| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2023-Jul-12 08:59:31 |
| Detected languages |
Chinese - PRC
Italian - Italy |
| FileVersion | 1.0.0.0 |
| FileDescription | Character Swap Trainer for RE4 UHD |
| ProductName | Trainer for RE4 UHD |
| ProductVersion | 1.0.0.8 |
| LegalCopyright | All rights reserved to qingsheng and kreed |
| Comments |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 36/72 (Scanned on 2026-04-17 14:40:40) |
APEX:
Malicious
Antiy-AVL: Trojan[Packed]/Win32.FlyStudio Bkav: W32.AIDetectMalware CTX: exe.trojan.flystudio ClamAV: Win.Packed.Flystudio-10010456-0 CrowdStrike: win/malicious_confidence_100% (W) Cylance: Unsafe Cynet: Malicious (score: 100) DeepInstinct: MALICIOUS ESET-NOD32: Win32/Packed.FlyStudio.AA potentially unwanted application Elastic: malicious (high confidence) Google: Detected Ikarus: Trojan.Win32.QQWare K7AntiVirus: Trojan ( 005246d51 ) K7GW: Trojan ( 005246d51 ) Lionic: Trojan.Win32.Flystudio.4!c Malwarebytes: Malware.AI.1937334022 MaxSecure: Trojan.Malware.300983.susgen McAfeeD: ti!BE6EE5119E68 Microsoft: PUA:Win32/Flystudio Paloalto: generic.ml Sangfor: Virus.Win32.Save.a SentinelOne: Static AI - Malicious PE Skyhigh: BehavesLike.Win32.Dropper.vc Sophos: Generic Reputation PUA (PUA) Symantec: ML.Attribute.HighConfidence Trapmine: malicious.moderate.ml.score TrellixENS: Artemis!DEE5B4048AD5 TrendMicro: TROJ_FRS.VSNTD926 TrendMicro-HouseCall: TROJ_FRS.VSNTD926 VBA32: BScope.Trojan.Emotet Varist: W32/Trojan.IRG.gen!Eldorado Xcitium: Worm.Win32.Dropper.RA@1qraug Yandex: Trojan.GenAsa!Fw5cPO0jg/I alibabacloud: VirTool:Win/Flystudio.AM tehtris: Generic.Malware |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2023-Jul-12 08:59:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0xe6000 |
| SizeOfInitializedData | 0x1be000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000C3A3D (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0xe7000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2e2000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x2ac042 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MSVFW32.dll |
DrawDibDraw
|
|---|---|
| AVIFIL32.dll |
AVIStreamInfoA
AVIStreamGetFrame |
| KERNEL32.dll |
SetHandleCount
GetStdHandle GetFileType GetEnvironmentVariableA HeapDestroy HeapCreate VirtualFree SetEnvironmentVariableA LCMapStringA LCMapStringW VirtualAlloc IsBadWritePtr GetEnvironmentStringsW GetStringTypeA GetStringTypeW CompareStringA CompareStringW IsBadReadPtr IsBadCodePtr SetStdHandle GetEnvironmentStrings FreeEnvironmentStringsW FreeEnvironmentStringsA UnhandledExceptionFilter GetACP HeapSize TerminateProcess CloseHandle GetLocalTime GetSystemTime GetTimeZoneInformation RaiseException RtlUnwind GetStartupInfoA GetOEMCP GetCPInfo GetProcessVersion SetErrorMode GlobalFlags GetCurrentThread GetFileTime GetFileSize TlsGetValue LocalReAlloc TlsSetValue TlsFree GlobalHandle TlsAlloc LocalAlloc lstrcmpA GetVersion GlobalGetAtomNameA GlobalAddAtomA GlobalFindAtomA GlobalDeleteAtom lstrcmpiA SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer DuplicateHandle lstrcpynA SetLastError FileTimeToLocalFileTime FileTimeToSystemTime LocalFree InterlockedDecrement InterlockedIncrement GetCurrentProcess WaitForSingleObject CreateSemaphoreA ResumeThread ReleaseSemaphore EnterCriticalSection LeaveCriticalSection GetProfileStringA WriteFile WaitForMultipleObjects CreateFileA SetEvent FindResourceA LoadResource LockResource ReadFile GetModuleFileNameA WideCharToMultiByte MultiByteToWideChar GetCurrentThreadId ExitProcess GlobalSize GlobalFree DeleteCriticalSection InitializeCriticalSection lstrcatA lstrlenA WinExec lstrcpyA FindNextFileA GlobalReAlloc HeapFree HeapReAlloc GetProcessHeap HeapAlloc GetFullPathNameA FreeLibrary LoadLibraryA GetLastError GetVersionExA WritePrivateProfileStringA CreateThread CreateEventA Sleep GlobalAlloc GlobalLock GlobalUnlock FindFirstFileA FindClose GetFileAttributesA SetCurrentDirectoryA GetVolumeInformationA GetModuleHandleA GetProcAddress MulDiv GetCommandLineA GetTickCount SetUnhandledExceptionFilter |
| USER32.dll |
GetDesktopWindow
GetClassNameA GetMenuCheckMarkDimensions SetMenuItemBitmaps CheckMenuItem IsDialogMessageA ScrollWindowEx SendDlgItemMessageA MapWindowPoints AdjustWindowRectEx GetScrollPos RegisterClassA CreateWindowExA GetClassLongA RemovePropA GetMessageTime GetLastActivePopup RegisterWindowMessageA GetWindowPlacement EndDialog CreateDialogIndirectParamA DestroyWindow GetDlgItem EndPaint BeginPaint CharUpperA GetWindowTextLengthA GetForegroundWindow GetNextDlgTabItem GetWindowTextA SetWindowTextA GetMenuItemCount GetMenuItemID GetMenuStringA GetMenuState GetTabbedTextExtentA DrawStateA GrayStringA TabbedTextOutA WindowFromDC EnumChildWindows GetWindowDC UnhookWindowsHookEx CallNextHookEx SetWindowsHookExA FrameRect GetPropA MoveWindow CallWindowProcA SetPropA DrawTextA GetCursor TranslateMessage DrawFrameControl DrawEdge DrawFocusRect WindowFromPoint DispatchMessageA SetRectEmpty RegisterClipboardFormatA CreateIconFromResourceEx CreateIconFromResource DrawIconEx CreatePopupMenu AppendMenuA ModifyMenuA CreateMenu CreateAcceleratorTableA GetDlgCtrlID GetSubMenu EnableMenuItem ClientToScreen EnumDisplaySettingsA LoadImageA SystemParametersInfoA ShowWindow IsWindowEnabled TranslateAcceleratorA GetKeyState CopyAcceleratorTableA PostQuitMessage IsZoomed GetClassInfoA DefWindowProcA GetSystemMenu DeleteMenu GetMenu SetMenu PeekMessageA IsIconic SetFocus GetActiveWindow GetWindow DestroyAcceleratorTable SetWindowRgn GetMessagePos ScreenToClient ChildWindowFromPointEx CopyRect LoadBitmapA WinHelpA KillTimer SetTimer ReleaseCapture GetCapture SetCapture GetScrollRange SetScrollRange SetScrollPos SetRect InflateRect IntersectRect DestroyIcon PtInRect OffsetRect IsWindowVisible EnableWindow RedrawWindow GetWindowLongA SetWindowLongA GetSysColor SetActiveWindow SetCursorPos LoadCursorA SetCursor GetDC FillRect IsRectEmpty ReleaseDC IsChild LoadStringA GetSysColorBrush GetMessageA TrackPopupMenu DestroyMenu SetForegroundWindow GetWindowRect EqualRect UpdateWindow ValidateRect InvalidateRect GetClientRect GetFocus GetParent GetTopWindow PostMessageA IsWindow SetParent DestroyCursor SendMessageA SetWindowPos MessageBoxA GetCursorPos GetSystemMetrics EmptyClipboard SetClipboardData OpenClipboard GetClipboardData CloseClipboard wsprintfA LoadIconA UnregisterClassA |
| GDI32.dll |
SetDIBitsToDevice
SetPolyFillMode SetROP2 SetMapMode SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx GetClipBox ExcludeClipRect MoveToEx LineTo GetWindowOrgEx GetTextColor CreatePolygonRgn ExtSelectClipRgn GetViewportExtEx GetTextMetricsA Escape ExtTextOutA TextOutA RectVisible PtVisible CreatePenIndirect RestoreDC SaveDC SetWindowOrgEx SetTextColor SetBkMode SetBkColor CreateRectRgnIndirect CreateDIBSection SetPixel SetStretchBltMode GetClipRgn GetBkMode GetBkColor GetROP2 GetStretchBltMode GetPolyFillMode CreateCompatibleBitmap CreateDCA CreateBrushIndirect CreateBitmap CreatePatternBrush BeginPath SelectClipRgn EndPath DeleteObject CreateDIBitmap GetSystemPaletteEntries PathToRegion CreatePalette StretchBlt SelectPalette RealizePalette GetDIBits GetWindowExtEx CreateEllipticRgn GetViewportOrgEx PatBlt SelectObject GetObjectA CreatePen GetDeviceCaps GetTextExtentPoint32A RoundRect GetCurrentObject DPtoLP LPtoDP Rectangle Ellipse SetPixelV CreateCompatibleDC GetPixel BitBlt StartPage StartDocA DeleteDC EndDoc EndPage CreateFontIndirectA GetStockObject CreateSolidBrush FillRgn CreateRectRgn CombineRgn CreateRoundRectRgn |
| WINMM.dll |
midiStreamRestart
midiStreamClose midiOutReset midiStreamStop midiStreamOut midiOutPrepareHeader midiStreamProperty midiStreamOpen midiOutUnprepareHeader waveOutOpen waveOutGetNumDevs waveOutClose waveOutReset waveOutPause waveOutWrite waveOutPrepareHeader waveOutUnprepareHeader PlaySoundA |
| MSIMG32.dll |
GradientFill
|
| WINSPOOL.DRV |
DocumentPropertiesA
OpenPrinterA ClosePrinter |
| comdlg32.dll |
GetFileTitleA
GetSaveFileNameA GetOpenFileNameA ChooseColorA |
| ADVAPI32.dll |
RegCreateKeyExA
RegQueryValueA RegSetValueExA RegOpenKeyExA RegCloseKey |
| SHELL32.dll |
Shell_NotifyIconA
ShellExecuteA |
| ole32.dll |
OleInitialize
OleUninitialize CLSIDFromString |
| OLEAUT32.dll |
LoadTypeLib
RegisterTypeLib UnRegisterTypeLib |
| COMCTL32.dll |
ImageList_Draw
_TrackMouseEvent ImageList_GetImageCount ImageList_AddMasked ImageList_GetIcon ImageList_SetBkColor #17 ImageList_Destroy ImageList_Create ImageList_Read ImageList_DrawIndirect ImageList_Duplicate ImageList_GetImageInfo |
| WS2_32.dll |
closesocket
WSAAsyncSelect WSACleanup accept getpeername recv ioctlsocket recvfrom inet_ntoa |
| 打开 |
| 保存为 |
| 所有文件 (*.*) |
| 无标题 |
| 一未命名文件 |
| 隐藏(&H) |
| 得不到出错信息。 |
| 试图执行系统不支持的操作。 |
| 必需的资源无法得到。 |
| 内存不足。 |
| 出现了未知的错误 |
| 无效的文件名。 |
| 打开文档失败。 |
| 保存文档失败。 |
| 将改动保存到 %1? |
| 建立空文档失败。 |
| 该文件太大,无法打开。 |
| 无法启动打印作业。 |
| 启动帮助失败。 |
| 内部应用程序出错。 |
| 命令失败。 |
| 没有足够的内存执行操作。 |
| 系统注册项已被移除并且相应的 INI 文件(假如存在)也被删除。 |
| 不是所有的系统注册项(或 INI 文件)都被移除。 |
| 在系统中没有找到此程序需要的文件%s。 |
| 此程序连接到文件 %s 中丢失的输出 %s 。此机器可能有一个 %s 不兼容的版本。 |
| 请键入一个整数。 |
| 请键入一个数。 |
| “请填入一个在%1和%2之间的整数。” |
| “请填入一个在%1和%2之间的数字。” |
| “请填入不多于%1个的字符。” |
| 请选择一个按钮。 |
| “请填入一个在0和255之间的整数。” |
| “请填入一个正整数。” |
| “请填入一个日期和/或时间值。” |
| “请填入一个货币值。” |
| 非预期的文件格式。 |
| 无法找到该文件。 |
| 请验证给出的路径和文件名是否正确。 |
| 目的磁盘驱动器已满。 |
| 无法对 %1 进行读操作,它已经被其他人打开。 |
| 无法对 %1 进行写操作,因为它是只读文件或已经被其他人打开。 |
| 在对 %1 进行读操作时发生了一个非预期的错误。 |
| 在对 %1 进行写操作时发生了一个非预期的错误。 |
| 无法读只写特性。 |
| 无法写只读特性。 |
| 无法装入邮件系统支援。 |
| 邮件系统 DLL 无效。 |
| 传递邮件未能传递信息。 |
| 无错误发生。 |
| 在对 %1 进行访问时发生了一个不明错误。 |
| 没有找到 %1。 |
| %1 中包含无效的路径。 |
| 无法打开 %1 因为太多文件已被打开。 |
| 对 %1 的存取被拒绝。 |
| 一个无效的文件柄与 %1 相关联。 |
| 无法删除 %1 因为它是当前目录。 |
| 该目录已满,无法创建 %1。 |
| 对 %1 进行查找失败。 |
| 在存取 %1 时一个硬件输入/输出错误被报告。 |
| 在存取 %1 时发生共享违例。 |
| 在存取 %1 时发生锁违例。 |
| 在存取 %1 时磁盘已满。 |
| 试图越过其尾端对 %1 进行读写。 |
| 无错误发生。 |
| 在对 %1 进行访问时发生了一个不明错误。 |
| 试图在对 %1 进行读操作的同时对其进行写操作。 |
| 试图越过其尾端对 %1 进行读写。 |
| 试图在对 %1 进行写操作的同时对其进行读操作。 |
| %1 格式错。 |
| %1 含有非预期的对象。 |
| %1 包含错误的模式。 |
| 象素 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.8 |
| ProductVersion | 1.0.0.8 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Chinese - PRC |
| FileVersion (#2) | 1.0.0.0 |
| FileDescription | Character Swap Trainer for RE4 UHD |
| ProductName | Trainer for RE4 UHD |
| ProductVersion (#2) | 1.0.0.8 |
| LegalCopyright | All rights reserved to qingsheng and kreed |
| Comments |
| Resource LangID | Chinese - PRC |
|---|
| XOR Key | 0x9b8ff31a |
|---|---|
| Unmarked objects | 0 |
| C++ objects (8047) | 2 |
| 12 (7291) | 3 |
| 19 (8022) | 44 |
| 14 (7299) | 44 |
| C objects (VS98 SP6 build 8804) | 194 |
| Total imports | 663 |
| 19 (8034) | 27 |
| C++ objects (VS98 SP6 build 8804) | 102 |
| C++ objects (VS98 build 8168) | 109 |
| C objects (VS98 build 8168) | 46 |
| Unmarked objects (#2) | 39 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
No comments yet.