NetApps.exe

NetApps Module

Legendsoft China (Beijing) Technology Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘netapps tray’.
Publisher:

Product:
NetApps Module

Version:
0, 0, 0, 22

MD5:
6d6b6e7ee01d0d0b1376520f60544b24

SHA-1:
338305c0b512037a850a070fb96e9485ec5f5ce8

SHA-256:
331e276b2321d9569244512babc4040cabdb51bb2f71e3e4e1a3c2d7acb76117

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 8:18:37 AM UTC  (today)

File size:
187.5 KB (192,048 bytes)

Product version:
0, 0, 0, 1

Copyright:
Copyright (C) 2013 Legendsoft China (Beijing) Technology Limited

Original file name:
NetApps.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\netapps\netapps.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/25/2013 8:00:00 AM

Valid to:
9/26/2014 7:59:59 AM

Subject:
CN=Legendsoft China (Beijing) Technology Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Legendsoft China (Beijing) Technology Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AE510F67F419D78BD0C061A7C5C8220

File PE Metadata
Compilation timestamp:
4/15/2014 12:15:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x1934A

Entry point:
6A, 60, 68, 98, 41, 42, 00, E8, 76, 03, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 3E, F1, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 6C, 21, 42, 00, 8B, 4E, 10, 89, 0D, FC, 85, 42, 00, 8B, 46, 04, A3, 08, 86, 42, 00, 8B, 56, 08, 89, 15, 0C, 86, 42, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 00, 86, 42, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 00, 86, 42, 00, C1, E0, 08, 03, C2, A3, 04, 86, 42, 00, 33, F6, 56, 8B, 3D, F4, 21, 42, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.4708

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
132 KB (135,168 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
netapps tray

Command:
"C:\Program Files\netapps\netapps.exe" -tray


Scan NetApps.exe - Powered by Reason Core Security