KerishDoctor.exe

Kerish Doctor

OOO AMA

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
Kerish Products  (signed by OOO AMA)

Product:
Kerish Doctor

Version:
4.60

MD5:
ab43b63aa3271980a173e3b34e99cf19

SHA-1:
cf65033c257a2b306a9b0f6f06448eef47a68c58

SHA-256:
36d3517b7e74c885c26efad8d390808174658b4bc91836f2d19cefdc55ddaddf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 1:51:53 AM UTC  (today)

File size:
2.8 MB (2,942,640 bytes)

Product version:
4.60

Copyright:
Kerish Products 2005-2015. All Rights reserved.

Trademarks:
Kerish Products 2005-2015. All Rights reserved.

Original file name:
KerishDoctor.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\kerish doctor\kerishdoctor.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/27/2014 3:00:00 AM

Valid to:
9/27/2015 2:59:59 AM

Subject:
CN=OOO AMA, OU=IT, O=OOO AMA, L=Voronezh, S=Voronezh region, C=RU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
10113097A9F7A4FC6296AF8DC613AB0D

File PE Metadata
Compilation timestamp:
2/7/2015 1:20:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:z3+/bmya+mHfoP7ZkldxVc/X3LDqM/TkLfPNR4ETyPsU0jHUlRzntbTSnxExNA:zKmya+IACldxVc/3v/TGPX4ETyPsU0jA

Entry address:
0xFC667

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, B9, D7, A4, 00, BF, 2A, 13, 6B, CC, 73, 83, 98, 94, 8D, FF, 45, F4, 9A, F8, 7D, 36, 21, 31, 42, E7, 72, EC, 40, CC, 71, 14, 70, C2, CB, 3D, E6, B3, 3A, 91, 84, 4E, E0, F8, EE, 09, B9, D0, 73, 21, 5D, 3C, 62, 6E, 56, 19, 40, AC, 98, E5, 6C, C8, A4, 20, 43, 64, 6D, 7B, E1, 2F, 81, C6, 07, 4F, 75, 67, 0E, 16, BA, A0, 73, FE, AA, 5C, 64, C4, 84, 2C, 56, F6, 6D, 39, 88, 79, 19, 46, 40, 71, 1E, 13, B6, 96, D5, 70, 60...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
6.9 MB (7,241,728 bytes)

Scheduled Task
Task name:
Kerish Doctor

Trigger:
Logon (Runs on logon)

Description:
Kerish Doctor Startup


Scan KerishDoctor.exe - Powered by Reason Core Security