Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2009-Oct-01 12:35:23 |
Detected languages |
Danish - Denmark
English - United Kingdom English - United States French - France German - Germany Italian - Italy Process Default Language Spanish - Spain (Traditional sort) |
Debug artifacts |
d:\Projects\LEGOSagaPC\saga\PC_Release\LEGOStarWarsSaga.pdb
|
CompanyName | Traveller's Tales (UK) Ltd |
FileDescription | LEGO® Star Wars™ Saga Main Executable |
FileVersion | 1.0.0.0 |
InternalName | LEGO® Star Wars™ Saga |
LegalCopyright | Copyright (C) 2007 |
OriginalFilename | LEGOStarWarsSaga.exe |
ProductName | LEGO® Star Wars™ Saga |
ProductVersion | 1.0.0.0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8 Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
Suspicious | The PE is possibly packed. | Unusual section name found: .extra |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2009-Oct-01 12:35:23 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 8.0 |
SizeOfCode | 0x350000 |
SizeOfInitializedData | 0x18f000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x002E74A2 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x351000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2638000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
GetSystemMetrics
DispatchMessageA TranslateMessage PeekMessageA SetCursorPos DestroyWindow DefWindowProcA PostQuitMessage ShowWindow GetWindowLongA CreateWindowExA RegisterClassExA LoadCursorA LoadIconA MoveWindow MessageBoxW GetForegroundWindow UpdateWindow MessageBoxA LoadKeyboardLayoutA SystemParametersInfoA MapVirtualKeyExA SetCursor AdjustWindowRect SendMessageA |
---|---|
d3dx9_35.dll |
D3DXCreateEffect
D3DXCreateCubeTextureFromFileInMemory D3DXCreateTextureFromFileInMemoryEx D3DXCreateEffectFromFileA D3DXCreateFontA D3DXCreateRenderToSurface D3DXCreateTextureFromFileInMemory D3DXSaveSurfaceToFileInMemory D3DXCreateEffectCompiler D3DXCreateBuffer D3DXCompileShader D3DXMatrixMultiply D3DXMatrixLookAtLH D3DXMatrixOrthoLH |
d3d9.dll |
Direct3DCreate9
D3DPERF_EndEvent D3DPERF_BeginEvent |
WINMM.dll |
timeKillEvent
timeSetEvent timeGetTime |
DSOUND.dll |
#11
|
DINPUT8.dll |
DirectInput8Create
|
binkw32.dll |
_BinkSetSoundTrack@8
_BinkOpen@8 _BinkNextFrame@4 _BinkSetVolume@12 _BinkOpenDirectSound@4 _BinkSetSoundSystem@8 _BinkDoFrame@4 _BinkCopyToBufferRect@44 _BinkGetRealtime@12 _BinkWait@4 _BinkGoto@12 _BinkClose@4 |
XINPUT1_3.dll |
#4
#2 #3 |
KERNEL32.dll |
EnumSystemLocalesA
IsValidLocale SetEndOfFile GetTimeZoneInformation CompareStringA GetUserDefaultLCID GetStringTypeW GetStringTypeA WriteConsoleW GetConsoleOutputCP WriteConsoleA GetLocaleInfoW CompareStringW SetEnvironmentVariableA OutputDebugStringW IsDebuggerPresent GetLocaleInfoA LoadLibraryA InterlockedExchange FreeLibrary SetStdHandle LCMapStringW LCMapStringA IsValidCodePage GetOEMCP GetACP GetCPInfo FlushFileBuffers GetConsoleMode GetConsoleCP SetFilePointer VirtualAlloc FatalAppExitA Sleep SetEvent LeaveCriticalSection EnterCriticalSection WaitForSingleObject ResumeThread SetThreadPriority CreateThread CreateEventA InitializeCriticalSection ResetEvent GetCurrentThreadId CreateFileA CloseHandle ReadFile WriteFile SetFilePointerEx MoveFileA DeleteFileA FindFirstFileA FindClose FindNextFileA FileTimeToSystemTime CreateDirectoryA GetFileAttributesExA QueryPerformanceCounter QueryPerformanceFrequency SetProcessAffinityMask GetProcessAffinityMask GetCurrentProcess MultiByteToWideChar GetTimeFormatA GetDateFormatA GetTickCount DebugBreak GetLogicalDriveStringsA DeleteCriticalSection WaitForMultipleObjects GetFileSize GetUserGeoID GetUserDefaultLangID GetModuleFileNameA GetModuleHandleA VerifyVersionInfoA VerSetConditionMask GetFileAttributesA ExpandEnvironmentStringsA SetThreadExecutionState SetThreadAffinityMask GetCurrentThread OutputDebugStringA GetCommandLineA HeapFree GetVersionExA HeapAlloc GetProcessHeap GetStartupInfoA GetLastError HeapReAlloc TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter GetSystemTimeAsFileTime RaiseException RtlUnwind GetProcAddress ExitProcess SetConsoleCtrlHandler TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError InterlockedDecrement HeapSize GetStdHandle FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStringsW SetHandleCount GetFileType HeapDestroy HeapCreate VirtualFree GetCurrentProcessId |
GDI32.dll |
DeleteObject
|
ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegQueryValueExA |
SHELL32.dll |
SHGetFolderPathA
ShellExecuteA SHCreateDirectoryExA |
ole32.dll |
CoInitializeEx
CoInitialize CoCreateInstance CoUninitialize CoSetProxyBlanket |
OLEAUT32.dll |
SysAllocString
SysFreeString |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.0 |
ProductVersion | 1.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United Kingdom |
CompanyName | Traveller's Tales (UK) Ltd |
FileDescription | LEGO® Star Wars™ Saga Main Executable |
FileVersion (#2) | 1.0.0.0 |
InternalName | LEGO® Star Wars™ Saga |
LegalCopyright | Copyright (C) 2007 |
OriginalFilename | LEGOStarWarsSaga.exe |
ProductName | LEGO® Star Wars™ Saga |
ProductVersion (#2) | 1.0.0.0 |
Resource LangID | English - United Kingdom |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2009-Oct-01 12:35:23 |
Version | 0.0 |
SizeofData | 84 |
AddressOfRawData | 0x3ea470 |
PointerToRawData | 0x3ea470 |
Referenced File | d:\Projects\LEGOSagaPC\saga\PC_Release\LEGOStarWarsSaga.pdb |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x829570 |
SEHandlerTable | 0x7ec9f0 |
SEHandlerCount | 17 |