| PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1524a<BR>timedatestamp.....: 0x492a18f5 (Mon Nov 24 03:01:09 2008)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 7 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x1943a 0x1a000 6.16 d54a962d1f185499196c4ecfcff4141f<BR>.rdata 0x1b000 0x6248 0x7000 6.68 6be80c351336d8c8b8694dbeb2239318<BR>.data 0x22000 0x4234 0x2000 3.66 38aa3fef9e7b465c28db5f4cc89edd15<BR>Shared_T 0x27000 0x10 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<BR>Shared_H 0x28000 0x20 0x1000 0.00 329be86fbc505430e3adcad57e1ccd2e<BR>.rsrc 0x29000 0x3d8 0x1000 1.06 b8892a998b5bd75b204a009dd936a608<BR>.reloc 0x2a000 0x2b38 0x3000 5.39 fd37af5fd690d9f7529d6d3b212e0b53<BR><BR>( 11 imports ) <BR>> KERNEL32.dll: UnmapViewOfFile, LeaveCriticalSection, EnterCriticalSection, GetShortPathNameA, GetSystemDirectoryA, GetWindowsDirectoryA, OpenMutexA, lstrcmpA, MapViewOfFile, GetTempPathA, LoadLibraryA, OpenFileMappingA, GetModuleFileNameW, CreateMutexA, GetLastError, TlsSetValue, VirtualProtect, GetLongPathNameA, TlsFree, TlsAlloc, VirtualQuery, IsBadWritePtr, lstrlenA, lstrcpynW, lstrcpynA, GetSystemTime, SystemTimeToFileTime, TlsGetValue, GetModuleFileNameA, GetCommandLineA, GetVersionExA, CreateFileMappingA, SetLastError, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, GetExitCodeThread, DeleteCriticalSection, InitializeCriticalSection, WaitForMultipleObjects, SetEvent, CreateEventA, CreateThread, WaitForSingleObject, TerminateThread, lstrcmpiA, GetVersion, GetCurrentProcessId, Module32First, Module32Next, CloseHandle, GetModuleHandleA, GetCurrentProcess, FlushInstructionCache, GetSystemInfo, GetProcAddress, Sleep, GetPrivateProfileStructA, WritePrivateProfileStructA, GetFileSize, WriteFile, InterlockedDecrement, CreateFileA, DeleteFileA, lstrcatA, CopyFileA, CreateProcessA, LocalFree, GetACP, LoadLibraryW, LoadLibraryExA, ReadProcessMemory, FreeLibrary, MoveFileExA, CreateDirectoryA, FindClose, FindNextFileA, FindFirstFileA, CreateFileW, ReadFile, GetTickCount<BR>> USER32.dll: IsWindow, PostMessageA, RegisterWindowMessageA, FindWindowExA, FindWindowA, GetClassNameA, SetTimer, EnumWindows, GetParent, GetWindowTextA, CallNextHookEx, UnhookWindowsHookEx, KillTimer, DestroyWindow, PostQuitMessage, GetClassInfoExA, RegisterClassExA, CreateWindowExA, SetWindowLongA, GetWindowLongA, DefWindowProcA, GetMessageA, TranslateMessage, DispatchMessageA, SendMessageA, GetWindowThreadProcessId<BR>> GDI32.dll: GetStockObject<BR>> ADVAPI32.dll: OpenProcessToken, GetLengthSid, RegSetValueExA, RegCreateKeyExA, RegDeleteValueA, RegOpenKeyA, RegEnumKeyExA, RegQueryValueExA, RegEnumKeyA, RegEnumValueA, RegCloseKey, RegNotifyChangeKeyValue, RegOpenKeyExA, CloseServiceHandle, CreateServiceA, OpenSCManagerA, DeleteService, OpenServiceA, QueryServiceStatus, StartServiceA, ControlService, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, CreateProcessAsUserW, SetTokenInformation, DuplicateTokenEx<BR>> ole32.dll: StringFromCLSID, CoCreateGuid, CoTaskMemFree<BR>> OLEAUT32.dll: -, -<BR>> SHLWAPI.dll: PathRemoveBackslashA, PathStripToRootA, PathIsDirectoryA, PathRemoveFileSpecA, PathFindExtensionA, PathRemoveExtensionA, PathRemoveBlanksA, PathAddExtensionA, PathAppendA, SHDeleteKeyA, SHDeleteValueA, SHSetValueA, SHGetValueA, PathFindFileNameA, StrStrIA, PathFileExistsA<BR>> MSVCRT.dll: fputs, fgets, rewind, fopen, wcslen, fwrite, strrchr, fread, ftell, malloc, __dllonexit, _onexit, __1type_info@@UAE@XZ, _initterm, _adjust_fdiv, fclose, strchr, _mbstok, atoi, _tempnam, rename, _ltoa, _snwprintf, sscanf, _mbsnbcpy, strstr, _mbscmp, time, srand, _mbschr, _mbsnbicmp, strncpy, _snprintf, rand, _mbsicmp, _CxxThrowException, memmove, realloc, free, _purecall, __CxxFrameHandler, __2@YAPAXI@Z, __3@YAXPAX@Z, _stricmp, _wcsicmp, _strnicmp, _strlwr, _wcsnicmp, strncat, fseek, _except_handler3<BR>> WS2_32.dll: -, -, -, -<BR>> VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA<BR>> SHELL32.dll: SHGetSpecialFolderPathA<BR><BR>( 6 exports ) <BR>DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer, Rundll32, Rundll32_<BR> |