rkp.exe

RemoveKP

AD79 Corp

Publisher:
AD79 Corp  (signed and verified)

Product:
RemoveKP

Version:
1.00

MD5:
dc3437ab58a4c3b731a3e59a69453725

SHA-1:
2b4b70e69a3a88c881a1d04aa6d030466fa54704

SHA-256:
f7c95154592a4830c71823db7fba2a60b402029c77ed6bcd6c114faff49adf12

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:48:36 AM UTC  (today)

File size:
82.6 KB (84,536 bytes)

Product version:
1.00

Original file name:
rkp.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\keypang\rkp.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/22/2013 9:00:00 AM

Valid to:
9/22/2014 8:59:59 AM

Subject:
CN=AD79 Corp, O=AD79 Corp, L=Yeonsu-gu, S=Incheon, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3000AE01184DFF956E01F0B36AF80075

File PE Metadata
Compilation timestamp:
11/20/2013 12:43:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:Ilxco+CLBAONn4Qmg9y4sOdPkMBCCUodb:IbBpNFmg9ysdPbB1

Entry address:
0x1418

Entry point:
68, 14, 7F, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, B2, 3A, F6, AB, 8D, 6A, 18, 41, A0, 62, 69, C7, 9B, 66, 77, 87, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, FC, 00, 00, 00, 00, 3F, 52, 65, 6D, 6F, 76, 65, 4B, 50, 00, 00, FC, 00, 00, 00, 00, 3F, 00, 00, 00, 00, FF, CC, 31, 00, 00, E6, 03, 22, 43, 11, 88, 37, 4A, 92, C4, BC, 6A, 57, 16, B1, 46, 94, 38, 82, A8, AD, 2D, B6, 4C, 88, 92, 96, C7, 61, 80, A5, 17, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
5.1334

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
40 KB (40,960 bytes)

Scan rkp.exe - Powered by Reason Core Security