wincmd.exe

DVDVIDEOSOFT.ORG

The application wincmd.exe by DVDVIDEOSOFT.ORG has been detected as a potentially unwanted program by 10 anti-malware scanners.
Publisher:
Microsoft  (signed by DVDVIDEOSOFT.ORG)

Description:
Windows command

Version:
1.7.0.0

MD5:
96cdf82b2e9bd29cd2e7bd4d09f18041

SHA-1:
f7e265b8cc2056aab6cebf664b87b212179af446

SHA-256:
b5fb84e78be89f52a6ca542db783f8f2d324d078fd3c3dfe46e0f8a77490287f

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:03:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Trojan.Heur.dR1@rezPTtbi
941

avast!
Win32:Malware-gen
2014.9-140709

Bitdefender
Gen:Trojan.Heur.dR1@rezPTtbi
1.0.20.950

Emsisoft Anti-Malware
Gen:Trojan.Heur.dR1@rezPTtbi
8.14.07.09.10

F-Prot
W32/Threat-SysVenFak-based!Maxi
v6.4.7.1.166

F-Secure
Gen:Trojan.Heur.dR1@rezPTtbi
11.2014-09-07_4

G Data
Gen:Trojan.Heur.dR1@rezPTtbi
14.7.24

MicroWorld eScan
Gen:Trojan.Heur.dR1@rezPTtbi
15.0.0.570

Norman
Suspicious.B!genr
11.20140709

Reason Heuristics
PUP.JiangsuCN
15.3.11.17

File size:
3.1 MB (3,205,032 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\win application\wincmd.exe

Digital Signature
Authority:
Root Agency

Valid from:
6/29/2014 10:55:53 AM

Valid to:
6/29/2017 10:55:52 AM

Subject:
CN=DVDVIDEOSOFT.ORG

Issuer:
CN=Root Agency

Serial number:
3DDC4527073ECA80403547242CF37D36

File PE Metadata
Compilation timestamp:
7/3/2014 7:58:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Y4/NRYdZS+BPvvK85bTnICQUjO7HipCk95aiJT3c5iRM:3VI9ICs2pl95aiY

Entry address:
0x20BEE8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 08, F8, 5F, 00, E8, BC, F4, DF, FF, 33, C0, 55, 68, 65, BF, 60, 00, 64, FF, 30, 64, 89, 20, E8, 89, 8A, DF, FF, 48, 7C, 49, A1, BC, 85, 61, 00, 8B, 00, E8, D6, 3C, F1, FF, A1, BC, 85, 61, 00, 8B, 00, C6, 40, 5F, 00, A1, BC, 85, 61, 00, 8B, 00, 33, D2, E8, DD, 59, F1, FF, 8B, 0D, F8, 82, 61, 00, A1, BC, 85, 61, 00, 8B, 00, 8B, 15, E4, E3, 5F, 00, E8, BD, 3C, F1, FF, A1, BC, 85, 61, 00, 8B, 00, E8, 15, 3E, F1, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 6C, BF, 60, 00, C3, E9, F2, A9...
 
[+]

Entropy:
6.2085

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,139,136 bytes)

Remove wincmd.exe - Powered by Reason Core Security