Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2012-Oct-02 05:04:04 |
Detected languages |
English - United States
|
Comments | This installation was built with Inno Setup. |
CompanyName | FreeTP.Org - Tiny Tinas Wonderlands Multiplayer Fix |
FileDescription | Tiny Tinas Wonderlands |
FileVersion | |
LegalCopyright | |
ProductName | Tiny Tinas Wonderlands |
ProductVersion | 1-1 |
Suspicious | The PE is possibly packed. | Unusual section name found: .itext |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
1183741 bytes of data starting at offset 0x25200.
The overlay data has an entropy of 7.99984 and is possibly compressed or encrypted. Overlay data amounts for 88.6163% of the executable. |
Malicious | VirusTotal score: 13/75 (Scanned on 2024-07-27 23:13:01) |
AhnLab-V3:
Unwanted/Win.Generic.R557998
CrowdStrike: win/grayware_confidence_60% (W) Cylance: Unsafe DeepInstinct: MALICIOUS Fortinet: PossibleThreat.PALLASNET.M Google: Detected Gridinsoft: Hack.Win32.Patcher.cl Ikarus: HackTool.Win32.Crack McAfee: Artemis!F7F46E3618C3 McAfeeD: ti!CE4D9CD0A4C7 Microsoft: HackTool:Win32/crack Webroot: W32.Trojan.Gen alibabacloud: Trojan:Win/Crack.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2012-Oct-02 05:04:04 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 2.0 |
SizeOfCode | 0x15000 |
SizeOfInitializedData | 0xfe00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00016478 (Section: .itext) |
BaseOfCode | 0x1000 |
BaseOfData | 0x17000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 6.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x2f000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
---|---|
advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
user32.dll |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
kernel32.dll |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
kernel32.dll (#2) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
user32.dll (#2) |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
kernel32.dll (#3) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
comctl32.dll |
InitCommonControls
|
kernel32.dll (#4) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
advapi32.dll (#3) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Invalid file name - %s |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
December |
Sun |
Mon |
Tue |
Wed |
Monitor support function not initialized |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
Variant or safe array is locked |
Invalid variant type conversion |
Invalid variant operation |
Invalid variant operation (%s%.8x) |
%s |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
Object lock not owned |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
Control-C hit |
Privileged instruction |
Operation aborted |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Out of memory |
I/O error %d |
File not found |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 0.0.0.0 |
ProductVersion | 0.0.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
Comments | This installation was built with Inno Setup. |
CompanyName | FreeTP.Org - Tiny Tinas Wonderlands Multiplayer Fix |
FileDescription | Tiny Tinas Wonderlands |
FileVersion (#2) | |
LegalCopyright | |
ProductName | Tiny Tinas Wonderlands |
ProductVersion (#2) | 1-1 |
Resource LangID | English - United States |
---|
StartAddressOfRawData | 0x41f000 |
---|---|
EndAddressOfRawData | 0x41f008 |
AddressOfIndex | 0x4177b4 |
AddressOfCallbacks | 0x420010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |