Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Nov-21 10:28:57 |
Detected languages |
Chinese - PRC
English - United States |
CompanyName | IPRadar software |
FileDescription | IP雷达 |
FileVersion | 5, 3, 0, 0 |
InternalName | IP雷达 |
LegalCopyright | CopyWrite (C) 2008 |
OriginalFilename | IPRadar.EXE |
ProductName | IP雷达 |
ProductVersion | 5, 3, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h) MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to internet browsers:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. |
Resource 133 is possibly compressed or encrypted.
Resource 146 is possibly compressed or encrypted. Resource 147 is possibly compressed or encrypted. Resource 176 is possibly compressed or encrypted. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2016-Nov-21 10:28:57 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 9.0 |
SizeOfCode | 0xcde00 |
SizeOfInitializedData | 0x82c00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0008A48C (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xcf000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x158000 |
SizeOfHeaders | 0x400 |
Checksum | 0x15e171 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WS2_32.dll |
#51
#3 #21 #56 #115 #15 #52 #14 #9 #11 #8 WSACloseEvent WSAResetEvent #111 WSACreateEvent #55 #12 #112 #23 #20 #116 |
---|---|
KERNEL32.dll |
ExitProcess
HeapSize GetStdHandle GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW SetHandleCount GetFileType GetStartupInfoA HeapCreate VirtualFree QueryPerformanceCounter GetCPInfo GetACP GetOEMCP IsValidCodePage LCMapStringW VirtualAlloc GetTimeZoneInformation GetConsoleCP GetConsoleMode InitializeCriticalSectionAndSpinCount LCMapStringA GetStringTypeA GetStringTypeW GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale WriteConsoleA GetConsoleOutputCP WriteConsoleW SetStdHandle GetCurrentDirectoryA GetDriveTypeA GetFullPathNameA CreateFileA SetEnvironmentVariableA GetFileInformationByHandle FindFirstFileA InterlockedExchangeAdd RemoveDirectoryW GetSystemDirectoryA SetErrorMode GetCurrentDirectoryW InterlockedIncrement HeapReAlloc LocalReAlloc TlsSetValue TlsAlloc GlobalHandle GlobalReAlloc WTSGetActiveConsoleSessionId ReadDirectoryChangesW CancelIo ReleaseSemaphore CreateSemaphoreW QueryDosDeviceW SleepEx SizeofResource LockResource LoadResource FindResourceW MultiByteToWideChar GetVersionExW CloseHandle GetCurrentProcess GetLongPathNameW GetModuleFileNameW Sleep GetLastError lstrlenW lstrcpyW GetSystemTimeAsFileTime GetCurrentProcessId CreateMutexW OpenMutexW GetCommandLineW HeapAlloc HeapFree GetProcessHeap GetLocalTime GetTickCount lstrcmpiW GlobalSize GlobalAlloc ReadFile GetFileSize CreateFileW GlobalFree WaitForSingleObject SetEvent GlobalUnlock TlsGetValue LocalAlloc GlobalFlags lstrlenA GetFileSizeEx LocalFileTimeToFileTime FileTimeToLocalFileTime FindNextFileW CreateThread ExitThread IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter RaiseException RtlUnwind TlsFree GetStartupInfoW UnmapViewOfFile MapViewOfFile CreateFileMappingW OpenFileMappingW GetProcessHandleCount GetShortPathNameW GetVolumeInformationW FindFirstFileW FindClose DuplicateHandle SetEndOfFile UnlockFile LockFile FlushFileBuffers SetFilePointer GetThreadLocale GetStringTypeExW MoveFileW InterlockedDecrement GlobalGetAtomNameW GetModuleHandleA GetPrivateProfileStringW WritePrivateProfileStringW GetPrivateProfileIntW GlobalFindAtomW CompareStringW LoadLibraryA GetVersionExA FreeResource GlobalAddAtomW SuspendThread SetThreadPriority GlobalDeleteAtom GetCurrentThread GetCurrentThreadId ConvertDefaultLocale GlobalLock GetProcessIoCounters GetProcessTimes WaitForSingleObjectEx QueueUserAPC EnumResourceLanguagesW lstrcmpA GetLocaleInfoW CompareStringA InterlockedExchange FreeLibrary CopyFileW FormatMessageW LocalFree MulDiv SetLastError GetDiskFreeSpaceW GetFullPathNameW GetTempFileNameW GetFileTime SetFileTime GetSystemDefaultUILanguage GetComputerNameExW GetComputerNameW GetLogicalDrives GetDriveTypeW GetDiskFreeSpaceExW GlobalMemoryStatusEx lstrcatW CreateProcessW ReadProcessMemory OpenProcess GetExitCodeProcess TerminateProcess LoadLibraryW DeleteCriticalSection OpenEventW CreateDirectoryW DeleteFileW GetFileAttributesW WriteFile SetFileAttributesW EnterCriticalSection LeaveCriticalSection InitializeCriticalSection FileTimeToSystemTime WideCharToMultiByte DeviceIoControl SystemTimeToFileTime GetModuleHandleW GetProcAddress GetWindowsDirectoryW lstrcmpW lstrcpynW CreateEventW ResumeThread PeekNamedPipe |
USER32.dll |
BringWindowToTop
TranslateAcceleratorW EndPaint BeginPaint GetWindowDC ClientToScreen GrayStringW DrawTextExW DrawTextW TabbedTextOutW ShowWindow MoveWindow SetWindowTextW IsDialogMessageW LoadIconW SendDlgItemMessageW SendDlgItemMessageA WinHelpW IsChild GetCapture GetClassLongW SetPropW GetPropW RemovePropW SetFocus GetWindowTextLengthW GetWindowTextW GetForegroundWindow BeginDeferWindowPos EndDeferWindowPos GetTopWindow UnhookWindowsHookEx GetMessageTime MapWindowPoints ScrollWindow SetRectEmpty SetScrollRange GetScrollRange SetScrollPos GetScrollPos ShowScrollBar CreateWindowExW GetClassInfoExW GetClassInfoW RegisterClassW GetSysColor AdjustWindowRectEx ScreenToClient EqualRect DeferWindowPos GetScrollInfo SetScrollInfo SetWindowPlacement DefWindowProcW CallWindowProcW GetMenu SetWindowLongW SetWindowPos IntersectRect SystemParametersInfoA IsIconic GetWindowPlacement SetActiveWindow CreateDialogIndirectParamW DrawIcon SetWindowRgn WindowFromPoint CharUpperW GetSysColorBrush DestroyIcon DestroyWindow IsWindow CreatePopupMenu InsertMenuItemW LoadAcceleratorsW DestroyMenu ReuseDDElParam UnpackDDElParam SetMenu GetDlgItem GetNextDlgTabItem EndDialog GetWindowThreadProcessId GetWindowLongW GetLastActivePopup IsWindowEnabled ShowOwnedPopups SetWindowsHookExW CallNextHookEx GetMessageW TranslateMessage DispatchMessageW GetActiveWindow PeekMessageW ValidateRect PostQuitMessage GetMenuStringW GetMenuItemID InsertMenuW GetMenuItemCount SetMenuItemBitmaps GetMenuCheckMarkDimensions LoadBitmapW IsWindowVisible GetIconInfo GetFocus GetDlgCtrlID ModifyMenuW OpenClipboard EmptyClipboard CloseClipboard SetClipboardData SetLayeredWindowAttributes GetKeyState GetClassNameW GetWindow GetMessagePos PostMessageW IsZoomed DrawIconEx PtInRect LoadCursorW LoadImageW SetCursor ReleaseDC RegisterWindowMessageW GetSystemMetrics ReleaseCapture GetCursorPos SetForegroundWindow SetCapture GetWindowRect LoadMenuW GetSubMenu GetMenuState EnableMenuItem CheckMenuItem DeleteMenu CopyRect OffsetRect InflateRect GetParent KillTimer SetTimer InvalidateRect FillRect GetDC GetClientRect SendMessageW UnregisterClassW GetMenuItemInfoW MessageBoxW SystemParametersInfoW EnableWindow UpdateWindow GetDesktopWindow TrackPopupMenu |
GDI32.dll |
TextOutW
ExtTextOutW Escape SelectObject SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx DeleteDC CreatePen DPtoLP CreateEllipticRgn RectVisible Ellipse PtVisible GetPixel DeleteObject MoveToEx LineTo CreateFontIndirectW GetObjectW GetCurrentObject PatBlt CreateSolidBrush CreateCompatibleBitmap CreateCompatibleDC BitBlt GetTextExtentPoint32W Rectangle GetStockObject RoundRect CreateBitmap GetDeviceCaps LPtoDP GetClipBox SetTextColor SetBkColor SaveDC RestoreDC SetBkMode SetMapMode CreatePatternBrush |
COMDLG32.dll |
GetSaveFileNameW
GetFileTitleW |
WINSPOOL.DRV |
ClosePrinter
OpenPrinterW DocumentPropertiesW |
ADVAPI32.dll |
SetSecurityDescriptorDacl
CryptAcquireContextW CryptDestroyKey CryptCreateHash CryptHashData CryptDeriveKey CryptDestroyHash CryptReleaseContext CryptImportKey CryptDecrypt CreateProcessAsUserW RegQueryValueExA RegOpenKeyExA RegCreateKeyW RegCreateKeyExW RegQueryValueW RegOpenKeyW RegEnumKeyW RegDeleteKeyW RegSetValueW GetFileSecurityW SetFileSecurityW RegQueryValueExW RegDeleteValueW RegOpenKeyExW RegSetValueExW RegCloseKey AllocateAndInitializeSid FreeSid GetTokenInformation CreateWellKnownSid CheckTokenMembership OpenProcessToken LookupPrivilegeValueW AdjustTokenPrivileges InitializeSecurityDescriptor |
SHELL32.dll |
ExtractIconW
SHGetFileInfoW DragQueryFileW DragFinish Shell_NotifyIconW SHOpenFolderAndSelectItems SHGetFolderPathW ShellExecuteW ShellExecuteExW SHGetDesktopFolder |
COMCTL32.dll |
_TrackMouseEvent
|
SHLWAPI.dll |
PathRemoveFileSpecW
PathIsUNCW PathStripToRootW PathFindFileNameW PathFindExtensionW StrStrIW |
ole32.dll |
CoTaskMemFree
CoInitialize CoUninitialize CreateStreamOnHGlobal CoCreateInstance CoInitializeEx |
OLEAUT32.dll |
#9
#12 #8 |
gdiplus.dll |
GdipImageSelectActiveFrame
GdipImageGetFrameDimensionsList GdipGetPropertyItemSize GdipGetPropertyItem GdipCreateBitmapFromStream GdipCreateBitmapFromStreamICM GdipImageGetFrameDimensionsCount GdipGetImageRawFormat GdipGetImageHeight GdipGetImageWidth GdipDisposeImage GdipDeleteGraphics GdipAlloc GdipFree GdiplusStartup GdiplusShutdown GdipCreateFromHDC GdipSetLinePresetBlend GdipDrawImageRectI GdipCloneImage GdipDeleteBrush GdipDrawRectangleI GdipFillRectangleI GdipFillEllipseI GdipDrawLineI GdipSetPenWidth GdipSetSolidFillColor GdipSetSmoothingMode GdipAddPathCurve2I GdipCreateSolidFill GdipCloneBrush GdipFillPath GdipDrawPath GdipAddPathArcI GdipAddPathLineI GdipSetPenDashStyle GdipSetPenColor GdipSetPenMode GdipCreateLineBrushI GdipDeletePath GdipCreatePath GdipDeletePen GdipCreatePen1 GdipImageGetFrameCount |
pdh.dll |
PdhEnumObjectsW
PdhEnumObjectItemsW PdhSelectDataSourceW PdhSetDefaultRealTimeDataSource PdhOpenQueryW PdhCloseQuery PdhCollectQueryData PdhGetFormattedCounterValue PdhMakeCounterPathW PdhAddCounterW |
PSAPI.DLL |
EnumProcesses
GetModuleFileNameExW GetProcessImageFileNameW GetProcessMemoryInfo GetPerformanceInfo |
SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
SetupDiDestroyDeviceInfoList SetupDiGetClassDevsW SetupDiGetDeviceInterfaceDetailW |
VERSION.dll |
GetFileVersionInfoSizeW
GetFileVersionInfoW VerQueryValueW |
WININET.dll |
HttpAddRequestHeadersW
HttpSendRequestW HttpQueryInfoW InternetReadFile InternetCloseHandle InternetOpenW InternetConnectW HttpOpenRequestW |
IPHLPAPI.DLL |
GetTcpTable
GetIfTable GetInterfaceInfo GetIpAddrTable NotifyAddrChange CancelIPChangeNotify GetAdaptersAddresses GetUdpTable |
WTSAPI32.dll |
WTSQueryUserToken
|
USERENV.dll |
DestroyEnvironmentBlock
CreateEnvironmentBlock |
OLEACC.dll (delay-loaded) |
LresultFromObject
CreateStdAccessibleObject |
Attributes | 0x1 |
---|---|
Name | OLEACC.dll |
ModuleHandle | 0x1055b0 |
DelayImportAddressTable | 0x1018fc |
DelayImportNameTable | 0xf8790 |
BoundDelayImportTable | 0xf87cc |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
IPTape |
IPTape |
IPTape.Document |
IPTape Document |
Save data to file |
IPTape |
?? |
????? |
?? |
???????? |
?? |
?????? |
?? |
?????? |
?? |
?????????????? |
??? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
????? |
?????? |
?? |
???? |
???? |
??????????????? |
?? |
??????????????? |
?? |
??????? |
?? |
??????? |
?? |
??????? |
?? |
????????????? |
?? |
?????? |
???? |
???????? |
?? |
???????????? |
???? |
??????????? |
?? |
??????,?????? |
?? |
??????;?????? |
?? |
???????? |
???? |
???????? |
???? |
??? |
?? |
?? |
?? |
?? |
?? |
?????? |
?????? |
???????? |
?????????? |
?????????? |
?????????? |
???????????????? |
?????????? |
????? |
打开 |
另存为 |
所有文件(*.*) |
无标题 |
未命名的文件 |
隐藏(&H) |
无法获取错误信息。 |
试图执行的操作不受支持。 |
所需资源不可用。 |
内存不足。 |
发生未知错误 |
遇到不适当的参数。 |
文件名不正确。 |
打开文档失败。 |
保存文档失败。 |
是否保存对 %1 的更改? |
建立空文档失败。 |
该文件太大,无法打开。 |
无法启动打印作业。 |
启动帮助失败。 |
内部应用程序出错。 |
命令失败。 |
没有足够的内存执行操作。 |
系统注册项已被移除并且相应的 INI 文件(如存在)也被删除。 |
不是所有的系统注册项(或 INI 文件)都被移除。 |
在系统中没有找到该程序所需的文件 %s。 |
该程序连接到丢失的输出 %s (在文件 %s 中)。该计算机上安装的可能是不兼容的 %s 版本。 |
请输入一个整数。 |
请输入一个数字。 |
请输入一个在 %1 和 %2 之间的整数。 |
请输入一个在 %1 和 %2 之间的数字。 |
请输入不多于 %1 个的字符。 |
请选择一个按钮。 |
请输入一个在 0 和 255 之间的整数。 |
请输入一个正整数。 |
请输入一个日期和/或时间值。 |
请输入一种货币。 |
请输入一个 GUID。 |
请输入一个时间。 |
请输入一个日期。 |
意外的文件格式。 |
%1 |
无法找到该文件。 |
请验证指定的路径和文件名是否正确。 |
目标磁盘驱动器已满。 |
无法对 %1 进行读操作,它已经被其他人打开。 |
无法对 %1 进行写操作,因为它是只读文件或已经被其他人打开。 |
在对 %1 进行读操作时发生错误。 |
在对 %1 进行写操作时发生错误。 |
%1: %2 |
是否继续运行脚本? |
调度异常: %1 |
无法读取只写属性。 |
无法写入只读属性。 |
无法加载邮件系统支持。 |
邮件系统 DLL 无效。 |
“发送邮件”未能发送邮件。 |
未发生错误。 |
访问 %1 时发生未知错误。 |
没有找到 %1。 |
%1 包含错误的路径。 |
无法打开 %1,因为打开的文件太多。 |
对 %1 的访问被拒绝。 |
与 %1 相关联的文件句柄不正确。 |
无法删除 %1,因为它是当前目录。 |
该目录已满,无法创建 %1。 |
对 %1 进行查找失败。 |
访问 %1 时遇到硬件 I/O 错误。 |
访问 %1 时遇到共享冲突。 |
访问 %1 时遇到锁定冲突。 |
访问 %1 时磁盘已满。 |
试图访问 %1 时超过它的结尾。 |
未发生错误。 |
访问 %1 时发生未知错误。 |
试图在对 %1 进行读操作的同时对其进行写操作。 |
试图访问 %1 时超过它的结尾。 |
试图在对 %1 进行写操作的同时对其进行读操作。 |
%1 格式错误。 |
%1 包含意外的对象。 |
%1 包含错误的架构。 |
像素 |
取消选中 |
选中 |
混合 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 5.3.0.0 |
ProductVersion | 5.3.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | IPRadar software |
FileDescription | IP雷达 |
FileVersion (#2) | 5, 3, 0, 0 |
InternalName | IP雷达 |
LegalCopyright | CopyWrite (C) 2008 |
OriginalFilename | IPRadar.EXE |
ProductName | IP雷达 |
ProductVersion (#2) | 5, 3, 0, 0 |
Resource LangID | Chinese - PRC |
---|
XOR Key | 0xf63f60f2 |
---|---|
Unmarked objects | 0 |
C objects (VS98 build 8168) | 2 |
Unmarked objects (#2) | 1 |
138 (VS2008 build 21022) | 13 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
C objects (VS2012 build 50727 / VS2005 build 50727) | 8 |
150 (20413) | 7 |
ASM objects (VS2008 build 21022) | 29 |
C objects (VS2008 build 21022) | 199 |
Total imports | 727 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 43 |
C++ objects (VS2008 build 21022) | 278 |
Linker (VS2008 build 21022) | 1 |
Resource objects (VS2008 build 21022) | 1 |