EmbassySecurityCheck.exe

Embassy Security Center

Wave Systems Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmbassySecurityCheck’.
Publisher:
Wave Systems Corp.  (signed and verified)

Product:
Embassy Security Center

Description:
ESC Embassy Security Check

Version:
03.05.00.014

MD5:
cb3d93d8c16e1b21537a87391332cb3d

SHA-1:
3d74eae4d90e40f8c5b3e4018ba5778347880743

SHA-256:
2ef51223221f022ef3e5681ea6bdeec3f823ebe06c69846b0249e1c356587e1b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 2:21:04 AM UTC  (today)

File size:
69.6 KB (71,232 bytes)

Product version:
03.05.00.014

Copyright:
Copyright (C) 2006 Wave Systems Corp. All rights reserved.

Original file name:
EmbassySecurityCheck.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/2/2006 1:00:00 AM

Valid to:
11/5/2008 12:59:59 AM

Subject:
CN=Wave Systems Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wave Systems Corp., L=Lee, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
16ED43CBE857960CC8FF2127D385F156

File PE Metadata
Compilation timestamp:
2/15/2007 11:15:16 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:MEL5nnc2CyDAwW8UDPUukx7g9z9n9x9h9V9o919u979v9X9m9n9SeinOAiFSMY8C:ME5FeBUukx7g9z9n9x9h9V9o919u9795

Entry address:
0x6877

Entry point:
E8, FA, 02, 00, 00, E9, 36, FD, FF, FF, CC, CC, CC, 68, 2A, 64, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 70, B1, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 38, B4, 40, 00, 89, 0D, 34, B4, 40, 00, 89, 15, 30, B4, 40, 00...
 
[+]

Code size:
28 KB (28,672 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmbassySecurityCheck

Command:
"C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe"


Scan EmbassySecurityCheck.exe - Powered by Reason Core Security