GridinSoft Threat Intelligence

gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 file report

Under review File reputation report
MD5 7ab32305b6cfd529ac88d7c12698beb0
Latest seen 2026-05-13 16:56:06 (2 weeks ago)
First seen 2026-05-13 16:56:06 (2 weeks ago)
Size 35 MB
Publisher Gridinsoft LLC
Signed by Gridinsoft TOV

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2026-05-13 16:56:06 (2 weeks ago); latest analysis 2026-05-13 16:56:06 (2 weeks ago).

Publisher context

Company metadata: Gridinsoft LLC. Product metadata: Gridinsoft® Anti-Malware.

Digital signature

Signed by Gridinsoft TOV. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 is a Windows file recorded in the ThreatInfo database. It is associated with Gridinsoft® Anti-Malware. The reported company name is Gridinsoft LLC. The current detection status is Undefined, based on the latest analysis from 2026-05-13 16:56:06 (2 weeks ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Gridinsoft® Anti-Malware
Company Name: Gridinsoft LLC
MD5: 7ab32305b6cfd529ac88d7c12698beb0
Size: 35 MB
First Published: 2026-05-13 16:56:06 (2 weeks ago)
Latest Published: 2026-05-13 16:56:06 (2 weeks ago)
Status: Undefined (on last analysis)
Analysis Date: 2026-05-13 16:56:06 (2 weeks ago)
Signed By: Gridinsoft TOV
Status: Valid

The signature on gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%commonappdata%\totalav\endpoint protection sdk\common

ThreatInfo has observed gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

gsam.exe.2DC68BDFFC492B7B666E404793CF52C7 is identified as pe for 64-bit systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 64-bit
Subsystem Windows GUI
Entry point 0x01283380
Image base 0x0000000000400000

PE Sections:

Sections 11
Raw data 37543424

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 19627008 bytes · 52.3% of section data
Large raw data
MD5 06edc42e2757beb85619606b849f5581
.data 1856000 bytes · 4.9% of section data
MD5 4a5d0e903f3768ea9ff54941b7641d96
.bss 0 bytes · 0.0% of section data
MD5 d41d8cd98f00b204e9800998ecf8427e
.idata 38912 bytes · 0.1% of section data
MD5 c2bbe71698f87abf7256ffbd1f5b591d
.didata 6144 bytes · 0.0% of section data
Uncommon name
MD5 590feee0a5c3e6f9fed9ff3db827d703
.edata 512 bytes · 0.0% of section data
MD5 6393c1546ceae20bfbe53b13861515fc
.tls 0 bytes · 0.0% of section data
MD5 d41d8cd98f00b204e9800998ecf8427e
.rdata 512 bytes · 0.0% of section data
MD5 dbb4076151dc36cd38d2a40e6a9b6263
.reloc 874496 bytes · 2.3% of section data
MD5 2c50830204480fbd42cb95fcfb5353aa
.pdata 1019392 bytes · 2.7% of section data
MD5 c0eb3445b5aaaf70b61b553c19e3f843
.rsrc 14120448 bytes · 37.6% of section data
Large raw data
MD5 3170b9a75cf4d622ea86128eedd5e8d4

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

This file is still under review

ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.

Scan with GridinSoft Anti-Malware Use a local scan if the file origin or behavior is unclear. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 7ab32305b6cfd529ac88d7c12698beb0.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan if the source, path, or behavior looks unusual.