AntiLogger.exe

Zemana AntiLogger

Zemana Information Technologies Industry Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AntiLogger’.
Publisher:
Zemana Ltd.  (signed by Zemana Information Technologies Industry Limited)

Product:
Zemana AntiLogger

Description:
Zemana AntiLogger User Interface

Version:
1.9.2.122

MD5:
e947094369e4799471f219dc0574241a

SHA-1:
ca3c254d48f946147ec0f6fe233a21e9a1fd4956

SHA-256:
d6b40a4600f45d536dda1fb80005c8d63220629b7dbad330a5f84ffa8733a98d

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/24/2024 5:27:10 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
PUA.Packed.ASPack
0.98/170.3

File size:
2.3 MB (2,393,456 bytes)

Product version:
1.9.2.0

Copyright:
© Zemana Ltd. All rights reserved.

Trademarks:
AntiLogger(tm) is a trademark of Zemana Ltd.

Original file name:
AntiLogger.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\antilogger\antilogger.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/28/2008 3:00:00 AM

Valid to:
12/4/2009 2:59:59 AM

Subject:
CN=Zemana Information Technologies Industry Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zemana Information Technologies Industry Limited, L=Istanbul, S=Uskudar, C=TR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AE026D2DAB457835BC5A9E9428B99F0

File PE Metadata
Compilation timestamp:
8/17/2009 12:43:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:v+dLuk7BqXnhDnZ99O3bQGTkalQ29UFJu/YwdNC6xi7:v+JJ7Bq39nZ99+RkpvZw7Cn7

Entry address:
0x1000

Entry point:
68, 01, B0, AE, 00, E8, 01, 00, 00, 00, C3, C3, 80, 90, 2D, 6F, 2F, 5A, 42, AB, 78, 1A, 08, 13, 44, 64, 21, B9, D4, 8B, 14, 23, CD, 18, F9, E3, 87, 76, FD, 89, 2B, D1, 8E, 20, 39, 02, 6A, AE, 46, 8B, 2D, 6C, D1, D0, 37, 52, 5F, 9D, 2B, AA, 76, 57, 76, AB, 75, 82, 36, 73, 1B, F3, C7, 72, 02, 06, B3, F3, 5B, 99, 16, E5, 9D, A7, 31, 02, 64, 97, FA, AB, 96, 1A, C3, 46, 08, 19, 1D, 9A, 58, F8, B6, A5, D2, 0C, 2C, A3, 64, B5, 4A, C6, 8F, 11, 7E, 89, 0B, 52, B4, E3, 48, 5A, 3B, 2F, 37, 50, D4, E9, AE, C4, 4D, ED...
 
[+]

Entropy:
7.9704

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.9 MB (2,031,616 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AntiLogger

Command:
"C:\Program Files\antilogger\antilogger.exe" \minimized


Scan AntiLogger.exe - Powered by Reason Core Security