avgtray.exe

AVG Internet Security

AVG Technologies

The executable avgtray.exe has been detected as malware by 6 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AVG8_TRAY’.
Publisher:
AVG Technologies CZ, s.r.o.  (signed by AVG Technologies)

Product:
AVG Internet Security

Description:
AVG Tray Monitor

Version:
8.5.0.454

MD5:
ebe8ed21ae9f4612626fbd2d9962cd34

SHA-1:
8d25070eab7af3ffc7cf48f4a41194100f5ee06e

SHA-256:
17ae53c297ffcf371e1558f7d69cbce21b1581405634d897b4f864f7ffe7bcb9

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/25/2024 10:00:30 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.Patched
8.3.2.4

Comodo Security
UnclassifiedMalware
23999

F-Prot
W32/Patched.Y.gen
v6.4.7.1.166

IKARUS anti.virus
Virus.Win32.Sality
t3scan.1.9.5.0

Qihoo 360 Security
Win32/Virus.7c2
1.0.0.1077

Rising Antivirus
PE:Junk.FileBroken!1.9A81 [F]
23.00.65.16210

File size:
1.9 MB (2,042,208 bytes)

Product version:
8.5.0.454

Copyright:
Copyright © 2011 AVG Technologies CZ, s.r.o.

Original file name:
avgtray.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\avg\avg8\avgtray.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/16/2010 4:00:00 PM

Valid to:
3/5/2012 3:59:59 PM

Subject:
CN=AVG Technologies, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVG Technologies, L=Brno, S=Jihomoravsky kraj, C=CZ

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20EBFBCFC7970C887CB0510AA423A604

File PE Metadata
Compilation timestamp:
10/12/2011 6:07:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:oiqqOsPzZaYYwW4fny4ESCeE7AJJHj0161feMAWGjKlLpdw0Z:HsYg4ESCGHq61fehnaLpi0Z

Entry address:
0xDF7DF

Entry point:
C3, C3, C3, C3, C3, C3, C3, C3, FF, FF, CC, FF, 25, 7C, EA, 50, 00, FF, 25, 78, EA, 50, 00, FF, 25, 58, EA, 50, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 64, BB, 54, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 64, BB, 54, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64...
 
[+]

Entropy:
6.3739

Code size:
1 MB (1,098,752 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AVG8_TRAY

Command:
C:\Program Files1\avg\avg8\avgtray.exe


Remove avgtray.exe - Powered by Reason Core Security