Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2000-Dec-13 13:48:52 |
Detected languages |
Japanese - Japan
|
CompanyName | |
FileDescription | skipscr |
FileVersion | 1, 0, 0, 0 |
InternalName | skipscr |
LegalCopyright | Copyright (C) 2000 S.Takenouchi |
OriginalFilename | skipscr.scr |
ProductName | スキップカウズスクリーンセーバー |
ProductVersion | 1, 0, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2000-Dec-13 13:48:52 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x11000 |
SizeOfInitializedData | 0x28000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000A9C4 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x12000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3a000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetFileSize
SuspendThread WriteFile ReadFile CreateFileA ExitThread TerminateThread ResumeThread SetFilePointer SetThreadPriority CreateThread FindResourceA GetModuleHandleA LoadResource LockResource FreeResource OutputDebugStringA Sleep OpenMutexA CreateMutexA ReleaseMutex GetLastError GetACP GetCPInfo GetOEMCP IsBadReadPtr SetUnhandledExceptionFilter IsBadCodePtr VirtualAlloc GetStringTypeW IsBadWritePtr MultiByteToWideChar GetStringTypeA HeapSize HeapReAlloc GetProcAddress HeapCreate HeapDestroy VirtualFree GetEnvironmentVariableA GetFileType GetVersionExA SetHandleCount GetEnvironmentStringsW GetStdHandle WideCharToMultiByte FreeEnvironmentStringsW GetEnvironmentStrings GetModuleFileNameA UnhandledExceptionFilter FreeEnvironmentStringsA HeapFree GetVersion HeapAlloc GetStartupInfoA RtlUnwind GetCommandLineA TerminateProcess ExitProcess GetCurrentProcess LCMapStringA LCMapStringW SetStdHandle FlushFileBuffers LoadLibraryA CloseHandle |
---|---|
USER32.dll |
LoadStringA
wsprintfA GetDesktopWindow GetDC ShowWindow IsWindow DefWindowProcA GetMessageA IsDialogMessageA DialogBoxParamA TranslateMDISysAccel TranslateAcceleratorA TranslateMessage DispatchMessageA GetClientRect PostQuitMessage GetSystemMetrics EndDialog LoadIconA GetClassInfoExA CreateWindowExA SetRect ShowCursor GetCursorPos GetForegroundWindow MessageBoxA SetCursor RegisterClassExA FindWindowExA EndPaint GetUpdateRect BeginPaint LoadCursorA DestroyWindow MoveWindow ReleaseDC GetWindowRect SendDlgItemMessageA |
GDI32.dll |
StretchDIBits
SetSystemPaletteUse RealizePalette GetDeviceCaps GetSystemPaletteEntries SelectPalette SetDIBitsToDevice DeleteObject GetStockObject CreatePalette |
ADVAPI32.dll |
RegQueryValueExA
RegSetValueExA RegCloseKey RegOpenKeyExA RegCreateKeyExA |
SHELL32.dll |
DragFinish
DragQueryFileA ShellExecuteA |
WINMM.dll |
timeGetTime
|
IMM32.dll |
ImmReleaseContext
ImmSetOpenStatus |
スキップカウズスクリーンセーバー Ver 1.0.0 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | Japanese - Japan |
CompanyName | |
FileDescription | skipscr |
FileVersion (#2) | 1, 0, 0, 0 |
InternalName | skipscr |
LegalCopyright | Copyright (C) 2000 S.Takenouchi |
OriginalFilename | skipscr.scr |
ProductName | スキップカウズスクリーンセーバー |
ProductVersion (#2) | 1, 0, 0, 0 |
Resource LangID | Japanese - Japan |
---|
XOR Key | 0x356f530f |
---|---|
Unmarked objects | 0 |
C++ objects (8797) | 8 |
14 (7299) | 18 |
C objects (8797) | 74 |
19 (8034) | 17 |
Total imports | 191 |
C++ objects (8799) | 14 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |