trgui.exe

Check Point Endpoint Security

Check Point Software Technologies Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Check Point Endpoint Security’.
Publisher:
Check Point Software Technologies  (signed by Check Point Software Technologies Ltd.)

Product:
Check Point Endpoint Security

Description:
Check Point Endpoint Security GUI

Version:
0000

MD5:
ef92ce4ab487e6b89c98c0fdc2216c08

SHA-1:
af5de9cc23ab42aa955f2e0a18dfa530b7344ad4

SHA-256:
d535b2d0cdeb5519b2d7b0db5adf521b51df7f095b73d9f7dbed0b0a12267e0b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:30:41 PM UTC  (today)

File size:
783.2 KB (801,968 bytes)

Product version:
VPN E75.20 EA

Copyright:
© 2005-2009 Copyright Check Point Software Technologies Ltd

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\checkpoint\endpoint connect\trgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/20/2011 8:00:00 AM

Valid to:
5/6/2014 7:59:59 AM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FE2705892AA0E8E6B945D5EA25EDA74

File PE Metadata
Compilation timestamp:
8/1/2011 12:18:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:WPFgD3GK44bb7ptascn6sE4wX/CQILkLrsP3UG+yB+ygYCFC:VjGK44bb7pPsM/ILkLFNyB+ygYCA

Entry address:
0x7296F

Entry point:
55, 8B, EC, 6A, FF, 68, 58, AE, 48, 00, 68, A8, 2C, 47, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 08, 12, 48, 00, 59, 83, 0D, AC, CF, 4B, 00, FF, 83, 0D, B0, CF, 4B, 00, FF, FF, 15, 04, 12, 48, 00, 8B, 0D, 84, CF, 4B, 00, 89, 08, FF, 15, 00, 12, 48, 00, 8B, 0D, 80, CF, 4B, 00, 89, 08, A1, FC, 11, 48, 00, 8B, 00, A3, A8, CF, 4B, 00, E8, B7, 02, 00, 00, 39, 1D, B0, CD, 4B, 00, 75, 0C, 68, 92, 2C, 47, 00, FF, 15, F8, 11...
 
[+]

Entropy:
6.3476

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
512 KB (524,288 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Check Point Endpoint Security

Command:
"C:\Program Files\checkpoint\endpoint connect\trgui.exe"


Scan trgui.exe - Powered by Reason Core Security