gwx_stopper_1.0.exe

GWX Stopper

Josh Mayfield

Publisher:
UltimateOutsider  (signed by Josh Mayfield)

Product:
GWX Stopper

Description:
GWX Stopper - Closes and configures the 'Get Windows 10' system tray application.

Version:
1.0.0.0

MD5:
ea1c2a2d8b8c659c852ac08582de19cc

SHA-1:
55efe9a57a9b7323b937be5c12dc258c908b2db8

SHA-256:
b0697d636f28b30d663a2328709d74615c65b9cd972dee7b1d0340c7a8781e79

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 7:31:59 PM UTC  (today)

File size:
4.2 MB (4,357,192 bytes)

Product version:
1.0.0.0

Copyright:
(c) 2015, Josh Mayfield/Ultimate Outsider. All rights reserved.

Original file name:
GWX_stopper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gwx_stopper_1.0.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/19/2015 2:00:00 AM

Valid to:
1/20/2016 1:59:59 AM

Subject:
CN=Josh Mayfield, O=Josh Mayfield, STREET=16958 NW Cove Ct, L=Portland, S=OR, PostalCode=97229, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
21EE4D19B5C3ACB45C47E786060905CD

File PE Metadata
Compilation timestamp:
8/31/2015 7:39:01 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:Zcti04IM+SA7lLDemEONR7XhqXbH4TTjpX3gC2FLOAkGkzdnEVomFHKnP8d:ZFf+LJnXhqXbHGJgC2FLOyomFHKnP8d

Entry address:
0x1239E6

Entry point:
E8, 01, 8A, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 40, 70, 60, 00, 75, 02, F3, C3, E9, 99, 4D, 00, 00, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 58, 4D, 61, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 4C, 72, 60, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 58, 4D, 61, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7...
 
[+]

Entropy:
7.0678

Code size:
1.6 MB (1,656,832 bytes)

The file gwx_stopper_1.0.exe has been seen being distributed by the following URL.

Scan gwx_stopper_1.0.exe - Powered by Reason Core Security