Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Mar-14 07:29:31 |
Detected languages |
Chinese - PRC
English - United States |
TLS Callbacks | 1 callback(s) detected. |
Debug artifacts |
E:\trunk\CommonPlatform\Helper2345\bin\Win32\Release\pdb\HelperMain.pdb
|
Comments | 2345.com |
CompanyName | 2345移动科技 |
FileDescription | 2345辅助模块 |
FileVersion | 3.2.1.797 |
InternalName | HelperMain |
LegalCopyright | 版权所有 (C) 2019, 2345移动科技 |
OriginalFilename | HelperMain.dll |
ProductName | 2345辅助模块 |
ProductVersion | 3.2.1.797 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Shanghai 2345 Mobile Technology Co.
Issuer: VeriSign Class 3 Code Signing 2010 CA |
Suspicious | VirusTotal score: 1/65 (Scanned on 2019-04-09 11:50:37) | Ikarus: PUA.OpenSUpdater |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x138 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 7 |
TimeDateStamp | 2019-Mar-14 07:29:31 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x2ebe00 |
SizeOfInitializedData | 0xce400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0018019F (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2ed000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x3be000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3b6eca |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
GetFileVersionInfoSizeW
VerQueryValueW GetFileVersionInfoW |
---|---|
KERNEL32.dll |
GetExitCodeProcess
WaitForMultipleObjects GetLongPathNameW GetFileAttributesExW GetFileSize SetFilePointer SetEndOfFile SetFileTime WriteFile ReadFile GetFileTime WideCharToMultiByte GetACP MultiByteToWideChar GetFileAttributesW ExpandEnvironmentStringsW FindResourceW LoadResource GetVersionExW LockResource GetSystemInfo QueryDosDeviceW SetEvent ResetEvent CreateEventW lstrcpyW HeapAlloc HeapFree GetProcessHeap GlobalFree InterlockedExchangeAdd GetFullPathNameW GetTempFileNameW GetSystemDirectoryW CopyFileW GetCurrentDirectoryW RemoveDirectoryW GetWindowsDirectoryW DeleteFileW SetFileAttributesW FindNextFileW GetFileSizeEx GetLogicalDriveStringsW InterlockedExchange FormatMessageW DeviceIoControl GetEnvironmentVariableW LoadLibraryExW SizeofResource CreateWaitableTimerW SetWaitableTimer FreeResource MapViewOfFileEx QueryPerformanceCounter QueryPerformanceFrequency CreateProcessW GetShortPathNameW lstrlenW lstrcpynW FindClose FileTimeToSystemTime SystemTimeToTzSpecificLocalTime FindFirstFileW GetStartupInfoW MoveFileW GetLocalTime GetTempPathW SwitchToThread GetFileInformationByHandle SetEnvironmentVariableA WriteConsoleW SetStdHandle SetFilePointerEx UnregisterWaitEx QueryDepthSList InterlockedFlushSList InterlockedPushEntrySList InterlockedPopEntrySList InitializeSListHead ReleaseSemaphore VirtualProtect VirtualFree VirtualAlloc GetModuleHandleA FreeLibraryAndExitThread GetThreadTimes OutputDebugStringW ReadConsoleW GetTimeZoneInformation FreeEnvironmentStringsW GetEnvironmentStringsW GetModuleFileNameA GetFileType GetOEMCP IsValidCodePage HeapReAlloc GetStdHandle HeapSize AreFileApisANSI GetModuleHandleExW ExitProcess GetConsoleMode GetConsoleCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW UnregisterWait RegisterWaitForSingleObject SetThreadAffinityMask GetProcessAffinityMask GetNumaHighestNodeNumber DeleteTimerQueueTimer ChangeTimerQueueTimer CreateTimerQueueTimer GetLogicalProcessorInformation GetThreadPriority SetThreadPriority SignalObjectAndWait WaitForSingleObjectEx CreateTimerQueue CreateSemaphoreW TlsFree TlsSetValue TlsGetValue TlsAlloc TerminateProcess UnhandledExceptionFilter GetCPInfo RtlUnwind ExitThread CreateThread IsProcessorFeaturePresent IsDebuggerPresent GetCommandLineA GetStringTypeW GetSystemTimeAsFileTime EncodePointer GetCurrentThread DuplicateHandle SuspendThread GetExitCodeThread OpenThread TerminateThread ResumeThread GlobalMemoryStatusEx OpenFileMappingW GetPrivateProfileStringA GetPrivateProfileStringW SetLastError FlushInstructionCache GlobalUnlock lstrcmpW MulDiv GlobalAlloc GlobalLock GetCurrentProcess WriteProcessMemory VirtualAllocEx ReadProcessMemory VirtualFreeEx OpenProcess GetModuleHandleW SetErrorMode lstrcmpiW InterlockedDecrement InterlockedIncrement LocalFree lstrcatW SetUnhandledExceptionFilter GetCommandLineW GetProcAddress CreateFileW LoadLibraryW FreeLibrary DeleteCriticalSection DecodePointer RaiseException InitializeCriticalSectionAndSpinCount CloseHandle GetModuleFileNameW MoveFileExW GetCurrentProcessId ReleaseMutex GetCurrentThreadId CreateFileMappingW EnterCriticalSection GetLastError LeaveCriticalSection Sleep InitializeCriticalSection GetTickCount WaitForSingleObject CreateDirectoryW UnmapViewOfFile MapViewOfFile CreateMutexW LocalAlloc |
USER32.dll |
ValidateRect
SetWindowRgn MapWindowPoints OpenClipboard UnregisterClassW GetWindowThreadProcessId IsWindow GetClassNameW GetWindowTextW GetForegroundWindow IsZoomed GetWindow FindWindowExW GetWindowLongW FindWindowW DefWindowProcW CallWindowProcW RemovePropW SetRectEmpty UpdateLayeredWindow SetRect SetCaretPos MsgWaitForMultipleObjects LoadBitmapW GetAsyncKeyState IsClipboardFormatAvailable EmptyClipboard GetClipboardData SetClipboardData CloseClipboard LoadImageW SetForegroundWindow GetCaretBlinkTime ToAscii GetKeyboardState EnableWindow DrawTextW GetIconInfo SetPropW GetPropW GetMonitorInfoW DrawIconEx CreateWindowExW SetWindowPos SetWindowLongW MonitorFromWindow SetParent GetParent PostMessageW DestroyWindow GetSystemMetrics SendMessageW MonitorFromPoint MoveWindow SetWindowTextW ReleaseCapture GetSysColor GetDesktopWindow RedrawWindow GetDlgItem ReleaseDC InvalidateRect RegisterClassExW GetDC GetClassInfoExW BeginPaint SetFocus CreateAcceleratorTableW GetClientRect LoadCursorW InvalidateRgn GetFocus SetCapture IsChild FillRect RegisterWindowMessageW CharNextW GetWindowRect ScreenToClient DestroyAcceleratorTable GetWindowTextLengthW ClientToScreen EndPaint GetShellWindow MessageBoxW wsprintfW IsWindowVisible GetCursorPos SystemParametersInfoW IntersectRect PtInRect IsIconic GetDCEx GetWindowDC SetCursor CopyRect OffsetRect IsRectEmpty EqualRect EnumChildWindows SetTimer KillTimer GetClassLongW GetMessageW TranslateMessage DispatchMessageW PeekMessageW PostQuitMessage TrackMouseEvent GetKeyState UnionRect ShowWindow ShowWindowAsync |
GDI32.dll |
PtInRegion
GetMapMode SetMapMode CreateRoundRectRgn CreateDCW GetDIBits ExtTextOutW GetClipBox CreateDIBSection EnumFontsW SetBkColor CreateFontIndirectW CreatePolygonRgn CreateRectRgnIndirect SetWorldTransform SetGraphicsMode SetViewportOrgEx GetRgnBox BitBlt GetDeviceCaps DeleteObject SelectObject CreateCompatibleDC CreateCompatibleBitmap GetObjectW GdiFlush GetStockObject CreateSolidBrush GetTextMetricsW SetTextColor EnumFontFamiliesExW GetCharABCWidthsW GetFontData GetGlyphOutlineW GetOutlineTextMetricsW GetFontUnicodeRanges GetGlyphIndicesW GetTextExtentPointI AddFontMemResourceEx RemoveFontMemResourceEx SetBkMode SetTextAlign GetTextFaceW DeleteDC |
ADVAPI32.dll |
QueryServiceConfigW
RegSetValueExW RegQueryInfoKeyW RegOpenKeyExW RegEnumKeyExW RegDeleteValueW RegDeleteKeyW RegCreateKeyExW RegCloseKey SystemFunction036 OpenServiceW OpenSCManagerW CloseServiceHandle GetUserNameW CheckTokenMembership FreeSid AllocateAndInitializeSid |
SHELL32.dll |
ShellExecuteW
SHGetFolderPathW SHGetSpecialFolderPathW CommandLineToArgvW SHGetDesktopFolder DragFinish DragQueryFileW #155 #680 #190 SHFileOperationW SHGetDataFromIDListW |
ole32.dll |
CoInitialize
CoUninitialize PropVariantClear CoTaskMemAlloc CoGetClassObject CoTaskMemFree OleUninitialize StringFromGUID2 CreateStreamOnHGlobal CLSIDFromString CLSIDFromProgID CoCreateGuid CoTaskMemRealloc OleLockRunning CoCreateInstance OleInitialize |
OLEAUT32.dll |
#6
#2 #146 #7 #9 #277 #162 #420 #4 #8 #161 |
SHLWAPI.dll |
PathFindFileNameW
StrToIntA #12 PathRemoveFileSpecW SHStrDupW |
COMCTL32.dll |
InitCommonControlsEx
_TrackMouseEvent |
MSIMG32.dll |
AlphaBlend
|
imagehlp.dll |
ImageEnumerateCertificates
ImageRemoveCertificate |
NETAPI32.dll |
NetLocalGroupGetMembers
|
gdiplus.dll |
GdipCloneStringFormat
GdipSetStringFormatFlags GdipSetStringFormatAlign GdipGetStringFormatAlign GdipSetStringFormatLineAlign GdipGetStringFormatLineAlign GdipSetStringFormatTrimming GdipAddPathLineI GdipAddPathArcI GdipAddPathBezierI GdipAddPathRectangleI GdipAddPathEllipseI GdipCreateRegionPath GdipCombineRegionPath GdipCombineRegionRegion GdipGetBrushType GdipSetTextureTransform GdipSetLineTransform GdipCreateFont GdipGetLineSpacing GdipGetCellDescent GdipGetCellAscent GdipGetEmHeight GdipGetFamilyName GdipDeleteFontFamily GdipCreateFontFamilyFromName GdipEndContainer GdipBeginContainer2 GdipRestoreGraphics GdipDeleteStringFormat GdipStringFormatGetGenericTypographic GdipMeasureString GdipDrawString GdipGetFontSize GdipSaveGraphics GdipGetClipBoundsI GdipSetClipRegion GdipSetClipRectI GdipDrawImageRectRectI GdipDrawImageRectRect GdipFillPath GdipFillEllipse GdipFillRectangleI GdipGraphicsClear GdipDrawPath GdipDrawRectangle GdipDrawArcI GdipDrawLine GdipRotateWorldTransform GdipScaleWorldTransform GdipTranslateWorldTransform GdipMultiplyWorldTransform GdipGetInterpolationMode GdipSetInterpolationMode GdipGetFontStyle GdipSetTextRenderingHint GdipSetPixelOffsetMode GdipGetSmoothingMode GdipSetCompositingQuality GdipDeleteGraphics GdipCreateFromHDC GdipSetImageAttributesWrapMode GdipSetImageAttributesColorMatrix GdipDisposeImageAttributes GdipCreateImageAttributes GdipCloneBitmapArea GdipGetImageGraphicsContext GdipSetPenDashStyle GdipDeletePen GdipCreatePen1 GdipGetLineTransform GdipSetLineWrapMode GdipSetLinePresetBlend GdipCreateLineBrushI GdipCreateSolidFill GdipGetTextureTransform GdipCreateTexture GdipDeleteBrush GdipCloneBrush GdipTransformRegion GdipDeleteRegion GdipCloneRegion GdipGetMatrixElements GdipDeleteMatrix GdipCreateMatrix2 GdipCreateMatrix GdipGetPathWorldBounds GdipAddPathString #1 GdipClosePathFigure GdipDeletePath GdipCreatePath GdipCloneBitmapAreaI GdipCreateBitmapFromScan0 GdipCreateBitmapFromFile GdipGetImagePixelFormat GdipBitmapUnlockBits GdipBitmapLockBits GdipCreateBitmapFromStreamICM GdipCreateBitmapFromStream GdipGetPropertyItem GdipGetPropertyItemSize GdipImageSelectActiveFrame GdipImageGetFrameCount GdipImageGetFrameDimensionsList GdipImageGetFrameDimensionsCount GdipGetImageHeight GdipGetImageWidth GdipDisposeImage GdipCloneImage GdipFree GdipAlloc GdiplusStartup GdiplusShutdown GdipGetFamily GdipGetTextRenderingHint GdipDeleteFont GdipCreateHBITMAPFromBitmap GdipSetCompositingMode GdipSetSmoothingMode |
IMM32.dll |
ImmReleaseContext
ImmAssociateContextEx ImmGetCompositionStringW ImmNotifyIME ImmSetCompositionWindow ImmGetContext |
USP10.dll |
ScriptFreeCache
ScriptShape ScriptItemize |
WINMM.dll |
timeGetTime
|
Ordinal | 1 |
---|---|
Address | 0x26380 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.2.1.797 |
ProductVersion | 3.2.1.797 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | Chinese - PRC |
Comments | 2345.com |
CompanyName | 2345移动科技 |
FileDescription | 2345辅助模块 |
FileVersion (#2) | 3.2.1.797 |
InternalName | HelperMain |
LegalCopyright | 版权所有 (C) 2019, 2345移动科技 |
OriginalFilename | HelperMain.dll |
ProductName | 2345辅助模块 |
ProductVersion (#2) | 3.2.1.797 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Mar-14 07:29:31 |
Version | 0.0 |
SizeofData | 96 |
AddressOfRawData | 0x333050 |
PointerToRawData | 0x332250 |
Referenced File | E:\trunk\CommonPlatform\Helper2345\bin\Win32\Release\pdb\HelperMain.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Mar-14 07:29:31 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x3330b0 |
PointerToRawData | 0x3322b0 |
StartAddressOfRawData | 0x1038f000 |
---|---|
EndAddressOfRawData | 0x1038f001 |
AddressOfIndex | 0x1038c8ac |
AddressOfCallbacks | 0x102edde0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_1BYTES
|
Callbacks |
0x10255D70
|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1037b4b0 |
SEHandlerTable | 0x103416a0 |
SEHandlerCount | 2844 |
XOR Key | 0x1bf3590c |
---|---|
Unmarked objects | 0 |
C++ objects (VS2013 UPD5 build 40629) | 250 |
C++ objects (VS2008 SP1 build 30729) | 1 |
C++ objects (20806) | 4 |
199 (41118) | 1 |
ASM objects (VS2013 build 21005) | 68 |
C++ objects (VS2013 build 21005) | 146 |
C objects (VS2013 build 21005) | 281 |
C objects (VS2008 SP1 build 30729) | 11 |
Total imports | 661 |
Imports (VS2008 SP1 build 30729) | 39 |
Unmarked objects (#2) | 1 |
C objects (VS2013 UPD4 build 31101) | 1 |
C++ objects (VS2013 UPD4 build 31101) | 133 |
229 (VS2013 UPD5 build 40629) | 216 |
Exports (VS2013 UPD5 build 40629) | 1 |
Resource objects (VS2013 build 21005) | 1 |
151 | 1 |
Linker (VS2013 UPD5 build 40629) | 1 |