BarClientTask.exe

BarClientTask.exe

Hangzhou Shunwang Information Technology Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BarClientTask’.
Publisher:
Sunward Information Technology Co.Ltd  (signed by Hangzhou Shunwang Information Technology Co., Ltd)

Product:
BarClientTask.exe

Version:
2010, 4, 1, 1

MD5:
8ceb3be2c3affa0001f0c044a70bdb6c

SHA-1:
8b05817631a534f62ed7fc50c60e22f3c1beda2a

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 7:21:47 PM UTC  (today)

Scan engine
Detection
Engine version

Norman
Malware.MQZY
11.20150716

File size:
390.1 KB (399,440 bytes)

Product version:
7, 1, 0, 0

Copyright:
Sunward Information Technology Co.Ltd

Original file name:
BarClientTask.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (PRC)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/26/2009 1:34:08 PM

Valid to:
6/27/2011 1:34:04 PM

Subject:
CN="Hangzhou Shunwang Information Technology Co., Ltd", OU="Hangzhou Shunwang Information Technology Co., Ltd", O="Hangzhou Shunwang Information Technology Co., Ltd", C=CN

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001221B4097E0

File PE Metadata
Compilation timestamp:
4/1/2010 12:14:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:nhQLcxQtCACRtIDlhSGR4RXtSPtfEq06pTpl+qiZY+museNjepN:nhQLcCtC9oDXSSMAPtfZNpTL+3seNj

Entry address:
0x2EBB7

Entry point:
6A, 60, 68, 68, EA, 44, 00, E8, D9, 0A, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 51, F1, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 58, 93, 44, 00, 8B, 4E, 10, 89, 0D, 1C, D5, 45, 00, 8B, 46, 04, A3, 28, D5, 45, 00, 8B, 56, 08, 89, 15, 2C, D5, 45, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 20, D5, 45, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 20, D5, 45, 00, C1, E0, 08, 03, C2, A3, 24, D5, 45, 00, 33, F6, 56, 8B, 3D, 04, 92, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.3708

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
288 KB (294,912 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BarClientTask

Command:
C:\nbmsclient\barclienttask.exe -startup


Scan BarClientTask.exe - Powered by Reason Core Security