hksave.exe

QUANTO SOLUCOES E SISTEMA LTDA

Publisher:
QUANTO SOLUCOES E SISTEMA LTDA  (signed and verified)

MD5:
2922107a178cbce482fb76da6cca4f6c

SHA-1:
5da316692e09e4ea892da863d1a7bc3aff99aaeb

SHA-256:
ed4a8839aaf25c9b9af962eb8e43637ae5a080df91e2a118e295dbf09d6fabfb

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/18/2024 3:20:31 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Banker-KYB [Trj]
2014.9-160417

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.F47V0610
7.2.108

File size:
960.3 KB (983,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\hksave.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/2/2014 7:00:00 PM

Valid to:
4/3/2015 6:59:59 PM

Subject:
CN=QUANTO SOLUCOES E SISTEMA LTDA, O=QUANTO SOLUCOES E SISTEMA LTDA, L=PRESIDENTE PRUDENTE, S=SAO PAULO, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
00B87EDE3281FFB1EE77DF86B54A8CB0

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:A4kQ9Ws4Zidbgzwi7QDnaaXjUUpARUUZQ3YGwWQH7gBDp9lbjYEh2f2:NbWpZmITQD9TUEdfwzyl4Ewf2

Entry address:
0xF22E0

Entry point:
EB, 04, AB, 85, 39, A6, 60, 81, C2, E2, AE, 65, 0E, 0F, BD, C3, 0F, C1, F6, 45, E8, 05, 00, 00, 00, CD, 6D, 4E, 8B, F5, 5D, 68, 0B, 73, 35, 74, BB, 6C, AD, 87, C2, 8A, C3, 4F, 5E, B8, 9D, 77, 01, 00, B2, 0F, 0F, C9, 0F, A5, F1, 68, B6, 00, 00, 00, E8, 03, 00, 00, 00, 03, CD, AF, 5B, 49, 0F, A5, EF, 5B, F3, C6, C5, 3C, 85, CF, 84, ED, 68, 28, 8C, 3B, 69, 5F, D3, E1, 8A, EA, C6, C1, BC, 03, DD, 87, C9, C1, F5, 8F, 0F, A3, ED, F6, C5, B0, 87, D2, F6, C6, 37, 2B, FE, F6, C6, F1, D1, E9, 31, 3B, 42, E8, 07, 00...
 
[+]

Entropy:
7.0886

Code size:
616 KB (630,784 bytes)

Scan hksave.exe - Powered by Reason Core Security