fixregistry.exe

Fix My Registry

Smart PC Solutions, Inc.

The application fixregistry.exe, “Fix My Registry software keeps Windows Registry of your PC i” by Smart PC Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from smartpctools.com and multiple other hosts.
Publisher:
Smart PC Solutions   (signed by Smart PC Solutions, Inc.)

Product:
Fix My Registry

Description:
Fix My Registry software keeps Windows Registry of your PC i

Version:
3.0

MD5:
33f193ca987a0a5eeb6300d2661c12a7

SHA-1:
65762cd1a24608ba042c38f7ae1bb75a3e12ff89

SHA-256:
12d234e354929663e9e584a390eb602d952bdc7cb04331bd54c942c21513579e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 6:49:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.SmartPCSolutions.L
14.6.10.14

File size:
2.3 MB (2,463,112 bytes)

Product version:
3.0

Copyright:
Smart PC Solutions

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\fixregistry.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/5/2011 2:00:00 AM

Valid to:
5/30/2014 1:59:59 AM

Subject:
CN="Smart PC Solutions, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Smart PC Solutions, Inc.", L=Alexandria, S=Virginia, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
502E76B6ACDCDE4F3336BF9286946063

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:faqH7NmBOj7U8Px9B53UgQLs0FTpwUlv4pj540AcJ7jJinXBgU:iqm0EAvLUgQLDFaUlApj5lAcJHARgU

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file fixregistry.exe has been seen being distributed by the following 3 URLs.

Remove fixregistry.exe - Powered by Reason Core Security