tray.exe

Simple Registry Cleaner

Vapc Lux Sarl

The application tray.exe by Vapc Lux Sarl has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Simple Registry Cleaner by SimpleStar. While running, it connects to the Internet address bam-2.nr-data.net on port 443.
Publisher:
Vapc Lux Sarl  (signed and verified)

Product:
Simple Registry Cleaner

Version:
4,10,1,4

MD5:
1bb15c57f9b60d2b6128f9781f7d0880

SHA-1:
b06bde2421f646fac2daffe8500fedcbd3ac1fd7

SHA-256:
7e3297a511016364e8435ff3f412db833723825e98d8b9c37f6f085bfbc90c08

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/22/2024 10:31:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SimpleStar (L)
16.12.14.0

File size:
2.1 MB (2,218,968 bytes)

Product version:
4.10.1.4

Copyright:
Copyright © 2016 SimpleStar. All Rights Reserved.

Original file name:
SimpleRegistryCleaner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\simple registry cleaner\tray.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/11/2016 4:11:14 PM

Valid to:
2/10/2017 4:57:32 PM

Subject:
E=Ludovic.trogliero@vapc.lu, CN=Vapc Lux Sarl, O=Vapc Lux Sarl, L=Luxembourg, C=LU

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130BA28CC6DC89090DD3923776478D67D

File PE Metadata
Compilation timestamp:
12/12/2016 5:50:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x37508

Entry point:
E8, 06, 07, 00, 00, E9, 6B, FD, FF, FF, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, 68, C8, 6F, 43, 00, 68, A0, AF, 47, 00, E8, 7C, 07, 00, 00, 83, C4, 18, 5D, C3, CC, FF, 25, E4, E4, 44, 00, FF, 25, E0, E4, 44, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, CC, CC, CC, CC...
 
[+]

Code size:
307.5 KB (314,880 bytes)

The file tray.exe has been discovered within the following program.

Simple Registry Cleaner  by SimpleStar
www.simplestar.com/support/simple-registry-cleaner
57% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-85-189-79.compute-1.amazonaws.com  (54.85.189.79:80)

TCP (HTTP):
Connects to ec2-52-2-143-52.compute-1.amazonaws.com  (52.2.143.52:80)

TCP (HTTP SSL):
Connects to cache.google.com  (31.209.137.14:443)

TCP (HTTP SSL):
Connects to bam-8.nr-data.net  (162.247.242.20:443)

TCP (HTTP SSL):
Connects to bam-2.nr-data.net  (50.31.164.166:443)

TCP (HTTP SSL):
Connects to bam-7.nr-data.net  (162.247.242.19:443)

TCP (HTTP SSL):
Connects to bam-6.nr-data.net  (162.247.242.18:443)

TCP (HTTP SSL):
Connects to 60-137-209-31.business.hringdu.is  (31.209.137.60:443)

Remove tray.exe - Powered by Reason Core Security