rfagent.exe

Registry First Aid Agent

Rose City Software

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘rfagent’.
Publisher:
KsL Software  (signed by Rose City Software)

Product:
Registry First Aid Agent

Description:
Registry First Aid Agent, the easy powerful registry maintenance program

Version:
7.0.0.1662

MD5:
cc21757caf31724c090b36f2339bb457

SHA-1:
ab2990e8f5f280032b00f2f9fef63b3cc18f8bb7

SHA-256:
f13003c02f1e31778f261c9c28b1f95679f18412c0e2c06b80f2ef6e5df0dde5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:34:15 AM UTC  (today)

File size:
895.3 KB (916,832 bytes)

Product version:
7.0.0.1662

Copyright:
Copyright (c) KsL Software, 2001-2009

Original file name:
rfagent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\rfa\rfagent.exe

Digital Signature
Authority:
GeoTrust Inc.

Valid from:
2/13/2008 1:34:58 AM

Valid to:
2/26/2009 1:34:58 AM

Subject:
E=jburke@infinisource.com, CN=Rose City Software, OU=Email and phone validated only., OU=Phone Validation - 1(503) 699-0463, OU=See Public S/MIME CPS www.geotrust.com/resources/CPS., OU=CPS terms incorporated by reference liability limited.

Issuer:
CN=GeoTrust True Credentials CA 2, O=GeoTrust Inc., C=US

Serial number:
108979

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:K1RyKSCdazuQe9CbDqeGZcMgmFsCqP2B+g6pZrj:IRXSg2e++eRmqh2567

Entry address:
0x42790

Entry point:
55, 8B, EC, 81, C4, F0, FE, FF, FF, 33, C0, 89, 45, F0, B8, D8, 25, 44, 00, E8, 30, 32, FC, FF, 33, C0, 55, 68, 5B, 28, 44, 00, 64, FF, 30, 64, 89, 20, 8D, 95, F0, FE, FF, FF, A1, 5C, C9, 43, 00, E8, 22, 05, FC, FF, 8D, 95, F0, FE, FF, FF, 8D, 45, F0, E8, C8, 12, FC, FF, 8B, 45, F0, E8, F0, 95, FE, FF, 84, C0, 74, 0E, B8, 70, 28, 44, 00, E8, AE, 9D, FE, FF, 84, C0, 74, 57, B8, 84, 28, 44, 00, E8, A0, 9D, FE, FF, 84, C0, 75, 49, B8, 94, 28, 44, 00, E8, 92, 9D, FE, FF, 84, C0, 75, 3B, A1, D8, 46, 44, 00, 8B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
262.5 KB (268,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
rfagent

Command:
"C:\Program Files\rfa\rfagent.exe"


Scan rfagent.exe - Powered by Reason Core Security