mwregicbc.exe

sss FakeBackStage

Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MWREGICBC.exe’.
Publisher:
sss  (signed by Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.)

Product:
sss FakeBackStage

Description:
FakeBackStage

Version:
2, 2, 0, 0

MD5:
4b418d30d4eab845884a6895629a9650

SHA-1:
95b18d664299f88147867902aa886c67271bc57d

SHA-256:
943d4aa65ffbf4995d97fdb8e78179a3406076d65e8b58c1ae7bd8943bffc75f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:04:13 AM UTC  (today)

File size:
38.5 KB (39,376 bytes)

Product version:
2, 2, 0, 0

Copyright:
Copyright ? 2013

Original file name:
FakeBackStage.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\icbcebanktools\mingwah\mwregicbc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/31/2012 8:00:00 AM

Valid to:
3/2/2014 7:59:59 AM

Subject:
CN="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", OU=Certification Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shenzhen Mingwah Aohan Digital Security Technology Co.,Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58C74BC5E723213EE607BE5B61B2B2CB

File PE Metadata
Compilation timestamp:
7/21/2013 11:29:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:x7WTdtS4kwC3LSHK0cmlMb7/cHCypMLGlnp4sMs9nYPLG1eMMvQS:RUdtuwu2HKZf/NHinmsF96QS

Entry address:
0x1041

Entry point:
55, 8B, EC, 6A, FF, 68, A8, 50, 40, 00, 68, 94, 24, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 10, 53, 56, 57, 89, 65, E8, FF, 15, 04, 50, 40, 00, 33, D2, 8A, D4, 89, 15, 00, 69, 40, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, FC, 68, 40, 00, C1, E1, 08, 03, CA, 89, 0D, F8, 68, 40, 00, C1, E8, 10, A3, F4, 68, 40, 00, 6A, 00, E8, C0, 12, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, 9A, 00, 00, 00, 59, 83, 65, FC, 00, E8, FF, 10, 00, 00, FF, 15, 00, 50, 40, 00, A3, 04, 7E, 40, 00, E8...
 
[+]

Entropy:
5.1852

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
16 KB (16,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MWREGICBC.exe

Command:
"C:\Program Files\icbcebanktools\mingwah\mwregicbc.exe"


The file mwregicbc.exe has been discovered within the following programs.

About 4% of users remove it
 
Powered by Should I Remove It?

Scan mwregicbc.exe - Powered by Reason Core Security