v_stuff_backup.exe

Virgin Media Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘V Stuff Backup’.
Publisher:
Steek  (signed by Virgin Media Ltd)

Description:
V Stuff Backup

Version:
1,6,2,16478

MD5:
aa7153e963a6923ec35c5cac7bfefaf1

SHA-1:
ddfb6c0006025f66cfae79809a8716e8adeaab9e

SHA-256:
7444e72a3ffd40b42b7ced30b48df74370031f685f0ab296b0bad8a444a6e076

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 12:40:59 AM UTC  (today)

File size:
7.9 MB (8,262,928 bytes)

Product version:
1,6,2,16478

Copyright:
Copyright (C) Agematis 2002-2009

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\Program Files\virginmedia\v stuff backup\v_stuff_backup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/27/2009 12:00:00 AM

Valid to:
3/24/2010 11:59:59 PM

Subject:
CN=Virgin Media Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=internet, O=Virgin Media Ltd, L=Liverpool, S=Merseyside, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7FE517036800DE3CD2E501DE904D50B5

File PE Metadata
Compilation timestamp:
1/19/2010 2:22:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:PoITI6TAyODmV3OMmDODekopto68Jq6hvMOBFJ6gcFTLHIVkGJ3YtA:W62smuekopttuS1JoT

Entry address:
0x29A1BE

Entry point:
E8, 20, 0A, 00, 00, E9, 35, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, D8, 65, 8F, 00, FF, 25, DC, 65, 8F, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, D0, AB, BC, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, D0, AB, BC, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4...
 
[+]

Entropy:
7.0147

Code size:
5 MB (5,197,824 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
V Stuff Backup

Command:
"C:\Program Files\virginmedia\v stuff backup\v_stuff_backup.exe" \delayed


Scan v_stuff_backup.exe - Powered by Reason Core Security