filename | Addnews.exe | |
---|---|---|
size | 2966528 (0x2d4400) | |
md5 | 1489999ce50ac7078e50483a79729c67 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
Aspack v2.12b (Alexey Solodovnikov) This file is packed with ASPack. Analysis will be incomplete without unpacking. |
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0xb48000 | 0xb48198 | 0xae7c30 | 0xb49010 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetProcAddress | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
oleaut32.dll | SysFreeString | ||
advapi32.dll | RegQueryValueExW | ||
user32.dll | LoadStringW | ||
user32.dll | CreateWindowExW | ||
msimg32.dll | AlphaBlend | ||
gdi32.dll | UnrealizeObject | ||
version.dll | VerQueryValueW | ||
advapi32.dll | SetSecurityDescriptorDacl | ||
oleaut32.dll | GetErrorInfo | ||
ole32.dll | CreateStreamOnHGlobal | ||
comctl32.dll | InitializeFlatSB | ||
ole32.dll | IsEqualGUID | ||
oleaut32.dll | SafeArrayPtrOfIndex | ||
imm32.dll | ImmSetCompositionWindow | ||
urlmon.dll | CoInternetCreateZoneManager | ||
wininet.dll | InternetSetOptionW | ||
shell32.dll | SHGetFileInfoA | ||
shell32.dll | SHGetSpecialFolderLocation | ||
comdlg32.dll | PrintDlgW | ||
winspool.drv | OpenPrinterW | ||
winspool.drv | GetDefaultPrinterW | ||
oleaut32.dll | SafeArrayCreate | ||
msvcrt.dll | free | ||
gdi32.dll | GetCharacterPlacementW | ||
oleaut32.dll | SysAllocStringLen | ||
oleacc.dll | AccessibleObjectFromWindow | ||
winmm.dll | timeGetTime | ||
user32.dll | SwitchToThisWindow |
StringTable 041904E3
CompanyName | soft4dle.com |
FileDescription | |
FileVersion | 4.2.3.95 |
InternalName | |
LegalCopyright | |
LegalTrademarks | |
OriginalFilename | |
ProductName | |
ProductVersion | 1.0.0.0 |
Comments |
VS_FIXEDFILEINFO
FileVersion | 4.2.3.95 |
ProductVersion | 4.2.3.95 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 4 |
FileType | 1 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[!] string size(15508) > stringtable size(396). truncated to 394
[!] cannot convert "{|\xB6\x14#)\xFF\xB3\x0E6r\xE7\xF5U\xAE\x11"... to UTF-16
[!] string size(2452) > stringtable size(952). truncated to 950
[!] cannot convert "\x9F%&\x98\xA19X\x1F\x99\xD8\xC7\xF9\x05Z\xDC\xF8"... to UTF-16
[!] string size(127376) > stringtable size(956). truncated to 954
[!] cannot convert "\xAE\xA5\xB9\xA7\xEA\xDA\xBA\xBF{\x7F\xE8tQ\x83\xB8w"... to UTF-16
[!] string size(35770) > stringtable size(496). truncated to 494
[!] cannot convert "][\x8F6\xAF\xE5SYGy}\xD8(\x84M\e"... to UTF-16
[!] string size(104232) > stringtable size(772). truncated to 770
[!] cannot convert "\x8B\x04\xD5\xD1&\x91v\xBB\x9B\x8E\x8D\f{\xE4\xAC\xA7"... to UTF-16
[!] string size(83580) > stringtable size(904). truncated to 902
[!] cannot convert "\x05\fF\xDD\xB4\xE0\v\ao\xACC\xE5\xA8\xC7\x06\xA1"... to UTF-16
[!] string size(6384) > stringtable size(324). truncated to 322
[!] cannot convert ":_\x8F!^D\x84\xCF\xC5\a$r+Ng\xBC"... to UTF-16
[!] string size(65566) > stringtable size(956). truncated to 954
[!] cannot convert "\xF8\x0F\x81yG\xEEi\xC5\xF0\xA8I\xFF\xF6G\xDD\xCB"... to UTF-16
[!] string size(95866) > stringtable size(1140). truncated to 1138
[!] cannot convert "6y^\xCC\xBF\x12~\x86\x8EEH\x85\xD6!\xBA\xFA"... to UTF-16
[!] string size(71958) > stringtable size(1424). truncated to 1422
[!] cannot convert "kf=mtd&\x99\xAF\x86J\xA2\xCA\x03\aE"... to UTF-16
[!] string size(94190) > stringtable size(1152). truncated to 1150
[!] cannot convert "\x17\xF0&\xC2\xFD\x10\xDA=\xAB0\x03&hQ\x19\xFD"... to UTF-16
[!] string size(58834) > stringtable size(1064). truncated to 1062
[!] cannot convert "9\x14\x12~\x1D\xD3-G\xF2\xEC\xA4U!$\xBF\xFA"... to UTF-16
[!] string size(91528) > stringtable size(996). truncated to 994
[!] cannot convert "\x99\x15\xC9\x8D#\xAB\e\x872\xB1\vb\x11P\xC8}"... to UTF-16
[!] string size(5302) > stringtable size(812). truncated to 810
[!] cannot convert "\xCD\x8A\xF4\x16\xCD\\\xE9\xB2\xC7\xA78\x91s\x1D\x15\xE9"... to UTF-16
[!] string size(11980) > stringtable size(1300). truncated to 1298
[!] cannot convert "\x131\xF2\x8A\x1D\xA2\x86\xED\xB3u?r\x17t\x17\x95"... to UTF-16
[!] string size(103350) > stringtable size(1204). truncated to 1202
[!] cannot convert "\xF8%\xF9;_y~\x10\xC5\x94\x10%9\x93\xBD\x89"... to UTF-16
[!] string size(93906) > stringtable size(712). truncated to 710
[!] cannot convert "&\x87'\xE2\xFD\xF9\\\x8E/^\x8D\xA3\x85s\xFE\xA6"... to UTF-16
[!] string size(79722) > stringtable size(680). truncated to 678
[!] cannot convert "p\xA9R\x8D\x11\a8u\x99\xC4\xED\x8B\xD0\xC6\xA9\a"... to UTF-16
[!] string size(118194) > stringtable size(844). truncated to 842
[!] cannot convert "\xE9\rNk\xF8\x1Al\x88^\x82\x11V\xB3\x88\x88;"... to UTF-16
[!] string size(79026) > stringtable size(1008). truncated to 1006
[!] cannot convert "^\xFF\xE0\fLIq\x91\xB3\x05(ON)\xE5\r"... to UTF-16
[!] string size(122860) > stringtable size(484). truncated to 482
[!] cannot convert "\xF0R1\xB0I\x8A\x86\xBD\x1A\r\xE9\xF1\x13\xCB\xC5\xEE"... to UTF-16
[!] string size(53788) > stringtable size(1000). truncated to 998
[!] cannot convert "\xE5\x1D=\x13\e\xA0\x8BH{\xB70\xAF\xD2h\x10\x8B"... to UTF-16
[!] string size(10338) > stringtable size(3036). truncated to 3034
[!] cannot convert "\xD0\xA7\x99\x11\xF2\ei\xBD\xF3\e6\xD9z/\xF6U"... to UTF-16
[!] string size(69078) > stringtable size(1220). truncated to 1218
[!] cannot convert "\x1Fs\xB8\x84\x96D,\x1E\xC0\xB2\x98O\x9A\xF5\x1AS"... to UTF-16
[!] string size(9490) > stringtable size(352). truncated to 350
[!] cannot convert "\xFC\xC2\x87\x13Ab]\x95\xA2\x03\xD5\x1C\\db^"... to UTF-16
[!] string size(55158) > stringtable size(396). truncated to 394
[!] cannot convert "/U\xFF\b\xE5\xB6\xAE\xAAj\x8A\x92Z\xB5\xE3\xECx"... to UTF-16
[!] string size(8112) > stringtable size(640). truncated to 638
[!] cannot convert "\x80\xF8\x0F\x80\xF8\x0F\x80\xF8\x0F\x80\xF8\x0F\x81\xA1C\xF5"... to UTF-16
[!] string size(69360) > stringtable size(892). truncated to 890
[!] cannot convert "\x91\xA8<nc\xD3\xAD\x8C\x19\xC4`e~\xDF\x11\x98"... to UTF-16
[!] string size(68380) > stringtable size(1524). truncated to 1522
[!] cannot convert "N\xFFrgj\xE6\xC5o\xF8\xA8s \xEC\xEC\x9Cb"... to UTF-16
[!] cannot convert "\xF0\x1F\x03h<_\xC2\x1AJ\xCD\xB5U\x8F\xF9\xA04"... to UTF-16
[!] string size(18160) > stringtable size(740). truncated to 738
[!] cannot convert "\xF5v>\xCC\x9F\xB3Sgd!\x8113\x9A\xEAb"... to UTF-16
[!] string size(113126) > stringtable size(1064). truncated to 1062
[!] cannot convert "\t\xD9\n\x8A\n\b\x19~)\xE5<\x0E\xF8\xE2\x14\x00"... to UTF-16
[!] string size(124500) > stringtable size(972). truncated to 970
[!] cannot convert "\xD4\xD8s\xBFiR4\xD93\x86\x91\x1D\x9F\xDAM\xED"... to UTF-16
[!] string size(57506) > stringtable size(1172). truncated to 1170
[!] cannot convert "\xB5\xFB3D\xA7\xB4\xEC&6OX\xC0?V\xB2\xCE"... to UTF-16
[!] string size(110368) > stringtable size(1268). truncated to 1266
[!] cannot convert "w\xCET\x87\x92~\xFD5\x84U\x17\xCC\x9079o"... to UTF-16
[!] string size(82020) > stringtable size(1296). truncated to 1294
[!] cannot convert "=\f\xB3\x8Eq\xEA(E\xD5\xDD;*\xDC\xF7\xFD\x87"... to UTF-16
[!] string size(112216) > stringtable size(1004). truncated to 1002
[!] cannot convert "\xEA3t\xB4\xF6jYnt\x8F\xC1\xAE\\\xB5\"\xBD"... to UTF-16
[!] string size(15944) > stringtable size(696). truncated to 694
[!] cannot convert "0\xB19\xCB3z\xCF\xD3\xBB\x82\x91}\x96\\\x13\xD0"... to UTF-16
[!] string size(87302) > stringtable size(1008). truncated to 1006
[!] cannot convert "\x13\x13\xA9\x92&n6q\xCE\xCF\xE7bTc*\xB6"... to UTF-16
[!] string size(95242) > stringtable size(1036). truncated to 1034
[!] cannot convert "\x1Ed\xC9\xACj}\x96\xD6\x12\xFDV\\b\xC0g;"... to UTF-16
[!] string size(68146) > stringtable size(800). truncated to 798
[!] cannot convert "\xE4\xCCt\xBAo\x1DJ\x90\xAE65*\x97\xBAFO"... to UTF-16
[!] string size(42210) > stringtable size(1096). truncated to 1094
[!] cannot convert "\xDC\xE0\xF2\xF9\xEA\x12\xD1\xDF\xC7\xD7\xB6\x11r\n\xC62"... to UTF-16
[!] string size(126748) > stringtable size(932). truncated to 930
[!] cannot convert "I\e\xDC\xEF0?\x9DK\xF7\xAB\xFFb\"\x80\x89`"... to UTF-16
[!] string size(130114) > stringtable size(972). truncated to 970
[!] cannot convert "\x81y\xA1\x91I\xB1Iq\xB3y\xB1\x7F\xEAI\xEF\b"... to UTF-16
[!] string size(27426) > stringtable size(700). truncated to 698
[!] cannot convert "Ao\xB3p|G\xE2K\x1D\xFB0x\xB0H\x1F\xE4"... to UTF-16
[!] string size(53768) > stringtable size(1032). truncated to 1030
[!] cannot convert "\xBD\xE5\x7F!\xFB\x95.<\x13\xB7\n{g\xBD\xEB\a"... to UTF-16
[!] string size(100316) > stringtable size(1204). truncated to 1202
[!] cannot convert "\xF5\x1E}H~?\xCF\xFAa\x82\xD0k\xAF\xE3i'"... to UTF-16
[!] string size(111420) > stringtable size(752). truncated to 750
[!] cannot convert "G\xFB\xAF9V\xACT\xCD\x89\xD4a\xBDj\xB7g\xD5"... to UTF-16
[!] string size(121110) > stringtable size(1008). truncated to 1006
[!] cannot convert "#\x92\xCD\x13WG$\xDC\x17?{\x88\x85Ft\x96"... to UTF-16
[!] string size(61020) > stringtable size(292). truncated to 290
[!] cannot convert "\x8Df\nX\xD3\x83\xC1\x04\xEF\xA8\xFB\v-\x9F\xBE\x18"... to UTF-16
[!] string size(61222) > stringtable size(212). truncated to 210
[!] cannot convert "6\xF7\xF7\xDDu4?\rwc\x90}*V$8"... to UTF-16
[!] string size(59950) > stringtable size(708). truncated to 706
[!] cannot convert "\x94$\x06\x01:EQ\e\x03\xBA{\x83\xDDJX\xF4"... to UTF-16
[!] string size(43680) > stringtable size(328). truncated to 326
[!] cannot convert "r\x84\xB2\x94W\xE4\xD54\xBA\x06\xC83\xA2Q\xB4|"... to UTF-16
[!] string size(92964) > stringtable size(1040). truncated to 1038
[!] cannot convert "\xB0\vl\xAAA\x06\xA6\x8C\x14\xC9L\xD4c\x9A\x90`"... to UTF-16
[!] string size(44388) > stringtable size(996). truncated to 994
[!] cannot convert "5\xA9\x96\xA6R\x96\xE0\xF3\xA6\xDC\xD5\xDB\x9B\xE5d4"... to UTF-16
[!] string size(109588) > stringtable size(916). truncated to 914
[!] cannot convert ")\x90|\xF7\xEB\x1A2\v\xE2\xAD\xAA\x81\xA1\x05\xF2\xFF"... to UTF-16
[!] string size(112844) > stringtable size(1480). truncated to 1478
[!] cannot convert "a\x8A\xDE\xD1\x89\xEEun&\x99\xE0\xAB\xA1\xC8\xA6\x8A"... to UTF-16
[!] string size(108768) > stringtable size(980). truncated to 978
[!] cannot convert "\xB9\xAE\x86\x8F0\x85\x00\xC5R\xDF\xC9\x9F\t\x93\xA5c"... to UTF-16
[!] string size(45046) > stringtable size(764). truncated to 762
[!] cannot convert "mi\xB6\x15\xB8a\x9B\xEB\xB4+\x8E\xD7T\xD5\x9D)"... to UTF-16
[!] string size(74818) > stringtable size(916). truncated to 914
[!] cannot convert "M\xE2.\xD5\x12\x9F\xAFR\xCC\xB1]+\x119]c"... to UTF-16
[!] string size(122882) > stringtable size(968). truncated to 966
[!] cannot convert "\x1F\x01\xF0\x1F\x01\xF0\x1F\x01\xF0\x1F\b\xF4\xFC\x1C\xCES"... to UTF-16
[!] string size(41762) > stringtable size(588). truncated to 586
[!] cannot convert "\x1F\x8D\x02\xC0\vF\x9D\xF8N\xD0\xD3\x8B~\xF8\xD9\n"... to UTF-16
[!] string size(126644) > stringtable size(184). truncated to 182
[!] cannot convert "{\xB12s/[\xD6\x89\x04\x88\x8D\xA0D\x7F\x95L"... to UTF-16
[!] string size(103742) > stringtable size(240). truncated to 238
[!] cannot convert "\xF1\xF3^\xD8Q\xC5\xD9\xD0{\xB7\x03j;\xEBb\xD0"... to UTF-16
[!] string size(77522) > stringtable size(832). truncated to 830
[!] cannot convert "\x8F\x10\x99\x19C\xCFu\x04\xF3+S9\xF7\"\xF3o"... to UTF-16
[!] string size(62986) > stringtable size(1152). truncated to 1150
[!] cannot convert "\xAD\xC7\xA3\x93\x99\x83\xED\x9A\xB8\nz\xA6\xCF\xC5\xA2\xAC"... to UTF-16
[!] string size(41448) > stringtable size(876). truncated to 874
[!] cannot convert "\x13\x1A\xB8A\xAF.\x1E\xDAM\x96\x0Eh\x17|\xA8a"... to UTF-16
[!] string size(73868) > stringtable size(756). truncated to 754
[!] cannot convert "X\x06p\x00\x01#\x00\x00\x90\xB2\x10\x99]\xE1!x"... to UTF-16
[?] can't find file_offset of VA 0x81a9e4
[?] can't find file_offset of VA 0x81c158
[?] can't find file_offset of VA 0x81db28
[?] can't find file_offset of VA 0x821054
[?] can't find file_offset of VA 0x821b2c
[?] can't find file_offset of VA 0x822640
[?] can't find file_offset of VA 0x822960
[?] can't find file_offset of VA 0x8247c4
[?] can't find file_offset of VA 0x82682c
[?] can't find file_offset of VA 0x82b6b8
[?] can't find file_offset of VA 0x82d9c4
[?] can't find file_offset of VA 0x82e330
[?] can't find file_offset of VA 0x8318f8
[?] can't find file_offset of VA 0x831f3c
[?] can't find file_offset of VA 0x832320
[?] can't find file_offset of VA 0x835b64
[?] can't find file_offset of VA 0x836fcc
[?] can't find file_offset of VA 0x837668
[?] can't find file_offset of VA 0x83e770
[?] can't find file_offset of VA 0x83ef98
[?] can't find file_offset of VA 0x83f8a8
[?] can't find file_offset of VA 0x83fd44
[?] can't find file_offset of VA 0x842720
[?] can't find file_offset of VA 0x844160
[?] can't find file_offset of VA 0x844494
[?] can't find file_offset of VA 0x845a18
[?] can't find file_offset of VA 0x84613c
[?] can't find file_offset of VA 0x84776c
[?] can't find file_offset of VA 0x848080
[?] can't find file_offset of VA 0x8800b4
[?] can't find file_offset of VA 0x880ae4
[?] can't find file_offset of VA 0x880d64
[?] can't find file_offset of VA 0x880ef8
[?] can't find file_offset of VA 0x8811f8
[?] can't find file_offset of VA 0x881574
[?] can't find file_offset of VA 0x88193c
[?] can't find file_offset of VA 0x8c39b0
[?] can't find file_offset of VA 0x8c516c
[?] can't find file_offset of VA 0x8c8784
[?] can't find file_offset of VA 0x8da970
[?] can't find file_offset of VA 0x8dad14
[?] can't find file_offset of VA 0x8dddf0
[?] can't find file_offset of VA 0x8df1ec
[?] can't find file_offset of VA 0x8df530
[?] can't find file_offset of VA 0x8e4ac0
[?] can't find file_offset of VA 0x8e847c
[?] can't find file_offset of VA 0x8ebb70
[?] can't find file_offset of VA 0x8f19ec
[?] can't find file_offset of VA 0x8f1f88
[?] can't find file_offset of VA 0x8f29a4
[?] can't find file_offset of VA 0x8f353c
[?] can't find file_offset of VA 0x8f38c0
[?] can't find file_offset of VA 0x8f89e4
[?] can't find file_offset of VA 0x8f8c30
[?] can't find file_offset of VA 0x8fe0ac
[?] can't find file_offset of VA 0x901628
[?] can't find file_offset of VA 0x904484
[?] can't find file_offset of VA 0x90749c
[?] can't find file_offset of VA 0x90b69c
[?] can't find file_offset of VA 0x90d134
[?] can't find file_offset of VA 0x90d990
[?] can't find file_offset of VA 0x91003c
[?] can't find file_offset of VA 0x911868
[?] can't find file_offset of VA 0x912014
[?] can't find file_offset of VA 0x9124f4
[?] can't find file_offset of VA 0x9127fc
[?] can't find file_offset of VA 0x917ac0
[?] can't find file_offset of VA 0x917f54
[?] can't find file_offset of VA 0x9183f8
[?] can't find file_offset of VA 0x9223c4
[?] can't find file_offset of VA 0x924ea4
[?] can't find file_offset of VA 0x925418
[?] can't find file_offset of VA 0x928b44
[?] can't find file_offset of VA 0x928fd8
[?] can't find file_offset of VA 0x929244
[?] can't find file_offset of VA 0x929608
[?] can't find file_offset of VA 0x929b50
[?] can't find file_offset of VA 0x929f74
[?] can't find file_offset of VA 0x92a4e0
[?] can't find file_offset of VA 0x92a800
[?] can't find file_offset of VA 0x92ce3c
[?] can't find file_offset of VA 0x92e6f8
[?] can't find file_offset of VA 0x92f688
[?] can't find file_offset of VA 0x944e04
[?] can't find file_offset of VA 0x94981c
[?] can't find file_offset of VA 0x94b248
[?] can't find file_offset of VA 0x94b25c
[?] can't find file_offset of VA 0x94b270
[?] can't find file_offset of VA 0x94b284
[?] can't find file_offset of VA 0x94b298
[?] can't find file_offset of VA 0x94b2ac
[?] can't find file_offset of VA 0x94b2c0
[?] can't find file_offset of VA 0x94b2d4
[?] can't find file_offset of VA 0x94b2e8
[?] can't find file_offset of VA 0x94b2fc
[?] can't find file_offset of VA 0x94b310
[?] can't find file_offset of VA 0x94b324
[?] can't find file_offset of VA 0x94b338
[?] can't find file_offset of VA 0x94b34c
[?] can't find file_offset of VA 0x94b360
[?] can't find file_offset of VA 0x94b374
[?] too many errors getting resource data, stopped on 0 of 1
[?] can't find file_offset of VA 0x0