Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

f8afebc5e4c1593e64efcf788d8c65a3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00075000 0x00000000 0.0
UPX1 0x00076000 0x00035000 0x00034a00 7.99664586292
.rsrc 0x000ab000 0x00006000 0x00006000 4.67014376584

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00096290 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00097778 0x00000098 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x000abb5c 0x00004c28 LANG_BULGARIAN SUBLANG_DEFAULT dBase IV DBT, blocks size 0, block length 18432, next free block index 40, next free block 0, next used block 4278255616
RT_DIALOG 0x0009c438 0x00000052 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009e4cc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000a59a8 0x00000fd5 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000a59a8 0x00000fd5 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000a59a8 0x00000fd5 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000a59a8 0x00000fd5 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000a69f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000b0788 0x00000014 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_VERSION 0x000b07a0 0x000004d4 LANG_BULGARIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.DLL:
0x4b0d3c LoadLibraryA
0x4b0d40 GetProcAddress
0x4b0d44 VirtualProtect
0x4b0d48 VirtualAlloc
0x4b0d4c VirtualFree
0x4b0d50 ExitProcess
Library advapi32.dll:
0x4b0d58 RegFlushKey
Library comctl32.dll:
0x4b0d60 ImageList_Add
Library gdi32.dll:
0x4b0d68 SaveDC
Library NetApi32.dll:
0x4b0d70 NetUserEnum
Library oleaut32.dll:
0x4b0d78 VariantCopy
Library shell32.dll:
0x4b0d80 Shell_NotifyIconA
Library user32.dll:
0x4b0d88 GetDC
Library version.dll:
0x4b0d90 VerQueryValueA

This program must be run under Win32
r-%=&i
@7m|0[
Dcj/~>
ysD]F+
*x#57N
./>S4Cf7R
x'TC4p
S9{>/P
;)h:=?Ad
%IkBPK
~SW>7<l
I#%%[W
Ir[I/B
#|UVUf
+Jfgo[X
@%;oeW^
@q7&7:$Y
ETY/Xbtx
M&ET2&
n_g+A]
7&%w3/
=BR=as
~Ov_Rcz
J0x/Ou$
&b!lV_FSG
;HKjd}
?|0p+G
:[\f.vI
Y"A&!+
_d$,Fm
*6{kPq
T52{ #3
D+v=~{
:Bo^o{
2t}afR`
,:X-"p
qZJ#`:#
<zqyL^x
%Q':q7R
7DA_nG
Rw?s!9j
0io1.<m
I.c8Qc
N@5V'2
Ucf++l
@>Qn>2J
Gf>R=A
/?Qp[-
vOg-o#
nr*%bcE
'HXXR}
yv-\V`
dj4.E[?9
CT}':2O
u-1S-U;
cLr+4|
+JF$cTPC6
h(T^7#
gk6R#/j
E9<(q%K
D--1K'
sM_`;9
=nU*or
aG2LIh
E/rVxQ
CI`n>H
(7,J4lHinE
|(>Gt
*4Y6dp
$mF=.Y!
uZ;P5Z!
uguA!9g8
P#?"hy
^aN6:N_
w%mY >
$8|n'P
\T;ap|
snjUE:b$
ZB} XQ
GooyAP
5FF7K*
<*Nt5J
5SO_&C
rwRS`j
Dz_+OZ
$l6O+}
CN!h"v
,?\L8V
M3g%6++
~HA'Wd
c')dC&
L@J@z
:5tWHV
e;"!_{
gsN|gj
TuOQ`C
m!Kl!?>
JM.][Z
=vlyAe+
fXd_,OE
t^TIV+
&4lmO$
vyL] /rt4
q2iT"d@
!9n,lt
e} LHO
s0H/M5
so[de+
@;`m~o
@R*Q#T
x4]=|a~;G
RC/j{J1
c Xo}^
KCa5C}
JH)wuqz
LA!%{rY
k211NaY
+\+jF(
1Mg-[/P9d
VkIr_V1Zb
r*i},|e
NE7~@y
eFXO7/
ao<d{u
5/RT#w
i7T8'e
$,q!::
|mV4W&
lg/Na})
L}59ZL
ds>c_yK
"\06a}
g1#GeR
A^D1c<
QdJi.?
>ZH0Tv
f`>P?zjH
PDPy4q83
vT(pV<n
VA #VQN"+k
o,M|2vV
Gq[G_%
WL3EUB
H)bd8](h
f=s^`Sr
x^_N>1
!,QY9_
MXHGos
YJ`H!\y
y."R;R
Y[`D*Z|PU
C4)p]/
}YKW&!
Hy4aIjyTw
eMFN>2q
m(B%|=
`u77D;
Jv]BrC
#:RBib
iXpmf-Y8
Np ``F
e`rM^~0
Q}n8D.
RP=f4
Ftn\c0
!)P/6(6
j$'9WI
[,6~w}9
C/+uBn
r+#MaH
mObZH
T]X{h.-
}{&?_N
28,2k&
n9LZ'B
)x"Wy#
Y}-ZQ&4X<
us>UvGp
~Cqy71
7i]*^ud
a3REeaX
WhFO[V
I^5)aw
\e;@T&
C,?B]X
0!2MxW(
LU|4yw`
[561Kx
^=kU7A=
3\/tbB
.{yg7e
'@Ge`T+s
T0+4E{
<$nnH'
;2cO1r)
V'TeLm9
n`"iK$Z
>j V+R
nrM1Fs
[v'}qJc
8L.{Rd<'
T7G-u=
(4sZyEfL
6Z5Ya$c,9Av
k6MH"
iClr1+
'gM_F\
s'#51kH
]M\n|O
c\20_w
~DJ9N3
B1rI~}x
3sc9Zx
dOK=G+
;%l]EY
++l@Ri
hD4S(C
%'T]xW
j~hL}R
1;$dQD
v?^\3s!
'(APm0
=p!saJ
"ss<v)l!
=>z|]]V
n,\Hi)>
~.dQ/H
F~!s-K
/:q,Nh
P?^LFr
SO:VMj@A
e$$1;`
6P<$vE
zvjr(t
d^>/]3n-
#'g'iD
\mhY'L
SSe-xc"
xeK F
Jm@(y
/+ GC;
H'%<JQ7=-
t[.g{f2w
A\ZUH&
^hrk-&-
?DP]6=W|
qffpt5
bmlgBCr3AO
3e~aF1n
L?rd1c
maWS>r
f/bxv!W
HhVbn
o(VR"
=`?AL.
qUzM_}
=hN^?7"
?SwR&@]
))EH]o
F!7:v=t*
Ag$~:B
!Abm;D
StpMs:
2@Gu60
})kc[t
>xiWSei
M*`|6+
%SJ2B=
H^w~A0
H}Lys,
^yB\`#
)iUo.A
_o'OJ/
n"F&eF
pa%.H{
_3kvPOV
l7+`h+
3W7<ar
zy59I0
|=4McW
WJjMOJ
CnGd\Z
S3WSg]
L`&mZUh}
3v$!n`
Bl9|/=
ea1ID{cJ
q@'?hwK
"\:I#%f`
!PJ'1n
=(/KDC
II)<zn
=e{y^Q_
{tn~)2
#2DY3>
69!m7e
88$b1U
f1nRhb
tCI=vg
X.9],mS
di9eaG
7F/Is+~
2c*cMC
L,AK:l
tPpGgbc
4zc.} CP
GIa#l6
!LJ1w;
{@{8Z'
{AZx=y
+{r'dH
>g7n3RI
>9y;Cj
O##kr)iKY!
9j?/2xd
&wY/B'tQ
:V239b$h
L~ajBu
U5%,re
7%58/(
Q*st&t
`M%3}W{M
Ys@@1:
bt(#EW
_?SN2Y
Uc75b,
da1#P:?f
yKeTy\
7oC(fx
6)I*x4
DOA@eo
L}b'!h
iqq_`t
k%5pxJ
TN%.Qk1
4mrXA>I
Y;q@e~
E-V,!HvB
Jg'7FI%
,AkpMj.O
F+Dv+9LE
,r,Y;)s
HEst,._!
T"{8:v
L4opZtr*
Pgv2ej`K
]-XNPz
ZAhmnyL
hSvHw.5
7NfP%4
rkl!wM
z|%sJ:
`lS2}B
O|yBb+
,VQUZ#
MXObo
0`wA4V4
B3]5Q4
bsrt6]U
Y:;`teH
&j+;MN
N*lX]|
a0cVgD
"56=Tt
$hd~0o
3dcBs4
/{;_Sz
;,Yee_
NyA]Ye
8Rr}^
/]p"f
u|#{<4
Mfu!|G
n8fByz
;PL2Km
)m?J=,
*s:xpX
a8 5}Yj?L
xhZ"ek(=yz
,a&-k.
.c.)i>\
YWx<_A
=M||+Rm
rsEg4L
%/_kp_h
l+xr);p
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
YYYYY@
TT}*Gw
TTT}*!h
......T
ll?**c. EE
KERNEL32.DLL
advapi32.dll
comctl32.dll
gdi32.dll
NetApi32.dll
oleaut32.dll
shell32.dll
user32.dll
version.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegFlushKey
ImageList_Add
SaveDC
NetUserEnum
VariantCopy
Shell_NotifyIconA
VerQueryValueA
BBABORT
BBCANCEL
BBCLOSE
BBHELP
BBIGNORE
BBRETRY
PREVIEWGLYPH
SPINDOWN
SPINUP
DLGTEMPLATE
DVCLAL
PACKAGEINFO
TFORM074212
TFORM2
MAINICON
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Sami Inc.
FileDescription
Time Limit for using Computer
FileVersion
1.0.16.8
InternalName
TimeLimit
LegalCopyright
Free Licence
LegalTrademarks
Free use for FRIENDS
OriginalFilename
TimeLimit.exe
ProductName
ProductVersion
1.0.16.8
Comments
With Daily Time Limit and Permit Time Zone, No load NThide.dll, Bug username corrected,Password change, Power On/Off, Switch user problem fixed, Application Start Blocker, Fixed Standard/Daylight change problem
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Aexlz.4!c
Elastic Clean
MicroWorld-eScan Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
FireEye Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
CAT-QuickHeal Clean
ALYac Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
TACHYON Clean
Emsisoft Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.dc
CMC Clean
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Gen:Trojan.WinlogonHook.NG0@aeXlZ3mO
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.WinlogonHook.EA411C
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Rundis.gen!A
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Clean
AVG FileRepMalware
Avast FileRepMalware
MaxSecure Clean
No IRMA results available.