jfcachemgr.exe

PIPI Cache Mgr

Zhejiang HaoYing Network Co.,Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘jfproc’.
Publisher:
皮皮科技  (signed by Zhejiang HaoYing Network Co.,Ltd)

Product:
PIPI Cache Mgr

Version:
2, 6, 0, 1

MD5:
dd954fa69bd91dc347463c0cc1b9e40c

SHA-1:
d2689a8a0d795314f97015239fd826df684b3e6f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:55:34 PM UTC  (today)

File size:
1.9 MB (1,945,456 bytes)

Product version:
2, 6, 0, 1

Copyright:
(C) <皮皮科技>。保留所有权利。

Original file name:
JiaFilmCacheMgr.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (PRC)

Common path:
C:\Program Files\pipi\jfcachemgr.exe

Digital Signature
Authority:
WoSign, Inc.

Valid from:
6/23/2009 5:00:00 PM

Valid to:
6/23/2012 4:59:59 PM

Subject:
CN="Zhejiang HaoYing Network Co.,Ltd", OU=WoSign Class 3 Code Signing, O="Zhejiang HaoYing Network Co.,Ltd", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=WoSign Code Signing Authority, O="WoSign, Inc.", C=US

Serial number:
00E6F22D853E2E9E1820B0F42B2E3AB9A6

File PE Metadata
Compilation timestamp:
12/14/2009 11:25:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
24576:Rgy8Nzq4YD8aWXmJffVumSRpwoY6BRXCeTB:Glg4YDSvrXhTB

Entry address:
0x98FE1

Entry point:
6A, 74, 68, B0, 25, 4B, 00, E8, FB, 01, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, A0, 20, 4A, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 4C, 2B, 4A, 00, 59, 83, 0D, AC, 0B, 4C, 00, FF, 83...
 
[+]

Entropy:
4.2635

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
644 KB (659,456 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
jfproc

Command:
C:\Program Files\pipi\jfcachemgr.exe


Scan jfcachemgr.exe - Powered by Reason Core Security