ravmond.exe

Rising AntiVirus 2012

Beijing Rising Information Technology Corporation Limited

It runs as a windows Service named “RFW Service”.
Publisher:
Beijing Rising Information Technology Co., Ltd.  (signed by Beijing Rising Information Technology Corporation Limited)

Product:
Rising AntiVirus 2012

Description:
ravmond

Version:
25, 0, 0, 1

MD5:
231daf91f7acbe363e192d996603f713

SHA-1:
9c3221947dcbf696ece1a8a54c8d0be94ef9fc6e

SHA-256:
9308fd960d6784ff67a068cbe222b2dfc3c78c6c539a732b2cc42725c414b88b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:14:04 PM UTC  (today)

File size:
270.9 KB (277,424 bytes)

Product version:
25.00

Copyright:
Copyright(C) 2012-2013 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.

Original file name:
ravmond.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese

Common path:
C:\Program Files\rising\rfw\ravmond.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/10/2012 9:00:00 PM

Valid to:
8/10/2015 8:59:59 PM

Subject:
CN=Beijing Rising Information Technology Corporation Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing Rising Information Technology Corporation Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
410026B7AE29963B608D61911B771E16

File PE Metadata
Compilation timestamp:
11/13/2013 5:58:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:90rv/H+OS6UR8U/rL0LYBASDWe5hrVHl6x8QTv/MOETIMQeYCC2BOsSRygBGO58e:9auDTR8Sv0LYBFWSBHlmr/MOETs3cLe

Entry address:
0x10EF0

Entry point:
8B, FF, 55, 8B, EC, E8, 86, EF, 00, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, 80, 75, 43, 00, 68, 50, 39, 41, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 94, 53, 56, 57, A1, 88, 91, 43, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, 6C, D1, 42, 00, C7, 45, FC, FE, FF, FF, FF, EB, 26, B8, 01, 00, 00, 00, C3, 8B, 65, E8, C7...
 
[+]

Code size:
176 KB (180,224 bytes)

Service
Display name:
RFW Service

Service name:
RsRFWMon

Type:
Win32OwnProcess, InteractiveProcess

Group:
COM Infrastructure

Depends on:
RpcSs


Scan ravmond.exe - Powered by Reason Core Security