× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: b41115b057ddc8474acdca7894b21ecc40a3724a0bce892568c48d317fb9e1a9
File name: setup.exe
Detection ratio: 0 / 43
Analysis date: 2011-11-22 17:00:33 UTC ( 4 years, 11 months ago ) View latest
Antivirus Result Update
AVG 20111122
AhnLab-V3 20111122
AntiVir 20111122
Antiy-AVL 20111122
Avast 20111122
BitDefender 20111122
ByteHero 20111114
CAT-QuickHeal 20111122
ClamAV 20111122
Commtouch 20111122
Comodo 20111122
DrWeb 20111122
Emsisoft 20111122
F-Prot 20111122
F-Secure 20111122
Fortinet 20111122
GData 20111122
Ikarus 20111122
Jiangmin 20111122
K7AntiVirus 20111122
Kaspersky 20111122
McAfee 20111122
McAfee-GW-Edition 20111122
Microsoft 20111122
NOD32 20111122
Norman 20111121
PCTools 20111122
Panda 20111122
Prevx 20111122
Rising 20111122
SUPERAntiSpyware 20111122
Sophos 20111122
Symantec 20111122
TheHacker 20111122
TrendMicro 20111122
TrendMicro-HouseCall 20111122
VBA32 20111122
VIPRE 20111122
ViRobot 20111122
VirusBuster 20111122
eSafe 20111122
eTrust-Vet 20111122
nProtect 20111122
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
(c) Microsoft Corporation. All rights reserved.

Original name setup.exe
Internal name setup.exe
File version 10.0.30319.1 built by: RTMRel
Description Setup
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2010-03-18 11:21:36
Entry Point 0x0002E541
Number of sections 4
PE sections
PE imports
CertFreeCertificateChain
CertVerifyCertificateChainPolicy
CertGetCertificateChain
GetStockObject
EnumFontFamiliesExW
CreateFontIndirectW
DeleteObject
CreateCompatibleDC
GetDeviceCaps
GetObjectW
DeleteDC
SelectObject
GetTextMetricsW
GetTextExtentPoint32W
Process32NextW
Process32FirstW
CreateToolhelp32Snapshot
GetCurrentProcessId
GetNativeSystemInfo
SetFilePointer
HeapSetInformation
CreateEventW
SetEvent
SizeofResource
LockResource
LoadResource
FindResourceW
GetVersionExW
CompareStringW
GetFileAttributesW
GetModuleFileNameW
ExpandEnvironmentStringsW
GlobalFree
OpenProcess
GetSystemDirectoryW
DeleteFileW
GetTempFileNameW
GetTempPathW
LocalFree
FormatMessageW
ReadFile
GetTimeFormatW
GetDateFormatW
CreateDirectoryW
CopyFileW
WideCharToMultiByte
GetWindowsDirectoryW
GetSystemInfo
GetCurrentProcess
GetEnvironmentVariableW
GetModuleHandleW
GetVersion
CreateFileW
EndUpdateResourceW
Sleep
GetDiskFreeSpaceExW
DeleteCriticalSection
CreateThread
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
MulDiv
lstrlenW
GetExitCodeProcess
SetEndOfFile
GetTickCount
FindFirstFileW
FindNextFileW
FindClose
GlobalAlloc
LoadLibraryW
UpdateResourceA
BeginUpdateResourceA
InterlockedCompareExchange
FindResourceA
DeleteFileA
lstrlenA
CreateFileA
UpdateResourceW
BeginUpdateResourceW
GetEnvironmentVariableA
SetStdHandle
WriteConsoleW
HeapReAlloc
IsValidLocale
EnumSystemLocalesA
GetLocaleInfoA
GetUserDefaultLCID
HeapSize
FlushFileBuffers
GetConsoleMode
GetConsoleCP
GetProcessHeap
MultiByteToWideChar
LCMapStringW
GetStringTypeW
GetLocaleInfoW
IsValidCodePage
GetOEMCP
GetACP
IsDebuggerPresent
UnhandledExceptionFilter
TerminateProcess
HeapAlloc
IsProcessorFeaturePresent
GetSystemTimeAsFileTime
QueryPerformanceCounter
HeapCreate
GetCurrentThreadId
InterlockedExchange
SwitchToThread
GetLastError
WaitForSingleObject
CloseHandle
GetProcAddress
FreeLibrary
WriteFile
SetLastError
InterlockedIncrement
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
GetFileType
InitializeCriticalSectionAndSpinCount
LocalAlloc
LoadLibraryA
RaiseException
GetCommandLineW
GetStartupInfoW
RtlUnwind
HeapFree
InterlockedDecrement
GetCPInfo
SetUnhandledExceptionFilter
ExitProcess
GetStdHandle
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
ShellExecuteExW
SHGetMalloc
SHGetPathFromIDListW
SHGetSpecialFolderLocation
ShellExecuteW
ShellExecuteA
GetComputerObjectNameW
MessageBoxA
ShowScrollBar
GetClientRect
SendMessageA
SetClassLongW
SetWindowTextW
LoadCursorW
SetCursor
CreateDialogIndirectParamW
SetForegroundWindow
EnableWindow
GetFocus
SetFocus
ScreenToClient
MoveWindow
LoadIconW
SetDlgItemTextW
SendMessageW
GetDlgItem
MsgWaitForMultipleObjects
PeekMessageW
IsDialogMessageW
TranslateMessage
DispatchMessageW
DestroyWindow
ShowWindow
SendDlgItemMessageW
GetWindowRect
SystemParametersInfoW
ExitWindowsEx
MessageBoxW
DrawTextW
GetSystemMetrics
GetDC
GetDialogBaseUnits
ReleaseDC
CreateDialogParamW
LoadImageW
InternetCrackUrlW
InternetCombineUrlW
4 more function(s) imported by ordinal)
CoUninitialize
CoInitialize
PE exports
ExifTool file metadata
SubsystemVersion
5.0

LinkerVersion
10.0

ImageVersion
10.0

FileSubtype
0

FileVersionNumber
10.0.30319.1

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
104960

FileOS
Win32

MIMEType
application/octet-stream

LegalCopyright
Microsoft Corporation. All rights reserved.

FileVersion
10.0.30319.1 built by: RTMRel

TimeStamp
2010:03:18 12:21:36+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
setup.exe

ProductVersion
10.0.30319.1

FileDescription
Setup

OSVersion
5.0

OriginalFilename
setup.exe

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
322048

ProductVersionNumber
10.0.30319.1

EntryPoint
0x2e541

ObjectFileType
Executable application

File identification
MD5 b46dfc02c05f4a2c7dd01eaa4e3314b0
SHA1 aadc994c41ea1cd94b381e268f5f9a1a0c6c7c4c
SHA256 b41115b057ddc8474acdca7894b21ecc40a3724a0bce892568c48d317fb9e1a9
ssdeep
6144:uqIpd/w8ylWKxavR+dJ1oMBClrbMAo+nhmuFfvY0SHZvuD3wojDuUlX6eOf:u7IRWDvFa+nhmuF3Y0scweDuUlX3u

File size 418.9 KB ( 428976 bytes )
File type Win32 DLL
Magic literal

TrID InstallShield setup (46.1%)
Win32 Executable MS Visual C++ (generic) (40.4%)
Win32 Executable Generic (9.1%)
Generic Win/DOS Executable (2.1%)
DOS Executable Generic (2.1%)
VirusTotal metadata
First submission 2011-11-22 17:00:33 UTC ( 4 years, 11 months ago )
Last submission 2011-11-24 14:46:58 UTC ( 4 years, 11 months ago )
File names setup.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!