wincmd.exe

DVDVIDEOSOFT.ORG

The application wincmd.exe by DVDVIDEOSOFT.ORG has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft  (signed by DVDVIDEOSOFT.ORG)

Description:
Windows command

Version:
1.7.0.0

MD5:
4a32ef6be7267c5cd8a28d387b87c2ca

SHA-1:
723740a0a2a46f755e31603064cfa762f60ae18c

SHA-256:
f424ef1120c21570de9c2b95bce0a4e51c198817e5b49404650e6a669c7f45da

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 10:32:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.JiangsuCN
15.3.11.17

File size:
3.1 MB (3,237,968 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\win application\wincmd.exe

Digital Signature
Authority:
Root Agency

Valid from:
6/29/2014 7:25:53 AM

Valid to:
6/29/2017 7:25:52 AM

Subject:
CN=DVDVIDEOSOFT.ORG

Issuer:
CN=Root Agency

Serial number:
3DDC4527073ECA80403547242CF37D36

File PE Metadata
Compilation timestamp:
7/30/2014 4:38:36 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:GlaYlPQlaFRsCS8cBZfNoPjEwfG5WcHtLv6ByBicTGXiPT/4:GlNMaZEHLvoyBiuPk

Entry address:
0x211F4C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 5C, 60, 60, 00, E8, 58, 94, DF, FF, 33, C0, 55, 68, C9, 1F, 61, 00, 64, FF, 30, 64, 89, 20, E8, 25, 2A, DF, FF, 48, 7C, 49, A1, C8, E5, 61, 00, 8B, 00, E8, F6, EE, F0, FF, A1, C8, E5, 61, 00, 8B, 00, C6, 40, 5F, 00, A1, C8, E5, 61, 00, 8B, 00, 33, D2, E8, FD, 0B, F1, FF, 8B, 0D, 00, E3, 61, 00, A1, C8, E5, 61, 00, 8B, 00, 8B, 15, E8, 47, 60, 00, E8, DD, EE, F0, FF, A1, C8, E5, 61, 00, 8B, 00, E8, 35, F0, F0, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, D0, 1F, 61, 00, C3, E9, 8E, 49...
 
[+]

Entropy:
6.2121

Developed / compiled with:
Microsoft Visual C++

Code size:
2.1 MB (2,165,760 bytes)

Remove wincmd.exe - Powered by Reason Core Security