EEKAS.EXE

Entrust Entelligence Security Provider

Entrust, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘eekas’.
Publisher:
Entrust(R)  (signed by Entrust, Inc.)

Product:
Entrust Entelligence Security Provider

Description:
Entrust Entelligence Key Access Service Application

Version:
9.2.0.3186

MD5:
bbeb403e0bc13a4353a95c60444ffbcc

SHA-1:
9649f7a4090ab2924d60bc9bfd67f902d39b7ff7

SHA-256:
bdf14d8a5290cdcbc6c797521524439bdbf7c78f9612f963bd9542ad683b8db7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 4:03:06 AM UTC  (today)

File size:
442.5 KB (453,168 bytes)

Product version:
9.2

Copyright:
Copyright 1994-2012 Entrust. All rights reserved.

Trademarks:
Entrust is a trademark or registered trademark of Entrust, Inc.

Original file name:
EEKAS.EXE

File type:
Executable application (Win32 EXE)

Language:
English (Canada)

Common path:
C:\Program Files\common files\entrust\esp\eekas.exe

Digital Signature
Signed by:

Authority:
Entrust, Inc.

Valid from:
11/13/2009 4:19:59 PM

Valid to:
11/12/2012 4:47:59 PM

Subject:
CN="Entrust, Inc.", O="Entrust, Inc.", L=Ottawa, ST=Ontario, C=CA

Issuer:
CN=Entrust Code Signing Certification Authority - L1D, OU="(c) 2009 Entrust, Inc.", OU=www.entrust.net/rpa is incorporated by reference, O="Entrust, Inc.", C=US

Serial number:
4A0881EC

File PE Metadata
Compilation timestamp:
2/17/2012 8:20:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:xuqGHszWqCY16wYNwKPCZfP+NH7AdDyiUu61:xdEoXKPCZfP+NbA/+

Entry address:
0x51EFC

Entry point:
E8, 72, 05, 00, 00, E9, 6B, FD, FF, FF, FF, 25, E8, 62, 45, 00, FF, 25, EC, 62, 45, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 80, F9, 40, 73, 16, 80, F9, 20, 73, 06, 0F, AD, D0, D3, FA, C3, 8B, C2, C1, FA, 1F, 80, E1, 1F, D3, F8, C3, C1, FA, 1F, 8B, C2, C3, CC, FF, 25, F4, 62, 45, 00, FF, 25, F8, 62, 45, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, A8, 12, 46, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3...
 
[+]

Code size:
338.5 KB (346,624 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
eekas

Command:
C:\Program Files\common files\entrust\esp\eekas.exe


Scan EEKAS.EXE - Powered by Reason Core Security