esuser.exe

WSM Client

Wyse Technology Inc

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘WSM Client’.
Publisher:
Wyse Technology Inc.  (signed by Wyse Technology Inc)

Product:
WSM Client

Version:
6.0.0.0

MD5:
9eacfa82fc54e259dd335887dba54d1d

SHA-1:
95fad2bd61ad73f22ce87e4b75a47793e3d2201d

SHA-256:
c5dcb50158dbd67492c8978b2bfd138cf0adab061d1335a1ee7f7d68d94fbe15

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 1:53:16 AM UTC  (today)

File size:
936.7 KB (959,208 bytes)

Product version:
6.0.0.0

Copyright:
Copyright © 2005 Wyse Technology Inc.

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wyse\wsm\esuser.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/17/2012 8:00:00 AM

Valid to:
9/18/2013 7:59:59 AM

Subject:
CN=Wyse Technology Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Wyse Technology Inc, O=Wyse Technology Inc, L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0771F240FB28B143EAAB7F12409D9532

File PE Metadata
Compilation timestamp:
7/25/2013 4:12:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1120C

Entry point:
55, 8B, EC, 6A, FF, 68, A0, 44, 46, 00, 68, F4, 15, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, EC, 40, 46, 00, 33, D2, 8A, D4, 89, 15, 50, B8, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 4C, B8, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 48, B8, 48, 00, C1, E8, 10, A3, 44, B8, 48, 00, 6A, 01, E8, AE, 48, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 30, 32, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
5.8828

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
396 KB (405,504 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WSM Client

Command:
"C:\Program Files\wyse\wsm\esuser.exe" startslow


Scan esuser.exe - Powered by Reason Core Security