PUP.PowerTool.A

Analysis Report

General information

Family Name: PUP.PowerTool.A
Signature status: No Signature

Known Samples

MD5: 3ef7893c315b8ff1e38174bd3a75fb4e
SHA1: a8c7a1dc8d238d2fda0c55178115c7be3fe9a707
SHA256: D2C1C367A46D2ED5A4376BA4802F55526D1659CD4394FE27A494F7D390ED4E6F
File Size: 2.25 MB, 2254417 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments For additional details, visit PortableApps.com
Company Name ThinstallSoft.com
File Description PowerTool Portable
File Version 2.0.0.0
Internal Name PowerTool Portable
Legal Copyright ThinstallSoft.com Installer Copyright 2010-2011 ThinstallSoft.com.
Original Filename PowerToolPortable_2.0_English.paf.exe
P O R T A B L E A P P S. C O M F O R M A T Version 2.0
Portable Apps.com App I D PowerToolPortable
Portable Apps.com Installer Version 2.0.8.0
Product Name PowerTool Portable
Product Version 2.0.0.0

File Traits

  • imgui
  • WriteProcessMemory
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsi390e.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsy391f.tmp\findprocdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy391f.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy391f.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsy391f.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy391f.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy391f.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsy391f.tmp\system.dll Generic Write,Read Attributes

Trending

Most Viewed

Loading...