ffPrivateAgent.exe

fideAS

Applied Security GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ffPrivate’.
Publisher:
Applied Security GmbH  (signed and verified)

Product:
fideAS

Description:
ffe Private Agent

Version:
6,1,0,6

MD5:
003c7bf84f08c6410fbd22364c77cdc7

SHA-1:
b12c527552ba863b9f02d290bbbd5a2756f283d4

SHA-256:
e302f3704341b1584f2231f22554915a56f4aa98bb0afe99b1de5c692f28d167

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 9:09:00 PM UTC  (today)

File size:
1.6 MB (1,650,672 bytes)

Product version:
6,1,0,6

Copyright:
Applied Security 2001 - 2014

Trademarks:
fideAS® is a registered trademark of Applied Security GmbH

Original file name:
ffPrivateAgent.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\apsec\fideas file enterprise\private agent\ffprivateagent.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/8/2013 2:00:00 AM

Valid to:
5/8/2016 1:59:59 AM

Subject:
CN=Applied Security GmbH, O=Applied Security GmbH, STREET=Einsteinstrasse 2a, L=Grosswallstadt, S=Bayern, PostalCode=63868, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0081A124DD2E58D6D23661F89EFBFA9B6C

File PE Metadata
Compilation timestamp:
4/7/2014 7:15:35 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:WdZ6nV4t3s1pZEFa1g0jDxYD+5OhIZNf+uQpOsk:WnDs1bvQhIZ4S

Entry address:
0x1047EC

Entry point:
E8, 97, 04, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, D4, 56, 00, 89, 0D, 04, D4, 56, 00, 89, 15, 00, D4, 56, 00, 89, 1D, FC, D3, 56, 00, 89, 35, F8, D3, 56, 00, 89, 3D, F4, D3, 56, 00, 66, 8C, 15, 20, D4, 56, 00, 66, 8C, 0D, 14, D4, 56, 00, 66, 8C, 1D, F0, D3, 56, 00, 66, 8C, 05, EC, D3, 56, 00, 66, 8C, 25, E8, D3, 56, 00, 66, 8C, 2D, E4, D3, 56, 00, 9C, 8F, 05, 18, D4, 56, 00, 8B, 45, 00, A3, 0C, D4, 56, 00, 8B, 45, 04, A3, 10, D4, 56, 00, 8D, 45, 08, A3, 1C, D4, 56...
 
[+]

Code size:
1.2 MB (1,207,808 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ffPrivate

Command:
"C:\Program Files\apsec\fideas file enterprise\private agent\ffprivateagent.exe"


Scan ffPrivateAgent.exe - Powered by Reason Core Security