Windesk Winsearch.exe

PC Software

The application Windesk Winsearch.exe by PC Software has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Windesk Winsearch’.
Publisher:
Windesk Winsearch  (signed by PC Software)

Product:
Windesk Winsearch

Version:
1.0.0.0

MD5:
5c8962ead835d2a7dd8fd03c045c5021

SHA-1:
d7b96eb784d4f5becb726e38c1847a9f1edcbbae

SHA-256:
ba6d9ca56dba59ffa58b645a9440ac62ed8d3fad9dea9eef8654ac8606a0e68e

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 3:36:29 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2851
9.0.1.05190

Reason Heuristics
PUP.PCSoftwa (M)
16.6.26.0

File size:
1.1 MB (1,133,448 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Trademarks:
Windesk Winsearch

Original file name:
Windesk Winsearch.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\Program Files\windeskwinsearch\windesk winsearch.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/10/2014 12:00:00 AM

Valid to:
9/10/2015 11:59:59 PM

Subject:
CN=PC Software, O=PC Software, STREET=5655 Silver Creek Valley Road, L=San Jose, S=CA, PostalCode=95138, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FFFC8D338C67107439C065EF8036902F

File PE Metadata
Compilation timestamp:
4/8/2015 1:42:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:8w+r/iMgCBNtew+r/iMgCBNtHE+rvi8gCBNt+Ve:8w+r6MgENtew+r6MgENtHE+rK8gENt+o

Entry address:
0xB259E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 06, 25, 55, 00, 00, 00, 00, 02, 00, 00, 00, 85, 00, 00, 00, 1C, 40, 0B, 00, 1C, 0A, 0B, 00, 52, 53...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
705.5 KB (722,432 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Windesk Winsearch

Command:
C:\Program Files\windeskwinsearch\windesk winsearch.exe


Remove Windesk Winsearch.exe - Powered by Reason Core Security