LooknStop.exe

Look 'n' Stop Firewall

GLOANNEC Frederic

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Look 'n' Stop’.
Publisher:
Soft4Ever  (signed by GLOANNEC Frederic)

Product:
Look 'n' Stop Firewall

Version:
2, 0, 0, 7

MD5:
37c66664aaa2237111e6d451ccc3adec

SHA-1:
1979069c94e1d54a2c6593aac921b2038e692667

SHA-256:
03401ba915d3cb94dbe21c2e06dcc1297093986e6459d9a18cd2edad3734647b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:19:45 PM UTC  (today)

File size:
575.2 KB (589,008 bytes)

Product version:
2, 0, 0, 7

Copyright:
Copyright © 2009

Original file name:
LooknStop.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\soft4ever\looknstop\looknstop.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/13/2008 5:01:41 PM

Valid to:
11/13/2011 5:01:41 PM

Subject:
E=fgloannec@soft4ever.com, CN=GLOANNEC Frederic, O=GLOANNEC Frederic, C=FR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011D9515098B

File PE Metadata
Compilation timestamp:
10/10/2009 11:03:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:45C6ioYPMGvjMno2ulCuFpp/PtNqyBsy23nyONmn16yqbeaxxIZjbZ:4KnjQonldNP2yBsy23Kqbea0j

Entry address:
0x3B93F

Entry point:
E8, 84, 05, 00, 00, E9, DD, FC, FF, FF, CC, FF, 25, 10, 08, 44, 00, FF, 25, 0C, 08, 44, 00, CC, CC, 68, B9, B2, 43, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 00, 34, 45, 00, 31, 45, FC, 33, C5, 89, 45, E4, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, E4, 33, CD, E8, F6, F7, FF, FF, E9, 7A, 02, 00, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C...
 
[+]

Entropy:
5.6998

Code size:
252 KB (258,048 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Look 'n' Stop

Command:
"C:\Program Files\soft4ever\looknstop\looknstop.exe" -auto


Scan LooknStop.exe - Powered by Reason Core Security