winpatrol.exe

WinPatrol Monitor

BillP Studios

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WinPatrol’. This is installed with WinPatrol.
Publisher:
BillP Studios  (signed and verified)

Product:
WinPatrol Monitor

Description:
WinPatrol System Monitor

Version:
20.0.2011.1

MD5:
b4930cabafa071373930062d6022a096

SHA-1:
f49169611a6ce366d43f847d9ce9e480bfc53964

SHA-256:
78d2960ee583135eb6f5e2de273ef616f8cf13d96964bf6e22e79fd87b22a17c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 3:37:14 PM UTC  (today)

File size:
317.4 KB (325,000 bytes)

Product version:
20.0.2011.1

Copyright:
Copyright © 1997- 2011 BillP Studios

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/12/2010 7:00:00 PM

Valid to:
6/10/2011 6:59:59 PM

Subject:
CN=BillP Studios, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BillP Studios, L=Scotia, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2CB9D8F0974B6E42054FC171E0C47C2A

File PE Metadata
Compilation timestamp:
3/15/2011 2:27:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:dq/NrRY1bLGIzT5XJ+pPy2k/nNxj2KuRMT/nmCK/44GiVAyD26uEmbrGiFj1+RqB:dq1rRmbnzTf+YPrl63GiVT1Oqrg

Entry address:
0x1765

Entry point:
E8, 95, 35, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D8, 64, 42, 00, 89, 0D, D4, 64, 42, 00, 89, 15, D0, 64, 42, 00, 89, 1D, CC, 64, 42, 00, 89, 35, C8, 64, 42, 00, 89, 3D, C4, 64, 42, 00, 66, 8C, 15, F0, 64, 42, 00, 66, 8C, 0D, E4, 64, 42, 00, 66, 8C, 1D, C0, 64, 42, 00, 66, 8C, 05, BC, 64, 42, 00, 66, 8C, 25, B8, 64, 42, 00, 66, 8C, 2D, B4, 64, 42, 00, 9C, 8F, 05, E8, 64, 42, 00, 8B, 45, 00, A3, DC, 64, 42, 00, 8B, 45, 04, A3, E0, 64, 42, 00, 8D, 45, 08, A3, EC, 64, 42...
 
[+]

Entropy:
6.1424

Code size:
113 KB (115,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinPatrol

Command:
C:\winpatrol\winpatrol.exe -expressboot


The file winpatrol.exe has been discovered within the following program.

WinPatrol  by BillP Studios
Publisher's description - “WinPatrol monitors and exposes adware, keyloggers, spyware, worms, cookies, and other malicious software. This program puts you back in control of your computer with no need for constant updates.”
www.winpatrol.com
3% remove it
 
Powered by Should I Remove It?

Scan winpatrol.exe - Powered by Reason Core Security