EMMSN.EXE

TGCM

INDRA SISTEMAS, S.A

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Escritorio Movistar Latam’.
Publisher:
Telefónica  (signed by INDRA SISTEMAS, S.A)

Product:
TGCM

Description:
Telefónica Group Connection Manager

Version:
8.9.8.680

MD5:
5e352b44fa475a643ba5009d7a5fe1ce

SHA-1:
67f494c0c42ad8ac5fd9fb4a26adfed4cd907629

SHA-256:
6cd7266a097240644db2e2ed1536e063ead1e6d95988a126ad3e3fec7cdb5016

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 3:56:01 PM UTC  (today)

File size:
4.1 MB (4,267,616 bytes)

Product version:
8.9.8.680

Copyright:
Copyright (C) Telefónica

Original file name:
EMMSN.EXE

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\movistar\escritorio movistar latam\emmsn.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/25/2011 7:00:00 PM

Valid to:
9/25/2013 6:59:59 PM

Subject:
CN="INDRA SISTEMAS, S.A", O="INDRA SISTEMAS, S.A", L=Madrid, S=Madrid, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7B3E59360633CC008A862FB82003D651

File PE Metadata
Compilation timestamp:
4/16/2013 7:15:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x22922D

Entry point:
E8, B9, A6, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 92, 5E, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 89, 0A, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 3F, 32, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 1E, 0F, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 43, 5E, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Code size:
2.7 MB (2,877,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Escritorio Movistar Latam

Command:
"C:\Program Files\movistar\escritorio movistar latam\emmsn.exe" -dock


Scan EMMSN.EXE - Powered by Reason Core Security