netkeeper.exe

E信网络组件2.5

Xi'an Xinli Software Technology Co.,Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ECP’.
Publisher:
XI AN XINLI SOFTWARE TECHNOLOGY CO.,LTD  (signed by Xi'an Xinli Software Technology Co.,Ltd. )

Product:
E信网络组件2.5

Description:
DialTerminal Microsoft 基础类应用程序

Version:
0, 1, 6, 7

MD5:
5d345134962e7fa73d105fd115c948f5

SHA-1:
f380cada8d73be3ffcbc107a9331ac8be17166fe

SHA-256:
1f0751f32e23b0d9e4381032deebf7f0b879ce9273e54edac9de012417a33486

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 3:44:19 PM UTC  (today)

File size:
2.5 MB (2,658,704 bytes)

Product version:
2, 5, 0, 0

Copyright:
版权所有 (C) 2009

Original file name:
DialTerminal.EXE

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/4/2011 8:00:00 AM

Valid to:
3/17/2012 7:59:59 AM

Subject:
CN="Xi'an Xinli Software Technology Co.,Ltd. ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Xi'an Xinli Software Technology Co.,Ltd. ", L=Xi'an, S=Shaanxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
49D2AA20840A53F8B303348A7CB06B64

File PE Metadata
Compilation timestamp:
6/2/2011 5:01:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:fH+6GXhi/n71oB1TRvJ7kQmnA7t2AFnHGp/Vamc/cfYjl/nabzUZ3zn:fH+jI/7SkJAZDnKV8/cfYR/abz+

Entry address:
0x4ED3AF

Entry point:
E8, D1, 3D, 0A, 00, 68, CB, A5, 40, 72, 00, B6, 38, 57, 14, 20, BD, 42, E1, 9D, 10, DC, 73, 4C, 9E, C0, CD, C8, 46, A9, 8D, 42, 0F, 3E, 79, 86, BA, 67, 28, 4D, 5D, 8E, 2D, 6B, EA, 56, B9, F4, 93, 17, 9C, 40, 98, A9, 62, DA, 1B, EE, 03, EA, BA, 7E, 2F, DC, 35, D6, B9, 86, 99, A4, 64, 68, 74, 9F, 77, 1B, C7, C2, B3, EE, 6A, 87, 66, AB, 8E, 00, BC, 73, EF, B1, 4E, 33, 4E, 72, 3D, 40, 5F, 9D, D7, 83, F9, 51, AB, D6, 1A, B9, 15, CE, 1E, 2F, F8, C5, 15, 58, FB, B3, 4F, 21, 9D, 13, 0E, 00, 3C, DD, 6B, 8E, 7D, 65...
 
[+]

Entropy:
7.8727  (probably packed)

Code size:
1 MB (1,085,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ECP

Command:
C:\exin\netkeeper\bin\netkeeper.exe


Scan netkeeper.exe - Powered by Reason Core Security