perdr 349b526e1e5f5a13ecf6e5d4222ad4ff
PeRdr by Frediano Ziglio. Build Jan 4 2004
File header information
Machine I386
Section # 3
TimeStamp 2A425E19
SymbolTable pointer 00000000
Symbol # 0
Optional header size 224
Characteristics 818F
Relocation info stripped from file
File is executable
Line nunbers stripped from file
Local symbols stripped from file
Bytes of machine word are reversed
32 bit word machine
Bytes of machine word are reversed
Optional header information
Magic 010B
Linker 2.25
Code size 00009000
Initialized data size 00001000
Uninitialized data size 00012000
Entry point RVA 0001BAEF
Code base RVA 00013000
Data base RVA 0001C000
Image base 00400000
Section/File align 00001000/00000200
O/S version 4.0
Image version 0.0
Subsystem version 4.0
Win32 version 00000000
Image size 0001D000
Headers size 00001000
Checksum 00000000
Subsystem 2 (Windows GUI)
DLL flags 00000000
Stack reserve/commit 00100000/00004000
Heap reserve/commit 00100000/00001000
Loader flags 00000000
RVA # 16
Name RVA Size
-----------------------------
Export 00000000 00000000
Import 0001C9C0 000001B8
Resource 0001C000 000009C0
Exception 00000000 00000000
Security 00000000 00000000
Relocation 00000000 00000000
Debug 00000000 00000000
Copyright 00000000 00000000
GlobalPtr 00000000 00000000
TLS 0001BC4C 00000018
Load Configuration 00000000 00000000
Bound Import 00000000 00000000
IAT 00000000 00000000
Delayed Imports 00000000 00000000
COM Runtime 00000000 00000000
Reserved 00000000 00000000
Section 0
Name code
PhysicalAddress 00012000
VirtualAddress 00001000
Size of raw data 00000000
Pointer to raw data 00000400
Pointer to relocations 00000000
Pointer to linenumbers 00000000
Number of relocations 0000
Number of line numbers 0000
Characteristics
Section contains initialized data
Readable
Writeable
Section 1
Name text
PhysicalAddress 00009000
VirtualAddress 00013000
Size of raw data 00008E00
Pointer to raw data 00000400
Pointer to relocations 00000000
Pointer to linenumbers 00000000
Number of relocations 0000
Number of line numbers 0000
Characteristics
Section contains initialized data
Readable
Writeable
Section 2
Name .rsrc
PhysicalAddress 00001000
VirtualAddress 0001C000
Size of raw data 00000C00
Pointer to raw data 00009200
Pointer to relocations 00000000
Pointer to linenumbers 00000000
Number of relocations 0000
Number of line numbers 0000
Characteristics
Section contains initialized data
Readable
Writeable
DLL: KERNEL32.DLL
Addr:0001CA60 hint:0(0000) Name:LoadLibraryA
Addr:0001CA64 hint:0(0000) Name:GetProcAddress
Addr:0001CA68 hint:0(0000) Name:ExitProcess
DLL: advapi32.dll
Addr:0001CA70 hint:0(0000) Name:RegCloseKey
DLL: mpr.dll
Addr:0001CA78 hint:0(0000) Name:WNetAddConnection2A
DLL: oleaut32.dll
Addr:0001CA80 hint:0(0000) Name:SysFreeString
DLL: URLMON.DLL
Addr:0001CA88 hint:0(0000) Name:URLDownloadToFileA
DLL: user32.dll
Addr:0001CA90 hint:0(0000) Name:CharNextA
DLL: wsock32.dll
Addr:0001CA98 hint:0(0000) Name:send
Resources
Characteristics 00000000
TimeDateStamp 307FBA99 Sat Oct 14 14:26:49 1995
Version 0:0
Entryes 0 named 3 id
Type icon (3)
Entryes 0 named 1 id
ID 1
Entryes 0 named 1 id
LangID 1031
OffsetToData 0001C100
Size 000008A8
CodePage 00000000
Reserved 00000000
00000000 28 00 00 00 20 00 00 00-40 00 00 00 01 00 08 00 (... ...@.......
00000010 00 00 00 00 80 04 00 00-00 00 00 00 00 00 00 00 ................
00000020 00 00 00 00 00 00 00 00-00 00 00 00 00 00 80 00 ................
00000030 00 80 00 00 00 80 80 00-80 00 00 00 80 00 80 00 ................
00000040 80 80 00 00 C0 C0 C0 00-C0 DC C0 00 F0 CA A6 00 ................
00000050 00 20 40 00 00 20 60 00-00 20 80 00 00 20 A0 00 . @.. `.. ... ..
00000060 00 20 C0 00 00 20 E0 00-00 40 00 00 00 40 20 00 . ... ...@...@ .
00000070 00 40 40 00 00 40 60 00-00 40 80 00 00 40 A0 00 .@@..@`..@...@..
00000080 00 40 C0 00 00 40 E0 00-00 60 00 00 00 60 20 00 .@...@...`...` .
00000090 00 60 40 00 00 60 60 00-00 60 80 00 00 60 A0 00 .`@..``..`...`..
000000A0 00 60 C0 00 00 60 E0 00-00 80 00 00 00 80 20 00 .`...`........ .
000000B0 00 80 40 00 00 80 60 00-00 80 80 00 00 80 A0 00 ..@...`.........
000000C0 00 80 C0 00 00 80 E0 00-00 A0 00 00 00 A0 20 00 .............. .
000000D0 00 A0 40 00 00 A0 60 00-00 A0 80 00 00 A0 A0 00 ..@...`.........
000000E0 00 A0 C0 00 00 A0 E0 00-00 C0 00 00 00 C0 20 00 .............. .
000000F0 00 C0 40 00 00 C0 60 00-00 C0 80 00 00 C0 A0 00 ..@...`.........
00000100 00 C0 C0 00 00 C0 E0 00-00 E0 00 00 00 E0 20 00 .............. .
00000110 00 E0 40 00 00 E0 60 00-00 E0 80 00 00 E0 A0 00 ..@...`.........
00000120 00 E0 C0 00 00 E0 E0 00-40 00 00 00 40 00 20 00 ........@...@. .
00000130 40 00 40 00 40 00 60 00-40 00 80 00 40 00 A0 00 @.@.@.`.@...@...
00000140 40 00 C0 00 40 00 E0 00-40 20 00 00 40 20 20 00 @...@...@ ..@ .
00000150 40 20 40 00 40 20 60 00-40 20 80 00 40 20 A0 00 @ @.@ `.@ ..@ ..
00000160 40 20 C0 00 40 20 E0 00-40 40 00 00 40 40 20 00 @ ..@ ..@@..@@ .
00000170 40 40 40 00 40 40 60 00-40 40 80 00 40 40 A0 00 @@@.@@`.@@..@@..
00000180 40 40 C0 00 40 40 E0 00-40 60 00 00 40 60 20 00 @@..@@..@`..@` .
00000190 40 60 40 00 40 60 60 00-40 60 80 00 40 60 A0 00 @`@.@``.@`..@`..
000001A0 40 60 C0 00 40 60 E0 00-40 80 00 00 40 80 20 00 @`..@`..@...@. .
000001B0 40 80 40 00 40 80 60 00-40 80 80 00 40 80 A0 00 @.@.@.`.@...@...
000001C0 40 80 C0 00 40 80 E0 00-40 A0 00 00 40 A0 20 00 @...@...@...@. .
000001D0 40 A0 40 00 40 A0 60 00-40 A0 80 00 40 A0 A0 00 @.@.@.`.@...@...
000001E0 40 A0 C0 00 40 A0 E0 00-40 C0 00 00 40 C0 20 00 @...@...@...@. .
000001F0 40 C0 40 00 40 C0 60 00-40 C0 80 00 40 C0 A0 00 @.@.@.`.@...@...
00000200 40 C0 C0 00 40 C0 E0 00-40 E0 00 00 40 E0 20 00 @...@...@...@. .
00000210 40 E0 40 00 40 E0 60 00-40 E0 80 00 40 E0 A0 00 @.@.@.`.@...@...
00000220 40 E0 C0 00 40 E0 E0 00-80 00 00 00 80 00 20 00 @...@......... .
00000230 80 00 40 00 80 00 60 00-80 00 80 00 80 00 A0 00 ..@...`.........
00000240 80 00 C0 00 80 00 E0 00-80 20 00 00 80 20 20 00 ......... ... .
00000250 80 20 40 00 80 20 60 00-80 20 80 00 80 20 A0 00 . @.. `.. ... ..
00000260 80 20 C0 00 80 20 E0 00-80 40 00 00 80 40 20 00 . ... ...@...@ .
00000270 80 40 40 00 80 40 60 00-80 40 80 00 80 40 A0 00 .@@..@`..@...@..
00000280 80 40 C0 00 80 40 E0 00-80 60 00 00 80 60 20 00 .@...@...`...` .
00000290 80 60 40 00 80 60 60 00-80 60 80 00 80 60 A0 00 .`@..``..`...`..
000002A0 80 60 C0 00 80 60 E0 00-80 80 00 00 80 80 20 00 .`...`........ .
000002B0 80 80 40 00 80 80 60 00-80 80 80 00 80 80 A0 00 ..@...`.........
000002C0 80 80 C0 00 80 80 E0 00-80 A0 00 00 80 A0 20 00 .............. .
000002D0 80 A0 40 00 80 A0 60 00-80 A0 80 00 80 A0 A0 00 ..@...`.........
000002E0 80 A0 C0 00 80 A0 E0 00-80 C0 00 00 80 C0 20 00 .............. .
000002F0 80 C0 40 00 80 C0 60 00-80 C0 80 00 80 C0 A0 00 ..@...`.........
00000300 80 C0 C0 00 80 C0 E0 00-80 E0 00 00 80 E0 20 00 .............. .
00000310 80 E0 40 00 80 E0 60 00-80 E0 80 00 80 E0 A0 00 ..@...`.........
00000320 80 E0 C0 00 80 E0 E0 00-C0 00 00 00 C0 00 20 00 .............. .
00000330 C0 00 40 00 C0 00 60 00-C0 00 80 00 C0 00 A0 00 ..@...`.........
00000340 C0 00 C0 00 C0 00 E0 00-C0 20 00 00 C0 20 20 00 ......... ... .
00000350 C0 20 40 00 C0 20 60 00-C0 20 80 00 C0 20 A0 00 . @.. `.. ... ..
00000360 C0 20 C0 00 C0 20 E0 00-C0 40 00 00 C0 40 20 00 . ... ...@...@ .
00000370 C0 40 40 00 C0 40 60 00-C0 40 80 00 C0 40 A0 00 .@@..@`..@...@..
00000380 C0 40 C0 00 C0 40 E0 00-C0 60 00 00 C0 60 20 00 .@...@...`...` .
00000390 C0 60 40 00 C0 60 60 00-C0 60 80 00 C0 60 A0 00 .`@..``..`...`..
000003A0 C0 60 C0 00 C0 60 E0 00-C0 80 00 00 C0 80 20 00 .`...`........ .
000003B0 C0 80 40 00 C0 80 60 00-C0 80 80 00 C0 80 A0 00 ..@...`.........
000003C0 C0 80 C0 00 C0 80 E0 00-C0 A0 00 00 C0 A0 20 00 .............. .
000003D0 C0 A0 40 00 C0 A0 60 00-C0 A0 80 00 C0 A0 A0 00 ..@...`.........
000003E0 C0 A0 C0 00 C0 A0 E0 00-C0 C0 00 00 C0 C0 20 00 .............. .
000003F0 C0 C0 40 00 C0 C0 60 00-C0 C0 80 00 C0 C0 A0 00 ..@...`.........
00000400 F0 FB FF 00 A4 A0 A0 00-80 80 80 00 00 00 FF 00 ................
00000410 00 FF 00 00 00 FF FF 00-FF 00 00 00 FF 00 FF 00 ................
00000420 FF FF 00 00 FF FF FF 00-00 00 00 00 00 00 00 00 ................
00000430 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000440 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000450 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000460 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000470 00 00 00 00 00 00 00 00-00 00 00 00 02 01 00 00 ................
00000480 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000490 00 00 00 00 00 00 00 00-00 01 02 02 02 00 00 00 ................
000004A0 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000004B0 00 00 00 00 00 00 00 01-02 02 02 03 03 00 07 00 ................
000004C0 00 00 A4 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000004D0 00 00 00 07 01 02 02 02-02 03 03 03 03 00 07 07 ................
000004E0 00 00 A4 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000004F0 00 01 02 07 02 02 03 03-03 03 03 06 06 06 00 07 ................
00000500 07 00 A4 00 00 00 00 00-00 00 00 00 00 00 00 01 ................
00000510 02 02 02 07 03 03 03 03-03 06 06 00 00 00 00 00 ................
00000520 07 07 A4 00 00 00 00 00-00 00 00 00 01 02 02 02 ................
00000530 02 03 03 07 03 03 03 06-06 00 00 00 04 04 00 00 ................
00000540 00 00 A4 07 00 00 00 00-00 00 01 02 07 06 03 03 ................
00000550 03 03 03 07 06 06 06 00-00 00 04 04 FC 00 00 00 ................
00000560 00 00 A4 07 07 07 00 00-00 01 02 02 FE 03 03 03 ................
00000570 03 06 06 07 00 00 00 00-04 04 FC FC FC 00 00 00 ................
00000580 00 00 A4 00 00 07 00 00-00 02 03 03 FE 03 03 06 ................
00000590 06 00 00 07 00 04 04 04-FC FC FC FC FC 00 07 07 ................
000005A0 00 00 A4 00 00 00 00 00-00 03 03 03 06 06 06 00 ................
000005B0 00 00 04 07 04 FC FC FC-FC FC FC FC FC FC 00 07 ................
000005C0 07 07 A4 00 00 00 00 00-00 06 06 06 00 00 00 00 ................
000005D0 04 04 FC 07 FC FC FC FC-FC FC FC 00 00 00 00 00 ................
000005E0 00 07 A4 07 00 00 00 00-00 00 00 00 00 04 04 04 ................
000005F0 FC FC FC 07 FC FC FC FC-FC 00 00 00 01 01 00 00 ................
00000600 00 00 A4 07 07 07 00 00-00 00 04 04 04 FC FC FC ................
00000610 FC FC FC 07 FC FC FC 00-00 00 01 01 01 00 00 00 ................
00000620 00 00 A4 00 00 07 00 00-00 00 04 FC FA FC FC FC ................
00000630 FC FC FC 07 00 00 00 00-01 01 01 05 05 00 07 00 ................
00000640 00 00 A4 00 00 00 00 00-00 FC FC FC FA FC FC FC ................
00000650 FC 00 00 07 00 01 01 01-01 05 05 05 05 00 07 07 ................
00000660 00 00 A4 00 00 00 00 00-00 FC FC FC FA FC FC 00 ................
00000670 00 00 01 07 01 01 05 05-05 05 05 05 05 05 00 07 ................
00000680 07 00 A4 00 00 00 00 00-00 FC FC FC 00 00 00 01 ................
00000690 01 01 01 07 05 05 05 05-05 05 05 05 05 00 05 00 ................
000006A0 07 07 A4 00 00 00 00 00-00 00 00 00 00 01 01 01 ................
000006B0 05 05 05 07 05 05 05 05-05 05 00 00 00 05 05 05 ................
000006C0 00 00 A4 07 07 00 00 00-00 00 01 01 01 07 05 05 ................
000006D0 05 05 05 07 05 05 05 00-00 00 05 05 05 05 05 05 ................
000006E0 07 07 00 00 07 07 00 00-00 00 01 01 05 FB 05 05 ................
000006F0 05 05 05 07 00 00 00 05-05 05 05 05 05 05 07 07 ................
00000700 05 05 05 05 00 00 00 00-00 05 05 05 05 FB 05 05 ................
00000710 05 05 00 00 07 05 05 05-05 05 05 07 07 07 05 05 ................
00000720 05 05 05 05 05 05 00 00-00 00 05 05 05 05 05 00 ................
00000730 00 00 05 05 05 07 07 05-05 07 07 05 05 05 05 05 ................
00000740 05 05 05 00 00 00 00 00-00 00 05 05 00 00 00 05 ................
00000750 05 05 05 05 05 05 07 07-07 07 05 05 05 05 05 05 ................
00000760 05 00 00 00 00 00 00 00-00 00 00 00 05 05 05 05 ................
00000770 05 05 05 05 07 07 05 07-05 07 07 07 07 05 00 00 ................
00000780 00 00 00 00 00 00 00 00-00 00 00 00 05 05 05 05 ................
00000790 05 07 07 07 05 05 05 07-05 05 07 00 00 00 00 00 ................
000007A0 00 00 00 00 00 00 00 00-00 00 00 00 00 00 05 07 ................
000007B0 07 05 05 05 05 05 07 05-00 00 00 07 00 00 00 00 ................
000007C0 00 00 00 00 00 00 00 00-00 00 00 00 00 07 07 00 ................
000007D0 05 05 05 05 05 05 07 00-00 00 00 00 00 00 00 00 ................
000007E0 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
000007F0 00 00 05 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000800 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000810 00 00 00 00 00 00 00 00-00 00 00 00 00 00 00 00 ................
00000820 00 00 00 00 00 00 00 00-FF FF FF FF FF FF E1 FF ................
00000830 FF FF 80 7F FF FE 03 BF-FF F0 01 CF FF 80 00 D3 ................
00000840 FE 00 00 5D F0 00 00 1E-C0 00 00 0E 80 00 03 81 ...]............
00000850 00 00 03 C1 00 00 00 D1-00 00 00 1C 00 00 00 0E ................
00000860 00 00 01 01 80 00 03 C1-00 00 01 D1 00 00 00 DC ................
00000870 00 00 00 5E 00 00 00 1D-00 00 00 05 80 00 00 01 ...^............
00000880 00 00 00 00 00 00 00 00-00 00 00 03 80 00 00 1F ................
00000890 80 00 00 7F E0 00 03 FF-F0 00 0F FF F8 00 FF FF ................
000008A0 FF 03 FF FF FF 8F FF FF- ........
Type unformatted resource data (10)
Entryes 1 named 0 id
ID DVCLAL
Entryes 0 named 1 id
LangID 0
OffsetToData 000199A4
Size 00000010
CodePage 00000000
Reserved 00000000
00000000 30 39 22 2C 78 48 19 24-2F 26 2B 3B 70 34 68 3B 09",xH.$/&+;p4h;
Type group icon (14)
Entryes 1 named 0 id
ID _
Entryes 0 named 1 id
LangID 1031
OffsetToData 0001C9AC
Size 00000014
CodePage 00000000
Reserved 00000000
00000000 00 00 01 00 01 00 20 20-08 00 01 00 04 00 A8 08 ...... ........
00000010 00 00 01 00 ....