FGKey.exe

Folder Guard Professional Edition

WinAbility Software Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FG_Monitor’.
Publisher:
WinAbility® Software Corporation  (signed by WinAbility Software Corp.)

Product:
Folder Guard Professional Edition

Description:
Folder Guard Utility

Version:
7.91

MD5:
1872fcef859cf8c49fc952447b02f49f

SHA-1:
9e824d61c30e227498a39b0be893179b2adba033

SHA-256:
010812468888df4f5a01b338b1536d3a2b94824ccd5f0bcad13b017b115a39f0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:25:21 PM UTC  (today)

File size:
129.6 KB (132,680 bytes)

Product version:
7.91

Copyright:
Copyright © 2007 WinAbility® Software Corporation. All rights reserved.

Trademarks:
Folder Guard® and WinAbility® are registered trademarks or trademarks of WinAbility Software Corporation and/or its suppliers.

Original file name:
FGKey.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/3/2007 5:00:00 AM

Valid to:
1/4/2008 4:59:59 AM

Subject:
CN=WinAbility Software Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WinAbility Software Corp., L=Rockville, S=Utah, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1F7ECAC8BA1DA3C5C74A484095405998

File PE Metadata
Compilation timestamp:
4/17/2007 2:18:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:BWQfCC5yobFKQUWF8f2KFjg5wMpwBZUiRf0JrklTuUxV8wq5VO+NuXbvC:4Ib/UmKFM5wMwBZvf3O550+NB

Entry address:
0x2686

Entry point:
E8, 32, 37, 00, 00, E9, 17, FE, FF, FF, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, C4, 1C, 41, 00, 00, 74, 05, E9, EC, 37, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F, C3, 8B...
 
[+]

Entropy:
5.8212

Code size:
40 KB (40,960 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FG_Monitor

Command:
C:\programs\fguard\fgkey.exe \start


Scan FGKey.exe - Powered by Reason Core Security