Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Feb-29 07:18:28 |
Detected languages |
English - United States
|
Debug artifacts |
h:\Build\BestCrypt\2016.02.29_BC_9.02.9_BCFNT_v.2.84\Projects\WinExe\Release\BCWipe.pdb
|
CompanyName | Jetico |
FileDescription | BCWipe command line utility. |
FileVersion | 3.10.6 |
InternalName | BCWipe.exe |
LegalCopyright | Copyright © 1997-2015 |
OriginalFilename | BCWipe.exe |
ProductName | BCWipe.exe |
ProductVersion | 3.10.6 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE's digital signature is invalid. |
Signer: Jetico Inc. Oy
Issuer: DigiCert SHA2 High Assurance Code Signing CA The file was modified after it was signed. |
Safe | VirusTotal score: 0/70 (Scanned on 2019-11-16 17:07:24) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2016-Feb-29 07:18:28 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x48400 |
SizeOfInitializedData | 0x61400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000227EB (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x4a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xad000 |
SizeOfHeaders | 0x400 |
Checksum | 0xb43d4 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA VerQueryValueW GetFileVersionInfoW GetFileVersionInfoSizeW |
---|---|
KERNEL32.dll |
SetFilePointer
CreateFileA ReadFile SetEndOfFile VirtualFree VirtualAlloc GetFileSize GetWindowsDirectoryW IsBadStringPtrW SetLastError GetVersionExA CreateThread DuplicateHandle GetCurrentThread SetErrorMode FindClose FindNextFileW Sleep GetFullPathNameW GetExitCodeThread CreateDirectoryW GetTempPathW GetVolumeInformationW GetLongPathNameW GetCurrentDirectoryW GetLocaleInfoA FileTimeToSystemTime FileTimeToLocalFileTime FindFirstFileA DeviceIoControl GetTimeFormatW GetDateFormatW GetLocalTime GetModuleHandleA CreateFileW GetFileAttributesW FindFirstFileW CopyFileW SetFileAttributesW DeleteFileW MoveFileExW GetShortPathNameW GetFileInformationByHandle GetLogicalDrives FormatMessageW GetFileAttributesExW RemoveDirectoryW GetCompressedFileSizeW GetExitCodeProcess ResumeThread CreateProcessW CreateDirectoryExW SetFileTime GetCommandLineW GetDriveTypeW GetLogicalDriveStringsW GetCurrentThreadId HeapAlloc HeapFree WriteFile InitializeCriticalSection DeleteCriticalSection GetComputerNameW GetDiskFreeSpaceW GlobalFree GlobalAlloc RtlUnwind GetFileAttributesA GetSystemTimeAsFileTime GetModuleHandleW ExitProcess GetCommandLineA GetStartupInfoA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement InterlockedDecrement TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent RaiseException HeapSize HeapCreate HeapDestroy FatalAppExitA GetSystemInfo GetStdHandle GetCPInfo GetACP GetOEMCP IsValidCodePage LCMapStringA LCMapStringW GetTimeZoneInformation SetConsoleCtrlHandler InterlockedExchange InitializeCriticalSectionAndSpinCount FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType QueryPerformanceCounter GetTickCount GetStringTypeA GetStringTypeW GetTimeFormatA GetDateFormatA GetUserDefaultLCID EnumSystemLocalesA IsValidLocale GetConsoleCP GetConsoleMode GetLocaleInfoW SetStdHandle WriteConsoleA GetConsoleOutputCP WriteConsoleW CompareStringA CompareStringW SetEnvironmentVariableA ExpandEnvironmentStringsA UnmapViewOfFile MapViewOfFile CreateFileMappingA WideCharToMultiByte MultiByteToWideChar LeaveCriticalSection EnterCriticalSection ReleaseSemaphore WaitForSingleObject OpenSemaphoreW FreeLibrary LoadLibraryExW LoadLibraryExA LoadLibraryA GetModuleFileNameA GetCurrentProcessId OpenProcess CreateSemaphoreW CreateMutexW LocalAlloc CreateNamedPipeW LocalFree GetCurrentProcess FlushFileBuffers CloseHandle GetModuleFileNameW GetVersion GetLastError GetProcAddress GetProcessHeap HeapReAlloc |
USER32.dll |
GetActiveWindow
SetWindowPos LoadStringA GetParent FindWindowW PostMessageA FindWindowExA LoadStringW SetDlgItemTextW GetWindowTextLengthW LoadImageA GetDlgItemTextW GetWindowTextA GetDlgItem GetDesktopWindow MessageBoxW GetWindowLongW SetWindowLongW SetClassLongW SendMessageA GetDC DrawTextW GetMenuItemInfoW GetMenuItemID GetMenuState ModifyMenuW SendMessageW GetWindowTextW IsWindow PeekMessageA TranslateMessage DispatchMessageW LoadCursorA SetCursor ExitWindowsEx MessageBoxA |
GDI32.dll |
CreateCompatibleBitmap
BitBlt ExtTextOutW DeleteObject SelectObject CreateCompatibleDC |
COMDLG32.dll |
CommDlgExtendedError
GetSaveFileNameW GetOpenFileNameW |
ADVAPI32.dll |
FreeSid
RegDeleteKeyA RegDeleteKeyW RegOpenKeyExA RegQueryValueExA RegCreateKeyExW AdjustTokenPrivileges LookupPrivilegeValueA OpenProcessToken RegSetValueExA RegDeleteValueA OpenThreadToken DuplicateTokenEx RevertToSelf ImpersonateNamedPipeClient RegCloseKey RegSetValueExW RegDeleteValueW RegOpenKeyExW RegQueryValueExW DecryptFileW RegEnumValueW RegEnumKeyExW RegQueryInfoKeyA SetThreadToken RegCreateKeyW |
SHELL32.dll |
SHGetPathFromIDListW
SHBrowseForFolderW SHGetSpecialFolderLocation #155 SHGetFileInfoW SHGetFolderLocation ShellExecuteExW SHGetSpecialFolderPathA ShellExecuteW SHGetDesktopFolder SHGetMalloc |
BCWipe command line utility |
Help hile is not found in current location. |
Do you want to browse it in another folders right now? |
Choose drive for free space wiping |
Choose help file |
HTML Help files (*.chm) |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.10.6.0 |
ProductVersion | 3.10.6.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Jetico |
FileDescription | BCWipe command line utility. |
FileVersion (#2) | 3.10.6 |
InternalName | BCWipe.exe |
LegalCopyright | Copyright © 1997-2015 |
OriginalFilename | BCWipe.exe |
ProductName | BCWipe.exe |
ProductVersion (#2) | 3.10.6 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Feb-29 07:18:28 |
Version | 0.0 |
SizeofData | 112 |
AddressOfRawData | 0x50dc0 |
PointerToRawData | 0x4f5c0 |
Referenced File | h:\Build\BestCrypt\2016.02.29_BC_9.02.9_BCFNT_v.2.84\Projects\WinExe\Release\BCWipe.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x457610 |
SEHandlerTable | 0x4514a0 |
SEHandlerCount | 235 |
XOR Key | 0x57937b89 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
ASM objects (VS2008 SP1 build 30729) | 26 |
C objects (VS2008 SP1 build 30729) | 143 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 15 |
Total imports | 245 |
C++ objects (VS2008 SP1 build 30729) | 88 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |