saservice.exe

Ark Information Systems inc.

It runs as a windows Service named “SpeedAdvance Service”.
Publisher:
Ark Information Systems inc.  (signed and verified)

MD5:
440d6aa2d26435fd646897957c2bb17a

SHA-1:
59f02543b67d15822302eb8058d32ab346b9c43d

SHA-256:
c5771b54eec450e64f8a84635d4339a41bb09c8da9a9e71df20e5d6df214a35a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:56:24 AM UTC  (today)

File size:
212.4 KB (217,504 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Windows\System32\saservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/8/2010 9:00:00 AM

Valid to:
7/9/2011 8:59:59 AM

Subject:
CN=Ark Information Systems inc., OU=KH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ark Information Systems inc., L=Chiyoda-Ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
629D4947F1EEDCB9967825F31F31DB6D

File PE Metadata
Compilation timestamp:
11/30/2010 3:08:32 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
3072:hj1Q5o0DWxoA5NEoJ9Cu4OFvYn0vgBvPIJeFCnM6uZOKz9wb73gSRtPSD2LmpYKX:U5o0DITJ9CTBHIIQnhuZO5t8GKdzV

Entry address:
0x10E00

Entry point:
48, 83, EC, 28, E8, 37, 67, 00, 00, 48, 83, C4, 28, E9, 4E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 40, 53, 48, 83, EC, 20, 48, 83, F9, E0, 48, 8B, D9, 0F, 87, 9B, 00, 00, 00, 48, 89, 74, 24, 30, 48, 85, C9, BE, 01, 00, 00, 00, 48, 0F, 45, F1, 48, 89, 7C, 24, 38, 66, 66, 90, 66, 66, 66, 90, 48, 8B, 0D, 99, 5E, 02, 00, 48, 85, C9, 75, 20, E8, 9F, 5E, 00, 00, B9, 1E, 00, 00, 00, E8, 55, 5C, 00, 00, B9, FF, 00, 00, 00, E8, 0B, 10, 00, 00, 48, 8B, 0D, 74, 5E, 02, 00, 4C, 8B, C6, 33...
 
[+]

Entropy:
6.1114

Code size:
135.5 KB (138,752 bytes)

Service
Display name:
SpeedAdvance Service

Type:
Win32OwnProcess, InteractiveProcess


Scan saservice.exe - Powered by Reason Core Security