ravmond.exe

Rising AntiVirus 2012

Beijing Rising Information Technology Corporation Limited

It runs as a windows Service named “RFW Service”.
Publisher:
Beijing Rising Information Technology Co., Ltd.  (signed by Beijing Rising Information Technology Corporation Limited)

Product:
Rising AntiVirus 2012

Description:
ravmond

Version:
24, 0, 0, 6

MD5:
862a0f0230e816e0051ead8009ede2b0

SHA-1:
be1e12294c4df56ed08f1712a82d81e8a0f76791

SHA-256:
f07169fb980f89b97da5eb9f897815622b77e71ac3d0c6da70f342b9b536f352

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 10:55:38 AM UTC  (today)

File size:
267.3 KB (273,712 bytes)

Product version:
24.00

Copyright:
Copyright(C) 2011-2012 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.

Original file name:
ravmond.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\Program Files\rising\rfw\ravmond.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2009 1:00:00 AM

Valid to:
7/23/2012 12:59:59 AM

Subject:
CN=Beijing Rising Information Technology Corporation Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing Rising Information Technology Corporation Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
484D09D50F2997425272B797AA28A557

File PE Metadata
Compilation timestamp:
4/13/2012 5:18:41 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:C38gmxvlVbRmiVAt/xjCe9W/5dgNx/fNFWt+ZG9AZIC/hxr7GIzaAXk/:skVRmiVAt/xjCe9WxdgNx/1FWtkG9AZM

Entry address:
0x10130

Entry point:
8B, FF, 55, 8B, EC, E8, E6, F4, 00, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, B0, 71, 43, 00, 68, 90, 2B, 41, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 94, 53, 56, 57, A1, 88, 91, 43, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, 68, D1, 42, 00, C7, 45, FC, FE, FF, FF, FF, EB, 26, B8, 01, 00, 00, 00, C3, 8B, 65, E8, C7...
 
[+]

Entropy:
6.2028

Code size:
174.5 KB (178,688 bytes)

Service
Display name:
RFW Service

Service name:
RsRFWMon

Type:
Win32OwnProcess, InteractiveProcess

Group:
COM Infrastructure

Depends on:
RpcSs


Scan ravmond.exe - Powered by Reason Core Security