gputemp.exe

White Sea Media

The application gputemp.exe by White Sea Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GPUTemp’. It is also typically executed from the user's temporary directory.
Publisher:
White Sea Media  (signed and verified)

MD5:
cda66fb03f91a4b1335a0717a5cee0cd

SHA-1:
e8aaba45088dd4ff13d11b36a7d3e8632f39318f

SHA-256:
1a920ba4128e61d0cd3956d4cd9f4e49d772dfaaef796c44760abd4388e365a3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 5:13:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WhiteSeaMedia (M)
16.1.12.2

File size:
894.7 KB (916,192 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\gputemp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/7/2013 9:00:00 PM

Valid to:
7/8/2014 8:59:59 PM

Subject:
CN=White Sea Media, O=White Sea Media, STREET=4142 Mariner Blvd, L=Spring Hill, S=FL, PostalCode=34609, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FB235ACA7565BA27ADC702B2BD05C7F

File PE Metadata
Compilation timestamp:
10/16/2013 7:34:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:/xRMg4Y3nVoWIRKRxCtObKb2Q49eA2K22wDV:tIRKRxCtOBfwDV

Entry address:
0x1EB000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 40, 0D, 00, 2D, 7F, CF, 09, 10, 05, 74, CF, 09, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 36, 8B, F9, 69, 68, F6, 58, 28, 79, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 55, D9, 06, DA, AE, F3, 1A, B5, CD, 00, 80, 0E, F7, 44...
 
[+]

Code size:
40 KB (40,960 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GPUTemp

Command:
"C:\users\{user}\appdata\local\temp\gputemp.exe"


Remove gputemp.exe - Powered by Reason Core Security