pw4srv.exe

O&K Print Watch

OK Software Ltd.

It runs as a separate (within the context of its own process) windows Service named “O&K Print Watch Service”.
Publisher:
O&K Software  (signed by OK Software Ltd.)

Product:
O&K Print Watch

Description:
O&K Print Watch Service

Version:
4.3.0.1337

MD5:
f3ae81fdac59a1b28af4a7d5870571fa

SHA-1:
f19610757c2d832b37d20262e9357cd75d50c78a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 8:34:40 AM UTC  (today)

File size:
2.1 MB (2,237,096 bytes)

Product version:
4.3.0.1337

Copyright:
(c) O&K Software. All rights reserved.

Original file name:
WatchSrv.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\o&k print watch\pw4srv.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/8/2006 11:27:27 AM

Valid to:
12/8/2007 11:27:27 AM

Subject:
CN=OK Software Ltd., OU=Secure Application Development, O=OK Software Ltd., L=Moscow, S=Moscow, C=RU

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
21B7493F1FDE14EA0FBC5B4F3A5F0D92

File PE Metadata
Compilation timestamp:
11/1/2007 9:48:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:gKELeH0iUcqRqvgfK7W0uzoLULWRGCG4M:g7wgSibC2

Entry address:
0xDE813

Entry point:
E8, 1C, 03, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, D8, 46, 59, 00, FF, 25, E0, 46, 59, 00, 3B, 0D, 38, D0, 60, 00, 75, 02, F3, C3, E9, 8F, 03, 00, 00, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, FF, 74, 24, 10, 68, 2A, E8, 4D, 00, 68, 38, D0, 60, 00, E8, 74, 04, 00, 00, 83, C4, 18, C3, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 6A, 04, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 54, 04, 00, 00, FF, 25, 74, 45, 59, 00, FF...
 
[+]

Code size:
1.6 MB (1,650,688 bytes)

Service
Display name:
O&K Print Watch Service

Type:
Win32OwnProcess

Depends on:
RPCSS Spooler


Scan pw4srv.exe - Powered by Reason Core Security