6y6s3y6u3u.exe

Open Source Developer

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘6Y6S3Y6u3u.exe’.
Publisher:
Realteck Device  (signed by Open Source Developer)

Product:
Realteck Device

Version:
5.4.6.4301

MD5:
02320360a53952cbc2af6977bc9a659e

SHA-1:
f78aff3eb11e3a305f48593515de1a4a0adb9454

SHA-256:
0203db1aab6b62c8ed41097742f575a9e1b6628bbd6d5f3ec9d2a088f14debeb

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 12:43:47 AM UTC  (today)

File size:
10.3 MB (10,841,808 bytes)

Product version:
5.4.6.4301

Copyright:
Realteck Device © 2006-2016, DRealteck Device. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\6y6s3y6u\6y6s3y6u3u.exe

Digital Signature
Authority:
Open Source Developer

Valid from:
12/9/2015 11:06:24 AM

Valid to:
12/31/2039 8:59:59 PM

Subject:
CN=Open Source Developer

Issuer:
CN=Open Source Developer

Serial number:
68B47EF571F658A141D8BCFAB1410BA8

File PE Metadata
Compilation timestamp:
1/11/2016 1:55:30 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:0f8o3FszWGa/c9octbokzKsCLZB1+BBBZ:R6SzWG9vbNCLZB1+BBBZ

Entry address:
0x9DC884

Entry point:
EB, 08, 76, C8, 83, 00, 00, 00, 00, 00, E9, F3, 46, FE, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
9.8 MB (10,232,320 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
6Y6S3Y6u3u.exe

Command:
C:\users\{user}\appdata\roaming\6y6s3y6u\6y6s3y6u3u.exe


Scan 6y6s3y6u3u.exe - Powered by Reason Core Security