WFMSAlert.exe

Trend Micro Worry-Free Managed Security

Trend Micro, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VMS Alert Monitor’.
Publisher:
Trend Micro Inc.  (signed by Trend Micro, Inc.)

Product:
Trend Micro Worry-Free Managed Security

Description:
WFMSAlert

Version:
2.1.0.1106

MD5:
88d2509310591040e38f00fa8dcc0feb

SHA-1:
cf5fc31c6c892a547ee5eb1f6407677b3046ba1c

SHA-256:
c548c11efef5689f6a55f081ec685659f0b9efcf45939c0fc6736f46c789fca4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:22:34 AM UTC  (today)

File size:
257 KB (263,192 bytes)

Product version:
2.1

Copyright:
Copyright (C) 2013 Trend Micro Incorporated. All rights reserved.

Trademarks:
Copyright (C) Trend Micro Inc.

Original file name:
WFMSAlert.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\trend micro\ragent\wfmsalert.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/17/2013 9:00:00 AM

Valid to:
3/19/2014 8:59:59 AM

Subject:
CN="Trend Micro, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Trend Micro, Inc.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1A9D178AD334ACDF47C8A0D15BB50E6E

File PE Metadata
Compilation timestamp:
8/21/2013 12:14:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:EQJMGSq+/5iMWLc+PG/L7jHSokcGptyIkUp7i7LiyvBS6j/fGhVv4RuXJBehGwtB:S5q+jWZPG//+d3yIn7Uh/+sR8eXR

Entry address:
0x10A33

Entry point:
E8, D9, E3, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 51, 51, 8D, 45, F8, 50, FF, 15, 80, 41, 43, 00, 8B, 45, F8, 8B, 4D, FC, 6A, 00, 05, 00, 80, C1, 2A, 68, 80, 96, 98, 00, 81, D1, 21, 4E, 62, FE, 51, 50, E8, 45, E4, 00, 00, 8B, 4D, 08, 85, C9, 74, 02, 89, 01, C9, C3, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 0C, 75, 1D, E8, 61, 3C, 00, 00, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, 55, F9, FF, FF, 83, C4, 14, 83, C8, FF, EB, 4E, 8B, 45, 08, 3B, C3, 74, DC, 56, FF, 75, 14, 89, 45, E8, FF, 75, 10, 89...
 
[+]

Entropy:
6.4242

Code size:
204 KB (208,896 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VMS Alert Monitor

Command:
C:\Program Files\trend micro\ragent\wfmsalert.exe


Scan WFMSAlert.exe - Powered by Reason Core Security