| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Dec-19 09:34:39 |
| Detected languages |
English - United States
|
| Debug artifacts |
d:\My Projects\wjxtdAutoPro - reset\release\wjxtdAutoPro.pdb
|
| FileDescription | wjxtdAuto Pro DLL |
| FileVersion | 1, 0, 2, 2 |
| LegalCopyright | holyiii@yahoo.com |
| LegalTrademarks | wjxtdAuto Pro |
| OriginalFilename | wjxtdAutoPro.dll |
| ProductName | wjxtdAuto Pro |
| ProductVersion | 1, 0, 0, 1 |
| Info | Matching compiler(s): |
Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8.0 MSVC++ v.8 (procedure 1 recognized - h) |
| Suspicious | PEiD Signature: | PeStubOEP v1.x |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2025-11-29 01:06:28) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2012-Dec-19 09:34:39 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 8.0 |
| SizeOfCode | 0x7f000 |
| SizeOfInitializedData | 0x27000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00061045 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x80000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xf3000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0xa9d8a |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WS2_32.dll |
inet_ntoa
gethostbyname |
|---|---|
| KERNEL32.dll |
GetCurrentProcessId
GetTickCount GetModuleFileNameA DisableThreadLibraryCalls InterlockedExchange WideCharToMultiByte CompareStringW FreeLibrary CompareStringA MultiByteToWideChar GetLastError LoadLibraryA ResumeThread ReadProcessMemory VirtualProtect GetCurrentThreadId SuspendThread GetThreadContext SetThreadContext VirtualQuery GetCurrentProcess InterlockedCompareExchange GetCurrentThread FlushInstructionCache VirtualAlloc SetLastError WriteFile CloseHandle SetFilePointer GetProcAddress GetModuleHandleA GetPrivateProfileStringA FindResourceA SizeofResource LockResource FindResourceExA GetPrivateProfileIntA LoadResource OpenProcess FreeConsole GetStdHandle AllocConsole FreeEnvironmentStringsA FlushFileBuffers ReadFile GetStartupInfoA SetHandleCount GetConsoleMode GetConsoleCP GetTimeZoneInformation IsValidCodePage GetOEMCP VirtualFree HeapCreate ExitProcess GetEnvironmentStrings TlsFree TlsSetValue TlsAlloc TlsGetValue LCMapStringW LCMapStringA GetCPInfo RtlUnwind GetCommandLineA GetFileType QueryPerformanceCounter SetEnvironmentVariableA SetEndOfFile CreateFileA WriteConsoleW GetConsoleOutputCP WriteConsoleA GetLocaleInfoW GetStringTypeW GetStringTypeA IsValidLocale EnumSystemLocalesA GetUserDefaultLCID GetEnvironmentStringsW FreeEnvironmentStringsW GetACP GetLocaleInfoA GetThreadLocale GetVersionExA HeapDestroy HeapAlloc HeapFree HeapReAlloc HeapSize GetProcessHeap RaiseException EnterCriticalSection LeaveCriticalSection InitializeCriticalSection DeleteCriticalSection InterlockedIncrement InterlockedDecrement Sleep TerminateProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent GetSystemTimeAsFileTime SetStdHandle |
| USER32.dll |
GetForegroundWindow
GetKeyState EnumWindows GetClassNameW PostMessageA GetAsyncKeyState DestroyWindow SetWindowLongA IsWindow CallWindowProcA UnhookWindowsHookEx IsWindowUnicode CallWindowProcW SendMessageA SetWindowLongW PostQuitMessage SendMessageW GetWindowThreadProcessId CallNextHookEx SetWindowsHookExA UnregisterClassA |
| engine.dll |
?GetGlobal@KJxScript@@QAEHPBD@Z
?GetTableField@KJxScript@@QAEHHPBD@Z ?PushNumber@KJxScript@@QAEHN@Z ?PushString@KJxScript@@QAEHPBD@Z ?PushTable@KJxScript@@QAEHXZ ?SetTableField@KJxScript@@QAEHPBD@Z ?SetTableIndex@KJxScript@@QAEHH@Z ?SetTopIndex@KJxScript@@QAEHH@Z ?CallTableFunction@KJxScript@@QAAHPBD0H0ZZ ?PopStack@KJxScript@@QAEHH@Z ?CallGlobalFunction@KJxScript@@QAAHPBDH0ZZ ?DoBuffer@KJxScript@@QAEHPBD0@Z ?GetInt@KJxScript@@QAEHH@Z ?GetTopIndex@KJxScript@@QAEHXZ |
| WINMM.dll |
timeGetTime
|
| Ordinal | 1 |
|---|---|
| Address | 0x14d0 |
| Ordinal | 2 |
|---|---|
| Address | 0x1540 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.2.2 |
| ProductVersion | 1.0.0.1 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| FileDescription | wjxtdAuto Pro DLL |
| FileVersion (#2) | 1, 0, 2, 2 |
| LegalCopyright | holyiii@yahoo.com |
| LegalTrademarks | wjxtdAuto Pro |
| OriginalFilename | wjxtdAutoPro.dll |
| ProductName | wjxtdAuto Pro |
| ProductVersion (#2) | 1, 0, 0, 1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2012-Dec-19 09:34:39 |
| Version | 0.0 |
| SizeofData | 85 |
| AddressOfRawData | 0x8c250 |
| PointerToRawData | 0x8c250 |
| Referenced File | d:\My Projects\wjxtdAutoPro - reset\release\wjxtdAutoPro.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x100964c8 |
| SEHandlerTable | 0x1008f370 |
| SEHandlerCount | 222 |
| XOR Key | 0x164860cf |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 34 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 158 |
| Imports (VS2012 build 50727 / VS2005 build 50727) | 2 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 72 |
| Total imports | 171 |
| Imports (VS2003 (.NET) build 4035) | 9 |
| 114 (VS2012 build 50727 / VS2005 build 50727) | 139 |
| Exports (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Resource objects (VS2012 build 50727 / VS2005 build 50727) | 1 |
| Linker (VS2012 build 50727 / VS2005 build 50727) | 1 |
No comments yet.