× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: b8add4d41f2f66c4d3568a2a5c6181333fc28ab1aac5c6aee913410f99b7a266
File name: toolbar-silent.exe
Detection ratio: 3 / 43
Analysis date: 2012-02-29 19:11:47 UTC ( 2 years, 1 month ago )
Antivirus Result Update
DrWeb Adware.Zugo.71 20120229
NOD32 Win32/Toolbar.Zugo 20120229
VIPRE Zugo Ltd (v) (not malicious) 20120229
AVG 20120229
AhnLab-V3 20120228
AntiVir 20120229
Antiy-AVL 20120229
Avast 20120229
BitDefender 20120229
ByteHero 20120225
CAT-QuickHeal 20120229
ClamAV 20120229
Commtouch 20120229
Comodo 20120229
Emsisoft 20120229
F-Prot 20120229
F-Secure 20120229
Fortinet 20120229
GData 20120229
Ikarus 20120229
Jiangmin 20120229
K7AntiVirus 20120229
Kaspersky 20120229
McAfee 20120229
McAfee-GW-Edition 20120229
Microsoft 20120229
Norman 20120229
PCTools 20120228
Panda 20120229
Prevx 20120229
Rising 20120228
SUPERAntiSpyware 20120229
Sophos 20120229
Symantec 20120229
TheHacker 20120228
TrendMicro 20120229
TrendMicro-HouseCall 20120229
VBA32 20120229
ViRobot 20120229
VirusBuster 20120229
eSafe 20120229
eTrust-Vet 20120229
nProtect 20120229
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block
Product GetMiro Toolbar
File version 1.0
Description GetMiro Toolbar
Signing date 2:06 PM 8/2/2011
PE header basic information
Number of sections 5
PE sections
PE imports
RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, CreateFileA, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, SetFileTime, GetTempPathA, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetWindowsDirectoryA
SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
ExifTool file metadata
IWKeyword
mro-getmiro-sntb

UninitializedDataSize
1024

InitializedDataSize
119808

ImageVersion
6.0

FileSubtype
0

FileVersionNumber
1.0.0.0

LanguageCode
English (U.S.)

FileFlagsMask
0x0000

CharacterSet
ASCII

LinkerVersion
6.0

MIMEType
application/octet-stream

FileVersion
1.0

TimeStamp
2009:12:05 23:50:46+01:00

FileType
Win32 EXE

PEType
PE32

SubsystemVersion
4.0

IWVersion
1.9

ProductVersion
1.0

FileDescription
GetMiro Toolbar

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

IWBuildDate
20110802T140556

CodeSize
23552

ProductName
GetMiro Toolbar

ProductVersionNumber
1.0.0.0

EntryPoint
0x323c

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 85e3882b58a87125fead59efd4290e3d
SHA1 62c16939991e20f8e4f959decb39a44ab04693ed
SHA256 b8add4d41f2f66c4d3568a2a5c6181333fc28ab1aac5c6aee913410f99b7a266
ssdeep
12288:W3yheGZPtzxTbO+ICG5DLkOhjFWEYBvsshQlkcPxx0kBucgIwI9pLmrqAFOW9:WQeGZPtzxe7XLkOivsFk40m+Iwkg2c9

File size 713.2 KB ( 730280 bytes )
File type Win32 EXE
Magic literal
MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
Tags
signed

VirusTotal metadata
First submission 2011-09-19 09:56:28 UTC ( 2 years, 7 months ago )
Last submission 2012-02-29 19:11:47 UTC ( 2 years, 1 month ago )
File names mro-getmiro-sntb.exe
toolbar-silent.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!