winsere.exe

Yan Jiang

The application winsere.exe by Yan Jiang has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a windows Service named “Winsere”.
Publisher:
Yan Jiang  (signed and verified)

MD5:
293c969f1cfd5da84f6146d5de4d817e

SHA-1:
d2eae29607f0aaa390ad2527513c0f5ab664aa69

SHA-256:
fb887333f40c9ad4ca40f34b43e1bb4abdc3d4e4ff05c0c3c22f7e41b15145cc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/2/2025 3:35:43 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX (M)
16.11.5.18

File size:
376 KB (385,015 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winsere\winsere\winsere.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/14/2016 6:00:00 AM

Valid to:
11/26/2016 5:59:59 AM

Subject:
CN=Yan Jiang, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0D086736E024A587D6959B6C9B0C8655

File PE Metadata
Compilation timestamp:
3/17/2016 6:55:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:Q7AahqP6YoQXnY4YyNSYU+fgfQgmnmCt1ovxBV+UdvrEFp7hKb7A:QfhqyYXXMogfQnt1ovxBjvrEH707A

Entry address:
0x1D15A

Entry point:
E9, 2E, 7F, FF, FF, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 10, 90, 44, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, F8, 72, 44, 00, 01, 0F, 82, 1B, 58, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03...
 
[+]

Entropy:
6.9231

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
218.5 KB (223,744 bytes)

Service
Display name:
Winsere

Description:
Enables the detection, download, and installation of updates for Winsere and other programs. If this service is disabled, users of this computer will not be able to use Winsere Update or its automatic

Type:
Win32OwnProcess, InteractiveProcess


Remove winsere.exe - Powered by Reason Core Security