FortKnoxGUI.exe

NETGATE FortKnox Personal Firewall

NETGATE Technologies s.r.o.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘FortKnoxPersonalFirewall’.
Publisher:
NETGATE Technologies s.r.o.  (signed and verified)

Product:
NETGATE FortKnox Personal Firewall

Description:
FortKnox Personal Firewall

Version:
5, 0, 305, 0

MD5:
1ce7750a85fd6491e284ea0a61562b7d

SHA-1:
cef1637e1a8c844c2ca2b0150e1ad37e7a6dec7e

SHA-256:
65cbc4896bd3c4debd4789673cf49abdfb9c20474b8552ca5595c410d5e69474

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 8:42:09 PM UTC  (today)

File size:
2.4 MB (2,524,240 bytes)

Product version:
5, 0, 305, 0

Copyright:
Copyright © 2007-2009 NETGATE Technologies s.r.o.

Original file name:
FortKnoxGUI.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\netgate\fortknox personal firewall\fortknoxgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2009 10:00:00 AM

Valid to:
4/21/2010 9:59:59 AM

Subject:
CN=NETGATE Technologies s.r.o., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NETGATE Technologies s.r.o., L=Prievidza, S=Slovakia, C=SK

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
09D2E437021CFDDDAECA807C2B36DE9B

File PE Metadata
Compilation timestamp:
11/17/2009 8:12:39 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:0urIrcVeTgWE8zCVTodMWjLcQfk28TVFwp+qASz2t9YHNrWG29k1i2ZRCsV9SWkg:99odMWjcOp+qASz2t9YHNrWG29k1i2Zf

Entry address:
0x11E8F0

Entry point:
48, 8B, C4, 48, 81, EC, A8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, AC, AC, 01, 00, 90, FF, 15, AD, AC, 01, 00, 48, 8B, C8, 33, D2, 41, B8, 94, 00, 00, 00, FF, 15, DC, AC, 01, 00, 48, 8B, D8, 48, 85, C0, 75, 0A, B8, FF, 00, 00, 00, E9, 62, 02, 00, 00, C7, 00, 94, 00, 00, 00, 48, 8B, C8, FF, 15, 0B, AB, 01, 00, 85, C0, 75, 1E, FF, 15, 71, AC, 01, 00, 48, 8B, C8, 4C, 8B, C3, 33, D2, FF, 15, 9B, AC, 01, 00, B8, FF, 00, 00, 00, E9, 31, 02, 00, 00, 8B, 43, 10, 89, 05, E4, D0, 08, 00...
 
[+]

Entropy:
5.9846

Code size:
1.2 MB (1,276,928 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
FortKnoxPersonalFirewall

Command:
"C:\Program Files\netgate\fortknox personal firewall\fortknoxgui.exe"


Scan FortKnoxGUI.exe - Powered by Reason Core Security