Loader.exe

Loader

shanghai xin hao yi software Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘loader’.
Publisher:
HintSoft  (signed by shanghai xin hao yi software Co., Ltd)

Product:
Loader

Description:
Loader

Version:
2, 0, 1, 42

MD5:
6b375c5bfa96297406762cb61c9d4bb3

SHA-1:
6e9b0aae07ac2faa40c67ddf46c5759bc173d509

SHA-256:
53d923a27f9fed8fcd80178b8a5fe49d0ac3c9c1fae846b4f8217d23b22d602e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:59:35 AM UTC  (today)

File size:
322.4 KB (330,176 bytes)

Product version:
2, 0, 0, 0

Copyright:
Copyright HintSoft 2009

Original file name:
Loader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hintsoft\gamemenu\bin\loader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/8/2011 9:00:00 AM

Valid to:
9/6/2013 8:59:59 AM

Subject:
CN="shanghai xin hao yi software Co., Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="shanghai xin hao yi software Co., Ltd", L=上海, S=上海, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6878C7D395192F067C7FD08152C8824B

File PE Metadata
Compilation timestamp:
5/30/2013 3:57:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2DF71

Entry point:
55, 8B, EC, 6A, FF, 68, 38, 0A, 44, 00, 68, AC, C2, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 78, E2, 43, 00, 33, D2, 8A, D4, 89, 15, F8, EB, 44, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, F4, EB, 44, 00, C1, E1, 08, 03, CA, 89, 0D, F0, EB, 44, 00, C1, E8, 10, A3, EC, EB, 44, 00, 6A, 01, E8, 3E, 37, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 0B, 33, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.3881

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
244 KB (249,856 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
loader

Command:
C:\Program Files\hintsoft\gamemenu\bin\loader.exe


Scan Loader.exe - Powered by Reason Core Security