clntsvc.exe

Trustware 101 Ltd.

It runs as a separate (within the context of its own process) windows Service named “BufferZone Service”. This file is installed with the program BufferZone.
Publisher:
Trustware 101 Ltd.  (signed and verified)

Version:
3.42.0.2

MD5:
de2b65995ff240b672c8b6d14202d842

SHA-1:
1e4dbde1f61fa2ea839853a6a478428467f19d80

SHA-256:
f20287bc92d59fa38b47109da207a2a7898907cc353f836b9ddb517f3d910bd0

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/16/2024 8:11:55 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.4959

Quick Heal
(Suspicious) - DNAScan
9.16.14.00

File size:
788.4 KB (807,368 bytes)

Product version:
3.42.0.2

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bufferzone\clntsvc.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/26/2010 2:00:42 PM

Valid to:
10/27/2011 2:00:40 PM

Subject:
CN=Trustware 101 Ltd., O=Trustware 101 Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012BE8657318

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:MAH4e867toi0XHqGPchG5pSluW01S6/tTW8PSB:MAYez7WFkhGj645dW8P2

Entry address:
0x193020

Entry point:
E9, A6, 00, 00, 00, 30, 49, 59, 00, C8, E8, 54, 00, 20, E3, 54, 00, 00, 00, 00, 00, 30, DD, 02, 00, E2, 30, 59, 00, 4E, 65, 6F, 4C, 69, 74, 65, 20, 45, 78, 65, 63, 75, 74, 61, 62, 6C, 65, 20, 46, 69, 6C, 65, 20, 43, 6F, 6D, 70, 72, 65, 73, 73, 6F, 72, 0D, 0A, 43, 6F, 70, 79, 72, 69, 67, 68, 74, 20, 28, 63, 29, 20, 31, 39, 39, 38, 2C, 31, 39, 39, 39, 20, 4E, 65, 6F, 57, 6F, 72, 78, 20, 49, 6E, 63, 0D, 0A, 50, 6F, 72, 74, 69, 6F, 6E, 73, 20, 43, 6F, 70, 79, 72, 69, 67, 68, 74, 20, 28, 63, 29, 20, 31, 39, 39...
 
[+]

Entropy:
7.6986

Packer / compiler:
NeoLite v2.0

Code size:
24.5 KB (25,088 bytes)

Service
Display name:
BufferZone Service

Service name:
BufferZoneSvc

Type:
Win32OwnProcess

Group:
COM Infrastructure

Depends on:
RPCSS


The file clntsvc.exe has been discovered within the following programs.

BufferZone  by Trustwave
Publisher's description - “BufferZone works by creating an isolated virtual environment where online apps and other potentially harmful sources can run completely separated from the corporate network and data, neutralizing even threats that seep through other security tiers.”
www.trustware.com
4% remove it
 
Powered by Should I Remove It?

Scan clntsvc.exe - Powered by Reason Core Security