winprotector.exe

HD革命/WinProtector Version 4.0

Ark Information Systems inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PwfCtrl’.
Publisher:
アーク情報システム  (signed by Ark Information Systems inc.)

Product:
HD革命/WinProtector Version 4.0

Version:
4.0.0.1

MD5:
93ede837c7ee4ecb6e3707be701a2cd6

SHA-1:
8297a13d1bdcd5c4a89979159af76e3e58ba7b2b

SHA-256:
a31f3912aa6cb36dfa92d434c43d6e13a8b5fb97190487629ecdf28acd95fa67

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 5:00:26 AM UTC  (today)

File size:
2.2 MB (2,267,776 bytes)

Product version:
4.0.0.1

Copyright:
Copyright (C) 2011 株式会社 アーク情報システム

Trademarks:
HD革命(R)

Original file name:
WinProtector

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ark information systems inc\winprotector\winprotector.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/5/2011 9:00:00 AM

Valid to:
7/5/2012 8:59:59 AM

Subject:
CN=Ark Information Systems inc., OU=KH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ark Information Systems inc., L=Chiyoda-Ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12C38454C4550880A009D55657B5A022

File PE Metadata
Compilation timestamp:
4/11/2012 6:25:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:RHO8Z95Ow0xW4Oewesw/sHSw0xW4OewWSJ:TZKJZwes+syJZwDJ

Entry address:
0x35F8C

Entry point:
E8, D3, 07, 00, 00, E9, 6B, FD, FF, FF, FF, 25, 30, B2, 43, 00, 3B, 0D, 80, D9, 44, 00, 75, 02, F3, C3, E9, 54, 08, 00, 00, CC, FF, 25, F0, B2, 43, 00, 8B, FF, 55, 8B, EC, F6, 45, 08, 02, 57, 8B, F9, 74, 25, 56, 68, 46, 69, 43, 00, 8D, 77, FC, FF, 36, 6A, 0C, 57, E8, 9D, 04, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 97, F4, FF, FF, 59, 8B, C6, 5E, EB, 14, E8, 5C, 09, 00, 00, F6, 45, 08, 01, 74, 07, 57, E8, 80, F4, FF, FF, 59, 8B, C7, 5F, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 14, FF, 75, 10, FF, 75, 0C...
 
[+]

Entropy:
7.3422

Code size:
230 KB (235,520 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PwfCtrl

Command:
"C:\Program Files\ark information systems inc\winprotector\winprotector.exe" autorun


Scan winprotector.exe - Powered by Reason Core Security