exeforservice.exe

Symantec Workspace Streaming Agent

Symantec Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AppMgrGui’.
Publisher:
Symantec Corporation  (signed and verified)

Product:
Symantec Workspace Streaming Agent

Description:
Streamed Application Launcher

Version:
6,4,0,134

MD5:
bd14d3e6302a1b870e92b70b636335e1

SHA-1:
1d1207c91e074afd7dc6818b7113e13f370ac87b

SHA-256:
aa4efc372f06340eb4f494fa9fade65315e777d49e9ecc02505fa3957161ed05

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 12:14:47 AM UTC  (today)

File size:
50.7 KB (51,872 bytes)

Product version:
6,4,0,134

Copyright:
Copyright 2011, Symantec Corporation

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\symantec\workspace streaming\bin\exeforservice.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/20/2008 9:00:00 PM

Valid to:
10/21/2011 8:59:59 PM

Subject:
CN=Symantec Corporation, OU=Symantec Endpoint Virtualization, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Mountain View, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7A18947C09BAEC9BD9D20A31D4802F3F

File PE Metadata
Compilation timestamp:
7/18/2011 3:12:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:MO5A064XkJbEduboW4TwvmmL5fUoV4LOXiH94LOXiH5LAmQbQox:MO5V64ygdqLHtf4LOXzLOX4LEJx

Entry address:
0x424F

Entry point:
E8, E4, 03, 00, 00, E9, 36, FD, FF, FF, CC, FF, 25, 10, 52, 40, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, 91, 40, 00, 89, 0D, 54, 91, 40, 00, 89, 15, 50, 91, 40, 00, 89, 1D, 4C, 91, 40, 00, 89, 35, 48, 91, 40, 00, 89, 3D, 44, 91, 40, 00, 66, 8C, 15, 70, 91, 40, 00, 66, 8C, 0D, 64, 91, 40, 00, 66, 8C, 1D, 40, 91, 40, 00, 66, 8C, 05, 3C, 91, 40, 00, 66, 8C, 25, 38, 91, 40, 00, 66, 8C, 2D, 34, 91, 40, 00, 9C, 8F, 05, 68, 91, 40, 00, 8B, 45, 00, A3, 5C, 91, 40, 00, 8B, 45, 04, A3, 60, 91, 40, 00...
 
[+]

Code size:
16 KB (16,384 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AppMgrGui

Command:
C:\Program Files\symantec\workspace streaming\bin\exeforservice.exe