|
|
发表于 2006-5-26 09:39:10
|
显示全部楼层
Dump of file C:\Program Files\锐捷网络\Ruijie Supplicant\8021x.exe
File Header
Machine: 014C<i386>
Number of Sections: 0004
TimeDateStamp: 425F166A
PointerToSymbolTable: 00000000
NumberOfSymbols: 00000000
SizeOfOptionalHeader: 00E0
Characteristics: 010F
RELOCS_STRIPPED
EXECUTABLE_IMAGE
LINE_NUMS_STRIPPED
LOCAL_SYMS_STRIPPED
32BIT_MACHINE
Optional Header
Magic 010B
linker versio 6.00
size of code 20000
size of initialized data 13000
size of uninitialized data 0
entrypoint RVA 1E564
base of code 1000
base of data 21000
image base 400000
section align 1000
file align 1000
required OS version 4.00
image version 0.00
subsystem version 4.00
size of image 34000
size of headers 1000
checksum 0
Subsystem 0002<Windows GUI>
stack reserve size 100000
stack commit size 1000
heap reserve size 100000
heap commit size 1000
RVAs & sizes 10
Data Directory
EXPORT rva: 00000000 size: 00000000
IMPORT rva: 000267F8 size: 00000104
RESOURCE rva: 0002B000 size: 00008630
EXCEPTION rva: 00000000 size: 00000000
SECURITY rva: 00000000 size: 00000000
BASERELOC rva: 00000000 size: 00000000
DEBUG rva: 00000000 size: 00000000
COPYRIGHT rva: 00000000 size: 00000000
GLOBALPTR rva: 00000000 size: 00000000
TLS rva: 00000000 size: 00000000
LOAD_CONFIG rva: 00000000 size: 00000000
BOUND_IMPORT rva: 00000000 size: 00000000
IAT rva: 00021000 size: 000006C0
unused rva: 00000000 size: 00000000
unused rva: 00000000 size: 00000000
unused rva: 00000000 size: 00000000
Section Table
01 .text VirtSize: 0001FF12 VirtAddr: 00001000
raw data offs: 00001000 raw data size: 00020000
relocation offs: 00000000 relocations: 00000000
line # offs: 00000000 line #`s: 00000000
characteristics: 60000020
CODE MEM_EXECUTE MEM_READ
02 .rdat VirtSize: 00006C96 VirtAddr: 00021000
raw data offs: 00021000 raw data size: 00007000
relocation offs: 00000000 relocations: 00000000
line # offs: 00000000 line #`s: 00000000
characteristics: 40000040
INITIALIZED_DATA MEM_READ
03 .data VirtSize: 00002AE8 VirtAddr: 00028000
raw data offs: 00028000 raw data size: 00002000
relocation offs: 00000000 relocations: 00000000
line # offs: 00000000 line #`s: 00000000
characteristics: C0000040
INITIALIZED_DATA MEM_READ MEM_WRITE
04 .rsrc VirtSize: 00008630 VirtAddr: 0002B000
raw data offs: 0002A000 raw data size: 00009000
relocation offs: 00000000 relocations: 00000000
line # offs: 00000000 line #`s: 00000000
characteristics: 40000040
INITIALIZED_DATA MEM_READ
Imports Table:
W32N50.dll
Hint/Name Table: 00026F5C
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021660
Ordn Name
75 W32N_OpenAdapterA
70 W32N_IsWindows95
59 W32N_DisableLoopback
80 W32N_PacketSend
72 W32N_MakeNdisRequest
78 W32N_PacketRead
69 W32N_IsWindows2000
64 W32N_GetLastError
57 W32N_CancelPacketRead
71 W32N_IsWindowsNT
82 W32N_SetBPFProgram
58 W32N_CloseAdapter
66 W32N_GetNextAdapterRegistryInfo
63 W32N_GetFirstAdapterRegistryInfo
iphlpapi.dll
Hint/Name Table: 00026FB4
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 000216B8
Ordn Name
25 GetAdaptersInfo
MFC42.DLL
Hint/Name Table: 000269E0
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 000210E4
Ordn Name
1948
2396
3346
5300
5303
4079
4699
5307
5289
5715
4622
4424
3663
0565
0817
2841
2726
4226
0535
6140
0654
0800
0341
0540
2764
0860
2107
5450
5440
6383
6394
0858
0537
4129
5953
6199
2818
4277
2763
6283
0924
0922
0940
0939
0536
2575
4396
3574
6055
1776
5290
3402
3721
4220
2584
3654
0795
0609
1146
1168
0567
2438
2370
2302
1644
2642
6334
6215
0941
6270
2863
2455
2528
2379
2864
1134
0801
2086
6143
0541
2256
0533
0798
2135
0818
1949
4034
0926
2820
3811
0656
0616
5710
5683
3499
0823
0355
2915
1567
0268
1187
1907
5161
5162
5160
4905
4742
4976
4948
4358
4377
4854
5287
4835
0768
0489
4258
3092
2301
4224
6197
6380
4287
6379
3610
2411
2023
4218
2578
4398
3582
1175
1200
6883
1158
1105
4202
6282
4278
6662
3173
5922
3215
0389
5858
6930
4673
4274
6375
4486
2554
2512
5731
1576
1089
5199
5302
4698
5714
3738
0561
0815
2621
2725
2298
2363
2358
6028
2299
2688
3573
3626
2414
0755
0470
1641
1908
1690
5288
4439
2054
4431
0771
1008
0496
4259
4715
3698
0765
6453
3742
1233
4275
2860
2152
5875
5789
2380
3706
2859
4710
4234
0641
0825
0324
3597
4425
4627
4080
3079
3825
3831
3830
2976
3081
2985
3262
3136
4465
3259
3147
2982
5277
2124
2446
5261
1727
5065
3749
6376
2055
2648
4441
4837
3798
5280
4353
6374
5163
2385
5241
4407
1775
4078
6052
2514
4998
4853
4376
5265
2515
3922
MSVCRT.dll
Hint/Name Table: 00026E00
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021504
Ordn Name
85 __dllonexit
14 ??1type_info@@UAE@XZ
605 fread
614 fwrite
720 time
692 srand
657 malloc
390 _onexit
606 free
594 fgets
402 _purecall
351 _mbsicmp
678 rand
600 fprintf
588 fclose
599 fopen
573 atoi
65 _CxxThrowException
211 _exit
72 _XcptFilter
143 _acmdln
88 __getmainargs
271 _initterm
131 __setusermatherr
157 _adjust_fdiv
106 __p__commode
111 __p__fmode
129 __set_app_type
202 _except_handler3
634 isupper
183 _controlfp
308 _itoa
426 _setmbcp
73 __CxxFrameHandler
664 memmove
345 _mbscmp
8 ??0exception@@QAE@ABV0@@Z
585 exit
KERNEL32.dll
Hint/Name Table: 00026954
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021058
Ordn Name
365 GetTickCount
662 Sleep
773 lstrcpynA
718 WaitForSingleObject
27 CloseHandle
282 GetLastError
63 CreateMutexA
308 GetPrivateProfileIntA
613 SetEvent
345 GetSystemDirectoryA
52 CreateFileA
314 GetPrivateProfileStringA
741 WritePrivateProfileStringA
739 WritePrivateProfileSectionA
670 TerminateProcess
68 CreateProcessA
338 GetStdHandle
373 GetVersionExA
250 GetCurrentThreadId
381 GetWindowsDirectoryA
202 GetCommandLineA
723 WinExec
294 GetModuleHandleA
336 GetStartupInfoA
711 VirtualQueryEx
495 OpenProcess
248 GetCurrentProcessId
716 WaitForMultipleObjects
555 ResetEvent
292 GetModuleFileNameA
450 LoadLibraryA
49 CreateEventA
318 GetProcAddress
180 FreeLibrary
USER32.dll
Hint/Name Table: 00026EA8
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 000215AC
Ordn Name
169 DrawIcon
240 GetClientRect
326 GetSystemMetrics
396 IsIconic
170 DrawIconEx
323 GetSysColor
369 InflateRect
604 SetWindowRgn
515 ReleaseDC
253 GetDC
497 RedrawWindow
267 GetIconInfo
416 LoadImageA
208 EnumWindows
314 GetPropA
618 ShowWindow
14 BringWindowToTop
332 GetTopWindow
399 IsWindow
348 GetWindowRect
255 GetDesktopWindow
516 RemoveMenu
252 GetCursorPos
560 SetForegroundWindow
322 GetSubMenu
478 PostMessageA
378 InvalidateRect
342 GetWindowLongA
600 SetWindowLongA
532 SendMessageA
422 LoadMenuA
578 SetPropA
414 LoadIconA
476 PeekMessageA
594 SetTimer
405 KillTimer
446 MessageBoxA
481 PostThreadMessageA
183 EnableWindow
181 EnableMenuItem
GDI32.dll
Hint/Name Table: 0002692C
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021030
Ordn Name
30 CombineRgn
74 CreateRoundRectRgn
71 CreatePolygonRgn
72 CreateRectRgn
168 FillRgn
172 FrameRgn
83 DeleteObject
351 GetStockObject
77 CreateSolidBrush
ADVAPI32.dll
Hint/Name Table: 000268FC
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021000
Ordn Name
327 OpenServiceA
350 RegCreateKeyA
356 RegDeleteValueA
325 OpenSCManagerA
53 ControlService
390 RegSetValueExA
120 DeleteService
52 CloseServiceHandle
370 RegOpenKeyExA
379 RegQueryValueExA
347 RegCloseKey
SHELL32.dll
Hint/Name Table: 00026E9C
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 000215A0
Ordn Name
114 ShellExecuteA
121 Shell_NotifyIconA
WSOCK32.dll
Hint/Name Table: 00026F98
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 0002169C
Ordn Name
0116
0115
0057
0052
0014
0008
VERSION.dll
Hint/Name Table: 00026F4C
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 00021650
Ordn Name
0 GetFileVersionInfoA
10 VerQueryValueA
1 GetFileVersionInfoSizeA
MSVCP60.dll
Hint/Name Table: 00026DD4
TimeDateStamp: 00000000
ForwarderChain: 00000000
First thunk RVA: 000214D8
Ordn Name
193 ??0logic_error@std@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@1@@Z
76 ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDABV?$allocator@D@1@@Z
198 ??0out_of_range@std@@QAE@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@1@@Z
1016 ?_Tidy@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEX_N@Z
687 ??_7out_of_range@std@@6B@
233 ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
287 ??1out_of_range@std@@UAE@XZ
197 ??0out_of_range@std@@QAE@ABV01@@Z
192 ??0logic_error@std@@QAE@ABV01@@Z
1056 ?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z |
|