vsweblaunch.exe

Visage 7

Visage Imaging GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘VisageAutoLaunch’.
Publisher:
Visage Imaging  (signed by Visage Imaging GmbH)

Product:
Visage 7

Description:
vsweblaunch.exe

Version:
7.1.6.884

MD5:
9f5f84d5d00e806db71800b37cc39878

SHA-1:
0f6f4e1e683494533b609420c05fe830ee9e7853

SHA-256:
b2feddc115d4d7b25020885a9c444a75b57d9bbea0b448beb82421708e731318

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/2/2024 3:18:51 PM UTC  (today)

File size:
537.7 KB (550,640 bytes)

Product version:
7.1

Copyright:
Copyright 2000-2014

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\visage imaging\visage 7.1\bin\arch-win\vsweblaunch.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/13/2013 8:00:00 PM

Valid to:
10/8/2015 7:59:59 PM

Subject:
CN=Visage Imaging GmbH, OU=Secure Application Development, O=Visage Imaging GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5CE82B8AF9A8F4512BE51E6E50493248

File PE Metadata
Compilation timestamp:
9/3/2015 3:39:55 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:8fVREQgL2VVzbivw5VY0hUe6n14tJGl36KyyOX:8fVKQgL2VVzbivQYhP14+yy

Entry address:
0x1B2A8

Entry point:
48, 83, EC, 28, E8, 8B, 04, 00, 00, 48, 83, C4, 28, E9, 32, FE, FF, FF, FF, 25, 68, 5E, 00, 00, FF, 25, A2, 5F, 00, 00, FF, 25, 64, 5E, 00, 00, 40, 53, 48, 83, EC, 20, 48, 83, 3D, 5E, 25, 02, 00, 00, 75, 36, BA, 08, 00, 00, 00, 8D, 4A, 18, FF, 15, 4E, 5F, 00, 00, 48, 8B, C8, 48, 8B, D8, FF, 15, DA, 5D, 00, 00, 48, 89, 05, 3B, 25, 02, 00, 48, 89, 05, 2C, 25, 02, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, 48, 8B, 0D...
 
[+]

Entropy:
4.9792

Code size:
127.5 KB (130,560 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
VisageAutoLaunch

Command:
"C:\Program Files\visage imaging\visage 7.1\bin\arch-win\vsweblaunch.exe"


Scan vsweblaunch.exe - Powered by Reason Core Security