timesync.exe

Atomic Time Synchronizer

LmhSoft

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Atomic Time Synchronizer’.
Publisher:
LmhSoft.com  (signed by LmhSoft)

Product:
Atomic Time Synchronizer

Version:
8.3.3.833

MD5:
cbad41a8f79f5a150c7836c625b986b4

SHA-1:
f206ebce644678fd39b9ce89974bfa3c05d77553

SHA-256:
325dd4c52cbaa9aff747fa2d81841b6f1b4e1f5338da4cb498707b55a37412ef

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/8/2024 3:00:26 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/DataStealer.P trojan
6.3.12010.0

File size:
3.4 MB (3,580,712 bytes)

Product version:
8.3.3.833

Copyright:
Copyright © 2014 LmhSoft.com

Trademarks:
Atomic Time Synchronizer

Original file name:
timesync.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\atsync\timesync.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/12/2013 8:00:00 AM

Valid to:
2/13/2016 7:59:59 AM

Subject:
CN=LmhSoft, O=LmhSoft, STREET=5-305 Nan Ming Yuan, STREET=Furong District, L=Changsha, S=Hunan, PostalCode=410000, C=CN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EDC19482D1499FC1839FF3CB50B7538A

File PE Metadata
Compilation timestamp:
12/23/2014 3:00:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x2B1DEC

Entry point:
55, 8B, EC, B9, 12, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, E4, 62, 6A, 00, E8, B3, B4, D5, FF, BE, E4, C9, 6C, 00, 33, C0, 55, 68, 2B, 29, 6B, 00, 64, FF, 30, 64, 89, 20, B8, 48, 29, 6B, 00, E8, 7A, EE, F9, FF, 84, C0, 74, 05, E8, 49, EE, F5, FF, 8D, 55, E8, B8, 01, 00, 00, 00, E8, D0, 4C, D5, FF, 8B, 45, E8, 8D, 55, EC, E8, 95, D7, D6, FF, 8B, 55, EC, B8, D8, C9, 6C, 00, E8, DC, 73, D5, FF, A1, D8, C9, 6C, 00, BA, 5C, 29, 6B, 00, E8, 81, 81, D5, FF, 74, 11, A1, D8, C9, 6C, 00, BA, 74...
 
[+]

Entropy:
6.6711

Developed / compiled with:
Microsoft Visual C++

Code size:
2.7 MB (2,825,728 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Atomic Time Synchronizer

Command:
"C:\Program Files\atsync\timesync.exe" \auto


Scan timesync.exe - Powered by Reason Core Security