Gridinsoft Logo
File Icon

The Chew WGA 0.9.eXe (The Perpetuation Endeavor) File Analysis

Technical Analysis

File Name Chew WGA 0.9.eXe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
196608:9O1vl2I4a7SdzRDymXLa4mnb0DtUog3jCUE2nKNfMILF9UBDHLSwxT1aQhS:Wt2O7Sd1ymX+4mnOU9+UCZM6kzWu12
Scanner Version 1.0.183.174
Database Version 2024-07-31 22:00:32 UTC

Suspicious File Detected

Detected by 48 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
70%
Detection Rate
9,458,428
File Size (bytes)
48/69
Engines Detected
2024-07-31
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6738d790fc0f3928a8a5f19d829cae4d
SHA1
db0a727520178061506c7ec07a99bac581610329
SHA256
60ca507ef4ba7dbbb7ef6ea4b975b9b09a24d7d0c91d38d0876331203f962d98
SHA512
ceacf7ecdf1fa12da540f96592bd7114eb963bab8dc50641c000c1dff74b0b03ee24049df631d6c68ae70d208ff62e3476674f25e2faf5a3a09c9f46555d97b6
ImpHash
73386bf3d64aacc4f390f8277f3d3e96

Security Engines with Detections (48 of 69)

Lionic
Hacktool.Win32.WpaKill.3!c Malicious
Elastic
malicious (high confidence) Malicious
MicroWorld-eScan
Application.WpaKill.G Malicious
FireEye
Generic.mg.6738d790fc0f3928 Malicious
CAT-QuickHeal
HackTool.Wincred Malicious
Skyhigh
Crack-WindowsWGA.b Malicious
McAfee
Crack-WindowsWGA.b Malicious
Malwarebytes
Generic.Malware.AI.DDS Malicious
Sangfor
Hacktool.Win32.Wincred.uppyg Malicious
K7AntiVirus
Riskware ( 0040eff71 ) Malicious
K7GW
Riskware ( 0040eff71 ) Malicious
Cybereason
malicious.520178 Malicious
Arcabit
Application.WpaKill.G Malicious
VirIT
Trojan.Win32.Generic.KXP Malicious
Symantec
Trojan.ADH Malicious
ESET-NOD32
Win32/HackTool.WinActivator.N potentially unsafe Malicious
Cynet
Malicious (score: 100) Malicious
Avast
FileRepPup [PUP] Malicious
ClamAV
Win.Tool.Wpakill-15 Malicious
Kaspersky
HackTool.Win32.WinCred.b Malicious
BitDefender
Application.WpaKill.G Malicious
Tencent
Malware.Win32.Gencirc.10be80ff Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
DrWeb
Tool.Wpakill.4 Malicious
VIPRE
Application.WpaKill.G Malicious
TrendMicro
HKTL_WPAKILL.GB Malicious
Emsisoft
Application.WpaKill.G (B) Malicious
Varist
W32/Backdoor.ERSB-7047 Malicious
MAX
malware (ai score=100) Malicious
Antiy-AVL
RiskWare[RiskTool]/Win32.WinActivator Malicious
Kingsoft
Win32.HACKTOOL.Generic.yl Malicious
Xcitium
Malware@#26ukamrrty1sf Malicious
Microsoft
HackTool:Win32/Wpakill!pz Malicious
ViRobot
Trojan.Win32.S.Agent.9458428 Malicious
ZoneAlarm
HackTool.Win32.WinCred.b Malicious
GData
Application.WpaKill.G Malicious
Google
Detected Malicious
AhnLab-V3
Win-AppCare/Wpakill.9458428 Malicious
TACHYON
Trojan/W32.HackTool.9458428 Malicious
Cylance
unsafe Malicious
TrendMicro-HouseCall
HKTL_WPAKILL.GB Malicious
Yandex
HackTool.WinActivator!8tgvyoQ+R1s Malicious
Ikarus
HackTool.Win32.Wpakill Malicious
MaxSecure
Trojan.Malware.9008201.susgen Malicious
Fortinet
Riskware/WinCred Malicious
AVG
FileRepPup [PUP] Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/grayware_confidence_100% (W) Malicious
21 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 361f164253a952fc23f0a9bf91390245
Fuzzy: 88999c53b431248487dbdf1ff7e06814
dHash: 1769457575513b06
Image Base 0x00400000
Entry Point 0x004173a6
Compilation Time 2009-06-23 17:57:07
Checksum 0x00000000 (Actual: 0x00911131)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 8 libraries
KERNEL32, USER32, GDI32, comdlg32, WINSPOOL, ADVAPI32, SHELL32, COMCTL32
Exports 0 functions
Resources 31 Resources
Sections 4 Sections

Version Information

Comments Created with AutoPlay Media Studio (www.indigorose.com)
CompanyName Anemeros Software
FileDescription The Perpetuation Endeavor
FileVersion 0.9.0.0
InternalName ams60_launch
LegalCopyright Copyright (c) 2009 - Anemeros Software
LegalTrademarks Chew-WGA
OriginalFilename cw.exe
ProductName Chew-WGA v0.9
ProductVersion 0.9.0.0
Translation 0x0409 0x0000

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 190,726 bytes 192,512 bytes 6.60 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9BA09777227435273354D46C8470FBD3
.rdata 0x00030000 33,838 bytes 36,864 bytes 4.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EC25192B7421C9CC51F1A1283F96B143
.data 0x00039000 40,200 bytes 24,576 bytes 2.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E4B5677A176F441E4836113962ECDDBA
.rsrc 0x00043000 395,772 bytes 397,312 bytes 5.60 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 323A1694F037532B91F1E69CD7B83147
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 31 (394,031 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 2 488 bytes
0.1%
RT_BITMAP 4 2,380 bytes
0.6%
RT_ICON 8 383,360 bytes
97.3%
RT_DIALOG 2 382 bytes
0.1%
RT_STRING 11 5,428 bytes
1.4%
RT_GROUP_CURSOR 1 34 bytes
0%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 968 bytes
0.2%
RT_MANIFEST 1 901 bytes
0.2%

Certificate Chain Analysis

Certificate Information
Product Chew-WGA v0.9
Description The Perpetuation Endeavor
File Version 0.9.0.0
Original Name cw.exe
Internal Name ams60_launch
Copyright Copyright (c) 2009 - Anemeros Software

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
48 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware