Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Jul-10 17:16:02 |
Detected languages |
English - Canada
English - United States |
Debug artifacts |
D:\arcdps\build-release-x64\pdb\d3d9.pdb
|
FileDescription | arcdps |
FileVersion | 0.0.0.1 |
ProductVersion | 0.0.0.1 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/67 (Scanned on 2018-07-12 09:52:12) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2018-Jul-10 17:16:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x60400 |
SizeOfInitializedData | 0x35800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000005F2D0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x9b000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WINMM.dll |
timeGetTime
timeBeginPeriod timeSetEvent timeKillEvent |
---|---|
d3dx9_43.dll |
D3DXCreateFontA
D3DXCreateSprite D3DXMatrixLookAtLH D3DXMatrixPerspectiveFovLH D3DXVec3Project |
KERNEL32.dll |
GetCurrentProcess
ExitProcess GetSystemDirectoryA VirtualAlloc FreeLibrary GetModuleHandleA GetProcAddress LoadLibraryA K32GetModuleInformation CreateTimerQueueTimer CreateSemaphoreA WideCharToMultiByte CloseHandle SetUnhandledExceptionFilter QueryPerformanceFrequency CreateThread GetCurrentThread SetThreadPriority ResumeThread GetThreadContext GetVersion GetTickCount64 MapViewOfFile GetModuleFileNameW GetLastError FormatMessageA CreateFileMappingA GetCurrentDirectoryA GetTickCount MultiByteToWideChar GetCurrentThreadId QueryPerformanceCounter CreateEventA FindClose FindFirstFileW FindNextFileW LoadLibraryW GetPrivateProfileStringW DeleteTimerQueueTimer GlobalAlloc GlobalLock GlobalUnlock K32GetProcessMemoryInfo VirtualProtect CreateFileW ReadFile ResetEvent ReleaseSemaphore WaitForSingleObject GetCurrentProcessId GetLogicalProcessorInformation QueueUserWorkItem GetPrivateProfileIntW WritePrivateProfileStringW CreateProcessW GetSystemTimeAsFileTime EncodePointer DecodePointer LocalFree |
USER32.dll |
FlashWindow
GetKeyState GetCursorPos ScreenToClient CallWindowProcA SetWindowLongPtrA GetActiveWindow AddClipboardFormatListener SendMessageA SetCursor MessageBoxA EmptyClipboard GetClientRect GetClipboardData SetClipboardData CloseClipboard OpenClipboard |
SHELL32.dll |
SHGetFolderPathW
ShellExecuteW SHCreateDirectoryExW |
CRYPT32.dll |
CryptBinaryToStringA
|
SHLWAPI.dll |
PathFileExistsA
|
MSVCR120.dll |
fflush
?terminate@@YAXXZ floorf ceilf sinf cosf _snprintf fmodf strncpy strchr memmove isprint _vacopy __clean_type_info_names_internal ?_type_info_dtor_internal_method@type_info@@QEAAXXZ _wfopen vfprintf sscanf ftell _initterm_e _initterm fprintf __iob_func _malloc_crt _amsg_exit __CppXcptFilter _vsnprintf _onexit __dllonexit _calloc_crt _unlock ??2@YAPEAX_K@Z ??3@YAXPEAX@Z __CxxFrameHandler3 qsort strftime _localtime64_s _time64 __C_specific_handler atan2f memset fclose _vswprintf_c_l _set_invalid_parameter_handler wcstof wcsstr memcmp roundf _vsnprintf_s strtoul strncmp mbstowcs wcstoul wcsncmp memcpy strstr tolower fread fseek fwrite _wfsopen _errno sqrtf _gmtime64_s _vscprintf exit free malloc _msize wcstol _lock |
IMM32.dll |
ImmSetCompositionWindow
ImmGetContext |
Ordinal | 1 |
---|---|
Address | 0x10c0 |
Ordinal | 2 |
---|---|
Address | 0x10d0 |
Ordinal | 3 |
---|---|
Address | 0x10e0 |
Ordinal | 4 |
---|---|
Address | 0x10f0 |
Ordinal | 5 |
---|---|
Address | 0x1310 |
Ordinal | 6 |
---|---|
Address | 0x1320 |
Ordinal | 7 |
---|---|
Address | 0x34cb0 |
Ordinal | 8 |
---|---|
Address | 0x14c0 |
Ordinal | 9 |
---|---|
Address | 0x14d0 |
Ordinal | 10 |
---|---|
Address | 0x14e0 |
Ordinal | 11 |
---|---|
Address | 0x14f0 |
Ordinal | 12 |
---|---|
Address | 0x1500 |
Ordinal | 13 |
---|---|
Address | 0x1510 |
Ordinal | 14 |
---|---|
Address | 0x1520 |
Ordinal | 15 |
---|---|
Address | 0x1590 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 0.0.0.1 |
ProductVersion | 0.0.0.1 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - Canada |
FileDescription | arcdps |
FileVersion (#2) | 0.0.0.1 |
ProductVersion (#2) | 0.0.0.1 |
Resource LangID | English - Canada |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jul-10 17:16:02 |
Version | 0.0 |
SizeofData | 65 |
AddressOfRawData | 0x6b330 |
PointerToRawData | 0x69b30 |
Referenced File | D:\arcdps\build-release-x64\pdb\d3d9.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2018-Jul-10 17:16:02 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x6b374 |
PointerToRawData | 0x69b74 |
Size | 0x70 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x180074068 |
XOR Key | 0x50d2f47e |
---|---|
Unmarked objects | 0 |
221 (20806) | 2 |
199 (41118) | 2 |
ASM objects (20806) | 5 |
C objects (20806) | 10 |
C++ objects (20806) | 5 |
Imports (21202) | 2 |
Imports (65501) | 19 |
Total imports | 191 |
C++ objects (VS2013 UPD5 build 40629) | 96 |
Exports (VS2013 UPD5 build 40629) | 1 |
Resource objects (VS2013 build 21005) | 1 |
151 | 1 |
Linker (VS2013 UPD5 build 40629) | 1 |