Gridinsoft Logo
File Icon

The UserDiag.exe (UserDiag) File Analysis

Technical Analysis

File Name UserDiag.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-16 11:01:01 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
50,336,512
File Size (bytes)
2025-03-16
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a98f4fd0cfe030b6680390b6fedff46f
SHA1
5cdd79cc22511c78c0e7a54269c6803ceca9a283
SHA256
c9e0596c74954a6943c050c674d802588a7f3d047c31738ff0d4829fffea3eda
SHA512
41bf789bf66ec8c461233bf573de5c92ba74618622f2501e0f3a001bd2463e3f812f0080750042687dec1ad1dc4087f003591f3272f0db1019c8db595259a84e
ImpHash
1895460fffad9475fda0c84755ecfee1

PE Analysis

Basic Information

Icon
Hash: 9c2f58d542aba2b58b77f9d048746ec7
Fuzzy: a9e92bbe91ffe4c0e853b4778c8ff15a
dHash: 5d6d6171714df878
Image Base 0x00400000
Entry Point 0x004204f7
Compilation Time 2023-04-10 15:22:18
Checksum 0x030046fd (Actual: 0x030046fd)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 18 libraries
Exports 0 functions
Resources 23 Resources
Sections 5 Sections

Version Information

FileVersion 24.12.2
Comments UserDiag
FileDescription UserDiag
ProductName UserDiag
ProductVersion 24.12.2
CompanyName SkyEmie_
LegalCopyright Copyright © since 2020 - All rights reserved
Translation 0x0409 0x04b0
Translation 0x0809 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 633,399 bytes 633,856 bytes 6.67 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 17187DF51446E12491449BC34D849147
.rdata 0x0009c000 195,474 bytes 195,584 bytes 5.69 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8AB1E4A7788882B436D7B30C3A4C9B0C
.data 0x000cc000 28,764 bytes 18,432 bytes 0.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C69381D9330FEC33B92360836B24215A
.rsrc 0x000d4000 49,446,546 bytes 49,446,912 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 02E61E1F9B4DD2D2843D99AB54423B31
.reloc 0x02ffc000 30,156 bytes 30,208 bytes 6.80 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 40B4850993E12FB1B505490E48047C95
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 23 (49,445,261 bytes)
Resource Type Count Total Size Percentage
RT_ICON 10 227,730 bytes
0.5%
RT_STRING 7 20,540 bytes
0%
RT_RCDATA 2 49,194,951 bytes
99.5%
RT_GROUP_ICON 1 146 bytes
0%
RT_VERSION 2 876 bytes
0%
RT_MANIFEST 1 1,018 bytes
0%

Certificate Chain Analysis

Certificate Information
Product UserDiag
Description UserDiag
File Version 24.12.2
Signing Date 12:26 AM 12/15/2024 (174 days ago)
Verification Status Signed
Signers CTRL-F; GlobalSign GCC R45 EV CodeSigning CA 2020; GlobalSign Code Signing Root R45
Counter Signers Globalsign TSA for Advanced - G4 - 202311; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign Root CA - R6
Copyright Copyright © since 2020 - All rights reserved
Certificate Chain Summary
GlobalSign GCC R45 EV CodeSigning CA 2020 #1 Primary
Validity Period: 2020-07-28 00:00:00 → 2030-07-28 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 77 BD 0E 05 B7 59 0B B6 1D 47 61 53 1E 3F 75 ED
CTRL-F #2 Chain
Validity Period: 2021-11-18 12:10:34 → 2025-01-18 14:59:57
Signature Algorithm: sha256RSA
Serial Number: 35 BA C7 BF A5 1C 96 08 01 8A 63 2A
Globalsign TSA for Advanced - G4 - 202311 #3 Chain
Validity Period: 2023-11-02 10:30:02 → 2034-12-04 10:30:02
Signature Algorithm: sha256RSA
Serial Number: 01 19 75 74 71 C9 92 D7 44 DF A5 96 EB B9 70 15
GlobalSign Timestamping CA - SHA384 - G4 #4 Chain
Validity Period: 2018-06-20 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 EC 1C 92 40 DE FD 2E 40 5D 7C 47 74
GlobalSign #5 Chain
Validity Period: 2014-12-10 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 45 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware