| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2014-Sep-18 06:10:13 |
| Detected languages |
English - United States
|
| Debug artifacts |
c:\audio_filter_agent-lync\chdtsr\objfre_wlh_amd64\amd64\CXAPOAgent64.pdb
|
| CompanyName | Conexant Systems, Inc. |
| FileDescription | Conexant APO Agent |
| FileVersion | 1.1.0.0 |
| InternalName | CXAPOAgent.exe |
| LegalCopyright | Copyright 2014 Conexant Systems, Inc. All Rights Reserved. |
| OriginalFilename | CXAPOAgent.exe |
| ProductName | Conexant APO Agent |
| ProductVersion | 1.1.0.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Conexant Systems LLC
Issuer: VeriSign Class 3 Code Signing 2010 CA |
| Safe | VirusTotal score: 0/69 (Scanned on 2021-05-13 18:40:24) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 4 |
| TimeDateStamp | 2014-Sep-18 06:10:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0xa7c00 |
| SizeOfInitializedData | 0x17000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000086560 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x1000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xbf0ce |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
RegOpenKeyW
RegQueryValueExW RegisterServiceCtrlHandlerW RegCloseKey InitializeSecurityDescriptor SetSecurityDescriptorDacl SetServiceStatus GetUserNameW RegSetValueExW RegCreateKeyExW |
|---|---|
| KERNEL32.dll |
GetVersionExW
TerminateProcess CreateEventW GetCommandLineW OutputDebugStringW RaiseException ResetEvent SetEvent GetModuleFileNameW WaitForSingleObject OpenProcess OutputDebugStringA Sleep LoadLibraryW GetProcAddress CreateFileW InitializeCriticalSection DeleteCriticalSection EnterCriticalSection lstrlenW GetCurrentThreadId LeaveCriticalSection GetLastError ExitProcess SetFilePointer WriteFile lstrcpyW DeviceIoControl HeapFree GetProcessHeap HeapAlloc GetModuleHandleW WideCharToMultiByte MultiByteToWideChar FreeLibrary CloseHandle GetCurrentProcess SetStdHandle GetConsoleMode GetConsoleCP GetStringTypeW InitializeCriticalSectionAndSpinCount LCMapStringW GetOEMCP GetACP GetCPInfo RtlCaptureContext RtlVirtualUnwind UnhandledExceptionFilter WriteConsoleW GetSystemTimeAsFileTime GetCurrentProcessId GetTickCount QueryPerformanceCounter HeapCreate HeapSetInformation FlsAlloc SetLastError FlsFree DecodePointer EncodePointer GetFileType SetHandleCount GetEnvironmentStringsW FreeEnvironmentStringsW GetModuleFileNameA GetStdHandle SetUnhandledExceptionFilter RtlLookupFunctionEntry RtlPcToFileHeader VirtualQuery GetSystemInfo SetThreadStackGuarantee VirtualAlloc VirtualProtect RtlUnwindEx FlushFileBuffers FlsGetValue FlsSetValue GetStartupInfoW HeapDestroy HeapReAlloc HeapSize GetVersionExA |
| USER32.dll |
UnregisterClassA
UnregisterDeviceNotification RegisterWindowMessageW PostMessageW KillTimer EndPaint BeginPaint RegisterClassExW LoadCursorW LoadIconW EnumDisplaySettingsW DefWindowProcW FindWindowW PostQuitMessage |
| ole32.dll |
PropVariantClear
CoCreateInstance CoTaskMemFree CoUninitialize CoInitializeEx |
| SETUPAPI.dll |
SetupDiDestroyDeviceInfoList
SetupDiGetClassDevsW SetupDiEnumDeviceInterfaces SetupDiGetDeviceInterfaceDetailW |
| WINMM.dll |
timeGetTime
|
| SHLWAPI.dll |
StrCmpNW
|
| PSAPI.DLL |
EnumProcesses
EnumProcessModules GetModuleBaseNameW |
| Ordinal | 1 |
|---|---|
| Address | 0x8503c |
| Ordinal | 2 |
|---|---|
| Address | 0x852d0 |
| Ordinal | 3 |
|---|---|
| Address | 0x8562c |
| Ordinal | 4 |
|---|---|
| Address | 0x8515c |
| Ordinal | 5 |
|---|---|
| Address | 0x855b8 |
| Ordinal | 6 |
|---|---|
| Address | 0x852dc |
| Ordinal | 7 |
|---|---|
| Address | 0x85450 |
| CHDTsr |
| CHDTSR |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.0.0 |
| ProductVersion | 1.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Conexant Systems, Inc. |
| FileDescription | Conexant APO Agent |
| FileVersion (#2) | 1.1.0.0 |
| InternalName | CXAPOAgent.exe |
| LegalCopyright | Copyright 2014 Conexant Systems, Inc. All Rights Reserved. |
| OriginalFilename | CXAPOAgent.exe |
| ProductName | Conexant APO Agent |
| ProductVersion (#2) | 1.1.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2014-Sep-18 06:10:13 |
| Version | 0.0 |
| SizeofData | 98 |
| AddressOfRawData | 0x82988 |
| PointerToRawData | 0x81d88 |
| Referenced File | c:\audio_filter_agent-lync\chdtsr\objfre_wlh_amd64\amd64\CXAPOAgent64.pdb |
| XOR Key | 0x93eadb8e |
|---|---|
| Unmarked objects | 0 |
| C++ objects (40310) | 1 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 10 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 135 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 54 |
| Imports (40310) | 21 |
| Total imports | 215 |
| C objects (40310) | 9 |
| 114 (VS2012 build 50727 / VS2005 build 50727) | 16 |
| Exports (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |
No comments yet.