FortKnoxGUI.exe

NETGATE FortKnox Personal Firewall

NETGATE Technologies s.r.o.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FortKnoxPersonalFirewall’.
Publisher:
NETGATE Technologies s.r.o.  (signed and verified)

Product:
NETGATE FortKnox Personal Firewall

Description:
FortKnox Personal Firewall

Version:
5, 0, 905, 0

MD5:
5631619cb144824c22acd51ccd379696

SHA-1:
872c695b8f660356e65b6e0fef79bdca966eaced

SHA-256:
dba2c6bbe8c3e44b2cc3f1bbab8472f32c8df8d8e2ff445b8f5b4fb95c6779ae

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 2:11:10 PM UTC  (today)

File size:
2.5 MB (2,574,488 bytes)

Product version:
5, 0, 905, 0

Copyright:
Copyright © 2007-2010 NETGATE Technologies s.r.o.

Original file name:
FortKnoxGUI.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\netgate\fortknox personal firewall\fortknoxgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/11/2010 3:00:00 AM

Valid to:
4/21/2011 2:59:59 AM

Subject:
CN=NETGATE Technologies s.r.o., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NETGATE Technologies s.r.o., L=Prievidza, S=Slovakia, C=SK

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5EE5DB781772D3FD5EC631E549B3CACD

File PE Metadata
Compilation timestamp:
8/30/2010 2:24:35 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:wEODjhJ2A4zqOO8zmT0F7oPDJSYz+XzZTkTUQp+qASz2t9YHNrWG29k1i2ZRCsVD:AhN0F7oA6THp+qASz2t9YHNrWG29k1ie

Entry address:
0x127120

Entry point:
48, 8B, C4, 48, 81, EC, A8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, 7C, B4, 01, 00, 90, FF, 15, 7D, B4, 01, 00, 48, 8B, C8, 33, D2, 41, B8, 94, 00, 00, 00, FF, 15, AC, B4, 01, 00, 48, 8B, D8, 48, 85, C0, 75, 0A, B8, FF, 00, 00, 00, E9, 62, 02, 00, 00, C7, 00, 94, 00, 00, 00, 48, 8B, C8, FF, 15, DB, B2, 01, 00, 85, C0, 75, 1E, FF, 15, 41, B4, 01, 00, 48, 8B, C8, 4C, 8B, C3, 33, D2, FF, 15, 6B, B4, 01, 00, B8, FF, 00, 00, 00, E9, 31, 02, 00, 00, 8B, 43, 10, 89, 05, B4, 08, 09, 00...
 
[+]

Entropy:
5.9919

Code size:
1.3 MB (1,311,744 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FortKnoxPersonalFirewall

Command:
"C:\Program Files\netgate\fortknox personal firewall\fortknoxgui.exe"


Scan FortKnoxGUI.exe - Powered by Reason Core Security