webinstall.exe

Gleim Internet,Inc

This is the uninstaller utility registered in the Windows Control Panel for the program Gleim CMA Test Prep 4.6 WebDeploy by Gleim. The file has been seen being downloaded from www.gleim.com.
Publisher:
Gleim Internet,Inc  (signed and verified)

MD5:
6f38c201269612ceef6974aa8b158049

SHA-1:
0ef099d8eebccfb0f17a4e6887ef4c637697a6ba

SHA-256:
a18b4042addb36f0870c3ddf1ce5c26a70fb119d5c22ca187fe399036cc86877

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 8:34:08 AM UTC  (today)

File size:
1.6 MB (1,636,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cmatp46\webinstall.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/2/2013 8:00:00 PM

Valid to:
8/26/2014 7:59:59 PM

Subject:
CN="Gleim Internet,Inc", OU=WWW, O="Gleim Internet,Inc", L=Gainesville, S=Florida, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0CECD7F135483325FE6D18A7E3D10496

File PE Metadata
Compilation timestamp:
1/2/2014 3:14:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:lzF0oC15OXtF6vBLZcHxM+6Bb6HD74N4AERySmPfNlSRocR1Uf7k1sdp2ngwSEDt:LjC2XtFYLKm+c6j7Vdm+haYH

Entry address:
0x9F988

Entry point:
55, 8B, EC, 83, C4, EC, 33, C0, 89, 45, EC, B8, 4C, E5, 49, 00, E8, F7, 82, F6, FF, 33, C0, 55, 68, 6C, FB, 49, 00, 64, FF, 30, 64, 89, 20, 68, 78, FB, 49, 00, E8, 4B, 86, F6, FF, 66, A3, 4C, CC, 4A, 00, 66, 83, 3D, 4C, CC, 4A, 00, 00, 0F, 84, B0, 00, 00, 00, 6A, 00, 68, 88, FB, 49, 00, E8, 0B, 8B, F6, FF, A3, 50, CC, 4A, 00, 83, 3D, 50, CC, 4A, 00, 00, 75, 11, 6A, 00, 68, 9C, FB, 49, 00, E8, F1, 8A, F6, FF, A3, 50, CC, 4A, 00, 83, 3D, 50, CC, 4A, 00, 00, 74, 7C, 6A, 00, 68, AC, FB, 49, 00, E8, D7, 8A, F6...
 
[+]

Entropy:
5.3046

Developed / compiled with:
Microsoft Visual C++

Code size:
634 KB (649,216 bytes)

Program Uninstaller
Program name:
Gleim CMA Test Prep 4.6 WebDeploy

Display publisher:
Gleim

Display version:
46

Uninstall string:
C:\Program Files (x86)\CMATP46\WebInstall.exe


The file webinstall.exe has been seen being distributed by the following URL.

Scan webinstall.exe - Powered by Reason Core Security