nllij.exe

Xgtray

gy

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RavTimeXP’.
Publisher:
gy

Product:
Xgtray

Version:
1.00

MD5:
978c58a1c40c2cd86c59cb6b2daf5db1

SHA-1:
0962ae5d6fe9dce123a35cc6bc6334781f7c32e9

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 6:36:59 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Worm/Wukill.E
2013.0.4756

Clam AntiVirus
Win.Worm.Rays-1
0.98/23207

File size:
136 KB (139,264 bytes)

Product version:
1.00

Original file name:
wukill.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (PRC)

Common path:
C:\windows\help\nllij.exe

File PE Metadata
Compilation timestamp:
7/6/2003 7:37:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x113C

Entry point:
0F, AF, D7, 8D, 2D, FF, 5D, 51, 0E, 80, C9, 7D, F2, 8B, EA, F2, F7, C7, CA, E6, C2, 7B, 3C, BA, 68, 5F, 0E, 47, 00, 55, 75, 0B, 69, E9, F5, 92, 88, 94, F6, C7, 80, 3B, FF, E8, 68, 00, 00, 00, F2, 8A, F7, 0F, BE, E9, 8D, 05, 9A, 7E, BD, AE, FE, CE, F2, 81, C7, 97, 08, F9, FF, 45, 81, C7, 46, BD, 07, 00, 83, E1, 00, BA, C3, EF, 24, 64, 11, CD, B6, F7, B6, AF, B7, FB, 8A, F1, 80, E8, B7, B3, 68, 81, C1, DA, F3, FF, FF, 86, D7, F2, 18, C8, 81, C1, 27, 0C, 00, 00, 8A, D1, 23, EB, 71, 06, FF, CD, 84, C3, 2B, D7...
 
[+]

Entropy:
6.2822

Code size:
32 KB (32,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RavTimeXP

Command:
C:\windows\help\nllij.exe


Scan nllij.exe - Powered by Reason Core Security