| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2011-Apr-06 21:41:06 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig2(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to Blowfish |
| Suspicious | The PE is possibly packed. | Unusual section name found: mProject |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
407859 bytes of data starting at offset 0xc3c00.
The overlay data has an entropy of 7.98462 and is possibly compressed or encrypted. |
| Safe | VirusTotal score: 0/42 (Scanned on 2012-04-29 20:04:32) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2011-Apr-06 21:41:06 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x40600 |
| SizeOfInitializedData | 0x5c200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00037699 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x42000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xcd000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| urlmon.dll |
CreateURLMoniker
CreateURLMonikerEx |
|---|---|
| VERSION.dll |
GetFileVersionInfoW
GetFileVersionInfoSizeW VerQueryValueA |
| WININET.dll |
InternetCloseHandle
InternetQueryOptionA HttpQueryInfoA InternetReadFileExA InternetOpenA InternetOpenUrlA InternetOpenUrlW InternetConnectA InternetGetLastResponseInfoA FtpGetFileA FtpPutFileA FtpDeleteFileA FtpRenameFileA FtpCreateDirectoryA FtpRemoveDirectoryA FtpSetCurrentDirectoryA FtpGetCurrentDirectoryA InternetFindNextFileA FtpFindFirstFileA |
| RPCRT4.dll |
RpcStringFreeA
UuidCreate UuidToStringA |
| WS2_32.dll |
WSAStartup
WSACleanup gethostbyname |
| KERNEL32.dll |
UnmapViewOfFile
CloseHandle WriteFile GetFileSize MapViewOfFile CreateFileMappingA CreateFileW GetProcAddress LoadLibraryA GetProcessTimes GetCurrentProcess InterlockedDecrement InterlockedIncrement GetModuleFileNameW CreateFileA GetTickCount InitializeCriticalSection FreeLibrary LoadLibraryW GetTempPathA GetTempPathW GetModuleFileNameA GetCommandLineW GlobalFree GetVersionExA GlobalSize DeleteFileA DeleteFileW ReadFile SetCurrentDirectoryW VirtualProtect GetCurrentThreadId MultiByteToWideChar WideCharToMultiByte WaitForSingleObject MoveFileExW VirtualFreeEx WriteProcessMemory VirtualAllocEx OpenProcess HeapAlloc GetProcessHeap VirtualAlloc VirtualFree GlobalAlloc HeapFree GetFileAttributesA GetFileAttributesW GetFileAttributesExA GetFileAttributesExW SetFileTime GetFileTime GetSystemTime SetLastError CreateDirectoryA CreateDirectoryW CopyFileA CopyFileW MoveFileA MoveFileW SetFilePointer RemoveDirectoryA RemoveDirectoryW FindClose FindNextFileA FindFirstFileA FindNextFileW FindFirstFileW GetComputerNameA GetComputerNameW GetSystemDirectoryA GetSystemDirectoryW GetWindowsDirectoryA GetWindowsDirectoryW GetEnvironmentVariableA GetEnvironmentVariableW SetEnvironmentVariableA SetEnvironmentVariableW WritePrivateProfileStringA GetShortPathNameA Process32NextW Process32FirstW CreateToolhelp32Snapshot GlobalLock GlobalUnlock Sleep EnterCriticalSection CreateThread LeaveCriticalSection CopyFileExW GetLastError SystemTimeToFileTime FileTimeToSystemTime HeapSize LCMapStringA LCMapStringW GetStdHandle RtlUnwind HeapReAlloc GetModuleHandleA UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA SetHandleCount GetFileType GetStartupInfoA SetUnhandledExceptionFilter IsBadCodePtr GetStringTypeA GetStringTypeW QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime SetStdHandle FlushFileBuffers GetLocaleInfoA GetCPInfo GetSystemInfo VirtualQuery InterlockedExchange GetStartupInfoW ExitProcess TerminateProcess HeapDestroy HeapCreate IsBadWritePtr GetACP GetOEMCP IsBadReadPtr SetEndOfFile |
| USER32.dll |
GetUserObjectInformationA
OpenDesktopA SetThreadDesktop IsZoomed LoadImageA GetClipboardData OpenClipboard EmptyClipboard SetClipboardData CloseClipboard LoadAcceleratorsA GetMessageA TranslateAcceleratorA TranslateMessage DispatchMessageA PostThreadMessageA LoadIconA LoadCursorA RegisterClassExA GetFocus SetFocus GetCursorPos ClientToScreen ReleaseCapture GetThreadDesktop EndPaint SetCapture GetWindowThreadProcessId PostMessageA DefWindowProcA GetDC UpdateLayeredWindow ReleaseDC PtInRect IsWindowUnicode UpdateWindow MessageBoxA FlashWindowEx CreatePopupMenu CreateWindowExA SetForegroundWindow TrackPopupMenu DestroyWindow DestroyMenu GetMenuItemCount InsertMenuW DestroyIcon SetWindowTextA GetWindowTextW GetWindowTextA IntersectRect CloseDesktop ChangeDisplaySettingsA EnumDisplaySettingsW ChangeDisplaySettingsW MessageBoxW GetWindow GetSysColor FindWindowW BeginPaint LoadImageW InvalidateRect KillTimer SetTimer PostQuitMessage SetWindowLongA SetLayeredWindowAttributes GetWindowRect GetWindowLongA AdjustWindowRectEx ShowWindow SystemParametersInfoA GetSystemMetrics GetClientRect SetWindowPos RedrawWindow IsWindow SendMessageA IsIconic IsWindowVisible GetDesktopWindow CreateWindowExW SetWindowTextW |
| GDI32.dll |
GetTextExtentPoint32W
PatBlt GetTextColor CreateDIBSection DeleteObject GetRgnBox CombineRgn CreateRectRgnIndirect GetTextMetricsA GetClipRgn OffsetRgn ExtTextOutW GetCurrentObject GetObjectA GetCurrentPositionEx GetClipBox CreateCompatibleDC SelectObject DeleteDC CreateSolidBrush SelectClipRgn CreateRectRgn GetBkColor |
| comdlg32.dll |
GetSaveFileNameA
GetOpenFileNameW GetSaveFileNameW ChooseColorA GetOpenFileNameA |
| ADVAPI32.dll |
RegDeleteValueA
GetUserNameW GetUserNameA RegSetValueExW RegCloseKey RegSetValueExA RegOpenKeyExA RegQueryValueExA RegCreateKeyExA RegCreateKeyExW RegDeleteKeyA RegDeleteKeyW RegOpenKeyExW RegDeleteValueW RegQueryValueExW RegEnumKeyA RegEnumKeyW RegEnumValueA RegEnumValueW RegQueryInfoKeyA RegQueryInfoKeyW |
| SHELL32.dll |
SHFileOperationW
SHFileOperationA SHChangeNotify Shell_NotifyIconW ShellExecuteW SHGetSpecialFolderLocation SHGetPathFromIDListW SHGetPathFromIDListA DragQueryFileW DragQueryFileA ShellExecuteA |
| ole32.dll |
RevokeDragDrop
RegisterDragDrop ReleaseStgMedium CreateStreamOnHGlobal CoCreateInstance OleUninitialize OleInitialize CoGetMalloc CoUninitialize CoInitialize CoTaskMemAlloc OleSetContainedObject OleCreate CLSIDFromProgID CLSIDFromString CoTaskMemFree |
| OLEAUT32.dll |
VariantInit
LoadTypeLibEx VariantChangeType SafeArrayGetDim SafeArrayGetLBound SafeArrayGetUBound SafeArrayGetElement DispInvoke VariantClear SysStringLen QueryPathOfRegTypeLib SysAllocStringLen SysReAllocStringLen SystemTimeToVariantTime VariantTimeToSystemTime SysAllocString SysFreeString SysReAllocString |
| Ordinal | 1 |
|---|---|
| Address | 0x7f3b8 |
| Ordinal | 2 |
|---|---|
| Address | 0x7f8e8 |
| Ordinal | 3 |
|---|---|
| Address | 0x7fea8 |
| Ordinal | 4 |
|---|---|
| Address | 0x7fa28 |
| Ordinal | 5 |
|---|---|
| Address | 0x80240 |
| Ordinal | 6 |
|---|---|
| Address | 0x80470 |
| Ordinal | 7 |
|---|---|
| Address | 0x805f0 |
| Ordinal | 8 |
|---|---|
| Address | 0x80d20 |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x481444 |
| SEHandlerTable | 0x453100 |
| SEHandlerCount | 185 |
| XOR Key | 0x9057d7c6 |
|---|---|
| Unmarked objects | 0 |
| 105 (2067) | 5 |
| ASM objects (VS2003 (.NET) build 3077) | 22 |
| 37 (8755) | 2 |
| C objects (9178) | 12 |
| Imports (2067) | 2 |
| Imports (2179) | 16 |
| Imports (9210) | 7 |
| Total imports | 341 |
| C objects (VS2003 (.NET) build 3077) | 137 |
| C++ objects (VS2003 (.NET) build 3077) | 72 |
| Exports (VS2003 (.NET) build 3077) | 1 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.