mwreg_gdbc.exe

CGBebank CertReg

Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MWReg_gdbc(user)’.
Publisher:
CGB  (signed by Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.)

Product:
CGBebank CertReg

Description:
CertRegister

Version:
1, 0, 1, 27

MD5:
9866f1523b518ad9960dc9492c811d5e

SHA-1:
6a1adeb9df75f957da84faed2d243eae71a6c40e

SHA-256:
f787835e173c4306fc5cf4d92843acb3adde0703d9c7948e3e71ceb57bed8987

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 1:12:57 AM UTC  (today)

File size:
82.4 KB (84,384 bytes)

Product version:
1, 0, 1, 27

Copyright:
Copyright all (C) 2011-2013

Original file name:
CertReg.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cgbebank\mwreg_gdbc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/31/2012 8:00:00 AM

Valid to:
3/2/2014 7:59:59 AM

Subject:
CN="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", OU=Certification Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58C74BC5E723213EE607BE5B61B2B2CB

File PE Metadata
Compilation timestamp:
4/23/2013 10:20:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:rvAeqrWKTs9xmWIPumxrrJtvgPsPNJOGCuLjh/C:rYrPTqQumx/JNgMNJONuLjh/C

Entry address:
0x6710

Entry point:
6A, 70, 68, 30, 77, 40, 00, E8, E4, 01, 00, 00, 33, DB, 89, 5D, FC, 8D, 45, 80, 50, FF, 15, B8, 70, 40, 00, 83, CF, FF, 89, 7D, FC, 66, 81, 3D, 00, 00, 40, 00, 4D, 5A, 75, 27, A1, 3C, 00, 40, 00, 8D, 80, 00, 00, 40, 00, 81, 38, 50, 45, 00, 00, 75, 14, 0F, B7, 48, 18, 81, F9, 0B, 01, 00, 00, 74, 20, 81, F9, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B8, 84, 00, 00, 00, 0E, 76, F2, 33, C9, 39, 98, F8, 00, 00, 00, EB, 0E, 83, 78, 74, 0E, 76, E2, 33, C9, 39, 98, E8, 00, 00, 00, 0F, 95, C1, 89, 4D, E4, C7...
 
[+]

Entropy:
5.4581

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MWReg_gdbc(user)

Command:
C:\Program Files\cgbebank\mwreg_gdbc.exe


Scan mwreg_gdbc.exe - Powered by Reason Core Security