FdSchedule.EXE

FdSchedule 응용 프로그램

FINAL DATA Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WPM’.
Publisher:
FinalData  (signed by FINAL DATA Inc.)

Product:
FdSchedule 응용 프로그램

Version:
1, 0, 0, 1

MD5:
75ea0b12e46b0c05552b1205315a800c

SHA-1:
729c7d928f1e6e6c838cdace1f2a307c7c6b80a1

SHA-256:
ce8c456cdf860f1a0e88a8ef9c7d9764a1f1b3a4c7c2d3062d6b34887639d0be

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/7/2024 3:17:26 PM UTC  (today)

File size:
833.5 KB (853,512 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2006

Original file name:
FdSchedule.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\finaldata\wpm\fdschedule.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/15/2007 3:16:59 PM

Valid to:
3/30/2008 4:25:36 PM

Subject:
CN=FINAL DATA Inc., OU=Software Development Department, O=FINAL DATA Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
18D1DF0B35EEE32A9146EDE022928FA9

File PE Metadata
Compilation timestamp:
12/9/2007 10:58:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x50E11

Entry point:
55, 8B, EC, 6A, FF, 68, 30, 0F, 48, 00, 68, D4, 3A, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, A0, B2, 47, 00, 33, D2, 8A, D4, 89, 15, 14, B7, 49, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 10, B7, 49, 00, C1, E1, 08, 03, CA, 89, 0D, 0C, B7, 49, 00, C1, E8, 10, A3, 08, B7, 49, 00, 6A, 01, E8, 54, 2F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 2B, 19, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.1504

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
488 KB (499,712 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WPM

Command:
"C:\Program Files\finaldata\wpm\fdschedule.exe" -startup


Scan FdSchedule.EXE - Powered by Reason Core Security