Gom.EXE

곰플레이어

Gretech Corp.

Publisher:
(주)그래텍  (signed by Gretech Corp.)

Product:
곰플레이어

Version:
2, 1, 10, 3777

MD5:
d274a762c524f649c4c49eb7d77a05d2

SHA-1:
8a26196af7b1d309f570d2b7eabaaf8953cf8184

SHA-256:
5e4cf945d21f2a08ed14c1f412ace40b3cc9cda8772fa433ce5965c252dd35e0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 9:59:00 AM UTC  (today)

Scan engine
Detection
Engine version

Prevx
Malicious Software
3.0.2

File size:
2.5 MB (2,631,224 bytes)

Product version:
2, 1, 10, 3777

Copyright:
Copyright(C) 2003-2008 Gretech Corp. All rights reserved.

Original file name:
Gom.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\gretech\gomplayer\gom.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
8/13/2007 7:56:21 PM

Valid to:
8/26/2009 7:24:14 PM

Subject:
CN=Gretech Corp., OU=Service Development Biz., O=Gretech Corp., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
0BBA07BB13591CD196FDC2E08A82564A

File PE Metadata
Compilation timestamp:
4/25/2008 2:10:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:A8Pc9QvysmkjeaOlBMbN/Rry00sWtzpi60cHIwkUv4UbUvfkqWG/+bjZ9HzTm9NE:k1qRV0JsoHIwilhql1zTEN/JbP0Y5xG

Entry address:
0x141F21

Entry point:
55, 8B, EC, 6A, FF, 68, A8, D4, 5B, 00, 68, B0, 5F, 54, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, EC, E2, 59, 00, 33, D2, 8A, D4, 89, 15, C0, 44, 64, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, BC, 44, 64, 00, C1, E1, 08, 03, CA, 89, 0D, B8, 44, 64, 00, C1, E8, 10, A3, B4, 44, 64, 00, 6A, 01, E8, 73, 6B, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C2, 00, 00, 00, 59, E8, 7E, 68, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B1, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.1726

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
1.6 MB (1,691,648 bytes)

Autoplay Handler
Display name:
GOMPlayDVDOnArrival


Scan Gom.EXE - Powered by Reason Core Security