lyi_my.exe

Beijing Caiyunshidai Technology Co., Ltd.

The application lyi_my.exe by Beijing Caiyunshidai Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:

MD5:
40b64dc5c5ba91853af0d1f624dfb357

SHA-1:
e994475aa6e4e5d0496152de8f29366181e74eb8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/15/2024 7:55:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.ELEX.SpeedSearch (M)
17.2.6.4

File size:
445.5 KB (456,192 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\lyi_my.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/22/2017 7:00:00 AM

Valid to:
3/4/2017 6:59:59 AM

Subject:
CN="Beijing Caiyunshidai Technology Co., Ltd.", O="Beijing Caiyunshidai Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
4B2CFE3405FD947CD3D15B0D4DACA81E

File PE Metadata
Compilation timestamp:
8/31/2001 4:04:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x7752C

Entry point:
8D, 09, 8B, F6, 83, 3C, 24, FF, 0F, 84, FA, FF, FF, FF, 8D, 64, 24, D0, 8D, 12, 8B, ED, 60, 8D, 7C, DB, FF, FC, 8D, 64, 24, 24, E8, 34, 02, 00, 00, 8D, 7C, 24, FC, 11, EA, 86, F6, 41, 87, 1F, 4A, 4B, 0F, B7, CB, E2, FE, 90, 66, 8B, D9, FF, 73, 3C, F7, D7, 59, F6, D4, F7, D6, F7, D7, 86, D6, 81, E9, FE, FF, FF, 7F, 73, E0, F6, D6, B0, 8E, 81, D9, 91, 11, 00, 00, 71, D4, 4E, F7, D6, 40, 80, C4, ED, 8B, 8C, 19, 90, 11, 00, 80, 81, F1, 50, 45, 00, 00, 75, BE, F6, D0, F5, 90, 8D, 0A, 68, E8, D1, 1A, 11, E8, 05...
 
[+]

Entropy:
7.8271  (probably packed)

Code size:
370.5 KB (379,392 bytes)

Remove lyi_my.exe - Powered by Reason Core Security