newlock.exe

F Key Solutions Inc

It runs as a separate (within the context of its own process) windows Service named “DeskSaverService”.
Publisher:
F Key Solutions Inc  (signed and verified)

MD5:
ee2ebdd0adffe2f3f6e02b52fea2a0af

SHA-1:
178883ddcd2e24f66e17e49691d7116accd378fc

SHA-256:
797da8571503ae56b23b705d44a473733b2fee713850352140ad34c842ef0233

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 7:26:56 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Trojan-Banker.Win32.Banker
t3scan.1.1.64.0

File size:
1.4 MB (1,457,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\1st security agent\newlock.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/5/2009 5:30:00 AM

Valid to:
6/6/2010 5:29:59 AM

Subject:
CN=F Key Solutions Inc, O=F Key Solutions Inc, STREET=37 Colonnade Rd, L=Toronto, S=Ontario, PostalCode=M2K2L6, C=CA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00E6DC3419CC4832C2E4B22B02FFAF2519

File PE Metadata
Compilation timestamp:
7/7/2008 2:20:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:6/H0lJazXRcQz+/f+MicuoaOYcZpvlld2gq4oO/wUkAywg:6kJYX0iCaRcpvH39oMwUC

Entry address:
0xB6578

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, E8, 89, 45, EC, B8, 90, 45, 4B, 00, E8, DC, 0E, F5, FF, 33, C0, 55, 68, F0, 66, 4B, 00, 64, FF, 30, 64, 89, 20, E8, B1, CD, F4, FF, 85, C0, 74, 41, E8, A8, CD, F4, FF, 85, C0, 7E, 42, 8D, 55, EC, B8, 01, 00, 00, 00, E8, F7, CD, F4, FF, 8B, 45, EC, BA, 04, 67, 4B, 00, E8, 4A, F1, F4, FF, 74, 1C, 8D, 55, E8, B8, 01, 00, 00, 00, E8, DB, CD, F4, FF, 8B, 45, E8, BA, 18, 67, 4B, 00, E8, 2E, F1, F4, FF, 75, 0A, E8, 5B, DC, FF, FF, E9, E3, 00, 00, 00, 68, 24, 67, 4B, 00, E8...
 
[+]

Entropy:
6.0948

Developed / compiled with:
Microsoft Visual C++

Code size:
725 KB (742,400 bytes)

Service
Display name:
DeskSaverService

Type:
Win32OwnProcess


Scan newlock.exe - Powered by Reason Core Security