Gridinsoft Logo
File Icon

RFiler Installer 1.2.0.5a.exe Adware VOPackage Analysis

Technical Analysis

File Name rFiler Installer 1.2.0.5a.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-06 03:00:36 UTC

Adware.Win32.VOPackage.oa!s1

Malware family: VOPackage

N/A
Detection Rate
3,045,606
File Size (bytes)
2025-03-06
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a8827809f67da117b678fed5287da0b8
SHA1
583c34b9ae89dece2bf2e8aba915bda1c7f1b5cb
SHA256
6d36408a5717740494c916a044a5eef4f7c97a05b0bac18014a8a18d3f630e97
SHA512
3ba1f577200cb39c9472b45d068fc557ff499c32c4d9464b644e3beab4a35230a4e2ea342fc7192f67a81fcf410631fe6151f3a387416ce385417090443bb1e2
ImpHash
40ab50289f7ef5fae60801f88d4541fc

PE Analysis

Basic Information

Icon
Hash: 7df77dbfbff9e154a204486ef633ac83
Fuzzy: decf4426eab7143b20557a5719d8b44a
dHash: 963b3d576f2b178e
Image Base 0x00400000
Entry Point 0x004a7f98
Compilation Time 2025-02-12 05:53:16
Checksum 0x00000000 (Actual: 0x002ec6cb)
OS Version 6.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 5 libraries
kernel32, comctl32, user32, oleaut32, advapi32
Exports 2 functions
Resources 22 Resources
Sections 11 Sections

Version Information

Comments This installation was built with Inno Setup.
CompanyName Cyber Sphere Data, Inc
FileDescription rFiler Setup
FileVersion
LegalCopyright
OriginalFileName
ProductName rFiler
ProductVersion 1.2.0.5
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 677,540 bytes 677,888 bytes 6.38 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 463E3AAAB99B053F2C4A2F67933C8E57
.itext 0x000a7000 5,952 bytes 6,144 bytes 6.17 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AABAD89A99811463C0C9E4733F9929F6
.data 0x000a9000 14,392 bytes 14,848 bytes 4.97 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4DAF07AD25DE9A5FBCE0E8BFA5BEBF31
.bss 0x000ad000 29,304 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x000b5000 4,076 bytes 4,096 bytes 5.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 627340DFF539EF99048969AA4824FB2D
.didata 0x000b6000 420 bytes 512 bytes 2.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FD11C1109737963CC6CB7258063ABFD6
.edata 0x000b7000 113 bytes 512 bytes 1.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7DE8CA0C7A61668A728FD3A88DC0942D
.tls 0x000b8000 24 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x000b9000 93 bytes 512 bytes 1.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D84006640084DC9F74A07C2FF9C7D656
.reloc 0x000ba000 68,992 bytes 69,120 bytes 6.71 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8871BB651F0D9A00A939AD4155039605
.rsrc 0x000cb000 113,652 bytes 113,664 bytes 7.65 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8F3D37681BAC638EE7F7FE9DFAEBC268
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 22 (112,377 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 99,681 bytes
88.7%
RT_STRING 11 8,336 bytes
7.4%
RT_RCDATA 3 912 bytes
0.8%
RT_GROUP_ICON 1 76 bytes
0.1%
RT_VERSION 1 1,412 bytes
1.3%
RT_MANIFEST 1 1,960 bytes
1.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Adware.Win32.VOPackage.oa!s1 Removal

Gridinsoft has the capability to identify and eliminate Adware.Win32.VOPackage.oa!s1 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware