PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x113cd
timedatestamp.....: 0x455537d1 (Sat Nov 11 02:39:13 2006)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4928 0x4a00 6.35 9db8eba7563ac4a6845fd4b46289174d
.rdata 0x6000 0x7c5 0x800 4.31 7f84f3c40c8332b4233cfc131b0a68c4
.data 0x7000 0x5c0 0x200 0.04 24203b33b9a53a29261d0ee9f94f2085
INIT 0x8000 0xa14 0xc00 4.85 96092ad28ffe9e9295d5923d041c4a71
.rsrc 0x9000 0x330 0x400 2.73 a86d63d5e4da66383543f98c521a32fb
.reloc 0xa000 0x618 0x800 4.95 1c66fd91c5e8b3e957534eb14de1f967
( 2 imports )
> ntoskrnl.exe: RtlInitUnicodeString, IoRegisterDriverReinitialization, ObfDereferenceObject, RtlCompareUnicodeString, IoGetDeviceObjectPointer, IoCreateDevice, RtlAppendUnicodeToString, ExAllocatePoolWithTag, IoDeleteSymbolicLink, IoCreateSymbolicLink, PsSetCreateThreadNotifyRoutine, PsSetCreateProcessNotifyRoutine, IoRegisterShutdownNotification, IoRegisterFsRegistrationChange, _wcslwr, memcpy, memset, ExInitializeNPagedLookasideList, KeInitializeEvent, ExFreePoolWithTag, IoDeleteDevice, InitSafeBootMode, _strnicmp, _stricmp, _snprintf, wcscpy, MmIsAddressValid, PsGetCurrentProcessId, PsGetCurrentThreadId, ExInitializeResourceLite, KeLeaveCriticalRegion, ExAcquireResourceSharedLite, KeEnterCriticalRegion, ExAcquireResourceExclusiveLite, ExReleaseResourceLite, _snwprintf, ZwQueryInformationFile, ZwDeleteValueKey, ZwQueryValueKey, ZwOpenKey, strncmp, strlen, IoGetCurrentProcess, IoDetachDevice, MmGetSystemRoutineAddress, ZwCreateFile, InterlockedPushEntrySList, ExGetPreviousMode, wcsncpy, IoAttachDeviceToDeviceStack, ExQueueWorkItem, KeSetEvent, KeWaitForSingleObject, IofCallDriver, IoBuildDeviceIoControlRequest, RtlEqualUnicodeString, ObQueryNameString, ObfReferenceObject, KeDelayExecutionThread, RtlCopyUnicodeString, RtlFreeUnicodeString, ZwReadFile, strncpy, strrchr, ZwEnumerateValueKey, ZwSetSystemInformation, KeServiceDescriptorTable, ZwQuerySystemInformation, IoGetBaseFileSystemDeviceObject, ObReferenceObjectByHandle, IoFileObjectType, RtlFreeAnsiString, RtlUnicodeStringToAnsiString, wcslen, RtlAnsiStringToUnicodeString, RtlAppendStringToString, RtlCompareString, _strlwr, RtlAppendUnicodeStringToString, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, IoFreeIrp, wcscat, KeGetCurrentThread, IoAllocateIrp, memmove, ZwTerminateProcess, ZwRestoreKey, ZwDeleteKey, ZwEnumerateKey, ZwSetValueKey, ZwClose, _except_handler3, InterlockedPopEntrySList, IofCompleteRequest
> HAL.dll: ExReleaseFastMutex, KeGetCurrentIrql, ExAcquireFastMutex
( 0 exports )
|