Microsoft (R) COFF/PE Dumper Version 8.00.50727.42 Copyright (C) Microsoft Corporation. All rights reserved. Dump of file tiny.exe PE signature found File Type: EXECUTABLE IMAGE FILE HEADER VALUES 14C machine (x86) 1 number of sections 4545BE5D time date stamp Mon Oct 30 00:57:01 2006 0 file pointer to symbol table 0 number of symbols 60 size of optional header 103 characteristics Relocations stripped Executable 32 bit word machine OPTIONAL HEADER VALUES 10B magic # (PE32) 8.00 linker version 4 size of code 0 size of initialized data 0 size of uninitialized data A4 entry point (004000A4) A4 base of code A8 base of data 400000 image base (00400000 to 004000A7) 4 section alignment 4 file alignment 4.00 operating system version 0.00 image version 4.00 subsystem version 0 Win32 version A8 size of image A4 size of headers 0 checksum 2 subsystem (Windows GUI) 400 DLL characteristics No structured exception handler 100000 size of stack reserve 1000 size of stack commit 100000 size of heap reserve 1000 size of heap commit 0 loader flags 0 number of directories SECTION HEADER #1 .text name 4 virtual size A4 virtual address (004000A4 to 004000A7) 4 size of raw data A4 file pointer to raw data (000000A4 to 000000A7) 0 file pointer to relocation table 0 file pointer to line numbers 0 number of relocations 0 number of line numbers 60000020 flags Code Execute Read 004000A4: 6A 2A push 2Ah 004000A6: 58 pop eax 004000A7: C3 ret Summary 4 .text