ac.activclient.scardactions.exe

ActivClient

ActivIdentity

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ac.activclient.scardactions.exe’.
Publisher:
ActivIdentity  (signed and verified)

Product:
ActivClient

Description:
ActivIdentity card event handler

Version:
7,0,0,33

MD5:
e770ee33e4ef44c7c9dc9727918769c1

SHA-1:
8da218a882fd82477e1b3a1df2e4730b5aa88dee

SHA-256:
461f5c87198f3b8fe6ad138f34601f013e1ee959fecfe7c1d50ba6ee81d9f827

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 10:24:31 AM UTC  (today)

File size:
551.9 KB (565,128 bytes)

Product version:
7,0

Copyright:
Copyright © 1998-2011 ActivIdentity (All rights reserved)

Original file name:
accrdsub.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\actividentity\activclient\ac.activclient.scardactions.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/27/2011 7:00:00 PM

Valid to:
1/28/2012 6:59:59 PM

Subject:
CN=ActivIdentity, OU=Engineering Code Signing, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ActivIdentity, L=Fremont, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5DDF0032AE561A392770A3EC60661C69

File PE Metadata
Compilation timestamp:
9/22/2011 12:16:53 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ReCnr6nqCMPReMVEMeiL4jUc5hLC4c6tCIfe0rUSDb7p1d60mAOa8u9lzkty:RvreqdphfeDxCIfedu92w

Entry address:
0x2B6C4

Entry point:
E8, A0, 04, 00, 00, E9, 6B, FD, FF, FF, 3B, 0D, 18, 00, 48, 00, 75, 02, F3, C3, E9, 27, 05, 00, 00, 6A, 14, 68, 88, 99, 47, 00, E8, D7, 03, 00, 00, FF, 35, AC, 15, 48, 00, 8B, 35, 74, F0, 42, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 84, F1, 42, 00, 59, EB, 64, 6A, 08, E8, 04, 06, 00, 00, 59, 83, 65, FC, 00, FF, 35, AC, 15, 48, 00, FF, D6, 89, 45, E4, FF, 35, A8, 15, 48, 00, FF, D6, 89, 45, E0, 8D, 45, E0, 50, 8D, 45, E4, 50, FF, 75, 08, 8B, 35, 70, F0, 42, 00, FF, D6, 50, E8, CA, 05...
 
[+]

Entropy:
5.3752

Code size:
184 KB (188,416 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ac.activclient.scardactions.exe

Command:
"C:\Program Files\actividentity\activclient\ac.activclient.scardactions.exe"