EvalPostExpire.exe

Wise For Windows Installer

Altiris Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WfwiEvalPostExpire’.
Publisher:
Altiris  (signed by Altiris Inc)

Product:
Wise For Windows Installer

Description:
EvalPostExpire

Version:
7.03.0.250

MD5:
a0bc3f1c263bca1c961eba7870df8cd0

SHA-1:
ad8917a902a2538d6f1bca4f3f29ac48f2541568

SHA-256:
6a32a470b84510c5c7c19cf023fc51ed3b9b8fed598f3ca208a4eaa62e7534de

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 7:44:40 PM UTC  (today)

File size:
471.1 KB (482,368 bytes)

Product version:
7.03

Copyright:
(c) Altiris All rights reserved.

Original file name:
EvalPostExpire.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\altiris\wise\windows installer editor\evalpostexpire.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/14/2007 3:30:00 AM

Valid to:
1/13/2009 3:29:59 AM

Subject:
CN=Altiris Inc, OU=Engineering Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Altiris Inc, L=Lindon, S=UTAH, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6BADDB11A0AB4A63A17EC5B847DB9328

File PE Metadata
Compilation timestamp:
11/21/2007 12:45:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:9E0RGc9Riu4wzI9LLfiVcqYQTsOLNxlFwFVmKSfFqe+WK8Y6Q0i0KWNQhbUyo:9nj9j4B9LOVMQTsOBzVK8PijWShoyo

Entry address:
0x1ABD1

Entry point:
6A, 60, 68, 48, CB, 43, 00, E8, 0F, 31, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, 07, FF, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 00, 82, 43, 00, 8B, 4E, 10, 89, 0D, 5C, 9A, 44, 00, 8B, 46, 04, A3, 68, 9A, 44, 00, 8B, 56, 08, 89, 15, 6C, 9A, 44, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, 60, 9A, 44, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, 60, 9A, 44, 00, C1, E0, 08, 03, C2, A3, 64, 9A, 44, 00, 33, F6, 56, 8B, 3D, 64, 82, 43, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Entropy:
6.5941

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
220 KB (225,280 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WfwiEvalPostExpire

Command:
C:\Program Files\altiris\wise\windows installer editor\evalpostexpire.exe


Scan EvalPostExpire.exe - Powered by Reason Core Security