rfagent.exe

Registry First Aid Agent

Rose City Software

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘rfagent’.
Publisher:
KsL Software  (signed by Rose City Software)

Product:
Registry First Aid Agent

Description:
Registry First Aid Agent, the easy powerful registry maintenance program

Version:
7.0.0.1658

MD5:
77aed6ac2581f6d15d42c422a7656b6e

SHA-1:
b15dfcd8467d9d3a040824e901adaf632ff7018b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:43:00 AM UTC  (today)

File size:
895.3 KB (916,800 bytes)

Product version:
7.0.0.1658

Copyright:
Copyright (c) KsL Software, 2001-2008

Original file name:
rfagent.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\rfa\rfagent.exe

Digital Signature
Authority:
GeoTrust Inc.

Valid from:
2/13/2008 9:34:58 AM

Valid to:
2/26/2009 9:34:58 AM

Subject:
E=jburke@infinisource.com, CN=Rose City Software, OU=Email and phone validated only., OU=Phone Validation - 1(503) 699-0463, OU=See Public S/MIME CPS www.geotrust.com/resources/CPS., OU=CPS terms incorporated by reference liability limited.

Issuer:
CN=GeoTrust True Credentials CA 2, O=GeoTrust Inc., C=US

Serial number:
108979

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:TJRya3OuYX+/gDKQ70/CbDqeGZcMgmFsCqP2B+g6pZrZ:tRd3OumDKQY4+eRmqh25671

Entry address:
0x4273C

Entry point:
55, 8B, EC, 81, C4, F0, FE, FF, FF, 33, C0, 89, 45, F0, B8, 84, 25, 44, 00, E8, 84, 32, FC, FF, 33, C0, 55, 68, 07, 28, 44, 00, 64, FF, 30, 64, 89, 20, 8D, 95, F0, FE, FF, FF, A1, 5C, C9, 43, 00, E8, 76, 05, FC, FF, 8D, 95, F0, FE, FF, FF, 8D, 45, F0, E8, 1C, 13, FC, FF, 8B, 45, F0, E8, 44, 96, FE, FF, 84, C0, 74, 0E, B8, 1C, 28, 44, 00, E8, 02, 9E, FE, FF, 84, C0, 74, 57, B8, 30, 28, 44, 00, E8, F4, 9D, FE, FF, 84, C0, 75, 49, B8, 40, 28, 44, 00, E8, E6, 9D, FE, FF, 84, C0, 75, 3B, A1, D8, 46, 44, 00, 8B...
 
[+]

Entropy:
6.0708

Developed / compiled with:
Microsoft Visual C++

Code size:
262.5 KB (268,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
rfagent

Command:
"C:\Program Files\rfa\rfagent.exe"


Scan rfagent.exe - Powered by Reason Core Security