vshare.exe

vshare

Shanghai ShengRi Information Technology Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VShare’.
Publisher:

Product:
vshare

Version:
2, 0, 5, 1

MD5:
84bae38ee51e7575ce93b7d07fbd11e8

SHA-1:
90d446739e57e4353efab546ca91445ec3deddd8

SHA-256:
0d407f8a948d75ab7096aca93511534a116aedf505705aae01a0535f4689b860

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 7:05:36 AM UTC  (today)

File size:
2.7 MB (2,848,152 bytes)

Product version:
2, 0, 5, 1

Copyright:
Copyright (C) 2013

Original file name:
vshare.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\vshare\vshare.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/24/2014 9:00:00 AM

Valid to:
4/25/2016 8:59:59 AM

Subject:
CN="Shanghai ShengRi Information Technology Co., Ltd.", OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Shanghai ShengRi Information Technology Co., Ltd.", L=ShangHai, S=ShangHai, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
200E9EA959FEA92F543FA4361282BA8A

File PE Metadata
Compilation timestamp:
9/5/2014 2:46:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:WFhgz/p80YMyzaD7syWEKyqu4cHBYNcfO9Qvvh2LaqdQ+SD/z3J0eyXb:2U/cipfAQvvLqdQp/LJUXb

Entry address:
0x7462B0

Entry point:
60, BE, 00, 20, 8B, 00, 8D, BE, 00, F0, B4, FF, C7, 87, E4, F8, 66, 00, 42, 99, 49, 99, 57, EB, 11, 90, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9199  (probably packed)

Code size:
2.6 MB (2,707,456 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VShare

Command:
C:\Program Files\vshare\vshare.exe


Scan vshare.exe - Powered by Reason Core Security