VeraCrypt.exe

VeraCrypt

IDRIX

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘VeraCrypt’.
Publisher:
IDRIX  (signed and verified)

Product:
VeraCrypt

Version:
1.20-BETA2

MD5:
61212b2f271dc1818bfb7412a5ed20aa

SHA-1:
e04285571b0f5483d02388be5699b28d1d1e6563

SHA-256:
ba619a3f8be49df5fed3b1a0339555e54bb12e8d5156b2fb4648e45f28d07b2b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 1:29:55 AM UTC  (today)

File size:
5.3 MB (5,605,008 bytes)

Product version:
1.20-BETA2

Trademarks:
VeraCrypt

Original file name:
VeraCrypt.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\veracrypt\veracrypt.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/16/2016 1:00:00 AM

Valid to:
4/30/2018 1:59:59 AM

Subject:
CN=IDRIX, O=IDRIX, L=Paris, S=Paris, C=FR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4881735DD957F825E7FDBFF04234A30E

File PE Metadata
Compilation timestamp:
12/30/2016 11:12:38 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0xBE378

Entry point:
48, 83, EC, 28, E8, D3, FC, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 4C, 8B, DC, 49, 89, 5B, 08, 49, 89, 6B, 18, 49, 89, 73, 20, 49, 89, 53, 10, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 40, 4D, 8B, 79, 08, 4D, 8B, 31, 8B, 41, 04, 49, 8B, 79, 38, 4D, 2B, F7, 4D, 8B, E1, 4C, 8B, EA, 48, 8B, E9, A8, 66, 0F, 85, ED, 00, 00, 00, 49, 63, 71, 48, 49, 89, 4B, C8, 4D, 89, 43, D0, 48, 8B, C6, 3B, 37, 0F, 83, 81, 01, 00, 00, 48, 03, C0, 48, 8D, 5C, C7, 0C, 8B, 43, F8, 4C, 3B, F0, 0F, 82, A8, 00, 00...
 
[+]

Code size:
890 KB (911,360 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VeraCrypt

Command:
"C:\Program Files\veracrypt\veracrypt.exe" \q preferences \a logon \a favorites


Scan VeraCrypt.exe - Powered by Reason Core Security