check.exe

Conkeeper

iMBC Co., Ltd.

Publisher:
iMBC  (signed by iMBC Co., Ltd.)

Product:
Conkeeper

Version:
1.0.0.7

MD5:
0e3025237d6059a072c2874cd89bfb9c

SHA-1:
aade73b719ed9fb5bcbb79886840d772e084371d

SHA-256:
f6f84c9dc3422f6371a7cda37b72a58f50ac0b043a3ba9f3760cd114b94e11d9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 8:35:09 PM UTC  (today)

File size:
9.3 MB (9,754,056 bytes)

Product version:
1.0.0.7

Copyright:
iMBC All rights reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gfile\gmf\check.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/21/2016 9:00:00 AM

Valid to:
5/8/2016 8:59:59 AM

Subject:
CN="iMBC Co., Ltd.", O="iMBC Co., Ltd.", L=Mapo-gu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0F6F12D10474ED4D1C13A26F4E401BCE

File PE Metadata
Compilation timestamp:
4/20/2016 2:29:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:9hibW1DHpTGTG6TM3TNSEEyUfvE9WAXT2dR8hEHsMDcIV4VNEGPf:XHDFENvI494VeGX

Entry address:
0x1758E

Entry point:
E8, 70, 05, 00, 00, E9, 63, FD, FF, FF, FF, 25, F0, C0, 46, 00, FF, 25, F4, C0, 46, 00, FF, 25, F8, C0, 46, 00, FF, 25, FC, C0, 46, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 8F, 48, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, FF, 25, 00, C1, 46, 00, FF, 25, 04, C1, 46, 00, FF, 25, 08, C1, 46, 00, FF, 25, 0C, C1...
 
[+]

Entropy:
6.6581

Code size:
426 KB (436,224 bytes)

The file check.exe has been discovered within the following program.

Wedisk Plug-in  by EZWON.Co.,Ltd
gl.wedisk.co.kr
About 9% of users remove it
 
Powered by Should I Remove It?

The file check.exe has been seen being distributed by the following 5 URLs.

http://apppatch.mfile.co.kr/update/new/.../Check.exe

http://patch.pdpop.com/appx/.../Check.exe

Scan check.exe - Powered by Reason Core Security