Gridinsoft Logo
File Icon

AGE_CHS.EXE PUP Patched Analysis

Technical Analysis

File Name AGE_CHS.EXE
File Type
MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
Scanner Version 1.0.218.174
Database Version 2025-06-15 01:00:19 UTC

PUP.Win32.Patched.cld

Malware family: Patched

Patched detection indicates legitimate files that have been modified by malicious software. These modifications often target essential system files through malware intervention.
N/A
Detection Rate
3,990,472
File Size (bytes)
2025-06-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6e249770a893e7bc97de0d078194e323
SHA1
f1f5814e040f69312d9e8d160fa615683bcf12af
SHA256
a43ce727056da4d1bb26380f16e1f4953ba3125e488fd3d27bb4b6bc7cdd8352
SHA512
a5baacaf747276bc9b74a6a03c3e964bf88ded22e03fa9f9c9559c96a866392ce872b044f88b03194fa795807c81eff96929fb5cdae29d17c0f82f7eaf9bbbfb
ImpHash
274e8773d52d241220ca1af683803c1e

PE Analysis

Basic Information

Icon
Hash: db86ee0310a8566fa7f38518adaed9fb
Fuzzy: 3c62a6392d598ee7dd8fb2ac1a927fab
dHash: 58506a6870c0f87c
Image Base 0x00400000
Entry Point 0x0058e561
Compilation Time 2021-08-03 10:13:38
Checksum 0x004a0789 (Actual: 0x003d5d29)
OS Version 6.0
PEiD Signatures MS-DOS executable PE32 executable (GUI) Intel 80386, for MS Windows, MZ for MS-DOS
Digital Signature No valid SignedData structure was found.
Imports 20 libraries
Exports 1 functions
Resources 29 Resources
Sections 12 Sections

Version Information

Comments ARCGameEngine
CompanyName ARC Software Laboratory
FileDesCription ARCGameEngine
FileVersion 4.85S
InternalName ARCGameEngine
LegalCopyright Copyright (c) ARC Software Laboratory 1999-2021
OriginalFilename AGE.EXE
ProductVersion 4.85.19.0
Translation 0x0411 0x03a4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 2,523,136 bytes 2,521,421 bytes 5.83 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 0EE114C1C51EC80D1A4CF356C8BE47BF
0x00269000 847,872 bytes 835,415 bytes 4.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 01FA4C4C8094DF1047C4A53A8D8B405B
0x00338000 57,344 bytes 35,195 bytes 4.59 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1E30064280BE6EFA41A395785550827F
0x00346000 16,384 bytes 2,364 bytes 3.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F8F93CC6E61FEDCC037A998977A46336
0x0034a000 4,096 bytes 268 bytes 0.04 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E6BAE569FF7C4CC256D53FB9CEAEB666
0x0034b000 4,096 bytes 7 bytes 1.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4E8E220C285738825E9D7E4459CA86A3
0x0034c000 4,096 bytes 2,020 bytes 4.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1BBCF45C2C0D9D0621754BF479FAA7D7
.rsrc 0x0034d000 602,112 bytes 500,329 bytes 5.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9AF86652F2654827389B9655DEA70B4C
0x003e0000 94,208 bytes 80,542 bytes 6.70 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 95D276C027D389C09C27B4D9E3129BA7
0x003f7000 4,096 bytes 641 bytes 0.92 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1323E34C8A4EA8FFDD65146F831C0A72
.SCY 0x003f8000 8,192 bytes 8,015 bytes 5.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 78DAE035956501689EC7AD4AB8049944
.Silvana 0x003fa000 4,096 bytes 456 bytes 3.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7C2E7670559D19EF9E294DBBA78D1E07
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 29 (498,789 bytes)
Resource Type Count Total Size Percentage
CSO 11 184,788 bytes
37%
RT_ICON 15 311,288 bytes
62.4%
RT_GROUP_ICON 1 216 bytes
0%
RT_VERSION 1 768 bytes
0.2%
RT_MANIFEST 1 1,729 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

PUP.Win32.Patched.cld Removal

Gridinsoft has the capability to identify and eliminate PUP.Win32.Patched.cld without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware