| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2014-Jul-10 21:16:41 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| CompanyName | Tactrix Inc. |
| FileDescription | Openport 2.0 J2534 Pass-Thru DLL |
| FileVersion | 1.01.0.4341 |
| ProductVersion | 1.01.0.4341 |
| LegalCopyright | (c) 2008-2014 Tactrix Inc. |
| LegalTrademarks | Openport, OpenECU, EcuFlash, and Tactrix are trademarks of Tactrix Inc. |
| OriginalFilename | op20pt32.dll |
| ProductName | Openport 2.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Tactrix Inc.
Issuer: VeriSign Class 3 Code Signing 2010 CA |
| Safe | VirusTotal score: 0/66 (Scanned on 2025-04-23 05:03:17) | All the AVs think this file is safe. |
| MD5 | 4b2cf7cf7913bfbaa30bca1071d72ecb 🔍 |
|---|---|
| SHA1 | 4be6fd8e9952966acdfbed421d4561ffe1df4b1b 🔍 |
| SHA256 | 9e58d677a284746cd42c5a5cde6975e13bd60e72f71e03c4d929ad9740a51514 🔍 |
| SHA3 | afc6bbc5d012e519ff9d4d42d716644fb827b99588f16aeac5aa58736895ea06 🔍 |
| SSDeep | 12288:TG+drWZ3B2XYdTNYiBWVF+hLc82gsr85:TUBEWR2VF+hd7 🔍 |
| Imports Hash | 4c9a040763e66611f4a2dd95169d3e26 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 6 |
| TimeDateStamp | 2014-Jul-10 21:16:41 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x38200 |
| SizeOfInitializedData | 0x39400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00023C40 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3a000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.1 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x79000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x79cea |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 00fb1d279fb55bb3cfeef6665742b859 🔍 |
|---|---|
| SHA1 | bf6001bae64c630589440ecf03d0c399504417f7 🔍 |
| SHA256 | e860c70432e4e6c19aacc86c4e5bc6bf81d60208f7352d3d60ec697087119313 🔍 |
| SHA3 | 67b6fcefbc5033ca1f41d6e86234a095d4b2c6418e44a08cafd34d3c27bf77e2 🔍 |
| VirtualSize | 0x38182 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x38200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.64429 |
| MD5 | cc0b0c2ffbbb74cbc47049c015bbf9e3 🔍 |
|---|---|
| SHA1 | 8422633101ee94ed97f5f61cfa956fe3aed167ac 🔍 |
| SHA256 | c65192307e1aa9e2ef73e1a09601a7bc343521bc7dc9ae9bc30ee44f5b9b6baf 🔍 |
| SHA3 | ae4595798e6d90aab7b01d01fb445d66d5ea55d6594ea0e2eda3c2ff7ce46cf8 🔍 |
| VirtualSize | 0x312f5 |
| VirtualAddress | 0x3a000 |
| SizeOfRawData | 0x31400 |
| PointerToRawData | 0x38600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.93781 |
| MD5 | 8466b5ab2c373139d623620a4e08a83c 🔍 |
|---|---|
| SHA1 | ad47c34c319b2074914adcd19bf0777ab6318a54 🔍 |
| SHA256 | 864daa7f6edc4053fbbfe64f88fb7927e07f8ebab6ac77deb95e63a98cc45459 🔍 |
| SHA3 | af2fe1b457cc6172e2b06b946416774207ddd452fdd6a1b08075094bc4f417b4 🔍 |
| VirtualSize | 0x501c |
| VirtualAddress | 0x6c000 |
| SizeOfRawData | 0x2e00 |
| PointerToRawData | 0x69a00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.23104 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x2 |
| VirtualAddress | 0x72000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x6c800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 89667ea0ab7156191cd84c4547978805 🔍 |
|---|---|
| SHA1 | 4225c77490e2ee25b28332fdee6d90f5f5752c3f 🔍 |
| SHA256 | 49d9251660ae7d7466bf02d0ea76327cb0c113adb443f6c6e2807589bec71097 🔍 |
| SHA3 | 4248fbbe6f94f4f6868ae6130e0056def1321a51906327347bed8b0a485fba0d 🔍 |
| VirtualSize | 0x588 |
| VirtualAddress | 0x73000 |
| SizeOfRawData | 0x600 |
| PointerToRawData | 0x6ca00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.40874 |
| MD5 | 4f445621d7dadc1895984aa7507a057a 🔍 |
|---|---|
| SHA1 | 3cf9e4ea4b4e1cf9b787de4e782409366b20332e 🔍 |
| SHA256 | d4fa1bdb7a06f012af29027d8d74e10191f521b47cb86f52fcb1d73da13ec92c 🔍 |
| SHA3 | 383c482a09e552a0fe11b22a8d7ce486174e9014d84f2f45f92b9f3e82bc4069 🔍 |
| VirtualSize | 0x4904 |
| VirtualAddress | 0x74000 |
| SizeOfRawData | 0x4a00 |
| PointerToRawData | 0x6d000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.48061 |
| KERNEL32.dll |
CreateEventA
CloseHandle SetEvent WaitForSingleObject GetSystemTimeAsFileTime GetTickCount HeapFree GetProcessHeap ReleaseSemaphore HeapAlloc CreateSemaphoreA DuplicateHandle GetCurrentProcess OutputDebugStringA CancelIo GetOverlappedResult WaitForMultipleObjects GetLastError ReadFile WriteFile CreateFileW ResetEvent CreateEventW FlushFileBuffers CompareStringW WriteConsoleW SetStdHandle GetConsoleMode WideCharToMultiByte InterlockedIncrement InterlockedDecrement InterlockedExchange MultiByteToWideChar Sleep InitializeCriticalSection DeleteCriticalSection EnterCriticalSection LeaveCriticalSection EncodePointer DecodePointer TlsAlloc TlsFree TlsGetValue GetCurrentThreadId GetCurrentProcessId OpenEventA TlsSetValue ResumeThread SystemTimeToFileTime SetWaitableTimer CreateWaitableTimerA LocalFree FormatMessageA QueryPerformanceFrequency QueryPerformanceCounter RaiseException RtlUnwind GetCommandLineA LCMapStringW GetCPInfo ExitThread CreateThread IsProcessorFeaturePresent GetStdHandle GetModuleFileNameW GetLocaleInfoW UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent TerminateProcess GetModuleHandleW SetLastError GetProcAddress HeapSize ExitProcess HeapCreate HeapDestroy GetTimeZoneInformation SetHandleCount InitializeCriticalSectionAndSpinCount GetFileType GetStartupInfoW GetModuleFileNameA FreeEnvironmentStringsW GetEnvironmentStringsW GetACP GetOEMCP IsValidCodePage GetStringTypeW HeapReAlloc GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale LoadLibraryW SetFilePointer GetConsoleCP SetEnvironmentVariableA |
|---|---|
| SETUPAPI.dll |
SetupDiEnumDeviceInterfaces
SetupDiDestroyDeviceInfoList SetupDiGetDeviceInterfaceDetailW SetupDiGetClassDevsW |
| Ordinal | 1 |
|---|---|
| Address | 0x1200 |
| Ordinal | 2 |
|---|---|
| Address | 0x1250 |
| Ordinal | 3 |
|---|---|
| Address | 0x12c0 |
| Ordinal | 4 |
|---|---|
| Address | 0x4c50 |
| Ordinal | 5 |
|---|---|
| Address | 0x5700 |
| Ordinal | 6 |
|---|---|
| Address | 0x11a0 |
| Ordinal | 7 |
|---|---|
| Address | 0x5330 |
| Ordinal | 8 |
|---|---|
| Address | 0x4540 |
| Ordinal | 9 |
|---|---|
| Address | 0x1650 |
| Ordinal | 10 |
|---|---|
| Address | 0x1450 |
| Ordinal | 11 |
|---|---|
| Address | 0x1310 |
| Ordinal | 12 |
|---|---|
| Address | 0x15e0 |
| Ordinal | 13 |
|---|---|
| Address | 0x13e0 |
| Ordinal | 14 |
|---|---|
| Address | 0x3970 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x38c |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.50887 |
| MD5 | 5a8c64fca03cf0e08950809d6c038694 🔍 |
| SHA1 | 6fad7bcaa274ddce44549de25e91bc97aff189ef 🔍 |
| SHA256 | 3282c6f35ec5289fbec9b6a8c80146b2b23bdf1dc0cd9fb66c3ab5ebed9e099b 🔍 |
| SHA3 | e3e5be686ea2cb70148e4299facc5b0d077fd70f726507e4586aac940b9a43d7 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | Latin 1 / Western European |
| Size | 0x15a |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.79597 |
| MD5 | 24d3b502e1846356b0263f945ddd5529 🔍 |
| SHA1 | bac45b86a9c48fc3756a46809c101570d349737d 🔍 |
| SHA256 | 49a60be4b95b6d30da355a0c124af82b35000bce8f24f957d1c09ead47544a1e 🔍 |
| SHA3 | 1244ed60820da52dc4b53880ec48e3b587dbdbd9545f01fa2b1c0fcfea1d5e9e 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.1.0.4341 |
| ProductVersion | 1.1.0.4341 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Tactrix Inc. |
| FileDescription | Openport 2.0 J2534 Pass-Thru DLL |
| FileVersion (#2) | 1.01.0.4341 |
| ProductVersion (#2) | 1.01.0.4341 |
| LegalCopyright | (c) 2008-2014 Tactrix Inc. |
| LegalTrademarks | Openport, OpenECU, EcuFlash, and Tactrix are trademarks of Tactrix Inc. |
| OriginalFilename | op20pt32.dll |
| ProductName | Openport 2.0 |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x10072000 |
|---|---|
| EndAddressOfRawData | 0x10072001 |
| AddressOfIndex | 0x1006f154 |
| AddressOfCallbacks | 0x1003a298 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks |
0x10020E60
|
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1006da28 |
| SEHandlerTable | 0x100670f0 |
| SEHandlerCount | 161 |
| XOR Key | 0xe86acfbf |
|---|---|
| Unmarked objects | 0 |
| ASM objects (VS2010 SP1 build 40219) | 25 |
| C objects (VS2010 SP1 build 40219) | 129 |
| Imports (VS2008 SP1 build 30729) | 5 |
| Total imports | 108 |
| C++ objects (VS2010 SP1 build 40219) | 66 |
| Exports (VS2010 SP1 build 40219) | 1 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |
No comments yet.