PUP.SmartFileAdvisor

Analysis Report

General information

Family Name: PUP.SmartFileAdvisor
Signature status: Hash Mismatch

Known Samples

MD5: 478c0d8225b35567bc2068a62096e966
SHA1: fb0dba6993438e793001f312f237139d9f75ecc6
SHA256: F24552B36A9927EC3617F0A14C9224E53C269DF2E96F717FBD35E5F1F6AF95E7
File Size: 8.23 MB, 8225848 bytes
MD5: 7b1fa6728d2098f4c7761836f695e00e
SHA1: d7fbad7d18d895ec0b062dd8b41be9b463810d21
SHA256: 08C609A174E5D0E90C7F53A669B5558D261C6C9677CB35BFAF7C9D844B7B87BB
File Size: 9.42 MB, 9417592 bytes
MD5: 5287d3af7b9c3833e5d87e14abadbed0
SHA1: 81f3720513579e3a0a4315f3422cbe20a7b45de6
SHA256: 1AC5D252C9DBEA110EBED81EAE99FE941A2C4503CB107490FA9D620A5BB5F17E
File Size: 8.02 MB, 8019112 bytes
MD5: 03a3a59e0475234fa872b64a13c53c55
SHA1: 83ee8eb6b687b81121e612c6aa3d95b41619fb92
SHA256: 6F04C6B26B615CC37005F5BBFF7C507BE1348A31DE3CBE5D0201AF1383F530AE
File Size: 9.43 MB, 9430456 bytes
MD5: fb1d6d106e79f6cc9e0d5358cf5f6437
SHA1: 43f4296430d8871d901857d58da44fd98214a787
SHA256: 6456F6F8EB6348CE9B1B84219D4CFCAF65271380B37CCBD7D975EB3CF90E9BC6
File Size: 8.60 MB, 8596624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Alcohol Soft Development Team
File Description
  • Alcohol 120% 2.0.3.8426 Setup
  • Alcohol 120% 2.0.3.10121 Setup
  • Alcohol Setup
File Version
  • 4.45.3.10121
  • 4.45.3.8426
  • 4.44.3.6890
  • 4.44.2.5830
Internal Name
  • Alcohol120_FE_2.0.2.5830.exe
  • Alcohol120_retail_2.0.3.6890.exe
  • Alcohol120_trial_2.0.2.5830.exe
Legal Copyright
  • Copyright(C) 2002-2013 Alcohol Soft Development Team
  • Copyright(C) 2002-2014 Alcohol Soft Development Team
  • Copyright(C) 2002-2016 Alcohol Soft Development Team
  • Copyright(C) 2002-2018 Alcohol Soft Development Team
Original Filename
  • Alcohol120_FE_2.0.2.5830.exe
  • Alcohol120_retail_2.0.3.6890.exe
  • Alcohol120_trial_2.0.2.5830.exe
Product Name Alcohol 120%
Product Version
  • 4.45.3.10121
  • 4.45.3.8426
  • 4.44.3.6890
  • 4.44.2.5830

Digital Signatures

Signer Root Status
Alcohol Soft Symantec Class 3 SHA256 Code Signing CA Hash Mismatch
Alcohol Soft Symantec Class 3 SHA256 Code Signing CA Self Signed
Alcohol Soft VeriSign Class 3 Code Signing 2010 CA Self Signed

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsca832.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsgbe17.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbe17.tmp\setuphlp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsgbe17.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsi74d8.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsia98b.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsl8912.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsqbe06.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nssa843.tmp\langdll.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nssa843.tmp\setuphlp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa843.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nssa97a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsv8901.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsx74e8.tmp\langdll.dll Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • ReadProcessMemory

Trending

Most Viewed

Loading...