edbsrvr.exe

ElevateDB Server (Win64 Unicode)

IHS Inc

It runs as a separate (within the context of its own process) windows Service named “ElevateDB Server”.
Publisher:
Elevate Software  (signed by IHS Inc)

Product:
ElevateDB Server (Win64 Unicode)

Version:
2.13 Build 2

MD5:
e9ee1f930cb2b99cd3e1555afbd2fae0

SHA-1:
ffc7f2d35e5985cfb8b27b75bfd95ad457ff2bf7

SHA-256:
14c8528d81ed291968116835a7a4d286d7a33ad4834464f2805b082865edceb9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 1:29:13 PM UTC  (today)

File size:
6.6 MB (6,936,856 bytes)

Product version:
4.1.2.5

Copyright:
Copyright 2013, IHS Inc.

Original file name:
edbsrvr.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/13/2013 6:00:00 PM

Valid to:
2/18/2016 5:59:59 PM

Subject:
CN=IHS Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=IHS Inc, L=Englewood, S=Colorado, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
564396E1886FC486591B26503ADECA3D

File PE Metadata
Compilation timestamp:
7/17/2013 5:53:55 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:0DQVJJ7qPDPJRS6PLpXYzc9H/cDZCD6KbYBeYpVcJ1en4bsZSP+pE21dyq9MB:VGRPNOCkeYqad0

Entry address:
0x599BA0

Entry point:
55, 53, 48, 81, EC, E8, 00, 00, 00, 48, 8B, EC, 48, C7, 45, 50, 00, 00, 00, 00, 48, C7, 45, 48, 00, 00, 00, 00, 48, C7, 45, 70, 00, 00, 00, 00, 48, C7, 45, 58, 00, 00, 00, 00, 48, C7, 45, 68, 00, 00, 00, 00, 48, C7, 45, 60, 00, 00, 00, 00, 48, C7, 85, 90, 00, 00, 00, 00, 00, 00, 00, 48, C7, 45, 78, 00, 00, 00, 00, 48, C7, 85, 88, 00, 00, 00, 00, 00, 00, 00, 48, C7, 85, 80, 00, 00, 00, 00, 00, 00, 00, 48, C7, 85, 98, 00, 00, 00, 00, 00, 00, 00, 48, C7, 85, B0, 00, 00, 00, 00, 00, 00, 00, 48, C7, 85, A8, 00...
 
[+]

Entropy:
5.8207

Code size:
5.6 MB (5,870,592 bytes)

Service
Display name:
ElevateDB Server

Service name:
EDBSRVR

Type:
Win32OwnProcess


Scan edbsrvr.exe - Powered by Reason Core Security