VolumeConcierge.exe

Volume Concierge

Hirtal Developments Ltd.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘VolumeConcierge’.
Publisher:
Softorino  (signed by Hirtal Developments Ltd.)

Product:
Volume Concierge

Version:
1.1.0

MD5:
ee4c2f3f4f2dbc086c49c0b67f037925

SHA-1:
1afdd5c0c6bf0db768ef590f20d7ad2d255d3e8b

SHA-256:
cfefe23161592590e8268d4f83cf2a15bb13da53f2e592c4e5531ade933c177a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 11:36:58 PM UTC  (a few moments ago)

File size:
485.9 KB (497,528 bytes)

Product version:
1.1.0

Copyright:
Copyright © Softorino 2011

Original file name:
VolumeConcierge.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\volume concierge\volumeconcierge.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/7/2012 5:00:00 PM

Valid to:
10/8/2013 4:59:59 PM

Subject:
CN=Hirtal Developments Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Hirtal Developments Ltd., L=Limassol, S=Cyprus, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A28EAE8EB9C86EFC35A04934EB3F7B9

File PE Metadata
Compilation timestamp:
11/8/2012 6:17:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:g6S2TAxnClDrDLpdyPDNEg20TVWx96vzfrczKSlZe30ea:vN0dClDrDfyPpOaW7Y4KSXe3ha

Entry address:
0x5BACA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9055

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
359 KB (367,616 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VolumeConcierge

Command:
"C:\Program Files\volume concierge\volumeconcierge.exe" \autorun


Scan VolumeConcierge.exe - Powered by Reason Core Security