filename | pokemid.exe | |
---|---|---|
size | 4312064 (0x41cc00) | |
md5 | 73dde1562b2a971767b31eb8622b1a00 | |
type | PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows | |
mimetype | application/x-dosexec | |
clamav | scan pending | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x824000 | 0x824060 | 0x81e61c | 0x823040 | 0 | 0 |
module_name | hint | ord | function_name |
---|---|---|---|
dbghelp.dll | 28 | MiniDumpWriteDump | |
dbghelp.dll | 32 | StackWalk64 | |
dbghelp.dll | 71 | SymFromAddr | |
dbghelp.dll | 80 | SymFunctionTableAccess64 | |
dbghelp.dll | 85 | SymGetLineFromAddr64 | |
dbghelp.dll | 97 | SymGetModuleBase64 | |
dbghelp.dll | 132 | SymInitialize | |
GDI32.dll | 143 | DeleteObject | |
KERNEL32.dll | 13 | AddVectoredContinueHandler | |
KERNEL32.dll | 85 | CloseHandle | |
KERNEL32.dll | 134 | CreateEventA | |
KERNEL32.dll | 149 | CreateFileW | |
KERNEL32.dll | 178 | CreateSemaphoreA | |
KERNEL32.dll | 194 | CreateTimerQueue | |
KERNEL32.dll | 195 | CreateTimerQueueTimer | |
KERNEL32.dll | 217 | DeleteCriticalSection | |
KERNEL32.dll | 225 | DeleteTimerQueueEx | |
KERNEL32.dll | 226 | DeleteTimerQueueTimer | |
KERNEL32.dll | 250 | EnterCriticalSection | |
KERNEL32.dll | 306 | FileTimeToLocalFileTime | |
KERNEL32.dll | 307 | FileTimeToSystemTime | |
KERNEL32.dll | 333 | FindFirstVolumeW | |
KERNEL32.dll | 344 | FindNextVolumeW | |
KERNEL32.dll | 350 | FindVolumeClose | |
KERNEL32.dll | 356 | FlushConsoleInputBuffer | |
KERNEL32.dll | 363 | FormatMessageA | |
KERNEL32.dll | 364 | FormatMessageW | |
KERNEL32.dll | 366 | FreeEnvironmentStringsA | |
KERNEL32.dll | 367 | FreeEnvironmentStringsW | |
KERNEL32.dll | 368 | FreeLibrary | |
KERNEL32.dll | 374 | GetACP | |
KERNEL32.dll | 385 | GetCPInfo | |
KERNEL32.dll | 406 | GetCommandLineW | |
KERNEL32.dll | 425 | GetConsoleCP | |
KERNEL32.dll | 443 | GetConsoleMode | |
KERNEL32.dll | 463 | GetCurrentProcess | |
KERNEL32.dll | 464 | GetCurrentProcessId | |
KERNEL32.dll | 467 | GetCurrentThread | |
KERNEL32.dll | 468 | GetCurrentThreadId | |
KERNEL32.dll | 479 | GetDiskFreeSpaceExW | |
KERNEL32.dll | 489 | GetEnvironmentStrings | |
KERNEL32.dll | 491 | GetEnvironmentStringsW | |
KERNEL32.dll | 493 | GetEnvironmentVariableW | |
KERNEL32.dll | 502 | GetFileAttributesA | |
KERNEL32.dll | 509 | GetFileInformationByHandle | |
KERNEL32.dll | 514 | GetFileSizeEx | |
KERNEL32.dll | 515 | GetFileTime | |
KERNEL32.dll | 516 | GetFileType | |
KERNEL32.dll | 524 | GetFullPathNameW | |
KERNEL32.dll | 530 | GetLastError | |
KERNEL32.dll | 532 | GetLocalTime | |
KERNEL32.dll | 549 | GetModuleFileNameW | |
KERNEL32.dll | 550 | GetModuleHandleA | |
KERNEL32.dll | 553 | GetModuleHandleW | |
KERNEL32.dll | 572 | GetNumaHighestNodeNumber | |
KERNEL32.dll | 600 | GetProcAddress | |
KERNEL32.dll | 613 | GetProcessTimes | |
KERNEL32.dll | 629 | GetStartupInfoA | |
KERNEL32.dll | 631 | GetStdHandle | |
KERNEL32.dll | 646 | GetSystemInfo | |
KERNEL32.dll | 650 | GetSystemTime | |
KERNEL32.dll | 651 | GetSystemTimeAdjustment | |
KERNEL32.dll | 652 | GetSystemTimeAsFileTime | |
KERNEL32.dll | 663 | GetTempFileNameW | |
KERNEL32.dll | 665 | GetTempPathW | |
KERNEL32.dll | 679 | GetTickCount | |
KERNEL32.dll | 683 | GetTimeFormatW | |
KERNEL32.dll | 684 | GetTimeZoneInformation | |
KERNEL32.dll | 700 | GetVolumeInformationW | |
KERNEL32.dll | 725 | GlobalMemoryStatusEx | |
KERNEL32.dll | 736 | HeapAlloc | |
KERNEL32.dll | 738 | HeapCreate | |
KERNEL32.dll | 740 | HeapDestroy | |
KERNEL32.dll | 742 | HeapFree | |
KERNEL32.dll | 747 | HeapSetInformation | |
KERNEL32.dll | 763 | InitializeCriticalSection | |
KERNEL32.dll | 786 | IsDBCSLeadByteEx | |
KERNEL32.dll | 845 | LeaveCriticalSection | |
KERNEL32.dll | 850 | LoadLibraryExW | |
KERNEL32.dll | 851 | LoadLibraryW | |
KERNEL32.dll | 859 | LocalFileTimeToFileTime | |
KERNEL32.dll | 861 | LocalFree | |
KERNEL32.dll | 889 | MoveFileW | |
KERNEL32.dll | 893 | MultiByteToWideChar | |
KERNEL32.dll | 929 | OutputDebugStringA | |
KERNEL32.dll | 931 | PeekConsoleInputA | |
KERNEL32.dll | 933 | PeekNamedPipe | |
KERNEL32.dll | 960 | QueryPerformanceCounter | |
KERNEL32.dll | 961 | QueryPerformanceFrequency | |
KERNEL32.dll | 975 | ReadConsoleInputA | |
KERNEL32.dll | 1009 | ReleaseSemaphore | |
KERNEL32.dll | 1018 | RemoveVectoredContinueHandler | |
KERNEL32.dll | 1026 | ResetEvent | |
KERNEL32.dll | 1031 | RtlAddFunctionTable | |
KERNEL32.dll | 1032 | RtlCaptureContext | |
KERNEL32.dll | 1039 | RtlLookupFunctionEntry | |
KERNEL32.dll | 1046 | RtlVirtualUnwind | |
KERNEL32.dll | 1051 | SearchPathW | |
KERNEL32.dll | 1069 | SetConsoleCtrlHandler | |
KERNEL32.dll | 1085 | SetConsoleMode | |
KERNEL32.dll | 1107 | SetEndOfFile | |
KERNEL32.dll | 1111 | SetEnvironmentVariableW | |
KERNEL32.dll | 1113 | SetEvent | |
KERNEL32.dll | 1126 | SetFilePointer | |
KERNEL32.dll | 1130 | SetFileTime | |
KERNEL32.dll | 1138 | SetLastError | |
KERNEL32.dll | 1141 | SetLocalTime | |
KERNEL32.dll | 1162 | SetSystemTime | |
KERNEL32.dll | 1163 | SetSystemTimeAdjustment | |
KERNEL32.dll | 1189 | SetUnhandledExceptionFilter | |
KERNEL32.dll | 1202 | Sleep | |
KERNEL32.dll | 1213 | SystemTimeToFileTime | |
KERNEL32.dll | 1216 | TerminateProcess | |
KERNEL32.dll | 1223 | TlsGetValue | |
KERNEL32.dll | 1236 | UnhandledExceptionFilter | |
KERNEL32.dll | 1239 | UnmapViewOfFile | |
KERNEL32.dll | 1260 | VirtualAlloc | |
KERNEL32.dll | 1264 | VirtualFree | |
KERNEL32.dll | 1267 | VirtualProtect | |
KERNEL32.dll | 1269 | VirtualQuery | |
KERNEL32.dll | 1275 | WaitForMultipleObjects | |
KERNEL32.dll | 1277 | WaitForSingleObject | |
KERNEL32.dll | 1301 | WideCharToMultiByte | |
msvcrt.dll | 55 | __C_specific_handler | |
msvcrt.dll | 63 | ___lc_codepage_func | |
msvcrt.dll | 78 | __dllonexit | |
msvcrt.dll | 81 | __getmainargs | |
msvcrt.dll | 82 | __initenv | |
msvcrt.dll | 83 | __iob_func | |
msvcrt.dll | 90 | __lconv_init | |
msvcrt.dll | 91 | __mb_cur_max | |
msvcrt.dll | 96 | __set_app_type | |
msvcrt.dll | 98 | __setusermatherr | |
msvcrt.dll | 115 | _access | |
msvcrt.dll | 116 | _acmdln | |
msvcrt.dll | 123 | _amsg_exit | |
msvcrt.dll | 124 | _assert | |
msvcrt.dll | 137 | _beginthreadex | |
msvcrt.dll | 141 | _cexit | |
msvcrt.dll | 153 | _close | |
msvcrt.dll | 158 | _chmod | |
msvcrt.dll | 176 | _creat | |
msvcrt.dll | 177 | _ctime64 | |
msvcrt.dll | 193 | _dup | |
msvcrt.dll | 194 | _dup2 | |
msvcrt.dll | 201 | _environ | |
msvcrt.dll | 203 | _errno | |
msvcrt.dll | 220 | _exit | |
msvcrt.dll | 237 | _fileno | |
msvcrt.dll | 253 | _fmode | |
msvcrt.dll | 257 | _fpreset | |
msvcrt.dll | 272 | _fstat64 | |
msvcrt.dll | 292 | _get_osfhandle | |
msvcrt.dll | 308 | _getpid | |
msvcrt.dll | 332 | _initterm | |
msvcrt.dll | 336 | _isatty | |
msvcrt.dll | 337 | _isatty | |
msvcrt.dll | 440 | _lock | |
msvcrt.dll | 452 | _lseeki64 | |
msvcrt.dll | 602 | _mkdir | |
msvcrt.dll | 613 | _onexit | |
msvcrt.dll | 616 | _open_osfhandle | |
msvcrt.dll | 623 | _pipe | |
msvcrt.dll | 640 | _read | |
msvcrt.dll | 645 | _read | |
msvcrt.dll | 673 | _setmode | |
msvcrt.dll | 688 | _snwprintf | |
msvcrt.dll | 731 | _strdup | |
msvcrt.dll | 789 | _telli64 | |
msvcrt.dll | 791 | _time64 | |
msvcrt.dll | 811 | _umask | |
msvcrt.dll | 817 | _unlink | |
msvcrt.dll | 821 | _unlock | |
msvcrt.dll | 823 | _utime64 | |
msvcrt.dll | 858 | _vsnwprintf | |
msvcrt.dll | 884 | _wcsdup | |
msvcrt.dll | 890 | _wcsdup | |
msvcrt.dll | 944 | _wfdopen | |
msvcrt.dll | 986 | _write | |
msvcrt.dll | 987 | _write | |
msvcrt.dll | 1005 | _wsplitpath_s | |
msvcrt.dll | 1007 | _wstat64 | |
msvcrt.dll | 1009 | _wstat | |
msvcrt.dll | 1033 | abort | |
msvcrt.dll | 1035 | acos | |
msvcrt.dll | 1036 | acosf | |
msvcrt.dll | 1038 | asin | |
msvcrt.dll | 1039 | asinf | |
msvcrt.dll | 1040 | atan | |
msvcrt.dll | 1043 | atanf | |
msvcrt.dll | 1044 | atexit | |
msvcrt.dll | 1045 | atof | |
msvcrt.dll | 1046 | atoi | |
msvcrt.dll | 1048 | bsearch | |
msvcrt.dll | 1050 | calloc | |
msvcrt.dll | 1056 | cos | |
msvcrt.dll | 1057 | cosf | |
msvcrt.dll | 1058 | cosh | |
msvcrt.dll | 1059 | coshf | |
msvcrt.dll | 1063 | exit | |
msvcrt.dll | 1064 | exp | |
msvcrt.dll | 1065 | expf | |
msvcrt.dll | 1067 | fclose | |
msvcrt.dll | 1068 | feof | |
msvcrt.dll | 1070 | fflush | |
msvcrt.dll | 1082 | fprintf | |
msvcrt.dll | 1084 | fputc | |
msvcrt.dll | 1086 | fputwc | |
msvcrt.dll | 1088 | fread | |
msvcrt.dll | 1089 | free | |
msvcrt.dll | 1095 | fseek | |
msvcrt.dll | 1097 | ftell | |
msvcrt.dll | 1098 | fwprintf | |
msvcrt.dll | 1099 | fwprintf | |
msvcrt.dll | 1101 | fwrite | |
msvcrt.dll | 1104 | getc | |
msvcrt.dll | 1106 | getenv | |
msvcrt.dll | 1119 | islower | |
msvcrt.dll | 1122 | isspace | |
msvcrt.dll | 1123 | isupper | |
msvcrt.dll | 1139 | ldexp | |
msvcrt.dll | 1141 | localeconv | |
msvcrt.dll | 1143 | log | |
msvcrt.dll | 1146 | logf | |
msvcrt.dll | 1148 | malloc | |
msvcrt.dll | 1151 | mbstowcs | |
msvcrt.dll | 1154 | memchr | |
msvcrt.dll | 1155 | memcmp | |
msvcrt.dll | 1156 | memcpy | |
msvcrt.dll | 1157 | memmove | |
msvcrt.dll | 1158 | memset | |
msvcrt.dll | 1163 | pow | |
msvcrt.dll | 1164 | powf | |
msvcrt.dll | 1172 | qsort | |
msvcrt.dll | 1174 | raise | |
msvcrt.dll | 1176 | realloc | |
msvcrt.dll | 1184 | setlocale | |
msvcrt.dll | 1186 | signal | |
msvcrt.dll | 1187 | sin | |
msvcrt.dll | 1188 | sinf | |
msvcrt.dll | 1189 | sinh | |
msvcrt.dll | 1190 | sinhf | |
msvcrt.dll | 1200 | strcmp | |
msvcrt.dll | 1202 | strcpy | |
msvcrt.dll | 1205 | strerror | |
msvcrt.dll | 1207 | strlen | |
msvcrt.dll | 1210 | strncmp | |
msvcrt.dll | 1211 | strncpy | |
msvcrt.dll | 1214 | strrchr | |
msvcrt.dll | 1216 | strstr | |
msvcrt.dll | 1218 | strtok | |
msvcrt.dll | 1220 | strtol | |
msvcrt.dll | 1225 | swprintf_s | |
msvcrt.dll | 1229 | tan | |
msvcrt.dll | 1230 | tanf | |
msvcrt.dll | 1231 | tanh | |
msvcrt.dll | 1242 | vfprintf | |
msvcrt.dll | 1254 | wcscat | |
msvcrt.dll | 1257 | wcscmp | |
msvcrt.dll | 1259 | wcscpy | |
msvcrt.dll | 1263 | wcslen | |
msvcrt.dll | 1266 | wcsncmp | |
msvcrt.dll | 1269 | wcsnlen | |
PSAPI.DLL | 4 | EnumProcessModules | |
PSAPI.DLL | 16 | GetModuleFileNameExW | |
PSAPI.DLL | 17 | GetModuleInformation | |
SHELL32.dll | 10 | CommandLineToArgvW | |
USER32.dll | 491 | MessageBoxA | |
USER32.dll | 498 | MessageBoxW | |
WINMM.dll | 149 | timeBeginPeriod | |
WINMM.dll | 150 | timeEndPeriod | |
WINMM.dll | 151 | timeGetDevCaps | |
WSOCK32.dll | 26 | WSAGetLastError | |
WSOCK32.dll | 37 | closesocket | |
WSOCK32.dll | 61 | recv | |
WSOCK32.dll | 66 | select | |
WSOCK32.dll | 67 | send |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x41e61c