Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2015-May-08 17:12:51 |
Detected languages |
Chinese - PRC
|
Debug artifacts |
Embedded COFF debugging symbols
|
Info | Matching compiler(s): | MASM/TASM - sig2(h) |
Suspicious | The PE is possibly packed. |
Unusual section name found: /text
Unusual section name found: .tdata Unusual section name found: .idata\xa4 Unusual section name found: .rsrc\x00\xff Unusual section name found: .r\x8aloc |
Info | The PE contains common functions which appear in legitimate applications. |
Can access the registry:
|
Info | The PE's resources present abnormal characteristics. | Resource 128 is possibly compressed or encrypted. |
Suspicious | The file contains overlay data. |
47658 bytes of data starting at offset 0xd000.
The overlay data has an entropy of 7.95478 and is possibly compressed or encrypted. |
Malicious | VirusTotal score: 32/56 (Scanned on 2015-05-30 08:39:57) |
Bkav:
W32.SympaiY.Trojan
MicroWorld-eScan: Trojan.Inject.AWW nProtect: Trojan.Inject.AWW Malwarebytes: Trojan.Inject K7GW: Trojan ( 004c388b1 ) K7AntiVirus: Trojan ( 004c388b1 ) NANO-Antivirus: Trojan.Win32.Winlock.dsfnau Symantec: WS.Reputation.1 ESET-NOD32: a variant of Win32/Injector.CBQB TrendMicro-HouseCall: Suspicious_GEN.F47V0528 Avast: Win32:Malware-gen Kaspersky: Trojan.Win32.Inject.uubl BitDefender: Trojan.Inject.AWW Tencent: Trojan.Win32.YY.Gen.0 Ad-Aware: Trojan.Inject.AWW Emsisoft: Trojan.Inject.AWW (B) F-Secure: Trojan.Inject.AWW DrWeb: Trojan.Winlock.12151 VIPRE: Trojan.Win32.Generic!BT Jiangmin: Backdoor/Hlux.hug Avira: TR/Crypt.Xpack.241160 Antiy-AVL: Trojan/Win32.TSGeneric Microsoft: VirTool:Win32/CeeInject.gen!KK GData: Trojan.Inject.AWW ALYac: Trojan.Inject.AWW AVware: Trojan.Win32.Generic!BT Baidu-International: Trojan.Win32.Injector.CBQB Ikarus: Trojan.Win32.Injector Fortinet: W32/CBQB!tr AVG: Inject2.CFME Panda: Trj/Genetic.gen Qihoo-360: Win32/Trojan.BO.9cb |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2015-May-08 17:12:51 |
PointerToSymbolTable | 0x60000 |
NumberOfSymbols | 234881024 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 1.0 |
SizeOfCode | 0x6001 |
SizeOfInitializedData | 0x6000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005D76 (Section: /text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | D.9 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xd000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_LIBRARY_PROCESS_INIT
IMAGE_LIBRARY_PROCESS_TERM
IMAGE_LIBRARY_THREAD_INIT
IMAGE_LIBRARY_THREAD_TERM
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1001 |
LoaderFlags | 0x600 |
NumberOfRvaAndSizes | 16 |
MFC42u.DLL |
#6051
#4072 #1768 #4401 #5233 #2374 #5157 #6370 #4347 #5279 #2641 #1658 #3793 #4831 #4430 #2640 #2047 #6372 #3744 #5059 #1720 #2437 #2116 #5273 #2977 #3142 #3254 #4459 #3131 #3257 #2980 #3076 #2971 #3825 #3826 #3820 #3074 #4075 #4621 #4421 #401 #674 #5250 #825 #823 #4606 #4604 #4269 #6371 #4480 #2546 #2504 #5727 #3917 #1089 #5193 #2388 #3341 #5296 #5298 #2717 #4074 #4692 #5303 #5285 #5710 #4616 #4418 #3733 #561 #815 #6211 #617 #5297 #5208 #296 #986 #411 #4154 #6113 #2613 #1131 #5261 #4370 #4847 #4992 #4704 #2506 #6048 #4073 #1767 #5237 #2377 #5276 #4435 #5257 #2438 #4419 #3592 #324 #641 #4229 #1817 #4233 #4690 #3053 #3060 #6332 #2502 #2534 #5239 #5736 #1739 #5573 #4147 #5649 #4414 #4947 #2391 #4381 #3449 #3193 #6076 #6171 #4617 #4420 #652 #338 #4817 #4852 #2879 #1165 #1912 #4257 #4583 #4582 #4893 #4364 #4886 #5070 #4335 #4343 #4883 #4525 #4539 #4537 #4520 #4523 #4518 #4957 #4954 #4103 #5236 #5286 #3743 #1718 #4426 #784 #517 #5256 #5673 #6127 #6212 #4717 #800 #616 #2078 #1971 #3313 #5769 #5438 #665 #5180 #354 #6381 #540 #2294 #3312 #613 #283 #289 #755 #470 #3568 #3621 #2406 #3658 #2854 #2403 #2015 #4213 #2570 #4392 #3397 #3577 #567 #4128 #4292 #1851 #4241 #3864 #2119 #2383 #5096 #5099 #4462 #3345 #975 #2875 #4148 #2375 #5280 #4431 #4422 #796 #554 #529 #402 #807 #2486 #2619 #2618 #5996 #2109 #6617 #4451 #5251 #4158 #2873 #2874 #3398 #5468 #976 #5006 #3346 #4298 #4461 #5098 #5094 #3054 #2382 #2715 #2093 #5095 #4240 #3167 #1850 #1569 |
---|---|
MSVCRT.dll |
_onexit
__dllonexit _except_handler3 __set_app_type __p__fmode __p__commode _adjust_fdiv __setusermatherr _initterm __wgetmainargs __CxxFrameHandler _ftol sqrt fabs rand _controlfp _exit _XcptFilter exit _wcmdln |
KERNEL32.dll |
GetStartupInfoW
GetModuleHandleW GetVersionExA WaitForSingleObject FindNextFileA HeapDestroy WriteFile ExitProcess FreeEnvironmentStringsA |
USER32.dll |
CreateWindowExA
SetClassLongA InsertMenuW GetMessageTime SendMessageW FillRect InvalidateRect GetClientRect EnableWindow UpdateWindow GetDC |
GDI32.dll | (EMPTY) |
ADVAPI32.dll |
RegCreateKeyW
|