Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2004-Dec-23 15:22:26 |
Detected languages |
Chinese - Taiwan
|
Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Borland C++ DLL MASM/TASM - sig1(h) Borland C++ for Win32 1999 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC+8 timezone. |
Safe | VirusTotal score: 0/70 (Scanned on 2019-11-23 04:50:49) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x200 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2004-Dec-23 15:22:26 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x6d000 |
SizeOfInitializedData | 0xb000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001314 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x6e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x8e000 |
SizeOfHeaders | 0x600 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
HID.DLL |
HidD_FreePreparsedData
HidD_GetAttributes HidD_GetHidGuid HidD_GetPreparsedData HidP_GetCaps HidP_GetSpecificValueCaps |
---|---|
SETUPAPI.DLL |
SetupDiDestroyDeviceInfoList
SetupDiEnumDeviceInterfaces SetupDiGetClassDevsA SetupDiGetDeviceInterfaceDetailA |
ADVAPI32.DLL |
RegCloseKey
RegOpenKeyExA RegQueryValueExA |
KERNEL32.DLL |
CloseHandle
CompareStringA CreateEventA CreateFileA CreateThread DeleteCriticalSection EnterCriticalSection EnumCalendarInfoA ExitProcess FindClose FindFirstFileA FindResourceA FormatMessageA FreeLibrary FreeResource GetACP GetCPInfo GetCommandLineA GetCurrentProcessId GetCurrentThreadId GetDiskFreeSpaceA GetEnvironmentStrings GetFileSize GetFileType GetLastError GetLocalTime GetLocaleInfoA GetModuleFileNameA GetModuleHandleA GetOEMCP GetPrivateProfileStringA GetProcAddress GetProcessHeap GetStartupInfoA GetStdHandle GetStringTypeExA GetStringTypeW GetSystemInfo GetThreadLocale GetTickCount GetVersion GetVersionExA GlobalAddAtomA GlobalAlloc GlobalDeleteAtom GlobalFindAtomA GlobalFree GlobalHandle GlobalLock GlobalReAlloc GlobalUnlock HeapAlloc HeapFree InitializeCriticalSection InterlockedDecrement InterlockedIncrement LeaveCriticalSection LoadLibraryA LoadLibraryExA LoadResource LocalAlloc LocalFree LockResource MulDiv MultiByteToWideChar RaiseException ReadFile ResetEvent RtlUnwind SetConsoleCtrlHandler SetEndOfFile SetErrorMode SetEvent SetFilePointer SetHandleCount SetLastError SetThreadLocale SizeofResource Sleep TlsAlloc TlsFree TlsGetValue TlsSetValue UnhandledExceptionFilter VirtualAlloc VirtualFree VirtualQuery WaitForSingleObject WideCharToMultiByte WriteFile lstrcpyA lstrcpynA lstrlenA |
COMCTL32.DLL |
ImageList_Add
ImageList_BeginDrag ImageList_Create ImageList_Destroy ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock ImageList_Draw ImageList_DrawEx ImageList_EndDrag ImageList_GetBkColor ImageList_GetDragImage ImageList_GetIconSize ImageList_GetImageCount ImageList_Read ImageList_Remove ImageList_ReplaceIcon ImageList_SetBkColor ImageList_SetDragCursorImage ImageList_SetIconSize ImageList_Write |
GDI32.DLL |
BitBlt
CopyEnhMetaFileA CreateBitmap CreateBrushIndirect CreateCompatibleBitmap CreateCompatibleDC CreateDIBSection CreateDIBitmap CreateFontIndirectA CreateHalftonePalette CreatePalette CreatePenIndirect CreateSolidBrush DeleteDC DeleteEnhMetaFile DeleteObject ExcludeClipRect ExtTextOutA GetBitmapBits GetBrushOrgEx GetClipBox GetCurrentPositionEx GetDCOrgEx GetDIBColorTable GetDIBits GetDeviceCaps GetEnhMetaFileBits GetEnhMetaFileHeader GetEnhMetaFilePaletteEntries GetObjectA GetPaletteEntries GetPixel GetStockObject GetSystemPaletteEntries GetTextExtentPoint32A GetTextMetricsA GetWinMetaFileBits GetWindowOrgEx IntersectClipRect LineTo MaskBlt MoveToEx PatBlt PlayEnhMetaFile RealizePalette RectVisible RestoreDC SaveDC SelectObject SelectPalette SetBkColor SetBkMode SetBrushOrgEx SetDIBColorTable SetEnhMetaFileBits SetPixel SetROP2 SetStretchBltMode SetTextColor SetViewportOrgEx SetWinMetaFileBits SetWindowOrgEx StretchBlt UnrealizeObject |
USER32.DLL |
ActivateKeyboardLayout
AdjustWindowRectEx BeginPaint CallNextHookEx CallWindowProcA CharLowerA CharLowerBuffA CharNextA CharUpperBuffA CheckMenuItem ClientToScreen CloseClipboard CreateIcon CreateMenu CreatePopupMenu CreateWindowExA DefFrameProcA DefMDIChildProcA DefWindowProcA DeleteMenu DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageA DrawEdge DrawFocusRect DrawFrameControl DrawIcon DrawIconEx DrawMenuBar DrawTextA EmptyClipboard EnableMenuItem EnableScrollBar EnableWindow EndPaint EnumClipboardFormats EnumThreadWindows EnumWindows EqualRect FillRect FindWindowA FrameRect GetActiveWindow GetCapture GetClassInfoA GetClassNameA GetClientRect GetClipboardData GetCursor GetCursorPos GetDC GetDCEx GetDesktopWindow GetFocus GetForegroundWindow GetIconInfo GetKeyNameTextA GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardState GetKeyboardType GetLastActivePopup GetMenu GetMenuItemCount GetMenuItemID GetMenuItemInfoA GetMenuState GetMenuStringA GetParent GetPropA GetScrollInfo GetScrollPos GetScrollRange GetSubMenu GetSystemMenu GetSystemMetrics GetTopWindow GetWindow GetWindowDC GetWindowLongA GetWindowPlacement GetWindowRect GetWindowTextA GetWindowThreadProcessId InflateRect InsertMenuA InsertMenuItemA IntersectRect InvalidateRect IsCharAlphaA IsCharAlphaNumericA IsChild IsDialogMessageA IsIconic IsRectEmpty IsWindow IsWindowEnabled IsWindowVisible IsZoomed KillTimer LoadBitmapA LoadCursorA LoadIconA LoadKeyboardLayoutA LoadStringA MapVirtualKeyA MapWindowPoints MessageBeep MessageBoxA OemToCharA OffsetRect OpenClipboard PeekMessageA PostMessageA PostQuitMessage PtInRect RedrawWindow RegisterClassA RegisterClipboardFormatA RegisterWindowMessageA ReleaseCapture ReleaseDC RemoveMenu RemovePropA ScreenToClient ScrollWindow SendMessageA SetActiveWindow SetCapture SetClassLongA SetClipboardData SetCursor SetFocus SetForegroundWindow SetKeyboardState SetMenu SetMenuItemInfoA SetPropA SetRect SetScrollInfo SetScrollPos SetScrollRange SetTimer SetWindowLongA SetWindowPlacement SetWindowPos SetWindowTextA SetWindowsHookExA ShowCursor ShowOwnedPopups ShowScrollBar ShowWindow SystemParametersInfoA TrackPopupMenu TranslateMDISysAccel TranslateMessage UnhookWindowsHookEx UnregisterClassA UpdateWindow WaitMessage WinHelpA WindowFromPoint wsprintfA GetSysColor |
OLEAUT32.DLL |
#15
#25 #20 #19 #148 #26 #40 #4 #6 #5 #125 #116 #113 #114 #104 #94 #64 #173 #174 #84 #147 #9 #10 #11 #8 |
Ordinal | 1 |
---|---|
Address | 0x136d |
Ordinal | 2 |
---|---|
Address | 0x4514 |
Ordinal | 3 |
---|---|
Address | 0x4524 |
Ordinal | 4 |
---|---|
Address | 0x6e098 |
Ordinal | 5 |
---|---|
Address | 0x73660 |
Cannot open clipboard |
Text exceeds memo capacity |
Menu '%s' is already being used by another form |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
PgUp |
PgDn |
End |
Home |
Left |
Up |
Right |
Down |
Ins |
Del |
Shift+ |
Ctrl+ |
Alt+ |
Unable to insert a line |
Invalid clipboard format |
Clipboard does not support Icons |
&Yes |
&No |
OK |
Cancel |
&Help |
&Abort |
&Retry |
&Ignore |
&All |
N&o to All |
Yes to &All |
BkSp |
Tab |
Esc |
Enter |
Space |
Cannot change Visible in OnShow or OnHide |
Cannot make a visible window modal |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
A control cannot have itself as its parent |
Cannot drag a form |
Invalid input value |
Invalid input value. Use escape key to abandon changes |
Warning |
Error |
Information |
Confirm |
Icon image is not valid |
Metafile is not valid |
Cannot change the size of an icon |
Unsupported clipboard format |
Out of system resources |
Canvas does not allow drawing |
Invalid image size |
Invalid ImageList |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
Cannot hide an MDI Child Form |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Bitmap image is not valid |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
November |
External exception %x |
Assertion failed |
Interface not supported |
Exception in safecall method |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Jul |
Read |
Write |
Error creating variant array |
Variant array index out of bounds |
Variant array is locked |
Invalid variant type conversion |
Invalid variant operation |
Invalid variant operation ($%.8x) |
Variant is not an array |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Stack overflow |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Property %s does not exist |
Stream write error |
'%s' is not a valid integer value |
'%s' is not a valid currency value |
'%g' is not a valid date and time |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Invalid stream format |
''%s'' is not a valid component name |
Invalid property value |
Invalid property path |
Invalid property value |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
Error reading %s%s%s: %s |
Stream read error |
Property is read-only |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
%s not in a class registration group |
Unable to find a Table of Contents |
No help found for %s |
No context-sensitive help installed |
No topic-based help system installed |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Can't write to a read-only resource stream |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file %s |
Cannot open file %s |
StartAddressOfRawData | 0x479000 |
---|---|
EndAddressOfRawData | 0x4790b4 |
AddressOfIndex | 0x473648 |
AddressOfCallbacks | 0x47a010 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |