zpstray.exe

Zoner Photo Studio Autoupdate

ZONER software, a.s.

The executable zpstray.exe has been detected as malware by 5 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Zoner Photo Studio Autoupdate’.
Publisher:
ZONER software  (signed by ZONER software, a.s.)

Product:
Zoner Photo Studio Autoupdate

Version:
18.0.1.9

MD5:
74548ff8668e64fe86b7dd5e824bfba1

SHA-1:
36493743aa34c1b57d118463f34d5e46d0412432

SHA-256:
a1a19af13db2dbeab637c53a1a9c09c32e3ee7c775da48090ab009490ae61264

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/5/2024 2:42:53 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Pioneer-C
160807-0

AVG
Win32/Floxif.A
2013.0.4447

ESET NOD32
Win32/Floxif.H virus
6.3

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.96

File size:
741 KB (758,807 bytes)

Product version:
18.0.1.9

Copyright:
Copyright © 1995-2016

Trademarks:
Zoner is trademark of ZONER software

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\zoner\photo studio 18\program32\zpstray.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
8/11/2015 5:00:00 AM

Valid to:
9/4/2016 4:59:59 AM

Subject:
CN="ZONER software, a.s.", OU=Software development, O="ZONER software, a.s.", L=Brno, S=Brno-mesto, C=CZ, SERIALNUMBER=49437381, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=CZ

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
65E8F5332C3C9E28F930BD0A45A0CDCA

File PE Metadata
Compilation timestamp:
3/24/2016 6:09:57 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:iLPjAOlbOWxL22SJ3roJgnFmymwQTjGbh4jqnux7jY7VecBjvrEH7J:ubAAL2T30qnFmymwQTYh4j+ux7j9WrEd

Entry address:
0x51BCE

Entry point:
E9, 81, AD, FE, FF, E9, 4C, FE, FF, FF, 3B, 0D, 00, CB, 47, 00, 75, 02, F3, C3, E9, B6, 01, 00, 00, CC, FF, 25, E8, C2, 45, 00, FF, 25, EC, C2, 45, 00, FF, 25, F0, C2, 45, 00, FF, 25, F4, C2, 45, 00, 83, 3D, 7C, FF, 49, 00, 00, 74, 03, 33, C0, C3, 56, 6A, 04, 6A, 20, FF, 15, 64, C3, 45, 00, 59, 59, 8B, F0, 56, FF, 15, E0, C0, 45, 00, A3, 7C, FF, 49, 00, A3, 78, FF, 49, 00, 85, F6, 75, 05, 6A, 18, 58, 5E, C3, 83, 26, 00, 33, C0, 5E, C3, 6A, 14, 68, D8, 20, 47, 00, E8, A8, 08, 00, 00, FF, 35, 7C, FF, 49, 00...
 
[+]

Entropy:
6.0709

Packer / compiler:
Xtreme-Protector v1.05

Code size:
361.5 KB (370,176 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Zoner Photo Studio Autoupdate

Command:
"C:\Program Files\zoner\photo studio 18\program32\zpstray.exe"


Remove zpstray.exe - Powered by Reason Core Security