banglamp.exe

Luhong Han

The application banglamp.exe by Luhong Han has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(BanglampP)”.
Publisher:
Luhong Han  (signed and verified)

MD5:
e2906ac98a76131b5ca2fa70f188e2a5

SHA-1:
1a3e4e97fd079f9cf449d41c85a2fdb7abeb9de6

SHA-256:
8187ba09b0a5737cb107150abacd1148a5db9ca921eb9db9e334b4a19fc2d97c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/9/2024 12:38:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.9.27.16

File size:
447.9 KB (458,624 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\banglamp\banglamp.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/19/2016 9:00:00 PM

Valid to:
4/1/2017 8:59:59 PM

Subject:
CN=Luhong Han, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3A4865996F1971B8EF43D56EEA05C52E

File PE Metadata
Compilation timestamp:
9/20/2016 3:03:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:NxOAeVPM/UR6k+UzRlMfft+iAm3RdJmAlrvv/QzvAOm2D4q2fb:N43VPM/UR6kxRlYfkiTfmDzvI24q2j

Entry address:
0x2D5A6

Entry point:
E8, BA, 07, 00, 00, E9, 8E, FE, FF, FF, FF, 25, 64, 03, 45, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 90, 46, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 90, 46, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45...
 
[+]

Code size:
315 KB (322,560 bytes)

Service
Display name:
Protect Service(BanglampP)

Service name:
BanglampP

Description:
To ensure your Banglamp software integrity. If this service is disabled or stopped, your Banglamp software will not be kept integrity check. This service uninstalls itself when there is no Banglamp so

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove banglamp.exe - Powered by Reason Core Security