zillya.exe

Zillya Antivirus

ALLIT Service, LLC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Zillya Antivirus’.
Publisher:
ALLIT Service, LLC.  (signed and verified)

Product:
Zillya Antivirus

Version:
1,1,3093,0

MD5:
36e53185716b8ffd94dab465a2edc4ae

SHA-1:
02595297a4a0ad75c9ca4a21f877c73c57fe7c5b

SHA-256:
087c818089ef790817d29663d17b52d846fababf62872e606100dad286a57b92

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 11:55:25 PM UTC  (a few moments ago)

File size:
1.7 MB (1,802,472 bytes)

Product version:
1,1,3093,0

Copyright:
(c) 2009 - 2011 ALLIT Service, LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\zillya antivirus\zillya.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/23/2011 2:00:00 AM

Valid to:
3/23/2012 1:59:59 AM

Subject:
CN="ALLIT Service, LLC.", O="ALLIT Service, LLC.", STREET="Observatornaya st., 23, apt. 17", L=Kyiv, S=Kyivska, PostalCode=04053, C=UA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
4D0A25012DF1FD466A61BB33E29EB980

File PE Metadata
Compilation timestamp:
8/23/2011 5:15:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:LDxMoGcxZMoxHbyj+3QzpHUeKRBpAlUzW:Luj8MAHby9tHUqU6

Entry address:
0x10ABF2

Entry point:
E8, BD, 05, 00, 00, E9, 35, FD, FF, FF, FF, 25, 24, AF, 53, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 4C, AF, 53, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 53, 57, 33, FF, 8B, 44, 24, 10, 0B, C0, 7D, 14, 47, 8B, 54, 24, 0C, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 10, 89, 54, 24, 0C, 8B, 44, 24, 18, 0B, C0, 7D, 13, 8B, 54, 24, 14, F7, D8, F7, DA, 83, D8, 00, 89, 44, 24, 18, 89, 54, 24, 14, 0B, C0, 75, 1B, 8B, 4C, 24, 14, 8B, 44, 24, 10, 33, D2, F7, F1, 8B, 44, 24, 0C, F7, F1, 8B...
 
[+]

Code size:
1.2 MB (1,282,048 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Zillya Antivirus

Command:
"C:\Program Files\zillya antivirus\zillya.exe" \min


Scan zillya.exe - Powered by Reason Core Security