hgvpnc.exe

HideGuard VPN

iTVA LLC

The application hgvpnc.exe, “HideGuard VPN Client” by iTVA has been detected as a potentially unwanted program by 5 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘HideGuard VPN’.
Publisher:
iTVA LLC  (signed and verified)

Product:
HideGuard VPN

Description:
HideGuard VPN Client

Version:
2.2.0.0

MD5:
7cef6e2948ea4f60e07722ea3c8ff047

SHA-1:
a060893d67fc3f4de3d737e60c3df3be92b6de7b

SHA-256:
0a3fa844462e6de09c53585fec026b03895d5f59004a17aa207fa463450c7e7d

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 12:29:41 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
UnclassifiedMalware
17995

ESET NOD32
probably unknown NewHeur_PE
8.9598

Qihoo 360 Security
Win32/Trojan.b77
1.0.0.1015

Reason Heuristics
PUP.Startup.iTVA.G
14.9.27.16

Trend Micro House Call
TROJ_GEN.F47V0322
7.2.86

File size:
3.7 MB (3,892,272 bytes)

Product version:
2.0.0.0

Copyright:
iTVA LLC

Trademarks:
HideGuard

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hideguard vpn\hgvpnc.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/23/2012 2:00:00 AM

Valid to:
11/24/2014 1:59:59 AM

Subject:
CN=iTVA LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=iTVA LLC, L=St.Petersburg, S=Russian Federation, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
65EB772671D39CAF088B0D4A828C5E61

File PE Metadata
Compilation timestamp:
3/17/2014 3:15:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:vGlvwuaky3Ucsk82cU3NYS67UYJrNsWLslTW2cth5XWIi71Mw:vGVwcy3VTcfZNjLsB0rXM

Entry address:
0x26482C

Entry point:
55, 8B, EC, 83, C4, E0, 53, 56, 57, B8, C0, BA, 65, 00, E8, F9, A6, DA, FF, 68, 90, 49, 66, 00, 6A, FF, 6A, 00, E8, 6B, DF, DA, FF, 8B, D8, 85, DB, 0F, 84, 2F, 01, 00, 00, E8, C0, E1, DA, FF, 3D, B7, 00, 00, 00, 0F, 84, 1F, 01, 00, 00, A1, 30, 18, 67, 00, 8B, 00, E8, 45, 18, FC, FF, A1, 30, 18, 67, 00, 8B, 00, 33, D2, E8, 83, 35, FC, FF, A1, 30, 18, 67, 00, 8B, 00, C6, 40, 6F, 00, B8, B4, 49, 66, 00, E8, 9A, 56, FF, FF, 83, E8, 02, 74, 05, 48, 74, 1C, EB, 32, 6A, 00, 68, B8, 0B, 00, 00, B9, C4, 49, 66, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.4 MB (2,504,704 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HideGuard VPN

Command:
"C:\Program Files\hideguard vpn\hgvpnc.exe"


Remove hgvpnc.exe - Powered by Reason Core Security