fltw.exe

Beehive Software Ltd.

It runs as a separate (within the context of its own process) windows Service named “WtFilterServ”.
Publisher:
Beehive Software Ltd.  (signed and verified)

Version:
2.0.6.0

MD5:
0e5e0c45781b5aa567ed5ba59335725d

SHA-1:
d1c77c273b681db41d2ccf02ed4512b348de5230

SHA-256:
c45c70fde36476f16aa50a907b8861e5701e38934b79935617564e17cb441484

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 5:12:54 PM UTC  (today)

File size:
1.1 MB (1,132,440 bytes)

Product version:
2.0.6.0

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\fltw.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/14/2010 6:00:00 AM

Valid to:
1/16/2011 5:59:59 AM

Subject:
CN=Beehive Software Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beehive Software Ltd., L=Murom, S=Vladimir rgn., C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
56A53D14620AA8D9A5FEBDE5EA879613

File PE Metadata
Compilation timestamp:
10/14/2010 12:32:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:U+GkhaWPC14cIx0OYpna3I8e0zopCJW3biFFChRpWefwUI2Ap:3Gk9PO4tYna3I8NECJsYFChRAFV2Ap

Entry address:
0x3BB8F

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 15, 80, 45, 00, 23, 90, C2, 95, 21, A2, E5, 2A, 45, 5B, 22, 08, 7B, B2, 1E, 30, 9D, 55, 1F, 82, 47, D9, 3C, 45, 86, 6C, 45, FB, 8E, A0, 00, 49, 19, 6A, 31, 97, 38, 5B, F7, 1D, C3, 34, 79, 18, 4D, CF, 59, A0, 8F, 7A, E8, 99, 22, 6E, AA, E0, 5B, 64, 2B, 7A, DB, CC, E6, 92, 37, 0D, 88, A2, AB, 97, 8C, F4, 9C, E0, 8D, E6, 4A, 07, 2A, 55, E8, B8, C0, B1, A5, 19, 6D, 18, 4E, 5E, 5A, E7, B5, 5B, AC, 94, 1B, 5F, 1E, CB...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1005.5 KB (1,029,632 bytes)

Service
Display name:
WtFilterServ

Service name:
wtflserv

Description:
{47F7E63E-262B-4533-8D97-5638988E0364}

Type:
Win32OwnProcess


Scan fltw.exe - Powered by Reason Core Security