rfagent64.exe

Registry First Aid

Rose City Software LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘rfagent’.
Publisher:
KsL Software  (signed by Rose City Software LLC)

Product:
Registry First Aid

Description:
Registry First Aid Agent

Version:
9.1.0.2160

MD5:
f87ac5ef95442bfff7778148b19d412d

SHA-1:
a76b1444876a4f22b2b46d119dc12345bd7d9f17

SHA-256:
9d2fbc3344d5fc000c1cc18f8a5d6e895b472d50050eb2e619ac3e97b5050f7e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 7:43:18 AM UTC  (today)

File size:
3.1 MB (3,279,536 bytes)

Product version:
9.1.0.2160

Copyright:
Copyright (c) KsL Software, 2001-2013

Trademarks:
Registry First Aid of KsL Software

Original file name:
reg1aid.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\rfa 9\rfagent64.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/2/2012 12:00:00 AM

Valid to:
10/2/2013 11:59:59 PM

Subject:
CN=Rose City Software LLC, O=Rose City Software LLC, STREET="3 Monroe Pkwy, Suite P-447", L=Lake Oswego, S=OR, PostalCode=97035, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
31DBEEA1420453795699B4648FD59717

File PE Metadata
OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.62

CTPH (ssdeep):
49152:ED4qF0KKr9fUU+dHPREVy44AkuiZM+eRmqU4:JqFUp+lPRp7lh2U

Entry address:
0x15990

Entry point:
48, 83, EC, 28, C6, 05, 35, E9, 1A, 00, 00, E8, C0, EE, FF, FF, 48, 83, C4, 28, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 55, 48, 89, E5, 48, 83, EC, 10, 65, 48, A1, 08, 00, 00, 00, 00, 00, 00, 00, 65, 48, 2B, 04, 25, 10, 00, 00, 00, C9, C3, 00, 00, 48, 83, EC, 28, 48, 89, 5C, 24, 20, 48, B9, 00, 00, 00, 01, 00, 00, 00, 00, E8, C8, FF, FF, FF, 48, 89, C3, 48, 8B, 05, 2E, 56, 27, 00, 48, 85, C0, 74, 0B, 8B, 0D, F3, 62, 27, 00, 48, FF, D0, EB, 07, 48, 8D, 05, EF, 62, 27, 00, 48, 89, 18, 48, 8B, 05, 0D...
 
[+]

Code size:
1.8 MB (1,840,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
rfagent

Command:
"C:\Program Files\rfa 9\rfagent64.exe"


Scan rfagent64.exe - Powered by Reason Core Security