File Name | microsoft-office-2007-pl-service-pack-1-6628206826363009-AsystentPobierania_v3.082.18.404.3.exe |
File Type |
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
Scanner Version | 1.0.171.174 |
Database Version | 2024-04-11 17:00:25 UTC |
Malware family: BundleInstaller
Hash Type | Value | Action |
---|---|---|
MD5 |
d4adc7605262e763df8ceae216ffd6f0
|
|
SHA1 |
aa30f307e71241153ea8cce368b0c0927d315f3f
|
|
SHA256 |
86334aecee74da35121138dd558010c6315e659b4cb91546c947f743da20a42a
|
|
SHA512 |
a608a55e241f8450180f502ccf2b9ad51e29dcb97b23fba8934e990ee42237281cc44dcc953e7735f3e5e20a305809010c5ee96c958b2012e09b26d37df707b0
|
|
ImpHash |
f34d5f2d4577ed6d9ceec516c1f5a744
|
Icon |
Hash: 9a26bff507f2a1b78831e7d0311620b5
Fuzzy: 3b5d3c7d207e37dceeedd301e35e2e58 dHash: 0000000000000000 |
Image Base | 0x00400000 |
Entry Point | 0x004f5f5e |
Compilation Time | 2023-09-10 08:23:00 |
Checksum | 0x001475fa (Actual: 0x001475fa) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
|
Digital Signature | OK |
Imports |
1 libraries
mscoree |
Exports | 0 functions |
Resources | 12 Resources |
Sections | 3 Sections |
Translation | 0x0000 0x04b0 |
Comments | Wirtualna Polska Media SA |
CompanyName | |
FileDescription | Wirtualna Polska Media SA |
FileVersion | 1.92.3.8643 |
InternalName | dobreprogramy.pl.exe |
LegalCopyright | Wirtualna Polska Media SA |
LegalTrademarks | |
OriginalFilename | dobreprogramy.pl.exe |
ProductName | Wirtualna Polska Media SA |
ProductVersion | 1.92.3.8643 |
Assembly Version | 1.92.3.8643 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00002000 |
999,284 bytes | 999,424 bytes | 3.88 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
F1ADAC7349DE93A3DF352317DA80E243 |
.rsrc |
0x000f6000 |
309,128 bytes | 309,248 bytes | 1.65 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
185EAEBF456CF65A76CFA80ABFA26C7F |
.reloc |
0x00142000 |
12 bytes | 512 bytes | 0.10 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
95409ACCC91D323B65C8AF04ABB180F7 |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 9 | 304,196 bytes | |
RT_GROUP_ICON | 1 | 132 bytes | |
RT_VERSION | 1 | 980 bytes | |
RT_MANIFEST | 1 | 3,132 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.BundleInstaller.sa without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system