| parent | PEview9small.exe | |
|---|---|---|
| filename | PEview9small.unpacked.exe | |
| size | 67584 (0x10800) | |
| md5 | f212eab0b0600ac312a204d2819101a2 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x6c |
| blocks_in_file | 1 |
| num_relocs | 0 |
| header_paragraphs | 2 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0 |
| checksum | 0 |
| ip | 0x11 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0x336e695700000000 |
| oem_id | 0x2032 |
| oem_info | 0x7250 |
| reserved2 | 0x6172676f |
| reserved3 | 0xa0d216d |
| reserved4 | 0xba09b424 |
| reserved5 | 0x21cd0100 |
| reserved6 | 0x21cd4cb4 |
| lfanew | 0x60 |
DOS stub
00000000: 57 69 6e 33 32 20 50 72 6f 67 72 61 6d 21 0d 0a |Win32 Program!..| 00000010: 24 b4 09 ba 00 01 cd 21 b4 4c cd 21 60 00 00 00 |$......!.L.!`...| 00000020: 47 6f 4c 69 6e 6b 2c 20 47 6f 41 73 6d 20 77 77 |GoLink, GoAsm ww| 00000030: 77 2e 47 6f 44 65 76 54 6f 6f 6c 2e 63 6f 6d 00 |w.GoDevTool.com.|
PE Header
Packer / Compiler
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| code | 0x1000 | 0x8110 | 0x8200 | R-X CODE | |
| data | 0xa000 | 0x1278 | 0x400 | RW- IDATA | |
| const | 0xc000 | 0x33b0 | 0x3400 | R-- IDATA | |
| .rsrc | 0x10000 | 0x3b00 | 0x3c00 | R-- IDATA | |
| .idata | 0x14000 | 0xd56 | 0xe00 | R-X CODE |
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0 | 0 | |
| IMPORT | 0x14264 | 0xa0 | |
| RESOURCE | 0x10000 | 0x3b00 | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0 | 0 | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0 | 0 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0 | 0 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| id | lang | string |
|---|---|---|
| 32 | 4105 | Commands for working with files. |
| 33 | 4105 | Commands for customizing this window. |
| 34 | 4105 | Commands for accessing view history. |
| 35 | 4105 | Commands for displaying Help. |
| 36 | 4105 | Open an existing file. |
| 37 | 4105 | Close the current file. |
| 38 | 4105 | Quit PEview. |
| 39 | 4105 | Show or hide the toolbar. |
| 40 | 4105 | Show or hide the status bar. |
| 41 | 4105 | Show or hide the treeview. |
| 42 | 4105 | Show or hide the header. |
| 43 | 4105 | Options for displaying the address. |
| 44 | 4105 | Display the address as an offset from the start of the file. |
| 45 | 4105 | Display the address as an offset from the start of the view. |
| 46 | 4105 | Display the address for sections as a relative virtual address. |
| 47 | 4105 | Display the address as a virtual address or as an offset from the start of an OBJ file. |
| 48 | 4105 | Options for displaying raw data. |
| 49 | 4105 | Display the raw data in BYTE format. |
| 50 | 4105 | Display the raw data in WORD format. |
| 51 | 4105 | Display the raw data in DWORD format. |
| 52 | 4105 | Change the split position between the two panes. |
| 53 | 4105 | Change the current font. |
| 54 | 4105 | Change additional program settings. |
| 55 | 4105 | Go back one step in the view history list. |
| 56 | 4105 | Go forward one step in the view history list. |
| 57 | 4105 | Go to next item in contents. |
| 58 | 4105 | Go to previous item in contents. |
| 59 | 4105 | Save additional view position for the current view to the view history list. |
| 60 | 4105 | Display program information, version number, and copyright. |
| 167 | 4105 | Open |
| 175 | 4105 | File Offset |
| 176 | 4105 | View Offset |
| 177 | 4105 | RVA |
| 178 | 4105 | VA |
| 180 | 4105 | BYTE |
| 181 | 4105 | WORD |
| 182 | 4105 | DWORD |
| 186 | 4105 | Back |
| 187 | 4105 | Forward |
| 188 | 4105 | Next |
| 189 | 4105 | Previous |
StringTable 040904E4
| CompanyName | Wayne J. Radburn |
| FileDescription | PE/COFF File Viewer |
| FileVersion | 0.9.9.0 |
| InternalName | PEview |
| LegalCopyright | Copyright© 1997-2011 Wayne J. Radburn |
| OriginalFilename | PEview.exe |
| ProductName | PEview |
| ProductVersion | 0.9.9.0 |
VS_FIXEDFILEINFO
| FileVersion | 0.9.9.0 |
| ProductVersion | 0.9.9.0 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )