certreg.exe

CertTest 应用程序

CFCA Operation CA2

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘CertReg’.
Publisher:
CFCA Operation CA2  (signed and verified)

Product:
CertTest 应用程序

Description:
CertTest Microsoft 基础类应用程序

Version:
1, 0, 0, 1

MD5:
777e78d68944c9b5abf262c66a8b0814

SHA-1:
8539eed214e9357e91b8ba89b4d6da6af8edce31

SHA-256:
43a0e4fd159984dc8831f102300d27604b66670d1b6175fd4c8a2269147e09ed

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/1/2024 1:27:24 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.W.Agent.lvzf
2.1.4+

File size:
98.7 KB (101,104 bytes)

Product version:
1, 0, 0, 1

Copyright:
版权所有 (C) 2008

Original file name:
CertTest.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\sdzf ukey tools\sdzf\certreg.exe

Digital Signature
Authority:
CFCA Operation CA2

Valid from:
5/6/2011 8:00:14 PM

Valid to:
5/6/2016 8:00:14 PM

Subject:
CN=96668e0000587941, OU=Customers, OU=YUZHI, O=CFCA Operation CA2, C=CN

Issuer:
O=CFCA Operation CA2, C=CN

Serial number:
7D43B0B870E2807376108CE7AE6A0A7E

File PE Metadata
Compilation timestamp:
11/23/2010 10:26:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:J2ZCQyrae3T2rI+agS/qTyB3Ckwn+zEquOffiA4ZICBi65uSMB90TIHV0A6vtD:J2Myej2UqT8++zLukfCBxuSMb1l6vtD

Entry address:
0x337F

Entry point:
55, 8B, EC, 6A, FF, 68, 58, 46, 40, 00, 68, 06, 35, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 3C, 42, 40, 00, 59, 83, 0D, 24, 28, 44, 00, FF, 83, 0D, 28, 28, 44, 00, FF, FF, 15, 38, 42, 40, 00, 8B, 0D, 18, 28, 44, 00, 89, 08, FF, 15, 34, 42, 40, 00, 8B, 0D, 14, 28, 44, 00, 89, 08, A1, 30, 42, 40, 00, 8B, 00, A3, 20, 28, 44, 00, E8, 17, 01, 00, 00, 39, 1D, 10, 66, 40, 00, 75, 0C, 68, 02, 35, 40, 00, FF, 15, 2C, 42...
 
[+]

Entropy:
3.8542

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CertReg

Command:
C:\Program Files\sdzf ukey tools\sdzf\certreg.exe


Scan certreg.exe - Powered by Reason Core Security