FdSchedule.EXE

FdSchedule 응용 프로그램

FINAL DATA Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WPM’.
Publisher:
FinalData  (signed by FINAL DATA Inc.)

Product:
FdSchedule 응용 프로그램

Version:
1, 0, 0, 1

MD5:
c52cb3f23372b1f1ee8d49cf2d0628dd

SHA-1:
4b599a8ea24e0e57ce2f8eeda165d40d6f1bc6eb

SHA-256:
896611c23c3d94ff6da0a034fc8a2a920eceed0535a3972bfc42596d9d824378

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:27:26 AM UTC  (today)

File size:
909.5 KB (931,344 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2008

Original file name:
FdSchedule.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\finaldata\wpm\fdschedule.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/28/2008 11:18:24 AM

Valid to:
3/30/2010 5:49:52 PM

Subject:
CN=FINAL DATA Inc., OU=Software Development Department, O=FINAL DATA Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
074BD0F320E254D8DBFA215F8EC88776

File PE Metadata
Compilation timestamp:
7/23/2008 5:08:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x5A91A

Entry point:
55, 8B, EC, 6A, FF, 68, 30, C8, 48, 00, 68, C0, DE, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 9C, 62, 48, 00, 33, D2, 8A, D4, 89, 15, 7C, 97, 4A, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 78, 97, 4A, 00, C1, E1, 08, 03, CA, 89, 0D, 74, 97, 4A, 00, C1, E8, 10, A3, 70, 97, 4A, 00, 6A, 01, E8, 37, 38, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, E2, 21, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.1716

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
532 KB (544,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WPM

Command:
"C:\Program Files\finaldata\wpm\fdschedule.exe" -startup


Scan FdSchedule.EXE - Powered by Reason Core Security