taskview.exe

TaskView

Rksoft Softwares

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘spmm’.
Publisher:
RK SOFT  (signed by Rksoft Softwares)

Product:
TaskView

Version:
3.03.0009

MD5:
b9fad36c2e73d789d568ac0dc688750b

SHA-1:
6b4b481debdd72af89d79721fa7de9a9b437b13b

SHA-256:
792e29b268b4814ee8786c99f9bd5c7d7f2a93207a820b97390d5e0f96a6db4d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 10:29:38 PM UTC  (today)

File size:
3.1 MB (3,301,832 bytes)

Product version:
3.03.0009

Original file name:
taskview.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\rksoft\splrk\taskview.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/5/2015 10:00:00 PM

Valid to:
11/5/2016 9:59:59 PM

Subject:
CN=Rksoft Softwares, O=Rksoft Softwares, STREET="Rua Nova Jerusalém, 339", L=São Paulo, S=São Paulo, PostalCode=03410-000, C=BR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
34D07423531A62BD2DB933736D665CF1

File PE Metadata
Compilation timestamp:
10/15/2016 3:46:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:ZWfQQQQQQQdidV/ZDGQZ5QQQQQQQQQQXvJK1Wl9NFl9Nn6:MQQQQQQQdidV/ZDGQZ5QQQQQQQQQQXvu

Entry address:
0x5CB8

Entry point:
68, 64, 9C, 52, 00, E8, EE, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, F6, 6E, F7, DA, 3C, E3, AF, 40, 9A, B9, F5, E5, 47, 69, 5F, EA, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 72, 6F, 6A, 65, 74, 6F, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B8, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 1A, 00, 00, 00, CF, CE, FE, F0, F1, 2C, 20, 4D, 97, C3, 83, 71, D2, AF, 59, 01, 01, 00, 00, 00, 98, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
3.1 MB (3,280,896 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
spmm

Command:
"C:\Program Files\rksoft\splrk\taskview.exe"


Scan taskview.exe - Powered by Reason Core Security