| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2010-Sep-09 06:18:35 |
| Debug artifacts |
DLL\proRFL\proRFL\Debug\proRFL.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ Microsoft Visual C++ v6.0 Microsoft Visual C++ v6.0 (Debug Version) |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 59 bytes of data starting at offset 0x3c000. |
| Safe | VirusTotal score: 0/71 (Scanned on 2025-03-17 10:31:36) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2010-Sep-09 06:18:35 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x30000 |
| SizeOfInitializedData | 0xd000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00007040 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x1000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3e000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
Sleep
SetEnvironmentVariableA CompareStringW CompareStringA FlushFileBuffers SetStdHandle SetFilePointer GetLocaleInfoW GetTimeZoneInformation GetOEMCP InterlockedDecrement InterlockedIncrement GetCommandLineA GetVersion InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection ExitProcess FatalAppExitA WideCharToMultiByte MultiByteToWideChar LCMapStringA LCMapStringW DebugBreak GetStdHandle WriteFile OutputDebugStringA GetProcAddress LoadLibraryA GetModuleFileNameA GetCurrentThreadId TlsSetValue TlsAlloc TlsFree SetLastError TlsGetValue GetLastError GetCurrentThread TerminateProcess GetCurrentProcess SetHandleCount GetFileType GetStartupInfoA IsBadWritePtr IsBadReadPtr HeapValidate FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW GetModuleHandleA GetEnvironmentVariableA GetVersionExA HeapDestroy HeapCreate HeapFree VirtualFree GetCPInfo IsValidLocale IsValidCodePage GetLocaleInfoA EnumSystemLocalesA GetUserDefaultLCID RtlUnwind GetStringTypeA GetStringTypeW SetConsoleCtrlHandler UnhandledExceptionFilter HeapAlloc HeapReAlloc VirtualAlloc GetACP CloseHandle |
|---|---|
| d12.dll |
readPortb
writePortb IniUsb |
| d12c.dll |
writePortPro
IniUsbPro CloseHandles readPortPro |
| Ordinal | 1 |
|---|---|
| Address | 0x104b |
| Ordinal | 2 |
|---|---|
| Address | 0x1014 |
| Ordinal | 3 |
|---|---|
| Address | 0x10be |
| Ordinal | 4 |
|---|---|
| Address | 0x1005 |
| Ordinal | 5 |
|---|---|
| Address | 0x100f |
| Ordinal | 6 |
|---|---|
| Address | 0x1091 |
| Ordinal | 7 |
|---|---|
| Address | 0x10b4 |
| Ordinal | 8 |
|---|---|
| Address | 0x1032 |
| Ordinal | 9 |
|---|---|
| Address | 0x1096 |
| Ordinal | 10 |
|---|---|
| Address | 0x100a |
| Ordinal | 11 |
|---|---|
| Address | 0x10a0 |
| Ordinal | 12 |
|---|---|
| Address | 0x102d |
| Ordinal | 13 |
|---|---|
| Address | 0x1041 |
| Ordinal | 14 |
|---|---|
| Address | 0x1028 |
| Ordinal | 15 |
|---|---|
| Address | 0x10aa |
| Ordinal | 16 |
|---|---|
| Address | 0x10af |
| Ordinal | 17 |
|---|---|
| Address | 0x1087 |
| Ordinal | 18 |
|---|---|
| Address | 0x10a5 |
| Ordinal | 19 |
|---|---|
| Address | 0x107d |
| Ordinal | 20 |
|---|---|
| Address | 0x105f |
| Ordinal | 21 |
|---|---|
| Address | 0x108c |
| Ordinal | 22 |
|---|---|
| Address | 0x1073 |
| Ordinal | 23 |
|---|---|
| Address | 0x1050 |
| Ordinal | 24 |
|---|---|
| Address | 0x1069 |
| Ordinal | 25 |
|---|---|
| Address | 0x1023 |
| Ordinal | 26 |
|---|---|
| Address | 0x1037 |
| Ordinal | 27 |
|---|---|
| Address | 0x10b9 |
| Ordinal | 28 |
|---|---|
| Address | 0x1046 |
| Ordinal | 29 |
|---|---|
| Address | 0x1055 |
| Ordinal | 30 |
|---|---|
| Address | 0x1064 |
| Ordinal | 31 |
|---|---|
| Address | 0x10c8 |
| Ordinal | 32 |
|---|---|
| Address | 0x109b |
| Ordinal | 33 |
|---|---|
| Address | 0x1019 |
| Ordinal | 34 |
|---|---|
| Address | 0x106e |
| Ordinal | 35 |
|---|---|
| Address | 0x10c3 |
| Ordinal | 36 |
|---|---|
| Address | 0x101e |
| Ordinal | 37 |
|---|---|
| Address | 0x105a |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2010-Sep-09 06:18:16 |
| Version | 0.0 |
| SizeofData | 59 |
| AddressOfRawData | 0 |
| PointerToRawData | 0x3c000 |
| Referenced File | DLL\proRFL\proRFL\Debug\proRFL.pdb |
| XOR Key | 0x8378b9a1 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS98 SP6 build 8804) | 1 |
| 14 (7299) | 20 |
| C objects (VS98 SP6 build 8804) | 83 |
| 19 (8034) | 3 |
| Total imports | 81 |
| C++ objects (VS98 build 8168) | 1 |
| Linker (VS98 build 8168) | 5 |
No comments yet.