trgui.exe

Check Point Endpoint Security

Check Point Software Technologies Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Check Point Endpoint Connect’.
Publisher:
Check Point Software Technologies  (signed by Check Point Software Technologies Ltd.)

Product:
Check Point Endpoint Security

Description:
Check Point Endpoint Security GUI

Version:
0000

MD5:
3b06c1463a061ad2da9587b7804be0fc

SHA-1:
7cbb2860e3125a32166788904cf4fde7f17e091e

SHA-256:
a39437e9cdc06b0acbce82977380ff61a2696dfec1c7915b590faa2a8ad5540d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/4/2024 3:11:07 AM UTC  (today)

File size:
625.5 KB (640,520 bytes)

Product version:
NGX R72

Copyright:
© 2005-2009 Copyright Check Point Software Technologies Ltd

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\checkpoint\endpoint security\endpoint connect\trgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/15/2010 1:00:00 AM

Valid to:
5/7/2011 12:59:59 AM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
423CF39BF1562989CB58D04FCD33D128

File PE Metadata
Compilation timestamp:
12/4/2010 10:58:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x5A644

Entry point:
55, 8B, EC, 6A, FF, 68, A0, F1, 46, 00, 68, 82, A9, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 30, 61, 46, 00, 59, 83, 0D, 44, 8F, 49, 00, FF, 83, 0D, 48, 8F, 49, 00, FF, FF, 15, 34, 61, 46, 00, 8B, 0D, 1C, 8F, 49, 00, 89, 08, FF, 15, 38, 61, 46, 00, 8B, 0D, 18, 8F, 49, 00, 89, 08, A1, 3C, 61, 46, 00, 8B, 00, A3, 40, 8F, 49, 00, E8, BC, 02, 00, 00, 39, 1D, 80, 8D, 49, 00, 75, 0C, 68, 6C, A9, 45, 00, FF, 15, 40, 61...
 
[+]

Entropy:
6.3232

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
404 KB (413,696 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Check Point Endpoint Connect

Command:
"C:\Program Files\checkpoint\endpoint security\endpoint connect\trgui.exe"


Scan trgui.exe - Powered by Reason Core Security