zlclient.exe

Zone Labs Client

Check Point Software Technologies Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Zone Labs Client’.
Publisher:
Zone Labs, LLC  (signed by Check Point Software Technologies Inc.)

Product:
Zone Labs Client

Version:
6.5.700.000

MD5:
274bbac33850a919459f7250d749653b

SHA-1:
918d7952ef764a4d5018f28c026b8967c90b99c1

SHA-256:
ff1bd09d40bf83c728b63d8fd59dde6acda903f8dca397d1cd5022798d660e9d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 3:05:39 PM UTC  (today)

File size:
946 KB (968,696 bytes)

Product version:
6.5.700.000

Copyright:
Copyright © 1998-2006, Zone Labs, LLC

Original file name:
zlclient.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\zone labs\zonealarm\zlclient.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/14/2005 7:00:00 PM

Valid to:
11/15/2006 6:59:59 PM

Subject:
CN=Check Point Software Technologies Inc., OU=Zone Labs, OU=Digital ID Class 3 - Netscape Object Signing, O=Check Point Software Technologies Inc., L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
24BA2CF10F7310D406E84C446CF4C837

File PE Metadata
Compilation timestamp:
5/31/2006 8:05:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:g3RZc+kMgvz+Pa//p6kDCdYf+mxcEM2MU8GUs0eckM28ksfcEMGMU8aUs0xckMxt:oRZcFMgX/wk5f4

Entry address:
0x24264

Entry point:
55, 8B, EC, 6A, FF, 68, F0, CF, 42, 00, 68, F0, 43, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, B0, B1, 42, 00, 59, 83, 0D, C0, 69, 43, 00, FF, 83, 0D, C4, 69, 43, 00, FF, FF, 15, A8, B1, 42, 00, 8B, 0D, 0C, 69, 43, 00, 89, 08, FF, 15, B8, B1, 42, 00, 8B, 0D, 08, 69, 43, 00, 89, 08, A1, BC, B1, 42, 00, 8B, 00, A3, BC, 69, 43, 00, E8, DF, 4B, FE, FF, 39, 1D, F0, 4D, 43, 00, 75, 0C, 68, EC, 43, 42, 00, FF, 15, B4, B1...
 
[+]

Entropy:
5.2739

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Zone Labs Client

Command:
"C:\Program Files\zone labs\zonealarm\zlclient.exe"


Scan zlclient.exe - Powered by Reason Core Security