BeTwinMessages.exe

BeTwin and WinConnect Server

ThinSoft Pte Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BeTwinMessages’.
Publisher:
ThinSoft Pte Ltd  (signed and verified)

Product:
BeTwin and WinConnect Server

Description:
BeTwin Messages Application

Version:
2.00.557

MD5:
dd69b30cd43428ca70cced89f3d1f05b

SHA-1:
14b97a12ac38ba2d4ba0a65e61cc911910c9cdca

SHA-256:
297964af03f5ce26caa12dcbcbcce7ab0dea0ec2a2d7ff6afea2093e4a36f854

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:27:52 AM UTC  (today)

File size:
118.6 KB (121,496 bytes)

Product version:
2.00.557

Copyright:
Copyright (C) 2001-2010 ThinSoft Pte Ltd

Original file name:
BeTwinMessages.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\betwin\betwinmessages.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/18/2009 12:00:00 AM

Valid to:
3/18/2011 11:59:59 PM

Subject:
CN=ThinSoft Pte Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ThinSoft Pte Ltd, L=Singapore, S=Singapore, C=SG

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7FF32E0848575D0931FF6E35F715EDBE

File PE Metadata
Compilation timestamp:
10/7/2010 3:53:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:FKmg2QIAP/923RWChBnpnxeVyyzTpc7+NvgdQTSEpszrbgEp7mkbrGOHrTKJgsAT:V/QI4SkVyyW84SS8Ebg8asrGOHrWJgl

Entry address:
0xCFF6

Entry point:
6A, 70, 68, B8, 1E, 41, 00, E8, 16, 03, 00, 00, 33, FF, 57, FF, 15, 28, F1, 40, 00, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 02, 5B, 53, FF, 15, 4C, F5, 40, 00, 59, 83, 0D, D0, 01, 46, 00, FF, 83, 0D, D4, 01...
 
[+]

Entropy:
5.6729

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
56 KB (57,344 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BeTwinMessages

Command:
"C:\Program Files\betwin\betwinmessages.exe"


Scan BeTwinMessages.exe - Powered by Reason Core Security