| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-May-10 15:58:59 |
| Detected languages |
English - United Kingdom
Process Default Language |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ v7.1 EXE Microsoft Visual Basic v5.0 - v6.0 MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Suspicious | PEiD Signature: | PeStubOEP v1.x |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE's digital signature is invalid. |
Signer: Frogwares Ireland ltd
Issuer: COMODO RSA Extended Validation Code Signing CA The file was modified after it was signed. |
| Safe | VirusTotal score: 0/75 (Scanned on 2024-09-05 07:57:35) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x150 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2012-May-10 15:58:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x215000 |
| SizeOfInitializedData | 0x210000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0020F9DE (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x216000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 1.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x426000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x427e08 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x800000 |
| SizeofStackCommit | 0x800000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3dx9_42.dll |
D3DXMatrixTranspose
D3DXPlaneTransform D3DXPlaneFromPointNormal D3DXMatrixInverse D3DXSaveTextureToFileInMemory D3DXCreateRenderToSurface D3DXCheckCubeTextureRequirements D3DXFillCubeTexture D3DXFillTexture D3DXGetImageInfoFromFileInMemory D3DXCreateTextureFromFileInMemoryEx D3DXCreateCubeTextureFromFileInMemory D3DXCreateBuffer D3DXGetShaderConstantTable D3DXCheckTextureRequirements |
|---|---|
| DINPUT8.dll |
DirectInput8Create
|
| PhysXLoader.dll |
NxGetCookingLib
NxCreatePhysicsSDKWithID NxGetUtilLib NxReleasePhysicsSDK |
| NxCharacter.dll |
NxCreateControllerManager
NxReleaseControllerManager |
| DSOUND.dll |
#11
|
| NxCooking.dll |
NxInitCooking
NxCloseCooking NxCookTriangleMesh |
| KERNEL32.dll |
CreateDirectoryA
FlushFileBuffers FreeLibrary OutputDebugStringA ReadFile WriteFile SetFilePointer GetFileSize GetSystemInfo CreateFileMappingA GetStartupInfoA OpenEventA UnmapViewOfFile MapViewOfFile CreateFileA LocalFree TryEnterCriticalSection InitializeCriticalSection Sleep LeaveCriticalSection DeleteFileA GetDateFormatW SystemTimeToTzSpecificLocalTime GetTimeFormatW FileTimeToSystemTime FindFirstFileA FindClose FindNextFileA GetLocalTime QueryPerformanceCounter QueryPerformanceFrequency GetModuleHandleA GetModuleFileNameA CreateProcessA CloseHandle WaitForSingleObject SetEvent CreateEventA SetThreadPriority IsDebuggerPresent GetCurrentThreadId GetProcAddress LoadLibraryA GetVersion WideCharToMultiByte MultiByteToWideChar GetFileTime GetFileAttributesA TerminateThread EnterCriticalSection DeleteCriticalSection GlobalLock GlobalAlloc GlobalUnlock FormatMessageA GetLastError |
| USER32.dll |
DestroyWindow
SetCursor GetWindowRect DeleteMenu LoadIconA GetMonitorInfoA GetSystemMenu ShowCursor GetKeyboardState GetKeyboardLayout UnregisterClassA CreateWindowExA ReleaseDC DefWindowProcA SetWindowPos GetMenuItemInfoA GetMenuItemCount SystemParametersInfoA AdjustWindowRect LoadCursorA SetWindowTextW SetMenuItemInfoW ChangeDisplaySettingsA RegisterClassA ToUnicodeEx CloseClipboard GetClipboardData EmptyClipboard OpenClipboard GetDC PostQuitMessage SetForegroundWindow SetFocus ShowWindow GetSystemMetrics EnumDisplaySettingsA MessageBoxA ClipCursor TranslateMessage PeekMessageA DispatchMessageA SetClipboardData |
| GDI32.dll |
GetDeviceCaps
DeleteDC CreateICA |
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegQueryValueExA |
| SHELL32.dll |
SHGetFolderPathA
|
| binkw32.dll |
_BinkClose@4
_BinkOpen@8 _BinkGoto@12 _BinkDoFrame@4 _BinkWait@4 _BinkGetRealtime@12 _BinkNextFrame@4 _BinkGetFrameBuffersInfo@8 _BinkPause@8 _BinkCopyToBuffer@28 |
| MSVCR71.dll |
_CxxThrowException
_callnewh ?what@exception@@UBEPBDXZ ??0exception@@QAE@ABQBD@Z _strlwr qsort ??1type_info@@UAE@XZ ?terminate@@YAXXZ _except_handler3 __dllonexit _onexit _iob _c_exit _exit _XcptFilter _ismbblead calloc localeconv setvbuf fscanf tmpfile _popen _pclose setlocale difftime mktime time localtime strftime clock tmpnam rename remove system strpbrk iscntrl __CxxFrameHandler ispunct isupper isxdigit toupper ldexp frexp modf _CIfmod ceil _CIacos _CIasin _CItanh _CIcosh _CIsinh fputs fgets _CIpow strcoll strcspn strncat strtoul _setjmp3 getc ungetc _cexit _acmdln _amsg_exit __getmainargs _initterm __setusermatherr _adjust_fdiv __p__commode __p__fmode _local_unwind2 __set_app_type _controlfp clearerr islower _errno strerror gmtime strtod abort getenv fprintf longjmp ?before@type_info@@QBEHABV1@@Z wcscmp memmove free malloc _purecall ??3@YAXPAX@Z exit sprintf ??8type_info@@QBEHABV0@@Z ??1exception@@UAE@XZ ??0exception@@QAE@XZ ??0exception@@QAE@ABV0@@Z ?name@type_info@@QBEPBDXZ rand srand vsprintf _beginthreadex ctime memchr atoi atof strchr realloc __RTDynamicCast floor isdigit wcslen _fpclass _stricmp strstr strncpy fflush fopen fread fwrite ftell fseek fclose printf sscanf _snprintf strncmp isspace isalnum tolower isalpha strrchr |
| Ordinal | 1 |
|---|---|
| Address | 0x12560 |
| Ordinal | 2 |
|---|---|
| Address | 0x2930 |
| Ordinal | 3 |
|---|---|
| Address | 0xd8090 |
| Ordinal | 4 |
|---|---|
| Address | 0x38490 |
| Ordinal | 5 |
|---|---|
| Address | 0x1dd980 |
| Ordinal | 6 |
|---|---|
| Address | 0x1a19d0 |
| Ordinal | 7 |
|---|---|
| Address | 0x172430 |
| Ordinal | 8 |
|---|---|
| Address | 0x29fc0 |
| Ordinal | 9 |
|---|---|
| Address | 0x1e0430 |
| Ordinal | 10 |
|---|---|
| Address | 0x1e3620 |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x764660 |
| SEHandlerTable | 0x651940 |
| SEHandlerCount | 381 |
| XOR Key | 0x58f04140 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2003 (.NET) build 3077) | 2 |
| ASM objects (VS2003 (.NET) build 3077) | 10 |
| Imports (9210) | 2 |
| Imports (2067) | 2 |
| Imports (2179) | 8 |
| 105 (2067) | 2 |
| C++ objects (VS2003 (.NET) build 3077) | 7 |
| C objects (2179) | 1 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 8 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Imports (VS2003 (.NET) build 4035) | 4 |
| C objects (VS2003 (.NET) build 4035) | 3 |
| Imports (VS2008 SP1 build 30729) | 3 |
| Total imports | 303 |
| C objects (VS2003 (.NET) build 3077) | 45 |
| 99 (VS2003 (.NET) build 3077) | 442 |
| Exports (VS2003 (.NET) build 3077) | 1 |
| 94 (VS2003 (.NET) build 3052) | 1 |
| Unmarked objects (#2) | 4 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.