Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2017-Jan-11 23:57:05 |
Detected languages |
English - United States
|
FileVersion | 1.0.0.17 |
ProductVersion | 1.0.0.17 |
FileDescription | Kaspersky Uninstall, Teamviewer Install |
CompanyName | SAR Elektronic GmbH |
LegalCopyright | tw/sar |
ProductName | TV_install_exe |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. | 15631 bytes of data starting at offset 0x13000. |
Malicious | The program tries to mislead users about its origins. | The PE pretends to be from Kaspersky but is not signed! |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2017-Jan-11 23:57:05 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xe000 |
SizeOfInitializedData | 0x4000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00007BE6 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xf000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb12000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x19a63 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetTempPathA
GetModuleFileNameA GetStdHandle Sleep SetConsoleCursorInfo SetConsoleCursorPosition SetConsoleTextAttribute GetTickCount GetVolumeInformationA GetConsoleMode ExitProcess TerminateProcess GetCurrentProcess GetCommandLineA GetVersion SetHandleCount GetFileType GetStartupInfoA GetLastError ReadFile SetFilePointer HeapFree CloseHandle GetFileAttributesA GetProcAddress GetModuleHandleA WriteFile UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree RtlUnwind HeapAlloc SetStdHandle FlushFileBuffers VirtualAlloc HeapReAlloc CreateFileA GetExitCodeProcess WaitForSingleObject CreateProcessA MultiByteToWideChar GetStringTypeA GetStringTypeW GetCPInfo GetACP GetOEMCP LoadLibraryA SetEndOfFile CompareStringA CompareStringW SetEnvironmentVariableA LCMapStringA LCMapStringW WriteConsoleA ReadConsoleInputA SetConsoleMode |
---|---|
WINMM.dll |
timeGetTime
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.17 |
ProductVersion | 1.0.0.17 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | UNKNOWN |
FileVersion (#2) | 1.0.0.17 |
ProductVersion (#2) | 1.0.0.17 |
FileDescription | Kaspersky Uninstall, Teamviewer Install |
CompanyName | SAR Elektronic GmbH |
LegalCopyright | tw/sar |
ProductName | TV_install_exe |
Resource LangID | UNKNOWN |
---|
XOR Key | 0x99506f88 |
---|---|
Unmarked objects | 0 |
12 (7291) | 2 |
C++ objects (VS98 build 8168) | 1 |
14 (7299) | 15 |
19 (8034) | 5 |
Total imports | 66 |
C objects (VS98 build 8168) | 95 |
Resource objects (VS98 cvtres build 1720) | 1 |