FdSchedule.EXE

FdSchedule 응용 프로그램

FINAL DATA Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WPM’.
Publisher:
FinalData  (signed by FINAL DATA Inc.)

Product:
FdSchedule 응용 프로그램

Version:
1, 0, 0, 1

MD5:
42a867e119ea9d5b177f88c98b476470

SHA-1:
cd000ac660fc45ce7eee304fc805f9f83fb6c031

SHA-256:
f160c6f44019dd4acdad8864c29e799c7c83ecbf623f203dfa72684b32606b24

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 4:42:22 AM UTC  (today)

File size:
925.5 KB (947,728 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2009

Original file name:
FdSchedule.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hanjin_shipping\cdm\fdschedule.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
3/28/2008 11:18:24 AM

Valid to:
3/30/2010 5:49:52 PM

Subject:
CN=FINAL DATA Inc., OU=Software Development Department, O=FINAL DATA Inc., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
074BD0F320E254D8DBFA215F8EC88776

File PE Metadata
Compilation timestamp:
6/26/2009 2:49:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x5E16A

Entry point:
55, 8B, EC, 6A, FF, 68, F8, F8, 48, 00, 68, 44, 0E, 46, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 9C, 92, 48, 00, 33, D2, 8A, D4, 89, 15, 84, DC, 4A, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 80, DC, 4A, 00, C1, E1, 08, 03, CA, 89, 0D, 7C, DC, 4A, 00, C1, E8, 10, A3, 78, DC, 4A, 00, 6A, 01, E8, 6B, 2F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 42, 19, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.1216

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
544 KB (557,056 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WPM

Command:
"C:\Program Files\hanjin_shipping\cdm\fdschedule.exe" -startup


Scan FdSchedule.EXE - Powered by Reason Core Security