winsecurity.exe

Microsoft Windows Operating System

Lei Qing

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application winsecurity.exe by Lei Qing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Windows Security”.
Publisher:
Microsoft Corporation  (signed by Lei Qing)

Product:
Microsoft Windows Operating System

Description:
Windows Security

Version:
6.3.9600.17284 (aaa.140822-1915)

MD5:
78be0e10fe35200923095b9b3aaaf896

SHA-1:
0a901d32244df8ec728564cfe66c66fdd3286bb1

SHA-256:
16870cb36dede7e0e25b60dd6697791af7a4ea82929b65b3726e8a5632fdd965

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
3/7/2026 2:31:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex.LeiQing.Meta (M)
16.7.9.11

File size:
6.9 MB (7,246,288 bytes)

Copyright:
Microsoft Corporation. All rights reserved.

Original file name:
winsecurity.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\windows security\winsecurity.exe

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
8/19/2015 5:00:23 AM

Valid to:
8/19/2016 5:00:23 AM

Subject:
CN=Lei Qing, L=Tianjin, S=Tianjin, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
2B8E845E7AA055FC643B525DF3001A41

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.0

CTPH (ssdeep):
49152:ZXjSiv28JaDECX/0vTlc58v8grOoRzjSUMxwV5MNJX/0c8YYQP9b5PFfCHewj2jH:9SirJaRX/4QgrOoE4WWFA

Entry address:
0x54340

Entry point:
83, EC, 0C, 8B, 44, 24, 0C, 8D, 5C, 24, 10, 89, 44, 24, 04, 89, 5C, 24, 08, C7, 04, 24, FF, FF, FF, FF, E9, 01, 00, 00, 00, CC, E9, 0B, D3, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 5C, 24, 04, 64, C7, 05, 34, 00, 00, 00, 00, 00, 00, 00, 89, E5, 8B, 4B, 04, 89, C8, C1, E0, 02, 29, C4, 89, E7, 8B, 73, 08, FC, F3, A5, FF, 13, 89, EC, 8B, 5C, 24, 04, 89, 43, 0C, 89, 53, 10, 64, 8B, 05, 34, 00, 00, 00, 89, 43, 14, C3, CC, CC, CC, CC, 83, EC, 18, C7, 04, 24, F4, FF, FF, FF, 89, E5, FF, 15, 58, A0...
 
[+]

Code size:
4.6 MB (4,818,432 bytes)

Service
Display name:
Windows Security

Service name:
WindowsSecurity

Type:
Win32OwnProcess


Remove winsecurity.exe - Powered by Reason Core Security