runhiddenconsole.exe

Atom Security OOO

The application runhiddenconsole.exe by Atom Security OOO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Atom Security OOO  (signed and verified)

MD5:
e29c1a39b7a69edc327c292de368f086

SHA-1:
867480838a15e3388ccd4a5ac95e8158fc20f5fa

SHA-256:
4ca3ed2bd5f0fb18c038a806cf2ef4c8633ce2b4acbc412968e1d13017591875

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/3/2024 5:33:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.AtomSecu
17.2.15.3

File size:
7.7 KB (7,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\syswow64\timecontrolsvc\proxy\runhiddenconsole.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/4/2015 8:00:00 AM

Valid to:
6/4/2018 7:59:59 AM

Subject:
CN=Atom Security OOO, OU=development, O=Atom Security OOO, STREET="Academician Koptyuga Prospect, 4,office 158", L=Novosibirsk, S=nso, PostalCode=630090, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2F74D159839B911DB6F1DFF991E70893

File PE Metadata
Compilation timestamp:
6/28/2005 6:18:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

Entry address:
0x1100

Entry point:
83, EC, 54, 53, 55, 56, 33, ED, 33, F6, B3, 20, FF, 15, 14, 10, 40, 00, 8B, D0, 80, 3A, 22, 75, 07, B3, 22, EB, 03, 8D, 49, 00, 8A, 42, 01, 42, 3A, C3, 74, 06, 84, C0, 75, F4, EB, 19, 80, 3A, 00, 74, 14, 8A, 42, 01, 42, 84, C0, 74, 0C, 3C, 20, 74, F4, 3C, 09, 74, F0, 84, C0, 75, 19, 55, 68, E8, 10, 40, 00, 68, 28, 10, 40, 00, 55, FF, 15, 1C, 10, 40, 00, 55, FF, 15, 10, 10, 40, 00, 3C, 2F, 75, 17, 8A, 42, 01, 0C, 20, 3C, 77, 75, 0E, 80, 7A, 02, 20, 75, 08, BE, 01, 00, 00, 00, 83, C2, 03, 8A, 02, 84, C0, 74...
 
[+]

Entropy:
7.1200

Code size:
1024 Bytes (1,024 bytes)

Remove runhiddenconsole.exe - Powered by Reason Core Security