WinTouch.exe

WinTouch Application

The application WinTouch.exe has been detected as a potentially unwanted program by 33 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WinTouch’.
Product:
WinTouch Application

Version:
1, 0, 0, 2

MD5:
a7df3f17c0210038b94e517a83429f79

SHA-1:
73b2313850497db9914a08af50c601efc261c56f

Scanner detections:
33 / 68

Status:
Potentially unwanted

Analysis date:
4/1/2025 7:26:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.25091
-40

AegisLab AV Signature
Troj.Downloader.W32.Agent.sdy!c
2.1.4+

AhnLab V3 Security
Trojan/Win32.Agent.C86512
3.8.2.16

Avira AntiVirus
TR/Downloader.Gen
8.3.3.4

Arcabit
Trojan.Generic.D6203
1.0.0.791

avast!
Win32:Agent-JOY [Trj]
2014.9-170315

AVG
NaviPromo.M
2018.0.2438

Bitdefender
Trojan.Generic.25091
1.0.20.370

Comodo Security
TrojWare.Win32.TrojanDownloader.Agent.sdy
26293

Dr.Web
Trojan.Click.16757
9.0.1.074

Emsisoft Anti-Malware
Trojan.Generic.25091
8.17.03.15.08

ESET NOD32
Win32/Adware.Vomba.AA potentially unwanted (variant)
11.14625

Fortinet FortiGate
PossibleThreat
3/15/2017

F-Prot
W32/Downldr2.FNNX
v6.4.7.1.166

F-Secure
Trojan.Generic.25091
11.2017-15-03_4

G Data
Trojan.Generic.25091
17.3.25

IKARUS anti.virus
AdWare.Win32.Gabpath
0.1.3.4

K7 AntiVirus
Trojan-Downloader
13.246.21818

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.-1314

McAfee
Generic.dx!A7DF3F17C021
5600.6094

MicroWorld eScan
Trojan.Generic.25091
18.0.0.222

NANO AntiVirus
Trojan.Win32.Agent.qpua
1.0.70.13328

Panda Antivirus
Trj/Genetic.gen
17.03.15.08

Qihoo 360 Security
Win32/Trojan.Downloader.18b
1.0.0.1120

Rising Antivirus
Trojan.Generic-yKjUpDB08xV (cloud)
23.00.65.17313

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Net-Wintouch/V2
8533

Total Defense
Win32/Matcash.CD
37.1.62.1

Trend Micro House Call
TROJ_DLOADER.AMF
7.2.74

Trend Micro
TROJ_DLOADER.AMF
10.465.15

Vba32 AntiVirus
TrojanDownloader.Agent
3.12.26.4

VIPRE Antivirus
Trojan.Unclassified.gen
54572

Zillya! Antivirus
Downloader.Agent.Win32.91297
2.0.0.3156

File size:
165 KB (168,960 bytes)

Product version:
1, 0, 0, 2

Copyright:
Copyright (C) 2007

Original file name:
WinTouch.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Application data\wintouch\wintouch.exe

File PE Metadata
Compilation timestamp:
8/24/2007 3:00:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x853E0

Entry point:
60, BE, 00, D0, 45, 00, 8D, BE, 00, 40, FA, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
164 KB (167,936 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WinTouch

Command:
C:\Documents and Settings\{user}\Application data\wintouch\wintouch.exe


Remove WinTouch.exe - Powered by Reason Core Security