cwagent.exe

Zimin Sergei Aleksandrovich IP

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ChildWebGuardian PRO Agent’.
Publisher:
Zimin Sergei Aleksandrovich IP  (signed and verified)

Description:
Internet filter

Version:
1.0.0.0

MD5:
08a517c315d80afb90aa0b812a93e1b0

SHA-1:
cf61c46253a66c0be22cfccdbb8ee072ed034359

SHA-256:
c3e25b060110c806e36e8784a5d1fb0962c75672a6a1f9ca79469c734dfa5bad

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 6:33:38 PM UTC  (today)

File size:
1.9 MB (2,026,904 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\Program Files\childwebguardian pro\cwagent.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/2/2012 2:00:00 AM

Valid to:
4/3/2013 1:59:59 AM

Subject:
CN=Zimin Sergei Aleksandrovich IP, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zimin Sergei Aleksandrovich IP, L=Murom, S=Vladimir rgn., C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72B6A7B444FE8DEE4102522A4F585AF5

File PE Metadata
Compilation timestamp:
12/11/2012 4:44:28 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1774DC

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E4, 89, 45, E8, 89, 45, EC, B8, B8, 46, 57, 00, E8, 62, 1C, E9, FF, 33, C0, 55, 68, 90, 77, 57, 00, 64, FF, 30, 64, 89, 20, E8, 9B, A3, F1, FF, 8B, 15, 4C, 27, 58, 00, 8B, 12, 8D, 45, EC, B9, A8, 77, 57, 00, E8, AA, F6, E8, FF, 8B, 45, EC, E8, AE, 65, E9, FF, 84, C0, 0F, 85, 43, 02, 00, 00, E8, D5, BE, E8, FF, 85, C0, 7E, 1C, 8D, 55, E8, B8, 01, 00, 00, 00, E8, 24, BF, E8, FF, 8B, 45, E8, BA, D4, 77, 57, 00, E8, 47, F9, E8, FF, 74, 04, 33, C0, EB, 02, B0...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,533,952 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ChildWebGuardian PRO Agent

Command:
"C:\Program Files\childwebguardian pro\cwagent.exe"


Scan cwagent.exe - Powered by Reason Core Security