ovpnagent.exe

OpenVPN Technologies, Inc.

The executable ovpnagent.exe has been detected as malware by 3 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “OpenVPN Agent”.
Publisher:
OpenVPN Technologies, Inc.  (signed and verified)

MD5:
005d2c038287a946c3319593326f3acb

SHA-1:
0f0570f55022d44803cb0b85e895ea0fb22feb18

SHA-256:
af3e2e3d7b7e3894fd983d4e0148def24d44c7bf4a5fb4cefab63d7fe0c4cc81

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/30/2024 11:32:15 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.16.24

File size:
1003.7 KB (1,027,759 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\openvpn technologies\privatetunnel\ovpnagent.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
2/8/2016 4:00:00 PM

Valid to:
2/13/2019 4:00:00 AM

Subject:
CN="OpenVPN Technologies, Inc.", O="OpenVPN Technologies, Inc.", L=Pleasanton, S=California, C=US, PostalCode=94588, STREET="5980 Stoneridge Drive, Suite 103", SERIALNUMBER=3761256, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0EBD24BDFBD4ADDDD2EDD27E8FB1953C

File PE Metadata
Compilation timestamp:
8/29/2016 10:26:32 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

Entry address:
0x68C18

Entry point:
E9, B2, F3, FC, FF, E9, 7A, FE, FF, FF, 6A, 10, 68, 58, 48, 4D, 00, E8, 92, 0B, 00, 00, 33, DB, 89, 5D, E0, 88, 5D, E7, 89, 5D, FC, 3B, 5D, 10, 74, 1A, 8B, 4D, 14, E8, E1, 05, 00, 00, 8B, 4D, 08, FF, 55, 14, 8B, 45, 0C, 01, 45, 08, 43, 89, 5D, E0, EB, E1, B0, 01, 88, 45, E7, C7, 45, FC, FE, FF, FF, FF, E8, 0E, 00, 00, 00, E8, 98, 0B, 00, 00, C2, 14, 00, 8B, 5D, E0, 8A, 45, E7, 84, C0, 75, 0F, FF, 75, 18, 53, FF, 75, 0C, FF, 75, 08, E8, 7B, 00, 00, 00, C3, 6A, 0C, 68, 78, 48, 4D, 00, E8, 29, 0B, 00, 00, C6...
 
[+]

Entropy:
6.7218

Packer / compiler:
Xtreme-Protector v1.05

Code size:
705 KB (721,920 bytes)

Service
Display name:
OpenVPN Agent

Service name:
ovpnagent

Type:
Win32OwnProcess


Remove ovpnagent.exe - Powered by Reason Core Security