附加信息 |
File size: 745472 bytes |
MD5 : e655ba28d3b46fb917fbe6e4f1272648 |
SHA1 : 20255ba804cbc90ecdaac2b929fa88af43b11307 |
SHA256: 0b9512a93b47fd9a5b384d518a2b7af0206df31e1eb78161d5c5e27a70365b86 |
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x2BF001
timedatestamp.....: 0x46D293EC (Mon Aug 27 11:05:48 2007)
machinetype.......: 0x14C (Intel I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xE7000 0x60E00 8.00 ccb128c4cac05c21c26ea881e0b76f09
.rdata 0xE8000 0x2B000 0x9A00 7.99 03bbc4f47de05c873569743b396e408e
.data 0x113000 0xD7000 0x3600 7.94 1f734b909e90930cf807ff20c250e6b7
.rsrc 0x1EA000 0xD5000 0x18C00 7.66 3284b14fe7eae1a5a015f3195abee57d
.aspack 0x2BF000 0x2F000 0x2F000 5.69 069d4c951bf69d1e860f7adefc082f85
.adata 0x2EE000 0x1000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
( 14 imports )
> advapi32.dll: LookupPrivilegeValueA
> comctl32.dll: ImageList_DrawEx
> comdlg32.dll: CommDlgExtendedError
> gdi32.dll: SetTextAlign
> kernel32.dll: GetProcAddress, GetModuleHandleA, LoadLibraryA
> ole32.dll: CoFreeUnusedLibraries
> oleaut32.dll: -
> oledlg.dll: -
> olepro32.dll: -
> psapi.dll: GetModuleFileNameExA
> shell32.dll: ShellExecuteA
> user32.dll: GetClassNameA
> winspool.drv: DocumentPropertiesA
> wsock32.dll: -
( 0 exports )
|
TrID : File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) |
ThreatExpert: http://www.threatexpert.com/report.aspx?md5=e655ba28d3b46fb917fbe6e4f1272648 |
ssdeep: 12288:vOQJlfYMZv+S2T66aG1mqHIDN8oQ7MxCmd1lw24cHP3in6s2/WjDEnpA:rJlA8wT66aG1mqHw8x7McYt4Q3i6s2O6 |
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=3D00FDA00002F86E60DD0B0A30135000BBB40AD1 |
PEiD : ASPack v2.12 |
packers (Kaspersky): ASPack |
packers (F-Prot): Aspack |
CWSandbox: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=e655ba28d3b46fb917fbe6e4f1272648 |
RDS : NSRL Reference Data Set
|
各位高手说下怎么回事啊