updservice.exe

Window Find Manager

IT NAVIGATOR LLC

The application updservice.exe by IT NAVIGATOR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Window Find Manager Update”. This file is typically installed with the program Window Find Manager by Labour LLC. While running, it connects to the Internet address oas-stats.sdev.pw on port 80 using the HTTP protocol.
Publisher:
Labour LLC  (signed by IT NAVIGATOR LLC)

Product:
Window Find Manager

Version:
5.4.5.6

MD5:
d89d4fb60c4e0f3cf5871ffeb3a3b686

SHA-1:
f0e4f38447a440476399dff3720593893e41a761

SHA-256:
6dd2ece766bdcfeac60af8cec48f213a8308982e1367518d664fd83820941302

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 12:52:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinRaw (L)
16.9.2.20

File size:
208.7 KB (213,688 bytes)

Product version:
5.4.5.6

Copyright:
Copyright (C) 2014

Original file name:
Window Find Manager

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\windfind\updservice.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2015 6:00:00 PM

Valid to:
12/19/2016 5:59:59 PM

Subject:
CN=IT NAVIGATOR LLC, OU=IT, O=IT NAVIGATOR LLC, STREET="Bud. 46a kv. 519, vul.Fedora Zaitseva", L=Kyyiv, S=Kyyiv, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
61BAEECB4D5416E1BE7333F527ED08F2

File PE Metadata
Compilation timestamp:
5/10/2016 3:55:07 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
3072:a4u3Tb1axgSZ7jLHoS+jUdPV4GcZMJR2sQqcDNDqODH:a4unSgSZe/rsQXDND9

Entry address:
0x5E81

Entry point:
E8, 81, 79, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, FF, 15, B8, 80, 41, 00, 6A, 01, A3, 74, 1B, 42, 00, E8, A0, 7A, 00, 00, FF, 75, 08, E8, 48, 7E, 00, 00, 83, 3D, 74, 1B, 42, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 86, 7A, 00, 00, 59, 68, 09, 04, 00, C0, E8, 16, 7E, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 94, FA, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 58, 19, 42, 00, 89, 0D, 54, 19, 42, 00, 89, 15, 50, 19, 42, 00, 89, 1D, 4C, 19, 42, 00, 89, 35, 48, 19, 42, 00, 89, 3D, 44...
 
[+]

Entropy:
6.2856

Code size:
91 KB (93,184 bytes)

Service
Display name:
Window Find Manager Update

Service name:
windfindServiceUpd

Type:
Win32OwnProcess


The file updservice.exe has been discovered within the following program.

Window Find Manager  by Labour LLC
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to oas-stats.sdev.pw  (162.221.224.45:80)

Remove updservice.exe - Powered by Reason Core Security