allaccess_appstart.exe

AT&T Services, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘AllAccess_AppStart.exe’. This is installed with AT&T AllAccess.
Publisher:
AT&T Services, Inc.  (signed and verified)

MD5:
8bd9c2ecbad318a46bbd30d14e34ab62

SHA-1:
f947d171d3c8e4473eb8086361c327b988d4e3d3

SHA-256:
fb8a655d76eb343d2f06a54821dc5cd65f6e8649664001f22642c50a39cdcd5a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:44:53 PM UTC  (a few moments ago)

File size:
241.9 KB (247,672 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\at&t\at&t allaccess\allaccess_appstart.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/7/2011 7:00:00 PM

Valid to:
9/7/2013 6:59:59 PM

Subject:
CN="AT&T Services, Inc.", OU=Architecture & Network Realization, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="AT&T Services, Inc.", L=Atlanta, S=Georgia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6D7AB334B5A27595C2E6B0950BB6102C

File PE Metadata
Compilation timestamp:
3/29/2013 9:27:46 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:rhCTv3TpgpHLv79DO2/WuHsqSh8EO6pNb7TSxJlKRC5qmOOLMU8Yxb5Jlc9MfhdF:lopg8Lh8EO6pNb7GxKRC8Sxb0j/c

Entry address:
0xD74B

Entry point:
E8, 98, 04, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F0, 85, 41, 00, 89, 0D, EC, 85, 41, 00, 89, 15, E8, 85, 41, 00, 89, 1D, E4, 85, 41, 00, 89, 35, E0, 85, 41, 00, 89, 3D, DC, 85, 41, 00, 66, 8C, 15, 08, 86, 41, 00, 66, 8C, 0D, FC, 85, 41, 00, 66, 8C, 1D, D8, 85, 41, 00, 66, 8C, 05, D4, 85, 41, 00, 66, 8C, 25, D0, 85, 41, 00, 66, 8C, 2D, CC, 85, 41, 00, 9C, 8F, 05, 00, 86, 41, 00, 8B, 45, 00, A3, F4, 85, 41, 00, 8B, 45, 04, A3, F8, 85, 41, 00, 8D, 45, 08, A3, 04, 86, 41...
 
[+]

Entropy:
6.7035

Code size:
58 KB (59,392 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
AllAccess_AppStart.exe

Command:
"C:\Program Files\at&t\at&t allaccess\allaccess_appstart.exe"


The file allaccess_appstart.exe has been discovered within the following program.

AT&T AllAccess  by AT&T Inc.
Publisher's description - “Activate new data service plans that best fit your tablet mobile broadband needs and monitor your real-time data usage. Choose from individual plans or add to a Mobile Share plan. View your billing cycle and receive free data usage notifications from AT&T.”
apps.microsoft.com/windows/en-us/app/at-t-allaccess
About 8% of users remove it
 
Powered by Should I Remove It?

Scan allaccess_appstart.exe - Powered by Reason Core Security