agentcond.exe

easymeetingOnCall

Feedback interactive systems Italia S.p.A.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConferenceOnCall’.
Publisher:

Product:
easymeetingOnCall

Description:
easymeeting™ - easymeetingOnCall

Version:
5.1.1.223

MD5:
078496c2505707ebb9a7a982c610767d

SHA-1:
4b789b9a9b5d0902846104f9b8b09b7d1413e332

SHA-256:
d5be46e43005ae151f0ff25dbde44da81fb04bb52f8a5f06852484a95f65e890

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/30/2024 12:50:22 PM UTC  (today)

File size:
3.5 MB (3,618,896 bytes)

Product version:
2.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Italian (Italy)

Common path:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/2/2010 5:30:00 AM

Valid to:
11/30/2011 5:29:59 AM

Subject:
CN=Feedback interactive systems Italia S.p.A., O=Feedback interactive systems Italia S.p.A., L=Moncalieri, S=Torino, C=IT

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
44E73D6D1E0F9FA40661DAA455F8EAF0

File PE Metadata
Compilation timestamp:
7/4/2011 2:40:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ZfKxg+F0jcOXPAOeFq04FY+PS59WvpB0Qsw44KSVK6yc5RMRCLgtwLq:ZqD09/AOUq0APi9WvpB0QswHC6FXMRD

Entry address:
0x2D1770

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 4C, E8, 6C, 00, E8, 8B, 60, D3, FF, 8B, 1D, F4, F5, 6D, 00, 8B, 03, E8, D6, CF, DA, FF, 8B, 03, BA, 74, 18, 6D, 00, E8, 82, CA, DA, FF, 8B, 0D, BC, F4, 6D, 00, 8B, 03, 8B, 15, 1C, 9B, 6A, 00, E8, CF, CF, DA, FF, 8B, 0D, 04, F1, 6D, 00, 8B, 03, 8B, 15, B4, 8C, 69, 00, E8, BC, CF, DA, FF, 8B, 0D, 28, EF, 6D, 00, 8B, 03, 8B, 15, B4, B3, 69, 00, E8, A9, CF, DA, FF, 8B, 0D, C4, F8, 6D, 00, 8B, 03, 8B, 15, F4, EF, 69, 00, E8, 96, CF, DA, FF, 8B, 0D, 38, F6, 6D, 00, 8B, 03, 8B, 15...
 
[+]

Entropy:
6.6069

Developed / compiled with:
Microsoft Visual C++

Code size:
2.8 MB (2,948,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConferenceOnCall

Command:
C:\Program Files\easymeeting\conferenceoncall\agentcond.exe


Scan agentcond.exe - Powered by Reason Core Security