guntony_server.exe

Shan Feng

The application guntony_server.exe by Shan Feng has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(Guntony_update)”.
Publisher:
Shan Feng  (signed and verified)

Version:
50.14.2661.78

MD5:
fa2c5b35ca039d86f76911f711ca3f30

SHA-1:
c4d7527e72b141884aec83ec4b84f827e521c324

SHA-256:
b5a6fdbf3214809754c1d230d479387e141c82b3911d1e917e6cc531d313f3a2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 1:21:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.10.28.8

File size:
462.4 KB (473,472 bytes)

Product version:
50.14.2661.78

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\guntony\guntony\bin\guntony_server.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/6/2016 12:00:00 AM

Valid to:
10/22/2016 11:59:59 PM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5468DE414178163609F5122D532EB4F4

File PE Metadata
Compilation timestamp:
5/12/2016 8:06:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:lmkRH1eYBQ7wI3Zlhyr+D+9LK04jVkQzOZMfZYHP7c0ADEk8doior3VwAW2Ush:lm4H16wIJlhyKD+gBZKP72DWdoiB6Ph

Entry address:
0x35A92

Entry point:
E8, 20, 4E, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 30, C3, 46, 00, 75, 02, F3, C3, E9, C4, 13, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 4C, E8, 46, 00, FF, 15, 10, 82, 45, 00, 85, C0, 75, 18, 56, E8, 79, 55, 00, 00, 8B, F0, FF, 15, 5C, 82, 45, 00, 50, E8, 7E, 55, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 4C, E8, 46, 00, 85, C0, 75, 1D, E8, 51, 4B, 00, 00, 6A, 1E, E8, A7, 4B, 00, 00, 68, FF, 00, 00, 00, E8, 9C, 36, 00, 00, A1, 4C...
 
[+]

Code size:
346.5 KB (354,816 bytes)

Service
Display name:
Update Service(Guntony_update)

Service name:
Guntony_update

Description:
Keeps your Guntony software up to date. If this service is disabled or stopped, your Guntony software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and f

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove guntony_server.exe - Powered by Reason Core Security