ERunAs.exe

Encrypted RunAs

Wingnut Software

Publisher:
Wingnut Software  (signed and verified)

Product:
Encrypted RunAs

Version:
1.01.0012

MD5:
87685826b730db4d98e58c627f942c33

SHA-1:
6b40dfcb7508d7745354adeaf5a281e2e386bc41

SHA-256:
bc4f15810c4f501c82d94b090973d3b611516366c7d939332913f1cfc8495bb5

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
5/3/2024 7:03:26 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Vba32 AntiVirus
SScope.Malware-Cryptor.VBCR.1841
3.12.26.3

File size:
63.7 KB (65,264 bytes)

Product version:
1.01.0012

Copyright:
(c) 2004-2006 Wingnut Software

Original file name:
ERunAs.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\erunas.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/15/2008 7:00:00 PM

Valid to:
3/16/2009 6:59:59 PM

Subject:
CN=Wingnut Software, O=Wingnut Software, STREET=10 Akeman Drive, STREET=Bracebridge Heath, L=Lincoln, S=Lincolnshire, PostalCode=LN4 2TL, C=GB

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
008EC4C05E5D63A65FCA3876031D4117D7

File PE Metadata
Compilation timestamp:
1/6/2009 7:53:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:6WkPMenMsubKnOdUyWF62kNd/xRhD5kR/3DMa3fcyEjIYF:EMenMphdo0/XZ5kRrMq0y+Im

Entry address:
0x1220

Entry point:
B8, 88, 2B, 43, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 88, 69, D5, FA, 7D, 96, 31, A7, 6F, 1F, 7B, 1D, 99, 7B, 94, 27, 58, FD, 08, 30, AA, 17, 0E, E7, 52, FB, CF, 76, B3, 82, D4, AA, FD, E6, 6A, 25, 6B, 3A, 72, D3, CC, 8A, 32, E5, A9, 48, B6, 76, D9, B4, 5F, 0D, E8, 8F, AA, B9, DA, 91, D5, 50, CB, 2B, 35, 09, E3, A6, 39, 24, D2, 62, 98, 7B, 6F, 4A, 2F, A5, 5C, 32, 44, 3A, 36, 8F, 8F, 53, 2C, FD, 00, B0, 75, 97, 87, 25, 67...
 
[+]

Entropy:
7.9198

Packer / compiler:
PECompact v2

Code size:
176 KB (180,224 bytes)

Scan ERunAs.exe - Powered by Reason Core Security