NetApps.exe

NetApps Module

Legendsoft China (Beijing) Technology Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘netapps tray’.
Publisher:

Product:
NetApps Module

Version:
0, 0, 0, 22

MD5:
d8f2ca3a3742f23dcaed9b8579139834

SHA-1:
d0f51d7094d270ef9878b39d95da138f1dd59457

SHA-256:
b8021d65ec157777646aa464e904bd1d56fab0ff0c15f29ad79bd1ca0f527e0c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 2:50:56 AM UTC  (today)

File size:
187.5 KB (192,048 bytes)

Product version:
0, 0, 0, 1

Copyright:
Copyright (C) 2013 Legendsoft China (Beijing) Technology Limited

Original file name:
NetApps.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\netapps\netapps.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/25/2013 8:00:00 AM

Valid to:
9/26/2014 7:59:59 AM

Subject:
CN=Legendsoft China (Beijing) Technology Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Legendsoft China (Beijing) Technology Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AE510F67F419D78BD0C061A7C5C8220

File PE Metadata
Compilation timestamp:
4/15/2014 12:15:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:mbz5nXUXr8NouoPpfarU08LF6HJfigiETO3svnQLwPWGVG59Ifl2gYHYGn4:mbz96qouWig0BHJqGCRRgYHYJ

Entry address:
0x1934A

Entry point:
6A, 60, 68, 98, 41, 42, 00, E8, 76, 03, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 3E, F1, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 6C, 21, 42, 00, 8B, 4E, 10, 89, 0D, FC, 85, 42, 00, 8B, 46, 04, A3, 08, 86, 42, 00, 8B, 56, 08, 89, 15, 0C, 86, 42, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 00, 86, 42, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 00, 86, 42, 00, C1, E0, 08, 03, C2, A3, 04, 86, 42, 00, 33, F6, 56, 8B, 3D, F4, 21, 42, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.4707

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
132 KB (135,168 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
netapps tray

Command:
"C:\Program Files\netapps\netapps.exe" -tray


Scan NetApps.exe - Powered by Reason Core Security