VpnConf.exe

TheGreenBow VPN Client

TheGreenBow

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘TgbVpn’. This is installed with TheGreenBow IPSec VPN Client.
Publisher:
TheGreenBow  (signed and verified)

Product:
TheGreenBow VPN Client

Version:
4.70

MD5:
88ce37f3522e5c1fb5ab01c945657f5a

SHA-1:
c5b6b1018f0c7f09366b7a8d698ce4b7c8efaef0

SHA-256:
ffee98a551098f51ad10cdb756c41dddd161180e4db82bd2e36352f1985f072d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:50:37 PM UTC  (today)

File size:
521.6 KB (534,072 bytes)

Product version:
4.70

Copyright:
© TheGreenBow 2010. All rights reserved.

Trademarks:
TheGreenBow

Original file name:
VpnConf.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\thegreenbow\thegreenbow vpn\vpnconf.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/14/2009 2:00:00 AM

Valid to:
8/24/2010 1:59:59 AM

Subject:
CN=TheGreenBow, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TheGreenBow, L=Paris, S=Paris, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2B2B7EF3A8EBB8F744E1A8557C67090B

File PE Metadata
Compilation timestamp:
6/28/2010 3:18:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:2wdGG1f9ASLfvm7A71quv7/0nkN6/VQhjKXRtWah6XRJ:265bfvxnzfN26jIzIXRJ

Entry address:
0x1AF6C0

Entry point:
60, BE, 00, 50, 54, 00, 8D, BE, 00, C0, EB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
428 KB (438,272 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
TgbVpn

Command:
"C:\Program Files\thegreenbow\thegreenbow vpn\vpnconf.exe"


The file VpnConf.exe has been discovered within the following program.

www.thegreenbow.com
About 1% of users remove it
 
Powered by Should I Remove It?

Scan VpnConf.exe - Powered by Reason Core Security