ExecutionService.exe

EMCO ehf.

It runs as a separate (within the context of its own process) windows Service named “EMCO Remote Shutdown Server”.
Publisher:
EMCO  (signed by EMCO ehf.)

Description:
EMCO Remote Server Module

Version:
1.0.1

MD5:
08271afe594847fb545cf50c30530454

SHA-1:
fe610d1cc3979fe77dbaf5096c904fba4cde5fdb

SHA-256:
0124049f10a724619cca35cf087c624c74359c457352c339d26cc0a4ed691fe9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:57:04 AM UTC  (today)

File size:
86.3 KB (88,344 bytes)

Product version:
1.0.1

Copyright:
Copyright © EMCO 2001 - 2011

Original file name:
ExecutionService.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\emco\remoteservices\shutdown\v4\executionservice.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/7/2011 9:00:00 PM

Valid to:
3/9/2012 8:59:59 PM

Subject:
CN=EMCO ehf., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=EMCO ehf., L=Reykjavik, S=Reykjavik, C=IS

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AD40A4B07EA9EC878844FB4A548C0C1

File PE Metadata
Compilation timestamp:
7/1/2011 7:24:00 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
1536:niTvoEhFbjlDahzPBKAE/XBLEo4O23ISk3JwhiKpVz0oK:iDogPlDMBKAEaTIxwhiKpVz4

Entry address:
0x3658

Entry point:
48, 83, EC, 28, E8, EF, 3A, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, FF, C8, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10, 4D, 8B, C8, 48...
 
[+]

Code size:
50 KB (51,200 bytes)

Service
Display name:
EMCO Remote Shutdown Server

Service name:
EMCORemoteShutdownServer

Description:
Allows EMCO Remote Shutdown to shutdown and reboot computers remotely.

Type:
Win32OwnProcess