Gridinsoft Logo

The oo2reck.exe File Analysis

Technical Analysis

File Name oo2reck.exe
File Type
PE32+ executable (console) x86-64, for MS Windows
Scanner Version 1.0.216.174
Database Version 2025-05-17 22:00:25 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
545,222
File Size (bytes)
2025-05-17
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
379cf69ee5f522783654025815db8501
SHA1
2632b37abb6a91b0fe0dc4218bd26779aa36e676
SHA256
e3b6d931082d9eb9a5e9c66449884bdba44c9e64a63aa52294509a98b20950f6
SHA512
d7c8cdb778c4a2df8b08dd830f6f5cc8c4db044fa8b5f4d6610197389657ab5b75bd15b9071a89a59a26730f6641313242420caba72281b5055bc74d3a1757a8
ImpHash
89aad8fd67620cef566de9a5902b3e54

PE Analysis

Basic Information

Image Base 0x100000000
Entry Point 0x100013e80
Compilation Time 1970-01-01 00:00:00
Checksum 0x00000000 (Actual: 0x00085c56)
OS Version 4.0
PEiD Signatures PE32+ executable (console) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
kernel32, oleaut32, user32
Exports 0 functions
Resources 0 Resources
Sections 11 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 187,360 bytes 187,392 bytes 5.85 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D9CB97A96C291148BFE8B63BE9A4DB57
.data 0x0002f000 7,764 bytes 8,192 bytes 3.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FEE3A4E9CB979AA3FD1B355A4A92FB28
.rdata 0x00031000 60,440 bytes 60,928 bytes 4.17 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D833B0338D13A411680724309ECA883F
.pdata 0x00040000 13,416 bytes 13,824 bytes 5.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 255497A4436F2A5171CA412338C464C3
.bss 0x00044000 19,688 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.CRT 0x00049000 40 bytes 512 bytes 0.06 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F5EB388D5AEB38C63CBB2B1B00C8294C
.idata 0x0004a000 3,373 bytes 3,584 bytes 4.04 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 56EE3F76699F6361B2D84CE84D5688DD
/4 0x0004b000 59,486 bytes 59,904 bytes 5.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ EEC27E0DAC94D6BFD3A2DED7D0857216
/16 0x0005a000 1,288 bytes 1,536 bytes 4.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 8AB3BB615AB25B95F0B9A1C33D07515D
/30 0x0005b000 5,941 bytes 6,144 bytes 4.50 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 3891F1845FE5C2C3913BAC467524C6A9
/42 0x0005d000 3,048 bytes 3,072 bytes 2.49 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D9E977D1802A2F2050C5809F701471E6

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware