File Name | Setup_171596135748016538.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
Scanner Version | 1.0.176.174 |
Database Version | 2024-05-17 18:00:20 UTC |
Malware family: PCAppStore
Hash Type | Value | Action |
---|---|---|
MD5 |
8d9729eed38788f31934f67d2ca0f634
|
|
SHA1 |
8118c27b4a19fb02480b5cd8954663faf36cbdb1
|
|
SHA256 |
bae2ecc1d0a3ff3a7d169a6fdcadb577b5fc4b208cf56e51179aaa9ca52c4838
|
|
SHA512 |
aff5ced5108850c8ddebb2c126384c7bd598736ce564606861febd9e760c338980fee1dfa9822d1daf3d339a2e73aba263b0b9162ab5467601e7491204c222c6
|
|
ImpHash |
56a78d55f3f7af51443e58e0ce2fb5f6
|
Icon |
Hash: f0a7b124f74f3fe7097b5cb11bac2382
Fuzzy: 5e467c414068e3f6b3a2d2c7cba55bbd dHash: 4dd4cc69b2498041 |
Image Base | 0x00400000 |
Entry Point | 0x0040352d |
Compilation Time | 2021-09-25 21:57:46 |
Checksum | 0x00020dee (Actual: 0x00020dee) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
Digital Signature | OK |
Imports |
7 libraries
ADVAPI32, SHELL32, ole32, COMCTL32, USER32, GDI32, KERNEL32 |
Exports | 0 functions |
Resources | 8 Resources |
Sections | 5 Sections |
CompanyName | Fast Corporation LTD |
FileDescription | PC App Store Setup |
LegalCopyright | Fast Corporation LTD |
ProductName | PC App Store |
ProductVersion | 1.0.0.1091g |
Translation | 0x0409 0x04e4 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
26,775 bytes | 27,136 bytes | 6.46 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
CE9DF19DF15AA7BFBC0A8D0AF0B841D0 |
.rdata |
0x00008000 |
5,286 bytes | 5,632 bytes | 5.02 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A118375C929D970903C1204233B7583D |
.data |
0x0000a000 |
176,152 bytes | 1,536 bytes | 4.15 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
82A10C59A8679BB952FC8316070B8A6C |
.ndata |
0x00036000 |
204,800 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x00068000 |
20,288 bytes | 20,480 bytes | 2.76 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D4ECA3339F2B9A6DC81370B707E8EFA4 |
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_ICON | 1 | 16,936 bytes | |
RT_DIALOG | 4 | 1,160 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 576 bytes | |
RT_MANIFEST | 1 | 1,059 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
OK
Gridinsoft has the capability to identify and eliminate PUP.Win32.PCAppStore.dd!i without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system