agentcond.exe

easymeetingOnCall

Feedback interactive systems Italia S.p.A.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConferenceOnCall’.
Publisher:

Product:
easymeetingOnCall

Description:
easymeeting™ - easymeetingOnCall

Version:
5.1.5.224

MD5:
89ca1608a260e44ee79e2c597e4489cf

SHA-1:
139af495bdf2325c471d89082ca1a8c26f273344

SHA-256:
4f5759b2631f999d88fa102d1701caef28bb308584d1004d334bda39a5395792

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/20/2024 2:23:40 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4924

File size:
13.2 MB (13,830,104 bytes)

Product version:
2.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Italian (Italy)

Common path:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/17/2011 1:00:00 AM

Valid to:
1/16/2014 12:59:59 AM

Subject:
CN=Feedback interactive systems Italia S.p.A., O=Feedback interactive systems Italia S.p.A., L=Moncalieri, S=Torino, C=IT

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
181DFB159432571D883FB53BE4EE15FD

File PE Metadata
Compilation timestamp:
12/17/2013 2:11:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:PL0oRAsRPcnANk1KJGkETPNp2bu3sGivBASaKYEJpg1Q:PL0oeEgANk1K3Ef2bu3sGaB1aNU

Entry address:
0x4DC744

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, 08, 92, 8D, 00, E8, 01, B6, B2, FF, 33, C0, 55, 68, 74, C7, 8D, 00, 64, FF, 30, 64, 89, 20, E8, 16, CA, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 0A, E9, FF, 82, B2, FF, E8, CE, 87, B2, FF, A1, 70, 08, 8F, 00, 8B, 00, E8, EE, CC, BA, FF, A1, 70, 08, 8F, 00, 8B, 00, B2, 01, E8, 38, EB, BA, FF, A1, 70, 08, 8F, 00, 8B, 00, BA, 50, C9, 8D, 00, E8, 87, C7, BA, FF, 8B, 0D, B8, 06, 8F, 00, A1, 70, 08, 8F, 00, 8B, 00, 8B, 15, A8, 1B, 89, 00, E8, CF, CC, BA, FF, 8B, 0D, D4...
 
[+]

Code size:
4.9 MB (5,093,888 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConferenceOnCall

Command:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe


Scan agentcond.exe - Powered by Reason Core Security