BarClientTask.exe

BarClientTask.exe

Hangzhou Shunwang Information Technology Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BarClientTask’.
Publisher:
Sunward Information Technology Co.Ltd  (signed by Hangzhou Shunwang Information Technology Co., Ltd)

Product:
BarClientTask.exe

Version:
2010, 12, 14, 1

MD5:
b77d40d0f239334960e3a02507b8e742

SHA-1:
01772b7ffa5070c7c6052c78bc9f9ee38acc4d1a

SHA-256:
2ac42952257e9eb4371ec70381bea3255f3fd44a1078f581b5e53f1e18cfc4e6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:49:54 AM UTC  (today)

File size:
1.2 MB (1,297,488 bytes)

Product version:
7, 1, 6, 0

Copyright:
Sunward Information Technology Co.Ltd

Original file name:
BarClientTask.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/26/2009 1:34:08 PM

Valid to:
6/27/2011 1:34:04 PM

Subject:
CN="Hangzhou Shunwang Information Technology Co., Ltd", OU="Hangzhou Shunwang Information Technology Co., Ltd", O="Hangzhou Shunwang Information Technology Co., Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001221B4097E0

File PE Metadata
Compilation timestamp:
12/14/2010 1:58:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:RRR0l5830PEtKY5sHlYUxUrf+YZPC56ncXKQTPTnpTyFwcMCKesuFnmKhma1/:G830PQKYy+jIPXXPTnpTyRuesuH8a1

Entry address:
0xCE37C

Entry point:
E8, 1D, C5, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, 59, 53, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, 59, 53, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.2524

Code size:
959 KB (982,016 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BarClientTask

Command:
C:\nbmsclient\barclienttask.exe -startup


Scan BarClientTask.exe - Powered by Reason Core Security