| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2005-Oct-07 09:05:22 |
| Detected languages |
English - United States
Process Default Language Russian - Russia |
| Comments | |
| CompanyName | MicroWorld Technologies Inc. |
| FileDescription | eScan for Windows |
| FileVersion | 11.0.1139.1077 |
| InternalName | eScanSetupSFX |
| LegalCopyright | Copyright © MicroWorld Technologies Inc. |
| LegalTrademarks | |
| OriginalFilename | eScan SFX |
| PrivateBuild | |
| ProductName | eScan for Windows |
| ProductVersion | 11.0.1139.1077 |
| SpecialBuild |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microworld Technologies Inc
Issuer: Sectigo Public Code Signing CA EV R36 |
| Malicious | VirusTotal score: 11/70 (Scanned on 2026-04-29 06:42:47) |
Alibaba:
Trojan:Win32/Generic.10b3d49a
CAT-QuickHeal: Trojan.Agent DeepInstinct: MALICIOUS Fortinet: W32/PossibleThreat Google: Detected Ikarus: Trojan-Spy.bot Kingsoft: Win32.Troj.Sekur.b Microsoft: Trojan:Win32/Suschil!rfn Sophos: Mal/Generic-S TrellixENS: Artemis!C234A0DA07AB Varist: W32/ABTrojan.OSRJ-2951 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x200 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2005-Oct-07 09:05:22 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 5.0 |
| SizeOfCode | 0x13000 |
| SizeOfInitializedData | 0x18a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x33000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x9f55a3 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.DLL |
AdjustTokenPrivileges
LookupPrivilegeValueA OpenProcessToken RegCloseKey RegCreateKeyExA RegOpenKeyExA RegQueryValueExA RegSetValueExA SetFileSecurityA SetFileSecurityW |
|---|---|
| KERNEL32.DLL |
CloseHandle
CompareStringA CreateDirectoryA CreateDirectoryW CreateFileA CreateFileW DeleteFileA DeleteFileW DosDateTimeToFileTime ExitProcess ExpandEnvironmentStringsA FileTimeToLocalFileTime FileTimeToSystemTime FindClose FindFirstFileA FindFirstFileW FindNextFileA FindNextFileW FindResourceA FreeLibrary GetCPInfo GetCommandLineA GetCurrentDirectoryA GetCurrentProcess GetDateFormatA GetFileAttributesA GetFileAttributesW GetFileType GetFullPathNameA GetLastError GetLocaleInfoA GetModuleFileNameA GetModuleHandleA GetNumberFormatA GetProcAddress GetProcessHeap GetStdHandle GetTempPathA GetTickCount GetTimeFormatA GetVersionExA GlobalAlloc HeapAlloc HeapFree HeapReAlloc IsDBCSLeadByte LoadLibraryA LocalFileTimeToFileTime MoveFileA MoveFileExA MultiByteToWideChar ReadFile SetCurrentDirectoryA SetEndOfFile SetEnvironmentVariableA SetFileAttributesA SetFileAttributesW SetFilePointer SetFileTime SetLastError Sleep SystemTimeToFileTime WaitForSingleObject WideCharToMultiByte WriteFile lstrcmpiA lstrlenA |
| COMCTL32.DLL |
#17
|
| COMDLG32.DLL |
CommDlgExtendedError
GetOpenFileNameA |
| GDI32.DLL |
DeleteObject
|
| SHELL32.DLL |
SHBrowseForFolderA
SHChangeNotify SHFileOperationA SHGetFileInfoA SHGetMalloc SHGetSpecialFolderLocation ShellExecuteExA SHGetPathFromIDListA |
| USER32.DLL |
CharToOemBuffA
CharUpperA CopyRect CreateWindowExA DefWindowProcA DestroyIcon DestroyWindow DialogBoxParamA DispatchMessageA EnableWindow EndDialog FindWindowExA GetClassNameA GetClientRect GetDlgItem GetDlgItemTextA GetMessageA GetParent GetSysColor GetSystemMetrics GetWindow GetWindowLongA GetWindowRect GetWindowTextA IsWindow IsWindowVisible LoadBitmapA LoadCursorA LoadIconA LoadStringA MapWindowPoints MessageBoxA OemToCharA OemToCharBuffA PeekMessageA PostMessageA RegisterClassExA SendDlgItemMessageA SendMessageA SetDlgItemTextA SetFocus SetMenu SetWindowLongA SetWindowPos SetWindowTextA ShowWindow TranslateMessage UpdateWindow WaitForInputIdle wsprintfA wvsprintfA |
| OLE32.DLL |
CLSIDFromString
CoCreateInstance CreateStreamOnHGlobal OleInitialize OleUninitialize |
| Select destination folder |
| Extracting %s |
| Skipping %s |
| Unexpected end of archive |
| The file "%s" header is corrupt |
| The archive comment header is corrupt |
| The archive comment is corrupt |
| Not enough memory |
| Unknown method in %s |
| Cannot open %s |
| Cannot create %s |
| Cannot create folder %s |
| CRC failed in the encrypted file %s (wrong password ?) |
| CRC failed in %s |
| Packed data CRC failed in %s |
| Wrong password for %s |
| Write error in the file %s. Probably the disk is full |
| Read error in the file %s |
| File close error |
| The required volume is absent |
| The archive is either in unknown format or damaged |
| Extracting from %s |
| Next volume |
| The archive header is corrupt |
| Close |
| Error |
| Errors encountered while performing the operation |
| Look at the information window for more details |
| bytes |
| modified on |
| folder is not accessible |
| Some files could not be created. |
| Please close all applications, reboot Windows and restart this installation |
| Some installation files are corrupt. |
| Please download a fresh copy and retry the installation |
| All files |
| <ul><li>Press <b>Install</b> button to start extraction.</li><br><br> |
| <li>Use <b>Browse</b> button to select the destination |
| folder from the folders tree. It can be also entered |
| manually.</lI><br><br> |
| <lI>If the destination folder does not exist, it will be |
| created automatically before extraction.</lI></ul> |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 11.0.1139.1077 |
| ProductVersion | 11.0.1139.1077 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| Comments | |
| CompanyName | MicroWorld Technologies Inc. |
| FileDescription | eScan for Windows |
| FileVersion (#2) | 11.0.1139.1077 |
| InternalName | eScanSetupSFX |
| LegalCopyright | Copyright © MicroWorld Technologies Inc. |
| LegalTrademarks | |
| OriginalFilename | eScan SFX |
| PrivateBuild | |
| ProductName | eScan for Windows |
| ProductVersion (#2) | 11.0.1139.1077 |
| SpecialBuild |
| Resource LangID | English - United States |
|---|
No comments yet.