Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -=[ ProtectionID v0.6.6.7 DECEMBER]=-
- (c) 2003-2015 CDKiLLER & TippeX
- Build 24/12/14-22:48:13
- <Previous Data Cleared>
- Scanning -> C:\Program Files\Steam\steamapps\common\Ubersoldier II\xtend.exe
- File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 819600 (0C8190h) Byte(s)
- Compilation TimeStamp : 0x38FE717C -> Thu 20th Apr 2000 02:54:52 (GMT)
- [TimeStamp] 0x38FE717C -> Thu 20th Apr 2000 02:54:52 (GMT) | PE Header | - | Offset: 0x00000128 | VA: 0x00400128 | -
- [TimeStamp] 0x38FE717C -> Thu 20th Apr 2000 02:54:52 (GMT) | Export | - | Offset: 0x00097674 | VA: 0x00498274 | -
- -> File Appears to be Digitally Signed @ Offset 0C6C38h, size : 01558h / 05464 byte(s)
- -> File has 56 (038h) bytes of appended data starting at offset 0C6C00h
- [File Heuristics] -> Flag #1 : 00000000000001001100000100110111 (0x0004C137)
- [Entrypoint Section Entropy] : 0.82 (section #6) ".start " | Size : 0x1000 (4096) byte(s)
- [DllCharacteristics] -> Flag : (0x0000) -> NONE
- [SectionCount] 8 (0x8) | ImageSize 0x338000 (3375104) byte(s)
- [Export] 100% of function(s) (2 of 2) are in file | 0 are forwarded | 2 code | 0 data | 0 uninit data | 0 unknown |
- [!] StarForce 32 Bit v3.4 - v5.0 [<Unknown>]
- - Scan Took : 1.852 Second(s) [00000047Ch (1148) tick(s)] [558 of 573 scan(s) done]
- Scanning -> C:\Program Files\Steam\steamapps\common\Ubersoldier II\protect.exe
- File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 661240 (0A16F8h) Byte(s)
- Compilation TimeStamp : 0x48903F33 -> Wed 30th Jul 2008 10:15:15 (GMT)
- [TimeStamp] 0x48903F33 -> Wed 30th Jul 2008 10:15:15 (GMT) | PE Header | - | Offset: 0x000000F0 | VA: 0x004000F0 | -
- -> File Appears to be Digitally Signed @ Offset 0A0190h, size : 01568h / 05480 byte(s)
- -> File has 514448 (07D990h) bytes of appended data starting at offset 022800h
- [!] Executable uses SEH Tables (/SAFESEH) (22154 calculated 257 recorded... 22140 invalid addresses)
- [!] * table may be compressed / encrypted *
- [File Heuristics] -> Flag #1 : 00000000000000001100001000100111 (0x0000C227)
- [Entrypoint Section Entropy] : 7.92 (section #1) "UPX1 " | Size : 0x20800 (133120) byte(s)
- [DllCharacteristics] -> Flag : (0x0000) -> NONE
- [SectionCount] 3 (0x3) | ImageSize 0x5D000 (380928) byte(s)
- [VersionInfo] Company Name : Russobit-M
- [VersionInfo] Product Name : US2
- [VersionInfo] Product Version : 4.70
- [VersionInfo] File Description : FrontLine Protection GUI Application
- [VersionInfo] File Version : 4.70.012.003
- [VersionInfo] Original FileName : CORE.EXE
- [VersionInfo] Internal Name : CORE.EXE
- [VersionInfo] Legal Copyrights : (c) Protection Technology (StarForce). 2000-2007
- [!] StarForce 32 Bit vPro [Pro]
- [!] UPX 3.02 compressed !
- upx internal version : 013 / compression method : 08 (M_NRV2E_LE32) - Level : 09
- decompressed adler32 : 0x71C2182A / compressed adler32 : 0xAADF9664
- uncompressed size : 0x00058F51 (0364369) / compressed size : 0x00020480 (0132224)
- original file size : 0x00053000 (0339968) / filter : 0x026 / ct0 0x13 / linkchecksum : 0x016
- - Scan Took : 0.343 Second(s) [000000157h (343) tick(s)] [558 of 573 scan(s) done]
- Scanning -> C:\Program Files\Steam\steamapps\common\Ubersoldier II\vfs.dll
- File Type : 32-Bit Dll (Subsystem : Win GUI / 2), Size : 204632 (031F58h) Byte(s)
- Compilation TimeStamp : 0x38FE717C -> Thu 20th Apr 2000 02:54:52 (GMT)
- [TimeStamp] 0x38FE717C -> Thu 20th Apr 2000 02:54:52 (GMT) | PE Header | - | Offset: 0x000000F0 | VA: 0x100000F0 | -
- [TimeStamp] 0x44FEC844 -> Wed 06th Sep 2006 13:08:20 (GMT) | Export | - | Offset: 0x0002ACD4 | VA: 0x1002B8D4 | -
- -> File Appears to be Digitally Signed @ Offset 030A00h, size : 01558h / 05464 byte(s)
- [File Heuristics] -> Flag #1 : 00000000000001001100000100110111 (0x0004C137)
- [Entrypoint Section Entropy] : 0.30 (section #5) ".start " | Size : 0x1000 (4096) byte(s)
- [DllCharacteristics] -> Flag : (0x0000) -> NONE
- [SectionCount] 7 (0x7) | ImageSize 0x58000 (360448) byte(s)
- [Export] 100% of function(s) (3 of 3) are in file | 0 are forwarded | 3 code | 0 data | 0 uninit data | 0 unknown |
- [!] StarForce 32 Bit v4.50 - 5.x (or higher) [<Unknown>]
- - Scan Took : 0.336 Second(s) [000000150h (336) tick(s)] [244 of 573 scan(s) done]
- Scanning -> C:\Program Files\Steam\steamapps\common\Ubersoldier II\protect.x86
- File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 76800 (012C00h) Byte(s)
- Compilation TimeStamp : 0x486D001F -> Thu 03rd Jul 2008 16:36:47 (GMT)
- [TimeStamp] 0x486D001F -> Thu 03rd Jul 2008 16:36:47 (GMT) | PE Header | - | Offset: 0x00000100 | VA: 0x00400100 | -
- [!] Executable uses SEH Tables (/SAFESEH) (8490 calculated 29 recorded... 8487 invalid addresses)
- [!] * table may be compressed / encrypted *
- [File Heuristics] -> Flag #1 : 00000000000000001100011000100011 (0x0000C623)
- [Entrypoint Section Entropy] : 7.92 (section #1) "UPX1 " | Size : 0x12000 (73728) byte(s)
- [DllCharacteristics] -> Flag : (0x0000) -> NONE
- [SectionCount] 3 (0x3) | ImageSize 0x29000 (167936) byte(s)
- [VersionInfo] Company Name : Playten Interactive
- [VersionInfo] Product Name : UberSoldier 2
- [VersionInfo] Product Version : 5.00
- [VersionInfo] File Description : FrontLine Helper
- [VersionInfo] File Version : 5.00.008.005
- [VersionInfo] Original FileName : CORE.ADMIN
- [VersionInfo] Internal Name : CORE.ADMIN
- [VersionInfo] Legal Copyrights : (c) Protection Technology (StarForce). 2000-2007
- [!] UPX 3.02 compressed !
- upx internal version : 013 / compression method : 02 (M_NRV2B_LE32) - Level : 09
- decompressed adler32 : 0xFB8F4730 / compressed adler32 : 0x07214D56
- uncompressed size : 0x00025703 (0153347) / compressed size : 0x00011DA2 (073122)
- original file size : 0x00024000 (0147456) / filter : 0x026 / ct0 0x13 / linkchecksum : 0x098
- - Scan Took : 0.419 Second(s) [0000001A3h (419) tick(s)] [499 of 573 scan(s) done]
- Scanning -> C:\Program Files\Steam\steamapps\common\Ubersoldier II\protect.dll
- File Type : 32-Bit Dll (Subsystem : Win GUI / 2), Size : 2582016 (0276600h) Byte(s)
- Compilation TimeStamp : 0x48903F22 -> Wed 30th Jul 2008 10:14:58 (GMT)
- [TimeStamp] 0x48903F22 -> Wed 30th Jul 2008 10:14:58 (GMT) | PE Header | - | Offset: 0x00000100 | VA: 0x10000100 | -
- [TimeStamp] 0x48903F22 -> Wed 30th Jul 2008 10:14:58 (GMT) | Export | - | Offset: 0x0001E7B4 | VA: 0x1034E5B4 | -
- -> File Appears to be Digitally Signed @ Offset 02750A8h, size : 01558h / 05464 byte(s)
- -> File has 2451112 (02566A8h) bytes of appended data starting at offset 01EA00h
- [File Heuristics] -> Flag #1 : 00000000000000001100001100100111 (0x0000C327)
- [Entrypoint Section Entropy] : 7.91 (section #1) "UPX1 " | Size : 0x1DE00 (122368) byte(s)
- [DllCharacteristics] -> Flag : (0x0000) -> NONE
- [SectionCount] 3 (0x3) | ImageSize 0x34F000 (3469312) byte(s)
- [Export] 0% of function(s) (0 of 3) are in file | 0 are forwarded | 3 code | 0 data | 0 uninit data | 0 unknown |
- [VersionInfo] Company Name : Russobit-M
- [VersionInfo] Product Name : US2
- [VersionInfo] Product Version : 4.70
- [VersionInfo] File Description : FrontLine Protection Library
- [VersionInfo] File Version : 4.70.012.003
- [VersionInfo] Original FileName : CORE.DLL
- [VersionInfo] Internal Name : CORE.DLL
- [VersionInfo] Legal Copyrights : (c) Protection Technology (StarForce). 2000-2007
- [!] StarForce 32 Bit vPro [Pro]
- [!] UPX 3.02 compressed !
- upx internal version : 013 / compression method : 08 (M_NRV2E_LE32) - Level : 09
- decompressed adler32 : 0xD5152232 / compressed adler32 : 0x879D9AAC
- uncompressed size : 0x0034B7EE (03454958) / compressed size : 0x0001DA83 (0121475)
- original file size : 0x00053000 (0339968) / filter : 0x026 / ct0 0x13 / linkchecksum : 0x097
- - Scan Took : 0.629 Second(s) [000000275h (629) tick(s)] [244 of 573 scan(s) done]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement