FdSchedule.EXE

FdSchedule 응용 프로그램

FINAL DATA Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WPM’.
Publisher:
FinalData  (signed by FINAL DATA Inc.)

Product:
FdSchedule 응용 프로그램

Version:
1, 0, 0, 1

MD5:
6367284af18b6e4e393a4e519794051e

SHA-1:
4b245f709ddd132c3b8cc3e4d4deaa4a052c4a79

SHA-256:
35dc4e59c81a3ea666196bc917fab44dd615a0997f7a7f49d32bd21f91af4dc7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:57:00 AM UTC  (today)

File size:
893.5 KB (914,952 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2008

Original file name:
FdSchedule.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\finaldata\wpm\fdschedule.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/28/2008 11:18:24 AM

Valid to:
3/30/2010 5:49:52 PM

Subject:
CN=FINAL DATA Inc., OU=Software Development Department, O=FINAL DATA Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
074BD0F320E254D8DBFA215F8EC88776

File PE Metadata
Compilation timestamp:
9/19/2008 5:22:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x5A99A

Entry point:
55, 8B, EC, 6A, FF, 68, D8, C8, 48, 00, 68, 74, D6, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 9C, 62, 48, 00, 33, D2, 8A, D4, 89, 15, BC, 97, 4A, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, B8, 97, 4A, 00, C1, E1, 08, 03, CA, 89, 0D, B4, 97, 4A, 00, C1, E8, 10, A3, B0, 97, 4A, 00, 6A, 01, E8, 6B, 2F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 42, 19, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.1400

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
532 KB (544,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WPM

Command:
"C:\Program Files\finaldata\wpm\fdschedule.exe" -startup


Scan FdSchedule.EXE - Powered by Reason Core Security