filename | mgv.exe | |
---|---|---|
size | 185856 (0x2d600) | |
md5 | ac14821e6d3dc75376e38ec2b423e524 | |
type | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows | |
mimetype | application/x-dosexec | |
clamav | scan pending | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x50 |
blocks_in_file | 2 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0xf |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0x1a |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x200 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000001c0:
PE Header
Packer / Compiler
Aspack v2.12b (Alexey Solodovnikov) This file is packed with ASPack. Analysis will be incomplete without unpacking. |
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x44b000 | 0x44b09c | 0x44ac70 | 0x44c010 | 0 | 0 |
id | lang | string |
---|---|---|
65520 | 0 | 35 4e a5 75 a4 9e b3 ae 0f d0 4d ef d0 39 e4 71 |5N.u......M..9.q| 30 f8 61 e2 03 54 c7 2b ee 0b 7d bd d3 f6 e9 f7 |0.a..T.+..}.....| d4 00 55 cb 3e fc d3 ae 54 16 f8 9c 5f f3 8f ee |..U.>...T..._...| 9a c4 fe a2 7e 0b 02 60 a5 12 df 55 6c df e6 ff |....~..`...Ul...| e5 49 df e7 c7 81 87 99 64 ee 9a b7 82 b2 50 f8 |.I......d.....P.| 1b 05 85 ae c2 3d 49 4e c1 46 bd 3e a4 23 dc 6d |.....=IN.F.>.#.m| d7 fc 40 ea 58 72 71 80 2f 00 f6 f1 e2 fa 2a b8 |..@.Xrq./.....*.| b9 5e af af 6f b0 02 b5 15 2e 10 02 ba 95 b3 3c |.^..o..........<| bf 4b 6a b7 bb 5b e8 6e 4f 6a 27 d5 1d ea 2a d3 |.Kj..[.nOj'...*.| e2 3c 4b 3c 3c 36 43 c5 40 e4 84 fc 91 38 2a 5c |. |
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetProcAddress | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
vcl60.bpl | __fastcall Consts::initialization() @Consts@initialization$qqrv | ||
vcl60.bpl | __fastcall Graphics::initialization() @Graphics@initialization$qqrv | ||
vcl60.bpl | __fastcall Printers::initialization() @Printers@initialization$qqrv | ||
vcl60.bpl | __fastcall Stdctrls::initialization() @Stdctrls@initialization$qqrv | ||
vcl60.bpl | __fastcall Extctrls::initialization() @Extctrls@initialization$qqrv | ||
vcl60.bpl | __fastcall Dialogs::initialization() @Dialogs@initialization$qqrv | ||
vcl60.bpl | __fastcall Clipbrd::initialization() @Clipbrd@initialization$qqrv | ||
vcl60.bpl | __fastcall Stdactns::initialization() @Stdactns@initialization$qqrv | ||
vcl60.bpl | __fastcall Winhelpviewer::initialization() @Winhelpviewer@initialization$qqrv | ||
vcl60.bpl | __fastcall Actnlist::initialization() @Actnlist@initialization$qqrv | ||
vcl60.bpl | __fastcall Forms::initialization() @Forms@initialization$qqrv | ||
vcl60.bpl | __fastcall Imglist::initialization() @Imglist@initialization$qqrv | ||
vcl60.bpl | __fastcall Menus::initialization() @Menus@initialization$qqrv | ||
vcl60.bpl | __fastcall Controls::initialization() @Controls@initialization$qqrv | ||
vcl60.bpl | __fastcall Buttons::initialization() @Buttons@initialization$qqrv | ||
vcl60.bpl | __fastcall Toolwin::initialization() @Toolwin@initialization$qqrv | ||
vcl60.bpl | __fastcall Comstrs::initialization() @Comstrs@initialization$qqrv | ||
vcl60.bpl | __fastcall Extdlgs::initialization() @Extdlgs@initialization$qqrv | ||
vcl60.bpl | __fastcall Extactns::initialization() @Extactns@initialization$qqrv | ||
vcl60.bpl | __fastcall Listactns::initialization() @Listactns@initialization$qqrv | ||
vcl60.bpl | __fastcall Comctrls::initialization() @Comctrls@initialization$qqrv | ||
vcl60.bpl | __fastcall Mask::initialization() @Mask@initialization$qqrv | ||
vcl60.bpl | __fastcall Grids::initialization() @Grids@initialization$qqrv | ||
rtl60.bpl | __fastcall System::initialization() @System@initialization$qqrv | ||
rtl60.bpl | __fastcall Types::initialization() @Types@initialization$qqrv | ||
rtl60.bpl | __fastcall Sysconst::initialization() @Sysconst@initialization$qqrv | ||
rtl60.bpl | __fastcall Sysutils::initialization() @Sysutils@initialization$qqrv | ||
rtl60.bpl | __fastcall Varutils::initialization() @Varutils@initialization$qqrv | ||
rtl60.bpl | __fastcall Variants::initialization() @Variants@initialization$qqrv | ||
rtl60.bpl | __fastcall Rtlconsts::initialization() @Rtlconsts@initialization$qqrv | ||
rtl60.bpl | __fastcall Typinfo::initialization() @Typinfo@initialization$qqrv | ||
rtl60.bpl | __fastcall Activex::initialization() @Activex@initialization$qqrv | ||
rtl60.bpl | __fastcall Classes::initialization() @Classes@initialization$qqrv | ||
rtl60.bpl | __fastcall Math::initialization() @Math@initialization$qqrv | ||
rtl60.bpl | __fastcall Contnrs::initialization() @Contnrs@initialization$qqrv | ||
rtl60.bpl | __fastcall Dateutils::initialization() @Dateutils@initialization$qqrv | ||
rtl60.bpl | __fastcall Inifiles::initialization() @Inifiles@initialization$qqrv | ||
rtl60.bpl | __fastcall Registry::initialization() @Registry@initialization$qqrv | ||
rtl60.bpl | __fastcall Strutils::initialization() @Strutils@initialization$qqrv | ||
rtl60.bpl | __fastcall Maskutils::initialization() @Maskutils@initialization$qqrv | ||
rtl60.bpl | __fastcall Helpintfs::initialization() @Helpintfs@initialization$qqrv | ||
rtl60.bpl | __fastcall Flatsb::initialization() @Flatsb@initialization$qqrv | ||
rtl60.bpl | __fastcall Mapi::initialization() @Mapi@initialization$qqrv | ||
rtl60.bpl | __fastcall Multimon::initialization() @Multimon@initialization$qqrv | ||
vclx60.bpl | __fastcall Checklst::initialization() @Checklst@initialization$qqrv | ||
bcbsmp60.bpl | __linkproc__ Ccalendr::Finalize @@Ccalendr@Finalize | ||
bcbsmp60.bpl | __linkproc__ Cgauges::Finalize @@Cgauges@Finalize | ||
bcbsmp60.bpl | __tpdsc__ Cspin::TCSpinEdit @$xp$16Cspin@TCSpinEdit | ||
borlndmm.dll | 2 | ||
gdi32.dll | CreateHalftonePalette | ||
shell32.dll | ShellExecuteA | ||
user32.dll | GetDC | ||
cc3260mt.dll | operator delete(void *) @$bdele$qpv |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[!] string size(40042) > stringtable size(172). truncated to 170
[!] cannot convert "\xA5u\xA4\x9E\xB3\xAE\x0F\xD0M\xEF\xD09\xE4q0\xF8"... to UTF-16
[?] can't find file_offset of VA 0x6f72c
[?] can't find file_offset of VA 0x7c830
[?] can't find file_offset of VA 0x7d8f0
[?] can't find file_offset of VA 0x7dbdc
[?] can't find file_offset of VA 0x7e2fc
[?] can't find file_offset of VA 0x4ac70
[?] can't find file_offset of VA 0x0