Gridinsoft Logo
File Icon

Rutview.exe Trojan Packed Analysis

Technical Analysis

File Name rutview.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.168.174
Database Version 2024-03-06 22:00:32 UTC

Trojan.Win32.Packed.sa

Malware family: Packed

Packed malware uses compression, encryption, or obfuscation techniques to alter code appearance and evade security detection. These methods modify the original malware structure to bypass signature-based detection systems and complicate analysis efforts.
N/A
Detection Rate
16,765,952
File Size (bytes)
2024-03-06
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c9213bd4e369a0e559c652efe1dc312d
SHA1
0f8c8b2c3a9c9bb1e2ae25ce3b9238f338e7886c
SHA256
e1f0e87a42b84c6b0be06da4026cb032903e91581b4c74357c920e0d9b38b10b
SHA512
ecfd9275b4a2859aeb0d8135e60dcd0625e4892d0c653ec02a050f20c9d07bb91b55e9d994b1d68cf4bf501fb3386e12d922b3f960ba40f730ac4ec2f2cc12ac
ImpHash
423f3efee1169ac4aebe20d014404557

PE Analysis

Basic Information

Icon
Hash: f6aa33ddfb9cb0bc81bae775e481fee8
Fuzzy: 0891e4a24a9b5015c6a894f642d9d247
dHash: c0dacabacac0c244
Image Base 0x00400000
Entry Point 0x01b049eb
Compilation Time 2023-10-23 19:49:59
Checksum 0x00ffe46e (Actual: 0x00ffe46e)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 26 libraries
Exports 3 functions
Resources 743 Resources
Sections 14 Sections

Version Information

CompanyName Remote Utilities Pty (Cy) Ltd.
FileDescription Remote Utilities - Viewer
FileVersion 7.2.2.0
LegalCopyright Copyright © 2023 Remote Utilities Pty (Cy) Ltd. All rights reserved.
LegalTrademarks Remote Utilities
ProductName Remote Utilities
ProductVersion 7.2.2.0
ProgramID com.remoteutilities.rutview
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 21,260,088 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.itext 0x01448000 42,852 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x01453000 211,768 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.bss 0x01487000 707,212 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x01534000 45,074 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.didata 0x01540000 31,404 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.edata 0x01548000 138 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.tls 0x01549000 1,640 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x0154a000 93 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.E~B 0x0154b000 1,750,575 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.o(K 0x016f7000 8,304 bytes 8,704 bytes 5.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6262F4EEB82483C6002C4CF3B7185A64
.,M* 0x016fa000 15,982,224 bytes 15,982,592 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 5725ABDDCBBC8D59B64A82ACE8EB2D7B
.reloc 0x02638000 1,504 bytes 1,536 bytes 4.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ ECB14E837C3A2BFA5F98740C58FE89A9
.rsrc 0x02639000 11,804,576 bytes 772,096 bytes 4.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5F57C2412DF874B9626808EFB567DFC4
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 743 (11,751,789 bytes)
Resource Type Count Total Size Percentage
AVI 8 132,096 bytes
1.1%
DXSKINS 2 3,811 bytes
0%
MAD 2 1,733,480 bytes
14.8%
PNG 30 140,574 bytes
1.2%
RT_RCDATA 195 7,174,355 bytes
61%
SVG 47 40,739 bytes
0.3%
UNICODEDATA 6 191,535 bytes
1.6%
WAVE 1 77,914 bytes
0.7%
RT_CURSOR 121 1,074,052 bytes
9.1%
RT_BITMAP 116 327,848 bytes
2.8%
RT_ICON 14 716,336 bytes
6.1%
RT_DIALOG 2 164 bytes
0%
RT_STRING 144 133,964 bytes
1.1%
RT_GROUP_CURSOR 50 1,994 bytes
0%
RT_GROUP_ICON 3 214 bytes
0%
RT_VERSION 1 912 bytes
0%
RT_MANIFEST 1 1,801 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Packed.sa Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Packed.sa without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware