haikeyuser_20988.exe

USBKey Tool(Haitai)

Beijing HaitaiFangyuan High Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HaiKeyUser_20988’.
Publisher:
HaiTaiFangYuan Inc  (signed by Beijing HaitaiFangyuan High Technology Co., Ltd.)

Product:
USBKey Tool(Haitai)

Description:
nns application

Version:
4, 1, 2014, 9031

MD5:
3d24a675fab0132965cbd8c3b9d1ef9b

SHA-1:
90451c98e9129e756ccafc409bd185376a0205ac

SHA-256:
11275ae5b812eb5d3f7dc76c25ff55e3e12e3cefd965560e4c8ca1349309a11b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 12:24:22 PM UTC  (today)

File size:
850.4 KB (870,792 bytes)

Product version:
4, 1, 2014, 9031

Copyright:
Haitai

Original file name:
USBKey Tool

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gecsp20988\gecsp20988\haikeyuser_20988.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/24/2013 8:00:00 AM

Valid to:
12/23/2016 7:59:59 AM

Subject:
CN="Beijing HaitaiFangyuan High Technology Co., Ltd.", OU=Basic Products Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing HaitaiFangyuan High Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
715E3C3A9F04ABB47B114FFBB1B11043

File PE Metadata
Compilation timestamp:
9/3/2014 5:20:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x71945

Entry point:
E8, D5, A3, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 5C, 25, 4B, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 5C, 25, 4B, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.4787

Code size:
551 KB (564,224 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HaiKeyUser_20988

Command:
C:\Program Files\gecsp20988\gecsp20988\haikeyuser_20988.exe


Scan haikeyuser_20988.exe - Powered by Reason Core Security