iestart_x64.exe

ZenSearch

The application iestart_x64.exe by ZenSearch has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program ZenSearch by ZenSearch ApS which is a potentially unwanted software program.
Publisher:
ZenSearch  (signed and verified)

MD5:
39a4aa00130556a50fcabaf2227b52f2

SHA-1:
ea0c1ae5b170adaf2807e5105ca60e918b0ed7a4

SHA-256:
598feb46b151e8224cf88e5ad1fe965dcddeb616be2e7e01be7d97255abeec42

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 1:45:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ZenSearch.L
14.8.31.22

File size:
171.7 KB (175,800 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\zensearch\iestart_x64.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/8/2013 5:00:00 PM

Valid to:
9/8/2016 4:59:59 PM

Subject:
CN=ZenSearch, O=ZenSearch, STREET=Bysoestraede 2B, L=Holbaek, S=DK, PostalCode=4300, C=DK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C453BD7E7881A198DDECCC1FC432D3ED

File PE Metadata
Compilation timestamp:
2/14/2014 2:00:45 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:cUW4QcB1Actlu4TQeBBOoRbVqnbsFbDR+CZcibzpE:cMQitlpTHIoRbVqnIFFLcibzpE

Entry address:
0x2550

Entry point:
48, 83, EC, 28, E8, 6F, 6B, 00, 00, 48, 83, C4, 28, E9, 36, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 20, 48, 8B, D9, FF, 15, E5, EB, 00, 00, B9, 01, 00, 00, 00, 89, 05, 82, A6, 01, 00, E8, CD, 6C, 00, 00, 48, 8B, CB, E8, B1, 44, 00, 00, 83, 3D, 6E, A6, 01, 00, 00, 75, 0A, B9, 01, 00, 00, 00, E8, B2, 6C, 00, 00, B9, 09, 04, 00, C0, 48, 83, C4, 20, 5B, E9, 6F, 44, 00, 00, CC, CC, CC, 48, 89, 4C, 24, 08, 48, 83, EC, 38, B9, 17, 00, 00, 00, E8, 09, BE, 00, 00, 85, C0, 74, 07, B9, 02, 00, 00, 00, CD, 29, 48, 8D...
 
[+]

Entropy:
5.6442

Code size:
62 KB (63,488 bytes)

The file iestart_x64.exe has been discovered within the following program.

ZenSearch  by ZenSearch ApS
From the EULA: "As part of the installation process of the Software, we may change your Internet Browser settings and/or provide you with the ability to opt to make changes to your Internet Browser settings.
zensearch.com
74% remove it
 
Powered by Should I Remove It?

Remove iestart_x64.exe - Powered by Reason Core Security