× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 0abfbcc65f7eeae25cda327b2c6602ca713baa17ce6f7ed17fcb78ab1107d9d3
File name: RebootRestoreRx.exe
Detection ratio: 2 / 50
Analysis date: 2014-03-23 02:31:08 UTC ( 3 weeks, 4 days ago )
Probably harmless! There are strong indicators suggesting that this file is safe to use.
Antivirus Result Update
Antiy-AVL Trojan/Win32.SGeneric 20140320
NANO-Antivirus Trojan.Win32.XPACK.cvcwik 20140323
AVG 20140322
Ad-Aware 20140323
AegisLab 20140323
Agnitum 20140322
AhnLab-V3 20140322
AntiVir 20140322
Avast 20140323
Baidu-International 20140322
BitDefender 20140323
Bkav 20140322
ByteHero 20140323
CAT-QuickHeal 20140322
CMC 20140319
ClamAV 20140322
Commtouch 20140323
Comodo 20140322
DrWeb 20140323
ESET-NOD32 20140323
Emsisoft 20140323
F-Prot 20140323
F-Secure 20140323
Fortinet 20140323
GData 20140323
Ikarus 20140322
Jiangmin 20140322
K7AntiVirus 20140321
K7GW 20140321
Kaspersky 20140323
Kingsoft 20140323
Malwarebytes 20140323
McAfee 20140323
McAfee-GW-Edition 20140323
MicroWorld-eScan 20140323
Microsoft 20140323
Norman 20140322
Panda 20140322
Qihoo-360 20140323
Rising 20140322
SUPERAntiSpyware 20140322
Sophos 20140322
Symantec 20140323
TheHacker 20140321
TotalDefense 20140322
TrendMicro 20140323
TrendMicro-HouseCall 20140323
VBA32 20140321
VIPRE 20140323
ViRobot 20140322
nProtect 20140321
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Packers identified
F-PROT RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, UTF-8, RAR, RAR, UTF-8, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, RAR, UTF-8, RAR, RAR, RAR, RAR, RAR
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2012-02-17 14:55:21
Link date 3:55 PM 2/17/2012
Entry Point 0x0000B583
Number of sections 5
PE sections
PE imports
RegCreateKeyExW
RegCloseKey
OpenProcessToken
RegSetValueExW
RegOpenKeyExW
SetFileSecurityW
AdjustTokenPrivileges
LookupPrivilegeValueW
SetFileSecurityA
RegQueryValueExW
InitCommonControlsEx
GetSaveFileNameW
CommDlgExtendedError
GetOpenFileNameW
GetDeviceCaps
DeleteDC
SelectObject
StretchBlt
GetObjectW
CreateCompatibleDC
DeleteObject
CreateCompatibleBitmap
SetFilePointer
GetSystemTime
GetLastError
HeapFree
GetStdHandle
DosDateTimeToFileTime
ReadFile
FileTimeToSystemTime
GetModuleFileNameW
WaitForSingleObject
GetVersionExW
GetExitCodeProcess
FindNextFileA
CompareStringW
HeapAlloc
SystemTimeToFileTime
IsDBCSLeadByte
GetCommandLineW
GetFileAttributesW
GetCurrentProcess
FileTimeToLocalFileTime
MoveFileW
OpenFileMappingW
SetFileAttributesA
GetDateFormatW
CreateDirectoryA
DeleteFileA
GetCPInfo
ExitProcess
MultiByteToWideChar
SetEnvironmentVariableW
CreateDirectoryW
DeleteFileW
GetProcAddress
GetProcessHeap
CreateFileMappingW
GetTimeFormatW
WriteFile
SetFileAttributesW
CloseHandle
WideCharToMultiByte
MapViewOfFile
MoveFileExW
ExpandEnvironmentStringsW
FindNextFileW
SetEndOfFile
GetFileAttributesA
GetTempPathW
FindFirstFileA
FindFirstFileW
HeapReAlloc
GetModuleHandleW
GetFullPathNameA
FreeLibrary
GetCurrentDirectoryW
LoadLibraryW
SetCurrentDirectoryW
UnmapViewOfFile
FindResourceW
CreateFileW
GlobalAlloc
LocalFileTimeToFileTime
FindClose
Sleep
GetFileType
GetFullPathNameW
SetFileTime
CreateFileA
GetTickCount
GetLocaleInfoW
GetNumberFormatW
SetLastError
CompareStringA
VariantInit
SHBrowseForFolderW
SHChangeNotify
SHFileOperationW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
ShellExecuteExW
SHGetFileInfoW
SHGetMalloc
SHAutoComplete
SetFocus
MapWindowPoints
GetParent
UpdateWindow
EndDialog
LoadBitmapW
DefWindowProcW
GetWindowTextW
GetMessageW
ShowWindow
GetSystemMetrics
SetWindowPos
wvsprintfW
CharToOemBuffA
SetWindowLongW
IsWindow
SendMessageW
GetWindowRect
RegisterClassExW
CharUpperW
DialogBoxParamW
CharToOemBuffW
wvsprintfA
SendDlgItemMessageW
GetDlgItemTextW
PostMessageW
GetSysColor
SetDlgItemTextW
GetDC
ReleaseDC
DestroyIcon
TranslateMessage
IsWindowVisible
LoadStringW
SetWindowTextW
GetDlgItem
GetWindow
MessageBoxW
DispatchMessageW
GetClassNameW
PeekMessageW
CharUpperA
GetClientRect
OemToCharA
EnableWindow
CopyRect
WaitForInputIdle
OemToCharBuffA
LoadCursorW
LoadIconW
FindWindowExW
CreateWindowExW
GetWindowLongW
SetForegroundWindow
DestroyWindow
CharToOemA
CreateStreamOnHGlobal
OleUninitialize
CoCreateInstance
OleInitialize
CLSIDFromString
Number of PE resources by type
RT_DIALOG 6
RT_STRING 6
RT_ICON 4
RT_MANIFEST 1
RT_BITMAP 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 19
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2012:02:17 15:55:21+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
73216

LinkerVersion
9.0

FileAccessDate
2014:03:23 03:31:32+01:00

EntryPoint
0xb583

InitializedDataSize
113152

SubsystemVersion
5.0

ImageVersion
0.0

OSVersion
5.0

FileCreateDate
2014:03:23 03:31:32+01:00

UninitializedDataSize
0

File identification
MD5 80be8b58a5cee9709aacaaa74bdb6cc5
SHA1 774863a2d2c9600fe3a46f0209901a53503e3528
SHA256 0abfbcc65f7eeae25cda327b2c6602ca713baa17ce6f7ed17fcb78ab1107d9d3
ssdeep
98304:YHpLizIJ/p6ytV2y9fCv98Njgaudu4gI4XdFIzd:YLiEJ/TFG2glJP4Nud

imphash 553ef6236c6cb4268814330cd1e93c7d
File size 4.5 MB ( 4669733 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (67.3%)
Win32 Dynamic Link Library (generic) (14.2%)
Win32 Executable (generic) (9.7%)
Generic Win/DOS Executable (4.3%)
DOS Executable Generic (4.3%)
Tags
peexe

VirusTotal metadata
First submission 2013-03-20 18:59:58 UTC ( 1 year ago )
Last submission 2014-03-23 02:31:08 UTC ( 3 weeks, 4 days ago )
File names RebootRestoreRx(2).exe
RebootRestoreRx
file-5282605_exe
RebootRestoreRx.exe
RebootRestoreRx.exe
RebootRestoreRx_Restore on Rebbot_Reset to Baseline on PC Start Up or Hard Reset_Like old WindowsSteadyState.zip
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.
UDP communications