keysharpnxbiz.exe

KeySharpNxBiz

RaonSecure

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘keysharpbiz’.
Publisher:
Wizvera  (signed by RaonSecure)

Product:
KeySharpNxBiz

Description:
KeySharpNxBiz 3.2.5.2

Version:
3.2.5.2

MD5:
52816e38adb0dd8fe05aa3c68f5d6a0c

SHA-1:
b88fc4fa083594544d51f4509cc268865e0c201f

SHA-256:
0fdb2086acfc985f5dc2a99fab9035c1f21c1cd86be7ccb11a8293d22d10c32a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 6:23:07 AM UTC  (today)

File size:
10.3 MB (10,751,328 bytes)

Product version:
3.2.5.2

Original file name:
keysharpbiz.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\keysharpnxbiz\keysharpnxbiz.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/22/2016 9:00:00 AM

Valid to:
5/22/2017 8:59:59 AM

Subject:
CN=RaonSecure, O=RaonSecure, L=Anyang-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4A52DB83A6B2B7E607189EDD0F5A72BA

File PE Metadata
Compilation timestamp:
7/6/2016 4:17:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x6C5CED

Entry point:
E8, 1F, 71, 01, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, 3D, AC, 2F, E5, 00, 00, 0F, 84, 82, 00, 00, 00, 83, EC, 08, 0F, AE, 5C, 24, 04, 8B, 44, 24, 04, 25, 80, 1F, 00, 00, 3D, 80, 1F, 00, 00, 75, 0F, D9, 3C, 24, 66, 8B, 04, 24, 66, 83, E0, 7F, 66, 83, F8, 7F, 8D, 64, 24, 08, 75, 55, E9, 89, 71, 01, 00, 90, 83, 3D, AC, 2F, E5, 00, 00, 74, 32, 83, EC, 08, 0F, AE, 5C, 24, 04, 8B, 44, 24, 04, 25, 80, 1F, 00, 00, 3D, 80, 1F, 00, 00, 75, 0F, D9, 3C, 24, 66, 8B, 04, 24, 66, 83, E0, 7F, 66...
 
[+]

Entropy:
6.6525

Code size:
7.6 MB (7,939,584 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
keysharpbiz

Command:
"C:\Program Files\keysharpnxbiz\keysharpnxbiz.exe" keysharpbiC:\exec\x86\16108\


Scan keysharpnxbiz.exe - Powered by Reason Core Security