filename | castleattack2.exe | |
---|---|---|
size | 26833382 (0x19971e6) | |
md5 | b59a38ab3ed21e485ca458aaf535b659 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xe8 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x681a | 0x7000 | R-X CODE | |
.rdata | 0x8000 | 0x120a | 0x2000 | R-- IDATA | |
.data | 0xa000 | 0x453c | 0x3000 | RW- IDATA | |
.rsrc | 0xf000 | 0xd194 | 0xe000 | R-- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x8748 | 0x64 | |
RESOURCE | 0xf000 | 0xd194 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0x8000 | 0x1fc | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
id | lang | string |
---|---|---|
1000 | 1033 | Application Error |
1001 | 1033 | This application cannot start as it cannot create needed files. There may not be enough free disk space. |
1002 | 1033 | This application cannot run, as it could not find the shared library MSVCRT.DLL. |
1003 | 1033 | This application requires Shockwave Player 10, which is not installed. Click OK to download it. |
1004 | 1033 | This application cannot run. |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.dll | 494 | GlobalAlloc | |
KERNEL32.dll | 77 | CreateFileA | |
KERNEL32.dll | 941 | _lwrite | |
KERNEL32.dll | 936 | _lclose | |
KERNEL32.dll | 938 | _llseek | |
KERNEL32.dll | 939 | _lopen | |
KERNEL32.dll | 940 | _lread | |
KERNEL32.dll | 937 | _lcreat | |
KERNEL32.dll | 778 | SetErrorMode | |
KERNEL32.dll | 512 | GlobalUnlock | |
KERNEL32.dll | 505 | GlobalLock | |
KERNEL32.dll | 211 | FindNextFileA | |
KERNEL32.dll | 201 | FindFirstFileA | |
KERNEL32.dll | 698 | RemoveDirectoryA | |
KERNEL32.dll | 197 | FindClose | |
KERNEL32.dll | 124 | DeleteFileA | |
KERNEL32.dll | 459 | GetTempPathA | |
KERNEL32.dll | 546 | InterlockedIncrement | |
KERNEL32.dll | 542 | InterlockedDecrement | |
KERNEL32.dll | 437 | GetStringTypeW | |
KERNEL32.dll | 434 | GetStringTypeA | |
KERNEL32.dll | 571 | LCMapStringW | |
KERNEL32.dll | 570 | LCMapStringA | |
KERNEL32.dll | 619 | MultiByteToWideChar | |
KERNEL32.dll | 395 | GetOEMCP | |
KERNEL32.dll | 245 | GetACP | |
KERNEL32.dll | 252 | GetCPInfo | |
KERNEL32.dll | 784 | SetFilePointer | |
KERNEL32.dll | 229 | FlushFileBuffers | |
KERNEL32.dll | 812 | SetStdHandle | |
KERNEL32.dll | 528 | HeapReAlloc | |
KERNEL32.dll | 69 | CreateDirectoryA | |
KERNEL32.dll | 501 | GlobalFree | |
KERNEL32.dll | 479 | GetVersionExA | |
KERNEL32.dll | 314 | GetCurrentProcess | |
KERNEL32.dll | 361 | GetLastError | |
KERNEL32.dll | 439 | GetSystemDefaultLangID | |
KERNEL32.dll | 906 | WinExec | |
KERNEL32.dll | 584 | LoadLibraryA | |
KERNEL32.dll | 312 | GetCurrentDirectoryA | |
KERNEL32.dll | 441 | GetSystemDirectoryA | |
KERNEL32.dll | 375 | GetModuleHandleA | |
KERNEL32.dll | 767 | SetCurrentDirectoryA | |
KERNEL32.dll | 408 | GetProcAddress | |
KERNEL32.dll | 239 | FreeLibrary | |
KERNEL32.dll | 373 | GetModuleFileNameA | |
KERNEL32.dll | 105 | CreateThread | |
KERNEL32.dll | 46 | CloseHandle | |
KERNEL32.dll | 342 | GetFileAttributesA | |
KERNEL32.dll | 175 | ExitProcess | |
KERNEL32.dll | 849 | TerminateProcess | |
KERNEL32.dll | 431 | GetStartupInfoA | |
KERNEL32.dll | 264 | GetCommandLineA | |
KERNEL32.dll | 478 | GetVersion | |
KERNEL32.dll | 537 | InitializeCriticalSection | |
KERNEL32.dll | 122 | DeleteCriticalSection | |
KERNEL32.dll | 143 | EnterCriticalSection | |
KERNEL32.dll | 583 | LeaveCriticalSection | |
KERNEL32.dll | 524 | HeapFree | |
KERNEL32.dll | 866 | UnhandledExceptionFilter | |
KERNEL32.dll | 237 | FreeEnvironmentStringsA | |
KERNEL32.dll | 238 | FreeEnvironmentStringsW | |
KERNEL32.dll | 905 | WideCharToMultiByte | |
KERNEL32.dll | 333 | GetEnvironmentStrings | |
KERNEL32.dll | 335 | GetEnvironmentStringsW | |
KERNEL32.dll | 793 | SetHandleCount | |
KERNEL32.dll | 433 | GetStdHandle | |
KERNEL32.dll | 350 | GetFileType | |
KERNEL32.dll | 318 | GetCurrentThreadId | |
KERNEL32.dll | 857 | TlsSetValue | |
KERNEL32.dll | 854 | TlsAlloc | |
KERNEL32.dll | 797 | SetLastError | |
KERNEL32.dll | 856 | TlsGetValue | |
KERNEL32.dll | 336 | GetEnvironmentVariableA | |
KERNEL32.dll | 522 | HeapDestroy | |
KERNEL32.dll | 520 | HeapCreate | |
KERNEL32.dll | 888 | VirtualFree | |
KERNEL32.dll | 716 | RtlUnwind | |
KERNEL32.dll | 918 | WriteFile | |
KERNEL32.dll | 518 | HeapAlloc | |
KERNEL32.dll | 885 | VirtualAlloc | |
USER32.dll | 225 | ExitWindowsEx | |
USER32.dll | 458 | LoadStringA | |
USER32.dll | 478 | MessageBoxA | |
USER32.dll | 516 | PostThreadMessageA | |
USER32.dll | 447 | LoadImageA | |
USER32.dll | 2 | AdjustWindowRectEx | |
USER32.dll | 270 | GetDesktopWindow | |
USER32.dll | 372 | GetWindowRect | |
USER32.dll | 96 | CreateWindowExA | |
USER32.dll | 657 | ShowWindow | |
USER32.dll | 698 | UpdateWindow | |
USER32.dll | 441 | LoadCursorA | |
USER32.dll | 533 | RegisterClassA | |
USER32.dll | 314 | GetMessageA | |
USER32.dll | 153 | DestroyWindow | |
USER32.dll | 681 | TranslateMessage | |
USER32.dll | 161 | DispatchMessageA | |
USER32.dll | 13 | BeginPaint | |
USER32.dll | 200 | EndPaint | |
USER32.dll | 268 | GetDC | |
USER32.dll | 403 | InvalidateRect | |
USER32.dll | 553 | ReleaseDC | |
USER32.dll | 142 | DefWindowProcA | |
USER32.dll | 366 | GetWindowLongA | |
USER32.dll | 639 | SetWindowLongA | |
USER32.dll | 515 | PostQuitMessage | |
GDI32.dll | 405 | GetObjectA | |
GDI32.dll | 45 | CreateCompatibleDC | |
GDI32.dll | 526 | SelectObject | |
GDI32.dll | 18 | BitBlt | |
GDI32.dll | 140 | DeleteDC | |
GDI32.dll | 69 | CreatePalette | |
GDI32.dll | 527 | SelectPalette | |
GDI32.dll | 594 | UnrealizeObject | |
GDI32.dll | 499 | RealizePalette | |
GDI32.dll | 143 | DeleteObject | |
ADVAPI32.dll | 426 | OpenProcessToken | |
ADVAPI32.dll | 333 | LookupPrivilegeValueA | |
ADVAPI32.dll | 28 | AdjustTokenPrivileges | |
ADVAPI32.dll | 482 | RegOpenKeyExA | |
ADVAPI32.dll | 491 | RegQueryValueA | |
ADVAPI32.dll | 457 | RegCloseKey |
StringTable 040904b0
CompanyName | Macromedia, Inc. |
FileDescription | Macromedia Projector |
FileVersion | 10.1r11 |
InternalName | Projector |
LegalCopyright | Copyright © 1985-2004 Macromedia, Inc. |
LegalTrademarks | Director® is a registered trademark and Shockwave(tm) is a trademark of Macromedia, Inc. |
OriginalFilename | Projector.exe |
ProductName | Director MX 2004 |
ProductVersion | 10.1 |
StringTable 040904E4
CompanyName | Macromedia, Inc. |
FileDescription | Macromedia Projector |
FileVersion | 10.1r11 |
InternalName | Projector |
LegalCopyright | Copyright © 1985-2004 Macromedia, Inc. |
LegalTrademarks | Director® is a registered trademark and Shockwave(tm) is a trademark of Macromedia, Inc. |
OriginalFilename | Projector.exe |
ProductName | Director MX 2004 |
ProductVersion | 10.1 |
VS_FIXEDFILEINFO
FileVersion | 10.1.0.11 |
ProductVersion | 10.1.0.11 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 1 |
FileSubtype | 0 |
offset | size | type | comment | |
---|---|---|---|---|
0 | 110592 | EXE | 09/09/2004 06:46:18 | # |
15c1 | 15 | HTM | # | |
1b124 | 151552 | DLL | 09/09/2004 06:46:12 | # |
40124 | 1495040 | DLL | 09/09/2004 06:03:02 | # |
1ad124 | 630784 | DLL | 09/09/2004 05:52:28 | # |
247124 | 266240 | DLL | 12/04/1998 01:03:22 | # |
89dc8b | 223151 | JPG | # | |
8d6217 | 24514 | JPG | # | |
8dc877 | 1180 | JPG | # | |
8dd56b | 4796 | JPG | # | |
8e07ab | 19061 | JPG | # | |
8e68af | 38832 | JPG | # | |
8f22b1 | 1162 | JPG | # | |
8f30fb | 988 | JPG | # | |
8f45e3 | 1594 | JPG | # | |
8f95b3 | 1596 | JPG | # | |
908537 | 1870 | JPG | # | |
91afd1 | 1820 | JPG | # | |
91b709 | 1797 | JPG | # | |
91be24 | 1326 | JPG | # | |
91c367 | 782 | JPG | # | |
920087 | 31708 | JPG | # | |
9311d3 | 1497 | JPG | # | |
93e943 | 1822 | JPG | # | |
93f077 | 1597 | JPG | # | |
93f6c7 | 1759 | JPG | # | |
942ba7 | 643 | JPG | # | |
945cff | 1257 | JPG | # | |
946713 | 940 | JPG | # | |
9482db | 1180 | JPG | # | |
94cd2f | 3429 | JPG | # | |
951aef | 1705 | JPG | # | |
953ac5 | 4833 | JPG | # | |
9557b1 | 4833 | JPG | # | |
9579a5 | 4833 | JPG | # | |
959b91 | 4833 | JPG | # | |
95b859 | 4833 | JPG | # | |
95d551 | 4833 | JPG | # | |
95f21d | 4833 | JPG | # | |
960e91 | 4833 | JPG | # | |
962b15 | 4833 | JPG | # | |
964ad9 | 4833 | JPG | # | |
96ff85 | 3217 | JPG | # | |
978c82 | 895 | JPG | # | |
97e6bd | 1197 | JPG | # | |
98a82f | 1893 | JPG | # | |
98fd03 | 782 | JPG | # | |
993ff5 | 158104 | JPG | # | |
9c7ceb | 38832 | JPG | # | |
9d1b53 | 24514 | JPG | # | |
9d881b | 38832 | JPG | # | |
9ee2cb | 1690 | JPG | # | |
9f34b3 | 782 | JPG | # | |
9f5ccf | 1180 | JPG | # | |
9fc5e7 | 14781 | JPG | # | |
a01743 | 14781 | JPG | # | |
a07b83 | 14781 | JPG | # | |
a0f3e3 | 1180 | JPG | # | |
a10be7 | 14781 | JPG | # | |
a18f5d | 738 | JPG | # | |
a19e21 | 745 | JPG | # | |
a1acdd | 741 | JPG | # | |
a1afc2 | 16237092 | BIN | overlay data past EOF | # |
Scanning the drive for archives: 1 file, 26833382 bytes (26 MiB) Errors: 1
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK