Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2005-Oct-02 11:01:22 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
Embedded COFF debugging symbols
|
Comments | http://www.whitetown.com |
CompanyName | WhiteTown Software |
FileDescription | DBF2XLS |
FileVersion | 1, 4, 0, 0 |
InternalName | DBF2XLS |
LegalCopyright | Copyright ? 2005 |
LegalTrademarks | DBF to XLS |
OriginalFilename | DBF2XLS.exe |
ProductName | DBF to XLS |
ProductVersion | 1, 4, 0, 0 |
Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig1(h) Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v5.0/v6.0 (MFC) |
Suspicious | The PE is possibly packed. |
Section .text is both writable and executable.
Section .rdata is both writable and executable. Section .data is both writable and executable. Section .rsrc is both writable and executable. |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE's resources present abnormal characteristics. | Resource 102 is possibly compressed or encrypted. |
Suspicious | VirusTotal score: 1/57 (Scanned on 2016-12-02 10:13:37) | CrowdStrike: malicious_confidence_67% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2005-Oct-02 11:01:22 |
PointerToSymbolTable | 0x726f4c5b |
NumberOfSymbols | 1564823652 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 6.0 |
SizeOfCode | 0x1d000 |
SizeOfInitializedData | 0x8a000 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000B2FA (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x1e000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x1000 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xa9000 |
SizeOfHeaders | 0x1000 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
advapi32.dll |
RegCloseKey
RegCreateKeyA RegSetValueExA RegOpenKeyA RegQueryValueExA |
---|---|
comctl32.dll |
PropertySheet
CreatePropertySheetPage InitCommonControls |
gdi32.dll |
SetMapMode
SetViewportOrgEx GetStockObject SelectObject RestoreDC SaveDC Escape ExtTextOutA TextOutA RectVisible PtVisible DeleteDC DeleteObject CreateFontIndirectA GetDeviceCaps GetTextMetricsA CreateBitmap GetObjectA SetBkColor SetTextColor GetClipBox ScaleWindowExtEx SetWindowExtEx ScaleViewportExtEx SetViewportExtEx OffsetViewportOrgEx |
kernel32.dll |
CreateThread
DeleteFileA FindFirstFileA FindNextFileA FindClose GetPrivateProfileIntA GetPrivateProfileStringA GetModuleFileNameA WritePrivateProfileStringA SetEndOfFile GetSystemTime lstrlen lstrcat CreateFileA SetFilePointer ReadFile WriteFile CloseHandle lstrcpy HeapAlloc HeapFree GetLastError InterlockedDecrement InterlockedIncrement ExitProcess TerminateProcess GetCurrentProcess GetTimeZoneInformation GetLocalTime RtlUnwind GetModuleHandleA GetStartupInfoA GetCommandLineA GetVersion HeapDestroy HeapCreate VirtualFree InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection VirtualAlloc HeapReAlloc IsBadWritePtr GetProcAddress GetCPInfo GetACP GetOEMCP WideCharToMultiByte MultiByteToWideChar LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetCurrentThreadId TlsSetValue TlsAlloc SetLastError TlsGetValue UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW LockResource GetStdHandle GetFileType SetStdHandle FlushFileBuffers SetUnhandledExceptionFilter IsBadReadPtr IsBadCodePtr LoadLibraryA RaiseException CompareStringA CompareStringW SetEnvironmentVariableA lstrcmp lstrcpyn GlobalUnlock GlobalLock GlobalAlloc GlobalReAlloc LocalFree LocalAlloc GlobalFree GlobalHandle LocalReAlloc GlobalDeleteAtom GlobalFindAtomA GlobalAddAtomA lstrcmpi GlobalGetAtomNameA FreeLibrary GetProcessVersion GlobalFlags HeapSize |
odbc32.dll |
SQLCancel
SQLFreeStmt SQLMoreResults SQLFetch SQLNumResultCols SQLExecDirect SQLAllocStmt SQLDriverConnect SQLAllocEnv SQLAllocConnect SQLSetConnectOption SQLGetInfo SQLSetStmtOption SQLFreeEnv SQLDisconnect SQLFreeConnect SQLError |
shell32.dll |
ShellExecuteA
SHGetPathFromIDList SHGetSpecialFolderLocation |
user32.dll |
CopyRect
GetClientRect AdjustWindowRectEx SetFocus GetSysColor MapWindowPoints LoadIconA SetWindowTextA GetSysColorBrush GetClassNameA PtInRect ClientToScreen PostQuitMessage DestroyMenu TabbedTextOutA DrawTextA GrayStringA GetClassInfoA RegisterClassA GetMenu GetMenuItemCount GetSubMenu GetMenuItemID GetDlgCtrlID DefWindowProcA DestroyWindow CreateWindowExA GetClassLongA GetPropA CallWindowProcA RemovePropA GetMessageTime GetMessagePos GetForegroundWindow SetForegroundWindow GetWindow SetWindowPos RegisterClipboardFormatA CharUpperA wsprintfA GetDesktopWindow LoadStringA IsWindowEnabled GetLastActivePopup UnhookWindowsHookEx SetWindowsHookExA PeekMessageA CallNextHookEx GetKeyState GetTopWindow GetCapture DispatchMessageA CharToOemA UpdateWindow CheckDlgButton EnableWindow CheckRadioButton InvalidateRect IsDlgButtonChecked LoadCursorA SetCursor OemToCharA GetWindowLongA SetWindowLongA SendMessageA GetParent PostMessageA GetDlgItemTextA SetDlgItemTextA GetDlgItem ShowWindow GetWindowTextA GetNextDlgTabItem GetFocus EnableMenuItem SystemParametersInfoA GetDC ReleaseDC MessageBoxA OemToCharBuffA SetPropA WinHelpA IsIconic GetWindowPlacement GetWindowRect GetSystemMetrics GetMenuCheckMarkDimensions LoadBitmapA GetMenuState ModifyMenuA SetMenuItemBitmaps CheckMenuItem |
winspool.drv |
OpenPrinterA
DocumentPropertiesA ClosePrinter |
comdlg32.dll |
GetOpenFileNameA
GetSaveFileNameA |
打开 DBF 文件 |
单击“浏览”按钮 |
选择输出的文件 |
单击“浏览”按钮 |
转换进度 |
这需要花几分钟…… |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.3.0.0 |
ProductVersion | 1.3.0.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
Comments | http://www.whitetown.com |
CompanyName | WhiteTown Software |
FileDescription | DBF2XLS |
FileVersion (#2) | 1, 4, 0, 0 |
InternalName | DBF2XLS |
LegalCopyright | Copyright ? 2005 |
LegalTrademarks | DBF to XLS |
OriginalFilename | DBF2XLS.exe |
ProductName | DBF to XLS |
ProductVersion (#2) | 1, 4, 0, 0 |
Resource LangID | Chinese - PRC |
---|
XOR Key | 0xd06050da |
---|---|
Unmarked objects | 0 |
19 (8022) | 32 |
12 (7291) | 4 |
14 (7299) | 39 |
Imports (VS97 SP3 link 5.10.7303) | 34 |
Unmarked objects (#2) | 15 |
19 (8034) | 17 |
Total imports | 385 |
C objects (VS98 build 8168) | 157 |
C objects (VC++ 6.0 SP5 build 8804) | 5 |
C++ objects (VS98 build 8168) | 63 |
Resource objects (VS98 cvtres build 1720) | 1 |
Linker (VS98 build 8168) | 1 |