/25/2006 6:00:00 PM

Valid to:
8/14/2007 6:59:59 PM

Subject:
CN=PGWARE LLC, OU=SECURE APPLICATION DEVELOPMENT, O=PGWARE LLC, L=Norman, S=Oklahoma, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
0E143F939726C3B692D5EE1955AC63EC

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:glAZ1m8nkaRuIuVgQwn9WvH7JJ7ad5K3AYGv0pSoL+Ot2jfX+QSfkYtzcyCP83CS:fm8nHRuIuVj+Wvzu+AJv0bL+qUuQSfkI

Entry address:
0x1000

Entry point:
B8, 38, 3C, 59, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 1C, 2C, 25, 02, E8, 43, 68, 61, FF, 53, 20, FF, 1B, 09, 90, 40, 29, F0, 08, 53, 6D, DC, 50, 43, 69, 6E, 74, 02, 81, 80, FF, 99, 02, 7F, 31, 58, 08, 07, 63, 49, 26, 65, 67, 91, 72, 04, A1, 54, 19, 05, 8B, C0, 70, 02, 18, 04, 42, 79, 08, 44, 51, 84, 08, 04, 05, 57, 6F, 72, 64, 03, 5C, 14, 62, 54, 98, 58, 43, CD, D6, 64, AE, 94, B8, 05, 18, 98, 02, 90, B0, DC, 31, FF, E2...
 
[+]

Entropy:
7.8562

Packer / compiler:
PECompact v2

Code size:
593 KB (607,232 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SuperRam

Command:
"C:\Program Files\superram\superram.exe" \start


Scan SUPERRAM.EXE - Powered by Reason Core Security