Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2007-Nov-14 16:27:56 |
Detected languages |
English - United States
|
Comments | Created with Multimedia Builder, version 4.9.8.13 |
CompanyName | |
FileDescription | |
FileVersion | 1.0.0.0 |
InternalName | |
LegalCopyright | |
LegalTrademarks | |
OriginalFilename | myaquaticlife.exe |
PrivateBuild | 1.0.0.0 |
ProductName | |
ProductVersion | 1.0.0.0 |
SpecialBuild | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
1859767 bytes of data starting at offset 0x13c000.
The overlay data has an entropy of 7.9965 and is possibly compressed or encrypted. |
Malicious | VirusTotal score: 5/68 (Scanned on 2021-09-20 10:21:40) |
FireEye:
Generic.mg.0b88f42023a42426
Cybereason: malicious.3ffe11 APEX: Malicious ClamAV: Win.Dropper.Agent-67351 Sophos: Generic ML PUA (PUA) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2007-Nov-14 16:27:56 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0xe9000 |
SizeOfInitializedData | 0xa5000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000BEBB7 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xea000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x18f000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.DLL |
SetEnvironmentVariableA
FindFirstFileA GetVolumeInformationA TlsGetValue TlsFree GetProfileStringA GetLocaleInfoW IsBadCodePtr CreateProcessA TerminateProcess lstrcpyA lstrlenA lstrcatA Sleep GetTickCount WaitForSingleObject GlobalFree GlobalUnlock GlobalLock FreeLibrary GetProcAddress LoadLibraryA GetSystemDirectoryA GetTempPathA SetFileAttributesA CloseHandle SetFileTime LocalFileTimeToFileTime DosDateTimeToFileTime CreateFileA MulDiv QueryPerformanceFrequency QueryPerformanceCounter MapViewOfFile GetLastError CreateFileMappingA UnmapViewOfFile MultiByteToWideChar CreateThread TerminateThread LocalFree FormatMessageA GetModuleHandleA WriteFile GlobalAlloc DeleteFileA GetCurrentThreadId GlobalSize ReadFile SetFilePointer LocalAlloc LocalUnlock LocalLock GlobalMemoryStatus GetVersionExA GetModuleFileNameA GetExitCodeProcess Process32Next OpenProcess Process32First CreateToolhelp32Snapshot OutputDebugStringA GlobalReAlloc GetDriveTypeA CreateDirectoryA GetWindowsDirectoryA OpenMutexA GlobalDeleteAtom GlobalAddAtomA GetCPInfo GetOEMCP lstrcmpiA SetEvent WaitForMultipleObjects SetPriorityClass GetCurrentProcess GlobalGetAtomNameA CreateMutexA CopyFileA GetFileAttributesA lstrcmpA SetThreadPriority InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection CreateEventA WideCharToMultiByte VirtualLock VirtualProtect TlsSetValue IsBadReadPtr TlsAlloc SetErrorMode LockResource LoadResource FindResourceA GetFileSize GlobalFindAtomA GetVersion InterlockedIncrement InterlockedDecrement SetLastError lstrcpynA DuplicateHandle FlushFileBuffers LockFile UnlockFile SetEndOfFile MoveFileA FindClose GetLocalTime ExitThread GetFullPathNameA GetThreadLocale ResumeThread SuspendThread FileTimeToSystemTime FileTimeToLocalFileTime GetPrivateProfileIntA GetPrivateProfileStringA WritePrivateProfileStringA GetCurrentThread GetFileTime FindNextFileA GlobalHandle LocalReAlloc GlobalFlags GetProcessVersion SizeofResource VirtualAlloc GetCurrentDirectoryA RtlUnwind HeapAlloc HeapFree GetFileType RaiseException GetTimeZoneInformation GetSystemTime GetStdHandle SetHandleCount GetStartupInfoA GetCommandLineA ExitProcess GetSystemTimeAsFileTime HeapReAlloc GetACP HeapSize GetEnvironmentVariableA HeapDestroy HeapCreate VirtualFree EnumSystemLocalesA IsBadWritePtr SetStdHandle GetStringTypeA GetStringTypeW SetUnhandledExceptionFilter IsValidLocale IsValidCodePage GetLocaleInfoA FreeEnvironmentStringsA GetUserDefaultLCID UnhandledExceptionFilter CompareStringA CompareStringW FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW LCMapStringA LCMapStringW |
---|---|
ADVAPI32.dll |
RegQueryValueExA
RegCreateKeyExA RegSetValueExA RegDeleteValueA RegCloseKey RegDeleteKeyA RegOpenKeyExA RegQueryValueA |
COMCTL32.dll |
#17
ImageList_Destroy |
comdlg32.dll |
ChooseColorA
PrintDlgA ChooseFontA GetOpenFileNameA GetSaveFileNameA GetFileTitleA CommDlgExtendedError |
GDI32.dll |
LPtoDP
CreateDCA GetTextAlign CloseMetaFile GetTextExtentPointA GetViewportExtEx GetTextColor Escape RectVisible PtVisible GetWindowExtEx GetCurrentPositionEx SetTextAlign DeleteMetaFile GetBkColor MoveToEx LineTo IntersectClipRect SelectClipRgn ScaleWindowExtEx SetWindowExtEx SetWindowOrgEx DeleteObject SetViewportExtEx OffsetViewportOrgEx SetViewportOrgEx RestoreDC SaveDC GetClipBox SetTextColor SetBkMode TextOutA GetSystemPaletteEntries RemoveFontResourceA AddFontResourceA StartDocA StartPage EndPage EndDoc AbortDoc GetPixel Polygon Ellipse GetWindowOrgEx CreatePolygonRgn GetStockObject SetRectRgn GetRegionData ExtCreateRegion CreatePalette GetEnhMetaFileBits SetEnhMetaFileBits PlayEnhMetaFile DeleteEnhMetaFile CreateFontA GetCharWidthA DPtoLP SetMapMode SetBkColor CreateBitmap CreatePen ExtTextOutA PatBlt CreateDIBitmap GdiFlush ScaleViewportExtEx CreateCompatibleBitmap GetDIBits DeleteDC StretchDIBits SetDIBitsToDevice GetTextExtentPoint32A CreateFontIndirectA GetTextMetricsA CreateSolidBrush GetObjectA CreateCompatibleDC GetMapMode SelectObject GetDeviceCaps SelectPalette RealizePalette BitBlt CombineRgn CreateRectRgnIndirect CreateRectRgn OffsetRgn EqualRgn |
MSACM32.dll |
acmStreamPrepareHeader
acmStreamUnprepareHeader acmStreamConvert acmFormatSuggest acmStreamClose acmStreamSize acmStreamOpen |
ole32.dll |
CoInitialize
OleUninitialize CoCreateInstance CoFreeUnusedLibraries CoUninitialize CoTaskMemAlloc CoTaskMemFree CreateILockBytesOnHGlobal StgCreateDocfileOnILockBytes StgOpenStorageOnILockBytes CoGetClassObject CLSIDFromString CLSIDFromProgID CoRegisterMessageFilter CoRevokeClassObject OleFlushClipboard OleIsCurrentClipboard OleInitialize |
OLEAUT32.dll |
VariantClear
VariantCopy SysAllocString SysAllocStringByteLen VariantChangeType SysStringLen SysFreeString SysAllocStringLen VariantTimeToSystemTime |
oledlg.dll |
#8
|
OLEPRO32.DLL |
#253
|
SHELL32.dll |
SHBrowseForFolderA
SHGetPathFromIDListA SHGetDesktopFolder SHGetMalloc ShellExecuteA DragQueryFileA ShellExecuteExA DragAcceptFiles |
USER32.dll |
IsDialogMessageA
SetWindowTextA MoveWindow IsWindowEnabled GetNextDlgTabItem CheckMenuItem SetMenuItemBitmaps ModifyMenuA GetMenuState GetMenuCheckMarkDimensions GetWindowDC BeginPaint EndPaint TabbedTextOutA CreateDialogIndirectParamA LoadStringA CharUpperA SetFocus ValidateRect GetMessageA SetWindowContextHelpId MapDialogRect DestroyMenu GetSysColorBrush CopyAcceleratorTableA GetNextDlgGroupItem MessageBeep RegisterClipboardFormatA PostThreadMessageA AdjustWindowRectEx GetScrollInfo SetScrollInfo GetScrollRange SetScrollPos GetTopWindow IsChild GetCapture WinHelpA GetClassInfoA GetMenuItemCount TrackPopupMenu GetDlgItem GetWindowTextLengthA GetDlgCtrlID GetClassLongA CreateWindowExA SetPropA CallWindowProcA RemovePropA IsRectEmpty GetMessageTime EnumThreadWindows EndDialog GetWindowTextA GetClassNameA RegisterHotKey UnregisterHotKey SetForegroundWindow SetDlgItemTextA EnableMenuItem GetFocus InvalidateRgn DrawIcon GetSystemMenu DeleteMenu FindWindowA ChangeDisplaySettingsA GetTabbedTextExtentA PostQuitMessage RegisterWindowMessageA RegisterClassA UnregisterClassA DefWindowProcA LoadBitmapA GetMessagePos GetLastActivePopup GetWindow SetWindowLongA DrawFocusRect FrameRect SetRect UnionRect GetAsyncKeyState GetCursorPos ScreenToClient IsZoomed GrayStringA GetWindowPlacement wvsprintfA GetActiveWindow DrawTextA InflateRect GetForegroundWindow CopyRect OffsetRect CallNextHookEx SetWindowsHookExA wsprintfA UnhookWindowsHookEx OpenClipboard IsClipboardFormatAvailable GetClipboardData EmptyClipboard SetClipboardData CloseClipboard GetKeyState PtInRect MessageBoxA IntersectRect DrawFrameControl ClientToScreen IsWindowVisible UpdateWindow GetDesktopWindow SetRectEmpty SetCursor ReleaseCapture KillTimer SetCapture SetTimer LoadCursorA IsIconic GetDC ReleaseDC GetWindowRect SystemParametersInfoA EqualRect SetActiveWindow LoadIconA EnableWindow GetWindowRgn SetWindowRgn GetMenu GetSubMenu GetMenuItemID BringWindowToTop SendDlgItemMessageA MapWindowPoints LoadCursorFromFileA LoadMenuA GetPropA CharNextA HideCaret ShowCaret GetSystemMetrics PeekMessageA TranslateMessage DispatchMessageA PostMessageA DestroyWindow GetWindowThreadProcessId GetParent SendMessageA ExcludeUpdateRgn DefDlgProcA IsWindowUnicode SetParent InvalidateRect ShowWindow IsWindow GetSysColor GetClientRect EnumWindows SetWindowPos WaitForInputIdle GetWindowLongA |
VERSION.dll |
GetFileVersionInfoSizeA
GetFileVersionInfoA VerQueryValueA |
WINMM.dll |
waveOutOpen
waveInOpen waveInClose waveInReset mixerSetControlDetails waveInStart waveInGetNumDevs waveInGetDevCapsA waveInUnprepareHeader waveInPrepareHeader waveInAddBuffer waveOutGetPosition waveOutReset waveOutWrite waveOutUnprepareHeader waveOutPrepareHeader waveOutClose mixerClose waveOutGetNumDevs waveOutGetDevCapsA mciGetErrorStringA timeSetEvent timeKillEvent mciSendCommandA mixerGetNumDevs mixerOpen timeGetTime mciSendStringA mixerGetLineControlsA mixerGetLineInfoA mixerGetDevCapsA mixerGetControlDetailsA |
WINSPOOL.DRV |
DocumentPropertiesA
ClosePrinter OpenPrinterA |
Multimedia Player 4.9.8 |
MediaChance |
Wave Files (*.wav)|*.wav|| |
Supported song types (*.mod;*.s3m;*.xm;*.it)|*.mod;*.s3m;*.xm;*.it|Module Files (*.mod)|*.mod|Scream Tracker 3 Files (*.s3m)|*.s3m|Fast Tracker II Files (*.xm)|*.xm|Impulse Tracker Files (*.it)|*.it|| |
Midi Files (*.mid;*.rmi)|*.mid;*.rmi|| |
Supported song types (*.mpg;*.mp1;*.mp2;*.mp3;*.ogg;*.wma;*.asf)|*.mpg;*.mp1;*.mp2;*.mp3;*.ogg;*.wma;*.asf|MPEG Audio Files (*.mpg;*.mp1;*.mp2;*.mp3)|*.mpg;*.mp1;*.mp2;*.mp3|OggVorbis Files (*.ogg)|*.ogg|Windows Media Audio Files (*.wma)|*.wma|Advanced Streaming Format Files (*.asf)|*.asf|| |
Supported song types (*.mpg;*.mp1;*.mp2;*.mp3;*.ogg;*.wma;*.asf;*.wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it)|*.mpg;*.mp1;*.mp2;*.mp3;*.ogg;*.wma;*.asf;*wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it|Wave Files (*.wav)|*.wav|MPEG Audio Files (*.mpg;*.mp1;*.mp2;*.mp3)|*.mpg;*.mp1;*.mp2;*.mp3|OggVorbis Files (*.ogg)|*.ogg|Windows Media Audio Files (*.wma)|*.wma|Advanced Streaming Format Files (*.asf)|*.asf|Midi Files (*.mid;*.rmi)|*.mid;*.rmi|Module Files (*.mod)|*.mod|Scream Tracker 3 Files (*.s3m)|*.s3m|Fast Tracker II Files (*.xm)|*.xm|Impulse Tracker Files (*.it)|*.it|| |
Supported song types (*.wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it)|*.wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it|Wave Files (*.wav)|*.wav|Module Files (*.mod)|*.mod|Scream Tracker 3 Files (*.s3m)|*.s3m|Fast Tracker II Files (*.xm)|*.xm|Impulse Tracker Files (*.it)|*.it|Midi Files (*.mid;*.rmi)|*.mid;*.rmi|| |
Supported song types (*.ogg;*.wma;*.asf;*.wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it)|*.ogg;*.wma;*.asf;*.wav;*.mid;*.rmi;*.mod;*.s3m;*.xm;*.it|Wave Files (*.wav)|*.wav|OggVorbis Files (*.ogg)|*.ogg|Windows Media Audio Files (*.wma)|*.wma|Advanced Streaming Format Files (*.asf)|*.asf|Midi Files (*.mid;*.rmi)|*.mid;*.rmi|Module Files (*.mod)|*.mod|Scream Tracker 3 Files (*.s3m)|*.s3m|Fast Tracker II Files (*.xm)|*.xm|Impulse Tracker Files (*.it)|*.it|| |
Supported song types (*.ogg;*.wma;*.asf)|*.ogg;*.wma;*.asf|OggVorbis Files (*.ogg)|*.ogg|Windows Media Audio Files (*.wma)|*.wma|Advanced Streaming Format Files (*.asf)|*.asf|| |
Terminate download |
Connected to %1 |
Receiving... |
Redirecting to %1 |
Sending request... |
Resolving %1 |
Getting file information... |
Failed to connect to %1. |
%2 |
Failed to connect to Internet. |
%1 |
Error opening %1. |
The server returned status code %2. |
Error opening %1. |
%2 |
Error sending request. |
%1 |
Flash Player Download |
Macromedia Flash Player is not installed on your computer. |
Would you like to download it now? |
Flash Player is not installed. |
Some of the pages may not be functional. |
To view these pages new version of Flash player is required. |
Do you want to install and run Macromedia Flash player? |
Multimedia Player |
Copy the selection to the clipboard |
Copy |
Cut the selection and put it on the Clipboard |
Cut |
Insert the clipboard contents |
Paste |
Open |
Save As |
All Files (*.*) |
Untitled |
an unnamed file |
&Hide |
No error message is available. |
An unsupported operation was attempted. |
A required resource was unavailable. |
Out of memory. |
An unknown error has occurred. |
Invalid filename. |
Failed to open document. |
Failed to save document. |
Save changes to %1? |
Failed to create empty document. |
The file is too large to open. |
Could not start print job. |
Failed to launch help. |
Internal application error. |
Command failed. |
Insufficient memory to perform operation. |
System registry entries have been removed and the INI file (if any) was deleted. |
Not all of the system registry entries (or INI file) were removed. |
This program requires the file %s, which was not found on this system. |
This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
Please enter an integer. |
Please enter a number. |
Please enter an integer between %1 and %2. |
Please enter a number between %1 and %2. |
Please enter no more than %1 characters. |
Please select a button. |
Please enter an integer between 0 and 255. |
Please enter a positive integer. |
Please enter a date and/or time. |
Please enter a currency. |
Unexpected file format. |
%1 |
Cannot find this file. |
Please verify that the correct path and file name are given. |
Destination disk drive is full. |
Unable to read from %1, it is opened by someone else. |
Unable to write to %1, it is read-only or opened by someone else. |
An unexpected error occurred while reading %1. |
An unexpected error occurred while writing %1. |
Unable to read write-only property. |
Unable to write read-only property. |
Unable to load mail system support. |
Mail system DLL is invalid. |
Send Mail failed to send message. |
No error occurred. |
An unknown error occurred while accessing %1. |
%1 was not found. |
%1 contains an invalid path. |
%1 could not be opened because there are too many open files. |
Access to %1 was denied. |
An invalid file handle was associated with %1. |
%1 could not be removed because it is the current directory. |
%1 could not be created because the directory is full. |
Seek failed on %1 |
A hardware I/O error was reported while accessing %1. |
A sharing violation occurred while accessing %1. |
A locking violation occurred while accessing %1. |
Disk full while accessing %1. |
An attempt was made to access %1 past its end. |
No error occurred. |
An unknown error occurred while accessing %1. |
An attempt was made to write to the reading %1. |
An attempt was made to access %1 past its end. |
An attempt was made to read from the writing %1. |
%1 has a bad format. |
%1 contained an unexpected object. |
%1 contains an incorrect schema. |
pixels |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 4.9.8.13 |
FileFlags |
VS_FF_PRIVATEBUILD
VS_FF_SPECIALBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
Comments | Created with Multimedia Builder, version 4.9.8.13 |
CompanyName | |
FileDescription | |
FileVersion (#2) | 1.0.0.0 |
InternalName | |
LegalCopyright | |
LegalTrademarks | |
OriginalFilename | myaquaticlife.exe |
PrivateBuild | 1.0.0.0 |
ProductName | |
ProductVersion (#2) | 1.0.0.0 |
SpecialBuild | 1.0.0.0 |
Resource LangID | English - United States |
---|
XOR Key | 0xe926e21e |
---|---|
Unmarked objects | 0 |
C++ objects (8047) | 1 |
12 (7291) | 4 |
19 (8022) | 37 |
14 (7299) | 49 |
C objects (8830) | 1 |
C++ objects (8830) | 1 |
Unmarked objects (#2) | 217 |
19 (8034) | 25 |
C objects (VS98 SP6 build 8804) | 252 |
Total imports | 604 |
C++ objects (VS98 SP6 build 8804) | 161 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |