Architecture |
Subsystem |
Compilation Date | 2006-Mar-04 17:05:21 |
Detected languages |
English - United States
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
Suspicious | The PE is an NSIS installer | Unusual section name found: .ndata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
Suspicious | The file contains overlay data. |
2148468 bytes of data starting at offset 0xdc00.
The overlay data has an entropy of 7.99991 and is possibly compressed or encrypted. Overlay data amounts for 97.4456% of the executable. |
Malicious | VirusTotal score: 3/72 (Scanned on 2024-07-23 19:29:42) |
win/grayware_confidence_60% (D)
Google: Detected Kingsoft: malware.kb.a.871 |
e_magic | MZ |
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
Machine |
NumberofSections | 5 |
TimeDateStamp | 2006-Mar-04 17:05:21 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
Magic | PE32 |
LinkerVersion | 6.0 |
SizeOfCode | 0x5a00 |
SizeOfInitializedData | 0x1d800 |
SizeOfUninitializedData | 0x400 |
AddressOfEntryPoint | 0x0000313E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x37000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
SetFileTime CompareFileTime SearchPathA GetShortPathNameA GetFullPathNameA MoveFileA SetCurrentDirectoryA GetFileAttributesA GetLastError CreateDirectoryA SetFileAttributesA Sleep GetFileSize GetModuleFileNameA GetTickCount GetCurrentProcess lstrcmpiA ExitProcess GetCommandLineA GetWindowsDirectoryA GetTempPathA lstrcpynA GetDiskFreeSpaceA GlobalUnlock GlobalLock CreateThread CreateProcessA RemoveDirectoryA CreateFileA GetTempFileNameA lstrlenA lstrcatA GetSystemDirectoryA lstrcmpA GetEnvironmentVariableA ExpandEnvironmentStringsA GlobalFree GlobalAlloc WaitForSingleObject GetExitCodeProcess SetErrorMode GetModuleHandleA LoadLibraryA GetProcAddress FreeLibrary MultiByteToWideChar WritePrivateProfileStringA GetPrivateProfileStringA WriteFile ReadFile MulDiv SetFilePointer FindClose FindNextFileA FindFirstFileA DeleteFileA CopyFileA |
USER32.dll |
GetWindowRect SetClassLongA IsWindowEnabled SetWindowPos GetSysColor GetWindowLongA SetCursor LoadCursorA CheckDlgButton GetMessagePos LoadBitmapA CallWindowProcA IsWindowVisible CloseClipboard SetClipboardData EmptyClipboard OpenClipboard EndDialog AppendMenuA CreatePopupMenu GetSystemMetrics SetDlgItemTextA GetDlgItemTextA MessageBoxA CharPrevA DispatchMessageA PeekMessageA CreateDialogParamA DestroyWindow SetTimer SetWindowTextA PostQuitMessage SetForegroundWindow wsprintfA SendMessageTimeoutA FindWindowExA RegisterClassA SystemParametersInfoA CreateWindowExA GetClassInfoA DialogBoxParamA CharNextA TrackPopupMenu ExitWindowsEx IsWindow GetDlgItem SetWindowLongA LoadImageA GetDC EnableWindow InvalidateRect SendMessageA DefWindowProcA BeginPaint GetClientRect FillRect DrawTextA EndPaint ShowWindow |
GDI32.dll |
GetDeviceCaps DeleteObject CreateBrushIndirect CreateFontIndirectA SetBkMode SetTextColor SelectObject |
SHELL32.dll |
SHGetPathFromIDListA SHBrowseForFolderA SHGetFileInfoA ShellExecuteA SHFileOperationA SHGetSpecialFolderLocation |
ADVAPI32.dll |
RegSetValueExA RegEnumKeyA RegEnumValueA RegOpenKeyExA RegDeleteKeyA RegDeleteValueA RegCloseKey RegCreateKeyExA |
COMCTL32.dll |
ImageList_Destroy #17 ImageList_Create |
ole32.dll |
OleUninitialize CoCreateInstance |
GetFileVersionInfoA VerQueryValueA |
XOR Key | 0xfb240da1 |
Unmarked objects | 0 |
C objects (2190) | 2 |
Total imports | 152 |
Imports (2179) | 17 |
48 (9044) | 9 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |