ReimageRepair.exe

Reimage Repair

Reimage Limited

The application ReimageRepair.exe, “Reimage Downloader” by Reimage Limited has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from cdnrep.reimage.com and multiple other hosts.
Publisher:
Reimage®  (signed by Reimage Limited)

Product:
Reimage Repair

Description:
Reimage Downloader

Version:
1.273

MD5:
17a515f253acf6c461fe4fc3f8f0fc00

SHA-1:
6695af83a5fa9289bf8b73a6f14bf9f6de3cbc40

SHA-256:
95be011abbda0483652f2e0f7039d066022476ff6f72811653a71dd7925ea225

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/25/2024 8:48:04 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod547.Trojan
1.3.0.4613

Dr.Web
Adware.Plugin.171
9.0.1.0108

ESET NOD32
Win32/Toolbar.Babylon
8.9482

McAfee
Artemis!D566201EF927
5600.7156

NANO AntiVirus
Riskware.Nsis.Babylon.cvvuwk
0.28.0.59048

nProtect
Joke/W32.ArchSMS.286720
13.05.03.04

Reason Heuristics
PUP.Optional.ReimageLimited.N
14.9.12.17

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.14416

Trend Micro House Call
TROJ_GEN.F47V0122
7.2.108

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
743.3 KB (761,160 bytes)

Product version:
1.273

Copyright:
© Reimage 2013

Original file name:
ReimageRepair.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\reimagerepair.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/10/2012 5:00:00 PM

Valid to:
5/3/2014 4:59:59 PM

Subject:
CN=Reimage Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Reimage Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
08242D065B8CE1035215AAA943CF9166

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:suoJxo5saxVF+ZPPfnEUnsEWfXsbKZp0xBFZO0gcCre50ET3cfE/KyDYfmIWgeVb:sXfaYlvANcNJX0EwfE/pYfH2V

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9518

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ReimageRepair.exe has been seen being distributed by the following 2 URLs.

Remove ReimageRepair.exe - Powered by Reason Core Security