VeraCrypt.exe

VeraCrypt

IDRIX

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘VeraCrypt’.
Publisher:
IDRIX  (signed and verified)

Product:
VeraCrypt

Version:
1.20-BETA1

MD5:
4da62548db7c39d94fcc912b71c33f2e

SHA-1:
8fc9f445dce51ba8d3f08ae612ac17668cb3af0a

SHA-256:
1cf13bffa6c7a0a20033e6a26fb3e16a6a6a51959a5b4b123ea5ff357629616f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 12:59:05 AM UTC  (today)

File size:
5.3 MB (5,576,848 bytes)

Product version:
1.20-BETA1

Trademarks:
VeraCrypt

Original file name:
VeraCrypt.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\veracrypt\veracrypt.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/16/2016 1:00:00 AM

Valid to:
4/30/2018 1:59:59 AM

Subject:
CN=IDRIX, O=IDRIX, L=Paris, S=Paris, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4881735DD957F825E7FDBFF04234A30E

File PE Metadata
Compilation timestamp:
12/8/2016 10:48:07 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0xBF508

Entry point:
48, 83, EC, 28, E8, 63, FD, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 4C, 8B, DC, 49, 89, 5B, 08, 49, 89, 6B, 18, 49, 89, 73, 20, 49, 89, 53, 10, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 40, 4D, 8B, 79, 08, 4D, 8B, 31, 8B, 41, 04, 49, 8B, 79, 38, 4D, 2B, F7, 4D, 8B, E1, 4C, 8B, EA, 48, 8B, E9, A8, 66, 0F, 85, ED, 00, 00, 00, 49, 63, 71, 48, 49, 89, 4B, C8, 4D, 89, 43, D0, 48, 8B, C6, 3B, 37, 0F, 83, 81, 01, 00, 00, 48, 03, C0, 48, 8D, 5C, C7, 0C, 8B, 43, F8, 4C, 3B, F0, 0F, 82, A8, 00, 00...
 
[+]

Code size:
894 KB (915,456 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VeraCrypt

Command:
"C:\Program Files\veracrypt\veracrypt.exe" \q preferences \a logon \a favorites


Scan VeraCrypt.exe - Powered by Reason Core Security