grlaunchertempsetup.exe

GOM Audio

GRETECH

The application grlaunchertempsetup.exe, “GOM Audio Setup File” by GRETECH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.metafilescurrent.com and multiple other hosts.
Publisher:
Gretech Corporation  (signed by GRETECH)

Product:
GOM Audio

Description:
GOM Audio Setup File

Version:
2.0.11.1156

MD5:
8ae0f1fbbbe1bc6aa3a5e633c665726f

SHA-1:
3cc6eb4507af729094c8879cad994821d179e69e

SHA-256:
a461fb265b7f2784f12d6d951005cb2928c3bd23864586633878f04ab9804437

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 10:18:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.GRETECH.GretechC.Installer.Meta (L)
16.6.10.10

File size:
6.9 MB (7,284,784 bytes)

Product version:
2.0

Copyright:
Copyright(C) Gretech Corp. All rights reserved. Since 2012

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\grlaunchertempsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/17/2015 5:00:00 PM

Valid to:
6/16/2017 4:59:59 PM

Subject:
CN=GRETECH, O=GRETECH, L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
11D67F2AF7440EBA275E7E62F6B634FF

File PE Metadata
Compilation timestamp:
2/24/2012 11:19:59 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:Sc98zeOsYh/UEEbG2iDCE1IEqapt6WxpJ5Z:SB7hcP6jx1B66Z

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9972

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file grlaunchertempsetup.exe has been seen being distributed by the following 50 URLs.

http://www.metafilescurrent.com/c?x=/lbvWwLYfIGWCZuqCFR7hFstRpn96VVuqpARqsGGXFg=&c=WtJ823LcMxk1pA/U2qU7tfESdq6QWubn9268Sg6WsGc9xuYa0ZHtkmVNYNDcRj9rxQbnkxF1GSTWWQsmy6iYqmoQ/Q8HjrmH9GKZ55eKH4IElk jdcWKuCt4VbRGSqV9fnjQB7sDxL6D95ovDoRw29Nk MiZDr1aCgFf08YKri0=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.signsvaultsmega.com/WVl6OTRQV1V5ZDNoU09GUkxkVXRPYUVSNk1Ha3hXbVZtTVZOd1FVWm9iRzlFVTFZMmNrTWxNa1pDWTNGQlZXZ3pjeVV6UkNaalBVSnpkRTU0U1RaM05tOGxNa0pDU0dKdVJqazRjaVV5UW1KV1F6WnNPVFZHV1V4SldVWkNSM1UyU0hnNGMwWlVaV2MwTVVKWU5scDBjekIxYldScmFXbzJVelZ2ZUd4WlptaFpTbTVHZUZoS2IyRklNR3AwYVU5TmVFSmlhWGhxU1U0MGRtd3llVVZMVUdFeFV6bGxaMVp2WkdKUE1WUmphMUJFTTFWNVVUbHhiVlJMV2tWblRqVnlPQ1V5UWxRemFHTlZXWFZ1WW5oQmFreFBRU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxSFQwMUJWVVJKVDBkTVQwSkJURk5GVkZWUUxrVllSU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbVJ2ZDI1c2IyRmtMbU51WlhRdVkyOXRKVEpHUjA5TkxVMWxaR2xoTFZCc1lYbGxjaVV5UmpNd01ERXRNVE0yTXpKZk5DMHhNRFUxTVRjNE5pNW9kRzFzSlROR2FHeHVaSElsTTBReA==

http://www.bitsflashclean.com/c?x=p1CQ3x83T0Cz1muErzv3U54y2VfCuyzek1YJ4GVo2Yo=&c=nE//90loJ4RfRhPLJb3H r90Jzie6ON6ddLQlyd1TZCdYn/wrROLBjn65bmCRb7nz8eLJEK BMRlEyQQdrLk m9egiD5AQ12cabFQ26UA0A4dYm5rA olcMW8PQlyMlH7j/u esP G1zzRAFHY4zRfsSSjHABfX1jAWG62yTz8=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.downloadsfactoryclean.com/c?x=ox4khZbqgX8924CEwNZa6voeHM99txln5lW8oaxYAAg=&c=S8SEZytleQMTPBuX2uwjMozn/QkCFSa8pKVdA4mZ2QQU lQcfevenOibAcoXPOtB0C5Xtkq77kepC2VLR7yc3N6tzXyMIul6H8Lwr5W1vg0LrtjUZcCQUhwi8tG9jde E0t7Ib/J/8tYJXFMGH7ijTXCCEvUKYC7aaPsn6iqYRs=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.applicationscycletag.com/c?x=DJSsahkJ8umdEXXJJsej036CkMI6mKGpHa5Ias7J4lA=&c=t4oYNPpl5JB lkmrn5SbXLC0Z/UoYffW9UdsxL67UIEPkasG9XAe30SlylK/ikgyajYnS9xAElEJ6jbxMs9j04zOGqNFLldEWlRM9c35RseqSpFYJX4JwkGGS6qFoKmZ09Wj2mod2YKwX6cyPd7TFP z7BSVZD wKpcAVmDMRQE=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.towerscleanworld.com/c?x=9KCKSNEDYTo6E9mS13vr9RjvR4JzdbBHfAI5UOWXwCk=&c=ccj2iyGXaFEroGF6ZGmCOAeoVe4NOOZawL38iX9tx9vG/N/yjKOQWk2IYMSxsCiKmkeSnNug7syZlj18lzdH48vgqzP0mSNccm245elufgr/vsWvyQLyoemaCmu2 euXhSkkqkvmYKvpCleoikJTq2Z5TqNegPGHy7xfiYfwljk=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.tourssignmeta.com/c?x=NkaJdcpSnP4VRT2R85aJHOdNcdH2WIZF3XVth7oHrXg=&c=Nl0n00wSWXyEsXpaPm9I8LyRkxuUUL/i8QgGFTDsKHPV 7XWCOti8MB8YuMp7SHIpl8rNeP1MVbER5i0TRvsAW2baDGlx9bfZqWqZAigslA59MJqzh9KpDU86iFQZEmybs3WwpV6ZX1cME6y4S/RkLm8JP8U1KH5MT72Nf7z0lY=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.townbitsbulk.com/c?x=UkNx4W2TOKI8yqF vasALW7t 0hK9UjzjY6/KVre3 Y=&c=rc/neOWgzw1qUHlq2SF1LLhkZ2psFCRg6N0d7J0wpitPoeM5S58hYymdMiAm5q42e0UBbMLigwJX RR3rjBm5Cg9hWvqBFAQwWb87VpcBxtnXC6oi3ORS1icIb/nF1GuvYo7QAeR6Gl EjHdZa5s/w==&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.downloadsfactoryclean.com/c?x=CCi8 OqtTUWERgUKZuYa8uIUADaxNqTws9aoxtsNSuw=&c=ERDNVFMMUYsuQSk8vqJzDnIa1eiTUgg4KvvaWMHbsdAallyzvNYobvkUz6e8bEl7WfXGGWRIOeclTD35h938UQQ8ypIHj6YktDUvQ XhNU61dQZl4nVod9gJk13RJI4IfPifM8clBT7n/ma3mz2pCtlEhNpoLaYhQEOvQGPwJQI=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.cyclebitsbundles.com/WVl6OTRQV2hWVkhOT1NXNVphVlpLYVVOd01VRlhhRk5TVUVoMk9WWlNjVlJNTTFWVGNEQTFXaVV5UmsxQlJubHBRU1V6UkNaalBWcEplRGhCYjNwdFNGcFlibGhoZVdRbE1rWWxNa1prVUZKME5rRTNKVEpDUVVWa1QyMVdhbWhOUkZVNE5qQlVKVEpHUTIxQlluQjVUWE5GYVU5NGQydEZaM1ZxTmxGSlMyVllaRWQzT1ZWaWIxbG5jMjVIYTFGdFNVTTRUWEp2VmtSak5VeHlTMVJyWkVWTmEyTkZRU1V5Um1SNlNEaHpXR3huUzFacGNHOXdjM1ZVSlRKR1dVZDBTVFJQWTNrekpUSkNiRzFSVUV4YVJ6UWxNa1lsTWtaclJVbG9VV2RKZHlVelJDVXpSQ1psUFRBbVpHOTNibXh2WVdSQmN6MUhUMDFCVlVSSlQwZE1UMEpCVEZORlZGVlFMa1ZZUlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1SdmQyNXNiMkZrTG1OdVpYUXVZMjl0SlRKR1IwOU5MVTFsWkdsaExWQnNZWGxsY2lVeVJqTXdNREV0TVRNMk16SmZOQzB4TURVMU1UYzROaTVvZEcxc0pUTkdhR3h1WkhJbE0wUXg=

http://www.farmupdatetag.com/c?x=XfTFqGR/iTqVqPiK7UfuZc1YEIuO /Vow5KAQ37Zm6E=&c=0yn8hrbDM6M38EmTcMXEP5LCWAw6fkhNYggHOv1kxlAwwqCZw559040FhLs/1qzT9sezzVXxbA1QD3ebUaxG1j2/pNtC8HXJBxEEYIACWKVjReLD4gWeTn8uHSNidbym4tACxeF0oNTeKsGVT7AwfX0XHe24510WZ58bhq8TNYs=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

http://www.appstockflash.com/WVl6OTRQVVZPVVNVeVFtNTRZVmcxTldocVZFaEtPR2hhU1RSVlpVdGFWaVV5UmtGNlUyaG5UR1k0Y2xSSFpWRWxNa0ozU0hjbE0wUW1ZejFVUVZKMVpsWmhjWFJSTWt4TmFUVm9iM1ZYYkdacloyUXpWVXBuSlRKR1RGVm9iU1V5UWxaRlprbFZWR3h0V21GemJHRnFTVTFPTmxwYU5VdDVhbnByVUhoNll6WjJTWHBFTVZCTmJ5VXlSbkJ2UlRGbWF5VXlRbGh6Ymt3elRtcENhMjlsTW5vMGJ6UTFhbGwwTkhaaU16bHJWMjF6ZW1GalMzaHhjekV3TmxWTE9IbEhlR3htZGpoT1NGVnZWMjVDZFVWc2JtOVFSblpLYVROSFFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFIVDAxQlZVUkpUMGRNVDBKQlRGTkZWRlZRTGtWWVJTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtUnZkMjVzYjJGa0xtTnVaWFF1WTI5dEpUSkdSMDlOTFUxbFpHbGhMVkJzWVhsbGNpVXlSak13TURFdE1UTTJNekpmTkMweE1EVTFNVGM0Tmk1b2RHMXNKVE5HYUd4dVpISWxNMFF4

http://www.towerworldcurrent.com/WVl6OTRQVlEwVVZGMU9HaERUREkwYlZsS1dsWnRkamNsTWtKSFNtWTJkamgzZUZBeWQzUkNOamRFVW5SWVNqTTRXU1V6UkNaalBXbGFaMjFVUzNjeFR6bHRUekV4T0U1QmJFaFZWWGR0VVRGbWQxSklOR3BPVGtnbE1rSnpja1EzYkVNbE1rSlBWSFpGUlRWcU1rWnVKVEpHVlVjMVZsZHBOa2xhTVRNNVYzcFZTR3RoTW1odlZYcEtVMHhHV2psWlMwbGlSa1pLVVUxVFpGRlFKVEpDTkRJbE1rSmlTVTBsTWtKQ1RqQlpTV013WjFwR1NFUnFjM0JFWkRkamRDVXlRbU5xTms1bFJrZFlaMFpNTXpsb2VrZGlVa2xSZW1OeFVYUkJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVkUFRVRlZSRWxQUjB4UFFrRk1VMFZVVlZBdVJWaEZKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdaRzkzYm14dllXUXVZMjVsZEM1amIyMGxNa1pIVDAwdFRXVmthV0V0VUd4aGVXVnlKVEpHTXpBd01TMHhNell6TWw4MExURXdOVFV4TnpnMkxtaDBiV3dsTTBab2JHNWtjaVV6UkRFPQ==

http://www.contentbodyclean.com/c?x=gRdPei/gZN3CvimD9ekKVgAmuTPsc4K44q58M1ibKcU=&c=5rK1RGZx1ygmq8lh1XGR/kj/WKj5MNotNkKnykAcjtVt1egNUlKfe3fV0N48eocEDBDgmT6bzrtYwBxOazRP0bvg3LJg5I1qB8BqnfkOkmiV euAQ5CGhbOHBCy5 HpT2pF5xMwOza3jRfm35zMjnyIPrT8g/OV2ZuwN/11Oj54=&e=0&downloadAs=GOMAUDIOGLOBALSETUP.EXE&fallback_url=http://download.cnet.com/.../3001-13632_4-10551786.html?hlndr=1

Latest 30 of 51 download URLs

Remove grlaunchertempsetup.exe - Powered by Reason Core Security