neo42UserPart.exe

neo42UserPart

neo42 GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘neo42UserPart’.
Publisher:
neo42 GmbH  (signed and verified)

Product:
neo42UserPart

Description:
Executes the userparts of neo42 VBS Packages

Version:
2.0.2.1

MD5:
bd5c8d02e07411e7d420e19211009cbe

SHA-1:
1104abf60e33e3946715d1c06bbb79cd910f053d

SHA-256:
d4ef49897fe6073d0d9cf7164298e9d1f62aafab1839f0f996d4f2fbc36bfa1d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
6/26/2025 10:11:35 AM UTC  (today)

File size:
487.3 KB (499,032 bytes)

Product version:
2.0.2.1

Copyright:
neo42 GmbH

Original file name:
neo42UserPart.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\ccmcache\2j\neoinstall\neo42userpart.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
11/17/2015 1:00:00 AM

Valid to:
11/14/2017 12:59:59 AM

Subject:
CN=neo42 GmbH, O=neo42 GmbH, L=Wiehl, S=Nordrhein-Westfalen, C=DE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
68450D6977FFBCA8D6F5EAB34F336350

File PE Metadata
Compilation timestamp:
5/23/2016 12:50:04 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:/sB2HGuTtjOPthJ2ttJKBDwnwAFSfYuSRPO8oDjklXRdZvOYHg:/sB2muTtj2J2tLKBDxL8o0lXRjzHg

Entry address:
0x139F6

Entry point:
E8, 60, 04, 00, 00, E9, 80, FE, FF, FF, 55, 8B, EC, FF, 75, 08, E8, FE, F6, FF, FF, 59, 5D, C3, 55, 8B, EC, F6, 45, 08, 01, 56, 8B, F1, C7, 06, 8C, E6, 42, 00, 74, 0A, 6A, 0C, 56, E8, D8, FF, FF, FF, 59, 59, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 00, F5, FF, FF, C7, 06, 94, E6, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 9C, E6, 42, 00, C7, 01, 94, E6, 42, 00, C3, 55, 8B, EC, 83, EC, 0C, 8D, 4D, F4, E8, B5, F4, FF, FF, 68, F4, 4A, 44...
 
[+]

Entropy:
6.2303

Code size:
176.5 KB (180,736 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
neo42UserPart

Command:
"C:\Program Files\common files\neo42\setup\neo42userpart.exe" \guiC:all


Scan neo42UserPart.exe - Powered by Reason Core Security