vetmsg.exe

Computer Associates Antivirus

Computer Associates International

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VetAlert’.
Publisher:
Computer Associates International, Inc.  (signed by Computer Associates International)

Product:
Computer Associates Antivirus

Description:
CA Antivirus Realtime Messaging Service

Version:
Version 11.0.5.3

MD5:
80c5e94438c1818f9e8fb7095d598d9a

SHA-1:
9fb27200ce57a2a02c1d9677da22c173c812f988

SHA-256:
47c9d1b11eba76e0a1c4092ea6cfd67ea4b96dd8866e0f0b3e42950635409c1c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:58:49 PM UTC  (today)

File size:
193.1 KB (197,744 bytes)

Product version:
Version 11.0.5.3

Copyright:
© 2004 Computer Associates International, Inc.

Trademarks:
Trademark of Computer Associates International, Inc.

Original file name:
vetmsg.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ca\etrust ez armor\etrust ez antivirus\vetmsg.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/15/2004 2:00:00 AM

Valid to:
5/13/2005 1:59:59 AM

Subject:
CN=Computer Associates International, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Computer Associates International, L=Islandia, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2001 CA, OU=Terms of use at https://www.verisign.com/rpa (c)01, OU=VeriSign Trust Network, O="VeriSign, Inc."

Serial number:
79F1AC18EBAACD3048D7DFAE282E2214

File PE Metadata
Compilation timestamp:
12/10/2004 8:32:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:SNA4kU0aMhv4bdYQQpCrtai3mT0ZUe91CnYcqu6VD/VkVBIL9Uotkl6NuFFc3BlG:ieaMR6dVMbi3m7ezzcqu6BVaYHhBlve

Entry address:
0x15995

Entry point:
6A, 60, 68, 18, 67, 42, 00, E8, 2F, 1D, 00, 00, BF, 94, 00, 00, 00, 8B, C7, E8, F3, FD, FF, FF, 89, 65, E8, 8B, F4, 89, 3E, 56, FF, 15, 28, 31, 42, 00, 8B, 4E, 10, 89, 0D, A4, DB, 42, 00, 8B, 46, 04, A3, B0, DB, 42, 00, 8B, 56, 08, 89, 15, B4, DB, 42, 00, 8B, 76, 0C, 81, E6, FF, 7F, 00, 00, 89, 35, A8, DB, 42, 00, 83, F9, 02, 74, 0C, 81, CE, 00, 80, 00, 00, 89, 35, A8, DB, 42, 00, C1, E0, 08, 03, C2, A3, AC, DB, 42, 00, 33, F6, 56, 8B, 3D, 98, 30, 42, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.0

Code size:
136 KB (139,264 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VetAlert

Command:
C:\Program Files2\ca\etrust ez armor\etrust ez antivirus\vetmsg.exe


Scan vetmsg.exe - Powered by Reason Core Security