installacoustics.exe

Client

Nanjing Wangya Computer Co.,Ltd.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘BIOSblinkClass’.
Publisher:
Microsoft  (signed by Nanjing Wangya Computer Co.,Ltd.)

Product:
Client

Version:
10.02.0023

MD5:
5a6aa04845e5d103366499df879fcad7

SHA-1:
46d24ad6126cff54c327ea29d0376ed4f68b6fe6

SHA-256:
ebb1470590c049f7c463fa038354c341d827cfa0b53298beab2448c202e60fa7

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/6/2024 8:45:13 AM UTC  (today)

Scan engine
Detection
Engine version

F-Secure
Trojan.Heur.3m1@sTL692pjy
5.15.154

File size:
894.8 KB (916,232 bytes)

Product version:
10.02.0023

Trademarks:
Client

Original file name:
WorkWinLm.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ibcjhkrlm\installacoustics.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/12/2016 8:00:00 AM

Valid to:
4/13/2018 7:59:59 AM

Subject:
CN="Nanjing Wangya Computer Co.,Ltd.", OU=Development Department, O="Nanjing Wangya Computer Co.,Ltd.", L=NanJing, S=JiangSu, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
345B52E008F607E9976DD14AE99E3C99

File PE Metadata
Compilation timestamp:
11/8/2016 11:20:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x9C84

Entry point:
68, B4, F2, 40, 00, E8, EE, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 91, 49, F4, E3, 00, C5, B0, 46, 87, E8, D4, 98, EE, 61, 82, 46, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 77, 6F, 72, 6B, 77, 69, 6E, 63, 00, 30, 34, 36, 7D, 23, 32, 2E, 00, 23, 30, 23, 2E, 2E, 5C, 2E, C0, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 07, 00, 00, 00, DD, 04, 92, 31, 35, 08, D1, 46, 93, 8E, B2, 5B, D4, C9, C6, 8F, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Entropy:
5.9724

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
868 KB (888,832 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BIOSblinkClass

Command:
C:\Program Files\ibcjhkrlm\installacoustics.exe


Scan installacoustics.exe - Powered by Reason Core Security