× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 939244f88f384aa37431dc19247225cd117dc5dd8fdd70f923db3b99cce1571f
File name: 08dbf5405d634b178aa219e74b1e9d55
Detection ratio: 34 / 57
Analysis date: 2015-03-20 23:59:28 UTC ( 4 years ago ) View latest
Antivirus Result Update
Ad-Aware Gen:Variant.Graftor.179392 20150320
Yandex TrojanSpy.Zbot!aamMiJsTvZ0 20150320
ALYac Gen:Variant.Graftor.179392 20150320
Antiy-AVL Trojan[Spy]/Win32.Zbot 20150320
Avast Win32:Malware-gen 20150320
AVG Inject2.BSCN 20150320
Avira (no cloud) TR/Crypt.ZPACK.95711 20150320
AVware Trojan.Win32.Generic!BT 20150320
Baidu-International Trojan.Win32.Zbot.vdna 20150320
BitDefender Gen:Variant.Graftor.179392 20150320
CAT-QuickHeal TrojanPWS.Zbot.A5 20150320
DrWeb Trojan.PWS.Panda.7708 20150320
Emsisoft Gen:Variant.Graftor.179392 (B) 20150320
ESET-NOD32 Win32/Spy.Zbot.ACB 20150320
F-Secure Gen:Variant.Graftor.179392 20150320
Fortinet W32/Zbot.ACB!tr.spy 20150320
GData Gen:Variant.Graftor.179392 20150320
Ikarus Trojan-Spy.Agent 20150320
K7AntiVirus Spyware ( 004a08e61 ) 20150320
K7GW Spyware ( 004a08e61 ) 20150320
Kaspersky Trojan-Spy.Win32.Zbot.vdna 20150320
McAfee RDN/Generic PWS.y!bcz 20150320
McAfee-GW-Edition BehavesLike.Win32.Packed.fc 20150320
Microsoft PWS:Win32/Zbot.gen!VM 20150320
eScan Gen:Variant.Graftor.179392 20150320
NANO-Antivirus Trojan.Win32.Zbot.doyvqm 20150320
Qihoo-360 Win32/Trojan.Spy.f5f 20150321
Sophos AV Mal/Wonton-AA 20150320
Symantec Trojan.Gen.2 20150320
Tencent Win32.Trojan-spy.Zbot.Hzf 20150321
TotalDefense Win32/Zbot.AXLMPIC 20150320
TrendMicro TROJ_FORUCON.BMC 20150320
TrendMicro-HouseCall TROJ_FORUCON.BMC 20150320
VIPRE Trojan.Win32.Generic!BT 20150320
AegisLab 20150320
AhnLab-V3 20150320
Alibaba 20150320
Bkav 20150320
ByteHero 20150321
ClamAV 20150320
CMC 20150317
Comodo 20150320
Cyren 20150320
F-Prot 20150320
Jiangmin 20150320
Kingsoft 20150321
Malwarebytes 20150320
Norman 20150320
nProtect 20150320
Panda 20150318
Rising 20150320
SUPERAntiSpyware 20150320
TheHacker 20150319
VBA32 20150320
ViRobot 20150320
Zillya 20150320
Zoner 20150320
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
WiseCleaner.COM

Publisher WiseCleaner.COM
Product Wise Auto Shutdown
Original name WiseAutoShutdown.exe
Internal name Wise Auto Shutdown
File version 1.4.4.72
Description Wise Auto Shutdown
Comments Auto Shutdown Computer
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-03-08 22:16:15
Entry Point 0x00005280
Number of sections 4
PE sections
PE imports
CryptDestroyKey
GetTokenInformation
CryptReleaseContext
CryptAcquireContextA
SetServiceStatus
CryptSetKeyParam
SetNamedSecurityInfoA
GetSecurityDescriptorSacl
CryptEncrypt
GetSecurityDescriptorOwner
GetFileSecurityA
LookupAccountSidA
RegisterServiceCtrlHandlerA
CryptImportKey
FlatSB_GetScrollInfo
InitCommonControlsEx
PrintDlgA
CertFreeCertificateContext
TextOutA
GetTextMetricsA
Rectangle
GetDeviceCaps
DeleteDC
EndDoc
StartPage
DeleteObject
BitBlt
CreateBitmapIndirect
SetTextColor
SetAbortProc
GetDIBits
CreateCompatibleDC
EndPage
SelectObject
StartDocA
CreateSolidBrush
Escape
SetBkColor
AbortDoc
CreateCompatibleBitmap
GetStdHandle
FileTimeToSystemTime
WaitForSingleObject
EncodePointer
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
LocalAlloc
FreeEnvironmentStringsW
SetStdHandle
GetCPInfo
WriteFile
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
OutputDebugStringW
FindClose
TlsGetValue
FindNextChangeNotification
OutputDebugStringA
SetLastError
GetModuleFileNameW
Beep
IsDebuggerPresent
HeapAlloc
GetModuleFileNameA
HeapSetInformation
UnhandledExceptionFilter
InterlockedDecrement
MultiByteToWideChar
GetModuleHandleA
CreateSemaphoreA
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
DecodePointer
SetEnvironmentVariableA
TerminateProcess
SetEndOfFile
GetCurrentThreadId
InterlockedIncrement
WriteConsoleW
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
SetHandleCount
LoadLibraryW
GetOEMCP
QueryPerformanceCounter
GetTickCount
SetConsoleTextAttribute
TlsAlloc
FlushFileBuffers
RtlUnwind
GetModuleHandleW
GetStartupInfoW
GetProcAddress
GetProcessHeap
CompareStringW
FindFirstFileExA
HeapValidate
FindNextFileA
GetTimeZoneInformation
CreateFileW
CreateEventA
GetFileType
TlsSetValue
CreateFileA
ExitProcess
LeaveCriticalSection
GetLastError
LCMapStringW
FindFirstChangeNotificationA
GetSystemInfo
lstrlenA
GlobalFree
GetConsoleCP
GetEnvironmentStringsW
OpenFile
FileTimeToLocalFileTime
GetCurrentProcessId
HeapQueryInformation
WideCharToMultiByte
HeapSize
GetCommandLineA
RaiseException
ReleaseSemaphore
TlsFree
SetFilePointer
ReadFile
CloseHandle
GetACP
GetVersion
IsValidCodePage
HeapCreate
Sleep
IsBadReadPtr
GetForegroundWindow
GetParent
UpdateWindow
EndDialog
EnumWindows
EnableScrollBar
ShowWindow
GetSystemMetrics
MessageBoxW
EnableWindow
MessageBoxA
DialogBoxParamA
GetSysColor
GetDC
InsertMenuItemA
GetAsyncKeyState
ReleaseDC
CreatePopupMenu
GetMenu
ShowScrollBar
SendMessageA
GetClientRect
GetDlgItem
CreateDialogParamA
IsWindow
SetScrollPos
SetRect
InvalidateRect
wsprintfA
CreateWindowExA
SetScrollRange
GetMenuItemInfoA
FillRect
GetWindowTextA
WindowFromDC
DestroyWindow
mmioOpenW
mmioWrite
mmioRead
mmioCreateChunk
mmioDescend
mmioAscend
mmioOpenA
mmioClose
mmioSeek
CryptCATAdminReleaseCatalogContext
CryptCATAdminReleaseContext
CryptCATCatalogInfoFromContext
WinVerifyTrust
CryptCATAdminCalcHashFromFileHandle
CryptCATAdminEnumCatalogFromHash
CryptCATAdminAcquireContext
CoCreateGuid
CoCreateInstance
CoInitialize
Number of PE resources by type
RT_GROUP_CURSOR 16
RT_BITMAP 7
RT_STRING 6
RT_ICON 4
TEXT 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 37
PE resources
ExifTool file metadata
LegalTrademarks
WiseCleaner.COM

SubsystemVersion
5.1

Comments
Auto Shutdown Computer

LinkerVersion
10.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.4.0.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
Wise Auto Shutdown

CharacterSet
Unicode

InitializedDataSize
214528

FileOS
Windows NT 32-bit

MIMEType
application/octet-stream

LegalCopyright
WiseCleaner.COM

FileVersion
1.4.4.72

TimeStamp
2015:03:08 23:16:15+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
Wise Auto Shutdown

ProductVersion
1.4

UninitializedDataSize
0

OSVersion
5.1

OriginalFilename
WiseAutoShutdown.exe

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
WiseCleaner.COM

CodeSize
189440

ProductName
Wise Auto Shutdown

ProductVersionNumber
1.4.0.0

EntryPoint
0x5280

ObjectFileType
Executable application

File identification
MD5 08dbf5405d634b178aa219e74b1e9d55
SHA1 e03a2c0acc8890f976786a204e6ae86610b744db
SHA256 939244f88f384aa37431dc19247225cd117dc5dd8fdd70f923db3b99cce1571f
ssdeep
12288:on5Ma9eEvyXUFzF9mpIDnnndYFaFHnnwXnnnnnnnnnnnc6nnnnnnnwnnnnnnnnWr:kN9/68F9mpinnndIaFHnngnnnnnnnnnd

authentihash 8a70e0235fcd51f0e81f7285555a371c1625f8c7a88cf7fa02792f67059ee441
imphash 5acd83fa83bb3544db53ec8de2345b41
File size 395.5 KB ( 404992 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (67.3%)
Win32 Dynamic Link Library (generic) (14.2%)
Win32 Executable (generic) (9.7%)
Generic Win/DOS Executable (4.3%)
DOS Executable Generic (4.3%)
Tags
peexe

VirusTotal metadata
First submission 2015-03-20 23:59:28 UTC ( 4 years ago )
Last submission 2015-04-14 03:12:47 UTC ( 3 years, 11 months ago )
File names Wise Auto Shutdown
WiseAutoShutdown.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Created processes
Created mutexes
Opened mutexes
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.