| filename | zVer.exe | |
|---|---|---|
| size | 328704 (0x50400) | |
| md5 | c1b4d9ba240073cfd1086a7e25ab814f | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xf8 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 12 | 7291 | 4 |
| 14 | 7299 | 43 |
| 10 | 9782 | 200 |
| 11 | 9782 | 91 |
| 19 | 8022 | 44 |
| 1 | 0 | 609 |
| 19 | 8034 | 23 |
| 11 | 8168 | 88 |
| 10 | 8168 | 27 |
| 0 | 0 | 72 |
| 6 | 1735 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
UPX Modified >> *$igBy Ahmed18 This file is packed with UPX. Analysis will be incomplete without unpacking. |
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| UPX0 | 0x1000 | 0x89000 | 0 | RWX UDATA | |
| UPX1 | 0x8a000 | 0x4e000 | 0x4dc00 | RWX IDATA | |
| .rsrc | 0xd8000 | 0x3000 | 0x2400 | RW- IDATA |
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0 | 0 | |
| IMPORT | 0xda09c | 0x334 | |
| RESOURCE | 0xd8000 | 0x209c | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0 | 0 | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0 | 0 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0 | 0 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| id | lang | string |
|---|---|---|
| 61440 | 2052 | 炖륒ⵢ㋑㏑㭧ⶵⰭ褷漵ꑱ胕枔㔞궛赶㾯ቷᣄ䧘敧㐶研㋉䁄譻睏э⧭龱竒潄ܗ孂輛弽 |
| 61456 | 2052 | 횑츁奥蕧勓࿂౮Ὠ콦䑉呁普Ȥ⊑࢈䶾晻⥗䗞䕤 |
| 61472 | 2052 | 37 bd 10 da 5b b9 37 1a 40 a7 0f 69 7e 5f 75 70 |7...[.7.@..i~_up| 7f 5f 0f d9 93 bb 98 2f 29 e1 35 5f ca 1a 05 4c |._...../).5_...L| 0a ed 07 5a 2b 7a be af 87 f7 54 f0 85 d3 8c 77 |...Z+z....T....w| dc 7a 47 62 ab 90 e9 63 75 81 09 4d 34 2b 2c c4 |.zGb...cu..M4+,.| 29 87 04 61 4f 58 64 6e 1a 22 89 5b d6 b2 6c 15 |)..aOXdn.".[..l.| 67 90 08 9b 9e c1 05 fa 20 27 81 3d 04 07 07 07 |g....... '.=....| 87 47 5d 50 77 48 eb aa 84 61 d0 f9 94 2b a4 f6 |.G]PwH...a...+..| 46 db 4e 55 4c 4c 4f a7 |F.NULLO. | |
| 61696 | 2052 | 6d 84 c8 85 bb af 4f 84 19 ac 21 58 67 86 09 66 |m.....O...!Xg..f| 3f ad 6b d6 94 5f 55 3a 7f 72 5f 49 4d ad 05 ec |?.k.._U:.r_IM...| ff 41 47 45 5f 56 45 52 53 49 4f 4e 7f b2 f3 16 |.AGE_VERSION....| 03 1b 23 c3 61 b8 70 0f c7 00 09 5e 79 82 60 05 |..#.a.p....^y.`.| 07 0b 39 e5 3f 46 2c a8 50 20 b6 68 9d 3d 08 b1 |..9.?F,.P .h.=..| 00 c1 25 67 6a 82 2d 39 11 4f 5b 18 3b e0 f6 13 |..%gj.-9.O[.;...| 2d 2c 70 5d 3a 9e 1d 75 46 6f 8f ff 06 63 6b 67 |-,p]:..uFo...ckg| 72 13 9e 26 02 6c a4 76 20 28 e3 29 74 40 6b 25 |r..&.l.v (.)t@k%| 4f 0f df 6a 16 6a 15 6f f5 51 b5 20 68 7f c4 38 |O..j.j.o.Q. h..8| 67 28 42 41 44 20 51 43 8a 3d 5c 9e 19 93 a7 1c |g(BAD QC.=\.....| d6 75 48 20 97 16 4c c1 91 01 55 8d 3a 3c 98 01 |.uH ..L...U.:<..| 2f a8 44 d6 04 72 b4 db 06 47 8f 1e 62 2d 4c 70 |/.D..r...G..b-Lp| 68 61 4b da 02 e4 1b 4f 2b df a5 da 15 86 5b 9c |haK....O+.....[.| 5d df 40 e0 12 ad 4e 61 4b 8f 79 81 4b 35 0b 8e |].@...NaK.y.K5..| 4b 97 c1 a0 e0 2e 00 4f 5b 31 36 31 1c 13 05 df |K......O[161....| 47 38 77 61 9b b9 6c ed 08 19 e0 06 12 d1 3a 0c |G8wa..l.......:.| 76 2e f0 32 7d 8d c0 07 4c 58 84 10 95 f8 f3 2f |v..2}...LX...../| 1e 6e c2 62 95 b0 2a 0c 63 8d 17 9a 0d 38 76 1f |.n.b..*.c....8v.| 3f d2 41 c6 a2 11 24 4f ad 8a d2 dc e2 07 7f 47 |?.A...$O.......G| bb 0a 4d b8 da 97 75 57 54 6b 80 2d 17 5c c9 21 |..M...uWTk.-.\.!| c1 30 e3 60 a7 af 73 a7 89 dd 39 02 dd 73 77 e6 |.0.`..s...9..sw.| 4b 85 45 ab 01 17 37 66 10 08 cc e6 80 1c 56 94 |K.E...7f......V.| e7 85 b6 0a a5 27 a3 c5 10 26 ac ef e5 c7 38 ba |.....'...&....8.| d0 ee 38 2d 32 71 d3 2f c0 c2 62 37 4f 61 fb 73 |..8-2q./..b7Oa.s| 6f 71 ea 0e f6 b4 4a 06 57 20 90 3c 6d e7 61 b1 |oq....J.W . |
| 61712 | 2052 | df 0f bf 87 30 d6 d6 7a cb f5 d0 a1 47 c5 b4 a7 |....0..z....G...|
67 1f ea 08 df af cf c2 0f c9 cf 1d 81 95 22 16 |g.............".|
ca 16 d2 41 84 17 77 c1 e5 7b 66 6a 01 e0 82 4a |...A..w..{fj...J|
0f d8 80 3e ae bd 86 32 0e 01 c8 0f 10 c0 0e 6b |...>...2.......k|
cf c8 b2 87 0f 02 b0 0f f6 04 f6 9e 20 a8 0e c0 |............ ...|
00 76 1f 20 13 dc 09 be 98 7f ff 86 0e 0c 8e 0f |.v. ............|
ae bd ef da 10 80 0e 1c 00 78 0f 02 70 0f bf f6 |.........x..p...|
da 7b 20 68 0f 10 60 7f 0e 58 1e 58 30 e0 5d ab |.{ h..`..X.X0.].|
b4 ca 00 50 e0 7e 48 e0 ae 40 cf 60 34 5f 53 69 |...P.~H..@.`4_Si|
5e 38 a8 30 1e d8 d8 28 ad 7b de f6 ec 00 00 20 |^8.0...(.{..... |
ae 90 18 5f 88 0e 10 33 0f a6 75 7f a0 6e 08 f8 |..._...3..u..n..|
c0 6f ad 6b ef 81 5e f8 81 0e 50 10 f0 0f 80 2e |.o.k..^...P.....|
e8 a7 be b0 75 0e 3e c9 ee bb 77 a1 1e d9 bd dc |....u.>...w.....|
bd ba ec 0f cc d2 b3 c8 bb 77 cf be ed bc c7 e0 |.........w......|
c0 b6 4a c2 cc 3f ec 1f d7 cf c9 ec c8 ca bb ab |..J..?..........|
5f d2 f8 b0 d7 c4 db b7 db 7f 9c dd cb b6 1a ba |_...............|
d6 7f 6f 3e 7f b2 d8 76 cf 32 8b 0a ef 7a 8f 5e |..o>...v.2...z.^|
0f 9c 9d 59 76 c6 b7 7f 0a 1f d1 de 82 0f 76 e4 |...Yv.........v.|
76 cf 7a 1f 6e 5f d2 c7 b3 8f |v.z.n_.... |
|
| 61728 | 2052 | e0 59 da bf 2e 7f ff b3 20 ed 0d be 7f fe ab 1f |.Y...... .......| ba f5 ad b1 b2 da 7f 36 55 01 00 3e a6 a1 42 6f |.......6U..>..Bo| 32 a6 a5 82 5e aa 8b 92 69 ac 8e 35 20 f7 0a 49 |2...^...i..5 ..I| 45 78 ad f9 47 d6 55 69 19 b4 3f cd 3f d0 72 b4 |Ex..G.Ui..?.?.r.| be de 52 3a 43 e7 74 c3 4c df 54 6a 76 20 b7 96 |..R:C.t.L.Tjv ..| 7a e8 2a de 72 c0 bd 68 6f b5 60 37 f2 3b 00 4f |z.*.r..ho.`7.;.O| ad 05 0b 85 ff 02 d0 08 b1 46 99 fa fc 4b db ed |.........F...K..| be 74 c2 e2 f7 4c 2f 4c d8 ec 75 68 9a c8 33 ef |.t...L/L..uh..3.| e0 89 47 21 67 1d 58 58 70 63 ae 9f 60 09 ab 81 |..G!g.XXpc..`...| b6 20 f7 48 93 46 60 cb 3d 93 06 da 7d da 3a 1c |. .H.F`.=...}.:.| f9 4f 6e 27 f8 ac 03 15 62 65 1a 6f 72 53 5f 29 |.On'....be.orS_)| f4 cc 36 23 5f 66 96 34 de 72 4c 72 c0 bc b1 23 |..6#_f.4.rLr...#| a1 48 6a 78 e8 a5 54 ba a0 75 63 01 03 3d 64 2f |.Hjx..T..uc..=d/| 16 b8 20 f7 5b 14 a8 30 5e 2a 72 b1 47 1b 6c 65 |.. .[..0^*r.G.le| 92 79 b5 2d d6 fb 86 62 6e 41 53 43 49 49 24 6e |.y.-...bnASCII$n| 63 07 61 89 6c 5f 5b 3e 52 b7 1b c2 a9 43 df 07 |c.a.l_[>R....C..| 00 b5 70 98 80 c3 02 e4 67 38 3b 44 58 8e a3 61 |..p.....g8;DX..a| 66 b6 58 7c 68 0b 13 98 27 74 52 4e 53 87 d6 a9 |f.X|h...'tRNS...| 90 e7 ff 58 21 e9 92 0a 69 37 c1 6e 8c d7 d7 43 |...X!...i7.n...C| 78 5a 45 88 c0 19 25 ed 6f 1b 1f ce 18 f7 d6 74 |xZE...%.o......t| ff 71 89 b4 d7 e9 |.q.... | |
| 61824 | 2052 | 6b 65 79 77 ad 00 c5 6b f8 64 17 9f 81 17 33 56 |keyw...k.d....3V| 8f c7 65 78 6a 35 6c cc 50 6b 44 89 8d 54 ad 55 |..exj5l.PkD..T.U| d7 f7 62 45 c7 5a ef 2d 57 d8 16 e9 81 98 d5 7a |..bE.Z.-W......z| 73 11 02 07 1b b5 c6 de 69 6d 07 49 bf ec 64 08 |s.......im.I..d.| |
| 61840 | 2052 | 71 86 71 75 69 02 db ec c1 0c b7 75 28 bf 47 a5 |q.qui......u(.G.| b5 55 b6 1b 27 c3 b1 9e 4c 66 64 f5 35 c6 b1 c1 |.U..'...Lfd.5...| 08 86 46 d8 80 4b 2d 06 a3 ad cf 30 86 77 23 9b |..F..K-....0.w#.| 75 63 1a 0c 58 53 cf 02 15 0e b5 3d 41 c3 9a 17 |uc..XS.....=A...| d2 37 e3 57 4d d0 60 10 6b af 98 00 6c 5f 78 c1 |.7.WM.`.k...l_x.| 97 57 d0 c5 b3 c6 1f 63 4f b4 10 57 f8 d3 3f 77 |.W.....cO..W..?w| e8 05 6c 89 |..l. | |
| 61856 | 2052 | 3b 29 8f 2d 62 db 42 55 22 69 0e 39 27 93 cc d2 |;).-b.BU"i.9'...|
5e 89 cf b6 2c af cb 88 01 c5 5f 21 14 c1 70 0c |^...,....._!..p.|
0b e6 41 6e 3f 01 57 80 22 e7 67 48 a3 63 82 d3 |..An?.W.".gH.c..|
00 f7 2f 38 2a c3 6e 3f bd bc a9 c8 0d 00 19 37 |../8*.n?.......7|
a7 be 1e 07 d0 63 58 24 76 77 b1 ea d6 9a 50 20 |.....cX$vw....P |
5d 4b 3b 50 72 02 8e d4 7a 73 c3 53 bd 0b 2e fa |]K;Pr...zs.S....|
da 5f de 65 70 5f 19 5f 4f 20 db 9c 35 12 53 86 |._.ep_._O ..5.S.|
95 2b 7b 97 ec 52 43 b6 c5 34 29 ec d2 60 d9 f5 |.+{..RC..4)..`..|
49 6b e3 d6 97 16 c9 6f cf 23 de a2 78 47 9f 95 |Ik.....o.#..xG..|
bf 2b 71 25 08 2c 94 6c 13 2e 9c b4 02 c7 21 3f |.+q%.,.l......!?|
54 69 1b 01 05 37 29 19 8a 06 1b 47 ea 67 62 94 |Ti...7)....G.gb.|
51 9b a6 7f 54 47 61 b6 b5 a0 7a 05 45 7f 9d 02 |Q...TGa...z.E...|
6b 69 7f 5b 7e ac 00 80 71 39 79 97 1f 76 04 77 |ki.[~...q9y..v.w|
e8 1d 47 48 13 b0 2e 60 5c 3d f7 83 d9 35 0e fd |..GH...`\=...5..|
eb 6c e6 87 c9 51 eb c6 3b 4d 00 c3 42 ad 9f b5 |.l...Q..;M..B...|
04 04 77 8b e0 13 29 fa 32 36 aa 03 c6 be 7f 57 |..w...).26.....W|
a5 20 ea 6c 6b 15 d1 32 03 7b 63 35 2b 1e 0c 38 |. .lk..2.{c5+..8|
1e 07 1f 8b 74 f0 41 8d 40 c1 63 85 ab 87 6d b8 |....t.A.@.c...m.|
9a 47 65 69 29 58 37 45 26 0a 1c a4 b6 83 7f 09 |.Gei)X7E&.......|
c0 0a 6c c6 2b 1b 19 ab 80 b3 bf d1 49 e2 d6 02 |..l.+.......I...|
ed 48 5f e6 5f e2 71 97 20 47 58 cf ff 00 2d 34 |.H_._.q. GX...-4|
8c 05 36 6f 63 47 87 00 bb b0 23 dd df 36 cb 8d |..6ocG....#..6..|
50 67 2b 49 2b 6b 49 1e 58 9b 2b a9 bf 60 56 18 |Pg+I+kI.X.+..`V.|
eb 9f 8e 85 ce 05 ca ac 09 7d 65 d5 2f 8c 04 03 |.........}e./...|
b4 b0 5f 60 5c 13 1f 8f fb 04 1f 42 ee 25 38 d6 |.._`\......B.%8.|
5a d8 3d 30 47 bb bf f0 d6 d1 3b 18 6e 1b f3 ee |Z.=0G.....;.n...|
77 6f 04 02 ed 81 be f1 61 86 57 a3 87 62 8c 08 |wo......a.W..b..|
97 d0 83 c2 42 bd 7e fb 35 b1 c6 30 d0 cd 85 00 |....B.~.5..0....|
18 58 11 42 c7 be 6c 6c 85 b5 41 00 36 4b 57 2c |.X.B..ll..A.6KW,|
c5 41 ba d3 07 79 6f 09 |.A...yo. |
|
| 61872 | 2052 | 00 16 5a 6e 88 b5 2e ad 6f db 87 0a 5b ed d2 ef |..Zn....o...[...| 15 2c 20 81 fd 62 d3 ea 09 59 73 6b 69 82 32 cf |., ..b...Yski.2.| 20 c1 00 9f 1b 63 30 62 4f 5f 41 bb 4f 1d 07 1e | ....c0bO_A.O...| 30 10 09 00 05 12 ed aa 4f 73 47 d0 17 52 84 da |0.......OsG..R..| 73 8f 9c 9b 15 7c 20 05 df b1 25 8b 08 6f 6d 47 |s....| ...%..omG| 31 61 60 22 42 68 3f cf 4d 41 88 d7 90 3d 77 66 |1a`"Bh?.MA...=wf| 61 3c bb ab d2 15 c8 68 0c 11 73 7a 97 83 2d 82 |a<.....h..sz..-.| 4b 1b af 27 b1 60 ed 08 af 27 e7 70 21 b4 54 77 |K..'.`...'.p!.Tw| 1f 21 46 b7 46 84 c9 af c7 68 8d c8 37 51 26 d4 |.!F.F....h..7Q&.| c2 80 45 89 01 47 a5 5d 0f d3 99 73 17 17 71 09 |..E..G.]...s..q.| 21 c6 39 b0 4b 11 18 21 3e 4f 47 14 61 8c 97 15 |!.9.K..!>OG.a...| a3 f4 9c 73 1b b1 1c 5d 01 8a 5f 1f 72 21 5a 04 |...s...].._.r!Z.| 49 9f 37 6f 05 6e 84 0b 1b 2f 71 6d 10 21 05 2f |I.7o.n.../qm.!./| f9 a3 11 06 5b 0b 6f 51 d7 d8 5e a3 18 7d 60 ff |....[.oQ..^..}`.| 6e 82 5d 4c cd 00 2f 20 16 3d 01 20 03 65 86 20 |n.]L../ .=. .e. | 45 85 89 9d 00 6f 0c da ca a5 b5 39 fe 57 85 da |E....o.....9.W..| 82 11 81 1b 5f f8 a3 6c 85 78 15 c0 ce c7 eb ca |...._..l.x......| e4 47 e1 1f |.G.. | |
| 61888 | 2052 | 붵蔒藞⣶搥Э倩氥╤쌆౫䫿䕐䵇䵅 |
| module_name | hint | ord | function_name |
|---|---|---|---|
| KERNEL32.DLL | LoadLibraryA | ||
| KERNEL32.DLL | GetProcAddress | ||
| KERNEL32.DLL | VirtualProtect | ||
| KERNEL32.DLL | VirtualAlloc | ||
| KERNEL32.DLL | VirtualFree | ||
| KERNEL32.DLL | ExitProcess | ||
| ADVAPI32.dll | RegCloseKey | ||
| COMCTL32.dll | 17 | ||
| comdlg32.dll | ChooseColorA | ||
| GDI32.dll | PatBlt | ||
| ole32.dll | OleInitialize | ||
| OLEAUT32.dll | 161 | ||
| RASAPI32.dll | RasHangUpA | ||
| SHELL32.dll | ShellExecuteA | ||
| USER32.dll | GetDC | ||
| WININET.dll | InternetOpenA | ||
| WINMM.dll | waveOutOpen | ||
| WINSPOOL.DRV | OpenPrinterA | ||
| WS2_32.dll | 1 |
StringTable 080404B0
| FileVersion | 1.0.0.0 |
| FileDescription | Windows资源管理器 |
| ProductName | Automatically |
| ProductVersion | 1.0.0.0 |
| LegalCopyright | 作者版权所有 请尊重并使用正版 |
| Comments | 本程序使用易语言编写(http://www.eyuyan.com) |
VS_FIXEDFILEINFO
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| StrucVersion | 0 |
| FileFlagsMask | 0 |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[!] string size(50270) > stringtable size(80). truncated to 78
[!] string size(98630) > stringtable size(44). truncated to 42
[!] string size(96878) > stringtable size(120). truncated to 118
[!] cannot convert "\x10\xDA[\xB97\x1A@\xA7\x0Fi~_up\x7F_"... to UTF-16
[!] string size(67802) > stringtable size(452). truncated to 450
[!] cannot convert "\xC8\x85\xBB\xAFO\x84\x19\xAC!Xg\x86\tf?\xAD"... to UTF-16
[!] string size(8126) > stringtable size(298). truncated to 296
[!] cannot convert "\xBF\x870\xD6\xD6z\xCB\xF5\xD0\xA1G\xC5\xB4\xA7g\x1F"... to UTF-16
[!] string size(46016) > stringtable size(326). truncated to 324
[!] cannot convert "\xDA\xBF.\x7F\xFF\xB3 \xED\r\xBE\x7F\xFE\xAB\x1F\xBA\xF5"... to UTF-16
[!] string size(51926) > stringtable size(64). truncated to 62
[!] cannot convert "yw\xAD\x00\xC5k\xF8d\x17\x9F\x81\x173V\x8F\xC7"... to UTF-16
[!] string size(68834) > stringtable size(100). truncated to 98
[!] cannot convert "qui\x02\xDB\xEC\xC1\f\xB7u(\xBFG\xA5\xB5U"... to UTF-16
[!] string size(21110) > stringtable size(472). truncated to 470
[!] cannot convert "\x8F-b\xDBBU\"i\x0E9'\x93\xCC\xD2^\x89"... to UTF-16
[!] string size(11264) > stringtable size(276). truncated to 274
[!] cannot convert "Zn\x88\xB5.\xADo\xDB\x87\n[\xED\xD2\xEF\x15,"... to UTF-16
[!] string size(23702) > stringtable size(36). truncated to 34
[!] refusing to read CURDIRENTRY beyond resource size
[!] refusing to read ICODIRENTRY beyond resource size
offset:( 0x )