filename | adobe.snr.patch.v2.0-painter.exe | |
---|---|---|
size | 601600 (0x92e00) | |
md5 | b31679db7db878992b4553290a9e6c7c | |
type | MS-DOS executable PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MZ for MS-DOS | |
mimetype | application/x-dosexec | |
clamav | Win.Malware.Agent-6365699-0 FOUND | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x40 |
blocks_in_file | 1 |
num_relocs | 0 |
header_paragraphs | 2 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0xa |
overlay_number | 0 |
reserved0 | 0xeba1f0e00000000 |
oem_id | 0xb400 |
oem_info | 0xcd09 |
reserved2 | 0x4c01b821 |
reserved3 | 0x695721cd |
reserved4 | 0x2032336e |
reserved5 | 0x4558452e |
reserved6 | 0x240a0d2e |
lfanew | 0x40 |
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.MPRESS1 | 0x1000 | 0x1a4000 | 0x8b000 | RWX CODE IDATA UDATA | |
.MPRESS2 | 0x1a5000 | 0xed8 | 0x1000 | RWX CODE IDATA UDATA | |
.rsrc | 0x1a6000 | 0x6be4 | 0x6c00 | RW- IDATA |
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x5a5ec8 | 0x5a5ed8 | 0x5a5ebc | 0 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.DLL | GetModuleHandleA | ||
KERNEL32.DLL | GetProcAddress | ||
user32.dll | CharNextA | ||
advapi32.dll | RegCloseKey | ||
oleaut32.dll | SysFreeString | ||
version.dll | VerQueryValueA | ||
gdi32.dll | SaveDC | ||
ole32.dll | CoInitialize | ||
comctl32.dll | ImageList_Add | ||
shell32.dll | SHGetFileInfoA | ||
comdlg32.dll | GetOpenFileNameA |
StringTable 041904b0
CompanyName | PainteR |
FileDescription | Universal Adobe Patcher |
FileVersion | 2.0.0.0 |
InternalName | Universal Adobe Patcher |
LegalCopyright | PainteR |
OriginalFilename | adobesnr.exe |
ProductName | Universal Adobe Patcher |
ProductVersion | 2.0.0.0 |
VS_FIXEDFILEINFO
FileVersion | 2.0.0.0 |
ProductVersion | 2.0.0.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 2 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x15f64c
[?] can't find file_offset of VA 0x173e4c
[?] can't find file_offset of VA 0x173f80
[?] can't find file_offset of VA 0x1740b4
[?] can't find file_offset of VA 0x1741e8
[?] can't find file_offset of VA 0x17431c
[?] can't find file_offset of VA 0x174450
[?] can't find file_offset of VA 0x174584
[?] can't find file_offset of VA 0x1746b8
[?] can't find file_offset of VA 0x1747ec
[?] can't find file_offset of VA 0x1749bc
[?] can't find file_offset of VA 0x174ba0
[?] can't find file_offset of VA 0x174d70
[?] can't find file_offset of VA 0x174f40
[?] can't find file_offset of VA 0x175110
[?] can't find file_offset of VA 0x1752e0
[?] can't find file_offset of VA 0x1754b0
[?] can't find file_offset of VA 0x175680
[?] can't find file_offset of VA 0x175850
[?] can't find file_offset of VA 0x175a20
[?] can't find file_offset of VA 0x175ea8
[?] can't find file_offset of VA 0x175f68
[?] can't find file_offset of VA 0x176048
[?] can't find file_offset of VA 0x176128
[?] can't find file_offset of VA 0x176208
[?] can't find file_offset of VA 0x1762c8
[?] can't find file_offset of VA 0x176388
[?] can't find file_offset of VA 0x176468
[?] can't find file_offset of VA 0x1770c0
[?] can't find file_offset of VA 0x1773e8
[?] can't find file_offset of VA 0x1774a8
[?] can't find file_offset of VA 0x177588
[?] can't find file_offset of VA 0x177670
[?] can't find file_offset of VA 0x177998
[?] can't find file_offset of VA 0x177a58
[?] can't find file_offset of VA 0x177d80
[?] can't find file_offset of VA 0x1780a8
[?] can't find file_offset of VA 0x1783d0
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x17d164
[?] can't find file_offset of VA 0x17d1b8
[?] can't find file_offset of VA 0x17d204
[?] can't find file_offset of VA 0x17d2b0
[?] can't find file_offset of VA 0x17d438
[?] can't find file_offset of VA 0x17d608
[?] can't find file_offset of VA 0x17d74c
[?] can't find file_offset of VA 0x17d7cc
[?] can't find file_offset of VA 0x17d7f0
[?] can't find file_offset of VA 0x17d990
[?] can't find file_offset of VA 0x17db68
[?] can't find file_offset of VA 0x17dd54
[?] can't find file_offset of VA 0x17de40
[?] can't find file_offset of VA 0x17e1b0
[?] can't find file_offset of VA 0x17e270
[?] can't find file_offset of VA 0x17e36c
[?] can't find file_offset of VA 0x17e48c
[?] can't find file_offset of VA 0x17e938
[?] can't find file_offset of VA 0x17eca4
[?] can't find file_offset of VA 0x17f034
[?] can't find file_offset of VA 0x17f464
[?] can't find file_offset of VA 0x17f554
[?] can't find file_offset of VA 0x17f62c
[?] can't find file_offset of VA 0x17f8a0
[?] can't find file_offset of VA 0x17fc80
[?] can't find file_offset of VA 0x180008
[?] can't find file_offset of VA 0x1802e0
[?] can't find file_offset of VA 0x180fa0
[?] can't find file_offset of VA 0x181348
[?] can't find file_offset of VA 0x1820a0
[?] can't find file_offset of VA 0x182db0
[?] can't find file_offset of VA 0x182dc0
[?] can't find file_offset of VA 0x183444
[?] can't find file_offset of VA 0x183878
[?] can't find file_offset of VA 0x183d2c
[?] can't find file_offset of VA 0x183ed0
[?] can't find file_offset of VA 0x184544
[?] can't find file_offset of VA 0x184cf8
[?] can't find file_offset of VA 0x185404
[?] can't find file_offset of VA 0x19fd10
[?] can't find file_offset of VA 0x1a0350
[?] can't find file_offset of VA 0x1a1f40
[?] can't find file_offset of VA 0x1a3f1c
[?] can't find file_offset of VA 0x1a4210
[?] can't find file_offset of VA 0x1a4224
[?] can't find file_offset of VA 0x1a4238
[?] can't find file_offset of VA 0x1a424c
[?] can't find file_offset of VA 0x1a4260
[?] can't find file_offset of VA 0x1a4274
[?] can't find file_offset of VA 0x1a4288
[?] can't find file_offset of VA 0x1a429c