ddzs.exe

东东助手3.2

长沙聚丰网络科技有限公司

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ddzs’.
Publisher:
jf  (signed by 长沙聚丰网络科技有限公司)

Product:
东东助手3.2

Version:
3.0.0.1

MD5:
49441ac9f1b9d6e91474baebc61a2c1f

SHA-1:
aa89356a604db1db9fb307a0904731372b55a636

SHA-256:
cffb79c5f32ab8637da355bcb21438e2e634b0d631376d8318b4e55faba399ec

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:43:03 AM UTC  (today)

File size:
847.1 KB (867,464 bytes)

Product version:
3.0.0.0

Copyright:
(C) jf Inc. All Rights Reserved。

Original file name:
ddzs.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ddzs\ddzs.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
5/12/2015 8:00:00 AM

Valid to:
5/12/2016 7:59:59 AM

Subject:
CN=长沙聚丰网络科技有限公司, OU=IT, O=长沙聚丰网络科技有限公司, L=长沙, S=湖南, C=CN

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
75F8AF7EE48ECB9DF5F227216DE25CDE

File PE Metadata
Compilation timestamp:
10/22/2015 9:51:22 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1EFCE

Entry point:
E8, A6, 04, 00, 00, E9, 6B, FD, FF, FF, 3B, 0D, 28, C0, 42, 00, 75, 02, F3, C3, E9, 2D, 05, 00, 00, CC, FF, 25, 40, 32, 42, 00, CC, CC, 8B, FF, 55, 8B, EC, F6, 45, 08, 02, 57, 8B, F9, 74, 25, 56, 68, 4A, F6, 41, 00, 8D, 77, FC, FF, 36, 6A, 0C, 57, E8, 8F, 00, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, C3, FC, FF, FF, 59, 8B, C6, 5E, EB, 14, E8, 22, 06, 00, 00, F6, 45, 08, 01, 74, 07, 57, E8, AC, FC, FF, FF, 59, 8B, C7, 5F, 5D, C2, 04, 00, FF, 25, 4C, 32, 42, 00, 6A, 14, 68, 70, 77, 42, 00, E8, 82, 03, 00, 00...
 
[+]

Entropy:
7.7343  (probably packed)

Code size:
133.5 KB (136,704 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ddzs

Command:
"C:\Program Files\ddzs\ddzs.exe" \start


Scan ddzs.exe - Powered by Reason Core Security