Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2016-Jun-15 08:38:34 |
Detected languages |
English - United States
|
Debug artifacts |
C:\Users\DarkstaR\Desktop\Writing\Chatpers\Code\GameHackingExamples\bin\Chapter1_MemoryPointers.pdb
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/61 (Scanned on 2017-04-01 08:30:43) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 6 |
TimeDateStamp | 2016-Jun-15 08:38:34 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0xc8800 |
SizeOfInitializedData | 0x37e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000813AA (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xca000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 0.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x10c000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1082f7 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
OPENGL32.dll |
glOrtho
glGetBooleanv glLoadIdentity glMatrixMode glViewport wglGetProcAddress glGetString wglDeleteContext glPixelTransferi glPushMatrix glRasterPos2f glDrawPixels glPopMatrix glTexSubImage2D glReadPixels glGetTexImage glGenTextures glGetError glTexParameteri glPushClientAttrib glTexImage2D glPixelStorei glPopClientAttrib glDeleteTextures glCopyTexSubImage2D glTranslatef glMultMatrixf wglMakeCurrent glDrawElements glColor4f wglCreateContext wglGetCurrentDC wglGetCurrentContext glFlush glGetIntegerv glScissor glEnable glDisable glBlendFunc glClear glClearColor glDisableClientState glDrawArrays glColorPointer glVertexPointer glEnableClientState glTexCoordPointer glBindTexture glLoadMatrixf |
---|---|
WINMM.dll |
timeBeginPeriod
timeEndPeriod timeGetTime |
SHLWAPI.dll |
PathFindOnPathA
|
PSAPI.DLL |
GetModuleFileNameExA
|
MSVCR100.dll |
memcpy
_CIsin _CIcos _endthreadex _beginthreadex abort malloc free realloc calloc tolower strncat isspace strrchr getenv memmove fflush _errno __iob_func wcsrchr _wfullpath _findclose _wfindnext64i32 _wfindfirst64i32 _wstat64i32 _wgetcwd _wchdir _wmkdir _wunlink _wrmdir _snwprintf _wfopen fgetc fwrite ftell fseek feof ferror clearerr ungetc toupper memchr _vsnprintf _beginthread qsort strstr strtol strchr strncmp _CIfmod ceil floor _hypotf _CIsqrt _CIasin _unlock __dllonexit _lock _onexit _amsg_exit __getmainargs _cexit _exit _XcptFilter exit __initenv _initterm _initterm_e _configthreadlocale __setusermatherr _commode _fmode __set_app_type _crt_debugger_hook _except_handler4_common ?terminate@@YAXXZ _invoke_watson _controlfp_s memset _time64 atol ??2@YAPAXI@Z fclose ??3@YAXPAX@Z fread fopen sprintf _fdopen _unlink _close _open longjmp strncpy _setjmp3 vfprintf |
KERNEL32.dll |
Sleep
GetCommandLineA GetCurrentProcess GetTempPathA GetLastError LoadLibraryA InitializeCriticalSection QueryPerformanceFrequency IsProcessorFeaturePresent GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter TerminateProcess HeapSetInformation InterlockedCompareExchange InterlockedExchange DecodePointer EncodePointer FormatMessageA WaitForMultipleObjects CreateWaitableTimerA SetWaitableTimer WideCharToMultiByte MultiByteToWideChar GetModuleHandleA CreateEventA SetEvent GetVersionExA GetFileAttributesW FreeLibrary GetProcAddress QueryPerformanceCounter ReleaseSemaphore CreateSemaphoreA WaitForSingleObject CloseHandle DeleteCriticalSection LeaveCriticalSection EnterCriticalSection GetModuleFileNameA |
USER32.dll |
PostMessageA
DefWindowProcA TrackMouseEvent GetRawInputData GetForegroundWindow SetCursor LoadCursorA EndPaint GetCapture GetUpdateRgn DestroyWindow RegisterWindowMessageA RegisterClassA GetDC ReleaseDC ChangeDisplaySettingsA UpdateWindow SystemParametersInfoA GetKeyState ToUnicode GetKeyboardState MapVirtualKeyA SetCursorPos ClientToScreen CreateIconIndirect MessageBoxW GetWindowTextLengthA SendMessageW SetWindowTextA GetClientRect InvalidateRect PostQuitMessage IsWindow TranslateMessage CreateWindowExW UnregisterClassA SetCapture ReleaseCapture GetWindowLongA SetWindowLongA ShowWindow GetSystemMenu DeleteMenu DrawMenuBar CreateWindowExA AdjustWindowRectEx SetWindowPos SetForegroundWindow PeekMessageA GetMessageA DispatchMessageA ChangeDisplaySettingsExA GetWindowInfo SendMessageA GetWindowRect ClipCursor FindWindowA GetSystemMetrics DestroyIcon GetWindowThreadProcessId MoveWindow PostThreadMessageA EnumDisplayDevicesA GetCursorPos EnumDisplaySettingsA BeginPaint |
GDI32.dll |
ChoosePixelFormat
CreateRectRgn SwapBuffers StretchDIBits GetRegionData DescribePixelFormat SetPixelFormat CreateCompatibleDC GetStockObject CreateFontA DeleteObject CreateBitmap CreateCompatibleBitmap SelectObject SetPixel DeleteDC |
COMDLG32.dll |
GetOpenFileNameA
GetSaveFileNameA |
SHELL32.dll |
SHBrowseForFolderA
SHGetPathFromIDListA SHGetFolderPathA |
ole32.dll |
CoInitialize
CoUninitialize |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Jun-15 08:38:34 |
Version | 0.0 |
SizeofData | 124 |
AddressOfRawData | 0xe1b38 |
PointerToRawData | 0xe0738 |
Referenced File | C:\Users\DarkstaR\Desktop\Writing\Chatpers\Code\GameHackingExamples\bin\Chapter1_MemoryPointers.pdb |
StartAddressOfRawData | 0x500000 |
---|---|
EndAddressOfRawData | 0x5000e8 |
AddressOfIndex | 0x4fe27c |
AddressOfCallbacks | 0x4ca4c0 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_TYPE_REG
|
Callbacks | (EMPTY) |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x4f6cbc |
SEHandlerTable | 0x4e1bc0 |
SEHandlerCount | 1 |
XOR Key | 0x36f94ecd |
---|---|
Unmarked objects | 0 |
152 (20115) | 4 |
Imports (VS2010 SP1 build 40219) | 2 |
ASM objects (VS2010 SP1 build 40219) | 7 |
C++ objects (VS2010 SP1 build 40219) | 5 |
C objects (VS2010 SP1 build 40219) | 113 |
Imports (VS2008 SP1 build 30729) | 21 |
Total imports | 282 |
175 (VS2010 SP1 build 40219) | 1 |
Linker (VS2010 SP1 build 40219) | 1 |