windrivetask.exe

Window Drive Manager updater

IT NAVIGATOR LLC

The application windrivetask.exe by IT NAVIGATOR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Window Drive Manager by Slideway Inc..
Publisher:
Slideway Inc.  (signed by IT NAVIGATOR LLC)

Product:
Window Drive Manager updater

Version:
1.3.4.3

MD5:
d74f32ba945517bc9d0255e3a4840c34

SHA-1:
3c4b99b513af715be36368e75bb1b2c1e30e2fa5

SHA-256:
9ce675f1496fb16ddc524222b99d179a92352bac795366588c0af71eaf830baf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 1:19:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinRaw (L)
16.9.2.20

File size:
1.7 MB (1,792,184 bytes)

Product version:
1.3.4.3

Copyright:
Copyright (C) 2015

Original file name:
Window Drive Manager updater

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\windriveuse\windrivetask.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2015 7:00:00 PM

Valid to:
12/19/2016 6:59:59 PM

Subject:
CN=IT NAVIGATOR LLC, OU=IT, O=IT NAVIGATOR LLC, STREET="Bud. 46a kv. 519, vul.Fedora Zaitseva", L=Kyyiv, S=Kyyiv, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
61BAEECB4D5416E1BE7333F527ED08F2

File PE Metadata
Compilation timestamp:
3/29/2016 11:35:14 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:DWj0lBOPWxUqp784mB0C9IZIf8NBjDlLwK+kFwUke+dRESdpm:6j0lBOuxx784mB0C+Z7BjDlLwK+kZ

Entry address:
0x11D855

Entry point:
E8, 51, 70, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 40, 40, 59, 00, 75, 02, F3, C3, E9, DD, 36, 00, 00, 55, 8B, EC, 8B, 45, 14, 56, 85, C0, 74, 3C, 83, 7D, 08, 00, 75, 13, E8, 6A, 2C, 00, 00, 6A, 16, 5E, 89, 30, E8, FC, 76, 00, 00, 8B, C6, EB, 25, 83, 7D, 10, 00, 74, E7, 39, 45, 0C, 73, 09, E8, 4C, 2C, 00, 00, 6A, 22, EB, E0, 50, FF, 75, 10, FF, 75, 08, E8, 1E, 77, 00, 00, 83, C4, 0C, 33, C0, 5E, 5D, C3, 55, 8B, EC, 56, 8B, F1, 8B, 4D, 08, C6, 46, 0C, 00, 85, C9, 75, 66, 57, E8, BE, 65, 00, 00, 8B, F8, 89, 7E...
 
[+]

Entropy:
6.5406

Code size:
1.3 MB (1,325,056 bytes)

The file windrivetask.exe has been discovered within the following program.

Window Drive Manager  by Slideway Inc.
About 4% of users remove it
 
Powered by Should I Remove It?

Remove windrivetask.exe - Powered by Reason Core Security