hcserver.exe

Tandem Systems Ltd.

It runs as a separate (within the context of its own process) windows Service named “WinAgents HyperConf Server 5.4”.
Publisher:
WinAgents Software Group  (signed by Tandem Systems Ltd.)

Description:
HyperConf Server

Version:
5.5.0.585

MD5:
015593eeec4320dbb86a34ae42f8fb45

SHA-1:
5586e03892282d8b5c706b2d777f6147df25b06a

SHA-256:
a55ff2518f49e6385a224e7486cc0b0fdf7beb97eed2aebdf47c5a9d414fd60e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:21:34 AM UTC  (today)

File size:
1.8 MB (1,884,432 bytes)

Product version:
5.5.0.585

Copyright:
(c) 2012 Tandem Systems, Ltd. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\winagents\hcserver.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/21/2011 7:00:00 PM

Valid to:
2/22/2012 6:59:59 PM

Subject:
CN=Tandem Systems Ltd., O=Tandem Systems Ltd., STREET="Office 509, 89,ul.Kommunisticheskaya", L=Saransk, S=Mordovia, PostalCode=430005, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009802B1A633CC5F72E113A469576CFDDD

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:GXLHZtTMmOEHMsvh9WEJR66h3u0BsTR+Ys1:GblOEHtvh4E9sds1

Entry address:
0x1000

Entry point:
68, 01, 90, 7D, 00, E8, 01, 00, 00, 00, C3, C3, B0, C2, A3, D2, 02, 52, F5, 03, 1F, 31, 45, 1B, D9, F1, 00, 85, 3D, E6, C4, 1D, 05, 10, C6, FE, F2, AB, 99, 9B, 7D, ED, 36, F1, CB, 75, 37, DB, C2, 86, 70, 30, E1, C8, 67, 9F, 88, F9, 96, 3A, A4, 55, FF, 85, 5B, C3, 14, B2, 60, E9, 45, 0D, D3, 71, 3F, 83, BE, FC, C0, 7F, D7, D0, D7, 3D, EA, DA, 9F, 1A, 33, EC, 50, 59, B4, 19, 56, 39, CE, DF, E1, 98, 6A, 57, 8F, 79, CC, 3B, 88, 1D, 6F, A7, CD, D5, 82, 9C, 3B, 9E, B2, 5D, 01, D1, 15, D6, C2, F0, D0, BB, 0E, DB...
 
[+]

Entropy:
7.8540

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
3.2 MB (3,323,392 bytes)

Service
Display name:
WinAgents HyperConf Server 5.4

Service name:
HyperConfServer6

Description:
Performs HyperConf's background tasks

Type:
Win32OwnProcess

Depends on:
SyslogService WinAgentsTftpService4


Scan hcserver.exe - Powered by Reason Core Security