Gridinsoft Logo

The wowreg32.exe (SetupAPI 64-bit Surrogate) File Analysis

Technical Analysis

File Name wowreg32.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.214.174
Database Version 2025-04-18 19:00:20 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
17,920
File Size (bytes)
2025-04-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0007386fe430341fe6c6edc6cc48542f
SHA1
c31402f33b4a4e2bf15bfb823440eedd2f8c1705
SHA256
e2a4237c8384e3b55edca7274bf53d4ea89e62aa70cc858e2b2c7509f2e51814
SHA512
d87da0b8c2502fd5455f9f18c4d530c6e78a74f9a5e9ba75b265947963b0ca74bc582e570e82e5b08eb844fe0c31a89e1ee40c50e73ccfd153879512d42cf188
ImpHash
9e395710d74bf587fac4f5ca37bf2548

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140002130
Compilation Time 2068-03-21 17:07:19
Checksum 0x000131e7 (Actual: 0x000131e7)
OS Version 10.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
PDB Path wowreg32.pdb
Digital Signature No valid SignedData structure was found.
Imports 7 libraries
KERNEL32, msvcrt, ntdll, ole32, SETUPAPI, SHELL32, USER32
Exports 0 functions
Resources 3 Resources
Sections 6 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription SetupAPI 64-bit Surrogate
FileVersion 10.0.19041.3636 (WinBuild.160101.0800)
InternalName WOWREG32.EXE
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WOWREG32.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.3636
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,368 bytes 6,656 bytes 5.78 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 27CF637A3D65CC710B4C443126E17290
.rdata 0x00003000 6,426 bytes 6,656 bytes 4.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7401726B56BAAA52E6A29F5137F19FC1
.data 0x00005000 1,688 bytes 512 bytes 0.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FAAEF9CD90101840434E88223AAA01C4
.pdata 0x00006000 372 bytes 512 bytes 2.99 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1D32208EA8B9C427C05E84F31BC2B380
.rsrc 0x00007000 2,016 bytes 2,048 bytes 4.33 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E58EC9F0F2481C7883FD83AA3B4CB682
.reloc 0x00008000 32 bytes 512 bytes 0.45 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 749F47383F20C407B899C55505F9683F

Resource Analysis

Total Resources: 3 (1,773 bytes)
Resource Type Count Total Size Percentage
MUI 1 200 bytes
11.3%
RT_VERSION 1 936 bytes
52.8%
RT_MANIFEST 1 637 bytes
35.9%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description SetupAPI 64-bit Surrogate
File Version 10.0.19041.3636 (WinBuild.160101.0800)
Original Name WOWREG32.EXE
Internal Name WOWREG32.EXE
Copyright © Microsoft Corporation. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware