PE Compile Time

2012-03-23 21:07:01

PE Imphash

44be92e8682bb60864ce3aa523405aa8

PEiD Signatures

BobSoft Mini Delphi -> BoB / BobSoft

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000d004 0x0000d200 4.38143902672
.itext 0x0000f000 0x00016200 0x00016200 0.0565612650545
.data 0x00026000 0x00001388 0x00001400 5.0436872073
.bss 0x00028000 0x00004908 0x00000000 0.0
.idata 0x0002d000 0x000006b2 0x00000800 4.24929229204
.tls 0x0002e000 0x00000008 0x00000000 0.0
.rdata 0x0002f000 0x00000018 0x00000200 0.20448815744
.reloc 0x00030000 0x00000b5c 0x00000c00 6.36942566564
.rsrc 0x00031000 0x000363f4 0x00036400 7.95909704529

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x00031270 0x000354d4 LANG_NEUTRAL SUBLANG_NEUTRAL GIF image data 2957 x
RT_ICON 0x00066744 0x000002e8 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 32 x 64 x 4, image size 512
RT_STRING 0x00067150 0x00000280 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00067150 0x00000280 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00067150 0x00000280 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00067150 0x00000280 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00067150 0x00000280 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000673d0 0x00000010 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000673e0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library oleaut32.dll:
0x42d1a4 SysFreeString
Library advapi32.dll:
0x42d1ac RegQueryValueExA
0x42d1b0 RegOpenKeyExA
0x42d1b4 RegCloseKey
Library user32.dll:
0x42d1bc GetKeyboardType
0x42d1c0 DestroyWindow
0x42d1c4 LoadStringA
0x42d1c8 MessageBoxA
0x42d1cc CharNextA
Library kernel32.dll:
0x42d1d4 GetACP
0x42d1d8 Sleep
0x42d1dc VirtualFree
0x42d1e0 VirtualAlloc
0x42d1e4 GetCurrentThreadId
0x42d1e8 VirtualQuery
0x42d1ec WideCharToMultiByte
0x42d1f0 lstrlenA
0x42d1f4 lstrcpynA
0x42d1f8 LoadLibraryExA
0x42d1fc GetThreadLocale
0x42d200 GetStartupInfoA
0x42d204 GetProcAddress
0x42d208 GetModuleHandleA
0x42d20c GetModuleFileNameA
0x42d210 GetLocaleInfoA
0x42d214 GetCommandLineA
0x42d218 FreeLibrary
0x42d21c FindFirstFileA
0x42d220 FindClose
0x42d224 ExitProcess
0x42d228 WriteFile
0x42d230 RtlUnwind
0x42d234 RaiseException
0x42d238 GetStdHandle
Library kernel32.dll:
0x42d240 TlsSetValue
0x42d244 TlsGetValue
0x42d248 LocalAlloc
0x42d24c GetModuleHandleA
Library user32.dll:
0x42d254 MessageBoxA
0x42d258 LoadStringA
0x42d25c GetSystemMetrics
0x42d260 CharNextA
0x42d264 CharToOemA
Library kernel32.dll:
0x42d26c WriteFile
0x42d270 VirtualQuery
0x42d274 LoadLibraryA
0x42d278 GetVersionExA
0x42d27c GetThreadLocale
0x42d280 GetStdHandle
0x42d284 GetProcAddress
0x42d288 GetModuleHandleA
0x42d28c GetModuleFileNameA
0x42d290 GetLocaleInfoA
0x42d294 GetDiskFreeSpaceA
0x42d298 GetCPInfo
0x42d29c FreeLibrary
0x42d2a0 EnumCalendarInfoA

This program must be run under Win32
`.itext
`.data
.idata
.rdata
@.reloc
B.rsrc
stringX
TObject
FastMM Borland Edition
2004, 2005 Pierre le Riche / Professional Software Development
An unexpected memory leak has occurred.
The unexpected small block leaks are:
bytes:
Unknown
String
The sizes of unexpected leaked medium and large blocks are:
Unexpected Memory Leak
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
ZTUWVSPRTj
tChLH@
kernel32.dll
GetLongPathNameA
Software\Borland\Locales
Software\Borland\Delphi\Locales
_^[YY]
Exception R@
EHeapException
EOutOfMemory
EInOutError0S@
EExternal
EExternalException
EIntError
EDivByZero
ERangeError
EIntOverflow
EMathError
EInvalidOp
EZeroDivideTV@
EOverflow
EUnderflow
EInvalidPointer`W@
EInvalidCast
EConvertError
EAccessViolation
EPrivilege
EStackOverflow
EControlC
EVariantError
EAssertionFailed
EAbstractError
EIntfCastError
ESafecallException
SysUtils
SysUtils
<*t"<0r=<9w9i
INFNAN
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
QQQQQQSVW3
QQQQQSVW
_^[YY]
TErrorRec
TExceptRec
m/d/yy
mmmm d, yyyy
:mm:ss
TUnitHashArray
SysUtils
TModuleInfo
kernel32.dll
GetDiskFreeSpaceExA
Runtime error at 00000000
0123456789ABCDEF
'Sk<B{,,*
T;t@O0v{
NY/{zXY
HMw}?l
NY6&(ubEA
oleaut32.dll
SysFreeString
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
user32.dll
GetKeyboardType
DestroyWindow
LoadStringA
MessageBoxA
CharNextA
kernel32.dll
GetACP
VirtualFree
VirtualAlloc
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
user32.dll
MessageBoxA
LoadStringA
GetSystemMetrics
CharNextA
CharToOemA
kernel32.dll
WriteFile
VirtualQuery
LoadLibraryA
GetVersionExA
GetThreadLocale
GetStdHandle
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetDiskFreeSpaceA
GetCPInfo
FreeLibrary
EnumCalendarInfoA
0,080<0@0D0H0L0P0T0b0j0r0z0
1"1*121:1B1n1v1~1
4%454j4x4
829<9T9Z9r9
9.:K:W:j:s:z:
>>)>B>
0V3a3p3
8'9=9+:1:O:q:|:L;P;V;Z;d;w;{;
;"<*<7<=<K<Z<g<z<
<:=O=\=|=
=$>(>,>0>4>8><>@>D>
31K1\1x1
354E4[4y4
6B7V7^7t7
<8<@<K<w<
=>=B=H=L=Q=X=^=f=q=
>0>:>_>i>s>{>
?&?2?K?
1K3f4o4K6
="=J=t=
>">*>2>:>B>J>R>Z>b>j>r>z>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1x1
202P2X2\2`2d2h2l2p2t2x2
3 3$3(3,3<3\3d3h3l3p3t3x3|3
4 4$4(4,4044484<4L4l4t4x4|4
5 5(5,5054585<5@5D5H5X5x5
6(6064686<6@6D6H6L6P6`6
747<7@7D7H7L7P7T7X7\7p7
8,8L8T8X8\8`8d8h8l8p8t8
9 9$9(989X9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:P:p:x:|:
;!;0;=;E;p;*=
m0q0u0y0}0
4!4)41494
:K:P:j:
;+;G;f;x;
<"<]<}<
=E=^=n=
? ?(?R?c?l?
!0+0u0
3#3+373w3
6Q6c6w6
6"717@7\7
88+81898B8N8S8\8e8n8w8
819O9x9
:6;;;I;R;
<,<5<P<c<v<
=#=7=E=Y=w=
>">7>?>\>i>(?X?q?
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2l2p2x2|2
3 3$3,30383<3D3H3P3T3\3`3h3l3t3x3
4 4(4,44484@4D4S4_4j4t4
5&505;5E5P5Z5`5j5p5z5
00%0)0/060:0T0]0f0r0|0
1;1E1S1
,0L0l0
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9$9,949<9D9L9T9\9d9l9t9
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
IXuI/
Q7~f^6K
K\5_n<
OrxNtN$
~xP;?\
L;d!.s
jF?you'
^?2:Jmh=v
176Ju)
>(iYf4+
Jut&rl
kneIpe
L7^%Bl<
2(ZUA3Zk
i1'Yk@k>
xHpI=v
A_c#%
JuA;>u
iiA[m@H
M)]AA
mgbdi=
zkNrO8
{7Q7On
|Mi^)7
?TeI&V~_+
_pl&~C#T
OYwVj4S
^[V+~e6
\0qY!&
LU@HH2B#mD
+C=hpL
zQmAK>
G>*&h>
|PuOx+
>\q+H[
'g%mT7
Az`#:-!
AtNY#&2
IsX8ax
*Qw<'0
LW-y`k
FUkICS3
"-@_NH
S!Z:f5@
40s@p~
ensP)>
1:[\3_
\igWp5
5$X:3^M
PW\~gyXU/>
c^#y`(
D@n4MeN
W6tHir
RPxiB?
M<Zp3D
=\(s,(>
O>7NFk
}Tt<y^
%2?P0m
Cj!/ef@
Bc(v#)t
W#<.!1=
LpjdOY:(
G!.Y_l@
E(z1i`c
,[ww,+
&/a-%B
;u9QgL
UO$e(h
O/">NU
HC=q$|
|PeY0N
P@kkrD_e~
Rt'<^eI
Ji{=NP
;LL:Xx
xOui*
Ah"/4P7#
)c'owh
}>,vxN%y
v'#Rf!=q+
xJe9(;
v}P!w}
dLfs,R
|D5bnN
Hu_,$/A|
%yyO@sw
udes$>
|k|^"n
jY*SvW
4#9VtGd
##ImeE
=R rOs
U-H> U&*
b0@3uZ
?>~#YC
?}@gfX<":eb]{I(
Cv)sPj
5!!(%x
I3sOe
\?y?NY
zm^R#"W
C#=cI\
_,b+-miL/
x>Q17
T$umub
p!|ig@q
tx'Ne
'eOig!k
Y~FPw0
6Bp<$R
H.WFaf
lx0O]K,#3.*
HyeNH&<L\
aMg;ek
BQ2$|\
vZd:tNo
@3ji"a)2l
u&e*]T
y"9=k
wTry~k\
_@p0B
t)C%"%
f!DSg|
!#yl!bog
1~qIv8
6Bt25zzM{RS
+nH\*90#
Ttd)Rg
HFu"F3
,Wuu6s
>5@VgO
ccq]I)c
>!F\"HZ
RNu~,
[#yYi)k
hSQ9Rz
jt?DfTp
-%34'1=
lDkY2/
iCXSS(N
|^eIGi
o\.yP)*
pe'(.c
w\u]n#
}B2SMw
Rv)@Ny]H
(Si!5|\C0
|awW@m
pa2]d?{^
~da)k!6p
y3Tj>\
X~8G-l
Aguc:7
1KfvIp#gk
bn\<U~9
|4Eh;m
vS @YU
)SO"&q
6i 1dd
jM1Y[nL
G-63w'X
+rrpvs
W<;!y$
Z}?~)d
R)+!(?
eH:#8i_
{}+Yr#
sh#Ch^
(n9Tmz
zaN([WS%YD
/;Q9v?
n.EA$h"v
Y:8MY`
>F)N(.
mX0e.OZ
OW84Zd
#3~H'qki
@,S#X{
' fA1t
f[b=UN
@_svko.[
w;#j!9yGpx
{ |;2z
KM~SvC
eX'koWx<A
j\1MXq
X')|n~GI
#>=:pZ
SXtJqBg
Qt$)]e
zXrMZ=
@Hx|R3
_.c#>M#4
:4iYM\ X
q2vAlt
8`ojjdI
[>8/ ,
7,GPtO
Sjr?s
"n+bNe
ZUeBW<
3EHpx}R#
~MM\1 Sg\
O:o'-g@'
*A2WX%+9B
Ss##0l!y9a@p
932t1|Gw
t93rD1
{")NGP3
F^ks(:
q,o~%X
{\F'B\e
=#((x=lg
qAf$3h2:
UjB@rMR
y B[t=
u&S\M7
5qF~S.\
7xAP,7[
!^Ym0R
]H\XDx
b ;jc2ix
O-?@\#
//eTDI
bZ+YIz
ZvoO1RQ
|lBTXY)vto
ouTXYD
cG*#HN'
vvCmQt_
c1ba;f
s/c;Ba
():KY0
fF$L&|
]T`soo
;NvIe9
x8>jBL
Y5d"Xv
<fYi\i
&:Y\Bl
IQT=fC'p
AI\B0YHf
G?'&(=
c LO#!W
;X'yowB
$.VKKF|
e(k!?L
AR BBt
7nTF6d
M(,^OT
"`$';{
=/4p&v
m2{YDJPgu
t/YAP.
Td`nNY
"[`^q^a
LR.&Tu
A7?3fr
Z.&Yeo@
("2-I!e
);{#@
LlvPd_S
gw[`dyP
qT^o}E/
Qtyw^mH
8(#sm!>|f
ZdylV5A
Y-!=(,p
NFHhrgV
VL6d<C
1'd A1
Zu.J%v
J !=h,$
r6{\Lai
[7x)NLwO:
UuKs.)VL
UMyW\2'w
mAQX%n
|ReO;:
*()sh<
|)8YJo
i+CpNkvtVx]e
*i@WP, KS
Ss##0f!
C1;:sEj1
>3J#)(
W^[MU_+9w
i#>+F`
dxnmip7
IYeu6y
lRrjv9Q
Bj8\<l%,
%7`NwN
9ye'Bq
r!|05w
Y<e:S)
o?l%0%L
&w%pJ}R
0'R%f=
j3Zic2i
0N!~ng
oT2Ytk*
I=@yvtRt
R~8fze
}]"Gmh>
`^o\,)
T`W5B
Be$uQE
l@M0Bn
0/3pb1
6u)e]+
q7Mg |
)f[`drR
lF5J/>
![.Ex|
C[+jd]T
7t.UEM
\>,qNm{
%eqF2pP
xubSejW
jA|fgZ
)GOy!'y7@
y_SpV="t,
?!EW9:
ZtWf^eI
tTWPqC
7(}{P&^
~iBt?#
\3@i"0
3RL)hE+L
_R#L,Q
DH&MT$
hsuuS+I
Sa=cxpa
(a=T@)#
'D;\p|
>|'<JI
SbA!G?%Y
'@T=n~2M
:%;3rCDR
Q[:,~q
q1*,pXq
yq^oXti
-C"$v(
&jx|2Q
V:4X^)V
0*|\dN
fuIz>s)
h`Q&0BZ
c0#eU<
'qFz6:xg
I;H\&'
yJ%) *
Pr#;fl
LxTh-=
\$|^ez
$R|l\VEG
TFt|pNeE
ss@pE~FtzVJaI
+#vfq{l'tpI
_e1v7YK
bH"<Zg
|b/y\<
}@.(="
_OTC9[
\^emH:
o_6r\lIu0
~O"r^ZU+y
t+!}_P
OHRPbOn
~uGh&
c.ayVNx
J34!&b
#@'m6V}
`!'Uj
xQ8q-vD
e[Zm/
pN3RA4
j.2!@@?
-Wd7eNfy
On)~kG
KRn+Sp3
7!b`'I
qYT:w~T)
iG@"-_Rt
qPE@hn
Dpm=Zd|tNeA
nnBUQ{X
`Dl>%y
RP;@V1`
RU3#>i!
bzXh^o
hB`drVt
yS\M+Qop
|ReO;:
`U"<Gq
`^khXU
$-hqcY
n!(@`]s
W1Qdw|
p*9HBEt,J
f%D"{nJy(
S% 10/
ss@pE~FtzVJe
j!!igTT
eOig!ie
C`hwSP
j(}}gL
$h#c>)
eI(nzM\
qbQF 0
j17tf@pw0_,
C z0\@7Q
&/N1w^
E$2XXU
G~"%bk:
rZY(>cOF-
'C;K$d=
,Wxdfn
6B]Cy+
G!3AwDp
Z0(Ijql
0n!~og
%!9oWCx
'3O.vvq
i.MT2K
f!yeg$
YOa_3^Xmw7
eCJ[zs~&hSAK"
`>;7J!
jq,aVPxN
Ow.?.!
qI`?8Y\
B2|cx
O|!!)G@P?
<lsI>n
nu&qe` 4F
*JH1Jz6{
I8&yY*
BtQTQeY
xbe6g=A
E+1mRb
j&hnuvrw
ft?{tp
xnC>(.
~lzNl@
7ro`zw
htw!iRR
w`@N|E
P*!Yhy
y@;d4bT>\~@
8?M}cc\G
Dx>YI6
I9pbYEh"a
aK''^#
~?cIk8
bIXz:h
tzs^cO)7
tus^zh
F#`W3m
G^vR4@
\AZ}Nl
%@9Hyut.
wYf/"h
<j81l@
2s-(>o
bOvtTs
F;?g@h_
2[jeDS
8] ksl
X/~Xy
]#I0<S
`#02NN
;$\.VH4kmQ|r
L;>Jc>07'jW
K3$d8x
`MD|&A(
/.g]Sj3
W~9TFPta
Rjols,C
#9QgPT\
q((?D\gu
LP9_$en!
jJ&jw[0
>n LDEw~
(Z AY?p%
yoOWTh
;j32ZQ;
=,l<~F
_sgWJ
&NT2|3
H#ppQiW
z1[nET -
jtMH;e
FOm{pf
!:E4%S
|J8I`#
Yt|Y}.Y
srk[kmuSr
!7ABP:B
zWE@~S
LQ)y,"
zYo_U_
Bt,%@`
@$n`^k
G"G:.3
,%W;m?p
I!u+HP
m'DHA=
y,>+}Y
m@ziZ{
lbuUAi
Sv)3Uj
3+<~*
GDQm;U
+0:!"i7@
hntC|^EH
c7ck0H8
^D&,RU5
Wz!YZk
+yBNy
Ahc>G0
OT2_Ru+
B'ktR.M
CJ+yS
l[4a%2
'pO=/?
m!TbwE
._{^qm
9os|zhn
v>~0?]cQd
+7f#@"8
3N:d1N
0nA?ioP
Zg5s|j(V
jI)Pq_
OVu]{W
dw^CS%
x|M3mZ
|Ut3\z
OKspbe
tsxOaI
W]=+cK
c#(J(2
Qh~"m<
BV"z6H.
`wKMRt
|+#}f!weg@
r+#sf!
6+#8f!0eg
Ttsz^d
=$#~i!s
2$#si!}jgFs
>$#?i!sh
i!vjgAs
w$#xi!
2$#3?"
jn,jg@3
$#9i!sjg
i!1<d@z
|YfI k
$#3i!}jg
i!:jgEs
"kjgC%
GcY^!hgp
t3tO*A}p
sda8ov
j.kin(
|pbM|^
d!Pog*v
vTtPz^uI
D1qw7FF
"+LNjI
K4h*iRK
Hx7E\t
_EZ;`k9
kf(g\An
%Jic@p
g4oWvI
^[3xae
[X>n?3
tN}k3A
"WjHCr
WHP/s6
yW2_f<
z]#J.=
WNRq<l^bE
f!Zj3N5
e:!M">V
M2`j h
c=d:k5NKY'
(f<Tw{
(w,Qik
5"8=J1
lTS6u
;cO"]c
'y/X6I
,p;9!r:k
c=t:IM
k^8M-QV
{E2pl1
Wu_\oj
~4wdFZ
/_6I)m*
J!{ge@a
X?8~eZb(
*reg~D
\zGhSX
VhJ%=&NR
!vjgS0
=A||o_v
00L2_b[
_k.9=h
`2'bLc_
u}oYKT
%;^Hmx
`qy~h)[
a7*Wn
l{bUZa
Z]-}MOd
2az^@cf
s]*J'=$N\
2vzg@S
W|_^dj
s=**']$.\
p,E^EI
6Utc)YeD
9zKl{eF_.
RpKl{eL_.
Sd89^ H
Fb"GJV
[i%@X[
~1Yx.re^
qdVxm;ZT
tx.QeI
(61fT_
x(u-6P
1#Vj!.ie@
uIMe:1s
Ra-N5N9'
E4Aeyt~
j Oi@@
@1m[r:
=-9?C$
|^d=<x
Gggfv@
&vvggd
wwgbvt
1wwwr"gf@
1wwwr"vv@
wr""gf@
wr""&f@
ww"w""@
wr'""@
{<:y&q?
PACKAGEINFO
DVCLAL
MAINICON
November
December
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
OctoberInvalid variant type conversion
Invalid variant operation
Invalid argument
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Write$Error creating variant or safe array)Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operationFloating point division by zero
Floating point overflow
Floating point underflow
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Delf-SES [Trj]
C4S ClamAV (Linux) Win.Malware.Delf-9890071-0
Trellix (Linux) GenDownloader.ne trojan
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Trojan.GenericKD.48705378
G Data Antivirus (Windows) Virus: Trojan.GenericKD.48705378 (Engine A)
WithSecure (Linux) Trojan.TR/Dropper.Gen8
ESET Security (Windows) Win32/Delf.OEN trojan
DrWeb Antivirus (Linux) Trojan.DownLoader5.60700
ClamAV (Linux) Win.Malware.Delf-9890071-0
eScan Antivirus (Linux) Trojan.GenericKD.48705378(DB)
Kaspersky Standard (Windows) HEUR:Trojan.Win32.Agent.gen
Emsisoft Commandline Scanner (Windows) Trojan.GenericKD.48705378 (B)
Cuckoo

We're processing your submission... This could take a few seconds.