GWX_control_panel.exe

GWX Control Panel

Josh Mayfield

Publisher:
UltimateOutsider  (signed by Josh Mayfield)

Product:
GWX Control Panel

Description:
GWX Control Panel - Closes and configures the 'Get Windows 10' system tray application.

Version:
1.3.0.0

MD5:
68e547db5559e823ce4cf7a03650ff47

SHA-1:
782aea51e6cd6df1350fb69d389db308d24df681

SHA-256:
a747fa5d09d880eaac589f33572a3739e87086d9cc2cc20e0ec55bf1b11d8e31

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 11:37:20 AM UTC  (today)

File size:
4.2 MB (4,372,040 bytes)

Product version:
1.3.0.0

Copyright:
(c) 2015, Josh Mayfield/Ultimate Outsider. All rights reserved.

Original file name:
GWX_control_panel.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/18/2015 7:00:00 PM

Valid to:
1/19/2016 6:59:59 PM

Subject:
CN=Josh Mayfield, O=Josh Mayfield, STREET=16958 NW Cove Ct, L=Portland, S=OR, PostalCode=97229, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
21EE4D19B5C3ACB45C47E786060905CD

File PE Metadata
Compilation timestamp:
9/12/2015 5:03:25 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:wOF1VFz+bFhbRM7oIrT6gwvE+Sn08RPX3gC2FLOAkGkzdnEVomFHKnPG9X:vJ2IwvE+SndvgC2FLOyomFHKnPG9X

Entry address:
0x125E30

Entry point:
E8, 07, 8A, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 40, A0, 60, 00, 75, 02, F3, C3, E9, 9F, 4D, 00, 00, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 7D, 61, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 4C, A2, 60, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 7D, 61, 00, 00, 0F, 83...
 
[+]

Entropy:
7.0661

Code size:
1.6 MB (1,666,560 bytes)

The file GWX_control_panel.exe has been seen being distributed by the following 3 URLs.

http://ftp-stahuj.centrum.cz/dl/814d0da3d8d25700eea519d874dcc048/5758facb/stahuj/download/software/secured/g/gwx-stopper/.../GWX_stopper.exe

Scan GWX_control_panel.exe - Powered by Reason Core Security