Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Full Information Dump:
- Number of Sections: 9
- Section Name Entropy Flags
- -----------------------------------------------------------------
- .data 1.835 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- D7Y[ ot 7.8178 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .edata 0.21075 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .text0 5.6881 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .rdata 3.1149 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .bss 0.0 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .idata 5.2289 IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- .rsrc 2.7137 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
- .reloc 5.1716 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
- ----------Parsing Warnings----------
- Suspicious flags set for section 3. Both IMAGE_SCN_MEM_WRITE and IMAGE_SCN_MEM_EXECUTE are set. This might indicate a packed executable.
- ----------DOS_HEADER----------
- [IMAGE_DOS_HEADER]
- 0x0 0x0 e_magic: 0x5A4D
- 0x2 0x2 e_cblp: 0x90
- 0x4 0x4 e_cp: 0x3
- 0x6 0x6 e_crlc: 0x0
- 0x8 0x8 e_cparhdr: 0x4
- 0xA 0xA e_minalloc: 0x0
- 0xC 0xC e_maxalloc: 0xFFFF
- 0xE 0xE e_ss: 0x0
- 0x10 0x10 e_sp: 0xB8
- 0x12 0x12 e_csum: 0x0
- 0x14 0x14 e_ip: 0x0
- 0x16 0x16 e_cs: 0x0
- 0x18 0x18 e_lfarlc: 0x40
- 0x1A 0x1A e_ovno: 0x0
- 0x1C 0x1C e_res:
- 0x24 0x24 e_oemid: 0x0
- 0x26 0x26 e_oeminfo: 0x0
- 0x28 0x28 e_res2:
- 0x3C 0x3C e_lfanew: 0x80
- ----------NT_HEADERS----------
- [IMAGE_NT_HEADERS]
- 0x80 0x0 Signature: 0x4550
- ----------FILE_HEADER----------
- [IMAGE_FILE_HEADER]
- 0x84 0x0 Machine: 0x14C
- 0x86 0x2 NumberOfSections: 0x9
- 0x88 0x4 TimeDateStamp: 0x1000 [Thu Jan 1 01:08:16 1970 UTC]
- 0x8C 0x8 PointerToSymbolTable: 0x20400
- 0x90 0xC NumberOfSymbols: 0x8A6
- 0x94 0x10 SizeOfOptionalHeader: 0xE0
- 0x96 0x12 Characteristics: 0x306
- Flags: IMAGE_FILE_32BIT_MACHINE, IMAGE_FILE_EXECUTABLE_IMAGE, IMAGE_FILE_DEBUG_STRIPPED, IMAGE_FILE_LINE_NUMS_STRIPPED
- ----------OPTIONAL_HEADER----------
- [IMAGE_OPTIONAL_HEADER]
- 0x98 0x0 Magic: 0x10B
- 0x9A 0x2 MajorLinkerVersion: 0x2
- 0x9B 0x3 MinorLinkerVersion: 0x11
- 0x9C 0x4 SizeOfCode: 0xC800
- 0xA0 0x8 SizeOfInitializedData: 0xA700
- 0xA4 0xC SizeOfUninitializedData: 0x1A00
- 0xA8 0x10 AddressOfEntryPoint: 0x201E0
- 0xAC 0x14 BaseOfCode: 0x0
- 0xB0 0x18 BaseOfData: 0x800
- 0xB4 0x1C ImageBase: 0x1000000
- 0xB8 0x20 SectionAlignment: 0x1000
- 0xBC 0x24 FileAlignment: 0x200
- 0xC0 0x28 MajorOperatingSystemVersion: 0x4
- 0xC2 0x2A MinorOperatingSystemVersion: 0x1
- 0xC4 0x2C MajorImageVersion: 0x1
- 0xC6 0x2E MinorImageVersion: 0x0
- 0xC8 0x30 MajorSubsystemVersion: 0x4
- 0xCA 0x32 MinorSubsystemVersion: 0x0
- 0xCC 0x34 Reserved1: 0x0
- 0xD0 0x38 SizeOfImage: 0x28000
- 0xD4 0x3C SizeOfHeaders: 0x400
- 0xD8 0x40 CheckSum: 0x2D217
- 0xDC 0x44 Subsystem: 0x3
- 0xDE 0x46 DllCharacteristics: 0x40
- 0xE0 0x48 SizeOfStackReserve: 0x200000
- 0xE4 0x4C SizeOfStackCommit: 0x1000
- 0xE8 0x50 SizeOfHeapReserve: 0x100000
- 0xEC 0x54 SizeOfHeapCommit: 0x1000
- 0xF0 0x58 LoaderFlags: 0x0
- 0xF4 0x5C NumberOfRvaAndSizes: 0x10
- DllCharacteristics: IMAGE_DLL_CHARACTERISTICS_DYNAMIC_BASE
- ----------PE Sections----------
- [IMAGE_SECTION_HEADER]
- 0x178 0x0 Name: .data
- 0x180 0x8 Misc: 0xF44
- 0x180 0x8 Misc_PhysicalAddress: 0xF44
- 0x180 0x8 Misc_VirtualSize: 0xF44
- 0x184 0xC VirtualAddress: 0x1000
- 0x188 0x10 SizeOfRawData: 0x1000
- 0x18C 0x14 PointerToRawData: 0x400
- 0x190 0x18 PointerToRelocations: 0x0
- 0x194 0x1C PointerToLinenumbers: 0x0
- 0x198 0x20 NumberOfRelocations: 0x0
- 0x19A 0x22 NumberOfLinenumbers: 0x0
- 0x19C 0x24 Characteristics: 0xC0300040
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 1.834969 (Min=0.0, Max=8.0)
- MD5 hash: ed56489e5e5994ca52dbe704bde1751b
- SHA-1 hash: 7226698eb59de3cb3834b7cc25812730f1b8d733
- SHA-256 hash: baec776d73d4eebb520d3269d603d65308fd127f6bdf5a33ac4323d20bd1900d
- SHA-512 hash: 902b74939dd4391dd74cebff3acc05eaba031689c434d2d4ac81f92b8fbabd759b855c48e902706a5d54d91f9cb60dd897ec0e0705957fd181654d55231f5905
- [IMAGE_SECTION_HEADER]
- 0x1A0 0x0 Name: D7Y[ ot
- 0x1A8 0x8 Misc: 0x105F4
- 0x1A8 0x8 Misc_PhysicalAddress: 0x105F4
- 0x1A8 0x8 Misc_VirtualSize: 0x105F4
- 0x1AC 0xC VirtualAddress: 0x2000
- 0x1B0 0x10 SizeOfRawData: 0x10600
- 0x1B4 0x14 PointerToRawData: 0x1400
- 0x1B8 0x18 PointerToRelocations: 0x0
- 0x1BC 0x1C PointerToLinenumbers: 0x0
- 0x1C0 0x20 NumberOfRelocations: 0x0
- 0x1C2 0x22 NumberOfLinenumbers: 0x0
- 0x1C4 0x24 Characteristics: 0xC0300040
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 7.817829 (Min=0.0, Max=8.0)
- MD5 hash: b4f1f7b9802963bbbaaae1cb613392c0
- SHA-1 hash: faf4ad86b92601ac75822b1ff42a309fba0a69a9
- SHA-256 hash: 8b94c7e945b8f25fbcc991f6e4ff943799427cd5c8cf0c994738647772490b19
- SHA-512 hash: de5cc12a5cb09c758fce15c66992832598cc3bbc8b345755aa1e53947f055892e2e462a7df32d1b63b3bcd2f5fbfe08f9a17338ac8712671a1faadf655b47978
- [IMAGE_SECTION_HEADER]
- 0x1C8 0x0 Name: .edata
- 0x1D0 0x8 Misc: 0x37
- 0x1D0 0x8 Misc_PhysicalAddress: 0x37
- 0x1D0 0x8 Misc_VirtualSize: 0x37
- 0x1D4 0xC VirtualAddress: 0x13000
- 0x1D8 0x10 SizeOfRawData: 0x200
- 0x1DC 0x14 PointerToRawData: 0x11A00
- 0x1E0 0x18 PointerToRelocations: 0x0
- 0x1E4 0x1C PointerToLinenumbers: 0x0
- 0x1E8 0x20 NumberOfRelocations: 0x0
- 0x1EA 0x22 NumberOfLinenumbers: 0x0
- 0x1EC 0x24 Characteristics: 0x40300040
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 0.210752 (Min=0.0, Max=8.0)
- MD5 hash: 2444d19c5833103c9dc0de21add28ed7
- SHA-1 hash: f15439d482144a34d19f916294aa960a3966a347
- SHA-256 hash: cada61ddaf3816c0185f56539e67e075570a5057a3c1969758e6e065fa8e814f
- SHA-512 hash: 9639d40c21c8097325722bad85ff640c4b330d471f03f905155efaa81c6f4a7d5cbb6aea03e69e3eee5527cfb3c2401483ac4c23af4b8360447105e15094ef3f
- [IMAGE_SECTION_HEADER]
- 0x1F0 0x0 Name: .text0
- 0x1F8 0x8 Misc: 0xC614
- 0x1F8 0x8 Misc_PhysicalAddress: 0xC614
- 0x1F8 0x8 Misc_VirtualSize: 0xC614
- 0x1FC 0xC VirtualAddress: 0x14000
- 0x200 0x10 SizeOfRawData: 0xC800
- 0x204 0x14 PointerToRawData: 0x11C00
- 0x208 0x18 PointerToRelocations: 0x0
- 0x20C 0x1C PointerToLinenumbers: 0x0
- 0x210 0x20 NumberOfRelocations: 0x0
- 0x212 0x22 NumberOfLinenumbers: 0x0
- 0x214 0x24 Characteristics: 0xE0500020
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 5.688115 (Min=0.0, Max=8.0)
- MD5 hash: a28815b25cb2e693c08260d08788598e
- SHA-1 hash: 9d47fb032a2984a9981f96b6ceee4adaeff5d4ea
- SHA-256 hash: b575c0e754a2733018f59bc788deda8ce199091e8743eb9f2468e0bfeb04b963
- SHA-512 hash: 1d82c80c3bf405069a681b25e7209dfdc11ab532d5b9875fb575810d5b8f396cd87f92fbc3d92ce2b70c8bb90a370863fae195f863e2f19c52bac733f86d1cba
- [IMAGE_SECTION_HEADER]
- 0x218 0x0 Name: .rdata
- 0x220 0x8 Misc: 0xFA
- 0x220 0x8 Misc_PhysicalAddress: 0xFA
- 0x220 0x8 Misc_VirtualSize: 0xFA
- 0x224 0xC VirtualAddress: 0x21000
- 0x228 0x10 SizeOfRawData: 0x200
- 0x22C 0x14 PointerToRawData: 0x1E400
- 0x230 0x18 PointerToRelocations: 0x0
- 0x234 0x1C PointerToLinenumbers: 0x0
- 0x238 0x20 NumberOfRelocations: 0x0
- 0x23A 0x22 NumberOfLinenumbers: 0x0
- 0x23C 0x24 Characteristics: 0x40300040
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 3.114937 (Min=0.0, Max=8.0)
- MD5 hash: 2e991c9e26904cbc089cb76dd7e551f3
- SHA-1 hash: 25eb20781f7170dfe426a90f15b686f842856a05
- SHA-256 hash: 4cecb09ab36686844364b1b1fce57efe36bae188aa0819582443303d40a4ad05
- SHA-512 hash: dfabeb802e3b1f2375414be28997f4718f080befc3b7c2fdb907ed98bd8cb685cfe59bfddb9ecd6d127da188044d8900586f3d48d11b94d649572caef96b62a8
- [IMAGE_SECTION_HEADER]
- 0x240 0x0 Name: .bss
- 0x248 0x8 Misc: 0x18A8
- 0x248 0x8 Misc_PhysicalAddress: 0x18A8
- 0x248 0x8 Misc_VirtualSize: 0x18A8
- 0x24C 0xC VirtualAddress: 0x22000
- 0x250 0x10 SizeOfRawData: 0x0
- 0x254 0x14 PointerToRawData: 0x1E600
- 0x258 0x18 PointerToRelocations: 0x0
- 0x25C 0x1C PointerToLinenumbers: 0x0
- 0x260 0x20 NumberOfRelocations: 0x0
- 0x262 0x22 NumberOfLinenumbers: 0x0
- 0x264 0x24 Characteristics: 0xC0300080
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 0.000000 (Min=0.0, Max=8.0)
- MD5 hash: d41d8cd98f00b204e9800998ecf8427e
- SHA-1 hash: da39a3ee5e6b4b0d3255bfef95601890afd80709
- SHA-256 hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
- SHA-512 hash: cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e
- [IMAGE_SECTION_HEADER]
- 0x268 0x0 Name: .idata
- 0x270 0x8 Misc: 0x18D8
- 0x270 0x8 Misc_PhysicalAddress: 0x18D8
- 0x270 0x8 Misc_VirtualSize: 0x18D8
- 0x274 0xC VirtualAddress: 0x24000
- 0x278 0x10 SizeOfRawData: 0x1A00
- 0x27C 0x14 PointerToRawData: 0x1E600
- 0x280 0x18 PointerToRelocations: 0x0
- 0x284 0x1C PointerToLinenumbers: 0x0
- 0x288 0x20 NumberOfRelocations: 0x0
- 0x28A 0x22 NumberOfLinenumbers: 0x0
- 0x28C 0x24 Characteristics: 0xC0300042
- Flags: IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_MEM_READ
- Entropy: 5.228930 (Min=0.0, Max=8.0)
- MD5 hash: e87a9043b4e80b1354f5eb095ae36399
- SHA-1 hash: 969ef892237588d7e297bc0875011edd927f7485
- SHA-256 hash: fdfe9455ca250200c10980ed8b5184a5ad169fb6a6d981823d058f8e08d1164f
- SHA-512 hash: 49340a70fba4ae1c7d69160acd9835573e9ce4528157fce1af8f77c900fb02237b310b97553c0709beae2313c0e05e8dfefec82ad066b774954003d320d99e46
- [IMAGE_SECTION_HEADER]
- 0x290 0x0 Name: .rsrc
- 0x298 0x8 Misc: 0x1000
- 0x298 0x8 Misc_PhysicalAddress: 0x1000
- 0x298 0x8 Misc_VirtualSize: 0x1000
- 0x29C 0xC VirtualAddress: 0x26000
- 0x2A0 0x10 SizeOfRawData: 0x600
- 0x2A4 0x14 PointerToRawData: 0x20000
- 0x2A8 0x18 PointerToRelocations: 0x0
- 0x2AC 0x1C PointerToLinenumbers: 0x0
- 0x2B0 0x20 NumberOfRelocations: 0x0
- 0x2B2 0x22 NumberOfLinenumbers: 0x0
- 0x2B4 0x24 Characteristics: 0x40000042
- Flags: IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
- Entropy: 2.713739 (Min=0.0, Max=8.0)
- MD5 hash: d622f861a82170e86284e08272f63b75
- SHA-1 hash: b41122a4784846ae783da4ada5a9c31466a59847
- SHA-256 hash: 88245aa475a2ca2b52dd4815775a4e05fb4cd7e44f2b68196cc20e32c89e1187
- SHA-512 hash: 4ad8119cae584acc568469dc0bb8c28438e9a5d2d1b485766c96373d39e6c48e24d73d542fe325179b83c4afe5706f4353bb25d73d94f0c76447b6b925cfd73f
- [IMAGE_SECTION_HEADER]
- 0x2B8 0x0 Name: .reloc
- 0x2C0 0x8 Misc: 0xFFE
- 0x2C0 0x8 Misc_PhysicalAddress: 0xFFE
- 0x2C0 0x8 Misc_VirtualSize: 0xFFE
- 0x2C4 0xC VirtualAddress: 0x27000
- 0x2C8 0x10 SizeOfRawData: 0x400
- 0x2CC 0x14 PointerToRawData: 0x20600
- 0x2D0 0x18 PointerToRelocations: 0x0
- 0x2D4 0x1C PointerToLinenumbers: 0x0
- 0x2D8 0x20 NumberOfRelocations: 0x0
- 0x2DA 0x22 NumberOfLinenumbers: 0x0
- 0x2DC 0x24 Characteristics: 0x42000041
- Flags: IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
- Entropy: 5.171587 (Min=0.0, Max=8.0)
- MD5 hash: 88903a441091f5b4b035277f4202bcaa
- SHA-1 hash: f53c7c7ea6c768b3a5c5377bf99ebf6f0570b4c2
- SHA-256 hash: 5e6770b17a67fc55eb690c8c2cfddcb013d1d36076c42705f4358d1a1c0ec963
- SHA-512 hash: 1c82c856989c05788d09e68b4df6ebe769f7890f1c18b99e4b34a0ca0aba67e4e8fd535536c1f5e004a0995430830df555119bce68890d1803ee6523e96a649b
- ----------Directories----------
- [IMAGE_DIRECTORY_ENTRY_EXPORT]
- 0xF8 0x0 VirtualAddress: 0x0
- 0xFC 0x4 Size: 0x1
- [IMAGE_DIRECTORY_ENTRY_IMPORT]
- 0x100 0x0 VirtualAddress: 0x2E0
- 0x104 0x4 Size: 0x104
- [IMAGE_DIRECTORY_ENTRY_RESOURCE]
- 0x108 0x0 VirtualAddress: 0x26000
- 0x10C 0x4 Size: 0x422
- [IMAGE_DIRECTORY_ENTRY_EXCEPTION]
- 0x110 0x0 VirtualAddress: 0x0
- 0x114 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_SECURITY]
- 0x118 0x0 VirtualAddress: 0x0
- 0x11C 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_BASERELOC]
- 0x120 0x0 VirtualAddress: 0x27000
- 0x124 0x4 Size: 0x2E8
- [IMAGE_DIRECTORY_ENTRY_DEBUG]
- 0x128 0x0 VirtualAddress: 0x0
- 0x12C 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_COPYRIGHT]
- 0x130 0x0 VirtualAddress: 0x0
- 0x134 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_GLOBALPTR]
- 0x138 0x0 VirtualAddress: 0x0
- 0x13C 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_TLS]
- 0x140 0x0 VirtualAddress: 0x0
- 0x144 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG]
- 0x148 0x0 VirtualAddress: 0x0
- 0x14C 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT]
- 0x150 0x0 VirtualAddress: 0x0
- 0x154 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_IAT]
- 0x158 0x0 VirtualAddress: 0x24458
- 0x15C 0x4 Size: 0x112F
- [IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT]
- 0x160 0x0 VirtualAddress: 0x0
- 0x164 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR]
- 0x168 0x0 VirtualAddress: 0x0
- 0x16C 0x4 Size: 0x0
- [IMAGE_DIRECTORY_ENTRY_RESERVED]
- 0x170 0x0 VirtualAddress: 0x0
- 0x174 0x4 Size: 0x0
- ----------Version Information----------
- [VS_VERSIONINFO]
- 0x20090 0x0 Length: 0x32C
- 0x20092 0x2 ValueLength: 0x34
- 0x20094 0x4 Type: 0x0
- [VS_FIXEDFILEINFO]
- 0x200B8 0x0 Signature: 0xFEEF04BD
- 0x200BC 0x4 StrucVersion: 0x10000
- 0x200C0 0x8 FileVersionMS: 0x10001
- 0x200C4 0xC FileVersionLS: 0x0
- 0x200C8 0x10 ProductVersionMS: 0x10001
- 0x200CC 0x14 ProductVersionLS: 0x0
- 0x200D0 0x18 FileFlagsMask: 0x17
- 0x200D4 0x1C FileFlags: 0x0
- 0x200D8 0x20 FileOS: 0x4
- 0x200DC 0x24 FileType: 0x2
- 0x200E0 0x28 FileSubtype: 0x0
- 0x200E4 0x2C FileDateMS: 0x0
- 0x200E8 0x30 FileDateLS: 0x0
- [StringFileInfo]
- 0x200EC 0x0 Length: 0x28A
- 0x200EE 0x2 ValueLength: 0x0
- 0x200F0 0x4 Type: 0x1
- [StringTable]
- 0x20110 0x0 Length: 0x266
- 0x20112 0x2 ValueLength: 0x0
- 0x20114 0x4 Type: 0x1
- LangID: 041104b0
- LegalCopyright: Copyright (C) 2009 KONICA MINOLTA, INC.
- InternalName: KMDrvAPI
- FileVersion: 1, 1, 0, 0
- CompanyName: KONICA MINOLTA, INC.
- ProductName: KMDrvAPI
- ProductVersion: 1, 1, 0, 0
- FileDescription: Printer Driver API Common Interface
- OriginalFilename: KMDrvAPI.dll
- [VarFileInfo]
- 0x20378 0x0 Length: 0x44
- 0x2037A 0x2 ValueLength: 0x0
- 0x2037C 0x4 Type: 0x1
- [Var]
- 0x20398 0x0 Length: 0x24
- 0x2039A 0x2 ValueLength: 0x4
- 0x2039C 0x4 Type: 0x0
- Translation: 0x0411 0x04b0
- ----------Imported symbols----------
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x2E0 0x0 OriginalFirstThunk: 0x24314
- 0x2E0 0x0 Characteristics: 0x24314
- 0x2E4 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x2E8 0x8 ForwarderChain: 0x0
- 0x2EC 0xC Name: 0x257E8
- 0x2F0 0x10 FirstThunk: 0x24654
- ntdll.dll.atol Hint[1969]
- ntdll.dll.isalpha Hint[1976]
- ntdll.dll.isdigit Hint[1978]
- ntdll.dll.isgraph Hint[1979]
- ntdll.dll.isspace Hint[1983]
- ntdll.dll.iswdigit Hint[1987]
- ntdll.dll.labs Hint[1992]
- ntdll.dll.qsort Hint[2003]
- ntdll.dll.sprintf Hint[2005]
- ntdll.dll.strcat Hint[2010]
- ntdll.dll.strcspn Hint[2016]
- ntdll.dll.strncmp Hint[2020]
- ntdll.dll.strspn Hint[2026]
- ntdll.dll.strtol Hint[2029]
- ntdll.dll.tolower Hint[2035]
- ntdll.dll.vsprintf Hint[2041]
- ntdll.dll.wcscmp Hint[2047]
- ntdll.dll.wcstombs Hint[2063]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x2F4 0x0 OriginalFirstThunk: 0x2437C
- 0x2F4 0x0 Characteristics: 0x2437C
- 0x2F8 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x2FC 0x8 ForwarderChain: 0x0
- 0x300 0xC Name: 0x2583C
- 0x304 0x10 FirstThunk: 0x246BC
- pdh.dll.PdhCalculateCounterFromRawValue Hint[13]
- pdh.dll.PdhEnumMachinesA Hint[26]
- pdh.dll.PdhEnumObjectsA Hint[34]
- pdh.dll.PdhGetDataSourceTimeRangeA Hint[48]
- pdh.dll.PdhGetRawCounterValue Hint[70]
- pdh.dll.PdhReadRawLogRecord Hint[90]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x308 0x0 OriginalFirstThunk: 0x24120
- 0x308 0x0 Characteristics: 0x24120
- 0x30C 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x310 0x8 ForwarderChain: 0x0
- 0x314 0xC Name: 0x25778
- 0x318 0x10 FirstThunk: 0x24460
- KERNEL32.dll.ActivateActCtx Hint[2]
- KERNEL32.dll.AddRefActCtx Hint[10]
- KERNEL32.dll.BackupWrite Hint[26]
- KERNEL32.dll.ClearCommError Hint[81]
- KERNEL32.dll.CompareFileTime Hint[97]
- KERNEL32.dll.CreateActCtxW Hint[122]
- KERNEL32.dll.CreateDirectoryExW Hint[128]
- KERNEL32.dll.CreateHardLinkA Hint[147]
- KERNEL32.dll.CreateHardLinkW Hint[150]
- KERNEL32.dll.CreateIoCompletionPort Hint[151]
- KERNEL32.dll.CreateMailslotA Hint[155]
- KERNEL32.dll.CreatePipe Hint[164]
- KERNEL32.dll.CreateSemaphoreW Hint[176]
- KERNEL32.dll.CreateToolhelp32Snapshot Hint[192]
- KERNEL32.dll.DeactivateActCtx Hint[199]
- KERNEL32.dll.DebugBreakProcess Hint[203]
- KERNEL32.dll.DeleteFileA Hint[214]
- KERNEL32.dll.DeleteFileW Hint[217]
- KERNEL32.dll.EncodePointer Hint[235]
- KERNEL32.dll.EncodeSystemPointer Hint[236]
- KERNEL32.dll.EnumCalendarInfoExW Hint[243]
- KERNEL32.dll.EnumResourceNamesA Hint[256]
- KERNEL32.dll.EnumSystemCodePagesA Hint[264]
- KERNEL32.dll.EnumSystemLanguageGroupsA Hint[268]
- KERNEL32.dll.EraseTape Hint[280]
- KERNEL32.dll.ExitThread Hint[283]
- KERNEL32.dll.FillConsoleOutputAttribute Hint[296]
- KERNEL32.dll.FindAtomW Hint[303]
- KERNEL32.dll.FindFirstFileExA Hint[309]
- KERNEL32.dll.FindFirstFileExW Hint[310]
- KERNEL32.dll.FindFirstVolumeMountPointA Hint[319]
- KERNEL32.dll.FindResourceExA Hint[334]
- KERNEL32.dll.FlushConsoleInputBuffer Hint[344]
- KERNEL32.dll.FoldStringA Hint[349]
- KERNEL32.dll.FreeConsole Hint[353]
- KERNEL32.dll.FreeEnvironmentStringsA Hint[354]
- KERNEL32.dll.GetAtomNameA Hint[368]
- KERNEL32.dll.GetCommProperties Hint[391]
- KERNEL32.dll.GetCompressedFileSizeA Hint[396]
- KERNEL32.dll.GetCompressedFileSizeW Hint[399]
- KERNEL32.dll.GetConsoleMode Hint[432]
- KERNEL32.dll.GetConsoleTitleA Hint[441]
- KERNEL32.dll.GetCurrentConsoleFont Hint[448]
- KERNEL32.dll.GetDefaultCommConfigW Hint[462]
- KERNEL32.dll.GetDevicePowerState Hint[463]
- KERNEL32.dll.GetDriveTypeW Hint[471]
- KERNEL32.dll.GetEnvironmentVariableW Hint[480]
- KERNEL32.dll.GetFileTime Hint[499]
- KERNEL32.dll.GetFileType Hint[500]
- KERNEL32.dll.GetLastError Hint[515]
- KERNEL32.dll.GetLongPathNameW Hint[527]
- KERNEL32.dll.GetModuleHandleExW Hint[535]
- KERNEL32.dll.GetModuleHandleW Hint[536]
- KERNEL32.dll.GetNumberOfConsoleMouseButtons Hint[566]
- KERNEL32.dll.GetOverlappedResult Hint[568]
- KERNEL32.dll.GetPrivateProfileIntA Hint[571]
- KERNEL32.dll.GetPrivateProfileSectionNamesA Hint[574]
- KERNEL32.dll.GetProcAddress Hint[581]
- KERNEL32.dll.GetProcessVersion Hint[596]
- KERNEL32.dll.GetProfileIntA Hint[602]
- KERNEL32.dll.GetProfileStringW Hint[607]
- KERNEL32.dll.GetShortPathNameA Hint[610]
- KERNEL32.dll.GetSystemDefaultLangID Hint[622]
- KERNEL32.dll.GetSystemDefaultUILanguage Hint[624]
- KERNEL32.dll.GetThreadIOPendingFlag Hint[652]
- KERNEL32.dll.GetTickCount Hint[663]
- KERNEL32.dll.GetUserDefaultUILanguage Hint[673]
- KERNEL32.dll.GetVersion Hint[677]
- KERNEL32.dll.GetVersionExW Hint[679]
- KERNEL32.dll.GlobalFlags Hint[701]
- KERNEL32.dll.GlobalSize Hint[711]
- KERNEL32.dll.HeapCreate Hint[722]
- KERNEL32.dll.InitAtomTable Hint[741]
- KERNEL32.dll.InterlockedDecrement Hint[755]
- KERNEL32.dll.IsBadHugeWritePtr Hint[766]
- KERNEL32.dll.IsDBCSLeadByteEx Hint[775]
- KERNEL32.dll.IsValidLocale Hint[788]
- KERNEL32.dll.LCMapStringA Hint[792]
- KERNEL32.dll.LeaveCriticalSection Hint[806]
- KERNEL32.dll.LoadLibraryExA Hint[810]
- KERNEL32.dll.LocalFree Hint[822]
- KERNEL32.dll.LocalUnlock Hint[828]
- KERNEL32.dll.Module32NextW Hint[843]
- KERNEL32.dll.MoveFileWithProgressA Hint[850]
- KERNEL32.dll.MoveFileWithProgressW Hint[851]
- KERNEL32.dll.OpenMutexW Hint[876]
- KERNEL32.dll.OpenThread Hint[883]
- KERNEL32.dll.Process32First Hint[897]
- KERNEL32.dll.QueryDepthSList Hint[906]
- KERNEL32.dll.QueryPerformanceCounter Hint[915]
- KERNEL32.dll.ReadConsoleA Hint[929]
- KERNEL32.dll.ReadConsoleOutputW Hint[938]
- KERNEL32.dll.ReadConsoleW Hint[939]
- KERNEL32.dll.RequestDeviceWakeup Hint[977]
- KERNEL32.dll.SearchPathA Hint[991]
- KERNEL32.dll.SetConsoleCtrlHandler Hint[1009]
- KERNEL32.dll.SetConsoleCursorPosition Hint[1013]
- KERNEL32.dll.SetConsoleTitleA Hint[1035]
- KERNEL32.dll.SetCriticalSectionSpinCount Hint[1038]
- KERNEL32.dll.SetEnvironmentVariableA Hint[1050]
- KERNEL32.dll.SetFileShortNameW Hint[1068]
- KERNEL32.dll.SetProcessShutdownParameters Hint[1094]
- KERNEL32.dll.SetSystemTime Hint[1103]
- KERNEL32.dll.SetTimerQueueTimer Hint[1126]
- KERNEL32.dll.SystemTimeToFileTime Hint[1151]
- KERNEL32.dll.TerminateThread Hint[1155]
- KERNEL32.dll.Thread32First Hint[1157]
- KERNEL32.dll.TlsSetValue Hint[1162]
- KERNEL32.dll.VerLanguageNameA Hint[1190]
- KERNEL32.dll.VerifyVersionInfoA Hint[1195]
- KERNEL32.dll.VirtualAllocEx Hint[1198]
- KERNEL32.dll.WaitForMultipleObjects Hint[1216]
- KERNEL32.dll.WaitNamedPipeA Hint[1224]
- KERNEL32.dll.WriteConsoleA Hint[1251]
- KERNEL32.dll.WriteConsoleOutputAttribute Hint[1257]
- KERNEL32.dll.WriteFile Hint[1262]
- KERNEL32.dll.WriteFileEx Hint[1263]
- KERNEL32.dll.WriteProfileStringW Hint[1277]
- KERNEL32.dll.WriteTapemark Hint[1278]
- KERNEL32.dll.lstrcmpW Hint[1293]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x31C 0x0 OriginalFirstThunk: 0x2440C
- 0x31C 0x0 Characteristics: 0x2440C
- 0x320 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x324 0x8 ForwarderChain: 0x0
- 0x328 0xC Name: 0x25490
- 0x32C 0x10 FirstThunk: 0x2474C
- msvcrt.dll.putchar Hint[1270]
- msvcrt.dll.wcsftime Hint[1367]
- msvcrt.dll.wctomb Hint[1390]
- msvcrt.dll.fscanf Hint[1194]
- msvcrt.dll.wscanf Hint[1394]
- msvcrt.dll.iswupper Hint[1235]
- msvcrt.dll.wprintf Hint[1392]
- msvcrt.dll.getwc Hint[1209]
- msvcrt.dll.iswascii Hint[1226]
- msvcrt.dll.rewind Hint[1282]
- msvcrt.dll.mbtowc Hint[1255]
- msvcrt.dll.abort Hint[1142]
- msvcrt.dll.localeconv Hint[1241]
- msvcrt.dll.realloc Hint[1279]
- msvcrt.dll.getenv Hint[1206]
- msvcrt.dll.iswgraph Hint[1230]
- msvcrt.dll.fputws Hint[1188]
- msvcrt.dll.fclose Hint[1170]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x330 0x0 OriginalFirstThunk: 0x243B4
- 0x330 0x0 Characteristics: 0x243B4
- 0x334 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x338 0x8 ForwarderChain: 0x0
- 0x33C 0xC Name: 0x2586C
- 0x340 0x10 FirstThunk: 0x246F4
- SHLWAPI.dll.wnsprintfW Hint[366]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x344 0x0 OriginalFirstThunk: 0x243D4
- 0x344 0x0 Characteristics: 0x243D4
- 0x348 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x34C 0x8 ForwarderChain: 0x0
- 0x350 0xC Name: 0x258CC
- 0x354 0x10 FirstThunk: 0x24714
- USER32.dll.AnimateWindow Hint[4]
- USER32.dll.CreateMDIWindowW Hint[88]
- USER32.dll.EnableWindow Hint[181]
- USER32.dll.GetLastActivePopup Hint[279]
- USER32.dll.GetWindowLongA Hint[346]
- USER32.dll.IsCharUpperW Hint[384]
- USER32.dll.IsWindowEnabled Hint[399]
- USER32.dll.MessageBeep Hint[437]
- USER32.dll.OpenInputDesktop Hint[463]
- USER32.dll.PtInRect Hint[478]
- USER32.dll.ReleaseDC Hint[498]
- USER32.dll.wsprintfA Hint[644]
- USER32.dll.wsprintfW Hint[645]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x358 0x0 OriginalFirstThunk: 0x24398
- 0x358 0x0 Characteristics: 0x24398
- 0x35C 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x360 0x8 ForwarderChain: 0x0
- 0x364 0xC Name: 0x2585C
- 0x368 0x10 FirstThunk: 0x246D8
- SHELL32.dll.DragAcceptFiles Hint[26]
- SHELL32.dll.DragQueryFileW Hint[31]
- SHELL32.dll.DragQueryPoint Hint[32]
- SHELL32.dll.ExtractAssociatedIconExW Hint[37]
- SHELL32.dll.SHGetFileInfoW Hint[192]
- SHELL32.dll.Shell_NotifyIconW Hint[318]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x36C 0x0 OriginalFirstThunk: 0x243BC
- 0x36C 0x0 Characteristics: 0x243BC
- 0x370 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x374 0x8 ForwarderChain: 0x0
- 0x378 0xC Name: 0x2588C
- 0x37C 0x10 FirstThunk: 0x246FC
- urlmon.dll.CoInternetCombineUrl Hint[10]
- urlmon.dll.CoInternetParseUrl Hint[25]
- urlmon.dll.FaultInIEFeature Hint[44]
- urlmon.dll.GetClassURL Hint[50]
- urlmon.dll.URLDownloadToFileA Hint[100]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x380 0x0 OriginalFirstThunk: 0x24360
- 0x380 0x0 Characteristics: 0x24360
- 0x384 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x388 0x8 ForwarderChain: 0x0
- 0x38C 0xC Name: 0x257F8
- 0x390 0x10 FirstThunk: 0x246A0
- ole32.dll.GetErrorInfo Hint[149]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x394 0x0 OriginalFirstThunk: 0x24368
- 0x394 0x0 Characteristics: 0x24368
- 0x398 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x39C 0x8 ForwarderChain: 0x0
- 0x3A0 0xC Name: 0x25814
- 0x3A4 0x10 FirstThunk: 0x246A8
- OLEAUT32.dll.VarCyFromI1 Hint[171]
- OLEAUT32.dll.VarR4FromDec Hint[316]
- OLEAUT32.dll.VarUI1FromCy Hint[349]
- OLEAUT32.dll.VarUI2FromI4 Hint[370]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x3A8 0x0 OriginalFirstThunk: 0x24118
- 0x3A8 0x0 Characteristics: 0x24118
- 0x3AC 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x3B0 0x8 ForwarderChain: 0x0
- 0x3B4 0xC Name: 0x2558C
- 0x3B8 0x10 FirstThunk: 0x24458
- GDI32.dll.SaveDC Hint[298]
- [IMAGE_IMPORT_DESCRIPTOR]
- 0x3BC 0x0 OriginalFirstThunk: 0x24304
- 0x3BC 0x0 Characteristics: 0x24304
- 0x3C0 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x3C4 0x8 ForwarderChain: 0x0
- 0x3C8 0xC Name: 0x25794
- 0x3CC 0x10 FirstThunk: 0x24644
- MPRAPI.dll.MprAdminMIBBufferFree Hint[34]
- MPRAPI.dll.MprAdminMIBEntryGet Hint[37]
- MPRAPI.dll.MprInfoRemoveAll Hint[114]
- ----------Resource directory----------
- [IMAGE_RESOURCE_DIRECTORY]
- 0x20000 0x0 Characteristics: 0x0
- 0x20004 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x20008 0x8 MajorVersion: 0x4
- 0x2000A 0xA MinorVersion: 0x0
- 0x2000C 0xC NumberOfNamedEntries: 0x0
- 0x2000E 0xE NumberOfIdEntries: 0x2
- Id: [0x10] (RT_VERSION)
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20010 0x0 Name: 0x10
- 0x20014 0x4 OffsetToData: 0x80000020
- [IMAGE_RESOURCE_DIRECTORY]
- 0x20020 0x0 Characteristics: 0x0
- 0x20024 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x20028 0x8 MajorVersion: 0x4
- 0x2002A 0xA MinorVersion: 0x0
- 0x2002C 0xC NumberOfNamedEntries: 0x0
- 0x2002E 0xE NumberOfIdEntries: 0x1
- Id: [0x1]
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20030 0x0 Name: 0x1
- 0x20034 0x4 OffsetToData: 0x80000038
- [IMAGE_RESOURCE_DIRECTORY]
- 0x20038 0x0 Characteristics: 0x0
- 0x2003C 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x20040 0x8 MajorVersion: 0x4
- 0x20042 0xA MinorVersion: 0x0
- 0x20044 0xC NumberOfNamedEntries: 0x0
- 0x20046 0xE NumberOfIdEntries: 0x1
- \--- LANG [17,1][LANG_JAPANESE,SUBLANG_DEFAULT]
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20048 0x0 Name: 0x411
- 0x2004C 0x4 OffsetToData: 0x80
- [IMAGE_RESOURCE_DATA_ENTRY]
- 0x20080 0x0 OffsetToData: 0x26090
- 0x20084 0x4 Size: 0x32C
- 0x20088 0x8 CodePage: 0x4E4
- 0x2008C 0xC Reserved: 0x0
- Id: [0x18] (RT_MANIFEST)
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20018 0x0 Name: 0x18
- 0x2001C 0x4 OffsetToData: 0x80000050
- [IMAGE_RESOURCE_DIRECTORY]
- 0x20050 0x0 Characteristics: 0x0
- 0x20054 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x20058 0x8 MajorVersion: 0x4
- 0x2005A 0xA MinorVersion: 0x0
- 0x2005C 0xC NumberOfNamedEntries: 0x0
- 0x2005E 0xE NumberOfIdEntries: 0x1
- Id: [0x2]
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20060 0x0 Name: 0x2
- 0x20064 0x4 OffsetToData: 0x80000068
- [IMAGE_RESOURCE_DIRECTORY]
- 0x20068 0x0 Characteristics: 0x0
- 0x2006C 0x4 TimeDateStamp: 0x0 [Thu Jan 1 00:00:00 1970 UTC]
- 0x20070 0x8 MajorVersion: 0x4
- 0x20072 0xA MinorVersion: 0x0
- 0x20074 0xC NumberOfNamedEntries: 0x0
- 0x20076 0xE NumberOfIdEntries: 0x1
- \--- LANG [9,1][LANG_ENGLISH,SUBLANG_ENGLISH_US]
- [IMAGE_RESOURCE_DIRECTORY_ENTRY]
- 0x20078 0x0 Name: 0x409
- 0x2007C 0x4 OffsetToData: 0x3BC
- [IMAGE_RESOURCE_DATA_ENTRY]
- 0x203BC 0x0 OffsetToData: 0x263CC
- 0x203C0 0x4 Size: 0x56
- 0x203C4 0x8 CodePage: 0x4E4
- 0x203C8 0xC Reserved: 0x0
- ----------Base relocations----------
- [IMAGE_BASE_RELOCATION]
- 0x20600 0x0 VirtualAddress: 0x1000
- 0x20604 0x4 SizeOfBlock: 0x20
- 00001144h HIGHLOW
- 0000128Ch HIGHLOW
- 000013D4h HIGHLOW
- 0000151Ch HIGHLOW
- 00001664h HIGHLOW
- 000017ACh HIGHLOW
- 000018F4h HIGHLOW
- 00001A3Ch HIGHLOW
- 00001B84h HIGHLOW
- 00001CCCh HIGHLOW
- 00001F40h HIGHLOW
- 00001000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20620 0x0 VirtualAddress: 0x16000
- 0x20624 0x4 SizeOfBlock: 0xC
- 0001628Ch HIGHLOW
- 00016000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x2062C 0x0 VirtualAddress: 0x17000
- 0x20630 0x4 SizeOfBlock: 0x14
- 000173B6h HIGHLOW
- 00017415h HIGHLOW
- 00017455h HIGHLOW
- 00017518h HIGHLOW
- 00017581h HIGHLOW
- 00017000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20640 0x0 VirtualAddress: 0x18000
- 0x20644 0x4 SizeOfBlock: 0x18
- 0001801Bh HIGHLOW
- 000188E6h HIGHLOW
- 0001893Ch HIGHLOW
- 0001896Bh HIGHLOW
- 000189DEh HIGHLOW
- 00018A29h HIGHLOW
- 00018BD4h HIGHLOW
- 00018000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20658 0x0 VirtualAddress: 0x19000
- 0x2065C 0x4 SizeOfBlock: 0x18
- 000190E4h HIGHLOW
- 0001917Ah HIGHLOW
- 0001922Fh HIGHLOW
- 0001924Dh HIGHLOW
- 00019329h HIGHLOW
- 0001934Dh HIGHLOW
- 000193A1h HIGHLOW
- 00019000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20670 0x0 VirtualAddress: 0x1A000
- 0x20674 0x4 SizeOfBlock: 0xC
- 0001A1E3h HIGHLOW
- 0001A36Ch HIGHLOW
- [IMAGE_BASE_RELOCATION]
- 0x2067C 0x0 VirtualAddress: 0x1B000
- 0x20680 0x4 SizeOfBlock: 0xC
- 0001B481h HIGHLOW
- 0001B000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20688 0x0 VirtualAddress: 0x1D000
- 0x2068C 0x4 SizeOfBlock: 0x14
- 0001DA57h HIGHLOW
- 0001DC4Dh HIGHLOW
- 0001DCD5h HIGHLOW
- 0001DCFEh HIGHLOW
- 0001DE06h HIGHLOW
- 0001D000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x2069C 0x0 VirtualAddress: 0x1E000
- 0x206A0 0x4 SizeOfBlock: 0x184
- 0001E2CAh HIGHLOW
- 0001E2D9h HIGHLOW
- 0001E2EDh HIGHLOW
- 0001E304h HIGHLOW
- 0001E34Bh HIGHLOW
- 0001E35Ch HIGHLOW
- 0001E364h HIGHLOW
- 0001E36Ch HIGHLOW
- 0001E374h HIGHLOW
- 0001E38Ah HIGHLOW
- 0001E392h HIGHLOW
- 0001E399h HIGHLOW
- 0001E3A1h HIGHLOW
- 0001E3B7h HIGHLOW
- 0001E3BFh HIGHLOW
- 0001E3C7h HIGHLOW
- 0001E3CFh HIGHLOW
- 0001E3D6h HIGHLOW
- 0001E3DEh HIGHLOW
- 0001E3E6h HIGHLOW
- 0001E3EEh HIGHLOW
- 0001E3F5h HIGHLOW
- 0001E3FCh HIGHLOW
- 0001E404h HIGHLOW
- 0001E40Ch HIGHLOW
- 0001E41Bh HIGHLOW
- 0001E49Eh HIGHLOW
- 0001E4A6h HIGHLOW
- 0001E4ADh HIGHLOW
- 0001E4CEh HIGHLOW
- 0001E4DDh HIGHLOW
- 0001E4E5h HIGHLOW
- 0001E4EDh HIGHLOW
- 0001E510h HIGHLOW
- 0001E517h HIGHLOW
- 0001E527h HIGHLOW
- 0001E537h HIGHLOW
- 0001E556h HIGHLOW
- 0001E55Dh HIGHLOW
- 0001E56Fh HIGHLOW
- 0001E576h HIGHLOW
- 0001E57Dh HIGHLOW
- 0001E585h HIGHLOW
- 0001E58Ch HIGHLOW
- 0001E593h HIGHLOW
- 0001E59Ah HIGHLOW
- 0001E5A7h HIGHLOW
- 0001E5AFh HIGHLOW
- 0001E5DDh HIGHLOW
- 0001E5E4h HIGHLOW
- 0001E5ECh HIGHLOW
- 0001E5F9h HIGHLOW
- 0001E601h HIGHLOW
- 0001E609h HIGHLOW
- 0001E620h HIGHLOW
- 0001E634h HIGHLOW
- 0001E63Fh HIGHLOW
- 0001E646h HIGHLOW
- 0001E65Ch HIGHLOW
- 0001E663h HIGHLOW
- 0001E68Dh HIGHLOW
- 0001E6A2h HIGHLOW
- 0001E6AAh HIGHLOW
- 0001E6B2h HIGHLOW
- 0001E6BAh HIGHLOW
- 0001E6D0h HIGHLOW
- 0001E6DDh HIGHLOW
- 0001E6E5h HIGHLOW
- 0001E6F2h HIGHLOW
- 0001E707h HIGHLOW
- 0001E70Eh HIGHLOW
- 0001E715h HIGHLOW
- 0001E71Ch HIGHLOW
- 0001E723h HIGHLOW
- 0001E72Ah HIGHLOW
- 0001E73Ah HIGHLOW
- 0001E742h HIGHLOW
- 0001E74Eh HIGHLOW
- 0001E756h HIGHLOW
- 0001E768h HIGHLOW
- 0001E777h HIGHLOW
- 0001E77Eh HIGHLOW
- 0001E795h HIGHLOW
- 0001E79Dh HIGHLOW
- 0001E7B3h HIGHLOW
- 0001E7CBh HIGHLOW
- 0001E7E3h HIGHLOW
- 0001E7EAh HIGHLOW
- 0001E7F2h HIGHLOW
- 0001E803h HIGHLOW
- 0001E80Ah HIGHLOW
- 0001E811h HIGHLOW
- 0001E823h HIGHLOW
- 0001E82Bh HIGHLOW
- 0001E832h HIGHLOW
- 0001E84Ah HIGHLOW
- 0001E865h HIGHLOW
- 0001E86Dh HIGHLOW
- 0001E87Eh HIGHLOW
- 0001E891h HIGHLOW
- 0001E8A4h HIGHLOW
- 0001E8ACh HIGHLOW
- 0001E8B3h HIGHLOW
- 0001E8BBh HIGHLOW
- 0001E8C3h HIGHLOW
- 0001E8CBh HIGHLOW
- 0001E8D2h HIGHLOW
- 0001E8D9h HIGHLOW
- 0001E8EEh HIGHLOW
- 0001E8F5h HIGHLOW
- 0001E8FCh HIGHLOW
- 0001E910h HIGHLOW
- 0001E91Ch HIGHLOW
- 0001E938h HIGHLOW
- 0001E93Fh HIGHLOW
- 0001E946h HIGHLOW
- 0001E94Dh HIGHLOW
- 0001E954h HIGHLOW
- 0001E95Bh HIGHLOW
- 0001E969h HIGHLOW
- 0001E975h HIGHLOW
- 0001E991h HIGHLOW
- 0001E998h HIGHLOW
- 0001E99Fh HIGHLOW
- 0001E9A6h HIGHLOW
- 0001E9ADh HIGHLOW
- 0001E9B4h HIGHLOW
- 0001E9C8h HIGHLOW
- 0001E9DAh HIGHLOW
- 0001E9E2h HIGHLOW
- 0001E9EAh HIGHLOW
- 0001E9F5h HIGHLOW
- 0001E9FDh HIGHLOW
- 0001EA1Ah HIGHLOW
- 0001EA21h HIGHLOW
- 0001EA2Dh HIGHLOW
- 0001EA41h HIGHLOW
- 0001EA48h HIGHLOW
- 0001EA4Fh HIGHLOW
- 0001EA56h HIGHLOW
- 0001EA6Ch HIGHLOW
- 0001EA73h HIGHLOW
- 0001EA88h HIGHLOW
- 0001EA9Eh HIGHLOW
- 0001EAA6h HIGHLOW
- 0001EAAEh HIGHLOW
- 0001EAB6h HIGHLOW
- 0001EABEh HIGHLOW
- 0001EAC5h HIGHLOW
- 0001EACCh HIGHLOW
- 0001EAD4h HIGHLOW
- 0001EAE7h HIGHLOW
- 0001EAEFh HIGHLOW
- 0001EB05h HIGHLOW
- 0001EB0Dh HIGHLOW
- 0001EB1Fh HIGHLOW
- 0001EB32h HIGHLOW
- 0001EB3Ah HIGHLOW
- 0001EB41h HIGHLOW
- 0001EB49h HIGHLOW
- 0001EB51h HIGHLOW
- 0001EB59h HIGHLOW
- 0001EB61h HIGHLOW
- 0001EB75h HIGHLOW
- 0001EB7Ch HIGHLOW
- 0001EB84h HIGHLOW
- 0001EB93h HIGHLOW
- 0001EB9Bh HIGHLOW
- 0001EBA2h HIGHLOW
- 0001EBAAh HIGHLOW
- 0001EBB2h HIGHLOW
- 0001EBB9h HIGHLOW
- 0001EBC1h HIGHLOW
- 0001EBC8h HIGHLOW
- 0001EBCFh HIGHLOW
- 0001EBD7h HIGHLOW
- 0001EBDFh HIGHLOW
- 0001EBE7h HIGHLOW
- 0001EBF6h HIGHLOW
- 0001EBFDh HIGHLOW
- 0001EC04h HIGHLOW
- 0001EC0Ch HIGHLOW
- 0001EC14h HIGHLOW
- 0001EC21h HIGHLOW
- 0001EC28h HIGHLOW
- 0001EC2Fh HIGHLOW
- 0001EC36h HIGHLOW
- 0001EEE9h HIGHLOW
- 0001EF3Bh HIGHLOW
- 0001EF79h HIGHLOW
- [IMAGE_BASE_RELOCATION]
- 0x20820 0x0 VirtualAddress: 0x1F000
- 0x20824 0x4 SizeOfBlock: 0x30
- 0001F102h HIGHLOW
- 0001F51Ch HIGHLOW
- 0001F615h HIGHLOW
- 0001F6E3h HIGHLOW
- 0001F952h HIGHLOW
- 0001F9FDh HIGHLOW
- 0001FA0Ah HIGHLOW
- 0001FCA5h HIGHLOW
- 0001FCABh HIGHLOW
- 0001FCE6h HIGHLOW
- 0001FCECh HIGHLOW
- 0001FD45h HIGHLOW
- 0001FD4Ch HIGHLOW
- 0001FDD1h HIGHLOW
- 0001FEC2h HIGHLOW
- 0001FEC7h HIGHLOW
- 0001FF61h HIGHLOW
- 0001FF67h HIGHLOW
- 0001FF8Fh HIGHLOW
- 0001F000h ABSOLUTE
- [IMAGE_BASE_RELOCATION]
- 0x20850 0x0 VirtualAddress: 0x20000
- 0x20854 0x4 SizeOfBlock: 0x98
- 00020041h HIGHLOW
- 00020099h HIGHLOW
- 00020264h HIGHLOW
- 0002026Ah HIGHLOW
- 00020270h HIGHLOW
- 0002029Bh HIGHLOW
- 000202A4h HIGHLOW
- 000202D1h HIGHLOW
- 000202D6h HIGHLOW
- 000202F0h HIGHLOW
- 00020317h HIGHLOW
- 0002032Fh HIGHLOW
- 000203CBh HIGHLOW
- 000203E4h HIGHLOW
- 000203EAh HIGHLOW
- 000203EFh HIGHLOW
- 00020404h HIGHLOW
- 0002044Eh HIGHLOW
- 00020456h HIGHLOW
- 0002045Eh HIGHLOW
- 00020466h HIGHLOW
- 0002046Eh HIGHLOW
- 00020476h HIGHLOW
- 0002047Eh HIGHLOW
- 00020486h HIGHLOW
- 0002048Eh HIGHLOW
- 00020496h HIGHLOW
- 0002049Eh HIGHLOW
- 000204A6h HIGHLOW
- 000204AEh HIGHLOW
- 000204B6h HIGHLOW
- 000204BEh HIGHLOW
- 000204C6h HIGHLOW
- 000204CEh HIGHLOW
- 000204D6h HIGHLOW
- 000204DEh HIGHLOW
- 000204E6h HIGHLOW
- 000204EEh HIGHLOW
- 000204F6h HIGHLOW
- 000204FEh HIGHLOW
- 00020506h HIGHLOW
- 0002050Eh HIGHLOW
- 00020516h HIGHLOW
- 0002051Eh HIGHLOW
- 00020526h HIGHLOW
- 0002052Eh HIGHLOW
- 00020536h HIGHLOW
- 0002053Eh HIGHLOW
- 00020546h HIGHLOW
- 0002054Eh HIGHLOW
- 00020556h HIGHLOW
- 0002055Eh HIGHLOW
- 00020566h HIGHLOW
- 0002056Eh HIGHLOW
- 00020576h HIGHLOW
- 0002057Eh HIGHLOW
- 00020586h HIGHLOW
- 0002058Eh HIGHLOW
- 00020596h HIGHLOW
- 0002059Eh HIGHLOW
- 000205A6h HIGHLOW
- 000205AEh HIGHLOW
- 000205B6h HIGHLOW
- 000205BEh HIGHLOW
- 000205C6h HIGHLOW
- 000205CEh HIGHLOW
- 000205D6h HIGHLOW
- 000205DEh HIGHLOW
- 000205E6h HIGHLOW
- 000205EEh HIGHLOW
- 000205F6h HIGHLOW
- 000205FEh HIGHLOW
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement