Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Oct-01 09:06:16 |
Detected languages |
English - United States
|
FileDescription | INF Scanner Installer |
FileVersion | 1.00.71 |
InternalName | wiainst |
Comments | Developed by Dmitry E. Smirnov |
OriginalFilename | wiainst.exe |
ProductName | INF Scanner Installer |
ProductVersion | 1.00.71 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Samsung Electronics CO.
Issuer: VeriSign Class 3 Code Signing 2004 CA |
Safe | VirusTotal score: 0/66 (Scanned on 2017-12-27 17:14:25) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 5 |
TimeDateStamp | 2010-Oct-01 09:06:16 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32+ |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0x15e00 |
SizeOfInitializedData | 0xb400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000000A160 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x26000 |
SizeOfHeaders | 0x400 |
Checksum | 0x293cf |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
---|---|
SETUPAPI.dll |
SetupCloseInfFile
SetupGetStringFieldA SetupFindFirstLineA SetupGetLineByIndexA SetupGetIntField SetupGetLineCountA SetupGetSourceInfoA SetupGetSourceFileLocationA SetupSetDirectoryIdA SetupOpenAppendInfFileA SetupOpenInfFileA SetupCloseFileQueue SetupInstallFromInfSectionA SetupInstallServicesFromInfSectionA SetupTermDefaultQueueCallback SetupDiGetClassDevsA SetupDiEnumDeviceInfo SetupDiGetDeviceRegistryPropertyA SetupDiGetINFClassA SetupDiCreateDeviceInfoList SetupDiCreateDeviceInfoA SetupDiSetDeviceRegistryPropertyA SetupDiCallClassInstaller SetupDiRemoveDevice SetupDiDestroyDeviceInfoList SetupOpenFileQueue SetupInstallFilesFromInfSectionA SetupScanFileQueueA SetupInitDefaultQueueCallbackEx SetupDefaultQueueCallbackA SetupCommitFileQueueA |
COMCTL32.dll |
#17
|
KERNEL32.dll |
InitializeCriticalSection
HeapSize GetLocaleInfoA EnterCriticalSection HeapReAlloc GetStringTypeW GetStringTypeA LCMapStringW LCMapStringA GetSystemTimeAsFileTime GetCurrentProcessId GetTickCount QueryPerformanceCounter HeapCreate LeaveCriticalSection lstrcpyA GetVersionExA lstrlenA CreateFileA GetTempPathA CloseHandle FormatMessageA WriteFile GetLastError GetTimeFormatA GetLocalTime CreateDirectoryA GetFileAttributesA ReadFile LoadLibraryA DeleteFileA FreeLibrary GetModuleFileNameA RemoveDirectoryA FindClose FindNextFileA FindFirstFileA lstrcmpiA lstrcatA GetFullPathNameA CreateProcessA LocalFree GetCurrentProcess WaitForSingleObject LocalAlloc Sleep GetShortPathNameA CompareFileTime GetFileTime GetWindowsDirectoryA GetSystemDirectoryA WritePrivateProfileSectionA GetPrivateProfileSectionA SetFileAttributesA MultiByteToWideChar CopyFileA GetModuleHandleA HeapSetInformation DeleteCriticalSection GetFileType SetHandleCount GetEnvironmentStringsW WideCharToMultiByte FreeEnvironmentStringsW GetEnvironmentStrings SetFilePointer SetStdHandle GetConsoleCP GetConsoleMode WriteConsoleW FlushFileBuffers WriteConsoleA GetConsoleOutputCP GetProcAddress FreeEnvironmentStringsA GetStdHandle ExitProcess RtlPcToFileHeader RaiseException FlsAlloc GetCurrentThreadId SetLastError RtlLookupFunctionEntry RtlUnwindEx GetCommandLineA HeapFree HeapAlloc GetProcessHeap GetStartupInfoA TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RtlVirtualUnwind RtlCaptureContext GetCPInfo GetACP GetOEMCP IsValidCodePage FlsGetValue FlsSetValue TlsFree FlsFree |
USER32.dll |
LoadStringA
wsprintfA MessageBoxA wvsprintfA |
WINSPOOL.DRV |
GetPrinterDriverDirectoryA
GetPrintProcessorDirectoryA |
ADVAPI32.dll |
RegOpenKeyExA
ChangeServiceConfig2A RegEnumKeyExA GetLengthSid RegDeleteKeyExA RegDeleteValueA RegEnumValueA RegDeleteKeyA RegSetValueExA RegCreateKeyExA RegQueryValueExA RegCloseKey |
SHELL32.dll |
SHFileOperationA
SHGetFolderPathA |
ole32.dll |
CoInitializeEx
CoCreateInstance CoUninitialize |
OLEAUT32.dll |
#2
#6 |
Program usage: |
>wiainst.exe [/h] [/?] |
>wiainst.exe InfPath [/iN] [/mManufacturer] [/w] |
>wiainst.exe /uScannerName [/mManufacturer] [/p] |
InfPath - INF filename (with path if needed) |
/mManufacturer - manufacturer |
/iN - index of scanner in INF file |
/w - overwrite files |
/d - delayed file copying (WinNT+) |
/x - non-device installation (USD driver) |
/r - restart STI service |
/lLanguage - current language suffix |
/uScannerName - uninstall scanner |
/p - remove pre-installed files |
/h, /? - show syntax |
Please refer to LOG file created: |
INF Scanner Installer - version |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.71.0 |
ProductVersion | 1.0.71.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | INF Scanner Installer |
FileVersion (#2) | 1.00.71 |
InternalName | wiainst |
Comments | Developed by Dmitry E. Smirnov |
OriginalFilename | wiainst.exe |
ProductName | INF Scanner Installer |
ProductVersion (#2) | 1.00.71 |
Resource LangID | English - United States |
---|
XOR Key | 0x18e93aba |
---|---|
Unmarked objects | 0 |
ASM objects (VS2012 build 50727 / VS2005 build 50727) | 8 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 90 |
Imports (40310) | 21 |
Total imports | 178 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 48 |
Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |