AVDm.exe

彩りプラスの設定

NEC Personal Products, Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AVDM’.
Publisher:
NEC Corporation, NEC Personal Products, Ltd.  (signed by NEC Personal Products, Ltd.)

Product:
彩りプラスの設定

Version:
2, 1, 0, 5

MD5:
842811f33c2f9820be16763b34884615

SHA-1:
977d3be1856bcf51f2ea8c31e7d1f2fc852c1cb9

SHA-256:
dbf91944e3fad5a89623f6cad997e7cac1c98b75a557e9bc1a250dcad158c468

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:45:13 PM UTC  (today)

File size:
705.3 KB (722,232 bytes)

Product version:
1.0.0.0

Copyright:
(C) NEC Corporation, NEC Personal Products, Ltd. 2008-2010

Trademarks:
NEC Corporation

Original file name:
AVDm.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\avdm\avdm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/20/2009 9:00:00 AM

Valid to:
1/21/2010 8:59:59 AM

Subject:
CN="NEC Personal Products, Ltd.", OU=D00, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NEC Personal Products, Ltd.", L=Shinagawa-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C35EB6EBC98D50241A2DED2B9439BF0

File PE Metadata
Compilation timestamp:
11/20/2009 2:57:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:eaD8EFziOd6VD+/19k8bUPW8V5MeXdru2um:eaD8eLkUUPWdQB

Entry address:
0x3D4BC

Entry point:
E8, 9A, 5D, 00, 00, E9, 17, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 14, 75, 20, E8, 14, 35, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 6C, 60, 00, 00, 83, C4, 14, 83, C8, FF, E9, C5, 00, 00, 00, 56, 8B, 75, 0C, 57, 8B, 7D, 10, 3B, FB, 74, 24, 3B, F3, 75, 20, E8, E4, 34, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 3C, 60, 00, 00, 83, C4, 14, 83, C8, FF, E9, 93, 00, 00, 00, 81, FF, FF, FF, FF, 3F, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 76, 09, C7, 45, E4...
 
[+]

Entropy:
5.7216

Code size:
348 KB (356,352 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AVDM

Command:
C:\Program Files\avdm\avdm.exe \resident


Scan AVDm.exe - Powered by Reason Core Security