esvc.exe

esvc

IProNet Sistemas, S.A.

It runs as a separate (within the context of its own process) windows Service named “e-netcamCLIENT Pro Recordings and Alarms Service”.
Publisher:
IProNet Sistemas, S.A.  (signed and verified)

Product:
esvc

Version:
7.00.0042

MD5:
0d8326818164a16a51e2127d65fb895a

SHA-1:
f33d9b360c2c09d19299c404e6bfb24083719772

SHA-256:
6ea98f7a1e26e7900f6612b59600f8aeb10988a88480c8fa2d89d2c7a3c2b7a4

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/28/2024 9:46:24 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

F-Prot
W32/VB-Backdoor-HRS-based!Maxim
4.6.5.141

File size:
442.6 KB (453,200 bytes)

Product version:
7.00.0042

Original file name:
esvc.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\ipronet\e-netcamclient 7.0\esvc.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/25/2013 2:00:00 AM

Valid to:
7/15/2015 1:59:59 AM

Subject:
CN="IProNet Sistemas, S.A.", OU=WINDOWS APLICATION DEVELOPMENT, O="IProNet Sistemas, S.A.", L=Bilbao, S=Bizkaia, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
61724974F4C241EE65CDE5BFAD7CF887

File PE Metadata
Compilation timestamp:
7/8/2014 12:32:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:tdaTNGKUf9PrjujegyRhU2sNUeOFZFQ03VIs:tMTsgUe2sNUeOFN3VIs

Entry address:
0x4088

Entry point:
68, 84, 4A, 40, 00, E8, EE, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 11, 74, 98, A3, 5E, 92, 7E, 47, A1, F0, 7E, 69, 2C, F4, 80, A3, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 49, 00, 86, 50, 82, 01, 65, 5F, 6E, 65, 74, 63, 61, 6D, 53, 56, 43, 00, 8C, 3C, 19, 03, 00, 00, 00, 00, D0, F9, 8B, 02, C0, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 1A, 00, 00, 00, D7, DE, 35, 64, 92, 0F, CD, 4F, BD, 10, AE, 8F, 1F, DD, CE, 06, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
404 KB (413,696 bytes)

Service
Display name:
e-netcamCLIENT Pro Recordings and Alarms Service

Service name:
e_ncsvcpro

Type:
Win32OwnProcess

Depends on:
e_diskmonpro


Scan esvc.exe - Powered by Reason Core Security