startrun.exe

方格子网娱平台

Shanghai wangheng culture spread Co., LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘StartRun’.
Publisher:
上海网恒文化传播有限公司  (signed by Shanghai wangheng culture spread Co., LTD)

Product:
方格子网娱平台

Description:
开机启动管理 2013.05.12

Version:
4.0.0.6

MD5:
0e88ff6e4982b5aff28eb8c4927b4a0f

SHA-1:
b73bf66eaff555b949ba5e3aa1cb713a6f4cfeb2

SHA-256:
b749fdb93faecbf8e3b95feb5f69418b834c4f7188aa7ced61933ae470ed3142

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 11:06:23 AM UTC  (today)

File size:
151.6 KB (155,200 bytes)

Product version:
4.0

Copyright:
2007-2011 ShanghaiNetho Corporation. All rights reserved.

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/17/2012 8:00:00 AM

Valid to:
7/17/2013 7:59:59 AM

Subject:
CN="Shanghai wangheng culture spread Co., LTD", OU=Provided by TrustAsia, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shanghai wangheng culture spread Co., LTD", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2ADBF235FF56EA48DF15EA23DC2655E9

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:duql5bvK1WOSoyh9eU8W1pLeTsSgeoDRAW9c9CUPjO57dagXa6WXyBzwuv9:jl574SfOfgtuW9c9/LidaIHwi9

Entry address:
0x1DFE0

Entry point:
55, 8B, EC, B9, 1A, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, D8, DE, 41, 00, E8, D0, 7C, FE, FF, BB, 68, 09, 42, 00, BF, 84, 0D, 42, 00, 33, C0, 55, 68, CD, EA, 41, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E4, 33, C0, E8, 3E, 49, FE, FF, 8B, 45, E4, 8D, 55, E8, E8, 6F, 9B, FE, FF, 8B, 45, E8, 8D, 55, EC, E8, BC, 90, FE, FF, 8B, 55, EC, B8, 70, 0B, 42, 00, E8, BF, 9D, FE, FF, 68, 70, 0B, 42, 00, E8, F5, 7F, FE, FF, E8, AC, 48, FE, FF, 85, C0, 7E, 2C, 8D, 55, E0, B8, 01, 00, 00, 00, E8, FB, 48, FE...
 
[+]

Entropy:
6.5568

Developed / compiled with:
Microsoft Visual C++

Code size:
119.5 KB (122,368 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StartRun

Command:
C:\nmenu\startrun.exe sysstart


Scan startrun.exe - Powered by Reason Core Security