Netkeeper.exe

SWU Client2.5

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SWU Client 2.5’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd.)

Product:
SWU Client2.5

Description:
DialTerminal Microsoft 基础类应用程序

Version:
1, 1, 7, 5

MD5:
7dbf2667d7878200d16300e43684da0f

SHA-1:
480ca1ae831f8700c68e97bc89e76abf5a3e15d1

SHA-256:
7db5c7c20819d63c0720951385e93710245f85ccef4fa682c9a5bbfee142d4f8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:00:47 PM UTC  (today)

File size:
3.5 MB (3,653,192 bytes)

Product version:
2, 5, 0, 0

Copyright:
版权所有 (C) 2005-2013

Original file name:
Netkeeper.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2013 8:00:00 AM

Valid to:
3/18/2014 7:59:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A2E339A4DDE0EA8DAA823A4BA7E3297

File PE Metadata
Compilation timestamp:
8/30/2013 8:48:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Ei7UVbcJ4P+C3Ty+v/aRFD7rsu7qkfg3JRtpVEPOFTX7:EuUxQAd3O1qJRhE2FTL

Entry address:
0x75AF29

Entry point:
E8, 41, 13, 00, 00, 35, C6, F7, A3, 5C, D7, F7, 4E, 95, 8F, 5E, C5, F6, C7, E5, E0, 23, 1F, 3E, 1F, 05, 2E, 42, 7D, 3A, 08, 4A, CB, E3, 98, 69, E0, 74, 27, C5, 27, 3C, 60, 47, CF, 2C, C1, 9B, 8A, 71, 1B, 92, 79, 0A, 72, 37, FA, 81, 16, 27, 3B, 7D, 6C, 68, 1B, E1, A5, 1A, 1A, 56, 74, 79, FF, D1, 83, A5, 9F, F8, 98, 55, BB, 61, 6F, 95, D1, 8D, 98, C7, 5C, 4C, 3E, 34, 1F, 6A, 17, 31, 68, C9, 21, 0D, 2C, 1A, D7, DC, C4, C2, CF, D5, F2, FF, D4, A3, AB, 60, 32, 20, 10, ED, CB, 3D, 34, 79, 00, 5E, 8F, A8, D2, 06...
 
[+]

Entropy:
7.8677  (probably packed)

Code size:
1 MB (1,060,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SWU Client 2.5

Command:
C:\swuclient\bin\netkeeper.exe


Scan Netkeeper.exe - Powered by Reason Core Security