KerishDoctor.exe

Kerish Doctor

OOO AMA

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. This is installed with Kerish Doctor 2017.
Publisher:
Kerish Products  (signed by OOO AMA)

Product:
Kerish Doctor

Version:
4.65

MD5:
e8b97f4078643595054794cdad13faaa

SHA-1:
012c0316b1ab5375c617b0c84a2d66a486273c47

SHA-256:
c198a78d092b74cd73b6dc6791944ffe159fb5b2aa1236cbc57c9cb25c40c780

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 12:18:34 PM UTC  (today)

File size:
3.8 MB (4,032,160 bytes)

Product version:
4.65

Copyright:
Kerish Products 2005-2017. All rights reserved.

Trademarks:
Kerish Products 2005-2017. All rights reserved.

Original file name:
KerishDoctor.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\kerish products\kerish doctor\update\kerishdoctor.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/7/2015 3:00:00 AM

Valid to:
10/8/2017 2:59:59 AM

Subject:
CN=OOO AMA, OU=OOO AMA, O=OOO AMA, L=Voronezh, S=Voronezh region, C=RU

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1D0F76AAF04C714C925B79F338122EE7

File PE Metadata
Compilation timestamp:
2/11/2017 4:12:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x147C92

Entry point:
55, 8B, EC, 83, C4, F0, B8, 00, 10, 40, 00, E8, 01, 00, 00, 00, 9A, 83, C4, 10, 8B, E5, 5D, E9, 62, 2C, F5, 00, AF, FD, 11, EF, 88, 65, F6, 06, F7, 6B, 86, CF, 3F, 68, C9, 3D, 90, 70, 28, 2E, F5, 34, A6, 67, 6E, 0B, 9A, DF, A7, 87, B7, 9A, 08, EF, 5B, E2, 65, 93, 27, 38, A8, 19, 2D, 4C, 3C, FE, D9, 2D, E4, 1D, C3, 66, 8C, 4B, 4E, 81, D7, F2, 36, 40, C2, A2, C5, DA, 8B, 29, 6D, C6, BB, 94, 71, 90, 7F, 69, CB, 3C, E3, FC, A7, AE, A4, 62, 66, C1, 18, 5E, EF, 82, 21, 9F, CB, DB, 14, C5, 28, 0C, D6, 2E, 74, E6...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 MB (7,839,744 bytes)

Scheduled Task
Task name:
Kerish Doctor

Trigger:
Logon (Runs on logon)

Description:
Kerish Doctor Startup


The file KerishDoctor.exe has been discovered within the following program.

Kerish Doctor 2017  by Kerish Products
www.kerish.org
About 4% of users remove it
 
Powered by Should I Remove It?

Scan KerishDoctor.exe - Powered by Reason Core Security