PartitionWizard.exe

MiniTool Partition Wizard

MiniTool Solution Ltd

The executable PartitionWizard.exe has been detected as malware by 10 anti-virus scanners.
Publisher:
MiniTool Solution Ltd.  (signed by MiniTool Solution Ltd)

Product:
MiniTool Partition Wizard

Version:
7, 6, 0, 1

MD5:
d63213d9af1bd385ca51accdcc6d1472

SHA-1:
a9a0e3623ab6b7b785ee275663a3bca379d629c8

SHA-256:
2836fdcd88ec0c2f720494ba7cd0980362056a263ea62c7b803c970d6f314756

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
4/25/2024 8:47:44 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Vitro
160118-1

AVG
Win32/Virut
2015.0.4477

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
10.0.0.5366

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Madangel.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.3536.0

Norman
Win32.Virtob.Gen.12
11.01.2016 17:30:26

VIPRE Antivirus
Threat.4737366
46660

File size:
4.7 MB (4,881,920 bytes)

Product version:
7, 6, 0, 1

Copyright:
Copyright (C) 2009 - 2012 MiniTool Solution Ltd. All rights reserved.

Original file name:
PartitionWizard.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\partitionwizard\partitionwizard.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
5/22/2012 1:18:09 AM

Valid to:
5/23/2015 1:18:09 AM

Subject:
E=support@minitool.ca, CN=MiniTool Solution Ltd, O=MiniTool Solution Ltd, L=SURREY, S=British Columbia, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121CB5D7302C7544C0407CB59FFDE7FB180

File PE Metadata
Compilation timestamp:
2/27/2001 1:05:37 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:BkqPeDf26syNMRfCE7RXuJqOgplWgjCemXtB/4b/8b/upgvZivyDJ:BdmDf26syNMRf77RXUqO3JemXYg

Entry address:
0x4AA92F

Entry point:
8B, C0, 83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 7D, FE, FF, FF, 4B, F7, D0, 66, 4B, 75, FC, 08, C6, 8A, F4, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 0F, 83, E5, FF, FF, FF, 81, D9, E6, 13, 00, 00, 8D, 71, 9D, 8B, D5, 71, D8, 01, E8, 97, 40, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, C1, FE, CA, 84, D2, 68, 75, 67, B5, 5F, E8, 08, FD, FF, FF, 89, 74, 24, 44, E8, 1B, FF, FF, FF, 89, 44, 24, 34, 87, C9, 83, E8, 04, 0F, 82, D6, FD, FF, FF, 80, DD, A4, 64, A1, 18...
 
[+]

Entropy:
5.2390

Code size:
1.2 MB (1,295,360 bytes)

Remove PartitionWizard.exe - Powered by Reason Core Security