rfwmain.EXE

Rising Personal FireWall 2008

Beijing Rising Science and Technology Corporation Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RfwMain’.
Publisher:
Beijing Rising Technology Co., Ltd.  (signed by Beijing Rising Science and Technology Corporation Limited)

Product:
Rising Personal FireWall 2008

Description:
Rising Personal FireWall Main Program

Version:
7.0.1.60

MD5:
a5ed5e664436d0980834e04cfeec97d0

SHA-1:
b394c31010d758d74335339fd0411ab562fb9bdf

SHA-256:
21865dde4de3b198032a0ddf237c317d37b2a4448b755518fce1cbf73b6d2da3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:00:55 PM UTC  (today)

File size:
562.6 KB (576,112 bytes)

Product version:
7.00

Copyright:
Rising Corp. All rights reserved.

Original file name:
rfwmain.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\rising\rfw\rfwmain.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/7/2007 9:00:00 AM

Valid to:
2/8/2008 8:59:59 AM

Subject:
CN=Beijing Rising Science and Technology Corporation Limited, OU=Networking Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Beijing Rising Science and Technology Corporation Limited, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5FEF736A627121BD63EBE8EAF8F9DFDB

File PE Metadata
Compilation timestamp:
1/22/2008 12:15:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x2BE72

Entry point:
6A, 74, 68, 08, 7C, 43, 00, E8, F6, 01, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, F0, 11, 43, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, A8, 17, 43, 00, 59, 83, 0D, 00, 3D, 44, 00, FF, 83...
 
[+]

Entropy:
6.2559

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
192 KB (196,608 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RfwMain

Command:
"C:\Program Files\rising\rfw\rfwmain.exe" -startup


Scan rfwmain.EXE - Powered by Reason Core Security