DWRCST.exe

DameWare Development DWRCST

DameWare Development, LLC.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DameWare MRC Agent’.
Publisher:
DameWare Development  (signed by DameWare Development, LLC.)

Product:
DameWare Development DWRCST

Description:
DameWare Mini Remote Control User Interface

Version:
7, 1, 0, 0

MD5:
fd2c27b65a33f76b284904ea2501a500

SHA-1:
7683f23c612869143bb60e489112b86cefe2cb84

SHA-256:
842762004406124b32b2894c543966eaf041413f7b693086e0ea60aa9faecae2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 5:17:38 AM UTC  (today)

File size:
291.4 KB (298,360 bytes)

Product version:
7, 1, 0, 0

Copyright:
Copyright © 1991-2011 DameWare Development LLC

Trademarks:
DameWare Mini Remote Control

Original file name:
DWRCST.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\windows\dwrcs\dwrcst.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/12/2008 2:00:00 AM

Valid to:
9/25/2011 1:59:59 AM

Subject:
CN="DameWare Development, LLC.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="DameWare Development, LLC.", L=Mandeville, S=Louisiana, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
75F6AA86C621CE342E7076E3E225243E

File PE Metadata
Compilation timestamp:
2/3/2011 9:58:04 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:hs7zDaAMvCgGQRNUoSA4OPlwtzP0lDu0212Kf:+7zSvpGQzUrn0W2m

Entry address:
0x12E64

Entry point:
48, 83, EC, 28, E8, 87, 60, 00, 00, 48, 83, C4, 28, E9, 1A, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90, 8A, 10, 48, FF, C0, 84, D2, 74, 5F, A8, 07, 75, F3, 49, B8, FF, FE, FE, FE, FE, FE, FE, 7E, 49, BB, 00, 01, 01, 01, 01, 01, 01, 81, 48, 8B, 10, 4D, 8B, C8, 48, 83, C0, 08, 4C, 03, CA, 48, F7, D2, 49, 33, D1, 49, 23, D3, 74, E8, 48, 8B, 50, F8, 84, D2, 74, 51, 84, F6, 74...
 
[+]

Code size:
126.5 KB (129,536 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DameWare MRC Agent

Command:
C:\windows\dwrcs\dwrcst.exe


Scan DWRCST.exe - Powered by Reason Core Security