File Name | winmaster.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
|
Scanner Version | 1.0.160.174 |
Database Version | 2024-02-11 21:00:16 UTC |
Malware family: Gen
Hash Type | Value | Action |
---|---|---|
MD5 |
9ab4225a119d958cd7b507af3d73fa3a
|
|
SHA1 |
8899144cc67f6507b65e84ff8bc57e43406c3a91
|
|
SHA256 |
4657950fe60ef10276612639f84e1b9ecab951e778c71d02535dfa2dd3f593b1
|
|
SHA512 |
df8aa7aec95d305fc3baa6f82df19bf17c8257ee41aaff6b2e9bc43f9eb13e753af436a3c590d1769b980906d4a907b86659beea0a8887962269a68869c96797
|
|
ImpHash |
de6c1dba92d61d6284c639e328489dd8
|
Icon |
Hash: af319e4dd53f9796517ff77ee1fd9b29
Fuzzy: 3d0d14bfbff073451dd7234e7f413fa6 dHash: aab2e8ccccf0b2aa |
Image Base | 0x00400000 |
Entry Point | 0x006ade00 |
Compilation Time | 2020-03-31 09:41:09 |
Checksum | 0x0012a1bb (Actual: 0x0012a1bb) |
OS Version | 5.1 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
|
Digital Signature | OK |
Imports | 17 libraries |
Exports | 0 functions |
Resources | 192 Resources |
Sections | 3 Sections |
CompanyName | 青岛软媒网络科技有限公司 |
FileDescription | 软媒设置大师 |
FileVersion | 3.7.3.0 |
InternalName | WinMaster |
LegalCopyright | 青岛软媒 |
OriginalFilename | WinMaster.exe |
ProductName | 软媒设置大师 |
ProductVersion | 3.7.3.0 |
Translation | 0x0804 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
UPX0 |
0x00001000 |
2,162,688 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
UPX1 |
0x00211000 |
647,168 bytes | 643,584 bytes | 7.93 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
E0F61F18D4D0ABCCFE65919BFC50087E |
.rsrc |
0x002af000 |
528,384 bytes | 526,336 bytes | 3.90 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
98FDCAF66354570A955174D147436FDF |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
GIF | 1 | 4,355 bytes | |
PNG | 88 | 82,305 bytes | |
RT_ICON | 29 | 510,341 bytes | |
RT_DIALOG | 49 | 28,216 bytes | |
RT_STRING | 10 | 3,424 bytes | |
RT_ACCELERATOR | 1 | 112 bytes | |
RT_GROUP_ICON | 7 | 448 bytes | |
RT_VERSION | 1 | 652 bytes | |
RT_HTML | 5 | 86,670 bytes | |
RT_MANIFEST | 1 | 651 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.Gen.bot!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system