ASCVER.exe is part of Advanced SystemCare and developed by IObit according to the ASCVER.exe version information.
ASCVER.exe's description is "ASCVER"
ASCVER.exe is digitally signed by IObit Information Technology.
ASCVER.exe is usually located in the 'c:\Program Files (x86)\IObit\Advanced SystemCare\' folder.
Some of the anti-virus scanners at VirusTotal detected ASCVER.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on ASCVER.exe:
Property | Value |
---|---|
Product name | Advanced SystemCare |
Company name | IObit |
File description | ASCVER |
Original filename | ASCVER.exe |
Legal copyright | © IObit. All rights reserved. |
Legal trademark | IObit |
Product version | 12.0 |
File version | 12.0.0.4 |
Here's a screenshot of the file properties when displayed by Windows Explorer:
Product name | Advanced SystemCare |
Company name | IObit |
File description | ASCVER |
Original filename | ASCVER.exe |
Legal copyright | © IObit. All rights reserved. |
Legal trademark | IObit |
Product version | 12.0 |
File version | 12.0.0.4 |
ASCVER.exe has a valid digital signature.
Property | Value |
---|---|
Signer name | IObit Information Technology |
Certificate issuer name | Symantec Class 3 SHA256 Code Signing CA |
Certificate serial number | 5cd0502920c27eeaec2a184d0452e53a |
2 of the 65 anti-virus programs at VirusTotal detected the ASCVER.exe file. That's a 3% detection rate.
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{ "directory_created": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\", "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept" ], "dll_loaded": [ "dwmapi.dll", "ntmarta.dll", "FaultRep.dll", "kernel32.dll", "imm32.dll" ], "file_opened": [ "", "\\Device\\NamedPipe\\", "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.bin", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders", "HKEY_LOCAL_MACHINE\\Software\\CodeGear\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP", "HKEY_CURRENT_USER\\Software\\CodeGear\\Locales", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes", "HKEY_CURRENT_USER\\Software\\Borland\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Keyboard Layouts\\04090409", "HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Keyboard Layouts\\041D0409" ], "file_written": [ "" ], "file_deleted": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept", "C:\\Users\\cuck\\AppData\\Local\\Temp" ], "directory_removed": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\" ], "file_exists": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\" ], "mutex": [ "madExceptSettingsMtx$99c", "_IObit_ASCVER_" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\MS Shell Dlg 2", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity" ], "directory_enumerated": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\*.*" ] }
[ { "process_path": "C:\\Windows\\System32\\lsass.exe", "process_name": "lsass.exe", "pid": 476, "summary": {}, "first_seen": 1607277190.421875, "ppid": 376 }, { "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.bin", "process_name": "e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.bin", "pid": 2460, "summary": { "directory_created": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\", "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept" ], "dll_loaded": [ "dwmapi.dll", "ntmarta.dll", "FaultRep.dll", "kernel32.dll", "imm32.dll" ], "file_opened": [ "", "\\Device\\NamedPipe\\", "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.bin", "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls" ], "regkey_opened": [ "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders", "HKEY_LOCAL_MACHINE\\Software\\CodeGear\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP", "HKEY_CURRENT_USER\\Software\\CodeGear\\Locales", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes", "HKEY_CURRENT_USER\\Software\\Borland\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Keyboard Layouts\\04090409", "HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales", "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Keyboard Layouts\\041D0409" ], "file_written": [ "" ], "file_deleted": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept", "C:\\Users\\cuck\\AppData\\Local\\Temp" ], "directory_removed": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\" ], "file_exists": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\" ], "mutex": [ "madExceptSettingsMtx$99c", "_IObit_ASCVER_" ], "regkey_read": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\MS Shell Dlg 2", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity" ], "directory_enumerated": [ "C:\\Users\\cuck\\AppData\\Local\\Temp\\e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0.madExcept\\*.*" ] }, "first_seen": 1607277190.6875, "ppid": 2740 } ]
[ { "markcount": 1, "families": [], "description": "At least one process apparently crashed during execution", "severity": 1, "marks": [ { "call": { "category": "system", "status": 1, "stacktrace": [], "api": "LdrLoadDll", "return_value": 0, "arguments": { "basename": "FaultRep", "module_address": "0x74f40000", "flags": 0, "module_name": "FaultRep.dll", "stack_pivoted": 0 }, "time": 1607277190.7805, "tid": 2888, "flags": {} }, "pid": 2460, "type": "call", "cid": 15 } ], "references": [], "name": "exec_crash" }, { "markcount": 1, "families": [], "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)", "severity": 1, "marks": [ { "category": "section", "ioc": ".itext", "type": "ioc", "description": null } ], "references": [], "name": "pe_features" }, { "markcount": 1, "families": [], "description": "The file contains an unknown PE resource name possibly indicative of a packer", "severity": 1, "marks": [ { "category": "resource name", "ioc": "MAD", "type": "ioc", "description": null } ], "references": [], "name": "pe_unknown_resource_name" }, { "markcount": 86, "families": [], "description": "Allocates read-write-execute memory (usually to unpack itself)", "severity": 2, "marks": [ { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00400000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 78 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 105 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x004e1000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 107 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x004e1000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 109 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00476000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 111 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00491000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 113 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 115 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 117 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 119 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 121 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00404000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 123 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00404000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 125 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 127 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 129 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 131 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00404000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 133 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00476000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 135 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00476000" }, "time": 1607277190.7965, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 137 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00607000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 166 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00608000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 168 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x74ea0000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 170 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x74f11000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 172 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x74f41000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 174 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75091000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 176 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75751000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 178 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75a01000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 180 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75cc1000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 182 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75e01000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 184 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x75f11000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 186 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x76031000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 188 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x76101000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 190 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x763a0000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 192 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x764a1000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 194 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x76531000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 196 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x76610000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 198 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x766c1000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 200 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x77311000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 202 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x77351000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 204 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x77571000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 206 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x775d1000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 208 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x766c2000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 211 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x77571000" }, "time": 1607277190.8125, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 213 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtAllocateVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "region_size": 4096, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "protection": 64, "process_handle": "0xffffffff", "allocation_type": 4096, "base_address": "0x00790000" }, "time": 1607277190.8275, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE", "allocation_type": "MEM_COMMIT" } }, "pid": 2460, "type": "call", "cid": 353 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtAllocateVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "region_size": 589824, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "protection": 64, "process_handle": "0xffffffff", "allocation_type": 8192, "base_address": "0x04580000" }, "time": 1607277190.8275, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE", "allocation_type": "MEM_RESERVE" } }, "pid": 2460, "type": "call", "cid": 455 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtAllocateVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "region_size": 4096, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 1, "protection": 64, "process_handle": "0xffffffff", "allocation_type": 4096, "base_address": "0x045d0000" }, "time": 1607277190.8275, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE", "allocation_type": "MEM_COMMIT" } }, "pid": 2460, "type": "call", "cid": 457 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00405000" }, "time": 1607277190.8435, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 569 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x004e1000" }, "time": 1607277190.8435, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 571 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x004e1000" }, "time": 1607277190.8435, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 573 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00476000" }, "time": 1607277190.8435, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 575 }, { "call": { "category": "process", "status": 1, "stacktrace": [], "api": "NtProtectVirtualMemory", "return_value": 0, "arguments": { "process_identifier": 2460, "stack_dep_bypass": 0, "stack_pivoted": 0, "heap_dep_bypass": 0, "length": 4096, "protection": 64, "process_handle": "0xffffffff", "base_address": "0x00491000" }, "time": 1607277190.8435, "tid": 2888, "flags": { "protection": "PAGE_EXECUTE_READWRITE" } }, "pid": 2460, "type": "call", "cid": 577 } ], "references": [], "name": "allocates_rwx" }, { "markcount": 11, "families": [], "description": "Foreign language identified in PE resource", "severity": 2, "marks": [ { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_ICON", "language": "LANG_CHINESE", "offset": "0x00260ec8", "filetype": "GLS_BINARY_LSB_FIRST", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000469" }, { "name": "RT_GROUP_ICON", "language": "LANG_CHINESE", "offset": "0x00294dcc", "filetype": "MS Windows icon resource - 8 icons, 256x256", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000076" }, { "name": "RT_MANIFEST", "language": "LANG_CHINESE", "offset": "0x002958f4", "filetype": "XML 1.0 document, ASCII text, with CRLF line terminators", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000352" }, { "name": "RT_MANIFEST", "language": "LANG_CHINESE", "offset": "0x002958f4", "filetype": "XML 1.0 document, ASCII text, with CRLF line terminators", "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED", "type": "generic", "size": "0x00000352" } ], "references": [], "name": "origin_langid" }, { "markcount": 1, "families": [], "description": "The binary likely contains encrypted or compressed data indicative of a packer", "severity": 2, "marks": [ { "entropy": 7.177627354519489, "section": { "size_of_data": "0x0006ce00", "virtual_address": "0x00229000", "entropy": 7.177627354519489, "name": ".rsrc", "virtual_size": "0x0006cc48" }, "type": "generic", "description": "A section with a high entropy has been found" } ], "references": [ "http:\/\/www.forensickb.com\/2013\/03\/file-entropy-explained.html", "http:\/\/virii.es\/U\/Using%20Entropy%20Analysis%20to%20Find%20Encrypted%20and%20Packed%20Malware.pdf" ], "name": "packer_entropy" } ]
The Yara rules did not detect anything in the file.
{ "tls": [], "udp": [ { "src": "192.168.56.101", "dst": "192.168.56.255", "offset": 546, "time": 3.0786728858947754, "dport": 137, "sport": 137 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2018, "time": 3.036417007446289, "dport": 5355, "sport": 51001 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2346, "time": 1.0207889080047607, "dport": 5355, "sport": 53595 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 2674, "time": 3.0502049922943115, "dport": 5355, "sport": 53848 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 3002, "time": 1.6416471004486084, "dport": 5355, "sport": 54255 }, { "src": "192.168.56.101", "dst": "224.0.0.252", "offset": 3330, "time": -0.09005594253540039, "dport": 5355, "sport": 55314 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 3658, "time": 1.5797529220581055, "dport": 1900, "sport": 1900 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 6986, "time": 1.053760051727295, "dport": 3702, "sport": 49152 }, { "src": "192.168.56.101", "dst": "239.255.255.250", "offset": 11178, "time": 3.0941250324249268, "dport": 1900, "sport": 53598 } ], "dns_servers": [], "http": [], "icmp": [], "smtp": [], "tcp": [], "smtp_ex": [], "mitm": [], "hosts": [], "pcap_sha256": "1a38e7b94d72c9b0c3c0c0c5f26c5bbc53720d92554f11dcb24709c049982fbf", "dns": [], "http_ex": [], "domains": [], "dead_hosts": [], "sorted_pcap_sha256": "2c06e84b8e3413d8880526e1eec038bd193e11251bb804cb1744b79bb2ba6dab", "irc": [], "https_ex": [] }
The instructions below shows how to remove ASCVER.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the ASCVER.exe file for removal, restart your computer and scan it again to verify that ASCVER.exe has been successfully removed. Here are the removal instructions in more detail:
Property | Value |
---|---|
MD5 | d93d736bc4519373ad8468f00309c5a8 |
SHA256 | e4abef8d0ba2949e08c00cecf045545e7b32bda3829a0efaa654778aff606af0 |
These are some of the error messages that can appear related to ascver.exe:
ascver.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
ascver.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
ASCVER has stopped working.
End Program - ascver.exe. This program is not responding.
ascver.exe is not a valid Win32 application.
ascver.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with ASCVER.exe:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.