| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2013-Aug-24 08:13:42 |
| Detected languages |
Chinese - PRC
English - United States |
| Debug artifacts |
E:\ç³»ç»æä»¶å¤¹\æçææ¡£\Visual Studio 2010\Projects\dnp\Release\DnPakStudio.pdb
|
| FileDescription | é¾ä¹è°·è¡¥ä¸å·¥å |
| FileVersion | 2.4.4984.28883 |
| InternalName | DnPakStudio.exe |
| LegalCopyright | Copyright © 2013 ãç¬æ åã. All Rights Reserved. |
| OriginalFilename | DnPakStudio.exe |
| ProductName | é¾ä¹è°·è¡¥ä¸å·¥å |
| ProductVersion | 2.4.4984.28883 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 2/70 (Scanned on 2023-09-21 23:27:34) |
APEX:
Malicious
Rising: Trojan.Generic@AI.90 (RDML:jWsmv3vx1v64FGIeGaVZlA) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2013-Aug-24 08:13:42 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x112200 |
| SizeOfInitializedData | 0x8ce00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000F05F3 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x114000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1aa000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1aef5f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
SetEnvironmentVariableA
GetConsoleMode GetConsoleCP LCMapStringW GetTimeZoneInformation GetStringTypeW IsValidCodePage GetOEMCP GetACP GetCPInfo IsProcessorFeaturePresent IsDebuggerPresent UnhandledExceptionFilter TerminateProcess QueryPerformanceCounter HeapCreate SetHandleCount GetEnvironmentStringsW FreeEnvironmentStringsW GetStdHandle SetUnhandledExceptionFilter GetFileType GetFileAttributesW SetStdHandle VirtualQuery GetSystemInfo VirtualAlloc GetSystemTimeAsFileTime ExitProcess CreateThread ExitThread HeapSize WriteConsoleW EncodePointer DecodePointer RaiseException RtlUnwind HeapReAlloc HeapFree HeapAlloc GetStartupInfoW HeapSetInformation GetCommandLineW FindResourceExW VirtualProtect SearchPathW Sleep GetProfileIntW GetTickCount GetTempPathW GetTempFileNameW GetCurrentDirectoryW GetNumberFormatW lstrcpyW GetSystemDirectoryW GetFileTime GetFileSizeEx FileTimeToLocalFileTime HeapQueryInformation GetFileAttributesExW GetUserDefaultUILanguage GetLocaleInfoW InterlockedExchange FreeResource GlobalFindAtomW GlobalDeleteAtom GetVersionExW InitializeCriticalSectionAndSpinCount WaitForSingleObject GetCurrentThreadId ResumeThread SetThreadPriority GetFullPathNameW GetVolumeInformationW FindFirstFileW FindClose GetCurrentProcess DuplicateHandle CloseHandle GetFileSize SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer WriteFile ReadFile CreateFileW lstrcmpiW GlobalAddAtomW GlobalFlags lstrcmpW TlsFree DeleteCriticalSection LocalReAlloc TlsSetValue TlsAlloc InitializeCriticalSection GlobalHandle GlobalReAlloc EnterCriticalSection TlsGetValue LeaveCriticalSection LocalAlloc GetCurrentProcessId CompareStringW ActivateActCtx ReleaseActCtx DeactivateActCtx InterlockedDecrement InterlockedIncrement GetModuleHandleW FileTimeToSystemTime lstrlenA lstrcmpA GlobalGetAtomNameW GetLastError SetLastError GlobalFree CopyFileW GlobalSize GlobalAlloc GlobalLock GlobalUnlock FormatMessageW LocalFree lstrlenW MulDiv WideCharToMultiByte FreeLibrary GetProcAddress LoadLibraryW GetWindowsDirectoryW FindResourceW LoadResource LockResource SizeofResource MultiByteToWideChar GetModuleFileNameW |
|---|---|
| USER32.dll |
TranslateMDISysAccel
DrawMenuBar DefMDIChildProcW DefFrameProcW WaitMessage PostThreadMessageW UnpackDDElParam ReuseDDElParam InsertMenuItemW TranslateAcceleratorW IsMenu MonitorFromPoint UpdateLayeredWindow UnionRect MapVirtualKeyExW IsCharLowerW EmptyClipboard CloseClipboard SetClipboardData OpenClipboard GetKeyNameTextW LockWindowUpdate BringWindowToTop SetCursorPos SetRect CreateAcceleratorTableW LoadAcceleratorsW GetKeyboardState GetKeyboardLayout ToUnicodeEx CopyAcceleratorTableW DrawFrameControl DrawEdge DrawStateW GetSystemMenu LoadMenuW SetClassLongW WindowFromPoint DestroyAcceleratorTable SetParent SetWindowRgn IsZoomed DeleteMenu ShowOwnedPopups CreateDialogIndirectParamW DrawIconEx GetNextDlgGroupItem KillTimer SetTimer LoadImageW GetIconInfo OffsetRect GetNextDlgTabItem MessageBeep NotifyWinEvent SetCursor EnableScrollBar HideCaret DrawFocusRect InvertRect GetAsyncKeyState SetCapture InvalidateRect MapVirtualKeyW IsRectEmpty CreatePopupMenu GetMenuDefaultItem SetLayeredWindowAttributes EnumDisplayMonitors SetRectEmpty CopyImage SystemParametersInfoW DestroyMenu GetMenuItemInfoW IntersectRect InflateRect SetMenuItemBitmaps GetMenuCheckMarkDimensions LoadBitmapW ModifyMenuW EnableMenuItem CheckMenuItem RegisterWindowMessageW SendDlgItemMessageA WinHelpW IsChild GetCapture GetClassLongW SetPropW GetPropW RemovePropW GetForegroundWindow SetActiveWindow BeginDeferWindowPos EndDeferWindowPos GetTopWindow GetMessageTime GetMessagePos MonitorFromWindow GetMonitorInfoW MapWindowPoints ScrollWindow TrackPopupMenu SetMenu SetScrollRange GetScrollRange SetForegroundWindow ShowScrollBar RedrawWindow GetClientRect PostMessageW GetClassInfoExW GetClassInfoW RegisterClassW AdjustWindowRectEx EqualRect DeferWindowPos GetScrollInfo SetScrollInfo SetWindowPlacement GetWindowPlacement CallWindowProcW GetMenu CopyRect GetWindowDC ScreenToClient GrayStringW DrawTextExW DrawTextW TabbedTextOutW FillRect SetWindowsHookExW CallNextHookEx GetMessageW TranslateMessage DispatchMessageW GetActiveWindow IsWindowVisible GetKeyState PeekMessageW GetCursorPos ValidateRect CharUpperW DestroyIcon SetWindowPos MoveWindow SetWindowLongW IsWindow IsDialogMessageW SendDlgItemMessageW CreateMenu SetMenuDefaultItem IsClipboardFormatAvailable FrameRect GetWindowRgn DestroyCursor DrawIcon MapDialogRect GetDlgItem CheckDlgButton GetScrollPos SetScrollPos SetFocus GetFocus GetDesktopWindow RealChildWindowFromPoint SubtractRect GetDoubleClickTime CharUpperBuffW CopyIcon RegisterClipboardFormatW IsIconic GetUpdateRect ClientToScreen GetWindow GetDlgCtrlID GetWindowRect GetClassNameW PtInRect SetWindowTextW GetWindowThreadProcessId SendMessageW GetParent GetWindowLongW GetLastActivePopup IsWindowEnabled EnableWindow UnhookWindowsHookEx GetSystemMetrics GetDC ReleaseDC GetSysColor GetSysColorBrush GetWindowTextLengthW GetWindowTextW GetMenuState GetMenuStringW AppendMenuW GetMenuItemID InsertMenuW GetMenuItemCount GetSubMenu RemoveMenu EndDialog PostQuitMessage EndPaint BeginPaint DefWindowProcW DestroyWindow UpdateWindow ShowWindow CreateWindowExW LoadCursorW LoadIconW MessageBoxW ReleaseCapture |
| GDI32.dll |
CreateFontIndirectW
CreateRectRgnIndirect SetRectRgn CombineRgn PatBlt DPtoLP GetTextExtentPoint32W CreateDIBitmap CreateCompatibleBitmap GetTextMetricsW EnumFontFamiliesW GetTextCharsetInfo GetBkColor CreatePalette GetPaletteEntries GetNearestPaletteIndex RealizePalette GetSystemPaletteEntries CreateDIBSection CreateRoundRectRgn CreatePolygonRgn GetTextColor CreateEllipticRgn Polyline Ellipse Polygon SetDIBColorTable StretchBlt CreateHatchBrush Rectangle OffsetRgn GetRgnBox EnumFontFamiliesExW LPtoDP GetWindowOrgEx GetViewportOrgEx PtInRegion FillRgn FrameRgn GetBoundsRect ExtFloodFill SetPaletteEntries SetPixelV GetTextFaceW OffsetViewportOrgEx SetViewportOrgEx SelectObject CreateSolidBrush Escape CreatePen GetObjectType SetViewportExtEx SelectPalette GetStockObject CreateCompatibleDC CreateBitmap CreatePatternBrush DeleteDC ExtSelectClipRgn ScaleWindowExtEx SetWindowExtEx OffsetWindowOrgEx SetWindowOrgEx SetPixel GetDeviceCaps ExtTextOutW TextOutW RectVisible PtVisible GetPixel BitBlt GetWindowExtEx GetViewportExtEx GetObjectW CreateRectRgn SelectClipRgn SetLayout GetLayout SetTextAlign MoveToEx LineTo IntersectClipRect ExcludeClipRect GetClipBox SetMapMode SetTextColor SetROP2 SetPolyFillMode SetBkMode SetBkColor RestoreDC SaveDC DeleteObject CreateDCW CopyMetaFileW ScaleViewportExtEx |
| MSIMG32.dll |
AlphaBlend
TransparentBlt |
| COMDLG32.dll |
GetFileTitleW
|
| WINSPOOL.DRV |
ClosePrinter
OpenPrinterW DocumentPropertiesW |
| ADVAPI32.dll |
RegOpenKeyExW
RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegSetValueExW RegCloseKey RegQueryValueExW RegEnumKeyExW |
| SHELL32.dll |
DragFinish
SHGetFileInfoW SHGetDesktopFolder SHGetPathFromIDListW SHGetSpecialFolderLocation ShellExecuteW SHAppBarMessage DragQueryFileW SHBrowseForFolderW |
| COMCTL32.dll |
ImageList_GetIconSize
|
| SHLWAPI.dll |
PathFindFileNameW
PathStripToRootW PathIsUNCW PathFindExtensionW PathRemoveFileSpecW |
| ole32.dll |
DoDragDrop
OleLockRunning IsAccelerator OleTranslateAccelerator OleDestroyMenuDescriptor OleCreateMenuDescriptor CreateStreamOnHGlobal CoInitializeEx CoUninitialize CoInitialize CoCreateInstance OleDuplicateData CoTaskMemAlloc ReleaseStgMedium CoTaskMemFree RevokeDragDrop CoLockObjectExternal RegisterDragDrop OleGetClipboard |
| OLEAUT32.dll |
SysFreeString
SysAllocString VariantInit VarBstrFromDate SysAllocStringLen SysStringLen SystemTimeToVariantTime VariantTimeToSystemTime VariantChangeType VariantClear |
| OLEACC.dll |
LresultFromObject
AccessibleObjectFromWindow CreateStdAccessibleObject |
| gdiplus.dll |
GdipGetImageGraphicsContext
GdipBitmapUnlockBits GdipBitmapLockBits GdipCreateBitmapFromScan0 GdipCreateBitmapFromStream GdipGetImagePalette GdipGetImagePaletteSize GdipGetImagePixelFormat GdipGetImageHeight GdipGetImageWidth GdipCloneImage GdipDrawImageRectI GdipSetInterpolationMode GdipCreateFromHDC GdiplusShutdown GdiplusStartup GdipCreateBitmapFromHBITMAP GdipDisposeImage GdipDeleteGraphics GdipAlloc GdipFree GdipDrawImageI |
| IMM32.dll |
ImmGetOpenStatus
ImmReleaseContext ImmGetContext |
| WINMM.dll |
PlaySoundW
|
| DnPakStudio |
| DNPAKSTUDIO |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.4.4984.28883 |
| ProductVersion | 2.4.4984.28883 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | Chinese - PRC |
| FileDescription | é¾ä¹è°·è¡¥ä¸å·¥å |
| FileVersion (#2) | 2.4.4984.28883 |
| InternalName | DnPakStudio.exe |
| LegalCopyright | Copyright © 2013 ãç¬æ åã. All Rights Reserved. |
| OriginalFilename | DnPakStudio.exe |
| ProductName | é¾ä¹è°·è¡¥ä¸å·¥å |
| ProductVersion (#2) | 2.4.4984.28883 |
| Resource LangID | Chinese - PRC |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2013-Aug-24 08:13:42 |
| Version | 0.0 |
| SizeofData | 112 |
| AddressOfRawData | 0x13d100 |
| PointerToRawData | 0x13b700 |
| Referenced File | E:\ç³»ç»æä»¶å¤¹\æçææ¡£\Visual Studio 2010\Projects\dnp\Release\DnPakStudio.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x5592f0 |
| SEHandlerTable | 0x544800 |
| SEHandlerCount | 770 |
| XOR Key | 0xf29a3c0a |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2008 SP1 build 30729) | 1 |
| C objects (VS2008 SP1 build 30729) | 12 |
| Imports (VS2008 SP1 build 30729) | 35 |
| Total imports | 748 |
| ASM objects (VS2010 SP1 build 40219) | 43 |
| C objects (VS2010 SP1 build 40219) | 179 |
| C++ objects (VS2010 SP1 build 40219) | 369 |
| 175 (VS2010 SP1 build 40219) | 2 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.