Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2001-Mar-16 00:48:44 |
Detected languages |
English - United States
|
Info | Matching compiler(s): |
Microsoft Visual C++
Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | The PE contains common functions which appear in legitimate applications. |
Can access the registry:
|
Safe | VirusTotal score: 0/65 (Scanned on 2018-04-25 21:54:21) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2001-Mar-16 00:48:44 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x25000 |
SizeOfInitializedData | 0x40000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000214B6 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x26000 |
ImageBase | 0x10900000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x66000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
Window.dll |
?OnCurrent@WWizardPage@@UAEXXZ
?InitWindowing@@YAXXZ ??0WLog@@QAE@PBGAAPAVFArchive@@VFName@@PAVWWindow@@@Z ?GLogWindow@@3PAVWLog@@A ?OpenWindow@WLog@@QAEXHH@Z ?Unused@FCommandTarget@@UAEXXZ ?Serialize@WWindow@@UAEXAAVFArchive@@@Z ?GetPackageName@WLog@@UAEPBGXZ ?GetNext@WWizardPage@@UAEPAV1@XZ ?WindowMessageOpen@@3IA ?WndProc@WLog@@UAEJIIJ@Z ?CallDefaultProc@WWindow@@UAEHIIJ@Z ?InterceptControlCommand@WWindow@@UAEHIIJ@Z ?GetText@WWindow@@UAE?AVFString@@XZ ?SetText@WLog@@UAEXPBG@Z ?GetLength@WWindow@@UAEHXZ ?OnCopyData@WLog@@UAEXPAUHWND__@@PAUtagCOPYDATASTRUCT@@@Z ?OnSetFocus@WTerminal@@UAEXPAUHWND__@@@Z ?OnInitDialog@WDialog@@UAEXXZ ?GetWindowClassName@WLog@@UAEXPAG@Z ?DoDestroy@WWindow@@UAEXXZ ?GetCancelText@WWizardPage@@UAEPBGXZ ?OnChar@WWindow@@UAEXG@Z ??1WWizardDialog@@UAE@XZ ??1WConfigProperties@@UAE@XZ ?OnCopy@WWindow@@UAEXXZ ?OnPaste@WWindow@@UAEXXZ ?OnShowWindow@WLog@@UAEXH@Z ?OnUndo@WWindow@@UAEXXZ ?OnPaint@WWindow@@UAEXXZ ?OnCreate@WTerminal@@UAEXXZ ?OnDrawItem@WWindow@@UAEXPAUtagDRAWITEMSTRUCT@@@Z ?OnMeasureItem@WWindow@@UAEXPAUtagMEASUREITEMSTRUCT@@@Z ?OnInitDialog@WWindow@@UAEXXZ ?OnEnterIdle@WWindow@@UAEXXZ ?OnMouseEnter@WWindow@@UAEXXZ ?OnMouseLeave@WWindow@@UAEXXZ ?OnMouseHover@WWindow@@UAEXXZ ?OnTimer@WWindow@@UAEXXZ ?OnReleaseCapture@WWindow@@UAEXXZ ?OnMdiActivate@WWindow@@UAEXH@Z ?OnCancel@WWizardPage@@UAEXXZ ?GetShow@WWizardPage@@UAEHXZ ?GetBackText@WWizardPage@@UAEPBGXZ ?GetFinishText@WWizardPage@@UAEPBGXZ ?GetNextText@WWizardPage@@UAEPBGXZ ?OnKillFocus@WWindow@@UAEXPAUHWND__@@@Z ?OnCancel@WWizardDialog@@UAEXXZ ?SetCurrent@WListBox@@QAEXHH@Z ?OnDestroy@WWindow@@UAEXXZ ?OnClose@WWindow@@UAEXXZ ?OnBack@WWizardDialog@@UAEXXZ ?OnFinish@WWizardDialog@@UAEXXZ ?OnNext@WWizardDialog@@UAEXXZ ?LocalizeText@WDialog@@UAEXPBG0@Z ?RefreshPage@WWizardDialog@@UAEXXZ ?Advance@WWizardDialog@@UAEXPAVWWizardPage@@@Z ?OnSize@WTerminal@@UAEXKHH@Z ?OnClose@WWizardDialog@@UAEXXZ ?DoModal@WDialog@@UAEHPAUHINSTANCE__@@@Z ??1WWizardPage@@UAE@XZ ?OnDestroy@WWizardDialog@@UAEXXZ ?OnCommand@WWindow@@UAEXH@Z ?OnCreate@WWindow@@UAEXXZ ?OnShowWindow@WWindow@@UAEXH@Z ?OnCopyData@WWindow@@UAEXPAUHWND__@@PAUtagCOPYDATASTRUCT@@@Z ?OnSize@WWindow@@UAEXKHH@Z ?OnSetFocus@WWindow@@UAEXPAUHWND__@@@Z ?WndProc@WWindow@@UAEJIIJ@Z ?SetText@WWindow@@UAEXPBG@Z ?CallDefaultProc@WDialog@@UAEHIIJ@Z ??1WCoolButton@@UAE@XZ ??1WButton@@UAE@XZ ??1WListBox@@UAE@XZ ?OnCommand@WLog@@UAEXH@Z ?OnActivate@WWindow@@UAEXH@Z ??1WLabel@@UAE@XZ ?AddString@WListBox@@QAEHPBG@Z ?Empty@WListBox@@QAEXXZ ??_7FDelegate@@6B@ ?GetString@WListBox@@QAE?AVFString@@H@Z ?GetCurrent@WListBox@@QAEHXZ ??_7WEdit@@6B@ ??0WWindow@@QAE@VFName@@PAV0@@Z ?SuperProc@WEdit@@2P6GJPAUHWND__@@IIJ@ZA ??_7WWizardPage@@6B@ ??0WDialog@@QAE@VFName@@HPAVWWindow@@@Z ??1WEdit@@UAE@XZ ??1WUrlButton@@UAE@XZ ?SuperProc@WLabel@@2P6GJPAUHWND__@@IIJ@ZA ??_7WUrlButton@@6B@ ?OnClick@WUrlButton@@QAEXXZ ??_7WButton@@6B@ ??_7WListBox@@6B@ ??0WControl@@QAE@PAVWWindow@@HP6GJPAUHWND__@@IIJ@Z@Z ?SuperProc@WListBox@@2P6GJPAUHWND__@@IIJ@ZA ?GetRoot@WConfigProperties@@UAEPAVFTreeItem@@XZ ?GetWindowClassName@WConfigProperties@@UAEXPAG@Z ?GetPackageName@WConfigProperties@@UAEPBGXZ ?SetValue@WProperties@@UAEXPBG@Z ?GetListItem@WPropertiesBase@@UAEPAVFTreeItem@@H@Z ?BeginSplitterDrag@WProperties@@UAEXXZ ?ForceRefresh@WProperties@@UAEXXZ ?SetItemFocus@WProperties@@UAEXH@Z ?ResizeList@WProperties@@UAEXXZ ?GetDividerWidth@WProperties@@UAEHXZ ?GetRoot@WObjectProperties@@UAEPAVFTreeItem@@XZ ?OnDestroy@WProperties@@UAEXXZ ?OnSetCursor@WProperties@@UAEHXZ ?OnFinishSplitterDrag@WProperties@@UAEXPAVWDragInterceptor@@H@Z ?OnPaint@WProperties@@UAEXXZ ?OnActivate@WProperties@@UAEXH@Z ?OnSize@WProperties@@UAEXKHH@Z ?GetWindowClassName@WObjectProperties@@UAEXPAG@Z ?DoDestroy@WProperties@@UAEXXZ ?GetPackageName@WObjectProperties@@UAEPBGXZ ?Serialize@WProperties@@UAEXAAVFArchive@@@Z ?SetNotifyHook@WWindow@@QAEXPAVFNotifyHook@@@Z ??0WConfigProperties@@QAE@VFName@@PBG@Z ?OpenWindow@WProperties@@QAEXPAUHWND__@@@Z ??0WObjectProperties@@QAE@VFName@@KPBGPAVWWindow@@H@Z ?ScrollCaret@WEdit@@QAEXXZ ?Show@WWindow@@QAEXH@Z ??1WLog@@UAE@XZ ??1WObjectProperties@@UAE@XZ ?OnMouseMove@WWindow@@UAEXKUFPoint@@@Z ?OnLeftButtonDown@WWindow@@UAEXXZ ?OnFinishSplitterDrag@WWindow@@UAEXPAVWDragInterceptor@@H@Z ?OnSetCursor@WWindow@@UAEHXZ ?OnClose@WLog@@UAEXXZ ?OnDestroy@WLog@@UAEXXZ ?TypeChar@WTerminal@@UAEXG@Z ?Paste@WTerminal@@UAEXXZ ?hInstanceWindow@@3PAUHINSTANCE__@@A ??0WButton@@QAE@PAVWWindow@@HUFDelegate@@P6GJPAUHWND__@@IIJ@Z@Z ??0WListBox@@QAE@PAVWWindow@@HP6GJPAUHWND__@@IIJ@Z@Z ??0WCoolButton@@QAE@PAVWWindow@@HUFDelegate@@K@Z ??0FDelegate@@QAE@ABU0@@Z ??0FDelegate@@QAE@PAVFCommandTarget@@P81@AEXXZ@Z ??0WWizardPage@@QAE@PBGHPAVWWizardDialog@@@Z ??0WLabel@@QAE@PAVWWindow@@HP6GJPAUHWND__@@IIJ@Z@Z ??0WWizardDialog@@QAE@XZ ??1WDialog@@UAE@XZ ??_7WCoolButton@@6B@ ??1WControl@@UAE@XZ ??_7WWizardDialog@@6B@ ?OnRightButtonDown@WWindow@@UAEXXZ ?FindStringChecked@WListBox@@QAEHPBG@Z ??1WWindow@@UAE@XZ ??_7WControl@@6B@ ?LoadFileToBitmap@@YAPAUHBITMAP__@@PBGAAH1@Z ??_7WLabel@@6B@ ?MaybeDestroy@WWindow@@QAEXXZ ?OnInitDialog@WWizardDialog@@UAEXXZ ?OnKeyDown@WWindow@@UAEXG@Z ?OnCut@WWindow@@UAEXXZ ?OnLeftButtonUp@WWindow@@UAEXXZ ?OnRightButtonUp@WWindow@@UAEXXZ |
---|---|
Core.dll |
??0FString@@QAE@ABV0@@Z
?appStrchr@@YAPAGPBGH@Z ??DFString@@QBE?AV0@PBG@Z ?Realloc@FArray@@IAEXH@Z ??0FArray@@IAE@HH@Z ?GUnicodeOS@@3HA ?appFailAssert@@YAXPBD0H@Z ?appStricmp@@YAHPBG0@Z ?appStrlen@@YAHPBG@Z ?appStrcpy@@YAPAGPAGPBG@Z ?winToUNICODE@@YAPAGPAGPBDH@Z ?GetTransientPackage@UObject@@SAPAVUPackage@@XZ ?StaticConstructObject@UObject@@SAPAV1@PAVUClass@@PAV1@VFName@@K1PAVFOutputDevice@@@Z ??1FRegistryObjectInfo@@QAE@XZ ?appAtof@@YAMPBG@Z ?appStaticString1024@@YAPAGXZ ?Log@FOutputDevice@@QAEXPBG@Z ??8FString@@QBEHABV0@@Z ?appStrcmp@@YAHPBG0@Z ?appLoadFileToString@@YAHAAVFString@@PBGPAVFFileManager@@@Z ?GCRCTable@@3PAKA ??YFString@@QAEAAV0@PBG@Z ?appSaveStringToFile@@YAHABVFString@@PBGPAVFFileManager@@@Z ?GWindowManager@@3PAVUSubsystem@@A ?appSleep@@YAXM@Z ?ParseCommand@@YAHPAPBGPBG@Z ?GObjObjects@UObject@@0V?$TArray@PAVUObject@@@@A ?ParseObject@@YAHPBG0PAVUClass@@AAPAVUObject@@PAV2@@Z ?appSqrt@@YANN@Z ?appLaunchURL@@YAXPBG0PAVFString@@@Z ?Add@FArray@@QAEHHH@Z GIsMMX ??0FString@@QAE@PBG@Z ?PrivateStaticClass@UClass@@0V1@A ?GetRegistryObjects@UObject@@SAXAAV?$TArray@VFRegistryObjectInfo@@@@PAVUClass@@1H@Z ?InStr@FString@@QBEHPBGH@Z ?Left@FString@@QBE?AV1@H@Z ?Len@FString@@QBEHXZ ?Mid@FString@@QBE?AV1@HH@Z ?Localize@@YAPBGPBG000H@Z GTimestamp ?GSecondsPerCycle@@3NA ?appSecondsSlow@@YANXZ ??_7FExec@@6B@ ??_7FNotifyHook@@6B@ ?GExec@@3PAVFExec@@A ?appAtoi@@YAHPBG@Z ?Printf@FString@@SA?AV1@PBGZZ ??0FArray@@QAE@XZ ?StaticLoadClass@UObject@@SAPAVUClass@@PAV2@PAV1@PBG2KPAVUPackageMap@@@Z ??0FName@@QAE@W4EName@@@Z ??0FString@@QAE@XZ ?LocalizeGeneral@@YAPBGPBG00@Z ??4FString@@QAEAAV0@PBG@Z ?NotifyPreChange@FNotifyHook@@UAEXPAX@Z ?NotifyPostChange@FNotifyHook@@UAEXPAX@Z ?NotifyExec@FNotifyHook@@UAEXPAXPBG@Z ?appStrfind@@YAPBGPBG0@Z ?appInit@@YAXPBG0PAVFMalloc@@PAVFOutputDevice@@PAVFOutputDeviceError@@PAVFFeedbackContext@@PAVFFileManager@@P6APAVFConfigCache@@XZH@Z ?GIsServer@@3HA ?GIsScriptable@@3HA ?GLazyLoad@@3HA ?GPhysicalMemory@@3KA ??HFString@@QAE?AV0@PBG@Z ?Empty@FArray@@QAEXHH@Z ??0FName@@QAE@PBGW4EFindName@@@Z ?LocalizeGeneral@@YAPBGPBDPBG1@Z ?Log@FOutputDevice@@QAEXW4EName@@PBG@Z ?Parse@@YAHPBG0AAVFString@@@Z ??HFString@@QAE?AV0@ABV0@@Z ?GIsRequestingExit@@3HA ?appPreExit@@YAXXZ ?Remove@FArray@@QAEXHHH@Z ?appExit@@YAXXZ ?appFromAnsi@@YAPBGPBD@Z ?winGetSizeUNICODE@@YAHPBD@Z ?GConfig@@3PAVFConfigCache@@A ??4FString@@QAEAAV0@ABV0@@Z ?TotalSize@FArchive@@UAEHXZ ?Precache@FArchive@@UAEXH@Z ??_7FArchive@@6B@ ??1FArchive@@UAE@XZ ?SerializeBits@FArchive@@UAEXPAXH@Z ?SerializeInt@FArchive@@UAEXAAKK@Z ?Preload@FArchive@@UAEXPAVUObject@@@Z ?CountBytes@FArchive@@UAEXKK@Z ??6FArchive@@UAEAAV0@AAPAVUObject@@@Z ??6FArchive@@UAEAAV0@AAVFName@@@Z ?MapName@FArchive@@UAEHPAVFName@@@Z ?MapObject@FArchive@@UAEHPAVUObject@@@Z ?AtEnd@FArchive@@UAEHXZ ?AttachLazyLoader@FArchive@@UAEXPAVFLazyLoader@@@Z ?DetachLazyLoader@FArchive@@UAEXPAVFLazyLoader@@@Z ?Flush@FArchive@@UAEXXZ ?GetError@FArchive@@UAEHXZ ??DFString@@QBE?AV0@ABV0@@Z ??1FArray@@QAE@XZ ??DFString@@QBEPBGXZ ??1FString@@QAE@XZ ??_7FFileManager@@6B@ ?winGetSizeANSI@@YAHPBG@Z ?winToANSI@@YAPADPADPBGH@Z ?GIsSlowTask@@3HA ?appGetVarArgs@@YAHPAGHAAPBG@Z ??_7FFeedbackContext@@6B@ ?GIsRunning@@3HA ?GIsClient@@3HA ?GIsEditor@@3HA ?GIsStarted@@3HA ?GNull@@3PAVFOutputDevice@@A ?LocalizeError@@YAPBGPBG00@Z ?appGetSystemErrorMessage@@YAPBGH@Z ?StaticShutdownAfterError@UObject@@SAXXZ ?GErrorHist@@3PAGA ?appStrncpy@@YAPAGPAGPBGH@Z ?appStrncat@@YAPAGPAGPBGH@Z ?GIsGuarded@@3HA ?appRequestExit@@YAXH@Z ??_7FOutputDeviceError@@6B@ ?GIsCriticalError@@3HA ?Initialized@FName@@0HA ?Names@FName@@0V?$TArray@PAUFNameEntry@@@@A ?appBaseDir@@YAPBGXZ ?Parse@@YAHPBG0PAGH@Z ?appPackage@@YAPBGXZ ?appStrcat@@YAPAGPAGPBG@Z ?appCmdLine@@YAPBGXZ ?GFileManager@@3PAVFFileManager@@A ?appTimestamp@@YAPBGXZ ?Logf@FOutputDevice@@QAAXW4EName@@PBGZZ ?appSprintf@@YAHPAGPBGZZ ?GLogHook@@3PAVFOutputDevice@@A ??_7FOutputDevice@@6B@ ?GLog@@3PAVFOutputDevice@@A ?Logf@FOutputDevice@@QAAXPBGZZ ?ParseParam@@YAHPBG0@Z ?LocalizeError@@YAPBGPBDPBG1@Z ?GError@@3PAVFOutputDeviceError@@A ?GPageSize@@3KA ?appUnwindf@@YAXPBGZZ ??_7FMalloc@@6B@ ?GMalloc@@3PAVFMalloc@@A |
Engine.dll |
?PrivateStaticClass@UEngine@@0VUClass@@A
?PrivateStaticClass@UGameEngine@@0VUClass@@A ?PrivateStaticClass@URenderDevice@@0VUClass@@A ?PrivateStaticClass@AActor@@0VUClass@@A |
USER32.dll |
SendMessageW
SetPropW PeekMessageW PeekMessageA GetForegroundWindow GetWindowThreadProcessId TranslateMessage EndDialog LoadIconW SetFocus SetForegroundWindow FindWindowExW LoadIconA GetPropW GetPropA FindWindowExA RemovePropW RemovePropA SetPropA PostThreadMessageW PostThreadMessageA MessageBoxW CreateDialogParamA GetDlgItem CreateDialogParamW SendMessageA UpdateWindow SetWindowPos GetMessageA DispatchMessageW GetMessageW SendMessageTimeoutW GetSystemMetrics DispatchMessageA PostQuitMessage |
KERNEL32.dll |
GetStartupInfoA
MoveFileA GetCurrentThreadId GetCurrentThread SetThreadPriority MultiByteToWideChar Sleep CreateMutexW CreateMutexA ExitProcess GetCommandLineW GetCurrentDirectoryW GetCurrentDirectoryA SetCurrentDirectoryW SetCurrentDirectoryA FindFirstFileW FindNextFileW FindFirstFileA FindNextFileA FindClose RemoveDirectoryW RemoveDirectoryA CreateDirectoryW CreateDirectoryA MoveFileW GetModuleHandleA DeleteFileW DeleteFileA CopyFileW CopyFileA WriteFile SetFileAttributesW SetFileAttributesA CloseHandle SetFilePointer ReadFile CreateFileW CreateFileA GetFileSize GetLastError GetSystemInfo VirtualFree VirtualAlloc GetSystemDirectoryA GetWindowsDirectoryA GetModuleFileNameA GetSystemDirectoryW GetWindowsDirectoryW GetModuleFileNameW CreateThread |
GDI32.dll |
DeleteObject
|
ADVAPI32.dll |
RegOpenKeyExW
RegOpenKeyExA RegQueryValueExA RegQueryValueExW RegCloseKey |
SHELL32.dll |
ShellExecuteW
ShellExecuteA |
MSVCRT.dll |
_controlfp
_XcptFilter _except_handler3 __set_app_type __p__fmode __p__commode _adjust_fdiv __setusermatherr _initterm __getmainargs _acmdln exit _exit _onexit __dllonexit ??1type_info@@UAE@XZ _purecall _CxxThrowException __CxxFrameHandler |
Ordinal | 1 |
---|---|
Address | 0x2c534 |
XOR Key | 0x2a8330b9 |
---|---|
Unmarked objects | 0 |
14 (7299) | 2 |
C++ objects (8797) | 1 |
C objects (8797) | 11 |
Linker (8797) | 2 |
19 (8034) | 10 |
Total imports | 416 |
C++ objects (VS98 build 8168) | 1 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |
Linker (VC++ 6.0 SP5 imp/exp build 8447) | 8 |