Gridinsoft Logo
File Icon

The wzdu35.exe (WinZip Driver Updater) File Analysis

Technical Analysis

File Name wzdu35.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
SSDEEP Hash
393216:HzhUTWXv7dmGGNL8L7wTYSVUn0SaR+UprR2+L8llTfPNgxpgGHIHeHgysL4tI:HzhUSX0GGNwL7wTTVU0SaRdprR2/llz3
Scanner Version 1.0.150.174
Database Version 2023-11-30 02:01:04 UTC

Suspicious File Detected

Detected by 7 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
10%
Detection Rate
21,683,080
File Size (bytes)
7/70
Engines Detected
2023-11-30
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
fc58eb11f398562a9a30996af95e3759
SHA1
588045bd4a04805e82377d4d4294956029017daa
SHA256
93ded1430b9c9ccea895e6866abbd88ce54b28756579f84719785dff4733013c
SHA512
68c4632ec1917efb9d0013d65a4c4ee3ead358bf289efd859e5a410e46d14231499bb18b940fb5dc5ed79f91e21014935b6c2e4e88605287e87a0d2befe49c47
ImpHash
bf95d1fc1d10de18b32654b123ad5e1f

Security Engines with Detections (7 of 70)

DrWeb
Program.Unwanted.4644 Malicious
Malwarebytes
PUP.Optional.WinZipDriverUpdater Malicious
ESET-NOD32
a variant of Win64/DriverReviver.A potentially unwanted Malicious
GData
Win32.Application.DriverReviver.A Malicious
DeepInstinct
MALICIOUS Malicious
Cylance
unsafe Malicious
Fortinet
Adware/DriverReviver Malicious
63 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 0608a43d1c1ad93ff44f9f882011d30d
Fuzzy: a4432c872e0d05459e9734cb028b6c4f
dHash: c4c4dcd0d0d4d849
Image Base 0x00400000
Entry Point 0x00403415
Compilation Time 2010-04-10 12:19:38
Checksum 0x014ba723 (Actual: 0x014ba723)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Digital Signature OK
Imports 8 libraries
KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, VERSION
Exports 0 functions
Resources 12 Resources
Sections 5 Sections

Digital Signatures

DigiCert Trusted Root G4 DigiCert, Inc. (US)
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Corel Corporation (CA)

Version Information

CompanyName Corel Corporation
FileDescription WinZip Driver Updater
FileVersion 5.42.2.10
LegalCopyright Copyright © 1991-2023 Corel Corporation. All Rights Reserved.
ProductName WinZip Driver Updater
ProductVersion 5.42.2.10
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 26,396 bytes 26,624 bytes 6.50 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CB807804553819B70F6E16B8A094D327
.rdata 0x00008000 6,614 bytes 6,656 bytes 5.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 161B329B4C70CE4FBD9C1143E738896B
.data 0x0000a000 463,772 bytes 512 bytes 1.74 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 140876BA314E7BC36379EE5C6DB80876
.ndata 0x0007c000 593,920 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x0010d000 373,128 bytes 373,248 bytes 5.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 433293E66278500BC1A667394C38BBB8
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 12 (372,401 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 370,224 bytes
99.4%
RT_DIALOG 3 636 bytes
0.2%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 716 bytes
0.2%
RT_MANIFEST 1 735 bytes
0.2%

Certificate Chain Analysis

Certificate #1
Subject DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
DigiCert, Inc.
US
Issuer DigiCert Trusted Root G4
Serial Number 11533403529598586876501374841704918745
Certificate #2
Subject Corel Corporation
Corel Corporation
CA
Issuer DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Serial Number 5084349746791588805075324576968336726
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
7 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware