Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 1970-Jul-30 05:12:29 |
Detected languages |
English - United States
|
Debug artifacts |
MoUsoCoreWorker.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | MoUSO Core Worker Process |
FileVersion | 10.0.19041.4355 (WinBuild.160101.0800) |
InternalName | MoUSO Core Worker Process |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | MoUSOCoreWorker.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.19041.4355 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
References the BITS service
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: | Uses known Mersenne Twister constants |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/72 (Scanned on 2024-05-14 04:53:44) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x110 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 1970-Jul-30 05:12:29 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x13f000 |
SizeOfInitializedData | 0x76e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000128B70 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x1ba000 |
SizeOfHeaders | 0x400 |
Checksum | 0x1bd2e5 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
msvcp_win.dll |
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@H@Z _Thrd_sleep ?widen@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAGD@Z ??0?$basic_istream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@_N@Z ?sbumpc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ ?sgetc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ ?snextc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ ??1?$basic_istream@GU?$char_traits@G@std@@@std@@UEAA@XZ ?get@?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@QEBA?AV?$istreambuf_iterator@GU?$char_traits@G@std@@@2@V32@0AEAVios_base@2@AEAHPEAUtm@@PEBG4@Z ?_Getcat@?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?id@?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@2V0locale@2@A ?_Ipfx@?$basic_istream@GU?$char_traits@G@std@@@std@@QEAA_N_N@Z ?_Xinvalid_argument@std@@YAXPEBD@Z ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ ?_XGetLastError@std@@YAXXZ ??0task_continuation_context@Concurrency@@AEAA@XZ ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z ?_ReportUnobservedException@details@Concurrency@@YAXXZ ?__ExceptionPtrCreate@@YAXPEAX@Z ?tolower@?$ctype@G@std@@QEBAGG@Z ?__ExceptionPtrCurrentException@@YAXPEAX@Z ?__ExceptionPtrRethrow@@YAXPEBX@Z ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ _Thrd_detach ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?_Throw_future_error@std@@YAXAEBVerror_code@1@@Z ?__ExceptionPtrToBool@@YA_NPEBX@Z ?_Rethrow_future_exception@std@@YAXVexception_ptr@1@@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z _Cnd_register_at_thread_exit ?__ExceptionPtrDestroy@@YAXPEAX@Z _Cnd_unregister_at_thread_exit ?_Xbad_function_call@std@@YAXXZ ?in@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAG3AEAPEAG@Z ?out@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBG1AEAPEBGPEAD3AEAPEAD@Z ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z ?id@?$codecvt@GDU_Mbstatet@@@std@@2V0locale@2@A ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z ??0?$codecvt@GDU_Mbstatet@@@std@@QEAA@_K@Z ??1?$codecvt@GDU_Mbstatet@@@std@@MEAA@XZ ?tolower@?$ctype@G@std@@QEBAPEBGPEAGPEBG@Z ?_Incref@facet@locale@std@@UEAAXXZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@_N@Z ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??0?$basic_iostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@@Z ??0?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@_N@Z ?_Xbad_alloc@std@@YAXXZ ?_Fiopen@std@@YAPEAU_iobuf@@PEBGHH@Z ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ ?_Throw_Cpp_error@std@@YAXH@Z _Thrd_join _Thrd_id _Cnd_do_broadcast_at_thread_exit ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ ?sputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAA_JPEBG_J@Z ?imbue@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAXAEBVlocale@2@@Z ?setbuf@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAPEAV12@PEAG_J@Z ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z ?uflow@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAGXZ ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ _Unlock_shared_ptr_spin_lock ?_Random_device@std@@YAIXZ _Mtx_trylock ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@J@Z ?_Getcat@?$codecvt@GDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?unshift@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?getloc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEBA?AVlocale@2@XZ ?put@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@G@Z ?_Init@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXXZ ?_Gndec@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@K@Z _Lock_shared_ptr_spin_lock _Mtx_current_owns _Cnd_timedwait ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z _Query_perf_frequency _Query_perf_counter _Cnd_wait ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ?widen@?$ctype@G@std@@QEBAGD@Z ?id@?$ctype@G@std@@2V0locale@2@A ?_Getcat@?$ctype@G@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ??Bid@locale@std@@QEAA_KXZ ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??0_Lockit@std@@QEAA@H@Z ??1_Lockit@std@@QEAA@XZ ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ ?sputc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGG@Z ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?_Lock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ ?uncaught_exception@std@@YA_NXZ ?_Osfx@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAXXZ ?sync@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAHXZ ?setstate@?$basic_ios@GU?$char_traits@G@std@@@std@@QEAAXH_N@Z ?flush@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ ?gbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z ??1?$basic_ostream@GU?$char_traits@G@std@@@std@@UEAA@XZ ??1?$basic_iostream@GU?$char_traits@G@std@@@std@@UEAA@XZ _Cnd_broadcast _Xtime_get_ticks _Cnd_signal _Mtx_unlock ?_Throw_C_error@std@@YAXH@Z _Mtx_lock ?_Xout_of_range@std@@YAXPEBD@Z ?_Winerror_message@std@@YAKKPEADK@Z ?_Winerror_map@std@@YAHH@Z ?_Execute_once@std@@YAHAEAUonce_flag@1@P6AHPEAX1PEAPEAX@Z1@Z ?_Syserror_map@std@@YAPEBDH@Z _Cnd_destroy_in_situ _Cnd_init_in_situ _Mtx_init_in_situ _Mtx_destroy_in_situ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1_Locinfo@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@PEBD@Z ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ??1facet@locale@std@@MEAA@XZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ??0facet@locale@std@@IEAA@_K@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@_K@Z ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?is@?$ctype@G@std@@QEBA_NFG@Z ?id@?$collate@G@std@@2V0locale@2@A _Wcsxfrm _Wcscoll ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z |
---|---|
api-ms-win-crt-string-l1-1-0.dll |
wcscmp
strnlen memset wcsnlen wcsncmp |
api-ms-win-crt-runtime-l1-1-0.dll |
_initterm_e
_c_exit _register_thread_local_exe_atexit_callback _initterm |
api-ms-win-crt-private-l1-1-0.dll |
_o__localtime64_s
_o__lock_file _o__ltow_s _o__mktime64 _o__purecall _o__recalloc _o__register_onexit_function _o__seh_filter_exe _o__set_app_type _o__set_errno _o__set_fmode _o__set_new_mode _o__stricmp _o__ui64toa_s _o__ui64tow_s _o__ultow_s _o__unlock_file _o__wcsicmp _o__wcsnicmp _o__wcstod_l _o__wtoi _o__wtol _o_exit _o_fclose _o_fflush _o_fgetc _o_fgetpos _o_fgetwc _o_fputc _o_fputwc _o_fread _o_free memmove _o_fwrite _o_iswspace _o_malloc _o_mbstowcs_s _o_pow _o_realloc _o_setvbuf _o_strncpy_s _o_strtol _o_strtoull _o_terminate _o_tolower _o_towlower _o_ungetc _o_ungetwc _o_wcscat_s _o_wcscpy_s _o_wcsftime _o_wcsncpy_s _o_wcstol _o_wcstoll _o_wcstoull __CxxFrameHandler3 _CxxThrowException _o__invalid_parameter_noinfo_noreturn _o__invalid_parameter_noinfo _o__initialize_wide_environment _o__initialize_onexit_table _o__i64tow_s _o__i64toa_s _o__get_wide_winmain_command_line _o__get_stream_buffer_pointers _o__fseeki64 _o__free_locale _o__exit _o__errno _o__crt_atexit _o__create_locale _o__configure_wide_argv _o__configthreadlocale memcpy memcmp _o__cexit _o__callnewh _o__beginthreadex _o___stdio_common_vswscanf _o___stdio_common_vswprintf_s _o___stdio_common_vswprintf _o___stdio_common_vsprintf_s _o___stdio_common_vsnwprintf_s _o___stdio_common_vsnprintf_s _o___std_exception_destroy _o___std_exception_copy _o___pctype_func _o___p__commode _o____lc_codepage_func __C_specific_handler __std_terminate __CxxFrameHandler4 _o_fsetpos strchr strrchr __std_type_info_compare |
api-ms-win-core-libraryloader-l1-2-0.dll |
LoadLibraryExW
GetModuleHandleW GetModuleHandleExW LoadResource FreeLibrary GetModuleFileNameA GetModuleFileNameW FindResourceExW GetModuleHandleA SizeofResource GetProcAddress |
api-ms-win-core-synch-l1-1-0.dll |
InitializeCriticalSectionAndSpinCount
CreateEventW ReleaseSemaphore CreateEventExW DeleteCriticalSection EnterCriticalSection LeaveCriticalSection ReleaseSRWLockShared AcquireSRWLockShared ReleaseSRWLockExclusive AcquireSRWLockExclusive WaitForSingleObject CreateSemaphoreExW SetEvent InitializeCriticalSectionEx ReleaseMutex OpenEventW CreateMutexExW ResetEvent InitializeSRWLock InitializeCriticalSection OpenSemaphoreW WaitForSingleObjectEx |
api-ms-win-core-heap-l1-1-0.dll |
HeapReAlloc
GetProcessHeap HeapFree HeapAlloc |
api-ms-win-core-errorhandling-l1-1-0.dll |
SetUnhandledExceptionFilter
SetErrorMode GetErrorMode GetLastError UnhandledExceptionFilter SetLastError RaiseException |
api-ms-win-core-processthreads-l1-1-0.dll |
CreateProcessW
TerminateProcess GetCurrentThread GetStartupInfoW TlsAlloc OpenThreadToken GetProcessId GetExitCodeThread GetCurrentProcess OpenProcessToken GetCurrentThreadId TlsSetValue GetCurrentProcessId TlsGetValue TlsFree CreateThread |
api-ms-win-core-localization-l1-2-0.dll |
FormatMessageW
|
api-ms-win-core-debug-l1-1-0.dll |
DebugBreak
OutputDebugStringW IsDebuggerPresent |
api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
DuplicateHandle |
OLEAUT32.dll |
VarUI4FromStr
VarUI8FromDec VariantTimeToSystemTime SysStringLen SysStringByteLen SysAllocString UnRegisterTypeLib SystemTimeToVariantTime VariantInit VariantClear SysAllocStringByteLen SysFreeString LoadTypeLib RegisterTypeLib |
api-ms-win-core-threadpool-l1-2-0.dll |
WaitForThreadpoolWaitCallbacks
WaitForThreadpoolTimerCallbacks CreateThreadpoolWait CreateThreadpoolTimer SetThreadpoolTimer CloseThreadpoolTimer SetThreadpoolWait CloseThreadpoolWait |
api-ms-win-eventing-provider-l1-1-0.dll |
EventUnregister
EventWriteTransfer EventActivityIdControl EventWriteString EventRegister EventSetInformation |
api-ms-win-core-com-l1-1-0.dll |
CoWaitForMultipleHandles
CoTaskMemAlloc CoRevokeClassObject CoGetMalloc CoGetApartmentType CoCreateGuid CoImpersonateClient CoRevertToSelf CoIncrementMTAUsage CoTaskMemRealloc CoInitializeEx CoSuspendClassObjects CoRegisterClassObject StringFromGUID2 CoResumeClassObjects CoTaskMemFree CoCreateInstance CoUninitialize CoCreateFreeThreadedMarshaler |
api-ms-win-core-string-l2-1-0.dll |
CharLowerBuffW
CharNextW CharUpperW |
api-ms-win-core-registry-l1-1-0.dll |
RegEnumValueW
RegQueryValueExW RegSetValueExW RegGetValueW RegDeleteTreeW RegDeleteValueW RegCloseKey RegQueryInfoKeyW RegCreateKeyExW RegEnumKeyExW RegOpenKeyExW |
api-ms-win-core-string-l1-1-0.dll |
WideCharToMultiByte
MultiByteToWideChar |
api-ms-win-security-sddl-l1-1-0.dll |
ConvertStringSecurityDescriptorToSecurityDescriptorW
|
api-ms-win-core-synch-l1-2-0.dll |
InitOnceComplete
InitOnceBeginInitialize Sleep InitOnceExecuteOnce |
api-ms-win-core-processenvironment-l1-1-0.dll |
GetCommandLineW
ExpandEnvironmentStringsW |
api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlVirtualUnwind
RtlCaptureContext RtlLookupFunctionEntry |
api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
|
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTimeAsFileTime
GetSystemWindowsDirectoryW GetTickCount64 GetSystemDirectoryW GetLocalTime GetVersionExW |
api-ms-win-core-interlocked-l1-1-0.dll |
InterlockedPushEntrySList
InitializeSListHead |
api-ms-win-core-string-obsolete-l1-1-0.dll |
lstrcmpiW
|
api-ms-win-core-localization-obsolete-l1-2-0.dll |
GetUserDefaultUILanguage
|
dmiso8601utils.dll |
SystemTimeToISO8601String
|
api-ms-win-eventing-controller-l1-1-0.dll |
ControlTraceW
EnableTraceEx2 QueryAllTracesW StartTraceW |
api-ms-win-core-heap-l2-1-0.dll |
LocalAlloc
LocalFree LocalReAlloc |
api-ms-win-core-registry-l1-1-1.dll |
RegSetKeyValueW
|
api-ms-win-security-base-l1-1-0.dll |
GetTokenInformation
AdjustTokenPrivileges FreeSid AllocateAndInitializeSid ImpersonateLoggedOnUser RevertToSelf |
api-ms-win-core-shutdown-l1-1-1.dll |
InitiateShutdownW
|
api-ms-win-power-setting-l1-1-0.dll |
PowerSettingUnregisterNotification
PowerSettingRegisterNotification |
api-ms-win-power-base-l1-1-0.dll |
CallNtPowerInformation
|
api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsCreateString
WindowsPreallocateStringBuffer WindowsDeleteStringBuffer WindowsPromoteStringBuffer WindowsDuplicateString WindowsCreateStringReference WindowsDeleteString WindowsGetStringRawBuffer |
api-ms-win-core-winrt-error-l1-1-0.dll |
SetRestrictedErrorInfo
RoTransformError RoOriginateError GetRestrictedErrorInfo |
api-ms-win-core-winrt-l1-1-0.dll |
RoInitialize
RoGetActivationFactory RoActivateInstance |
RPCRT4.dll |
RpcBindingFree
RpcStringFreeW RpcBindingSetAuthInfoExW RpcStringBindingComposeW RpcBindingFromStringBindingW NdrClientCall3 UuidCreate |
api-ms-win-core-sysinfo-l1-2-0.dll |
VerSetConditionMask
|
api-ms-win-core-file-l1-1-0.dll |
SetFileAttributesW
GetFileAttributesW RemoveDirectoryW GetFileAttributesExW GetDiskFreeSpaceExW FindClose GetDriveTypeW DeleteVolumeMountPointW SetFileInformationByHandle FlushFileBuffers GetFileSize SetEndOfFile GetFileInformationByHandle GetFinalPathNameByHandleW GetVolumeInformationW CreateFileW CreateDirectoryW SetFilePointerEx FindNextFileW SetFilePointer DeleteFileW ReadFile WriteFile FindFirstFileExW |
IPHLPAPI.DLL |
GetNetworkConnectivityHint
|
api-ms-win-core-libraryloader-l1-2-1.dll |
LoadLibraryW
|
api-ms-win-core-timezone-l1-1-0.dll |
TzSpecificLocalTimeToSystemTime
FileTimeToSystemTime SystemTimeToFileTime |
CRYPT32.dll |
CertVerifyCertificateChainPolicy
|
api-ms-win-core-datetime-l1-1-1.dll |
GetDateFormatEx
GetTimeFormatEx |
api-ms-win-core-delayload-l1-1-1.dll |
ResolveDelayLoadedAPI
|
api-ms-win-core-delayload-l1-1-0.dll |
DelayLoadFailureHook
|
api-ms-win-core-file-l2-1-0.dll |
CreateSymbolicLinkW
CreateHardLinkW MoveFileExW GetFileInformationByHandleEx |
api-ms-win-core-io-l1-1-0.dll |
DeviceIoControl
|
api-ms-win-core-file-l1-2-0.dll |
GetVolumePathNamesForVolumeNameW
GetTempPathW |
api-ms-win-core-file-l2-1-2.dll |
CopyFileW
|
api-ms-win-eventing-legacy-l1-1-0.dll |
QueryTraceW
FlushTraceW |
api-ms-win-core-shlwapi-legacy-l1-1-0.dll |
PathFileExistsW
PathFindFileNameW |
api-ms-win-core-kernel32-legacy-l1-1-1.dll |
PowerSetRequest
PowerCreateRequest VerifyVersionInfoW PowerClearRequest SetVolumeMountPointW |
ntdll.dll |
RtlUnsubscribeWnfNotificationWaitForCompletion
NtQueryWnfStateData RtlSubscribeWnfStateChangeNotification RtlPublishWnfStateData NtPowerInformation LdrUnloadDll RtlAllocateHeap RtlFreeHeap RtlNtStatusToDosError LdrAddRefDll RtlDosPathNameToNtPathName_U NtClose DbgPrintEx RtlRaiseStatus RtlReAllocateHeap |
api-ms-win-stateseparation-helpers-l1-1-0.dll |
GetPersistedRegistryLocationW
|
api-ms-win-oobe-notification-l1-1-0.dll |
OOBEComplete
|
api-ms-win-service-private-l1-1-0.dll |
I_QueryTagInformation
|
api-ms-win-core-apiquery-l1-1-0.dll |
ApiSetQueryApiSetPresence
|
UMPDC.dll |
PdcTaskClientUnregister
PdcTaskClientRegister PdcTaskClientRequest |
UpdatePolicy.dll |
ReadPolicyWithFallback
ReadPolicy ReleaseEnterprisePolicyValue ReleaseUpdatePolicyValue |
DMCmnUtils.dll |
InvStrCmpW
SafeStringToDword DecodeBase64W CopyString EncodeBase64W |
api-ms-win-core-synch-l1-2-1.dll |
WaitForMultipleObjects
|
api-ms-win-devices-config-l1-1-1.dll |
CM_Get_Device_Interface_PropertyW
CM_Get_Device_Interface_List_SizeW CM_Get_Device_Interface_ListW |
api-ms-win-core-memory-l1-1-0.dll |
VirtualFree
VirtualAlloc |
api-ms-win-core-errorhandling-l1-1-2.dll |
RaiseFailFastException
|
api-ms-win-shcore-stream-winrt-l1-1-0.dll |
CreateRandomAccessStreamOnFile
|
XmlLite.dll |
CreateXmlReader
CreateXmlWriter |
winsqlite3.dll |
sqlite3_exec
sqlite3_open16 sqlite3_prepare16_v2 sqlite3_step sqlite3_column_int sqlite3_initialize sqlite3_busy_timeout sqlite3_close_v2 sqlite3_bind_text16 sqlite3_bind_int sqlite3_column_text16 sqlite3_bind_blob sqlite3_column_bytes sqlite3_column_blob sqlite3_finalize |
bcrypt.dll |
BCryptGetProperty
BCryptHashData BCryptDestroyHash BCryptFinishHash BCryptOpenAlgorithmProvider BCryptCloseAlgorithmProvider BCryptCreateHash |
api-ms-win-core-path-l1-1-0.dll |
PathCchAppend
PathCchRemoveBackslash PathAllocCanonicalize PathCchCanonicalize PathCchSkipRoot |
profapi.dll |
#104
|
api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
api-ms-win-crt-math-l1-1-0.dll |
ceilf
|
api-ms-win-rtcore-ntuser-window-l1-1-0.dll (delay-loaded) |
GetMessageW
DispatchMessageW TranslateMessage PostThreadMessageW |
Attributes | 0x1 |
---|---|
Name | api-ms-win-rtcore-ntuser-window-l1-1-0.dll |
ModuleHandle | 0x1a6228 |
DelayImportAddressTable | 0x1b50d8 |
DelayImportNameTable | 0x199218 |
BoundDelayImportTable | 0x1995f8 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x112990 |
Ordinal | 2 |
---|---|
Address | 0x114f50 |
Ordinal | 3 |
---|---|
Address | 0x1187f0 |
Ordinal | 4 |
---|---|
Address | 0x112760 |
Ordinal | 5 |
---|---|
Address | 0x114bb0 |
Ordinal | 6 |
---|---|
Address | 0x116e40 |
Ordinal | 7 |
---|---|
Address | 0x116e80 |
Ordinal | 8 |
---|---|
Address | 0x116460 |
Ordinal | 9 |
---|---|
Address | 0x116920 |
Ordinal | 10 |
---|---|
Address | 0x1187b0 |
Ordinal | 11 |
---|---|
Address | 0x113060 |
Ordinal | 12 |
---|---|
Address | 0x1136c0 |
Ordinal | 13 |
---|---|
Address | 0x1133f0 |
Ordinal | 14 |
---|---|
Address | 0x112bc0 |
Ordinal | 15 |
---|---|
Address | 0x115f20 |
Ordinal | 16 |
---|---|
Address | 0x112cc0 |
Ordinal | 17 |
---|---|
Address | 0x113cc0 |
Ordinal | 18 |
---|---|
Address | 0x116110 |
Ordinal | 19 |
---|---|
Address | 0x1149e0 |
Ordinal | 20 |
---|---|
Address | 0x113950 |
Ordinal | 21 |
---|---|
Address | 0x113b00 |
Ordinal | 22 |
---|---|
Address | 0x113a50 |
Ordinal | 23 |
---|---|
Address | 0x114ac0 |
Ordinal | 24 |
---|---|
Address | 0x113870 |
Ordinal | 25 |
---|---|
Address | 0x114380 |
Ordinal | 26 |
---|---|
Address | 0x1134d0 |
Ordinal | 27 |
---|---|
Address | 0x113200 |
Ordinal | 28 |
---|---|
Address | 0x113310 |
Ordinal | 29 |
---|---|
Address | 0x119000 |
Ordinal | 30 |
---|---|
Address | 0x112eb0 |
Ordinal | 31 |
---|---|
Address | 0x118e00 |
Ordinal | 32 |
---|---|
Address | 0x112db0 |
Ordinal | 33 |
---|---|
Address | 0x1156d0 |
Ordinal | 34 |
---|---|
Address | 0x115a90 |
Ordinal | 35 |
---|---|
Address | 0x1153b0 |
Ordinal | 36 |
---|---|
Address | 0x114dd0 |
Ordinal | 37 |
---|---|
Address | 0x112a00 |
Ordinal | 38 |
---|---|
Address | 0x1187c0 |
Ordinal | 39 |
---|---|
Address | 0x114d00 |
Ordinal | 40 |
---|---|
Address | 0x112a80 |
Ordinal | 41 |
---|---|
Address | 0x113e00 |
Ordinal | 42 |
---|---|
Address | 0x114460 |
Ordinal | 43 |
---|---|
Address | 0x119390 |
Ordinal | 44 |
---|---|
Address | 0x1155d0 |
Ordinal | 45 |
---|---|
Address | 0x1135c0 |
Ordinal | 46 |
---|---|
Address | 0x114fe0 |
Ordinal | 47 |
---|---|
Address | 0x115100 |
Ordinal | 48 |
---|---|
Address | 0x116ec0 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.19041.4355 |
ProductVersion | 10.0.19041.4355 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | MoUSO Core Worker Process |
FileVersion (#2) | 10.0.19041.4355 (WinBuild.160101.0800) |
InternalName | MoUSO Core Worker Process |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | MoUSOCoreWorker.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.19041.4355 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 1970-Jul-30 05:12:29 |
Version | 0.0 |
SizeofData | 44 |
AddressOfRawData | 0x179c5c |
PointerToRawData | 0x17905c |
Referenced File | MoUsoCoreWorker.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 1970-Jul-30 05:12:29 |
Version | 0.0 |
SizeofData | 1284 |
AddressOfRawData | 0x179c88 |
PointerToRawData | 0x179088 |
Characteristics |
0
|
---|---|
TimeDateStamp | 1970-Jul-30 05:12:29 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0x17a18c |
PointerToRawData | 0x17958c |
StartAddressOfRawData | 0x14017a1d0 |
---|---|
EndAddressOfRawData | 0x14017a1d8 |
AddressOfIndex | 0x1401a62a8 |
AddressOfCallbacks | 0x140149688 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x118 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1401a4ed0 |
GuardCFCheckFunctionPointer | 5370057416 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xfcdb4baf |
---|---|
Unmarked objects | 0 |
Imports (33135) | 2 |
Imports (VS2008 SP1 build 30729) | 152 |
C objects (27412) | 17 |
ASM objects (27412) | 3 |
Total imports | 1689 |
Imports (27412) | 11 |
C objects (LTCG) (27412) | 144 |
C++ objects (27412) | 41 |
253 (27412) | 1 |
Exports (27412) | 1 |
Resource objects (27412) | 1 |
Linker (27412) | 1 |