| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2008-Mar-14 01:42:55 |
| Detected languages |
English - United States
|
| FileDescription | QuickSFV Application |
| FileVersion | 2, 3, 6, 0 |
| InternalName | QuickSFV |
| LegalCopyright | Copyright (C) 2008 |
| OriginalFilename | QuickSFV.exe |
| ProductName | QuickSFV Application |
| ProductVersion | 2, 3, 6, 0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .text2 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 4/72 (Scanned on 2026-02-21 21:53:35) |
APEX:
Malicious
Jiangmin: Packed.Krap.gwhv MaxSecure: Trojan.Malware.331160341.susgen Webroot: W32.Malware.Gen |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2008-Mar-14 01:42:55 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 9.0 |
| SizeOfCode | 0x12600 |
| SizeOfInitializedData | 0x6a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000A6DC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x15000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x82f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x22ba8 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| COMCTL32.dll |
ImageList_Add
ImageList_Create #17 ImageList_GetImageCount |
|---|---|
| KERNEL32.dll |
FindNextFileA
FindFirstFileA GetLastError CreateFileA WaitForMultipleObjects ReadFile MapViewOfFile CreateThread CreateEventA CreateSemaphoreA GetVersionExA WriteFile CreateDirectoryA GetCurrentDirectoryA SetEndOfFile SetFilePointer DeleteFileA WritePrivateProfileStringA GlobalUnlock GlobalLock FreeLibrary GetProcAddress LoadLibraryA GetPrivateProfileStringA VirtualAlloc InitializeCriticalSection DeleteCriticalSection LeaveCriticalSection VirtualFree EnterCriticalSection WideCharToMultiByte GetFileTime Sleep ResetEvent SetCurrentDirectoryA GetTickCount GetSystemTimeAsFileTime GetModuleFileNameA HeapSize WriteConsoleW GetConsoleOutputCP WriteConsoleA LocalFree InitializeCriticalSectionAndSpinCount FindClose GetLocaleInfoA GetStringTypeW GetStringTypeA FlushFileBuffers GetConsoleMode GetConsoleCP SetStdHandle GetCurrentProcessId QueryPerformanceCounter GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA LCMapStringW MultiByteToWideChar LCMapStringA ExitProcess HeapCreate HeapReAlloc RtlUnwind GetFileType GetStdHandle SetHandleCount GetCurrentThreadId SetLastError TlsFree TlsSetValue TlsAlloc TlsGetValue GetModuleHandleW IsValidCodePage GetOEMCP GetACP InterlockedDecrement InterlockedIncrement GetCPInfo HeapFree IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess GetStartupInfoA GetCommandLineA GetFileSize CreateFileMappingA ReleaseSemaphore UnmapViewOfFile SetEvent WaitForSingleObject CloseHandle LocalAlloc lstrlenA lstrcpyA GlobalAlloc GlobalFree HeapAlloc MoveFileA |
| USER32.dll |
EndPaint
SetWindowLongA DefWindowProcA WindowFromPoint KillTimer GetParent SetTimer GetDesktopWindow IsWindow SetWindowTextA MsgWaitForMultipleObjects PeekMessageA TranslateMessage DispatchMessageA LoadIconA RegisterClassA LoadMenuA SetWindowPlacement LoadBitmapA AppendMenuA ReleaseCapture EnableMenuItem GetCursorPos TrackPopupMenu SetCapture CallWindowProcA PostMessageA OpenClipboard EmptyClipboard SetClipboardData CloseClipboard GetSystemMenu CheckMenuItem DialogBoxParamA GetWindowPlacement MoveWindow GetSysColor MessageBeep InvalidateRect SetFocus GetMenu EndDialog GetSystemMetrics GetDlgItemTextA GetDlgItem ShowWindow DestroyWindow DestroyMenu wvsprintfA GetWindowRect SendMessageA wsprintfA MessageBoxA GetDC ReleaseDC CreateWindowExA GetClientRect LoadCursorA RegisterClassExA UnregisterClassA GetWindowLongA BeginPaint CreatePopupMenu |
| GDI32.dll |
MoveToEx
LineTo SetBkColor TextOutA CreateFontA GetTextExtentPoint32A SetTextColor SetBkMode SelectObject ExtTextOutA DeleteObject GetStockObject |
| COMDLG32.dll |
GetOpenFileNameA
CommDlgExtendedError |
| SHELL32.dll |
SHBrowseForFolderA
ShellExecuteA SHGetPathFromIDListA SHGetMalloc |
| ole32.dll |
CoUninitialize
CoInitialize |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.3.6.0 |
| ProductVersion | 2.3.6.0 |
| FileFlags | (EMPTY) |
| FileOs | (EMPTY) |
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | QuickSFV Application |
| FileVersion (#2) | 2, 3, 6, 0 |
| InternalName | QuickSFV |
| LegalCopyright | Copyright (C) 2008 |
| OriginalFilename | QuickSFV.exe |
| ProductName | QuickSFV Application |
| ProductVersion (#2) | 2, 3, 6, 0 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0xf9407ce5 |
|---|---|
| Unmarked objects | 0 |
| Unmarked objects (#2) | 3 |
| 150 (20413) | 2 |
| C++ objects (VS2008 build 21022) | 36 |
| ASM objects (VS2008 build 21022) | 19 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 15 |
| Total imports | 208 |
| C objects (VS2008 build 21022) | 123 |
| Linker (VS2008 build 21022) | 1 |
| Resource objects (VS2008 build 21022) | 1 |