| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Apr-09 19:40:44 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Disk Diagnostic User Resolver |
| FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
| InternalName | DFDWiz.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | DFDWiz.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 6.1.7600.16385 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | PEiD Signature: | UPolyX V0.1 -> Delikon |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 1 bytes of data starting at offset 0x24027. |
| Info | The PE is digitally signed. |
Signer: 4mb5gWTlIemu0h0
Issuer: 4mb5gWTlIemu0h0 |
| Malicious | VirusTotal score: 64/72 (Scanned on 2025-08-28 05:17:39) |
ALYac:
Gen:Variant.Razy.114098
APEX: Malicious AVG: Win32:Karagany Acronis: suspicious AhnLab-V3: Trojan/Win32.Zbot.R23747 Alibaba: VirTool:Win32/Obfuscator.9792ca5c Antiy-AVL: Trojan[Packed]/Win32.Krap Arcabit: Trojan.Razy.D1BDB2 Avast: Win32:Karagany Avira: TR/Dldr.Expack.A Baidu: Win32.Adware.Kryptik.b BitDefender: Gen:Variant.Razy.114098 Bkav: W32.AIDetectMalware CAT-QuickHeal: TrojanPWS.Fareit.C CTX: exe.trojan.generic ClamAV: Win.Packed.Zbot-9754664-0 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS DrWeb: Trojan.PWS.Multi.541 ESET-NOD32: Win32/PSW.Agent.NTM Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Razy.114098 (B) F-Secure: Trojan.TR/Dldr.Expack.A Fortinet: W32/Kryptik.AEFJ!tr GData: Gen:Variant.Razy.114098 Google: Detected Ikarus: Trojan.SuspectCRC Jiangmin: Trojan/Generic.zibl K7AntiVirus: Spyware ( 003919791 ) K7GW: Spyware ( 003919791 ) Kaspersky: Packed.Win32.Krap.iu Kingsoft: Win32.Troj.Undef.a Lionic: Trojan.Win32.Generic.lw2L Malwarebytes: Generic.Malware.AI.DDS McAfeeD: ti!0A50B74AC552 MicroWorld-eScan: Gen:Variant.Razy.114098 Microsoft: PWS:Win32/Fareit NANO-Antivirus: Trojan.Win32.Multi.mrced Paloalto: generic.ml Panda: Bck/Qbot.AO Rising: Spyware.Zbot!8.16B (TFE:3:JO2GSNafipM) Sangfor: Trojan.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: PWS-Zbot.gen.bew Sophos: Troj/Zbot-DHN Symantec: Packed.Generic.459 Tencent: Malware.Win32.Gencirc.10b29914 Trapmine: malicious.high.ml.score TrellixENS: PWS-Zbot.gen.bew TrendMicro: TROJ_GEN.F29EZEN TrendMicro-HouseCall: TROJ_GEN.F29EZEN VBA32: BScope.TrojanPSW.Panda VIPRE: Gen:Variant.Razy.114098 Varist: W32/Zbot.DQ.gen!Eldorado VirIT: Trojan.Win32.Generic.CCJR Webroot: W32.Downloader.Gen Xcitium: TrojWare.Win32.Kryptik.ADXK@4nyoqo Zillya: Trojan.Agent.Win32.3287213 ZoneAlarm: Troj/Zbot-DHN alibabacloud: Virtool:Win/Fareit.Gen huorong: Trojan/Tepfer.c tehtris: Generic.Malware |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2012-Apr-09 19:40:44 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x1c200 |
| SizeOfInitializedData | 0x7600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0001BC50 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1e000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x26000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x3264c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteTapemark
UnregisterWait CreateDirectoryExW DeleteCriticalSection GetVersionExW GlobalCompact AddConsoleAliasW FindFirstVolumeW FindFirstVolumeMountPointW WriteFileGather FindFirstVolumeA HeapUnlock lstrcmpiW CreateFileA SystemTimeToTzSpecificLocalTime GetTempPathA Process32FirstW GetConsoleTitleA EndUpdateResourceA OpenThread EnumCalendarInfoW SetConsoleTextAttribute GetFileAttributesExW ReadConsoleA GetMailslotInfo SetConsoleDisplayMode ConnectNamedPipe EnumResourceNamesW SetCommState GetProfileSectionA QueueUserAPC GetFullPathNameW HeapSize VirtualAllocEx DeleteFileA OpenEventA GetConsoleAliasExesLengthW UnlockFile GetCPInfoExW _llseek UnmapViewOfFile Thread32Next OpenFileMappingW DnsHostnameToComputerNameA GetSystemDefaultUILanguage FindNextVolumeMountPointW GetProcessPriorityBoost LCMapStringW GetLogicalDriveStringsW ReleaseSemaphore GetNumberOfConsoleMouseButtons GetSystemInfo SetThreadIdealProcessor GetStringTypeA VirtualAlloc SetFileAttributesW BeginUpdateResourceA CreateRemoteThread TlsGetValue GetLocaleInfoW DosDateTimeToFileTime FatalAppExitW GetCurrencyFormatW SetEnvironmentVariableA CopyFileExA SetSystemTime GetUserDefaultUILanguage WriteProfileSectionA GetEnvironmentStrings TryEnterCriticalSection FindNextVolumeA GetDateFormatA SetProcessPriorityBoost Heap32ListNext GetBinaryType GetTempFileNameW FillConsoleOutputCharacterA EnumResourceTypesA RequestWakeupLatency LockResource HeapLock CreateHardLinkA MapViewOfFileEx BackupSeek CreateConsoleScreenBuffer SetProcessWorkingSetSize GetProfileSectionW GlobalAddAtomA SetConsoleOutputCP LoadLibraryExW GlobalLock ResetWriteWatch GetCommConfig GlobalAddAtomW GetWindowsDirectoryA WritePrivateProfileSectionA AllocateUserPhysicalPages GetCurrentProcess IsBadReadPtr LocalFileTimeToFileTime GetDiskFreeSpaceA PeekConsoleInputW IsDBCSLeadByte ResetEvent DeleteTimerQueueEx GetSystemDefaultLCID CreateIoCompletionPort lstrcpyA InterlockedIncrement DefineDosDeviceA CancelWaitableTimer GetConsoleDisplayMode GetPrivateProfileSectionA VirtualFreeEx SetFileAttributesA CancelDeviceWakeupRequest VirtualProtectEx FindNextChangeNotification EnumResourceLanguagesA HeapCompact DeviceIoControl CreateJobObjectW SearchPathW lstrcmpA LocalFlags CreateMutexA WriteConsoleOutputW _lread GetDriveTypeA GetVersion SetEnvironmentVariableW GetThreadSelectorEntry InterlockedExchangeAdd LoadModule ReadProcessMemory WritePrivateProfileSectionW GetStdHandle FindFirstFileExA FindFirstFileA SetFileApisToANSI LocalAlloc VirtualLock SetComputerNameExW WritePrivateProfileStructA SetSystemTimeAdjustment lstrcpyW GetFileSize SetThreadLocale ReadConsoleOutputA GetVolumeInformationA GlobalReAlloc SetStdHandle GetCommState EnumLanguageGroupLocalesW SetSystemPowerState IsDebuggerPresent GlobalMemoryStatusEx ReleaseMutex GetProcessVersion lstrcpynA GetComputerNameW SetConsoleTitleW OpenSemaphoreA Heap32First OpenWaitableTimerW GetCommProperties GetThreadTimes GetLastError SetVolumeMountPointA GetProcAddress _lopen FlushFileBuffers DeleteTimerQueueTimer LocalCompact MoveFileWithProgressA ProcessIdToSessionId Process32Next EnumSystemLanguageGroupsW GetConsoleAliasesLengthA MoveFileExW GetProfileIntW WriteFile FindAtomW GetCompressedFileSizeA GetPrivateProfileSectionNamesA OpenEventW GetCompressedFileSizeW CreateMailslotW SetComputerNameW GlobalAlloc GetConsoleAliasW CreateEventA IsBadHugeReadPtr Beep ReadConsoleW GetFileAttributesW GetPriorityClass FindNextVolumeW PeekNamedPipe ReadFile GetVolumePathNameA lstrlenW FlushConsoleInputBuffer AddAtomA LockFile EnumLanguageGroupLocalesA GlobalMemoryStatus GetSystemDirectoryW SetHandleCount GetDefaultCommConfigW HeapWalk CreateSemaphoreA UnregisterWaitEx InitializeCriticalSectionAndSpinCount GetProcessTimes WriteProfileSectionW FormatMessageW MulDiv ReadConsoleInputW GetLocalTime GetCurrentProcessId RtlFillMemory SetConsoleCursor FindAtomA IsValidLocale CreateProcessA GetTimeZoneInformation SwitchToFiber IsBadStringPtrA GetComputerNameA WriteConsoleOutputCharacterA Module32NextW OpenMutexA GetAtomNameW Toolhelp32ReadProcessMemory CopyFileW GetExitCodeProcess GetStartupInfoA CreateNamedPipeA _lclose PurgeComm LoadLibraryW ReplaceFile BuildCommDCBW InterlockedCompareExchange GetFileSizeEx WriteFileEx CreateFileW GetCommModemStatus SetCommBreak EnterCriticalSection CreateJobObjectA ExitThread SetVolumeLabelA EnumResourceNamesA OpenSemaphoreW CreateProcessW LoadLibraryA lstrcatA FileTimeToDosDateTime |
|---|---|
| USER32.dll |
InternalGetWindowText
ReplyMessage SetScrollRange MapVirtualKeyW CreateDesktopW FindWindowW CopyAcceleratorTableW SendNotifyMessageA GetMenuState GetMenuContextHelpId GetWindowTextLengthW SendMessageCallbackA ModifyMenuA OemToCharBuffA DdeGetData SetDlgItemTextA GetDlgCtrlID GetTabbedTextExtentA TrackPopupMenuEx DefDlgProcA MsgWaitForMultipleObjectsEx ValidateRect GetWindowContextHelpId DestroyCaret DdeQueryStringA EnableMenuItem BeginPaint DefMDIChildProcW GetWindowTextA UnregisterClassW LoadStringW GetWindowLongW CharPrevA GetClipboardFormatNameA wsprintfW CascadeWindows WinHelpW WaitMessage RegisterClipboardFormatW SetScrollInfo RealGetWindowClassW IsDialogMessageW LoadBitmapW SetWindowsHookA ChangeDisplaySettingsExW EndPaint ExcludeUpdateRgn CharPrevW WINNLSGetEnableStatus DdeFreeStringHandle CountClipboardFormats GetKeyState GetMenuItemID IMPQueryIMEW EnumThreadWindows SetSystemCursor ToUnicode GetMenuItemInfoW IsWindowEnabled keybd_event LookupIconIdFromDirectoryEx GetUserObjectInformationA ClipCursor EditWndProc GetScrollPos ImpersonateDdeClientWindow MapDialogRect GetKeyNameTextW GetMenuStringW GetWindowPlacement SetUserObjectInformationW DefDlgProcW GetProcessDefaultLayout GetUpdateRect GetMessagePos UpdateLayeredWindow GetKBCodePage DdeImpersonateClient ChangeDisplaySettingsExA RegisterDeviceNotificationW RemovePropW UnregisterClassA ChangeMenuA EnumDisplayDevicesA AllowSetForegroundWindow SwitchDesktop PostThreadMessageA EnumClipboardFormats OpenWindowStationW SetClipboardData SendMessageW EnumPropsA CharUpperW EnumDesktopsW DlgDirListComboBoxA IsHungAppWindow BroadcastSystemMessageA GetOpenClipboardWindow LoadIconA SetDebugErrorLevel DeferWindowPos SetDoubleClickTime GetDCEx CreateIconIndirect ScrollWindow DrawEdge AdjustWindowRect MapVirtualKeyExA GetMenuItemRect WINNLSGetIMEHotkey EnumWindowStationsW GetWindowRect DdeCreateStringHandleA DdeEnableCallback LookupIconIdFromDirectory PaintDesktop CloseWindow DdeConnectList EnumWindowStationsA OemToCharW InsertMenuW CheckMenuItem HiliteMenuItem CopyImage DestroyWindow CallWindowProcW DdeAccessData GetWindowModuleFileNameA IsZoomed WaitForInputIdle InSendMessageEx LoadKeyboardLayoutW OemToCharBuffW GetClassLongW DestroyIcon InvalidateRect SystemParametersInfoA GetSystemMenu DdeAbandonTransaction GetCaretBlinkTime InvertRect DdeNameService GetShellWindow SetCursorPos RegisterShellHookWindow GetWindow DdeAddData WINNLSEnableIME InvalidateRgn CreateIconFromResource GetIconInfo IsCharLowerW OpenWindowStationA DdeCreateStringHandleW GetUserObjectInformationW GetUserObjectSecurity SetParent GetMenuItemCount IsCharAlphaNumericW AppendMenuA SetMenuItemInfoA InsertMenuItemA IMPGetIMEW CharNextW SetClassWord FrameRect DestroyMenu GetClassInfoExA IsCharLowerA GetMenuBarInfo IsCharUpperA OpenInputDesktop IsCharAlphaA CloseWindowStation DrawTextExA SetClipboardViewer SetDlgItemInt DdeQueryConvInfo ChildWindowFromPointEx PostThreadMessageW TabbedTextOutA ClientToScreen SetWindowLongW RemovePropA IMPSetIMEA DefMDIChildProcA MapVirtualKeyA GetCursorInfo DdeDisconnect GetLastActivePopup SetCapture GetAltTabInfoW TileChildWindows GetKeyNameTextA CheckRadioButton GetDlgItem CascadeChildWindows VkKeyScanExW FreeDDElParam UnpackDDElParam CharLowerA GetClassNameA EnumPropsExA SetDlgItemTextW RegisterClassA GetSubMenu GetSystemMetrics SetThreadDesktop GetWindowTextW FlashWindow LoadAcceleratorsA DdeSetUserHandle DlgDirSelectComboBoxExA OffsetRect InSendMessage ChangeDisplaySettingsW CharLowerBuffA EnumDisplaySettingsA GetDlgItemTextA GetGuiResources EnumDisplaySettingsExA GetNextDlgTabItem SetFocus GetInputDesktop GetTabbedTextExtentW SetDeskWallpaper CreateAcceleratorTableW GetClipCursor MenuItemFromPoint GetForegroundWindow PeekMessageW UpdateWindow EnumPropsExW LoadKeyboardLayoutA SetClassLongW SendMessageCallbackW CallMsgFilter GetClassInfoA GetWindowModuleFileName SendIMEMessageExA GetAsyncKeyState WindowFromDC OemToCharA CallMsgFilterA GetDlgItemTextW GetTitleBarInfo |
| msvcrt.dll |
memcpy
|
| SHLWAPI.dll |
StrFormatKBSizeW
PathFileExistsW StrRChrA SHRegSetUSValueW StrCatBuffA SHRegEnumUSValueA wnsprintfW SHStrDupA PathIsNetworkPathA PathUnExpandEnvStringsW StrIsIntlEqualW UrlIsOpaqueW UrlGetLocationW PathGetArgsA SHRegCreateUSKeyA PathIsRelativeW AssocQueryStringByKeyW SHRegCreateUSKeyW UrlCompareW SHRegGetPathW SHEnumValueW SHSetValueA StrDupW UrlGetLocationA ChrCmpIA SHRegGetBoolUSValueW StrFromTimeIntervalA SHCreateStreamOnFileA PathMakeSystemFolderW wvnsprintfA PathCanonicalizeW SHRegCloseUSKey StrRetToStrW PathUnExpandEnvStringsA PathParseIconLocationW PathStripToRootW PathAddExtensionW StrStrIW PathIsDirectoryEmptyW SHRegSetPathW PathStripPathA StrCpyNW StrCmpNA StrCmpIW SHOpenRegStreamA PathRelativePathToA UrlApplySchemeW wvnsprintfW UrlHashW HashData PathFindFileNameA PathSkipRootA PathSetDlgItemPathA PathRemoveBlanksW SHRegGetUSValueA PathFindExtensionW PathCommonPrefixA StrRetToBufW StrCSpnA SHAutoComplete PathRenameExtensionW StrStrA StrRChrIA UrlUnescapeW #16 SHRegDuplicateHKey SHRegDeleteEmptyUSKeyA PathSetDlgItemPathW StrToIntW PathBuildRootW PathSearchAndQualifyA SHRegEnumUSKeyW UrlIsNoHistoryW StrStrIA PathFileExistsA PathMakeSystemFolderA SHRegEnumUSValueW SHRegDeleteUSValueW PathRenameExtensionA PathIsUNCServerW SHOpenRegStreamW StrCmpNIW PathFindOnPathA SHRegQueryInfoUSKeyW PathFindNextComponentA UrlCreateFromPathW PathBuildRootA AssocQueryStringA PathStripPathW UrlGetPartA SHSetValueW PathCompactPathA SHEnumKeyExA StrRChrIW PathRemoveExtensionA StrChrA StrCatBuffW PathCompactPathExW PathAddBackslashW SHRegEnumUSKeyA PathSkipRootW SHCopyKeyW PathCompactPathExA PathRemoveBackslashW StrRChrW PathUndecorateW StrRStrIW StrFormatKBSizeA SHEnumValueA PathUnquoteSpacesA PathCommonPrefixW StrTrimA StrToIntExA SHGetThreadRef UrlUnescapeA SHRegQueryUSValueA SHGetInverseCMAP StrCatW StrPBrkW PathFindOnPathW StrRetToBufA ChrCmpIW IntlStrEqWorkerA UrlCompareA StrPBrkA PathMakePrettyA StrCmpW SHRegDeleteUSValueA PathIsContentTypeA SHDeleteKeyW PathIsDirectoryA SHRegGetBoolUSValueA StrCmpNIA PathIsUNCA StrRetToStrA PathIsFileSpecW SHQueryValueExA PathUnmakeSystemFolderW PathIsPrefixW SHRegQueryUSValueW PathRemoveBlanksA SHRegQueryInfoUSKeyA ColorHLSToRGB SHGetValueA PathRemoveFileSpecW PathIsPrefixA PathAppendA PathAddExtensionA PathFindSuffixArrayW PathUndecorateA wnsprintfA PathFindExtensionA SHRegDeleteEmptyUSKeyW PathCombineW SHRegWriteUSValueA PathParseIconLocationA PathRemoveArgsW PathIsSameRootW StrSpnW GetMenuPosFromID PathIsSameRootA SHRegSetUSValueA SHRegOpenUSKeyA StrCSpnW AssocQueryKeyA AssocCreate SHSkipJunction StrToIntExW AssocQueryStringByKeyA StrFormatByteSize64A SHOpenRegStream2W SHEnumKeyExW PathIsRootW PathIsUNCServerShareW PathUnmakeSystemFolderA PathIsFileSpecA PathIsContentTypeW StrFormatByteSizeW PathMatchSpecA PathQuoteSpacesA PathMatchSpecW SHCreateShellPalette UrlCombineW StrCSpnIW SHDeleteEmptyKeyW StrDupA PathFindSuffixArrayA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.1.7600.16385 |
| ProductVersion | 6.1.7600.16385 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Windows Disk Diagnostic User Resolver |
| FileVersion (#2) | 6.1.7600.16385 (win7_rtm.090713-1255) |
| InternalName | DFDWiz.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | DFDWiz.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 6.1.7600.16385 |
| Resource LangID | English - United States |
|---|
No comments yet.