Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Sep-23 18:23:22 |
Detected languages |
English - United States
|
CompanyName | IgorWare |
FileDescription | Check is Windows 64bit or 32bit? |
FileVersion | 1, 5, 0, 0 |
InternalName | 64bit Checker |
LegalCopyright | Copyright (C) 2015 IgorWare |
OriginalFilename | 64bit-checker.exe |
ProductName | 64bit Checker |
ProductVersion | 1, 5, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE Microsoft Visual C++ 7.0 MFC |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2018-Sep-23 18:23:22 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.0 |
SizeOfCode | 0xa000 |
SizeOfInitializedData | 0xa000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001194 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xb000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x16000 |
SizeOfHeaders | 0x1000 |
Checksum | 0x1e55e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
GetProcAddress
CreateConsoleScreenBuffer GetPrivateProfileStringA LoadLibraryA WriteConsoleA GetSystemInfo GetModuleHandleA GetVersionExA CloseHandle GetTempPathA CreateThread VirtualProtect GetLocaleInfoA GetStringTypeW GetStringTypeA LCMapStringW MultiByteToWideChar LCMapStringA GetStdHandle GetCurrentProcessId GetTickCount QueryPerformanceCounter InitializeCriticalSection GetCPInfo GetOEMCP GetACP VirtualQuery InterlockedExchange RtlUnwind VirtualAlloc EnterCriticalSection LeaveCriticalSection VirtualFree HeapCreate HeapDestroy TlsGetValue TlsSetValue TlsFree GetCurrentThreadId SetLastError TlsAlloc DeleteCriticalSection GetFileType SetHandleCount GetTempPathW GlobalUnlock CreateFileW FileTimeToSystemTime CreateFileA GlobalAlloc WriteFile GetDateFormatA GetPrivateProfileStringW GlobalLock FreeLibrary AllocConsole GetSystemTimeAsFileTime GetEnvironmentStringsW GetLastError GetStartupInfoA GetCommandLineA HeapReAlloc HeapAlloc ExitProcess TerminateProcess GetCurrentProcess HeapSize HeapFree GetModuleFileNameA UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte |
---|---|
USER32.dll |
ClientToScreen
DestroyWindow SetCursor GetMessageA CloseClipboard GetSystemMenu SetTimer ScreenToClient GetWindowRect CreateDialogParamA PostQuitMessage KillTimer LoadIconA wsprintfA GetClientRect GetWindowTextLengthA SendMessageA wsprintfW GetDC IsDialogMessageA TranslateMessage SetWindowLongA MessageBoxA CreateWindowExA ReleaseDC EmptyClipboard GetDlgItem EndDialog SetWindowPos ShowWindow GetSysColorBrush GetMenuItemCount DispatchMessageA OpenClipboard GetSystemMetrics InsertMenuA SetWindowTextA SetClipboardData CallWindowProcA LoadCursorA GetDlgCtrlID DialogBoxParamA SetWindowTextW DestroyIcon GetWindowTextA |
GDI32.dll |
GetDeviceCaps
CreateFontIndirectA SetBkMode DeleteObject SetTextColor |
COMDLG32.dll |
GetSaveFileNameA
GetSaveFileNameW |
ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegQueryValueExA |
SHELL32.dll |
ShellExecuteA
|
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.5.0.0 |
ProductVersion | 1.5.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | IgorWare |
FileDescription | Check is Windows 64bit or 32bit? |
FileVersion (#2) | 1, 5, 0, 0 |
InternalName | 64bit Checker |
LegalCopyright | Copyright (C) 2015 IgorWare |
OriginalFilename | 64bit-checker.exe |
ProductName | 64bit Checker |
ProductVersion (#2) | 1, 5, 0, 0 |
Resource LangID | UNKNOWN |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x40f2c0 |
SEHandlerTable | 0x40dab0 |
SEHandlerCount | 2 |
XOR Key | 0xd5ff184b |
---|---|
Unmarked objects | 0 |
C++ objects (VS2003 (.NET) SP1 build 6030) | 4 |
ASM objects (VS2003 (.NET) SP1 build 6030) | 21 |
C objects (VS2003 (.NET) SP1 build 6030) | 86 |
Imports (VS2008 SP1 build 30729) | 13 |
Total imports | 144 |
100 (VS2003 (.NET) SP1 build 6030) | 2 |
Linker (VS2008 build 21022) | 1 |
Linker (VS2003 (.NET) SP1 build 6030) | 1 |