How to remove hstart.exe
hstart.exe
The module hstart.exe has been detected as Risk.Gen
File Details
Product Name: | Hidden Start |
Company Name: | NTWind Software |
MD5: | c1c769d742f88e441ded76bf57a5a45c |
Size: | 43 KB |
First Published: | 2017-05-30 20:03:05 (7 years ago) |
Latest Published: | 2020-03-11 03:18:11 (4 years ago) |
Status: | Risk.Gen (on last analysis) | |
Analysis Date: | 2020-03-11 03:18:11 (4 years ago) |
Overview
Signed By: | Alexander Avdonin |
Status: | Invalid (digital signature could be stolen or file could be patched) |
Common Places:
%windir%\syswow64 |
%desktop%\品管部資料\軟體 |
%appdata%\pdf publisher |
%desktop%\open shell batch\creat or replace then you can save the key |
%desktop%\jose\micro antitgo\users\junior\appdata\local |
%system% |
%programfiles% |
%programfiles%\powertc\tools |
%desktop%\new folder (2)\nimt_smartcard |
%desktop%\new folder (2)\nimt_smartcard\nimt_smrt |
File Names:
cs.exe |
hstart.exe |
hid.exe |
Geography:
15.4% | ||
15.4% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% | ||
7.7% |
OS Version:
Windows 10 | 46.2% | |
Windows 7 | 46.2% | |
Windows 8.1 | 7.7% |
Analysis
Subsystem: | Windows GUI |
PE Type: | pe |
OS Bitness: | 32 |
Image Base: | 0x00400000 |
Entry Address: | 0x00001e10 |
PE Sections:
Name | Size of data | MD5 |
.text | 7680 | 7afd724de716f5fabbf7ca8dab63d895 |
.rdata | 5120 | 49187d56f7b04c51a4dfe8edece9927c |
.data | 512 | 6b85ca398417e397f359851b4941961f |
.rsrc | 26112 | 21099580029eeaec2e1a16f9a7dccfdf |
More information:
Download GridinSoft
Anti-Malware - Removal tool for hstart.exe