Loading ...

Play interactive tourEdit tour

Windows Analysis Report Firmware Update - HD-HD1A-V1.7.2_GPS.exe

Overview

General Information

Sample Name:Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Analysis ID:86
MD5:654dbe89655b5c9defa4e02ef17f5bd7
SHA1:ab77cc7aa63e90884a531173e89413110a3ebfe3
SHA256:853f3f4b030b482657da5f72ba243087ca0d2064986ba1ae6fff0cfdcd512389
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Contains capabilities to detect virtual machines
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Tries to load missing DLLs
Uses 32bit PE files

Classification

Process Tree

  • System is start
  • Firmware Update - HD-HD1A-V1.7.2_GPS.exe (PID: 7188 cmdline: 'C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe' MD5: 654DBE89655B5C9DEFA4E02EF17F5BD7)
    • Firmware Update - HD-HD1A-V1.7.2_GPS.exe (PID: 7908 cmdline: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe MD5: 95006D123804D900990096CFB1381931)
  • Firmware Update - HD-HD1A-V1.7.2_GPS.exe (PID: 7724 cmdline: 'C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe' MD5: 95006D123804D900990096CFB1381931)
  • Firmware Update - HD-HD1A-V1.7.2_GPS.exe (PID: 7692 cmdline: 'C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe' MD5: 95006D123804D900990096CFB1381931)
  • cleanup

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus detection for dropped fileShow sources
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeAvira: detection malicious, Label: TR/Dropper.Gen
Source: Firmware Update - HD-HD1A-V1.7.2_GPS.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\4145796.tmp
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscomenu.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscomen.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscoenu.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: vb6chs.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscomenu.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscomen.dll
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: mscoenu.dll
Source: Firmware Update - HD-HD1A-V1.7.2_GPS.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: classification engineClassification label: mal48.winEXE@5/18@0/0
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD-HD1A-V1.7.2_GPS
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeMutant created: \Sessions\1\BaseNamedObjects\HD-HD1A-V1.7.2_GPSmutex
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Users\alfredo\AppData\Local\Temp\aiw4138250.bmp
Source: Firmware Update - HD-HD1A-V1.7.2_GPS.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile read: C:\Users\desktop.ini
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile read: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Source: unknownProcess created: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe 'C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe'
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Source: unknownProcess created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Source: unknownProcess created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeKey value created or modified: HKEY_CURRENT_USER\Control Panel\Mouse MouseHoverTime
Source: Firmware Update - HD-HD1A-V1.7.2_GPS.exeStatic file information: File size 2774325 > 1048576
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSDBRPTR.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\comdlg32.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Uninstall.exeJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSRDO20.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSSTDFMT.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Users\alfredo\AppData\Local\Temp\aiw4139984.EXEJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\mscomctl.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSDBRPTR.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\comdlg32.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSRDO20.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\MSSTDFMT.DLLJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Windows\SysWOW64\mscomctl.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile created: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD-HD1A-V1.7.2_GPS
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeDropped PE file which has not been started: C:\Windows\SysWOW64\comdlg32.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeDropped PE file which has not been started: C:\Users\alfredo\AppData\Local\Temp\aiw4139984.EXEJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mscomctl.ocxJump to dropped file
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft\Windows
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeFile opened: C:\Users\alfredo\AppData\Roaming\Microsoft
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exeQueries volume information: C:\ VolumeInformation

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationDLL Side-Loading1Process Injection1Masquerading22OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobRegistry Run Keys / Startup Folder1DLL Side-Loading1Virtualization/Sandbox Evasion1LSASS MemoryVirtualization/Sandbox Evasion1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Registry Run Keys / Startup Folder1Process Injection1Security Account ManagerFile and Directory Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)DLL Side-Loading1NTDSSystem Information Discovery12Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

No Antivirus matches

Dropped Files

SourceDetectionScannerLabelLink
C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe100%AviraTR/Dropper.Gen

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

No contacted IP infos

General Information

Joe Sandbox Version:32.0.0 Black Diamond
Analysis ID:86
Start date:29.06.2021
Start time:21:39:37
Joe Sandbox Product:CloudBasic
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Number of analysed new started processes analysed:11
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Detection:MAL
Classification:mal48.winEXE@5/18@0/0
Warnings:
Show All
  • Exclude process from analysis (whitelisted): svchost.exe
  • Report size getting too big, too many NtCreateKey calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtSetValueKey calls found.

Created / dropped Files

C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):454656
Entropy (8bit):7.334997258346603
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:true
Antivirus:
  • Antivirus: Avira, Detection: 100%
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g.y.#...#...#......."...J...'......."...Rich#...................PE..L......_.....................@....................@.........................................................................4...(........$..................................................................0... ....................................text.............................. ..`.data...D...........................@....rsrc....$.......0..................@..@l.[J............MSVBVM60.DLL............................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Uninstall.exe
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:modified
Size (bytes):346654
Entropy (8bit):7.889148607317336
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........+j..E9..E9..E9..I9..E9..N9..E9{.K9..E9..O9..E9..E9..E9..V9..E9..V9..E9..D9`.E9..N9..E9?.C9..E9Rich..E9........PE..L.....H@.....................4.......i............@......................................................................... ...........X............................................................................................................text............................... ..`.rdata..............................@..@.data...|...........................@....rsrc...X...........................@..@................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw4138250.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 636 x 61 x 24
Category:dropped
Size (bytes):116442
Entropy (8bit):4.729001881244087
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(...|...=.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw4138484.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):6.206632501179402
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X...............................^..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..\..\..\..\..\..\..\..\..\..\..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B....\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..\..\..\..\..\..\..\..\..\..\..\..\..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B..B.
C:\Users\alfredo\AppData\Local\Temp\aiw4138765.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):3.147025307853983
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=...e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e
C:\Users\alfredo\AppData\Local\Temp\aiw4139046.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):4.394500643269032
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8...`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.Pp.Pp.Pp.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`8.`
C:\Users\alfredo\AppData\Local\Temp\aiw4139328.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):3.6147958656153993
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X................................e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=...e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.Tv.Tv.Tv.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e=.e
C:\Users\alfredo\AppData\Local\Temp\aiw4139562.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:MS Windows icon resource - 1 icon, 32x32, 2 colors
Category:dropped
Size (bytes):326
Entropy (8bit):1.6176853708804466
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: ...... ......0.......(... ...@......................................................................................................................................................................................................................................?................................................................
C:\Users\alfredo\AppData\Local\Temp\aiw4139703.bmp
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PC bitmap, Windows 3.x format, 162 x 344 x 24
Category:dropped
Size (bytes):167926
Entropy (8bit):6.018738622681652
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: BM........6...(.......X........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z/.Z/.V>.UA.Ii.Gn.M\.Z1.Z..Y0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Y/.Y0.RG.Fp.Hk.OS.[+.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z0.Z
C:\Users\alfredo\AppData\Local\Temp\aiw4139984.EXE
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):48128
Entropy (8bit):6.3377933069406085
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........+j..E9..E9..E9..I9..E9..N9..E9{.K9..E9..O9..E9..E9..E9..V9..E9..V9..E9..D9`.E9..N9..E9?.C9..E9Rich..E9........PE..L.....H@.....................4.......i............@......................................................................... ...........X............................................................................................................text............................... ..`.rdata..............................@..@.data...|...........................@....rsrc...X...........................@..@................................................................................................................................................................................................................................................................................................................................................................
C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.lnk
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Dec 17 07:03:09 2020, mtime=Mon May 31 03:40:15 2021, atime=Thu Dec 17 07:03:10 2020, length=454656, window=hide
Category:dropped
Size (bytes):1326
Entropy (8bit):4.633540847225508
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... .......K....ag.jm..`..K................................P.O. .:i.....+00.../C:\.....................1......R.%..PROGRA~2.........sN.&.R.%....^...............V.....4.k.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....r.1......R.%..HD-HD1~1.2_G..V.......R.%.R.%....<j....................L4z.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.......2......Qf@ .FIRMWA~1.EXE.........Qe@.R.%....jj........................F.i.r.m.w.a.r.e. .U.p.d.a.t.e. .-. .H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S...e.x.e.......................-............................C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe..j.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.\.F.i.r.m.w.a.r.e. .U.p.d.a.t.e. .-. .H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S...e.x.e.).C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.........*...............
C:\Users\alfredo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD-HD1A-V1.7.2_GPS\Uninstall HD-HD1A-V1.7.2_GPS.lnk
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon May 31 03:40:15 2021, mtime=Mon May 31 03:40:15 2021, atime=Mon May 31 03:40:15 2021, length=0, window=hide
Category:dropped
Size (bytes):1191
Entropy (8bit):4.588838213435859
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... ....C4.jm...C4.jm...C4.jm...............................P.O. .:i.....+00.../C:\.....................1......R.%..PROGRA~2.........sN.&.R.%....^...............V.....4.k.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....r.1......R.%..HD-HD1~1.2_G..V.......R.%.R.%....<j....................L4z.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.....h.2......R.% .UNINST~1.EXE..L.......R.%.R.%.....j....................L4z.U.n.i.n.s.t.a.l.l...e.x.e.......f...............-.......e....................C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Uninstall.exe..O.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.\.U.n.i.n.s.t.a.l.l...e.x.e.).C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.........*................@Z|...K.J.........`.......X.......835180..........N...n..O...}R.....Km.......).].N...n..O...}R.....Km.......).].............1SPS.X
C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.lnk
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Dec 17 07:03:09 2020, mtime=Mon May 31 03:40:11 2021, atime=Thu Dec 17 07:03:10 2020, length=454656, window=hide
Category:dropped
Size (bytes):1290
Entropy (8bit):4.667919376770167
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: L..................F.... .......K.......jm..`..K................................P.O. .:i.....+00.../C:\.....................1......R.%..PROGRA~2.........sN.&.R.%....^...............V.....4.k.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....r.1......R.%..HD-HD1~1.2_G..V.......R.%.R.%....<j....................L4z.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.......2......Qf@ .FIRMWA~1.EXE.........Qe@.R.%....jj........................F.i.r.m.w.a.r.e. .U.p.d.a.t.e. .-. .H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S...e.x.e.......................-............................C:\Program Files (x86)\HD-HD1A-V1.7.2_GPS\Firmware Update - HD-HD1A-V1.7.2_GPS.exe..X.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.\.F.i.r.m.w.a.r.e. .U.p.d.a.t.e. .-. .H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S...e.x.e.).C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.D.-.H.D.1.A.-.V.1...7...2._.G.P.S.........*................@Z|...K.J.........`.......X.......
C:\Windows\SysWOW64\MSDBRPTR.DLL
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):322560
Entropy (8bit):6.022042357945053
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:@...........#................[.............*'................................Y............................... ........P.......p...#......................P2...................................................T...............................text...................... .....|@ ..`.rdata...3.......@..................@..@.data...P?.......@..................@....idata..|....P... ...P..............@....rsrc....#...p...0...p..............@....reloc..l3.......@..................@..B................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\MSRDO20.DLL
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):397824
Entropy (8bit):5.945413428477709
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....:@...........#..............................g#.................................>...............................\..........................................\,...k...............................................................................text...2........................... ..`.rdata...K... ...P... ..............@..@.data....Z...p...`...p..............@....idata..............................@....rsrc...............................@....reloc..\,.......0..................@..B................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\MSSTDFMT.DLL
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):119808
Entropy (8bit):5.950998905309213
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....:@...........#........................0.....$................................................................pF.......`.......p...1...........................0...............................................b..p............................text...2........ .......... .....=. ..`.rdata.......0... ...0..............@..@.data...F....P.......P..............@....idata.......`.......`..............@....rsrc....1...p...@...p..............@....reloc..D........ ..................@..B................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\comdlg32.ocx
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):163480
Entropy (8bit):5.796385844990045
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.T...........#.....(... ......W........@....z!.........................p......."....@..........................5.......'..........L............d.......P.......................................................................................text....&.......0.......... H...._. ..`.data....2...@...0...@..............@....rsrc...L............p..............@....reloc..r....P... ...@..............@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
C:\Windows\SysWOW64\mscomctl.ocx
Process:C:\Users\alfredo\Desktop\Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):1070232
Entropy (8bit):6.301401815183038
Encrypted:false
SSDEEP:
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false
Reputation:low
Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....;V...........#..............................X'.........................@......)g....@.........................0........z....... ..(g...........:...............................................................................................text...................... .....z. ..`.data....~.......p..................@....rsrc...(g... ...p..................@....reloc.............................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................

Static File Info

General

File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.980160847169625
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.40%
  • InstallShield setup (43055/19) 0.43%
  • Windows Screen Saver (13104/52) 0.13%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
File name:Firmware Update - HD-HD1A-V1.7.2_GPS.exe
File size:2774325
MD5:654dbe89655b5c9defa4e02ef17f5bd7
SHA1:ab77cc7aa63e90884a531173e89413110a3ebfe3
SHA256:853f3f4b030b482657da5f72ba243087ca0d2064986ba1ae6fff0cfdcd512389
SHA512:709ef8dec7810995702f4f0b451dedaba97ad23aac1638074058c7466230520cfa5e790f5aa2d70e48b7c40093433b173189f290a3830af465d885fe4518a564
SSDEEP:49152:pjGmekmoOSbE33Mpia9m1tJRAaKG3v4y7YIwjDKPa+9E94oNs:pdekESb+30ia81fRPKFy7YIwXQ
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........P...1...1...1...-...1..*....1..A-...1..*....1.......1.......1...1...1.......1...1..91..=....1...7...1..Rich.1.................

File Icon

Icon Hash:c8d49ccde690ae46

Static PE Info

General

Entrypoint:0x4253ca
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
DLL Characteristics:
Time Stamp:0x40813A96 [Sat Apr 17 14:09:26 2004 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:76d5c02c1b61ff55cf8d344cde5d8b26

Entrypoint Preview

Instruction
push ebp
mov ebp, esp
push FFFFFFFFh
push 00428828h
push 00424EE0h
mov eax, dword ptr fs:[00000000h]
push eax
mov dword ptr fs:[00000000h], esp
sub esp, 58h
push ebx
push esi
push edi
mov dword ptr [ebp-18h], esp
call dword ptr [0042812Ch]
xor edx, edx
mov dl, ah
mov dword ptr [0047F344h], edx
mov ecx, eax
and ecx, 000000FFh
mov dword ptr [0047F340h], ecx
shl ecx, 08h
add ecx, edx
mov dword ptr [0047F33Ch], ecx
shr eax, 10h
mov dword ptr [0047F338h], eax
xor esi, esi
push esi
call 00007F967C542EC5h
pop ecx
test eax, eax
jne 00007F967C542DEAh
push 0000001Ch
call 00007F967C542E95h
pop ecx
mov dword ptr [ebp-04h], esi
call 00007F967C544218h
call dword ptr [00428108h]
mov dword ptr [0047F840h], eax
call 00007F967C5440D6h
mov dword ptr [0047F378h], eax
call 00007F967C543E7Fh
call 00007F967C543DC1h
call 00007F967C542593h
mov dword ptr [ebp-30h], esi
lea eax, dword ptr [ebp-5Ch]
push eax
call dword ptr [0042818Ch]
call 00007F967C543D52h
mov dword ptr [ebp-64h], eax
test byte ptr [ebp-30h], 00000001h
je 00007F967C542DE8h
movzx eax, word ptr [ebp-2Ch]
jmp 00007F967C542DE5h
push 0000000Ah
pop eax
push eax
push dword ptr [ebp-64h]
push esi
push esi
call dword ptr [0042822Ch]

Rich Headers

Programming Language:
  • [ C ] VS98 (6.0) build 8168
  • [EXP] VC++ 6.0 SP5 build 8804
  • [C++] VS98 (6.0) build 8168

Data Directories

NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x28b880xf0.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x800000xfb0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x280000x418.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

Sections

NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x26ae00x26c00False0.58205015121data6.59632180574IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
.rdata0x280000x22080x2400False0.415907118056zlib compressed data5.57765758968IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x2b0000x548580x3200False0.465703125data5.50529776871IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
.rsrc0x800000xfb00x1000False0.37744140625data4.30991765431IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

Resources

NameRVASizeTypeLanguageCountry
RT_CURSOR0x80e600x134dataFinnishFinland
RT_BITMAP0x80c880x1d4dataFinnishFinland
RT_ICON0x806d00x2e8dataFinnishFinland
RT_DIALOG0x802a00xf0dataFinnishFinland
RT_DIALOG0x804380x1e0dataFinnishFinland
RT_DIALOG0x803900xa6dataFinnishFinland
RT_DIALOG0x806180xb6dataFinnishFinland
RT_GROUP_CURSOR0x80f980x14Lotus unknown worksheet or configuration, revision 0x1FinnishFinland
RT_GROUP_ICON0x809b80x14dataFinnishFinland
RT_MANIFEST0x809d00x2b8XML 1.0 document, ASCII text, with CRLF line terminatorsFinnishFinland

Imports

DLLImport
KERNEL32.dllWaitForSingleObject, GetModuleFileNameA, GetDateFormatA, GetSystemDirectoryA, GetWindowsDirectoryA, GetCommandLineA, GetVersionExA, CreateMutexA, GetPrivateProfileIntA, GetPrivateProfileStringA, lstrcmpA, GetSystemTime, LocalFree, LocalAlloc, GetVersion, GetSystemInfo, GetComputerNameA, SetEndOfFile, LCMapStringA, GetStringTypeW, GetStringTypeA, GetOEMCP, lstrcpynA, GetCPInfo, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapSize, HeapReAlloc, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetStartupInfoA, RtlUnwind, TerminateProcess, HeapAlloc, HeapFree, GetExitCodeProcess, SetFileTime, GlobalMemoryStatus, GetShortPathNameA, SetErrorMode, WritePrivateProfileStringA, WritePrivateProfileSectionA, MoveFileExA, GetCurrentProcess, ExitProcess, WideCharToMultiByte, CreateProcessA, RemoveDirectoryA, GetFileTime, VerLanguageNameA, CompareFileTime, CopyFileA, GetFileSize, GetLogicalDriveStringsA, FreeLibrary, GetCurrentDirectoryA, SetCurrentDirectoryA, MultiByteToWideChar, SetFileAttributesA, LCMapStringW, GetTempPathA, GetFileAttributesA, CreateDirectoryA, GetLocaleInfoA, FindFirstFileA, lstrcmpiA, FindNextFileA, FindClose, GetDriveTypeA, lstrcatA, GetModuleHandleA, LoadLibraryA, GetProcAddress, GetTickCount, Sleep, GetCurrentThread, QueryPerformanceFrequency, QueryPerformanceCounter, GetThreadPriority, SetThreadPriority, GlobalReAlloc, GlobalUnlock, GlobalFree, GlobalAlloc, GlobalLock, MulDiv, lstrlenA, GetLastError, FormatMessageA, WriteFile, ReadFile, lstrcpyA, SetFilePointer, CreateFileA, CloseHandle, GetACP, DeleteFileA
USER32.dllFindWindowA, IsIconic, PostMessageA, RegisterClassA, SetRectEmpty, ExitWindowsEx, MsgWaitForMultipleObjects, GetMessageA, TranslateMessage, DispatchMessageA, FillRect, PostQuitMessage, EnableWindow, SetWindowPos, SetTimer, GetDlgItemTextA, CreateDialogParamA, GetWindowLongA, IsWindowEnabled, GetSystemMetrics, RegisterClassExA, GetClientRect, IsWindowVisible, PtInRect, SetCursor, EndDialog, GetActiveWindow, WaitMessage, IsDialogMessageA, MessageBoxA, CopyRect, KillTimer, DrawEdge, GetDlgItem, SendDlgItemMessageA, SetDlgItemTextA, PeekMessageA, SetWindowTextA, ReleaseDC, EnumDisplaySettingsA, LoadBitmapA, GetDC, DestroyWindow, DefWindowProcA, GetWindowRect, InvalidateRect, LoadIconA, LoadImageA, GetSysColor, GetDesktopWindow, SystemParametersInfoA, SetForegroundWindow, DialogBoxParamA, GetWindowTextLengthA, GetWindowTextA, CreateWindowExA, SetWindowLongA, SetFocus, GetSystemMenu, DeleteMenu, AppendMenuA, ShowWindow, LoadCursorA, GetCursorPos, ScreenToClient, SendMessageA
GDI32.dllSaveDC, SetMapMode, SetViewportOrgEx, RestoreDC, StartDocA, StartPage, EndPage, TextOutA, SetBkMode, SelectObject, CreateFontA, GetDeviceCaps, BitBlt, DeleteDC, DeleteObject, CreateSolidBrush, GetStockObject, SetBkColor, SetTextColor, CreateCompatibleBitmap, CreateCompatibleDC, StretchDIBits, GetTextExtentPoint32A, CreateBitmap, CreateDIBitmap, CreatePalette, AddFontResourceA, CreateScalableFontResourceA, EndDoc, RemoveFontResourceA
comdlg32.dllGetOpenFileNameA, PrintDlgA
ADVAPI32.dllRegCloseKey, RegOpenKeyExA, AdjustTokenPrivileges, LookupPrivilegeValueA, RegDeleteValueA, RegQueryInfoKeyA, RegEnumKeyExA, OpenThreadToken, DuplicateToken, AllocateAndInitializeSid, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, IsValidSecurityDescriptor, AccessCheck, FreeSid, GetUserNameA, RegSetValueExA, RegCreateKeyExA, OpenProcessToken, RegQueryValueExA
SHELL32.dllSHFileOperationA, SHBrowseForFolderA, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc, ShellExecuteA, SHChangeNotify
ole32.dllCoUninitialize, CoInitialize, OleInitialize, CoCreateInstance, OleUninitialize
OLEAUT32.dllRegisterTypeLib, LoadTypeLib
WINMM.dllwaveOutGetNumDevs, midiOutGetNumDevs, joyGetPos
COMCTL32.dllImageList_Create, ImageList_Add
VERSION.dllGetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

Possible Origin

Language of compilation systemCountry where language is spokenMap
FinnishFinland