PopBlock.exe

火绒安全软件

HuoRongBoRui (Beijing) Technology Co.,Ltd

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
北京火绒网络科技有限公司  (signed by HuoRongBoRui (Beijing) Technology Co.,Ltd)

Product:
火绒安全软件

Description:
火绒弹窗拦截

Version:
0, 1, 0, 100

MD5:
fd9020f53bec64a821a2ca4d80e89c77

SHA-1:
74d4097f402cbcf12fe30de859de3ae6ab103c3d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:23:19 PM UTC  (today)

File size:
640.1 KB (655,488 bytes)

Product version:
4.0.0.0

Copyright:
北京火绒网络科技有限公司

Original file name:
PopBlock.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Taiwan)

Common path:
C:\Program Files\huorong\sysdiag\bin\popblock.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/25/2015 8:00:00 AM

Valid to:
6/24/2018 7:59:59 AM

Subject:
CN="HuoRongBoRui (Beijing) Technology Co.,Ltd", O="HuoRongBoRui (Beijing) Technology Co.,Ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
705BAFA86C31B25B22F23B09AB056BCF

File PE Metadata
Compilation timestamp:
3/15/2017 4:22:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x2CE81

Entry point:
E8, C7, 04, 00, 00, E9, 8E, FE, FF, FF, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 58, 00, 00, 00, C7, 06, 08, AA, 44, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 10, AA, 44, 00, C7, 01, 08, AA, 44, 00, C3, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 25, 00, 00, 00, C7, 06, 24, AA, 44, 00, 8B, C6, 5E, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 2C, AA, 44, 00, C7, 01, 24, AA, 44, 00, C3, 55, 8B, EC, 56, 8B, F1, 8D, 46, 04, C7, 06, E8, A9, 44, 00, 83...
 
[+]

Entropy:
6.0409

Code size:
289 KB (295,936 bytes)

Scheduled Task
Task name:
Huorong PopBlock

Path:
C:\WINDOWS\Tasks\Huorong PopBlock.job

Trigger:
Logon (Runs on logon)


Scan PopBlock.exe - Powered by Reason Core Security