HipServAgent.exe

Axentra QuickConnect

Axentra Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘HipServ Agent’.
Publisher:
Axentra Corporation  (signed and verified)

Product:
Axentra QuickConnect

Description:
HipServAgent Application

Version:
1.3.3.1073

MD5:
81330086c1cf1a857aff4fc5503439e1

SHA-1:
bb0ea00ea7fdbe41f677c39d69432e2603f9607b

SHA-256:
eefb747253832319dfa6938e246536d224067eb3978851a957e6fedce9cd6f63

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 1:23:13 PM UTC  (today)

File size:
2.3 MB (2,437,376 bytes)

Product version:
1.3.3.1073

Copyright:
©2009 NETGEAR,Inc.

Original file name:
HipServAgent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\netgear\stora desktop applications\hipservagent\hipservagent.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/1/2009 8:00:00 PM

Valid to:
6/2/2010 7:59:59 PM

Subject:
CN=Axentra Corporation, O=Axentra Corporation, STREET=377 Dalhousie St., STREET=Suite 210, L=Ottawa, S=Ontario, PostalCode=K1N 9N8, C=CA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6C977BB7B1D99AD9A41589F167DF66F6

File PE Metadata
Compilation timestamp:
8/26/2009 3:36:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:F2rt0zdUstWTXGuuuuuuuuuuuKuuuuuuuuuuueOSxJuuuuuuuuuuuuu+rOJ:QCPduuuuuuuuuuuKuuuuuuuuuuueOSzS

Entry address:
0xEC2D0

Entry point:
E8, BF, 06, 00, 00, E9, 35, FD, FF, FF, 6A, 10, 68, 98, 5E, 56, 00, E8, 2A, 03, 00, 00, 33, C0, 89, 45, E0, 89, 45, FC, 89, 45, E4, 8B, 45, E4, 3B, 45, 10, 7D, 13, 8B, 75, 08, 8B, CE, FF, 55, 14, 03, 75, 0C, 89, 75, 08, FF, 45, E4, EB, E5, C7, 45, E0, 01, 00, 00, 00, C7, 45, FC, FE, FF, FF, FF, E8, 08, 00, 00, 00, E8, 31, 03, 00, 00, C2, 14, 00, 83, 7D, E0, 00, 75, 11, FF, 75, 18, FF, 75, E4, FF, 75, 0C, FF, 75, 08, E8, 84, FA, FF, FF, C3, CC, 83, 3D, D0, C2, 58, 00, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83...
 
[+]

Entropy:
6.1139

Code size:
1.1 MB (1,122,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
HipServ Agent

Command:
C:\Program Files\netgear\stora desktop applications\hipservagent\hipservagent.exe


Scan HipServAgent.exe - Powered by Reason Core Security