eMATE ON.exe

eMATE ON

Saerom Information Systems, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘eMATE ON’.
Publisher:
Saerom Information Systems, Inc.  (signed and verified)

Product:
eMATE ON

Version:
2, 6, 51, 2

MD5:
56b15620cf7afbff0aa2c84e92a16d26

SHA-1:
bf27fb52399a8ce86058019aca67a7a367932495

SHA-256:
1cbd1acd58fcb0e5cbb9151183f1de2da6e04188f07f3b3e31f0c9ea8cb10f24

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 10:50:25 PM UTC  (today)

File size:
2.7 MB (2,882,200 bytes)

Product version:
2, 6, 51, 2

Copyright:
(C) Saerom Information Systems, Inc.

Original file name:
eMATE ON.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\daesang\ds on\emate on.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/8/2014 9:00:00 AM

Valid to:
6/7/2016 8:59:59 AM

Subject:
CN="Saerom Information Systems, Inc.", O="Saerom Information Systems, Inc.", L=Geumcheon-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2CD309363E2129551BFE909C46938C79

File PE Metadata
Compilation timestamp:
4/9/2014 8:15:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1FA54A

Entry point:
55, 8B, EC, 6A, FF, 68, 60, 95, 64, 00, 68, 54, A7, 5F, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, E0, AF, 63, 00, 59, 83, 0D, A0, 94, 6C, 00, FF, 83, 0D, A4, 94, 6C, 00, FF, FF, 15, DC, AF, 63, 00, 8B, 0D, 84, 8F, 6C, 00, 89, 08, FF, 15, D8, AF, 63, 00, 8B, 0D, 80, 8F, 6C, 00, 89, 08, A1, D4, AF, 63, 00, 8B, 00, A3, 9C, 94, 6C, 00, E8, 2E, 76, FD, FF, 39, 1D, B0, AF, 6B, 00, 75, 0C, 68, 7E, A7, 5F, 00, FF, 15, D0, AF...
 
[+]

Entropy:
6.1615

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2.2 MB (2,330,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
eMATE ON

Command:
C:\Program Files\daesang\ds on\emate on.exe


Scan eMATE ON.exe - Powered by Reason Core Security