| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Oct-09 10:37:35 |
| Detected languages |
English - United States
French - France Portuguese - Brazil Russian - Russia Spanish - Spain (International sort) |
| Debug artifacts |
C:\BUILD\work\8b0ebd312dc47f30\projects\avast\microstub\x86\Release\microstub.pdb
|
| CompanyName | Gen Digital Inc. |
| Edition | 15 |
| FileDescription | AVG Installer |
| FileVersion | 2.1.137.0 |
| InternalName | microstub |
| LegalCopyright | Copyright é 2025 Gen Digital Inc. All rights reserved. |
| OriginalFilename | microstub.exe |
| ProductName | AVG |
| ProductVersion | 2.1.137.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Gen Digital Inc.
Issuer: Sectigo Public Code Signing CA R36 |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-05-18 19:49:09) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x128 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2025-Oct-09 10:37:35 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x23200 |
| SizeOfInitializedData | 0x19200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001020 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x25000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x41000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x4446a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
InterlockedExchangeAdd
HeapFree GetLastError SetLastError Sleep GetFileSizeEx WriteFile SetEndOfFile SetFilePointerEx CloseHandle MapViewOfFile UnmapViewOfFile CreateFileMappingW FindResourceExW EnumResourceNamesW GetWindowsDirectoryW CreateDirectoryW CreateFileW MultiByteToWideChar WideCharToMultiByte CreateThread GetSystemTimeAsFileTime GetNativeSystemInfo lstrcatA lstrlenA GetVersionExA GetCurrentProcess GetExitCodeProcess ResumeThread ReleaseMutex WaitForSingleObject CreateMutexW CreateProcessW GetPrivateProfileIntA GetPrivateProfileIntW GetPrivateProfileStringA GetPrivateProfileStringW GetDiskFreeSpaceExW CopyFileW MoveFileExW CreateHardLinkW LocalFree HeapAlloc GetProcessHeap HeapSetInformation ExitProcess IsProcessorFeaturePresent lstrcpyW GetModuleHandleW GetCommandLineW GetSystemDirectoryW SetDllDirectoryW WriteConsoleW FlushFileBuffers GetConsoleMode GetConsoleCP SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCPInfo GetOEMCP IsValidCodePage FindNextFileW FindFirstFileExW FindClose LCMapStringW FindResourceW LoadLibraryW SizeofResource LoadResource GlobalFree GlobalUnlock GlobalLock GlobalAlloc GetVersionExW FreeLibrary LockResource GetFileType GetStringTypeW InterlockedExchange GetUserDefaultLangID GetACP GetModuleHandleExW RaiseException GetSystemInfo VirtualProtect VirtualQuery LoadLibraryExA LoadLibraryA DecodePointer GetVersion HeapDestroy HeapReAlloc HeapSize InitializeCriticalSectionAndSpinCount DeleteCriticalSection DeviceIoControl GetVolumeNameForVolumeMountPointW GetVolumePathNameW EnterCriticalSection LeaveCriticalSection SetEvent ResetEvent WaitForSingleObjectEx CreateEventW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW TerminateProcess OutputDebugStringW RtlUnwind EncodePointer TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW GetCommandLineA GetStdHandle GetModuleFileNameW GetProcAddress |
|---|---|
| USER32.dll |
ReleaseDC
GetMessageW TranslateMessage DispatchMessageW AllowSetForegroundWindow PostMessageW wsprintfA LoadStringW MessageBoxExW wsprintfW SystemParametersInfoW IsDialogMessageW LoadImageW DestroyIcon FindWindowW FillRect GetWindowRect SendMessageW EndPaint BeginPaint InvalidateRect GetDC SetForegroundWindow GetSystemMetrics KillTimer SetTimer SetFocus SetWindowPos DestroyWindow CreateWindowExW RegisterClassExW PostQuitMessage DefWindowProcW |
| GDI32.dll |
GetObjectW
CreateDIBSection SelectObject GetTextExtentPoint32W DeleteObject CreateSolidBrush CreatePatternBrush CreateFontIndirectW |
| ADVAPI32.dll |
CryptDestroyHash
CryptHashData CryptCreateHash CryptGenRandom CryptGetHashParam CryptReleaseContext CryptAcquireContextA GetSidSubAuthorityCount GetSidSubAuthority IsValidSid GetTokenInformation OpenProcessToken ConvertStringSecurityDescriptorToSecurityDescriptorA |
| ole32.dll |
CoInitializeEx
CoCreateInstance CreateStreamOnHGlobal CoUninitialize |
| COMCTL32.dll |
#17
|
| SHLWAPI.dll |
StrStrW
StrToIntW |
| WindowsCodecs.dll (delay-loaded) |
WICConvertBitmapSource
|
| Attributes | 0x1 |
|---|---|
| Name | WindowsCodecs.dll |
| ModuleHandle | 0x30a48 |
| DelayImportAddressTable | 0x32048 |
| DelayImportNameTable | 0x2e0e4 |
| BoundDelayImportTable | 0x2e22c |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Global\{32B25EF2-80FD-4C66-97E1-0890D9E9F87B} |
| {08CF729B-3FA8-477D-B80C-42CA25A49937} |
| avgSfxProgressClass |
| UA-58120669-4 |
| G-0DKJC5WS6X |
| oM1HsGwPRq6kClvE8VLkzw |
| {08CF729B-3FA8-477D-B80C-42CA25A49938} |
| AVG Microstub/2.1 |
| s-iavg.avcdn.net/avg/iavs9x/avg_antivirus_free_setup.exe |
| s-iavg.avcdn.net/avg/iavs9x/avg_antivirus_free_setup_x64.exe |
| honzik.avcdn.net/setup/avg-av/release/avg_antivirus_free_online_setup.exe |
| honzik.avcdn.net/setup/avg-av/release/avg_antivirus_free_online_setup.exe |
| honzik.avcdn.net/setup/avg-av/release/avg_antivirus_free_online_setup.exe |