| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2002-Sep-26 14:02:35 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ v7.1 EXE Microsoft Visual Basic v5.0 - v6.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .data1 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/70 (Scanned on 2026-05-04 02:13:50) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2002-Sep-26 14:02:35 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x228000 |
| SizeOfInitializedData | 0x1eb7000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0016FDD6 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x229000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x20e0000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x576c08 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WINMM.dll |
timeBeginPeriod
timeEndPeriod timeKillEvent timeSetEvent timeGetTime |
|---|---|
| DINPUT8.dll |
DirectInput8Create
|
| KERNEL32.dll |
LoadLibraryA
GetProcAddress GetModuleHandleA WriteFile GetLastError GetFileSize MapViewOfFile CreateFileMappingA CreateFileA CreateFileW WideCharToMultiByte GetVersionExA UnmapViewOfFile LockResource LoadResource SizeofResource GetDriveTypeA FindResourceW IsProcessorFeaturePresent GetCurrentProcessId GetCurrentThreadId GetTickCount GetStartupInfoA ExitProcess LeaveCriticalSection EnterCriticalSection DeleteCriticalSection InitializeCriticalSection lstrcmpiA HeapFree HeapDestroy HeapCreate HeapAlloc CloseHandle CreateMutexA GlobalMemoryStatus Sleep ExitThread GetSystemTimeAsFileTime SetFilePointer GetFullPathNameA FindResourceA RemoveDirectoryA lstrlenA GetExitCodeThread SetEvent CreateThread SetThreadPriorityBoost PulseEvent SuspendThread GetCurrentThread GetThreadPriority SetThreadPriority ResumeThread QueryPerformanceFrequency MultiByteToWideChar ReadFile lstrcpyA lstrcatA SystemTimeToFileTime CopyFileA WaitForSingleObject ReleaseMutex FindFirstFileA FindNextFileA FindClose GetOverlappedResult SetFileAttributesA GetDiskFreeSpaceExA GetLocalTime DeleteFileA OutputDebugStringA GetThreadLocale GetLocaleInfoA CreateDirectoryA GetACP InterlockedExchange FileTimeToSystemTime FileTimeToLocalFileTime CreateEventA QueryPerformanceCounter |
| USER32.dll |
LoadCursorA
PeekMessageA TranslateMessage wsprintfA MessageBoxA DispatchMessageA UpdateWindow ShowWindow CreateWindowExA DefWindowProcA SendMessageA PostQuitMessage EndPaint BeginPaint RegisterClassExA |
| GDI32.dll |
DeleteObject
|
| ADVAPI32.dll |
RegQueryValueExA
RegOpenKeyA RegCloseKey |
| d3d8.dll |
Direct3DCreate8
|
| DSOUND.dll |
#11
|
| binkw32.dll |
_BinkSetSoundOnOff@8
_BinkOpen@8 _BinkSetSoundTrack@8 _BinkSetSoundSystem@8 _BinkOpenDirectSound@4 _BinkClose@4 _BinkCopyToBuffer@28 _BinkNextFrame@4 _BinkDoFrame@4 _BinkWait@4 _BinkPause@8 |
| MSVCR70.dll |
wcslen
??_V@YAXPAX@Z _stricmp strncpy strncmp ??1exception@@UAE@XZ ??0exception@@QAE@XZ _strnicmp ??0exception@@QAE@ABV0@@Z _CIasin _aligned_malloc _aligned_free fputs fprintf strtoul strtok fgets ??_U@YAPAXI@Z ceil puts iswascii __security_error_handler _c_exit _exit _XcptFilter _cexit _acmdln _amsg_exit __getmainargs _initterm __setusermatherr _adjust_fdiv __p__commode __p__fmode __set_app_type ?terminate@@YAXXZ __dllonexit _onexit ??1type_info@@UAE@XZ _except_handler3 _controlfp strstr _beginthread qsort strncat fseek ftell srand vsprintf fread fwrite fclose _finite _ftol isspace isdigit _setjmp3 longjmp ??2@YAPAXI@Z ??3@YAXPAX@Z __CxxFrameHandler fopen exit malloc free sprintf printf _CIpow _CIfmod floor _CIacos calloc _CxxThrowException |
| MSVCP70.dll |
??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z
??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z ??Mstd@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@0@Z |
| ole32.dll |
CoInitialize
|
| XOR Key | 0x58983dec |
|---|---|
| Unmarked objects | 0 |
| 39 (9162) | 1 |
| ASM objects (VS2002 (.NET) build 9466) | 9 |
| Imports (VS2002 (.NET) build 9466) | 6 |
| 49 (9044) | 1 |
| 48 (9044) | 56 |
| C objects (9178) | 4 |
| C++ objects (9178) | 68 |
| 18 (8444) | 1 |
| Unmarked objects (#2) | 8 |
| Imports (9210) | 19 |
| Total imports | 197 |
| C++ objects (VS2002 (.NET) build 9466) | 155 |
| C objects (VS2002 (.NET) build 9466) | 291 |
| Linker (VS2002 (.NET) build 9466) | 1 |
No comments yet.