gctrainer.exe

The executable gctrainer.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www443.megaupload.com.
MD5:
2caa22cb69f365c5f8c6d8850501299c

SHA-1:
287322633df195bad889e000a299cb598f936ef7

SHA-256:
457c24cd3760922de88dce66576ffbcfd3d53a62c3baa62fd1816a117893d191

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/24/2024 12:56:57 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.880128.17
7.11.214.140

Bkav FE
HW32.Packed
1.3.0.6379

Comodo Security
UnclassifiedMalware
21319

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.8.6.0

Norman
Suspicious_Gen2.UYTIV
11.20160508

Panda Antivirus
Generic Malware
16.05.08.05

Qihoo 360 Security
Win32/Trojan.f56
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
5.16.14.00

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
38190

File size:
859.5 KB (880,128 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\gctrainer.exe

File PE Metadata
Compilation timestamp:
12/19/2011 1:52:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:qRgzbAuAk1PeprKF5g5rgNppZn418F+YkP96dpn:qSzbT1ieX9ZZkz67

Entry address:
0x18C8F4

Entry point:
E8, 60, 1B, FF, FF, 79, A4, A3, BF, F6, 69, 90, 99, 4C, DC, C1, 02, BA, 27, 41, 5C, AA, 0B, 1B, 2A, 78, DA, 15, 30, 4A, 6D, 76, 86, A1, FA, 14, 3B, 89, AC, CE, 64, 9F, 26, 36, 5D, 66, 77, 87, 96, E4, 9A, E1, C6, 01, 34, 61, AF, C6, E9, E2, 1D, DA, 20, 01, CD, 4C, B6, F9, EA, EA, 6B, 38, D9, 46, 58, 93, 6B, 8E, F2, 7F, F5, 26, 49, B6, 76, B1, D1, A8, 4C, 8C, 61, 09, 79, 3A, BE, 01, AE, AF, EA, 76, E4, 1F, FE, 7A, ED, A6, EE, 86, B9, D5, F8, 14, 33, 4F, 56, C9, D4, 47, 76, FE, 39, 55, 6C, 88, 9B, B7, E2, B7...
 
[+]

Code size:
10 KB (10,240 bytes)

The file gctrainer.exe has been seen being distributed by the following URL.

Remove gctrainer.exe - Powered by Reason Core Security