romedicxp.exe

RoMedic

This is a setup program which is used to install the application. The file has been seen being downloaded from download1721.mediafire.com and multiple other hosts.
Product:
RoMedic

Version:
1.0.0.0

MD5:
f6a28f9d682fc8ef96349147e907c3c3

SHA-1:
eb22a660b40ab6ca588275f5b371f04022e1524c

SHA-256:
b3afdc9c2892fde404c3a2d5ae613fcff3ec8af2529c7d418b32865b01b100b5

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/18/2024 11:41:49 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6379

File size:
6.4 MB (6,714,880 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2009

Original file name:
RoMedic.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\extras\ragnarok\nova pasta\puff\romedicxp.exe

File PE Metadata
Compilation timestamp:
1/27/2011 4:18:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
98304:IQoFxYUEX/vZBz69ni3JVbJhgMd/YYeDkr1q90ZEZc/RXmZ9wzqQg1k:1ojYN/vZQQJVdCMJTr187ERXy2zqQge

Entry address:
0x117CC

Entry point:
FF, 25, BC, 17, 41, 00, 00, 00, 5F, 43, 6F, 72, 45, 78, 65, 4D, 61, 69, 6E, 00, 6D, 73, 63, 6F, 72, 65, 65, 2E, 64, 6C, 6C, 00, B4, 4B, 00, 00, 7B, 7A, 7D, 02, D2, C7, BA, 97, DC, 39, D3, C1, B7, 59, B5, AF, F4, FE, FF, D8, 41, 3E, B1, 97, 85, 80, 39, 5E, 61, BD, 1A, D1, 51, 00, BB, 59, D0, 33, FD, EE, 18, 73, 1C, 48, AB, 71, 3E, 7B, 31, 3C, DC, 9D, 76, FF, 4B, B4, E3, 72, D9, 78, E7, B2, 53, 4B, E9, F4, 35, 56, 00, 87, E1, A7, 3B, 68, 2E, 09, D5, B4, DB, BB, FB, A2, FC, B8, BE, D3, 38, 2E, 90, ED, 3C, A7...
 
[+]

Code size:
6.4 MB (6,686,720 bytes)

The file romedicxp.exe has been seen being distributed by the following 2 URLs.

http://download1721.mediafire.com/vuq32d5obzfg/.../RoMedicXP.exe

Scan romedicxp.exe - Powered by Reason Core Security