winzipdu.exe

WinZip Driver Updater

WinZip Computing LLC

It runs as a scheduled task under the Windows Task Scheduler named WinZipDriverUpdaterRunAtStartup triggered to execute each time a user logs in.
Publisher:
WinZip Computing, S.L. (WinZip Computing)  (signed by WinZip Computing LLC)

Product:
WinZip Driver Updater

Version:
1.0.648.16566

MD5:
d192d1f0b9aa4a7a6fdd047ffa39e7f2

SHA-1:
251f52dbcc25f542ee3ebf829d1b8afe164235bb

SHA-256:
698e40bc0c5ec1b2e62917dbfa6893561a0ceaa8c9c6681db197aec3e6816a2f

Scanner detections:
16 / 68

Status:
Clean  (16 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/16/2024 10:05:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.1286181
357

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
DriverCleaner.SysTweak
2017.0.2835

Bitdefender
Adware.Generic.1286181
1.0.20.215

Bkav FE
W32.HfsAdware
1.3.0.7062

Emsisoft Anti-Malware
Adware.Generic.1286181
8.16.02.12.03

ESET NOD32
Win32/Systweak.R potentially unwanted
10.12103

Fortinet FortiGate
Riskware/Systweak
2/12/2016

F-Secure
Adware.Generic.1286181
11.2016-12-02_6

G Data
Adware.Generic.1286181
16.2.25

K7 AntiVirus
Adware
13.2016902

McAfee
Artemis!CDB6FD0CDB34
5600.6491

MicroWorld eScan
Adware.Generic.1286181
17.0.0.129

Qihoo 360 Security
Win32/Virus.fe8
1.0.0.1015

Sophos
Generic PUA EI (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
42940

File size:
10.8 MB (11,344,040 bytes)

Product version:
1.0.648.16566

Copyright:
Copyright (C) 2011 Systweak Inc., All rights reserved.

Trademarks:
WinZip Driver Updater

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\winzip driver updater\winzipdu.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/9/2013 6:49:58 PM

Valid to:
7/10/2015 6:49:58 PM

Subject:
E=help@winzip.com, CN=WinZip Computing LLC, O=WinZip Computing LLC, L=Storrs Mansfield, S=CT, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112144096D1CB7E1128D086CAB8DEEAB88F2

File PE Metadata
Compilation timestamp:
2/3/2015 6:46:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:nozy+eDKfMlU+g7qwbKg5yNikXcS/6ODhwSgP+/kqMf3:ozBxfFp7qBg5c9/4f3

Entry address:
0x105765

Entry point:
E8, F0, B1, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, A8, 57, 82, 00, 75, 02, F3, C3, E9, 72, B2, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 9A, 6A, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, AE, 06, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 38, B3, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 77, 71, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Code size:
3.7 MB (3,905,536 bytes)

Scheduled Task
Task name:
WinZipDriverUpdaterRunAtStartup

Trigger:
Logon (Runs on logon)


Scan winzipdu.exe - Powered by Reason Core Security