| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2008-Jul-31 17:22:44 |
| Detected languages |
English - United States
|
| Comments | Created with Setup Factory 8.0 |
| FileDescription | Setup Application |
| FileVersion | 8.1.1000.0 |
| InternalName | suf80_launch |
| LegalCopyright | Setup Engine Copyright © 2004-2008 Indigo Rose Corporation |
| LegalTrademarks | Setup Factory is a trademark of Indigo Rose Corporation. |
| OriginalFilename | suf80_launch.exe |
| ProductName | Setup Factory 8.0 Runtime |
| ProductVersion | 8.1.1000.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
| Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h) UPX -> www.upx.sourceforge.net UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains a XORed PE executable:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
14584758 bytes of data starting at offset 0x14000.
The overlay data has an entropy of 7.9996 and is possibly compressed or encrypted. Overlay data amounts for 99.4415% of the executable. |
| Suspicious | VirusTotal score: 2/58 (Scanned on 2024-11-06 05:01:49) |
Antiy-AVL:
Virus/Win32.Expiro.imp
Ikarus: Trojan.Patched |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2008-Jul-31 17:22:44 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x7000 |
| SizeOfInitializedData | 0xc000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00002FB9 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x8000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x15000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x1e8c1 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetUnhandledExceptionFilter
lstrcmpiA lstrcpyA lstrlenA _lclose GetModuleFileNameA _lread _llseek _lopen _lwrite _lcreat CreateDirectoryA SetCurrentDirectoryA lstrcatA FreeLibrary GetProcAddress LoadLibraryA UnhandledExceptionFilter GetFileAttributesA RemoveDirectoryA DeleteFileA GetTempPathA GetCurrentDirectoryA CloseHandle GetExitCodeProcess LocalFree HeapSize RtlUnwind LCMapStringW LCMapStringA GetStringTypeW GetCurrentProcess GetDiskFreeSpaceA TerminateProcess MultiByteToWideChar GetStringTypeA GetModuleHandleA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId GetLastError InterlockedDecrement ExitProcess HeapFree HeapAlloc GetCommandLineA GetVersionExA GetProcessHeap GetStartupInfoA DeleteCriticalSection LeaveCriticalSection EnterCriticalSection GetCPInfo GetACP GetOEMCP Sleep WriteFile GetStdHandle InitializeCriticalSection HeapDestroy HeapCreate VirtualFree VirtualAlloc HeapReAlloc FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemTimeAsFileTime GetLocaleInfoA |
|---|---|
| USER32.dll |
TranslateMessage
DispatchMessageA PeekMessageA wsprintfA LoadCursorA SetCursor MessageBoxA MsgWaitForMultipleObjects |
| ADVAPI32.dll |
GetTokenInformation
OpenProcessToken |
| SHELL32.dll |
ShellExecuteExA
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 8.1.1000.0 |
| ProductVersion | 8.1.1000.0 |
| FileFlags |
VS_FF_PRIVATEBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | Created with Setup Factory 8.0 |
| FileDescription | Setup Application |
| FileVersion (#2) | 8.1.1000.0 |
| InternalName | suf80_launch |
| LegalCopyright | Setup Engine Copyright © 2004-2008 Indigo Rose Corporation |
| LegalTrademarks | Setup Factory is a trademark of Indigo Rose Corporation. |
| OriginalFilename | suf80_launch.exe |
| ProductName | Setup Factory 8.0 Runtime |
| ProductVersion (#2) | 8.1.1000.0 |
| Resource LangID | English - United States |
|---|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x40b020 |
| SEHandlerTable | 0x409d40 |
| SEHandlerCount | 3 |
| XOR Key | 0x45d0d24e |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 16 |
| Imports (VS2003 (.NET) build 4035) | 9 |
| Total imports | 106 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 74 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 31 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |
No comments yet.