× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: e67e30fe93cd924b4f610a3a7000cb2e626075e1a1fced4a602ee2b47c2317dc
File name: e67e30fe93cd924b4f610a3a7000cb2e626075e1a1fced4a602ee2b47c2317dc.bin
Detection ratio: 0 / 43
Analysis date: 2012-01-15 22:40:05 UTC ( 7 years, 1 month ago ) View latest
Trusted source! This file belongs to the Microsoft Corporation software catalogue.
Antivirus Result Update
AVG 20120115
AhnLab-V3 20120115
AntiVir 20120115
Antiy-AVL 20120115
Avast 20120115
BitDefender 20120115
ByteHero 20120111
CAT-QuickHeal 20120115
ClamAV 20120114
Commtouch 20120115
Comodo 20120115
DrWeb 20120115
Emsisoft 20120115
F-Prot 20120115
F-Secure 20120115
Fortinet 20120115
GData 20120115
Ikarus 20120115
Jiangmin 20120115
K7AntiVirus 20120113
Kaspersky 20120115
McAfee 20120115
McAfee-GW-Edition 20120115
Microsoft 20120115
NOD32 20120115
Norman 20120115
PCTools 20120115
Panda 20120115
Prevx 20120115
Rising 20120113
SUPERAntiSpyware 20120114
Sophos AV 20120115
Symantec 20120115
TheHacker 20120115
TrendMicro 20120115
TrendMicro-HouseCall 20120115
VBA32 20120113
VIPRE 20120115
ViRobot 20120115
VirusBuster 20120115
eSafe 20120115
eTrust-Vet 20120113
nProtect 20120115
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © Xerox Corporation 1998-2000. All Rights Reserved.

Product CentreWare
Original name webtemp.DLL
Internal name webtemp
File version 1, 0, 0, 1
Description webtemp Module
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2001-08-18 05:36:03
Entry Point 0x00003929
Number of sections 4
PE sections
PE imports
Ord(57)
Ord(23)
Ord(58)
Ord(21)
Ord(30)
Ord(16)
Ord(15)
Ord(32)
Ord(18)
LocalFree
EnterCriticalSection
WideCharToMultiByte
LocalAlloc
InitializeCriticalSection
DeleteCriticalSection
InterlockedDecrement
InterlockedIncrement
lstrlenW
LeaveCriticalSection
Ord(1988)
Ord(3147)
Ord(4080)
Ord(2512)
Ord(2396)
Ord(3830)
Ord(2554)
Ord(1168)
Ord(3738)
Ord(269)
Ord(6375)
Ord(1197)
Ord(3136)
Ord(2982)
Ord(3079)
Ord(1176)
Ord(3262)
Ord(826)
Ord(1575)
Ord(1182)
Ord(825)
Ord(600)
Ord(3081)
Ord(1253)
Ord(5199)
Ord(1578)
Ord(1131)
Ord(5808)
Ord(3259)
Ord(4424)
Ord(540)
Ord(5714)
Ord(5289)
Ord(3953)
Ord(1075)
Ord(2985)
Ord(3346)
Ord(3229)
Ord(4622)
Ord(561)
Ord(3831)
Ord(1255)
Ord(2915)
Ord(5302)
Ord(4698)
Ord(3825)
Ord(1570)
Ord(823)
Ord(4486)
Ord(690)
Ord(5204)
Ord(815)
Ord(1089)
Ord(3922)
Ord(2725)
Ord(5731)
Ord(389)
Ord(5356)
Ord(1577)
Ord(2976)
Ord(1116)
Ord(800)
Ord(5300)
Ord(6467)
Ord(5307)
Ord(2818)
Ord(4274)
Ord(941)
Ord(1243)
Ord(4465)
Ord(860)
Ord(4079)
Ord(342)
LoadRegTypeLib
SysFreeString
SysStringLen
_purecall
?terminate@@YAXXZ
malloc
__CxxFrameHandler
??1type_info@@UAE@XZ
_adjust_fdiv
free
_onexit
__dllonexit
_except_handler3
_initterm
sprintf
PE exports
Number of PE resources by type
TYPELIB 1
RT_STRING 1
REGISTRY 1
RT_VERSION 1
Number of PE resources by language
ENGLISH US 4
PE resources
Debug information
ExifTool file metadata
LegalTrademarks
Xerox , The Document Company(TM), and CentreWare(TM) are legal trademarks of Xerox Corporation.

SubsystemVersion
4.0

LinkerVersion
7.0

ImageVersion
5.1

FileSubtype
0

FileVersionNumber
1.0.0.1

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
webtemp Module

CharacterSet
Unicode

InitializedDataSize
12800

EntryPoint
0x3929

OriginalFileName
webtemp.DLL

MIMEType
application/octet-stream

LegalCopyright
Copyright Xerox Corporation 1998-2000. All Rights Reserved.

FileVersion
1, 0, 0, 1

TimeStamp
2001:08:18 05:36:03+00:00

FileType
Win32 DLL

PEType
PE32

InternalName
webtemp

ProductVersion
1, 0, 0, 1

UninitializedDataSize
0

OSVersion
5.1

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Xerox Corporation

CodeSize
13824

ProductName
CentreWare

ProductVersionNumber
1.0.0.1

FileTypeExtension
dll

ObjectFileType
Dynamic link library

CarbonBlack CarbonBlack acts as a surveillance camera for computers
Compressed bundles
File identification
MD5 119e9676f50ab41f1632230e29920ffb
SHA1 ab6f02d715c94564a61c6e4c46f7b5cc8f8b5c2e
SHA256 e67e30fe93cd924b4f610a3a7000cb2e626075e1a1fced4a602ee2b47c2317dc
ssdeep
384:II+AjaKlHixsdhRV5Q05CJyMA2asBI2edf8B4fNfwGIq7:hlHix6hpQ0IyM+KI2edf8KfN1Iq7

authentihash d30902d9029c8b0791450429ac200b384c5ec5c1cbe1df4616d4debc7c1c1fdb
imphash 606cce67e2dc73cebd7891bd0534c29e
File size 22.5 KB ( 23040 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit

TrID DirectShow filter (55.5%)
Windows ActiveX control (32.1%)
Win64 Executable (generic) (7.6%)
Win32 Dynamic Link Library (generic) (1.8%)
Win32 Executable (generic) (1.2%)
Tags
nsrl pedll trusted

Trusted verdicts
This file belongs to the Microsoft Corporation software catalogue. The file is often found with xrxwbtmp.dll as its name. The file belongs to the Windows XP Professional product, more specifically in ['SW CD Windows XP Professional English #1 ProdAct FPP w/SP2'].
VirusTotal metadata
First submission 2009-11-05 11:52:42 UTC ( 9 years, 3 months ago )
Last submission 2018-05-02 09:06:37 UTC ( 9 months, 2 weeks ago )
File names sbs_ve_ambr_20151022210802.801_ 9974
webtemp
sbs_ve_ambr_20151109173612.468_ 73861
sbs_ve_ambr_20160213222128.628_ 275304
sbs_ve_ambr_20160118210617.130_ 6617
sbs_ve_ambr_20151127030938.750_ 15984
sbs_ve_ambr_20170211095027.750_ 29241
setf4f.tmp
tmpfae.tmp
sbs_ve_ambr_20151110163652.296_ 27735
sbs_ve_ambr_20151123211712.546_ 345597
setf8b.tmp
setf8e.tmp
setfde.tmp
setfb0.tmp
sbs_ve_ambr_20160913210123.440_ 6671
sbs_ve_ambr_20161124093828.669_ 603344
tmpf65.tmp
sbs_ve_ambr_20160102210524.671_ 6634
tmpf8f.tmp
sbs_ve_ambr_20150905120928.578_ 662851
sbs_ve_ambr_20160430081211.056_ 119759
tmpf8c.tmp
sbs_ve_ambr_20151113210746.703_ 559837
xrxwbtmp.dll
National Software Reference Library (NIST)
The National Software Reference Library (NSRL) is designed to collect software from various sources and incorporate file profiles computed from this software into a reference data set of information. This file was found in the NSRL dataset, in the following products and with the following file names.
Products Windows XP (Microsoft)
Platforms SDKs/DDKs (Microsoft)
Windows XP Home Edition (Microsoft)
Windows XP Professional (Microsoft)
Windows XP eMbedded Evaluation Software (Microsoft)
Windows XP Tablet PC Edition (Microsoft)
Platforms, SDK/DDK, Developer Tools (Microsoft)
Windows CE .NET Evaluation Software (Microsoft)
Platforms, SDK/DDK (Microsoft)
Windows XP Professional 2002 Service Pack 1 (Microsoft)
MSDN Disc 3264 (Microsoft)
MSDN Disc 2041 (Microsoft)
MSDN Disc 2307 (Microsoft)
MSDN Disc 2428.1 (Microsoft)
MSDN Disc 2428.2 (Microsoft)
Compaq Operating System CD (Compaq)
MSDN Disc 2428 (Microsoft)
MSDN Disc2428.3 (Microsoft)
MSDN Disc 2428.4 (Microsoft)
MSDN Disc 2428.7 (Microsoft)
File names xrxwbtmp.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!