sliesvc.exe

Yantai ZhengHao Network Technology Co.,Ltd.

It runs as a separate (within the context of its own process) windows Service named “Sulang IE Protect Service”.
Publisher:

Version:
1.0.0.1

MD5:
4ccd1eedb275eff3945f71a96b6f8910

SHA-1:
39fa57866a87cb26eae37742a2c5c0d506cd17d6

SHA-256:
41f03219e4d767749dd60597d6c3af5243b2cd5115d0282435fb095120207594

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/28/2024 5:41:34 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.ShouQu.20
9.0.1.05190

File size:
105.9 KB (108,480 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
DcrIeSvc.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\sulang\sliesvc.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/28/2014 8:00:00 AM

Valid to:
8/28/2015 7:59:59 AM

Subject:
CN="Yantai ZhengHao Network Technology Co.,Ltd.", O="Yantai ZhengHao Network Technology Co.,Ltd.", L=Yantai, S=Shandong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
06C8D3DDAA7D7BE474B1D69973E3ACB4

File PE Metadata
Compilation timestamp:
6/6/2014 12:19:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:Hk2wvAOP21VssuvtorTDuQROSh0qBLO1mmppj5tfz:twYOPKuvtorTKQRJhjO1mmppj/z

Entry address:
0x8826

Entry point:
E8, 98, 04, 00, 00, E9, 6B, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, E8, D2, 40, 00, 89, 0D, E4, D2, 40, 00, 89, 15, E0, D2, 40, 00, 89, 1D, DC, D2, 40, 00, 89, 35, D8, D2, 40, 00, 89, 3D, D4, D2, 40, 00, 66, 8C, 15, 00, D3, 40, 00, 66, 8C, 0D, F4, D2, 40, 00, 66, 8C, 1D, D0, D2, 40, 00, 66, 8C, 05, CC, D2, 40, 00, 66, 8C, 25, C8, D2, 40, 00, 66, 8C, 2D, C4, D2, 40, 00, 9C, 8F, 05, F8, D2, 40, 00, 8B, 45, 00, A3, EC, D2, 40, 00, 8B, 45, 04, A3, F0, D2, 40, 00, 8D, 45, 08, A3, FC, D2, 40...
 
[+]

Entropy:
5.8119

Code size:
34 KB (34,816 bytes)

Service
Display name:
Sulang IE Protect Service

Type:
Win32OwnProcess


Scan sliesvc.exe - Powered by Reason Core Security