qdesk.exe

ZhongXiang ZhiXing Network Service Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Qdesk’.
Publisher:

MD5:
bd7e3e5b8dc96292ff94b5f8aa28ee37

SHA-1:
06c80817658c382bb950ee20d9aa1ebf62c1d9e8

SHA-256:
6aa695306ac965584d0c4449d1bae74d6340e8c2e871ae308643eca45e5a05c7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 3:45:35 PM UTC  (today)

File size:
2.3 MB (2,389,448 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\qdesk\qdesk.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/21/2011 8:00:00 AM

Valid to:
7/21/2012 7:59:59 AM

Subject:
CN="ZhongXiang ZhiXing Network Service Co., Ltd.", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="ZhongXiang ZhiXing Network Service Co., Ltd.", L=ZhongXiang, S=HuBei, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
358252724C2051F6C0E98451E597F300

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:0E0rPHz8fomXUvy2kwsIdwi/bUzYgAck+T:0nrPgfUdwldAH+T

Entry address:
0x15BC44

Entry point:
55, 8B, EC, 83, C4, F0, B8, CC, B5, 55, 00, E8, E8, AA, EA, FF, 68, B0, BC, 55, 00, 68, C0, BC, 55, 00, E8, 5D, B5, EA, FF, 85, C0, 76, 11, 6A, 00, 6A, 00, 68, 00, 14, 00, 00, 50, E8, 22, B8, EA, FF, EB, 30, A1, 38, 2E, 56, 00, 8B, 00, E8, 74, 93, F1, FF, 8B, 0D, AC, 2A, 56, 00, A1, 38, 2E, 56, 00, 8B, 00, 8B, 15, A8, 65, 55, 00, E8, 74, 93, F1, FF, A1, 38, 2E, 56, 00, 8B, 00, E8, E8, 93, F1, FF, E8, 33, 85, EA, FF, 00, 00, 00, 51, 64, 65, 73, 6B, 4D, 61, 69, 6E, 46, 6F, 72, 6D, 00, 00, 00, 51, 44, 65, 73...
 
[+]

Entropy:
6.9174

Developed / compiled with:
Microsoft Visual C++

Code size:
1.4 MB (1,420,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Qdesk

Command:
"C:\Program Files\qdesk\qdesk.exe" \start


Scan qdesk.exe - Powered by Reason Core Security