js_kwm_16_2640.exe

Beijing Tuo Lang Technology Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Statiskwmus’.
Publisher:
Timecount  (signed by Beijing Tuo Lang Technology Co., Ltd)

Product:
Timecount

Description:
时间统计

Version:
1.2.7.3

MD5:
f31cf55a8eac94cb9a359597003e3f70

SHA-1:
55765967e5780113dac37df9403df2ca2447bfc6

SHA-256:
81d3e1f554a350f274ce9407ecf7e49ebca8c41e4822caf0940197fb1968cd84

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:03:18 AM UTC  (today)

File size:
263.1 KB (269,416 bytes)

Product version:
1.2.7.3

Copyright:
Timecount

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kuwo\js_kwm_16_2640.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/26/2012 8:00:00 AM

Valid to:
9/25/2014 7:59:59 AM

Subject:
CN="Beijing Tuo Lang Technology Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing Tuo Lang Technology Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
32D2EA5448D5823DACFDD58DCAD631A8

File PE Metadata
Compilation timestamp:
7/3/2012 10:50:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0xC0001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 00, 0C, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Entropy:
7.9366

Packer / compiler:
ASPack v2.12

Code size:
420 KB (430,080 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Statiskwmus

Command:
C:\Program Files\kuwo\js_kwm_16_2640.exe


Scan js_kwm_16_2640.exe - Powered by Reason Core Security