The Eraser 6 2 0 2996 exe (Eraser Setup Bootstrapper) The Eraser Project File Malware Analysis
Gridinsoft Logo
File Icon

The Eraser 6.2.0.2996.exe (Eraser Setup Bootstrapper) File Analysis

Technical Analysis

File Name Eraser 6.2.0.2996.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.229.174
Database Version 2025-11-27 03:00:37 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
8,857,720
File Size (bytes)
2025-11-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
eda2786932b974ec98969fbb28be2d98
SHA1
03028ce564f2b42b2a33320a91593d1e9672d925
SHA256
031a46d174283f84475f908abbc559199b935d60e67be6ec5e22db154dd5a31c
SHA512
c6ae1f2e89af68fd3917e7e463f49666e99e913970aa9b73fcc96a9a70f4ab3125e90e451fd8fc5e7182371faf3b9cd0414070748b11f229b7b02a078a8eb5ea
ImpHash
83c398be415e99dc1d5d428efa4389f5

PE Analysis

Basic Information

Icon
Hash: be6b281f1000bf96682e643e82963a5f
Fuzzy: 218e87de484f388ef7db8c75ad8b81a4
dHash: d4f0b2b2b0a292b2
Image Base 0x00400000
Entry Point 0x0040d464
Compilation Time 2025-04-03 23:02:14
Checksum 0x0087e4fe (Actual: 0x0087e4fe)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 5 libraries
COMCTL32, KERNEL32, USER32, GDI32, SHELL32
Exports 0 functions
Resources 11 Resources
Sections 5 Sections

Version Information

Comments Eraser Setup Bootstrapper
CompanyName The Eraser Project
FileDescription Eraser Setup Bootstrapper
FileVersion 6.2.0.2996
InternalName Eraser Setup Bootstrapper
LegalCopyright Copyright © 2008-2021 The Eraser Project
OriginalFilename Eraser Setup Bootstrapper
ProductVersion 6.2.0.2996
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 99,947 bytes 100,352 bytes 6.60 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3BFCD4EC46B1357415987E71B3CF4B3D
.rdata 0x0001a000 42,072 bytes 42,496 bytes 5.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 992D24144258C13CA3C58309EC0CAA1D
.data 0x00025000 14,880 bytes 3,072 bytes 2.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A28330FA1CF67E83C512466827760D74
.rsrc 0x00029000 8,694,756 bytes 8,694,784 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DAC31C79B24EE5C9F497DBA1C3E80397
.reloc 0x00874000 5,504 bytes 5,632 bytes 6.53 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 19ECD05487BC97FDA6119CF76E01D93B
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 11 (8,694,086 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 56,653 bytes
0.7%
RT_RCDATA 1 8,635,849 bytes
99.3%
RT_GROUP_ICON 1 104 bytes
0%
RT_VERSION 1 872 bytes
0%
RT_MANIFEST 1 608 bytes
0%

Certificate Chain Analysis

Certificate Information
Description Eraser Setup Bootstrapper
File Version 6.2.0.2996
Original Name Eraser Setup Bootstrapper
Signing Date 10:44 AM 04/04/2025 (279 days ago)
Verification Status Signed
Signers HEIDI COMPUTERS LIMITED; GlobalSign GCC R45 CodeSigning CA 2020; GlobalSign Code Signing Root R45
Counter Signers Globalsign TSA for Advanced - G4 - 202311; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign Root CA - R6
Internal Name Eraser Setup Bootstrapper
Copyright Copyright © 2008-2021 The Eraser Project
Certificate Chain Summary
GlobalSign GCC R45 CodeSigning CA 2020 #1 Primary
Validity Period: 2020-07-28 00:00:00 → 2030-07-28 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 77 BD 0E 03 A1 B7 08 F8 54 AB 06 72 10 D9 04 47
HEIDI COMPUTERS LIMITED #2 Chain
Validity Period: 2023-11-03 15:32:21 → 2027-01-30 15:32:21
Signature Algorithm: sha256RSA
Serial Number: 17 6C 90 76 23 CB 0D 8F AC 7A F8 E9
Globalsign TSA for Advanced - G4 - 202311 #3 Chain
Validity Period: 2023-11-02 10:30:02 → 2034-12-04 10:30:02
Signature Algorithm: sha256RSA
Serial Number: 01 19 75 74 71 C9 92 D7 44 DF A5 96 EB B9 70 15
GlobalSign Timestamping CA - SHA384 - G4 #4 Chain
Validity Period: 2018-06-20 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 EC 1C 92 40 DE FD 2E 40 5D 7C 47 74
GlobalSign #5 Chain
Validity Period: 2014-12-10 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 45 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware