× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: f3cfb9430964746a43eb1c648c54779f3303b89202231a272efec0b3f49a8e50
File name: setup.exe
Detection ratio: 0 / 47
Analysis date: 2013-11-01 14:53:08 UTC ( 4 years, 9 months ago ) View latest
Antivirus Result Update
Yandex 20131101
AhnLab-V3 20131101
AntiVir 20131101
Antiy-AVL 20131101
Avast 20131101
AVG 20131101
Baidu-International 20131101
BitDefender 20131101
Bkav 20131101
ByteHero 20131028
CAT-QuickHeal 20131101
ClamAV 20131101
Commtouch 20131101
Comodo 20131101
DrWeb 20131101
Emsisoft 20131101
ESET-NOD32 20131101
F-Prot 20131101
F-Secure 20131101
Fortinet 20131101
GData 20131101
Ikarus 20131101
Jiangmin 20131101
K7AntiVirus 20131101
K7GW 20131101
Kaspersky 20131101
Kingsoft 20130829
Malwarebytes 20131101
McAfee 20131101
McAfee-GW-Edition 20131101
Microsoft 20131101
eScan 20131028
NANO-Antivirus 20131101
Norman 20131101
nProtect 20131101
Panda 20131101
Rising 20131101
Sophos AV 20131101
SUPERAntiSpyware 20131101
Symantec 20131101
TheHacker 20131029
TotalDefense 20131101
TrendMicro 20131101
TrendMicro-HouseCall 20131101
VBA32 20131101
VIPRE 20131101
ViRobot 20131101
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright (c) 2013 Flexera Software LLC. All Rights Reserved.

Publisher LogicLevels
Product RemoteGPU
Original name InstallShield Setup.exe
Internal name Setup
File version 1.0.2
Description Setup Launcher Unicode
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-07-02 04:46:43
Entry Point 0x0006B0CB
Number of sections 4
PE sections
PE imports
SetSecurityDescriptorOwner
RegCreateKeyExW
RegCloseKey
RegCreateKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegOpenKeyExW
RegDeleteKeyW
RegDeleteValueW
RegQueryValueExW
SetSecurityDescriptorDacl
OpenProcessToken
RegEnumKeyW
RegOpenKeyW
GetTokenInformation
RegQueryInfoKeyW
RegEnumKeyExW
OpenThreadToken
RegEnumValueW
RegSetValueExW
FreeSid
AllocateAndInitializeSid
InitializeSecurityDescriptor
EqualSid
SetSecurityDescriptorGroup
GetDIBColorTable
GetSystemPaletteEntries
CreateHalftonePalette
GetDeviceCaps
TranslateCharsetInfo
DeleteDC
SetBkMode
CreateFontIndirectW
GetObjectW
BitBlt
RealizePalette
SetTextColor
CreatePalette
GetStockObject
CreateDIBitmap
SelectPalette
UnrealizeObject
CreateCompatibleDC
CreateFontW
SelectObject
CreateSolidBrush
DeleteObject
GetStdHandle
GetDriveTypeW
GetConsoleOutputCP
SetEvent
HeapDestroy
GetFileAttributesW
DuplicateHandle
GetLocalTime
HeapAlloc
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
GetLocaleInfoA
LocalAlloc
SetErrorMode
FreeEnvironmentStringsW
lstrcatW
GetThreadContext
GetLocaleInfoW
SetStdHandle
GetFileTime
GetCPInfo
GetStringTypeA
GetDiskFreeSpaceW
InterlockedExchange
FindResourceExW
WaitForSingleObject
GetSystemTimeAsFileTime
HeapReAlloc
GetStringTypeW
GetExitCodeProcess
LocalFree
FormatMessageW
ResumeThread
CreateEventW
LoadResource
FindClose
InterlockedDecrement
MoveFileW
SetFileAttributesW
GetEnvironmentVariableW
SetLastError
InitializeCriticalSection
CopyFileW
GetUserDefaultLangID
RemoveDirectoryW
IsDebuggerPresent
ExitProcess
VerLanguageNameW
GetModuleFileNameA
LoadLibraryA
QueryPerformanceFrequency
EnumSystemLocalesA
SetConsoleCtrlHandler
UnhandledExceptionFilter
LoadLibraryExW
MultiByteToWideChar
FatalAppExitA
FlushInstructionCache
GetPrivateProfileStringW
SetFilePointer
CreateThread
MoveFileExW
GetSystemDirectoryW
GetExitCodeThread
SetUnhandledExceptionFilter
MulDiv
SetEnvironmentVariableA
SetThreadContext
TerminateProcess
SearchPathW
WriteConsoleA
SetCurrentDirectoryW
GlobalAlloc
SetEndOfFile
GetVersion
InterlockedIncrement
WriteConsoleW
CreateToolhelp32Snapshot
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
SetHandleCount
LoadLibraryW
GetVersionExW
FreeLibrary
QueryPerformanceCounter
GetTickCount
TlsAlloc
VirtualProtect
FlushFileBuffers
lstrcmpiW
RtlUnwind
GetStartupInfoA
GetDateFormatA
GetWindowsDirectoryW
GetFileSize
WriteProcessMemory
OpenProcess
GetDateFormatW
GetStartupInfoW
CreateDirectoryW
DeleteFileW
GetUserDefaultLCID
VirtualProtectEx
GetProcessHeap
GetTempFileNameW
CreateFileMappingW
WriteFile
CompareStringW
lstrcpyW
GetModuleFileNameW
ExpandEnvironmentStringsW
lstrcmpA
FindNextFileW
lstrcpyA
GetTimeFormatA
ResetEvent
FindFirstFileW
IsValidLocale
lstrcmpW
GetProcAddress
GetTempPathW
GetCurrentDirectoryW
GetTimeZoneInformation
CreateFileW
GetFileType
TlsSetValue
CreateFileA
GetCurrentThreadId
LeaveCriticalSection
GetLastError
SystemTimeToFileTime
LCMapStringW
UnmapViewOfFile
GetSystemInfo
lstrlenA
GlobalFree
GetConsoleCP
LCMapStringA
GetTimeFormatW
GetProcessTimes
GetEnvironmentStringsW
GlobalUnlock
VirtualQuery
lstrlenW
Process32NextW
CreateProcessW
SizeofResource
CompareFileTime
GetCurrentProcessId
LockResource
SetFileTime
GetCommandLineW
WideCharToMultiByte
HeapSize
Process32FirstW
GetCurrentThread
lstrcpynW
GetSystemDefaultLangID
RaiseException
MapViewOfFile
TlsFree
GetModuleHandleA
ReadFile
CloseHandle
lstrcpynA
GetACP
GlobalLock
GetModuleHandleW
TlsGetValue
IsValidCodePage
HeapCreate
FindResourceW
VirtualFree
Sleep
IsBadReadPtr
VirtualAlloc
GetOEMCP
CompareStringA
VarUI4FromStr
VariantChangeType
SysStringLen
SystemTimeToVariantTime
VarBstrFromDate
CreateErrorInfo
SysStringByteLen
VarBstrCat
VariantClear
SysAllocStringLen
SysAllocStringByteLen
SysReAllocStringLen
RegisterTypeLib
SysAllocString
GetErrorInfo
SysFreeString
LoadTypeLib
SetErrorInfo
UuidFromStringW
UuidCreate
UuidToStringW
RpcStringFreeW
SHBrowseForFolderW
ShellExecuteW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
ShellExecuteExW
SHGetMalloc
CommandLineToArgvW
SetFocus
EndPaint
CreateDialogIndirectParamW
IntersectRect
EndDialog
BeginPaint
SetWindowTextW
TranslateMessage
DefWindowProcW
MoveWindow
KillTimer
CharPrevW
PostQuitMessage
ShowWindow
GetMessageW
SetWindowPos
wvsprintfW
GetDesktopWindow
GetSystemMetrics
SetWindowLongW
IsWindow
PeekMessageW
GetWindowRect
EnableWindow
CharUpperW
GetWindowDC
SendDlgItemMessageW
GetWindow
PostMessageW
GetSysColor
DispatchMessageW
SetActiveWindow
GetDC
CreateDialogParamW
ReleaseDC
GetDlgCtrlID
SendMessageW
RegisterClassW
wsprintfW
SubtractRect
SetTimer
GetDlgItem
GetDlgItemTextW
MessageBoxW
FindWindowW
ClientToScreen
SetRect
CharNextW
LoadImageW
IsDialogMessageW
FillRect
GetClientRect
WaitForInputIdle
SetDlgItemTextW
GetSysColorBrush
DialogBoxIndirectParamW
LoadCursorW
LoadIconW
CreateWindowExW
MsgWaitForMultipleObjects
GetWindowLongW
SetForegroundWindow
DestroyWindow
ExitWindowsEx
SetCursor
VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
ProgIDFromCLSID
CoUninitialize
CoInitialize
CoTaskMemAlloc
CoCreateInstance
CoCreateGuid
CoTaskMemRealloc
CLSIDFromProgID
CoInitializeSecurity
GetRunningObjectTable
CoTaskMemFree
StringFromGUID2
CreateItemMoniker
Number of PE resources by type
RT_STRING 25
RT_DIALOG 23
RT_ICON 11
RT_BITMAP 6
RT_GROUP_ICON 3
GIF 2
RT_MANIFEST 1
RT_VERSION 1
Number of PE resources by language
NEUTRAL 46
ENGLISH US 26
PE resources
ExifTool file metadata
UninitializedDataSize
0

InitializedDataSize
499712

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.2.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
Setup Launcher Unicode

CharacterSet
Unicode

LinkerVersion
9.0

FileOS
Win32

InternalBuildNumber
130492

ISInternalVersion
20.0.405

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
1.0.2

TimeStamp
2013:07:02 05:46:43+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
Setup

FileAccessDate
2014:11:02 13:24:57+01:00

ProductVersion
1.0.2

SubsystemVersion
5.0

ISInternalDescription
Setup Launcher Unicode

OSVersion
5.0

FileCreateDate
2014:11:02 13:24:57+01:00

OriginalFilename
InstallShield Setup.exe

LegalCopyright
Copyright (c) 2013 Flexera Software LLC. All Rights Reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
LogicLevels

CodeSize
715776

ProductName
RemoteGPU

ProductVersionNumber
1.0.2.0

EntryPoint
0x6b0cb

ObjectFileType
Dynamic link library

File identification
MD5 e6b901d21992d69cd211a6a38c9f3fda
SHA1 2b24831e2fee937940c3196b0f89398d3e8becbb
SHA256 f3cfb9430964746a43eb1c648c54779f3303b89202231a272efec0b3f49a8e50
ssdeep
49152:KNQ1pZDuOTLHNs/pV2yO7TsDZBK/hx6AcV3T83ELQznr:KNLOHHNs/pV2gZBIaZ83Qcr

authentihash 523f666dd4401249c9fc6fb8d2090d1a5d1a10ddc6125bd42f876a997b1e25f6
imphash 8716dfcb53e9237687620dc5ebbd5d82
File size 1.8 MB ( 1883134 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID InstallShield setup (48.1%)
Win32 Executable MS Visual C++ (generic) (34.9%)
Win32 Dynamic Link Library (generic) (7.3%)
Win32 Executable (generic) (5.0%)
Generic Win/DOS Executable (2.2%)
Tags
peexe

VirusTotal metadata
First submission 2013-11-01 14:53:08 UTC ( 4 years, 9 months ago )
Last submission 2013-11-01 14:53:08 UTC ( 4 years, 9 months ago )
File names InstallShield Setup.exe
setup.exe
Setup
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Copied files
Deleted files
Set keys
Created processes
Code injections in the following processes
Opened mutexes
Runtime DLLs
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl Windows API function.