gvc.exe

Pitaya Tech Ltd

The application gvc.exe by Pitaya Tech has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “0A053C05-52A5-49a0-9B9B-AC9FC38D7FF0”.
Publisher:
Pitaya Tech Ltd  (signed and verified)

Version:
1.0.0.3

MD5:
4e3aa9af9b9efd7d44908bc88b747a6e

SHA-1:
3d0b8feb74fae773901d9724d3468fcb6abe0426

SHA-256:
4e14ca2aa061611444aed4de3ecfe7822732de452fe6113c05b6ce1a83e3a866

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:19:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bitcocktail.PitayaTech (M)
16.3.5.21

File size:
128.8 KB (131,896 bytes)

Product version:
1.0.0.3

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\shop for rewards\gvc.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/22/2014 5:00:00 AM

Valid to:
9/23/2015 4:59:59 AM

Subject:
CN=Pitaya Tech Ltd, O=Pitaya Tech Ltd, STREET=Rakefet 19, L=Hod Hasharon, S=Sharon, PostalCode=4510034, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6FAC939FE352559AD7790E9C81C9A639

File PE Metadata
Compilation timestamp:
9/22/2014 7:23:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:rdERCv4icAtWcLUh6vCoXL89S8WRzKsyctn/vOsWjcdVeTojaADNAVAQH8c9qvrj:pWaCobQmNKsd/pVeTohDOVAxwqn

Entry address:
0xA5CC

Entry point:
E8, 06, 47, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 51, 8D, 45, FC, 50, 68, 44, 40, 41, 00, 6A, 00, FF, 15, 58, 31, 41, 00, 85, C0, 74, 17, 68, 5C, 40, 41, 00, FF, 75, FC, FF, 15, CC, 30, 41, 00, 85, C0, 74, 05, FF, 75, 08, FF, D0, C9, C3, 55, 8B, EC, FF, 75, 08, E8, C3, FF, FF, FF, 59, FF, 75, 08, FF, 15, 54, 31, 41, 00, CC, 55, 8B, EC, E8, 5B, 08, 00, 00, FF, 75, 08, E8, B0, 08, 00, 00, 59, 68, FF, 00, 00, 00, E8, B0, 00, 00, 00, CC, 6A, 01, 6A, 01, 6A, 00, E8, 40, 01, 00, 00, 83, C4, 0C, C3, 6A, 01, 6A...
 
[+]

Code size:
72 KB (73,728 bytes)

Service
Display name:
0A053C05-52A5-49a0-9B9B-AC9FC38D7FF0

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove gvc.exe - Powered by Reason Core Security