Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
Compilation Date | 2010-Nov-20 09:28:05 |
Detected languages |
English - United States
|
Debug artifacts |
srv.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Server driver |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | SRV.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRV.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
Suspicious | The PE is possibly packed. |
Unusual section name found: PAGE
Unusual section name found: PAGE8FIL Section INIT is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
Info | The PE's resources present abnormal characteristics. | Resource MOFRESOURCENAME is possibly compressed or encrypted. |
Safe | VirusTotal score: 0/73 (Scanned on 2020-01-06 03:37:54) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 9 |
TimeDateStamp | 2010-Nov-20 09:28:05 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 9.1 |
SizeOfCode | 0x65800 |
SizeOfInitializedData | 0x2de00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000009406C (Section: INIT) |
BaseOfCode | 0x1000 |
ImageBase | 0x10000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 6.1 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x99000 |
SizeOfHeaders | 0x400 |
Checksum | 0x79b5f |
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntoskrnl.exe |
RtlCompareMemory
KeInitializeEvent ExInitializeResourceLite InitializeSListHead KeAcquireSpinLockRaiseToDpc KeReleaseSpinLock ExInterlockedRemoveHeadList ExAcquireResourceExclusiveLite RtlEqualUnicodeString ExReleaseResourceLite ExpInterlockedPopEntrySList ExDeleteResourceLite NlsMbOemCodePageTag RtlxUnicodeStringToOemSize RtlUnicodeStringToOemString KeResetEvent ExAcquireResourceSharedLite KeAcquireSpinLockAtDpcLevel KeReleaseSpinLockFromDpcLevel RtlUpcaseUnicodeChar KeGetCurrentProcessorNumberEx ExpInterlockedPushEntrySList ObfDereferenceObject IoGetRelatedDeviceObject IoFreeIrp IoCheckDesiredAccess PsIsThreadImpersonating IoGetCurrentProcess PsDereferencePrimaryToken PsDereferenceImpersonationToken PsImpersonateClient RtlCopyUnicodeString KeStackAttachProcess KeUnstackDetachProcess RtlLengthSecurityDescriptor ZwClose NtQueryVolumeInformationFile NtOpenFile NtQueryInformationFile KeInitializeTimer KeCancelTimer KeReadStateEvent KeInitializeDpc KeSetTargetProcessorDpcEx KeClearEvent KeSetTimer RtlOemStringToUnicodeString IoInitializeIrp MmBuildMdlForNonPagedPool ExFreePoolWithTag KeInsertQueue IoFreeMdl ZwUnmapViewOfSection ZwMapViewOfSection IoAllocateMdl MmProbeAndLockPages IofCallDriver IoCreateFile ZwCreateSection NtReadFile NtSetInformationFile NtWriteFile ObReferenceObjectByHandle RtlUpperChar ExAllocatePoolWithTag IoWMIWriteEvent MmGetSystemRoutineAddress IoWMIRegistrationControl IofCompleteRequest IoCreateDevice IoDeleteDevice KeInsertHeadQueue WmiGetClock IoIs32bitProcess KeEnterCriticalRegion KeLeaveCriticalRegion IoAllocateWorkItem MmUnlockPages KeQueryTimeIncrement IoGetRequestorProcess KeAttachProcess KeDetachProcess ExAllocatePoolWithTagPriority IoQueueWorkItem MmUnmapLockedPages IoBuildPartialMdl RtlFreeOemString ZwOpenEvent RtlAnsiStringToUnicodeString IoFreeWorkItem KeInitializeQueue RtlCreateSecurityDescriptor RtlLengthRequiredSid RtlInitializeSid MmMapLockedPagesSpecifyCache RtlLengthSid RtlCreateAcl RtlAddAccessAllowedAce RtlSetDaclSecurityDescriptor RtlSetOwnerSecurityDescriptor ZwOpenKey ZwQueryValueKey KeDelayExecutionThread KeRundownQueue RtlGetDaclSecurityDescriptor RtlGetOwnerSecurityDescriptor MmUnlockPagableImageSection _wcsupr KeGetProcessorNumberFromIndex KeReadStateQueue _wcsicmp ZwSetValueKey ExSystemTimeToLocalTime RtlTimeToSecondsSince1970 NtQuerySecurityObject FsRtlDoesNameContainWildCards SeSinglePrivilegeCheck SeExports RtlTimeToTimeFields RtlTimeFieldsToTime ObfReferenceObject IoAllocateIrp IoQueueThreadIrp IoReuseIrp MmLockPagableDataSection IoCreateFileEx RtlPrefixUnicodeString IoCheckEaBufferValidity IoCheckFunctionAccess IoSetThreadHardErrorMode RtlIntegerToUnicodeString IoCancelIrp RtlInitString RtlInt64ToUnicodeString _stricmp wcschr strncmp IoFastQueryNetworkAttributes RtlSecondsSince1970ToTime IoCheckQuerySetFileInformation RtlUpcaseUnicodeStringToOemString NtDeviceIoControlFile RtlFreeAnsiString IoCheckQuerySetVolumeInformation NtSetVolumeInformationFile RtlValidRelativeSecurityDescriptor NtSetSecurityObject NtQueryQuotaInformationFile NtSetQuotaInformationFile _wcsnicmp RtlInitAnsiString RtlIsNameLegalDOS8Dot3 FsRtlIsFatDbcsLegal NlsOemLeadByteInfo RtlUpcaseUnicodeToOemN RtlUnicodeToOemN IoSetFileOrigin PsAssignImpersonationToken RtlMapGenericMask SeFreePrivileges ExQueueWorkItem ObOpenObjectByPointer ZwDuplicateObject RtlAppendUnicodeToString RtlAppendUnicodeStringToString IoCreateFileSpecifyDeviceObjectHint FsRtlInitializeExtraCreateParameterList FsRtlInitializeExtraCreateParameter FsRtlInsertExtraCreateParameter RtlValidSecurityDescriptor RtlCompareUnicodeString KeQueryActiveProcessorCountEx KeGetRecommendedSharedDataAlignment _vsnwprintf IoBuildDeviceIoControlRequest NtClose toupper FsRtlIsNameInExpression RtlNtStatusToDosErrorNoTeb VerSetConditionMask RtlVerifyVersionInfo MmSizeOfMdl MmIsThisAnNtAsSystem PsCreateSystemThread NtSetInformationThread KeQueryGroupAffinity KeSetSystemGroupAffinityThread KeSetIdealProcessorThread KeRemoveQueue PsTerminateSystemThread NtFreeVirtualMemory NtAllocateVirtualMemory KeSetEvent RtlFreeUnicodeString RtlUpcaseUnicodeString KeWaitForSingleObject SeUnlockSubjectContext SeQueryAuthenticationIdToken SeLockSubjectContext SeReleaseSubjectContext SeCaptureSubjectContext ExInterlockedAddUlong ExLocalTimeToSystemTime KeBugCheckEx DbgPrint RtlSubAuthoritySid RtlInitUnicodeString ExAcquireFastMutex ExReleaseFastMutex __C_specific_handler |
---|---|
WMILIB.SYS |
WmiCompleteRequest
WmiSystemControl |
ksecdd.sys |
AddCredentialsW
FreeCredentialsHandle AcquireCredentialsHandleW DeleteSecurityContext InitSecurityInterfaceW RevertSecurityContext QueryContextAttributesW ImpersonateSecurityContext MapSecurityError AcceptSecurityContext KSecValidateBuffer FreeContextBuffer SystemPrng |
srvnet.sys |
SrvLibIsNetworkAddress
SrvNetCloseConnection SrvLibGetBaseFileName SrvXsSchedulePrintJob SrvAdminDeregisterFile SrvLibAuditForceAccess SrvAdminDeregisterSession SrvLibLookasideAllocate SrvLibLookasideFree SrvAdminDeregisterTreeConnect SrvAdminQueryResumeKeyTarget SrvAdminIsScopedName SrvLibLogError SrvLibIsLoggableError SrvLibGenerateSrvServiceSD SrvLibApplySrvDeviceAcl SrvLibFreeSrvServiceSD SrvNetReceiveData SrvNetGetQueueStatistics SrvNetRegisterClient SrvNetStartClient SrvXsConnect SrvNetInitializeStatisticsQueues SrvLibLookasideInitialize SrvLibLookasideCreatePool SrvLibLookasideDirectFreeBuffer SrvLibLookasideDirectNonPagedAllocateBuffer SrvLibLookasideDirectPagedAllocateBuffer SrvAdminRegisterProvider SrvNetStopClient SrvNetDeregisterClient SrvXsClosePrinter SrvXsDisconnect SrvAdminDeregisterProvider SrvNetDisableStatisticsQueue SrvLibLookasideDestroyPool SrvAdminRefreshAnonymousLists SrvAdminRefreshNoRemapPipeList SrvLibGetDWord SrvLibQueryLicensingDWord SrvLibSetSrvErrorLogIgnore SrvGraftName SrvNetFreePool SrvNetQueryConnectionInformation SrvNetSetConnectionInformation SrvNetSendData SrvXsAddPrintJob SrvAdminRemapPipeName SrvAdminRegisterFile SrvNetUpdateStatisticsFromQueues SrvNetUpdateIOCountFromQueues SrvAdminDoesShareAllowAnonymous SrvLibTruncateDnsName SrvAdminEvaluateServerAlias SrvAdminRegisterSession SrvLibIsFsctlDisallowed SrvLibIsDosDeviceName SrvAdminDoesPipeAllowAnonymous SrvLibAllocatePipeEa SrvLibFreePipeEa SrvLibAuditSuccessEnabled SrvLibAuditShareAccess SrvLibRetrieveMaximalAccessRightsForUser SrvLibAuditShareConnect SrvAdminRegisterTreeConnect SrvXsOpenPrinter SrvNetGetStatisticsAndLock SrvAdminSetUserLimit SrvNetQueryRssScalability SrvXsDownLevelAPI SrvAdminAuditSpnCheck SrvAdminCheckSpn SrvLibSeAccessCheck SrvAdminAllowIdlePowerDownForActivity SrvAdminInhibitIdlePowerDownForActivity SrvAdminInhibitIdlePowerDownForOpenFiles SrvAdminAllowIdlePowerDownForOpenFiles SrvNetDisconnectConnection |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.1.7601.17514 |
ProductVersion | 6.1.7601.17514 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DRV
|
FileSubtype | VFT2_DRV_NETWORK |
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Server driver |
FileVersion (#2) | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | SRV.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRV.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.1.7601.17514 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:28:05 |
Version | 0.0 |
SizeofData | 32 |
AddressOfRawData | 0x14c78 |
PointerToRawData | 0x14078 |
Referenced File | srv.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:28:05 |
Version | 565.6526 |
SizeofData | 4 |
AddressOfRawData | 0x14c74 |
PointerToRawData | 0x14074 |
XOR Key | 0x367ecf5a |
---|---|
Unmarked objects | 0 |
Total imports | 305 |
Imports (VS2008 SP1 build 30729) | 9 |
ASM objects (VS2008 SP1 build 30729) | 4 |
C objects (VS2008 SP1 build 30729) | 7 |
142 (VS2008 SP1 build 30729) | 74 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |