yinyuetai.exe

音悦mini2.0内测版

Yinyuechangxiang Network Technology (Beijing) Co Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘yinyuetai’.
Publisher:
www.yinyuetai.com  (signed by Yinyuechangxiang Network Technology (Beijing) Co Ltd)

Product:
音悦mini2.0内测版

Description:
yinyuetai

Version:
1.0.0.1

MD5:
03691500ae43b3569fd329e67a4ec949

SHA-1:
7244d2f171dcd5e6a371fa2fefc1ebda7f877005

SHA-256:
dffe29c6d4169f1e63812f18a27d492471132112875fa8536844ff10da8808de

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 3:46:09 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win32/IRCBot.worm.Gen
2014.06.02

File size:
2.8 MB (2,953,160 bytes)

Product version:
1.0.0.1

Copyright:
www.yinyuetai.com. All rights reserved.

Original file name:
yinyuetai.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\yinyuetai\yinyuetai.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/7/2013 8:00:00 AM

Valid to:
8/7/2014 7:59:59 AM

Subject:
CN=Yinyuechangxiang Network Technology (Beijing) Co Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Yinyuechangxiang Network Technology (Beijing) Co Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64DFE485373381D402C46A678FC0F13B

File PE Metadata
Compilation timestamp:
4/29/2014 5:20:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:7nhLdGSuwTdE/xEDqyiohseoIOWKsPUOfOA/dl3P4ftWuYaBvbxLdxTL7ABbFsVq:rpzTkxEeyioieoiKsPdfHFJktWjAvbxq

Entry address:
0x187E11

Entry point:
E8, 85, E5, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 20, 73, 64, 00, 75, 02, F3, C3, E9, EE, 6F, 00, 00, 51, C7, 01, 84, F4, 60, 00, E8, 06, ED, 00, 00, 59, C3, 55, 8B, EC, 8D, 41, 09, 50, 8B, 45, 08, 83, C0, 09, 50, E8, 65, EC, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 55, 8B, EC, 56, 8B, F1, E8, C9, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 52, B5, ED, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, FF, 75, 18, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 05, 00, 00, 00, 83, C4, 18...
 
[+]

Entropy:
6.5919

Code size:
1.9 MB (1,944,064 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
yinyuetai

Command:
C:\Program Files\yinyuetai\yinyuetai.exe yyt_hide


Scan yinyuetai.exe - Powered by Reason Core Security