raw00039.dll

StartIsBack

Stanislav Zinukhov

Publisher:
www.startisback.com  (signed by Stanislav Zinukhov)

Product:
StartIsBack

Description:
StartIsBack Helper Tool

Version:
4.0.0

MD5:
a5726bfdb34d2b2718301148981210ba

SHA-1:
f0f31e23f2036e281bb42dc73f0913e7337d3475

SHA-256:
2a450b364b12c00968353e31d3d8abbe542d98ecb924db1bc7cccc1ab81dbdd3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 8:42:03 PM UTC  (today)

File size:
56 KB (57,344 bytes)

Product version:
4.0.0

Copyright:
Copyright (C) 2013+, Tihiy

Original file name:
StartScreen.exe

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\raw00039.dll

Digital Signature
Authority:
StartCom Ltd.

Valid from:
10/23/2014 3:42:50 PM

Valid to:
10/23/2016 1:55:24 AM

Subject:
E=tihiy.mozg@gmail.com, CN=Stanislav Zinukhov, L=Moscow, S=Moscow City, C=RU, Description=2rsUwMPWJuFdSNsA

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
109C

File PE Metadata
Compilation timestamp:
7/30/2015 5:52:51 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
384:gNjJ/uEB1jy1/BMAG+SRlInYPLwGibcVVPk0Ci0o7QKT4DcN:g5jjy3lMepQVVPk0PjTWm

Entry address:
0x1820

Entry point:
55, 8B, EC, 83, EC, 08, 8D, 45, F8, 50, FF, 15, 04, 20, 40, 00, 50, FF, 15, 38, 20, 40, 00, 89, 45, FC, 83, 7D, F8, 02, 7D, 0A, E8, 1B, F8, FF, FF, E9, 97, 00, 00, 00, 68, 70, 23, 40, 00, B9, 04, 00, 00, 00, C1, E1, 00, 8B, 55, FC, 8B, 04, 0A, 50, FF, 15, 6C, 20, 40, 00, 83, C4, 08, 85, C0, 75, 1E, 83, 7D, F8, 02, 7E, 18, B9, 04, 00, 00, 00, D1, E1, 8B, 55, FC, 8B, 04, 0A, 50, E8, 7C, FE, FF, FF, 83, C4, 04, EB, 58, 68, 90, 23, 40, 00, B9, 04, 00, 00, 00, C1, E1, 00, 8B, 55, FC, 8B, 04, 0A, 50, FF, 15, 6C...
 
[+]

Entropy:
5.6573

Developed / compiled with:
Microsoft Visual C++

Code size:
2.5 KB (2,560 bytes)

Scan raw00039.dll - Powered by Reason Core Security