registrywizard_setup.exe

RegistryWizard

eSupport.com, Inc

This is a setup and installation application. The file has been seen being downloaded from www.registrywizard.com.
Publisher:
eSupport.com, Inc

Product:
RegistryWizard

Description:
RegistryWizard Setup

Version:
3.2.16.513

MD5:
1a58219e79f282d770f86180d4934ed7

SHA-1:
5e3a384d8472ed787ddc1931d6b3408231dadee4

SHA-256:
c000e2b6d6e89ab47c831cbed0a63ac2b09f19e7592a2c8731d2741fd250cf44

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/11/2025 7:58:45 PM UTC  (today)

File size:
8.2 MB (8,610,344 bytes)

Product version:
3.2.16.513

Copyright:
Copyright © 2015 eSupport.com, Inc · All Rights Reserved

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\registrywizard_setup.exe

File PE Metadata
Compilation timestamp:
7/16/2015 4:24:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:2Uzful6WTJLfCpkf4FgCz6amXPQL842vK46vq7n4C1Rnh6xg0mxhM:2gGl6WNLKpH+CfqQL842i46vy4c6g0mM

Entry address:
0x113BC

Entry point:
8B, D1, 0C, 49, 87, CF, 8D, 3D, D6, 81, D8, 96, 52, EB, 09, 8D, 35, 5F, 09, 64, 33, 85, FA, F3, EB, 05, 28, F1, 0F, BE, FD, 86, E6, 88, DF, E8, 2B, 00, 00, 00, 4D, 15, 6C, 4D, D7, 56, 8D, 05, 12, A0, C7, CF, 8D, 15, E8, C6, A3, D0, 0F, AF, C7, 8D, 0D, 42, BE, 57, DA, 84, CF, 81, EE, A5, C1, 01, 00, 41, 4A, 81, C6, 3C, CA, 00, 00, 8A, FD, FE, C6, 25, 14, 6A, 56, 86, F6, C2, F1, 0F, B7, DD, 41, 33, F0, 32, DE, 5B, 87, C6, F7, C5, 15, DB, BB, 78, 68, 9C, 23, 46, 00, 68, 51, DF, DC, 00, F3, 0B, C2, 81, EA, 26...
 
[+]

Entropy:
7.9937  (probably packed)

Code size:
63.5 KB (65,024 bytes)

The file registrywizard_setup.exe has been seen being distributed by the following URL.

Scan registrywizard_setup.exe - Powered by Reason Core Security