asdtray.exe

Anvi Smart Defender

Anvei Technology Co., LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Anvi Smart Defender’.
Publisher:
Anvisoft  (signed by Anvei Technology Co., LTD)

Product:
Anvi Smart Defender

Version:
1.9.1.1564

MD5:
6b4d65dcbc03e8badd10798cf46ae871

SHA-1:
06228b5735699729dcff3a4d8a1937081acd98a0

SHA-256:
b36a23d41ba9bec16ca918cd510e17dd084f01305e2ce45a24a0cb610e92a31c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:44:20 AM UTC  (today)

File size:
1.5 MB (1,606,376 bytes)

Product version:
1.9.1.0

Copyright:
Copyright (C) 2011-2012 Anvisoft

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\anvisoft\anvi smart defender\asdtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/13/2011 9:00:00 AM

Valid to:
10/13/2014 8:59:59 AM

Subject:
CN="Anvei Technology Co., LTD", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Anvei Technology Co., LTD", L=Chengdu, S=Sichuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1C0BF93BBAA58FC100BA37A6E491A8FB

File PE Metadata
Compilation timestamp:
7/31/2013 3:12:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:IR/I6g9iu4ewEI0kJIBhWDuA+qRz1lfkljtL4NHlSl9zbdqqTeXbZBNcMw8E:Iq6JoQfklRgHlobdqqTerZ9w5

Entry address:
0x8DAA2

Entry point:
E8, 2B, BF, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, B8, B9, 50, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, D0, B2, 50, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.7408

Code size:
1 MB (1,088,000 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Anvi Smart Defender

Command:
C:\Program Files\anvisoft\anvi smart defender\asdtray.exe


Scan asdtray.exe - Powered by Reason Core Security