Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2003-May-20 18:15:00 |
Detected languages |
English - United States
|
CompanyName | ScanSoft, Inc. |
FileDescription | OmniForm Mailable Filler Bootstrapper |
FileVersion | 5.1 |
InternalName | OMNIBOOT |
LegalCopyright | Copyright © ScanSoft, Inc. 1988-2003 |
OriginalFilename | OMNIBOOT.EXE |
ProductName | OmniForm |
ProductVersion | 5.1 |
Info | Matching compiler(s): |
Installer VISE Custom
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | The file contains overlay data. |
673663 bytes of data starting at offset 0xc000.
The overlay data has an entropy of 7.91208 and is possibly compressed or encrypted. Overlay data amounts for 93.1999% of the executable. |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2003-May-20 18:15:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x6000 |
SizeOfInitializedData | 0xa000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000023FC (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x11000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
CloseHandle
SetFilePointer ReadFile CreateFileA CreateProcessA GetTempFileNameA GetTempPathA GetModuleFileNameA DeleteFileA Sleep GetStringTypeA LCMapStringW LCMapStringA MultiByteToWideChar SetEndOfFile HeapAlloc GetModuleHandleA GetStartupInfoA GetCommandLineA GetVersion ExitProcess HeapFree GetLastError WriteFile TerminateProcess GetCurrentProcess SetHandleCount GetStdHandle GetFileType GetEnvironmentVariableA GetVersionExA HeapDestroy HeapCreate VirtualFree VirtualAlloc HeapReAlloc UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW RtlUnwind SetStdHandle FlushFileBuffers GetCPInfo GetACP GetOEMCP GetProcAddress LoadLibraryA GetStringTypeW |
---|---|
USER32.dll |
MessageBeep
MessageBoxA FindWindowA LoadStringA |
OmniForm Mailable Filler |
Failed to launch application. |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.1.0.0 |
ProductVersion | 5.1.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | ScanSoft, Inc. |
FileDescription | OmniForm Mailable Filler Bootstrapper |
FileVersion (#2) | 5.1 |
InternalName | OMNIBOOT |
LegalCopyright | Copyright © ScanSoft, Inc. 1988-2003 |
OriginalFilename | OMNIBOOT.EXE |
ProductName | OmniForm |
ProductVersion (#2) | 5.1 |
Resource LangID | English - United States |
---|
XOR Key | 0xc9c7c9ef |
---|---|
Unmarked objects | 0 |
C++ objects (8047) | 1 |
14 (7299) | 14 |
C objects (8047) | 55 |
19 (9049) | 5 |
Total imports | 56 |
C objects (VC++ 6.0 SP5 build 8804) | 3 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |