LanTalk.exe

LanTalk.NET Messenger

CEZEO software Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘LanTalk.NET’.
Publisher:
CEZEO software Ltd.  (signed and verified)

Product:
LanTalk.NET Messenger

Version:
3, 6, 54, 15

MD5:
5969e29795f182120997a3ddc731fb4d

SHA-1:
232bda9dcf7ce640362b3a8828d2c82ce7fd6061

SHA-256:
4cdd31ab0333646f77b2e60d5276f3fd179e7056dd3f87523bce4bd762b92ed3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:18:41 PM UTC  (today)

File size:
290.8 KB (297,808 bytes)

Product version:
3, 6, 54, 15

Copyright:
CEZEO software Ltd. (c) 1999 - 2010

Trademarks:
LanTalk (R)

Original file name:
LanTalk.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cezeo software\lantalk net\lantalk.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/14/2010 7:00:00 AM

Valid to:
4/15/2011 6:59:59 AM

Subject:
CN=CEZEO software Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=CEZEO software Ltd., L=St.Petersburg, S=St.Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1D80EBD7047D4340C581E0F7B35B8565

File PE Metadata
Compilation timestamp:
1/4/2011 10:09:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:s3TK7UMrxf2DYH/Y4Y8Z1qjM0klwXDCbtx7Mb7:s3TmODG/d1+ete7

Entry address:
0x1000

Entry point:
68, 01, 30, 47, 00, E8, 01, 00, 00, 00, C3, C3, 44, E1, AC, 51, 2D, D6, 56, B4, 7A, BB, 1C, A4, D7, 48, 66, 49, A2, 9F, EF, EB, 7B, 4E, 73, 50, C2, D7, E5, 1F, 86, 20, 2C, 7E, 51, 43, 32, 84, 67, 77, D6, DB, 74, 61, 02, 51, CA, BB, 45, 4F, B4, 37, 3E, AD, 8D, BC, B5, F2, 0C, 5C, 45, 57, 35, 8D, 67, 5B, 43, AB, 9C, AA, 8C, 19, 58, 54, 41, 73, B2, 07, E2, F1, 37, 1E, FA, 78, 72, 99, 42, 80, 9F, B2, 13, 36, 3E, BD, 9C, 0D, 10, 0E, 64, 2E, 60, D0, C7, 7B, 85, 4D, C2, 81, 37, 23, BD, D8, BB, 97, FF, DA, 5A, B5...
 
[+]

Entropy:
7.4778

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
259 KB (265,216 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
LanTalk.NET

Command:
C:\Program Files\cezeo software\lantalk net\lantalk.exe


Scan LanTalk.exe - Powered by Reason Core Security