hcserver.exe

Tandem Systems Ltd.

It runs as a separate (within the context of its own process) windows Service named “WinAgents HyperConf Server 5.4”.
Publisher:
WinAgents Software Group  (signed by Tandem Systems Ltd.)

Description:
HyperConf Server

Version:
5.5.0.581

MD5:
f9b1034ffd566f934ac16597adc01867

SHA-1:
ae31291bde4f3cfb777c17e6db1245f22b464577

SHA-256:
178319331e6bf0035fa7f7cd8976e9bcb96639ccb22901cca3df813fc16ff06e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:04:50 AM UTC  (today)

File size:
1.8 MB (1,884,432 bytes)

Product version:
5.5.0.581

Copyright:
(c) 2011 Tandem Systems, Ltd. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\winagents\hcserver.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/21/2011 7:00:00 PM

Valid to:
2/22/2012 6:59:59 PM

Subject:
CN=Tandem Systems Ltd., O=Tandem Systems Ltd., STREET="Office 509, 89,ul.Kommunisticheskaya", L=Saransk, S=Mordovia, PostalCode=430005, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009802B1A633CC5F72E113A469576CFDDD

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:2sF0XadwT26djbmLWWsz1qJn6h3u0ERsTR+YCaJS:2sqaG2a/0shqJ3sdCag

Entry address:
0x1000

Entry point:
68, 01, 90, 7D, 00, E8, 01, 00, 00, 00, C3, C3, 93, 62, 69, 14, A3, DC, 99, E5, 9C, 21, 42, 3B, 0D, 38, 10, 5D, FA, FA, F4, CF, 1C, 86, 70, F4, E7, A8, 8B, EA, 3F, 85, CC, E8, D3, 0B, B4, 2A, 88, F3, 87, A3, 29, 18, B4, BD, 4A, 1B, FF, B8, 51, DB, BD, 4A, E9, BE, 25, E2, 33, 8E, 43, 07, 78, 66, 6F, 08, D6, 27, B0, E6, E9, 97, E9, 6F, 69, 50, 4C, 0D, A8, D8, 22, FF, DC, C0, C8, 59, 63, 4A, 11, 96, D3, B9, CC, 13, 07, 4D, 52, 93, C9, 06, 3D, 33, 28, EC, A4, 3A, C3, 41, EB, CD, 73, 07, 0B, 09, 02, 5D, 4A, 09...
 
[+]

Entropy:
7.8541

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
3.2 MB (3,322,880 bytes)

Service
Display name:
WinAgents HyperConf Server 5.4

Service name:
HyperConfServer6

Description:
Performs HyperConf's background tasks

Type:
Win32OwnProcess

Depends on:
SyslogService WinAgentsTftpService4


Scan hcserver.exe - Powered by Reason Core Security