Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2015-Aug-05 00:46:33 |
Detected languages |
English - United States
|
CompanyName | Intel Corporation |
FileDescription | The Intel® System Support Utility |
FileVersion | 2.5.0.12 |
LegalCopyright | Copyright © Intel Corporation 2015 |
OriginalFileName | SSU.exe |
ProductName | Intel® System Support Utility |
ProductVersion | 2.5.0.12 |
Suspicious | The PE is an NSIS installer | Unusual section name found: .ndata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Intel(R) INTELND1617S2
Issuer: Intel External Issuing CA 7B |
Safe | VirusTotal score: 0/67 (Scanned on 2018-04-10 13:41:29) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xc8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2015-Aug-05 00:46:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x6000 |
SizeOfInitializedData | 0x27c00 |
SizeOfUninitializedData | 0x400 |
AddressOfEntryPoint | 0x000030E2 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 6.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x45000 |
SizeOfHeaders | 0x400 |
Checksum | 0x6a85f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTickCount
GetFullPathNameA MoveFileA SetCurrentDirectoryA GetFileAttributesA GetLastError CreateDirectoryA SetFileAttributesA SearchPathA GetShortPathNameA GetFileSize GetModuleFileNameA GetCurrentProcess CopyFileA ExitProcess SetEnvironmentVariableA GetWindowsDirectoryA GetTempPathA Sleep CloseHandle LoadLibraryA lstrlenA lstrcpynA GetDiskFreeSpaceA GlobalUnlock GlobalLock CreateThread CreateProcessA RemoveDirectoryA CreateFileA GetTempFileNameA ReadFile lstrcpyA lstrcatA GetSystemDirectoryA GetVersion GetProcAddress GlobalAlloc CompareFileTime SetFileTime ExpandEnvironmentStringsA lstrcmpiA lstrcmpA WaitForSingleObject GlobalFree GetExitCodeProcess GetModuleHandleA SetErrorMode GetCommandLineA LoadLibraryExA FindFirstFileA FindNextFileA DeleteFileA SetFilePointer WriteFile FindClose WritePrivateProfileStringA MultiByteToWideChar MulDiv GetPrivateProfileStringA FreeLibrary |
---|---|
USER32.dll |
CreateWindowExA
EndDialog ScreenToClient GetWindowRect EnableMenuItem GetSystemMenu SetClassLongA IsWindowEnabled SetWindowPos GetSysColor GetWindowLongA SetCursor LoadCursorA CheckDlgButton GetMessagePos LoadBitmapA CallWindowProcA IsWindowVisible CloseClipboard GetDC SystemParametersInfoA RegisterClassA TrackPopupMenu AppendMenuA CreatePopupMenu GetSystemMetrics SetDlgItemTextA GetDlgItemTextA MessageBoxIndirectA CharPrevA DispatchMessageA PeekMessageA ReleaseDC EnableWindow InvalidateRect SendMessageA DefWindowProcA BeginPaint GetClientRect FillRect DrawTextA GetClassInfoA DialogBoxParamA CharNextA ExitWindowsEx DestroyWindow CreateDialogParamA SetTimer GetDlgItem wsprintfA SetForegroundWindow ShowWindow IsWindow LoadImageA SetWindowLongA SetClipboardData EmptyClipboard OpenClipboard EndPaint PostQuitMessage FindWindowExA SendMessageTimeoutA SetWindowTextA |
GDI32.dll |
SelectObject
SetBkMode CreateFontIndirectA SetTextColor DeleteObject GetDeviceCaps CreateBrushIndirect SetBkColor |
SHELL32.dll |
SHGetSpecialFolderLocation
SHGetPathFromIDListA SHBrowseForFolderA SHGetFileInfoA ShellExecuteA SHFileOperationA |
ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegDeleteKeyA RegDeleteValueA RegEnumValueA RegCreateKeyExA RegSetValueExA RegQueryValueExA RegEnumKeyA |
COMCTL32.dll |
ImageList_Create
ImageList_AddMasked ImageList_Destroy #17 |
ole32.dll |
CoCreateInstance
CoTaskMemFree OleInitialize OleUninitialize |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0 |
FileVersion | 2.5.0.12 |
ProductVersion | 2.5.0.12 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Intel Corporation |
FileDescription | The Intel® System Support Utility |
FileVersion (#2) | 2.5.0.12 |
LegalCopyright | Copyright © Intel Corporation 2015 |
OriginalFileName | SSU.exe |
ProductName | Intel® System Support Utility |
ProductVersion (#2) | 2.5.0.12 |
Resource LangID | English - United States |
---|
XOR Key | 0x69eb1175 |
---|---|
Unmarked objects | 0 |
C objects (VS2003 (.NET) build 4035) | 2 |
Total imports | 158 |
Imports (VS2003 (.NET) build 4035) | 17 |
48 (9044) | 10 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |