Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2024-Oct-01 16:55:24 |
Detected languages |
English - United States
|
Debug artifacts |
G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb
|
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Looks for VMWare presence:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA256 Uses constants related to AES |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x160 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2024-Oct-01 16:55:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x438c00 |
SizeOfInitializedData | 0x1caaa00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x003E3072 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x43a000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x20e7000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoA GetFileVersionInfoSizeA |
---|---|
WINMM.dll |
timeGetTime
|
WS2_32.dll |
WSAAsyncSelect
connect setsockopt inet_addr htons WSAStartup closesocket gethostbyname send inet_ntoa recv socket WSAGetLastError |
DDRAW.dll |
DirectDrawCreate
|
KERNEL32.dll |
GetExitCodeThread
GetSystemInfo IsDBCSLeadByte ReadProcessMemory GlobalMemoryStatusEx GetModuleHandleW GetSystemTime InitializeCriticalSection GetCurrentDirectoryA SetCurrentDirectoryA GlobalAlloc GlobalFree GlobalLock CreateDirectoryA GlobalUnlock GetFileSize EnterCriticalSection LeaveCriticalSection WaitForSingleObject SetEvent CreateEventA GetLocaleInfoA CompareStringA FreeLibrary GetSystemDirectoryA WaitForSingleObjectEx FormatMessageA LocalFree FileTimeToLocalFileTime CreateDirectoryW FlushFileBuffers GetOEMCP GetACP IsValidCodePage GetFileSizeEx SetEndOfFile SetStdHandle DeleteFileW GetTimeZoneInformation EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW GetTempPathW DecodePointer FindNextFileW FindFirstFileExW GetCurrentDirectoryW SetCurrentDirectoryW SetEnvironmentVariableW GetFullPathNameW SystemTimeToTzSpecificLocalTime GetFileInformationByHandle GetDriveTypeW GetConsoleOutputCP ReadConsoleW GetConsoleMode SetFilePointerEx GetFileType GetModuleHandleExW ExitThread LoadLibraryExW GetCurrentThreadId TlsSetValue TlsGetValue TlsAlloc SetLastError RtlUnwind VirtualAlloc VirtualFree InterlockedCompareExchange InterlockedExchange UnmapViewOfFile CreateFileMappingA MapViewOfFile OutputDebugStringW GetCPInfo CompareStringEx LCMapStringEx EncodePointer HeapAlloc CreateThread RaiseException HeapReAlloc LoadLibraryA GetCurrentThread HeapSize InitializeCriticalSectionEx OutputDebugStringA HeapFree VirtualProtect GetVersionExA DeviceIoControl CreateIoCompletionPort CancelIo FreeEnvironmentStringsW GetModuleHandleA FindClose GetModuleFileNameA GetLocalTime FileTimeToSystemTime QueryPerformanceCounter WideCharToMultiByte lstrcpyA QueryPerformanceFrequency CreateFileA lstrlenA GetFullPathNameA FreeLibraryAndExitThread GetPrivateProfileStringA WritePrivateProfileStringA GetTickCount Sleep MultiByteToWideChar GetModuleFileNameW lstrlenW WaitNamedPipeW GetCurrentProcessId SetThreadPriority FindNextFileA TerminateProcess GetCurrentProcess FindFirstFileA GetVolumeInformationA CheckRemoteDebuggerPresent IsDebuggerPresent GetProcessHeap ExitProcess DeleteCriticalSection GetProcAddress GetThreadContext TlsFree CloseHandle GetLastError CreateFileW PeekNamedPipe WriteFile WriteConsoleW ReadFile GetCommandLineW GetEnvironmentStringsW GetStdHandle GetPrivateProfileIntA lstrcmpiA GetComputerNameA GetCommandLineA IsBadReadPtr SetUnhandledExceptionFilter CopyFileA InitializeCriticalSectionAndSpinCount ResetEvent CreateEventW UnhandledExceptionFilter IsProcessorFeaturePresent GetStartupInfoW GetSystemTimeAsFileTime InitializeSListHead InitializeSRWLock ReleaseSRWLockExclusive AcquireSRWLockExclusive TryEnterCriticalSection InitializeConditionVariable WakeConditionVariable WakeAllConditionVariable SleepConditionVariableCS SleepConditionVariableSRW GetStringTypeW |
USER32.dll |
LoadStringA
SetRect GetDC SetWindowTextA GetDesktopWindow wvsprintfW GetKeyboardLayout ClientToScreen ShowCursor SetCursorPos OffsetRect CopyRect GetWindowRect SetWindowPos ScreenToClient SetWindowLongA MoveWindow GetCursorPos PtInRect GetAsyncKeyState OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData FlashWindowEx ReleaseDC wsprintfA PostMessageA DefWindowProcW GetMessageA DispatchMessageA GetFocus LoadCursorA DestroyWindow FillRect GetSystemMetrics ShowWindow MessageBoxA AdjustWindowRect DefWindowProcA CreateWindowExA SetFocus TranslateMessage SendMessageA SetCursor LoadIconA SystemParametersInfoA GetClientRect PeekMessageA PostQuitMessage RegisterClassExA UpdateWindow GetClassNameA GetWindowTextA EnumWindows UnregisterClassA GetWindowTextLengthA |
GDI32.dll |
CreateFontIndirectW
SetTextAlign ExtTextOutA MoveToEx ExtTextOutW CreateFontIndirectA GetFontLanguageInfo GetTextMetricsW SetBkMode GetCharacterPlacementA GetGlyphOutlineA GetTextMetricsA GetObjectW GetObjectA GetCharacterPlacementW SetTextColor SetBkColor SetMapMode CreateFontA SetDeviceGammaRamp GetTextExtentPoint32A GetDeviceGammaRamp GetTextExtentPoint32W CreateDCA BitBlt CreateCompatibleBitmap SelectObject CreateCompatibleDC DeleteDC DeleteObject CreateSolidBrush CreateDIBSection |
ADVAPI32.dll |
RegCreateKeyExW
RegSetValueExW RegOpenKeyA GetUserNameA RegQueryValueExA RegOpenKeyExA RegCloseKey |
SHELL32.dll |
SHBrowseForFolderA
SHGetPathFromIDListA ShellExecuteA SHGetMalloc |
ole32.dll |
CoCreateInstance
CoUninitialize CoInitialize |
OLEAUT32.dll |
SystemTimeToVariantTime
VariantInit SysStringLen VariantClear |
IPHLPAPI.DLL |
GetAdaptersInfo
|
gdiplus.dll |
GdipFree
GdipCloneImage GdiplusShutdown GdipDisposeImage GdipAlloc GdipSaveImageToFile GdipCreateBitmapFromHBITMAP GdiplusStartup |
IMM32.dll |
ImmGetContext
ImmReleaseContext ImmGetConversionStatus ImmGetProperty ImmGetCompositionStringW ImmGetIMEFileNameA ImmAssociateContext ImmGetOpenStatus ImmSetConversionStatus ImmNotifyIME ImmGetCandidateListW ImmIsIME |
d3d9.dll |
Direct3DCreate9
|
DINPUT8.dll |
DirectInput8Create
|
DSOUND.dll |
#11
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags |
VS_FF_PRIVATEBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_STATIC_LIB
|
Language | UNKNOWN |
CompanyName | UZC |
FileDescription | Shaiya |
FileVersion (#2) | 1.0.0.0 |
InternalName | Shaiya |
LegalCopyright | All Rights Reserved |
OriginalFilename | Shaiya |
ProductName | Shaiya |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:55:24 |
Version | 0.0 |
SizeofData | 107 |
AddressOfRawData | 0x49f7a4 |
PointerToRawData | 0x49e7a4 |
Referenced File | G:\shaiya-sources\shaiya_eg_vc2010\_temp\client\Win32\EG_ReleaseGM_2010\GameGM.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:55:24 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x49f810 |
PointerToRawData | 0x49e810 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2024-Oct-01 16:55:24 |
Version | 0.0 |
SizeofData | 956 |
AddressOfRawData | 0x49f824 |
PointerToRawData | 0x49e824 |
StartAddressOfRawData | 0x89fbf0 |
---|---|
EndAddressOfRawData | 0x89fbf8 |
AddressOfIndex | 0x8c745c |
AddressOfCallbacks | 0x83ad5c |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0xbc |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x8b3348 |
SEHandlerTable | 0 |
SEHandlerCount | 0 |
XOR Key | 0xfe4e5d79 |
---|---|
Unmarked objects | 0 |
ASM objects (27412) | 46 |
C++ objects (27412) | 227 |
Imports (VS2003 (.NET) build 4035) | 2 |
C objects (VS2003 (.NET) build 4035) | 1 |
C objects (2067) | 12 |
18 (8444) | 6 |
253 (28518) | 3 |
C++ objects (30034) | 94 |
C objects (30034) | 22 |
ASM objects (30034) | 29 |
C objects (30154) | 10 |
C objects (27412) | 35 |
C objects (CVTCIL) (27412) | 1 |
Imports (9210) | 6 |
C objects (9178) | 2 |
C++ objects (VS2003 (.NET) build 4035) | 127 |
Imports (27412) | 29 |
Total imports | 426 |
C objects (VC++ 6.0 SP5 build 8804) | 78 |
C++ objects (LTCG) (30154) | 472 |
Resource objects (30154) | 1 |
151 | 1 |
Linker (30154) | 1 |