Static | ZeroBOX

PE Compile Time

2010-11-08 22:12:00

PE Imphash

1d88d597200c0081784c27940d743ec5

PEiD Signatures

UPX 2.93 - 3.00 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00379000 0x00000000 0.0
UPX1 0x0037a000 0x0006c000 0x0006b400 7.99936560018
.rsrc 0x003e6000 0x00058000 0x00057800 2.54632732755

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_ICON 0x003fafbc 0x00042028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 8192, next free block index 40, next free block 0, next used block 0
RT_RCDATA 0x003e20e4 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode text, with no line terminators
RT_RCDATA 0x003e20e4 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode text, with no line terminators
RT_RCDATA 0x003e20e4 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode text, with no line terminators
RT_RCDATA 0x003e20e4 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode text, with no line terminators
RT_RCDATA 0x003e20e4 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode text, with no line terminators
RT_GROUP_ICON 0x0043cfe8 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0043d048 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0043d290 0x00000263 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text

Imports

Library KERNEL32.DLL:
0x83d5a8 LoadLibraryA
0x83d5ac GetProcAddress
0x83d5b0 VirtualProtect
0x83d5b4 VirtualAlloc
0x83d5b8 VirtualFree
0x83d5bc ExitProcess
Library COMCTL32.dll:
0x83d5c4 InitCommonControls
Library GDI32.dll:
0x83d5cc SetBkColor
Library MSVCRT.dll:
0x83d5d4 memset
Library OLE32.dll:
0x83d5dc CoInitialize
Library SHELL32.dll:
0x83d5e4 ShellExecuteExA
Library SHLWAPI.dll:
0x83d5ec PathQuoteSpacesA
Library USER32.dll:
0x83d5f4 IsChild

!This program cannot be run in DOS mode.
PxCJk[
qvwa{o
?iW0V!
|n:L;-
s%K:mF,
sB9up2
OAj!}I
Me3p&?6
$J -:/}
Lqaxdg
95ym^k
:N(>HD
ZVvbZPI
3o7Qaa
7E[9yO
[m>N4[
b&Bp;%F
{)"o},G
?J:9h8
RP>1%5n
0-]v|q
fKB9Ts
htb_R}
u[dGfb
6T8na0
,Oi*~Cc
#B7ta.
I]p"|P
v4W_Z;
YG)`vXY
.:FUR>[
rb7v~$
'2Er3S
_Hh0!]
<R.aGS
'5<0';
-(}Oq[
>g`a;ya
4 TR~>n
d+=kCI
#u2Ru{:
wdrO04<
hPU|I;c
u9$a:Z
| W`\c
nDX8l"
WFG[~
4k_43r
Q]XJ8k
moJFGa
V&?TFm
*9?&P<
L+4tWF
)V>Od7
})k.V0
1LRB+?
hLPT1<
[*0gin
$(]6>{
`Hs >M
h^`01
L')&s
[p\vM;
)-:X]<
[_+%-%c?S
/uS)AP5
?r|IA#w
duog(8J_'
Ph+yRwPU
J,Tl6G
6&*gM^
$5-R B
ddf\i~
W:lyfh
SUXW?.|
>$azz*
A %-&]
P!nsRD
Bja0cJ
8xpe,qW
y:;E,j
}<|GF~%
Wcds3A
%};VD;l
+0!%w"o
QT,v5!s
H1q 1H
?tOWW(
d8InQh
XWy3'+
0d>[1H
y`BY#L6
;&b*X\
zB/d/Q
kk^otpg
o^uRJa
]>^|^0|
zVNcW[
Do\10n
j`__4.5
[OW)BF~
#AS%U\
0{P5kOt]
/H8[e-!
N<Y+gu]7
W3f\Py
0q2N?hR
J"vqE\
_H)'yVG
Nf20{~
~w)Eql
y%,2MU
0Kq:CE)
hq7a;3Iq
Tk5C,p
)}KCP{B/Y
&'AeWI
<`'lC*
;Ts:|F
h&x|J@
l\}2}>M
0(l%/>
[KJu_m/
tbXN8h=1
5\(gGj
lw=m$p
XZyYW'
%S~r!\
O;FYMB)
Vy~~&
J&cz%3b
nWjZ?c
[EA3[Y
_ZA@P~
P,aBbJ
jmiv{K
`Gt6dg~
G8~~E
?f3o`*
vXjo~V
@8u/}^^
Pq.<CE
6W:tTcG|
!#Ji6z
c\b\UQ
bJ~Q,+H
Oj_-/x2tP
Q_rX&l
P`O#k{q
LON\&t
d ,f3t
E_2![.
Y&9UM_
rztgw)
[tFI8\Hs
6yF4!!gi>
Ub"Viz
N^8_*f>
]HnGq1
&SfymU
jDF`Jr U
j<-IR'.
>r(7o{
?5!DCV
~b-u]2X@
qt,aXs
%hc6+c
]2}0u>K3~]
W7^:m(
}e^Una
V=kBgr
hQ&"!t@4
Qx&mjl
[>1O@T#`
n1_M|Wj
5:XUw6
hT.._Dh
e_,7K=!k5F
d)C7eb
Q1P*;==@
UVf0vp
%-O6u
JRE&<AI
q$`glh
B:z;{g
&X;<G
y19%l]
QB2Ht$
mOol|J
j\7Oh.q
EP(^Ix
djWig9@
%|_@[#}[
c`H*^a
W{a;}Qj
1/l@z4
-[hq+i
LUMgxn
2&9)-;*
lz|C]B,
\3dvEO
OKQ1 2
-(.')rt
8>VTfrA1
R"B`G#k"
+$d_kM
0f:k-2
g1B<m#
_a?b qC
9%@yJU6!
pdTW/=
m&D+PM
ZE5By\
?GKK-\
MK%$Nk
\[L7'H>
0MP~X#
#n8wc<?
1Go,H{&
RiU+gbR
.$,$#R,
7$w]5u
p$7ngi
l';uK9}
U*tB2h
1[wXJ[
w7v9w~
\Z}L6]
@{pO#V?+
J2K;&';
|,_"^M
bejx8S
y)S?F@
^ADQ'\
0LA\J[n[
%TP&Ttz
xZKRqjX
?~mZ:t
]R(By
c]QA~!
hpXgN#cY
}1i_BC
LJH9&_/
w7$`IX7x
sed34;
^fJ`Se
1^x3+@q
PDCo*'
g6?3C,
Jn7^xv[
6X1'PA
.NrD6x
7INT8S
KUr!KS]4=)
VRV2u<R}N
H;_YID
pwY!4t
t^\[WF
5!22Q6
_79: >T
Fx9U2H
cdz(8+
f,swV;u7
aBhQ`D>
|5{GrP}D
HxBjz)(S
TnJ[QF
^O|vqO
%E46Jh2
l0~.ia
^5;b l$
*UD%LW|
/oZM/w7X
3^3jtv
sZkdc{
gnI^nkK9
o0YXu!
Jgk_t'
R3uI(CdQ
C&Bw8b
0OZ\H1r
F(Xl]W
$QG(,I
Oo|+uv
u}9kYg
-E>TZm
llB_AX
!N'*G4
3=0^Vx
=gstbc
:?tmJO
b5xJ5O
CQ(3C`
TqI@7^
=hT}"!
SLMc[ed
sy%o~0]U
A{(_}={
o 9e'TP
bD\g^D
?&o?yr
C&fQ_q
W`IJ^9
[c`w.fia
5?ep1"
acQGHjc
:1pa[D)y
N_/pJb
,uX#jC
7 Y'|8
^/E=YY
|0XNY1L
xk#w4m[
QQulb|
YdZ57P
5n$ SQ
.W}>Yth
8CDM[.D$g'
_q:s+P8
04aaLfu
Z)KAkjw
sFI>$kd
fgvIb-
9Z,5a/
yOQeCI
#L#H[
1dm(I~
i7$]lH
}LUF9Z
Ovd(9mm
.!ZY^z
pqP!!7
IzMF~(#
6AU-=#5
KBjQ_Osr#0Y
9{Is5o
EKNF0WiX:Y
ryCyGS
FH90 g
{EjE|vx
sW/fS"
R_G;|{
32X2>J
1hD!f'
y\Y7sj
SYMjf~
Uc4'Zq
}=9Ew4'
t5,<dNC
Kb8#"Y
b9G_7$
~Rr :H=
*ztrr P
*FT.qA
<KnH.HR5K
n(os]j
D?K`_C
n}>KFe
UQ,wMK
_Ept{RkJI
atm8}UKF
=:;_kY
7#E<P5{
8G|2Z
Tws`/B
|]tfPm
'WRolio
>xba [
`GVf!a
WP"d%p
/p==tR
,s,/M)-
^[ sxf"
6Q;6^u
}NVrCa\&%p{#
$%LIo0
?dR/d@-
~4gg8Zv@
,RJ.yg
3P)eB#
}S#fxw
< 7k["3rd
a<u`s_
AHg]Gx
x0NQMF
h/G[jqF
i]kaXr`
__)<5;<
8F=5[d
w)x]g^
<J3/yok
Xopv$L>M
O[R97y
pSHi"AG
V9iBE})
lL:;f}
#w}i1z
[$)dk
^}:Uz6
cg5= )
.l{/x]
'5MFvQ
2tC:h;'MQ
2&bq;L
:&_j`El
nvniY]=
Ng@.m\
Y3q^gK
AEYiJ
&d`7@G.T
-TxHOf
e4k&+NB
s5cbVM
\NI[c~
)`Aqxne
@oiDF
PAOE0&^av)
]TC1M"m
\[VFv_
>sHMW6^
~now`
-n&he'
[%d2\8
+Vb64Di
liZsmL
OZMGxP
&g#j1@7
P)VpH]v
DTzbK;
!&sLR6
ivLF.U
JezjB3
MDCS9`1
yJJ%7<3
>q5`2i
,i\uF@=p4
6yTOH
O~7>Ku
3`L$vA=
<4FMIh
g;jg&
oV*GVV
i_/C0_
+2(j6o
L 1T\]
+9HE>
Z|*1+I
2ctk@><
kuQ#K$K
_96N+T
#|=5kD
QXZBzPR,|#
-sQkzy
&95T1jWE
V%%2V@r
5'`)bM
C',T|,~
|;^?%n
)f ?P=
FXSIlLB
K|g/?|^
=>.h`Y-
pf':]@[-*
pt2~O%
ql_j}um
&E]\E{
u,^8|A
+!Rrgk
^Lv=.
&`B6ca
k|W"gc
!~m]q29 U*VL
_fS/,'
j"EWSn.^
![Zwns
K~n 0-
[mBk'i
z8pRI)
$ *X,A)
`U^*YBN
pO ,ME
#eNONL
;ve~PDp
lESs.GF
QxMa,D
0'E8$_
\#/%ue
SmCUW2X<
G\`9(O@
];N=fK
7@BGuP
)0]cgP
ouA[%d
'D\pL\
'~'*@V#
cZ;H^
L*t3^F'
xl>0%K[L
Wz%RVmjW
+]_NJU[}n>
S~<:RV
Xz^Vtf
\5t59B
'2X[hO
3C7hm}
>j32q+:
yG/Q,L
SWK|J=
$v<*cBQ
c|u@t)<
/&lTP{
EK2}#O-
G@4i3?
_S2jWA
~Z9s@q~'
n?m^@];>
Q=RNq=
7tq3rdS
h,h`XU
$nr{eY
;IdU.@}6
^p#DLj
xKgUyg+
sJF<t
ywDk&_
yHb/l%
^M?HMi$!
TAY8,O
n{kU(i
!|+gb41
A%xq[a
]J$:,\
d]7L[u
Mk8HYo
$=#f8U
u]Xugi
dX^RTH
W8|?m5
k>bXZs2
s(OoG
T*e^"%*
L!:2K\
8%~eWGya
V"><&+
'6-|j4E
@vp{11
okFL9u&
{3;r3|h
[i8[az~
wc8*mvJSB
;GDfx7
``?>Y+Xx
g:r7kJ
6M<8zbU
V71_7,G
"s}<j
&C.~o`G
|S38OzE
4ZeZWzO
/a4aXiJ|
\^VBe!}
kaSw3U8`h
[T!"%ayvg
rJcQIF
YJ],l(
M1R=Iwm
GSi(~mjP
%1<ySx
HHJa/v=
j?*xuKq_
U#FyQZ
^'?R<%
<et$wL
dEIcPd
R$u-'o
uN-"3a|(
byb2ZcaI%2qY
KR=dCffF
/LmCuoB
gLG9rr
|,{2Ea'
iSi+J@Q)
w}$ETXwv
/7F%tW
fpm_@ya
=3Uk3{
\k#e_{
5X'~xB
g9N)"o;
>k(qLv
]J~nE0
v1x$je^
<"Uvv~
#8Cq[t^Eg
Q`Rm<A
jq12IV
3$#21X
N~ 0:+$
$~MCk0
qr3A,r
DkSh|B
6b|Bu*
Z_Y:u*
*SM|4\ma$,!
5TiF+1
RzQVUI
W2#+EI
:\8 C5.?
nF|+_L
4#xZ#l
LC-u8^n
[sV gG
SaF}Vy
H1lzQSmLy
$X<^M&
Mn|+IO
C4.td7
jO,,\w
]%rO'
B&2B%O"
6Bymf%: Fr
x{V[^*b
XLeE[V
tP+mn3
?y|Ahg
"y/6AN+
wF)8Bv
=oNMf_
$k(_Zo
~0r9`?*
Thw-_$^
WTM.<jN
}xT[9Y
^G,Rpa8l.
`'*S,,
XFqBk6
)*m4mQ
Jj# V!
1p F%b
Gg[hJ[Q
6r!~>,y
T&!Serm
g6d&R"5l
duY-Tm
AC t7D
<Q66}(
moh*9z
|=JW *
<'Y0*z
}ies@m
Q2TH_
]bDETXb
~SdvZO
9rR#e"Om
j!58G
J;L5~b
RRm8iX
AHr?|[
5$hmMZ_5e
7]K,<.
r93 ;k
Y,B@,1>
mWn*BX
`pR1i2-tR
PImGPg
pvsN.x
r5}w%m
D9"X]yt
yRQuUof
kSUt0t
hQ$gvu
1cVpw~
e@_FB\
=r9A0Ejl
3RS1}HX
N:u8d
cfRSTk
L;}9qb
|%*iua
;^eH3"
UH#]Jn
nw"jWB6
>?VxO+
Hv@K\.[^m
Cmm-!#
j2y|~iD
e+O7~O
o#GHAH
q81gL79
[~,Z'>=
Pu$H i`
(0)p2i
:</5TnR)
;XTK#yjX"
4v?UC1
RjS<Q)
:duq^
mk>N S\i
fJ(@xh
(2o|.^L}
v)P,p&
^`#v B
!RSgv0
gs]SHj
*stMs<
:omjhX+
}q0bLj
;$Y9yR
BW+fsm_
Y`a^6P/M
#'y{%]
xZM=s5
0$pDbVO
;P,6f:
v1b7S-
Eu?#{V
l bm,~
gyzOG}I
OQW3W6
4vb?wOe
*m,_@?
uFrhM'
9/oZ,:
QDGn%y_
b^wHcFF
tYnTvd
3*>X0p
u<[:Xw
Nv*{]O
+_9]HZc
ScvEcp>3
R A_Po
01HwRrP
mo}8/Z
gbtx>C
i8cv[9X
2V)sT#v
`e0 1F
n;u+F@u
~cf4mS
49=-y:
8L3t2)
tI9{[$
]d_pk%G
_GiK$
<;E*rFC[$
NnOcnFr'T
H_h>8{
:L4wP|
aLxP`v
rFu;)d
OM#;\x
iPf/ f
y=w.Yc
*jVK[jOz
+G!@O|j
kR.>?W
'MQP&"
y&rRyI
>vkgn5
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="X86"
name="CompanyName.ProductName.YourApp"
type="win32" />
<description></description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="X86"
publicKeyToken="6595b64144ccf1df"
language="*" />
</dependentAssembly>
</dependency>
</assembly>P
KERNEL32.DLL
COMCTL32.dll
GDI32.dll
MSVCRT.dll
OLE32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
InitCommonControls
SetBkColor
memset
CoInitialize
ShellExecuteExA
PathQuoteSpacesA
IsChild
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
boblox
FileDescription
free bobux
FileVersion
1,0,0,0
ProductName
free bobux
InternalName
ProductVersion
1,0,0,0
LegalCopyright
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Trojan.GenericKD.36168245
ClamAV Clean
FireEye Trojan.GenericKD.36168245
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.36168245
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.V6dm
K7AntiVirus Clean
BitDefender Trojan.GenericKD.36168245
K7GW Clean
CrowdStrike Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 BAT/BadJoke.RA
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Zpevdo!8.F912 (CLOUD)
Sophos Generic Reputation PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.36168245
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.36168245 (B)
Ikarus Trojan.BAT.BadJoke
GData Trojan.GenericKD.36168245
Jiangmin HackTool.KMSAuto.en
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Trojan/BAT.BadJoke
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D227E235
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!794B00893A1B
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 TrojanPSW.Zbot
Malwarebytes Malware.Heuristic.1003
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09BL23
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.201038644.susgen
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.