fltw.exe

Beehive Software Ltd.

It runs as a separate (within the context of its own process) windows Service named “WtFilterServ”.
Publisher:
Beehive Software Ltd.  (signed and verified)

MD5:
07941ab5651af3a50cb1361b798847f3

SHA-1:
8a49459b26e5f856ce936cb7f5cfc01df1bd877f

SHA-256:
4d08c13d6fbf1f9806b95400a461ce6d6f0d493935f0d878c3cb5434a4852547

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 12:13:36 AM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-Banker.Win32.Banker
t3scan.1.8.6.0

File size:
1 MB (1,085,328 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\fltw.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/14/2010 3:00:00 AM

Valid to:
1/16/2011 2:59:59 AM

Subject:
CN=Beehive Software Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beehive Software Ltd., L=Murom, S=Vladimir rgn., C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56A53D14620AA8D9A5FEBDE5EA879613

File PE Metadata
Compilation timestamp:
5/11/2010 5:04:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Alr9qkF4SJE42GLDxuCTdKXTfWs7DKCEMMLR4KMRC:AZ9qWJE42u98us3Sm1C

Entry address:
0x2136E

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, C2, 9B, 45, 00, 4D, 25, 25, E6, 48, 07, 59, C5, B1, 0E, 67, CD, 09, B9, 83, 4F, 6F, B2, 00, F1, 5E, 44, 6C, 95, E5, 58, 52, B5, 6F, 8D, C8, D8, 01, 17, 23, 27, 74, D7, 8E, 02, A1, D7, 6B, 8A, 76, F0, 80, 6C, ED, DB, A9, 1D, CE, AB, 2F, F9, F0, DF, 71, 5E, 88, C9, 14, 74, F2, 9F, C0, 9D, AF, 84, 6F, 68, 0C, 98, C3, F6, 43, 7E, 00, C3, 5F, BD, E5, 8B, 5B, BB, 04, EA, 27, 14, CA, 42, 17, 09, 46, 47, 49, 2B, 8A, 09...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1005 KB (1,029,120 bytes)

Service
Display name:
WtFilterServ

Service name:
wtflserv

Description:
{47F7E63E-262B-4533-8D97-5638988E0364}

Type:
Win32OwnProcess


Scan fltw.exe - Powered by Reason Core Security