webguide.exe

goodcomms Inc.

The application webguide.exe by goodcomms has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
goodcomms Inc.  (signed and verified)

MD5:
d0c08dd5e41b365e9f6a14d0bd5fedca

SHA-1:
25d9d3658629204c495852d0c1ed794c2833611a

SHA-256:
21436febb3999fff5afebabe06d86d5ece349488725b27b795bca290fa90116f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:13:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.GoodComms (M)
16.9.17.18

File size:
462.1 KB (473,216 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\webguide\webguide.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
11/18/2011 9:00:00 AM

Valid to:
11/18/2012 8:59:59 AM

Subject:
CN=goodcomms Inc., OU=marketing, O=goodcomms Inc., L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
195A4CBA4A685695C96ED6E8C5A0EA1D

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:xPoNu3d5r26bC7o7YQbWPQB/50v/CnRKN9V40kYvIUF5Dod/QQK+4zLWalgX:J53r26bC7o8Xo55SCQV4LYLUg+SLxgX

Entry address:
0x619E8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 48, 17, 46, 00, E8, 00, 4B, FA, FF, 33, C0, 55, 68, 75, 1A, 46, 00, 64, FF, 30, 64, 89, 20, B8, C8, 4D, 46, 00, BA, 8C, 1A, 46, 00, E8, 5F, 2A, FA, FF, B2, 01, A1, EC, 0D, 46, 00, E8, 53, FC, FF, FF, A3, C4, 4D, 46, 00, 33, C0, 55, 68, 60, 1A, 46, 00, 64, FF, 30, 64, 89, 20, A1, C4, 4D, 46, 00, E8, BE, F6, FF, FF, A1, C4, 4D, 46, 00, E8, F4, F7, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, 68, 67, 1A, 46, 00, A1, C4, 4D, 46, 00, E8, 4D, 1C, FA, FF, C3, E9, 97, 23, FA, FF, EB, EE, 33...
 
[+]

Entropy:
6.6328

Developed / compiled with:
Microsoft Visual C++

Code size:
387 KB (396,288 bytes)

Remove webguide.exe - Powered by Reason Core Security