Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2020-Apr-02 01:40:19 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
C:\jenkins\workspace\DFAppFoundation\drfonetoolkit\ModuleUpgrade\SharpUpgrade\Release\InstallAssistService.pdb
|
CompanyName | Wondershare |
FileDescription | Wondershare InstallAssist |
FileVersion | 1.0.0.5 |
InternalName | InstallAssistService.exe |
LegalCopyright | Copyright (C) 2020 |
OriginalFilename | InstallAssistService.exe |
ProductName | Wondershare InstallAssist |
ProductVersion | 1.0.0.5 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Wondershare Technology Co.
Issuer: DigiCert Assured ID Code Signing CA-1 |
Safe | VirusTotal score: 0/73 (Scanned on 2020-05-16 04:15:05) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2020-Apr-02 01:40:19 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x2a600 |
SizeOfInitializedData | 0x13c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00014B25 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2c000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x43000 |
SizeOfHeaders | 0x400 |
Checksum | 0x5060e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
MultiByteToWideChar
WideCharToMultiByte GetModuleFileNameW Sleep WTSGetActiveConsoleSessionId OpenProcess GetCurrentThread GetCurrentProcess CloseHandle QueueUserWorkItem CreateEventW GetLastError SetEvent WaitForSingleObject CompareStringW GetProcessHeap SetEndOfFile CreateFileW CreateFileA WriteConsoleW SetStdHandle LoadLibraryW HeapReAlloc IsValidLocale EnumSystemLocalesA GetLocaleInfoA GetUserDefaultLCID HeapSize GetLocaleInfoW GetCurrentProcessId GetTickCount QueryPerformanceCounter GetEnvironmentStringsW FreeEnvironmentStringsW GetTimeZoneInformation FlushFileBuffers GetConsoleMode GetConsoleCP WriteFile SetFilePointer ReadFile InterlockedIncrement InterlockedDecrement InterlockedCompareExchange InterlockedExchange GetStringTypeW EncodePointer DecodePointer InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection HeapFree HeapAlloc GetFileAttributesA CreateDirectoryA GetTimeFormatA GetDateFormatA GetSystemTimeAsFileTime GetCommandLineW HeapSetInformation RaiseException GetCPInfo RtlUnwind LCMapStringW TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent IsProcessorFeaturePresent GetACP GetOEMCP IsValidCodePage TlsAlloc TlsGetValue TlsSetValue TlsFree GetModuleHandleW SetLastError GetCurrentThreadId GetProcAddress SetHandleCount GetStdHandle InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW HeapCreate ExitProcess SetEnvironmentVariableA |
---|---|
ADVAPI32.dll |
GetTokenInformation
ControlService QueryServiceStatus StartServiceW ChangeServiceConfig2W OpenServiceW OpenSCManagerW DeleteService CloseServiceHandle CreateServiceW ReportEventW RegisterServiceCtrlHandlerW SetServiceStatus DeregisterEventSource StartServiceCtrlDispatcherW RegisterEventSourceW FreeSid AllocateAndInitializeSid OpenProcessToken OpenThreadToken EqualSid CreateProcessAsUserW SetTokenInformation DuplicateTokenEx |
ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
OLEAUT32.dll |
#9
#8 #6 #2 |
WTSAPI32.dll |
WTSEnumerateSessionsW
|
USERENV.dll |
CreateEnvironmentBlock
DestroyEnvironmentBlock |
WS2_32.dll |
#20
#2 #23 #3 #21 #6 #15 #115 #17 #9 #8 #11 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.5 |
ProductVersion | 1.0.0.5 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Chinese - PRC |
CompanyName | Wondershare |
FileDescription | Wondershare InstallAssist |
FileVersion (#2) | 1.0.0.5 |
InternalName | InstallAssistService.exe |
LegalCopyright | Copyright (C) 2020 |
OriginalFilename | InstallAssistService.exe |
ProductName | Wondershare InstallAssist |
ProductVersion (#2) | 1.0.0.5 |
Resource LangID | Chinese - PRC |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Apr-02 01:40:19 |
Version | 0.0 |
SizeofData | 135 |
AddressOfRawData | 0x30158 |
PointerToRawData | 0x2eb58 |
Referenced File | C:\jenkins\workspace\DFAppFoundation\drfonetoolkit\ModuleUpgrade\SharpUpgrade\Release\InstallAssistService.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x434674 |
SEHandlerTable | 0x431130 |
SEHandlerCount | 81 |
XOR Key | 0x42a70ff4 |
---|---|
Unmarked objects | 0 |
152 (20115) | 3 |
ASM objects (VS2010 build 30319) | 25 |
C++ objects (VS2010 build 30319) | 64 |
C objects (VS2010 build 30319) | 180 |
C objects (VS2008 SP1 build 30729) | 2 |
Imports (VS2008 SP1 build 30729) | 15 |
Total imports | 148 |
175 (VS2010 build 30319) | 8 |
Resource objects (VS2010 build 30319) | 1 |
Linker (VS2010 build 30319) | 1 |