ca.exe

EZ Firewall

Zone Labs, Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Zone Labs Client’.
Publisher:
Computer Associates  (signed by Zone Labs, Inc)

Product:
EZ Firewall

Version:
4.5.554.000

MD5:
29ff8b681cc9e48c3833b8e531a258e6

SHA-1:
f5c045735bd21eb9a417b82b2c097a93c857de08

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:27:30 AM UTC  (today)

File size:
685.3 KB (701,720 bytes)

Product version:
4.5.554.000

Copyright:
Copyright © 1998-2003, Computer Associates..............

Original file name:
ca.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ca\etrust ez armor\etrust ez firewall\ca.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/24/2003 6:00:00 PM

Valid to:
3/22/2004 6:59:59 PM

Subject:
CN="Zone Labs, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zone Labs, Inc", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2001 CA, OU=Terms of use at https://www.verisign.com/rpa (c)01, OU=VeriSign Trust Network, O="VeriSign, Inc."

Serial number:
2D2E776409C2F2727258E02A43BEAF38

File PE Metadata
Compilation timestamp:
1/7/2004 11:45:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:c3cnEvk0diDiLO8f7pRNkzMw1auo7qzeYpIe2YoeX6UZ1dXwHPfeIEO6SieFd:c3yE8mqUf7pXkgEauoOx2YoeXxdKfe

Entry address:
0x1F4D2

Entry point:
55, 8B, EC, 6A, FF, 68, 30, 62, 42, 00, 68, 58, F6, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 90, 41, 42, 00, 59, 83, 0D, 00, BB, 42, 00, FF, 83, 0D, 04, BB, 42, 00, FF, FF, 15, 94, 41, 42, 00, 8B, 0D, DC, BA, 42, 00, 89, 08, FF, 15, 8C, 41, 42, 00, 8B, 0D, D8, BA, 42, 00, 89, 08, A1, A0, 41, 42, 00, 8B, 00, A3, FC, BA, 42, 00, E8, 6E, 6F, FE, FF, 39, 1D, D0, A4, 42, 00, 75, 0C, 68, 54, F6, 41, 00, FF, 15, 74, 41...
 
[+]

Entropy:
5.5754

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
136 KB (139,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Zone Labs Client

Command:
C:\Program Files1\ca\etrust~1\etrust~2\ca.exe


Scan ca.exe - Powered by Reason Core Security