msg

17408 bytes

NT Headers
Data Directory
Section Headers
Export Directory
.: RESiSTANCE IS FUTiLE 2004 :.
Import Directory

IMAGE_DOS_HEADER

OffsetRVADescriptionValue
0000000000000000e_magic "MZ"
0000000200000002e_cblp 0050
0000000400000004e_cp 0002
0000000600000006e_crlc 0000
0000000800000008e_cparhdr 0004
0000000A0000000Ae_minalloc 000F
0000000C0000000Ce_maxalloc FFFF
0000000E0000000Ee_ss 0000
0000001000000010e_sp 00B8
0000001200000012e_csum 0000
0000001400000014e_ip 0000
0000001600000016e_cs 0000
0000001800000018e_lfarlc 0040
0000001A0000001Ae_ovno 001A
0000001C0000001Ce_res 0000000000000000
0000002400000024e_oemid 0000
0000002600000026e_oeminfo 0000
0000002800000028e_res2 0000000000000000000000000000000000000000
0000003C0000003Ce_lfanew 00000100

IMAGE_NT_HEADERS

OffsetRVADescriptionValue
0000010000000100Signature "PE"

IMAGE_FILE_HEADER

OffsetRVADescriptionValue
0000010400000104Machine 014C
Intel i860
0000010600000106NumberOfSections 0009
0000010800000108TimeDateStamp 2A425E19
0000010C0000010CPointerToSymbolTable 00000000
0000011000000110NumberOfSymbols 00000000
0000011400000114SizeOfOptionalHeader 00E0
0000011600000116Characteristics 818E
File is Exe

IMAGE_OPTIONAL_HEADER

OffsetRVADescriptionValue
0000011800000118Magic 010B
0000011A0000011AMajorLinkerVersion 02
0000011B0000011BMinorLinkerVersion 19
02.19
0000011C0000011CSizeOfCode 00002C00
0000012000000120SizeOfInitializedData 00001400
0000012400000124SizeOfUninitializedData 00000000
0000012800000128AddressOfEntryPoint 000040AC
".itext"
0000012C0000012CBaseOfCode 00001000
".text"
0000013000000130BaseOfData 00005000
".data"
0000013400000134ImageBase 00400000
0000013800000138SectionAlignment 00001000
0000013C0000013CFileAlignment 00000200
0000014000000140MajorOperatingSystemVersion 0004
0000014200000142MinorOperatingSystemVersion 0000
0004.0000
0000014400000144MajorImageVersion 0000
0000014600000146MinorImageVersion 0000
0000.0000
0000014800000148MajorSubsystemVersion 0004
0000014A0000014AMinorSubsystemVersion 0000
0004.0000
0000014C0000014CWin32VersionValue 00000000
0000015000000150SizeOfImage 0000E000
0000015400000154SizeOfHeaders 00000400
0000015800000158CheckSum 00000000
0000015C0000015CSubsystem 0002
Windows GUI
0000015E0000015EDllCharacteristics 0000
0000016000000160SizeOfStackReserve 00100000
0000016400000164SizeOfStackCommit 00004000
0000016800000168SizeOfHeapReserve 00100000
0000016C0000016CSizeOfHeapCommit 00001000
0000017000000170LoaderFlags 00000000
0000017400000174NumberOfRvaAndSizes 00000010

IMAGE_DATA_DIRECTORY

OffsetRVADescriptionValue
0000017800000178Export.VirtualAddress 00000000
0000017C0000017CExport.isize 00000000
0000018000000180Import.VirtualAddress 00009000
0000018400000184Import.isize 0000038C
".idata"
0000018800000188Resource.VirtualAddress 0000D000
0000018C0000018CResource.isize 00000200
".rsrc"
0000019000000190Exception.VirtualAddress 00000000
0000019400000194Exception.isize 00000000
0000019800000198Security.VirtualAddress 00000000
0000019C0000019CSecurity.isize 00000000
000001A0000001A0BaseReloc.VirtualAddress 0000C000
000001A4000001A4BaseReloc.isize 000002E4
".reloc"
000001A8000001A8Debug.VirtualAddress 00000000
000001AC000001ACDebug.isize 00000000
000001B0000001B0Copyright.VirtualAddress 00000000
000001B4000001B4Copyright.isize 00000000
000001B8000001B8GlobalPtr.VirtualAddress 00000000
000001BC000001BCGlobalPtr.isize 00000000
000001C0000001C0TLS.VirtualAddress 0000B000
000001C4000001C4TLS.isize 00000018
".rdata"
000001C8000001C8Load Config.VirtualAddress 00000000
000001CC000001CCLoad Config.isize 00000000
000001D0000001D0Bound Import.VirtualAddress 00000000
000001D4000001D4Bound Import.isize 00000000
000001D8000001D8IAT.VirtualAddress 00009110
000001DC000001DCIAT.isize 00000084
".idata"



IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
000001F8000001F8Name1 ".text"
0000020000000200Misc.VirtualSize 000028D4
0000020400000204VirtualAddress 00001000
0000020800000208SizeOfRawData 00002A00
0000020C0000020CPointerToRawData 00000400
0000021000000210PointerToRelocations 00000000
0000021400000214PointerToLinenumbers 00000000
0000021800000218NumberOfRelocations 0000
0000021A0000021ANumberOfLinenumbers 0000
0000021C0000021CCharacteristics 60000020
Readable || Executable || Code

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000022000000220Name1 ".itext"
0000022800000228Misc.VirtualSize 000000E4
0000022C0000022CVirtualAddress 00004000
0000023000000230SizeOfRawData 00000200
0000023400000234PointerToRawData 00002E00
0000023800000238PointerToRelocations 00000000
0000023C0000023CPointerToLinenumbers 00000000
0000024000000240NumberOfRelocations 0000
0000024200000242NumberOfLinenumbers 0000
0000024400000244Characteristics 60000020
Readable || Executable || Code

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000024800000248Name1 ".data"
0000025000000250Misc.VirtualSize 00000790
0000025400000254VirtualAddress 00005000
0000025800000258SizeOfRawData 00000800
0000025C0000025CPointerToRawData 00003000
0000026000000260PointerToRelocations 00000000
0000026400000264PointerToLinenumbers 00000000
0000026800000268NumberOfRelocations 0000
0000026A0000026ANumberOfLinenumbers 0000
0000026C0000026CCharacteristics C0000040
Writeable || Readable || Data

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000027000000270Name1 ".bss"
0000027800000278Misc.VirtualSize 000027F0
0000027C0000027CVirtualAddress 00006000
0000028000000280SizeOfRawData 00000000
0000028400000284PointerToRawData 00003800
0000028800000288PointerToRelocations 00000000
0000028C0000028CPointerToLinenumbers 00000000
0000029000000290NumberOfRelocations 0000
0000029200000292NumberOfLinenumbers 0000
0000029400000294Characteristics C0000000
Writeable || Readable

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000029800000298Name1 ".idata"
000002A0000002A0Misc.VirtualSize 0000038C
000002A4000002A4VirtualAddress 00009000
000002A8000002A8SizeOfRawData 00000400
000002AC000002ACPointerToRawData 00003800
000002B0000002B0PointerToRelocations 00000000
000002B4000002B4PointerToLinenumbers 00000000
000002B8000002B8NumberOfRelocations 0000
000002BA000002BANumberOfLinenumbers 0000
000002BC000002BCCharacteristics C0000040
Writeable || Readable || Data

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
000002C0000002C0Name1 ".tls"
000002C8000002C8Misc.VirtualSize 00000008
000002CC000002CCVirtualAddress 0000A000
000002D0000002D0SizeOfRawData 00000000
000002D4000002D4PointerToRawData 00003C00
000002D8000002D8PointerToRelocations 00000000
000002DC000002DCPointerToLinenumbers 00000000
000002E0000002E0NumberOfRelocations 0000
000002E2000002E2NumberOfLinenumbers 0000
000002E4000002E4Characteristics C0000000
Writeable || Readable

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
000002E8000002E8Name1 ".rdata"
000002F0000002F0Misc.VirtualSize 00000018
000002F4000002F4VirtualAddress 0000B000
000002F8000002F8SizeOfRawData 00000200
000002FC000002FCPointerToRawData 00003C00
0000030000000300PointerToRelocations 00000000
0000030400000304PointerToLinenumbers 00000000
0000030800000308NumberOfRelocations 0000
0000030A0000030ANumberOfLinenumbers 0000
0000030C0000030CCharacteristics 40000040
Readable || Data

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000031000000310Name1 ".reloc"
0000031800000318Misc.VirtualSize 000002E4
0000031C0000031CVirtualAddress 0000C000
0000032000000320SizeOfRawData 00000400
0000032400000324PointerToRawData 00003E00
0000032800000328PointerToRelocations 00000000
0000032C0000032CPointerToLinenumbers 00000000
0000033000000330NumberOfRelocations 0000
0000033200000332NumberOfLinenumbers 0000
0000033400000334Characteristics 42000040
Readable || Discardable || Data

IMAGE_SECTION_HEADER

OffsetRVADescriptionValue
0000033800000338Name1 ".rsrc"
0000034000000340Misc.VirtualSize 00000200
0000034400000344VirtualAddress 0000D000
0000034800000348SizeOfRawData 00000200
0000034C0000034CPointerToRawData 00004200
0000035000000350PointerToRelocations 00000000
0000035400000354PointerToLinenumbers 00000000
0000035800000358NumberOfRelocations 0000
0000035A0000035ANumberOfLinenumbers 0000
0000035C0000035CCharacteristics 40000040
Readable || Data



IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000380000009000OriginalFirstThunk 0000908C
0000380400009004TimeDateStamp 00000000
0000380800009008ForwarderChain 00000000
0000380C0000900CName1 00009194 "advapi32.dll"
0000381000009010FirstThunk 00009110

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
91A20000RegQueryValueExA 91A20000RegQueryValueExA
91B60000RegOpenKeyExA 91B60000RegOpenKeyExA
91C60000RegCloseKey 91C60000RegCloseKey

IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000381400009014OriginalFirstThunk 0000909C
0000381800009018TimeDateStamp 00000000
0000381C0000901CForwarderChain 00000000
0000382000009020Name1 000091D4 "user32.dll"
0000382400009024FirstThunk 00009120

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
91E00000GetKeyboardType 91E00000GetKeyboardType
91F20000DestroyWindow 91F20000DestroyWindow
92020000MessageBoxA 92020000MessageBoxA

IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000382800009028OriginalFirstThunk 000090AC
0000382C0000902CTimeDateStamp 00000000
0000383000009030ForwarderChain 00000000
0000383400009034Name1 00009210 "kernel32.dll"
0000383800009038FirstThunk 00009130

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
921E0000GetACP 921E0000GetACP
92280000Sleep 92280000Sleep
92300000VirtualFree 92300000VirtualFree
923E0000VirtualAlloc 923E0000VirtualAlloc
924E0000GetCurrentThreadId 924E0000GetCurrentThreadId
92640000VirtualQuery 92640000VirtualQuery
92740000GetStartupInfoA 92740000GetStartupInfoA
92860000GetCommandLineA 92860000GetCommandLineA
92980000FreeLibrary 92980000FreeLibrary
92A60000ExitProcess 92A60000ExitProcess
92B40000WriteFile 92B40000WriteFile
92C00000UnhandledExceptionFilter 92C00000UnhandledExceptionFilter
92DC0000RtlUnwind 92DC0000RtlUnwind
92E80000RaiseException 92E80000RaiseException
92FA0000GetStdHandle 92FA0000GetStdHandle

IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000383C0000903COriginalFirstThunk 000090EC
0000384000009040TimeDateStamp 00000000
0000384400009044ForwarderChain 00000000
0000384800009048Name1 0000930A "kernel32.dll"
0000384C0000904CFirstThunk 00009170

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
93180000TlsSetValue 93180000TlsSetValue
93260000TlsGetValue 93260000TlsGetValue
93340000LocalAlloc 93340000LocalAlloc
93420000GetModuleHandleA 93420000GetModuleHandleA

IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000385000009050OriginalFirstThunk 00009100
0000385400009054TimeDateStamp 00000000
0000385800009058ForwarderChain 00000000
0000385C0000905CName1 00009356 "user32.dll"
0000386000009060FirstThunk 00009184

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
93620000MessageBoxA 93620000MessageBoxA

IMAGE_IMPORT_DESCRIPTOR

OffsetRVADescriptionValue
0000386400009064OriginalFirstThunk 00009108
0000386800009068TimeDateStamp 00000000
0000386C0000906CForwarderChain 00000000
0000387000009070Name1 00009370 "kernel32.dll"
0000387400009074FirstThunk 0000918C

DESCRIPTION :

Thunk (ILT)OrdNameThunk (IAT)OrdName
937E0000FreeLibrary 937E0000FreeLibrary

Created with PE2HTML v2.1 - by the Dr. rED mEAT and Jupiter
RESiSTANCE IS FUTiLE