strtupap.exe

Quick Heal AntiVirus

Thirtyseven4, LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Thirtyseven4 Core UI’.
Publisher:
Quick Heal Technologies (P) Ltd.  (signed by Thirtyseven4, LLC)

Product:
Quick Heal AntiVirus

Description:
Quick Heal Startup Main

Version:
4.0.0.1

MD5:
badb7bf0d649ff35534b8d414a7ef4da

SHA-1:
0cc471a7ae6b976e04269c681df9d510e47701d5

SHA-256:
754cd80d20918363bacb69a3265673ec3b8a0e8b25722f64a77cd38b337936c9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 10:01:31 PM UTC  (today)

File size:
45.4 KB (46,512 bytes)

Product version:
11.00

Copyright:
© Quick Heal Technologies (P) Ltd. All rights reserved.

Original file name:
strtupap.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\thirtyseven4\thirtyseven4\strtupap.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/28/2009 7:00:00 PM

Valid to:
7/29/2010 6:59:59 PM

Subject:
CN="Thirtyseven4, LLC", OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Thirtyseven4, LLC", L=Medina, S=Ohio, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
693E3CB3C6B14B7456B94C98683DD97D

File PE Metadata
Compilation timestamp:
7/28/2009 2:41:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
768:tv9iYSugcgo7uEdx4UfXiclVrs+KLWWbCNx:tMsgcvdKUnlRsta2CNx

Entry address:
0x12DC

Entry point:
6A, 60, 68, 28, 62, 40, 00, E8, D4, 0D, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 2C, 0F, 00, 00, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 28, 60, 40, 00, 8B, 4E, 10, 89, 0D, B8, 88, 40, 00, 8B, 46, 04, A3, C4, 88, 40, 00, 8B, 56, 08, 89, 15, C8, 88, 40, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, BC, 88, 40, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, BC, 88, 40, 00, C1, E0, 08, 03, C2, A3, C0, 88, 40, 00, 33, F6, 56, 8B, 3D, 1C, 60, 40, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
5.1502

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
20 KB (20,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Thirtyseven4 Core UI

Command:
C:\Program Files2\thirty~1\thirty~1\strtupap.exe


Scan strtupap.exe - Powered by Reason Core Security