StartTSL.exe

Transparent Screen Lock for Windows

Esm Software

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘StartTSL’.
Publisher:
e-motional.com a division of Esm Software  (signed by Esm Software)

Product:
Transparent Screen Lock for Windows

Description:
TSL Startup routines PRO

Version:
6.0.0.0

MD5:
8f30beb18db948d639dd1c512d727a84

SHA-1:
92a934fe3d0053505ed116ca01601ca63113bbe2

SHA-256:
e6365add2ee486609afdd9c4c867ff4a4f0751963137f52254548976b11dcfd3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/4/2026 3:05:51 PM UTC  (today)

File size:
219.9 KB (225,168 bytes)

Product version:
6.0.0.0

Copyright:
Copyright © 2002-16 Esm Software

Original file name:
StartTSL.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Windows\System32\starttsl.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/13/2013 3:00:00 AM

Valid to:
12/12/2016 2:59:59 AM

Subject:
CN=Esm Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Esm Software, L=Kirkland, S=Quebec, C=CA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F5D200FB411562031277FF39421C360

File PE Metadata
Compilation timestamp:
4/18/2016 5:16:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:p+pST7JsnYiRByz49vm4iU4Tj3zhtfh8EO:GrnYp4dTuv1zO

Entry address:
0x13FA0

Entry point:
E8, 6A, 8D, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 00, C8, 42, 00, E8, FE, 06, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, F0, 48, 43, 00, 77, 22, 6A, 04, E8, 55, 8F, 00, 00, 59, 83, 65, FC, 00, 56, E8, 5C, 97, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 0A, 07, 00, 00, C3, 6A, 04, E8, 50, 8E, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, AC, 62, 42, 00, 83, 3D, 9C, 36, 43, 00, 00, 75, 18, E8, BC, 83, 00...
 
[+]

Entropy:
6.4990

Code size:
146 KB (149,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StartTSL

Command:
C:\Windows\System32\starttsl.exe


Scan StartTSL.exe - Powered by Reason Core Security