| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2005-Oct-24 01:16:38 |
| Debug artifacts |
f:\mw\Speed\Pc\Install\safemode_inst\safemode_inst\Release\safemode_inst.pdb
|
| Info | Matching compiler(s): |
Microsoft Visual C++ 7.0
Microsoft Visual C++ 7.1 Microsoft Visual C++ 6.0 - 8.0 Microsoft Visual C++ v7.0 Microsoft Visual C++ v7.1 EXE |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Suspicious | VirusTotal score: 1/70 (Scanned on 2026-07-30 19:24:31) | Jiangmin: Trojan/Generic.qvvv |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 3 |
| TimeDateStamp | 2005-Oct-24 01:16:38 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 7.0 |
| SizeOfCode | 0x6000 |
| SizeOfInitializedData | 0x4000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00001706 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x7000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 4.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xb000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
MultiByteToWideChar
LocalFree FormatMessageA VirtualProtect GetLocaleInfoA GetStringTypeW GetStringTypeA ExitProcess GetModuleHandleA GetCommandLineA GetVersionExA QueryPerformanceCounter GetTickCount GetCurrentThreadId GetCurrentProcessId GetSystemTimeAsFileTime GetModuleFileNameA SetHandleCount GetStdHandle GetFileType GetStartupInfoA HeapAlloc GetProcAddress TerminateProcess GetCurrentProcess WriteFile UnhandledExceptionFilter FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW WideCharToMultiByte GetLastError GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree HeapFree LoadLibraryA RtlUnwind InterlockedExchange VirtualQuery VirtualAlloc HeapReAlloc FlushFileBuffers GetACP GetOEMCP GetCPInfo SetFilePointer CloseHandle HeapSize SetStdHandle LCMapStringA LCMapStringW GetSystemInfo |
|---|---|
| ole32.dll |
CoUninitialize
CoCreateInstance CoInitialize |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2005-Oct-24 01:16:38 |
| Version | 0.0 |
| SizeofData | 101 |
| AddressOfRawData | 0x7f78 |
| PointerToRawData | 0x7f78 |
| Referenced File | f:\mw\Speed\Pc\Install\safemode_inst\safemode_inst\Release\safemode_inst.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x409044 |
| SEHandlerTable | 0x407fe0 |
| SEHandlerCount | 2 |
| XOR Key | 0x965c87ad |
|---|---|
| Unmarked objects | 0 |
| C objects (VS2003 (.NET) build 3077) | 57 |
| ASM objects (VS2003 (.NET) build 3077) | 12 |
| C objects (2179) | 1 |
| C objects (9178) | 1 |
| Imports (2179) | 5 |
| Total imports | 58 |
| C++ objects (VS2003 (.NET) build 3077) | 4 |
| Linker (VS2003 (.NET) build 3077) | 1 |
No comments yet.