18e4bd6e6bba8f2a6e4540b9673e867e5a20a600999af61cf80bd7e47ac1df3d

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-Sep-18 06:10:13
Detected languages English - United States
Debug artifacts c:\audio_filter_agent-lync\chdtsr\objfre_wlh_amd64\amd64\CXAPOAgent64.pdb
CompanyName Conexant Systems, Inc.
FileDescription Conexant APO Agent
FileVersion 1.1.0.0
InternalName CXAPOAgent.exe
LegalCopyright Copyright 2014 Conexant Systems, Inc. All Rights Reserved.
OriginalFilename CXAPOAgent.exe
ProductName Conexant APO Agent
ProductVersion 1.1.0.0

Plugin Output

Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • FindWindowW
Can access the registry:
  • RegOpenKeyW
  • RegQueryValueExW
  • RegCloseKey
  • RegSetValueExW
  • RegCreateKeyExW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Manipulates other processes:
  • OpenProcess
  • EnumProcesses
  • EnumProcessModules
Info The PE is digitally signed. Signer: Conexant Systems LLC
Issuer: VeriSign Class 3 Code Signing 2010 CA
Safe VirusTotal score: 0/69 (Scanned on 2021-05-13 18:40:24) All the AVs think this file is safe.

Hashes

MD5 78319d58628ed0e22ff6174584fac44b
SHA1 d1ba049ed49f83c9613fa00c2dd93b62707efc84
SHA256 18e4bd6e6bba8f2a6e4540b9673e867e5a20a600999af61cf80bd7e47ac1df3d
SHA3 722b7ab0ee162e83015118d1db9371a551fb1fc02bbff0a89a7598c244c38031
SSDeep 12288:TYD8JLTx2c4ShJ74QRR0IA+Emk3us3tELv4fCTjiTpU2:sD8J3xESX0IA+EBv3tdIjopf
Imports Hash bf790773d2fb48d24ab814e2c920d458

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 4
TimeDateStamp 2014-Sep-18 06:10:13
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 8.0
SizeOfCode 0xa7c00
SizeOfInitializedData 0x17000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000086560 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x1000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 6.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0xc1000
SizeOfHeaders 0x400
Checksum 0xbf0ce
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x80000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 eae80e89be2141cc5a8f51cc805c4699
SHA1 641518c397b88c1dd5444f43243bfcdba82ab1e0
SHA256 7fc0e4127c76a2e745ce9f3be9bba8369dbdd0a07fc2cc2ac0edd5efc03e2eaf
SHA3 4b8a408f00afec4ff4791bea1979c98a306eba49ed08304262d49400d26486a0
VirtualSize 0xa7bc4
VirtualAddress 0x1000
SizeOfRawData 0xa7c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.68849

.data

MD5 1aac1d958394099c5157d7ea6d659f31
SHA1 39356979508da2d61853fe0496d7f15ac41aaddd
SHA256 afdbc3b45c5dde9a92c87c5c8f6047287fa6c90f2a9d50bf8bb9d292e706b472
SHA3 f56cbd67a2b2852024c1adafbc36475d77bf890044e67c587b29f6637792f384
VirtualSize 0xf4f8
VirtualAddress 0xa9000
SizeOfRawData 0x3c00
PointerToRawData 0xa8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.793

.pdata

MD5 4d7997d993f145c81adb8a012f73f60d
SHA1 51c3d7155a1aee24444bbfb5d925951c51272561
SHA256 970a8b5949b5ddc2b6fbab526e006fd89d38d383668087a230ca3d138a9b61ab
SHA3 12601deb966c8bc254add1f29fafc3a4637ce8d4d7148891bc6e74d518f0ef7d
VirtualSize 0xce4
VirtualAddress 0xb9000
SizeOfRawData 0xe00
PointerToRawData 0xabc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.07314

.rsrc

MD5 535d6708b3291ccf7feed4346b7ad4a4
SHA1 f10e976b88af24d2dd4ed8a2f1409f28b68fdb1b
SHA256 622ed39ac96586608522876941c3acf23d71a0e6fdb8973cf3a25717e244d0c2
SHA3 014a3d5dcb6dddc49c20353ad11733282f4113ae6d602325afda20b81731687e
VirtualSize 0x6af8
VirtualAddress 0xba000
SizeOfRawData 0x6c00
PointerToRawData 0xaca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.40916

Imports

ADVAPI32.dll RegOpenKeyW
RegQueryValueExW
RegisterServiceCtrlHandlerW
RegCloseKey
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
SetServiceStatus
GetUserNameW
RegSetValueExW
RegCreateKeyExW
KERNEL32.dll GetVersionExW
TerminateProcess
CreateEventW
GetCommandLineW
OutputDebugStringW
RaiseException
ResetEvent
SetEvent
GetModuleFileNameW
WaitForSingleObject
OpenProcess
OutputDebugStringA
Sleep
LoadLibraryW
GetProcAddress
CreateFileW
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
lstrlenW
GetCurrentThreadId
LeaveCriticalSection
GetLastError
ExitProcess
SetFilePointer
WriteFile
lstrcpyW
DeviceIoControl
HeapFree
GetProcessHeap
HeapAlloc
GetModuleHandleW
WideCharToMultiByte
MultiByteToWideChar
FreeLibrary
CloseHandle
GetCurrentProcess
SetStdHandle
GetConsoleMode
GetConsoleCP
GetStringTypeW
InitializeCriticalSectionAndSpinCount
LCMapStringW
GetOEMCP
GetACP
GetCPInfo
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
WriteConsoleW
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
HeapCreate
HeapSetInformation
FlsAlloc
SetLastError
FlsFree
DecodePointer
EncodePointer
GetFileType
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetModuleFileNameA
GetStdHandle
SetUnhandledExceptionFilter
RtlLookupFunctionEntry
RtlPcToFileHeader
VirtualQuery
GetSystemInfo
SetThreadStackGuarantee
VirtualAlloc
VirtualProtect
RtlUnwindEx
FlushFileBuffers
FlsGetValue
FlsSetValue
GetStartupInfoW
HeapDestroy
HeapReAlloc
HeapSize
GetVersionExA
USER32.dll UnregisterClassA
UnregisterDeviceNotification
RegisterWindowMessageW
PostMessageW
KillTimer
EndPaint
BeginPaint
RegisterClassExW
LoadCursorW
LoadIconW
EnumDisplaySettingsW
DefWindowProcW
FindWindowW
PostQuitMessage
ole32.dll PropVariantClear
CoCreateInstance
CoTaskMemFree
CoUninitialize
CoInitializeEx
SETUPAPI.dll SetupDiDestroyDeviceInfoList
SetupDiGetClassDevsW
SetupDiEnumDeviceInterfaces
SetupDiGetDeviceInterfaceDetailW
WINMM.dll timeGetTime
SHLWAPI.dll StrCmpNW
PSAPI.DLL EnumProcesses
EnumProcessModules
GetModuleBaseNameW

Delayed Imports

?HDMI_GetCnxtPlaybackAudioDeviceInfo@@YAJPEAK@Z

Ordinal 1
Address 0x8503c

?HDMI_GetDefaultAudioDevice@@YAJPEAKW4__MIDL___MIDL_itf_mmdeviceapi_0000_0000_0001@@@Z

Ordinal 2
Address 0x852d0

?HDMI_GetDefaultAudioDeviceFromRegistry@@YAJPEAK@Z

Ordinal 3
Address 0x8562c

?HDMI_SetDefaultAudioDevice@@YAJKW4__MIDL___MIDL_itf_mmdeviceapi_0000_0000_0001@@@Z

Ordinal 4
Address 0x8515c

?HDMI_SetDefaultAudioDeviceToRegistry@@YAJK@Z

Ordinal 5
Address 0x855b8

?HDMI_SetThirdPartyDefaultAudioDevice@@YAJPEAGKW4__MIDL___MIDL_itf_mmdeviceapi_0000_0000_0001@@@Z

Ordinal 6
Address 0x852dc

?HDMI_SetThirdPartySingleHDMIDefaultAudioDevice@@YAJXZ

Ordinal 7
Address 0x85450

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32389
MD5 ce4db77a5a5fec0d5ea2e57b7e80051b
SHA1 4b4ea51c3fe466f511981334892233f354d37c01
SHA256 129f21bfe43fd022c1bb3bc335b90e01c55752512d8f57862e18819833b38673
SHA3 06a250af760b6c5a815194482e23c91057ee9730b72e399e76fce886404c48a7

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89005
MD5 6084b8ad73747b299699eb3eec45e7dc
SHA1 2c9ce3ea9a49025409f4fbe0fbaa8d505c07a378
SHA256 b4b2f722234d9e7f31ff4facd631adcc0482b81c4ad1eb1458fc822175277c21
SHA3 bb24114010889c9f80fd5363f152c6315e4f275b8582e304a385531de5d61957

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.54353
MD5 e8658c45887b965ef05fc75aa46500e3
SHA1 0091c56d319743f075ce4d7af0ef65b896a02041
SHA256 803572ed52c34a6b6c2efa70c0f7a5279e21bad55a4d5d18744b270937404fe2
SHA3 fe1cde23bbcac573b68e909b1f54a64f8d189045e58a9d185f6d93ee3d0ec3af

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.35478
MD5 d042f1c698b7e67ab19323c03defcfaa
SHA1 a7f6b7f33babceb621f66db8e4932e4668ad916d
SHA256 0a4938500c6f3d33430c7fed3c2271a78b34ee727a78475eb6d1a435f4a00bdb
SHA3 53ba211529ed344097e112c4d327f04e8f09951109c686c8291b58004de28755

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17501
MD5 43553baed02ba66915b18d4e17cfce16
SHA1 f00698b999f0887c350c61e4aa083d79bea26cb7
SHA256 2ae3c5d4d767d49adf27595ac6e6c282cba327b4cdb89f9dc2a735c314eb7d18
SHA3 8acbc751b6d2a0f54b1ac8df53fc05b74e6774c176b94e6876afad010dd15e4f

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47748
MD5 4ac79bef346bca3604bba0e200cbda0b
SHA1 f45f4f77b61adba0151d1942c978689e41e28dae
SHA256 b1f2927559496473b1bd7ca8d8cb21b67e56eefa87fc06945eba67c71d268645
SHA3 07ca004b480e2182e3be16a4706a0653bc4c76de33ba8853eb9529aeeeb34fed

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83156
MD5 4786e9acb4ceb2b23d50e0dabb6cecd5
SHA1 164fadfaa648ed5c8adb7dd14b494b3501ed77de
SHA256 10f2dfcb31c0f0816447923633e79ef4ff7ca1bf89d5f6984e4cce62615ea729
SHA3 cc4907d29a3eeee6042b743fa967b659f8eef2975da67a6143489be39014d52f

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44197
MD5 4f6369dca29c639671dd504fa585b183
SHA1 09b1ab98de685f3f09d47b93f6186963c03b7946
SHA256 aec3c266b0f119a982069893611ffd2cdd271fdbcf915b17fdf9b00d445676c9
SHA3 3ec84b0f83e5972044ed977444b56836a03dc0b42df2b59ccd78ad6ebedf83fd

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.05874
MD5 d10df39d7ee26d29c547f5df1da71fa1
SHA1 dcbba9f2f7c3c5f6e884d4ed8b36f6cb6055317c
SHA256 7ad7dd241cc84dad41c3f1ee55c9272bd835e6172e6144423af4be38ce3fe2a1
SHA3 ffd528465a691f1a4f797c3f9bfcdb4579dbc2708ad3c2ff0bf46f14563d6205

109

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71163
MD5 2886ccd7dc1bd6dec8413a00b53046a0
SHA1 a09dea8ae745541a9d191d42d68510db8f648b5d
SHA256 a29831e4a3fac395e2aa86df5a0906ed2beebda018745be869477d636148f7af
SHA3 fc89873b946c12a8b176b7eff05b2c4445b56a96c045e40e9d49ecc09a4d0fcb

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x12e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0843
MD5 f5fc5b97633c4da3054a26c438705003
SHA1 1b6d7feb689a59c68be791e820ca23fd4339c03f
SHA256 69361e799a2f65918d1dffb12fcb10108c6a7ac36223fbd43072adfa85803c98
SHA3 ec2fdfaf1c891b01be1edf26197633aea9ba136f65237b1de8e3a0d7cfe63904

7 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x38
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.58455
MD5 25a7d71f6464272ba81cc64af36751fa
SHA1 73c20318439368833dc7e5f46fc0f1d2346f51b4
SHA256 75f70264572a309b3c49aad3ae286a2f535136636976b83aa1aedd190f33558f
SHA3 62fb30523a95e558a11b78d41033d196c31215cdcbfe5e5cedb59bf3d260f4c9

109 (#2)

Type RT_ACCELERATOR
Language English - United States
Codepage UNKNOWN
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.79879
MD5 3d2b1af3424dbcd504f73918619c7d99
SHA1 10d6ed54ea742211a14a05414883f6c00c03080a
SHA256 c2f0c188d6c493d7827bf83fb89c704815796445a0178bb2ae79658d96703a3c
SHA3 b8c5f28d2c132e5bc304e4dc1b314a3f32a2e48675c06828a2a8a014ea05e7fb

107

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

108

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85255
Detected Filetype Icon file
MD5 7fd86e1ef40a59043395816bf4dc5b3d
SHA1 473cc9d1c0be043c717dd32a4d2b2a06f11e3d0d
SHA256 348205d48d2d52de412742e01091cbee6259da841a58676000eb10cb17948603
SHA3 ae28a0810b905f65c5e1025b6440ce7934f73e4cafa1a993c48c7eca3614bc3c

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3596
MD5 c545e1aeea9074edfd0e98b6fd825c76
SHA1 94895dd84935905cce533cc8062b346f52030b22
SHA256 540ea06968ca1b65664a8484becae0c848a14b77cd6c143f6b2fa6d4d9e9ba50
SHA3 510eaf412e9ce15685b641a0d7324dac53af50f91a6ac806c488fc45f6e2300b

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x2e3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95903
MD5 fb7db15601c6ff507e40b13d110bf0d3
SHA1 47ade9efa56b7f1343351e737ea164c42e6f5062
SHA256 39f9d686172be1c409328360495fdb73c55a0f90a934ad6630f3719b80c8dce6
SHA3 f81babd99986d1c01a4a42592d5f83c4c9d20f029e8d372d2e63dc3e4981057c

String Table contents

CHDTsr
CHDTSR

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.1.0.0
ProductVersion 1.1.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Conexant Systems, Inc.
FileDescription Conexant APO Agent
FileVersion (#2) 1.1.0.0
InternalName CXAPOAgent.exe
LegalCopyright Copyright 2014 Conexant Systems, Inc. All Rights Reserved.
OriginalFilename CXAPOAgent.exe
ProductName Conexant APO Agent
ProductVersion (#2) 1.1.0.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2014-Sep-18 06:10:13
Version 0.0
SizeofData 98
AddressOfRawData 0x82988
PointerToRawData 0x81d88
Referenced File c:\audio_filter_agent-lync\chdtsr\objfre_wlh_amd64\amd64\CXAPOAgent64.pdb

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x93eadb8e
Unmarked objects 0
C++ objects (40310) 1
ASM objects (VS2012 build 50727 / VS2005 build 50727) 10
C objects (VS2012 build 50727 / VS2005 build 50727) 135
C++ objects (VS2012 build 50727 / VS2005 build 50727) 54
Imports (40310) 21
Total imports 215
C objects (40310) 9
114 (VS2012 build 50727 / VS2005 build 50727) 16
Exports (VS2012 build 50727 / VS2005 build 50727) 1
Resource objects (VS2012 build 50727 / VS2005 build 50727) 1
Linker (VS2012 build 50727 / VS2005 build 50727) 1

Errors

Leave a comment

No comments yet.