Netkeeper.exe

SWU Client2.5

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SWUClient2.5’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd.)

Product:
SWU Client2.5

Description:
DialTerminal Microsoft 基础类应用程序

Version:
1, 1, 7, 5

MD5:
76a6b61a7d4e33f9b4b86bb6da7c29e5

SHA-1:
de42b88500c86b814fa14574db3ded1947f192f9

SHA-256:
4dd59b7dd74164645570ca21c133c4b9fd2322c1104f42ee0a8dbdc9362fd068

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:47:54 PM UTC  (today)

File size:
3.8 MB (3,980,872 bytes)

Product version:
2, 5, 0, 0

Copyright:
版权所有 (C) 2005-2013

Original file name:
Netkeeper.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\swuclient\bin\netkeeper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2013 8:00:00 AM

Valid to:
3/18/2014 7:59:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd.", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A2E339A4DDE0EA8DAA823A4BA7E3297

File PE Metadata
Compilation timestamp:
6/8/2013 6:16:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:fCNHFh6njlzopWdaLxuB2sFF4U8RbYpJchy2nEiGLUiPeePmIhxZrvLyOF7:fCNlwnBIW8ALprpJ9oiP1t+0

Entry address:
0x43E808

Entry point:
E9, 6E, A9, 3B, 00, 94, EE, C6, FB, B9, 82, 88, 3D, BD, 44, 94, E7, CF, C9, E3, EB, FD, F1, FB, C5, DB, CD, E0, F2, 1C, AB, 09, 3A, A0, 70, 27, 86, DD, 86, 9E, 7D, 22, 42, 8C, D8, 31, D3, 94, D4, AC, 40, BC, 8B, 8F, 95, 9B, CA, 4F, A7, 81, 7D, 7B, FE, 05, E2, 7B, CB, EA, E7, FF, 0F, 83, 57, 88, 6F, 14, 31, 9B, C8, 59, DE, 6D, 15, 4B, AF, D8, 81, 55, AC, D2, C7, E2, 8A, DD, 0B, E3, 9A, 22, BE, 0D, 3F, 0D, 45, 51, 65, 31, FD, 0A, 54, 52, 5B, D9, 8A, B5, AD, 69, C8, D4, 07, 45, 2A, 4B, 62, 54, 42, 7A, 7A, 48...
 
[+]

Entropy:
7.8789

Packer / compiler:
Xtreme-Protector v1.05

Code size:
1 MB (1,064,960 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SWUClient2.5

Command:
C:\Program Files\swuclient\bin\netkeeper.exe


Scan Netkeeper.exe - Powered by Reason Core Security