Device Search Application.exe

Device Search Application

TATA Consultancy Services Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘wapp’.
Publisher:
TATA Consultancy Services Limited  (signed and verified)

Product:
Device Search Application

Version:
02.00.00

MD5:
b175214b398391964fac2bc46856c190

SHA-1:
1892ab2419dc51843ca34d91ac47070cedd7ee53

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 9:03:00 PM UTC  (today)

File size:
1.5 MB (1,564,240 bytes)

Product version:
02.00.00

Copyright:
NISSAN Copyright (C) 2010

Original file name:
Device Search Application.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/21/2012 1:00:00 AM

Valid to:
3/22/2015 12:59:59 AM

Subject:
CN=TATA Consultancy Services Limited, OU=EIS, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TATA Consultancy Services Limited, L=Pune, S=Maharashtra, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71364D24BDD9BBB6309812FD9251B02E

File PE Metadata
Compilation timestamp:
2/4/2013 9:05:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:i1TtDAFlkP0kET2ixV5enlhbEufM6+J10xImyw6/cM7UApiw6ps6l21KwDyCpol/:iVtD+Sri2TDmWyP/cPp2dJN4jlEAF

Entry address:
0x8545

Entry point:
E8, 0A, 48, 00, 00, E9, 78, FE, FF, FF, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04, 2B...
 
[+]

Code size:
82 KB (83,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
wapp

Command:
"C:\consult-iii_plus\system\middleware\nissan\vi2 application driver\device search application\device search application.exe"


Scan Device Search Application.exe - Powered by Reason Core Security