hjxtp1_ly.exe

TESTIT

广州微娱网络科技有限公司

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘hjxtp1_ly.exe’.
Publisher:
广州微娱网络科技有限公司  (signed and verified)

Product:
TESTIT

Version:
1.00

MD5:
727ecde0d0d82c791d129dd45b1ea90a

SHA-1:
9bd2f278ce31d318243a2d10aa01b59113695b25

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 8:15:05 PM UTC  (today)

File size:
161.4 KB (165,280 bytes)

Product version:
1.00

Original file name:
playIco.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\hjxtp1_ly.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/25/2013 8:00:00 AM

Valid to:
2/26/2015 7:59:59 AM

Subject:
CN=广州微娱网络科技有限公司, OU=研发部, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=广州微娱网络科技有限公司, L=guangzhou, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
59E4E1C94F2114A80E4D13AB5933681A

File PE Metadata
Compilation timestamp:
4/3/2013 4:50:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:AHYhWDBQYxMDoz5l/8UC8kAyRjdWJe3xalJeL3i7BiRJb+bx5PqJeEmJeNtz4eoM:GYhWDyq/D8Z8kAyVdriARJv7tsef

Entry address:
0x2A70

Entry point:
68, 1C, 5F, 40, 00, E8, EE, FF, FF, FF, 00, 00, 40, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, FC, 1C, 85, 06, 5A, 72, 51, 4B, 9E, F6, 00, 26, A1, F7, 5C, 85, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, 45, 53, 54, 49, 54, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 88, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 06, 00, 00, 00, EF, 51, 15, E3, 4A, 34, 01, 4B, A3, 2F, EB, CC, 88, DC, EE, E9, 01, 00, 00, 00, A0, 00, 00, 00, B0, 00, 00, 00, 01, 00, 00, 00...
 
[+]

Entropy:
5.9255

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
136 KB (139,264 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
hjxtp1_ly.exe

Command:
"C:\DOCUME~1\{user}\Locals~1\temp\hjxtp1_ly.exe" "C:\Program Files\hjxtp1_ly.exe"


Scan hjxtp1_ly.exe - Powered by Reason Core Security