eGdpSvc.exe

Wsys Control

Skytouch Technology Co., Limited

The application eGdpSvc.exe, “Wsys Control 1.0.0.2601” by Skytouch Technology Co., Limited has been detected as adware by 16 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Wsys Service”.
Publisher:
Wsys Co., Ltd.  (signed by Skytouch Technology Co., Limited)

Product:
Wsys Control

Description:
Wsys Control 1.0.0.2601

Version:
1.0.0.2601

MD5:
e2a0fad868a56b5c10f920114f3d19f9

SHA-1:
ce59487c1eb4c66becafbe5add2a0964640cb879

SHA-256:
17a37c82e69b3ef2bcb132ec2d3a6e2d14fb33088fec1f1346702289e5dd89fc

Scanner detections:
16 / 68

Status:
Adware

Analysis date:
5/10/2024 12:16:08 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Staser
2013.08.26

Avira AntiVirus
TR/Wysotot.Gen
7.11.131.2

AVG
Win32/DH{AB41DCcofl0gIiUTF2Q}
2015.0.3551

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.14226

Boost by Reason
Optional.Service.SkytouchTechnologyCoLimited.H
188861

Comodo Security
Heur.Suspicious
16824

ESET NOD32
Win32/ELEX (variant)
7.8727

Fortinet FortiGate
W32/Dloadr.DSY!tr
12/19/2013

Malwarebytes
PUP.Optional.Wsys.A
v2014.02.26.09

McAfee
Artemis!E2A0FAD868A5
5600.7276

Microsoft Security Essentials
Trojan:Win32/Wysotot.A
1.165.247.01

Reason Heuristics
PUP.Service.SkytouchTechnologyCoLimited.H
14.3.20.14

Sophos
Troj/Dloadr-DSY
4.91

Total Defense
Win32/Wysotot.A!generic
37.0.10756

Trend Micro House Call
TROJ_GEN.F47V0805
7.2.353

VIPRE Antivirus
Trojan.Win32.Generic
20884

File size:
382.1 KB (391,288 bytes)

Product version:
1.0.0.2601

Copyright:
Copyright (C) 2013

Original file name:
eGdpSvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\ProgramData\esafe\egdpsvc.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/8/2013 11:29:59 AM

Valid to:
7/9/2014 11:29:59 AM

Subject:
CN="Skytouch Technology Co., Limited", O="Skytouch Technology Co., Limited", L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216078022FA91C0EB61326E0E8FDBE9C30

File PE Metadata
Compilation timestamp:
8/5/2013 12:13:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:xHHNGaWXHxrfzFiNLE0g/+zOACZWjTP9xcJHxA/1HRer1v4ac:VPWXJfzFWFrPP9iDVpc

Entry address:
0x2335A

Entry point:
E8, AE, B8, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 10, 56, 89, 55, FC, 89, 4D, F4, 85, C9, 75, 16, E8, B0, 47, 00, 00, 6A, 16, 5E, 89, 30, E8, B1, 69, 00, 00, 8B, C6, E9, EE, 00, 00, 00, 53, 57, 85, D2, 75, 0D, E8, 94, 47, 00, 00, 6A, 16, 5E, E9, AB, 00, 00, 00, 8B, 5D, 14, 33, C0, 85, DB, 66, 89, 01, 0F, 95, C0, 40, 3B, D0, 77, 09, E8, 75, 47, 00, 00, 6A, 22, EB, DF, 8B, 45, 10, 6A, 22, 83, C0, FE, 5E, 3B, C6, 77, CB, 8B, 55, 0C, 33, C0, 89, 45, 14, 8B, F9, 85, DB, 74, 1B, 6A, 2D, 58, 66, 89, 01...
 
[+]

Entropy:
6.0182

Code size:
242.5 KB (248,320 bytes)

Service
Display name:
Wsys Service

Service name:
WsysSvc

Description:
Wsys update service

Type:
Win32OwnProcess


Remove eGdpSvc.exe - Powered by Reason Core Security