1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
|
Microsoft (R) EXE File Header Utility Version 2.01
Copyright (C) Microsoft Corp 1985-1990. All rights reserved.
.EXE size (bytes) 3200
Magic number: 5a4d
Bytes on last page: 00a3
Pages in file: 0018
Relocations: 0000
Paragraphs in header: 0020
Extra paragraphs needed: 0000
Extra paragraphs wanted: ffff
Initial stack location: 0004:0100
Word checksum: eb10
Entry point: 0000:0000
Relocation table address: 0040
Reserved words:
0000 0000 0000 0000 0000 0000 0000 0000
0000 0000 0000 0000 0000
New .EXE header address: 00000400
Memory needed: 12K
Library: WIN87EM
Description: Microsoft Windows 3.1 Coprocessor/Emulator Library 7.00.00
Operating system: Microsoft Windows
Data: NONE
Initialization: Global
Initial CS:IP: seg 1 offset 0058
Initial SS:SP: seg 0 offset 0000
Linker version: 5.01
32-bit Checksum: 00b41495
Segment Table: 00000440 length 0010 (16)
Resource Table: 00000450 length 0000 (0)
Resident Names Table: 00000450 length 004f (79)
Module Reference Table: 0000049f length 0002 (2)
Imported Names Table: 000004a1 length 0013 (19)
Entry Table: 000004b4 length 0015 (21)
Non-resident Names Table: 000004c9 length 003e (62)
Movable entry points: 0
Segment sector size: 512
Application type: WINDOWAPI
Other module flags:
no. type address file mem flags
1 CODE 00000800 02763 02763 EXECUTEREAD, PRELOAD, NONCONFORMING, NOIOPL,
relocs, (fixed), (nondiscardable), (nonshared)
2 DATA 00003000 00170 00170 READWRITE, SHARED, PRELOAD, NOEXPANDDOWN, NOIOPL,
(fixed), (nondiscardable)
Exports:
ord seg offset name
2 1 0089 WEP exported
1 1 002a __FPMATH exported
3 1 01ab __WIN87EMINFO exported
4 1 0220 __WIN87EMRESTORE exported
5 1 01e3 __WIN87EMSAVE exported
1 type offset target
OFFSET 2692 imp KERNEL.__WINFLAGS
PTR 0613 imp KERNEL.171
PTR 0665 imp KERNEL.176
BASE 0e0a seg 2 offset 016f
BASE 274d seg 2 offset 0170
5 relocations
|