player.exe.exe

DevalVR 3D Plugin

Phoscode SL

Publisher:
www.devalvr.com  (signed by Phoscode SL)

Product:
DevalVR 3D Plugin

Description:
DevalVR 3D Plugin 0,6,5,2

Version:
0, 6, 5, 2

MD5:
a06e9cd19f10d5d654c74c9ec692cf19

SHA-1:
403c55666206f19ed0bb08bbc19b4436e515daa1

SHA-256:
b10a83493f4a2922b9c249922913ae1ab15d60326f44b88c8229e60151160d68

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 6:55:01 AM UTC  (today)

File size:
657 KB (672,816 bytes)

Product version:
0, 6, 5, 2

Copyright:
Copyleft © 2006 Phoscode S.L.

Original file name:
npdevalvr.dll

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\player.exe.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/13/2007 3:30:00 AM

Valid to:
1/14/2008 3:29:59 AM

Subject:
CN=Phoscode SL, O=Phoscode SL, STREET="Diego de Velazquez 1, 3º K", L=Villamediana de Iregua, S=La Rioja, PostalCode=26142, C=ES

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B40EDAE60152EE9D0054161AA3F9DD91

File PE Metadata
Compilation timestamp:
12/24/2007 9:46:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Sg5MjmgHWIt1C3hdCkb20FvzxfCm/opoGO4R8:PMjJsL520B1Cm/opoGO4R8

Entry address:
0x5F0AE

Entry point:
55, 8B, EC, 6A, FF, 68, 78, 62, 46, 00, 68, 80, F4, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, 9C, 35, 46, 00, 59, 83, 0D, E0, C1, 48, 00, FF, 83, 0D, E4, C1, 48, 00, FF, FF, 15, A0, 35, 46, 00, 8B, 0D, D4, C1, 48, 00, 89, 08, FF, 15, A4, 35, 46, 00, 8B, 0D, D0, C1, 48, 00, 89, 08, A1, A8, 35, 46, 00, 8B, 00, A3, DC, C1, 48, 00, E8, 60, 03, 00, 00, 39, 1D, 88, F9, 46, 00, 75, 0C, 68, 7C, F4, 45, 00, FF, 15...
 
[+]

Entropy:
5.8788

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
392 KB (401,408 bytes)

Scan player.exe.exe - Powered by Reason Core Security