| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2005-Nov-14 17:05:18 |
| Detected languages |
English - United States
Finnish - Finland |
| CompanyName | Mediamond Tmi |
| FileDescription | DSJ3 Setup |
| FileVersion | 1, 4, 0, 0 |
| InternalName | Setup |
| LegalCopyright | Copyright © Jussi Koskela 2005 |
| OriginalFilename | Setup.exe |
| ProductName | DSJ3 Setup |
| ProductVersion | 1, 4, 0, 0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/62 (Scanned on 2017-04-12 00:34:46) | Zillya: Trojan.Genome.Win32.91604 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2005-Nov-14 17:05:18 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x18000 |
| SizeOfInitializedData | 0x12000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00008377 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x19000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2b000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d8.dll |
Direct3DCreate8
|
|---|---|
| DSOUND.dll |
#2
|
| KERNEL32.dll |
FileTimeToSystemTime
FileTimeToLocalFileTime RaiseException RtlUnwind FindNextFileA GetStartupInfoA GetCommandLineA ExitProcess HeapAlloc HeapFree TerminateProcess HeapReAlloc HeapSize GetACP GetTimeZoneInformation SetUnhandledExceptionFilter UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings SetHandleCount GetStdHandle GetFileType GetEnvironmentVariableA GetVersionExA HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW IsBadReadPtr IsBadCodePtr SetStdHandle CompareStringA CompareStringW SetEnvironmentVariableA FindFirstFileA FreeLibrary LoadLibraryA GetModuleFileNameA GetLastError FindClose FlushFileBuffers SetFilePointer WriteFile GetCurrentProcess SetErrorMode GetOEMCP GetCPInfo GetProcessVersion WritePrivateProfileStringA GlobalFlags TlsGetValue LocalReAlloc TlsSetValue EnterCriticalSection GlobalReAlloc LeaveCriticalSection TlsFree GlobalHandle DeleteCriticalSection TlsAlloc InitializeCriticalSection LocalFree LocalAlloc lstrcpynA MulDiv SetLastError CreateMutexA MultiByteToWideChar WideCharToMultiByte lstrlenA CloseHandle InterlockedIncrement InterlockedDecrement GetVersion lstrcatA GlobalGetAtomNameA GlobalAddAtomA GlobalFindAtomA lstrcpyA GetModuleHandleA GetProcAddress GlobalUnlock GlobalFree LockResource FindResourceA LoadResource GlobalLock GlobalAlloc GlobalDeleteAtom lstrcmpA lstrcmpiA GetCurrentThread GetCurrentThreadId GetEnvironmentStringsW |
| USER32.dll |
CopyRect
AdjustWindowRectEx SetFocus GetSysColor MapWindowPoints SendDlgItemMessageA UpdateWindow IsDialogMessageA SetWindowTextA ShowWindow LoadStringA DestroyMenu ClientToScreen GetDC ReleaseDC BeginPaint EndPaint TabbedTextOutA DrawTextA GrayStringA LoadCursorA GetClassNameA PtInRect GetSysColorBrush RegisterClassA GetMenu GetMenuItemCount GetSubMenu GetMenuItemID GetWindowTextA GetDlgCtrlID CreateWindowExA GetClassLongA SetPropA UnhookWindowsHookEx GetPropA CallWindowProcA RemovePropA DefWindowProcA GetMessageTime GetMessagePos GetForegroundWindow GetWindow SetWindowLongA SetWindowPos RegisterWindowMessageA SystemParametersInfoA GetWindowRect EndDialog SetActiveWindow CreateDialogIndirectParamA DestroyWindow GetDlgItem GetMenuCheckMarkDimensions LoadBitmapA GetMenuState ModifyMenuA SetMenuItemBitmaps CheckMenuItem EnableMenuItem GetFocus GetNextDlgTabItem GetMessageA TranslateMessage DispatchMessageA GetActiveWindow GetKeyState CallNextHookEx ValidateRect IsWindowVisible PeekMessageA GetCursorPos SetWindowsHookExA GetParent IsWindowEnabled GetWindowLongA MessageBoxA SetCursor PostQuitMessage PostMessageA EnableWindow GetSystemMetrics GetClientRect DrawIcon GetSystemMenu AppendMenuA SendMessageA LoadIconA GetTopWindow GetCapture wsprintfA WinHelpA GetClassInfoA FindWindowA GetLastActivePopup SetForegroundWindow IsIconic OpenIcon UnregisterClassA IsWindow GetWindowPlacement |
| GDI32.dll |
SetBkColor
GetObjectA DeleteDC SaveDC RestoreDC SelectObject GetStockObject SetMapMode SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx SetTextColor DeleteObject GetDeviceCaps PtVisible RectVisible TextOutA ExtTextOutA Escape GetClipBox CreateBitmap |
| WINSPOOL.DRV |
OpenPrinterA
DocumentPropertiesA ClosePrinter |
| ADVAPI32.dll |
RegQueryValueExA
RegSetValueExA RegCloseKey RegCreateKeyExA RegOpenKeyExA |
| COMCTL32.dll |
#17
|
| &About Setup... |
| Open |
| Save As |
| All Files (*.*) |
| Untitled |
| an unnamed file |
| &Hide |
| No error message is available. |
| An unsupported operation was attempted. |
| A required resource was unavailable. |
| Out of memory. |
| An unknown error has occurred. |
| Invalid filename. |
| Failed to open document. |
| Failed to save document. |
| Save changes to %1? |
| Failed to create empty document. |
| The file is too large to open. |
| Could not start print job. |
| Failed to launch help. |
| Internal application error. |
| Command failed. |
| Insufficient memory to perform operation. |
| System registry entries have been removed and the INI file (if any) was deleted. |
| Not all of the system registry entries (or INI file) were removed. |
| This program requires the file %s, which was not found on this system. |
| This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
| Please enter an integer. |
| Please enter a number. |
| Please enter an integer between %1 and %2. |
| Please enter a number between %1 and %2. |
| Please enter no more than %1 characters. |
| Please select a button. |
| Please enter an integer between 0 and 255. |
| Please enter a positive integer. |
| Please enter a date and/or time. |
| Please enter a currency. |
| Unexpected file format. |
| %1 |
| Cannot find this file. |
| Please verify that the correct path and file name are given. |
| Destination disk drive is full. |
| Unable to read from %1, it is opened by someone else. |
| Unable to write to %1, it is read-only or opened by someone else. |
| An unexpected error occurred while reading %1. |
| An unexpected error occurred while writing %1. |
| Unable to read write-only property. |
| Unable to write read-only property. |
| Unable to load mail system support. |
| Mail system DLL is invalid. |
| Send Mail failed to send message. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| %1 was not found. |
| %1 contains an invalid path. |
| %1 could not be opened because there are too many open files. |
| Access to %1 was denied. |
| An invalid file handle was associated with %1. |
| %1 could not be removed because it is the current directory. |
| %1 could not be created because the directory is full. |
| Seek failed on %1 |
| A hardware I/O error was reported while accessing %1. |
| A sharing violation occurred while accessing %1. |
| A locking violation occurred while accessing %1. |
| Disk full while accessing %1. |
| An attempt was made to access %1 past its end. |
| No error occurred. |
| An unknown error occurred while accessing %1. |
| An attempt was made to write to the reading %1. |
| An attempt was made to access %1 past its end. |
| An attempt was made to read from the writing %1. |
| %1 has a bad format. |
| %1 contained an unexpected object. |
| %1 contains an incorrect schema. |
| pixels |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.4.0.0 |
| ProductVersion | 1.4.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Mediamond Tmi |
| FileDescription | DSJ3 Setup |
| FileVersion (#2) | 1, 4, 0, 0 |
| InternalName | Setup |
| LegalCopyright | Copyright © Jussi Koskela 2005 |
| OriginalFilename | Setup.exe |
| ProductName | DSJ3 Setup |
| ProductVersion (#2) | 1, 4, 0, 0 |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x2e6bf043 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (8047) | 1 |
| Unmarked objects (#2) | 6 |
| 19 (8034) | 14 |
| 14 (7299) | 26 |
| C objects (VS98 SP6 build 8804) | 108 |
| Total imports | 384 |
| Imports (9210) | 5 |
| C++ objects (VS98 SP6 build 8804) | 74 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.