viguard.exe

LANDesk Software

LANDesk Software, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘LANDesk Endpoint Security’.
Publisher:
LANDesk Software, Inc. and its affiliates  (signed by LANDesk Software, Inc.)

Product:
LANDesk Software

Description:
LANDesk Host Intrusion Prevention

Version:
9.00.2.221

MD5:
e94b5e31ddbdda027261fced3fe399a7

SHA-1:
0c6dca1f08e659454e39882d16714689f391575d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 11:47:58 PM UTC  (a few moments ago)

File size:
3.5 MB (3,639,104 bytes)

Product version:
9.00.2.221

Copyright:
Copyright © 2010 LANDesk Software, Inc. and its affiliates

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\landesk\ldclient\hips\viguard.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/6/2008 8:00:00 PM

Valid to:
10/7/2011 7:59:59 PM

Subject:
CN="LANDesk Software, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LANDesk Software, Inc.", L=South Jordan, S=Utah, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7FFC8730506903F99136F16CA6DF2B07

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:nrSaL6eizwsnZUSiM7Oanm8yFI9P+8s92VUcl3vxRAUUgPU4w:fOxBJiMTPEIVFsc3cpgQ

Entry address:
0x243EC0

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, E8, 89, 45, EC, B8, 50, 35, 64, 00, E8, 84, 37, DC, FF, 33, C0, 55, 68, 1D, 40, 64, 00, 64, FF, 30, 64, 89, 20, 33, D2, B0, 01, E8, C9, 51, E7, FF, E8, 50, F4, E6, FF, 6A, 00, A1, CC, C8, 64, 00, 8B, 00, 8B, 40, 30, 50, E8, 5E, 48, DC, FF, A1, CC, C8, 64, 00, 8B, 00, C6, 40, 5B, 00, B8, 34, 40, 64, 00, E8, 61, E1, E6, FF, E8, 08, F5, FF, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, BF, EC, DB, FF, 8B, 45, EC, BA, 58, 40, 64, 00, E8, 82, 12, DC, FF, 75, 05, E8, BF, 0C, DC...
 
[+]

Entropy:
6.6484

Developed / compiled with:
Microsoft Visual C++

Code size:
2.3 MB (2,372,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
LANDesk Endpoint Security

Command:
"C:\Program Files\landesk\ldclient\hips\viguard.exe" \startup


Scan viguard.exe - Powered by Reason Core Security