winfindsync.exe

Window Find Manager

IT NAVIGATOR LLC

The application winfindsync.exe by IT NAVIGATOR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Window Find Manager”. This file is typically installed with the program Window Find Manager by Labour LLC. While running, it connects to the Internet address oas-stats.sdev.pw on port 80 using the HTTP protocol.
Publisher:
Labour LLC  (signed by IT NAVIGATOR LLC)

Product:
Window Find Manager

Version:
12.5.90.4

MD5:
c24201389f528d63ea4faf067b04a184

SHA-1:
54b919119b8bf4a434e3d5813e0e212cae292ee4

SHA-256:
c646f3d7b633f1f71050fb48fe39c6cec3c56b2f6dcebc5cce8e8fd856651944

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 1:00:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinRaw (L)
16.9.2.20

File size:
137.7 KB (140,984 bytes)

Product version:
12.5.90.4

Copyright:
Copyright (C) 2015

Original file name:
Window Find Manager

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\windfind\winfindsync.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2015 6:00:00 PM

Valid to:
12/19/2016 5:59:59 PM

Subject:
CN=IT NAVIGATOR LLC, OU=IT, O=IT NAVIGATOR LLC, STREET="Bud. 46a kv. 519, vul.Fedora Zaitseva", L=Kyyiv, S=Kyyiv, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
61BAEECB4D5416E1BE7333F527ED08F2

File PE Metadata
Compilation timestamp:
5/9/2016 9:07:18 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
3072:tCNuXHTKbJ0xau1Jvn6p3mjnih3EYDUKFODx:tpoJHu1fih3lfg

Entry address:
0x6DEB

Entry point:
E8, D7, 69, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, FF, 15, 00, 71, 41, 00, 6A, 01, A3, CC, 07, 42, 00, E8, F6, 6A, 00, 00, FF, 75, 08, E8, 9E, 6E, 00, 00, 83, 3D, CC, 07, 42, 00, 00, 59, 59, 75, 08, 6A, 01, E8, DC, 6A, 00, 00, 59, 68, 09, 04, 00, C0, E8, 6C, 6E, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, AE, DF, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, B0, 05, 42, 00, 89, 0D, AC, 05, 42, 00, 89, 15, A8, 05, 42, 00, 89, 1D, A4, 05, 42, 00, 89, 35, A0, 05, 42, 00, 89, 3D, 9C...
 
[+]

Entropy:
6.4552

Code size:
86 KB (88,064 bytes)

Service
Display name:
Window Find Manager

Service name:
WinFindSvc

Type:
Win32OwnProcess


The file winfindsync.exe has been discovered within the following program.

Window Find Manager  by Labour LLC
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to oas-stats.sdev.pw  (162.221.224.45:80)

Remove winfindsync.exe - Powered by Reason Core Security