82c113ebbf068d7a937322168bceb4e8

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Nov-01 09:22:02
Detected languages English - United States
Debug artifacts O:\CPPwrapper_VS2010\Release_RS\optimizerpro_silent.pdb
CompanyName PC Utilities Software Limited
FileDescription Keep your PC drivers up to date
FileVersion 3.2.0.2
InternalName Driver Pro
LegalCopyright PC Utilities Software Limited
OriginalFilename Driver Pro
ProductName Driver Pro v3.2
ProductVersion 3.2.0.2

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious PEiD Signature: UPolyX V0.1 -> Delikon
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Malicious The PE is possibly a dropper. Resource IDB_BIN_INSTALL detected as a PE Executable.
Resources amount for 96.3317% of the executable.
Info The PE is digitally signed. Signer: PC Utilities Software Limited.
Issuer: COMODO RSA Code Signing CA.
Malicious VirusTotal score: 31/57 (Scanned on 2016-11-04 04:50:07) Bkav: W32.HfsAdware.59EA
CAT-QuickHeal: PUA.Driverpro.PR8
McAfee: Artemis!3107C28DA15C
Malwarebytes: PUP.Optional.DriverPro
VIPRE: OptimizerPro (fs) (not malicious)
K7GW: Adware ( 004b203a1 )
K7AntiVirus: Adware ( 004b203a1 )
Baidu: Win32.Adware.SpeedingUpMyPC.a
Symantec: SMG.Heur!gen
Avast: Win32:Adware-CJK [PUP]
Kaspersky: not-a-virus:HEUR:RiskTool.Win32.Generic
NANO-Antivirus: Riskware.Win32.OptimizerPro.dtleju
AegisLab: Win.Troj.Optimizerpro.mfLp
Rising: Malware.Generic!cjJGP5m65YM@4 (thunder)
Comodo: Application.Win32.Optimizero.K
DrWeb: Trojan.PWS.Tibia.2591
Zillya: Trojan.GenericCRTD.Win32.196
Invincea: virus.win32.parite.b
Jiangmin: Adware.BProtector.h
Avira: PUA/OptimizerPro.RE
Antiy-AVL: RiskWare[RiskTool:not-a-virus]/Win32.OptimizerPro
AhnLab-V3: PUP/Win32.Optimizer.R116134
AVware: OptimizerPro (fs)
ESET-NOD32: Win32/Adware.SpeedingUpMyPC.Q
Yandex: Riskware.OptimizerPro!
Ikarus: PUA.SpeedingUpMyPC
GData: Win32.Application.OptimizerPro.L
AVG: Generic.77D
Panda: Trj/Genetic.gen
CrowdStrike: malicious_confidence_100% (D)
Qihoo-360: HEUR/QVM41.1.0000.Malware.Gen

Hashes

MD5 82c113ebbf068d7a937322168bceb4e8
SHA1 9b1ae7675da9c62702ffd1c4ce56683ad9f8f728
SHA256 abcdcbe1158f6f446855bb007b5973c0d0a9c425f5e8086499b2713f7af8afdd
SHA3 2e8c6f38ee4106d2b51db6fec59d42de586f6259d89725be146a77c651074a01
SSDeep 98304:D3bobVkwiXFlJboUaQXK1XR0ZNSHm8GeRLfWFZzo:Lbeirfa1GZN+PhLIZ8
Imports Hash 23ee14b7b8bad73645664a22cfd7f754

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2016-Nov-01 09:22:02
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0x14600
SizeOfInitializedData 0x366800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x6869 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x16000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x380000
SizeOfHeaders 0x400
Checksum 0x381b68
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 153c25a894558c86b486e20495de16f9
SHA1 3eea3f9c3aa324614c019cf46cbcb856b6a7b6f5
SHA256 d2eeab52fd5b0cf39503f5d697a20f2f3b8efe97d4eb9d3e2a5b7221cc6aff67
SHA3 e22916cd483d0612f529260ddf3d7fd9441879a5e4a8d241e4174fad317b6468
VirtualSize 0x144cd
VirtualAddress 0x1000
SizeOfRawData 0x14600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.57123

.rdata

MD5 8ea5d734322df60fcdfe41193e6c3d59
SHA1 5e010578c0fb862c680195df62863736f98a3529
SHA256 1c8f840f57169c80230987ea147d55bfe7f828131ae312a510a30ccbdd605117
SHA3 72807848f27b53fdcbeb6475be9ba1919d3981ccd687f47cff40914c64968e0f
VirtualSize 0x5112
VirtualAddress 0x16000
SizeOfRawData 0x5200
PointerToRawData 0x14a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.89844

.data

MD5 2cef89c59f35f4fcafe95749186c0933
SHA1 a950abfbf7487b1574b3c9ba6d3f5ce4893dd900
SHA256 2c330216762c94c8210d40ff0331b88161a20af72f58ea98fdc2b300bf9d60ea
SHA3 ae84723005178e82376ad84e6f85b630312830d165bb85e2935ed35c6b525fed
VirtualSize 0x3484
VirtualAddress 0x1c000
SizeOfRawData 0x1600
PointerToRawData 0x19c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.1127

.rsrc

MD5 4fb8f31a4c2c45c1f8b028908219e86a
SHA1 77df7a101450b90b7c41a4c14e90b358f2657485
SHA256 850f909879943566dbf4d5a92e672b645bc8332aa980808142081b30c62b8e38
SHA3 d4e50b135dfc7155de8941392577e490b67c551e05c8556541e7e6fc154f10e2
VirtualSize 0x35bf24
VirtualAddress 0x20000
SizeOfRawData 0x35c000
PointerToRawData 0x1b200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.86249

.reloc

MD5 55998d3b6241dc40b18743b0cdd28cca
SHA1 2da954cd291964be65091eba85d468553b1e667c
SHA256 7cb755cc024b5ff2f5400bb529d7bdfd789cb549462cd149ed7d2573e88202e5
SHA3 b560dd0adf032fc42a027a88fa2ead4f6ce08ff91227fced6b27bee0500e2e12
VirtualSize 0x3f60
VirtualAddress 0x37c000
SizeOfRawData 0x4000
PointerToRawData 0x377200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.69317

Imports

KERNEL32.dll GetExitCodeProcess
GetModuleFileNameW
SizeofResource
LockResource
CloseHandle
WaitForSingleObject
CreateProcessW
LoadResource
GetTempPathW
FindResourceA
SetEndOfFile
CreateFileW
WriteConsoleW
SetStdHandle
InterlockedIncrement
InterlockedDecrement
EncodePointer
DecodePointer
Sleep
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetLastError
HeapFree
GetCommandLineW
HeapSetInformation
GetStartupInfoW
RaiseException
RtlUnwind
HeapAlloc
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetCPInfo
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
IsProcessorFeaturePresent
HeapCreate
GetProcAddress
GetModuleHandleW
ExitProcess
ReadFile
SetFilePointer
WriteFile
GetConsoleCP
GetConsoleMode
FlushFileBuffers
FreeEnvironmentStringsW
GetEnvironmentStringsW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoW
HeapSize
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeW
HeapReAlloc
LoadLibraryW
GetProcessHeap
ADVAPI32.dll RegCloseKey
RegFlushKey
RegCreateKeyExW
RegSetValueExW
ole32.dll CoUninitialize
CoInitialize

Delayed Imports

IDB_BIN_INSTALL

Type INSTALLER
Language English - United States
Codepage Latin 1 / Western European
Size 0x313c00
Entropy 7.99365
Detected Filetype PE Executable
MD5 3107c28da15cc8db52ecaeb41e92fa27
SHA1 9498f3281c0b79a8f051ca9aeb0d6132dcf0ca0f
SHA256 e9318226bff1cf3225c26f0bde46ad08f2a745fe9de55153a41c7bf7eb194325
SHA3 903244e247128299dea6be0777ad14404f487a41d9f9bfd9bbd831bed700fe84

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
Entropy 5.55719
MD5 45ee323ce43873307490c3794c814560
SHA1 a5ab033f792f86a0b12515f99d0a52422efb2a95
SHA256 b28cdfb367ce98d9a96c7ff9fe19af0f2985befcd083828039bf892367bd2959
SHA3 52d8cc9a550992721f1b9d8880309d8c6381010364c7bdb7912bf535a7a77ed7

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
Entropy 5.99883
MD5 41f0453be5c5ba7beda7159cf5116e7b
SHA1 df5372c3b00e9421d8755ad46284356b8d91570f
SHA256 3c6ecb505d686fd6b52a9a7ce53af543b4cc8f9e6c9f8bb36fb0e5a8a10b24f8
SHA3 283aa976b4efad52a6c82a8ce43aa51355d9ff17efd3bf2782bc6e39f8bded79

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
Entropy 6.1731
MD5 8e1f9dfb39e5a2c8a727f4066e3d55d2
SHA1 a7fd960c52f243b845c9e8dab117ca4ea7765db3
SHA256 32313d600df4354e7031682c696202cd249d3b60224d260d73aa4ca988f26e05
SHA3 4603268c6e8af7e8de1be4953ea796daea9d1907960c57458998ec0e121d6d9a

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
Entropy 4.19059
MD5 e674207f8267af19a2bfef20770a123e
SHA1 3b8b95ea78756c3807955e126e07d61b4191028a
SHA256 a16ac8cfa75422fa4fa05b0252f2e58040fddd1380488535965ac320ea7cde01
SHA3 ae9354cc6aa6cdd8660e6944a8d7ca4664b76413c5d10a6e9afd0a8f2caf0340

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
Entropy 5.31401
MD5 d1a4ef17cd92170630df50d841663a5d
SHA1 cdfd82f6e112a2224d5e118229be7125caf6245e
SHA256 aab411a3141e56bc242ed90d0dc9dc10b92a54f8990ab3038fc5e46fbad07dfc
SHA3 18a79f5be8978c203c9733aa0d059a92ca8eaf09e83fd0d5f38d1f409b708f40

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
Entropy 5.68398
MD5 30c3e5306044bb310a9e99509246b786
SHA1 5de37c60a5d3f13079a2ecf5b673eeae859c026e
SHA256 377d0afd25039f3a4fbc7341c8afa42472e2f59898ae8ae0184e16b5ddd14afd
SHA3 5befe41527095b31ce0ef76f0e48a366dc95642d81cb6b861c8e2e78498d448e

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
Entropy 5.18086
MD5 bd327d7c67c24446c74a49b21b4b5ba5
SHA1 6df73441fb571765fa8cbbcb287d8ab0e9c30ec6
SHA256 9d35dc1f17f6ed09cfadb35fb70dc5c12cf053ad3c9a13a646b709ebab92aa94
SHA3 10b97c80dc2beb5c14f7f9d974119cb291f688ec50bc39a7e99d45cac8871f4e

IDI_ICON1

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
Entropy 2.71787
Detected Filetype Icon file
MD5 eee2def6081be6fc6c237a1035cd0d47
SHA1 8806faa001a31ea3b44f50dd48cc65beaeaf5980
SHA256 b4a86ff543995d1a1dcad86ec767539180bbe55d27b306186eb5fa4bc3d5872f
SHA3 78d5eea63069b93e68cee5d50fede595c1b89746d7c1bfada26d66ee8f9609bf

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x31c
Entropy 3.38995
MD5 b239dad8c82afb611bc992bb0811b1b1
SHA1 69dba71117f00c1f739555ebd6c428e1123d62b9
SHA256 ea75a3c3d3a5ac3eb9f1af9929dd08bb4a0c3d73ab776cc9a8c4c09af5a2ce97
SHA3 66ae46db4345f62910a51fd1ea25f50fae571ce2c27ede6314a30811db3ad877

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x525
Entropy 5.27601
MD5 de157d6976c58b4344370299a42f1ce6
SHA1 c7a4336882f496d9541e449469b388fb303a1cd0
SHA256 ca38643ca48ef25db36c9dc27aae15a9c198df2bc55b6e96e9023f8eebf0bbc8
SHA3 e08517754b6bbafdf75d08006a248bf38a8f7499bf885134b6991daca0b10e8f

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.2.0.2
ProductVersion 3.2.0.2
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName PC Utilities Software Limited
FileDescription Keep your PC drivers up to date
FileVersion (#2) 3.2.0.2
InternalName Driver Pro
LegalCopyright PC Utilities Software Limited
OriginalFilename Driver Pro
ProductName Driver Pro v3.2
ProductVersion (#2) 3.2.0.2
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2016-Nov-01 09:22:02
Version 0.0
SizeofData 80
AddressOfRawData 0x19280
PointerToRawData 0x17c80
Referenced File O:\CPPwrapper_VS2010\Release_RS\optimizerpro_silent.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x41c490
SEHandlerTable 0x419b80
SEHandlerCount 27

Errors