| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Feb-15 05:51:59 |
| Detected languages |
Chinese - Taiwan
|
| CompanyName | Megawin Technology Co., Ltd. |
| FileDescription | DFU Dynamic Link Library |
| FileVersion | 1, 1, 5, 0 |
| InternalName | DFU.DLL |
| LegalCopyright | Copyright (C) 2009 |
| OriginalFilename | DFU.dll |
| ProductName | Megawin DFU |
| ProductVersion | 1, 1, 5, 0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 DLL (Debug) Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ Microsoft Visual C++ v6.0 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/63 (Scanned on 2026-05-13 04:47:37) | Cynet: Malicious (score: 100) |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2012-Feb-15 05:51:59 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 6.0 |
| SizeOfCode | 0x5000 |
| SizeOfInitializedData | 0x7000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000019FC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x6000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xd000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
Sleep
OutputDebugStringA WriteFile CancelIo CreateFileA CloseHandle HeapFree HeapAlloc GetCommandLineA GetVersion GetModuleHandleA GetModuleFileNameA GetEnvironmentVariableA GetVersionExA HeapDestroy HeapCreate VirtualFree VirtualAlloc HeapReAlloc InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection ExitProcess RtlUnwind TerminateProcess GetCurrentProcess GetCurrentThreadId TlsSetValue TlsAlloc TlsFree SetLastError TlsGetValue GetLastError SetHandleCount GetStdHandle GetFileType GetStartupInfoA FreeEnvironmentStringsA FreeEnvironmentStringsW WideCharToMultiByte GetEnvironmentStrings GetEnvironmentStringsW GetCPInfo GetACP GetOEMCP GetProcAddress LoadLibraryA InterlockedDecrement InterlockedIncrement MultiByteToWideChar LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW |
|---|---|
| CFGMGR32.dll |
CMP_WaitNoPendingInstallEvents
|
| HID.DLL |
HidD_GetHidGuid
HidD_GetAttributes HidD_GetPreparsedData HidD_SetFeature HidD_GetFeature HidP_GetCaps HidD_FreePreparsedData |
| SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
SetupDiGetDeviceInterfaceDetailA SetupDiDestroyDeviceInfoList SetupDiGetClassDevsA |
| Ordinal | 1 |
|---|---|
| Address | 0x1420 |
| Ordinal | 2 |
|---|---|
| Address | 0x16c0 |
| Ordinal | 3 |
|---|---|
| Address | 0x13d0 |
| Ordinal | 4 |
|---|---|
| Address | 0x1370 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.5.0 |
| ProductVersion | 1.1.5.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | Chinese - Taiwan |
| CompanyName | Megawin Technology Co., Ltd. |
| FileDescription | DFU Dynamic Link Library |
| FileVersion (#2) | 1, 1, 5, 0 |
| InternalName | DFU.DLL |
| LegalCopyright | Copyright (C) 2009 |
| OriginalFilename | DFU.dll |
| ProductName | Megawin DFU |
| ProductVersion (#2) | 1, 1, 5, 0 |
| Resource LangID | Chinese - Taiwan |
|---|
| XOR Key | 0x8a8c3a22 |
|---|---|
| Unmarked objects | 0 |
| 14 (7299) | 20 |
| C objects (VS98 SP6 build 8804) | 56 |
| Imports (9210) | 4 |
| Imports (VS2003 (.NET) build 4035) | 2 |
| 19 (8034) | 3 |
| Total imports | 81 |
| C++ objects (VS98 SP6 build 8804) | 3 |
| Resource objects (VS98 SP6 cvtres build 1736) | 1 |
| Linker (VC++ 6.0 SP5 imp/exp build 8447) | 1 |
No comments yet.