agentcond.exe

easymeetingOnCall

Feedback interactive systems Italia S.p.A.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConferenceOnCall’.
Publisher:

Product:
easymeetingOnCall

Description:
easymeeting™ - easymeetingOnCall

Version:
5.1.1.223

MD5:
df48e97abcf2ad9ab919ce3e21ec603a

SHA-1:
159a4916496122500041f87ec176353aa19c27ad

SHA-256:
99a1ed2337dd7a97deb63e1884b04ef613e68063c2aa4e2899d26ae242a37c74

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/5/2024 2:16:43 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

File size:
3.1 MB (3,286,936 bytes)

Product version:
2.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Italian (Italy)

Common path:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
9/29/2009 8:00:00 PM

Valid to:
10/30/2010 7:59:59 PM

Subject:
CN=Feedback interactive systems Italia S.p.A., O=Feedback interactive systems Italia S.p.A., L=Moncalieri, S=Torino, C=IT

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
50594596D12CE0414CC213C4C22B741B

File PE Metadata
Compilation timestamp:
10/28/2009 7:35:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:WCaCySAmRmjh1QPZ/Hl0E3BcziMHTQVtMeCPZm8SHupaDFSV73p2DL6:WCJyowh1QVl0uc2MHTQVtMeCPZtQcd/

Entry address:
0x2986EC

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, A4, 63, 69, 00, E8, B7, F0, D6, FF, 8B, 1D, 0C, 56, 6A, 00, 8B, 03, E8, 9A, 4D, DE, FF, 8B, 03, BA, CC, 87, 69, 00, E8, 46, 48, DE, FF, 8B, 0D, DC, 54, 6A, 00, 8B, 03, 8B, 15, 84, D9, 67, 00, E8, 93, 4D, DE, FF, 8B, 0D, 28, 51, 6A, 00, 8B, 03, 8B, 15, CC, 30, 67, 00, E8, 80, 4D, DE, FF, 8B, 0D, 4C, 4F, 6A, 00, 8B, 03, 8B, 15, A4, 40, 67, 00, E8, 6D, 4D, DE, FF, 8B, 0D, D0, 58, 6A, 00, 8B, 03, 8B, 15, 24, 59, 67, 00, E8, 5A, 4D, DE, FF, 8B, 0D, 50, 56, 6A, 00, 8B, 03, 8B, 15...
 
[+]

Entropy:
6.5733

Developed / compiled with:
Microsoft Visual C++

Code size:
2.6 MB (2,717,184 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConferenceOnCall

Command:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe


Scan agentcond.exe - Powered by Reason Core Security