EmbassySecurityCheck.exe

Embassy Security Center

Wave Systems Corp.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘EmbassySecurityCheck’.
Publisher:
Wave Systems Corp.  (signed and verified)

Product:
Embassy Security Center

Description:
ESC Embassy Security Check

Version:
04.01.00.042

MD5:
0d860c53510b7c8873f56524b8b38fd8

SHA-1:
ee462a5107cfbdbe2d5a4285a4b8edd10f51f0d3

SHA-256:
6b8cb2896fd98be1a1825637fbc06e1fc6323ca679b94c48b585e350d01a4c88

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 10:26:19 PM UTC  (today)

File size:
97.4 KB (99,712 bytes)

Product version:
04.01.00.042

Copyright:
©2010 Wave Systems Corp. All rights reserved

Original file name:
EmbassySecurityCheck.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/4/2009 10:00:00 PM

Valid to:
11/5/2010 9:59:59 PM

Subject:
CN=Wave Systems Corp., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Wave Systems Corp., L=Lee, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
336AC3DBB500ABD45835543A07FC2370

File PE Metadata
Compilation timestamp:
1/18/2010 2:36:58 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:gur+CJdJXI3OtnVw828pWO6bpdqaSMgUM8CRMEpnttfZzCs7vt6U7x7s2nBH+zs0:guiCJdpGOthxpWOcpdq7x7Yv

Entry address:
0x9650

Entry point:
48, 83, EC, 28, E8, 87, 03, 00, 00, 48, 83, C4, 28, E9, BE, FC, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, AD, 6E, 00, 00, FF, 15, 3F, 1A, 00, 00, 48, 8B, 05, 98, 6F, 00, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, F5, 05, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24...
 
[+]

Code size:
36.5 KB (37,376 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
EmbassySecurityCheck

Command:
"C:\Program Files\wave systems corp\embassy security setup\embassysecuritycheck.exe"


Scan EmbassySecurityCheck.exe - Powered by Reason Core Security