| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2050-Nov-28 05:33:42 |
| Detected languages |
English - United States
|
| CompanyName | |
| FileDescription | The Everchanging Book of Names Executable |
| FileVersion | 2.1.0 |
| InternalName | EBoN |
| LegalCopyright | © 1997-1998 Sami Pyörre. All Rights Reserved. |
| LegalTrademarks | |
| OriginalFilename | EBoN.exe |
| ProductName | The Everchanging Book of Names |
| ProductVersion | 2.1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Borland C / Borland Builder |
| Suspicious | The PE is possibly packed. | Unusual section name found: .INIT |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
| Suspicious | The file contains overlay data. | 2048 bytes of data starting at offset 0x5b800. |
| Safe | VirusTotal score: 0/69 (Scanned on 2021-07-23 17:06:04) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2050-Nov-28 05:33:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x45200 |
| SizeOfInitializedData | 0x16000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001000 (Section: CODE) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x47000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 1.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x61000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
ReadFile
FileTimeToLocalFileTime GlobalFree GetLocalTime GetStartupInfoA GetSystemInfo LoadLibraryA GetCommandLineA FreeResource RaiseException GetProcAddress WideCharToMultiByte GetFileSize LeaveCriticalSection LocalHandle FindFirstFileA GlobalUnlock GetEnvironmentStrings FileTimeToDosDateTime WriteFile GetVersion FindResourceA GetModuleHandleA SetEndOfFile ExitThread FindNextFileA GetVolumeInformationA GetCurrentProcessId VirtualAlloc InitializeCriticalSection CreateThread SetFilePointer SetFileTime GetFileTime SetHandleCount EnterCriticalSection GlobalMemoryStatus GetFileAttributesA VirtualFree DosDateTimeToFileTime GetTimeZoneInformation lstrcmpiA lstrcmpA LocalReAlloc UnhandledExceptionFilter SetErrorMode FreeLibrary SetConsoleCtrlHandler GetModuleFileNameA LockResource MulDiv CreateFileA LocalUnlock GetFullPathNameA GetVersionExA WinExec GetCurrentThreadId GlobalAlloc GetStdHandle GlobalLock FindClose SetFileAttributesA GetLastError ExitProcess RtlUnwind LocalLock GetFileType LocalFileTimeToFileTime CloseHandle LoadResource |
|---|---|
| USER32.dll |
GetWindowLongA
SendMessageA ScreenToClient GetWindowTextLengthA PostQuitMessage PostMessageA GetWindow InsertMenuItemA MessageBeep LoadMenuIndirectA IsDialogMessageA LoadAcceleratorsA IsZoomed IsWindowVisible GrayStringA IsWindowEnabled IsChild InvalidateRect LoadBitmapA GetWindowRect GetWindowPlacement IsMenu LoadMenuA GetSubMenu MapWindowPoints GetParent GetMenuStringA GetMenuState GetSysColor GetSystemMenu GetUpdateRgn GetWindowDC GetMenuItemInfoA GetWindowTextA GetWindowThreadProcessId InsertMenuA GetMenuItemID IsClipboardFormatAvailable IsIconic IsWindow GetMenuItemCount GetMenuDefaultItem LoadCursorA LoadImageA LoadIconA GetSystemMetrics MessageBoxExA GetFocus GetDlgItem PostThreadMessageA RegisterWindowMessageA PeekMessageA GetDesktopWindow GetDC SetClipboardData GetCursorPos OpenClipboard GetClientRect GetClassInfoA RegisterClassA FrameRect FillRect EnumThreadWindows ModifyMenuA EndPaint EnableWindow RemoveMenu DrawTextA DrawMenuBar SendDlgItemMessageA ReleaseDC DrawFrameControl DrawEdge SetCapture DispatchMessageA DialogBoxParamA DestroyWindow DestroyMenu ReleaseCapture DestroyCursor DeleteMenu DefWindowProcA SetMenu CreateWindowExA CreatePopupMenu CreateMenu CreateDialogParamA DestroyIcon SetFocus CloseClipboard CheckMenuRadioItem CheckMenuItem CallWindowProcA DrawFocusRect BeginPaint DrawIcon AppendMenuA DrawStateA SetCursor EnableMenuItem TrackPopupMenu EndDialog TranslateMDISysAccel EnumClipboardFormats wsprintfA UnregisterClassA WinHelpA GetCapture WaitMessage GetClassNameA UpdateWindow GetClipboardData TranslateMessage TranslateAcceleratorA WindowFromPoint GetDlgCtrlID TabbedTextOutA GetDlgItemInt ShowWindow GetMenu ShowScrollBar SetWindowPos SetWindowPlacement SetWindowLongA SetScrollInfo SetParent SetMenuItemInfoA GetScrollInfo SetMenuDefaultItem SetWindowTextA MessageBoxA |
| GDI32.dll |
RestoreDC
ResetDCA Rectangle RealizePalette PlayMetaFile PlayEnhMetaFile PatBlt OffsetWindowOrgEx OffsetViewportOrgEx IntersectClipRect GetViewportOrgEx GetTextMetricsA GetTextExtentPointA GetSystemPaletteEntries GetStockObject GetPaletteEntries GetObjectA GetMetaFileBitsEx GetMetaFileA GetEnhMetaFileA GetDeviceCaps GetCurrentObject GetClipRgn ExtTextOutA ExtCreatePen DeleteObject DeleteMetaFile DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRoundRectRgn CreateRectRgnIndirect CreateRectRgn CreatePolygonRgn CreatePolyPolygonRgn CreatePenIndirect CreatePen CreatePatternBrush CreatePalette CreateICA CreateHatchBrush CreateFontIndirectA CreateFontA CreateEllipticRgnIndirect CreateDiscardableBitmap CreateDIBitmap CreateDIBPatternBrush CreateDCA CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmapIndirect CreateBitmap CopyMetaFileA CopyEnhMetaFileA TextOutA SetWindowOrgEx CombineRgn SetWindowExtEx SetViewportOrgEx BitBlt SetViewportExtEx SetTextColor SetPixel SetMetaFileBitsEx SetMapMode SetEnhMetaFileBits SetBkMode SetBkColor SelectPalette SelectObject SelectClipRgn ScaleWindowExtEx ScaleViewportExtEx SaveDC |
| Ordinal | 1 |
|---|---|
| Address | 0x1074 |
| Ordinal | 2 |
|---|---|
| Address | 0x512a0 |
| Ordinal | 3 |
|---|---|
| Address | 0x3cbf8 |
| Ordinal | 4 |
|---|---|
| Address | 0x3cc20 |
| Invalid client window %s |
| Invalid child window %s |
| Invalid window %s |
| Invalid DIB handle %X |
| GDI object %X destroy failure |
| GDI object %X delete failure |
| GDI file read failure |
| GDI resource load failure |
| GDI creation failure |
| GDI allocate failure |
| GDI failure |
| Invalid relative window specified in layout constraint in window %s |
| Incomplete layout constraints specified in window %s |
| Printer error |
| Validator syntax error |
| Menu creation failure |
| Child create fail for window %s |
| Execute fail for window %s |
| Create fail for window %s |
| Child class registration fail for window %s |
| Class registration fail for window %s |
| VBX Library init failure |
| Invalid MainWindow |
| Invalid module specified for window |
| Out of memory |
| No application object |
| Unknown error |
| Unhandled Exception |
| OK to resume? |
| ObjectWindows Exception |
| Unknown exception |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.1.0 |
| ProductVersion | 2.0.1.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS16
VOS_OS232_PM32
VOS__PM32
VOS__WINDOWS16
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | |
| FileDescription | The Everchanging Book of Names Executable |
| FileVersion (#2) | 2.1.0 |
| InternalName | EBoN |
| LegalCopyright | © 1997-1998 Sami Pyörre. All Rights Reserved. |
| LegalTrademarks | |
| OriginalFilename | EBoN.exe |
| ProductName | The Everchanging Book of Names |
| ProductVersion (#2) | 2.1 |
| Resource LangID | UNKNOWN |
|---|
No comments yet.