reimagerepair.exe

Reimage Repair

Reimage Limited

The application reimagerepair.exe, “Reimage Downloader” by Reimage Limited has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.reimageplus.com and multiple other hosts. While running, it connects to the Internet address vip080.ssl.hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Reimage  (signed by Reimage Limited)

Product:
Reimage Repair

Description:
Reimage Downloader

Version:
1.529

MD5:
068da6555315d417179a0d3c86deaf29

SHA-1:
088590c9abec94f61cfe5d765b717dc3175387bb

SHA-256:
e425e421228148f7dd93d213b43655f47c8d681edc6df310e725d124fda178ee

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
1/17/2022 12:01:40 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
riskware program Program.Unwanted.1470
9.0.1.05190

Reason Heuristics
PUP.Reimage.Installer.Meta (L)
16.6.30.6

File size:
750.4 KB (768,416 bytes)

Product version:
1.529

Copyright:
© Reimage 2016

Trademarks:
Reimage

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\reimagerepair.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/17/2016 2:00:00 AM

Valid to:
8/17/2019 1:59:59 AM

Subject:
CN=Reimage Limited, O=Reimage Limited, L=Dasoupoli, S=Nicosia, C=CY

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
4320101ADF7A07C7405BC4433AE31FFD

File PE Metadata
Compilation timestamp:
2/24/2012 8:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:20gC7z6rFIaNNBX73RT7E9Yzewxnl/NTO0gcCre50ET3cfE/KyZowelOq8wp:B37m5IaNNNbhE0pnlHX0EwfE/Pg8

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file reimagerepair.exe has been seen being distributed by the following 50 URLs.

http://www.reimageplus.com/.../router_land.php?tracking=2-vir&exec=run

http://hwcdn.net/a9w5e5v5/cds/rpl/.../ReimageRepair.exe

http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe

http://zondervirus.nl/.../ReimageRepair

http://winhow.org/.../download

http://programwiki.org/.../download

http://cdnrep.reimage.com/rpq/.../ReimageRepair.exe

http://www.fixfilesnow.com/download

http://downloadreimage.com/download.php

http://winwiki.org/.../downloadit

http://easysoftwareuk.com/.../download

http://www.scanerrors.com/download_portuguese_reimage.php

C:\Users\seyfettin\Downloads\ReimageRepair.exe

http://ox-d.majorgeeks.com/w/.../rc?bi=b947a348-d7ad-4839-aa5a-18a444f42487&ts=1fHJpZD1lZDhlZmEwNS05MzljLTRhMzQtYTI2YS02NDVlYTY3N2YxYTJ8cnQ9MTQ0Njg4NjY4MXxhdWlkPTEyNjg5fGF1bT1ETUlELldFQnxzc2lkPTI0MDF8c2lkPTU1MXxwdWI9MTU4NXxwYz1VU0R8cmFpZD0yN2I3ZmU4Zi0zZTM2LTQ1ZWQtYTNkMi0yMzRlNWJjYTQwNjd8YWlkPTUzNzE2OTEzNXx0PTF8YXM9MzM2eDI4MHxsaWQ9NTM2OTA2MDkzfG9pZD03MzYyNnxwPTIwMDB8cHI9MjAwMHxhdGI9MjAwMHxhZHY9NDU5MXxhYz1VU0R8cG09UFJJQ0lORy5DUE18Ym09QlVZSU5HLk5PTkdVQVJBTlRFRUR8bGM9Mnxsdz0xNDQwfHVyPWpWc0RNeUhER0U

http://ads.reimagenetwork.com/imp7654?a=64221329&ci=17&context=c64271932&size=0x0&rt=lp&SourceID=426876;278184943168319580&r=http://.../rotator?id=abec03d1d4f7d0a3c196931aaba914ed_link&s1=426876&s2=278184943168319580&u=http://.../rotator?id=abec03d1d4f7d0a3c196931aaba914ed_link&s1=426876&s2=278184943168319580

http://cdnrep.reimageplus.com/in/.../ReimageRepair.exe

http://fwerror.reimage.revenuewire.net/.../download?0x80131500

http://winwiki.org/.../downloadreimage

http://cleo.li/.../CLEO4_setup.exe

http://cdnrep.reimage.com/ins/.../ReimageRepair.exe

http://113.171.224.246/.../ReimageRepair.exe

Latest 30 of 111 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to vip080.ssl.hwcdn.net  (205.185.208.80:80)

Remove reimagerepair.exe - Powered by Reason Core Security