MD5 : 4ca30fcb63647aad1ee9cd8097919758
SHA1 : 1b8bfb90cb8de021e846f0ea8468f06826389997
SHA256: fedadfe479da258f63b570d3028929de4e96d7aeae5bd56d40fe48634c598ea5
ssdeep: 196608:OZ2YjYHdQrnVURySYJWuVp90oSQ99iMEMbAF:OZ2QYHdkuRiJWuVpNSQ99fG
File size : 11841568 bytes
First seen: 2011-02-15 20:43:07
Last seen : 2011-02-21 10:57:28
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x7A5C02
timedatestamp....: 0x4D54890C (Fri Feb 11 00:55:40 2011)
machinetype......: 0x14c (I386)
[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x9D5DBA, 0x9D6000, 6.45, 913263f1772b878f9fb6571d418bb840
.rdata, 0x9D7000, 0x1327AE, 0x133000, 4.73, b8aef7cbe3465f74812cacb04de32d20
.data, 0xB0A000, 0x2E3890, 0x36000, 4.08, b57c64facb315a9656f9a0e25afa1956
.rsrc, 0xDEE000, 0xAF80, 0xB000, 4.68, 723a4955de3700df48411d10a29e1b77
[[ 18 import(s) ]]
GDI32.dll: SetBkMode, SetPixel, GetPixel, SetDIBColorTable, GetTextMetricsA, GetTextExtentPoint32W, CreatePalette, RealizePalette, SelectPalette, SetPaletteEntries, SetTextColor, CreateDIBSection, CreateFontA, GetDeviceGammaRamp, GetStockObject, GetObjectA, SetBkColor, CreateSolidBrush, GetTextExtentPoint32A, DeleteDC, CreateCompatibleDC, AddFontResourceA, BitBlt, CreateFontIndirectA, SetDeviceGammaRamp, DeleteObject, CreateCompatibleBitmap, PatBlt, GetDIBits, SelectObject, GetGlyphOutlineW, RemoveFontResourceA
ADVAPI32.dll: RegCreateKeyA, RegEnumValueA, RegDeleteKeyA, RegQueryInfoKeyA, RegEnumKeyExA, GetUserNameA, AllocateAndInitializeSid, OpenProcessToken, RegCloseKey, RegSetValueExA, RegCreateKeyExA, GetTokenInformation, EqualSid, FreeSid, RegOpenKeyExA, RegOpenKeyA, RegQueryValueExA
USER32.dll: IsWindow, FindWindowA, SetFocus, CallNextHookEx, CallWindowProcA, UnhookWindowsHookEx, SetWindowLongA, GetWindowLongA, SetWindowsHookExA, RegisterHotKey, LoadAcceleratorsA, SetForegroundWindow, LoadStringA, GetSystemMetrics, SetWindowTextW, GetDlgItem, IsDlgButtonChecked, DialogBoxParamA, CharNextA, MessageBoxW, PtInRect, DestroyWindow, ShowWindow, UpdateWindow, MoveWindow, DefWindowProcA, CreateWindowExA, RegisterClassExA, GetFocus, GetKeyboardLayout, ShowCaret, HideCaret, CloseClipboard, GetClipboardData, OpenClipboard, GetWindowTextA, CharUpperBuffA, wsprintfA, SetCursor, GetWindow, ChangeDisplaySettingsA, SystemParametersInfoA, EnumDisplaySettingsA, ClipCursor, GetClassLongA, GetMenu, SetMenu, DestroyAcceleratorTable, LoadMenuA, RegisterClassA, DestroyMenu, GetIconInfo, EnableWindow, CheckRadioButton, SetWindowTextA, AppendMenuA, CreatePopupMenu, CreateMenu, CharNextExA, IsClipboardFormatAvailable, IsCharAlphaW, IsCharAlphaNumericW, SetCursorPos, ScreenToClient, GetCursorPos, SetClipboardData, EmptyClipboard, PostMessageA, GetWindowThreadProcessId, EndDialog, SetWindowPos, GetWindowRect, AdjustWindowRect, GetClientRect, GetDesktopWindow, LoadCursorA, LoadIconA, DispatchMessageA, SendMessageA, GetKeyState, MessageBoxA, SetRect, TranslateMessage, TranslateAcceleratorA, GetMessageA, CharNextW, GetActiveWindow, PostQuitMessage, ReleaseDC, GetDC, PeekMessageA
IMM32.dll: ImmGetCandidateWindow, ImmSetConversionStatus, ImmGetConversionStatus, ImmNotifyIME, ImmSetCandidateWindow, ImmGetCompositionStringW, ImmGetContext, ImmReleaseContext, ImmGetProperty, ImmAssociateContext
KERNEL32.dll: GetFileType, SetHandleCount, GetTimeZoneInformation, HeapSize, LCMapStringW, LCMapStringA, GetConsoleCP, GetOEMCP, GetCPInfo, GetCurrentThread, TlsFree, TlsSetValue, TlsAlloc, GetConsoleMode, SetConsoleCtrlHandler, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, VirtualQuery, GetTimeFormatA, IsValidCodePage, InterlockedExchange, Sleep, ReadFile, CloseHandle, GetFileSize, CreateFileA, WriteFile, CreateFileW, DebugBreak, lstrlenA, GetLastError, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, SetFilePointer, WideCharToMultiByte, InterlockedIncrement, InterlockedDecrement, ResetEvent, CreateEventA, DeleteFileA, CreateDirectoryA, SetCurrentDirectoryA, MultiByteToWideChar, SetEvent, WaitForSingleObject, CreateThread, OutputDebugStringA, GetUserDefaultLCID, GetModuleFileNameA, GetCurrentThreadId, GlobalFree, GlobalAlloc, LoadLibraryA, FreeLibrary, GetProcAddress, lstrcmpW, GetACP, GetVersion, GlobalUnlock, GlobalLock, Beep, GetModuleHandleA, CreateMutexA, WinExec, GetCurrentProcess, GetCurrentProcessId, GetLocalTime, SetUnhandledExceptionFilter, CompareStringA, FindClose, FindFirstFileA, FileTimeToSystemTime, FileTimeToLocalFileTime, GetFileTime, GetSystemDirectoryA, GetCommandLineA, GetLocaleInfoA, GetThreadLocale, GetVersionExA, lstrcmpA, GetSystemInfo, IsProcessorFeaturePresent, MapViewOfFile, CreateFileMappingA, UnmapViewOfFile, LockResource, LoadResource, SizeofResource, FindResourceA, FindResourceW, GetFullPathNameA, lstrcmpiA, HeapAlloc, GetProcessHeap, HeapFree, TlsGetValue, GetStdHandle, HeapCreate, HeapDestroy, HeapReAlloc, VirtualAlloc, VirtualFree, FatalAppExitA, IsDebuggerPresent, TerminateProcess, GetStartupInfoA, UnhandledExceptionFilter, ExitProcess, GetSystemTimeAsFileTime, RtlUnwind, RaiseException, GetFileAttributesA, SetFileAttributesA, CopyFileA, GetCurrentDirectoryA, GlobalMemoryStatus, SetLastError, Process32First, Process32Next, CreateToolhelp32Snapshot, Module32First, Module32Next, GetDateFormatA, EnumSystemLocalesA, IsValidLocale, GetStringTypeA, GetStringTypeW, GetLocaleInfoW, SetStdHandle, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEndOfFile, CompareStringW, SetEnvironmentVariableA, IsBadReadPtr, CreateProcessA, GetWindowsDirectoryA, ReleaseMutex, GetExitCodeProcess, VirtualProtect, lstrcpyA, lstrcpynA, LocalFree, FormatMessageA, _lwrite, ExitThread, QueryPerformanceFrequency, MulDiv, lstrcatA, TerminateThread, GetExitCodeThread, ResumeThread, SetThreadPriority, SuspendThread, CreateIoCompletionPort, PostQueuedCompletionStatus, GetQueuedCompletionStatus, FlushViewOfFile, ReleaseSemaphore, SleepEx, FlushInstructionCache, FindNextFileA, GetTickCount
SHELL32.dll: ExtractIconExA, ShellExecuteA, ShellExecuteW, SHGetSpecialFolderPathA
ole32.dll: CoUninitialize, CoCreateGuid, OleInitialize, OleUninitialize, CoInitialize
OLEAUT32.dll: -, -, -
WININET.dll: FtpRenameFileA, InternetSetStatusCallback, InternetConnectA, InternetCrackUrlA, InternetOpenA, InternetCloseHandle, InternetGetLastResponseInfoA, FtpSetCurrentDirectoryA, FtpCreateDirectoryA, FtpRemoveDirectoryA, FtpDeleteFileA, HttpOpenRequestA, InternetWriteFile, FtpOpenFileA, FtpPutFileA, FtpGetFileA, FtpGetCurrentDirectoryA, InternetFindNextFileA, FtpFindFirstFileA, HttpSendRequestA
urlmon.dll: URLDownloadToFileA
WS2_32.dll: WSARecvFrom, WSASendTo, WSASetEvent, -, -, -, -, -, -, -, -, -, -, -, WSAGetOverlappedResult, WSAResetEvent, WSAWaitForMultipleEvents, WSACloseEvent, WSARecv, WSAIoctl, -, -, -, -, -, -, -, -, -, WSACreateEvent, -, -, -, -, WSASend, -, WSASocketA, -
USP10.dll: ScriptItemize, ScriptStringAnalyse, ScriptStringFree, ScriptStringCPtoX, ScriptStringXtoCP, ScriptStringOut, ScriptString_pSize
VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
DDRAW.dll: DirectDrawCreateEx
iphlpapi.dll: GetTcpTable, GetAdaptersInfo
WINMM.dll: timeSetEvent, mmioOpenA, mmioGetInfo, timeKillEvent, mmioWrite, mmioAdvance, mmioSetInfo, mmioSeek, mmioCreateChunk, mmioClose, mmioDescend, mmioRead, mmioAscend, timeGetTime
d3d9.dll: Direct3DCreate9
DSOUND.dll: -
ExifTool:
file metadata
CodeSize: 10313728
EntryPoint: 0x7a5c02
FileSize: 11 MB
FileType: Win32 EXE
ImageVersion: 0.0
InitializedDataSize: 4333568
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
PEType: PE32
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2011:02:11 01:55:40+01:00
UninitializedDataSize: 0