mwreg_gdbc.exe

CGBebank CertReg

Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MWReg_gdbc(user)’.
Publisher:
CGB  (signed by Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.)

Product:
CGBebank CertReg

Description:
CertRegister

Version:
1, 0, 1, 29

MD5:
f3c796500d94400385d782dc89cdd036

SHA-1:
7f99cd848b68b3eba35944286b74d8f556e874f4

SHA-256:
fc288043f836fa341354bbf9eea0c6e4ecd800a465d4e8a507772ec8ab9208cf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:08:53 AM UTC  (today)

File size:
78.4 KB (80,288 bytes)

Product version:
1, 0, 1, 29

Copyright:
Copyright all (C) 2011-2013

Original file name:
CertReg.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cgbebank\mwreg_gdbc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/31/2012 8:00:00 AM

Valid to:
3/2/2014 7:59:59 AM

Subject:
CN="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", OU=Certification Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58C74BC5E723213EE607BE5B61B2B2CB

File PE Metadata
Compilation timestamp:
2/27/2014 7:43:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:iB2vilZccSWzoDPlsXwdTBCysCdqqftHyNJOGCuLjvu:pKlZcPPlqwDCysCdqqVyNJONuLjvu

Entry address:
0x6652

Entry point:
55, 8B, EC, 6A, FF, 68, E0, 76, 40, 00, 68, F8, 65, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 94, 72, 40, 00, 59, 83, 0D, 00, 9F, 40, 00, FF, 83, 0D, 04, 9F, 40, 00, FF, FF, 15, 98, 72, 40, 00, 8B, 0D, 6C, 9D, 40, 00, 89, 08, FF, 15, 9C, 72, 40, 00, 8B, 0D, 68, 9D, 40, 00, 89, 08, A1, A0, 72, 40, 00, 8B, 00, A3, FC, 9E, 40, 00, E8, D8, F3, FF, FF, 39, 1D, 40, 97, 40, 00, 75, 0C, 68, DA, 67, 40, 00, FF, 15, A4, 72...
 
[+]

Entropy:
5.6370

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
24 KB (24,576 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MWReg_gdbc(user)

Command:
C:\Program Files\cgbebank\mwreg_gdbc.exe


Scan mwreg_gdbc.exe - Powered by Reason Core Security