<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PPJoy 0.8.4.5 has finally been released!</title>
	<atom:link href="http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/feed/" rel="self" type="application/rss+xml" />
	<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/</link>
	<description>GlovePIE, input devices, politics, and environmentalism</description>
	<lastBuildDate>Fri, 03 Feb 2012 07:18:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: what ????</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-14825</link>
		<dc:creator>what ????</dc:creator>
		<pubDate>Mon, 02 Jan 2012 15:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-14825</guid>
		<description>Hey BLOGGER, you fucking SUCK.

Infected my pc wqith a fucking virus but i can&#039;t imnagine HOW LOW your IQ MUST BE.

GO DIE</description>
		<content:encoded><![CDATA[<p>Hey BLOGGER, you fucking SUCK.</p>
<p>Infected my pc wqith a fucking virus but i can&#8217;t imnagine HOW LOW your IQ MUST BE.</p>
<p>GO DIE</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: endahosor</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-14578</link>
		<dc:creator>endahosor</dc:creator>
		<pubDate>Sun, 11 Dec 2011 08:15:57 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-14578</guid>
		<description>bg4m3r:
you can search &quot;PPJoy 64 bit Windows 7 - Old Version !&quot; on Youtube,
or check this: http://www.youtube.com/watch?v=JjVaLi2c74I

hope it helps.</description>
		<content:encoded><![CDATA[<p>bg4m3r:<br />
you can search &#8220;PPJoy 64 bit Windows 7 &#8211; Old Version !&#8221; on Youtube,<br />
or check this: <a href="http://www.youtube.com/watch?v=JjVaLi2c74I" rel="nofollow">http://www.youtube.com/watch?v=JjVaLi2c74I</a></p>
<p>hope it helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ahmednino</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-14572</link>
		<dc:creator>ahmednino</dc:creator>
		<pubDate>Sat, 19 Nov 2011 22:59:36 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-14572</guid>
		<description>actually .. i downloaded it and try to setup but say something like that (verify your 64-bit system) &gt;but setup continue &gt; after finished install a MSG fatal error appeared say cant open the PPJoy device driver.please install the PPJoyBus.sys first</description>
		<content:encoded><![CDATA[<p>actually .. i downloaded it and try to setup but say something like that (verify your 64-bit system) &gt;but setup continue &gt; after finished install a MSG fatal error appeared say cant open the PPJoy device driver.please install the PPJoyBus.sys first</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mac</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-14545</link>
		<dc:creator>Mac</dc:creator>
		<pubDate>Fri, 07 Oct 2011 19:37:26 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-14545</guid>
		<description>Yeah, this is really disturbing.  I sent it into VirusTotal, and I got more malware hits than I&#039;ve ever seen before.  Granted, most of the alarms are coming from antivirus products I&#039;ve not even heard of, or that are known for being twitchy, but it&#039;s still kind of a nervous thought.

And the MD5 signature isn&#039;t matching that from Method139&#039;s post, which is especially odd.  &#039;Course, I don&#039;t know who Method139 is, so I don&#039;t know if I should trust him either ;)

Here&#039;s the result listing:

CAT-QuickHeal 	11.00 	2011.09.10 	Trojan.Agent.nq
Commtouch 	5.3.2.6 	2011.09.10 	W32/MalwareF.ACETX
DrWeb 	5.0.2.03300 	2011.09.11 	Trojan.DownLoad2.15989
Emsisoft 	5.1.0.11 	2011.09.10 	Dropper.Win32.Dldr.Agent.duuj!A2
F-Prot 	4.6.2.117 	2011.09.10 	W32/MalwareF.ACETX
Fortinet 	4.3.370.0 	2011.09.10 	W32/Agent.DUUJ!tr.dldr
K7AntiVirus 	9.112.5114 	2011.09.09 	Trojan-Downloader
McAfee 	5.400.0.1158 	2011.09.11 	Artemis!EA889891CC34
McAfee-GW-Edition 	2010.1D 	2011.09.10 	Artemis!EA889891CC34
Norman 	6.07.11 	2011.09.10 	W32/Suspicious_Gen2.EGQDV
nProtect 	2011-09-10.01 	2011.09.10 	Trojan-Downloader/W32.Agent.2173165
Rising 	23.74.03.03 	2011.09.09 	Trojan.Win32.Generic.1275CD3D
TrendMicro 	9.500.0.1008 	2011.09.09 	TROJ_GEN.F35CZHO
TrendMicro-HouseCall 	9.500.0.1008 	2011.09.11 	TROJ_GEN.F35CZHO
VBA32 	3.12.16.4 	2011.09.09 	TrojanDownloader.Agent.duuj
VIPRE 	10437 	2011.09.11 	Trojan.Win32.Generic!BT
ViRobot 	2011.9.10.4666 	2011.09.10 	Backdoor.Win32.S.Hupigon.2173165
VirusBuster 	14.0.206.1 	2011.09.10 	Trojan.DL.Agent!gtD1ZNDIAp4

Additional information
MD5   : ea889891cc340c312e8dce2988426785
SHA1  : fabd5893626ded6f461642a60c73a59091436e9a
SHA256: f32d653c7c4b52037c2b5c50cd9695b79abae3dd325cd08fa1a25dd825bf96d6
ssdeep: 49152:+0eQitOAz1UJWvCBNvyXUhQoB3jAV4piN++yk2B9:d0tOHZyXUC23jAV4pX+O9
File size : 2173165 bytes
First seen: 2009-12-03 23:35:16
Last seen : 2011-09-11 03:56:31
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)[*lb*]Win32 Executable Generic (14.7%)[*lb*]Win32 Dynamic Link Library (generic) (13.1%)[*lb*]Generic Win/DOS Executable (3.4%)[*lb*]DOS Executable Generic (3.4%)
sigcheck:
publisher....: n/a[*lb*]copyright....: n/a[*lb*]product......: n/a[*lb*]description..: n/a[*lb*]original name: n/a[*lb*]internal name: n/a[*lb*]file version.: n/a[*lb*]comments.....: n/a[*lb*]signers......: -[*lb*]signing date.: -[*lb*]verified.....: Unsigned[*lb*]
PEiD: -
packers (F-Prot): NSIS, appended, UTF-8
packers (Kaspersky): DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x30FA
timedatestamp....: 0x4A2AE2A7 (Sat Jun 06 21:41:59 2009)
machinetype......: 0x14C (Intel I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x5C4C, 0x5E00, 6.44, 856b32eb77dfd6fb67f21d6543272da5
.rdata, 0x7000, 0x129C, 0x1400, 5.05, dc77f8a1e6985a4361c55642680ddb4f
.data, 0x9000, 0x25C58, 0x400, 4.8, 7922d4ce117d7d5b3ac2cffe4b0b5e4f
.ndata, 0x2F000, 0x9000, 0x0, 0.0, d41d8cd98f00b204e9800998ecf8427e
.rsrc, 0x38000, 0x4130, 0x4200, 2.07, 58a83b15075402f325febf830d4f177a

[[ 8 import(s) ]]
advapi32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
comctl32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
gdi32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
kernel32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, GetWindowsDirectoryA, SetFileTime, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetTempPathA
ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
shell32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
user32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
version.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
ThreatExpert:
http://www.threatexpert.com/report.aspx?md5=ea889891cc340c312e8dce2988426785
Androguard:
-
ExifTool:
file metadata[*lb*]CodeSize: 24064[*lb*]EntryPoint: 0x30fa[*lb*]FileSize: 2.1 MB[*lb*]FileType: Win32 EXE[*lb*]ImageVersion: 6.1[*lb*]InitializedDataSize: 164864[*lb*]LinkerVersion: 6.0[*lb*]MIMEType: application/octet-stream[*lb*]MachineType: Intel 386 or later, and compatibles[*lb*]OSVersion: 4.0[*lb*]PEType: PE32[*lb*]Subsystem: Windows GUI[*lb*]SubsystemVersion: 4.0[*lb*]TimeStamp: 2009:06:06 23:41:59+02:00[*lb*]UninitializedDataSize: 1024[*lb*]
Symantec reputation:Suspicious.Insight

VT Community

    User:    CRDF
    Reputation:    10143 credits
    Comment date:    2011-02-04 02:00:01 (UTC)
    The file is a malware known as &quot;CaM.Trojan.DownLoad2.Win32.PEx.C.91073854829&quot;. - 36905 -
    Tags: malware, agent, 2173165, ea889891cc34</description>
		<content:encoded><![CDATA[<p>Yeah, this is really disturbing.  I sent it into VirusTotal, and I got more malware hits than I&#8217;ve ever seen before.  Granted, most of the alarms are coming from antivirus products I&#8217;ve not even heard of, or that are known for being twitchy, but it&#8217;s still kind of a nervous thought.</p>
<p>And the MD5 signature isn&#8217;t matching that from Method139&#8242;s post, which is especially odd.  &#8216;Course, I don&#8217;t know who Method139 is, so I don&#8217;t know if I should trust him either <img src='http://glovepie.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Here&#8217;s the result listing:</p>
<p>CAT-QuickHeal 	11.00 	2011.09.10 	Trojan.Agent.nq<br />
Commtouch 	5.3.2.6 	2011.09.10 	W32/MalwareF.ACETX<br />
DrWeb 	5.0.2.03300 	2011.09.11 	Trojan.DownLoad2.15989<br />
Emsisoft 	5.1.0.11 	2011.09.10 	Dropper.Win32.Dldr.Agent.duuj!A2<br />
F-Prot 	4.6.2.117 	2011.09.10 	W32/MalwareF.ACETX<br />
Fortinet 	4.3.370.0 	2011.09.10 	W32/Agent.DUUJ!tr.dldr<br />
K7AntiVirus 	9.112.5114 	2011.09.09 	Trojan-Downloader<br />
McAfee 	5.400.0.1158 	2011.09.11 	Artemis!EA889891CC34<br />
McAfee-GW-Edition 	2010.1D 	2011.09.10 	Artemis!EA889891CC34<br />
Norman 	6.07.11 	2011.09.10 	W32/Suspicious_Gen2.EGQDV<br />
nProtect 	2011-09-10.01 	2011.09.10 	Trojan-Downloader/W32.Agent.2173165<br />
Rising 	23.74.03.03 	2011.09.09 	Trojan.Win32.Generic.1275CD3D<br />
TrendMicro 	9.500.0.1008 	2011.09.09 	TROJ_GEN.F35CZHO<br />
TrendMicro-HouseCall 	9.500.0.1008 	2011.09.11 	TROJ_GEN.F35CZHO<br />
VBA32 	3.12.16.4 	2011.09.09 	TrojanDownloader.Agent.duuj<br />
VIPRE 	10437 	2011.09.11 	Trojan.Win32.Generic!BT<br />
ViRobot 	2011.9.10.4666 	2011.09.10 	Backdoor.Win32.S.Hupigon.2173165<br />
VirusBuster 	14.0.206.1 	2011.09.10 	Trojan.DL.Agent!gtD1ZNDIAp4</p>
<p>Additional information<br />
MD5   : ea889891cc340c312e8dce2988426785<br />
SHA1  : fabd5893626ded6f461642a60c73a59091436e9a<br />
SHA256: f32d653c7c4b52037c2b5c50cd9695b79abae3dd325cd08fa1a25dd825bf96d6<br />
ssdeep: 49152:+0eQitOAz1UJWvCBNvyXUhQoB3jAV4piN++yk2B9:d0tOHZyXUC23jAV4pX+O9<br />
File size : 2173165 bytes<br />
First seen: 2009-12-03 23:35:16<br />
Last seen : 2011-09-11 03:56:31<br />
Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit<br />
TrID:<br />
Win32 Executable MS Visual C++ (generic) (65.2%)[*lb*]Win32 Executable Generic (14.7%)[*lb*]Win32 Dynamic Link Library (generic) (13.1%)[*lb*]Generic Win/DOS Executable (3.4%)[*lb*]DOS Executable Generic (3.4%)<br />
sigcheck:<br />
publisher&#8230;.: n/a[*lb*]copyright&#8230;.: n/a[*lb*]product&#8230;&#8230;: n/a[*lb*]description..: n/a[*lb*]original name: n/a[*lb*]internal name: n/a[*lb*]file version.: n/a[*lb*]comments&#8230;..: n/a[*lb*]signers&#8230;&#8230;: -[*lb*]signing date.: -[*lb*]verified&#8230;..: Unsigned[*lb*]<br />
PEiD: -<br />
packers (F-Prot): NSIS, appended, UTF-8<br />
packers (Kaspersky): DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack, DoomPack<br />
PEInfo: PE structure information</p>
<p>[[ basic data ]]<br />
entrypointaddress: 0x30FA<br />
timedatestamp&#8230;.: 0x4A2AE2A7 (Sat Jun 06 21:41:59 2009)<br />
machinetype&#8230;&#8230;: 0x14C (Intel I386)</p>
<p>[[ 5 section(s) ]]<br />
name, viradd, virsiz, rawdsiz, ntropy, md5<br />
.text, 0&#215;1000, 0x5C4C, 0x5E00, 6.44, 856b32eb77dfd6fb67f21d6543272da5<br />
.rdata, 0&#215;7000, 0x129C, 0&#215;1400, 5.05, dc77f8a1e6985a4361c55642680ddb4f<br />
.data, 0&#215;9000, 0x25C58, 0&#215;400, 4.8, 7922d4ce117d7d5b3ac2cffe4b0b5e4f<br />
.ndata, 0x2F000, 0&#215;9000, 0&#215;0, 0.0, d41d8cd98f00b204e9800998ecf8427e<br />
.rsrc, 0&#215;38000, 0&#215;4130, 0&#215;4200, 2.07, 58a83b15075402f325febf830d4f177a</p>
<p>[[ 8 import(s) ]]<br />
advapi32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA<br />
comctl32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create<br />
gdi32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject<br />
kernel32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, GetWindowsDirectoryA, SetFileTime, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetTempPathA<br />
ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance<br />
shell32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation<br />
user32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow<br />
version.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA<br />
ThreatExpert:<br />
<a href="http://www.threatexpert.com/report.aspx?md5=ea889891cc340c312e8dce2988426785" rel="nofollow">http://www.threatexpert.com/report.aspx?md5=ea889891cc340c312e8dce2988426785</a><br />
Androguard:<br />
-<br />
ExifTool:<br />
file metadata[*lb*]CodeSize: 24064[*lb*]EntryPoint: 0x30fa[*lb*]FileSize: 2.1 MB[*lb*]FileType: Win32 EXE[*lb*]ImageVersion: 6.1[*lb*]InitializedDataSize: 164864[*lb*]LinkerVersion: 6.0[*lb*]MIMEType: application/octet-stream[*lb*]MachineType: Intel 386 or later, and compatibles[*lb*]OSVersion: 4.0[*lb*]PEType: PE32[*lb*]Subsystem: Windows GUI[*lb*]SubsystemVersion: 4.0[*lb*]TimeStamp: 2009:06:06 23:41:59+02:00[*lb*]UninitializedDataSize: 1024[*lb*]<br />
Symantec reputation:Suspicious.Insight</p>
<p>VT Community</p>
<p>    User:    CRDF<br />
    Reputation:    10143 credits<br />
    Comment date:    2011-02-04 02:00:01 (UTC)<br />
    The file is a malware known as &#8220;CaM.Trojan.DownLoad2.Win32.PEx.C.91073854829&#8243;. &#8211; 36905 -<br />
    Tags: malware, agent, 2173165, ea889891cc34</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bg4m3r</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-10847</link>
		<dc:creator>bg4m3r</dc:creator>
		<pubDate>Thu, 30 Jun 2011 21:37:52 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-10847</guid>
		<description>This is great...or, rather, it would be if Windows would let me install the damn thing! Since it&#039;s unsigned, it keeps blocking it...I&#039;ve tried everything I can find online...utilities, testmodes, disabling driver related services, registry hacks, SDK bypasses, etc...nothing works! F-ing Micro$hit! If only there was some way to force it in through linux or something! :(</description>
		<content:encoded><![CDATA[<p>This is great&#8230;or, rather, it would be if Windows would let me install the damn thing! Since it&#8217;s unsigned, it keeps blocking it&#8230;I&#8217;ve tried everything I can find online&#8230;utilities, testmodes, disabling driver related services, registry hacks, SDK bypasses, etc&#8230;nothing works! F-ing Micro$hit! If only there was some way to force it in through linux or something! <img src='http://glovepie.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dark_grimmjow</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-9101</link>
		<dc:creator>dark_grimmjow</dc:creator>
		<pubDate>Tue, 12 Apr 2011 16:27:21 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-9101</guid>
		<description>I agree with known. I scanned the installer with AVG before installing and it found 2 trojans. If you are going to download this, you&#039;d best look elsewhere.</description>
		<content:encoded><![CDATA[<p>I agree with known. I scanned the installer with AVG before installing and it found 2 trojans. If you are going to download this, you&#8217;d best look elsewhere.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-8877</link>
		<dc:creator>Christian</dc:creator>
		<pubDate>Mon, 04 Apr 2011 21:00:16 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-8877</guid>
		<description>WTF? I downloaded the PPjoy crap, and my anti-virus detected it as malware? WTF?</description>
		<content:encoded><![CDATA[<p>WTF? I downloaded the PPjoy crap, and my anti-virus detected it as malware? WTF?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sk</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-8024</link>
		<dc:creator>sk</dc:creator>
		<pubDate>Tue, 15 Mar 2011 22:05:55 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-8024</guid>
		<description>AVG says that http://glovepie.org/PPJoySetup-0.8.4.5-early-release.exe contains a virus ...</description>
		<content:encoded><![CDATA[<p>AVG says that <a href="http://glovepie.org/PPJoySetup-0.8.4.5-early-release.exe" rel="nofollow">http://glovepie.org/PPJoySetup-0.8.4.5-early-release.exe</a> contains a virus &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jtcressy</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-7639</link>
		<dc:creator>jtcressy</dc:creator>
		<pubDate>Fri, 04 Mar 2011 15:38:53 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-7639</guid>
		<description>When i try to run it, adaware blocks it saying its a trojan downloader??? are you sure this thing is safe? or is adaware just confused?</description>
		<content:encoded><![CDATA[<p>When i try to run it, adaware blocks it saying its a trojan downloader??? are you sure this thing is safe? or is adaware just confused?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Connecting your Wii Classic Controller to your PC &#124; Crazy Photon's Blog</title>
		<link>http://glovepie.org/blog/2010/01/25/ppjoy-0-8-4-5-has-finally-been-released/comment-page-1/#comment-6777</link>
		<dc:creator>Connecting your Wii Classic Controller to your PC &#124; Crazy Photon's Blog</dc:creator>
		<pubDate>Fri, 11 Feb 2011 02:05:32 +0000</pubDate>
		<guid isPermaLink="false">http://glovepie.org/blog/?p=43#comment-6777</guid>
		<description>[...] 3) Install PPJoy. This one is tricky because its drivers are signed with test signatures. This means that in order for the driver to work, you need to tell windows to accept running drivers in test mode. This is accomplished by running the following commands from a command prompt with administrative rights: [...]</description>
		<content:encoded><![CDATA[<p>[...] 3) Install PPJoy. This one is tricky because its drivers are signed with test signatures. This means that in order for the driver to work, you need to tell windows to accept running drivers in test mode. This is accomplished by running the following commands from a command prompt with administrative rights: [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

