× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 0eb673dbfc5e6a7b6d4a23ebda6031d8ec17ab46193166251829776b10b26c93
File name: HibernateOnPowerFail
Detection ratio: 1 / 50
Analysis date: 2014-01-26 06:55:20 UTC ( 2 months, 3 weeks ago )
Antivirus Result Update
Qihoo-360 HEUR/Malware.QVM19.Gen 20140122
AVG 20140125
Ad-Aware 20140126
Agnitum 20140125
AhnLab-V3 20140125
AntiVir 20140125
Antiy-AVL 20140125
Avast 20140126
Baidu-International 20140125
BitDefender 20140126
Bkav 20140125
ByteHero 20140121
CAT-QuickHeal 20140125
CMC 20140122
ClamAV 20140126
Commtouch 20140126
Comodo 20140126
DrWeb 20140125
ESET-NOD32 20140125
Emsisoft 20140126
F-Prot 20140126
F-Secure 20140126
Fortinet 20140126
GData 20140126
Ikarus 20140126
Jiangmin 20140126
K7AntiVirus 20140125
K7GW 20140125
Kaspersky 20140126
Kingsoft 20130829
Malwarebytes 20140126
McAfee 20140126
McAfee-GW-Edition 20140126
MicroWorld-eScan 20140126
Microsoft 20140126
NANO-Antivirus 20140126
Norman 20140126
Panda 20140125
Rising 20140126
SUPERAntiSpyware 20140125
Sophos 20140126
Symantec 20140126
TheHacker 20140126
TotalDefense 20140125
TrendMicro 20140126
TrendMicro-HouseCall 20140126
VBA32 20140125
VIPRE 20140126
ViRobot 20140125
nProtect 20140126
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block
Copyright
2011 Axel Walthelm

Publisher www.walthelm.net
Product www.visionventions.com
Original name HibernateOnPowerFail.exe
Internal name HibernateOnPowerFail
File version 0.9.0.1
Description Hibernate notebook when power offline
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2011-05-15 18:20:49
Link date 7:20 PM 5/15/2011
Entry Point 0x0000145C
Number of sections 2
PE sections
PE imports
CloseServiceHandle
StartServiceW
OpenProcessToken
SetServiceStatus
QueryServiceStatus
OpenSCManagerW
OpenServiceW
AdjustTokenPrivileges
ControlService
StartServiceCtrlDispatcherW
LookupPrivilegeValueW
DeleteService
CreateProcessAsUserW
CreateServiceW
GetLastError
HeapFree
GetModuleFileNameW
WaitForSingleObject
SetEvent
HeapAlloc
LoadLibraryA
GetCurrentProcess
GetCommandLineW
GetProcAddress
GetSystemPowerStatus
GetProcessHeap
CreateThread
SetSystemPowerState
InterlockedExchange
CloseHandle
GetModuleHandleW
FreeLibrary
TerminateProcess
CreateEventW
InterlockedDecrement
Sleep
ExitProcess
InterlockedIncrement
MessageBoxW
RegisterClassExW
GetMessageW
DefWindowProcW
MessageBoxA
CreateWindowExW
TranslateMessage
DispatchMessageW
DestroyWindow
Number of PE resources by type
RT_ICON 2
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 3
NEUTRAL DEFAULT 1
ExifTool file metadata
SubsystemVersion
4.0

InitializedDataSize
13824

ImageVersion
0.0

ProductName
www.visionventions.com

FileVersionNumber
0.9.0.1

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

CharacterSet
ASCII

LinkerVersion
6.0

FileOS
Windows NT 32-bit

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
0.9.0.1

TimeStamp
2011:05:15 19:20:49+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
HibernateOnPowerFail

ProductVersion
0.9.0.1

FileDescription
Hibernate notebook when power offline

OSVersion
4.0

OriginalFilename
HibernateOnPowerFail.exe

LegalCopyright
2011 Axel Walthelm

MachineType
Intel 386 or later, and compatibles

CompanyName
www.walthelm.net

CodeSize
0

FileSubtype
0

ProductVersionNumber
0.9.0.1

EntryPoint
0x145c

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 b422c9b7de1f1e4e2524e8dab14ab88c
SHA1 502c53c663a4b92b009b109660b10aa3a45837d0
SHA256 0eb673dbfc5e6a7b6d4a23ebda6031d8ec17ab46193166251829776b10b26c93
ssdeep
192:TCxugT5DcyhsFfv+HQAnjAKFxA8BDkowVnij0W57DF5LTqex:TCxPVNC+HQodDkpBij0Wxeex

File size 14.5 KB ( 14848 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (43.5%)
Win32 Executable (generic) (29.8%)
Generic Win/DOS Executable (13.2%)
DOS Executable Generic (13.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Tags
peexe

VirusTotal metadata
First submission 2012-08-06 12:13:30 UTC ( 1 year, 8 months ago )
Last submission 2013-10-22 00:40:16 UTC ( 5 months, 4 weeks ago )
File names HibernateOnPowerFail
0eb673dbfc5e6a7b6d4a23ebda6031d8ec17ab46193166251829776b10b26c93
HibernateOnPowerFail.exe
file-4342320_exe
HibernateOnPowerFail.exe
Advanced heuristic and reputation engines
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!