esuser.exe

WSM Client

Wyse Technology LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WSM Client’.
Publisher:
Wyse Technology Inc.  (signed by Wyse Technology LLC)

Product:
WSM Client

Version:
6.1.0.0

MD5:
9a1eda4ef05b88205289f49da9a06549

SHA-1:
420a2f63de5a33f3770bec5891c38a090299993f

SHA-256:
275a186db19a4f9ddfc81ca4fb32388d018296064b548f958c7d72dbd43f3c72

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 4:14:48 AM UTC  (today)

File size:
936.7 KB (959,208 bytes)

Product version:
6.1.0.0

Copyright:
Copyright © 2005 Wyse Technology Inc.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wyse\wsm\esuser.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/4/2013 2:00:00 AM

Valid to:
9/6/2014 1:59:59 AM

Subject:
CN=Wyse Technology LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Wyse Technology LLC, O=Wyse Technology LLC, L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4A3E6CA1832F7BE6C8025ADAC36A4D1E

File PE Metadata
Compilation timestamp:
11/25/2013 11:05:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1120C

Entry point:
55, 8B, EC, 6A, FF, 68, A0, 44, 46, 00, 68, F4, 15, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, EC, 40, 46, 00, 33, D2, 8A, D4, 89, 15, 50, B8, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 4C, B8, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 48, B8, 48, 00, C1, E8, 10, A3, 44, B8, 48, 00, 6A, 01, E8, AE, 48, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 30, 32, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
396 KB (405,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WSM Client

Command:
"C:\Program Files\wyse\wsm\esuser.exe" startslow


Scan esuser.exe - Powered by Reason Core Security