showgetx.exe

showgetx

PODCornCommunication. Co., Ltd.

The application showgetx.exe by PODCornCommunication. Co. has been detected as a potentially unwanted program by 9 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup.
Publisher:
PODCornCommunication. Co., Ltd.  (signed and verified)

Product:
showgetx

Version:
1.00

MD5:
2a831af7dafad8ea0a16fa0396d80d84

SHA-1:
bdf42068611fd0b985732a8abef7a818da78cfa6

SHA-256:
b7b3ecadc3897c14243a88a372f2517a71eb559b5cc3e7529f126dfcd10d2c2e

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
5/4/2024 8:00:06 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader.Rozena
2017.0.2585

Baidu Antivirus
Trojan.Win32.Downloader
4.0.3.161019

Comodo Security
TrojWare.Win32.TrojanDownloader.VB.PMEA
23256

ESET NOD32
Win32/Downloader.Agent.NBH potentially unsafe (variant)
10.12273

IKARUS anti.virus
Downloader.Rozena
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.210.17258

McAfee
Artemis!2A831AF7DAFA
5600.6241

Sophos
Generic PUA LN (PUA)
4.98

VIPRE Antivirus
Trojan.Win32.Generic
43852

File size:
362.8 KB (371,520 bytes)

Product version:
1.00

Original file name:
showgetx.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\downloaded Program Files\showgetx.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
12/10/2014 9:00:00 AM

Valid to:
2/9/2016 8:59:59 AM

Subject:
CN="PODCornCommunication. Co., Ltd.", OU=IT Team, O="PODCornCommunication. Co., Ltd.", L=Geumcheon-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5750301F8766C00EB7F1C12F1D83B068

File PE Metadata
Compilation timestamp:
12/22/2014 9:41:11 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:oZIEOhR0G6OF68CZdjW6kqAETG+Ljm4dEVOhR0G6OF68CZdjW6kqAETG+Ljm4dpp:KTKlb0WqPTiKlb0WqPTpp

Entry address:
0x1298

Entry point:
68, 9C, 13, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 40, 00, 00, 00, 00, 04, EA, D4, 01, 91, AC, 4F, AC, 27, 82, 25, A1, 54, D3, 60, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, E0, E0, E0, 1F, E0, E0, 50, 72, 6A, 53, 74, 61, 72, 74, 00, 1F, E0, E0, E0, 1F, E0, E0, 73, 68, 6F, 77, 67, 65, 74, 78, 00, 1F, E0, E0, E0, 1F, E0, E0, 00, 00, 00, 00, 06, 00, 00, 00, 4C, 1D, 40, 00, 07, 00, 00, 00, 1C, 1C, 40, 00, 07, 00, 00, 00, 64, 1B, 40, 00, 01, 00, 01, 00, 2C, 19, 40, 00...
 
[+]

Entropy:
5.5484

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
176 KB (180,224 bytes)

ActiveX Install
Name:
{8E706A14-C13A-4F36-9F00-8F4E44F45C30}


Remove showgetx.exe - Powered by Reason Core Security