| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Jan-29 22:29:32 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
ytdesktop.pdb
|
| CompanyName | ytdesktop |
| FileDescription | YouTube Desktop |
| FileVersion | 1.0.0 |
| ProductName | YouTube Desktop |
| ProductVersion | 1.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-06-08 01:10:28) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Jan-29 22:29:32 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x35d600 |
| SizeOfInitializedData | 0x13f600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000034122C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x4a2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| bcryptprimitives.dll |
ProcessPrng
|
|---|---|
| ntdll.dll |
NtOpenFile
NtReadFile RtlGetVersion RtlNtStatusToDosError NtCreateNamedPipeFile NtWriteFile |
| kernel32.dll |
IsProcessorFeaturePresent
RtlLookupFunctionEntry WaitForSingleObjectEx GetCurrentProcess GetCurrentProcessId ReleaseMutex WaitForSingleObject HeapAlloc IsDebuggerPresent GetModuleFileNameW SleepEx SetWaitableTimer ExitProcess CompareStringOrdinal GetSystemDirectoryW GetWindowsDirectoryW DuplicateHandle GetSystemTimeAsFileTime SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive SwitchToThread GetProcessHeap HeapFree TerminateProcess GetCurrentThreadId GetModuleHandleW Sleep GetProcAddress LoadLibraryA CloseHandle RtlPcToFileHeader LCIDToLocaleName HeapReAlloc GlobalLock GlobalSize WideCharToMultiByte GlobalUnlock SetLastError GetLastError SetThreadStackGuarantee GetCurrentThread RaiseException GlobalAlloc MultiByteToWideChar GlobalFree lstrlenW GetSystemTimePreciseAsFileTime FormatMessageW EncodePointer GetFinalPathNameByHandleW GetFileAttributesW GetFileType GetTempPathW SetFileInformationByHandle GetFileInformationByHandleEx TlsAlloc GetFileInformationByHandle GetFullPathNameW WriteConsoleW GetConsoleOutputCP GetConsoleScreenBufferInfo SetConsoleTextAttribute SetConsoleMode GetConsoleMode GetStdHandle FindFirstFileExW FindClose FindNextFileW LoadLibraryW TlsGetValue TlsSetValue GetSystemInfo FreeLibrary LoadLibraryExW TlsFree OutputDebugStringW OutputDebugStringA GetUserDefaultUILanguage GetModuleHandleA LoadLibraryExA |
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmGetWindowAttribute DwmSetWindowAttribute |
| oleaut32.dll |
SysStringLen
SetErrorInfo GetErrorInfo SysFreeString |
| api-ms-win-core-synch-l1-2-0.dll |
WakeByAddressAll
WakeByAddressSingle WaitOnAddress |
| user32.dll |
FlashWindowEx
CloseTouchInputHandle GetWindowDC IsWindow IsWindowEnabled IsIconic IsWindowVisible EnableWindow GetWindowRect MapWindowPoints GetClientRect GetMenuBarInfo PostQuitMessage ShowWindow SystemParametersInfoA GetActiveWindow SetMenu RemoveMenu CreateIcon SetMenuItemInfoW DrawMenuBar CreatePopupMenu CreateMenu CreateAcceleratorTableW DestroyAcceleratorTable DestroyIcon DestroyMenu SetPropW GetKeyboardState SetWindowTextW GetWindowTextW DrawTextW GetForegroundWindow CloseClipboard GetWindowTextLengthW RegisterClipboardFormatW SetWindowDisplayAffinity OpenClipboard MonitorFromRect OffsetRect LoadCursorW TrackMouseEvent FindWindowExW ToUnicodeEx SetClipboardData MapVirtualKeyExW GetKeyboardLayout SetCursor GetSystemMetrics EmptyClipboard GetClipCursor ShowCursor SystemParametersInfoW SetCursorPos GetClipboardData SetCapture TranslateAcceleratorW GetMenuItemInfoW SetWindowLongW SendMessageW SetWindowRgn InvalidateRect UpdateWindow DestroyWindow EnumChildWindows GetSystemMenu GetMonitorInfoW DispatchMessageA GetMessageA SetWindowPos RegisterClassExW SetParent SetFocus MapVirtualKeyW GetUpdateRect ValidateRect GetWindowPlacement GetRawInputData MsgWaitForMultipleObjectsEx DispatchMessageW TranslateMessage PeekMessageW PostThreadMessageW PostMessageW GetWindowLongPtrW SetWindowPlacement RedrawWindow AdjustWindowRect EnumDisplayMonitors MonitorFromPoint ChangeDisplaySettingsExW GetMessageW SetWindowLongPtrW CreateWindowExW RegisterRawInputDevices AdjustWindowRectEx GetAsyncKeyState GetMenu GetWindowLongW InvalidateRgn ReleaseCapture GetWindow GetKeyState GetParent DefWindowProcW RegisterWindowMessageA FillRect GetTouchInputInfo ReleaseDC IsProcessDPIAware MonitorFromWindow TrackPopupMenu SetForegroundWindow ClientToScreen GetCursorPos EnableMenuItem DrawIconEx ScreenToClient GetDC AppendMenuW InsertMenuW SendInput CheckMenuItem IsClipboardFormatAvailable ClipCursor RegisterTouchWindow |
| comctl32.dll |
RemoveWindowSubclass
TaskDialogIndirect DefSubclassProc SetWindowSubclass |
| ole32.dll |
RegisterDragDrop
CoTaskMemAlloc CoUninitialize RevokeDragDrop CoCreateFreeThreadedMarshaler CoInitializeEx CoCreateInstance CoTaskMemFree OleInitialize |
| shlwapi.dll |
SHCreateMemStream
|
| gdi32.dll |
SelectObject
CombineRgn DeleteDC CreateDIBSection SetBkMode SetTextColor CreateRectRgn CreateSolidBrush DeleteObject BitBlt CreateCompatibleDC GetDeviceCaps |
| shell32.dll |
DragFinish
DragQueryFileW SHAppBarMessage ShellExecuteW SHGetKnownFolderPath |
| KERNEL32.dll |
SetEnvironmentVariableW
GetCommandLineW AddVectoredExceptionHandler RtlCaptureContext InitializeSListHead RtlVirtualUnwind GetCurrentDirectoryW CreateMutexA UnhandledExceptionFilter CreateDirectoryW CreateFileW QueryPerformanceFrequency CreateThread WriteFileEx ReadFileEx QueryPerformanceCounter CreateWaitableTimerExW CreateProcessW GetEnvironmentStringsW FreeEnvironmentStringsW SetUnhandledExceptionFilter RtlUnwindEx DeleteCriticalSection GetEnvironmentVariableW InitializeCriticalSectionAndSpinCount |
| ADVAPI32.dll |
RegOpenKeyExW
EventUnregister EventWriteTransfer EventSetInformation EventRegister RevertToSelf ImpersonateAnonymousToken RegQueryValueExW RegCloseKey RegGetValueW |
| api-ms-win-crt-string-l1-1-0.dll |
strcpy_s
wcslen strlen wcsncmp _wcsicmp wcscmp strcmp |
| api-ms-win-crt-runtime-l1-1-0.dll |
_get_initial_narrow_environment
strerror _set_app_type _cexit _c_exit _register_thread_local_exe_atexit_callback _initialize_narrow_environment __p___argv _initterm _configure_narrow_argv _initialize_onexit_table _register_onexit_function _crt_atexit terminate _initterm_e exit _exit abort _seh_filter_exe __p___argc |
| api-ms-win-crt-math-l1-1-0.dll |
floor
roundf __setusermatherr pow trunc round |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
_ultow_s _wtoi |
| api-ms-win-crt-stdio-l1-1-0.dll |
_set_fmode
__p__commode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-heap-l1-1-0.dll |
_callnewh
malloc free _set_new_mode calloc |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | ytdesktop |
| FileDescription | YouTube Desktop |
| FileVersion (#2) | 1.0.0 |
| ProductName | YouTube Desktop |
| ProductVersion (#2) | 1.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-29 22:29:32 |
| Version | 0.0 |
| SizeofData | 38 |
| AddressOfRawData | 0x474874 |
| PointerToRawData | 0x473274 |
| Referenced File | ytdesktop.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-29 22:29:32 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x47489c |
| PointerToRawData | 0x47329c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Jan-29 22:29:32 |
| Version | 0.0 |
| SizeofData | 1068 |
| AddressOfRawData | 0x4748b0 |
| PointerToRawData | 0x4732b0 |
| StartAddressOfRawData | 0x140474d28 |
|---|---|
| EndAddressOfRawData | 0x140474ed4 |
| AddressOfIndex | 0x140484bbc |
| AddressOfCallbacks | 0x14035fba8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001402A1870
|
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1404826c0 |
| XOR Key | 0xe78d4061 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 9 |
| C objects (35207) | 13 |
| C++ objects (35207) | 47 |
| Imports (33145) | 5 |
| Total imports | 347 |
| Unmarked objects (#2) | 44 |
| Resource objects (35222) | 1 |
| Linker (35222) | 1 |
No comments yet.