附加信息
File size: 69632 bytes
MD5...: 2f4a14fc486be56907581bb595da0d7e
SHA1..: fc66c3a3e38880687aae70aa9cad1e71070c7f3d
SHA256: 438e01d36e078e379881ca8c28157fa656c69fd7581a3f8c66df402e732acd95
SHA512: f314735a1373085bb51ed86efa2c6c529289b584645e089446fce13410dfde89
1943895810cd6f92f07c007828de13fdbbf5004f13c683119c7ae5be60fb46cd
PEiD..: Armadillo v1.71
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x405dee
timedatestamp.....: 0x48880a59 (Thu Jul 24 04:51:37 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x4f40 0x5000 6.31 4915d3590742e254dfbc9664f983f6fd
.rdata 0x6000 0xbf8 0x1000 3.88 ec0704d4877f9bd2a8afadfa38c29c97
.data 0x7000 0x1f7db0 0x3000 6.43 2366d269ddfdfbee8365f39dee61df21
.rsrc 0x1ff000 0x64a8 0x7000 5.22 a8e25ec9d7b4ff258fd4bf101bd7dc87
( 6 imports )
> KERNEL32.dll: CloseHandle, WaitForMultipleObjects, CreateThread, CreateEventA, WriteFile, lstrlenA, lstrcpynA, Sleep, GetTickCount, GetWindowsDirectoryA, ReadFile, CreateFileA, MoveFileA, DeleteFileA, SetEvent, GetTempFileNameA, GetTempPathA, SetFilePointer, GetProcAddress, LoadLibraryA, GetModuleHandleA, LeaveCriticalSection, EnterCriticalSection, lstrcmpA, GetLastError, DeleteCriticalSection, InitializeCriticalSection, MultiByteToWideChar, lstrcmpiA, ExitThread, lstrcpyA, GetFileSize, lstrcatA
> USER32.dll: wsprintfA
> WININET.dll: FtpGetCurrentDirectoryA, FtpSetCurrentDirectoryA, FtpOpenFileA, InternetOpenA, InternetWriteFile, FtpFindFirstFileA, InternetFindNextFileA, InternetCloseHandle, InternetCrackUrlA, InternetReadFile, InternetConnectA
> SHELL32.dll: SHGetSpecialFolderPathA, ShellExecuteA
> ADVAPI32.dll: RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, SetServiceStatus
> MSVCRT.dll: __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, __p___initenv, exit, _XcptFilter, _exit, _strrev, _controlfp, _except_handler3, __2@YAPAXI@Z, strlen, sprintf, __3@YAXPAX@Z, strstr, memset, atol, atoi, fclose, fread, ftell, fseek, fopen, __CxxFrameHandler, memcpy, memmove, isspace, strchr, _strupr
( 0 exports )