| filename | PEview - Control.exe | |
|---|---|---|
| size | 67584 (0x10800) | |
| md5 | ec63e8be0717bd92c0ffbf7a21749a54 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x6c |
| blocks_in_file | 1 |
| num_relocs | 0 |
| header_paragraphs | 2 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0 |
| checksum | 0 |
| ip | 0x11 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0x336e695700000000 |
| oem_id | 0x2032 |
| oem_info | 0x7250 |
| reserved2 | 0x6172676f |
| reserved3 | 0xa0d216d |
| reserved4 | 0xba09b424 |
| reserved5 | 0x21cd0100 |
| reserved6 | 0x21cd4cb4 |
| lfanew | 0x60 |
DOS stub
00000000: 57 69 6e 33 32 20 50 72 6f 67 72 61 6d 21 0d 0a |Win32 Program!..| 00000010: 24 b4 09 ba 00 01 cd 21 b4 4c cd 21 60 00 00 00 |$......!.L.!`...| 00000020: 47 6f 4c 69 6e 6b 2c 20 47 6f 41 73 6d 20 77 77 |GoLink, GoAsm ww| 00000030: 77 2e 47 6f 44 65 76 54 6f 6f 6c 2e 63 6f 6d 00 |w.GoDevTool.com.|
PE Header
Packer / Compiler
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| code | 0x1000 | 0x8110 | 0x8200 | R-X CODE | |
| data | 0xa000 | 0x1278 | 0x400 | RW- IDATA | |
| const | 0xc000 | 0x33b0 | 0x3400 | R-- IDATA | |
| .rsrc | 0x10000 | 0x3b00 | 0x3c00 | R-- IDATA | |
| .idata | 0x14000 | 0xd56 | 0xe00 | R-X CODE |
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0 | 0 | |
| IMPORT | 0x14264 | 0xa0 | |
| RESOURCE | 0x10000 | 0x3b00 | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0 | 0 | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0 | 0 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0x14304 | 0x1b4 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| id | lang | string |
|---|---|---|
| 32 | 4105 | Commands for working with files. |
| 33 | 4105 | Commands for customizing this window. |
| 34 | 4105 | Commands for accessing view history. |
| 35 | 4105 | Commands for displaying Help. |
| 36 | 4105 | Open an existing file. |
| 37 | 4105 | Close the current file. |
| 38 | 4105 | Quit PEview. |
| 39 | 4105 | Show or hide the toolbar. |
| 40 | 4105 | Show or hide the status bar. |
| 41 | 4105 | Show or hide the treeview. |
| 42 | 4105 | Show or hide the header. |
| 43 | 4105 | Options for displaying the address. |
| 44 | 4105 | Display the address as an offset from the start of the file. |
| 45 | 4105 | Display the address as an offset from the start of the view. |
| 46 | 4105 | Display the address for sections as a relative virtual address. |
| 47 | 4105 | Display the address as a virtual address or as an offset from the start of an OBJ file. |
| 48 | 4105 | Options for displaying raw data. |
| 49 | 4105 | Display the raw data in BYTE format. |
| 50 | 4105 | Display the raw data in WORD format. |
| 51 | 4105 | Display the raw data in DWORD format. |
| 52 | 4105 | Change the split position between the two panes. |
| 53 | 4105 | Change the current font. |
| 54 | 4105 | Change additional program settings. |
| 55 | 4105 | Go back one step in the view history list. |
| 56 | 4105 | Go forward one step in the view history list. |
| 57 | 4105 | Go to next item in contents. |
| 58 | 4105 | Go to previous item in contents. |
| 59 | 4105 | Save additional view position for the current view to the view history list. |
| 60 | 4105 | Display program information, version number, and copyright. |
| 167 | 4105 | Open |
| 175 | 4105 | File Offset |
| 176 | 4105 | View Offset |
| 177 | 4105 | RVA |
| 178 | 4105 | VA |
| 180 | 4105 | BYTE |
| 181 | 4105 | WORD |
| 182 | 4105 | DWORD |
| 186 | 4105 | Back |
| 187 | 4105 | Forward |
| 188 | 4105 | Next |
| 189 | 4105 | Previous |
| module_name | hint | ord | function_name |
|---|---|---|---|
| ADVAPI32.dll | 608 | RegOpenKeyExA | |
| ADVAPI32.dll | 621 | RegQueryValueExA | |
| ADVAPI32.dll | 560 | RegCloseKey | |
| ADVAPI32.dll | 568 | RegCreateKeyExA | |
| ADVAPI32.dll | 637 | RegSetValueExA | |
| ADVAPI32.dll | 573 | RegDeleteKeyA | |
| ADVAPI32.dll | 615 | RegQueryInfoKeyA | |
| KERNEL32.dll | 281 | ExitProcess | |
| KERNEL32.dll | 533 | GetModuleHandleA | |
| KERNEL32.dll | 390 | GetCommandLineA | |
| KERNEL32.dll | 446 | GetCurrentDirectoryA | |
| KERNEL32.dll | 1100 | SetCurrentDirectoryA | |
| KERNEL32.dll | 1052 | SearchPathA | |
| KERNEL32.dll | 136 | CreateFileA | |
| KERNEL32.dll | 137 | CreateFileMappingA | |
| KERNEL32.dll | 855 | MapViewOfFile | |
| KERNEL32.dll | 496 | GetFileSize | |
| KERNEL32.dll | 1238 | UnmapViewOfFile | |
| KERNEL32.dll | 82 | CloseHandle | |
| KERNEL32.dll | 514 | GetLastError | |
| KERNEL32.dll | 349 | FormatMessageA | |
| KERNEL32.dll | 1048 | RtlUnwind | |
| KERNEL32.dll | 293 | FileTimeToSystemTime | |
| KERNEL32.dll | 454 | GetDateFormatA | |
| KERNEL32.dll | 661 | GetTimeFormatA | |
| KERNEL32.dll | 1257 | VirtualAlloc | |
| KERNEL32.dll | 1260 | VirtualFree | |
| KERNEL32.dll | 1297 | WideCharToMultiByte | |
| USER32.dll | 761 | TranslateAcceleratorA | |
| USER32.dll | 764 | TranslateMessage | |
| USER32.dll | 174 | DispatchMessageA | |
| USER32.dll | 345 | GetMessageA | |
| USER32.dll | 155 | DefWindowProcA | |
| USER32.dll | 494 | LoadImageA | |
| USER32.dll | 588 | RegisterClassExA | |
| USER32.dll | 109 | CreateWindowExA | |
| USER32.dll | 171 | DialogBoxParamA | |
| USER32.dll | 709 | SetWindowPlacement | |
| USER32.dll | 785 | UpdateWindow | |
| USER32.dll | 484 | LoadAcceleratorsA | |
| USER32.dll | 331 | GetMenu | |
| USER32.dll | 673 | SetMenuItemInfoA | |
| USER32.dll | 631 | SendMessageA | |
| USER32.dll | 658 | SetFocus | |
| USER32.dll | 382 | GetSystemMetrics | |
| USER32.dll | 747 | SystemParametersInfoA | |
| USER32.dll | 379 | GetSysColor | |
| USER32.dll | 166 | DestroyWindow | |
| USER32.dll | 567 | PostQuitMessage | |
| USER32.dll | 71 | ClientToScreen | |
| USER32.dll | 412 | GetWindowRect | |
| USER32.dll | 411 | GetWindowPlacement | |
| USER32.dll | 276 | GetClientRect | |
| USER32.dll | 710 | SetWindowPos | |
| USER32.dll | 650 | SetCursorPos | |
| USER32.dll | 648 | SetCursor | |
| USER32.dll | 640 | SetCapture | |
| USER32.dll | 72 | ClipCursor | |
| USER32.dll | 289 | GetDC | |
| USER32.dll | 196 | DrawFocusRect | |
| USER32.dll | 612 | ReleaseCapture | |
| USER32.dll | 613 | ReleaseDC | |
| USER32.dll | 288 | GetCursorPos | |
| USER32.dll | 246 | FillRect | |
| USER32.dll | 446 | InvalidateRect | |
| USER32.dll | 714 | SetWindowTextA | |
| USER32.dll | 565 | PostMessageA | |
| USER32.dll | 659 | SetForegroundWindow | |
| USER32.dll | 526 | MessageBoxA | |
| USER32.dll | 735 | ShowWindow | |
| USER32.dll | 586 | RedrawWindow | |
| USER32.dll | 295 | GetDlgItem | |
| USER32.dll | 218 | EndDialog | |
| USER32.dll | 516 | MapDialogRect | |
| USER32.dll | 699 | SetTimer | |
| USER32.dll | 483 | KillTimer | |
| USER32.dll | 405 | GetWindowLongA | |
| USER32.dll | 707 | SetWindowLongA | |
| USER32.dll | 688 | SetScrollInfo | |
| USER32.dll | 373 | GetScrollInfo | |
| USER32.dll | 623 | ScrollDC | |
| USER32.dll | 14 | BeginPaint | |
| USER32.dll | 220 | EndPaint | |
| GDI32.dll | 631 | SelectObject | |
| GDI32.dll | 230 | DeleteObject | |
| GDI32.dll | 48 | CreateCompatibleDC | |
| GDI32.dll | 19 | BitBlt | |
| GDI32.dll | 227 | DeleteDC | |
| GDI32.dll | 639 | SetBkMode | |
| GDI32.dll | 678 | SetTextColor | |
| GDI32.dll | 75 | CreatePen | |
| GDI32.dll | 61 | CreateFontIndirectA | |
| GDI32.dll | 446 | GetCharacterPlacementA | |
| GDI32.dll | 311 | ExtTextOutA | |
| GDI32.dll | 570 | MoveToEx | |
| GDI32.dll | 566 | LineTo | |
| COMDLG32.dll | 11 | GetOpenFileNameA | |
| COMDLG32.dll | 2 | ChooseFontA | |
| COMCTL32.dll | 102 | InitCommonControlsEx | |
| COMCTL32.dll | 107 | MenuHelp | |
| SHELL32.dll | 29 | DragQueryFileA | |
| SHELL32.dll | 27 | DragFinish |
StringTable 040904E4
| CompanyName | Wayne J. Radburn |
| FileDescription | PE/COFF File Viewer |
| FileVersion | 0.9.9.0 |
| InternalName | PEview |
| LegalCopyright | Copyright© 1997-2011 Wayne J. Radburn |
| OriginalFilename | PEview.exe |
| ProductName | PEview |
| ProductVersion | 0.9.9.0 |
VS_FIXEDFILEINFO
| FileVersion | 0.9.9.0 |
| ProductVersion | 0.9.9.0 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )