zentimoservice.exe

Crystal Rich, Ltd

It runs as a separate (within the context of its own process) windows Service named “Zentimo Assistant”.
Publisher:
Crystal Rich, Ltd  (signed and verified)

MD5:
df4adc9297c5fbbcb074af293d2bc58c

SHA-1:
01f1357bf34fe1f7f7900afe434677e9cfde9519

SHA-256:
6c4349713325672660e0341813a1454ea0a9b373e03aff161eef40a1337ad3a4

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/19/2024 1:58:40 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

File size:
548.7 KB (561,824 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\zentimo\zentimoservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/2/2010 1:00:00 AM

Valid to:
12/3/2011 12:59:59 AM

Subject:
CN="Crystal Rich, Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Crystal Rich, Ltd", L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
582E502BCA04FD9767BEE4917A3608A0

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
2.42

CTPH (ssdeep):
6144:TKd60AjNIUACy/15wH+F/I2wyd94tGrMaXnlNHec6hTYvj4xk9YvG7dxDJ:Tf0oOrwH+1hBdmHayQj4xk9Yv4DJ

Entry address:
0x120B0

Entry point:
48, 81, EC, 88, 00, 00, 00, C6, 05, 62, 5F, 07, 00, 01, B9, F6, FF, FF, FF, E8, 68, F0, FE, FF, 48, 89, C1, 48, 8D, 15, EE, 6D, 07, 00, E8, 29, F3, FE, FF, E8, 64, FF, FF, FF, 48, 81, C4, 88, 00, 00, 00, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 55, 48, 89, E5, 48, 81, EC, 80, 00, 00, 00, 48, 89, 5D, D0, 48, 89, 7D, D8, 48, 89, 75, E0, 4C, 89, 65, E8, 48, 89, CB, 41, B4, 00, 48, BF, 00, 00, 00, 00, 00, 00, 00, 00, 48, 8D, 75, F0, E8, EC, F2, FE, FF, 89, C1, 48, 89, DA, 41, B9, 10, 00, 00, 00, 48...
 
[+]

Code size:
413.2 KB (423,104 bytes)

Service
Display name:
Zentimo Assistant

Service name:
ZentimoService

Description:
Zentimo uses this service for auxiliary operations. It is not recommended to stop the service while the program is working

Type:
Win32OwnProcess

Group:
Base


Scan zentimoservice.exe - Powered by Reason Core Security