Windesk Winsearch.exe

PC Software

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windesk Winsearch’.
Publisher:
Windesk Winsearch  (signed by PC Software)

Product:
Windesk Winsearch

Version:
1.0.0.0

MD5:
da8d11fdc56a6de18a9c4787aaad3e10

SHA-1:
b45e294e84ffd5c569d6fc60321d52ac14642c31

SHA-256:
4c633213c451b6a8813db5fc027a58384c89336ec624a90550fd6d479e04694b

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/27/2024 3:55:18 PM UTC  (today)

Scan engine
Detection
Engine version

Sophos
Winsearch
4.98

Trend Micro House Call
Suspicious_GEN.F47V0429
7.2.131

VIPRE Antivirus
InstallMonetizer
40054

File size:
1 MB (1,060,744 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Trademarks:
Windesk Winsearch

Original file name:
Windesk Winsearch.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\windeskwinsearch\windesk winsearch.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/9/2014 9:00:00 PM

Valid to:
9/10/2015 8:59:59 PM

Subject:
CN=PC Software, O=PC Software, STREET=5655 Silver Creek Valley Road, L=San Jose, S=CA, PostalCode=95138, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FFFC8D338C67107439C065EF8036902F

File PE Metadata
Compilation timestamp:
4/8/2015 1:34:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:4w+r/iMgCBNtew+r/iMgCBNtAE+rvi8gCBNt:4w+r6MgENtew+r6MgENtAE+rK8gENt

Entry address:
0xB259E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A0, 58, 25, 55, 00, 00, 00, 00, 02, 00, 00, 00, 85, 00, 00, 00, 1C, 40, 0B, 00, 1C, 0A, 0B, 00, 52, 53...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
705.5 KB (722,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windesk Winsearch

Command:
C:\Program Files\windeskwinsearch\windesk winsearch.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ocsp.comodoca.com  (178.255.83.1:80)

Scan Windesk Winsearch.exe - Powered by Reason Core Security