bootcheckinwtool.exe

BootCheck 응용 프로그램

WooJung ITS Co., Ltd.

The application bootcheckinwtool.exe, “BootCheck MFC 응용 프로그램” by WooJung ITS Co. has been detected as a potentially unwanted program by 12 anti-malware scanners.
Publisher:
WooJung ITS Co., Ltd.  (signed and verified)

Product:
BootCheck 응용 프로그램

Description:
BootCheck MFC 응용 프로그램

Version:
1, 0, 0, 1

MD5:
97c785ab2971c025065c3c550d519369

SHA-1:
c420a54216336b138c08b6c787d54dfced8c3b90

SHA-256:
7382b5ff499dc4e4f149bca83884560b28550e5dab8266a3081b368e99ee5124

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
5/5/2024 7:15:18 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Kraddare
7.1.1

Avira AntiVirus
Adware/Graftor.11053.2
7.11.150.100

Bitdefender
Gen:Variant.Adware.Graftor.11053
1.0.20.1090

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.11053
8.14.08.06.10

ESET NOD32
Win32/AdWare.Kraddare.KC
8.9820

Fortinet FortiGate
Riskware/Kraddare
8/6/2014

F-Secure
Gen:Variant.Adware.Graftor.11053
11.2014-06-08_4

G Data
Gen:Variant.Adware.Graftor.11053
14.8.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

Malwarebytes
Trojan.Agent
v2014.08.06.10

MicroWorld eScan
Gen:Variant.Adware.Graftor.11053
15.0.0.654

VIPRE Antivirus
Trojan.Win32.Generic
29382

File size:
46.6 KB (47,704 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 2010

Original file name:
BootCheck.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\bootcheckinwtool.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/18/2013 9:00:00 AM

Valid to:
12/19/2014 8:59:59 AM

Subject:
CN="WooJung ITS Co., Ltd.", OU=IT Team, O="WooJung ITS Co., Ltd.", L=Gangnam-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
675A424B38694F7C3A8287CAEE21CC50

File PE Metadata
Compilation timestamp:
2/26/2014 6:54:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:pFWOy9FVoD/LFgVGXpWC8hjBRWBnmqHyhgYkrqx/p:pFTy9TYFgOSBRWBnmqHyGVm/

Entry address:
0x34BF

Entry point:
55, 8B, EC, 6A, FF, 68, B0, 48, 40, 00, 68, 7C, 34, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 0C, 43, 40, 00, 59, 83, 0D, 50, 63, 40, 00, FF, 83, 0D, 54, 63, 40, 00, FF, FF, 15, 10, 43, 40, 00, 8B, 0D, 44, 63, 40, 00, 89, 08, FF, 15, 14, 43, 40, 00, 8B, 0D, 40, 63, 40, 00, 89, 08, A1, 18, 43, 40, 00, 8B, 00, A3, 4C, 63, 40, 00, E8, 1D, 01, 00, 00, 39, 1D, 50, 62, 40, 00, 75, 0C, 68, 48, 36, 40, 00, FF, 15, 1C, 43...
 
[+]

Entropy:
5.5272

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

Remove bootcheckinwtool.exe - Powered by Reason Core Security