Windesk Winsearch.exe

PC Software

The application Windesk Winsearch.exe by PC Software has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windesk Winsearch’.
Publisher:
Windesk Winsearch  (signed by PC Software)

Product:
Windesk Winsearch

Version:
1.0.0.0

MD5:
11bc9d6be1480fd608658b9887ef5cfb

SHA-1:
a69367ca4d492c2c63c3db64aac56cd81c319b22

SHA-256:
86fd40a76eb8d6927391e8e776b3c12c91a240830625af466e3a5ce04f861c25

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 5:30:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PCSoftware (M)
16.1.15.0

VIPRE Antivirus
Threat.4786532
39486

File size:
1 MB (1,061,256 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Trademarks:
Windesk Winsearch

Original file name:
Windesk Winsearch.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\windeskwinsearch\windesk winsearch.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/9/2014 7:00:00 PM

Valid to:
9/10/2015 6:59:59 PM

Subject:
CN=PC Software, O=PC Software, STREET=5655 Silver Creek Valley Road, L=San Jose, S=CA, PostalCode=95138, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FFFC8D338C67107439C065EF8036902F

File PE Metadata
Compilation timestamp:
3/30/2015 4:29:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:aw+r/iMgCBNtew+r/iMgCBNtjE+rvi8gCBNt:aw+r6MgENtew+r6MgENtjE+rK8gENt

Entry address:
0xB259E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 2E, C0, 19, 55, 00, 00, 00, 00, 02, 00, 00, 00, 99, 00, 00, 00, 1C, 40, 0B, 00, 1C, 0A, 0B, 00, 52, 53...
 
[+]

Entropy:
7.1835

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
705.5 KB (722,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windesk Winsearch

Command:
C:\Program Files\windeskwinsearch\windesk winsearch.exe


Remove Windesk Winsearch.exe - Powered by Reason Core Security