gg5cm4cr.exe

Verti Technology Group, Inc.

This is part of the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file gg5cm4cr.exe by Verti Technology Group has been detected as adware by 2 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Verti Technology Group, Inc.  (signed and verified)

Version:
1.0.137.0

MD5:
b166c355c7df4433c68acc67f2f42b42

SHA-1:
b1048362f9393c07c86acbf7e9bcd805e0cfd474

SHA-256:
c2623d1a480539df682c0c56747bfe5609e08f0d041553e68aa85922e8244610

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/24/2024 3:54:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.VertiTechnologyGroup.M
14.11.3.23

VIPRE Antivirus
Rocketfuel Installer
21544

File size:
561 KB (574,456 bytes)

Product version:
1.0.137.0

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\gg5cm4cr.exe.part

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/13/2011 6:00:00 PM

Valid to:
11/13/2013 5:59:59 PM

Subject:
CN="Verti Technology Group, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Verti Technology Group, Inc.", L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E5A8F44B995DF01701554FBF18173B7

File PE Metadata
Compilation timestamp:
9/5/2013 9:26:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:SDgMTDNq8Rac0grpCR/fp5gsGP71PzBoL/xsTkKFYrfaC2z7aSkBI6nuZqtmgOVk:BMTDNBYc0gkR/fp5gsGP71PzBoL/xsTc

Entry address:
0x2EA8F

Entry point:
E8, F1, 9E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 38, 21, 46, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 3C, 21, 46, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, E6, 10, 00, 00, 85, C0, 75, 06, B8, A0, 22, 46, 00, C3, 83, C0, 08, C3, E8, D3, 10, 00, 00, 85, C0, 75, 06, B8, A4, 22, 46, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
6.7279

Code size:
278.5 KB (285,184 bytes)

Remove gg5cm4cr.exe - Powered by Reason Core Security