shutdownservice.exe

zhaoping liu

It runs as a windows Service named “PCAutoShutdown_Service”.
Publisher:
GoldSolution Software, Inc.  (signed by zhaoping liu)

Description:
PC Auto Shutdown Service

Version:
5.0.0.0

MD5:
c39f942d214c312f26190883b1d94bd5

SHA-1:
382aebf91a6e8908f30be9e1c859c6b4051a7f71

SHA-256:
d77dce12e6278bbaffabdc1555bf130fd4530838836a23b3f9329bf9d5317e03

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 1:44:19 AM UTC  (today)

File size:
431.8 KB (442,136 bytes)

Product version:
5.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pc auto shutdown\shutdownservice.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/18/2010 8:00:00 AM

Valid to:
1/18/2013 7:59:59 AM

Subject:
CN=zhaoping liu, O=zhaoping liu, STREET="415 Gateway Drive, apt 33", L=Pacifica, S=CA, PostalCode=94044, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
5FDAFF1C5F7FF6330F6090FAA6CA4C47

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:yhoe/yy1XgX3iSt/5xMA5hU2HFKJCQFXA/ZeyCn:yW6ZQX3iStYt2leCINn

Entry address:
0x5A158

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 50, 9F, 45, 00, E8, 43, C2, FA, FF, A1, 48, C1, 45, 00, 8B, 00, 8B, 10, FF, 52, 34, A1, 48, C1, 45, 00, 8B, 00, 83, C0, 34, BA, BC, A1, 45, 00, E8, 2F, A4, FA, FF, 8B, 0D, E4, BF, 45, 00, A1, 48, C1, 45, 00, 8B, 00, 8B, 15, 38, 9D, 45, 00, 8B, 18, FF, 53, 30, A1, 48, C1, 45, 00, 8B, 00, 8B, 10, FF, 52, 38, 5B, E8, 3D, A2, FA, FF, 00, FF, FF, FF, FF, 18, 00, 00, 00, 50, 43, 20, 41, 75, 74, 6F, 20, 53, 68, 75, 74, 64, 6F, 77, 6E, 20, 53, 65, 72, 76, 69, 63, 65, 00, 00, 00, 00...
 
[+]

Entropy:
6.5671

Developed / compiled with:
Microsoft Visual C++

Code size:
356.5 KB (365,056 bytes)

Service
Display name:
PCAutoShutdown_Service

Type:
Win32OwnProcess, InteractiveProcess


Scan shutdownservice.exe - Powered by Reason Core Security