Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1974-May-29 19:08:33 |
Detected languages |
Arabic - Saudi Arabia
Bulgarian - Bulgaria Chinese - PRC Chinese - Taiwan Croatian - Croatia Czech - Czech Republic Danish - Denmark Dutch - Netherlands English - United Kingdom English - United States Estonian - Estonia Finnish - Finland French - Canada French - France German - Germany Greek - Greece Hebrew - Israel Hungarian - Hungary Italian - Italy Japanese - Japan Korean - Korea Latvian - Latvia Lithuanian - Lithuania Norwegian - Norway (Bokmal) Polish - Poland Portuguese - Brazil Portuguese - Portugal Romanian - Romania Russian - Russia Slovak - Slovakia Slovenian - Slovenia Spanish - Mexico Spanish - Spain (International sort) Swedish - Sweden Thai - Thailand Turkish - Turkey Ukrainian - Ukraine |
Debug artifacts |
SetupPrep.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Instalacija izdanja Windows 10 |
FileVersion | 10.0.19041.572 (vb_release_svc_prod1.201007-1724) |
InternalName | SetupPrep.exe |
LegalCopyright | © Microsoft Corporation. Sva prava zadržana. |
OriginalFilename | SetupPrep.exe |
ProductName | Operativni sistem Microsoft® Windows® |
ProductVersion | 10.0.19041.572 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA1
Uses constants related to SHA256 |
Suspicious | The PE is possibly packed. | Unusual section name found: .boxload |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010 |
Safe | VirusTotal score: 0/69 (Scanned on 2024-04-23 08:54:54) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 1974-May-29 19:08:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x77c00 |
SizeOfInitializedData | 0xa8b800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000729B0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x79000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xb0a000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1290880 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
GetTokenInformation
SetSecurityDescriptorGroup RegQueryValueExW OpenThreadToken AddAccessAllowedAce DuplicateTokenEx SetSecurityDescriptorControl GetLengthSid RegDeleteValueW CreateProcessAsUserW RegOpenKeyExW InitializeAcl InitializeSecurityDescriptor CheckTokenMembership FreeSid OpenProcessToken RegSetValueExW RegSetKeySecurity CopySid RegCreateKeyExW RegFlushKey AllocateAndInitializeSid RegDeleteKeyW SetTokenInformation GetAce SetSecurityDescriptorOwner RegQueryInfoKeyW RegEnumKeyW RegCloseKey RegNotifyChangeKeyValue SetSecurityDescriptorDacl GetTraceEnableLevel AdjustTokenPrivileges RegEnumValueW InitiateSystemShutdownExW SetSecurityInfo RegUnLoadKeyW QueryAllTracesW GetTraceLoggerHandle StopTraceW UnregisterTraceGuids RegisterTraceGuidsW GetTraceEnableFlags |
---|---|
KERNEL32.dll |
DeleteFileW
CloseHandle GetNativeSystemInfo LoadLibraryW FindResourceExW ResetEvent LoadResource GetOverlappedResult SetFilePointerEx LocalFree MoveFileExW ReplaceFileW LockFileEx DeleteCriticalSection GetCurrentProcessId CreateProcessW GetModuleHandleW FreeLibrary CopyFileW WideCharToMultiByte SystemTimeToTzSpecificLocalTime GetSystemTime DosDateTimeToFileTime GetSystemWindowsDirectoryW MoveFileW IsWow64Process GetDriveTypeW LoadLibraryExW FlushFileBuffers LockResource GetCurrentThread SetEvent CreateFileA VerifyVersionInfoW IsValidLocale VerSetConditionMask IsValidCodePage MapViewOfFile CreateFileMappingW CreatePipe GetUserDefaultUILanguage GetSystemDefaultUILanguage SearchPathW OutputDebugStringA SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive GetLastError LeaveCriticalSection InitializeCriticalSectionAndSpinCount GetTickCount64 LocalFileTimeToFileTime GetTimeZoneInformation Sleep GetExitCodeProcess MultiByteToWideChar CreateEventW GetLogicalDriveStringsW SetFileAttributesW GetSystemDirectoryW OpenEventW GetFileAttributesW CreateFileW WaitForSingleObject SetFilePointer FindClose CreateHardLinkW CreateMutexW UnlockFileEx SetEndOfFile GetVersionExW SetThreadPreferredUILanguages GetLocaleInfoW GetPrivateProfileIntW InitializeCriticalSection GlobalUnlock GlobalLock MulDiv FindResourceW SizeofResource QueryDosDeviceW RaiseException DuplicateHandle GetShortPathNameW HeapSize HeapReAlloc IsDebuggerPresent VirtualQuery GetPriorityClass GetThreadPriority OutputDebugStringW GetExitCodeThread SetThreadPriority SetPriorityClass CreateThread FormatMessageW GetPrivateProfileSectionW GetFileTime FileTimeToSystemTime CompareFileTime CopyFileExW SetFileInformationByHandle GetFileInformationByHandle DeviceIoControl GetFileInformationByHandleEx SetCurrentDirectoryW GetCurrentDirectoryW GetFinalPathNameByHandleW GetLongPathNameW SetLastError GetTickCount GetSystemTimeAsFileTime GetCurrentThreadId QueryPerformanceCounter SetUnhandledExceptionFilter UnhandledExceptionFilter GetStartupInfoW SetEnvironmentVariableW WaitForMultipleObjects GetModuleFileNameW SetFileTime TerminateProcess ExpandEnvironmentStringsW WriteFile GetCurrentProcess FindNextFileW GetFullPathNameW GetCommandLineW EnterCriticalSection CompareStringW GetFileSizeEx FindFirstFileW ReadFile CreateDirectoryW GetProcessHeap GetProcAddress HeapAlloc GetModuleHandleExW HeapFree GetVersionExA UnmapViewOfFile |
USER32.dll |
GetKeyState
GetFocus IsChild GetNextDlgTabItem GetWindowLongW RedrawWindow CopyRect DrawFocusRect SetWindowLongW SystemParametersInfoW GetDC GetSysColor GetClientRect GetParent InvalidateRect LoadStringW PostMessageW GetSystemMenu GetSysColorBrush ClientToScreen GetSystemMetrics IsWindowVisible FillRect AdjustWindowRectEx SetCursor LoadCursorW TrackMouseEvent EnableWindow EnableMenuItem DrawTextW CharUpperW GetWindowRect MessageBoxW ScreenToClient SendMessageW SetTimer PostThreadMessageW KillTimer LoadImageW |
MFC42u.dll |
#4470
#4282 #3084 #3870 #2634 #5977 #5047 #543 #2385 #1106 #3614 #2388 #817 #803 #3579 #3341 #5296 #5299 #4074 #4693 #5303 #5285 #4118 #5711 #3949 #565 #268 #3397 #6051 #4294 #4279 #1633 #323 #6153 #640 #5781 #470 #755 #3568 #521 #1571 #6466 #600 #269 #826 #3621 #2406 #1560 #4418 #4616 #4075 #3074 #3820 #3826 #3825 #2971 #3076 #2980 #3257 #3131 #4459 #3254 #3142 #2977 #1202 #1940 #6433 #4221 #1165 #3716 #795 #2294 #609 #1131 #3658 #540 #861 #2820 #800 #4704 #4992 #4847 #4419 #1767 #6048 #5261 #3133 #567 #5273 #2116 #2438 #5257 #1720 #6195 #6193 #6211 #5059 #3744 #6372 #2047 #2640 #4435 #4831 #3793 #5286 #4347 #6370 #5157 #2377 #5237 #4401 #818 #1768 #4073 #4621 #2858 #2637 #4155 #4229 #1143 #1808 #324 #2078 #2161 #3952 #2506 #4370 #641 #5276 #3000 #3087 #329 #5978 #3196 #4131 #643 #1787 #2567 #4390 #3915 #2372 #4162 #2371 #3871 #2859 #3792 #6278 #6279 #5871 #2397 #2854 #1921 #4270 #1634 #2855 #6303 |
msvcrt.dll |
iswspace
bsearch __CxxFrameHandler3 __setusermatherr __p__fmode _cexit _exit realloc _errno _wtoi free towlower _wcstoui64 wcstoul towupper _vscwprintf _vsnprintf _wcsicmp wcsrchr exit wcsncmp __set_app_type __wgetmainargs _amsg_exit __p__commode _XcptFilter _wcsnicmp wcsstr wcschr _purecall _vsnwprintf memcpy_s _CxxThrowException __RTDynamicCast _ftol2 memcmp memcpy _initterm _wcmdln memmove _except_handler4_common _controlfp ??1type_info@@UAE@XZ ?terminate@@YAXXZ _onexit __dllonexit _unlock _lock memset |
COMCTL32.dll |
InitCommonControlsEx
|
ole32.dll |
CoUninitialize
CoCreateInstance CoInitializeEx |
SHELL32.dll |
CommandLineToArgvW
|
ntdll.dll |
NtSetInformationThread
NtShutdownSystem RtlAllocateHeap RtlNtStatusToDosError NtSetInformationFile RtlDosPathNameToNtPathName_U_WithStatus RtlFreeHeap NtWriteFile RtlInitUnicodeString NtReadFile RtlReAllocateHeap NtClose RtlExpandEnvironmentStrings NtQueryInformationFile NtWaitForSingleObject NtOpenFile NtDuplicateToken RtlGetVersion RtlRaiseStatus NtYieldExecution RtlAdjustPrivilege NtSetInformationProcess |
USERENV.dll |
DestroyEnvironmentBlock
CreateEnvironmentBlock |
WTSAPI32.dll |
WTSQueryUserToken
|
WDSCORE.dll |
WdsSetupLogMessageW
ConstructPartialMsgVW WdsGenericSetupLogInit CurrentIP WdsSetupLogDestroy |
RPCRT4.dll |
I_RpcMapWin32Status
UuidToStringW RpcStringFreeW UuidFromStringW |
GDI32.dll |
CreateICW
CreateSolidBrush DeleteObject DeleteDC StretchBlt CreateCompatibleDC BitBlt SetBrushOrgEx SetBkMode GetStockObject GetObjectW GetDeviceCaps CreateFontIndirectW CreateDIBSection TranslateCharsetInfo CreateDCW EnumFontFamiliesExW SetTextColor |
Cabinet.dll |
#23
#20 #22 |
OLEAUT32.dll |
VariantInit
VariantClear SysFreeString SysAllocString |
VERSION.dll |
GetFileVersionInfoExW
GetFileVersionInfoSizeExW VerQueryValueW |
WIMGAPI.DLL |
WIMUnmountImage
WIMInitFileIOCallbacks WIMSetFileIOCallbackTemporaryPath |
bcrypt.dll |
BCryptDestroyHash
BCryptCloseAlgorithmProvider BCryptFinishHash BCryptOpenAlgorithmProvider BCryptHashData BCryptCreateHash |
UxTheme.dll |
IsAppThemed
|