EvalSession.exe

EvalSession

IBM

Publisher:
IBM Corp.  (signed by IBM)

Product:
EvalSession

Description:
IBM BigFix EvalSession Application

Version:
9.5.4.38

MD5:
9fc481316c12a8d225f9150654ca2b44

SHA-1:
4e5cc0591fe23b87ac5da2c429671960bacfaead

SHA-256:
f8f9b3694bd69312bb835f6ae593f12072560c1746ef0a62ffa6a3a36db69132

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 12:23:47 AM UTC  (today)

File size:
6.4 MB (6,684,656 bytes)

Product version:
9.5.4.38

Copyright:
(c) Copyright IBM Corp 2001-2016

Original file name:
EvalSession.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\temp\{random}.tmp\evalsession.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/4/2016 8:00:00 AM

Valid to:
4/5/2019 7:59:59 AM

Subject:
CN=IBM, O=IBM, L=Emeryville, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
70D2F3E9A1CE0672883573ACFFA674D8

File PE Metadata
Compilation timestamp:
12/2/2016 9:43:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

Entry address:
0x21EB33

Entry point:
E8, 3F, E3, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 83, 65, E0, 00, 57, 6A, 07, 33, C0, 59, 8D, 7D, E4, F3, AB, 39, 45, 14, 75, 18, E8, 1A, 07, 00, 00, C7, 00, 16, 00, 00, 00, E8, 83, A2, 00, 00, 83, C8, FF, E9, C4, 00, 00, 00, 8B, 7D, 10, 56, 8B, 75, 0C, 85, FF, 74, 1C, 85, F6, 75, 18, E8, F3, 06, 00, 00, C7, 00, 16, 00, 00, 00, E8, 5C, A2, 00, 00, 83, C8, FF, E9, 9C, 00, 00, 00, C7, 45, EC, 42, 00, 00, 00, 89, 75, E8, 89, 75, E0, 81, FF, FF, FF, FF, 3F, 76, 09, C7, 45, E4, FF, FF, FF, 7F, EB...
 
[+]

Entropy:
6.2733

Code size:
3 MB (3,163,648 bytes)

The file EvalSession.exe has been discovered within the following program.

Fixlet Debugger  by BigFix Enterprise
About 1% of users remove it
 
Powered by Should I Remove It?

Scan EvalSession.exe - Powered by Reason Core Security