EPWD.exe

End Point Security

Check Point Software Technologies Ltd.

The executable EPWD.exe, “Check Point Endpoint Client Watchdog” has been detected as malware by 3 anti-virus scanners. It runs as a windows Service named “Check Point Endpoint Client Watchdog”.
Publisher:

Product:
End Point Security

Description:
Check Point Endpoint Client Watchdog

Version:
860011001

MD5:
788becd2fce082e9b2bea1e0c4917c12

SHA-1:
6b0bf43a8fef8691eeeeacad5a996fd19f9c9854

SHA-256:
c583da704f68880656dbd7e166f40c3a686ceafbc0cea8d9f06704cf4e925ccb

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/26/2024 3:20:55 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
357 KB (365,551 bytes)

Product version:
R80

Copyright:
2009 Copyright Check Point Software Technologies Ltd.

Original file name:
EPWD.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\checkpoint\endpoint connect\watchdog\epwd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/12/2014 5:00:00 AM

Valid to:
7/11/2017 4:59:59 AM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47E81C30F2CA2304E8F8BC304E44AB6F

File PE Metadata
Compilation timestamp:
10/22/2015 5:05:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x23555

Entry point:
E9, D1, D2, FE, FF, E9, 36, FD, FF, FF, CC, FF, 25, 68, 82, 42, 00, FF, 25, 6C, 82, 42, 00, FF, 25, 70, 82, 42, 00, FF, 25, 74, 82, 42, 00, FF, 25, 78, 82, 42, 00, FF, 25, 7C, 82, 42, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, 80, 82, 42, 00, FF, 25, 84, 82, 42, 00, FF, 25, 88, 82, 42, 00, FF, 25, 8C, 82, 42, 00, FF, 25, 90, 82, 42, 00, CC, CC, 83, 3D, 28, 78, 43, 00, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83, E4, F8, DD, 1C, 24, F2, 0F, 2C, 04, 24, C9, C3, 83, 3D, 28, 78, 43, 00, 00, 74, 11...
 
[+]

Entropy:
6.7736

Packer / compiler:
Xtreme-Protector v1.05

Code size:
153 KB (156,672 bytes)

Service
Display name:
Check Point Endpoint Client Watchdog

Service name:
EPWD

Description:
Check Point Endpoint Client Watchdog service

Type:
Win32OwnProcess, InteractiveProcess


Remove EPWD.exe - Powered by Reason Core Security