× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ead2450fd6486313a79a7c55421738d0a1a819c3b3f7ee4c0b17b12aa4ec3e0b
File name: GrampsAIO-4.2.1-2_win64(1).exe
Detection ratio: 0 / 55
Analysis date: 2015-12-26 00:37:01 UTC ( 3 years, 3 months ago ) View latest
Antivirus Result Update
Ad-Aware 20151224
AegisLab 20151225
Yandex 20151225
AhnLab-V3 20151225
Alibaba 20151208
ALYac 20151225
Antiy-AVL 20151226
Arcabit 20151226
Avast 20151231
AVG 20151231
Avira (no cloud) 20151225
AVware 20151225
Baidu-International 20151225
BitDefender 20151226
Bkav 20151225
ByteHero 20151226
CAT-QuickHeal 20151224
ClamAV 20151225
CMC 20151217
Comodo 20151231
Cyren 20151231
DrWeb 20151230
Emsisoft 20151226
ESET-NOD32 20151231
F-Prot 20151230
F-Secure 20151225
Fortinet 20151226
GData 20151226
Ikarus 20151226
Jiangmin 20151225
K7AntiVirus 20151225
K7GW 20151225
Kaspersky 20151231
Malwarebytes 20151225
McAfee 20151226
McAfee-GW-Edition 20151226
Microsoft 20151231
eScan 20151226
NANO-Antivirus 20151226
nProtect 20151224
Panda 20151225
Qihoo-360 20151226
Rising 20151230
Sophos AV 20151225
SUPERAntiSpyware 20151225
Symantec 20151225
Tencent 20151231
TheHacker 20151223
TrendMicro 20151231
TrendMicro-HouseCall 20151231
VBA32 20151225
VIPRE 20151225
ViRobot 20151225
Zillya 20151230
Zoner 20151225
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Packers identified
F-PROT NSIS, appended, UTF-8, packed
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-07-14 20:09:44
Entry Point 0x0000324D
Number of sections 5
PE sections
Overlays
MD5 a9f2bd8e8050ec80229f9dbf00a6fd60
File type data
Offset 167424
Size 83654704
Entropy 8.00
PE imports
RegDeleteKeyA
RegCloseKey
RegQueryValueExA
RegSetValueExA
RegEnumKeyA
RegDeleteValueA
RegCreateKeyExA
RegOpenKeyExA
RegEnumValueA
ImageList_Create
Ord(17)
ImageList_Destroy
ImageList_AddMasked
GetDeviceCaps
SelectObject
CreateBrushIndirect
CreateFontIndirectA
SetBkMode
SetBkColor
DeleteObject
SetTextColor
GetLastError
ReadFile
lstrlenA
lstrcmpiA
GlobalFree
WaitForSingleObject
GetExitCodeProcess
CopyFileA
ExitProcess
SetFileTime
GlobalUnlock
GetModuleFileNameA
DeleteFileA
LoadLibraryA
GetShortPathNameA
GetCurrentProcess
LoadLibraryExA
CompareFileTime
GetPrivateProfileStringA
WritePrivateProfileStringA
GetFileSize
lstrcatA
CreateDirectoryA
ExpandEnvironmentStringsA
GetWindowsDirectoryA
SetErrorMode
MultiByteToWideChar
GetCommandLineA
GlobalLock
SetFileAttributesA
SetFilePointer
GetTempPathA
CreateThread
GetFileAttributesA
GetModuleHandleA
lstrcmpA
FindFirstFileA
lstrcpyA
CloseHandle
GetTempFileNameA
lstrcpynA
FindNextFileA
RemoveDirectoryA
GetSystemDirectoryA
GetDiskFreeSpaceA
GetProcAddress
SetEnvironmentVariableA
GetFullPathNameA
FreeLibrary
MoveFileA
CreateProcessA
WriteFile
GlobalAlloc
SearchPathA
FindClose
Sleep
CreateFileA
GetTickCount
GetVersion
SetCurrentDirectoryA
MulDiv
SHGetFileInfoA
SHBrowseForFolderA
SHGetSpecialFolderLocation
SHGetPathFromIDListA
ShellExecuteA
SHFileOperationA
CharPrevA
GetMessagePos
EndPaint
ReleaseDC
EndDialog
BeginPaint
ShowWindow
DefWindowProcA
GetClassInfoA
SetClassLongA
LoadBitmapA
SetWindowPos
GetSystemMetrics
IsWindow
AppendMenuA
PostQuitMessage
GetWindowRect
DispatchMessageA
ScreenToClient
SetDlgItemTextA
MessageBoxIndirectA
LoadImageA
GetDlgItemTextA
PeekMessageA
SetWindowLongA
IsWindowEnabled
GetSysColor
CheckDlgButton
GetDC
SystemParametersInfoA
CreatePopupMenu
wsprintfA
DialogBoxParamA
SetClipboardData
IsWindowVisible
SendMessageA
DrawTextA
GetClientRect
SetTimer
GetDlgItem
SetForegroundWindow
CreateDialogParamA
EnableMenuItem
RegisterClassA
SendMessageTimeoutA
InvalidateRect
GetWindowLongA
FindWindowExA
CreateWindowExA
LoadCursorA
TrackPopupMenu
SetWindowTextA
FillRect
OpenClipboard
CharNextA
CallWindowProcA
GetSystemMenu
EmptyClipboard
EnableWindow
CloseClipboard
DestroyWindow
ExitWindowsEx
SetCursor
GetFileVersionInfoSizeA
GetFileVersionInfoA
VerQueryValueA
CoTaskMemFree
OleUninitialize
CoCreateInstance
OleInitialize
Number of PE resources by type
RT_ICON 7
RT_DIALOG 6
RT_MANIFEST 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 15
PE resources
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

FileTypeExtension
exe

TimeStamp
2013:07:14 21:09:44+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
23552

LinkerVersion
6.0

EntryPoint
0x324d

InitializedDataSize
119808

SubsystemVersion
4.0

ImageVersion
6.0

OSVersion
4.0

UninitializedDataSize
1024

File identification
MD5 e1b497441407dcbc8f88717056eccbe4
SHA1 ade4e7c27bed3fd53d597396195678eb4b2bc375
SHA256 ead2450fd6486313a79a7c55421738d0a1a819c3b3f7ee4c0b17b12aa4ec3e0b
ssdeep
1572864:LAojCfxWvRSUB9PAemYDj2+0jRJJt3g6QDjJgKcb8XcwSjP9qQMwaKBHDL:9SUIUB9NXQRdg6QDYGSb9qQB/P

authentihash 4443c343001b60d22ce820f0caf6cf4c97fbbe932371c5ef3cef08a6b731b06e
imphash e990dd07e89d04c53e337ab9b3f5e0cc
File size 79.9 MB ( 83822128 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID NSIS - Nullsoft Scriptable Install System (91.9%)
Win32 Executable MS Visual C++ (generic) (3.3%)
Win64 Executable (generic) (3.0%)
Win32 Dynamic Link Library (generic) (0.7%)
Win32 Executable (generic) (0.4%)
Tags
nsis peexe overlay

VirusTotal metadata
First submission 2015-10-31 11:01:48 UTC ( 3 years, 5 months ago )
Last submission 2016-05-07 04:18:06 UTC ( 2 years, 11 months ago )
File names GrampsAIO-4.2.1-2_win64.exe
GrampsAIO-4.2.1-2_win64(1).exe
GrampsAIO-4.2.1-2_win64.exe
GrampsAIO-4.2.1-2_win64.exe
GrampsAIO-4.2.1-2_win64.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!