Online Virus Checker | v.1.0.195.174 |
DB Version: | 2024-11-02 20:00:24 |
Packing is a common tactic used by malware authors to make their malicious code more difficult to analyze and detect by antivirus and security programs. These techniques involve compressing, encrypting, or otherwise altering the malware's code to make it appear different from its original form. The goal is to hide the true nature of the malware from security tools.
File | SamFwToolSetup.exe |
Checked | 2024-11-02 18:50:24 |
MD5 | a3a38db6f62269ed7cee99fabb676135 |
SHA1 | 39f4958ae7481b2a3e7452c2dffb648ea5e200be |
SHA256 | 7640282150d51c407ffdfe2fab35f2c60b93b0dc56ac93ad2459b16789aec61b |
SHA512 | e340b323bba664fd2b2d819da151c886ec66849ba3798377cf0e8cbcf253f9604ce248e62b22ac184939e5947f87a2f5964ee649099d6d14971c71270894771d |
Imphash | e569e6f445d32ba23766ad67d1e3787f |
File Size | 59530215 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win32.Packed.cl without requiring further user intervention.
Comments | This installation was built with Inno Setup. |
CompanyName | SamFw.com |
FileDescription | SamFw Tool Setup |
FileVersion | |
LegalCopyright | |
OriginalFileName | |
ProductName | SamFw Tool |
ProductVersion | 4.9 |
Translation | 0x0000 0x04b0 |
a0ef7c81eee20e999575764306184ccf 8341e53a6f1047f3c936b4d36dc8f542 5050d274ccec82ae |
|
Image Base: | 0x00400000 |
Entry Point: | 0x004b5eec |
Compilation: | 2023-02-15 14:54:16 |
Checksum: | 0x00000000 (Actual: 0x038d1360) |
OS Version: | 6.1 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | No valid SignedData structure was found. |
Sections: | 10 |
Imports: | kernel32, comctl32, version, user32, oleaut32, netapi32, advapi32, |
Exports: | 3 |
Resources: | 30 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000b39e4 | 0x000b3a00 | 43af0a9476ca224d8e8461f1e22c94da | 6.36 |
.itext | 0x000b5000 | 0x00001688 | 0x00001800 | 185e04b9a1f554e31f7f848515dc890c | 5.97 |
.data | 0x000b7000 | 0x000037a4 | 0x00003800 | cab2107c933b696aa5cf0cc6c3fd3980 | 5.05 |
.bss | 0x000bb000 | 0x00006de8 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.idata | 0x000c2000 | 0x00000fdc | 0x00001000 | e7d1635e2624b124cfdce6c360ac21cd | 5.03 |
.didata | 0x000c3000 | 0x000001a4 | 0x00000200 | 8ced971d8a7705c98b173e255d8c9aa7 | 2.75 |
.edata | 0x000c4000 | 0x0000009a | 0x00000200 | 8d4e1e508031afe235bf121c80fd7d5f | 1.88 |
.tls | 0x000c5000 | 0x00000018 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rdata | 0x000c6000 | 0x0000005d | 0x00000200 | 8f2f090acd9622c88a6a852e72f94e96 | 1.38 |
.rsrc | 0x000c7000 | 0x00011000 | 0x00011000 | f2c506d4c35b9e67e87ce9122eabc891 | 3.69 |