| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2007-Sep-06 18:27:36 |
| Detected languages |
Chinese - PRC
|
| CompanyName | www.winchiphead.com |
| FileDescription | EXE For Driver Installation |
| FileVersion | 1, 4, 0, 0 |
| InternalName | SETUP |
| LegalCopyright | Copyright (C) W.ch 2001-2007 |
| OriginalFilename | SETUP.EXE |
| ProductName | Setup.exe |
| ProductVersion | 1.40 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-01-23 05:24:26) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2007-Sep-06 18:27:36 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x8000 |
| SizeOfInitializedData | 0xd000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000040D0 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x9000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x16000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetUserDefaultLangID
CreateThread CloseHandle Sleep GetLastError GetProcAddress LoadLibraryA GetPrivateProfileSectionA GetPrivateProfileStringA DeleteFileA CopyFileA SetLastError LocalAlloc LocalFree GetVersion GetSystemDirectoryA CompareStringW CompareStringA FlushFileBuffers SetStdHandle HeapReAlloc VirtualAlloc HeapAlloc SetFilePointer GetTimeZoneInformation GetStringTypeW GetCurrentDirectoryA LCMapStringW LCMapStringA MultiByteToWideChar WriteFile RtlUnwind HeapFree VirtualFree HeapCreate HeapDestroy GetFileType GetStdHandle SetHandleCount GetEnvironmentStringsW GetEnvironmentStrings WideCharToMultiByte FreeEnvironmentStringsW FreeEnvironmentStringsA GetModuleFileNameA UnhandledExceptionFilter GetCurrentProcess TerminateProcess GetOEMCP SetEnvironmentVariableA GetACP GetCPInfo ExitProcess GetCommandLineA GetStartupInfoA GetWindowsDirectoryA GetStringTypeA lstrlenA FindFirstFileA FindNextFileA FileTimeToSystemTime FileTimeToLocalFileTime GetModuleHandleA |
|---|---|
| USER32.dll |
UpdateWindow
CharUpperA IsDlgButtonChecked EnableWindow FindWindowExA EnumChildWindows GetWindowTextA SendDlgItemMessageA SetDlgItemTextA MessageBoxA DefWindowProcA GetDlgItem ShowWindow LoadIconA SendMessageA EndDialog DialogBoxParamA |
| SETUPAPI.dll |
SetupDiBuildDriverInfoList
SetupDiEnumDriverInfoA SetupDiGetDriverInfoDetailA SetupDiDestroyDriverInfoList SetupDefaultQueueCallbackA SetupOpenInfFileA SetupDiGetActualSectionToInstallA SetupOpenFileQueue SetupInitDefaultQueueCallbackEx SetupInstallFilesFromInfSectionA SetupCommitFileQueueA SetupCloseFileQueue SetupCloseInfFile SetupTermDefaultQueueCallback SetupCopyOEMInfA SetupDiGetClassDevsA SetupDiEnumDeviceInfo SetupDiGetDeviceRegistryPropertyA SetupDiCallClassInstaller SetupDiDestroyDeviceInfoList SetupDiSetDeviceRegistryPropertyA |
| CFGMGR32.dll |
CM_Reenumerate_DevNode
CM_Locate_DevNodeA |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.4.0.0 |
| ProductVersion | 1.4.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Chinese - PRC |
| CompanyName | www.winchiphead.com |
| FileDescription | EXE For Driver Installation |
| FileVersion (#2) | 1, 4, 0, 0 |
| InternalName | SETUP |
| LegalCopyright | Copyright (C) W.ch 2001-2007 |
| OriginalFilename | SETUP.EXE |
| ProductName | Setup.exe |
| ProductVersion (#2) | 1.40 |
| Resource LangID | Chinese - PRC |
|---|
| XOR Key | 0x4daf4c41 |
|---|---|
| Unmarked objects | 0 |
| 12 (7291) | 1 |
| 14 (7299) | 17 |
| C objects (VS98 build 8168) | 60 |
| 19 (8152) | 2 |
| 19 (8034) | 7 |
| Total imports | 105 |
| C++ objects (VS98 build 8168) | 3 |
| Resource objects (VS98 cvtres build 1720) | 1 |
No comments yet.