File Name | Advanced-System-Repair-Pro-RepairTool.W.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-18 07:00:31 UTC |
Malware family: AdvancedSystemRepair
Hash Type | Value | Action |
---|---|---|
MD5 |
f4d0eea8ec0a2171ad416314d39bc8c2
|
|
SHA1 |
3df7d6998ad6a57813f7d990e9645d2d281f63ae
|
|
SHA256 |
98ad94de05423fe96750b518111c957a069e8c336ed9557c92d9771ff926e167
|
|
SHA512 |
29d25e1d4270b013887552d6d763dbbcd8ca1ace584b1d0160619c20db789cc6e6a32272b101730f8c01ba70b1ad292360d9a25a3c4e5fa894a52c94c3c3711c
|
|
ImpHash |
b3d334858d86ba48b9ecf38a1337c67a
|
Icon |
Hash: 7174db92f27194536e80e3d6e208cdf6
Fuzzy: 12e062a7dd939b843f71c190b612ec6d dHash: f0aee2f8f2d469b2 |
Image Base | 0x00400000 |
Entry Point | 0x00503160 |
Compilation Time | 2023-08-25 20:34:32 |
Checksum | 0x0117f785 (Actual: 0x0117f785) |
OS Version | 5.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports | 16 libraries |
Exports | 0 functions |
Resources | 84 Resources |
Sections | 5 Sections |
CompanyName | Advanced System Repair, Inc. |
LegalCopyright | (c) Advanced System Repair, Inc. All rights reserved. |
FileDescription | Advanced System Repair Pro |
FileVersion | 2.0.0.8 |
InternalName | Advanced System Repair Pro |
OriginalFilename | Advanced System Repair Pro |
ProductName | Advanced System Repair Pro |
ProductVersion | 2.0.0.8 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
1,228,358 bytes | 1,228,800 bytes | 6.56 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
5EE11B008B9465EC39BBFA9CFEB3608D |
.rdata |
0x0012d000 |
305,892 bytes | 306,176 bytes | 5.15 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6ACD2DAA2980AF6ADC0B56C5755581CC |
.data |
0x00178000 |
52,568 bytes | 23,552 bytes | 4.69 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
697846F3809B3C755CC5F25AAB6E8345 |
.rsrc |
0x00185000 |
486,716 bytes | 486,912 bytes | 6.47 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
9800709FF3F07CD3D2616CB343772FF1 |
.reloc |
0x001fc000 |
152,994 bytes | 153,088 bytes | 5.30 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
427D7ACF3A7A57DA05766DD0BC0980A9 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_CURSOR | 16 | 4,800 bytes | |
RT_BITMAP | 23 | 365,196 bytes | |
RT_ICON | 6 | 102,992 bytes | |
RT_DIALOG | 8 | 1,936 bytes | |
RT_STRING | 13 | 5,542 bytes | |
RT_GROUP_CURSOR | 15 | 314 bytes | |
RT_GROUP_ICON | 1 | 90 bytes | |
RT_VERSION | 1 | 924 bytes | |
RT_MANIFEST | 1 | 633 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.AdvancedSystemRepair.dd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system