home *** CD-ROM | disk | FTP | other *** search
Unknown | 2005-07-11 | 2.0 KB |
open in:
MacOS 8.1
|
Win98
|
DOS
view JSON data
|
view as text
This file was not able to be converted.
This format is not currently supported by dexvert.
Confidence | Program | Detection | Match Type | Support
|
---|
100%
| file
| data
| default
| |
100%
| gt2
| Kopftext: 'KmxBiG Driver - DriverEntry
| default (weak)
|
|
hex view+--------+-------------------------+-------------------------+--------+--------+
|00000000| 4b 6d 78 42 69 47 20 44 | 72 69 76 65 72 20 2d 20 |KmxBiG D|river - |
|00000010| 44 72 69 76 65 72 45 6e | 74 72 79 0a 43 6f 6d 70 |DriverEn|try.Comp|
|00000020| 69 6c 65 64 20 61 74 20 | 32 33 3a 32 31 3a 30 39 |iled at |23:21:09|
|00000030| 20 6f 6e 20 4a 75 6c 20 | 31 31 20 32 30 30 35 0a | on Jul |11 2005.|
|00000040| 00 00 00 00 4b 00 6d 00 | 78 00 42 00 69 00 47 00 |....K.m.|x.B.i.G.|
|00000050| 4c 00 6f 00 67 00 00 00 | 4b 6d 78 42 69 47 20 2d |L.o.g...|KmxBiG -|
|00000060| 20 44 72 69 76 65 72 45 | 6e 74 72 79 0a 00 00 00 | DriverE|ntry....|
|00000070| 5c 00 44 00 65 00 76 00 | 69 00 63 00 65 00 5c 00 |\.D.e.v.|i.c.e.\.|
|00000080| 4b 00 6d 00 78 00 42 00 | 69 00 47 00 00 00 00 00 |K.m.x.B.|i.G.....|
|00000090| 5c 00 44 00 6f 00 73 00 | 44 00 65 00 76 00 69 00 |\.D.o.s.|D.e.v.i.|
|000000a0| 63 00 65 00 73 00 5c 00 | 4b 00 6d 00 78 00 42 00 |c.e.s.\.|K.m.x.B.|
|000000b0| 69 00 47 00 00 00 00 00 | 44 72 69 76 65 72 45 6e |i.G.....|DriverEn|
|000000c0| 74 72 79 20 2d 20 45 72 | 72 6f 72 20 6c 6f 61 64 |try - Er|ror load|
|000000d0| 69 6e 67 20 4b 6d 78 42 | 69 47 0a 00 cc cc cc cc |ing KmxB|iG......|
|000000e0| 83 ec 10 56 68 00 70 01 | 00 e8 94 c2 ff ff 83 c4 |...Vh.p.|........|
|000000f0| 04 68 4b 6d 78 42 e8 a5 | aa ff ff e8 e0 a9 ff ff |.hKmxB..|........|
|00000100| 8b f0 85 f6 74 0e e8 a5 | aa ff ff 8b c6 5e 83 c4 |....t...|.....^..|
|00000110| 10 c2 08 00 8b 44 24 1c | 53 57 68 44 70 01 00 68 |.....D$.|SWhDp..h|
|00000120| 18 40 01 00 50 e8 96 b8 | ff ff 8b 0d 30 40 01 00 |.@..P...|....0@..|
|00000130| 68 58 70 01 00 68 fc 10 | 01 00 51 68 18 40 01 00 |hXp..h..|..Qh.@..|
|00000140| e8 2b b6 ff ff 8b 1d 28 | 10 01 00 83 c4 10 68 70 |.+.....(|......hp|
|00000150| 70 01 00 8d 54 24 10 52 | ff d3 8b 74 24 20 68 10 |p...T$.R|...t$ h.|
|00000160| 40 01 00 6a 00 6a 00 6a | 22 8d 44 24 1c 50 6a 00 |@..j.j.j|".D$.Pj.|
|00000170| 56 ff 15 24 10 01 00 8b | f8 85 ff 7c 4c 68 90 70 |V..$....|...|Lh.p|
|00000180| 01 00 8d 4c 24 18 51 ff | d3 8b 3d 20 10 01 00 8d |...L$.Q.|..= ....|
|00000190| 54 24 0c 52 8d 44 24 18 | 50 ff d7 85 c0 7d 3a 8d |T$.R.D$.|P....}:.|
|000001a0| 4c 24 14 51 ff 15 1c 10 | 01 00 8d 54 24 0c 52 8d |L$.Q....|...T$.R.|
|000001b0| 44 24 18 50 ff d7 8b f8 | 85 ff 7d 1d 8b 0d 10 40 |D$.P....|..}....@|
|000001c0| 01 00 51 ff 15 14 10 01 | 00 e8 e2 a9 ff ff 8b c7 |..Q.....|........|
|000001d0| 5f 5b 5e 83 c4 10 c2 08 | 00 8b 15 10 40 01 00 89 |_[^.....|....@...|
|000001e0| 15 3c 40 01 00 b8 e0 19 | 01 00 89 46 70 89 46 74 |.<@.....|...Fp.Ft|
|000001f0| 89 46 38 89 46 40 89 86 | 80 00 00 00 c7 46 34 c0 |.F8.F@..|.....F4.|
|00000200| 19 01 00 e8 28 a0 ff ff | 8b f0 85 f6 7d 2f a1 30 |....(...|....}/.0|
|00000210| 40 01 00 68 b8 70 01 00 | 68 fc 10 01 00 50 68 18 |@..h.p..|h....Ph.|
|00000220| 40 01 00 e8 48 b5 ff ff | 8b 0d 10 40 01 00 83 c4 |@...H...|...@....|
|00000230| 10 51 ff 15 14 10 01 00 | e8 73 a9 ff ff 5f 5b 8b |.Q......|.s..._[.|
|00000240| c6 5e 83 c4 10 c2 08 00 | 94 72 00 00 00 00 00 00 |.^......|.r......|
|00000250| 00 00 00 00 3a 77 00 00 | 10 10 00 00 84 72 00 00 |....:w..|.....r..|
|00000260| 00 00 00 00 00 00 00 00 | 88 77 00 00 00 10 00 00 |........|.w......|
|00000270| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000280| 00 00 00 00 5e 77 00 00 | 48 77 00 00 74 77 00 00 |....^w..|Hw..tw..|
|00000290| 00 00 00 00 a6 73 00 00 | ba 73 00 00 cc 73 00 00 |.....s..|.s...s..|
|000002a0| e2 73 00 00 fa 73 00 00 | 12 74 00 00 24 74 00 00 |.s...s..|.t..$t..|
|000002b0| 3c 74 00 00 48 74 00 00 | 58 74 00 00 62 74 00 00 |<t..Ht..|Xt..bt..|
|000002c0| 6c 74 00 00 8a 74 00 00 | a8 74 00 00 bc 74 00 00 |lt...t..|.t...t..|
|000002d0| de 74 00 00 f2 74 00 00 | 14 75 00 00 30 75 00 00 |.t...t..|.u..0u..|
|000002e0| 44 75 00 00 54 75 00 00 | 70 75 00 00 7a 75 00 00 |Du..Tu..|pu..zu..|
|000002f0| 88 75 00 00 a6 75 00 00 | b8 75 00 00 ca 75 00 00 |.u...u..|.u...u..|
|00000300| e0 75 00 00 ea 75 00 00 | f4 75 00 00 02 76 00 00 |.u...u..|.u...v..|
|00000310| 1a 76 00 00 9c 73 00 00 | 3c 76 00 00 4c 76 00 00 |.v...s..|<v..Lv..|
|00000320| 64 76 00 00 84 76 00 00 | a0 76 00 00 ac 76 00 00 |dv...v..|.v...v..|
|00000330| be 76 00 00 ca 76 00 00 | d8 76 00 00 e8 76 00 00 |.v...v..|.v...v..|
|00000340| f6 76 00 00 0a 77 00 00 | 24 77 00 00 86 73 00 00 |.v...w..|$w...s..|
|00000350| 78 73 00 00 32 76 00 00 | 60 73 00 00 00 00 00 00 |xs..2v..|`s......|
|00000360| 3a 00 45 78 41 6c 6c 6f | 63 61 74 65 50 6f 6f 6c |:.ExAllo|catePool|
|00000370| 57 69 74 68 54 61 67 00 | 47 00 45 78 46 72 65 65 |WithTag.|G.ExFree|
|00000380| 50 6f 6f 6c 00 00 3a 01 | 49 6f 47 65 74 43 75 72 |Pool..:.|IoGetCur|
|00000390| 72 65 6e 74 50 72 6f 63 | 65 73 73 00 bb 04 77 63 |rentProc|ess...wc|
|000003a0| 73 63 70 79 00 00 0c 03 | 52 74 6c 43 6f 6d 70 61 |scpy....|RtlCompa|
|000003b0| 72 65 4d 65 6d 6f 72 79 | 00 00 25 01 49 6f 44 65 |reMemory|..%.IoDe|
|000003c0| 6c 65 74 65 44 65 76 69 | 63 65 00 00 97 01 49 6f |leteDevi|ce....Io|
|000003d0| 66 43 6f 6d 70 6c 65 74 | 65 52 65 71 75 65 73 74 |fComplet|eRequest|
|000003e0| 00 00 27 01 49 6f 44 65 | 6c 65 74 65 53 79 6d 62 |..'.IoDe|leteSymb|
|000003f0| 6f 6c 69 63 4c 69 6e 6b | 00 00 21 01 49 6f 43 72 |olicLink|..!.IoCr|
|00000400| 65 61 74 65 53 79 6d 62 | 6f 6c 69 63 4c 69 6e 6b |eateSymb|olicLink|
|00000410| 00 00 1b 01 49 6f 43 72 | 65 61 74 65 44 65 76 69 |....IoCr|eateDevi|
|00000420| 63 65 00 00 66 03 52 74 | 6c 49 6e 69 74 55 6e 69 |ce..f.Rt|lInitUni|
|00000430| 63 6f 64 65 53 74 72 69 | 6e 67 00 00 2d 00 44 62 |codeStri|ng..-.Db|
|00000440| 67 50 72 69 6e 74 00 00 | 36 04 5a 77 4c 6f 61 64 |gPrint..|6.ZwLoad|
|00000450| 44 72 69 76 65 72 00 00 | b8 04 77 63 73 63 61 74 |Driver..|..wcscat|
|00000460| 00 00 bd 04 77 63 73 6c | 65 6e 00 00 5e 00 45 78 |....wcsl|en..^.Ex|
|00000470| 49 6e 74 65 72 6c 6f 63 | 6b 65 64 50 6f 70 45 6e |Interloc|kedPopEn|
|00000480| 74 72 79 53 4c 69 73 74 | 00 00 60 00 45 78 49 6e |trySList|..`.ExIn|
|00000490| 74 65 72 6c 6f 63 6b 65 | 64 50 75 73 68 45 6e 74 |terlocke|dPushEnt|
|000004a0| 72 79 53 4c 69 73 74 00 | c4 01 4b 65 49 6e 69 74 |rySList.|..KeInit|
|000004b0| 69 61 6c 69 7a 65 45 76 | 65 6e 74 00 4d 00 45 78 |ializeEv|ent.M.Ex|
|000004c0| 49 6e 69 74 69 61 6c 69 | 7a 65 4e 50 61 67 65 64 |Initiali|zeNPaged|
|000004d0| 4c 6f 6f 6b 61 73 69 64 | 65 4c 69 73 74 00 63 03 |Lookasid|eList.c.|
|000004e0| 52 74 6c 49 6e 69 74 41 | 6e 73 69 53 74 72 69 6e |RtlInitA|nsiStrin|
|000004f0| 67 00 ff 02 52 74 6c 41 | 70 70 65 6e 64 55 6e 69 |g...RtlA|ppendUni|
|00000500| 63 6f 64 65 53 74 72 69 | 6e 67 54 6f 53 74 72 69 |codeStri|ngToStri|
|00000510| 6e 67 00 00 70 03 52 74 | 6c 49 6e 74 65 67 65 72 |ng..p.Rt|lInteger|
|00000520| 54 6f 55 6e 69 63 6f 64 | 65 53 74 72 69 6e 67 00 |ToUnicod|eString.|
|00000530| dd 01 4b 65 51 75 65 72 | 79 53 79 73 74 65 6d 54 |..KeQuer|ySystemT|
|00000540| 69 6d 65 00 22 04 5a 77 | 43 72 65 61 74 65 46 69 |ime.".Zw|CreateFi|
|00000550| 6c 65 00 00 00 03 52 74 | 6c 41 70 70 65 6e 64 55 |le....Rt|lAppendU|
|00000560| 6e 69 63 6f 64 65 54 6f | 53 74 72 69 6e 67 00 00 |nicodeTo|String..|
|00000570| 1d 04 5a 77 43 6c 6f 73 | 65 00 73 04 5a 77 57 72 |..ZwClos|e.s.ZwWr|
|00000580| 69 74 65 46 69 6c 65 00 | 3e 00 45 78 44 65 6c 65 |iteFile.|>.ExDele|
|00000590| 74 65 4e 50 61 67 65 64 | 4c 6f 6f 6b 61 73 69 64 |teNPaged|Lookasid|
|000005a0| 65 4c 69 73 74 00 34 01 | 49 6f 46 72 65 65 57 6f |eList.4.|IoFreeWo|
|000005b0| 72 6b 49 74 65 6d 00 00 | 5d 01 49 6f 51 75 65 75 |rkItem..|].IoQueu|
|000005c0| 65 57 6f 72 6b 49 74 65 | 6d 00 05 01 49 6f 41 6c |eWorkIte|m...IoAl|
|000005d0| 6c 6f 63 61 74 65 57 6f | 72 6b 49 74 65 6d 00 00 |locateWo|rkItem..|
|000005e0| a1 04 6d 65 6d 6d 6f 76 | 65 00 a8 04 73 74 72 63 |..memmov|e...strc|
|000005f0| 68 72 00 00 8e 04 5f 76 | 73 6e 70 72 69 6e 74 66 |hr...._v|snprintf|
|00000600| 00 00 fa 00 49 6e 74 65 | 72 6c 6f 63 6b 65 64 49 |....Inte|rlockedI|
|00000610| 6e 63 72 65 6d 65 6e 74 | 00 00 f7 00 49 6e 74 65 |ncrement|....Inte|
|00000620| 72 6c 6f 63 6b 65 64 44 | 65 63 72 65 6d 65 6e 74 |rlockedD|ecrement|
|00000630| 00 00 c0 04 77 63 73 6e | 63 70 79 00 96 01 49 6f |....wcsn|cpy...Io|
|00000640| 66 43 61 6c 6c 44 72 69 | 76 65 72 00 bc 02 4f 62 |fCallDri|ver...Ob|
|00000650| 66 44 65 72 65 66 65 72 | 65 6e 63 65 4f 62 6a 65 |fDerefer|enceObje|
|00000660| 63 74 00 00 0b 01 49 6f | 42 75 69 6c 64 44 65 76 |ct....Io|BuildDev|
|00000670| 69 63 65 49 6f 43 6f 6e | 74 72 6f 6c 52 65 71 75 |iceIoCon|trolRequ|
|00000680| 65 73 74 00 3d 01 49 6f | 47 65 74 44 65 76 69 63 |est.=.Io|GetDevic|
|00000690| 65 4f 62 6a 65 63 74 50 | 6f 69 6e 74 65 72 00 00 |eObjectP|ointer..|
|000006a0| 91 04 5f 77 63 73 6e 69 | 63 6d 70 00 57 04 5a 77 |.._wcsni|cmp.W.Zw|
|000006b0| 51 75 65 72 79 56 61 6c | 75 65 4b 65 79 00 3e 04 |QueryVal|ueKey.>.|
|000006c0| 5a 77 4f 70 65 6e 4b 65 | 79 00 17 03 52 74 6c 43 |ZwOpenKe|y...RtlC|
|000006d0| 6f 70 79 53 69 64 00 00 | 7f 03 52 74 6c 4c 65 6e |opySid..|..RtlLen|
|000006e0| 67 74 68 53 69 64 00 00 | 37 03 52 74 6c 45 71 75 |gthSid..|7.RtlEqu|
|000006f0| 61 6c 53 69 64 00 6a 03 | 52 74 6c 49 6e 69 74 69 |alSid.j.|RtlIniti|
|00000700| 61 6c 69 7a 65 53 69 64 | 00 00 4f 04 5a 77 51 75 |alizeSid|..O.ZwQu|
|00000710| 65 72 79 49 6e 66 6f 72 | 6d 61 74 69 6f 6e 54 6f |eryInfor|mationTo|
|00000720| 6b 65 6e 00 40 04 5a 77 | 4f 70 65 6e 50 72 6f 63 |ken.@.Zw|OpenProc|
|00000730| 65 73 73 54 6f 6b 65 6e | 00 00 6e 74 6f 73 6b 72 |essToken|..ntoskr|
|00000740| 6e 6c 2e 65 78 65 00 00 | 00 00 45 78 41 63 71 75 |nl.exe..|..ExAcqu|
|00000750| 69 72 65 46 61 73 74 4d | 75 74 65 78 00 00 01 00 |ireFastM|utex....|
|00000760| 45 78 52 65 6c 65 61 73 | 65 46 61 73 74 4d 75 74 |ExReleas|eFastMut|
|00000770| 65 78 00 00 44 00 4b 65 | 47 65 74 43 75 72 72 65 |ex..D.Ke|GetCurre|
|00000780| 6e 74 49 72 71 6c 00 00 | 48 41 4c 2e 64 6c 6c 00 |ntIrql..|HAL.dll.|
|00000790| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007a0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007b0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007c0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007d0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007e0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|000007f0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
+--------+-------------------------+-------------------------+--------+--------+