wbrunonce.exe

wbrunonce

The World Bank

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WBRunOnce’.
Publisher:
The World Bank Group  (signed by The World Bank)

Product:
wbrunonce

Version:
2.0.0.3

MD5:
17e96157d9eac5a4c9a3d96a34aa9436

SHA-1:
6e40c0d0457aa501ecf3983aed6a3535a0c6a080

SHA-256:
05327222a9ff754057b7719b7ed11f2c7dbd3475d3ec58893919a2ecd57d885c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 3:44:52 AM UTC  (today)

File size:
22.1 KB (22,624 bytes)

Product version:
2.0.0.3

Copyright:
Copyright © ITSEW 2015

Original file name:
wbrunonce.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
WBG Issuing CA2

Valid from:
9/25/2013 5:28:12 PM

Valid to:
9/24/2018 5:28:12 PM

Subject:
E=sm-desktop@worldbank.org, CN=ITSWE Applocker Whitelisting - Code Signing Certificate ver.1.0, OU=ITSWE, O=The World Bank, L=Washington, S=DC, C=US

Issuer:
CN=WBG Issuing CA2, DC=ad, DC=worldbank, DC=org

Serial number:
141A302A0000000269E3

File PE Metadata
Compilation timestamp:
10/9/2015 2:40:39 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x54CE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5440

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WBRunOnce

Command:
C:\wbg\utility\wbrunonce.exe \logon


Scan wbrunonce.exe - Powered by Reason Core Security