Versions
(Note, Hefei Feiqiu Info Tech Ltd publishes each variation of this file with the same version, but the hashes are unique.)
egdpsvc.exe
Wsys Control by Hefei Feiqiu Info Tech Ltd (Signed)
Overview
There are 3 versions of egdpsvc.exe in the wild, the latest version being 10.2.1.2652. It is started as a Windows Service called 'Wsys Service' with the name 'WsysSvc' and described as “Wsys update service”. . In addition, it is run under the context of the SYSTEM account with extensive privileges (the administrator accounts have the same privileges). The average file size is about 1.63 MB. The file is a digitally signed and issued to Hefei Feiqiu Info Tech Ltd by GlobalSign nv-sa. Some variations of the file have been seen to be installed with the program Wsys Control 10.2.1.2652 from Banyan Tree Technology Limited. During the process's lifecycle, the typical CPU resource utilization is about 0.0046% including both foreground and background operations, the average private memory consumption is about 6.79 MB with the maximum memory reaching around 13.42 MB.
Details |
File name: | egdpsvc.exe |
Publisher: | Wsys Co., Ltd. |
Product name: | Wsys Control |
Description: | Wsys Control 10.2.1.2652 |
Typical file path: | C:\ProgramData\esafe\egdpsvc.exe |
Original name: | Wsys.exe |
Certificate |
Issued to: | Hefei Feiqiu Info Tech Ltd |
Authority (CA): | GlobalSign nv-sa |
Effective date: | Thursday, January 24, 2013 |
Expiration date: | Monday, January 25, 2016 |
Windows Service |
Service name: | WsysSvc |
Display name: | Wsys Service |
Description: | “Wsys update service” |
Type: | Win32OwnProcess |
Programs installed in
(Note, the programs listed below are for all versions of Wsys Control.)
|
Banyan Tree Technology Limited |
|
Wsys Control also known as Delta-homes.com is a potentially unwanted web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web brows...
Behaviors
(Note, the behaviors below are for all versions of egdpsvc.exe, select a unique version for details.)
Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
- 'WsysSvc' (Wsys Service)
- WsysSvc
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Documents and Settings\user\Application Data\eSafe\eGdpSvc.exe'
All file variations of egdpsvc.exe
Distribution by Windows OS
OS version | distribution |
Windows 8 |
33.33% |
|
Microsoft Windows XP |
22.22% |
|
Windows 8 Pro |
22.22% |
|
Windows 7 Ultimate |
11.11% |
|
Windows 7 Professional |
11.11% |
|
Distribution by country
Vietnam installs about 22.22% of Wsys Control.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Toshiba |
26.67% |
|
Compaq |
26.67% |
|
Intel |
26.67% |
|
Lenovo |
13.33% |
|
Hewlett-Packard |
6.67% |
|