GPClient.exe

Игры ростелеком

Rostelecom

The executable GPClient.exe has been detected as malware by 6 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Rostelecom GPClient’.
Publisher:
Ростелеком  (signed by Rostelecom)

Product:
Игры ростелеком

Version:
1.1.56.0

MD5:
35109d136d7218bda8540deb30a91100

SHA-1:
bf847ffb62301a851341321739f9d1ee7d5b0ba3

SHA-256:
70a8e45f516ddd09f7dd62c10ffa8011d08a8bfd8234f0a25232612343c9a849

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
4/26/2024 7:30:06 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Confuser.1440256.4
8.3.2.4

avast!
Win32:Malware-gen
2014.9-160219

Baidu Antivirus
Hacktool.MSIL.Confuser
4.0.3.16219

ESET NOD32
MSIL/Packed.Confuser.N suspicious (variant)
10.12656

K7 AntiVirus
Trojan
13.212.18026

Sophos
Generic PUA LP (PUA)
4.98

File size:
3.8 MB (4,016,568 bytes)

Product version:
1.1.56.0

Copyright:
Ростелеком © 2015

Original file name:
GPClient.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\rostelecom\gameplatform\gpclient.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/28/2015 10:38:16 PM

Valid to:
10/1/2016 11:42:48 AM

Subject:
OID.0.9.2342.19200300.100.1.1=10765899, CN=Rostelecom, OU=Rostelecom

Issuer:
CN=Symantec Enterprise Mobile CA for Microsoft, OU=Windows Phone Enterprise Applications, O=Symantec Corporation, C=US

Serial number:
104B

File PE Metadata
Compilation timestamp:
11/24/2015 2:52:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:zwLtIyj0x4YBJy7i0x4YyJ9WGcIFoWpS2ctp996xRxQ27y49dzpKSTuR:PMmvFtctUC2v9d6

Entry address:
0x3D800A

Entry point:
FF, 25, 00, 80, 7D, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
3.6 MB (3,809,280 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Rostelecom GPClient

Command:
C:\Program Files\rostelecom\gameplatform\gpclient.exe


Remove GPClient.exe - Powered by Reason Core Security