| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2009-Feb-11 16:02:04 |
| Detected languages |
English - United States
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .secu
Section .secu is both writable and executable. |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. |
10999998 bytes of data starting at offset 0x315000.
Overlay data amounts for 77.292% of the executable. |
| Malicious | VirusTotal score: 11/72 (Scanned on 2026-04-07 00:51:30) |
APEX:
Malicious
CAT-QuickHeal: Trojan.Ghanarava.1515421465a38ea0 CrowdStrike: win/malicious_confidence_60% (W) DeepInstinct: MALICIOUS Google: Detected Gridinsoft: Virus.Win32.Virut.cl Microsoft: PUA:Win32/GameHack NANO-Antivirus: Virus.Win32.Virut-Gen.bwpxnc TrellixENS: Artemis!E26B9BEE8555 Varist: W32/Risk.LORQ-1960 Xcitium: Virus.Win32.Virut.CE@1fhkga |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2009-Feb-11 16:02:04 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x26b000 |
| SizeOfInitializedData | 0x16d000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0021C2A1 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x238000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3d9000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x500000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3dx9_35.dll |
D3DXCreateEffectPool
D3DXCreateEffectEx D3DXMatrixInverse D3DXMatrixOrthoLH D3DXMatrixMultiply D3DXMatrixTranspose |
|---|---|
| WINMM.dll |
timeBeginPeriod
timeEndPeriod |
| COMCTL32.dll |
#17
|
| fmod_event.dll |
?setCallback@Event@FMOD@@QAG?AW4FMOD_RESULT@@P6G?AW43@PAUFMOD_EVENT@@W4FMOD_EVENT_CALLBACKTYPE@@PAX22@Z2@Z
_FMOD_EventSystem_Create@4 ?start@Event@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?setVolume@Event@FMOD@@QAG?AW4FMOD_RESULT@@M@Z ?stop@Event@FMOD@@QAG?AW4FMOD_RESULT@@_N@Z ?getUserData@Event@FMOD@@QAG?AW4FMOD_RESULT@@PAPAX@Z ?setPaused@Event@FMOD@@QAG?AW4FMOD_RESULT@@_N@Z ?setPitch@Event@FMOD@@QAG?AW4FMOD_RESULT@@M@Z ?set3DAttributes@Event@FMOD@@QAG?AW4FMOD_RESULT@@PBUFMOD_VECTOR@@00@Z ?getPropertyByIndex@Event@FMOD@@QAG?AW4FMOD_RESULT@@HPAX_N@Z ?setUserData@Event@FMOD@@QAG?AW4FMOD_RESULT@@PAX@Z ?getState@Event@FMOD@@QAG?AW4FMOD_RESULT@@PAI@Z _FMOD_File_SetDiskBusy@4 _FMOD_Debug_SetLevel@4 |
| fmodex.dll |
?stop@Channel@FMOD@@QAG?AW4FMOD_RESULT@@XZ
?createStream@System@FMOD@@QAG?AW4FMOD_RESULT@@PBDIPAUFMOD_CREATESOUNDEXINFO@@PAPAVSound@2@@Z ?setPaused@Channel@FMOD@@QAG?AW4FMOD_RESULT@@_N@Z ?getOpenState@Sound@FMOD@@QAG?AW4FMOD_RESULT@@PAW4FMOD_OPENSTATE@@PAIPA_N@Z ?release@Sound@FMOD@@QAG?AW4FMOD_RESULT@@XZ ?isPlaying@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PA_N@Z ?getPaused@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PA_N@Z ?setCallback@Channel@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_CHANNEL_CALLBACKTYPE@@P6G?AW43@PAUFMOD_CHANNEL@@0HII@ZH@Z ?setSpeakerLevels@Channel@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_SPEAKER@@PAMH@Z ?setFrequency@Channel@FMOD@@QAG?AW4FMOD_RESULT@@M@Z ?set3DMinMaxDistance@Channel@FMOD@@QAG?AW4FMOD_RESULT@@MM@Z ?set3DAttributes@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PBUFMOD_VECTOR@@0@Z ?getPosition@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAII@Z ?createSound@System@FMOD@@QAG?AW4FMOD_RESULT@@PBDIPAUFMOD_CREATESOUNDEXINFO@@PAPAVSound@2@@Z ?getSubSound@Sound@FMOD@@QAG?AW4FMOD_RESULT@@HPAPAV12@@Z ?setMode@Sound@FMOD@@QAG?AW4FMOD_RESULT@@I@Z ?setPriority@Channel@FMOD@@QAG?AW4FMOD_RESULT@@H@Z ?getFrequency@Channel@FMOD@@QAG?AW4FMOD_RESULT@@PAM@Z ?playSound@System@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_CHANNELINDEX@@PAVSound@2@_NPAPAVChannel@2@@Z FMOD_Memory_Initialize FMOD_Memory_GetStats ?set3DListenerAttributes@System@FMOD@@QAG?AW4FMOD_RESULT@@HPBUFMOD_VECTOR@@000@Z ?setSoftwareFormat@System@FMOD@@QAG?AW4FMOD_RESULT@@HW4FMOD_SOUND_FORMAT@@HHW4FMOD_DSP_RESAMPLER@@@Z ?setSpeakerMode@System@FMOD@@QAG?AW4FMOD_RESULT@@W4FMOD_SPEAKERMODE@@@Z ?setDSPBufferSize@System@FMOD@@QAG?AW4FMOD_RESULT@@IH@Z ?getDriverCaps@System@FMOD@@QAG?AW4FMOD_RESULT@@HPAIPAH1PAW4FMOD_SPEAKERMODE@@@Z ?setSoftwareChannels@System@FMOD@@QAG?AW4FMOD_RESULT@@H@Z ?getVersion@System@FMOD@@QAG?AW4FMOD_RESULT@@PAI@Z ?setVolume@Channel@FMOD@@QAG?AW4FMOD_RESULT@@M@Z |
| DINPUT8.dll |
DirectInput8Create
|
| binkw32.dll |
_BinkOpen@8
_BinkSetVolume@12 _BinkWait@4 _BinkClose@4 _BinkSetSoundSystem@8 _BinkDoFrame@4 _BinkShouldSkip@4 _BinkNextFrame@4 _BinkCopyToBufferRect@44 _BinkGetRects@8 _BinkOpenDirectSound@4 _BinkPause@8 |
| SHLWAPI.dll |
PathAppendW
PathFileExistsW |
| KERNEL32.dll |
GetConsoleMode
GetConsoleCP GetLocaleInfoA GetStringTypeW GetStringTypeA GetCurrentProcessId GetTickCount GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW GetEnvironmentStrings FreeEnvironmentStringsA GetStartupInfoA SetHandleCount SetFilePointer LCMapStringW LCMapStringA LoadLibraryA HeapSize VirtualAlloc VirtualFree HeapCreate HeapDestroy GetModuleFileNameA GetCurrentThreadId SetLastError TlsFree TlsSetValue TlsAlloc TlsGetValue IsValidCodePage GetOEMCP GetACP InterlockedDecrement InterlockedIncrement GetCPInfo GetStartupInfoW GetProcessHeap GetSystemTimeAsFileTime FlushFileBuffers WideCharToMultiByte ExitProcess GetModuleHandleA RtlUnwind SetStdHandle IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter TerminateProcess HeapFree HeapAlloc HeapReAlloc GetStdHandle WriteConsoleW CreateFileA WriteConsoleA EnterCriticalSection LeaveCriticalSection InitializeCriticalSection QueryPerformanceCounter QueryPerformanceFrequency DeleteCriticalSection GetModuleHandleW GetVersionExW MultiByteToWideChar FreeLibrary GetProcAddress LoadLibraryW GetCommandLineW SetThreadExecutionState Sleep GetLastError GetModuleFileNameW CloseHandle GetCurrentProcess lstrlenW GetVersionExA GetFileAttributesW ExpandEnvironmentStringsW CreateEventW WriteFile CreateFileW GetUserDefaultUILanguage ReadFile CompareFileTime SystemTimeToFileTime GetDiskFreeSpaceW SystemTimeToTzSpecificLocalTime GetTimeZoneInformation GetSystemTime FindClose FindFirstFileW SetFileAttributesW DeleteFileW Process32NextW Process32FirstW CreateToolhelp32Snapshot SetProcessAffinityMask GetConsoleOutputCP SetEndOfFile RaiseException GetFileType |
| USER32.dll |
SendMessageW
IsWindowVisible IsZoomed AdjustWindowRect IsIconic SetWindowPos SetWindowPlacement GetMenu GetWindowPlacement SetMenu SetWindowLongW GetWindowLongW DefWindowProcW GetCursorPos UnregisterClassW DestroyWindow DestroyMenu ScreenToClient CreateWindowExW PostQuitMessage RegisterClassW LoadCursorW DestroyAcceleratorTable DispatchMessageW TranslateMessage TranslateAcceleratorW PeekMessageW GetMonitorInfoW EnumDisplaySettingsW SystemParametersInfoA SetTimer UnhookWindowsHookEx SetWindowsHookExW CallNextHookEx GetIconInfo GetDC ReleaseDC ShowWindow GetSystemMetrics MessageBoxW GetClientRect SetCursor GetClassLongW GetWindowRect ClipCursor SetRect SystemParametersInfoW |
| GDI32.dll |
GetDIBits
DeleteObject GetObjectW CreateCompatibleDC SelectObject GetStockObject DeleteDC |
| SHELL32.dll |
SHGetFolderPathW
SHCreateDirectoryExW ShellExecuteW ExtractIconW CommandLineToArgvW |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x6dc2e0 |
| SEHandlerTable | 0x681180 |
| SEHandlerCount | 61 |
No comments yet.