WinFixPro.exe

WinFix Pro

IMALI - N.I. MEDIA TD

The application WinFixPro.exe, “WinFix Downloader” by IMALI - N.I. MEDIA TD has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program WinFix Pro by IMALI - N.I. MEDIA TD which is a potentially unwanted software program. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdnrep.winfixprofessionals.com and multiple other hosts.
Publisher:
WinFix®  (signed by IMALI - N.I. MEDIA TD)

Product:
WinFix Pro

Description:
WinFix Downloader

Version:
1.509

MD5:
d399c9eb0c54a1423ae859dac42602b6

SHA-1:
d125acdda7b2646b13a8b66a3da58ef15cad688c

SHA-256:
81240f541a44b287aa9ec1d0b8ed4f829efe74e9720823083bcea3cdcc635b66

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/24/2024 11:13:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.IMALINIMEDIATD
15.2.22.2

File size:
767.4 KB (785,840 bytes)

Product version:
1.509

Copyright:
© WinFix 2014

Trademarks:
WinFix

Original file name:
WinFixPro.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\winfixpro.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
12/13/2014 7:00:00 PM

Valid to:
12/16/2015 7:00:00 AM

Subject:
CN=IMALI - N.I. MEDIA TD, O=IMALI - N.I. MEDIA TD, L=tel aviv, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
017B4EC01F594ADE73E421BB2CDD9FE2

File PE Metadata
Compilation timestamp:
2/24/2012 2:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Y0g3Mpnsy73RTnE9Yzewxnl9+pVeTTO0gcCre50ET3cfE/KybyAfKVQiowelOq8t:jUMiybNE0pnl5pX0EwfE/HfK1g8t

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Entropy:
7.9090

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file WinFixPro.exe has been discovered within the following programs.

WinFix Pro  by IMALI - N.I. MEDIA TD
Publisher's description - “During repair, WinFix not only removes damage, but also reverses the damage done to your Windows OS by replacing corrupted and deleted files with fresh Windows files and components from our continuously updated online database.”
www.winfixprofessionals.com
About 58% of users remove it
 
Powered by Should I Remove It?

The file WinFixPro.exe has been seen being distributed by the following 2 URLs.

Remove WinFixPro.exe - Powered by Reason Core Security