Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2011-Aug-24 01:07:33 |
Detected languages |
English - United States
|
Debug artifacts |
explorer.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Windows Explorer |
FileVersion | 6.2.8102.0 (winmain_win8m3.110823-1455) |
InternalName | explorer |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | EXPLORER.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.2.8102.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Microsoft's Cryptography API |
Suspicious | The PE is possibly packed. | Unusual section name found: .imrsiv |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Windows
Issuer: Microsoft Windows PCA 2010 |
Safe | VirusTotal score: 0/56 (Scanned on 2015-01-10 23:55:10) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2011-Aug-24 01:07:33 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 10.2 |
SizeOfCode | 0xf9400 |
SizeOfInitializedData | 0x20fe00 |
SizeOfUninitializedData | 0x200 |
AddressOfEntryPoint | 0x000000000003386C (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.2 |
ImageVersion | 6.2 |
SubsystemVersion | 6.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x30e000 |
SizeOfHeaders | 0x600 |
Checksum | 0x31586f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0xe000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
RegCreateKeyW
RegCloseKey EventWrite RegOpenKeyExW RegGetValueW EventEnabled GetTraceLoggerHandle GetTraceEnableLevel GetTraceEnableFlags RegisterTraceGuidsW UnregisterTraceGuids RegQueryValueExW GetLengthSid GetTokenInformation OpenProcessToken RegSetValueExW EventRegister EventUnregister TraceMessage RegOpenKeyW RegDeleteValueW RegCreateKeyExW CloseServiceHandle OpenSCManagerW OpenServiceW QueryServiceStatus CheckTokenMembership ConvertStringSecurityDescriptorToSecurityDescriptorW EqualSid LookupAccountNameW ConvertSidToStringSidW ConvertStringSidToSidW LsaOpenPolicy LsaLookupSids LsaFreeMemory LsaClose IsValidSid GetSidSubAuthorityCount GetSidSubAuthority OpenThreadToken RegQueryInfoKeyW StartTraceW EnableTraceEx StopTraceW RegEnumValueW CryptAcquireContextW CryptCreateHash CryptHashData CryptGetHashParam CryptDestroyHash CryptReleaseContext StartServiceW CreateWellKnownSid RegOpenCurrentUser RegEnumKeyExW |
---|---|
KERNEL32.dll |
ReadFile
GetFileSize CreateFileW FlushInstructionCache RaiseException SetLastError OpenThread GetSystemTimeAsFileTime GetDateFormatW GetDateFormatEx GetTimeFormatEx GetLocalTime MultiByteToWideChar GetCurrentThreadId GetCurrentProcessId GetLongPathNameW SetTermsrvAppInstallMode ResetEvent FindClose FindNextFileW lstrcmpiW FindFirstFileW GetFileAttributesW GlobalGetAtomNameW ExpandEnvironmentStringsW SystemTimeToFileTime GetSystemTime OpenEventW MulDiv GetTickCount64 GetThreadPriority LeaveCriticalSection EnterCriticalSection SetEvent ResolveDelayLoadedAPI DelayLoadFailureHook UnmapViewOfFile MapViewOfFile SearchPathW GetDynamicTimeZoneInformation GetTimeZoneInformation ChangeTimerQueueTimer DeleteTimerQueueTimer CreateTimerQueueTimer GetModuleHandleExW CreateThreadpoolTimer FreeLibraryWhenCallbackReturns GetCurrentThread CloseThreadpoolTimer QueryPerformanceFrequency QueueUserWorkItem GetProductInfo GetSystemInfo DeleteFileW GetModuleHandleA GetWindowsDirectoryW TerminateThread CreateIoCompletionPort GetQueuedCompletionStatus CompareStringW lstrcmpA QueryFullProcessImageNameW GetLocaleInfoW ProcessIdToSessionId GetSystemDirectoryW CreateFileMappingW OpenMutexW DuplicateHandle CompareFileTime WideCharToMultiByte GetComputerNameW GlobalFree GetCurrentDirectoryW GlobalUnlock GlobalLock lstrlenW GlobalAlloc lstrlenA DeactivateActCtx ActivateActCtx ReleaseActCtx CreateActCtxW LoadLibraryExW LockResource LoadResource FindResourceExW WaitForMultipleObjects ExitProcess GetModuleHandleW HeapDestroy RegisterApplicationRestart SetProcessShutdownParameters GetStartupInfoW ReleaseMutex CreateMutexW InitializeCriticalSection DeleteCriticalSection SetErrorMode CreateEventW GetTickCount WaitForMultipleObjectsEx GetVersionExW FreeLibrary GetProcAddress LoadLibraryW GetUserDefaultUILanguage WaitForSingleObject GetCurrentProcess CompareStringOrdinal GetCommandLineW GetModuleFileNameW CreateProcessW HeapFree GetProcessHeap HeapAlloc OpenProcess LocalFree LocalAlloc QueryInformationJobObject Sleep CreateThread SetPriorityClass GetPriorityClass ResumeThread AssignProcessToJobObject SetInformationJobObject GetLastError SetThreadPriority SetThreadpoolTimer VirtualFree InterlockedPopEntrySList VirtualAlloc InterlockedPushEntrySList RtlCaptureContext UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess RtlLookupFunctionEntry RtlVirtualUnwind QueryPerformanceCounter CreateJobObjectW CloseHandle GetProcessId GetUserDefaultLangID |
GDI32.dll |
CombineRgn
SetDIBits GetRgnBox SetLayout GetLayout LPtoDP OffsetViewportOrgEx GdiFlush OffsetRgn GetTextMetricsW SetWindowOrgEx StretchBlt CreateSolidBrush CreatePen Polyline GetRegionData ExtCreateRegion GetTextColor GetTextExtentPoint32W GetDIBits GetStockObject ExtTextOutW SetTextAlign StretchDIBits SelectClipRgn SetViewportOrgEx GetViewportOrgEx IntersectClipRect GetClipRgn CreateRectRgn GetBkColor PatBlt CreateBitmap GetDeviceCaps CreateFontIndirectW CreateRectRgnIndirect CreateCompatibleDC CreateDIBSection SelectObject DeleteObject DeleteDC GdiAlphaBlend GetObjectW GetClipBox GetTextExtentPointW CreateCompatibleBitmap OffsetWindowOrgEx SetBkColor SetTextColor BitBlt SetBkMode |
USER32.dll |
GetWindowLongPtrW
SetWindowLongPtrW ShutdownBlockReasonCreate LoadStringW RegisterClassW DefWindowProcW DestroyWindow MsgWaitForMultipleObjectsEx PeekMessageW PostQuitMessage SetCursor LoadCursorW ReleaseDC GetDC FindWindowW DestroyMenu GetMenuDefaultItem CreatePopupMenu SystemParametersInfoW PostMessageW DispatchMessageW TranslateMessage GetMessageW CharPrevW CharNextW GetWindow PtInRect GetWindowRect GetSystemMetrics CreateWindowExW DialogBoxParamW GetClassInfoW GetClassInfoExW GetMenuItemCount GetMenuItemInfoW GetClassNameW ActivateKeyboardLayout GetKeyboardLayout SystemParametersInfoA GetMenuStringW InsertMenuW InsertMenuItemW SetMenuItemInfoW IsChild IsWinEventHookInstalled IsProcessDPIAware GetMenuState CharLowerW IsCharAlphaNumericW UnionRect GetClassLongW SetClassLongW GetGUIThreadInfo GetDlgCtrlID GetNextDlgGroupItem GetNextDlgTabItem MoveWindow ChildWindowFromPointEx GetWindowDC CharUpperW UnregisterClassW FrameRect WindowFromDC SendMessageCallbackW UpdateLayeredWindow GetUserObjectInformationW GetProcessWindowStation GetThreadDesktop ShowWindowAsync BringWindowToTop GetClassWord GetClassLongPtrW GetIconInfo SetThreadDesktop EndTask OpenInputDesktop CloseDesktop IsZoomed SetScrollInfo GetScrollInfo SetScrollPos InternalGetWindowText GetWindowInfo EnumDisplayDevicesW GetCaretBlinkTime SetLayeredWindowAttributes GetLayeredWindowAttributes GetUpdateRect SetWindowsHookExW UnhookWindowsHookEx CallNextHookEx SetTimer MapWindowPoints ShowWindow MonitorFromPoint SetWindowPos GetMonitorInfoW KillTimer SetRect CopyRect LockSetForegroundWindow TrackMouseEvent GetCursorPos SetFocus GetAncestor GetCapture ReleaseCapture GetDoubleClickTime SetWindowCompositionAttribute GetWindowBand HungWindowFromGhostWindow #2005 SendMessageW GetClientRect SetWindowTextW SetWindowPlacement IsRectEmpty SetRectEmpty EnumDisplayMonitors InflateRect UpdateWindow SendNotifyMessageW ChangeWindowMessageFilterEx IntersectRect MonitorFromWindow IsWindowVisible GetForegroundWindow EnumWindows GetParent IsWindow TranslateAcceleratorW WaitMessage GetWindowTextW TrackPopupMenuEx GhostWindowFromHungWindow EnumChildWindows GetWindowLongW SetActiveWindow GetKeyState SubtractRect RedrawWindow BeginDeferWindowPos DeferWindowPos EndDeferWindowPos InvalidateRect OffsetRect SendMessageTimeoutW SetWindowRgn UpdateLayeredWindowIndirect GetWindowRgnBox LoadImageW GetWindowPlacement SetForegroundWindow GetLastInputInfo RemovePropW GetLastActivePopup SwitchToThisWindow MessageBeep GetActiveWindow GetFocus UnregisterHotKey RegisterHotKey SendDlgItemMessageW EndDialog GetDesktopWindow UnhookWinEvent SetWinEventHook GetAsyncKeyState GetShellWindow ChildWindowFromPoint SetCursorPos GetMessagePos BeginPaint FillRect DrawEdge EndPaint GetSystemMenu EnableMenuItem ReplyMessage ExitWindowsEx LoadIconW DestroyIcon IsIconic DeleteMenu CheckMenuItem ModifyMenuW WindowFromPoint ClientToScreen TrackPopupMenu IsHungAppWindow GetWindowThreadProcessId AppendMenuW CascadeWindows TileWindows GetPropW LockWorkStation ScreenToClient RegisterClipboardFormatW RegisterPowerSettingNotification UnregisterPowerSettingNotification NotifyWinEvent ValidateRect GetSysColor DrawFocusRect AdjustWindowRectEx CopyIcon MsgWaitForMultipleObjects MonitorFromRect RegisterWindowMessageW CreateIconIndirect FindWindowExW GetSysColorBrush AllowSetForegroundWindow GetSubMenu EqualRect SetPropW RegisterClassExW GetDlgItem EnableWindow GetDlgItemInt LoadMenuW SetMenuDefaultItem RemoveMenu DrawIconEx SetGestureConfig SetDlgItemInt IsDlgButtonChecked GetMessageExtraInfo CalculatePopupWindowPosition AdjustWindowRect DrawTextW SetCapture CallWindowProcW CheckDlgButton IsWindowEnabled LoadAcceleratorsW |
msvcrt.dll |
strchr
iswalpha wcschr memset memcpy memcmp memmove wcsrchr _wtoi _wcsicmp bsearch _unlock __dllonexit sin cosf ceil _vsnwprintf free wcsstr realloc malloc _XcptFilter _amsg_exit __wgetmainargs __set_app_type exit _onexit __CxxFrameHandler3 _exit _cexit __setusermatherr _initterm __C_specific_handler _wcmdln _fmode _commode _lock ?terminate@@YAXXZ sqrt |
ntdll.dll |
RtlNtStatusToDosError
NtQueryInformationToken RtlGetProductInfo NtQueryInformationProcess NtSetInformationProcess WinSqmIsOptedIn WinSqmSetString WinSqmSetDWORD WinSqmAddToStreamEx NtOpenThreadToken WinSqmEventEnabled WinSqmAddToStream RtlQueryWnfStateData NtSetSystemInformation WinSqmIncrementDWORD NtClose NtOpenProcessToken |
SHLWAPI.dll |
#260
#278 #240 #193 #163 StrCmpW #571 #467 AssocQueryStringW #433 SHDeleteKeyW #560 SHRegGetUSValueW #548 #212 #184 PathIsNetworkPathW #213 SHOpenRegStream2W #631 #629 #16 PathQuoteSpacesW SHDeleteValueW SHSetValueW SHGetValueW #618 #635 PathGetArgsW SHRegGetBoolUSValueW StrChrIW #413 #478 #460 ChrCmpIW #510 AssocQueryKeyW PathStripPathW #509 PathIsRootW #156 PathParseIconLocationW StrCmpIW #437 PathIsPrefixW #225 #177 #178 #484 SHCreateStreamOnFileW SHQueryInfoKeyW StrCmpNW StrTrimW #12 #168 PathStripToRootW #256 StrRetToBufW #24 PathCommonPrefixW #503 #502 SHStrDupA #154 #236 PathRemoveExtensionW PathIsFileSpecW #487 #439 #632 #215 AssocCreate #476 #217 StrRetToStrW PathFileExistsW PathGetDriveNumberW #630 #204 #165 #197 #157 #292 PathRemoveFileSpecW PathIsDirectoryW #479 #388 StrStrIW StrCmpNIW PathRemoveBlanksW PathRemoveArgsW SHRegGetValueW PathFindFileNameW #174 SHSetThreadRef SHCreateThreadRef #10 PathCombineW #158 #9 #8 StrChrW StrToIntW #270 #176 #199 SHStrDupW #172 #175 #164 #219 #279 PathFindExtensionW |
SHELL32.dll |
#152
#23 #28 SHGetSpecialFolderLocation SHBindToFolderIDListParent SHBindToFolderIDListParentEx #95 #850 SHGetFileInfoW #727 SHChangeNotify #747 SHGetItemFromObject #723 #100 #85 #18 SHParseDisplayName #155 #190 SHGetFolderLocation SHGetSpecialFolderPathW SHBindToObject #89 #245 #200 #68 #680 SHGetKnownFolderIDList ShellExecuteExW SetCurrentProcessExplicitAppUserModelID #899 #188 #840 #906 #904 #201 #206 SHGetNameFromIDList #892 SHCreateShellItem #67 #711 SHChangeNotifyRegisterThread #19 #16 #17 #25 #21 #137 #733 #753 #644 #645 SHGetPathFromIDListW #731 #4 #244 SHFileOperationW SHGetFolderPathEx #2 SHUpdateRecycleBinIcon #60 #896 #64 #61 SHBindToParent SHGetFolderPathW SHGetPathFromIDListA ShellExecuteW SHEnableServiceObject #54 #254 #886 #91 #132 SHGetIDListFromObject SHCreateItemFromIDList #893 SHAddToRecentDocs Shell_NotifyIconW Shell_NotifyIconGetRect ExtractIconExW SHEvaluateSystemCommandTemplate SHCreateItemWithParent SHCreateShellItemArray #660 SHCreateShellItemArrayFromIDLists #102 SHAppBarMessage #162 #894 SHGetPropertyStoreForWindow #181 SHCreateAssociationRegistration #22 SHGetStockIconInfo #241 #6 #895 #902 #74 Shell_GetCachedImageIndexW #154 #88 #193 #790 #787 SHGetLocalizedName SHCreateDataObject #165 #885 #814 #818 #849 SHCreateItemFromParsingName SHCreateShellItemArrayFromShellItem #265 SHGetKnownFolderPath DragQueryFileW #134 |
SHCORE.dll |
SetProcessReference
|
ole32.dll |
CoTaskMemFree
CoCreateInstance CoRegisterClassObject CoRevokeClassObject CoWaitForMultipleHandles CoGetApartmentType OleInitialize OleUninitialize StringFromGUID2 CoRegisterMessageFilter CoFreeUnusedLibraries CoMarshalInterThreadInterfaceInStream CoReleaseMarshalData CoInitialize RegisterDragDrop RevokeDragDrop CoGetInterfaceAndReleaseStream CoGetMalloc CoTaskMemAlloc CLSIDFromString CoTaskMemRealloc CoCreateFreeThreadedMarshaler CreateBindCtx PropVariantClear ReleaseStgMedium CreateStreamOnHGlobal CoInitializeEx CoUninitialize |
OLEAUT32.dll |
SysFreeString
SysAllocString SysAllocStringLen SysAllocStringByteLen VariantInit VariantClear |
UxTheme.dll |
GetThemeMargins
EndBufferedPaint DrawThemeTextEx BeginBufferedPaint GetThemePartSize GetThemeBackgroundContentRect GetWindowTheme DrawThemeParentBackground GetThemeBackgroundExtent DrawThemeText GetThemeTextExtent DrawThemeBackground GetThemeMetric SetWindowTheme CloseThemeData BufferedPaintInit IsCompositionActive IsAppThemed GetThemeFont GetThemeColor #97 #99 #95 #98 #86 IsThemeActive BufferedPaintClear GetBufferedPaintBits DrawThemeIcon GetThemeBool BufferedPaintUnInit OpenThemeData GetThemeBackgroundRegion IsThemePartDefined GetThemeRect |
POWRPROF.dll |
CallNtPowerInformation
GetPwrCapabilities |
dwmapi.dll |
DwmQueryThumbnailSourceSize
DwmSetWindowAttribute DwmEnableBlurBehindWindow #113 #124 DwmUpdateThumbnailProperties DwmUnregisterThumbnail #114 #127 DwmIsCompositionEnabled |
gdiplus.dll |
GdiplusShutdown
GdiplusStartup GdipAlloc GdipDisposeImage GdipCreateFromHDC GdipDeleteGraphics GdipSetCompositingMode GdipSetInterpolationMode GdipDrawImageRectI GdipCloneImage GdipGetImageWidth GdipGetImageHeight GdipCreateBitmapFromHBITMAP GdipFree |
Secur32.dll |
GetUserNameExW
|
USERENV.dll |
GetProfileType
|
WTSAPI32.dll |
WTSFreeMemory
WTSQuerySessionInformationW |
TWINAPI.dll |
#19
|
api-ms-win-core-path-l1-1-0.dll |
PathCchAppend
PathCchCombine PathCchAddExtension |
RPCRT4.dll |
RpcBindingFree
NdrClientCall3 RpcBindingFromStringBindingW RpcStringBindingComposeW RpcBindingSetAuthInfoExW RpcStringFreeW I_RpcExceptionFilter |
PROPSYS.dll |
PropVariantToStringAlloc
PropVariantToGUID PropVariantToUInt32 PropVariantToBoolean VariantToInt32WithDefault VariantToBooleanWithDefault PropVariantToString VariantToStringWithDefault VariantToStringAlloc InitVariantFromResource PSCreateMemoryPropertyStore |
WINTRUST.dll (delay-loaded) |
WTGetSignatureInfo
|
Attributes | 0x1 |
---|---|
Name | WINTRUST.dll |
ModuleHandle | 0x134550 |
DelayImportAddressTable | 0x133000 |
DelayImportNameTable | 0x11fb20 |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.2.8102.0 |
ProductVersion | 6.2.8102.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Windows Explorer |
FileVersion (#2) | 6.2.8102.0 (winmain_win8m3.110823-1455) |
InternalName | explorer |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | EXPLORER.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.2.8102.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2011-Aug-24 01:07:33 |
Version | 0.0 |
SizeofData | 37 |
AddressOfRawData | 0xfa22c |
PointerToRawData | 0xf982c |
Referenced File | explorer.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2011-Aug-24 01:07:33 |
Version | 565.30117 |
SizeofData | 8 |
AddressOfRawData | 0xfa224 |
PointerToRawData | 0xf9824 |
Size | 0x70 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140134548 |
XOR Key | 0x349bafd9 |
---|---|
Unmarked objects | 0 |
187 (30716) | 2 |
189 (30716) | 75 |
185 (30716) | 47 |
Total imports | 1142 |
198 (30716) | 119 |
188 (30716) | 32 |
183 (30716) | 1 |
186 (30716) | 1 |