Recently, we collected the fileinfo information of the PE and found that not every PE exists, and not all of them exist. The summary of the sample basically includes the following information:
Legalcopyright: copyright information
Internalname: Internal name
Fileversion: file version
CompanyName: Company Name
Legaltrademarks: Registered Trademark
Comments: Comments
Productname: Product Name
Productversion: product version
Filedescription: file description
Originalfilename: original file name
Privatebuild: Private compilation (see sample 3)
Specialbuild: special compilation
Several special information:
Builddate: Compilation date (see sample 1)
Buildnumber: Compilation number (see sample 1)
Filetype: file type (this should have occurred in vs_fixedfileinfo, but it has appeared in fileinfo again, resulting in a conflict, whichever is in vs_fixedfileinfo) (see sample 1)
Oleselfregister: (See sample 2)
File analysis information list:
Sample 1: http://files.cnblogs.com/fengmk2/35d417aa12d58edfc4ed0156e8ee855f.Nap.txt
Sample 1: http://files.cnblogs.com/fengmk2/OLESelfRegister_QQ.exe.txt
Sample 3: http://files.cnblogs.com/fengmk2/PrivateBuild_8c26cc7d912ab9568b44a62291f7ac51.dll.txt
Technorati:PE, fileinfo