Static | ZeroBOX

PE Compile Time

2005-09-13 18:01:06

PE Imphash

5ef21414f390ccd1ad383d2c569cd765

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0001c000 0x00000000 0.0
UPX1 0x0001d000 0x0000b000 0x0000ae00 7.88609656918
.rsrc 0x00028000 0x00003000 0x00002600 6.38810762853

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000164b0 0x0000d32e LANG_ENGLISH SUBLANG_ENGLISH_US empty
RT_BITMAP 0x000164b0 0x0000d32e LANG_ENGLISH SUBLANG_ENGLISH_US empty
RT_BITMAP 0x000164b0 0x0000d32e LANG_ENGLISH SUBLANG_ENGLISH_US empty
RT_ICON 0x00028224 0x00001ca8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00014220 0x0000028a LANG_ENGLISH SUBLANG_ENGLISH_US empty
RT_STRING 0x000257e8 0x0000002a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00029ed0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00029ee8 0x00000348 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.DLL:
0x42a30c LoadLibraryA
0x42a310 GetProcAddress
0x42a314 ExitProcess
Library COMCTL32.dll:
0x42a31c _TrackMouseEvent
Library GDI32.dll:
0x42a324 BitBlt
Library MFC42.DLL:
0x42a32c None
Library MSIMG32.dll:
0x42a334 TransparentBlt
Library MSVCP60.dll:
0x42a33c ?_Xran@std@@YAXXZ
Library MSVCRT.dll:
0x42a344 rand
Library SHELL32.dll:
0x42a34c ShellExecuteExA
Library USER32.dll:
0x42a354 GetDC
Library WINMM.dll:
0x42a35c PlaySoundA

!This program cannot be run in DOS mode.
Ck0KE8D$z4
k]w[5|
TCRIX6
DUQWSY
Sg0B{0
hDCP-Y
tzG|>X>p
$QRPS.
qv`te\uZL
UK_(}-
p?FPPR
5(ei8i5N-
D^@/dA
!F0;W2Bb
NQ{^#$
v.w(BX
^D.;vtaN
Sr!HJ
t/bc~p
3NuRSW
Is2\0`
7 9|+u
R#Z<ik
1VS?AO
QaxQN
lN(w^pa$
P%P-BC
R?;HGR
.Bf`{=
T$4D'F$vX"
l=8wK u
(X0A8@@
D#``1<
[LQ!W4
5dKJtj
hQP?\I5
Nw34Xj
9|I V_
XUV-WPS
HWw$dF%hQ
+5jj/u
K8[|pOu
D\j&P6[0"1%D
[}lq:1$
0h4{hH
<0HP#Wa
p:NaA!W
4Vdon
l@4v|
&0WT7RF%;
4h@0GUt
l3| aV
6);DN
_;D3mT"
\^[t.>
A29v`A
aVXSR[B
UaNhSQ
)ShUwe'
Y0,&$7P
PTD`&[
24@TW2
L`(y@2 @
E<$O=
p><E4E
KfP^GXX
8V"pSv@AXB
L-k@`IZ3&s
G\*?X&
GlGPHD<
,L84P8Is
=tLh[DZ.
Pq3(T
s@H3 gO
<hH Vq
t?z9oL
'ZRCZ0 SHE[
{N#j(n
+*6Sqv'
$(dddd,048dddd<@DHddddLPTXdddd`dhlddddptx|dddd
&p&;c<K
V6HB0"$
*4<JRi
vbRB0l
YB<60*
!/ y q
,o7 vG
A>3P/X
DVAPI32.dll
?CAdvComboBox
c7open
Flash 8ireworks
;c0%ulu
S San:
AS7if+
MyButt
UxThemeHO
Data'lose
Background
oc$ctl
NWXPEdit
$Qqi+n
I&$8F
ULL0}C&
`.L8&a
N:7$L(
%BH$:7FH
l#Ke,c -s
#!^k?Y
;~oo5a
[GWx![s_
S8pj%_G
FBEuq6a`
[VK^cA
6a%y#E
K*{KmX
D@"CW
kE-{!0
EsI)d2
2xcC;I
]X5) #
@+c;S/
-!!}2*!E{
)+;S,8
S#(aO1^
s=2FR"
@J{Oe#!
y@.ZH3
_JpYHN~I
s`e,#gi`
Ss2:-+[
,eM`$1#i
bY#acE
Z`IoXd+{
ModuleHand
ProcAddress
eLibrary
mFi3R$ourc9
ckSizeof
Global
MseEve2
4SObjecKCyate
XBitmap
.S!idBr
tchDIMsA
+Out!1
sc\MdiFl
m9S7k7
@std@@YAXXZ
gL?0GQ
QBEIPB
_EosKKe
v{_CU1?
M:14K-U
_IxxF:mG
mbsnbcpy(
qsNDlg:
ub9nu+
TabbedBHi
k:pje6
M .rxa
KERNEL32.DLL
COMCTL32.dll
GDI32.dll
MFC42.DLL
MSIMG32.dll
MSVCP60.dll
MSVCRT.dll
SHELL32.dll
USER32.dll
WINMM.dll
LoadLibraryA
GetProcAddress
ExitProcess
_TrackMouseEvent
BitBlt
TransparentBlt
?_Xran@std@@YAXXZ
ShellExecuteExA
PlaySoundA
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
You have been traced.
CompanyName
FileDescription
Keymaker
FileVersion
2, 0, 0, 5
InternalName
keygen.exe
LegalCopyright
Copyright 2005
LegalTrademarks
OriginalFilename
keygen.exe
PrivateBuild
ProductName
Keymaker
ProductVersion
2, 0, 0, 5
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Keygen.4!c
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Generic Malware.ch!ats
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Keygen.Vopt
CrowdStrike win/grayware_confidence_100% (W)
Alibaba Clean
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
Baidu Clean
VirIT Trojan.Win32.Generic.LAG
Paloalto generic.ml
Symantec PUA.Keygen
tehtris Clean
ESET-NOD32 Win32/Keygen.IH potentially unsafe
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Keygen (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!4D3D060D8EC7
Trapmine Clean
CTX exe.trojan.keygen
Emsisoft Clean
huorong Clean
FireEye Clean
Jiangmin Worm.Viking.py
Webroot W32.Hack.Tool
Varist W32/Keygen.Y.gen!Eldorado
Avira Clean
Fortinet W32/Shifu.AEZ!tr
Antiy-AVL RiskWare/Win32.KeyGen
Kingsoft Clean
Gridinsoft PUP.Win32.Presenoker.oa
Xcitium Malware@#30poc4x7fwuf9
Arcabit Clean
SUPERAntiSpyware Hack.Tool/Gen-Keygen
ZoneAlarm Clean
Microsoft HackTool:Win32/Keygen!pz
Google Detected
AhnLab-V3 Unwanted/Win32.Keygen.R23827
Acronis Clean
McAfee Generic Malware.ch!ats
TACHYON Clean
VBA32 Clean
Malwarebytes Keygen.CrackTool.RiskWare.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus not-a-virus:Keygen.Acronis
MaxSecure Trojan.Malware.2588.susgen
GData Win32.Application.Keygen.B
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.