NetKeeper.exe

xinli NetKeeper

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetKeeper2.5’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd. )

Product:
xinli NetKeeper

Description:
DialTerminal MFC Application

Version:
1, 0, 7, 0

MD5:
3c7e5a2bcdd94b91e1b08936fbdd6ccf

SHA-1:
76bd979977d8729ae9b7a48cc8b3a1d0e6fc59a0

SHA-256:
a1829cca7c8fb4f2083d24112e5436a442b2a3d05293de27feb1dca50323e9fc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:46:02 PM UTC  (today)

File size:
2.5 MB (2,649,232 bytes)

Product version:
2, 5, 0, 0

Copyright:
Copyright @ 2005-2012

Original file name:
NetKeeper.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/6/2012 8:00:00 AM

Valid to:
3/17/2013 7:59:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd. ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd. ", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6B0EE2EA4D90C62A4EB22EF6F37FD805

File PE Metadata
Compilation timestamp:
11/15/2012 11:02:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:fGcCUh8DPctA7inMw5Pub7h5+QS1UlcQTta10C09SUJ5G+IWrx6vUu:ff3A7in3Pub7z+KlcUuxC57xQUu

Entry address:
0x334D9C

Entry point:
E9, D2, 91, 01, 00, BC, 99, 32, AF, 8E, 2B, 8A, C1, 18, 1B, 6E, 8D, 7C, 93, D2, 19, 34, 8F, BA, BD, A2, 7B, 5B, 9C, D3, 8F, 21, 34, 4B, 10, 6A, 81, C4, 66, 69, 33, 1C, 64, 48, 6F, AC, EA, D2, 87, C9, B2, 4E, D1, 3D, EC, 1F, C8, 37, EB, EC, D5, A1, 8F, 66, 6C, 12, 19, 17, 66, 43, 22, 6B, 55, 28, 36, 44, 31, E0, E7, 6D, 74, 7B, 6C, B5, 8E, BB, 1C, 39, 36, 0F, 38, 39, 22, 63, FC, 94, E6, 0E, 3B, 9D, 0C, F5, 0E, D6, 08, FE, E9, F4, AA, 0A, 00, 22, C2, 0D, AC, 8E, 2B, B7, 1A, F1, 38, 7B, 8A, 8D, D8, EF, 62, 59...
 
[+]

Entropy:
7.9051

Packer / compiler:
Xtreme-Protector v1.05

Code size:
1 MB (1,052,672 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetKeeper2.5

Command:
C:\chinanetsn\bin\netkeeper.exe


Scan NetKeeper.exe - Powered by Reason Core Security