Static | ZeroBOX

PE Compile Time

2009-07-14 09:14:14

PE Imphash

84da4a3165e248148f65dbe03b98a436

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001e31 0x00002000 5.86736799933
.rdata 0x00003000 0x00000e90 0x00001000 4.52247672909
.data 0x00004000 0x00000b38 0x00000b38 0.412477155041
.pdata 0x00005000 0x0000018c 0x00000200 3.1215718721
.rsrc 0x00006000 0x00000958 0x00000a00 4.38617166505
.reloc 0x00007000 0x00000014 0x00000200 0.221676205458

Resources

Name Offset Size Language Sub-language File type
MUI 0x00006890 0x000000c8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000064f0 0x000003a0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000060f0 0x000003fa LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0xff193000 RegOpenKeyExW
0xff193008 RegCloseKey
0xff193010 RegQueryValueW
Library KERNEL32.dll:
0xff193020 SetErrorMode
0xff193028 FreeLibrary
0xff193030 CreateProcessW
0xff193038 LoadLibraryExW
0xff193040 WaitForSingleObject
0xff193048 GetModuleHandleW
0xff193050 WideCharToMultiByte
0xff193060 FormatMessageW
0xff193068 GetExitCodeProcess
0xff193070 SetFilePointer
0xff193078 ReadFile
0xff193080 CreateFileW
0xff193088 lstrcmpW
0xff193090 lstrlenW
0xff1930a0 GetLastError
0xff1930a8 GetProcAddress
0xff1930b0 LocalAlloc
0xff1930b8 HeapSetInformation
0xff1930c0 CloseHandle
0xff1930d0 GetStartupInfoW
0xff1930d8 Sleep
0xff1930e0 GetCommandLineW
0xff1930e8 lstrcpynW
0xff1930f0 GetTickCount
0xff1930f8 GetCurrentThreadId
0xff193108 GetCurrentProcessId
0xff193118 TerminateProcess
0xff193120 GetCurrentProcess
Library USER32.dll:
0xff193138 LoadStringW
0xff193140 CharNextW
Library msvcrt.dll:
0xff193150 exit
0xff193158 _wcmdln
0xff193160 _initterm
0xff193168 _amsg_exit
0xff193170 __setusermatherr
0xff193178 _commode
0xff193180 _fmode
0xff193188 __set_app_type
0xff193190 ?terminate@@YAXXZ
0xff193198 _cexit
0xff1931a0 __C_specific_handler
0xff1931a8 __wgetmainargs
0xff1931b0 __argc
0xff1931b8 wcscpy_s
0xff1931c0 strcat_s
0xff1931c8 __wargv
0xff1931d0 _wsplitpath_s
0xff1931d8 wcsncpy_s
0xff1931e0 swprintf_s
0xff1931e8 _exit
0xff1931f0 _XcptFilter
0xff1931f8 wcscat_s
0xff193200 memset
Library ole32.dll:
0xff193210 OleInitialize
0xff193218 OleUninitialize
Library ntdll.dll:
0xff193228 RtlLookupFunctionEntry
0xff193230 RtlVirtualUnwind
0xff193238 RtlCaptureContext
Library COMCTL32.dll:
0xff193248 None

!This program cannot be run in DOS mode.
U%<Rich
`.rdata
@.data
.pdata
@.rsrc
@.reloc
ADVAPI32.dll
KERNEL32.dll
USER32.dll
msvcrt.dll
NTDLL.DLL
ole32.dll
COMCTL32.dll
9l$puO9l$T
A_A^A]A\_
WATAUAVAW
u*9Q<|%
WATAUAVAWH
A_A^A]A\_
LcA<E3
regsvr32.pdb
DllInstall
SetProcessDPIAware
DllRegisterServerExW
DllRegisterServerEx
COMCTL32.dll
ntdll.dll
ole32.dll
msvcrt.dll
USER32.dll
KERNEL32.dll
ADVAPI32.dll
RegOpenKeyExW
RegCloseKey
RegQueryValueW
SetErrorMode
FreeLibrary
CreateProcessW
LoadLibraryExW
WaitForSingleObject
GetModuleHandleW
WideCharToMultiByte
GetSystemWow64DirectoryW
FormatMessageW
GetExitCodeProcess
SetFilePointer
ReadFile
CreateFileW
lstrcmpW
lstrlenW
Wow64EnableWow64FsRedirection
GetLastError
GetProcAddress
LocalAlloc
HeapSetInformation
CloseHandle
SetUnhandledExceptionFilter
GetStartupInfoW
GetCommandLineW
lstrcpynW
GetTickCount
GetCurrentThreadId
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
LoadStringW
CharNextW
_wcmdln
_initterm
_amsg_exit
__setusermatherr
_commode
_fmode
__set_app_type
?terminate@@YAXXZ
_cexit
__C_specific_handler
__wgetmainargs
__argc
wcscpy_s
strcat_s
__wargv
_wsplitpath_s
wcsncpy_s
swprintf_s
_XcptFilter
wcscat_s
memset
OleInitialize
OleUninitialize
RtlLookupFunctionEntry
RtlVirtualUnwind
RtlCaptureContext
DllRegisterServer
DllUnregisterServer
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="amd64"
name="Microsoft.Windows.RegSvr32"
type="win32"
<description>Microsoft Register Server</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
processorArchitecture="amd64"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
AutoRegister
0x%08lx
RegSvr32
DllInstall
\regsvr32.exe
user32.dll
Excessive # of DLL's on cmdline
/n must be used with the /i switch
DllRegisterServer
DllUnregisterServer
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft(C) Register Server
FileVersion
6.1.7600.16385 (win7_rtm.090713-1255)
InternalName
REGSVR32
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
REGSVR32.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7600.16385
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.