windrivesync_.exe

Window Drive Manager

IT NAVIGATOR LLC

The application windrivesync_.exe by IT NAVIGATOR has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Window Drive Manager2”. This file is typically installed with the program Window Drive Manager by Slideway Inc..
Publisher:
Slideway Inc.  (signed by IT NAVIGATOR LLC)

Product:
Window Drive Manager

Version:
12.5.80.3

MD5:
fb4166136d297916f8554b97fbaa6dc8

SHA-1:
e9ccdbc1494b515858dddbf90342371ad28506fc

SHA-256:
0925088400bd791f317bc16da7caf261cbcc7ddc9c46748078e71a8ac6a64595

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
8/10/2025 12:11:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WinRaw (L)
16.9.2.20

File size:
137.7 KB (140,984 bytes)

Product version:
12.5.80.3

Copyright:
Copyright (C) 2015

Original file name:
Window Drive Manager

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\windriveuse\windrivesync_.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2015 7:00:00 PM

Valid to:
12/19/2016 6:59:59 PM

Subject:
CN=IT NAVIGATOR LLC, OU=IT, O=IT NAVIGATOR LLC, STREET="Bud. 46a kv. 519, vul.Fedora Zaitseva", L=Kyyiv, S=Kyyiv, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
61BAEECB4D5416E1BE7333F527ED08F2

File PE Metadata
Compilation timestamp:
3/30/2016 7:30:47 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.0

CTPH (ssdeep):
3072:2a6QqIARKpAxcVX3Jwr2prmjY2L2EYDogHODC6:2tKlphVH6T2lts

Entry address:
0x6DEF

Entry point:
E8, D3, 69, 00, 00, E9, 7B, FE, FF, FF, 55, 8B, EC, FF, 15, 00, 71, 41, 00, 6A, 01, A3, CC, 07, 42, 00, E8, F2, 6A, 00, 00, FF, 75, 08, E8, 9A, 6E, 00, 00, 83, 3D, CC, 07, 42, 00, 00, 59, 59, 75, 08, 6A, 01, E8, D8, 6A, 00, 00, 59, 68, 09, 04, 00, C0, E8, 68, 6E, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, AA, DF, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, B0, 05, 42, 00, 89, 0D, AC, 05, 42, 00, 89, 15, A8, 05, 42, 00, 89, 1D, A4, 05, 42, 00, 89, 35, A0, 05, 42, 00, 89, 3D, 9C...
 
[+]

Entropy:
6.4557

Code size:
86 KB (88,064 bytes)

Service
Display name:
Window Drive Manager2

Service name:
WinDriveSvc2

Type:
Win32OwnProcess


The file windrivesync_.exe has been discovered within the following program.

Window Drive Manager  by Slideway Inc.
About 4% of users remove it
 
Powered by Should I Remove It?

Remove windrivesync_.exe - Powered by Reason Core Security