× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ad9530982fd3fdf463679497e6d0429db5bc799c2778cc743a598d0f9bd49ce8
File name: xpsp2res.dll
Detection ratio: 0 / 57
Analysis date: 2015-06-21 20:49:39 UTC ( 3 years, 10 months ago )
Antivirus Result Update
Ad-Aware 20150621
AegisLab 20150621
Yandex 20150621
AhnLab-V3 20150621
Alibaba 20150620
ALYac 20150621
Antiy-AVL 20150621
Arcabit 20150621
Avast 20150621
AVG 20150621
Avira (no cloud) 20150621
AVware 20150621
Baidu-International 20150621
BitDefender 20150621
Bkav 20150620
ByteHero 20150621
CAT-QuickHeal 20150620
ClamAV 20150621
CMC 20150618
Comodo 20150621
Cyren 20150621
DrWeb 20150621
Emsisoft 20150621
ESET-NOD32 20150621
F-Prot 20150621
F-Secure 20150621
Fortinet 20150621
GData 20150621
Ikarus 20150621
Jiangmin 20150620
K7AntiVirus 20150621
K7GW 20150621
Kaspersky 20150621
Kingsoft 20150621
Malwarebytes 20150621
McAfee 20150621
McAfee-GW-Edition 20150621
Microsoft 20150621
eScan 20150621
NANO-Antivirus 20150621
nProtect 20150619
Panda 20150621
Qihoo-360 20150621
Rising 20150618
Sophos AV 20150621
SUPERAntiSpyware 20150621
Symantec 20150621
Tencent 20150621
TheHacker 20150620
TotalDefense 20150621
TrendMicro 20150621
TrendMicro-HouseCall 20150621
VBA32 20150620
VIPRE 20150621
ViRobot 20150621
Zillya 20150621
Zoner 20150619
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows command line subsystem.
FileVersionInfo properties
Copyright
© ?????????? ?????????? (Microsoft Corp.) ??? ????? ????????.

Publisher ?????????? ??????????
Product ???????????? ??????? Microsoft® Windows®
Original name xpsp2res.dll
Internal name xpsp2res.dll
File version 5.1.2600.5512 (xpsp.080413-2113)
Description ????????? ?????? ?????????? 2
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2008-04-13 17:39:24
Number of sections 1
PE sections
Number of PE resources by type
RT_ICON 335
RT_STRING 202
RT_DIALOG 185
RT_GROUP_ICON 83
RT_BITMAP 39
RT_HTML 21
RT_MENU 11
RT_GROUP_CURSOR 4
RT_CURSOR 4
REGISTRY 3
RT_RCDATA 3
AVI 2
RT_ACCELERATOR 2
Struct(2110) 2
RT_MESSAGETABLE 1
FOO 1
RT_VERSION 1
Number of PE resources by language
RUSSIAN 872
NEUTRAL 27
PE resources
ExifTool file metadata
UninitializedDataSize
0

InitializedDataSize
6585856

ImageVersion
5.1

ProductName
Microsoft Windows

FileVersionNumber
5.1.2600.5512

LanguageCode
Russian

FileFlagsMask
0x003f

FileDescription
2

CharacterSet
Unicode

LinkerVersion
7.1

FileTypeExtension
dll

OriginalFileName
xpsp2res.dll

MIMEType
application/octet-stream

Subsystem
Windows command line

FileVersion
5.1.2600.5512 (xpsp.080413-2113)

TimeStamp
2008:04:13 18:39:24+01:00

FileType
Win32 DLL

PEType
PE32

InternalName
xpsp2res.dll

ProductVersion
5.1.2600.5512

SubsystemVersion
5.1

OSVersion
5.1

FileOS
Windows NT 32-bit

LegalCopyright
(Microsoft Corp.) .

MachineType
Intel 386 or later, and compatibles

CodeSize
0

FileSubtype
0

ProductVersionNumber
5.1.2600.5512

EntryPoint
0x0000

ObjectFileType
Dynamic link library

File identification
MD5 209f825737102432ffe1707b45ba524c
SHA1 9302593904d1f09d99fac0dec7ca564cb4f86da4
SHA256 ad9530982fd3fdf463679497e6d0429db5bc799c2778cc743a598d0f9bd49ce8
ssdeep
98304:oGm1+V5VE7zsZtqVPaHVjUbVEE3AVObNvMVtVVqVObQV9+qLoFFKVsSN02:uHvsZtQaFU2shZ43LqLqS

authentihash eda845de4e390f5579af870b37ec96671f1ae803eb36d5db2d979c5acdaaab77
File size 6.3 MB ( 6586368 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (console) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (43.5%)
Win32 Executable (generic) (29.8%)
Generic Win/DOS Executable (13.2%)
DOS Executable Generic (13.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
Tags
pedll

VirusTotal metadata
First submission 2015-06-08 04:55:14 UTC ( 3 years, 10 months ago )
Last submission 2015-06-08 04:55:14 UTC ( 3 years, 10 months ago )
File names xpsp2res.dll
xpsp2res.dll
xpsp2res.dll
xpsp2res.dll
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!