× В вашем браузере отключены куки (cookie). Для полноценной работы сайта необходимо включить сохранение файлов cookie.
SHA256: 2f9ebfd6aea7500ea2d1c1a48c403cc96f71bb47535d72610ecaa79ee47c24e6
Имя файла: K-Lite_Codec_Pack_1035_Standard.exe
Показатель выявления: 0 / 51
Дата анализа: 2014-04-15 20:18:13 UTC (4 лет, 7 месяцев назад) Показать последний анализ
Антивирус Результат Дата обновления
Ad-Aware 20140415
AegisLab 20140415
Yandex 20140415
AhnLab-V3 20140415
AntiVir 20140415
Antiy-AVL 20140415
Avast 20140415
AVG 20140415
Baidu-International 20140415
BitDefender 20140415
Bkav 20140415
ByteHero 20140415
CAT-QuickHeal 20140415
ClamAV 20140415
CMC 20140411
Commtouch 20140415
Comodo 20140415
DrWeb 20140415
Emsisoft 20140415
ESET-NOD32 20140415
F-Prot 20140415
F-Secure 20140415
Fortinet 20140413
GData 20140415
Ikarus 20140415
Jiangmin 20140415
K7AntiVirus 20140415
K7GW 20140415
Kaspersky 20140415
Kingsoft 20140415
Malwarebytes 20140415
McAfee 20140415
McAfee-GW-Edition 20140415
Microsoft 20140415
eScan 20140415
NANO-Antivirus 20140415
Norman 20140415
nProtect 20140415
Panda 20140415
Qihoo-360 20140415
Rising 20140415
Sophos AV 20140415
SUPERAntiSpyware 20140415
Symantec 20140415
TheHacker 20140413
TotalDefense 20140415
TrendMicro 20140415
TrendMicro-HouseCall 20140415
VBA32 20140415
VIPRE 20140415
ViRobot 20140415
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright

Product K-Lite Codec Pack
File version 10.3.5.0
Description K-Lite Codec Pack Setup
Comments This installation was built with Inno Setup.
Packers identified
F-PROT INNO, appended
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-10-13 08:19:32
Entry Point 0x000113BC
Number of sections 8
PE sections
Overlays
MD5 2a0e6a93f298b7e0a7796e06291c722b
File type data
Offset 257024
Size 18139696
Entropy 8.00
PE imports
RegCloseKey
OpenProcessToken
RegOpenKeyExW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegQueryValueExW
InitCommonControls
GetLastError
GetStdHandle
GetUserDefaultLangID
GetSystemInfo
GetModuleFileNameW
WaitForSingleObject
GetVersionExW
FreeLibrary
QueryPerformanceCounter
GetTickCount
GetThreadLocale
VirtualProtect
GetFileAttributesW
RtlUnwind
lstrlenW
GetExitCodeProcess
CreateProcessW
GetStartupInfoA
SizeofResource
GetWindowsDirectoryW
LocalAlloc
LockResource
GetDiskFreeSpaceW
GetCommandLineW
SetErrorMode
UnhandledExceptionFilter
LoadLibraryExW
MultiByteToWideChar
EnumCalendarInfoW
GetCPInfo
DeleteFileW
GetProcAddress
InterlockedCompareExchange
GetLocaleInfoW
lstrcpynW
RaiseException
WideCharToMultiByte
RemoveDirectoryW
SetFilePointer
GetFullPathNameW
ReadFile
GetEnvironmentVariableW
InterlockedExchange
CreateDirectoryW
WriteFile
GetCurrentProcess
CloseHandle
FindFirstFileW
GetACP
GetModuleHandleW
SignalObjectAndWait
SetEvent
FormatMessageW
LoadLibraryW
CreateEventW
GetVersion
LoadResource
FindResourceW
CreateFileW
VirtualQuery
VirtualFree
FindClose
TlsGetValue
Sleep
SetEndOfFile
TlsSetValue
ExitProcess
GetCurrentThreadId
VirtualAlloc
GetFileSize
SetLastError
ResetEvent
SysReAllocStringLen
SysFreeString
SysAllocStringLen
GetSystemMetrics
SetWindowLongW
MessageBoxW
PeekMessageW
LoadStringW
MessageBoxA
CreateWindowExW
MsgWaitForMultipleObjects
TranslateMessage
CharUpperBuffW
CallWindowProcW
CharNextW
GetKeyboardType
ExitWindowsEx
DispatchMessageW
DestroyWindow
Number of PE resources by type
RT_ICON 10
RT_STRING 6
RT_RCDATA 4
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 14
NEUTRAL 9
PE resources
ExifTool file metadata
SubsystemVersion
5.0

Comments
This installation was built with Inno Setup.

InitializedDataSize
190976

ImageVersion
6.0

ProductName
K-Lite Codec Pack

FileVersionNumber
10.3.5.0

UninitializedDataSize
0

LanguageCode
Neutral

FileFlagsMask
0x003f

CharacterSet
Unicode

LinkerVersion
2.25

FileTypeExtension
exe

MIMEType
application/octet-stream

FileVersion
10.3.5.0

TimeStamp
2013:10:13 09:19:32+01:00

FileType
Win32 EXE

PEType
PE32

ProductVersion
10.3.5

FileDescription
K-Lite Codec Pack Setup

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
65024

FileSubtype
0

ProductVersionNumber
10.3.5.0

EntryPoint
0x113bc

ObjectFileType
Executable application

CarbonBlack CarbonBlack acts as a surveillance camera for computers
While monitoring an end-user machine in-the-wild, CarbonBlack noticed the following files in execution wrote this sample to disk.
Compressed bundles
File identification
MD5 150dd2ca9cdc8236e100e4385e65e821
SHA1 2f9abede79767cbe17126f4b970a34d21da52514
SHA256 2f9ebfd6aea7500ea2d1c1a48c403cc96f71bb47535d72610ecaa79ee47c24e6
ssdeep
393216:TyPVa36Y6OquOT5orr1vGqJ2Y1F6S6oqD3VDbbRJsfsc:ONSquCCOQLgxbbfEsc

authentihash 03e86ddd46c4e97175ea4a4fc626ae9bd3280bcc592a4753f79781824d739de0
imphash 48aa5c8931746a9655524f67b25a47ef
Размер файла 17.5 MБ ( 18396720 bytes )
Тип файла Win32 EXE
Описание
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable Delphi generic (57.2%)
Win32 Executable (generic) (18.2%)
Win16/32 Executable Delphi generic (8.3%)
Generic Win/DOS Executable (8.0%)
DOS Executable Generic (8.0%)
Tags
peexe overlay

VirusTotal metadata
First submission 2014-02-27 20:27:18 UTC (4 лет, 8 месяцев назад)
Last submission 2017-08-16 07:15:32 UTC (1 год, 3 месяцев назад)
Имена файлов K-Lite_Codec_Pack_1035_Standard.exe
aa
K-Lite_Codec_Pack_Standard.exe
file-6736287_exe
filename
K-Lite Codec Pack Standard 10.3.5.exe
K-Lite Codec Pack Standard v10.3.5.exe
K-Lite_Codec_Pack_1035_Standard.exe
K-Lite_Codec_Pack_1035_Standard.exe
bit9c3c.tmp
K-Lite_Codec_Pack_1035_Standard (1).exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
Нет комментариев. Из участников сообщества VirusTotal ещё пока никто не оставил комментарий по поводу результатов анализа. Станьте первым!

Оставьте свой комментарий...

?
Отправить

Вы не выполнили вход. Только зарегистрированные пользователи могут оставлять комментарии. Выполните вход и получите право голоса!

Нет голосов. Ещё пока никто не проголосовал за результаты анализа. Станьте первым!