Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2008-Aug-05 15:01:45 |
Detected languages |
English - United States
|
CompanyName | Adobe Systems Incorporated |
FileDescription | AutoPlay |
FileVersion | 6.0 |
InternalName | AutoPlay |
LegalCopyright | © 1990-2008 Adobe Systems Incorporated |
OriginalFilename | AutoPlay.exe |
ProductName | Autoplay |
ProductVersion | 6.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
Can access the registry:
|
Info | The PE is digitally signed. |
Signer: Adobe Systems Incorporated
Issuer: VeriSign Class 3 Code Signing 2004 CA |
Suspicious | VirusTotal score: 1/72 (Scanned on 2024-11-02 07:59:35) | Jiangmin: Trojan.Generic.hetyo |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2008-Aug-05 15:01:45 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x1d000 |
SizeOfInitializedData | 0x93000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0001257A (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb1000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x38bb5 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
COMCTL32.dll |
_TrackMouseEvent
#17 |
---|---|
MSVFW32.dll |
MCIWndCreateW
MCIWndCreateA |
WINMM.dll |
waveOutSetVolume
waveOutGetVolume PlaySoundA waveOutGetNumDevs |
SHLWAPI.dll |
PathRemoveFileSpecW
|
KERNEL32.dll |
InterlockedExchange
GetModuleHandleA GetModuleFileNameA GetWindowsDirectoryA GetSystemDirectoryA LoadLibraryA SetLastError GetOEMCP GetACP SetEndOfFile CreateFileA FlushFileBuffers SetStdHandle GetTimeZoneInformation GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter VirtualQuery GetSystemInfo VirtualProtect GetLocaleInfoA IsBadCodePtr IsBadReadPtr SetFilePointer GetStringTypeA IsBadWritePtr VirtualAlloc VirtualFree HeapCreate HeapDestroy GetCommandLineW GetCommandLineA GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter CompareStringA WaitForSingleObject CloseHandle DeviceIoControl MulDiv FreeLibrary Sleep ReleaseMutex GetLastError GetUserDefaultLCID GetUserDefaultUILanguage GetSystemDefaultLangID WriteFile ReadFile GetStartupInfoA GetFileType GetStdHandle SetHandleCount SetUnhandledExceptionFilter SetEnvironmentVariableA HeapSize HeapReAlloc RtlUnwind FindClose FileTimeToSystemTime FileTimeToLocalFileTime FindFirstFileA RaiseException ExitProcess TerminateProcess GetCurrentProcess GetVersionExA HeapAlloc HeapFree LCMapStringA |
USER32.dll |
DestroyIcon
GetSystemMetrics SetFocus BeginPaint FillRect DrawEdge keybd_event SetForegroundWindow UpdateWindow TranslateMessage ReleaseDC GetAsyncKeyState SetCursor EndPaint RedrawWindow MoveWindow GetIconInfo CreateIconIndirect GetClientRect InvalidateRect ShowWindow PostQuitMessage DrawIconEx SetRect GetDC GetWindowRect |
GDI32.dll |
CreateSolidBrush
GetStockObject PatBlt CreateCompatibleBitmap CreateCompatibleDC SetTextAlign SetLayout LineTo SetBkMode StretchBlt BitBlt SetTextColor CreatePenIndirect SelectObject MoveToEx Polyline DeleteObject DeleteDC |
ADVAPI32.dll |
RegQueryValueA
RegCloseKey |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.0.0.0 |
ProductVersion | 6.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Adobe Systems Incorporated |
FileDescription | AutoPlay |
FileVersion (#2) | 6.0 |
InternalName | AutoPlay |
LegalCopyright | © 1990-2008 Adobe Systems Incorporated |
OriginalFilename | AutoPlay.exe |
ProductName | Autoplay |
ProductVersion (#2) | 6.0 |
Resource LangID | English - United States |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x425258 |
SEHandlerTable | 0x421cf0 |
SEHandlerCount | 13 |
XOR Key | 0xe78f8e88 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2003 (.NET) build 3077) | 17 |
C objects (VS2003 (.NET) build 3077) | 131 |
Imports (2067) | 2 |
Imports (2179) | 10 |
Imports (9210) | 5 |
Total imports | 133 |
105 (2067) | 52 |
C objects (2179) | 54 |
C++ objects (VS2003 (.NET) build 3077) | 27 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |