EECWATCH.EXE

Entrust Entelligence Security Provider

Entrust, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘espwatchdog’.
Publisher:
Entrust(R)  (signed by Entrust, Inc.)

Product:
Entrust Entelligence Security Provider

Description:
Entrust Entelligence Digital ID Monitor

Version:
9.2.10.3202

MD5:
2395003d3833058227f54462f3342304

SHA-1:
4993f64c0ef65ea09d907ab528f37cda4d5489f3

SHA-256:
8a4bb7e301a2fc3e507fd4f7cd8e3ec8dd9d2fa078943ad68060878ce8955a60

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 7:36:54 PM UTC  (today)

File size:
31.1 KB (31,840 bytes)

Product version:
9.2

Copyright:
Copyright 1994-2012 Entrust. All rights reserved.

Trademarks:
Entrust is a trademark or registered trademark of Entrust, Inc.

Original file name:
EECWATCH.EXE

File type:
Executable application (Win32 EXE)

Language:
English (Canada)

Common path:
C:\Program Files\common files\entrust\esp\eecwatch.exe

Digital Signature
Signed by:

Authority:
Entrust, Inc.

Valid from:
3/5/2012 1:24:13 PM

Valid to:
3/5/2015 11:47:18 PM

Subject:
CN="Entrust, Inc.", O="Entrust, Inc.", L=Kanata, ST=Ontario, C=CA

Issuer:
CN=Entrust Code Signing Certification Authority - L1D, OU="(c) 2009 Entrust, Inc.", OU=www.entrust.net/rpa is incorporated by reference, O="Entrust, Inc.", C=US

Serial number:
4C1710AE

File PE Metadata
Compilation timestamp:
5/28/2012 3:51:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:HwrtESL7AS1QdrTVftilmpT1EOa+n1Xd476IIL2+x6:HyESgcuBFpmOH1X/iT

Entry address:
0x3510

Entry point:
E8, 9E, 04, 00, 00, E9, 6B, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, C0, 65, 40, 00, 89, 0D, BC, 65, 40, 00, 89, 15, B8, 65, 40, 00, 89, 1D, B4, 65, 40, 00, 89, 35, B0, 65, 40, 00, 89, 3D, AC, 65, 40, 00, 66, 8C, 15, D8, 65, 40, 00, 66, 8C, 0D, CC, 65, 40, 00, 66, 8C, 1D, A8, 65, 40, 00, 66, 8C, 05, A4, 65, 40, 00, 66, 8C, 25, A0, 65, 40, 00, 66, 8C, 2D, 9C, 65, 40, 00, 9C, 8F, 05, D0, 65, 40, 00, 8B, 45, 00, A3, C4, 65, 40, 00, 8B, 45, 04, A3, C8, 65, 40, 00, 8D, 45, 08, A3, D4, 65, 40...
 
[+]

Entropy:
6.1445

Code size:
11.5 KB (11,776 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
espwatchdog

Command:
C:\Program Files\common files\entrust\esp\eecwatch.exe


Scan EECWATCH.EXE - Powered by Reason Core Security