Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Mar-14 20:01:24 |
Detected languages |
English - United Kingdom
English - United States |
Comments | www.opautoclicker.com |
FileDescription | OP Auto Clicker |
FileVersion | 3.0 |
LegalCopyright | www.opautoclicker.com |
ProductName | OP Auto Clicker |
ProductVersion | 3.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Is an AutoIT compiled script:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses known Mersenne Twister constants |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/69 (Scanned on 2022-05-13 23:31:49) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2019-Mar-14 20:01:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0x80200 |
SizeOfInitializedData | 0x1f000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00016310 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x82000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xb6000 |
SizeOfHeaders | 0x400 |
Checksum | 0xd83ce |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x400000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x400000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WSOCK32.dll |
__WSAFDIsSet
setsockopt ntohs recvfrom sendto htons select listen WSAStartup bind closesocket connect socket send WSACleanup ioctlsocket accept WSAGetLastError inet_addr gethostbyname gethostname recv |
---|---|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoW GetFileVersionInfoSizeW |
WINMM.dll |
timeGetTime
waveOutSetVolume mciSendStringW |
COMCTL32.dll |
ImageList_Remove
ImageList_SetDragCursorImage ImageList_BeginDrag ImageList_DragEnter ImageList_DragLeave ImageList_EndDrag ImageList_DragMove ImageList_ReplaceIcon ImageList_Create InitCommonControlsEx ImageList_Destroy |
MPR.dll |
WNetCancelConnection2W
WNetGetConnectionW WNetAddConnection2W WNetUseConnectionW |
WININET.dll |
InternetReadFile
InternetCloseHandle InternetOpenW InternetSetOptionW InternetCrackUrlW HttpQueryInfoW InternetConnectW HttpOpenRequestW HttpSendRequestW FtpOpenFileW FtpGetFileSize InternetOpenUrlW InternetQueryOptionW InternetQueryDataAvailable |
PSAPI.DLL |
EnumProcesses
GetModuleBaseNameW GetProcessMemoryInfo EnumProcessModules |
USERENV.dll |
CreateEnvironmentBlock
DestroyEnvironmentBlock UnloadUserProfile LoadUserProfileW |
KERNEL32.dll |
HeapAlloc
Sleep GetCurrentThreadId RaiseException MulDiv GetVersionExW GetSystemInfo MultiByteToWideChar WideCharToMultiByte GetModuleHandleW QueryPerformanceCounter VirtualFreeEx OpenProcess VirtualAllocEx WriteProcessMemory ReadProcessMemory CreateFileW SetFilePointerEx ReadFile WriteFile FlushFileBuffers TerminateProcess CreateToolhelp32Snapshot Process32FirstW Process32NextW SetFileTime GetFileAttributesW FindFirstFileW FindClose DeleteFileW FindNextFileW lstrcmpiW MoveFileW CopyFileW CreateDirectoryW RemoveDirectoryW SetSystemPowerState QueryPerformanceFrequency FindResourceW LoadResource LockResource SizeofResource GetProcessHeap OutputDebugStringW GetLocalTime CompareStringW CompareStringA InterlockedIncrement InterlockedDecrement DeleteCriticalSection EnterCriticalSection LeaveCriticalSection InitializeCriticalSectionAndSpinCount GetStdHandle CreatePipe InterlockedExchange TerminateThread GetTempPathW GetTempFileNameW VirtualFree FormatMessageW GetExitCodeProcess SetErrorMode GetPrivateProfileStringW WritePrivateProfileStringW GetPrivateProfileSectionW WritePrivateProfileSectionW GetPrivateProfileSectionNamesW FileTimeToLocalFileTime FileTimeToSystemTime SystemTimeToFileTime LocalFileTimeToFileTime GetDriveTypeW GetDiskFreeSpaceExW GetDiskFreeSpaceW GetVolumeInformationW SetVolumeLabelW CreateHardLinkW DeviceIoControl SetFileAttributesW GetShortPathNameW CreateEventW SetEvent GetEnvironmentVariableW SetEnvironmentVariableW GlobalLock GlobalUnlock GlobalAlloc GetFileSize GlobalFree GlobalMemoryStatusEx Beep GetComputerNameW GetWindowsDirectoryW GetSystemDirectoryW GetCurrentProcessId GetCurrentThread GetProcessIoCounters CreateProcessW SetPriorityClass LoadLibraryW VirtualAlloc LoadLibraryExW HeapFree WaitForSingleObject CreateThread DuplicateHandle GetLastError CloseHandle GetCurrentProcess GetProcAddress LoadLibraryA FreeLibrary GetModuleFileNameW GetFullPathNameW ExitProcess ExitThread GetSystemTimeAsFileTime SetCurrentDirectoryW IsDebuggerPresent GetCurrentDirectoryW ResumeThread GetStartupInfoW TlsGetValue TlsAlloc TlsSetValue TlsFree SetLastError HeapSize GetCPInfo GetACP GetOEMCP IsValidCodePage UnhandledExceptionFilter SetUnhandledExceptionFilter GetModuleFileNameA HeapReAlloc HeapCreate SetHandleCount GetFileType GetStartupInfoA SetStdHandle GetConsoleCP GetConsoleMode LCMapStringW LCMapStringA RtlUnwind SetFilePointer GetTimeZoneInformation GetTimeFormatA GetDateFormatA FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetTickCount GetStringTypeA GetStringTypeW GetLocaleInfoA GetModuleHandleA WriteConsoleA GetConsoleOutputCP WriteConsoleW CreateFileA SetEndOfFile EnumResourceNamesW SetEnvironmentVariableA |
USER32.dll |
SetWindowPos
GetCursorInfo RegisterHotKey ClientToScreen GetKeyboardLayoutNameW IsCharAlphaW IsCharAlphaNumericW IsCharLowerW IsCharUpperW GetMenuStringW GetSubMenu GetCaretPos IsZoomed MonitorFromPoint GetMonitorInfoW SetWindowLongW SetLayeredWindowAttributes FlashWindow GetClassLongW TranslateAcceleratorW IsDialogMessageW GetSysColor InflateRect DrawFocusRect DrawTextW FrameRect DrawFrameControl FillRect PtInRect DestroyAcceleratorTable CreateAcceleratorTableW SetCursor GetWindowDC GetSystemMetrics GetActiveWindow CharNextW wsprintfW RedrawWindow DrawMenuBar DestroyMenu SetMenu GetWindowTextLengthW CreateMenu IsDlgButtonChecked DefDlgProcW ReleaseCapture SetCapture WindowFromPoint CreateIconFromResourceEx mouse_event ExitWindowsEx SetActiveWindow FindWindowExW EnumThreadWindows SetMenuDefaultItem InsertMenuItemW IsMenu TrackPopupMenuEx GetCursorPos DeleteMenu CheckMenuRadioItem CopyImage GetMenuItemCount SetMenuItemInfoW GetMenuItemInfoW SetForegroundWindow IsIconic FindWindowW SystemParametersInfoW PeekMessageW SendInput GetAsyncKeyState SetKeyboardState GetKeyboardState GetKeyState VkKeyScanW LoadStringW DialogBoxParamW MessageBeep EndDialog SendDlgItemMessageW GetDlgItem SetWindowTextW CopyRect ReleaseDC GetDC EndPaint BeginPaint GetClientRect GetMenu DestroyWindow EnumWindows GetDesktopWindow IsWindow IsWindowEnabled IsWindowVisible EnableWindow InvalidateRect GetWindowThreadProcessId AttachThreadInput GetFocus GetWindowTextW ScreenToClient SendMessageTimeoutW EnumChildWindows CharUpperBuffW GetClassNameW GetParent GetDlgCtrlID SendMessageW MapVirtualKeyW PostMessageW GetWindowRect SetUserObjectSecurity GetUserObjectSecurity CloseDesktop CloseWindowStation OpenDesktopW SetProcessWindowStation GetProcessWindowStation OpenWindowStationW MessageBoxW DefWindowProcW MoveWindow AdjustWindowRectEx SetRect SetClipboardData EmptyClipboard CountClipboardFormats CloseClipboard GetClipboardData IsClipboardFormatAvailable OpenClipboard BlockInput GetMessageW LockWindowUpdate DispatchMessageW GetMenuItemID TranslateMessage SetFocus PostQuitMessage KillTimer CreatePopupMenu RegisterWindowMessageW SetTimer ShowWindow CreateWindowExW RegisterClassExW LoadIconW LoadCursorW GetSysColorBrush GetForegroundWindow MessageBoxA DestroyIcon UnregisterHotKey CharLowerBuffW MonitorFromRect keybd_event LoadImageW GetWindowLongW |
GDI32.dll |
DeleteObject
GetObjectW GetTextExtentPoint32W ExtCreatePen StrokeAndFillPath StrokePath EndPath SetPixel CloseFigure CreateCompatibleBitmap CreateCompatibleDC SelectObject StretchBlt GetDIBits LineTo AngleArc MoveToEx Ellipse PolyDraw BeginPath Rectangle GetDeviceCaps SetBkMode RoundRect SetBkColor CreatePen CreateSolidBrush SetTextColor CreateFontW GetTextFaceW GetStockObject CreateDCW GetPixel DeleteDC SetViewportOrgEx |
COMDLG32.dll |
GetSaveFileNameW
GetOpenFileNameW |
ADVAPI32.dll |
RegEnumValueW
RegDeleteValueW RegDeleteKeyW RegSetValueExW RegCreateKeyExW GetUserNameW RegConnectRegistryW RegEnumKeyExW CloseServiceHandle UnlockServiceDatabase LockServiceDatabase OpenSCManagerW InitiateSystemShutdownExW AdjustTokenPrivileges RegCloseKey RegQueryValueExW RegOpenKeyExW OpenThreadToken OpenProcessToken LookupPrivilegeValueW DuplicateTokenEx CreateProcessAsUserW CreateProcessWithLogonW InitializeSecurityDescriptor InitializeAcl GetLengthSid SetSecurityDescriptorDacl CopySid LogonUserW GetTokenInformation GetAclInformation GetAce AddAce GetSecurityDescriptorDacl |
SHELL32.dll |
DragQueryPoint
ShellExecuteExW SHGetFolderPathW DragQueryFileW SHEmptyRecycleBinW SHBrowseForFolderW SHFileOperationW SHGetPathFromIDListW SHGetDesktopFolder SHGetMalloc ExtractIconExW Shell_NotifyIconW ShellExecuteW DragFinish |
ole32.dll |
OleSetMenuDescriptor
MkParseDisplayName OleSetContainedObject CoInitialize CoUninitialize CoCreateInstance CreateStreamOnHGlobal CoTaskMemAlloc CoTaskMemFree CLSIDFromString StringFromCLSID IIDFromString StringFromIID OleInitialize CreateBindCtx CLSIDFromProgID CoInitializeSecurity CoCreateInstanceEx CoSetProxyBlanket OleUninitialize |
OLEAUT32.dll |
SafeArrayAllocData
SafeArrayAllocDescriptorEx SysAllocString OleLoadPicture SafeArrayGetVartype SafeArrayDestroyData SafeArrayAccessData VarR8FromDec VariantTimeToSystemTime VariantClear VariantCopy VariantInit SafeArrayDestroyDescriptor LoadRegTypeLib GetActiveObject SafeArrayUnaccessData |
(Paused) |
AutoIt Error |
AutoIt has detected the stack has become corrupt. |
Stack corruption typically occurs when either the wrong calling convention is used or when the function is called with the wrong number of arguments. |
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention. |
Badly formatted "Func" statement. |
Missing right bracket ')' in expression. |
Missing operator in expression. |
Unbalanced brackets in expression. |
Error in expression. |
Error parsing function call. |
Incorrect number of parameters in function call. |
"ReDim" used without an array variable. |
Illegal text at the end of statement (one statement per line). |
"If" statement has no matching "EndIf" statement. |
"Else" statement with no matching "If" statement. |
"EndIf" statement with no matching "If" statement. |
Too many "Else" statements for matching "If" statement. |
"While" statement has no matching "Wend" statement. |
"Wend" statement with no matching "While" statement. |
Variable used without being declared. |
Array variable has incorrect number of subscripts or subscript dimension range exceeded. |
Array variable subscript badly formatted. |
Subscript used with non-Array variable. |
Too many subscripts used for an array. |
Missing subscript dimensions in "Dim" statement. |
No variable given for "Dim", "Local", "Global", "Struct" or "Const" statement. |
Expected a "=" operator in assignment statement. |
Invalid keyword at the start of this line. |
Array maximum size exceeded. |
"Func" statement has no matching "EndFunc". |
Duplicate function name. |
Unknown function name. |
Unknown macro. |
Unable to get a list of running processes. |
Unable to get the process token. |
Invalid element in a DllStruct. |
Unknown option or bad parameter specified. |
Unable to load the internet libraries. |
"Struct" statement has no matching "EndStruct". |
Unable to open file, the maximum number of open files has been exceeded. |
Invalid file filter given. |
Expected a variable in user function call. |
"Do" statement has no matching "Until" statement. |
"Until" statement with no matching "Do" statement. |
"For" statement is badly formatted. |
"Next" statement with no matching "For" statement. |
"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop. |
"For" statement has no matching "Next" statement. |
"Case" statement with no matching "Select"or "Switch" statement. |
"EndSelect" statement with no matching "Select" statement. |
Recursion level has been exceeded - AutoIt will quit to prevent stack overflow. |
Cannot make existing variables static. |
Cannot make static variables into regular variables. |
Badly formated Enum statement |
This keyword cannot be used after a "Then" keyword. |
"Select" statement is missing "EndSelect" or "Case" statement. |
"If" statements must have a "Then" keyword. |
Badly formated Struct statement. |
Cannot assign values to constants. |
Cannot make existing variables into constants. |
Only Object-type variables allowed in a "With" statement. |
"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead. |
Object referenced outside a "With" statement. |
Nested "With" statements are not allowed. |
Variable must be of type "Object". |
The requested action with this object has failed. |
Variable appears more than once in function declaration. |
ReDim array can not be initialized in this manner. |
An array variable can not be used in this manner. |
Can not redeclare a constant. |
Can not redeclare a parameter inside a user function. |
Can pass constants by reference only to parameters with "Const" keyword. |
Can not initialize a variable with itself. |
Incorrect way to use this parameter. |
"EndSwitch" statement with no matching "Switch" statement. |
"Switch" statement is missing "EndSwitch" or "Case" statement. |
"ContinueCase" statement with no matching "Select"or "Switch" statement. |
Assert Failed! |
Obsolete function/parameter. |
Invalid Exitcode (reserved for AutoIt internal use). |
Unable to parse line. |
Unable to open the script file. |
String missing closing quote. |
Badly formated variable or macro. |
Missing separator character after keyword. |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 3.0.0.0 |
ProductVersion | 3.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_UNKNOWN
|
Language | English - United States |
Comments | www.opautoclicker.com |
FileDescription | OP Auto Clicker |
FileVersion (#2) | 3.0 |
LegalCopyright | www.opautoclicker.com |
ProductName | OP Auto Clicker |
ProductVersion (#2) | 3.0 |
Resource LangID | English - United States |
---|
XOR Key | 0xbeafe369 |
---|---|
Unmarked objects | 0 |
150 (20413) | 2 |
ASM objects (VS2008 SP1 build 30729) | 30 |
C objects (VS2008 SP1 build 30729) | 178 |
C++ objects (VS2008 SP1 build 30729) | 57 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 10 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 33 |
Total imports | 525 |
143 (VS2008 SP1 build 30729) | 70 |
ASM objects (VS2008 build 21022) | 2 |
Linker (VS2008 build 21022) | 1 |
151 | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |