trgui.exe

Check Point Endpoint Security

Check Point Software Technologies Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Check Point VPN’.
Publisher:
Check Point Software Technologies  (signed by Check Point Software Technologies Ltd.)

Product:
Check Point Endpoint Security

Description:
Check Point Endpoint Security VPN GUI

Version:
80, 60, 0, 0

MD5:
bd54964919301b15f744a7873d940fdd

SHA-1:
8761cb5b5393a134ed19469cc6ef908378acb3f9

SHA-256:
ff5ac1fe5c88c07b0746c69d293658c1dbc7c1a23aa07a9d077ff2d91f331f5d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/4/2024 3:57:48 PM UTC  (today)

File size:
1.2 MB (1,263,384 bytes)

Product version:
VPN E80.64

Copyright:
© 2003-2014 Check Point Software Technologies Ltd.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\checkpoint\endpoint connect\trgui.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/21/2015 1:00:00 AM

Valid to:
12/21/2018 12:59:59 AM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
61D73145ADE15140CEE8B9F52BA0DF43

File PE Metadata
Compilation timestamp:
12/14/2016 12:43:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0xBA7F7

Entry point:
E8, 9E, 04, 00, 00, E9, 1C, FD, FF, FF, CC, FF, 25, D8, 21, 4D, 00, FF, 25, D4, 21, 4D, 00, 6A, 10, 68, D0, 93, 50, 00, E8, 76, 01, 00, 00, 33, C0, 89, 45, E0, 89, 45, FC, 89, 45, E4, 8B, 45, E4, 3B, 45, 10, 7D, 13, 8B, 75, 08, 8B, CE, FF, 55, 14, 03, 75, 0C, 89, 75, 08, FF, 45, E4, EB, E5, C7, 45, E0, 01, 00, 00, 00, C7, 45, FC, FE, FF, FF, FF, E8, 08, 00, 00, 00, E8, 7D, 01, 00, 00, C2, 14, 00, 83, 7D, E0, 00, 75, 11, FF, 75, 18, FF, 75, E4, FF, 75, 0C, FF, 75, 08, E8, 8B, FA, FF, FF, C3, 8B, FF, 55, 8B...
 
[+]

Code size:
834 KB (854,016 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Check Point VPN

Command:
"C:\Program Files\checkpoint\endpoint connect\trgui.exe"


Scan trgui.exe - Powered by Reason Core Security