RestoreDefaultServices.exe

RestoreDefaultServices.exe

Geek Squad, Inc

Publisher:
Geek Squad  (signed by Geek Squad, Inc)

Product:
RestoreDefaultServices.exe

Description:
Restore Default XP/Vista/7/8/8.1/10 Services

Version:
5.10.3.2500

MD5:
9c88f8797661b712a27e9c461d7c3a71

SHA-1:
e0b2cc6f46fdecf9c08333d6c1924f9d06ae2d80

SHA-256:
e39d0919511bcba08550c25a68e9cf4f38977da54616c3e7ac2aeb0e8a2af2d8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/25/2025 1:12:48 PM UTC  (today)

File size:
5.8 MB (6,048,488 bytes)

Product version:
5.10.3.2500

Copyright:
Confidential Trade Secret of ©2011-2016 Best Buy Enterprise Services, Inc. For internal use only.

Original file name:
RestoreDefaultServices.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\restoredefaultservices.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
7/10/2016 7:00:00 PM

Valid to:
11/12/2018 5:59:59 PM

Subject:
CN="Geek Squad, Inc", O="Geek Squad, Inc", L=Richfield, S=Minnesota, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
56F79C9CD393268C4E0C2FCA340B20A4

File PE Metadata
Compilation timestamp:
8/20/2016 12:23:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
98304:0I6BYwGKFngwIUFtFHRrBR2zydvjjxaBkAiVU2eQQsb1MxxoTJn6U40IBDUsPEN/:YFgsR2+Vs7gpMAM0oEYi

Entry address:
0x19F30

Entry point:
B8, C8, B6, 9E, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 0E, 27, 7C, A4, 9A, 53, 84, 23, 9E, 60, D2, 88, 4C, 27, E3, 46, 2F, F1, B9, 85, 81, 85, 0E, 92, 1A, 95, AE, 80, D9, 22, 71, EB, 91, 70, 31, 5B, 6E, E9, E8, 96, 1A, C0, 2F, 4D, 0E, 9A, 03, CB, 4D, F7, AE, 3C, FA, 3F, 4F, 31, 64, 61, 40, 12, DE, 90, 1F, 3A, 99, 60, A0, 45, 74, 21, A1, 02, CD, 9E, A6, 76, C8, FB, C1, BC, A6, 0C, F4, CC, E5, B0, 70, 3E, 5B, 50, 7C, CA, C2...
 
[+]

Entropy:
7.9999

Packer / compiler:
PECompact v2

Code size:
188 KB (192,512 bytes)

Scan RestoreDefaultServices.exe - Powered by Reason Core Security