× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 713aebc2778cc48c410b53bfe28933058ef68a6f60978bb70f83bd34d8c66db4
File name: converter_install.exe
Detection ratio: 0 / 68
Analysis date: 2018-01-06 16:34:01 UTC ( 1 week, 4 days ago ) View latest
Antivirus Result Update
Ad-Aware 20180106
AegisLab 20180105
AhnLab-V3 20180106
Alibaba 20180105
ALYac 20180106
Antiy-AVL 20180106
Arcabit 20180106
Avast 20180106
Avast-Mobile 20180105
AVG 20180106
Avira (no cloud) 20180106
AVware 20180103
Baidu 20180105
BitDefender 20180106
Bkav 20180106
CAT-QuickHeal 20180106
ClamAV 20180106
CMC 20180106
Comodo 20180106
CrowdStrike Falcon (ML) 20171016
Cybereason 20171103
Cylance 20180106
Cyren 20180106
DrWeb 20180106
eGambit 20180106
Emsisoft 20180106
Endgame 20171130
ESET-NOD32 20180106
F-Prot 20180106
F-Secure 20180106
Fortinet 20180106
GData 20180106
Ikarus 20180106
Sophos ML 20170914
Jiangmin 20180106
K7AntiVirus 20180106
K7GW 20180106
Kaspersky 20180106
Kingsoft 20180106
Malwarebytes 20180106
MAX 20180106
McAfee 20180102
McAfee-GW-Edition 20180106
Microsoft 20180106
eScan 20180106
NANO-Antivirus 20180106
nProtect 20180106
Palo Alto Networks (Known Signatures) 20180106
Panda 20180106
Qihoo-360 20180106
Rising 20180106
SentinelOne (Static ML) 20171224
Sophos AV 20180106
SUPERAntiSpyware 20180106
Symantec 20180106
Tencent 20180106
TheHacker 20180103
TotalDefense 20180106
TrendMicro 20180106
TrendMicro-HouseCall 20180106
Trustlook 20180106
VBA32 20180105
VIPRE 20180106
ViRobot 20180106
Webroot 20180106
WhiteArmor 20171226
Yandex 20171229
Zillya 20180105
ZoneAlarm by Check Point 20180106
Zoner 20180106
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
MarkelSoft, Inc.

Product MarkelSoft Converter for iTunes
Original name converter_install.exe
Internal name Converter
File version 1.0
Description MarkelSoft Converter for iTunes
Packers identified
PEiD Video-Lan-Client
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2009-05-12 11:20:58
Entry Point 0x000011F8
Number of sections 5
PE sections
Overlays
MD5 31ce2e8dedc7bdaf470f33f05d59a95d
File type data
Offset 365568
Size 22202368
Entropy 8.00
PE imports
RegCloseKey
RegQueryValueExA
RegSetValueExA
RegCreateKeyExA
RegOpenKeyExA
RegEnumKeyExA
InitCommonControls
GetOpenFileNameA
AreFileApisANSI
GetLastError
InitializeCriticalSection
EnterCriticalSection
GetConsoleOutputCP
GetShortPathNameW
lstrlenA
GetFileAttributesA
WaitForSingleObject
LockResource
FreeLibrary
ExitProcess
TlsAlloc
GetVersionExA
GetModuleFileNameA
GetCommandLineW
LoadLibraryA
GetShortPathNameA
FreeEnvironmentStringsA
GetCurrentProcess
GetEnvironmentStrings
GetWindowsDirectoryA
SetThreadPriority
GetCurrentProcessId
AllocConsole
CreateDirectoryA
DeleteFileA
GetCurrentDirectoryA
MultiByteToWideChar
GetConsoleTitleA
GetCommandLineA
GetProcAddress
ReadFile
LeaveCriticalSection
CreateMutexA
SetFilePointer
GetTempPathA
CreateSemaphoreA
CreateThread
GetModuleFileNameW
GetModuleHandleA
FindFirstFileA
SetUnhandledExceptionFilter
WriteFile
GetStartupInfoA
SetConsoleTitleA
CloseHandle
GetTempFileNameA
lstrcpynA
FindNextFileA
RemoveDirectoryA
DuplicateHandle
SetEnvironmentVariableA
GetFullPathNameA
GetExitCodeProcess
TerminateProcess
SizeofResource
CreateProcessA
WideCharToMultiByte
GetEnvironmentVariableA
LoadResource
SearchPathA
FindClose
TlsGetValue
Sleep
ReleaseMutex
TlsSetValue
CreateFileA
GetTickCount
FindResourceA
SetCurrentDirectoryA
SetLastError
InterlockedIncrement
SHGetPathFromIDListA
SHGetMalloc
SHGetDesktopFolder
GetParent
EndDialog
EnumWindows
ShowWindow
FindWindowA
SetWindowPos
GetWindowThreadProcessId
SendDlgItemMessageA
MessageBoxW
GetWindowRect
SetDlgItemTextA
MessageBoxA
DialogBoxParamA
SetWindowTextA
GetLastActivePopup
IsWindowVisible
OffsetRect
SetForegroundWindow
GetDlgItem
IsIconic
RegisterClassA
LoadCursorA
LoadIconA
DefDlgProcA
CopyRect
GetDesktopWindow
GetWindowTextA
ExitWindowsEx
getc
__p__environ
fclose
strtoul
_fstat
fflush
_fmode
strtol
fputc
strtok
fwrite
mktime
_close
_fileno
_strupr
_isatty
wcsncmp
_write
memcpy
strstr
ctime
memmove
signal
remove
_tempnam
_mkdir
strcmp
memchr
strncmp
memset
wcschr
strcat
_stricmp
_wcslwr
atexit
_setmode
fgets
strchr
fopen
ftell
exit
sprintf
strrchr
ferror
free
__getmainargs
_read
strcpy
_fpreset
__mb_cur_max
_iob
rand
_putenv
_getcwd
calloc
_lseek
_assert
printf
_rmdir
strncpy
_cexit
_itoa
wcscmp
_chdir
_HUGE
_open
wcslen
srand
_isctype
wcsncpy
_pctype
getenv
wcscat
atoi
vfprintf
wcscpy
swprintf
vsprintf
wcstombs
malloc
fread
abort
fprintf
_fdopen
_errno
fseek
rewind
_fullpath
fwprintf
difftime
time
__set_app_type
Number of PE resources by type
RT_ICON 4
RT_DIALOG 3
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 10
PE resources
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
2.56

ImageVersion
1.0

FileSubtype
0

FileVersionNumber
1.0.0.0

UninitializedDataSize
51200

LanguageCode
Neutral

FileFlagsMask
0x0017

CharacterSet
Unicode

InitializedDataSize
364544

EntryPoint
0x11f8

OriginalFileName
converter_install.exe

MIMEType
application/octet-stream

LegalCopyright
MarkelSoft, Inc.

FileVersion
1.0

TimeStamp
2009:05:12 12:20:58+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
Converter

ProductVersion
1.0

FileDescription
MarkelSoft Converter for iTunes

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
MarkelSoft, Inc.

CodeSize
170496

ProductName
MarkelSoft Converter for iTunes

ProductVersionNumber
1.0.0.0

FileTypeExtension
exe

ObjectFileType
Unknown

File identification
MD5 d9a11ca8e6c5a7ba480b5ec78174fb51
SHA1 15671b5beb602636c07bee17b5cbd19cea597e41
SHA256 713aebc2778cc48c410b53bfe28933058ef68a6f60978bb70f83bd34d8c66db4
ssdeep
393216:3eQVEx1NBwGXkYEptzra6c7iAZoHCWxFZeYENv0EDrxSbrlzglt:37Ex1N6uzZ7i9jov0exSbrlzglt

authentihash fc7d6802f9f57ba2571b4d09d0ac42aea71928ca08bfc3b3729df6482bb7d6ad
imphash 29b0c23be10f9dece5497f5e5c38e818
File size 21.5 MB ( 22567936 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386

TrID InstallShield setup (36.1%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win64 Executable (generic) (23.1%)
Win32 Dynamic Link Library (generic) (5.5%)
Win32 Executable (generic) (3.7%)
Tags
peexe overlay

VirusTotal metadata
First submission 2012-11-17 02:09:37 UTC ( 5 years, 2 months ago )
Last submission 2017-04-05 09:31:46 UTC ( 9 months, 2 weeks ago )
File names 713AEBC2778CC48C410B53BFE28933058EF68A6F60978BB70F83BD34D8C66DB4
converter_install.exe
72DB68093710D546CA2E6A8F3C70ACC4 - converter_install.exe
Converter
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!