-
Notifications
You must be signed in to change notification settings - Fork 3
/
EventLogEdit_Lp.dll.dumpbin
205 lines (186 loc) · 7.49 KB
/
EventLogEdit_Lp.dll.dumpbin
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
Dump of file D:\4150\equationGroupWindows\equation_drug\EventLogEdit_Lp.dll
PE signature found
File Type: DLL
FILE HEADER VALUES
14C machine (x86)
4 number of sections
45C38E15 time date stamp Fri Feb 2 21:16:37 2007
0 file pointer to symbol table
0 number of symbols
E0 size of optional header
210E characteristics
Executable
Line numbers stripped
Symbols stripped
32 bit word machine
DLL
OPTIONAL HEADER VALUES
10B magic # (PE32)
7.10 linker version
5000 size of code
F000 size of initialized data
0 size of uninitialized data
37D4 entry point (100037D4)
1000 base of code
6000 base of data
10000000 image base (10000000 to 10014FFF)
1000 section alignment
1000 file alignment
4.00 operating system version
1.00 image version
4.00 subsystem version
0 Win32 version
15000 size of image
1000 size of headers
0 checksum
2 subsystem (Windows GUI)
0 DLL characteristics
100000 size of stack reserve
1000 size of stack commit
100000 size of heap reserve
1000 size of heap commit
0 loader flags
10 number of directories
11770 [ 3E] RVA [size] of Export Directory
10F20 [ 50] RVA [size] of Import Directory
0 [ 0] RVA [size] of Resource Directory
0 [ 0] RVA [size] of Exception Directory
0 [ 0] RVA [size] of Certificates Directory
13000 [ CB8] RVA [size] of Base Relocation Directory
0 [ 0] RVA [size] of Debug Directory
0 [ 0] RVA [size] of Architecture Directory
0 [ 0] RVA [size] of Global Pointer Directory
0 [ 0] RVA [size] of Thread Storage Directory
10618 [ 40] RVA [size] of Load Configuration Directory
0 [ 0] RVA [size] of Bound Import Directory
6000 [ E0] RVA [size] of Import Address Table Directory
0 [ 0] RVA [size] of Delay Import Directory
0 [ 0] RVA [size] of COM Descriptor Directory
0 [ 0] RVA [size] of Reserved Directory
SECTION HEADER #1
.text name
4DDF virtual size
1000 virtual address (10001000 to 10005DDE)
5000 size of raw data
1000 file pointer to raw data (00001000 to 00005FFF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers
60000020 flags
Code
Execute Read
SECTION HEADER #2
.rdata name
B7AE virtual size
6000 virtual address (10006000 to 100117AD)
C000 size of raw data
6000 file pointer to raw data (00006000 to 00011FFF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers
40000040 flags
Initialized Data
Read Only
Section contains the following imports:
MSVCP71.dll
10006024 Import Address Table
10010F94 Import Name Table
0 time date stamp
0 Index of first forwarder reference
21F ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
151 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z
158 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z
220 ??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ
314 ??Y?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV01@ABV01@@Z
15E ??0?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@ABV01@@Z
165 ??0?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@PBG@Z
316 ??Y?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV01@PBG@Z
315 ??Y?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV01@G@Z
16A ??0?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ
4DA ?_Nomemory@std@@YAXXZ
273 ??4?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV01@PBG@Z
9D7 ?reserve@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEXI@Z
271 ??4?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAEAAV01@ABV01@@Z
8C ??$?MGU?$char_traits@G@std@@V?$allocator@G@1@@std@@YA_NABV?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@0@0@Z
KERNEL32.dll
10006000 Import Address Table
10010F70 Import Name Table
0 time date stamp
0 Index of first forwarder reference
383 WaitForSingleObject
2E CloseHandle
5A CreateMutexA
EB FormatMessageW
387 WideCharToMultiByte
26B MultiByteToWideChar
84 DisableThreadLibraryCalls
2B6 ReleaseMutex
MSVCR71.dll
10006064 Import Address Table
10010FD4 Import Name Table
0 time date stamp
0 Index of first forwarder reference
44 _CxxThrowException
2E5 memcpy
30C strlen
334 wcslen
2AC free
2DF malloc
226 _vsnwprintf
308 strcpy
331 wcscpy
2E7 memset
F1 _except_handler3
12 ??3@YAXPAX@Z
10 ??1type_info@@UAE@XZ
13F _initterm
BB _adjust_fdiv
4C __CppXcptFilter
2E ?terminate@@YAXXZ
6B __dllonexit
1B8 _onexit
51 __CxxFrameHandler
A ??0exception@@QAE@ABV0@@Z
F ??1exception@@UAE@XZ
B ??0exception@@QAE@XZ
1EA _snwprintf
20 ??_V@YAXPAX@Z
2C9 iswalnum
2CA iswalpha
2BC gmtime
31E time
CC _callnewh
SECTION HEADER #3
.data name
180 virtual size
12000 virtual address (10012000 to 1001217F)
1000 size of raw data
12000 file pointer to raw data (00012000 to 00012FFF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers
C0000040 flags
Initialized Data
Read Write
SECTION HEADER #4
.reloc name
13E0 virtual size
13000 virtual address (10013000 to 100143DF)
2000 size of raw data
13000 file pointer to raw data (00013000 to 00014FFF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers
42000040 flags
Initialized Data
Discardable
Read Only
Summary
1000 .data
C000 .rdata
2000 .reloc
5000 .text