winlock.exe

WinLock Professional

Crystal Office Systems

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘0wl’. This is installed with WinLock Professional.
Publisher:
Crystal Office Systems  (signed and verified)

Product:
WinLock Professional

Version:
5.3.0.0

MD5:
b44998cd4e3b85c2a038ec2cd8529bc6

SHA-1:
5089dbf9e3380500028acb52b1a0a502ac72fa0d

SHA-256:
1e4241002162fb08e935929c5792192cd11c9922d7dc2722991a6cfb6006c91c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 6:45:24 AM UTC  (today)

File size:
2.7 MB (2,784,592 bytes)

Product version:
5.3

Copyright:
© 1999-2011 Crystal Office Systems

Original file name:
winlock.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\winlockpro\winlock.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/21/2011 1:00:00 AM

Valid to:
2/22/2012 12:59:59 AM

Subject:
CN=Crystal Office Systems, O=Crystal Office Systems, STREET="Kantemirovskaya street, 53-1-51", L=Moscow, S=RU, PostalCode=115477, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00C7DF5EC2BCD9DEA8C0BEBD21B0B003DD

File PE Metadata
Compilation timestamp:
8/27/2011 4:36:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:ptl5SQM489yFYRGITgSVzIJXTvhplrK2RPdlgh7k/kcOU7m6ZlUN:fHP89MeGIT/e5pp9jHlgh7kfOU7ZlUN

Entry address:
0x1000

Entry point:
68, 01, F0, 9D, 00, E8, 01, 00, 00, 00, C3, C3, 5C, 37, BC, 67, 85, BE, 74, 70, 96, 46, 03, 62, C0, C3, 38, EF, 2C, 66, 50, 4F, 47, 2C, 76, 57, E7, 09, 48, C7, C3, 5D, D4, 07, A9, 07, 8B, AE, 1C, FE, 97, CD, 22, F0, BF, 06, 64, A2, A0, 79, 97, 65, D4, D9, 86, 23, 02, 4B, 12, BE, B2, 77, 41, D2, 17, AC, AC, F7, D0, 26, 0D, C4, 93, 1C, CF, D4, E5, DF, 8F, B9, C1, 82, CD, 44, 8E, E3, 13, CB, 02, 63, 79, 8A, BA, 11, AC, 60, 67, 06, 72, F0, 66, 14, 20, 54, 93, B0, BC, 04, A7, FB, 10, 55, C3, 83, FE, B1, F2, FF...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
3.2 MB (3,354,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
0wl

Command:
C:\Program Files\winlockpro\winlock.exe


The file winlock.exe has been discovered within the following program.

WinLock Professional  by Crystal Office Systems
Publisher's description - “WinLock is a comprehensive security solution for personal or publicly accessible computers. It is a program that ensures that only authorized people can access sensitive information on your computer. With WinLock, you can control how long others can use your computer.”
www.crystaloffice.com/winlockpro
5% remove it
 
Powered by Should I Remove It?

Scan winlock.exe - Powered by Reason Core Security