File Name | CredentialsFileView.exe |
File Type |
PE32+ executable (GUI) x86-64, for MS Windows
|
Scanner Version | 1.0.178.174 |
Database Version | 2024-06-07 14:00:44 UTC |
Malware family: GenericMC
Hash Type | Value | Action |
---|---|---|
MD5 |
98ebc043f4772794444692dc05c48c26
|
|
SHA1 |
c300545976d9a91d1080de05c9bb6aa51599e4fb
|
|
SHA256 |
96cd6464e9f8005f1c428f5b5f939b6d3bd351e2bee1a16775e7571cc5135f74
|
|
SHA512 |
1dea323649b8e0a7422bd14dcafb8116ce44f713064e36cf81a53f4902d9f660317f731f250cfb650c42d8dd805014fcbe3072d52fafb4ecf90530809e645bf3
|
|
ImpHash |
12fa4297f63c3c5ad358a59bb8dccfb0
|
Icon |
Hash: d258b4d8ddc716b5258c54dccb16792b
Fuzzy: 97cd73458bc15bb6744c4afe3e7d5836 dHash: c88cbab1f2f2b390 |
Image Base | 0x140000000 |
Entry Point | 0x1400175c0 |
Compilation Time | 2017-10-29 08:13:25 |
Checksum | 0x0002c610 (Actual: 0x0002c610) |
OS Version | 4.0 |
PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
PDB Path | c:\Projects\VS2005\CredentialsFileView\x64\Release\CredentialsFileView.pdb |
Digital Signature | OK |
Imports |
10 libraries
msvcrt, COMCTL32, VERSION, CRYPT32, KERNEL32, USER32, GDI32, comdlg32, ADVAPI32, SHELL32 |
Exports | 0 functions |
Resources | 31 Resources |
Sections | 5 Sections |
CompanyName | NirSoft |
FileDescription | CredentialsFileView |
FileVersion | 1.07 |
InternalName | CredentialsFileView |
LegalCopyright | Copyright © 2016 - 2017 Nir Sofer |
OriginalFilename | CredentialsFileView.exe |
ProductName | CredentialsFileView |
ProductVersion | 1.07 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
92,935 bytes | 93,184 bytes | 6.17 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
02A098FE570B59396DBB5B6483A69147 |
.rdata |
0x00018000 |
20,378 bytes | 20,480 bytes | 4.77 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8406F2AAAAC0CAA7AC64B2EF4E7623AF |
.data |
0x0001d000 |
9,456 bytes | 1,536 bytes | 2.84 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
62E998907895E0923B87C00D031A6837 |
.pdata |
0x00020000 |
3,684 bytes | 4,096 bytes | 4.68 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B0BA4EC4AD214998D17835D9DDF83930 |
.rsrc |
0x00021000 |
23,068 bytes | 23,552 bytes | 5.31 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
574BA54937366A296D2289BD0453416B |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_CURSOR | 2 | 616 bytes | |
RT_BITMAP | 3 | 5,848 bytes | |
RT_ICON | 3 | 5,688 bytes | |
RT_MENU | 2 | 1,786 bytes | |
RT_DIALOG | 5 | 3,548 bytes | |
RT_STRING | 9 | 1,742 bytes | |
RT_ACCELERATOR | 1 | 80 bytes | |
RT_GROUP_CURSOR | 2 | 40 bytes | |
RT_GROUP_ICON | 2 | 54 bytes | |
RT_VERSION | 1 | 780 bytes | |
RT_MANIFEST | 1 | 1,095 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate Malware.Win64.GenericMC.cc without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system