DGClient.exe

DGClient

HANGZHOU HUATU SOFTWARE CO., LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘UserInit’.
Publisher:
Huatusoft  (signed by HANGZHOU HUATU SOFTWARE CO., LTD)

Product:
DGClient

Version:
4.5.4.2002

MD5:
a95cdef85f350959dfca0cadc79bf58b

SHA-1:
44689b5e0b098122bd05526014fbf02afbb5af40

SHA-256:
0e23c52f29a4e8506cc7d58b7952db5a3561dfabaaa574af2c784437e8a2b089

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 2:02:59 AM UTC  (today)

File size:
2.2 MB (2,310,008 bytes)

Product version:
4.5.4.2002

Original file name:
DGClient.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\dg\dgclient.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/29/2012 8:00:00 AM

Valid to:
12/30/2014 7:59:59 AM

Subject:
CN="HANGZHOU HUATU SOFTWARE CO., LTD", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="HANGZHOU HUATU SOFTWARE CO., LTD", L=hangzhou, S=zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
10371154B28FF40CC6B488DE06262E7D

File PE Metadata
Compilation timestamp:
6/25/2013 3:20:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x142269

Entry point:
E8, 72, 9F, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 40, 3F, 5F, 00, 75, 02, F3, C3, E9, F4, 9F, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 00, 4C, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D7, 25, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, C4, 73, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 33, 4E, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.3771

Code size:
1.6 MB (1,651,200 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
UserInit

Command:
C:\Program Files\dg\dgclient.exe


Scan DGClient.exe - Powered by Reason Core Security