Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Sep-09 21:39:00 |
Detected languages |
English - United States
|
CompanyName | Tous Les Drivers |
FileDescription | Mes Drivers |
FileVersion | 3. 0. 4. 0 |
InternalName | |
LegalCopyright | Copyright © 2016 Tous Les Drivers - Tous droits réservés |
LegalTrademarks | |
OriginalFilename | |
ProductName | Mes Drivers |
ProductVersion | 3. 0. 4. 0 |
Comments |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to RC5 or RC6 |
Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE is possibly a dropper. |
Resource RC_SCRIPT is possibly compressed or encrypted.
Resources amount for 76.6289% of the executable. |
Info | The PE is digitally signed. |
Signer: Tous Les Drivers
Issuer: COMODO Code Signing CA 2 |
Malicious | VirusTotal score: 12/72 (Scanned on 2020-07-08 13:33:09) |
FireEye:
Generic.mg.50a5e891da27e63d
Sangfor: Malware APEX: Malicious Rising: Trojan.Wacatac!8.10C01 (RDMK:cmRtazq1Wxlgo7KwYOEaUtOojc4V) Zillya: Trojan.Generic.Win32.145 Invincea: heuristic Jiangmin: Trojan.Agent.asds Webroot: W32.Adware.Gen VBA32: Trojan.MulDrop Ikarus: Trojan-Ransom.FileCrypter eGambit: Unsafe.AI_Score_99% MaxSecure: Trojan.Malware.11973.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2016-Sep-09 21:39:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x55a00 |
SizeOfInitializedData | 0x133c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0005678C (Section: .itext) |
BaseOfCode | 0x1000 |
BaseOfData | 0x57000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x19f000 |
SizeOfHeaders | 0x400 |
Checksum | 0x18d8a0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
---|---|
advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
user32.dll |
MessageBoxA
CharNextW LoadStringW |
kernel32.dll |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
kernel32.dll (#2) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
user32.dll (#2) |
MessageBoxA
CharNextW LoadStringW |
version.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
kernel32.dll (#3) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
ole32.dll |
CreateBindCtx
CoTaskMemFree CLSIDFromProgID StringFromCLSID CoCreateInstance CoLockObjectExternal CoDisconnectObject CoRevokeClassObject CoRegisterClassObject CoUninitialize CoInitialize IsEqualGUID |
kernel32.dll (#4) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
URLMON.DLL |
MkParseDisplayNameEx
|
shell32.dll |
SHGetSpecialFolderPathW
|
kernel32.dll (delay-loaded) |
Sleep
VirtualFree VirtualAlloc lstrlenW lstrcpynW VirtualQuery GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess GetCurrentThreadId DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
Attributes | 0x1 |
---|---|
Name | kernel32.dll |
ModuleHandle | 0x62060 |
DelayImportAddressTable | 0x6206c |
DelayImportNameTable | 0x62088 |
BoundDelayImportTable | 0x620a4 |
UnloadDelayImportTable | 0x620b8 |
TimeStamp | 1970-Jan-01 00:00:00 |
Demo Version |
The object does not implement the observer interface |
Error creating system registry entry |
OLE error %.8x |
Object factory for class %s missing |
Type information missing for class %s |
Incorrect type information for class %s |
Dispatch interface missing from class %s |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
Dispatch methods do not support more than 64 parameters |
DAX Error |
COM Server Warning |
There are still active COM objects in this application. One or more clients may have references to these objects, so manually closing |
this application may cause those client application(s) to fail. |
Are you sure you want to close this application? |
Error: %s |
Line: %d |
Position: %d |
%s |
This program created with Unregistered version of ScriptCryptor. |
Please register your copy to remove this window. |
Visit http://www.abyssmedia.com for details. |
''%s'' is not a valid integer value |
%s (Version %d.%d, Build %d, %5:s) |
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
32-bit Edition |
64-bit Edition |
Windows |
Windows Vista |
Windows Server 2008 |
Windows 7 |
Windows Server 2008 R2 |
Windows 2000 |
Windows XP |
Windows Server 2003 |
Windows Server 2003 R2 |
Observer is not supported |
Cannot have multiple single cast observers added to the observers collection |
Invalid property path |
Invalid property value |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
%s has not been registered as a COM class |
Error reading %s%s%s: %s |
Stream read error |
Property is read-only |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
Property %s does not exist |
Stream write error |
The specified file was not found |
Start index out of bounds (%d) |
Invalid count (%d) |
Invalid destination index (%d) |
Invalid code page |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Can't write to a read-only resource stream |
Class %s not found |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file "%s". %s |
Cannot open file "%s". %s |
Invalid file name - %s |
''%s'' is not a valid component name |
Invalid property value |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Invalid source array |
Invalid destination array |
Character index out of bounds (%d) |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
December |
Sun |
Monitor support function not initialized |
Feature not implemented |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Aug |
Sep |
Invalid variant type conversion |
Invalid variant operation |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
Object lock not owned |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
'%d.%d' is not a valid timestamp |
Out of memory |
I/O error %d |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.0.4.0 |
ProductVersion | 3.0.4.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
CompanyName | Tous Les Drivers |
FileDescription | Mes Drivers |
FileVersion (#2) | 3. 0. 4. 0 |
InternalName | |
LegalCopyright | Copyright © 2016 Tous Les Drivers - Tous droits réservés |
LegalTrademarks | |
OriginalFilename | |
ProductName | Mes Drivers |
ProductVersion (#2) | 3. 0. 4. 0 |
Comments |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0x463000 |
---|---|
EndAddressOfRawData | 0x463010 |
AddressOfIndex | 0x457c04 |
AddressOfCallbacks | 0x464010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |