forcefield.exe
ZoneAlarm Browser Security by Check Point Software Technologies Ltd. (Signed)
Version: | 1, 5, 393, 18 |
MD5: | 0fc23c1779922059afce60c5b8a91af5 |
SHA1: | df411203340476f997641599fdebe673fec784ea |
SHA256: | a493c9cc1e0d8e70d9abc23d847c87f91e08cb57027d4546b9e2e73f2d3265e3 |
What is forcefield.exe?
Check Point's ZoneAlarm ForceField is designed to secure Web browsing sessions through the use of browser virtualization, inline download scanning and DNS validation services.
About forcefield.exe (from Check Point Software Technologies Ltd.)
“Get ZoneAlarm ForceField for your browser. ForceField works hard at Web safety so you don't have to, but you should continue to browse with common sense in mind.”
Overview
forcefield.exe executes as a process with the local user's privileges typically within the context of its parent
iswsvc.exe (ZoneAlarm Browser Security by Check Point Software Technologies Ltd.). It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). The file is digitally signed by Check Point Software Technologies Ltd. which was issued by the VeriSign certificate authority (CA).
Details
File name: | forcefield.exe |
Publisher: | Check Point Software Technologies |
Product name: | ZoneAlarm Browser Security |
Typical file path: | C:\Program Files\checkpoint\zaforcefield\forcefield.exe |
File version: | 1, 5, 393, 18 |
Size: | 721.66 KB (738,984 bytes) |
Certificate |
Issued to: | Check Point Software Technologies Ltd. |
Authority (CA): | VeriSign |
Expiration date: | Monday, May 5, 2014 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C++ 8.0 |
.NET CLR: | No |
More details
Behaviors
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'ISW' → "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
Network connections
[TCP] 204.93.43.50:80
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00013929% | |
Kernel CPU: | 0.00009342% | |
User CPU: | 0.00004587% | |
Kernel CPU time: | 244,922 ms/min | |
Memory |
Private memory: | 38.27 MB | |
Private (maximum): | 31.33 MB | |
Private (minimum): | 896 KB | |
Non-paged memory: | 38.27 MB | |
Virtual memory: | 181.59 MB | |
Virtual memory (peak): | 216.52 MB | |
Working set: | 24.49 MB | |
Working set (peak): | 31.54 MB | |
Page faults: | 728,739/min | |
I/O |
I/O read transfer: | 2.69 KB/sec | |
I/O read operations: | 2/sec | |
I/O write transfer: | 108.07 KB/sec | |
I/O write operations: | 11/sec | |
I/O other transfer: | 6.31 KB/sec | |
I/O other operations: | 86/sec | |
Resource allocations |
Threads: | 34 | |
Handles: | 789 | |
GUI GDI count: | 106 | |
GUI USER count: | 24 | |
Process properties
Threads
Averages
ntdll.dll |
Total CPU: | 0.00670057% | |
Kernel CPU: | 0.00293553% | |
User CPU: | 0.00376504% | |
Memory: | 712 KB | |
ForceField.exe (main module) |
Total CPU: | 0.00007544% | |
Kernel CPU: | 0.00006560% | |
User CPU: | 0.00000984% | |
Memory: | 716 KB | |
Common loaded modules
These are modules that are typiclaly loaded within the context of this process.
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
51.85% |
|
Microsoft Windows XP |
14.81% |
|
Windows Vista Home Basic |
7.41% |
|
Windows 8 Pro |
7.41% |
|
Windows 7 Professional |
7.41% |
|
Windows 7 Ultimate N |
3.70% |
|
Windows Vista Ultimate |
3.70% |
|
Windows 7 Ultimate |
3.70% |
|
Distribution by country
United States installs about 55.56% of ZoneAlarm Browser Security.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
80.00% |
|
Acer |
20.00% |
|