winfindsync_.exe

Window Find Manager

IT NAVIGATOR LLC

The application winfindsync_.exe by IT NAVIGATOR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Window Find Manager2”. This file is typically installed with the program Window Find Manager by Labour LLC. While running, it connects to the Internet address oas-stats.sdev.pw on port 80 using the HTTP protocol.
Publisher:
Labour LLC  (signed by IT NAVIGATOR LLC)

Product:
Window Find Manager

Version:
12.5.90.4

MD5:
87770861362f417521fb25b4dc030d39

SHA-1:
fa6fe7c75baf2cf4d1f29b6e3011ab5b115f4b69

SHA-256:
98847eb15699b44892d4576aacb9f92a06c264eec98317991ae77ffc32902778

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 12:57:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinRaw (L)
16.9.2.20

File size:
150.2 KB (153,784 bytes)

Product version:
12.5.90.4

Copyright:
Copyright (C) 2015

Original file name:
Window Find Manager

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\windfind\winfindsync_.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2015 6:00:00 PM

Valid to:
12/19/2016 5:59:59 PM

Subject:
CN=IT NAVIGATOR LLC, OU=IT, O=IT NAVIGATOR LLC, STREET="Bud. 46a kv. 519, vul.Fedora Zaitseva", L=Kyyiv, S=Kyyiv, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
61BAEECB4D5416E1BE7333F527ED08F2

File PE Metadata
Compilation timestamp:
5/9/2016 9:04:51 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

CTPH (ssdeep):
3072:6Hv/thEZvZ03Civ3ifP2MWTe6EPeFMcZqd28HfG+tODTt:sXkvZ03CMqtWTegpmP0

Entry address:
0x59B6

Entry point:
E8, 10, 06, 00, 00, E9, 7A, FE, FF, FF, 55, 8B, EC, 6A, 00, FF, 15, 24, A1, 41, 00, FF, 75, 08, FF, 15, 20, A1, 41, 00, 68, 09, 04, 00, C0, FF, 15, C4, A0, 41, 00, 50, FF, 15, C0, A0, 41, 00, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 5C, 29, 01, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 90, 3B, 42, 00, 89, 0D, 8C, 3B, 42, 00, 89, 15, 88, 3B, 42, 00, 89, 1D, 84, 3B, 42, 00, 89, 35, 80, 3B, 42, 00, 89, 3D, 7C, 3B, 42, 00, 66, 8C, 15, A8, 3B, 42, 00, 66, 8C, 0D, 9C, 3B, 42, 00, 66, 8C, 1D, 78...
 
[+]

Entropy:
6.5213

Code size:
98 KB (100,352 bytes)

Service
Display name:
Window Find Manager2

Service name:
WinFindSvc2

Type:
Win32OwnProcess


The file winfindsync_.exe has been discovered within the following program.

Window Find Manager  by Labour LLC
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to oas-stats.sdev.pw  (162.221.224.45:80)

Remove winfindsync_.exe - Powered by Reason Core Security