PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x40cae4
timedatestamp.....: 0x48645212 (Fri Jun 27 02:36:02 2008)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xbc70 0xc000 6.80 2d5e42d4bcc9004170e28bb0c4778d65
.rdata 0xd000 0x4b0c 0x5000 7.32 50c3527437298f5e1f7bc1dc04943d17
.data 0x12000 0x1ab50 0x1b000 7.98 acd70dd277dbb7511b1fc450f3a9be46
( 9 imports )
> USER32.dll: wsprintfA
> SHELL32.dll: SHGetSpecialFolderPathA
> ole32.dll: CoInitialize, CoCreateGuid, CoCreateInstance
> RPCRT4.dll: UuidToStringA
> ADVAPI32.dll: RegCloseKey, StartServiceA, RegCreateKeyExA, RegSetValueExA, RegOpenKeyExA, CreateServiceA, OpenSCManagerA, DeleteService, CryptReleaseContext, CryptGenRandom, CryptAcquireContextA, CloseServiceHandle, OpenServiceA
> SHLWAPI.dll: StrStrIA, SHGetValueA, SHEnumKeyExA, SHSetValueA, SHEnumValueA
> MSVCRT.dll: strlen, ispunct, isspace, strerror, tolower, isalnum, printf, wctomb, __mb_cur_max, malloc, isupper, islower, fwrite, free, fclose, fopen, time, sprintf, atoi, strncpy, wcscpy, mbstowcs, srand, _exit, _XcptFilter, exit, _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, isxdigit, memcmp, isalpha, rand, isgraph, strcpy, strcat, memcpy, memset, __2@YAPAXI@Z
> IMAGEHLP.dll: ImageNtHeader
> KERNEL32.dll: FindFirstFileA, lstrlenA, ExitProcess, GetVersionExA, GetLocalTime, SleepEx, GetModuleHandleA, GetFileAttributesA, GetPrivateProfileStringA, FindNextFileA, WideCharToMultiByte, GetLastError, GetSystemDirectoryA, GetFileAttributesExA, CreateFileA, SetFileTime, CloseHandle, GetStartupInfoA
( 0 exports )
|