Windesk Winsearch.exe

PC Software

The executable Windesk Winsearch.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windesk Winsearch’.
Publisher:
Windesk Winsearch  (signed by PC Software)

Product:
Windesk Winsearch

Version:
1.0.0.0

MD5:
da8d11fdc56a6de18a9c4787aaad3e10

SHA-1:
094742f7e2b0c8c91a5c00aa2ed66982930faf96

SHA-256:
4c633213c451b6a8813db5fc027a58384c89336ec624a90550fd6d479e04694b

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 3:46:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.6.17

File size:
1 MB (1,060,744 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Trademarks:
Windesk Winsearch

Original file name:
Windesk Winsearch.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\windeskwinsearch\windesk winsearch.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/9/2014 7:00:00 PM

Valid to:
9/10/2015 6:59:59 PM

Subject:
CN=PC Software, O=PC Software, STREET=5655 Silver Creek Valley Road, L=San Jose, S=CA, PostalCode=95138, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FFFC8D338C67107439C065EF8036902F

File PE Metadata
Compilation timestamp:
4/8/2015 11:34:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0xB259E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A0, 58, 25, 55, 00, 00, 00, 00, 02, 00, 00, 00, 85, 00, 00, 00, 1C, 40, 0B, 00, 1C, 0A, 0B, 00, 52, 53...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
705.5 KB (722,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windesk Winsearch

Command:
C:\Program Files\windeskwinsearch\windesk winsearch.exe


Remove Windesk Winsearch.exe - Powered by Reason Core Security