f43adfe423dc03e3aa5ca355553706a3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Aug-06 15:00:14
Detected languages English - United States
Debug artifacts C:\Release\misinterpreted.pdb
Comments Identically Bkmarks Delete Networkinterface
InternalName Attached
ProductName Attached
FileDescription Identically Bkmarks Delete Networkinterface
LegalCopyright Copyright 2015
CompanyName Bitdefender LLC
ProductVersion 1.9.7.964

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • LoadLibraryW
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegCreateKeyExA
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegQueryValueExW
  • RegDeleteKeyA
  • RegDeleteValueA
  • RegSetValueExA
  • RegEnumKeyExA
  • RegQueryInfoKeyA
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • #101
  • #9
  • #2
  • #23
Info The PE's resources present abnormal characteristics. Resource 8286 is possibly compressed or encrypted.
Resource 9191 is possibly compressed or encrypted.
Resource 9446 is possibly compressed or encrypted.
Resource 9447 is possibly compressed or encrypted.
Resource 9448 is possibly compressed or encrypted.
Malicious VirusTotal score: 40/67 (Scanned on 2018-10-12 03:42:22) MicroWorld-eScan: Trojan.GenericKD.40387862
CAT-QuickHeal: Trojan.Agent
ALYac: Trojan.GenericKD.40387862
Zillya: Trojan.GenericKD.Win32.148723
K7GW: Trojan ( 0053a32b1 )
K7AntiVirus: Trojan ( 0053a32b1 )
TrendMicro: TROJ_GEN.R004C0OHE18
Cyren: W32/Trojan.UYFX-8749
Symantec: Trojan.Gen.2
TrendMicro-HouseCall: TROJ_GEN.R004C0OHE18
Avast: Win32:Malware-gen
Kaspersky: Trojan.Win32.Agent.qwhdst
BitDefender: Trojan.GenericKD.40387862
NANO-Antivirus: Trojan.Win32.DarkVNC.fhqfrc
Tencent: Win32.Trojan.Agent.Eawo
Ad-Aware: Trojan.GenericKD.40387862
Sophos: Mal/Generic-S
Comodo: UnclassifiedMalware
F-Secure: Trojan.GenericKD.40387862
DrWeb: BackDoor.DarkVNC.1
Invincea: heuristic
McAfee-GW-Edition: BehavesLike.Win32.Generic.bc
Emsisoft: Trojan.GenericKD.40387862 (B)
Paloalto: generic.ml
Fortinet: W32/Agent.CHUI!tr
Antiy-AVL: Trojan/Win32.Agent
Endgame: malicious (high confidence)
Arcabit: Trojan.Generic.D2684516
ZoneAlarm: Trojan.Win32.Agent.qwhdst
AhnLab-V3: Win-Trojan/Sagecrypt.Gen
McAfee: RDN/Generic.dx
MAX: malware (ai score=99)
Cylance: Unsafe
ESET-NOD32: a variant of Win32/Kryptik.GJSX
Yandex: Trojan.Agent!U8JOfcSIljM
GData: Trojan.GenericKD.40387862
AVG: Win32:Malware-gen
Panda: Trj/GdSda.A
CrowdStrike: malicious_confidence_80% (D)
Qihoo-360: Win32/Trojan.777

Hashes

MD5 f43adfe423dc03e3aa5ca355553706a3
SHA1 49803073dd274c8740e0163fc30300cbae8f2cc9
SHA256 7c9f3607e7ded8209a0d73274834dc35cc0b0300ffb882f0dd4d4114959e9ece
SHA3 df22a28b1db4e6788a14ff8fec0774583385e639269838c3c6b577eaffc7fc87
SSDeep 12288:5V18cvDNpMkee5PtFw98fP9PBRZJuU0owFq3LtFDKVL74uq7o8BM6B7iW:HvDl5PtPZJ/l9tFW6uYoIBAW
Imports Hash 915bdaef6797e6d38b14cb670e296c2f

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2018-Aug-06 15:00:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x24e00
SizeOfInitializedData 0x93e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00012325 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x26000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0xbe000
SizeOfHeaders 0x400
Checksum 0xc36be
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 84556625169cfba4f5c1b2c2f30b3a57
SHA1 e1305c63341688bf8d6e4b2211d42a45492f9cc2
SHA256 ded6102a8d0ba4b5eba330ac99d6349ed48b35a3f2c3f073906d0bd2808094ae
SHA3 e8d860c5873894a232d2b8774200cf541e430e30a17aae2e1b4d746bdc0ebf40
VirtualSize 0x24d73
VirtualAddress 0x1000
SizeOfRawData 0x24e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.68747

.rdata

MD5 1ada875e56797979a25feaac7a1bae5b
SHA1 ed6b8afe12fdb9058e9d0f4e8532a5b32a233237
SHA256 036764c43e293f1aaf7e39067d7a713062515fcbedab7c900205bde0d4adb437
SHA3 99fb60fc299229b607a5b2ffb576846925f4f4a197e2d64c980629e68c5e9e2b
VirtualSize 0x9608
VirtualAddress 0x26000
SizeOfRawData 0x9800
PointerToRawData 0x25200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.09198

.data

MD5 1eb79560f516b0ad67ef9daae37ac89c
SHA1 51ab161bdcb6dea5cd44800af71c7092c841d147
SHA256 b64c3179dfc31a6b271723fbc5a099cfc1408c9601c66c5899a4dbd9d55d256a
SHA3 16391cc81a3dfda327cc89a9b261e27f4ab0ccf58e45197e7828c9dd8aecddf7
VirtualSize 0x5084
VirtualAddress 0x30000
SizeOfRawData 0x3400
PointerToRawData 0x2ea00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.04737

.rsrc

MD5 6612a7cf80b82adad5a2c6f167252904
SHA1 76ba291f50927b2665b378bd65d12e079334765d
SHA256 931a929d3691c9e8899753c7f396cdd94fee642d286de8cefd9e7817e92d956d
SHA3 4c1f320fa2b75c056a1916a645c73927850adf62b7a4ddb19dbb223559dc5c5d
VirtualSize 0x871bc
VirtualAddress 0x36000
SizeOfRawData 0x87200
PointerToRawData 0x31e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.78787

Imports

KERNEL32.dll FindResourceA
LoadLibraryExA
LoadLibraryW
LoadLibraryA
VirtualAlloc
WaitForSingleObject
CreateEventA
FillConsoleOutputCharacterA
GetTimeFormatA
FileTimeToSystemTime
FileTimeToLocalFileTime
ReadFile
SetEndOfFile
GetConsoleOutputCP
WriteConsoleA
CreateFileA
CloseHandle
FlushFileBuffers
SetStdHandle
InitializeCriticalSectionAndSpinCount
GetLocaleInfoA
LCMapStringW
LCMapStringA
GetConsoleMode
GetConsoleCP
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetUserDefaultLCID
SetHandleCount
ExitProcess
Sleep
WriteFile
HeapSize
HeapReAlloc
LoadResource
HeapCreate
GetStringTypeW
GetStringTypeA
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
GetStartupInfoA
GetCommandLineA
GetModuleFileNameW
GetStdHandle
GetFileType
WriteConsoleW
RtlUnwind
VirtualQuery
GetSystemInfo
GetModuleHandleW
VirtualProtect
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
VirtualFree
IsProcessorFeaturePresent
SizeofResource
FreeLibrary
MulDiv
IsDBCSLeadByte
GetModuleHandleA
GetProcAddress
InterlockedIncrement
GetLastError
lstrlenW
WideCharToMultiByte
MultiByteToWideChar
FindResourceExW
GetModuleFileNameA
GetLocaleInfoW
DeleteCriticalSection
InitializeCriticalSection
SetLastError
OutputDebugStringA
RaiseException
DebugBreak
GetCurrentThreadId
InterlockedDecrement
LeaveCriticalSection
EnterCriticalSection
HeapAlloc
GetProcessHeap
HeapFree
InterlockedCompareExchange
lstrcmpiA
lstrlenA
CompareStringA
GetCurrentProcess
GetSystemDefaultLCID
FlushInstructionCache
GetVersionExA
SetFilePointer
USER32.dll CreateWindowExA
SetWindowLongA
SystemParametersInfoA
GetWindowLongA
GetWindowTextA
UnregisterClassA
GetClientRect
GetParent
GetDlgItem
IsWindow
SetWindowPos
MapWindowPoints
GetMonitorInfoA
GetWindowTextLengthA
FillRect
DrawIcon
EndDeferWindowPos
AppendMenuA
LoadIconA
CreateMenu
GetKeyState
SetActiveWindow
LoadAcceleratorsA
CreateDialogParamA
RedrawWindow
IsWindowVisible
PeekMessageA
GetMessageA
TranslateMessage
DispatchMessageA
MonitorFromWindow
DialogBoxParamA
GetSysColor
GetFocus
GetCapture
ReleaseCapture
EndPaint
BeginPaint
GetCursorPos
SetCursor
DrawFocusRect
ShowWindow
PtInRect
CallWindowProcA
GetDlgCtrlID
SetFocus
SetCapture
IsWindowEnabled
InvalidateRect
UpdateWindow
ScreenToClient
SetRectEmpty
DefWindowProcA
PostQuitMessage
LoadImageA
IsDialogMessageA
DestroyWindow
GetClassNameA
LoadCursorA
OffsetRect
ReleaseDC
GetDC
CharNextA
DrawTextA
SendMessageA
EndDialog
GetWindow
GetWindowRect
GDI32.dll SetBkMode
GetTextExtentPoint32A
SetTextAlign
SetBrushOrgEx
SetTextColor
CreateFontIndirectA
GetStockObject
DeleteDC
GetObjectA
SelectObject
DeleteObject
ADVAPI32.dll RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegQueryValueExW
RegDeleteKeyA
RegDeleteValueA
RegSetValueExA
IsTextUnicode
RegEnumKeyExA
RegQueryInfoKeyA
RegCloseKey
SHELL32.dll ShellExecuteA
ole32.dll StgCreateDocfile
CoTaskMemAlloc
CoTaskMemRealloc
CoUninitialize
CoTaskMemFree
CoCreateInstance
CoInitialize
OLEAUT32.dll #185
#9
#15
#23
#24
#19
#8
#277
ODBC32.dll #75
COMCTL32.dll InitCommonControlsEx
_TrackMouseEvent
WS2_32.dll #101
#9
#2
#23
NETAPI32.dll NetApiBufferFree
NetServerEnum
MSACM32.dll acmDriverOpen
WINMM.dll waveOutUnprepareHeader
pdh.dll PdhBrowseCountersA
OPENGL32.dll wglShareLists
IMM32.dll ImmGetDefaultIMEWnd
WTSAPI32.dll WTSQuerySessionInformationA
AUTHZ.dll AuthzInitializeObjectAccessAuditEvent
AuthzInitializeResourceManager
AuthzInitializeContextFromToken

Delayed Imports

363

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33609
MD5 27fc5529ad790189bbf410c7e3a70fb7
SHA1 ea2456c9b26f884a7f7abb051f460ec98cb9451c
SHA256 601635482a9b1864ea0c61ce0282c5c9fe1d014aa95dbb4f60770f1c2b6df3da
SHA3 24ab306744896452b2a7f7055c97671ab0aad3965342b3d0cead7a6cb640238d

364

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.31114
MD5 49ca9d25ceb458297ddf84fff64c8d55
SHA1 fbd6d992b7e2a59c9e24372ea8d30a5dcdbd46f9
SHA256 f9c81ce9b4176b305c554a15f0ca2b98b11be76c1f13ef22169999aa07e9612f
SHA3 03f7002b636940864ef7d399ba60fb8de3f455da32f311ee39cdf6602c5d348b

365

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.40163
MD5 9f8bed0e96d3a3f70f98386a4e1a52f7
SHA1 6818ba2b5256229158d2e2ab68d6200b38647037
SHA256 82d14b20a8d9635d59f1432a9a220864bf429cfbd888c5256377e4a2b710bd3e
SHA3 57d41639cb36de10f25c9acd33e187884376a6164f2ad45bc77b429199ec7e0e

366

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34038
MD5 d78a341fa7444ba9ccb74ad0c943d0ac
SHA1 a3fdcb001587c47b72f06441087455e8027baca1
SHA256 652988945185cf5d604d9b48de66288d82d8ed0acdd134398e90d002d2d9fc72
SHA3 2ddf8193c735adcec9a83d3a9032dc70796778b1d0c967a43789f1a6bb3da15f

367

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x10ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.602623
MD5 0706ea491fb80740fddcd935e6898099
SHA1 9f6929403b85312d6021dc9d06bd5c9cd8360d84
SHA256 ee223cba4fe240e36aed483815d9cdbdd9fd3c0e79bf63d123709559f414a088
SHA3 ea301aa270b7e3de12a416c72eefd1c80f1a424a7989adfedf1f8dac753d028c

734

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81491
MD5 ff43eaab521694d0356618a92cd83b55
SHA1 f1ed8d456a5a3d87d1a8349e992c99e22bf3624e
SHA256 cfc4ff9e46fbb61f61b68f36adc6593b137233d1cbaa50fe37e5653f0cb20396
SHA3 7069692bfbe0c043b33390a40f8033c3d0aa3092c3b1ca1b01fc899dc760ec48

735

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10016
MD5 4bfaa5ad112338fc90bf84b1ba21859d
SHA1 f175fb276720b4f98bc75dd3edc8c53ed563bdf4
SHA256 c4a6e3a7a346baecb09a0c49268eb44f388382a7866a4e912b53d48fa3b34c26
SHA3 eb1f5efadebebc4b756ef49661343ee08641f53184ad8ee83e33d6665028a00d

736

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x10ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.65455
MD5 70550ddcab807bee447ccfd3486b8345
SHA1 28cd0bfa4a6a3c5e32199f3fd5b443514fd50b10
SHA256 0765e630d7898abd70007627820e65612d35c70ada3f1be34b97b89864aac46e
SHA3 df89580a19aea3bfd7a1c817077add3b57a2eb7c8e69680965790d90f7c81529

737

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.5106
MD5 978155561ed11394711656fbab914c78
SHA1 298e046248ee5db2b74e4ef2730326f9471321c9
SHA256 7ab6ed60fc59f41d188c7df233828157e82573e71e2057886d8b87713784fd2d
SHA3 90b2ef4fe35ebe7cd2ae9961d58fa24944359fb88ee57b3b6472d336fb2275f6

738

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74274
MD5 9fa8a914823ac7e5370652146901f4f1
SHA1 eb3224109abb341b6e464d2606fdbed1a7160bc6
SHA256 f64ccc0582bc7c66af8b40049e485e8e241335261ec95ace909293ba50b2e4a3
SHA3 bb348af06514e27cd1fa21ad524dfd037edcd3b36ef4cc6ab24c4a8ec38995ff

739

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34505
MD5 0a12283479aa8a8677dd27bb0f584a34
SHA1 63679153c4d14fc591d1286cc98ff5044a5b589d
SHA256 322e92d75b3fec9e16b81466f4cf111d298b80812d5b238f4ee032c025a02050
SHA3 d6fc5e08b9d51b2cc80c1a2a34ca495e28edd0ca1bc65f317958b773c675de7e

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x16e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.93533
MD5 17943bcf1b7809181e95bd994c54d8b6
SHA1 7464aed5e1694741fe5aaf26e4d1836105e5d2b9
SHA256 29862d159a57bb6e7c2bdc14f85a406a49992322b758ed6eb82d063f7277ecc7
SHA3 5c14a794b7a0cc9db0d9cc326b90940c06affd2f42eb2fb5dd95137759e3ef81

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.69318
MD5 42a16b3c3b3068dabe0c0370ef1e7a77
SHA1 0acdd7d81267cc59b67774b18a38d17dd0f2b54a
SHA256 4e34fa9d8a907ebc3bb1fb826fba5493b9845eed2c58c813774d0ab40b4ee229
SHA3 bbbd54aab6eacb6ba485298dfb9253a548225e9dbc8785e7c099afc1a8de8746

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05225
MD5 9f0264db4864fd0d80f28d4343762dab
SHA1 30a34673abaabd02eaf881c9e809eb11caacf709
SHA256 0d5c5782eaa244c5ff5f48d4061001fd493fd0c037524f1cc8a57942eba93864
SHA3 bd4bee144f193565c419d3b2a5ba3fa82098020fdb85e7b575daa7a4f439c0a9

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.00809
MD5 def09f872453f9d638b72ff42726c251
SHA1 ffb5918635c2d0f6a800b84c4bf8df2ca1a74eb7
SHA256 c162d193ee2cb59cc74b8c58c6bd625b9ae4254026e5c234e95894a291545efa
SHA3 20809e97c73758ec3fd2f7cd7fcf3c20b54c285f26cf0728f081d7114f9f194c

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33953
MD5 acd667bbb8ab3371617e16cc28d6566e
SHA1 d9d43ec51b579ddc7f32829bce0085f88b9a0428
SHA256 9bf6d2c354213debec1c7618a5c853bd3cbc0a03654c3548af7b84ae99109298
SHA3 2d403020e4c6cfa9817f6eee0702e336c1eb179b3d18b85f8cda0e56011376ae

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.27232
MD5 b6c5a20f642e2372c33401b179f9c271
SHA1 90d2b505ae57546ae62a86284539bc251d95f4a3
SHA256 c72698ed938e46324df13a6bba35f7dfcc5ea4ef014dde847d6447882a29e753
SHA3 0d0101b5b77221e33868ae3f9e3095aee3a0bac2d09db566b59aae6c376fc95e

9086

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x27a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76686
MD5 a152f8c41867da07b18a02256315e93d
SHA1 6160270f1dc51018175816007ea8e4476385ae0e
SHA256 63325e7721307e2f05e83a7c8c3a08c6d5ad34f8f2f5ec4b4f09c51da60535c3
SHA3 50d3faf068b8d96fe60c6f46dfe232d07719474f5e7b8acae664ed87da7cade2

9404

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x48c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.56948
MD5 fb6d29acea3ba8e6c708a17a08136b7b
SHA1 a5c321ea3c967edb4a76d272135c42734a1b9892
SHA256 c7dd572d1d1196e5db9f0c2becd7b444d2f9e29aba7048179c2a26bed34c3e81
SHA3 ed4d2d76774e64b3dd4e6f8b0b6c06e4ff46609ef8c1ad61d7732af55c760be3

9666

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1345
MD5 940f2cbc9ce010819a801e9ae44e3d14
SHA1 37484141fb271b0dccc26239ebd7ba23a67c72af
SHA256 87596a1507381b9941c395edffc5c2c29f16e93360133584537dabff54089bd1
SHA3 9324ad2867b7e3e4a72a55223fe326e3ec753386ef3201b69c60c15755d5b0cd

9837

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x34
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.41669
MD5 72723d63b211c60717138184c1675b66
SHA1 ecd2be6587bb32a080e51b5c3f3a816e8b637c85
SHA256 4cf716efaf68e0cb2ec45ec55d291050b5712b05653cae68edbb999f803d2a98
SHA3 6031fa1100e39d04c89ed42890fe9833adb0503fe1857940533b7356aec9d306

9838

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.66181
MD5 bb611b5da5775e0c5a2fbec4fbe87622
SHA1 feaeb8607d983f19c5c13ff2fb0b384f86465e80
SHA256 a5f1f74b431caa139a61423edb3d2a6b81f5e5821549f1fc977445121680050d
SHA3 35302c5ebeab2915c3b3e8dff3cfefc6a54048245669ffd9bea2bec33cb789e0

310

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ea
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.86979
MD5 78be25532304baf816b743990412285d
SHA1 163ebfc35f6d1edfad25820f7d1f23ed3fc55ec8
SHA256 4cb2236eb8a5b567fb071185433c2d958bf38c01df896470b9902fba35b0219d
SHA3 28c09fe474546ae130a4ec8aa6b1be38b7c11d5d3ba2871bd05aa35a480c8966

311

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.28243
MD5 22a0abe6424a7c57be89589d81a8dec8
SHA1 b33c036859e702a34625aa1c62ec057bf1eab90d
SHA256 02963252086101cbeaf33737f04208f00dee09db23742fa192f71c2133e9fcd0
SHA3 36913af80467d58a052563f97b8d6bdb42762cc9ffe5e3a36a6bd32eb5fed984

574

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa1c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24289
MD5 d16927c7ef9f0a32da6fbf1ed184849f
SHA1 d19494824c4137b9a542d3102ff2a30bfa18bba0
SHA256 790c41de3b6c94e2c1ffed6f28918f72dd3829c52c0cc72b302a0f0275903f69
SHA3 501358510b89d04ba63219f06d643bc65a725120d4a34e76baa336f5331e7d84

575

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x23c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.48121
MD5 d5e033fa8aa4a74a9043445a4535c388
SHA1 4e0cbac9d6c19ff06b76e6e601f496d3317587c5
SHA256 58a2475654e31b5f7c22f7f3b4826c4be291461ad8a51abd5271db9e9996d3e0
SHA3 4faa4ffdc837f7dc6c880ee515d3da8fcee0d0c3328261f27441832aa1ba21dc

576

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xe6a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2501
MD5 3d81447028eedd62e2a661d4b8fce7bf
SHA1 79e96e8db2ce0752a886748f95586fc9ae1dedab
SHA256 470e537b238ceb25094b98970e142a2d38c4fe5a5479fa037919d6d39af10e44
SHA3 01d5616da51c1905bd5984bb8fdf168289825a9745c88fbbcbe0dad8e98db9f8

968

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21924
Detected Filetype Cursor file
MD5 717df67f121c85ba4c651b0ea636b674
SHA1 362f583a190ee88d16010fec1f1f1c91cae4ede7
SHA256 fa3ecdbf7ea4a076608fb8dfc75d03c5e6af70061c1062ec221c207071d3d812
SHA3 ac88b8768d92d69e173c526f369c8c779caa7f2385af9cfaa62d3695b6ef5646

969

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21924
Detected Filetype Cursor file
MD5 b762c445488032cf104e0bcb0bfa3d61
SHA1 d0726975ce0bcb1b4ce4e324866b9abb336be0aa
SHA256 0866e7a3c13ad68d9270475d7c097fa58ebed372eda46d07cd4a6be44326eff3
SHA3 962fcb3d59983fcfea85d265091790b14f04dfe832816a854ac1ec73827b529f

970

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.05878
Detected Filetype Cursor file
MD5 7e68da438d06972412341d26a0b154e0
SHA1 2e8b4399fad4b323487c836ad0ad8b3042ba877d
SHA256 1ae3e871bb24efadc5c3ed9b87b902421883b191abb09c3d1033e38d9e538d4b
SHA3 d24bacc625f1fc96c0271b4dba4103749c504fb542a9af06709a51eaff6aaf3e

971

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.25451
Detected Filetype Cursor file
MD5 7dc72975fd1b452d93754743dab09689
SHA1 14a6c5a72a6b97df5c6a89ec97ef36b4c8c3be9b
SHA256 acf4cb3670de9fc2ad284380e472c7b077f3f357fabadd2fe21e473e4a1b99c6
SHA3 f3e606c7ce891a9d559ede273e6cc2a09ca7983f4f21c337fa28c04a5275da0c

972

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 b3dbdfe1835416bbc3f5065baca9aca9
SHA1 334d5af1355f6a13c35be4ad16e76baaecf209f1
SHA256 ec26c438d10e3e84ec855c47f07a176e6c11bbfae1557d526490711b80f087fe
SHA3 2409b439f48a139d3764b226eda46c6a629d5bd208991369ae0c85e37c17c71d

977

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 22a9b94eda22d068a6823a72268fdada
SHA1 7923c0aa606f67498391ecdb828292fcc3bc3ed6
SHA256 a2f0549cca7170ae03ba042464efe62365fba38c20049e439871c9e5ce0f914f
SHA3 565227501bdf04ce5d2afeb14e48062d4cdd6de7b76c62d26a15f6e4a34ba5c1

978

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 5df05404b0dab444d7bc0fe0bee0d519
SHA1 ecbc2591eaf234bcc87df4731b5e26266728ff6d
SHA256 28b8110695851e5280ff55cb78507b03e8b74dd370b8e122179c82b56f7e5f37
SHA3 f18323f0f4e67af79d43a527df26273c9f7e53e73b1ba51cd426cff3412927d2

979

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1cd71148c4a650e298e26668e22c3733
SHA1 5aeaabee3ae2ad999e9ed91c85119a42c83473c6
SHA256 4ecc7f2578fd7b137c04f85ffcbd67d6eab0bc8b1df4246cebd2a2aa517f3c60
SHA3 89ccb4ca5392e186b8eeb9848f78a12843e40792c3500e104225869bf9be1894

980

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.25451
Detected Filetype Cursor file
MD5 b0cb31fcbc28823843fc2f620f026e52
SHA1 d5db4f24dc38e069256a220ca69a29245e9bfc06
SHA256 bb88f756ae5fa20409bbc7bc8e0bd3a7d04838dee9eb76559d5927350604d196
SHA3 d640a836c1df70324c94a7e057e7eec01cdcff62f8d252a6a51d6e4345d72885

981

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 975596b334c3811a6899d17dc1083c83
SHA1 77adb688a202706cd60619067d29413db049e2c3
SHA256 749de8c6268f233434feebbff1f5f5539d32cb07e993e3683224a191a035362e
SHA3 f71229575da7bdbcc657ce7b3d0ea4a9395a2a1c748478c6d01ff7cc47ba620c

101

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03869
Detected Filetype Icon file
MD5 3ffc817cff13f88f85246b2dca97e936
SHA1 8aac2c4cce94c8c8351ee08c09b7f3dfeec8aa62
SHA256 e65b41fd58d668dd5c74548217df4c27e5add145117a7b7f6c43830c160a532d
SHA3 d8c37047449e000dfdd6b3edbf68755390cd618dd774470cc597109299d9e2a7

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x304
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44177
MD5 f0125d7f56ff42e3a690e433ad9207ed
SHA1 5661c080f7c7cde46081b34b49c98e07d7028b7f
SHA256 dc575b87c5248559e4bd66571613e3b59699e60f2e720785653b66d05644853c
SHA3 4168c50dcc33063b339c29e02ab332647c4c15cc8213e62511edee4e21d89b23

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x291
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93343
MD5 1bfa84a0d9e52454e8f24612c123fd91
SHA1 78cdaf895a183ed1109b29481564be1a558ddfaa
SHA256 dc4043aea23c0887855bdb7b06345b9caaf395cc28cf2f260838fc21aa7f8f53
SHA3 f11af4c1e333209ea255718a0fe803d9b4f36c795a6a5c1fba01fcdfe3bc29d4

8286

Type UNKNOWN
Language English - United States
Codepage Latin 1 / Western European
Size 0x1871d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.96992
MD5 6d1d766a2d7271a9ba9eb1e2b8db94bd
SHA1 f3eeb5697d47e11dab94c8c0a78bdf1c7194527a
SHA256 1fb217005c9038a979b77ae323b9f46941aa7ffbcf94001c844a9bef8e2c2147
SHA3 2ba599d13ffc4896a14f035ed99958ade9b522ef03d3ad25cecb96f7ff9eb888

9191

Type UNKNOWN
Language English - United States
Codepage Latin 1 / Western European
Size 0x15b49
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9958
MD5 c05476242c36beeb97f38ee6487549b1
SHA1 1b0e33c4c0ad80274a804571432a91bc2c6d6425
SHA256 02ffe916347b70b85af3f709d0484ca4aff7bda8e304728f5fd0934abb62ba9b
SHA3 bfff1bd878343fea27d00bc0e4a19206bb0874528bff1a8ee85b7664075c60fe

9446

Type UNKNOWN
Language English - United States
Codepage Latin 1 / Western European
Size 0xadd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99361
MD5 0d014f3dfb40c12c3862dcac4230abea
SHA1 1c742443e6eca03bd737813df3c92837d74ccf55
SHA256 1134c21f1acc805a9304c7b3d123df62cf6b62b949d739eba36206aea468cfeb
SHA3 6e1fc88cbacdce8c8a0d66093ee9c86b12ed385969d944016e2e13a55ada3082

9447

Type UNKNOWN
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b292
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99655
MD5 5d70539f01aaef97a908022a8084d7e9
SHA1 eaa6b1d8b1e64f8128afe6d0f936d2840c07b636
SHA256 9aaec37df3c7874aff685ba700d341797c9ab1d9ff519b26b6adababbfd034f2
SHA3 808d6142df11dccb535cf5c5cb8e766948ffb88dc42a035c36996d9a18fa61a6

9448

Type UNKNOWN
Language English - United States
Codepage Latin 1 / Western European
Size 0x1de07
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99733
MD5 1522c21336ffc411349a9a009e293913
SHA1 8d77df48cb2dcd84d44c5cb246e0882d1b2a602a
SHA256 5888c6e59bae23a5a41f4d39d23f0a7dabaaf81e72a31f70fb99583432444324
SHA3 db7396cba9fafede51eb5028419c445085926787de023df452273dd5fa7dcc1a

String Table contents

ID процесса
Командная строка
ID родительского процесса
Путь процесса
Ярлыки
Название задачи
Значение по умолчанию
Путь Autorun.inf
Путь реестра
Цифровая подпись
Действительный
Недействительный
Путь файла
Размер файла
Версия файла
Описание файла
ピクセル
Élément de démarrage sensible du système
Élément de démarrage sensible du système observé par le centre 360 Security, dont dépend le fonctionnement des principaux composants du système.
Variables d'environnement système
Le système pourrait gérer l'invocation croisée entre tous les processus situés sous cet élément, ce qui est important pour son fonctionnement normal.
Tâches planifiées
Définir l'heure d'exécution d'un programme, comme s'il s'agissait d'un programme planifié.
Pilotes
Le logiciel renforce leur capacité à contrôler le système au moyen de pilotes, notamment les logiciels antivirus et un pilote matériel.
Services
Le logiciel renforce sa capacité de contrôle du système par le biais des services, notamment les logiciels antivirus.
Options d'exécution de fichier image
Les options d'exécution de fichier image seront réattribuées à un autre programme lors du démarrage du programme, mais ce dernier n'est pas parvenu à démarrer.
Élément préchargé de processus
L'exécution de tout programme charge automatiquement les modules spécifiés, et l'exécution des modules est automatiquement chargée.
Bibliothèque chargée par défaut
Tous les modules de programme situés sous ce dossier, considéré comme le point sensible du système, seront chargés en priorité au démarrage du système.
系統組態策略
系統工具或介面的設定,如鎖定登錄編輯程式、禁用快速鍵等。
舊版作業系統啟動項
作業系統為相容Windows 3.x版軟體自動啟動所設定的項目。
群組原則啟動項
系統啟動時會自動運行,這些程式通常是通過系統群組原則工具來設定。
系統登錄介面
為使用者登錄系統提供入口,通常支援用戶名/密碼來登錄系統。
系統登錄管理
管理系統登錄後將自動運行,通常這些程式是由系統指定的。
登錄對話方塊設定
系統預設的登錄對話方塊。
預設工作管理員
負責設定系統預設工作管理員程式,用於展示系統資源使用、行程清單等方面的資訊。
預設螢幕保護裝置程式
系統預設螢幕保護裝置程式。
Mantiene actualizado tu software de %1!s!. Si este servicio se desactiva o se detiene, tu software de %1!s! no se mantendrá actualizado, lo que implica que las vulnerabilidades de seguridad que puedan aparecer no podrán arreglarse y es posible que algunas funciones no anden. Este servicio se desinstala automáticamente si ningún software de %1!s! la utiliza.
Mantiene actualizado tu software de %1!s!. Si esta tarea se desactiva o se detiene, tu software de %1!s! no se mantendrá actualizado, lo que implica que las vulnerabilidades de seguridad que puedan aparecer no podrán arreglarse y es posible que algunas funciones no anden. Esta tarea se desinstala automáticamente si ningún software de %1!s! la utiliza.
No se puede conectar a Internet. Si utilizas un firewall, incluye a %1!s! en la lista blanca.
No se puede conectar a Internet. HTTP 401 no autorizado. Comprueba la configuración del proxy.
No se puede conectar a Internet. HTTP 403 no permitido. Comprueba la configuración del proxy.
No se puede conectar a Internet. El servidor proxy requiere autenticación.
No se pudo realizar la instalación debido a un error del servidor. Vuelve a intentarlo más adelante.
La instalación falló porque el acceso está restringido en este país.
El servidor devolvió el siguiente error: %1!s!. Vuelve a intentarlo más tarde.
Falló la instalación porque tu versión de Windows no es compatible.
Se produjo un error en la instalación porque tu computadora no cumple los requisitos de hardware mínimos de %1!s!.
Falló la verificación del archivo descargado.
Falló la descarga.
El programa de instalación no se almacenó en la memoria caché. Error: 0x%1!08x!.
El archivo de instalación no ha podido realizar la verificación. Prueba a descargar de nuevo el archivo de instalación.
El nombre de archivo del instalador %1!s! es no válido o no está admitido.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.9.7.964
ProductVersion 1.9.7.964
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Identically Bkmarks Delete Networkinterface
InternalName Attached
ProductName Attached
FileDescription Identically Bkmarks Delete Networkinterface
LegalCopyright Copyright 2015
CompanyName Bitdefender LLC
ProductVersion (#2) 1.9.7.964
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2018-Aug-06 15:00:14
Version 0.0
SizeofData 62
AddressOfRawData 0x2ca90
PointerToRawData 0x2bc90
Referenced File C:\Release\misinterpreted.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x431af0
SEHandlerTable 0x42d3f0
SEHandlerCount 18

RICH Header

XOR Key 0x700de2b4
Unmarked objects 0
C++ objects (VS2008 build 21022) 4
ASM objects (VS2008 SP1 build 30729) 43
C objects (VS2008 SP1 build 30729) 157
C objects (VS2012 build 50727 / VS2005 build 50727) 1
Imports (VS2012 build 50727 / VS2005 build 50727) 37
Total imports 245
C++ objects (VS2008 SP1 build 30729) 65
Linker (VS2008 build 21022) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

[!] Error: Could not locate RT_ICON with ID 12! [*] Warning: Resource 968 is empty! [!] Error: Could not locate RT_ICON with ID 3! [*] Warning: Resource 969 is empty! [!] Error: Could not locate RT_ICON with ID 1! [*] Warning: Resource 970 is empty! [!] Error: Could not locate RT_ICON with ID 100! [*] Warning: Resource 971 is empty! [!] Error: Could not locate RT_ICON with ID 8! [*] Warning: Resource 972 is empty! [!] Error: Could not locate RT_ICON with ID 13! [*] Warning: Resource 977 is empty! [!] Error: Could not locate RT_ICON with ID 11! [*] Warning: Resource 978 is empty! [!] Error: Could not locate RT_ICON with ID 15! [*] Warning: Resource 979 is empty! [!] Error: Could not locate RT_ICON with ID 5! [*] Warning: Resource 980 is empty! [!] Error: Could not locate RT_ICON with ID 30! [*] Warning: Resource 981 is empty!
<-- -->