929fe80ec71936dcee84d199d117c9a89149f216fd15117c5316e65c5ec53a2f

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2005-Oct-07 09:05:22
Detected languages English - United States
Process Default Language
Russian - Russia
Comments
CompanyName MicroWorld Technologies Inc.
FileDescription eScan for Windows
FileVersion 11.0.1139.1077
InternalName eScanSetupSFX
LegalCopyright Copyright © MicroWorld Technologies Inc.
LegalTrademarks
OriginalFilename eScan SFX
PrivateBuild
ProductName eScan for Windows
ProductVersion 11.0.1139.1077
SpecialBuild

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExA
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegSetValueExA
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathA
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityA
  • SetFileSecurityW
Info The PE is digitally signed. Signer: Microworld Technologies Inc
Issuer: Sectigo Public Code Signing CA EV R36
Malicious VirusTotal score: 11/70 (Scanned on 2026-04-29 06:42:47) Alibaba: Trojan:Win32/Generic.10b3d49a
CAT-QuickHeal: Trojan.Agent
DeepInstinct: MALICIOUS
Fortinet: W32/PossibleThreat
Google: Detected
Ikarus: Trojan-Spy.bot
Kingsoft: Win32.Troj.Sekur.b
Microsoft: Trojan:Win32/Suschil!rfn
Sophos: Mal/Generic-S
TrellixENS: Artemis!C234A0DA07AB
Varist: W32/ABTrojan.OSRJ-2951

Hashes

MD5 c234a0da07ab2c3089b1cc5f7c8a0213
SHA1 22a99012f3d39e3f93bc5749b4297d486299fc60
SHA256 929fe80ec71936dcee84d199d117c9a89149f216fd15117c5316e65c5ec53a2f
SHA3 9e01146f4e6e3a71edd80841d8219bb0dd71d4189f5ba563cc7c8d3acfcd5875
SSDeep 196608:0H9FVIdXhUM5CHbAAJV1Wy+zGV1zIMMX3SIlp76yUNjhi0Ez90F95wys6:M8RUM5Ctp+atIN6tk0E0F95wyx
Imports Hash a6d1f237a38b6e7d3a48b606fa0d7939

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x200

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2005-Oct-07 09:05:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 5.0
SizeOfCode 0x13000
SizeOfInitializedData 0x18a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00001000 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x14000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x33000
SizeOfHeaders 0x400
Checksum 0x9f55a3
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 bcefd13d879b5aa1628d5731462b1935
SHA1 5e05fbf6b8bf012397b847cd5d10aee153dc895d
SHA256 2d3a4ddfb60b52ad4f07d6ec13a2f23362dc378aff4319837d761e9169b3a263
SHA3 c8dbd4f6ed58cadbfd2f79c23a75843673e20614d3b23be4e112461a3ec664c2
VirtualSize 0x13000
VirtualAddress 0x1000
SizeOfRawData 0x12600
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45699

.data

MD5 0eb9af4768d13f3fe805922a21fcbf55
SHA1 9665ae9e81ee6c6c0d2193973be588eb90aa031c
SHA256 d90cad2a887439de07f1f04bc2dc68107775f0f4d9992ab8a918319b3889473c
SHA3 2cbef5840cc56dd2dffef8878b27429cb5429b9575d8602ece9285ce4747efaa
VirtualSize 0x7000
VirtualAddress 0x14000
SizeOfRawData 0xa00
PointerToRawData 0x12c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.73447

.idata

MD5 7f9440e32acb299f3bda96288136b63a
SHA1 1d51ab1fb34c6b541f544524a63c3d9d73f566f9
SHA256 4afbc86b14d087a46656ac48917a0e7c02637c58dd65a6d26c458f03cc549369
SHA3 0fe9fe80410685c9cc0a1bcc226b059cd42ad08b29db58eb51712e575a3b4035
VirtualSize 0x1000
VirtualAddress 0x1b000
SizeOfRawData 0x1000
PointerToRawData 0x13600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.02033

.rsrc

MD5 0747d272487b20711b0d806b313931be
SHA1 e8a046d9d312c6536d076c272b542f8bf536193a
SHA256 549195f89790685a1cde3be26218283ac6f23de4fe0585dabe734cfbd0c97867
SHA3 f3f73ebc6c01b4d0048032b3a21b2157b789487f107c1844c373ffe6762cfa36
VirtualSize 0x16edc
VirtualAddress 0x1c000
SizeOfRawData 0x17000
PointerToRawData 0x14600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.93786

Imports

ADVAPI32.DLL AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
SetFileSecurityA
SetFileSecurityW
KERNEL32.DLL CloseHandle
CompareStringA
CreateDirectoryA
CreateDirectoryW
CreateFileA
CreateFileW
DeleteFileA
DeleteFileW
DosDateTimeToFileTime
ExitProcess
ExpandEnvironmentStringsA
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileA
FindFirstFileW
FindNextFileA
FindNextFileW
FindResourceA
FreeLibrary
GetCPInfo
GetCommandLineA
GetCurrentDirectoryA
GetCurrentProcess
GetDateFormatA
GetFileAttributesA
GetFileAttributesW
GetFileType
GetFullPathNameA
GetLastError
GetLocaleInfoA
GetModuleFileNameA
GetModuleHandleA
GetNumberFormatA
GetProcAddress
GetProcessHeap
GetStdHandle
GetTempPathA
GetTickCount
GetTimeFormatA
GetVersionExA
GlobalAlloc
HeapAlloc
HeapFree
HeapReAlloc
IsDBCSLeadByte
LoadLibraryA
LocalFileTimeToFileTime
MoveFileA
MoveFileExA
MultiByteToWideChar
ReadFile
SetCurrentDirectoryA
SetEndOfFile
SetEnvironmentVariableA
SetFileAttributesA
SetFileAttributesW
SetFilePointer
SetFileTime
SetLastError
Sleep
SystemTimeToFileTime
WaitForSingleObject
WideCharToMultiByte
WriteFile
lstrcmpiA
lstrlenA
COMCTL32.DLL #17
COMDLG32.DLL CommDlgExtendedError
GetOpenFileNameA
GDI32.DLL DeleteObject
SHELL32.DLL SHBrowseForFolderA
SHChangeNotify
SHFileOperationA
SHGetFileInfoA
SHGetMalloc
SHGetSpecialFolderLocation
ShellExecuteExA
SHGetPathFromIDListA
USER32.DLL CharToOemBuffA
CharUpperA
CopyRect
CreateWindowExA
DefWindowProcA
DestroyIcon
DestroyWindow
DialogBoxParamA
DispatchMessageA
EnableWindow
EndDialog
FindWindowExA
GetClassNameA
GetClientRect
GetDlgItem
GetDlgItemTextA
GetMessageA
GetParent
GetSysColor
GetSystemMetrics
GetWindow
GetWindowLongA
GetWindowRect
GetWindowTextA
IsWindow
IsWindowVisible
LoadBitmapA
LoadCursorA
LoadIconA
LoadStringA
MapWindowPoints
MessageBoxA
OemToCharA
OemToCharBuffA
PeekMessageA
PostMessageA
RegisterClassExA
SendDlgItemMessageA
SendMessageA
SetDlgItemTextA
SetFocus
SetMenu
SetWindowLongA
SetWindowPos
SetWindowTextA
ShowWindow
TranslateMessage
UpdateWindow
WaitForInputIdle
wsprintfA
wvsprintfA
OLE32.DLL CLSIDFromString
CoCreateInstance
CreateStreamOnHGlobal
OleInitialize
OleUninitialize

Delayed Imports

101

Type RT_BITMAP
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x14b92
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9786
MD5 74dc732383ae99fceb9d356634908fc4
SHA1 728e5d279c6883ac6d767e642b937d3fad3bdfd5
SHA256 15a34a4cc840a25c5ddb3d297650328d53c7176ae450251d5e5470bb53afa119
SHA3 30491473d62cb742a0be60d54a506d98aabd33bc7a44d9b3105fe1f18e08e4b7
Preview

1

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49476
MD5 7bed76bcbcdbd677f73d7b706b633d54
SHA1 27eb4be89069b23315734c3bf65bf90d1cd14760
SHA256 f75abd2099750c421541700a9ee3aa264df50677fe70035d42edd0052b4c7ddf
SHA3 bac5aca71609f7497e563037cde3cb53206a7c9718d6dd55e7e68c4038c4fabc

ASKNEXTVOL

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x282
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42532
MD5 844e654049749f17fb4dba40bbd80b96
SHA1 aef3a79572e1bb0f19c3d3dd44497f1abd6c6328
SHA256 d5b66c18f1c58f5f71f4a105236fc84b675667d28e9c24280aa3b02599bf55ef
SHA3 562f1f00a86f7c796c8d5918e0f2c79ca79b2434768c335f8f36b689d5501308

GETPASSWORD1

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29928
MD5 b871a68fc937cdefc6da15ca3604307b
SHA1 16626589c44e3c7ca6c0dbf4042f35abba18c37f
SHA256 25f8c0af54cb1a6b60d42caed499df18cd7784bd30f88e00c35d80390fefc1e3
SHA3 f9b79770488acf19f77f1165c9e785141c298174ce6463c456e24ea55864411a

LICENSEDLG

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17045
MD5 96343853e01b2f98ff543c5d726dc238
SHA1 82aacebeef5748071f69c8a3ffbe89d6467c7aa6
SHA256 53221a0c5e28eede68216dd40e7fd5c8182bc745ad40bcbc4134405af2232eca
SHA3 4c9146419922da380eaf55e4cf0ed4f6d5fd49565d50ba5e16f7b8dbdd1c82b4

RENAMEDLG

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x12e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06349
MD5 ec1e0bcd499d4114fc8088d828b182b7
SHA1 a3fff76ca74e044b4b4716ded8145d7f7a25c091
SHA256 dfc5d86a32ef4fea8a11d3564c063ab5c0a9c2e9e465fcc94f896512905a4c23
SHA3 65d52f72751bf24dbbc9ced56bb2309b7317aef12bb9928dad078a5436bd740c

REPLACEFILEDLG

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2667
MD5 92652c8f69c20c24aa1297b488c156c4
SHA1 db4d332e09bbf4ed0f09c0086a8e79bf8fc157ba
SHA256 ac477c1333323ce557269a65c04c7328500fa0020520d61c502e795053f484ee
SHA3 5efaed9d7bd1493637a9e4e5a5eb86ecd0ff6828fbe11319532b2fd59b095500

STARTDLG

Type RT_DIALOG
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x222
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44866
MD5 62cc6677400590f80825cd049b150ad4
SHA1 0c33916c9686b8e47e58c76e8b01927677078a4a
SHA256 c7b50f643821bd49542897116bbf09ab805aea89ed0786114c4ad4917a0c453e
SHA3 82f25337588e4c260fd8ec9d54737fb3f0dc697e0da861c74ecc7461debe8ffa

7

Type RT_STRING
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x22c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24143
MD5 fb61b3469ae245a497410d4de5b70d45
SHA1 fbc73ddd8d7c9099ab425bfb2c0776bb8251e8d9
SHA256 99dbe051efdcf261267620d163c0c2e02109d7b2207f70492b79245b7fc3219b
SHA3 ada313e02983cdccf389ba63e0ce66948cc82b05aa9a5085644923f1ea268cd2

8

Type RT_STRING
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x3b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28574
MD5 40af8f5e67322567fa168093753945fc
SHA1 b162cfa156d54acd08b7d876b0dadce621ef683c
SHA256 1750fcca6d01cfba66d6d910b82f0c98779eaa29062bb411c2aa19fb9fa0e337
SHA3 cc4ef287baea3a510a31666760e52e3cde1d3f7dac86a645ade95b6fad19af14

9

Type RT_STRING
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x212
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04375
MD5 c1d1d43f5fa2588205da7bc620ee7020
SHA1 c68a9fcf6f70b5f17ea1adcd93f48b68da9407bc
SHA256 1c02c9c1f7683c2de81796ccbfd9aa13c8a4a9147d0cf146f76f9d5df50f8ca3
SHA3 066b9e7de99aea5ed745dac0ce210e3c2387d26ecc9245592073936b5031b80d

10

Type RT_STRING
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15563
MD5 2e187dbd96ef2cf97d74d14d58e565fe
SHA1 1b893afcd3a9cbe96a15a218504291994116ac5e
SHA256 4f3a2ca9dca82d4b3dac64a998a07251312d9b3845b149cf5c8ce8ca54daf4c6
SHA3 6719aeb4077e168cb2e28500aa3b162f17927df8ecd48d61b287c418b8d38cb8

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

100

Type RT_GROUP_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83321
Detected Filetype Icon file
MD5 716963c2a0dbd2423c1233c862ea0626
SHA1 314496dc16a379bae3275e26fe58239c3bc039fa
SHA256 ce779380320caaadd02d060188aaa21489ebdef69fef812c0d0f7300b8b4eccb
SHA3 ee2a107392fc59f84b6095f6ca1811665b1adbaecbae74ff14b085746ae4f058

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x3cc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44141
MD5 39b03ae355589178f91ce5e6ef7b7724
SHA1 5c1a359c2e614e00d3912b6c7573cc6391fc8844
SHA256 1d37d40bbdbabefa422c80f47535af305ec90a9f47fa0003b1819dc84a0f30d9
SHA3 03b40d94fe2bc635423572ab9b12c1e7e1bc4a2139c7976d1cd8b5412d401f2e

1 (#3)

Type RT_MANIFEST
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x213
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.10885
MD5 0b2228ec82e3e8ad3d6c6342b7e1aae0
SHA1 8176f4da16edda1683a2d8b5a4ed0e2856442b3c
SHA256 15324e5059af9c43aa7112792329216902d5821bb49bb206b71c25d9c6cd0b6a
SHA3 5945667bdbab29f6ee030e69f32289cd94c4baebf97e8fbbbd9fe89037902e76

1 (#4)

Type UNKNOWN
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.5
MD5 08be85fb3297822484e5fe137a1dd17f
SHA1 05bc1c597f6f699d155faaf572f4f1b652ec7eb6
SHA256 491a8630a743f48f990faf4fd76781fd3e4c228a4e6340da2fca2a4a944b454b
SHA3 4f2498ceba52ef47eba93c7423b5d430d7c4938fadb4552615cedce9d2e1bc44

String Table contents

Select destination folder
Extracting %s
Skipping %s
Unexpected end of archive
The file "%s" header is corrupt
The archive comment header is corrupt
The archive comment is corrupt
Not enough memory
Unknown method in %s
Cannot open %s
Cannot create %s
Cannot create folder %s
CRC failed in the encrypted file %s (wrong password ?)
CRC failed in %s
Packed data CRC failed in %s
Wrong password for %s
Write error in the file %s. Probably the disk is full
Read error in the file %s
File close error
The required volume is absent
The archive is either in unknown format or damaged
Extracting from %s
Next volume
The archive header is corrupt
Close
Error
Errors encountered while performing the operation
Look at the information window for more details
bytes
modified on
folder is not accessible
Some files could not be created.
Please close all applications, reboot Windows and restart this installation
Some installation files are corrupt.
Please download a fresh copy and retry the installation
All files
<ul><li>Press <b>Install</b> button to start extraction.</li><br><br>
<li>Use <b>Browse</b> button to select the destination
folder from the folders tree. It can be also entered
manually.</lI><br><br>
<lI>If the destination folder does not exist, it will be
created automatically before extraction.</lI></ul>

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 11.0.1139.1077
ProductVersion 11.0.1139.1077
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments
CompanyName MicroWorld Technologies Inc.
FileDescription eScan for Windows
FileVersion (#2) 11.0.1139.1077
InternalName eScanSetupSFX
LegalCopyright Copyright © MicroWorld Technologies Inc.
LegalTrademarks
OriginalFilename eScan SFX
PrivateBuild
ProductName eScan for Windows
ProductVersion (#2) 11.0.1139.1077
SpecialBuild
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

Errors

Leave a comment

No comments yet.