× В вашем браузере отключены куки (cookie). Для полноценной работы сайта необходимо включить сохранение файлов cookie.
SHA256: fcf43ee07f72514e0fa89f6fda7e6b91062cb2bfa3566a480bc7211201607847
Имя файла: RegOrganizer.exe
Показатель выявления: 1 / 67
Дата анализа: 2017-11-11 14:21:46 UTC (1 неделя, 5 дней назад) Показать последний анализ
Антивирус Результат Дата обновления
Cylance Unsafe 20171111
Ad-Aware 20171111
AegisLab 20171111
AhnLab-V3 20171111
Alibaba 20170911
ALYac 20171110
Antiy-AVL 20171111
Arcabit 20171110
Avast 20171111
Avast-Mobile 20171111
AVG 20171111
Avira (no cloud) 20171111
AVware 20171111
Baidu 20171109
BitDefender 20171111
Bkav 20171111
CAT-QuickHeal 20171110
ClamAV 20171111
CMC 20171109
Comodo 20171111
CrowdStrike Falcon (ML) 20171016
Cybereason 20171030
Cyren 20171111
DrWeb 20171111
eGambit 20171111
Emsisoft 20171111
Endgame 20171024
ESET-NOD32 20171111
F-Prot 20171111
F-Secure 20171111
Fortinet 20171111
GData 20171111
Ikarus 20171111
Sophos ML 20170914
Jiangmin 20171110
K7AntiVirus 20171111
K7GW 20171111
Kaspersky 20171111
Kingsoft 20171111
Malwarebytes 20171111
MAX 20171111
McAfee 20171111
McAfee-GW-Edition 20171111
Microsoft 20171111
eScan 20171111
NANO-Antivirus 20171111
nProtect 20171111
Palo Alto Networks (Known Signatures) 20171111
Panda 20171111
Qihoo-360 20171111
Rising 20171111
SentinelOne (Static ML) 20171019
Sophos AV 20171111
SUPERAntiSpyware 20171111
Symantec 20171110
Symantec Mobile Insight 20171110
Tencent 20171111
TheHacker 20171102
TrendMicro 20171111
TrendMicro-HouseCall 20171111
Trustlook 20171111
VBA32 20171110
VIPRE 20171111
ViRobot 20171111
Webroot 20171111
WhiteArmor 20171104
Yandex 20171110
Zillya 20171110
ZoneAlarm by Check Point 20171111
Zoner 20171111
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Product Reg Organizer
File version 0.0.0.0
Description Reg Organizer
Signature verification A certificate chain could not be built to a trusted root authority.
Signing date 6:20 PM 11/23/2017
Packers identified
F-PROT PecBundle
PEiD PECompact 2.xx --> BitSum Technologies
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2017-11-09 07:46:32
Entry Point 0x00002CB0
Number of sections 2
PE sections
Overlays
MD5 e32d0a03713a5719972ee7f2306aa86c
File type data
Offset 4794368
Size 3496
Entropy 7.40
PE imports
VirtualFree
LoadLibraryA
VirtualAlloc
GetProcAddress
Number of PE resources by type
RT_RCDATA 65
RT_STRING 46
RT_BITMAP 21
RT_GROUP_CURSOR 8
RT_CURSOR 8
RT_ICON 7
RT_FONT 2
RT_MANIFEST 1
RT_FONTDIR 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 108
ENGLISH US 52
RUSSIAN 1
PE resources
ExifTool file metadata
SubsystemVersion
5.0

InitializedDataSize
4832768

ImageVersion
0.0

ProductName
Reg Organizer

FileVersionNumber
0.0.0.0

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x0000

CharacterSet
Windows, Latin1

LinkerVersion
5.0

FileTypeExtension
exe

MIMEType
application/octet-stream

FileVersion
0.0.0.0

TimeStamp
2017:11:09 08:46:32+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
8.03

FileDescription
Reg Organizer

OSVersion
4.0

FileOS
Unknown (0)

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Chemtable Software

CodeSize
17062400

FileSubtype
0

ProductVersionNumber
8.3.0.0

EntryPoint
0x2cb0

ObjectFileType
Unknown

Execution parents
Compressed bundles
File identification
MD5 dbcad758f2a96256deeb8aa1a50d677f
SHA1 53ae235578cb03d59a225cc8e21cf0bd83cee370
SHA256 fcf43ee07f72514e0fa89f6fda7e6b91062cb2bfa3566a480bc7211201607847
ssdeep
98304:yJjAFjwr6wtVpvFKW1i1OUeSPWylT3m4xPRp7GyLipgKOywss7Z3:ScFkGwtVNFKkgOUeSPc4ZRXipJpsh

authentihash 54b475a6599a63aa7f6a28d5dcb9e796a25410675138555a517a26f2cf2f22c7
imphash 09d0478591d4f788cb3e5ea416c25237
Размер файла 4.6 MБ ( 4797864 bytes )
Тип файла Win32 EXE
Описание
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable (generic) (52.9%)
Generic Win/DOS Executable (23.5%)
DOS Executable Generic (23.5%)
Tags
pecompact peexe overlay

VirusTotal metadata
First submission 2017-11-11 14:04:41 UTC (1 неделя, 5 дней назад)
Last submission 2017-11-23 17:20:38 UTC (12 часов, 10 минут назад)
Имена файлов RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
regorganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
regorganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
RegOrganizer.exe
Нет комментариев. Из участников сообщества VirusTotal ещё пока никто не оставил комментарий по поводу результатов анализа. Станьте первым!

Оставьте свой комментарий...

?
Отправить

Вы не выполнили вход. Только зарегистрированные пользователи могут оставлять комментарии. Выполните вход и получите право голоса!

Нет голосов. Ещё пока никто не проголосовал за результаты анализа. Станьте первым!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Runtime DLLs
UDP communications