winlock.exe

WinLock Professional

Crystal Office Systems

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘0wl’.
Publisher:
Crystal Office Systems  (signed and verified)

Product:
WinLock Professional

Version:
6.0.1.0

MD5:
abc422e9a7e3401e6a8c13b61ea3ac80

SHA-1:
89061a45451deda3d1b62150089cc3f4d4201919

SHA-256:
dfd75339a2dd422e573c6db813ba1a3f7b4bf20e40c4978a0801a40bc7f29eb9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:44:44 PM UTC  (today)

File size:
2.7 MB (2,838,112 bytes)

Product version:
6.01

Copyright:
© 1999-2012 Crystal Office Systems

Original file name:
winlock.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\winlockpro\winlock.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/8/2012 7:00:00 AM

Valid to:
2/8/2014 6:59:59 AM

Subject:
CN=Crystal Office Systems, O=Crystal Office Systems, STREET="Kantemirovskaya street, 53-1-51", L=Moscow, S=RU, PostalCode=115477, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
641A324A34F2B894BA79BC39CE01E16A

File PE Metadata
Compilation timestamp:
8/2/2012 1:35:21 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
49152:Lq4N+gbEwv0glXsX7SSFOx2Zj6l9m0R3Ll6HerYaNG79qyC5630HOJZ4cOU7m6OT:LFxxMWSFOx8j+mi4erf479qyCSUOXLO6

Entry address:
0x1000

Entry point:
68, 01, 30, AB, 00, E8, 01, 00, 00, 00, C3, C3, 4D, 03, B9, 83, 91, E0, 59, 33, 28, 03, 20, D7, 4D, 2A, 98, 02, 0E, D4, 51, 7C, CA, 85, BE, 57, F4, 69, 99, 83, 82, 4C, 95, 4E, 1B, 6E, 47, 3E, 7B, 10, 37, 92, 3C, 10, 3F, 00, D3, 6B, 2E, 05, 17, 63, 3A, 31, EA, 19, E6, C4, EB, 2D, FB, AD, E4, 95, 91, 30, D2, 80, F5, D8, AA, 30, 5E, 2C, A8, 8F, 4A, 2B, 31, DB, 9E, 6A, 10, 73, 7F, 09, 66, 80, A1, 73, F7, E9, AB, FB, B9, 60, B9, 35, 3C, 1E, 64, F5, 9A, CB, 10, 6F, 72, 35, 72, 54, 6F, ED, 70, 4C, 57, 25, BA, 42...
 
[+]

Entropy:
7.9530

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4 MB (4,186,112 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
0wl

Command:
C:\Program Files\winlockpro\winlock.exe


Scan winlock.exe - Powered by Reason Core Security