hstart.exe

Hidden Start

Alexander Avdonin

The executable hstart.exe, “Hidden Start (32-bit)” has been detected as malware by 1 anti-virus scanner.
Publisher:
NTWind Software  (signed by Alexander Avdonin)

Product:
Hidden Start

Description:
Hidden Start (32-bit)

Version:
4.2.0.0

MD5:
242bc18499b3187525edf639941dfceb

SHA-1:
55e64f6f338c7d5e6824cce11f4e257581f77a90

SHA-256:
ab8f4cab1b8c3aa78bf960392372562a87c4f81d80a010ca9573618c4401127a

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/23/2024 10:04:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win.HiddenStart
16.11.10.9

File size:
184.1 KB (188,487 bytes)

Product version:
4.2.0.0

Copyright:
© 2013 NTWind Software

Original file name:
hstart.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/21/2012 6:00:00 AM

Valid to:
3/22/2015 5:59:59 AM

Subject:
CN=Alexander Avdonin, O=Alexander Avdonin, STREET=Menshikovsky pr. 3-25, L=Saint Petersburg, S=Saint Petersburg, PostalCode=195067, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0CF1F3DD67017040C6C52F66A828FCCC

File PE Metadata
Compilation timestamp:
3/18/2013 12:46:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:OPKZqpiHlp72DYNFZWoqDus0kF+DwIo4s2lQBV+UdE+rECWp7hKsa:OPKZ0iFp72DYNFZWoqDCwV4KBV+UdvrZ

Entry address:
0x1B00

Entry point:
E9, 80, 27, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 18, 1C, 41, 00, E8, 5E, 23, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, E0, 48, 41, 00, 03, 75, 43, 6A, 04, E8, 96, 27, 00, 00, 59, 83, 65, FC, 00, 56, E8, BE, 27, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, DF, 27, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, 82, 26, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 04, 46, 41, 00, FF, 15, C4, E0, 40, 00, 85, C0, 75, 16, E8, B3, 25, 00...
 
[+]

Entropy:
7.1058

Packer / compiler:
Xtreme-Protector v1.05

Code size:
52 KB (53,248 bytes)

Remove hstart.exe - Powered by Reason Core Security