qdeskswt.exe

ZhongXiang ZhiXing Network Service Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘QdeskSwt’.
Publisher:

MD5:
f13cc1209ef52c988d56c0ce61a68396

SHA-1:
c790333edbb573a10fe6312ed22bfaa744d8a163

SHA-256:
89e8a3cd6a26a809c67203201b92eeaa30579cff09a8824dc443ee9ff9b88fdc

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/23/2024 11:33:45 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17329

File size:
2.4 MB (2,491,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\qdeskswt\qdeskswt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/21/2011 8:00:00 AM

Valid to:
7/21/2012 7:59:59 AM

Subject:
CN="ZhongXiang ZhiXing Network Service Co., Ltd.", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ZhongXiang ZhiXing Network Service Co., Ltd.", L=ZhongXiang, S=HuBei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
358252724C2051F6C0E98451E597F300

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:6zSJVuamUvGaQY305CVxDsgJRZ749XX1vm:6zEVuYvGV2JCA

Entry address:
0x160ED8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 58, 08, 56, 00, E8, 54, 58, EA, FF, 68, 44, 0F, 56, 00, 68, 54, 0F, 56, 00, E8, C9, 62, EA, FF, 85, C0, 76, 11, 6A, 00, 6A, 00, 68, 00, 14, 00, 00, 50, E8, 8E, 65, EA, FF, EB, 30, A1, 64, 7E, 56, 00, 8B, 00, E8, 18, 51, F1, FF, 8B, 0D, D0, 7A, 56, 00, A1, 64, 7E, 56, 00, 8B, 00, 8B, 15, 7C, B4, 55, 00, E8, 18, 51, F1, FF, A1, 64, 7E, 56, 00, 8B, 00, E8, 8C, 51, F1, FF, E8, 9F, 32, EA, FF, 00, 00, 00, 51, 64, 65, 73, 6B, 4D, 61, 69, 6E, 46, 6F, 72, 6D, 00, 00, 00, 51, 64, 65, 73...
 
[+]

Entropy:
6.9549

Developed / compiled with:
Microsoft Visual C++

Code size:
1.4 MB (1,441,792 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
QdeskSwt

Command:
"C:\Program Files\qdeskswt\qdeskswt.exe" \start


Scan qdeskswt.exe - Powered by Reason Core Security