Loading ...

Play interactive tourEdit tour

Windows Analysis Report HD1(GPS) v2.24.exe

Overview

General Information

Sample Name:HD1(GPS) v2.24.exe
Analysis ID:85
MD5:1148fd1e4b2c4237bf152a9ceb94a62f
SHA1:41463fd921d1f07033560338e533f91f8747ed6e
SHA256:3cd2b40b277c073b3d29387d9fcbe8b09cca7a47b3213c5f212ce847ec23c64f
Infos:

Most interesting Screenshot:

Detection

Score:4
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Contains capabilities to detect virtual machines
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Tries to load missing DLLs
Uses 32bit PE files

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample searches for specific file, try point organization specific fake files to the analysis machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior

Process Tree

  • System is start
  • HD1(GPS) v2.24.exe (PID: 8168 cmdline: 'C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe' MD5: 1148FD1E4B2C4237BF152A9CEB94A62F)
    • HD1(GPS) v2.24.exe (PID: 8136 cmdline: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe MD5: B4EA834A92DC4ECCF771006F0B473E30)
  • cleanup

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: HD1(GPS) v2.24.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\6327187.tmp
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeSection loaded: vb6chs.dll
Source: HD1(GPS) v2.24.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: classification engineClassification label: clean4.winEXE@3/25@0/0
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Program Files (x86)\HD1(GPS)
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD1(GPS)
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeFile created: C:\Users\alfredo\AppData\Local\Temp\~DF43C76EB627536632.TMP
Source: HD1(GPS) v2.24.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile read: C:\Users\desktop.ini
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
Source: unknownProcess created: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe 'C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe'
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess created: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess created: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeKey value created or modified: HKEY_CURRENT_USER\Control Panel\Mouse MouseHoverTime
Source: HD1(GPS) v2.24.exeStatic file information: File size 3592691 > 1048576
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\Actbar3.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\msbind.dllJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\msflxgrd.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\mscomm32.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Program Files (x86)\HD1(GPS)\Uninstall.exeJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\MSCOMCTL.OCXJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\COMDLG32.OCXJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\Command.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\mshflxgd.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Users\alfredo\AppData\Local\Temp\aiw6306984.EXEJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\Actbar3.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\msbind.dllJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\msflxgrd.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\mscomm32.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\MSCOMCTL.OCXJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\COMDLG32.OCXJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\Command.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Windows\SysWOW64\mshflxgd.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile created: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD1(GPS)
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeDropped PE file which has not been started: C:\Windows\SysWOW64\Actbar3.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeDropped PE file which has not been started: C:\Windows\SysWOW64\COMDLG32.OCXJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeDropped PE file which has not been started: C:\Windows\SysWOW64\Command.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mshflxgd.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeDropped PE file which has not been started: C:\Users\alfredo\AppData\Local\Temp\aiw6306984.EXEJump to dropped file
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exeQueries volume information: C:\ VolumeInformation

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationDLL Side-Loading1Process Injection1Masquerading22OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobRegistry Run Keys / Startup Folder1DLL Side-Loading1Virtualization/Sandbox Evasion1LSASS MemoryVirtualization/Sandbox Evasion1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Registry Run Keys / Startup Folder1Process Injection1Security Account ManagerFile and Directory Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)DLL Side-Loading1NTDSSystem Information Discovery12Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

No Antivirus matches

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

No contacted IP infos

General Information

Joe Sandbox Version:32.0.0 Black Diamond
Analysis ID:85
Start date:29.06.2021
Start time:21:25:09
Joe Sandbox Product:CloudBasic
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:HD1(GPS) v2.24.exe
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Number of analysed new started processes analysed:11
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Detection:CLEAN
Classification:clean4.winEXE@3/25@0/0
Warnings:
Show All
  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe
  • Report size getting too big, too many NtCreateKey calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtSetInformationFile calls found.
  • Report size getting too big, too many NtSetValueKey calls found.

Created / dropped Files

C:\Program Files (x86)\HD1(GPS)\11.tb3
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:data
Category:dropped
Size (bytes):67002
Entropy (8bit):4.596222790733321
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: ............../...........................................BM........6...(...`......... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Program Files (x86)\HD1(GPS)\CSWJ.tw
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:data
Category:dropped
Size (bytes):862
Entropy (8bit):6.590862113291391
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: ......8.?...qo...|..I....p.;c...xs.?g~..........x..|.p...ygOx.C~..D....._o}~?w~?WLd..SwO....<...|X.{_O|A|b'~?x?5_.o~.o_~?gf.om_y[.="....A...A`;x.gx.55--(.O.~?Oy.w}A.~.|..|.|.o?w?..|g|OcIxxPP.|q.~.|.p.p.oyap@.sg@.P........;b.~..wwD1wD1B?|#..~.@..~0.7:.u|.q.y..n.{@>p'x?x.*U*U/{~_w}?o{~_w}?o{~0.|`.y@?Ay..x.f.L....aq.T<?| 5.`| | |?@._M....`.@.p.x.p.@..@....~w.yp.|.|.p.~.|.`|?`.`.x.o~.@p.|..`?x.~.@p?~.~.p.~.p.p.@.`.`.|.~|.x.p.@.p.~.p.|.@.@.@SLQFEO......%S.%S.....H.@......%.A%.A....I..a.%.F%.F....%.@%.@...p.p.0.%XC%XC.....A%A%0.%.F%.F.....#.#.0........ ............000000..u...1...3...1A..3...Call1...CALL2...CALL3.list1...KEY......""""".33333.DDDDD.UUUUU.fffff.wwwww................... 0@P`p.......... 0@P`p...........radio-1).radio-2..radio-3list1@...Radio-1list1...CALL1)..CALL2...CALL3.CALL4..%c.%c....I...`...%SA%SA...I...`list1...list2...list3....
C:\Program Files (x86)\HD1(GPS)\CSWJ.txt
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):129659
Entropy (8bit):2.0284694119888735
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, .. FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, .. FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, .. FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, .. FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, .. FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FFFF, FF
C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):2928640
Entropy (8bit):5.836793538282988
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........+.[.J...J...J..9V...J...h...J...l...J..Rich.J..................PE..L....{m`..................'..p................(...@..........................p-......;-.....................................t.'.(.....(.....................................................................0... ....................................text...D.'.......'................. ..`.data.........(.......(.............@....rsrc.........(.......(.............@..@l.[J............MSVBVM60.DLL............................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Program Files (x86)\HD1(GPS)\Uninstall.exe
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):346696
Entropy (8bit):7.917287971920076
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........+j..E9..E9..E9..I9..E9..N9..E9{.K9..E9..O9..E9..E9..E9..V9..E9..V9..E9..D9`.E9..N9..E9?.C9..E9Rich..E9........PE..L.....H@.....................4.......i............@......................................................................... ...........X............................................................................................................text............................... ..`.rdata..............................@..@.data...|...........................@....rsrc...X...........................@..@................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw6305109.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 636 x 61 x 24
Category:dropped
Size (bytes):116442
Entropy (8bit):4.729001881244087
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(...|...=.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw6305296.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):6.206632501179402
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X...............................^..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..\..\..\..\..\..\..\..\..\..\..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B....\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..\..\..\..\..\..\..\..\..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B.
C:\Users\alfredo\AppData\Local\Temp\aiw6305531.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):3.147025307853983
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=...e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e
C:\Users\alfredo\AppData\Local\Temp\aiw6305859.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):4.394500643269032
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8...`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`
C:\Users\alfredo\AppData\Local\Temp\aiw6306140.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):3.6147958656153993
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=...e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e
C:\Users\alfredo\AppData\Local\Temp\aiw6306515.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:MS Windows icon resource - 1 icon, 32x32, 2 colors
Category:dropped
Size (bytes):326
Entropy (8bit):1.6176853708804466
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: ...... ......0.......(... ...@......................................................................................................................................................................................................................................?................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw6306656.bmp
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):6.018738622681652
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z/.Z/.V>.UA.Ii.Gn.M\.Z1.Z..Y0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Y/.Y0.RG.Fp.Hk.OS.[+.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z
C:\Users\alfredo\AppData\Local\Temp\aiw6306984.EXE
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):48128
Entropy (8bit):6.3377933069406085
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........+j..E9..E9..E9..I9..E9..N9..E9{.K9..E9..O9..E9..E9..E9..V9..E9..V9..E9..D9`.E9..N9..E9?.C9..E9Rich..E9........PE..L.....H@.....................4.......i............@......................................................................... ...........X............................................................................................................text............................... ..`.rdata..............................@..@.data...|...........................@....rsrc...X...........................@..@................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD1(GPS)\HD1(GPS) v2.24.lnk
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Apr 7 08:31:15 2021, mtime=Mon May 31 03:26:04 2021, atime=Wed Apr 7 08:31:24 2021, length=2928640, window=hide
Category:modified
Size (bytes):1142
Entropy (8bit):4.635117562984788
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... ....R^..+......hm..0...+....,..........................P.O. .:i.....+00.../C:\.....................1......R:#..PROGRA~2.........sN.&.R:#....^...............V......&..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....Z.1......RB#..HD1(GPS)..B.......R:#.RB#.....j.....................n..H.D.1.(.G.P.S.).....r.2...,..R.K .HD1(GP~1.EXE..V......R.K.R=#.....k........................H.D.1.(.G.P.S.). .v.2...2.4...e.x.e.......a...............-.......`..............$.....C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe..J.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).\.H.D.1.(.G.P.S.). .v.2...2.4...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).........*................@Z|...K.J.........`.......X.......899552..........N...n..O...}R...p..Km.......).].N...n..O...}R...p..Km.......).].............1SPS.XF.L8C....&.m.m................S.-.1.-.5.-.2.1.-.2
C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD1(GPS)\Uninstall HD1(GPS).lnk
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon May 31 03:26:03 2021, mtime=Mon May 31 03:26:03 2021, atime=Mon May 31 03:26:03 2021, length=0, window=hide
Category:dropped
Size (bytes):1117
Entropy (8bit):4.609547621877304
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... ...c'..hm..c'..hm..c'..hm...............................P.O. .:i.....+00.../C:\.....................1......R:#..PROGRA~2.........sN.&.R:#....^...............V......&..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....Z.1......RB#..HD1(GPS)..B.......R:#.RB#.....j.....................n..H.D.1.(.G.P.S.).....h.2......RB# .UNINST~1.EXE..L.......RB#.RB#.....k.....................n..U.n.i.n.s.t.a.l.l...e.x.e.......\...............-.......[..............$.....C:\Program Files (x86)\HD1(GPS)\Uninstall.exe..E.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).\.U.n.i.n.s.t.a.l.l...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).........*................@Z|...K.J.........`.......X.......899552..........N...n..O...}R...?..Km.......).].N...n..O...}R...?..Km.......).].............1SPS.XF.L8C....&.m.m................S.-.1.-.5.-.2.1.-.2.6.6.0.4.9.6.7.3.7.-.5.3.
C:\Users\alfredo\Desktop\HD1(GPS) v2.24.lnk
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Apr 7 08:31:15 2021, mtime=Mon May 31 03:25:56 2021, atime=Wed Apr 7 08:31:24 2021, length=2928640, window=hide
Category:dropped
Size (bytes):1106
Entropy (8bit):4.666610459479573
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... ....R^..+..7.3.hm..0...+....,..........................P.O. .:i.....+00.../C:\.....................1......R:#..PROGRA~2.........sN.&.R:#....^...............V......&..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....Z.1......RB#..HD1(GPS)..B.......R:#.RB#.....j.....................n..H.D.1.(.G.P.S.).....r.2...,..R.K .HD1(GP~1.EXE..V......R.K.R=#.....k........................H.D.1.(.G.P.S.). .v.2...2.4...e.x.e.......a...............-.......`..............$.....C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).\.H.D.1.(.G.P.S.). .v.2...2.4...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.1.(.G.P.S.).........*................@Z|...K.J.........`.......X.......899552..........N...n..O...}R...p..Km.......).].N...n..O...}R...p..Km.......).].............1SPS.XF.L8C....&.m.m................S.-.1.-.5.-.2.1.-.2.6.6.0.4.9.6.7.3.7.-.5.3.0.7.7.2.4.8
C:\Users\alfredo\Desktop\tempqfeo.dat
Process:C:\Program Files (x86)\HD1(GPS)\HD1(GPS) v2.24.exe
File Type:data
Category:dropped
Size (bytes):765697
Entropy (8bit):0.6916559918233969
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: SLQFEO...............................................................................................................................................................%S..%S......H.........@.........................................................................................................................................................%.A.%.A.....I.........a.............................%.F.%.F.................................%.@.%.@........p.p..0...................%XC.%XC........A%A%.0...................%.F.%.F........#.#..0..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\Actbar3.ocx
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):933960
Entropy (8bit):6.355065762804709
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........F..(..(..(..(..(...;..(..)...(...;..(...#..(.S.&..(.."...(..#...(......(./.,..(.Rich.(.................PE..L......C...........!...............................5.........................p......%........................................{....... ..X............*..H............................................................................................text............................... ..`.rdata..T...........................@..@.data....~.......V..................@....rsrc...X.... ......................@..@.reloc..@............t..............@..B................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\COMDLG32.OCX
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):163480
Entropy (8bit):5.796385844990045
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.T...........#.....(... ......W........@....z!.........................p......."....@..........................5.......'..........L............d.......P.......................................................................................text....&.......0.......... H...._. ..`.data....2...@...0...@..............@....rsrc...L............p..............@....reloc..r....P... ...@..............@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\Command.ocx
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):147456
Entropy (8bit):5.536016637218308
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........AN. .. .. ..<... ...).. ...-.. .~.$.. .Rich. .................PE..L...c.GA...........!.........................................................`......................................P...........(........-...................@..P...........................................`... .......d............................text............................... ..`.data...4$..........................@....rsrc....-.......0..................@..@.reloc.......@... ... ..............@..B..:@............MSVBVM60.DLL............................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\MSCOMCTL.OCX
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):1070232
Entropy (8bit):6.301401815183038
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....;V...........#..............................X'.........................@......)g....@.........................0........z....... ..(g...........:...............................................................................................text...................... .....z. ..`.data....~.......p..................@....rsrc...(g... ...p..................@....reloc.............................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\msbind.dll
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):85648
Entropy (8bit):5.751764686105291
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....R...........#.........R......B8.............$.........................0...... .....@.............................................P*...........4....... ..H.......................................................8............................text...................... .....n. ..`.rdata..c...........................@..@.data...H...........................@....idata..............................@....rsrc...P*.......0..................@....reloc....... ....... ..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\mscomm32.ocx
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):119960
Entropy (8bit):5.894311725943536
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....R...........#................Cw.............!......................................@.......................................... ...l......................|....................................................................................text...S................... .....G. ..`.data...&...........................@....rsrc....l... ...p... ..............@....reloc........... ..................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\msflxgrd.ocx
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):259736
Entropy (8bit):5.892051514062089
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......R...........#......................... ..... .................................Z....@.........................p.......x........`...@...........................................................................................................text...3................... ......% ..`.data....6... ...0... ..............@....rsrc....@...`...P...P..............@....reloc..h".......0..................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\mshflxgd.ocx
Process:C:\Users\alfredo\Desktop\HD1(GPS) v2.24.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):444840
Entropy (8bit):6.35089801730904
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....).U...........#......................................................................@..........................y............... ..........................F..................................................`................................text....................... .....lN ..`.rdata...j.......l..................@..@.data....z.......V...d..............@....idata..T...........................@....rsrc....... ......................@....reloc..>I.......J...d..............@..B................................................................................................................................................................................................................................................................................................................................................................................................

Static File Info

General

File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.986913455063313
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.40%
  • InstallShield setup (43055/19) 0.43%
  • Windows Screen Saver (13104/52) 0.13%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
File name:HD1(GPS) v2.24.exe
File size:3592691
MD5:1148fd1e4b2c4237bf152a9ceb94a62f
SHA1:41463fd921d1f07033560338e533f91f8747ed6e
SHA256:3cd2b40b277c073b3d29387d9fcbe8b09cca7a47b3213c5f212ce847ec23c64f
SHA512:31a801a8e4ef5b52d37f8e1f3b435efae2b19c98b1c274134d592d42eb50df8b40615668d931fedbc5af2680f5e4591a5da485aaec8030b3739329c26ca7a5b6
SSDEEP:98304:pwYe48gRVGISZWZWka30ia81fR2ARmGf7YIw1f:p+V93WZ/SYATLw1f
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........P...1...1...1...-...1..*....1..A-...1..*....1.......1.......1...1...1.......1...1..91..=....1...7...1..Rich.1.................

File Icon

Icon Hash:c8d49ccde690ae46

Static PE Info

General

Entrypoint:0x4253ca
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
DLL Characteristics:
Time Stamp:0x40813A96 [Sat Apr 17 14:09:26 2004 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:76d5c02c1b61ff55cf8d344cde5d8b26

Entrypoint Preview

Instruction
push ebp
mov ebp, esp
push FFFFFFFFh
push 00428828h
push 00424EE0h
mov eax, dword ptr fs:[00000000h]
push eax
mov dword ptr fs:[00000000h], esp
sub esp, 58h
push ebx
push esi
push edi
mov dword ptr [ebp-18h], esp
call dword ptr [0042812Ch]
xor edx, edx
mov dl, ah
mov dword ptr [0047F344h], edx
mov ecx, eax
and ecx, 000000FFh
mov dword ptr [0047F340h], ecx
shl ecx, 08h
add ecx, edx
mov dword ptr [0047F33Ch], ecx
shr eax, 10h
mov dword ptr [0047F338h], eax
xor esi, esi
push esi
call 00007F9160C834F5h
pop ecx
test eax, eax
jne 00007F9160C8341Ah
push 0000001Ch
call 00007F9160C834C5h
pop ecx
mov dword ptr [ebp-04h], esi
call 00007F9160C84848h
call dword ptr [00428108h]
mov dword ptr [0047F840h], eax
call 00007F9160C84706h
mov dword ptr [0047F378h], eax
call 00007F9160C844AFh
call 00007F9160C843F1h
call 00007F9160C82BC3h
mov dword ptr [ebp-30h], esi
lea eax, dword ptr [ebp-5Ch]
push eax
call dword ptr [0042818Ch]
call 00007F9160C84382h
mov dword ptr [ebp-64h], eax
test byte ptr [ebp-30h], 00000001h
je 00007F9160C83418h
movzx eax, word ptr [ebp-2Ch]
jmp 00007F9160C83415h
push 0000000Ah
pop eax
push eax
push dword ptr [ebp-64h]
push esi
push esi
call dword ptr [0042822Ch]

Rich Headers

Programming Language:
  • [ C ] VS98 (6.0) build 8168
  • [EXP] VC++ 6.0 SP5 build 8804
  • [C++] VS98 (6.0) build 8168

Data Directories

NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x28b880xf0.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x800000xfb0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x280000x418.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

Sections

NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x26ae00x26c00False0.58205015121data6.59632180574IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
.rdata0x280000x22080x2400False0.415907118056zlib compressed data5.57765758968IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x2b0000x548580x3200False0.465703125data5.50529776871IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
.rsrc0x800000xfb00x1000False0.37744140625data4.30991765431IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

Resources

NameRVASizeTypeLanguageCountry
RT_CURSOR0x80e600x134dataFinnishFinland
RT_BITMAP0x80c880x1d4dataFinnishFinland
RT_ICON0x806d00x2e8dataFinnishFinland
RT_DIALOG0x802a00xf0dataFinnishFinland
RT_DIALOG0x804380x1e0dataFinnishFinland
RT_DIALOG0x803900xa6dataFinnishFinland
RT_DIALOG0x806180xb6dataFinnishFinland
RT_GROUP_CURSOR0x80f980x14Lotus unknown worksheet or configuration, revision 0x1FinnishFinland
RT_GROUP_ICON0x809b80x14dataFinnishFinland
RT_MANIFEST0x809d00x2b8XML 1.0 document, ASCII text, with CRLF line terminatorsFinnishFinland

Imports

DLLImport
KERNEL32.dllWaitForSingleObject, GetModuleFileNameA, GetDateFormatA, GetSystemDirectoryA, GetWindowsDirectoryA, GetCommandLineA, GetVersionExA, CreateMutexA, GetPrivateProfileIntA, GetPrivateProfileStringA, lstrcmpA, GetSystemTime, LocalFree, LocalAlloc, GetVersion, GetSystemInfo, GetComputerNameA, SetEndOfFile, LCMapStringA, GetStringTypeW, GetStringTypeA, GetOEMCP, lstrcpynA, GetCPInfo, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapSize, HeapReAlloc, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetStartupInfoA, RtlUnwind, TerminateProcess, HeapAlloc, HeapFree, GetExitCodeProcess, SetFileTime, GlobalMemoryStatus, GetShortPathNameA, SetErrorMode, WritePrivateProfileStringA, WritePrivateProfileSectionA, MoveFileExA, GetCurrentProcess, ExitProcess, WideCharToMultiByte, CreateProcessA, RemoveDirectoryA, GetFileTime, VerLanguageNameA, CompareFileTime, CopyFileA, GetFileSize, GetLogicalDriveStringsA, FreeLibrary, GetCurrentDirectoryA, SetCurrentDirectoryA, MultiByteToWideChar, SetFileAttributesA, LCMapStringW, GetTempPathA, GetFileAttributesA, CreateDirectoryA, GetLocaleInfoA, FindFirstFileA, lstrcmpiA, FindNextFileA, FindClose, GetDriveTypeA, lstrcatA, GetModuleHandleA, LoadLibraryA, GetProcAddress, GetTickCount, Sleep, GetCurrentThread, QueryPerformanceFrequency, QueryPerformanceCounter, GetThreadPriority, SetThreadPriority, GlobalReAlloc, GlobalUnlock, GlobalFree, GlobalAlloc, GlobalLock, MulDiv, lstrlenA, GetLastError, FormatMessageA, WriteFile, ReadFile, lstrcpyA, SetFilePointer, CreateFileA, CloseHandle, GetACP, DeleteFileA
USER32.dllFindWindowA, IsIconic, PostMessageA, RegisterClassA, SetRectEmpty, ExitWindowsEx, MsgWaitForMultipleObjects, GetMessageA, TranslateMessage, DispatchMessageA, FillRect, PostQuitMessage, EnableWindow, SetWindowPos, SetTimer, GetDlgItemTextA, CreateDialogParamA, GetWindowLongA, IsWindowEnabled, GetSystemMetrics, RegisterClassExA, GetClientRect, IsWindowVisible, PtInRect, SetCursor, EndDialog, GetActiveWindow, WaitMessage, IsDialogMessageA, MessageBoxA, CopyRect, KillTimer, DrawEdge, GetDlgItem, SendDlgItemMessageA, SetDlgItemTextA, PeekMessageA, SetWindowTextA, ReleaseDC, EnumDisplaySettingsA, LoadBitmapA, GetDC, DestroyWindow, DefWindowProcA, GetWindowRect, InvalidateRect, LoadIconA, LoadImageA, GetSysColor, GetDesktopWindow, SystemParametersInfoA, SetForegroundWindow, DialogBoxParamA, GetWindowTextLengthA, GetWindowTextA, CreateWindowExA, SetWindowLongA, SetFocus, GetSystemMenu, DeleteMenu, AppendMenuA, ShowWindow, LoadCursorA, GetCursorPos, ScreenToClient, SendMessageA
GDI32.dllSaveDC, SetMapMode, SetViewportOrgEx, RestoreDC, StartDocA, StartPage, EndPage, TextOutA, SetBkMode, SelectObject, CreateFontA, GetDeviceCaps, BitBlt, DeleteDC, DeleteObject, CreateSolidBrush, GetStockObject, SetBkColor, SetTextColor, CreateCompatibleBitmap, CreateCompatibleDC, StretchDIBits, GetTextExtentPoint32A, CreateBitmap, CreateDIBitmap, CreatePalette, AddFontResourceA, CreateScalableFontResourceA, EndDoc, RemoveFontResourceA
comdlg32.dllGetOpenFileNameA, PrintDlgA
ADVAPI32.dllRegCloseKey, RegOpenKeyExA, AdjustTokenPrivileges, LookupPrivilegeValueA, RegDeleteValueA, RegQueryInfoKeyA, RegEnumKeyExA, OpenThreadToken, DuplicateToken, AllocateAndInitializeSid, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, IsValidSecurityDescriptor, AccessCheck, FreeSid, GetUserNameA, RegSetValueExA, RegCreateKeyExA, OpenProcessToken, RegQueryValueExA
SHELL32.dllSHFileOperationA, SHBrowseForFolderA, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc, ShellExecuteA, SHChangeNotify
ole32.dllCoUninitialize, CoInitialize, OleInitialize, CoCreateInstance, OleUninitialize
OLEAUT32.dllRegisterTypeLib, LoadTypeLib
WINMM.dllwaveOutGetNumDevs, midiOutGetNumDevs, joyGetPos
COMCTL32.dllImageList_Create, ImageList_Add
VERSION.dllGetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

Possible Origin

Language of compilation systemCountry where language is spokenMap
FinnishFinland