Static | ZeroBOX

PE Compile Time

2010-12-16 01:21:31

PE Imphash

3af4cfbd1aa2e14fd4d3ad1fb8182305

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000942a 0x0000a000 6.33283897411
.rdata 0x0000b000 0x00000f86 0x00001000 5.08600501933
.data 0x0000c000 0x00004000 0x00004000 1.52996462854
.rsrc 0x00010000 0x00006f28 0x00007000 3.25741351949

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000167b0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x00016ca0 0x00000284 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00016c18 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00010610 0x00000420 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00010300 0x0000030f LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40b000 GetTempFileNameA
0x40b004 GetTempPathA
0x40b008 CreateDirectoryA
0x40b00c RemoveDirectoryA
0x40b010 FindClose
0x40b014 FindNextFileA
0x40b018 FindFirstFileA
0x40b01c Sleep
0x40b024 CloseHandle
0x40b028 GetExitCodeProcess
0x40b02c CreateProcessA
0x40b030 GetModuleFileNameA
0x40b034 GetStringTypeW
0x40b038 GetStringTypeA
0x40b03c IsBadCodePtr
0x40b040 IsBadReadPtr
0x40b048 LoadLibraryA
0x40b04c GetProcAddress
0x40b050 LCMapStringW
0x40b054 LCMapStringA
0x40b058 CreateFileA
0x40b05c GetLastError
0x40b060 ReadFile
0x40b064 WriteFile
0x40b068 SetFilePointer
0x40b074 HeapFree
0x40b078 HeapAlloc
0x40b07c DeleteFileA
0x40b080 ExitProcess
0x40b084 TerminateProcess
0x40b088 GetCurrentProcess
0x40b08c GetModuleHandleA
0x40b090 GetStartupInfoA
0x40b094 GetCommandLineA
0x40b098 GetVersion
0x40b09c RtlUnwind
0x40b0a0 HeapCompact
0x40b0a4 HeapReAlloc
0x40b0ac GetVersionExA
0x40b0b0 HeapDestroy
0x40b0b4 HeapCreate
0x40b0b8 VirtualFree
0x40b0bc VirtualAlloc
0x40b0c0 IsBadWritePtr
0x40b0d0 WideCharToMultiByte
0x40b0dc SetHandleCount
0x40b0e0 GetStdHandle
0x40b0e4 GetFileType
0x40b0e8 GetCPInfo
0x40b0ec GetACP
0x40b0f0 GetOEMCP
0x40b0f4 MultiByteToWideChar
Library USER32.dll:
0x40b0fc wsprintfA
0x40b100 PeekMessageA
0x40b104 GetMessageA
0x40b10c TranslateMessage
0x40b110 DispatchMessageA
0x40b114 LoadStringA
0x40b118 MessageBoxA

!This program cannot be run in DOS mode.
`.rdata
@.data
t'Fj\V
T$ PQRRj j
T$(j RS
L$HPQS
>wwwwu
~(9~$u
T$LPQR
|$LPWS
L$ RPQ
T$HPVS
T$PRWS
T$,RWV
T$,RWV
T$,RWV
T$,RWV
L$ RUPj
T$,PQh(
D$0Qh
L$(SUV
N4_^]3
QQSVWd
t.;t$$t(
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
VC20XC00U
sO;>|C;~
"WWSh@
HHtYHHtF
tFGQPS
^}%95l
inflate 1.1.3 Copyright 1995-1998 Mark Adler
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetTempFileNameA
GetTempPathA
CreateDirectoryA
RemoveDirectoryA
FindClose
FindNextFileA
FindFirstFileA
SetCurrentDirectoryA
CloseHandle
GetExitCodeProcess
CreateProcessA
GetModuleFileNameA
KERNEL32.dll
MessageBoxA
LoadStringA
DispatchMessageA
TranslateMessage
MsgWaitForMultipleObjects
GetMessageA
PeekMessageA
wsprintfA
USER32.dll
CreateFileA
GetLastError
ReadFile
WriteFile
SetFilePointer
SetEnvironmentVariableA
GetCurrentDirectoryA
HeapFree
HeapAlloc
DeleteFileA
ExitProcess
TerminateProcess
GetCurrentProcess
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersion
RtlUnwind
HeapCompact
HeapReAlloc
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetCPInfo
GetACP
GetOEMCP
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetProcAddress
LoadLibraryA
SetUnhandledExceptionFilter
IsBadReadPtr
IsBadCodePtr
GetStringTypeA
GetStringTypeW
/SO%d
/SF "
need dictionary
incorrect data check
incorrect header check
invalid window size
unknown compression method
invalid bit length repeat
too many length or distance symbols
invalid stored block lengths
invalid block type
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
invalid literal/length code
invalid distance code
incomplete dynamic bit lengths tree
oversubscribed dynamic bit lengths tree
incomplete literal/length tree
oversubscribed literal/length tree
empty distance tree with lengths
incomplete distance tree
oversubscribed distance tree
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="X86"
name="Application"
type="win32"
<description>Application</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="X86"
publicKeyToken="6595b64144ccf1df"
language="*"
</dependentAssembly>
</dependency>
</assembly>
wwwwwwww
wwwwww
wwwwww
wwwwwww
fffffffff
~~~~~~~~~`w
~~~~~~~~v
~~~~~~~~~`
~~~~~~~~v
~~~~~~~~~`x
wwwwwwww
wwwwww
wwwwww
wwwwwww
fffffffff
~~~~~~~~~`w
~~~~~~~~v
~~~~~~~~~`
~~~~~~~~v
~~~~~~~~~`x
stdrt.exe
[n,Cx:
x1=Exd
3"ZOa%
s{s.2JK
rb}<B^
oi8T:-
PsrIuK
PF55)#
]&A*4:
8.Jla
`LDqFb
DrH[kD
MaT!O
W:"bx2
+f6$6H
zhMb:L
D~j(7D
few66|
8u.rCf
^aoEfON
QvKF3?3a
2qI<N$?
"$Rp[2
2ho1|_
}7rSVW
O5~]?7{
?zQWm+
BmnoAyOy
x!OB{.
{i&?lv
7v0<tb%:
DksP,T~
[nI>=
oGBu35|
-^A |8]wixL
E8hyrh
CZSwT*
M<{r(b
p94?MT
"a [D~
E(~~|qX
7|%yoH
EJK?9lD
YkF#Kmt
}wD}(syA
}SiyDt
!W&?Kw
[}ez3-
U7\\k_
rbC`.
odGY_b#
'WA2~F
ezrbZ=r
TyuS`
}{~)VY
Z:04[a
4!-mJj
C^3{1*
;++(B7
&f}yotY;m
=igjl7
aU\{c4~g
U>;5*r
Q=ws?U
J,TabSE*-4
r[Xf>e2=Q@
J>(bKC
-qv0-X-PM
IK=lcV
{oUu-
SA"v\4za
goG2NZ^
y{>{h+
?D=q/m
F,5Zn1
:~M&q3
Y`68P8
JBM+4V
8rLCR
FZLt2I>q}
;=Z>/O
=(>?Tm
D0.-Lq
*O/RVV
Ay1L3,
tdy`t~|Jn"
N<MJWc
RNxh?#
>A!h-f
+!1Q-G9
^I(V,\
{RpJB6!
{u}NCFd
~vqe%[l
^aXK!\1
x9=?eFO
^@~*BV@
X71^40
Ykaz)w
jSp0\q
+)5";s{
v5hsMK
>{_}`OU4
gpFgtF
d1bXF
Wu>vV]
M"2@37b)a
]UxyWBX
roC[[!
lHn)6Gf
Tl4Dg
O_rn"g
j4*/@W
5|IkpJ
T9#qX*d
Nguhxq)?
@FEt>*
}=e<J#
#>'AuN.
MJs5T-
HH.94_
~#om?:
!W<mJ7
84vI^]X
GOzg$
j+u0^l
Ul1^@Y
IVOb^'
VW\JYk
5E[ ue
?H?LB|/
Fr#3XNj
imth]
Xgt2D>
}aakv"
lJ 'W*
j<=QH4
>yVA:4
J.AU<
p$yG9|
UF:y_CA
\[c*R$<
88^ l6M
>"bz68
UVDfYtw~3
8MbKN9
RcwrZ_u
SL>2W~
p_$0Cd
33`-K`-
@eI{^e
$za,073`
"HHlkb
[Br#/lYZ
G~?eE
!:x$[#O
s!H]eB(
BTf={y
{%}goJ
-w'gN-
Isp.`;@R
JiV&j\^5
"]U06YTs
]pW8N4
=#Ikk[
YH_:b`
sk?u)x
#[01hSg
9WCnWkH
Dh;1(J
iu"cH<k+
aldc:8
, p!I(
U;nb-\h
N-Phv1
^X0?"v
|/3^O2{
:}*`;O
(c;]tS
R`ReJq+lg3
l~9v`c
i#4{g
pnXjFr
oP!>>J
3/i&oA
JV',k$
v_&'a_
$</=e1
)VWP77
>oKW!h
-h2 6x
2.5%.sJ2
2/sBIjR
32<qq{
v]`^7J
bYAN]|e
7Q.XxR
0MR.D@
?jG4*Y
yi89 d
%O=N`JD~>LV
l(IdKi
w:#msJbY
eV#qQ%H3
g86i^BW
%m_;%<"'
)gaeTP
cybVY1-V
*Zz-^'
w N/HV
cD7;}C
2%s}{{
i'%W:
;`8?9j
=~]jY#
B$l)p'
>xY&nlz
hu36C{
-E4OA
3axjOb
y-]8gQ9
!9K*%S
y^(}&'
k+'kUh
~T;5"L
XSF.fA
wU?4%
<IYfdC
xg<}J$O
IYijlqF
'LyeS:tv
"v&MX/
VoJVWb
x@K<HK<
k&L^~~
=|.R^,
.V*.fK.U
|_`?4+
ac,E;L
lJa:$N
%f~!&;
pj^Y5U
sY0z_L
BU;I"-w
MMefV+
mWZ[[Mt
U*)[-dOB
f{cxv,e
E_|?QA{
GqGut
.h<=ClQ
Z8d#3u
Al~#>2Ya&P
FGkGia,(-
2y9*B\=b
|-g2SK)-
qBz,NH?b
0_l~No
EfR+bs
52M}JF
M<5Yxl
h .$Q-U
=LUaOCP
|YzlV`
jPK%j9
bR;+W9]F
^V[+D_
VS}}E[
g#~XCk
,sRBG
}(x/C
i;Pz#
:p)p=p;p?
XTEv`!P
_}yRA{>
]^QwfM
1F^mF^YF
nA&=]A&}
*lSPSg
B::XVJ
*=?w>>v
o9,6i?
mmfs2.dll
]GM6%5
f$IZ;l`
oATfso
pZnm 5C
pRL'`ZB5
Rc>F=Q?05
#l+Qym
a/#coA^
S#0*k'
=]nuX[_
F "0A
'i1tD8
Pi("Gd
k-]a/W
!++'u(
g+fK6/\5
Mhdu2`
=ma@?W
=D/fTiN=Iz%
L^y!92
-00i[s
Bau.[1
39n>,f
NjLN5J
{W|&k
M]d<<'
sFu|$/
7@7}@F
K[i*(Nu
Q04vQMv')
.@Mv{T
&`lH-0
'2|l`"
ml^>[PF)VJ
T,oSt
*<mDa~B
1?->RS?
;2#Wom^u
zHt_}:wQ
*O^zt)
qA{P/Qe
|;c.9)]P
Te|5l~
%|]jR1
la-&el
s% H4
0z&|`/
/Z:_r~
S?fakx
{z?~qR
Sm4Z]4Z
p|>WJ
1<]n:d
e?w>nA
v*0S/0$_*
$xd~G1
8Y WhMl
XB:g%6
KlPM]SKCV{
rY1*!E;
w`%}+TA
bWWaKs
Nl(VOO
W9gcK!i#&uSC
v!qhs8
s$KvBi
=SQCHt
_XOCyb
ix?An\_
8K3!5c
[N ,+;
ANi^<+;
r!]hZ_%KB
I-)y%|b-
78 ,t:
sTv:8M
hG~pI@
\=C}B*
ci$Mb3
!fq>{'
$NP,9A
@X"j@gl
DX4yXQ
+}|X!K
Ht_?~~\
Unx@*k
?4mMbX
$UFL'$
@86${2
qdx'a6
RGb`=[?K}
>TrMF%p
%)nhan
?8iWF(
d1kpi#
S,'hrO/
r6. %q
b;o?iL
OSz5G>
ZH;;`t
I={d\O
7N.N'[e
Db(%hT
z7W:|?s
G~#/PmZ
r_MF~9?
k<<n3?P5
: oC:_
8GC)5o
m?Pxh@
6;O4cW
SJR[`O
'0u`"S
.y-^6y
j#C9sk
?kigX+.
g+1^L`
+B^nhdN
s1QPfK
7nepntT
g"h$xkz^
%5*%W*
m\TcnOu%N
DoonO/
K#59PGS
x15@Y*
oZ}nW]/
i4M+1G
$j~X_r
!ca(o{$
,`xVF9
mKgi\d
E<NEx?
cu=B%
xahUCu
IEHPjI
>8%7f[
)ConWo%P
EBeM;4Q&
2WC3jZ
h~? W Z
:#`Q5
UN7{EfE4
avsC3s.
?t5O_H
G^q6B}D
P`Qb,D
%G{tGi
z^ fh)
5"GC}\
~PxW Ml
\})8E(
B0Y)uY
$6;N[&K
YB2_L,w
)9rQf>>
Bb~\z
Dzz~Z:
j96`DW
h-A1{J
.s! @_{2>
.L::R2
_5key`.
Y=@H5I
HLY,3e
T%J^mcf|
d+!Rem
6>~D;_Oo'
\9;G$[vlG0
W44HsL
2SRkWY
`DU-cUu
k*ud#=
E4x[N
G{$ka$
"(r;{
55,b<\
t8~AG{
-yk<t}
5G/5u*
C~ie~a
Mt:FG2C4
|tcKX\
[qnAp@
+tQp>=
0^[_HCk
G[I:6i
sy%|`\R
Ibgi7~
XJR;.4*Z
oqu]807p"
8v9{ZM
&eRHGX;
aYX0,d
mH^%c!t
t4MM9v
e|Y';{
*[L%[y
4z~qTbM
q`w*:z
]5Y3^9
iG8_S^
VQ*rgrc
lyjK74
\a'%:rD
VbMhu}
G/AqfEv
q,TnVE
abgI'/
VwQg@_
_'Z-@kH
"d~#5:
M-jp>}
hGRZSO
bQ<Xw^
E:N#ld
m3]S+EY
)B]1 }
Kj>[q]
-@80BV
H,****
9YogD=
&Si~dj
(MN&
~>S$B/
*ZMkh-
KcButton.mfx
hiK2_T]
VY-J Zc
Ys6MuVY
'fsMP
}}HA2'
:|K?54
WAt#.Mn
7X'a}x&v
UE;><M
=4 LRP
-gQ4Wh
#j15DnbZ
n_R/.!S
aKsTj3
`]+mR#
WNV;_M
`^wJhuIx
zAd]j/r
KY8)EF)
JuNxH
o#:$JM
V^VJ^DP
$sWt4w
i)qCJ|
?#%~QJ
UxejPJ
d_e1m4.mid
wd$0cZ
I[dJ^b
=k}#F!
F(1*Yh
aw|LirL
`){bdA
2'&$+)p8
tPRl:E
K;Y+Qhh#
@~bU?l
39pw&Y
(n0QT'
s)*MLO4d
[/7-
P,y0I2
cd`f``
String
ERP6#
cbP```
Button
cfP```
ca`f``
gM~(8o2
5Ot<~Tw
&0BhF&FC
IfR5?'
ih[=vpe
Z[dks,AkS
w<cJ5{
8(yXO?
ox<6Wl
(qSyn.{p
D~k,9g
n~5+qs
3Xh:()6
$Zh2!j
QBtXHrM
F_?eD7
m_&F]e/
/"Xm3y
M*]@V&
RAI#GD
((((( H
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
FileDescription
FileVersion
LegalCopyright
VarFileInfo
Translation
Cannot open executable file !!Invalid data in executable file !
Not enough memory !3Cannot create subdirectory in temporary directory !+Cannot create file in temporary directory ! Cannot write to temporary file !cThe disk that contains the Windows temporary directory is full !
Please free some space and retry.
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
VirIT Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
Varist Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
Cybereason Clean
Avast Clean
No IRMA results available.