Gridinsoft Logo
File Icon

The Defraggler_v2.21.993.exe (Defraggler Installer) File Analysis

Technical Analysis

File Name Defraggler_v2.21.993.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
SSDEEP Hash
98304:U9wu+wEOftnKviIRE0dXvjrF0QaO+za/qKJ8FLTZH:UGnw9lhHEXLr2IlKFLx
Scanner Version 1.0.227.174
Database Version 2025-10-17 11:00:19 UTC

Suspicious File Detected

Detected by 5 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
7%
Detection Rate
4,529,456
File Size (bytes)
5/71
Engines Detected
2025-10-17
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
ca2c52d0a9f9e213884cffff9109c6d9
SHA1
ef0a247e60aa7ba2f364b1a75be2707ac48bc880
SHA256
c49553cb735aa2bc76dfa7379d0232aabf718e635021215035b35f4d3b9ff7e5
SHA512
4948363d9bad1e90fa10065c6fc7458cccb4e9947f5dc54c642a211ebfb073dca6b6c241139fe45a0c311d0080f6fde12e8dbb275818507e3b760b447f5f1a30
ImpHash
377a97652fdf5740d8cc11d5ce124fed

Security Engines with Detections (5 of 71)

Cylance
Unsafe Malicious
ESET-NOD32
Win32/Bundled.Toolbar.Google.D potentially unsafe Malicious
Microsoft
PUABundler:Win32/PiriformBundler Malicious
Yandex
Trojan.Igent.bRYV50.1 Malicious
DeepInstinct
MALICIOUS Malicious
66 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 3443874fd60a0379eb7e45e9587cba62
Fuzzy: 74a89ee598283ed8bf17c360ddd8423e
dHash: e862eae6b696c6cc
Image Base 0x00400000
Entry Point 0x00403a1c
Compilation Time 2015-12-29 21:34:49
Checksum 0x004560c1 (Actual: 0x004560c1)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Digital Signature OK
Imports 7 libraries
KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32
Exports 0 functions
Resources 49 Resources
Sections 5 Sections

Version Information

CompanyName Piriform Ltd
FileDescription Defraggler Installer
FileVersion 1.0.0.0
LegalCopyright Copyright © 2006-2016 Piriform Ltd
ProductName Defraggler
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 29,264 bytes 29,696 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2CF4CEA611906ABDA27F6BEC5B76FFBD
.rdata 0x00009000 11,064 bytes 11,264 bytes 4.42 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5275F8CAE603F81939930AC752DE3D01
.data 0x0000c000 425,692 bytes 512 bytes 1.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3096D49B7B4C3DE8338C4639CBB79A13
.ndata 0x00074000 3,428,352 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x003b9000 37,024 bytes 37,376 bytes 4.80 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C6E0B2FD63218C25EF67F5D7DA8BFBF0

Resource Analysis

Total Resources: 49 (34,494 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 19,376 bytes
56.2%
RT_DIALOG 40 13,484 bytes
39.1%
RT_GROUP_ICON 1 90 bytes
0.3%
RT_VERSION 1 576 bytes
1.7%
RT_MANIFEST 1 968 bytes
2.8%

Certificate Chain Analysis

Certificate Information
Product Defraggler
Description Defraggler Installer
File Version 1.0.0.0
Signing Date 03:18 PM 03/08/2016 (3594 days ago)
Verification Status Signed
Signers Piriform Ltd; Symantec Class 3 SHA256 Code Signing CA; VeriSign
Counter Signers Symantec Time Stamping Services Signer - G4; Symantec Time Stamping Services CA - G2; Thawte Timestamping CA
Copyright Copyright © 2006-2016 Piriform Ltd
Certificate Chain Summary
Symantec Time Stamping Services CA - G2 #1 Primary
Validity Period: 2012-12-21 00:00:00 → 2020-12-30 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
Symantec Time Stamping Services Signer - G4 #2 Chain
Validity Period: 2012-10-18 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
Piriform Ltd #3 Chain
Validity Period: 2015-08-12 00:00:00 → 2018-10-10 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 4B 48 B2 7C 82 24 FE 37 B1 7A 6A 2E D7 A8 1C 9F
Symantec Class 3 SHA256 Code Signing CA #4 Chain
Validity Period: 2013-12-10 00:00:00 → 2023-12-09 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 3D 78 D7 F9 76 49 60 B2 61 7D F4 F0 1E CA 86 2A
GeoTrust 2048-bit Timestamping Signer 1 #5 Chain
Validity Period: 2015-06-11 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 5F D6 93 FA B0 98 E3 F4 67 7B B8 CB 67 2C 22 9E
Thawte Timestamping CA #6 Chain
Validity Period: 1997-01-01 00:00:00 → 2020-12-31 23:59:59
Signature Algorithm: md5RSA
Serial Number: 00

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
5 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware