WR_Tray_Icon.exe

WR Tray Icon

Tweaking LLC

The executable WR_Tray_Icon.exe, “Tweaking.com - Windows Repair Tray Icon” has been detected as malware by 3 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
Tweaking.com  (signed by Tweaking LLC)

Product:
WR Tray Icon

Description:
Tweaking.com - Windows Repair Tray Icon

Version:
3.0.0.0

MD5:
d705aa990e2daca4082bf0a0df18d410

SHA-1:
1d0e7296923eeaeb8f75679ec5f9be4fe6c6ad06

SHA-256:
5982f54fffbc7ef4de5c2c5aafbaddba0bc9bcc457fa43d6f2580f4aedb71f9a

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
12/25/2024 1:48:39 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
141.7 KB (145,095 bytes)

Product version:
3.0.0.0

Original file name:
WR_Tray_Icon.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\tweaking.com\windows repair (all in one)\wr_tray_icon.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/15/2015 4:00:00 PM

Valid to:
1/15/2017 3:59:59 PM

Subject:
CN=Tweaking LLC, OU=Major Geeks, O=Tweaking LLC, POBox=13031, STREET=7 Braniff Dr, L=Camillus, S=New York, PostalCode=13031, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FA9A6751C25E175F8CD0A34198E61E79

File PE Metadata
Compilation timestamp:
3/11/2015 5:43:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x22A00

Entry point:
E9, 8F, F2, FF, FF, 00, 8D, BE, 00, 30, FE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
6.8311

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
20 KB (20,480 bytes)

Scheduled Task
Task name:
Tweaking.com - Windows Repair Tray Icon

Trigger:
Logon (Runs on logon)

Description:
Created By Tweaking.com - Windows Repair


Remove WR_Tray_Icon.exe - Powered by Reason Core Security