FdSchedule.EXE

FdSchedule 응용 프로그램

FINAL DATA Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WPM’.
Publisher:
FinalData  (signed by FINAL DATA Inc.)

Product:
FdSchedule 응용 프로그램

Version:
1, 0, 0, 1

MD5:
9656bfd14b95f786ed26ca578c577efb

SHA-1:
3e5f4c0c039ad5c6b8b3d0922fdb930d840cc294

SHA-256:
4567b55bf9313892c81e5b18b1a987b74a33784969af9c6ae11e16703d7ac025

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:45:08 AM UTC  (today)

File size:
1.2 MB (1,254,592 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2010

Original file name:
FdSchedule.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\finaldata\wpm\fdschedule.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
4/1/2010 9:00:00 AM

Valid to:
4/1/2012 8:59:59 AM

Subject:
CN=FINAL DATA Inc., O=FINAL DATA Inc., L=SEOUL, S=GYEONGGI-DO, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
78FCF083D7C31C8291CB3F7C7EE2BE2A

File PE Metadata
Compilation timestamp:
8/26/2010 7:36:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:M6F43aa0eoCk2hp2EPcdznoNaSQ6ciy72hMDovQTMQbxNhZp5a/DvEAXV6Hnhtip:x2K5mk2h8EChiyShMDovQNfKlXV6BM

Entry address:
0xA5CF1

Entry point:
E8, 84, BD, 00, 00, E9, 16, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 40, D7, 4E, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 40, D7, 4E, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B...
 
[+]

Entropy:
6.2991

Code size:
768 KB (786,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WPM

Command:
"C:\Program Files\finaldata\wpm\fdschedule.exe" -startup


Scan FdSchedule.EXE - Powered by Reason Core Security