CLIStart.exe

Catalyst Control Center

Advanced Micro Devices, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘StartCCC’.
Publisher:
Advanced Micro Devices, Inc.

Product:
Catalyst® Control Center

Description:
Catalyst® Control Center Launcher

Version:
3.5.0.0

MD5:
d784b22fea64a6983cd5a9502451bfe3

SHA-1:
e64a05a347f6ddfae7676f98ae3bc64dec6e3785

SHA-256:
c7cf57658361d5aaa95bdecac47e43a1b79a20df3871d36f6875f213625a66a0

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 10:29:27 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Ramnit-CY
160118-1

AVG
Win32/Ramnit.A
2015.0.4489

Boost by Reason
Optional.AdvancedMicroDevices.Startup
188838

File size:
385 KB (394,240 bytes)

Product version:
3.5.0.0

Copyright:
© 2008 Advanced Micro Devices, Inc.

Original file name:
CLIStart.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\ati technologies\ati.ace\core-static\clistart.exe

File PE Metadata
Compilation timestamp:
5/25/2011 6:45:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:vN/301AAWFhmxTB7drI/7gkzKTr6gQux:vN/01ANKv6gQux

Entry address:
0x1EBA

Entry point:
E8, B0, 1C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, A8, AC, 40, 00, 89, 0D, A4, AC, 40, 00, 89, 15, A0, AC, 40, 00, 89, 1D, 9C, AC, 40, 00, 89, 35, 98, AC, 40, 00, 89, 3D, 94, AC, 40, 00, 66, 8C, 15, C0, AC, 40, 00, 66, 8C, 0D, B4, AC, 40, 00, 66, 8C, 1D, 90, AC, 40, 00, 66, 8C, 05, 8C, AC, 40, 00, 66, 8C, 25, 88, AC, 40, 00, 66, 8C, 2D, 84, AC, 40, 00, 9C, 8F, 05, B8, AC, 40, 00, 8B, 45, 00, A3, AC, AC, 40, 00, 8B, 45, 04, A3, B0, AC, 40, 00, 8D, 45, 08, A3, BC, AC, 40...
 
[+]

Code size:
22 KB (22,528 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
StartCCC

Command:
"C:\Program Files\ati technologies\ati.ace\core-static\clistart.exe" msrun


Scan CLIStart.exe - Powered by Reason Core Security