File Name | kavremvr.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.216.174 |
Database Version | 2025-05-06 17:00:17 UTC |
No threats detected by our scanner
Hash Type | Value | Action |
---|---|---|
MD5 |
fef34d54be99e90a57c0129c50da5362
|
|
SHA1 |
b37de26852bb0cb4f8cb5f4e9f1b9c27ada1fcea
|
|
SHA256 |
c1f39b041774289129a8c269c436313bd3792e4814a382c2de72162a67b32921
|
|
SHA512 |
6347d0a14679e25e630df060c5542173ef2ff7c85437787b3ffb357e6761bab50c0048497b0d8db36df6295bf5af9e1b0b963f8d86effef664e2cff42c96baf3
|
|
ImpHash |
8b18edac65cf62fc24dc39039063d3c6
|
Icon |
Hash: 63ed0c24b57411c23dc8aa46e2969b00
Fuzzy: 3772edfa42e8bd174708b293d6c0d6b0 dHash: a7d5e96553356763 |
Image Base | 0x00400000 |
Entry Point | 0x00404a50 |
Compilation Time | 2025-04-09 11:23:15 |
Checksum | 0x00f64b54 (Actual: 0x00f64b54) |
OS Version | 5.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | C:\a\c\d_00000000\s\product\kleaner\source\_out\Win32\Release\kavremvr.pdb |
Digital Signature | OK |
Imports |
1 libraries
KERNEL32 |
Exports | 1 functions |
Resources | 11 Resources |
Sections | 7 Sections |
CompanyName | Kaspersky Lab ZAO |
LegalCopyright | © 2013 Kaspersky Lab ZAO. All Rights Reserved. |
LegalTrademarks | Registered trademarks and service marks are the property of their respective owners |
ProductName | Kaspersky Removal Tool |
ProductVersion | 1.0.5514.0 |
FileVersion | 1.0.(5514).0 |
FileDescription | KAV Removal Tool |
InternalName | KAVREMVR |
OriginalFilename | KAVREMVR.EXE |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
317,228 bytes | 317,440 bytes | 6.61 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
5263EE226B5562DAE4F3E146E9AF185F |
.rdata |
0x0004f000 |
117,214 bytes | 117,248 bytes | 5.41 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
057FF0E6E005C448987FFE1DC0D9C37B |
.data |
0x0006c000 |
10,652 bytes | 6,144 bytes | 3.86 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
0F96200059659CE79A317EBF7608854C |
.didat |
0x0006f000 |
444 bytes | 512 bytes | 4.03 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BE181805838554E34C55E3DD27C0BE1D |
.eecseg |
0x00070000 |
344 bytes | 512 bytes | 2.53 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A7D99CE3BFE80094F862D70AC760278A |
.rsrc |
0x00071000 |
15,605,936 bytes | 15,606,272 bytes | 6.52 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
18C4B0B825EF1CD4C21ACEDC3AFBA63A |
.reloc |
0x00f54000 |
19,120 bytes | 19,456 bytes | 6.63 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
4275FEA5F82647F25525B7421D3B8A4E |
3 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 7 | 10,616 bytes | |
RT_RCDATA | 1 | 15,591,528 bytes | |
RT_GROUP_ICON | 1 | 104 bytes | |
RT_VERSION | 1 | 1,024 bytes | |
RT_MANIFEST | 1 | 1,985 bytes |
Product | Kaspersky Removal Tool |
Description | KAV Removal Tool |
File Version | 1.0.(5514).0 |
Original Name | KAVREMVR.EXE |
Signing Date | 11:23 AM 04/09/2025 (58 days ago) |
Verification Status | Signed |
Signers | AO Kaspersky Lab; GlobalSign GCC R45 EV CodeSigning CA 2020; GlobalSign Code Signing Root R45; GlobalSign Root CA - R3 |
Counter Signers | DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert |
Internal Name | KAVREMVR |
Copyright | © 2013 Kaspersky Lab ZAO. All Rights Reserved. |
61 05 F7 1E 00 00 00 00 00 32
61 03 DC F6 00 00 00 00 00 0C
61 16 68 34 00 00 00 00 00 1C
61 15 08 27 00 00 00 00 00 0C
79 A2 A5 85 F9 D1 15 42 13 D9 B8 3E F6 B6 8D ED
47 BF 19 95 DF 8D 52 46 43 F7 DB 6D 48 0D 31 A4
25 0C E8 E0 30 61 2E 9F 2B 89 F7 05 4D 7C F8 FD
61 0C 12 06 00 00 00 00 00 1B
16 E5 A7 75 12 03 00 FB 34 19 45 8B 40 D4 08 34
84 68 9E 02 36 AF 4F 57 B0 76 AD 93 6F B0 24 DD
E5 6E FB 3F 32 2C 46 CF 85 AD F1 06 1A A1 16 10
91 0A C6 82 F3 AC 4D A3 86 90 D3 CC 5F 18 C2 90
47 A2 7E 59 46 1D 43 AE BC C6 41 44 6D 5C 99 F2
78 03 18 42 45 70 8A 41 CF 6F 01 B8 EE B4 A9 54
77 BD 0E 05 B7 59 0B B6 1D 47 61 53 1E 3F 75 ED
✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important