winsere.exe

Yan Jiang

The application winsere.exe by Yan Jiang has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a windows Service named “Winsere”.
Publisher:
Yan Jiang  (signed and verified)

MD5:
189b8f47ff7c2c73a105dc8b454f33dc

SHA-1:
956158d22b67d2b486ee65c1bc77e87a265fce9a

SHA-256:
c0277030cb202fc43d4749fe7bf7db6a278cec1717f49082c5f06ee994787702

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/2/2025 3:33:38 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX (M)
17.1.20.0

File size:
3.5 MB (3,661,824 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winsere\winsere\winsere.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/14/2016 8:00:00 AM

Valid to:
11/26/2016 7:59:59 AM

Subject:
CN=Yan Jiang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0D086736E024A587D6959B6C9B0C8655

File PE Metadata
Compilation timestamp:
3/15/2016 9:39:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x1D14E

Entry point:
E8, 81, 53, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 4C, 90, 44, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 70, 74, 44, 00, 01, 0F, 82, 99, 58, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83...
 
[+]

Entropy:
0.8442

Code size:
218.5 KB (223,744 bytes)

Service
Display name:
Winsere

Description:
Enables the detection, download, and installation of updates for Winsere and other programs. If this service is disabled, users of this computer will not be able to use Winsere Update or its automatic

Type:
Win32OwnProcess, InteractiveProcess


Remove winsere.exe - Powered by Reason Core Security