FontLocaleCP.exe

FontLocaleCP

Whatlink Software Limited

It runs as a separate (within the context of its own process) windows Service named “Font Storage Control Process”.
Publisher:
PFontLocaleCP  (signed by Whatlink Software Limited)

Product:
FontLocaleCP

Version:
2.1.0.0

MD5:
55d34cecda6626e44f162c9e71036403

SHA-1:
cd258b683d09f3fb89fb42841479bf07179554ba

SHA-256:
1aafded9780d64635cf08a9b7f14b60f8e63b41795a3fe9851fe2af5b42ac6f4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 3:11:31 AM UTC  (today)

File size:
54.2 KB (55,536 bytes)

Product version:
2.1.0.0

Copyright:
PFontLocaleCP

Original file name:
FontLocaleCP.exe

File type:
Executable application (Win32 EXE)

Language:
English (Ireland)

Common path:
C:\Program Files\icedeep, inc\myusbonly by icedeep\fontlocalecp.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/22/2012 5:00:00 PM

Valid to:
5/23/2014 4:59:59 PM

Subject:
CN=Whatlink Software Limited, O=Whatlink Software Limited, STREET="23F, New Trend Centre, 704 Prince Edward Road East, San Po Kong", L=San Po Kong, S=Kowloon, PostalCode=00000, C=HK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
43259EC376010D27AB2FB3A264BA523A

File PE Metadata
Compilation timestamp:
1/8/2014 12:05:10 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

CTPH (ssdeep):
768:FamLvhcHTgWWke2bfDeiHpZdUsFXpxfJpVJmF79qvVkJ2t+xhXF:AGhcH8S3bfDhbQ3Q22tmhXF

Entry address:
0x7022

Entry point:
55, 8B, EC, 6A, FF, 68, D8, 83, 40, 00, 68, 60, 71, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 20, 53, 56, 57, 89, 65, E8, 83, 65, FC, 00, 6A, 01, FF, 15, 38, 82, 40, 00, 59, 83, 0D, 4C, A9, 40, 00, FF, 83, 0D, 50, A9, 40, 00, FF, FF, 15, 34, 82, 40, 00, 8B, 0D, 44, A9, 40, 00, 89, 08, FF, 15, 30, 82, 40, 00, 8B, 0D, 40, A9, 40, 00, 89, 08, A1, 2C, 82, 40, 00, 8B, 00, A3, 48, A9, 40, 00, E8, CF, 00, 00, 00, 83, 3D, 58, A8, 40, 00, 00, 75, 0C, 68, 5C, 71, 40, 00, FF, 15, 28, 82...
 
[+]

Entropy:
5.5645

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
28 KB (28,672 bytes)

Service
Display name:
Font Storage Control Process

Service name:
FontLocaleCP

Type:
Win32OwnProcess


Scan FontLocaleCP.exe - Powered by Reason Core Security