strtupap.exe

Quick Heal AntiVirus

Thirtyseven4, LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Thirtyseven4 Core UI’.
Publisher:
Quick Heal Technologies (P) Ltd.  (signed by Thirtyseven4, LLC)

Product:
Quick Heal AntiVirus

Description:
Quick Heal AntiVirus Start-up Application

Version:
7.0.0.1

MD5:
9451163573a17cca7a64f0679a093cac

SHA-1:
424659a141bb57f51c027cb93932d477bda01e3d

SHA-256:
99d176bcc24a216f3e5faa967bc100e18b63b5afc518ad6c25b0dd6f350fc2a5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 10:23:05 PM UTC  (today)

File size:
158 KB (161,768 bytes)

Product version:
14.00

Copyright:
© Quick Heal Technologies (P) Ltd. All rights reserved.

Original file name:
strtupap.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\thirtyseven4\thirtyseven4\strtupap.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/11/2012 7:00:00 PM

Valid to:
7/28/2013 6:59:59 PM

Subject:
CN="Thirtyseven4, LLC", OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Thirtyseven4, LLC", L=Medina, S=Ohio, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
02AE7CC8941DA3CA789AC991F8AAAEFC

File PE Metadata
Compilation timestamp:
8/1/2012 5:22:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:0r0lJZbcHVd8JiWz3HS9A8DJWBp1P5m7OX:00lJZbsdMZKipmyX

Entry address:
0x44B8

Entry point:
E8, 2D, 96, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, A3, 44, 71, 42, 00, 5D, C3, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 48, 60, 42, 00, 33, C5, 89, 45, FC, 83, A5, D8, FC, FF, FF, 00, 53, 6A, 4C, 8D, 85, DC, FC, FF, FF, 6A, 00, 50, E8, 52, FD, FF, FF, 8D, 85, D8, FC, FF, FF, 89, 85, 28, FD, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, 2C, FD, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89...
 
[+]

Entropy:
6.5832

Code size:
129 KB (132,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Thirtyseven4 Core UI

Command:
"C:\Program Files\thirtyseven4\thirtyseven4\strtupap.exe"


Scan strtupap.exe - Powered by Reason Core Security