EminentWareExtensionProvider.exe

EminentWare Extension WMI Provider

SolarWinds, Inc.

This is installed with multiple programs including SolarWinds WMI Providers and SolarWinds TFTP Server.
Publisher:
SolarWinds  (signed by SolarWinds, Inc.)

Product:
EminentWare Extension WMI Provider

Version:
1.80.785.0

MD5:
d1a0619c66ad3cdfdd246644683f44f2

SHA-1:
ad8fbbc7e590e8dc3079c4c89d270cf7ab42d8cf

SHA-256:
4d803288c2f1ab38a474cd9cb13eb04d7711c75007ddf3a736c7c835780d3e7a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:25:17 AM UTC  (today)

File size:
4.9 MB (5,148,008 bytes)

Product version:
1.80.785.0

Copyright:
Copyright (C) 2012 SolarWinds

Original file name:
EminentWareExtensionProvider.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\{6941c209-e716-4c72-aa72-b8bbd5cfa01f}\offline\abcfad53\d426d453\eminentwareextensionprovider.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/9/2012 7:00:00 PM

Valid to:
8/18/2013 6:59:59 PM

Subject:
CN="SolarWinds, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SolarWinds, Inc.", L=Austin, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4D1AD4813484CD2C046846391B68FADB

File PE Metadata
Compilation timestamp:
9/5/2012 4:16:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:JIPKDoKsWYR3b+QNC3vrq+qMEictr41SNK6y6WywMCz9m3blMLN64Q:BSzxb+QNC3vm+E5r4oy6WywMCzOlMLNy

Entry address:
0x1FA0D7

Entry point:
E8, FB, E4, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 45, A1, 5F, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 2B, E2, 01, 00, 8B, 45, 0C, 8B, 40, 04, 83, E0, FD, 8B, 4D, 0C, 89, 41, 04, 64, 8B, 3D...
 
[+]

Entropy:
6.5619

Code size:
3.2 MB (3,368,448 bytes)

The file EminentWareExtensionProvider.exe has been discovered within the following programs.

SolarWinds TFTP Server  by SolarWinds
Publisher's description - “SolarWinds free TFTP Server is a multi-threaded TFTP server commonly used to upload and download executable images and back up configurations for routers and switches. TFTP Server is the most robust, widely-trusted, and easy-to-use free TFTP solution available.”
www.solarwinds.com/products/freetools/free_tftp_server.aspx
6% remove it
SolarWinds WMI Providers  by SolarWinds
Publisher's description - “The SolarWinds WMI Providers for managed clients provide additional management and inventory tools that are not native to WSUS. Without them, you can only use Patch Manager to interface with WSUS, not directly with any managed clients.”
www.solarwinds.com
12% remove it
 
Powered by Should I Remove It?