| File name: | ex4 to mq4 4.0.509.5 freeware.exe |
| Full analysis: | https://app.any.run/tasks/deb393ec-650f-4bc5-bc7e-9efcec75d1ed |
| Verdict: | No threats detected |
| Analysis date: | November 18, 2019, 03:33:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows |
| MD5: | 2150174270DC03C749E00F2D2A01A5A2 |
| SHA1: | D7A0140E3BE850E5FD598ABF0BF912AE4E935558 |
| SHA256: | 94655B38370CFB4CF794861BEF9A62B8C229D1D8CB0733401ACAD332747B40E0 |
| SSDEEP: | 49152:U2jDSuSLuJZDtwWPaQq055MuNckCTxiErXTTtAFNsh:U76wWPNCFi1F |
| .scr | | | Windows screen saver (60.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (20.8) |
| .exe | | | Generic Win/DOS Executable (9.2) |
| .exe | | | DOS Executable Generic (9.2) |
| .vxd | | | VXD Driver (0.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:03:11 22:12:55+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 5 |
| CodeSize: | 3215360 |
| InitializedDataSize: | 2764800 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x62cdeb |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.0.509.5 |
| ProductVersionNumber: | 4.0.509.5 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | MetaQuotes Software Corp |
| FileDescription: | EX4-TO-MQ4 Decompiler Free |
| FileVersion: | 4.0.509.5 |
| LegalCopyright: | Copyright (C) 2007-2014 MetaQuotes Software Corp |
| OriginalFileName: | ex4_to_mq4_freeware.exe |
| ProductName: | EX4-TO-MQ4 Decompiler Free |
| ProductVersion: | 4.0.509.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2584 | "C:\Users\admin\AppData\Local\Temp\ex4 to mq4 4.0.509.5 freeware.exe" | C:\Users\admin\AppData\Local\Temp\ex4 to mq4 4.0.509.5 freeware.exe | — | explorer.exe | |||||||||||
User: admin Company: MetaQuotes Software Corp Integrity Level: MEDIUM Description: EX4-TO-MQ4 Decompiler Free Exit code: 0 Version: 4.0.509.5 Modules
| |||||||||||||||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRULegacy |
| Operation: | write | Name: | MRUListEx |
Value: FFFFFFFF | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 02000000070000000100000009000000080000000000000006000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlgLegacy |
| Operation: | write | Name: | TV_FolderType |
Value: {FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9} | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlgLegacy |
| Operation: | write | Name: | TV_TopViewID |
Value: {82BA0782-5B7A-4569-B5D7-EC83085F08CC} | |||
| (PID) Process: | (2584) ex4 to mq4 4.0.509.5 freeware.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlgLegacy |
| Operation: | write | Name: | TV_TopViewVersion |
Value: 0 | |||