desktop.exe

Desktop

4sync Inc.

The application desktop.exe by 4sync has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
New IT Solutions  (signed by 4sync Inc.)

Product:
Desktop

Version:
4.0.11.26545

MD5:
216b900255c4a72e9846301bc7be4c32

SHA-1:
1d82841bfd4d21845e907fd7a12e77bfaf07678f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 10:14:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewITSolutions.Optional (L)
17.1.31.23

File size:
13.2 MB (13,879,256 bytes)

Product version:
4.0

Copyright:
New IT Solutions

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\4shared desktop\desktop.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/21/2013 7:56:47 PM

Valid to:
10/21/2016 7:56:47 PM

Subject:
CN=4sync Inc., O=4sync Inc., L=San Francisco, S=California, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B26471C28D70E

File PE Metadata
Compilation timestamp:
8/26/2014 6:28:45 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x871EFC

Entry point:
55, 8B, EC, 83, C4, EC, 53, 33, C0, 89, 45, EC, B8, E0, 1B, C5, 00, E8, 72, E6, 79, FF, 33, C0, 55, 68, 46, 20, C7, 00, 64, FF, 30, 64, 89, 20, 8D, 45, EC, 8B, 15, 20, 70, C9, 00, 8B, 12, E8, 7C, 9E, 79, FF, 8B, 55, EC, B9, 01, 00, 00, 00, B8, 60, 20, C7, 00, E8, 4E, A4, 79, FF, 8B, D8, 68, 7C, 20, C7, 00, 68, 9C, 20, C7, 00, E8, 35, 34, 7A, FF, 85, C0, 75, 0F, 68, 7C, 20, C7, 00, 68, AC, 20, C7, 00, E8, 22, 34, 7A, FF, 85, C0, 74, 3E, 85, DB, 7E, 11, A1, 20, 71, C9, 00, 8B, 00, E8, AE, A8, 9C, FF, E9, B1...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
8.4 MB (8,849,920 bytes)

Remove desktop.exe - Powered by Reason Core Security