× Les cookies sont désactivés ! Ce site exige que les cookies soient activés pour fonctionner correctement
SHA256: 0f1248e012e049dea4736c111a4480bd49ae4c2d3a6f7093dbc41d9c402a365f
Nom du fichier : qbpssetup.exe.bin
Ratio de détection : 17 / 68
Date d'analyse : 2019-03-27 09:26:03 UTC (il y a 3 semaines, 2 jours)
Antivirus Résultat Mise à jour
AhnLab-V3 Malware/Gen.Generic.C3111500 20190327
Avast Win32:Malware-gen 20190327
AVG Win32:Malware-gen 20190327
DrWeb Program.Unwanted.3897 20190327
Emsisoft Application.OptInstall (A) 20190327
ESET-NOD32 a variant of Win32/GT32SupportGeeks.U potentially unwanted 20190327
Fortinet Riskware/GT32SupportGeeks 20190327
K7AntiVirus Adware ( 005418911 ) 20190327
K7GW Adware ( 005418911 ) 20190327
Kaspersky Hoax.Win32.DeceptPCClean.cug 20190327
Malwarebytes PUP.Optional.PCVARK 20190327
McAfee Artemis!2DAEFEBD4ABC 20190327
McAfee-GW-Edition Artemis 20190326
Qihoo-360 Win32/Trojan.Hoax.799 20190327
Sophos AV Generic PUA AF (PUA) 20190327
Webroot W32.Adware.Gen 20190327
ZoneAlarm by Check Point Hoax.Win32.DeceptPCClean.cug 20190327
Acronis 20190327
Ad-Aware 20190327
AegisLab 20190327
Alibaba 20190306
ALYac 20190327
Antiy-AVL 20190327
Arcabit 20190327
Avast-Mobile 20190327
Avira (no cloud) 20190327
Babable 20180918
Baidu 20190318
BitDefender 20190327
Bkav 20190326
CAT-QuickHeal 20190326
ClamAV 20190327
CMC 20190321
Comodo 20190326
CrowdStrike Falcon (ML) 20190212
Cybereason 20190325
Cylance 20190327
Cyren 20190327
eGambit 20190327
Endgame 20190322
F-Prot 20190327
FireEye 20190327
GData 20190327
Ikarus 20190326
Sophos ML 20190313
Jiangmin 20190327
Kingsoft 20190327
MAX 20190327
Microsoft 20190327
eScan 20190327
NANO-Antivirus 20190327
Palo Alto Networks (Known Signatures) 20190327
Panda 20190326
Rising 20190327
SentinelOne (Static ML) 20190317
SUPERAntiSpyware 20190321
Symantec 20190327
Symantec Mobile Insight 20190325
TACHYON 20190327
Tencent 20190327
TheHacker 20190324
Trapmine 20190325
Trustlook 20190327
VBA32 20190327
VIPRE 20190326
ViRobot 20190327
Yandex 20190327
Zillya 20190326
Zoner 20190327
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Authenticode signature block and FileVersionInfo properties
Copyright

Product Qbit-PC-Speedup
File version 1.0.0.2
Description Qbit-PC-Speedup Setup
Comments This installation was built with Inno Setup.
Signature verification Signed file, verified signature
Signing date 11:24 AM 3/19/2019
Signers
[+] ADEQUATE SOFTWARES
Status This certificate or one of the certificates in the certificate chain is not time valid.
Issuer COMODO RSA Code Signing CA
Valid from 12:00 AM 02/20/2019
Valid to 11:59 PM 03/19/2019
Valid usage Code Signing
Algorithm sha256RSA
Thumbprint 074067B0C482D950E072960711723313080FD305
Serial number 64 A2 B9 03 6D F6 67 B9 A9 80 DF DE A6 7F FF F8
[+] COMODO RSA Code Signing CA
Status Valid
Issuer COMODO RSA Certification Authority
Valid from 12:00 AM 05/09/2013
Valid to 11:59 PM 05/08/2028
Valid usage Code Signing
Algorithm sha384RSA
Thumbprint B69E752BBE88B4458200A7C0F4F5B3CCE6F35B47
Serial number 2E 7C 87 CC 0E 93 4A 52 FE 94 FD 1C B7 CD 34 AF
[+] COMODO SECURE™
Status Valid
Issuer COMODO RSA Certification Authority
Valid from 12:00 AM 01/19/2010
Valid to 11:59 PM 01/18/2038
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha384RSA
Thumbprint AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4
Serial number 4C AA F9 CA DB 63 6F E0 1F F7 4E D8 5B 03 86 9D
Counter signers
[+] COMODO SHA-1 Time Stamping Signer
Status Valid
Issuer UTN-USERFirst-Object
Valid from 12:00 AM 12/31/2015
Valid to 06:40 PM 07/09/2019
Valid usage Timestamp Signing
Algorithm sha1RSA
Thumbrint 03A5B14663EB12023091B84A6D6A68BC871DE66B
Serial number 16 88 F0 39 25 5E 63 8E 69 14 39 07 E6 33 0B
[+] UTN-USERFirst-Object
Status Valid
Issuer AddTrust External CA Root
Valid from 08:09 AM 06/07/2005
Valid to 10:48 AM 05/30/2020
Valid usage All
Algorithm sha1RSA
Thumbrint 8AD5C9987E6F190BD6F5416E2DE44CCD641D8CDA
Serial number 42 1A F2 94 09 84 19 1F 52 0A 4B C6 24 26 A7 4B
[+] The USERTrust Network™
Status Valid
Issuer AddTrust External CA Root
Valid from 10:48 AM 05/30/2000
Valid to 10:48 AM 05/30/2020
Valid usage Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
Algorithm sha1RSA
Thumbrint 02FAF3E291435468607857694DF5E45B68851868
Serial number 01
Packers identified
F-PROT INNO, appended, Unicode
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-01-15 08:22:50
Entry Point 0x000113BC
Number of sections 8
PE sections
Overlays
MD5 ff2aa353b242f5747438b7a45887440e
File type data
Offset 170496
Size 7017248
Entropy 8.00
PE imports
RegCloseKey
OpenProcessToken
RegOpenKeyExW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegQueryValueExW
InitCommonControls
GetLastError
GetStdHandle
GetUserDefaultLangID
GetSystemInfo
GetModuleFileNameW
WaitForSingleObject
GetVersionExW
FreeLibrary
QueryPerformanceCounter
GetTickCount
GetThreadLocale
VirtualProtect
GetFileAttributesW
RtlUnwind
lstrlenW
GetExitCodeProcess
CreateProcessW
GetStartupInfoA
SizeofResource
GetWindowsDirectoryW
LocalAlloc
LockResource
GetDiskFreeSpaceW
GetCommandLineW
SetErrorMode
UnhandledExceptionFilter
LoadLibraryExW
MultiByteToWideChar
EnumCalendarInfoW
GetCPInfo
DeleteFileW
GetProcAddress
InterlockedCompareExchange
GetLocaleInfoW
lstrcpynW
RaiseException
WideCharToMultiByte
RemoveDirectoryW
SetFilePointer
GetFullPathNameW
ReadFile
GetEnvironmentVariableW
InterlockedExchange
CreateDirectoryW
WriteFile
GetCurrentProcess
CloseHandle
FindFirstFileW
GetACP
GetModuleHandleW
SignalObjectAndWait
SetEvent
FormatMessageW
LoadLibraryW
CreateEventW
GetVersion
LoadResource
FindResourceW
CreateFileW
VirtualQuery
VirtualFree
FindClose
TlsGetValue
Sleep
SetEndOfFile
TlsSetValue
ExitProcess
GetCurrentThreadId
VirtualAlloc
GetFileSize
SetLastError
ResetEvent
SysReAllocStringLen
SysFreeString
SysAllocStringLen
GetSystemMetrics
SetWindowLongW
MessageBoxW
PeekMessageW
LoadStringW
MessageBoxA
CreateWindowExW
MsgWaitForMultipleObjects
TranslateMessage
CharUpperBuffW
CallWindowProcW
CharNextW
GetKeyboardType
ExitWindowsEx
DispatchMessageW
DestroyWindow
Number of PE resources by type
RT_ICON 6
RT_STRING 6
RT_RCDATA 4
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 10
NEUTRAL 9
PE resources
ExifTool file metadata
SubsystemVersion
5.0

Comments
This installation was built with Inno Setup.

LinkerVersion
2.25

ImageVersion
6.0

FileSubtype
0

FileVersionNumber
1.0.0.2

LanguageCode
Neutral

FileFlagsMask
0x003f

FileDescription
Qbit-PC-Speedup Setup

ImageFileCharacteristics
No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi

CharacterSet
Unicode

InitializedDataSize
104448

EntryPoint
0x113bc

MIMEType
application/octet-stream

FileVersion
1.0.0.2

TimeStamp
2016:01:15 09:22:50+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
1.0.0.2

UninitializedDataSize
0

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
65024

ProductName
Qbit-PC-Speedup

ProductVersionNumber
1.0.0.2

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 2daefebd4abce0aab7460a7ed60bed4d
SHA1 05cbd7a3f2115837b7e937af1e8758f0f16cfa78
SHA256 0f1248e012e049dea4736c111a4480bd49ae4c2d3a6f7093dbc41d9c402a365f
ssdeep
98304:Cb20CrxWOOrbpVx9dR4pqrcTuIQeysWO8RwLwgiAgPXtfb0K7zhLmIgawRtw6t74:CbGtOcqcuXhnRiLc1b0QzhqIsU6t8

authentihash b57f844f327f06b701a54b2555d380d27c26bb6ccf0d8bdb535eaefa520ba2cc
imphash 48aa5c8931746a9655524f67b25a47ef
File size 6.9 MB ( 7187744 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable Delphi generic (52.9%)
Win32 Executable (generic) (16.8%)
Win16/32 Executable Delphi generic (7.7%)
OS/2 Executable (generic) (7.5%)
Generic Win/DOS Executable (7.4%)
Tags
peexe signed overlay

VirusTotal metadata
First submission 2019-03-27 09:26:03 UTC (il y a 3 semaines, 2 jours)
Last submission 2019-03-27 09:26:03 UTC (il y a 3 semaines, 2 jours)
Noms du fichier qbpssetup.exe
qbpssetup.exe.bin
Aucun commentaire. Aucun membre de la communauté VirusTotal n'a encore commenté cet élément, soyez le premier à le faire !

Laissez votre commentaire...

?
Poster un commentaire

Vous n'êtes pas connecté. Seuls les utilisateurs enregistrés peuvent laisser des commentaires, connectez-vous pour commenter !

Aucun vote. Personne n'a encore voté pour cet élément, soyez le premier à le faire !
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Deleted files
Created processes
Shell commands
Opened mutexes
Runtime DLLs