File Name | WCInstaller (9).exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.210.174 |
Database Version | 2025-03-04 17:00:21 UTC |
Malware family: WebCompanion
Hash Type | Value | Action |
---|---|---|
MD5 |
a97af612311a8e7897e3123aca4686ad
|
|
SHA1 |
aefdc08019c8a2532d9951f8e083e6ec210b3a25
|
|
SHA256 |
b7c85f97d22c2185c6d58cf7c329c9ec86d3f20e836e82b49e204975b8488f75
|
|
SHA512 |
9d4dace2e0c3b97641eae983722ef27bcf3ee6c875135a3ddbf4621e4b94c453a73fd763130f2c175ff6b92d1a3190a988b3d9a82802c8023fbd55e14f88db08
|
|
ImpHash |
e00de6e48b9b06aceb12a81e7bf494c9
|
Icon |
Hash: 5d22a7ff7121dddf8a76e69fbfa77d4f
Fuzzy: 12c3f1debd31ced5359a163aa35b6563 dHash: 00118ac8c4686900 |
Image Base | 0x00400000 |
Entry Point | 0x004148d4 |
Compilation Time | 2011-04-18 18:54:06 |
Checksum | 0x000899c7 (Actual: 0x000821d2) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | OK |
Imports |
4 libraries
OLEAUT32, USER32, SHELL32, KERNEL32 |
Exports | 0 functions |
Resources | 14 Resources |
Sections | 5 Sections |
FileVersion | 7.0.2417.4248 |
ProductVersion | 7.0.2417.4248 |
CompanyName | Lavasoft |
FileDescription | Web Companion Installer |
InternalName | Installer.exe |
LegalCopyright | c Lavasoft Limited. All Rights Reserved. |
OriginalFilename | Installer.exe |
ProductName | Web Companion Installer |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
104,384 bytes | 104,448 bytes | 6.61 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
206B62D600BEB166F8BF863AD5301F8C |
.rdata |
0x0001b000 |
17,552 bytes | 17,920 bytes | 4.38 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B0314F39355CAB7D4674A0928D3B15F2 |
.data |
0x00020000 |
23,144 bytes | 12,800 bytes | 1.38 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
8D44C03D32E0C923339CDA9FAE15827A |
.sxdata |
0x00026000 |
4 bytes | 512 bytes | 0.02 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_LNK_INFO|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
35925CFDC1176BD9FFC634A58B40EC17 |
.rsrc |
0x00027000 |
29,152 bytes | 29,184 bytes | 4.66 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
852AECDCEEBC493B369CF84401D77D29 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 7 | 25,291 bytes | |
RT_DIALOG | 1 | 184 bytes | |
RT_STRING | 2 | 200 bytes | |
RT_GROUP_ICON | 2 | 110 bytes | |
RT_VERSION | 1 | 836 bytes | |
RT_MANIFEST | 1 | 1,674 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.WebCompanion.vfd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system