gputemp.exe

White Sea Media

The application gputemp.exe by White Sea Media has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GPUTemp’. This is a trojan Bot that uses IRC to communicate with a comand and control network. The Trojan drops other malicious software and opens a backdoor on the infected computer and will run automatically on each boot.
Publisher:
White Sea Media  (signed and verified)

MD5:
6d9f1ecceff70c1fb52557424b16024d

SHA-1:
a9cdd101a235c134d63ed52d61ce93794381306e

SHA-256:
0085cc1af05fe4246b9500de243b343a1142ad823cab06953db76730a3d60bb1

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Part of a backdoor IRC bot network.

Analysis date:
11/5/2024 11:31:24 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.221
9.0.1.0354

Reason Heuristics
PUP.Startup.WhiteSeaMedia.H
14.8.7.21

Trend Micro House Call
TROJ_GEN.F47V1202
7.2.354

VIPRE Antivirus
Backdoor.Win32.Ircbot.gen
24866

File size:
1.3 MB (1,316,576 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\gputemp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/7/2013 9:00:00 PM

Valid to:
7/8/2014 8:59:59 PM

Subject:
CN=White Sea Media, O=White Sea Media, STREET=4142 Mariner Blvd, L=Spring Hill, S=FL, PostalCode=34609, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FB235ACA7565BA27ADC702B2BD05C7F

File PE Metadata
Compilation timestamp:
11/22/2013 7:37:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:6Qmcj3VMeEnbqzm7enhtB44Oi0nnU2dH9mfiDPAWRoeskx85X7KXa:jr37QbDyHbp0nFPmfiDPnoesh5aa

Entry address:
0x347000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 60, 13, 00, 2D, 8F, 8E, 0A, 10, 05, 84, 8E, 0A, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 85, 69, 7D, 19, 68, 85, 85, FF, 54, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 9D, FB, A2, FF, 95, 82, 6B, A1, 32, B6, 16, E0, 55, 6A...
 
[+]

Code size:
41 KB (41,984 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GPUTemp

Command:
"C:\users\{user}\appdata\local\temp\gputemp.exe"


The file gputemp.exe has been seen being distributed by the following URL.

Remove gputemp.exe - Powered by Reason Core Security