mwreg_gdbc.exe

CGBebank CertReg

Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MWReg_gdbc(user)’.
Publisher:
CGB  (signed by Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.)

Product:
CGBebank CertReg

Description:
CertRegister(2011-5-13-10-31)

Version:
1, 0, 1, 9

MD5:
622ef457a6b6379f4e8af4e6afe2410a

SHA-1:
9d32cc3b4c37a3d719b3566a3bd9cf35a75bb55e

SHA-256:
892d5eaa93f6e6971a99a53de73f9b2bf0b0f6459aa12cd2504f5cf28aaf98e9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 7:11:22 AM UTC  (today)

File size:
68.5 KB (70,144 bytes)

Product version:
1, 0, 1, 9

Copyright:
Copyright all (C) 2011

Original file name:
CertReg.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cgbebank4.0\mwreg_gdbc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/29/2010 8:00:00 AM

Valid to:
11/29/2011 7:59:59 AM

Subject:
CN="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", L=shenzhen, S=guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
48101CC00E245F5758C9A03FC1202842

File PE Metadata
Compilation timestamp:
5/13/2011 10:31:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:lYUFAo7AaxAujsLPk1xWKexuha5fRAk+jghCuruAjm8DdoLW7bCvV:j8bujwc1xWKL88jOCu6p8xoa3CvV

Entry address:
0x17001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 70, 01, 00, 83, BD, 22, 04, 00, 00, 00, 89, 9D, 22, 04, 00, 00, 0F, 85, 65, 03, 00, 00, 8D, 85, 2E, 04, 00, 00, 50, FF, 95, 4D, 0F, 00, 00, 89, 85, 26, 04, 00, 00, 8B, F8, 8D, 5D, 5E, 53, 50, FF, 95, 49, 0F, 00, 00, 89, 85, 4D, 05, 00, 00, 8D, 5D, 6B, 53, 57, FF, 95, 49, 0F, 00, 00, 89, 85, 51, 05, 00, 00, 8D, 45, 77, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72...
 
[+]

Entropy:
6.1040

Packer / compiler:
ASPack v2.12

Code size:
20 KB (20,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MWReg_gdbc(user)

Command:
C:\Program Files\cgbebank4.0\mwreg_gdbc.exe


Scan mwreg_gdbc.exe - Powered by Reason Core Security