| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2022-Mar-08 08:07:02 |
| Detected languages |
English - United States
Russian - Russia Spanish - Argentina |
| CompanyName | RadiXX11 |
| FileDescription | HD Sentinel 6.x PRO Activator |
| FileVersion | 1.2.0.0 |
| InternalName | Activator.exe |
| LegalCopyright | © 2022, RadiXX11 |
| LegalTrademarks | |
| OriginalFilename | Activator.exe |
| ProductName | HD Sentinel 6.x PRO Activator |
| ProductVersion | 1.2.0.0 |
| Comments |
| Suspicious | PEiD Signature: |
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h) UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser |
| Suspicious | The PE is possibly packed. |
Section CODE is both writable and executable.
Section .text is both writable and executable. |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. |
Resource 1 is possibly compressed or encrypted.
Resource 2 is possibly compressed or encrypted. Resource 3 is possibly compressed or encrypted. Resource 4 is possibly compressed or encrypted. Resource 5 is possibly compressed or encrypted. Resource 6 is possibly compressed or encrypted. Resource 7 is possibly compressed or encrypted. Resource 8 is possibly compressed or encrypted. Resource BBABORT is possibly compressed or encrypted. Resource BBALL is possibly compressed or encrypted. Resource BBCANCEL is possibly compressed or encrypted. Resource BBCLOSE is possibly compressed or encrypted. Resource BBHELP is possibly compressed or encrypted. Resource BBIGNORE is possibly compressed or encrypted. Resource BBNO is possibly compressed or encrypted. Resource BBOK is possibly compressed or encrypted. Resource BBRETRY is possibly compressed or encrypted. Resource BBYES is possibly compressed or encrypted. Resource BLUR5 is possibly compressed or encrypted. Resource CLOSEDFOLDER is possibly compressed or encrypted. Resource CURRENTFOLDER is possibly compressed or encrypted. Resource EXECUTABLE is possibly compressed or encrypted. Resource MENUBTN is possibly compressed or encrypted. Resource METRIC is possibly compressed or encrypted. Resource OPENFOLDER is possibly compressed or encrypted. Resource PREVIEWGLYPH is possibly compressed or encrypted. Resource PS is possibly compressed or encrypted. Resource RASTER is possibly compressed or encrypted. Resource TTF is possibly compressed or encrypted. Resource UNKNOWN is possibly compressed or encrypted. Resource UNKNOWNFILE is possibly compressed or encrypted. Resource 3684 is possibly compressed or encrypted. Resource 3685 is possibly compressed or encrypted. Resource 3686 is possibly compressed or encrypted. Resource 4076 is possibly compressed or encrypted. Resource 4077 is possibly compressed or encrypted. Resource 4078 is possibly compressed or encrypted. Resource 4079 is possibly compressed or encrypted. Resource 4080 is possibly compressed or encrypted. Resource 4081 is possibly compressed or encrypted. Resource 4082 is possibly compressed or encrypted. Resource 4084 is possibly compressed or encrypted. Resource 4085 is possibly compressed or encrypted. Resource 4086 is possibly compressed or encrypted. Resource 4087 is possibly compressed or encrypted. Resource 4088 is possibly compressed or encrypted. Resource 4089 is possibly compressed or encrypted. Resource 4090 is possibly compressed or encrypted. Resource 4091 is possibly compressed or encrypted. Resource 4093 is possibly compressed or encrypted. Resource 4094 is possibly compressed or encrypted. Resource 4095 is possibly compressed or encrypted. Resource 4096 is possibly compressed or encrypted. Resource ACGL is possibly compressed or encrypted. Resource ACHINT is possibly compressed or encrypted. Resource ACMASK1 is possibly compressed or encrypted. Resource ACMASK2 is possibly compressed or encrypted. Resource ACSHDA is possibly compressed or encrypted. Resource ACSHDI is possibly compressed or encrypted. Resource BANNER is possibly compressed or encrypted. Resource CREDITS is possibly compressed or encrypted. Resource ICON is possibly compressed or encrypted. Resource PACKAGEINFO is possibly compressed or encrypted. Resource SC is possibly compressed or encrypted. Resource SD is possibly compressed or encrypted. Resource SE is possibly compressed or encrypted. Resource SF is possibly compressed or encrypted. Resource SR is possibly compressed or encrypted. Resource TABOUTFORM is possibly compressed or encrypted. Resource TMAINFORM is possibly compressed or encrypted. Resource TPATHDIALOGFORM is possibly compressed or encrypted. Resource TSCALCFORM is possibly compressed or encrypted. Resource TSCOLORDIALOGFORM is possibly compressed or encrypted. Resource TSPOPUPCALENDAR is possibly compressed or encrypted. Resource TUPDATECHECKFORM is possibly compressed or encrypted. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2022-Mar-08 08:07:02 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0xa7000 |
| SizeOfInitializedData | 0x9000 |
| SizeOfUninitializedData | 0x12b000 |
| AddressOfEntryPoint | 0x001D1990 (Section: .text) |
| BaseOfCode | 0x12c000 |
| BaseOfData | 0x1d3000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1dc000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0xb1d08 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| advapi32.dll |
FreeSid
|
|---|---|
| comctl32.dll |
ImageList_Add
|
| comdlg32.dll |
GetSaveFileNameA
|
| gdi32.dll |
SaveDC
|
| IMAGEHLP.DLL |
MapAndLoad
|
| KERNEL32.DLL |
LoadLibraryA
ExitProcess GetProcAddress VirtualProtect |
| ole32.dll |
CoInitialize
|
| oleaut32.dll |
VariantCopy
|
| shell32.dll |
SHGetMalloc
|
| user32.dll |
GetDC
|
| version.dll |
VerQueryValueA
|
| winspool.drv |
OpenPrinterA
|
| KNOWNUNKNOWNFILEDLGTEMPLATEACGLACHINTACMASK1ACMASK2ACSHDAACSHDIBANNER |
| CREDITS |
| DVCLAL |
| ICON |
| PACKAGEINFO |
| SC |
| SD |
| SE |
| SF |
| SR |
| TABOUTFORM |
| TMAINFORM |