wconnect7.exe

Winconnection 7

Winco Tecnologia e Sistemas LTDA

It runs as a separate (within the context of its own process) windows Service named “Winconnection 7”.
Publisher:
Winco Sistemas Ltda.  (signed by Winco Tecnologia e Sistemas LTDA)

Product:
Winconnection 7

Description:
Servidor Winconnection

Version:
7.0

MD5:
1330e1816e52140668b241678f0ed560

SHA-1:
1202d6db633c26b3311885a9485e736e0c8d129a

SHA-256:
723d91c79381f75b23342448d3d6417dfb9a6a616d1c5c9f4f07282d2bfaf8e7

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 6:15:03 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.Sality
2.1.4+

File size:
1.8 MB (1,855,016 bytes)

Product version:
7.0.0.0

Original file name:
wconnect7.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\Program Files\winco\winconnection7\wconnect7.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/23/2014 9:00:00 PM

Valid to:
4/24/2016 8:59:59 PM

Subject:
CN=Winco Tecnologia e Sistemas LTDA, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Winco Tecnologia e Sistemas LTDA, L=Rio de Janeiro, S=Rio de Janeiro, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
57B2D61775CE7F81CB4C316BE44C7091

File PE Metadata
Compilation timestamp:
1/5/2016 10:10:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:rAU6IpIWNZIGQ0S+UPYbXnNoE2LTCRw7/CTz8+RpYbqtAD05nZqIVIB3/bVcY8s1:rOfXfqnU08+IynwIVGvbVAY

Entry address:
0x11C45C

Entry point:
E8, 4D, 20, 01, 00, E9, 40, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 53, 33, DB, 39, 5D, 10, 75, 20, E8, 1E, D9, FF, FF, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, E5, FA, FF, FF, 83, C4, 14, 83, C8, FF, E9, 80, 00, 00, 00, 8B, 4D, 0C, 3B, CB, 56, 8B, 75, 08, 74, 21, 3B, F3, 75, 1D, E8, EF, D8, FF, FF, 53, 53, 53, 53, 53, C7, 00, 16, 00, 00, 00, E8, B6, FA, FF, FF, 83, C4, 14, 83, C8, FF, EB, 53, B8, FF, FF, FF, 7F, 3B, C8, 89, 45, E4, 77, 03, 89, 4D, E4, 57, FF, 75, 18, 8D, 45, E0, FF, 75, 14, C7, 45, EC...
 
[+]

Code size:
1.4 MB (1,425,408 bytes)

Service
Display name:
Winconnection 7

Service name:
Winconnection7

Type:
Win32OwnProcess


Scan wconnect7.exe - Powered by Reason Core Security