Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2007-Apr-28 08:11:59 |
Detected languages |
English - United States
|
Debug artifacts |
c:\Dev\Xbox360\Xplorer360\Original\Release\Xplorer360.pdb
|
FileDescription | Xbox 360 File Explorer |
FileVersion | 0, 10, 0, 1 |
InternalName | Xplorer360 |
LegalCopyright | Copyright (C) 2006 roofus |
OriginalFilename | Xplorer360.exe |
ProductName | Xplorer360 |
ProductVersion | 0, 10, 0, 1 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ v7.1 EXE Microsoft Visual Basic v5.0 - v6.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | VirusTotal score: 2/64 (Scanned on 2018-04-09 02:14:25) |
Bkav:
W32.eHeur.Malware14
ClamAV: Win.Worm.Bybz-204 |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2007-Apr-28 08:11:59 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0xa000 |
SizeOfInitializedData | 0x11000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00009C80 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1c000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SHELL32.dll |
SHFileOperationA
DragQueryFileA ShellExecuteA SHGetPathFromIDListA SHGetFileInfoA SHBrowseForFolderA |
---|---|
urlmon.dll |
CopyStgMedium
|
SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
SetupDiGetDeviceInterfaceDetailA SetupDiDestroyDeviceInfoList SetupDiGetClassDevsA |
KERNEL32.dll |
GetStartupInfoA
ExitProcess RaiseException GetVersionExA DebugBreak QueryPerformanceCounter GetTickCount CreateFileA GetLogicalDrives GlobalAlloc CreateDirectoryA SetCurrentDirectoryA GlobalFree DeviceIoControl GetCurrentDirectoryA CloseHandle GetTempPathA GetFileSize WaitForSingleObject SetEvent WriteFile CreateEventA ReadFile GetOverlappedResult FindFirstFileA GetLastError ResetEvent FindNextFileA GetFileAttributesA CreateThread GetModuleHandleW LoadLibraryW GetFileAttributesW GetModuleFileNameW SetLastError GetProcAddress LoadLibraryA GetModuleHandleA OutputDebugStringA GetVersion lstrlenA GlobalLock GlobalUnlock InitializeCriticalSection DeleteCriticalSection LeaveCriticalSection EnterCriticalSection CancelIo GetCurrentThreadId GetCurrentProcessId FreeLibrary GetProcessHeap HeapFree GetCurrentProcess GetSystemTimeAsFileTime GetModuleFileNameA HeapAlloc |
USER32.dll |
PeekMessageA
MessageBoxA SetTimer GetDlgCtrlID LoadCursorA CallWindowProcA GetSysColorBrush EndDialog GetDlgItem SetWindowLongA SetPropA RegisterClipboardFormatA GetCursorPos PostQuitMessage SetCapture GetKeyState GetFocus LoadIconA wsprintfA GetClientRect CheckMenuRadioItem EnableMenuItem DefWindowProcA ShowWindow ReleaseCapture RegisterClassA MoveWindow GetMessageA TranslateMessage ChildWindowFromPoint DispatchMessageA SetWindowTextA UpdateWindow DialogBoxParamA SetDlgItemTextA ScreenToClient TrackPopupMenu GetSubMenu GetMenu GetWindowTextA GetWindowLongA CreateWindowExA MsgWaitForMultipleObjectsEx SetCursor GetPropA SendMessageA |
GDI32.dll |
SetTextColor
CreateFontIndirectA SetBkMode DeleteObject SelectObject GetObjectA |
comdlg32.dll |
GetOpenFileNameA
GetSaveFileNameA |
ole32.dll |
RevokeDragDrop
OleInitialize OleUninitialize ReleaseStgMedium CoCreateInstance DoDragDrop RegisterDragDrop |
MSVCR71.dll |
_getcwd
_mkdir time strncmp strlen sprintf strcat _chdir _itoa _controlfp ?terminate@@YAXXZ __security_error_handler _except_handler3 __set_app_type __p__fmode __p__commode _adjust_fdiv __setusermatherr _initterm __getmainargs _amsg_exit _acmdln exit _cexit _ismbblead vsprintf _XcptFilter _exit _c_exit _onexit __dllonexit _snprintf __CxxFrameHandler ??2@YAPAXI@Z ??3@YAXPAX@Z memcmp strcmp strncpy _stat free memcpy strcpy _stricmp localtime memset |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 0.10.0.1 |
ProductVersion | 0.10.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
FileDescription | Xbox 360 File Explorer |
FileVersion (#2) | 0, 10, 0, 1 |
InternalName | Xplorer360 |
LegalCopyright | Copyright (C) 2006 roofus |
OriginalFilename | Xplorer360.exe |
ProductName | Xplorer360 |
ProductVersion (#2) | 0, 10, 0, 1 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2007-Apr-28 08:11:59 |
Version | 0.0 |
SizeofData | 82 |
AddressOfRawData | 0xd470 |
PointerToRawData | 0xd470 |
Referenced File | c:\Dev\Xbox360\Xplorer360\Original\Release\Xplorer360.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40f040 |
SEHandlerTable | 0x40d4d0 |
SEHandlerCount | 6 |
XOR Key | 0xd7b93e77 |
---|---|
Unmarked objects | 0 |
105 (2067) | 5 |
Imports (VS2003 (.NET) build 3077) | 2 |
ASM objects (VS2003 (.NET) build 3077) | 7 |
C objects (VS2003 (.NET) build 3077) | 15 |
C++ objects (VS2003 (.NET) build 3077) | 11 |
Total imports | 175 |
Imports (VS2003 (.NET) build 4035) | 17 |
C objects (VS2003 (.NET) build 4035) | 4 |
100 (VS2003 (.NET) build 3077) | 16 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |