MSNLite20.exe

MSNLite

Hada Online (Beijing) Network Technology Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MSNLite’.
Publisher:
hada.im  (signed by Hada Online (Beijing) Network Technology Ltd.)

Product:
MSNLite

Version:
2.6.0.3618

MD5:
772fc832fbbe89b9635735b2bc73d9fa

SHA-1:
f41cd277333d5655e02a14385da4317519f09f99

SHA-256:
05cda7c18ec288c44f41f26d07ce781a1e01a57ab94bcd0fd5c57ef95ccdc464

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:37:00 AM UTC  (today)

File size:
12.4 MB (13,037,952 bytes)

Product version:
2.6.0.3618

Original file name:
MSNLite20.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/7/2011 8:00:00 AM

Valid to:
1/8/2012 7:59:59 AM

Subject:
CN=Hada Online (Beijing) Network Technology Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Hada Online (Beijing) Network Technology Ltd., L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3FB410A23B8919BF0FFD64DB03D1FA0E

File PE Metadata
Compilation timestamp:
11/9/2011 2:24:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
393216:iDJZA/hkXbFEm6i8yjMtx/ozpAporkTLnYgxpMS:iDJ6/c5Em6i8IM5O4HtpMS

Entry address:
0x6828D1

Entry point:
E8, E0, 3D, 01, 00, E9, 79, FE, FF, FF, 3B, 0D, A8, 69, F6, 00, 75, 02, F3, C3, E9, 62, 3E, 01, 00, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00, C7, 00, C4, 99, DB, 00, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 57, 8B, F9, C7, 07, C4, 99, DB, 00, 8B, 03, 85, C0, 74, 26, 50, E8, F6, D4, 00, 00, 8B, F0, 46, 56, E8, B2, 15, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 12, FF, 33, 56, 50, E8, 43, 10, 01, 00, 83, C4, 0C, EB, 04, 83, 67, 04, 00, C7, 47, 08, 01, 00, 00, 00, 8B, C7, 5F, 5E, 5B, 5D, C2, 04, 00, 8B, FF, 55...
 
[+]

Entropy:
6.3800

Code size:
8.8 MB (9,227,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MSNLite

Command:
C:\users\{user}\desktop\tina's file\msn\msnlite20.exe


Scan MSNLite20.exe - Powered by Reason Core Security