Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2006-Dec-07 08:33:40 |
Detected languages |
English - United States
French - France |
Debug artifacts |
c:\Prog\Totemtech\Zouna\Csr\CSRTNLBF.pdb
|
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/61 (Scanned on 2017-03-17 15:19:27) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2006-Dec-07 08:33:40 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0x181000 |
SizeOfInitializedData | 0x7a000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0016397A (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x182000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1fc000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
COMCTL32.dll |
#17
|
---|---|
DINPUT8.dll |
DirectInput8Create
|
d3dx9_27.dll |
D3DXMatrixMultiply
D3DXCompileShaderFromResourceA |
d3d9.dll |
Direct3DCreate9
|
DDRAW.dll |
DirectDrawCreate
|
DSOUND.dll |
#1
|
WINMM.dll |
timeKillEvent
timeSetEvent sndPlaySoundA |
KERNEL32.dll |
OutputDebugStringA
MultiByteToWideChar LoadLibraryA Sleep LCMapStringA CreateFileA FlushFileBuffers SetStdHandle GetTimeZoneInformation RaiseException InterlockedExchange GetCPInfo GetOEMCP GetACP GetStringTypeW GetStringTypeA IsBadCodePtr IsBadReadPtr SetUnhandledExceptionFilter GetFileAttributesA VirtualQuery WaitForSingleObject GetTickCount ReadFile SetFilePointer CloseHandle GetFileType SetHandleCount GetEnvironmentStringsW WideCharToMultiByte FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA UnhandledExceptionFilter GetStdHandle WriteFile GetModuleFileNameA GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId QueryPerformanceCounter HeapSize IsBadWritePtr VirtualAlloc VirtualFree HeapCreate GetCommandLineA GetDriveTypeA GetUserDefaultLangID LCMapStringW VirtualProtect GetExitCodeProcess SetConsoleCtrlHandler CreateProcessA HeapDestroy GetSystemInfo RemoveDirectoryA SetCurrentDirectoryA DeleteFileA CompareStringW CompareStringA SetEndOfFile GetCurrentDirectoryA HeapFree RtlUnwind HeapAlloc HeapReAlloc ExitProcess GetProcAddress GetModuleHandleA TerminateProcess GetCurrentProcess GetStartupInfoA GetVersionExA FindClose FileTimeToSystemTime FileTimeToLocalFileTime GetLastError FindFirstFileA FindNextFileA CreateDirectoryA SetEnvironmentVariableA GetLocaleInfoA |
USER32.dll |
LoadIconA
GetKeyNameTextA ShowWindow GetSysColor GetDC ReleaseDC AppendMenuA CheckMenuItem EnableMenuItem ClientToScreen TrackPopupMenu LoadMenuA GetSubMenu MessageBoxA InvalidateRect GetClientRect GetWindowLongA EndDialog SetWindowTextA GetWindowTextA CallWindowProcA CreateDialogParamA GetDlgItem GetWindowRect LoadCursorA RegisterClassA CreateWindowExA GetSystemMetrics SetWindowLongA UpdateWindow SetFocus SetWindowPos ShowCursor PostQuitMessage DefWindowProcA SetCursor SendMessageA DispatchMessageA TranslateMessage PeekMessageA GetMessageA |
GDI32.dll |
CreateBrushIndirect
StretchDIBits CreateFontA GetStockObject CreatePen |
ADVAPI32.dll |
RegFlushKey
RegQueryValueExA RegSetValueExA RegOpenKeyExA RegCreateKeyExA RegCloseKey |
ole32.dll |
CoUninitialize
CoInitialize CoCreateInstance |
Characteristics |
0
|
---|---|
TimeDateStamp | 2006-Dec-07 08:33:40 |
Version | 0.0 |
SizeofData | 65 |
AddressOfRawData | 0x19e978 |
PointerToRawData | 0x19e978 |
Referenced File | c:\Prog\Totemtech\Zouna\Csr\CSRTNLBF.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x5b7060 |
SEHandlerTable | 0x59e9c0 |
SEHandlerCount | 1406 |
XOR Key | 0xda7f1243 |
---|---|
Unmarked objects | 0 |
105 (2067) | 4 |
ASM objects (VS2003 (.NET) build 3077) | 35 |
C objects (VS2003 (.NET) build 3077) | 135 |
Imports (2067) | 2 |
C objects (9178) | 2 |
Imports (2179) | 13 |
C objects (VS2003 (.NET) build 4035) | 2 |
Total imports | 148 |
Imports (VS2003 (.NET) build 4035) | 10 |
C++ objects (VS2003 (.NET) build 4035) | 1 |
C++ objects (VS2003 (.NET) build 3077) | 460 |
94 (VS2003 (.NET) build 3052) | 1 |
Linker (VS2003 (.NET) build 3077) | 1 |