HipServAgent.exe

Axentra QuickConnect

Axentra Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HipServ Agent’.
Publisher:
Axentra Corporation  (signed and verified)

Product:
Axentra QuickConnect

Description:
HipServAgent Application

Version:
1.3.4.112

MD5:
104419b9f4d54320856db222c78796d6

SHA-1:
a2f311735e0cac279bf669066070e5afb2fbe190

SHA-256:
1b057d288e3678bea7907cc3a2cf517f4fd3fa4fc9956faf6b576a28cc489c24

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/24/2024 11:42:26 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.AT
7.11.30.172

File size:
1.9 MB (1,954,056 bytes)

Product version:
1.3.4.112

Copyright:
© 2003-2009 Axentra Corporation.

Original file name:
HipServAgent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\orange\home library\hipservagent\hipservagent.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/2/2009 2:00:00 AM

Valid to:
6/3/2010 1:59:59 AM

Subject:
CN=Axentra Corporation, O=Axentra Corporation, STREET=377 Dalhousie St., STREET=Suite 210, L=Ottawa, S=Ontario, PostalCode=K1N 9N8, C=CA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6C977BB7B1D99AD9A41589F167DF66F6

File PE Metadata
Compilation timestamp:
10/16/2009 6:11:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:TToUgD393FXHhZ7zkhy4clI36JIY8w8TICAZYzHPX:TgDnxlHa6JI5RTjVzHv

Entry address:
0xE791A

Entry point:
E8, C5, 06, 00, 00, E9, 35, FD, FF, FF, 6A, 10, 68, B8, 04, 56, 00, E8, 30, 03, 00, 00, 33, C0, 89, 45, E0, 89, 45, FC, 89, 45, E4, 8B, 45, E4, 3B, 45, 10, 7D, 13, 8B, 75, 08, 8B, CE, FF, 55, 14, 03, 75, 0C, 89, 75, 08, FF, 45, E4, EB, E5, C7, 45, E0, 01, 00, 00, 00, C7, 45, FC, FE, FF, FF, FF, E8, 08, 00, 00, 00, E8, 37, 03, 00, 00, C2, 14, 00, 83, 7D, E0, 00, 75, 11, FF, 75, 18, FF, 75, E4, FF, 75, 0C, FF, 75, 08, E8, 7E, FA, FF, FF, C3, CC, CC, CC, CC, CC, CC, CC, 83, 3D, F0, 61, 58, 00, 00, 74, 2D, 55...
 
[+]

Code size:
1.1 MB (1,101,824 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HipServ Agent

Command:
C:\Program Files\orange\home library\hipservagent\hipservagent.exe


Scan HipServAgent.exe - Powered by Reason Core Security