reimagerepair.exe

The application reimagerepair.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from cdnrep.reimage.com.
MD5:
983242adede2d6542781c0c9ffcc3db7

SHA-1:
757a8a0769727ab2da3bc3e2eeb4be5752747f5f

SHA-256:
3a6ae68ce98d6a15e645f7968d967be2e9af0fe4aeb4bd328dfe5251f6af76fc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 2:41:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Reimage (L)
16.8.3.20

File size:
822.4 KB (842,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\reimagerepair.exe

File PE Metadata
Compilation timestamp:
2/25/2012 2:20:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:QCd4zl2ONo7m5IaNNNbhE0pnlHX0EwfE/Pg8:Fd4znNgLINNlE0pnlHX0tF8

Entry address:
0x38AF

Entry point:
B7, 8C, 0F, B7, F8, 69, F2, 12, 8C, DF, B4, FE, C0, C7, C2, 6B, 57, A8, B6, E8, 2D, 00, 00, 00, 8A, D0, 0F, CB, C7, C2, BD, 09, 95, 69, 8D, 35, E7, 80, 00, 00, F6, C0, 91, 81, F6, 0B, 0F, 00, 00, FE, C7, 8D, 2E, 78, 05, B9, B4, A2, A7, C6, 81, ED, 01, 06, 00, 00, 33, C5, 4B, 88, F7, 0F, C8, 81, F2, 7E, 71, 00, 00, 84, D0, 5A, FE, C3, 32, C9, 33, E8, 0F, AF, C3, 0F, 6E, E2, 02, F7, 23, C7, 81, F9, 45, 80, 00, 00, 75, 02, 86, FE, 8D, 15, 49, D8, FF, FF, 81, EA, BD, 38, 00, 00, 52, 5E, EB, 05, BA, 9D, B4, C2...
 
[+]

Entropy:
7.9237  (probably packed)

Code size:
29 KB (29,696 bytes)

The file reimagerepair.exe has been seen being distributed by the following URL.

Remove reimagerepair.exe - Powered by Reason Core Security