DGClient.exe

DGClient

hangzhou huatu software co., ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘UserInit’.
Publisher:
Huatusoft  (signed by hangzhou huatu software co., ltd)

Product:
DGClient

Version:
4.4.0.1

MD5:
adb2a02b019f7516622066ad4e9f2e56

SHA-1:
9121612849b1cff0df361fa2f846d3b212cb7d66

SHA-256:
07a4caf761e6eecf06606515e9c9d1b5f115f1e4b4e4f43d656c14618175551f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:06:04 AM UTC  (today)

File size:
1.9 MB (1,971,048 bytes)

Product version:
4.4

Original file name:
DGClient.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\dg\dgclient.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/26/2010 8:00:00 AM

Valid to:
11/26/2012 7:59:59 AM

Subject:
CN="hangzhou huatu software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="hangzhou huatu software co., ltd", L=hangzhou, S=zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2E4E1F0E36B2A493124C81511B30B009

File PE Metadata
Compilation timestamp:
11/16/2011 1:28:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:43ACKrrG6v5qEVbmUL+ouBGePBTN1vU/9UJBU2Lgbqd:43SrUERmUL+ou/dNFU/+U2Lgb

Entry address:
0x11DE35

Entry point:
E8, 96, 9B, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 70, 8F, 5A, 00, 75, 02, F3, C3, E9, 18, 9C, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 7F, 43, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 1F, 1D, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 18, 6E, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 57, 47, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.3799

Code size:
1.3 MB (1,364,480 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
UserInit

Command:
C:\Program Files\dg\dgclient.exe


Scan DGClient.exe - Powered by Reason Core Security