haikeyuser_20227.exe

USBKey Tool(Haitai)

Beijing HaitaiFangyuan High Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HaiKeyUser_20227’.
Publisher:
HaiTaiFangYuan Inc  (signed by Beijing HaitaiFangyuan High Technology Co., Ltd.)

Product:
USBKey Tool(Haitai)

Version:
4, 0, 2012, 12191

MD5:
5b5494028b4ccaed74e9b7a9bf80c670

SHA-1:
cd8a2f5e1505ab707215da95717d6e9f5d66b883

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 3:03:52 AM UTC  (today)

File size:
772 KB (790,552 bytes)

Product version:
4, 0, 2012, 12191

Copyright:
Haitai

Original file name:
USBKey Tool

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gecsp20227\gecsp20227\haikeyuser_20227.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/15/2010 8:00:00 AM

Valid to:
11/22/2013 7:59:59 AM

Subject:
CN="Beijing HaitaiFangyuan High Technology Co., Ltd.", OU=Techsupport Dept, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing HaitaiFangyuan High Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7E683C04981E3C137CAFF24C7487EC27

File PE Metadata
Compilation timestamp:
12/19/2012 3:49:38 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x6317D

Entry point:
E8, 49, 9F, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 5C, B4, 49, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 5C, B4, 49, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.4305

Code size:
484 KB (495,616 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HaiKeyUser_20227

Command:
C:\Program Files\gecsp20227\gecsp20227\haikeyuser_20227.exe


Scan haikeyuser_20227.exe - Powered by Reason Core Security