File Name | hdd.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.148.174 |
Database Version | 2023-11-22 22:01:04 UTC |
Malware family: SlimWare
Hash Type | Value | Action |
---|---|---|
MD5 |
2f123e435da52034e970f1fe4c6aa51e
|
|
SHA1 |
14711b0734c8a82209b67ad302fc39696a559a0f
|
|
SHA256 |
74f0f4c046e85f2ef5cac053a3c8df762f9d438acc36d770614f2ed8bade3c38
|
|
SHA512 |
603170266e56df85ee57dbcd623c986e24c4ff070d3ab7844e6a13c6063d9fcfe2dd09675d34ec97de73663f197f63c1a1d662aaf9a6cdcdbb0feb398d5de37c
|
|
ImpHash |
e85cfcade1b885be4607ae52008eba57
|
Icon |
Hash: 30adcb5c0b2e3c35eaec2c110733c9f8
Fuzzy: c98f96d6ffe5af8d4eb0870c1dc20826 dHash: 92e0b496a6cada72 |
Image Base | 0x00400000 |
Entry Point | 0x004376bb |
Compilation Time | 2016-07-30 16:10:51 |
Checksum | 0x00000000 (Actual: 0x000f8fcc) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB Path | E:\BuildAgent\work\cdc3d0ebfd4f8694\bin\Release\LittleInstaller.pdb |
Digital Signature | OK |
Imports | 12 libraries |
Exports | 0 functions |
Resources | 121 Resources |
Sections | 5 Sections |
Thawte Timestamping CA | Symantec Corporation (US) |
Symantec Time Stamping Services CA - G2 | Symantec Corporation (US) |
VeriSign Class 3 Code Signing 2010 CA | Slimware Utilities Holdings, Inc. (US) |
VeriSign Class 3 Public Primary Certification Authority - G5 | VeriSign, Inc. (US) |
CompanyName | Slimware Utilities Holdings, Inc. |
FileDescription | DriverUpdate Setup Wizard |
FileVersion | 2.7.1 |
InternalName | LittleInstaller |
LegalCopyright | Copyright 2011-2016 Slimware Utilities Holdings, Inc. |
OriginalFilename | DriverUpdate-setup.exe |
ProductName | DriverUpdate |
ProductVersion | 2.7.1 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
347,916 bytes | 348,160 bytes | 6.64 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
DAC79876157EE0F0BA978A563FAA3E33 |
.rdata |
0x00056000 |
97,562 bytes | 98,304 bytes | 4.68 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D5E031E5F0DC45391315435E5B8272AE |
.data |
0x0006e000 |
32,444 bytes | 16,384 bytes | 4.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D947A72AE9353E2F3D37C83D487EB597 |
.rsrc |
0x00076000 |
450,414 bytes | 450,560 bytes | 5.83 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
ED2C04813BBB97AEF85B84400EA8A1E4 |
.reloc |
0x000e4000 |
52,080 bytes | 53,248 bytes | 4.09 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
6C86E5FFFF6BC51A3F5E33E2C950D936 |
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_CURSOR | 2 | 488 bytes | |
RT_BITMAP | 2 | 508 bytes | |
RT_ICON | 4 | 4,640 bytes | |
RT_DIALOG | 11 | 3,916 bytes | |
RT_STRING | 75 | 59,110 bytes | |
RT_MESSAGETABLE | 1 | 1,720 bytes | |
RT_GROUP_CURSOR | 1 | 34 bytes | |
RT_GROUP_ICON | 1 | 62 bytes | |
RT_VERSION | 1 | 860 bytes | |
RT_MANIFEST | 1 | 1,211 bytes | |
None | 22 | 372,890 bytes |
Subject |
Symantec Time Stamping Services CA - G2 Symantec Corporation US |
Issuer | Thawte Timestamping CA |
Serial Number | 168250781398245547403531165097821404219 |
Subject |
Symantec Time Stamping Services Signer - G4 Symantec Corporation US |
Issuer | Symantec Time Stamping Services CA - G2 |
Serial Number | 19688950797630895426199952712430983760 |
Subject |
Slimware Utilities Holdings, Inc. Slimware Utilities Holdings, Inc. US |
Issuer | VeriSign Class 3 Code Signing 2010 CA |
Serial Number | 48411647503751905988622831571218561274 |
Subject |
VeriSign Class 3 Code Signing 2010 CA VeriSign, Inc. US |
Issuer | VeriSign Class 3 Public Primary Certification Authority - G5 |
Serial Number | 109001353806506068745144901449045193671 |
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.SlimWare.sd!c without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system