Static | ZeroBOX

PE Compile Time

2013-08-08 01:54:12

PE Imphash

55d05e5267c1de07a1891bc6ae8ec4ee

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001a80a 0x0001aa00 6.53187531418
.rdata 0x0001c000 0x0000403b 0x00004200 5.0882680191
.data 0x00021000 0x000030c0 0x00002c00 5.37559771768
.reloc 0x00025000 0x000010a6 0x00001200 4.64695391458

Imports

Library KERNEL32.dll:
0x1001c000 GetProcAddress
0x1001c004 GetVersion
0x1001c008 Sleep
0x1001c00c LoadLibraryA
0x1001c010 GetSystemDirectoryA
0x1001c014 GetLastError
0x1001c018 SystemTimeToFileTime
0x1001c01c GetSystemTime
0x1001c020 OutputDebugStringA
0x1001c024 RtlUnwind
0x1001c028 InterlockedExchange
0x1001c030 TerminateProcess
0x1001c034 GetCurrentProcess
0x1001c044 GetTickCount
0x1001c048 GetCurrentThreadId
0x1001c04c FreeLibrary
0x1001c050 GetCurrentProcessId
Library WS2_32.dll:
0x1001c05c WSASetLastError
0x1001c060 getservbyport
0x1001c064 ntohs
0x1001c068 gethostbyaddr
0x1001c06c getservbyname
0x1001c070 htonl
0x1001c074 inet_ntoa
0x1001c078 gethostbyname
0x1001c07c WSAGetLastError
0x1001c080 inet_addr
0x1001c084 getsockopt
0x1001c088 WSAStartup
0x1001c08c listen
0x1001c090 bind
0x1001c094 closesocket
0x1001c098 setsockopt
0x1001c09c socket
0x1001c0a0 select
0x1001c0a4 connect
0x1001c0a8 ioctlsocket
0x1001c0ac send
0x1001c0b0 recv
0x1001c0b4 htons
Library msvcrt.dll:
0x1001c0bc _XcptFilter
0x1001c0c0 _initterm
0x1001c0c4 _adjust_fdiv
0x1001c0c8 isleadbyte
0x1001c0cc _itoa
0x1001c0d0 wctomb
0x1001c0d4 __badioinfo
0x1001c0d8 __pioinfo
0x1001c0dc _fileno
0x1001c0e0 _lseeki64
0x1001c0e4 _write
0x1001c0e8 _isatty
0x1001c0ec realloc
0x1001c0f0 sprintf
0x1001c0f4 memchr
0x1001c0f8 tolower
0x1001c0fc toupper
0x1001c100 strtoul
0x1001c104 calloc
0x1001c108 memcmp
0x1001c10c _snprintf
0x1001c110 strcmp
0x1001c114 printf
0x1001c118 strlen
0x1001c11c memcpy
0x1001c120 free
0x1001c124 malloc
0x1001c128 abort
0x1001c12c fprintf
0x1001c130 memmove
0x1001c134 memset
0x1001c138 _iob
0x1001c13c strchr
0x1001c140 _errno
0x1001c144 _amsg_exit

Exports

Ordinal Address Name
1 0x1000171a DaveEntry
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
F(HtAHttHH
j _UjBW
PPSSSS
f9A"t+
E`S@PSSSSSj
SSWWSS
]d9^$v|
Ed;F$r
HtJHt+Ht
:Fragt%B@;
WWWWWj
9.vJV9
SVVSSS
H1f;H'
SSSSSj
E(SSSSSj
vX8][u*
u"FVj*
VWVVVVVVj
t$SUSP
HYYt.H
tb8^,t
t8Nt'Nu
E89Etu
u,t^HtEHt
X9EXsl+u|Vh
X9EXs3+u|Vh
;+u|Vh
YYG;}\v
EP0C;_
YYF;u\v
YYG;}\v
KWj@SV
9}Hu ;
u39}(u
YYt"Ht
YYt%Ht
Ht|HtGHt
@BBAA;L$
YYf94Cu
0SSSSS
0SSSSS
0SSSSS
URPQQh
YSSSSS
HHtXHHt
>If90t
UQPXY]Y[
WrLehDO
\PIPE\LANMAN
zb12g12DWrLehig24
WARNING: out-of-memory allocating a block of size %u (%s:%u)
Out Of Memory!!!
..\..\source\src\google\protobuf-c\protobuf-c.c
data too short after length-prefix of %u
error parsing length for length-prefixed data
bad protobuf-c type %u for packed-repeated
length must be a multiple of 8 for fixed-length 64-bit types
length must be a multiple of 4 for fixed-length 32-bit types
bad packed-repeated boolean value
bad packed-repeated int64/uint64 value
bad packed-repeated sint64 value
bad packed-repeated enum or uint32 value
bad packed-repeated sint32 value
bad packed-repeated int32 value
error parsing member %s of %s
*unknown-field*
message '%s': missing required field '%s'
counting packed elements
too many fields
unterminated varint at offset %u
unsupported tag %u at offset %u
error parsing tag/wiretype at offset %u
too short after 64bit wiretype at offset %u
too short after 32bit wiretype at offset %u
Windows NT 4.0
Windows NT 1381
Windows 2000 5.0
Windows 2000 2195
Windows 2002 5.1
Windows 2002 2600
Windows 2002 Service Pack 2 2600
Windows 2002 Service Pack 3 2600
Windows Server 2003 5.2
Windows Server 2003 3790
Windows Server 2003 3790 Service Pack 1
Windows Server 2003 3790 Service Pack 2
Samba 4.0.0tp4
Windows XP 3790 Service Pack 1
Windows XP 3790 Service Pack 2
ErrorClass: %x Error=%x
Command Format Error: Error=%x
Warning: Error=%x
Hardware Error: Error=%x
Server Error: Error=%x
Dos Error: Error=%x
NT Error: Error=%x
ILLEGAL
SMB 2.???
SMB 2.002
SMB 2.001
NT LANMAN 1.0
Windows for Workgroups 3.1a
XENIX CORE
NT LM 0.13
Cairo 0.xa
NT LM 0.12
DOS LANMAN2.1
LANMAN2.1
DOS LM1.2X002
LM1.2X002
LANMAN1.0
MICROSOFT NETWORKS 3.0
MICROSOFT NETWORKS 1.03
PCLAN1.0
PC NETWORK PROGRAM 1.0
*SMBSERVER
*SMBCLIENT
\wship6
\ws2_32
freeaddrinfo
getnameinfo
getaddrinfo
%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X
?Unknown error value
EpmpServerUnavailable
EpmpSyntaxNotRegistered
EpmpUpdateFailed
EpmpCantAccessItem
EpmpCantCreateItem
EpmpInvalidDatabase
EpmpCantPerformOperation
SmbWarningBufferOverflow
ServerErrorCantSupportRaw
ServerErrorInvalidUserID
ServerErrorInvalidAttributeMode
ServerErrorInsuffAccessPerm
ServerErrorReserved
ServerErrorInvalidFileIDPath
ServerErrorInternalError
ServerErrorSMBCommandNotRecognized
ServerErrorUnknown
ServerErrorNotMe
ServerErrorWorking
ServerErrorBadSID
ServerErrorInvalidDeviceType
ServerErrorInvalidNetworkName
ServerErrorInvalidTreeId
ServerErrorNetworkAccessDenied
ServerErrorDFSPathNotFound
ServerErrorBadNamePassword
ServerErrorNonSpecific
DosErrorVcDisconnected
DosErrorMoreData
DosErrorPipeNotConnected
DosErrorNoData
DosErrorPipeBusy
DosErrorBadPipe
DosErrorNetWriteFault
DosErrorRedirPaused
DosErrorRequestNotAccepted
DosErrorSharingPaused
DosErrorTooManySessions
DosErrorTooManyNames
DosErrorBadNetName
DosErrorBadDeviceType
DosErrorNetworkAccessDenied
DosErrorNetNameDeleted
DosErrorPrintCancelled
DosErrorNoSpoolSpace
DosErrorPrintQFull
DosErrorBadRemoteAdapter
DosErrorUnexpectedNetError
DosErrorBadNetworkResponse
DosErrorAdapterHardwareError
DosErrorTooManyCmds
DosErrorDeviceNotExist
DosErrorNetworkBusy
DosErrorBadNetPath
DosErrorDuplicateName
DosErrorRemoteNotListening
DosErrorNotSupported
DosErrorInvalidDrive
DosErrorInvalidHandle
DosErrorAccessDenied
DosErrorTooManyOpenFiles
DosErrorInvalidPath
DosErrorInvalidFile
DosErrorInvalidFunction
NtErrorInsufficientServerResources
NtErrorNoTrustSamAccount
NtErrorUndefinedCharacter
NtErrorUnmappableCharacter
NtErrorIllegalCharacter
NtErrorLogonTypeNotGranted
NtErrorLogonNotGranted
NtErrorPipeBroken
NtErrorInvalidComputerName
NtErrorStatusCancelled
NtErrorInvalidBuffer
NtErrorCorruption
NtErrorPipeEmpty
NtErrorBadNetworkName
NtErrorBadDeviceType
NtStatusNetworkBusy
NtStatusBadNetworkPath
NtStatusDuplicateName
NtStatusRemoteNotListening
NtStatusNotSupported
NtErrorFileIsDirectory
NtErrorFileForcedClosed
NtErrorPipeListening
NtErrorPipeConnected
NtErrorPipeClosing
NtErrorPipeDisconnected
NtErrorIllegalFunction
NtErrorPipeBusy
NtErrorInvalidPipeState
NtErrorPipeNotAvailable
NtErrorCantOpenAnonymous
NtErrorBadImpersonationLevel
NtErrorInsufficientResources
NtErrorFileInvalid
NtErrorDiskFull
NtErrorPasswordExpired
NtErrorLogonFailure
NtErrorPasswordRestriction
NtErrorIllformedPassword
NtErrorWrongPassword
NtErrorLastAdminAccount
NtErrorMemberNotInGroup
NtErrorMemberInGroup
NtErrorNoSuchGroup
NtErrorGroupAlreadyExists
NtErrorNoSuchUser
NtErrorUserAlreadyExists
NtErrorInvalidAccountName
NtErrorPrivilegeNotHeld
NtErrorNoSuchPrivilege
NtErrorNoLogonSession
NtErrorNoLogonServers
NtErrorCantDisableMandatory
NtErrorNoImpersonationToken
NtErrorInvalidPrimaryGroup
NtErrorInvalidOwner
NtErrorDeletePending
NtErrorLockNotGranted
NtErrorLockConflict
NtErrorSharingViolation
NtErrorObjectPathSyntaxBad
NtErrorObjectPathNotFound
NtErrorObjectPathInvalid
NtErrorPortDisconnected
NtErrorDuplicateNameConflict
NtErrorObjectNameNotFound
NtErrorObjectNameInvalid
NtErrorUnwindException
NtErrorObjectTypeMismatch
NtErrorAccessDenied
NtErrorMoreProcessingRequired
NtErrorEndOfFile
NtErrorInvalidDeviceRequest
NtErrorNoSuchFile
NtErrorNoSuchDevice
NtErrorInvalidParameter
NtErrorTimerNotCanceled
NtErrorInvalidCid
NtErrorBadInitPc
NtErrorBadInitStack
NtErrorInvalidHandle
NtErrorPageFileQuota
NtErrorInPageError
NtErrorAccessViolation
NtErrorInfoLengthMismatch
NtErrorInvalidInfoClass
NtErrorNotImplemented
NtErrorUnsuccessful
RpcErrorInvalidCRC
RpcErrorInvalidChecksum
RpcErrorUnsupportedAuthLevel
RpcErrorInvalidXferStx
RpcErrorUnsupportedType
RpcErrorServerBusy
RpcErrorOutputArgsTooBig
RpcErrorProtocolError
RpcErrorYouCrashed
RpcErrorWrongBootTime
RpcErrorUnknownInterface
RpcErrorNoSuchMethod2
RpcErrorCommFailure
RpcErrorRemoteOutOfMemory
RpcErrorBadCtx
RpcErrorPipeMemory
RpcErrorPipeCommError
RpcErrorPipeDiscipline
RpcErrorPipeOrder
RpcErrorPipeClosed
RpcErrorPipeEmpty
RpcErrorUnspecifiedFault
RpcErrorOverflow
RpcErrorFPError
RpcErrorIllegalInstruction
RpcErrorFaultCancel
RpcErrorNoSuchCall
RpcErrorFailedWhoAreYou
RpcErrorBadActid
RpcErrorUnspecifiedReject
RpcErrorVersionMismatch
RpcErrorInvalidBound
RpcErrorInvalidTag
RpcErrorFPOverflow
RpcErrorFPUnderflow
RpcErrorFPZeroDivide
RpcErrorAddressError
RpcErrorZeroDivide
RpcErrorNoSuchObject
RpcErrorNoSuchInterface
RpcErrorInvalidExtension
RpcErrorInvalidHeader
RpcErrorComVersionMisMatch
RpcErrorObjectDisconnected
RpcErrorNoSuchMethod
RpcErrorChangedMode
RpcErrorServerFault
RpcErrorFault
RpcErrorNotRegistered
ErrorAlreadyExists
ErrorInvalidArg
ErrorOutOfMemory2
ErrorInvalidHandle
ErrorAccessDenied3
ErrorFileNotFound2
ErrorInterfaceNotRegistered
ErrorClassNotRegistered
ErrorUnexpectedError
ErrorFailed2
ErrorOperationAborted2
ErrorInvalidPointer
ErrorNoInterface
ErrorNotImplemented2
ErrorPending
ErrorAccessDenied2
ErrorFailed
ErrorOperationAborted
ErrorOutOfMemory
ErrorSmbV1NotSupported
ErrorServiceNotRunning
ErrorUnsupportedAccountOption
ErrorUnknownObjectVersion
ErrorNoSecurityServices
ErrorAccountDatabaseCorrupt
The account name was not found
Account information is not set for hte task
The task is invalid
Cannot open the specified task
The service is not installed
The specified task is not running
Task is not ready
ErrorTaskTriggerNotFound
TaskEventTrigger
The registered task has no valid triggers
Task has terminated
Task is not scheduled to run
Task has no more runs
Task has not run
Task is disabled
Task is already running
Task ready
Task is not scheduled
ErrorContextExpired
ErrorPipeEmpty
ErrorPipeClosed
ErrorInvalidSetId
ErrorInvalidOid
ErrorInvalidOxid
ErrorWrongStubVersion
ErrorSecPackageError
ErrorNotRpcErrCode
ErrorNoPrincipalNameRegistered
ErrorUnsupportedAuthLevel
ErrorCommFailure
ErrorBindingIncomplete
ErrorCallCancelled
ErrorNoInterfaces
ErrorInvalidPrinterCommand
ErrorInvalidPrinterName
ErrorUnknownPrintProcessor
ErrorUnknownPrinterDriver
ErrorUnknownPort
ErrorAccountExpired
ErrorNetlogonNotStarted
ErrorRpcBadStub
ErrorRpcByteCountTooSmall
ErrorRpcEnumOutOfRange
ErrorRpcOpnumOutOfRange
ErrorRpcNullRefPtr
ErrorRpcFpZeroDivide
ErrorRpcZeroDivide
ErrorAccountDisabled
ErrorPasswordExpired
ErrorStatusPending
ErrorAccessDenied
ErrorPathNotFound
ErrorFileNotFound
WsaErrorNotInitialized
WsaErrorWouldBlock
WsaErrorConnectionTimedOut
WsaErrorSocketTypeNotSupported
WsaErrorShutdown
WsaErrorProtocolTypeNotSupported
WsaErrorProtocolNotSupported
WsaErrorTooManyProcesses
WsaErrorProtoFamliyNotSupported
WsaErrorOpNotSupported
WsaErrorNotSocket
WsaErrorNotConnected
WsaErrorBadProtocolOption
WsaErrorNoBufs
WsaErrorNetUnreachable
WsaErrorNetReset
WsaErrorNetDown
WsaErrorMsgSize
WsaErrorMFile
WsaErrorIsConnected
WsaErrorInvalidArg
WsaErrorInterrupted
WsaErrorOpInProgress
WsaErrorHostUnreachable
WsaErrorHostDown
WsaErrorFault
WsaErrorGracefulShutdownInProgress
WsaErrorDestAddrRequired
WsaErrorConnReset
WsaErrorConnectionRefused
WsaErrorConnectionAbortedBySoftware
WsaErrorBadF
WsaErrorAlreadyInProgress
WsaErrorAddressFamilyNotSupported
WsaErrorAddrNotAvailable
WsaErrorAddrInUse
WsaErrorAcessDenied
ErrorCouldNotCreateRegisterChoicesForDecoder
ErrorCantGenerateValue
ErrorCantConstructBaseDecoder
ErrorStage2EncoderFailed
ErrorInvalidStage2EncodingOfUserEgg
ErrorInvalidStage1EncodingOfStage2
ErrorStage2EncodedUserEggHasBadBytes
ErrorStage1EncodedStage2HasBadBytes
ErrorStage1DecoderHasBadBytes
ErrorMismatchedStage1Stage2
ErrorMismatchedStage1Decoder
ErrorMismatchedStage2Decoder
ErrorBadOriginalRegister
ErrorUninitializedOriginalRegister
ErrorBadAllowedBytes
ErrorBadEscapeByte
ErrorBadMagicMultiplier
ErrorBadNumGoodValue
ErrorBadStage2Decoder
ErrorBadStage2Len
ErrorBadMagicBytes
ErrorInvalidEndianness
ErrorBadCharIsNeeded
ErrorInvalidRegister
ErrorEncoderFailed
ErrorExpectedEvenLengthBuffer
ErrorKerbApModified
ErrorKerbApSkew
ErrorKerbApTicketNotYetValid
ErrorKerbApExpired
ErrorKerbExchangeGotKerbError
RdpError_InitializingCrypto
RdpError_UnsupportedCertFormat
RdpError_LicenseHandshake
RdpError_BadSspMessage
RdpError_DecryptingMessage
RdpError_EncryptingMessage
RdpError_SslHandshake
RdpError_SslInitialize
RdpError_ProtocolNegotiate
RdpError_NLARequired
SMB bad domain name
SMB bad OS string
SMB negotiate bad wordcount
SMB bad seek mode
SMB bad file offset
SMB bad file mode
SMB path string parse failed
SMB path string build failed
SMB string parse failed
SMB string build failed
SMB string buffer parse failed
SMB string buffer build failed
SMB formatted data parse failed
SMB formatted data build failed
SMB pattern build error
SMB packet build failed
SMB packet parse failed
SMB-Netbios decoder error
SMB-Netbios encoder error
SMB bad chunk size
SMB Bad dialect
SMB bad netbios name
SMB bad search pattern
SMB bad pipe name
SMB bad share name
SMB bad version
SMB bad file name
SMB bad file handle
SMB unknown error
RPC packet parse failed
RPC packet build failed
RPC bad bind
RPC bad packet header
RPC bad syntax
RPC bad auth blob
RPC bad context
RPC bad port name
RPC-SMB read failed
RPC-SMB write failed
Must use SMB for this RPC action
Bind ACK with no auth
Invalid context flags for the RPC structure
GenericRpcError
ErrorUnknownReason
ErrorTextHasNoMatch
ErrorInvalidData
ErrorBadString
ErrorInvalidSize
ErrorValueIsReadOnly
ErrorNotSupported
ErrorProvidedBufferTooSmallForPurpose: Cannot put data to the buffer or the requested read will exceed buffer bounds
ErrorNotInitialized
ErrorNotImplemented
ErrorActionFailed
ErrorBadParameter
ErrorBufferIsImmutable
ErrorFileCreateFailed
ErrorFileReadFailed
ErrorFileWriteFailed
ErrorFileOperationFailed
ErrorNoMemory
ErrorInvalidTimeSpecified
ErrorNoNetbiosDomain
ErrorNoNetbiosName
ErrorNoDnsDomain
ErrorNoDnsName
ErrorNoPassword
ErrorNoUsername
ErrorSomeKindOfCryptoFailure
ErrorBadNetworkName
ErrorBadChecksum
ErrorFailedAuthentication
ErrorSocketInUse: The socket is already in use
ErrorBadUdpHandshake
ErrorRpcBindFailed
ErrorBadPacketType
ErrorBadPacket
WarningPacketNeedsMoreData
ErrorConnectionTimedOut
ErrorRecvFailed
ErrorSendFailed
ErrorConnectionClosed (TCP Ack/Fin)
ErrorConnectFailed
ErrorBadProtocol
ErrorSocketCommandFailed
ErrorAbort
Success
Invalid parameter passed to C runtime function.
(null)
```hhh
xppwpp
GetProcAddress
GetVersion
KERNEL32.dll
WS2_32.dll
_errno
strchr
memset
memmove
fprintf
malloc
memcpy
strlen
printf
strcmp
_snprintf
memcmp
calloc
strtoul
toupper
tolower
memchr
sprintf
realloc
msvcrt.dll
_XcptFilter
_initterm
_amsg_exit
_adjust_fdiv
isleadbyte
wctomb
__badioinfo
__pioinfo
_fileno
_lseeki64
_write
_isatty
FreeLibrary
LoadLibraryA
GetSystemDirectoryA
GetLastError
SystemTimeToFileTime
GetSystemTime
OutputDebugStringA
RtlUnwind
InterlockedExchange
InterlockedCompareExchange
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
etchCore-0.dll
DaveEntry
Qkkbal
 ##%%&&))**,,//1122447788;;==>>@@CCEEFFIIJJLLOOQQRRTTWWXX[[]]^^aabbddgghhkkmmnnppssuuvvyyzz||
2&343E3E4
</<S<y<
0%030A0O0
=(>w>}>
R0W0`0x0~0
1*1.12161 3
45(5,5054585<5@5D5H5L5P5T5X5\5
9":&:*:.:2:6:::>:B:F:J:N:R:V:Z:^:b:3;
;D<*=c=u>{>
808\89<
3"3(3.343:3@3F3L3R3X3^3d3j3p3v3|3
4"4:4 5
809>9F9M9T9[9b9i9~9
9 :':2:E:\:n:
?(?<?_?
2H3r3*4Q4
s1O4U6
2 20292>2F2L2T2]2j2u2
2h3p3S4m4
00-090O0Y0j0x0
01A1U1d1
4.4<4J4S4x4
5#5,5B5P5^5g5
8U:a:m;
=:>B>G>c>k>u>
?+?1?8?O?U?i?o?|?
3F4L4R4X4^4d4k4r4y4
:,<C=>
052d2|2
4L5j5t5z5
636@6L6T6\6h6
X1\1h1
5 5$50545<5@5
: :P:X:\:d:h:p:t:|:
3 3$3,30343<3@3D3L3P3T3\3`3d3h3l3p3t3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1p1t1x1|1
(null)
No antivirus signatures available.
No IRMA results available.