V3LTray.exe

V3 Lite

AhnLab, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AhnLab V3Lite Tray Process’.
Publisher:
AhnLab, Inc.  (signed and verified)

Product:
V3 Lite

Description:
Tray Application

Version:
1, 0, 1, 13

MD5:
d31d1b9317443dea55af7ec8f6a44e1b

SHA-1:
519f211b73b380afefc04fe80b6fa0af94028b53

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 12:31:21 AM UTC  (today)

File size:
530.6 KB (543,320 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C), AhnLab, Inc. 1988-2008, All rights reserved.

Original file name:
V3LTray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ahnlab\v3lite\v3ltray.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/29/2010 9:00:00 AM

Valid to:
10/30/2011 8:59:59 AM

Subject:
CN="AhnLab, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="AhnLab, Inc.", L=Yeongdeungpo, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5997DBAFDD3129299BE1A5EBCC6D1E33

File PE Metadata
Compilation timestamp:
11/4/2010 6:46:58 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x4DF2D

Entry point:
E8, D2, 09, 00, 00, E9, D8, FC, FF, FF, 8B, 00, 81, 38, 63, 73, 6D, E0, 74, 03, 33, C0, C3, E9, 51, 0A, 00, 00, 6A, 14, 68, B0, DB, 46, 00, E8, B7, 08, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, 05, 0A, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, AD, 08, 00, 00, C2, 10, 00, 6A, 0C, 68, D0, DB, 46...
 
[+]

Entropy:
6.2243

Code size:
332.5 KB (340,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AhnLab V3Lite Tray Process

Command:
"C:\Program Files\ahnlab\v3lite\v3ltray.exe" \logon


Scan V3LTray.exe - Powered by Reason Core Security