| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2020-Dec-29 12:48:03 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
F:\ææ\lx\SmartUpdate2\UsbUpdateAppX\Release\UsbUpdateAppX.pdb
|
| CompanyName | TODO: <Company name> |
| FileDescription | UsbUpdateAppX |
| FileVersion | 1.0.0.1 |
| InternalName | UsbUpdateAppX.exe |
| LegalCopyright | TODO: (c) <Company name>. All rights reserved. |
| OriginalFilename | UsbUpdateAppX.exe |
| ProductName | TODO: <Product name> |
| ProductVersion | 1.0.0.1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains another PE executable:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. | Resource 130 detected as a PE Executable. |
| Suspicious | VirusTotal score: 1/71 (Scanned on 2026-04-29 09:46:47) | APEX: Malicious |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2020-Dec-29 12:48:03 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x125400 |
| SizeOfInitializedData | 0xfec00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00102128 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x127000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x22f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x226b54 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetEnvironmentVariableA
GetConsoleMode GetConsoleCP LCMapStringW GetTimeZoneInformation IsValidCodePage GetOEMCP GetACP GetCPInfo IsProcessorFeaturePresent GetStringTypeW IsDebuggerPresent UnhandledExceptionFilter TerminateProcess QueryPerformanceCounter HeapCreate SetHandleCount GetEnvironmentStringsW FreeEnvironmentStringsW GetStdHandle SetUnhandledExceptionFilter GetFileType SetStdHandle FindResourceW VirtualQuery GetSystemInfo VirtualAlloc GetSystemTimeAsFileTime HeapSize HeapQueryInformation CreateThread ExitThread RaiseException WriteConsoleW HeapReAlloc HeapFree HeapAlloc ExitProcess DecodePointer EncodePointer GetStartupInfoW HeapSetInformation GetCommandLineW FindResourceExW VirtualProtect SearchPathW GetProfileIntW InitializeCriticalSectionAndSpinCount GetNumberFormatW GetWindowsDirectoryW GetTickCount GetTempPathW GetTempFileNameW GetFileTime GetFileSizeEx GetFileAttributesW FileTimeToLocalFileTime GetFileAttributesExW SetErrorMode GetFullPathNameW GetVolumeInformationW FindFirstFileW RtlUnwind FindClose GetCurrentProcess DuplicateHandle GetFileSize SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer ReadFile lstrcmpiW GlobalFlags GetCurrentDirectoryW InterlockedIncrement TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection GlobalHandle GlobalReAlloc EnterCriticalSection TlsGetValue LeaveCriticalSection LocalAlloc FileTimeToSystemTime GetThreadLocale GlobalGetAtomNameW GlobalFindAtomW GetVersionExW CompareStringW InterlockedDecrement ReleaseActCtx CreateActCtxW GlobalAddAtomW CreateEventW SuspendThread SetEvent WaitForSingleObject ResumeThread SetThreadPriority GetCurrentProcessId GetPrivateProfileStringW WritePrivateProfileStringW GetPrivateProfileIntW lstrcpyW lstrcmpA GlobalDeleteAtom GetCurrentThread GetCurrentThreadId GetUserDefaultUILanguage ConvertDefaultLocale GetSystemDefaultUILanguage GetModuleFileNameW GetLocaleInfoW ActivateActCtx DeactivateActCtx lstrcmpW GetModuleHandleW InterlockedExchange GlobalFree CopyFileW GlobalSize GlobalAlloc GlobalLock GlobalUnlock FormatMessageW LocalFree MulDiv SetLastError GetDriveTypeW lstrlenA WideCharToMultiByte lstrlenW MultiByteToWideChar DeleteFileW GetLogicalDrives Sleep FreeLibrary GetProcAddress LoadLibraryW FreeResource WriteFile CreateFileW CloseHandle GetLastError CreateMutexW LockResource SizeofResource LoadResource |
|---|---|
| USER32.dll |
CharUpperBuffW
CopyIcon FrameRect EmptyClipboard CloseClipboard SetClipboardData OpenClipboard CopyImage GetIconInfo HideCaret InvertRect RegisterClipboardFormatW LockWindowUpdate SetCursorPos CreateAcceleratorTableW GetKeyboardState GetKeyboardLayout ToUnicodeEx DrawFocusRect DrawFrameControl DrawEdge DrawIconEx SetClassLongW DestroyAcceleratorTable SetParent UnpackDDElParam ReuseDDElParam LoadImageW LoadAcceleratorsW InsertMenuItemW BringWindowToTop TranslateAcceleratorW UnregisterClassW DestroyIcon GetMenuDefaultItem SetMenuDefaultItem CreatePopupMenu IsMenu MonitorFromPoint UpdateLayeredWindow EnableScrollBar UnionRect CharUpperW IsZoomed GetAsyncKeyState NotifyWinEvent RedrawWindow SetWindowRgn LoadMenuW MessageBeep GetNextDlgGroupItem InvalidateRgn IntersectRect SetRect IsRectEmpty CopyAcceleratorTableW OffsetRect CharNextW SetLayeredWindowAttributes EnumDisplayMonitors KillTimer SetTimer RealChildWindowFromPoint DeleteMenu WaitMessage ReleaseCapture WindowFromPoint SetCapture LoadCursorW GetSysColorBrush SystemParametersInfoW DestroyMenu GetMenuItemInfoW InflateRect ShowWindow MoveWindow SetWindowTextW IsDialogMessageW PostThreadMessageW CheckDlgButton SendDlgItemMessageW SendDlgItemMessageA WinHelpW IsChild GetCapture GetClassLongW SetPropW GetPropW RemovePropW SetFocus GetWindowTextLengthW GetWindowTextW GetForegroundWindow BeginDeferWindowPos EndDeferWindowPos GetTopWindow GetMessageTime GetMessagePos MonitorFromWindow GetMonitorInfoW MapWindowPoints ScrollWindow TrackPopupMenu SetMenu SetScrollRange GetScrollRange SetScrollPos GetScrollPos SetForegroundWindow ShowScrollBar CreateWindowExW GetClassInfoExW GetClassInfoW RegisterClassW AdjustWindowRectEx EqualRect DeferWindowPos GetScrollInfo SetScrollInfo SetWindowPlacement GetWindowPlacement GetDlgCtrlID DefWindowProcW CallWindowProcW GetMenu SetWindowLongW GetClassNameW InvalidateRect UpdateWindow DrawStateW ShowOwnedPopups SetCursor GetMessageW IsWindowVisible GetKeyState ValidateRect SetMenuItemBitmaps GetMenuCheckMarkDimensions LoadBitmapW ModifyMenuW EnableMenuItem CheckMenuItem SetWindowsHookExW UnhookWindowsHookEx GetCursorPos CallNextHookEx GetFocus GetWindowRect PtInRect GetSysColor DefFrameProcW DefMDIChildProcW DrawMenuBar TranslateMDISysAccel CreateMenu GetWindowRgn DestroyCursor SubtractRect EndPaint BeginPaint GetWindowDC ClientToScreen ScreenToClient GrayStringW DrawTextExW DrawTextW TabbedTextOutW FillRect GetWindowThreadProcessId MapVirtualKeyExW IsCharLowerW GetDoubleClickTime GetUpdateRect IsClipboardFormatAvailable GetLastActivePopup MessageBoxW MapVirtualKeyW GetKeyNameTextW ReleaseDC GetDC CopyRect GetDesktopWindow GetActiveWindow SetActiveWindow CreateDialogIndirectParamW DestroyWindow IsWindow GetWindowLongW GetDlgItem IsWindowEnabled GetNextDlgTabItem EndDialog RegisterWindowMessageW GetWindow SetWindowContextHelpId GetParent MapDialogRect SetWindowPos PostMessageW GetMenuState GetMenuStringW GetMenuItemID InsertMenuW GetMenuItemCount GetSubMenu RemoveMenu DrawIcon GetClientRect GetSystemMetrics IsIconic SendMessageW AppendMenuW GetSystemMenu LoadIconW EnableWindow DispatchMessageW TranslateMessage PostQuitMessage PeekMessageW SetRectEmpty |
| GDI32.dll |
CreateFontIndirectW
GetTextExtentPoint32W CreateDIBitmap CreateCompatibleBitmap GetTextMetricsW EnumFontFamiliesW GetTextCharsetInfo GetBkColor GetTextColor GetRgnBox SetRectRgn CombineRgn GetMapMode DPtoLP CreateRoundRectRgn CreateDIBSection CreatePolygonRgn CreateEllipticRgn Polyline Ellipse Polygon CreatePalette GetPaletteEntries GetNearestPaletteIndex RealizePalette GetSystemPaletteEntries OffsetRgn SetDIBColorTable CreateHatchBrush SetPixel Rectangle EnumFontFamiliesExW ExtFloodFill SetPaletteEntries LPtoDP GetWindowOrgEx GetViewportOrgEx PtInRegion FillRgn FrameRgn GetBoundsRect GetTextFaceW SetPixelV SetViewportOrgEx SelectObject Escape CreateSolidBrush ExtTextOutW CreatePen GetObjectType OffsetViewportOrgEx SelectPalette GetStockObject CreateCompatibleDC CreateBitmap CreatePatternBrush DeleteDC ExtSelectClipRgn ScaleWindowExtEx SetWindowExtEx OffsetWindowOrgEx SetWindowOrgEx ScaleViewportExtEx StretchBlt GetDeviceCaps TextOutW RectVisible PtVisible GetPixel BitBlt GetWindowExtEx GetViewportExtEx GetObjectW CreateRectRgn SelectClipRgn DeleteObject SetLayout GetLayout SetTextAlign MoveToEx LineTo IntersectClipRect ExcludeClipRect GetClipBox SetMapMode SetTextColor SetROP2 SetPolyFillMode SetBkMode SetBkColor RestoreDC SaveDC PatBlt CreateRectRgnIndirect CreateDCW CopyMetaFileW SetViewportExtEx |
| MSIMG32.dll |
AlphaBlend
TransparentBlt |
| COMDLG32.dll |
GetFileTitleW
|
| WINSPOOL.DRV |
ClosePrinter
OpenPrinterW DocumentPropertiesW |
| ADVAPI32.dll |
RegQueryValueExW
RegOpenKeyExW RegCreateKeyExW RegSetValueExW RegDeleteValueW RegDeleteKeyW RegEnumKeyW RegQueryValueW RegCloseKey RegEnumKeyExW RegEnumValueW |
| SHELL32.dll |
DragQueryFileW
SHGetSpecialFolderLocation SHGetMalloc SHGetPathFromIDListW SHBrowseForFolderW SHAppBarMessage ShellExecuteW SHGetDesktopFolder DragFinish SHGetFileInfoW |
| COMCTL32.dll |
InitCommonControlsEx
ImageList_GetIconSize |
| SHLWAPI.dll |
PathFindFileNameW
PathStripToRootW PathIsUNCW PathFindExtensionW PathRemoveFileSpecW |
| ole32.dll |
OleLockRunning
IsAccelerator OleTranslateAccelerator OleDestroyMenuDescriptor OleCreateMenuDescriptor CoInitializeEx DoDragDrop OleFlushClipboard OleIsCurrentClipboard CreateStreamOnHGlobal OleInitialize CoFreeUnusedLibraries OleUninitialize CreateILockBytesOnHGlobal CoGetClassObject CoInitialize CoUninitialize CoCreateInstance CLSIDFromString CLSIDFromProgID CoCreateGuid OleDuplicateData CoTaskMemAlloc ReleaseStgMedium RevokeDragDrop CoLockObjectExternal StgCreateDocfileOnILockBytes CoTaskMemFree RegisterDragDrop OleGetClipboard CoRegisterMessageFilter StgOpenStorageOnILockBytes CoRevokeClassObject |
| OLEAUT32.dll |
SysFreeString
OleCreateFontIndirect VarBstrFromDate SysStringLen SystemTimeToVariantTime VariantTimeToSystemTime VariantCopy VariantInit VariantChangeType VariantClear SysAllocStringLen SysAllocString SafeArrayDestroy |
| oledlg.dll |
OleUIBusyW
|
| gdiplus.dll |
GdipGetImageGraphicsContext
GdipBitmapUnlockBits GdipBitmapLockBits GdipCreateBitmapFromScan0 GdipCreateBitmapFromStream GdipGetImagePalette GdipGetImagePaletteSize GdipGetImagePixelFormat GdipGetImageHeight GdipGetImageWidth GdipCloneImage GdipDrawImageRectI GdipSetInterpolationMode GdipCreateFromHDC GdiplusShutdown GdiplusStartup GdipCreateBitmapFromHBITMAP GdipDisposeImage GdipDeleteGraphics GdipAlloc GdipFree GdipDrawImageI |
| OLEACC.dll |
LresultFromObject
AccessibleObjectFromWindow CreateStdAccessibleObject |
| IMM32.dll |
ImmGetOpenStatus
ImmReleaseContext ImmGetContext |
| WINMM.dll |
PlaySoundW
|
| &About UsbUpdateAppX... |
| Open |
| Save As |
| All Files (*.*) |
| Untitled |
| an unnamed file |
| &Hide |
| No error message is available. |
| Attempted an unsupported operation. |
| A required resource was unavailable. |
| Out of memory. |
| An unknown error has occurred. |
| Encountered an improper argument. |
| Incorrect filename. |
| Failed to open document. |
| Failed to save document. |
| Save changes to %1? |
| Failed to create empty document. |
| The file is too large to open. |
| Could not start print job. |
| Failed to launch help. |
| Internal application error. |
| Command failed. |
| Insufficient memory to perform operation. |
| System registry entries have been removed and the INI file (if any) was deleted. |
| Not all of the system registry entries (or INI file) were removed. |
| This program requires the file %s, which was not found on this system. |
| This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
| Enter an integer. |
| Enter a number. |
| Enter an integer between %1 and %2. |
| Enter a number between %1 and %2. |
| Enter no more than %1 characters. |
| Select a button. |
| Enter an integer between 0 and 255. |
| Enter a positive integer. |
| Enter a date and/or time. |
| Enter a currency. |
| Enter a GUID. |
| Enter a time. |
| Enter a date. |
| Unexpected file format. |
| %1 |
| Cannot find this file. |
| Verify that the correct path and file name are given. |
| Destination disk drive is full. |
| Unable to read from %1, it is opened by someone else. |
| Unable to write to %1, it is read-only or opened by someone else. |
| Encountered an unexpected error while reading %1. |
| Encountered an unexpected error while writing %1. |
| %1: %2 |
| Continue running script? |
| Dispatch exception: %1 |
| Unable to read write-only property. |
| Unable to write read-only property. |
| Unable to load mail system support. |
| Mail system DLL is invalid. |
| Send Mail failed to send message. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| %1 was not found. |
| %1 contains an incorrect path. |
| Could not open %1 because there are too many open files. |
| Access to %1 was denied. |
| An incorrect file handle was associated with %1. |
| Could not remove %1 because it is the current directory. |
| Could not create %1 because the directory is full. |
| Seek failed on %1 |
| Encountered a hardware I/O error while accessing %1. |
| Encountered a sharing violation while accessing %1. |
| Encountered a locking violation while accessing %1. |
| Disk full while accessing %1. |
| Attempted to access %1 past its end. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| Attempted to write to the reading %1. |
| Attempted to access %1 past its end. |
| Attempted to read from the writing %1. |
| %1 has a bad format. |
| %1 contained an unexpected object. |
| %1 contains an incorrect schema. |
| pixels |
| Uncheck |
| Check |
| Mixed |
| One or more auto-saved documents were found. |
| These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
| Do you want to recover these auto-saved documents? |
| Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
| Recover the auto-saved documents |
| Open the auto-saved versions instead of the explicitly saved versions |
| Don't recover the auto-saved documents |
| Use the last explicitly saved versions of the documents |
| %s [Recovered] |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | TODO: <Company name> |
| FileDescription | UsbUpdateAppX |
| FileVersion (#2) | 1.0.0.1 |
| InternalName | UsbUpdateAppX.exe |
| LegalCopyright | TODO: (c) <Company name>. All rights reserved. |
| OriginalFilename | UsbUpdateAppX.exe |
| ProductName | TODO: <Product name> |
| ProductVersion (#2) | 1.0.0.1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Dec-29 12:48:03 |
| Version | 0.0 |
| SizeofData | 90 |
| AddressOfRawData | 0x1521d8 |
| PointerToRawData | 0x1509d8 |
| Referenced File | F:\ææ\lx\SmartUpdate2\UsbUpdateAppX\Release\UsbUpdateAppX.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x571ca0 |
| SEHandlerTable | 0x55ab10 |
| SEHandlerCount | 854 |
| XOR Key | 0x67072aac |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2008 SP1 build 30729) | 15 |
| Imports (VS2008 SP1 build 30729) | 35 |
| Total imports | 752 |
| ASM objects (VS2010 build 30319) | 43 |
| C objects (VS2010 build 30319) | 179 |
| C++ objects (VS2010 build 30319) | 376 |
| 175 (VS2010 build 30319) | 3 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |
No comments yet.