worktime.exe

WorkTime

NesterSoft Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WorkTime’.
Publisher:
NesterSoft Inc.  (signed and verified)

Product:
WorkTime

Version:
4.22.0.433

MD5:
e095038e6ca321e876c4827bf436f375

SHA-1:
3e0c0b7bc3e6b9086deab6bec5db3548c2db61b2

SHA-256:
139757e5da3acb3cac24dbf5b2b60386ebed2de219aa6d8271f49c62ba734c65

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:26:57 PM UTC  (today)

File size:
2.2 MB (2,306,800 bytes)

Product version:
4.XX

Trademarks:
WorkTime(r) NesterSoft Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\worktime\worktime.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/20/2009 12:00:00 AM

Valid to:
11/19/2012 11:59:59 PM

Subject:
CN=NesterSoft Inc., O=NesterSoft Inc., STREET=56 Noble Prince Pl, L=Woodbridge, S=ON, PostalCode=L4H1S5, C=CA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
550CFF8D8820F2EBD59B3B511E78B8DB

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:25dUb0/nGFhPpDzElmdsXNLYgc6THEA2LHFidd9eW0:qghPpDzLdUNbneLgdd9eH

Entry address:
0x1000

Entry point:
68, 01, 70, 8B, 00, E8, 01, 00, 00, 00, C3, C3, 95, 59, 61, FF, 47, 8E, DF, 00, E0, 16, 0D, BC, F7, 3E, D2, F5, 93, 46, 98, 5B, 40, 74, 1C, 36, 8C, BB, 4D, F0, B9, 83, 44, 57, 15, 4F, 26, A2, 8C, 9B, F2, 65, CD, 22, 2A, 49, 8A, C3, 84, A7, E4, 3E, 9B, 6B, 0A, 71, 15, 32, 45, 57, 67, A6, 5D, BC, F6, 8F, 70, A0, 5C, 3A, 04, DD, 27, CC, DA, 88, 0F, 53, 14, 6F, AF, AE, 85, EA, 9C, 62, 7C, 5F, E4, 9F, 26, 3D, 54, 40, B5, 01, 1C, 67, FD, 41, BA, 0A, FE, 1C, 69, 2E, 4D, 2E, 1D, 3E, 80, 3A, 73, BD, E6, 1F, FC, FD...
 
[+]

Entropy:
7.5639

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
3.6 MB (3,780,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WorkTime

Command:
C:\Program Files\worktime\worktime.exe


Scan worktime.exe - Powered by Reason Core Security