Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-May-30 16:33:32 |
Detected languages |
English - United Kingdom
English - United States |
Comments | www.goldensoft.org |
FileDescription | GS Auto Clicker |
FileVersion | 3.1.4 |
LegalCopyright | goldensoft.org |
ProductName | GS Auto Clicker |
ProductVersion | 3.1.4 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses known Mersenne Twister constants |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
219049 bytes of data starting at offset 0x9e400.
The overlay data has an entropy of 7.99918 and is possibly compressed or encrypted. |
Malicious | VirusTotal score: 4/71 (Scanned on 2023-06-10 02:03:28) |
Bkav:
W32.AIDetectMalware
APEX: Malicious Jiangmin: Trojan.Generic.ecdsu MaxSecure: Trojan.Malware.74623402.susgen |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2016-May-30 16:33:32 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x80200 |
SizeOfInitializedData | 0x1de00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00016310 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x82000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb5000 |
SizeOfHeaders | 0x400 |
Checksum | 0xd72a0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x400000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WSOCK32.dll |
__WSAFDIsSet
setsockopt ntohs recvfrom sendto htons select listen WSAStartup bind closesocket connect socket send WSACleanup ioctlsocket accept WSAGetLastError inet_addr gethostbyname gethostname recv |
---|---|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
WINMM.dll |
timeGetTime
waveOutSetVolume mciSendStringW |
COMCTL32.dll |
ImageList_Remove
ImageList_SetDragCursorImage ImageList_BeginDrag ImageList_DragEnter ImageList_DragLeave ImageList_EndDrag ImageList_DragMove ImageList_ReplaceIcon ImageList_Create InitCommonControlsEx ImageList_Destroy |
MPR.dll |
WNetCancelConnection2W
WNetGetConnectionW WNetAddConnection2W WNetUseConnectionW |
WININET.dll |
InternetReadFile
InternetCloseHandle InternetOpenW InternetSetOptionW InternetCrackUrlW HttpQueryInfoW InternetConnectW HttpOpenRequestW HttpSendRequestW FtpOpenFileW FtpGetFileSize InternetOpenUrlW InternetQueryOptionW InternetQueryDataAvailable |
PSAPI.DLL |
EnumProcesses
GetModuleBaseNameW GetProcessMemoryInfo EnumProcessModules |
USERENV.dll |
CreateEnvironmentBlock
DestroyEnvironmentBlock UnloadUserProfile LoadUserProfileW |
KERNEL32.dll |
HeapAlloc
Sleep GetCurrentThreadId RaiseException MulDiv GetVersionExW GetSystemInfo MultiByteToWideChar WideCharToMultiByte GetModuleHandleW QueryPerformanceCounter VirtualFreeEx OpenProcess VirtualAllocEx WriteProcessMemory ReadProcessMemory CreateFileW SetFilePointerEx ReadFile WriteFile FlushFileBuffers TerminateProcess CreateToolhelp32Snapshot Process32FirstW Process32NextW SetFileTime GetFileAttributesW FindFirstFileW FindClose DeleteFileW FindNextFileW lstrcmpiW MoveFileW CopyFileW CreateDirectoryW RemoveDirectoryW SetSystemPowerState QueryPerformanceFrequency FindResourceW LoadResource LockResource SizeofResource GetProcessHeap OutputDebugStringW GetLocalTime CompareStringW CompareStringA InterlockedIncrement InterlockedDecrement DeleteCriticalSection EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount GetStdHandle CreatePipe InterlockedExchange TerminateThread GetTempPathW GetTempFileNameW VirtualFree FormatMessageW GetExitCodeProcess SetErrorMode GetPrivateProfileStringW WritePrivateProfileStringW GetPrivateProfileSectionW WritePrivateProfileSectionW GetPrivateProfileSectionNamesW FileTimeToLocalFileTime FileTimeToSystemTime SystemTimeToFileTime LocalFileTimeToFileTime GetDriveTypeW GetDiskFreeSpaceExW GetDiskFreeSpaceW GetVolumeInformationW SetVolumeLabelW CreateHardLinkW DeviceIoControl SetFileAttributesW GetShortPathNameW CreateEventW SetEvent GetEnvironmentVariableW SetEnvironmentVariableW GlobalLock GlobalUnlock GlobalAlloc GetFileSize GlobalFree GlobalMemoryStatusEx Beep GetComputerNameW GetWindowsDirectoryW GetSystemDirectoryW GetCurrentProcessId GetCurrentThread GetProcessIoCounters CreateProcessW SetPriorityClass LoadLibraryW VirtualAlloc LoadLibraryExW HeapFree WaitForSingleObject CreateThread DuplicateHandle GetLastError CloseHandle GetCurrentProcess GetProcAddress LoadLibraryA FreeLibrary GetModuleFileNameW GetFullPathNameW ExitProcess ExitThread GetSystemTimeAsFileTime SetCurrentDirectoryW IsDebuggerPresent GetCurrentDirectoryW ResumeThread GetStartupInfoW TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError HeapSize GetCPInfo GetACP GetOEMCP IsValidCodePage UnhandledExceptionFilter SetUnhandledExceptionFilter GetModuleFileNameA HeapReAlloc HeapCreate SetHandleCount GetFileType GetStartupInfoA SetStdHandle GetConsoleCP GetConsoleMode LCMapStringW LCMapStringA RtlUnwind SetFilePointer GetTimeZoneInformation GetTimeFormatA GetDateFormatA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetTickCount GetStringTypeA GetStringTypeW GetLocaleInfoA GetModuleHandleA WriteConsoleA GetConsoleOutputCP WriteConsoleW CreateFileA SetEndOfFile EnumResourceNamesW SetEnvironmentVariableA |
USER32.dll |
SetWindowPos
GetCursorInfo RegisterHotKey ClientToScreen GetKeyboardLayoutNameW IsCharAlphaW IsCharAlphaNumericW IsCharLowerW IsCharUpperW GetMenuStringW GetSubMenu GetCaretPos IsZoomed MonitorFromPoint GetMonitorInfoW SetWindowLongW SetLayeredWindowAttributes FlashWindow GetClassLongW TranslateAcceleratorW IsDialogMessageW GetSysColor InflateRect DrawFocusRect DrawTextW FrameRect DrawFrameControl FillRect PtInRect DestroyAcceleratorTable CreateAcceleratorTableW SetCursor GetWindowDC GetSystemMetrics GetActiveWindow CharNextW wsprintfW RedrawWindow DrawMenuBar DestroyMenu SetMenu GetWindowTextLengthW CreateMenu IsDlgButtonChecked DefDlgProcW ReleaseCapture SetCapture WindowFromPoint CreateIconFromResourceEx mouse_event ExitWindowsEx SetActiveWindow FindWindowExW EnumThreadWindows SetMenuDefaultItem InsertMenuItemW IsMenu TrackPopupMenuEx GetCursorPos DeleteMenu CheckMenuRadioItem CopyImage GetMenuItemCount SetMenuItemInfoW GetMenuItemInfoW SetForegroundWindow IsIconic FindWindowW SystemParametersInfoW PeekMessageW SendInput GetAsyncKeyState SetKeyboardState GetKeyboardState GetKeyState VkKeyScanW LoadStringW DialogBoxParamW MessageBeep EndDialog SendDlgItemMessageW GetDlgItem SetWindowTextW CopyRect ReleaseDC GetDC EndPaint BeginPaint GetClientRect GetMenu DestroyWindow EnumWindows GetDesktopWindow IsWindow IsWindowEnabled IsWindowVisible EnableWindow InvalidateRect GetWindowThreadProcessId AttachThreadInput GetFocus GetWindowTextW ScreenToClient SendMessageTimeoutW EnumChildWindows CharUpperBuffW GetClassNameW GetParent GetDlgCtrlID SendMessageW MapVirtualKeyW PostMessageW GetWindowRect SetUserObjectSecurity GetUserObjectSecurity CloseDesktop CloseWindowStation OpenDesktopW SetProcessWindowStation GetProcessWindowStation OpenWindowStationW MessageBoxW DefWindowProcW MoveWindow AdjustWindowRectEx SetRect SetClipboardData EmptyClipboard CountClipboardFormats CloseClipboard GetClipboardData IsClipboardFormatAvailable OpenClipboard BlockInput GetMessageW LockWindowUpdate DispatchMessageW GetMenuItemID TranslateMessage SetFocus PostQuitMessage KillTimer CreatePopupMenu RegisterWindowMessageW SetTimer ShowWindow CreateWindowExW RegisterClassExW LoadIconW LoadCursorW GetSysColorBrush GetForegroundWindow MessageBoxA DestroyIcon UnregisterHotKey CharLowerBuffW MonitorFromRect keybd_event LoadImageW GetWindowLongW |
GDI32.dll |
DeleteObject
GetObjectW GetTextExtentPoint32W ExtCreatePen StrokeAndFillPath StrokePath EndPath SetPixel CloseFigure CreateCompatibleBitmap CreateCompatibleDC SelectObject StretchBlt GetDIBits LineTo AngleArc MoveToEx Ellipse PolyDraw BeginPath Rectangle GetDeviceCaps SetBkMode RoundRect SetBkColor CreatePen CreateSolidBrush SetTextColor CreateFontW GetTextFaceW GetStockObject CreateDCW GetPixel DeleteDC SetViewportOrgEx |
COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
ADVAPI32.dll |
RegEnumValueW
RegDeleteValueW RegDeleteKeyW RegSetValueExW RegCreateKeyExW GetUserNameW RegConnectRegistryW RegEnumKeyExW CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW InitiateSystemShutdownExW AdjustTokenPrivileges RegCloseKey RegQueryValueExW RegOpenKeyExW OpenThreadToken OpenProcessToken LookupPrivilegeValueW DuplicateTokenEx CreateProcessAsUserW CreateProcessWithLogonW InitializeSecurityDescriptor InitializeAcl GetLengthSid SetSecurityDescriptorDacl CopySid LogonUserW GetTokenInformation GetAclInformation GetAce AddAce GetSecurityDescriptorDacl |
SHELL32.dll |
DragQueryPoint
ShellExecuteExW SHGetFolderPathW DragQueryFileW SHEmptyRecycleBinW SHBrowseForFolderW SHFileOperationW SHGetPathFromIDListW SHGetDesktopFolder SHGetMalloc ExtractIconExW Shell_NotifyIconW ShellExecuteW DragFinish |
ole32.dll |
OleSetMenuDescriptor
MkParseDisplayName OleSetContainedObject CoInitialize CoUninitialize CoCreateInstance CreateStreamOnHGlobal CoTaskMemAlloc CoTaskMemFree CLSIDFromString StringFromCLSID IIDFromString StringFromIID OleInitialize CreateBindCtx CLSIDFromProgID CoInitializeSecurity CoCreateInstanceEx CoSetProxyBlanket OleUninitialize |
OLEAUT32.dll |
SafeArrayAllocData
SafeArrayAllocDescriptorEx SysAllocString OleLoadPicture SafeArrayGetVartype SafeArrayDestroyData SafeArrayAccessData VarR8FromDec VariantTimeToSystemTime VariantClear VariantCopy VariantInit SafeArrayDestroyDescriptor LoadRegTypeLib GetActiveObject SafeArrayUnaccessData |
(暂停中) |
AutoIt 错误 |
AutoIt 检测到堆栈错误. |
堆栈错误一般出现在错误的调用函数,或者使用了错误的参数之后. |
AutoIt 支持 __stdcall (WINAPI) 和 __cdecl 两种调用方式. __stdcall (WINAPI) 为默认使用的方法,但是 __cdecl 也可以用来替代. 请参考 DllCall() 文档得到详细信息. |
错误格式的 "Func" 声明. |
表达式里面丢失右括号 ')'. |
表达式里面没有任何操作. |
表达式里面的括号错乱. |
表达式错误. |
解析函数Call错误. |
函数call里面包含错误的参数. |
"ReDim" 没有使用到数组变量. |
结束语句包含非法文本. |
"If" 声明没有与之匹配的 "EndIf" 声明. |
"Else" 声明没有匹配的 "If" 声明. |
"EndIf" 声明没有匹配的 "If" 声明. |
太多的 "Else" 声明都没有 "If" 声明匹配. |
"While" 声明没有匹配的 "Wend" 声明. |
"Wend" 声明没有匹配的 "While" 声明. |
变量没有在开始声明. |
错误的数组或者数组超出界限. |
数组变量格式错误. |
子脚本使用了非数组变量. |
太多子脚本使用了数组. |
"Dim" 声明丢失子脚本维度. |
没有给 "Dim", "Local", "Global", "Struct" 或者 "Const" 声明赋值. |
没有给 "=" 操作分配一个声明.请检查您的代码 |
行首有错误的关键字. |
数组超出界限. |
"Func" 声明没有匹配的 "EndFunc". |
重复的函数名. |
未知函数名. |
未知宏. |
不能得到运行的进程列表. |
关键字过后丢失分隔符. |
DllStruct 中含有错误的元素. |
指定了一个未知的选项或者参数. |
不能载入因特网的库文件. |
"Struct" 声明没有匹配的 "EndStruct". |
不能打开文件,超出了最大可以打开文件的限制. |
错误的文件筛选赋值. |
Expected a variable in user function call. |
"Do" 声明没有匹配的 "Until" 声明. |
"Until" 声明没有匹配的 "Do" 声明. |
"For" 声明格式错误. |
"Next" 声明没有匹配的 "For" 声明. |
"ExitLoop/ContinueLoop" 声明只能在 For/Do/While loop 里面才有效. |
"For" 声明没有匹配的 "Next" 声明. |
"Case" 声明没有匹配的 "Select" 或者 "Switch" 声明. |
"EndSelect" 声明没有匹配的 "Select" 声明. |
递归等级超出限制 - AutoIt 为了避免堆栈溢出而退出. |
错误格式的 Enum 声明 |
这个关键字不能在 "Then" 后面使用. |
"Select" 声明没有匹配的 "EndSelect" 或者 "Case" 声明. |
"If" 声明必须有一个 "Then" 关键字. |
错误格式的 Struct 声明. |
不能对常量赋值! |
不能把一个存在的常量转为变量! |
只有对象类型的变量才允许使用 "With" 声明. |
"long_ptr", "int_ptr" 和 "short_ptr" DllCall() 类型能不被支持. 请使用 "long*", "int*" 和 "short*" 代替. |
对象参考在 "With" 声明外面. |
不允许 "With" 声明嵌套使用. |
变量类型必须为对象类型("Object"). |
请求动作失败(请求于对象). |
这个变量貌似已经不止一次被声明. |
重新定义一个数组不能这样初始化. |
一个数组变量不能如此使用. |
不能重新声明一个常量. |
不能重新声明一个用户函数中的参数. |
Can pass constants by reference only to parameters with "Const" keyword. |
不能初始化一个变量本身. |
您使用这个参数时使用了不正确的方法. |
"EndSwitch" 声明没有匹配的 "Switch" 声明. |
"Switch" 声明没有匹配的 "EndSwitch" 或者 "Case" 声明. |
"ContinueCase" 声明没有匹配的 "Select" 或者 "Switch" 声明. |
声明失败! |
无效的函数/参数. |
错误的退出代码 (AutoIt 保留内部使用). |
不能解析行. |
不能打开脚本文件. |
字符串丢失引号的下一半. |
错误格式的变量或者宏. |
关键字过后丢失分隔字符. |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.1.4.0 |
ProductVersion | 3.1.4.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
Comments | www.goldensoft.org |
FileDescription | GS Auto Clicker |
FileVersion (#2) | 3.1.4 |
LegalCopyright | goldensoft.org |
ProductName | GS Auto Clicker |
ProductVersion (#2) | 3.1.4 |
Resource LangID | English - United States |
---|
XOR Key | 0xbeafe369 |
---|---|
Unmarked objects | 0 |
150 (20413) | 2 |
ASM objects (VS2008 SP1 build 30729) | 30 |
C objects (VS2008 SP1 build 30729) | 178 |
C++ objects (VS2008 SP1 build 30729) | 57 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 10 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 33 |
Total imports | 525 |
143 (VS2008 SP1 build 30729) | 70 |
ASM objects (VS2008 build 21022) | 2 |
Linker (VS2008 build 21022) | 1 |
151 | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |