trgui.exe

Check Point Software Technologies Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Check Point Endpoint Connect’.
Publisher:

MD5:
8dcb26912b6585270ba34d8431d852d6

SHA-1:
a3850f1c06a5c6e71ac724d432e785f43db82614

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/13/2025 8:19:33 AM UTC  (today)

File size:
517.4 KB (529,808 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\checkpoint\endpoint connect\trgui.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/11/2008 1:00:00 AM

Valid to:
4/29/2009 1:59:59 AM

Subject:
CN=Check Point Software Technologies Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Check Point Software Technologies Ltd., L=Ramat-Gan, S=Ramat-Gan, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
378D50C7F313848BF0949DC36599C3F5

File PE Metadata
Compilation timestamp:
1/19/2009 11:18:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x48B20

Entry point:
55, 8B, EC, 6A, FF, 68, 40, A9, 45, 00, 68, 5E, 8E, 44, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, C8, 20, 45, 00, 59, 83, 0D, BC, D4, 47, 00, FF, 83, 0D, C0, D4, 47, 00, FF, FF, 15, D8, 20, 45, 00, 8B, 0D, B4, D4, 47, 00, 89, 08, FF, 15, D0, 20, 45, 00, 8B, 0D, B0, D4, 47, 00, 89, 08, A1, D4, 20, 45, 00, 8B, 00, A3, B8, D4, 47, 00, E8, BC, 02, 00, 00, 39, 1D, B8, D3, 47, 00, 75, 0C, 68, 48, 8E, 44, 00, FF, 15, E4, 20...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
324 KB (331,776 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Check Point Endpoint Connect

Command:
"C:\Program Files\checkpoint\endpoint connect\trgui.exe"


Scan trgui.exe - Powered by Reason Core Security