| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2008-Apr-14 00:11:25 |
| Detected languages |
English - United States
|
| Debug artifacts |
msctfime.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Text Frame Work Service IME |
| FileVersion | 5.1.2600.5512 (xpsp.080413-2105) |
| InternalName | MSCTFIME |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | MSCTFIME.IME |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 5.1.2600.5512 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.1
Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ 7.0 DLL |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2008-Apr-14 00:11:25 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.1 |
| SizeOfCode | 0x26c00 |
| SizeOfInitializedData | 0x4800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00019FE1 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x28000 |
| ImageBase | 0x755c0000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 5.1 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x2e000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2d2b7 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| msvcrt.dll |
strncmp
_vsnprintf _ftol _except_handler3 wcsncpy _adjust_fdiv malloc _initterm free wcscpy memmove wcstoul |
|---|---|
| USER32.dll |
DrawTextExW
DrawTextExA RegisterWindowMessageA UnregisterClassW LoadIconA LoadCursorA GetClassInfoExW RegisterClassExW GetActiveWindow GetCaretBlinkTime BeginPaint EndPaint GetSysColor CreateWindowExW GetSystemMetrics MapWindowPoints SetWindowPos DestroyWindow GetCursorPos MoveWindow IsWindowVisible ShowWindow LoadImageA DestroyIcon PtInRect ScreenToClient InvalidateRect SetWindowLongA DefWindowProcA KillTimer SetTimer GetWindowLongA SystemParametersInfoA GetDC SetRect ReleaseDC GetClientRect ClientToScreen PostMessageW PostMessageA GetFocus IsWindow ToUnicode GetKeyboardLayout CreateWindowExA ReleaseCapture SetCapture AdjustWindowRectEx WindowFromPoint RegisterClassExA GetClassInfoExA SetCursor GetDoubleClickTime DrawEdge DrawIconEx FillRect GetIconInfo OffsetRect InflateRect IntersectRect GetSysColorBrush DrawStateA FrameRect GetCursor GetKeyState keybd_event SendMessageW IsWindowUnicode GetWindowRect SendMessageA GetKeyboardState |
| ADVAPI32.dll |
RegOpenKeyExA
RegCloseKey RegQueryValueExW RegCreateKeyExA RegSetValueExA FreeSid AllocateAndInitializeSid CheckTokenMembership RegQueryValueExA |
| KERNEL32.dll |
WideCharToMultiByte
IsDBCSLeadByteEx GetLocaleInfoW GetProcAddress InitializeCriticalSectionAndSpinCount DeleteCriticalSection TlsAlloc TlsFree GetVersionExA GetACP QueryPerformanceCounter GetTickCount GetCurrentThreadId GetCurrentProcessId GetSystemTimeAsFileTime TerminateProcess GetCurrentProcess MultiByteToWideChar SetUnhandledExceptionFilter FreeLibrary LeaveCriticalSection EnterCriticalSection LoadLibraryExA lstrcmpA LocalFree LocalAlloc IsBadWritePtr lstrlenA lstrlenW lstrcpynA GetSystemDirectoryA GetSystemWindowsDirectoryA GetSystemDirectoryW GetSystemWindowsDirectoryW GetModuleHandleA LoadLibraryA GetModuleHandleW LoadLibraryW LocalReAlloc GetLastError InterlockedDecrement InterlockedIncrement TlsGetValue TlsSetValue GetModuleFileNameA LoadResource FindResourceA GetSystemDefaultLangID EnumResourceLanguagesA GetWindowsDirectoryA UnhandledExceptionFilter |
| GDI32.dll |
Polyline
BitBlt CreateFontIndirectW CreateFontIndirectA SelectObject GetTextMetricsA DeleteObject MoveToEx ExtCreatePen GetTextColor SetTextColor SetBkColor PatBlt DeleteDC SetViewportOrgEx CreateCompatibleBitmap GetDeviceCaps CreateCompatibleDC SetBkMode CreatePen CreateFontA CreateSolidBrush CreateDCA CreateDIBSection CreateRectRgn GetClipRgn IntersectClipRect ExtSelectClipRgn GetViewportExtEx GetWindowExtEx GetTextExtentPointA GetTextExtentPoint32W GetTextAlign SetTextAlign ExtTextOutA ExtTextOutW GetObjectA TranslateCharsetInfo GetCurrentObject GetObjectW CreateBitmap CreateBrushIndirect LineTo GetStockObject |
| IMM32.dll |
ImmDestroyIMCC
ImmNotifyIME ImmEnumInputContext ImmGetContext ImmGetDefaultIMEWnd ImmSetConversionStatus ImmGetAppCompatFlags ImmSetCompositionStringW ImmGetProperty ImmCreateIMCC ImmLockIMC ImmUnlockIMC ImmLockIMCC ImmUnlockIMCC ImmGetIMCCSize ImmReSizeIMCC ImmRequestMessageA ImmSetOpenStatus ImmGetCompositionFontA ImmGetCompositionStringW CtfImmGenerateMessage CtfImmIsCiceroStartedInThread |
| Ordinal | 1 |
|---|---|
| Address | 0x13818 |
| Ordinal | 2 |
|---|---|
| Address | 0x19699 |
| Ordinal | 3 |
|---|---|
| Address | 0x19590 |
| Ordinal | 4 |
|---|---|
| Address | 0x1913a |
| Ordinal | 5 |
|---|---|
| Address | 0x1961b |
| Ordinal | 6 |
|---|---|
| Address | 0x196fe |
| Ordinal | 7 |
|---|---|
| Address | 0x19737 |
| Ordinal | 8 |
|---|---|
| Address | 0x19548 |
| Ordinal | 9 |
|---|---|
| Address | 0x1931a |
| Ordinal | 10 |
|---|---|
| Address | 0x1976b |
| Ordinal | 11 |
|---|---|
| Address | 0x19979 |
| Ordinal | 12 |
|---|---|
| Address | 0x192c5 |
| Ordinal | 13 |
|---|---|
| Address | 0x196c7 |
| Ordinal | 14 |
|---|---|
| Address | 0x19365 |
| Ordinal | 15 |
|---|---|
| Address | 0x1940e |
| Ordinal | 16 |
|---|---|
| Address | 0x190c5 |
| Ordinal | 17 |
|---|---|
| Address | 0x190cf |
| Ordinal | 18 |
|---|---|
| Address | 0x190c5 |
| Ordinal | 19 |
|---|---|
| Address | 0x76f9 |
| Ordinal | 20 |
|---|---|
| Address | 0x19120 |
| Ordinal | 21 |
|---|---|
| Address | 0x76f9 |
| Ordinal | 22 |
|---|---|
| Address | 0x19899 |
| Ordinal | 23 |
|---|---|
| Address | 0x76f9 |
| Ordinal | 24 |
|---|---|
| Address | 0x19120 |
| Ordinal | 25 |
|---|---|
| Address | 0x19120 |
| Ordinal | 26 |
|---|---|
| Address | 0x1946d |
| Ordinal | 27 |
|---|---|
| Address | 0x194af |
| Ordinal | 28 |
|---|---|
| Address | 0x76f9 |
| Ordinal | 29 |
|---|---|
| Address | 0x19507 |
| Ordinal | 30 |
|---|---|
| Address | 0x1912a |
| OK |
| Cancel |
| &Abort |
| &Retry |
| &Ignore |
| &Yes |
| &No |
| Enter |
| Finalize the string |
| Conversion |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 5.1.2600.5512 |
| ProductVersion | 5.1.2600.5512 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DRV
|
| FileSubtype | VFT2_DRV_INPUTMETHOD |
| Language | UNKNOWN |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Text Frame Work Service IME |
| FileVersion (#2) | 5.1.2600.5512 (xpsp.080413-2105) |
| InternalName | MSCTFIME |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | MSCTFIME.IME |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 5.1.2600.5512 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2008-Apr-13 18:39:30 |
| Version | 0.0 |
| SizeofData | 37 |
| AddressOfRawData | 0x4398 |
| PointerToRawData | 0x3798 |
| Referenced File | msctfime.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x755e8050 |
| SEHandlerTable | 0x755c43c0 |
| SEHandlerCount | 1 |
| XOR Key | 0xb7ba2ba6 |
|---|---|
| Unmarked objects | 0 |
| Total imports | 238 |
| Imports (VS2003 (.NET) build 4035) | 13 |
| ASM objects (VS2003 (.NET) build 4035) | 2 |
| Exports (VS2003 (.NET) build 4035) | 1 |
| 94 (VS2003 (.NET) build 4035) | 1 |
| C objects (VS2003 (.NET) build 4035) | 18 |
| C++ objects (VS2003 (.NET) build 4035) | 69 |
| Linker (VS2003 (.NET) build 4035) | 1 |