filename | mRGSS300.dll | |
---|---|---|
size | 824320 (0xc9400) | |
md5 | 56629d3f4c272d6c3a2a28e7d90b0f6e | |
type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x5344 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xf0 |
Rich Header
lib id | version | times used |
---|---|---|
96 | 4035 | 1 |
150 | 20413 | 16 |
149 | 30729 | 67 |
109 | 50727 | 3 |
123 | 50727 | 21 |
1 | 0 | 328 |
131 | 30729 | 381 |
132 | 30729 | 144 |
146 | 30729 | 1 |
148 | 21022 | 1 |
145 | 30729 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
UPX v2.00-V2.90 (Markus Oberhumer & Laszlo Molnar & John Reiser) This file is packed with UPX. Analysis will be incomplete without unpacking. |
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
UPX0 | 0x1000 | 0x20a000 | 0 | RWX UDATA | |
UPX1 | 0x20b000 | 0xc9000 | 0xc8200 | RWX IDATA | |
.rsrc | 0x2d4000 | 0x1000 | 0xe00 | RW- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0x2d4930 | 0x2dc | |
IMPORT | 0x2d46cc | 0x264 | |
RESOURCE | 0x2d4000 | 0x6cc | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0x2d4c0c | 0xc | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
id | lang | string |
---|---|---|
192 | 0 | 10 eb 7e 61 77 4f bc 63 6e 72 e2 f3 f9 33 f9 0b |..~awO.cnr...3..| 5e fa c0 47 7f ab e7 d8 4c 7e 68 10 a8 d0 8a 85 |^..G....L~h.....| a4 3d ca fa 87 e3 d5 1b 4b 1d 3e e1 f8 66 5e 15 |.=......K.>..f^.| 4e 8d cc 00 c5 fe 5b 25 a9 c0 50 ff c7 ab 4b e1 |N.....[%..P...K.| 0e 39 f9 97 24 12 5b 80 15 e4 d3 11 4c d9 f7 b3 |.9..$.[.....L...| 51 8a 07 67 71 68 e3 89 cd dc 0c 81 bc 0f 97 73 |Q..gqh.........s| ee 21 4e 86 27 aa 8f d8 5d 50 c8 af 04 c4 af aa |.!N.'...]P......| 21 a3 07 77 35 a4 83 f8 88 51 9b 0d e6 1c 4a 66 |!..w5....Q....Jf| 8a 41 de bb 49 f4 25 8c 7b cd b1 9d 21 02 c4 75 |.A..I.%.{...!..u| 0d ee b7 a9 f9 1d 78 22 f5 42 8a 1f 91 cf a9 71 |......x".B.....q| a8 16 f7 d3 88 6c ed f8 b5 c0 47 c7 9b ee 83 46 |.....l....G....F| 5a 24 f0 cc f9 22 8d 85 a7 42 b2 e6 d2 27 38 37 |Z$..."...B...'87| 18 f5 31 c9 32 c2 a6 67 a7 63 e5 04 8c 5d fa ab |..1.2..g.c...]..| 2d c6 d9 ec c8 70 7e 75 63 d7 11 0e 0a 1e ea bb |-....p~uc.......| df c3 67 cd 50 45 3b 76 a1 b2 8a b8 38 b5 b7 cb |..g.PE;v....8...| df eb c9 8a c3 36 5a d0 89 d4 69 e2 51 23 91 1a |.....6Z...i.Q#..| 9c 12 e8 90 a2 eb 8a 52 72 34 bc 06 5a 04 62 be |.......Rr4..Z.b.| 9e 00 7c 9f 76 49 18 48 c5 25 4b af 4c 7d a3 dc |..|.vI.H.%K.L}..| 9c 29 1a 84 fe cb 38 b1 87 02 1c 9a 4a 34 18 75 |.)....8.....J4.u| c4 c7 ff 78 1f b9 f3 8f ce 26 7b 71 e5 3d 23 d7 |...x.....&{q.=#.| dc ee 75 66 97 eb 57 59 1d cf 2a 94 a2 94 4d 76 |..uf..WY..*...Mv| bf 68 5a 44 87 6a e5 c7 5b b1 cb a0 89 e4 17 e1 |.hZD.j..[.......| 57 6e e7 20 0f af 2d c6 c1 d5 17 55 68 a8 d7 78 |Wn. ..-....Uh..x| 55 b3 fd 0c 3c 0b 54 04 99 1f 11 e4 01 1a e3 1b |U...<.T.........| 14 e1 d1 2d 2b 42 ed 00 fe ec e1 cc 9c 58 95 90 |...-+B.......X..| 86 bf b9 42 58 95 ee 0f 84 21 81 2c 07 9f 2f a0 |...BX....!.,../.| d6 66 85 29 6a 60 fd 07 b6 c7 0b c5 80 70 74 96 |.f.)j`.......pt.| 12 c2 7f df 2b d6 69 21 9b 15 4f 86 f1 be 37 a4 |....+.i!..O...7.| 47 91 75 b0 5d 06 35 75 87 3f e5 42 80 91 fa e0 |G.u.].5u.?.B....| 7c 07 a3 fd 56 98 fa 1e 2d 05 ||...V...-. | |
208 | 0 | 35 ec 0e f9 a8 57 11 95 7a 2d 5d a5 e6 22 27 b0 |5....W..z-].."'.| 2f 97 94 1c 8d ba 01 37 e4 10 0b cc e2 3c 4d 15 |/......7..... |
288 | 0 | 9b f3 96 5f 4a 6c 3f 13 d2 34 ee 5f 47 1d cb 3e |..._Jl?..4._G..>| f4 da 78 b2 71 b2 f7 ae 13 27 5f 1c 65 07 d4 5c |..x.q....'_.e..\| e6 db b9 90 1d 2b bb 34 4b 84 4d e5 ab f7 1f 04 |.....+.4K.M.....| c5 fa 7f 92 6d 76 85 d7 72 f0 6b a9 9d 98 05 23 |....mv..r.k....#| 37 1a a7 79 68 95 fd 5d c7 5a 64 42 69 89 eb 26 |7..yh..].ZdBi..&| ef 0c a0 ff 82 88 d6 64 a1 29 00 a6 c5 50 64 c0 |.......d.)...Pd.| 30 9c e9 4d 6b d9 6b 8d 16 83 d0 b9 6b f7 71 6a |0..Mk.k.....k.qj| 90 59 36 20 95 07 55 c7 98 fc e1 62 11 47 56 b4 |.Y6 ..U....b.GV.| 4f aa db 92 8f fe ee 3c ef 25 d3 36 e6 34 |O......<.%.6.4 | |
304 | 0 | 꽭㖅㭐冯Ḳ릠⯔묳ᴒµꙨ랰ર﮶嗤缉髧斔龪昸ﮎ컰莟畻쮳耾伺婵籦⎁隶뎎閛瀻쫓ሥ쁁軮鈢Ʌ举흦돡ⱗ宅柭喟팲妈ぶ猪죥骒齂沁檓哭엨ᓹ⯢矧曄梆ᯭ팕韺ᩰ謖줅獰憛⸸⟓욟Ɵ囡䤦麯㵛䘓ൈ聪撔㹱倪铐❛眮䃌ࠞ‚鵰䭉蝴볠績펖႕긦䪏髻钁䩞앃ꏪ讹䰹촕愎﹚廰봟Ꝭ뫟냍☻淂類ⴹ睈㊒鑼Ⰻꃰ峥뎒昫粕幤葖ߑ䔩ꆚⴺ⠂辦쨫胲먦턧ⷩꄧὅ氕㺙鬏ꉻႻ肴⟡孹ⰽᏵ헵ᢞ퀅ꡔ峛䄑汚뒧⨛簝ꤣힼᔻ臅傾臁舠籧ե쀴Ⅶ叄䄜᪤둚㨦嶰껀 |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.DLL | LoadLibraryA | ||
KERNEL32.DLL | GetProcAddress | ||
KERNEL32.DLL | VirtualProtect | ||
KERNEL32.DLL | VirtualAlloc | ||
KERNEL32.DLL | VirtualFree | ||
advapi32.dll | RegCloseKey | ||
comctl32.dll | PropertySheetW | ||
GDI32.dll | BitBlt | ||
msacm32.dll | acmStreamOpen | ||
ole32.dll | CoInitialize | ||
shell32.dll | SHGetMalloc | ||
user32.dll | GetDC | ||
winmm.dll | mmioRead | ||
ws2_32.dll | send |
ord | entry_va | function_name | |
---|---|---|---|
1 | 0x46b0 | RGSSAddRTPPath | |
2 | 0x3690 | RGSSAudioFinalize | |
3 | 0x35f0 | RGSSAudioInitialize | |
4 | 0x46d0 | RGSSClearRTPPath | |
5 | 0x40d0 | RGSSErrorMessage | |
6 | 0x40b0 | RGSSErrorType | |
7 | 0x3740 | RGSSEval | |
8 | 0x35e0 | RGSSFinalize | |
9 | 0x4700 | RGSSGC | |
10 | 0x36e0 | RGSSGameMain | |
11 | 0x3770 | RGSSGetBool | |
12 | 0x3820 | RGSSGetDouble | |
13 | 0x37a0 | RGSSGetInt | |
14 | 0x4100 | RGSSGetPathWithRTP | |
15 | 0x4690 | RGSSGetRTPPath | |
16 | 0x39e0 | RGSSGetStringACP | |
17 | 0x3b50 | RGSSGetStringUTF16 | |
18 | 0x3990 | RGSSGetStringUTF8 | |
19 | 0x3930 | RGSSGetSymbol | |
20 | 0x3890 | RGSSGetTable | |
21 | 0x35c0 | RGSSInitialize3 | |
22 | 0x3c70 | RGSSSetString | |
23 | 0x3dd0 | RGSSSetStringACP | |
24 | 0x3f70 | RGSSSetStringUTF16 | |
25 | 0x3d20 | RGSSSetStringUTF8 | |
26 | 0x46e0 | RGSSSetupFonts | |
27 | 0x4230 | RGSSSetupRTP |
StringTable 040904b0
FileDescription | RGSS3 Core |
FileVersion | 3, 0, 0, 1 |
LegalCopyright | Copyright (C) 2011 Enterbrain, Inc. / Yoji Ojima |
ProductName | Ruby Game Scripting System |
ProductVersion | 3, 0, 0, 1 |
VS_FIXEDFILEINFO
FileVersion | 3.0.0.1 |
ProductVersion | 3.0.0.1 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 2 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[!] string size(120352) > stringtable size(474). truncated to 472
[!] cannot convert "~awO\xBCcnr\xE2\xF3\xF93\xF9\v^\xFA"... to UTF-16
[!] string size(120938) > stringtable size(288). truncated to 286
[!] cannot convert "\x0E\xF9\xA8W\x11\x95z-]\xA5\xE6\"'\xB0/\x97"... to UTF-16
[!] string size(124726) > stringtable size(142). truncated to 140
[!] cannot convert "\x96_Jl?\x13\xD24\xEE_G\x1D\xCB>\xF4\xDA"... to UTF-16
[!] string size(15562) > stringtable size(418). truncated to 416