DS3_Tool.exe

DS3_Tool

Shenzhen Saikeware Technology Co., Ltd.

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DS3 Tool’. The file has been seen being downloaded from download1998.mediafire.com and multiple other hosts.
Publisher:
www.motioninjoy.com  (signed by Shenzhen Saikeware Technology Co., Ltd.)

Product:
DS3_Tool

Version:
0.6.0.3

MD5:
a911d0d323079d22833da43d3d0bf803

SHA-1:
a2e13aadb6925a59cd9bc4374ea6ea5d38535201

SHA-256:
a84c9c358816fc6777bdac37a886e839913a334690b61afb7071f6f5a7565d57

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 4:20:43 AM UTC  (today)

File size:
107.8 KB (110,352 bytes)

Product version:
0.6.0.3

Copyright:
Copyright © Motioninjoy 2009

Trademarks:
MotioninJoy

Original file name:
DS3_Tool.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\motioninjoy\ds3\ds3_tool.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/20/2010 2:00:00 AM

Valid to:
10/21/2011 1:59:59 AM

Subject:
CN="Shenzhen Saikeware Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Saikeware Technology Co., Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4ED2A52E7516F9F5C8A78FB0951C2BFE

File PE Metadata
Compilation timestamp:
1/1/2011 3:57:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:dBYuxYuW4yuFW5sZEs/hLFuZaH2D2U11U4H91LjwpC+ajkV7yIIJIIvXIdz2ygN6:dBPYuW4yuFW5oEs/hLIcAgFpCDkvz2A

Entry address:
0x194DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
93.5 KB (95,744 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DS3 Tool

Command:
C:\Program Files\motioninjoy\ds3\ds3_tool.exe -mini


The file DS3_Tool.exe has been seen being distributed by the following 11 URLs.

http://download1998.mediafire.com/n17dy0nn67og/.../DS3_Tool.exe

http://download1998.mediafire.com/080bdjswb6yg/.../DS3_Tool.exe

http://download1998.mediafire.com/5r735hy1p8tg/.../DS3_Tool.exe

http://download1095.mediafire.com/qdg8h75442ng/.../DS3_Tool.exe

http://199.91.152.207/2nlovss78s6g/.../DS3_Tool.exe

Scan DS3_Tool.exe - Powered by Reason Core Security