awc.exe

Advanced SystemCare 3

四川联翔印务有限公司

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Advanced SystemCare 3’.
Publisher:
IObit  (signed by 四川联翔印务有限公司)

Product:
Advanced SystemCare 3

Version:
2.9.26.571

MD5:
4cf12ecf9b9d459bbf8fd7c001a2d774

SHA-1:
c459cf5a973118b22b065d73ba60a4651a02331e

SHA-256:
d38c4d317d4d4bec21aa01f9911cf2b93d0bf19aac91444604189f9693c8bd71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 7:12:44 PM UTC  (today)

File size:
2.1 MB (2,229,824 bytes)

Product version:
3.0.0.0

Copyright:
Copyright(C) 2005-2008

Trademarks:
IObit.com

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\iobit\advanced systemcare 3\awc.exe

Digital Signature
Authority:
WoSign, Inc.

Valid from:
6/19/2008 1:00:00 AM

Valid to:
6/20/2009 12:59:59 AM

Subject:
CN=IObit.com, OU=Class 3 - for Microsoft Authenticode Signing, O=四川联翔印务有限公司, L=成都市, S=四川省, C=CN

Issuer:
CN=WoSign Code Signing Authority, O="WoSign, Inc.", C=US

Serial number:
5EE356C4F2709BD1E1C2E368DBEF57AE

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:WNaze9no7dAb5tTMxTT8TtC/tRGC9GA4CrVZQD5:WiEo7KXE11R99RhTQD5

Entry address:
0x10F420

Entry point:
55, 8B, EC, 83, C4, EC, 53, 33, C0, 89, 45, EC, B8, 98, EB, 50, 00, E8, 9E, 21, EF, FF, 8B, 1D, 64, 2A, 52, 00, 33, C0, 55, 68, 60, F5, 50, 00, 64, FF, 30, 64, 89, 20, E8, 4D, F6, FF, FF, 8B, 03, E8, 8E, 5C, EF, FF, 8B, 03, BA, 78, F5, 50, 00, E8, 62, 5C, EF, FF, 8B, 0D, D8, C8, 51, 00, 8B, 03, 8B, 15, AC, D8, 4E, 00, E8, 77, 5C, EF, FF, 8B, 0D, 18, CB, 51, 00, 8B, 03, 8B, 15, 28, 59, 4E, 00, E8, 64, 5C, EF, FF, 8B, 0D, D0, C9, 51, 00, 8B, 03, 8B, 15, 18, D0, 4D, 00, E8, 51, 5C, EF, FF, 8B, 0D, AC, CB, 51...
 
[+]

Entropy:
6.7934

Developed / compiled with:
Microsoft Visual C++

Code size:
1.1 MB (1,107,456 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Advanced SystemCare 3

Command:
"C:\Program Files\iobit\advanced systemcare 3\awc.exe" \startup


Scan awc.exe - Powered by Reason Core Security