NetKeeper.exe

xinli NetKeeper

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘NetKeeper2.5’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd.)

Product:
xinli NetKeeper

Description:
DialTerminal MFC Application

Version:
1, 1, 7, 3

MD5:
3a386bcb760a3e21d4310b292a162df6

SHA-1:
9d69ccaafd4990d74fba5f557bd06e7791c1b5f9

SHA-256:
603de7ae2ebfc2a04998e49c4515f4887e46d34766f1f7339fccbd83958316de

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:21:31 AM UTC  (today)

File size:
3.6 MB (3,735,112 bytes)

Product version:
2, 5, 0, 0

Copyright:
Copyright @ 2005-2013

Original file name:
NetKeeper.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2013 5:30:00 AM

Valid to:
3/18/2014 5:29:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A2E339A4DDE0EA8DAA823A4BA7E3297

File PE Metadata
Compilation timestamp:
3/12/2013 7:16:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:4f6Y+H2qQnryV2nauKURIRVnO0zvHXZR5svEnhv2W:4f6RHoyduFSRVnVDXL5svEnheW

Entry address:
0x43A05B

Entry point:
9C, C7, 04, 24, 7C, 49, 1B, 13, 9C, 66, 89, 3C, 24, 68, 70, 14, A4, E8, C7, 44, 24, 04, 68, 72, 95, DD, 55, 68, 54, AC, 94, EE, 8D, 64, 24, 0C, E9, 35, DD, 34, 00, 01, C7, C0, EF, 07, 60, 9C, 8B, 5A, 20, 66, 0F, AB, D1, 66, D1, D9, C0, E5, 04, 80, E1, B1, 01, C3, 66, 0F, C9, 68, 21, 76, 54, B4, D2, F1, C7, 45, F8, 00, 00, 00, 00, 59, 8D, 8B, 46, A6, F5, 43, 66, 0F, BD, CB, 8D, 0C, 7D, 53, 3E, 48, 6E, 8B, 4A, 18, F8, E8, 37, E3, FD, FF, 02, AA, 6E, 83, F5, AB, 4A, F8, E3, 85, F9, E0, DF, F6, 20, 4B, C3, 3D...
 
[+]

Entropy:
7.8774  (probably packed)

Code size:
1 MB (1,060,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
NetKeeper2.5

Command:
C:\chinanetsn\bin\netkeeper.exe


Scan NetKeeper.exe - Powered by Reason Core Security