| filename | TemperHumDll.dll | |
|---|---|---|
| size | 32768 (0x8000) | |
| md5 | 875fe80ee2e818fea3be4c155c500a49 | |
| type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x50 |
| blocks_in_file | 2 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0xf |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0x1a |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
UPX v0.89.6 - v1.02 / v1.05 - v1.22 DLL This file is packed with UPX. Analysis will be incomplete without unpacking. |
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| UPX0 | 0x1000 | 0xf000 | 0 | RWX UDATA | |
| UPX1 | 0x10000 | 0x7000 | 0x6c00 | RWX IDATA | |
| .rsrc | 0x17000 | 0x1000 | 0x1000 | RW- IDATA |
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0x17a70 | 0x38c | |
| IMPORT | 0x17934 | 0x13c | |
| RESOURCE | 0x17000 | 0x934 | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0x17dfc | 0xc | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0 | 0 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0 | 0 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| type | name | size | cp | |
|---|---|---|---|---|
| ICON | #1 | 744 | 0 | |
| STRING | #4091 | 64 | 0 | |
| STRING | #4092 | 244 | 0 | |
| STRING | #4093 | 196 | 0 | |
| STRING | #4094 | 748 | 0 | |
| STRING | #4095 | 832 | 0 | |
| STRING | #4096 | 704 | 0 | |
| RCDATA | DVCLAL | 16 | 0 | |
| RCDATA | PACKAGEINFO | 96 | 0 | |
| GROUP_ICON | MAINICON | 20 | 0 | |
| VERSION | #1 | 860 | 0 |
| id | lang | string |
|---|---|---|
| 65440 | 0 | bf d5 15 f7 f6 85 d2 75 14 0e b9 90 01 60 00 18 |.......u.....`..|
a2 f1 dc 07 af 79 62 6c 7b f4 59 d9 f0 f0 a0 7d |.....ybl{.Y....}|
3b 06 9f 5e b4 4e 7f 8d 04 40 02 bf 99 a8 25 80 |;..^.N...@....%.|
c0 ef fb fe 01 0f 82 8e 04 bc 80 73 57 ff c1 0f |...........sW...|
|
| 65456 | 0 | 87 83 2d db dd ed 10 cd 72 7d 05 0c 77 77 0b fb |..-.....r}..ww..|
71 ba df 04 b0 7e c7 ac 3b 5c 42 fe 77 64 0c 48 |q....~..;\B.wd.H|
7f 11 58 80 2c 11 1b 16 03 5c 4a 7e ec 5b eb fe |..X.,....\J~.[..|
41 48 04 18 ce 49 8b c1 a5 99 f7 fe 69 f1 24 45 |AH...I......i.$E|
6c a2 5b 8b d1 9a db ee 5e fb 03 f2 2b f0 1f b6 |l.[.....^...+...|
1f f9 03 f0 2f c3 04 61 a1 6d 7c 81 ee 5a 95 88 |..../..a.m|..Z..|
89 3d 52 f4 4c ab 65 11 09 13 27 e4 12 4e 18 f8 |.=R.L.e...'..N..|
48 54 40 f0 01 b6 9a 1c c4 2c eb 59 cf 00 26 c8 |HT@......,.Y..&.|
15 14 80 56 6d 09 fa 73 c0 66 56 0e 04 2b d7 fe |...Vm..s.fV..+..|
84 e8 0a 66 0d 5f c0 dd 5c 24 67 0e d1 7b 9e ef |...f._..\$g..{..|
16 50 1e 18 16 14 57 11 9b fb ad e8 08 18 dd 1c |.P....W.........|
24 9b 51 4a 20 b6 5c 98 27 67 00 ff ab 14 68 0f |$.QJ .\.'g....h.|
0b ba a1 a7 8d 8d 00 27 42 c8 bd 12 0b 0d 10 12 |.......'B.......|
b0 49 c4 14 a2 8b 86 e0 9e cc 09 b9 d6 67 35 61 |.I...........g5a|
a7 7a cb 51 f1 6a 38 ac 3d 82 02 10 0f 40 05 16 |.z.Q.j8.=....@..|
e1 80 25 46 |..%F |
|
| 65472 | 0 | eb fb 07 c0 1d ba 48 b2 fc c2 74 6b d5 28 36 66 |......H...tk.(6f| 10 ec e9 52 43 d5 41 1d 60 40 9f 0d b8 37 84 8e |...RC.A.`@...7..| c5 b8 73 3e 68 0d af c7 a8 f7 b6 26 51 00 42 da |..s>h......&Q.B.| 62 07 43 53 f0 22 6c 6a bb bd ef a2 1a aa b5 a4 |b.CS."lj........| 40 d4 55 6a 0b 77 d1 d5 01 b1 b9 ab 50 a7 8d 43 |@.Uj.w......P..C| 44 2c 1a 10 bf 48 65 b4 59 3c db 64 64 64 ec d8 |D,...He.Y<.ddd..| 22 f0 80 38 98 8a 47 9e f0 8b c7 43 83 c7 cf db |"..8..G....C....| e6 61 6f 33 0d 75 ae 60 d7 04 d7 20 2e 05 16 61 |.ao3.u.`... ...a| 78 04 95 f9 aa 84 19 59 b6 4b 06 ec b0 c9 61 25 |x......Y.K....a%| 03 37 b6 70 ec ec 90 91 2e 24 e8 cc 2a 72 92 ea |.7.p.....$..*r..| 23 39 e8 08 75 9c b0 41 85 36 f7 62 0e 3a 1f 66 |#9..u..A.6.b.:.f| 16 34 e3 a4 3a 0e bd eb 54 85 62 17 82 23 1b 33 |.4..:...T.b..#.3| f6 a5 4b 5a |..KZ | |
| 65488 | 0 | e8 6e 6f 3e 07 74 1f 4a 3c 9d aa 48 57 f0 53 60 |.no>.t.J<..HW.S`|
22 56 21 09 93 8a 2a 16 34 c6 be ea c6 9c 93 13 |"V!...*.4.......|
dc 0c ab 3d 58 b9 60 0e 32 61 4b 2c 64 ff 41 c9 |...=X.`.2aK,d.A.|
10 cc a3 47 ae b0 81 c5 c6 76 5f a0 89 60 64 58 |...G.....v_..`dX|
b6 5c 42 0a dc c0 2d 8e 75 72 b0 d8 b0 13 77 76 |.\B...-.ur....wv|
63 63 77 23 b8 60 5f d3 b9 13 78 ba 0b 7b 5d 0c |ccw#.`_...x..{].|
47 d9 1e 6a ba 5c 6d d7 05 43 14 8e 3b fd 83 e1 |G..j.\m..C..;...|
c3 ef 1b 7b 3c 6a 04 56 2f 50 6e 18 0a 98 ba 98 |...{ |
| 65504 | 0 | b6 23 40 25 43 48 b1 44 ac 9c 30 00 0e b3 7f 84 |.#@%CH.D..0.....|
d2 89 5d a1 28 8f 4f 24 21 68 cf 5a 90 5e a2 da |..].(.O$!h.Z.^..|
8a 8d 47 04 fc fe b6 f7 6f 83 39 0f 1a c0 64 8f |..G.....o.9...d.|
05 fc 29 0c 02 5b 56 d5 14 a3 40 0a 4b 9e 40 93 |..)..[V...@.K.@.|
68 a6 51 9c e3 59 d8 36 4d 54 c6 e4 07 62 4a 0e |h.Q..Y.6MT...bJ.|
08 c4 60 ec 68 ad 61 27 52 58 7d d8 bb 2a 33 f1 |..`.h.a'RX}..*3.|
0e 57 04 65 ff bb e2 92 13 d9 bd 69 74 8d 2c e6 |.W.e.......it.,.|
18 56 a2 54 ed ca c8 46 f2 d6 81 69 7b 2d f8 ba |.V.T...F...i{-..|
02 c0 67 11 c8 cd a7 80 78 0c a3 de 3d 12 6d 20 |..g.....x...=.m |
14 c3 45 ac 0e 09 54 18 8a 85 14 fc 52 65 63 08 |..E...T.....Rec.|
0c 6e f0 71 84 53 33 db 5e ac 48 eb 01 ef 06 fe |.n.q.S3.^.H.....|
25 60 fb 06 7f 09 3b 34 dd 9d e8 75 f1 0d dc 7c |%`....;4...u...||
a8 e7 15 8b 0c ec 9d 47 7c 0c eb 1d 6d 0d 2a 55 |.......G|...m.*U|
7f 2d 43 54 d5 65 3b a8 fc 16 c3 70 1e 69 1d 75 |.-CT.e;....p.i.u|
a8 b8 ed 70 0c 80 07 6a 06 b0 18 f5 2c 0e 0a 54 |...p...j....,..T|
3c 80 53 ff 5d 83 1b 28 d0 fe ca 6e 03 10 4a 80 |<.S.]..(...n..J.|
ea 16 72 12 eb 2c d0 60 ec 5f 05 d7 90 eb 2b 07 |..r..,.`._....+.|
94 76 4b 51 a4 62 31 5d 3f 48 2d d6 1a 11 61 6b |.vKQ.b1]?H-...ak|
85 39 ea d6 be 56 97 6f c4 08 47 c2 e9 64 9e 3a |.9...V.o..G..d.:|
3c 31 93 a7 e0 30 ab 11 1d 79 e0 d9 f0 68 41 8e |<1...0...y...hA.|
15 10 6b 38 73 58 e0 51 bd 42 18 cb 0d 0d c2 53 |..k8sX.Q.B.....S|
a9 ce 77 34 9d fc b6 75 a9 16 6f 31 e8 0b c5 ec |..w4...u..o1....|
06 a6 d6 96 cb f0 7d f4 f8 83 14 4b 1d 7b f2 6c |......}....K.{.l|
2a e0 54 4d e0 f9 4e 84 e5 81 d1 e2 92 da 89 6b |*.TM..N........k|
3f 68 0d 19 91 e0 91 e8 e9 6c 47 75 10 f3 89 cc |?h.......lGu....|
f1 6d 00 bc dc 82 bb 59 bb 28 6a 98 8d d5 c1 04 |.m.....Y.(j.....|
23 4c e8 59 e0 6b 44 1f 67 88 b0 25 f9 54 24 4e |#L.Y.kD.g..%.T$N|
e4 35 00 c8 20 83 41 89 59 53 f9 43 fe c8 55 3c |.5.. .A.YS.C..U<|
48 74 48 eb 55 33 74 37 eb 47 46 7e 46 06 35 28 |HtH.U3t7.GF~F.5(|
16 eb 2f 25 96 6d ab 6f 1d eb 21 b0 03 fd 04 02 |../%.m.o..!.....|
05 06 59 96 65 59 07 08 09 0b 0c 51 8b 96 65 0d |..Y.eY.....Q..e.|
0e 16 6f c2 64 84 27 f3 6b 88 a8 8b 89 5b 61 1e |..o.d.'.k....[a.|
a2 6f 8c 58 85 67 64 64 7b 08 05 b0 a8 ac 54 e4 |.o.X.gdd{.....T.|
60 40 9d 6d e7 20 6c f0 1d 3a 58 fc 83 7b 14 87 |`@.m. l..:X..{..|
0f 93 38 99 84 c8 90 a2 20 43 f2 77 60 80 5e c4 |..8..... C.w`.^.|
45 dc 50 8b 43 0c 50 a0 fc a8 78 7d ec 10 85 b6 |E.P.C.P...x}....|
83 11 a2 c1 a9 d7 40 e0 c2 69 a0 bd 0f 0f 84 99 |......@..i......|
a4 32 d8 fe af 41 ac 19 fe 8d 8d 21 2d 05 8b 00 |.2...A.....!-...|
bd b9 38 e6 15 6c b0 76 e0 b5 62 9d c0 bc 39 19 |..8..l.v..b...9.|
1b 83 66 c0 0b 12 c4 0f c8 de 64 64 3b f8 59 cc |..f.......dd;.Y.|
d0 66 f2 bd 56 88 56 46 f6 c1 4c 0e 72 8c 77 8d |.f..V.VF..L.r.w.|
0f 3c 4c bc eb 5d 32 76 c6 c6 98 90 3e 94 5e 98 |. |
| 65520 | 0 | 6a 48 0a a4 5f 9b c5 f3 6e c4 6c c5 7f 17 9c 2b |jH.._...n.l....+|
e8 f9 3e 6c 0c 0a a8 6d 24 be d2 04 b4 6b 58 a9 |..>l...m$....kX.|
c4 0c 74 7a a7 aa 7c c3 44 cf 72 ac 55 f4 5d b2 |..tz..|.D.r.U.].|
1a a1 07 c6 28 08 8b b5 03 44 b2 d6 8f 22 82 43 |....(....D...".C|
06 19 94 94 94 10 cd 66 8f c7 22 9b 0e 39 e4 73 |.......f.."..9.s|
77 08 a4 6c 9c 87 73 90 43 a8 c4 18 13 06 d4 97 |w..l..s.C.......|
4b b0 6c ff c7 04 24 94 7b d0 a3 7a 74 43 46 34 |K.l...$.{..ztCF4|
4f f3 74 1d fc c4 08 04 c8 08 cc 65 a1 7b 7b 8e |O.t........e.{{.|
17 01 75 10 11 0c f9 ff 28 f6 16 78 16 99 09 0f |..u.....(..x....|
0a 88 de aa 0e 8b d4 55 14 b9 80 af dc 6b 41 3f |.......U.....kA?|
66 5f ef c0 02 ba b8 6b 7b 62 66 80 3c f1 60 85 |f_.....k{bf.<.`.|
09 ab 37 10 14 8a 00 22 4c 7a fb bf c1 85 eb eb |..7...."Lz......|
f7 4e 9c 4e 85 f6 7c 12 8a 0c 30 81 e1 1f da 42 |.N.N..|...0....B|
f5 39 0d 72 e9 ca ce 12 8d e8 6f a0 6c 79 05 49 |.9.r......o.ly.I|
83 c9 fe 41 4b 83 32 61 ff 04 b2 02 eb 13 8a 04 |...AK.2a........|
38 49 02 26 67 70 16 44 c3 56 12 80 98 01 2c 0f |8I.&gp.D.V....,.|
4c 48 0f eb bb 60 07 b5 af 3c 70 44 ef 33 c9 36 |LH...`... |
| module_name | hint | ord | function_name |
|---|---|---|---|
| KERNEL32.DLL | LoadLibraryA | ||
| KERNEL32.DLL | GetProcAddress | ||
| KERNEL32.DLL | VirtualProtect | ||
| KERNEL32.DLL | VirtualAlloc | ||
| KERNEL32.DLL | VirtualFree | ||
| advapi32.dll | RegCloseKey | ||
| oleaut32.dll | SysFreeString | ||
| user32.dll | CharNextA |
| ord | entry_va | function_name | |
|---|---|---|---|
| 1 | 0xcbf8 | TemperSetCal | |
| 2 | 0xccc8 | TemperGetCal | |
| 3 | 0xcb44 | TemperRead | |
| 4 | 0xc964 | TemperSetDeviceByIndex | |
| 5 | 0xc948 | TemperSetDevice | |
| 6 | 0xc90c | TemperGetActiveDevice | |
| 7 | 0xc7c8 | TemperSelect | |
| 8 | 0xc740 | TemperDewPoint | |
| 9 | 0xc6fc | TemperFtoC | |
| 10 | 0xc6c8 | TemperCtoF | |
| 11 | 0xc670 | TemperGetVersionEx | |
| 12 | 0xc3b0 | TemperGetVersion | |
| 13 | 0xc124 | TemperNtcSetCalibration | |
| 14 | 0xbf84 | TemperNtcGetCalibration | |
| 15 | 0xbc14 | TemperSetCalibration_1K2 | |
| 16 | 0xbe3c | TemperGetCalibration_1K2 | |
| 17 | 0xb9e8 | Temper2SetCalibration | |
| 18 | 0xb630 | TemperSetCalibration | |
| 19 | 0xb4c4 | Temper2GetCalibration | |
| 20 | 0xb2f0 | TemperGetCalibration | |
| 21 | 0xb168 | TemperRead1K2 | |
| 22 | 0xaf4c | TemperReadTempHum | |
| 23 | 0xadec | TemperReadHum | |
| 24 | 0xabac | TemperNtcReadC | |
| 25 | 0xa9ec | Temper2ReadC | |
| 26 | 0xa864 | TemperReadC | |
| 27 | 0x9be8 | TemperCount | |
| 28 | 0xa1bc | TemperReset | |
| 29 | 0xa214 | CloseTemper | |
| 30 | 0x9ebc | InitTemper | |
| 31 | 0x962c | TemperGetAllIDs | |
| 32 | 0x93c0 | TemperGetIDs |
StringTable 000004B0
| Auteur | R.T.G. van Steenis |
| CompanyName | Van Steenis Software |
| FileDescription | TEMPerHumDll.dll |
| FileVersion | 1, 5, 0, 0 |
| InternalName | TEMPerHumDll.dll |
| LegalCopyright | Copyright Van Steenis Software |
| OriginalFilename | TEMPerHumDll.dll |
| ProductName | TEMPerHumDll.dll |
| ProductVersion | 1, 5, 0, 0 |
VS_FIXEDFILEINFO
| FileVersion | 1.5.0.0 |
| ProductVersion | 1.5.0.0 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 0x40004 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[!] string size(109438) > stringtable size(64). truncated to 62
[!] cannot convert "\x15\xF7\xF6\x85\xD2u\x14\x0E\xB9\x90\x01`\x00\x18\xA2\xF1"... to UTF-16
[!] string size(67342) > stringtable size(244). truncated to 242
[!] cannot convert "-\xDB\xDD\xED\x10\xCDr}\x05\fww\v\xFBq\xBA"... to UTF-16
[!] string size(128982) > stringtable size(196). truncated to 194
[!] cannot convert "\a\xC0\x1D\xBAH\xB2\xFC\xC2tk\xD5(6f\x10\xEC"... to UTF-16
[!] string size(56784) > stringtable size(748). truncated to 746
[!] cannot convert "o>\at\x1FJ<\x9D\xAAHW\xF0S`\"V"... to UTF-16
[!] string size(18284) > stringtable size(832). truncated to 830
[!] cannot convert "@%CH\xB1D\xAC\x9C0\x00\x0E\xB3\x7F\x84\xD2\x89"... to UTF-16
[!] string size(37076) > stringtable size(704). truncated to 702
[!] cannot convert "\n\xA4_\x9B\xC5\xF3n\xC4l\xC5\x7F\x17\x9C+\xE8\xF9"... to UTF-16
offset:( 0x )