KerishDoctor.exe

Kerish Doctor 2012

OOO AMA

Publisher:
Kerish Products  (signed by OOO AMA)

Product:
Kerish Doctor 2012

Version:
4.45

MD5:
6076235083eeaf4ca349864464e7c7a7

SHA-1:
594e80791981e458bbc0a79eaa669c472b91937d

SHA-256:
c5dbe076e5ac0b0f7192f34b3b04cceae1a26273af92dba339a4247da39243e4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 7:23:18 PM UTC  (today)

File size:
2.1 MB (2,233,416 bytes)

Product version:
4.45

Copyright:
Kerish Products 2005-2012. All Rights reserved.

Trademarks:
Kerish Products 2005-2012. All Rights reserved.

Original file name:
KerishDoctor.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\kerish products\kerish doctor\update\kerishdoctor.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/30/2012 5:00:00 PM

Valid to:
7/31/2013 4:59:59 PM

Subject:
CN=OOO AMA, OU=it, O=OOO AMA, L=Voronegh, S=Voroneghskaya oblast, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5FC6B3B8D216CFEF94FEFBDBC8BE144D

File PE Metadata
Compilation timestamp:
10/28/2012 11:02:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:jgVzVlvHD5b3YiXexC/ItqzTyP2GNEMMoTiLXy1t4OYfHDHhvcdgJxw0c8:UV5JD5MVxwlzTyP2GNEMMuWCQfjhvpN/

Entry address:
0x45849

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 8F, 9D, 76, 00, 9E, 50, 23, 61, 00, 74, E7, B0, 0B, DE, C9, 57, 17, 3F, 2B, 61, 36, D8, 69, 04, 55, EA, BE, 14, 37, FF, 8C, B7, A6, A6, EA, 9F, B3, 23, A7, 09, AD, 5B, 54, 29, 6F, 22, 30, 3F, 39, A9, 2A, 2A, 98, 01, D0, EC, 03, 7B, 3E, 3D, 91, 1B, 9F, 94, 1C, 72, CA, AE, 78, BE, 5E, C2, 77, 34, 06, B6, 8A, 9D, 26, B6, 9C, 70, 1D, A6, 07, 90, AB, 0A, A4, 64, 84, 2D, 70, 6A, 28, DF, F6, 74, 32, AD, 9F, 8F, 00, 15...
 
[+]

Entropy:
7.8903

Developed / compiled with:
Microsoft Visual C++

Code size:
3.4 MB (3,567,616 bytes)

Scan KerishDoctor.exe - Powered by Reason Core Security