GWX_control_panel.exe

GWX Control Panel

Josh Mayfield

This is installed with GWX Control Panel. The file has been seen being downloaded from hardatworkpc-my.sharepoint.com and multiple other hosts.
Publisher:
UltimateOutsider  (signed by Josh Mayfield)

Product:
GWX Control Panel

Description:
GWX Control Panel - Closes and configures the 'Get Windows 10' system tray application.

Version:
1.7.2.0

MD5:
3cbaa23ab6ed2824dc5d8be8b6afbce9

SHA-1:
519465821ff83471685e7d64d2b8e20b53969c76

SHA-256:
d11ecbfbaaffc58d26594923cdd096defed0e081eeade05b65a4173f1866ad42

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:55:14 AM UTC  (today)

File size:
4.3 MB (4,559,944 bytes)

Product version:
1.7.2.0

Copyright:
(c) 2016, Josh Mayfield/Ultimate Outsider. All rights reserved.

Original file name:
GWX_control_panel.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ultimateoutsider\gwx control panel\gwx_control_panel.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/6/2016 7:00:00 PM

Valid to:
1/6/2017 6:59:59 PM

Subject:
CN=Josh Mayfield, O=Josh Mayfield, STREET=16958 NW Cove Ct, L=Portland, S=OR, PostalCode=97229, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
04F29C8A4DD805F9181F6B3859FCAF83

File PE Metadata
Compilation timestamp:
1/24/2016 12:08:33 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:gjuPYYu/i8/IWn7rU9YEaZc+BHfjKAsnOX3gCKFLOAkGkzdnEVomFHKnPZ:866tc+BHfjCnwgCKFLOyomFHKnPZ

Entry address:
0x139BC1

Entry point:
E8, D8, 98, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 30, 14, 63, 00, 75, 02, F3, C3, E9, 64, 34, 00, 00, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B8, F3, 63, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, BC, 14, 63, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B8, F3, 63, 00, 00, 0F, 83, A7...
 
[+]

Entropy:
7.0402

Code size:
1.7 MB (1,781,760 bytes)

The file GWX_control_panel.exe has been discovered within the following program.

GWX Control Panel  by UltimateOutsider
blog.ultimateoutsider.com/2015/08/using-gwx-stopper-to-permanently-remove.html
About 7% of users remove it
 
Powered by Should I Remove It?

The file GWX_control_panel.exe has been seen being distributed by the following 8 URLs.

https://hardatworkpc-my.sharepoint.com/personal/curtis_hardatworkpc_com/_layouts/15/download.aspx?SourceUrl=/personal/curtis_hardatworkpc_com/Documents/.../GWX_control_panel.exe

http://doughoward.net/.../GWX_control_panel.exe

http://files1.majorgeeks.com/93f97410020f1aeb261aa376df54f44d/.../GWX_control_panel.exe

http://ultimateoutsider.com/mwg-internal/.../progress?id=nXCMTa3qjSHonZTmE6GSEiTZPxy9CmVP7j1_aJ5hYDc,&dl

Scan GWX_control_panel.exe - Powered by Reason Core Security