Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2010-Nov-20 12:00:05 |
Detected languages |
English - United States
|
Debug artifacts |
imm32.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Multi-User Windows IMM32 API Client DLL |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | imm32 |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | imm32 |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/64 (Scanned on 2022-01-31 08:10:09) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xd8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2010-Nov-20 12:00:05 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.1 |
SizeOfCode | 0x16800 |
SizeOfInitializedData | 0x6800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001355 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x18000 |
ImageBase | 0x75a40000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 6.1 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x1f000 |
SizeOfHeaders | 0x400 |
Checksum | 0x27a42 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
SystemParametersInfoW
GetClassInfoExW LoadIconW RegisterClassExW GetParent GetCapture DrawEdge BeginPaint EndPaint InvalidateRect DefWindowProcW ReleaseCapture SetWindowPos GetWindow keybd_event GetMonitorInfoW SetCursor GetCursorPos ScreenToClient SetCapture MessageBeep GetSystemMetrics GetWindowRect DrawTextExW GetWindowLongW SetWindowLongW GetClientRect GetDC ReleaseDC LoadBitmapW UnloadKeyboardLayout CharUpperW User32InitializeImmEntryTable LoadKeyboardLayoutW GetFocus GetActiveWindow GetClassInfoW GetWindowThreadProcessId GetKeyboardLayoutList SendMessageA PostMessageW PostMessageA WCSToMBEx GetKeyboardLayout IsWindow MonitorFromWindow UpdateWindow ShowWindow CreateWindowExW MapVirtualKeyW DestroyWindow ToAsciiEx ToUnicode GetKeyboardState ClientToScreen GetForegroundWindow MapWindowPoints CharNextA CharNextW IsWindowUnicode GetDesktopWindow SendMessageTimeoutW SendMessageW LoadCursorW |
---|---|
ntdll.dll |
RtlUnwind
RtlIsThreadWithinLoaderCallout RtlDllShutdownInProgress RtlUnicodeToMultiByteSize wcstol _wcsicmp RtlUnicodeStringToInteger RtlIntegerToUnicodeString RtlDeleteCriticalSection NtQuerySystemInformation _vsnwprintf RtlEnterCriticalSection RtlLeaveCriticalSection memset memcpy RtlInitializeCriticalSection RtlSetLastWin32Error |
API-MS-Win-Core-LocalRegistry-L1-1-0.dll |
RegDeleteKeyExW
RegCloseKey RegCreateKeyExW RegSetValueExW RegQueryValueExW RegEnumKeyExW RegOpenKeyExW |
API-MS-Win-Security-Base-L1-1-0.dll |
AllocateAndInitializeSid
FreeSid CheckTokenMembership |
KERNEL32.dll |
Sleep
TlsGetValue TlsSetValue TlsAlloc OpenFileMappingW GetCurrentProcessId CreateFileMappingW MapViewOfFile UnmapViewOfFile CloseHandle GetLastError lstrlenA IsDBCSLeadByte GetProfileIntW CreateThread GlobalSize SetLastError GlobalAlloc GlobalLock TlsFree GlobalUnlock HeapAlloc GetLocaleInfoW LocalSize LocalReAlloc LocalFlags GetFullPathNameW lstrlenW OpenFile _lclose GetThreadLocale GetSystemDirectoryW LocalAlloc GetACP FreeLibrary GetModuleHandleW LoadLibraryW GetProcAddress LocalFree GetSystemDefaultLCID IsDBCSLeadByteEx MultiByteToWideChar WideCharToMultiByte GetCurrentThreadId InterlockedDecrement LocalLock LocalUnlock HeapFree InterlockedIncrement QueryPerformanceCounter GetTickCount GetSystemTimeAsFileTime TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter GlobalFree lstrcmpW BaseCheckAppcompatCache |
GDI32.dll |
CreateCompatibleDC
DeleteDC DeleteObject BitBlt GetStockObject SelectObject Rectangle PatBlt TranslateCharsetInfo CreateDIBitmap GetDIBits ExtTextOutW GetTextMetricsW GetTextExtentPoint32W CreateDCW GetObjectW CreateFontIndirectW SetBkColor CreateCompatibleBitmap |
MSCTF.dll |
CtfImeProcessCicHotkey
CtfImeDestroyInputContext TF_CreateLangBarMgr CtfImeGetGuidAtom CtfImeIsGuidMapEnable CtfImeCreateInputContext TF_Notify TF_SetDefaultRemoteKeyboardLayout TF_GetCompatibleKeyboardLayout CtfImeCreateThreadMgr CtfImeDestroyThreadMgr CtfImeDispatchDefImeMessage TF_CleanUpPrivateMessages TF_CanUninitialize CtfImeEscapeEx CtfImeInquireExW CtfImeInquire CtfImeConversionList CtfImeRegisterWord CtfImeUnregisterWord CtfImeGetRegisterWordStyle CtfImeEnumRegisterWord CtfImeConfigure CtfImeDestroy CtfImeEscape CtfImeProcessKey CtfImeSelect CtfImeSetActiveContext CtfImeToAsciiEx CtfNotifyIME CtfImeSetCompositionString TF_GetAppCompatFlags CtfImeSetFocus CtfImeSelectEx CtfImeAssociateFocus TF_MapCompatibleKeyboardTip |
Ordinal | 1 |
---|---|
Address | 0x15ed7 |
Ordinal | 2 |
---|---|
Address | 0x3f7e |
Ordinal | 3 |
---|---|
Address | 0x1579 |
Ordinal | 4 |
---|---|
Address | 0x4ab7 |
Ordinal | 5 |
---|---|
Address | 0xbf72 |
Ordinal | 6 |
---|---|
Address | 0x15ec7 |
Ordinal | 7 |
---|---|
Address | 0x15cae |
Ordinal | 8 |
---|---|
Address | 0x15eed |
Ordinal | 9 |
---|---|
Address | 0x36da |
Ordinal | 10 |
---|---|
Address | 0x15c51 |
Ordinal | 11 |
---|---|
Address | 0x15e93 |
Ordinal | 12 |
---|---|
Address | 0x4466 |
Ordinal | 13 |
---|---|
Address | 0x15d27 |
Ordinal | 14 |
---|---|
Address | 0x2d3c |
Ordinal | 15 |
---|---|
Address | 0x4259 |
Ordinal | 16 |
---|---|
Address | 0x4ad0 |
Ordinal | 17 |
---|---|
Address | 0x152d |
Ordinal | 18 |
---|---|
Address | 0x15c1a |
Ordinal | 19 |
---|---|
Address | 0x4648 |
Ordinal | 20 |
---|---|
Address | 0x2e7c |
Ordinal | 21 |
---|---|
Address | 0x15eb7 |
Ordinal | 22 |
---|---|
Address | 0x2ed6 |
Ordinal | 23 |
---|---|
Address | 0xbc7d |
Ordinal | 24 |
---|---|
Address | 0x9b87 |
Ordinal | 25 |
---|---|
Address | 0x3515 |
Ordinal | 26 |
---|---|
Address | 0x6449 |
Ordinal | 27 |
---|---|
Address | 0x14e3a |
Ordinal | 28 |
---|---|
Address | 0x9cde |
Ordinal | 29 |
---|---|
Address | 0x9eac |
Ordinal | 30 |
---|---|
Address | 0x4c0c |
Ordinal | 31 |
---|---|
Address | 0x3a10 |
Ordinal | 32 |
---|---|
Address | 0xfa86 |
Ordinal | 33 |
---|---|
Address | 0x4ba0 |
Ordinal | 34 |
---|---|
Address | 0x3fef |
Ordinal | 35 |
---|---|
Address | 0xfc16 |
Ordinal | 36 |
---|---|
Address | 0x35ab |
Ordinal | 37 |
---|---|
Address | 0x35ab |
Ordinal | 38 |
---|---|
Address | 0x15ead |
Ordinal | 39 |
---|---|
Address | 0x40d2 |
Ordinal | 40 |
---|---|
Address | 0xca4e |
Ordinal | 41 |
---|---|
Address | 0xcbac |
Ordinal | 42 |
---|---|
Address | 0xa08a |
Ordinal | 43 |
---|---|
Address | 0xa309 |
Ordinal | 44 |
---|---|
Address | 0xa548 |
Ordinal | 45 |
---|---|
Address | 0xbe02 |
Ordinal | 46 |
---|---|
Address | 0x443d |
Ordinal | 47 |
---|---|
Address | 0x8da2 |
Ordinal | 48 |
---|---|
Address | 0x8d6c |
Ordinal | 49 |
---|---|
Address | 0x8d87 |
Ordinal | 50 |
---|---|
Address | 0x8dc3 |
Ordinal | 51 |
---|---|
Address | 0x2d87 |
Ordinal | 52 |
---|---|
Address | 0x6c07 |
Ordinal | 53 |
---|---|
Address | 0x6ca3 |
Ordinal | 54 |
---|---|
Address | 0x84b9 |
Ordinal | 55 |
---|---|
Address | 0x77b0 |
Ordinal | 56 |
---|---|
Address | 0x2d44 |
Ordinal | 57 |
---|---|
Address | 0x299d |
Ordinal | 58 |
---|---|
Address | 0x7c96 |
Ordinal | 59 |
---|---|
Address | 0x7de6 |
Ordinal | 60 |
---|---|
Address | 0x37dc |
Ordinal | 61 |
---|---|
Address | 0x27f2 |
Ordinal | 62 |
---|---|
Address | 0xab9d |
Ordinal | 63 |
---|---|
Address | 0xafd3 |
Ordinal | 64 |
---|---|
Address | 0x8de4 |
Ordinal | 65 |
---|---|
Address | 0x8e05 |
Ordinal | 66 |
---|---|
Address | 0x91b4 |
Ordinal | 67 |
---|---|
Address | 0xbc14 |
Ordinal | 68 |
---|---|
Address | 0xbc60 |
Ordinal | 69 |
---|---|
Address | 0xbdc3 |
Ordinal | 70 |
---|---|
Address | 0xb1b9 |
Ordinal | 71 |
---|---|
Address | 0xb076 |
Ordinal | 72 |
---|---|
Address | 0x2dd7 |
Ordinal | 73 |
---|---|
Address | 0x1594e |
Ordinal | 74 |
---|---|
Address | 0x15975 |
Ordinal | 75 |
---|---|
Address | 0x6766 |
Ordinal | 76 |
---|---|
Address | 0x4af6 |
Ordinal | 77 |
---|---|
Address | 0xc848 |
Ordinal | 78 |
---|---|
Address | 0xc94f |
Ordinal | 79 |
---|---|
Address | 0x6799 |
Ordinal | 80 |
---|---|
Address | 0xc0a8 |
Ordinal | 81 |
---|---|
Address | 0x106d3 |
Ordinal | 82 |
---|---|
Address | 0x1069f |
Ordinal | 83 |
---|---|
Address | 0x10610 |
Ordinal | 84 |
---|---|
Address | 0x10504 |
Ordinal | 85 |
---|---|
Address | 0x103a8 |
Ordinal | 86 |
---|---|
Address | 0x10280 |
Ordinal | 87 |
---|---|
Address | 0xbace |
Ordinal | 88 |
---|---|
Address | 0xb7e1 |
Ordinal | 89 |
---|---|
Address | 0x2ceb |
Ordinal | 90 |
---|---|
Address | 0xbd81 |
Ordinal | 91 |
---|---|
Address | 0xbda2 |
Ordinal | 92 |
---|---|
Address | 0x2fc6 |
Ordinal | 93 |
---|---|
Address | 0x4356 |
Ordinal | 94 |
---|---|
Address | 0x2730 |
Ordinal | 95 |
---|---|
Address | 0x2827 |
Ordinal | 96 |
---|---|
Address | 0x2967 |
Ordinal | 97 |
---|---|
Address | 0x2ac6 |
Ordinal | 98 |
---|---|
Address | 0x49cd |
Ordinal | 99 |
---|---|
Address | 0x48bf |
Ordinal | 100 |
---|---|
Address | 0x1599c |
Ordinal | 101 |
---|---|
Address | 0xbc3a |
Ordinal | 102 |
---|---|
Address | 0x25b2 |
Ordinal | 103 |
---|---|
Address | 0xc0f3 |
Ordinal | 104 |
---|---|
Address | 0xc230 |
Ordinal | 105 |
---|---|
Address | 0x2a67 |
Ordinal | 106 |
---|---|
Address | 0x912a |
Ordinal | 107 |
---|---|
Address | 0x9148 |
Ordinal | 108 |
---|---|
Address | 0x10441 |
Ordinal | 109 |
---|---|
Address | 0x10426 |
Ordinal | 110 |
---|---|
Address | 0x2b63 |
Ordinal | 111 |
---|---|
Address | 0x14f8d |
Ordinal | 112 |
---|---|
Address | 0x6eb9 |
Ordinal | 113 |
---|---|
Address | 0x6d3f |
Ordinal | 114 |
---|---|
Address | 0x47ef |
Ordinal | 115 |
---|---|
Address | 0x9166 |
Ordinal | 116 |
---|---|
Address | 0x918d |
Ordinal | 117 |
---|---|
Address | 0x4772 |
Ordinal | 118 |
---|---|
Address | 0x4c7d |
Ordinal | 119 |
---|---|
Address | 0x2596 |
ForwardName | USER32.CliImmSetHotKey |
Ordinal | 120 |
---|---|
Address | 0x4d84 |
Ordinal | 121 |
---|---|
Address | 0x6e51 |
Ordinal | 122 |
---|---|
Address | 0xfc27 |
Ordinal | 123 |
---|---|
Address | 0x964c |
Ordinal | 124 |
---|---|
Address | 0xbd2a |
Ordinal | 125 |
---|---|
Address | 0xfdb9 |
Ordinal | 126 |
---|---|
Address | 0x27a0 |
Ordinal | 127 |
---|---|
Address | 0x28a8 |
Ordinal | 128 |
---|---|
Address | 0x2982 |
Ordinal | 129 |
---|---|
Address | 0x2a79 |
Ordinal | 130 |
---|---|
Address | 0xc37f |
Ordinal | 131 |
---|---|
Address | 0xc4bc |
Ordinal | 132 |
---|---|
Address | 0x10171 |
Ordinal | 133 |
---|---|
Address | 0x10198 |
Ordinal | 134 |
---|---|
Address | 0x15ead |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.1.7601.17514 |
ProductVersion | 6.1.7601.17514 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Multi-User Windows IMM32 API Client DLL |
FileVersion (#2) | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | imm32 |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | imm32 |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.1.7601.17514 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:06:58 |
Version | 0.0 |
SizeofData | 34 |
AddressOfRawData | 0x176b0 |
PointerToRawData | 0x16ab0 |
Referenced File | imm32.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:06:58 |
Version | 565.6526 |
SizeofData | 4 |
AddressOfRawData | 0x176ac |
PointerToRawData | 0x16aac |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x75a58198 |
SEHandlerTable | 0x75a45da0 |
SEHandlerCount | 2 |
XOR Key | 0x618b0652 |
---|---|
Unmarked objects | 0 |
ASM objects (VS2008 SP1 build 30729) | 4 |
Imports (VS2008 SP1 build 30729) | 15 |
Total imports | 209 |
Exports (VS2008 SP1 build 30729) | 1 |
C objects (VS2008 SP1 build 30729) | 37 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |