ScanMsg.exe

Quick Heal AntiVirus

Cat Computer Services (P) Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Messenger’.
Publisher:
Quick Heal Technologies (P) Ltd.  (signed by Cat Computer Services (P) Ltd.)

Product:
Quick Heal AntiVirus

Description:
Bulettin Application

Version:
2.0.0.1

MD5:
4788641e5db4b2b0ef1d6190f8e6c805

SHA-1:
475d423d4d9d1b53815bf536253e15d93d15bc26

SHA-256:
f3976770e02f92fb7b6201a0d5aafd6b188332f0c28b258be05100e6433c8e4f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/16/2024 8:33:30 PM UTC  (today)

File size:
213.4 KB (218,488 bytes)

Product version:
9.50

Copyright:
© Quick Heal Technologies (P) Ltd. All rights reserved.

Original file name:
ScanMsg.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\quick heal\quick heal antivirus plus\scanmsg.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/31/2006 5:30:00 AM

Valid to:
11/1/2008 5:29:59 AM

Subject:
CN=Cat Computer Services (P) Ltd., OU=Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cat Computer Services (P) Ltd., L=Pune, S=Maharashtra, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
501DF4EF3498E9EF63F6D44419879472

File PE Metadata
Compilation timestamp:
4/15/2008 7:06:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

Entry address:
0x23996

Entry point:
6A, 74, 68, 28, C3, 42, 00, E8, F6, 01, 00, 00, 33, DB, 89, 5D, E0, 53, 8B, 3D, 48, 0C, 43, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, AC, 11, 43, 00, 59, 83, 0D, 30, FF, 42, 00, FF, 83...
 
[+]

Entropy:
5.1738

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
164 KB (167,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Messenger

Command:
C:\Program Files2\quickh~1\quickh~1\scanmsg.exe


Scan ScanMsg.exe - Powered by Reason Core Security