imadwm.exe

C S S CORPORATIVO SISTEMAS E SOLUCOES LTDA ME

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Security’.
Publisher:

Description:
Cartoon Protect

Version:
1.0.0.0

MD5:
94a6e4ffde4f246897a8498f21680293

SHA-1:
3b3adb8291bab83f425376398c7751269f884106

SHA-256:
4f1ef3043b87f44739ddd6fd0b5dfa0da1562a5fc31a0a4ec7c2ca3060a4c856

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/29/2024 9:21:05 AM UTC  (today)

Scan engine
Detection
Engine version

Sophos
Mal/Cleaman-B
4.98

File size:
10.2 MB (10,667,096 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Inuktitut (Latino, Canadá)

Common path:
C:\users\{user}\appdata\roaming\imadwm.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
8/11/2014 9:00:00 PM

Valid to:
8/12/2015 8:59:59 PM

Subject:
CN=C S S CORPORATIVO SISTEMAS E SOLUCOES LTDA ME, OU=software, O=C S S CORPORATIVO SISTEMAS E SOLUCOES LTDA ME, L=CRICIUMA, S=SANTA CATARINA, C=BR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
20BE615B9C56F97B0FFA3EA9711B19AD

File PE Metadata
Compilation timestamp:
12/30/2014 7:32:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:9F52H/LcRrEUMdLGDoUtT3l+QlXlhXcHFMQzmaXrYsIAK+aCGQn8cG71:9F52HzIrDME1TV+glRuu0MD+aCGQG1

Entry address:
0x1568D54

Entry point:
60, 52, 56, E8, CD, 74, 00, 00, 8D, 64, 24, 50, 0F, 8D, 98, F4, 05, 00, 88, F8, AC, 9C, E9, 4C, 50, 00, 00, B4, B5, A2, 21, 36, ED, 40, 8E, 52, 84, 08, 88, 92, D6, E2, 6A, 50, EB, 58, 4F, E8, FF, B1, 84, DE, 19, 47, 12, 70, CB, C9, 6C, D5, CC, AA, 8D, C8, 12, ED, EC, 3F, 6A, 1A, D6, 20, 08, 48, 16, 9F, A1, FF, 1E, 26, B9, E3, 51, 11, 6F, 28, DC, CE, B0, F5, 49, 27, D8, 0A, 18, 13, DD, D8, CD, 3B, 41, C3, D2, 68, CA, DE, 2F, 76, 37, 54, C7, 9B, 9C, 0B, 51, 35, 7D, 57, 29, AC, D4, 48, 0E, 6A, 0B, 7A, 1F, 71...
 
[+]

Code size:
3.7 MB (3,883,008 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Security

Command:
C:\users\{user}\appdata\roaming\imadwm.exe


Scan imadwm.exe - Powered by Reason Core Security