ABNotify.exe

ABNotify Application

CHENGDU AOMEI Tech Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ABNotify’.
Publisher:
CHENGDU AOMEI Tech Co., Ltd.  (signed and verified)

Product:
ABNotify Application

Description:
AOMEI ABNotify

Version:
4, 0, 2, 0

MD5:
539869df24740de00374d9dcb525b9ad

SHA-1:
698ae05a09e3b0bd5d0b79d6d09163093869ea66

SHA-256:
1d235d4c234e747644dc0befebf0ae76fb4fcb6be35e15147e02f0a9624216fc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 4:37:01 PM UTC  (today)

File size:
87.9 KB (89,968 bytes)

Product version:
4, 0, 2, 0

Copyright:
Copyright (C) AOMEI Tech, 2009-2016.

Original file name:
ABNotify.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\aomei backupper\abnotify.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/29/2016 8:00:00 AM

Valid to:
6/30/2019 7:59:59 AM

Subject:
CN="CHENGDU AOMEI Tech Co., Ltd.", O="CHENGDU AOMEI Tech Co., Ltd.", L=ChengDu, S=SiChuan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
28736D0D296789512BAC66CCE86C4A00

File PE Metadata
Compilation timestamp:
3/7/2017 4:43:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x1C1E

Entry point:
E8, 5D, 04, 00, 00, E9, 36, FD, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 48, 41, 40, 00, 89, 0D, 44, 41, 40, 00, 89, 15, 40, 41, 40, 00, 89, 1D, 3C, 41, 40, 00, 89, 35, 38, 41, 40, 00, 89, 3D, 34, 41, 40, 00, 66, 8C, 15, 60, 41, 40, 00, 66, 8C, 0D, 54, 41, 40, 00, 66, 8C, 1D, 30, 41, 40, 00, 66, 8C, 05, 2C, 41, 40, 00, 66, 8C, 25, 28, 41, 40, 00, 66, 8C, 2D, 24, 41, 40, 00, 9C, 8F, 05, 58, 41, 40, 00, 8B, 45, 00, A3, 4C, 41, 40, 00, 8B, 45, 04, A3, 50, 41, 40, 00, 8D, 45, 08, A3, 5C, 41, 40, 00, 8B...
 
[+]

Entropy:
5.2051

Code size:
8 KB (8,192 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ABNotify

Command:
C:\Program Files\aomei backupper\abnotify.exe -auto


Scan ABNotify.exe - Powered by Reason Core Security