Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
Compilation Date | 2010-Nov-20 09:27:20 |
Detected languages |
English - United States
|
Debug artifacts |
srvnet.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Server Network driver |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | SRVNET.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRVNET.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Suspicious | The PE is possibly packed. |
Unusual section name found: PAGE
Section INIT is both writable and executable. |
Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
Safe | VirusTotal score: 0/73 (Scanned on 2020-01-02 10:14:42) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 9 |
TimeDateStamp | 2010-Nov-20 09:27:20 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 9.1 |
SizeOfCode | 0x20400 |
SizeOfInitializedData | 0x9600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000002D06C (Section: INIT) |
BaseOfCode | 0x1000 |
ImageBase | 0x10000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 6.1 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x31000 |
SizeOfHeaders | 0x400 |
Checksum | 0x34967 |
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntoskrnl.exe |
ExInitializeResourceLite
KeCancelTimer KeAcquireSpinLockAtDpcLevel ExAllocatePoolWithTagPriority IofCallDriver KeAcquireSpinLockRaiseToDpc ExGetPreviousMode MmMapLockedPagesSpecifyCache IoGetRelatedDeviceObject RtlUnicodeStringToOemString RtlEqualUnicodeString KeUnstackDetachProcess NtCreateFile ZwClose ObReferenceObjectByHandle IoFreeIrp IoAllocateIrp ObfDereferenceObject RtlFreeOemString DbgPrint KeStackAttachProcess KeLeaveCriticalRegion KeGetCurrentProcessorNumberEx KeEnterCriticalRegion RtlGUIDFromString KeClearEvent IoQueueThreadIrp ObfReferenceObject NtDeviceIoControlFile IoFreeMdl IoQueueWorkItem MmUnlockPages RtlCaptureStackBackTrace IoAllocateMdl wcsncmp _wcsicmp RtlQueryRegistryValues RtlIpv4AddressToStringW RtlIpv4AddressToStringA RtlIpv6AddressToStringW RtlIpv6AddressToStringA ExQueueWorkItem MmUnmapLockedPages MmBuildMdlForNonPagedPool MmSizeOfMdl KeBugCheckEx KeQueryTimeIncrement ExReleaseResourceLite IoAllocateWorkItem IoGetCurrentProcess ExAcquireResourceSharedLite KeSetEvent IoDeleteDevice RtlInitUnicodeString IoWMIWriteEvent KeReadStateQueue ExFreePoolWithTag IoWMIRegistrationControl IoWriteOperationCount ExAcquireResourceExclusiveLite IoCreateDevice IoReadTransferCount ExDeleteResourceLite RtlCompareMemory KeSetTimer IoWriteTransferCount IoReadOperationCount KeWaitForSingleObject ExQueryDepthSList IofCompleteRequest KeQueryActiveProcessorCountEx MmProbeAndLockPages ExInitializePagedLookasideList PoCreatePowerRequest PoDeletePowerRequest ExDeletePagedLookasideList ZwOpenFile ZwCreateEvent ZwFsControlFile ZwWaitForSingleObject PoSetPowerRequest PoClearPowerRequest ExpInterlockedPushEntrySList ExpInterlockedPopEntrySList RtlAnsiStringToUnicodeString RtlFreeUnicodeString RtlCompareUnicodeString RtlInitializeGenericTableAvl RtlIsGenericTableEmptyAvl RtlEnumerateGenericTableAvl RtlDeleteElementGenericTableAvl RtlLookupElementGenericTableAvl RtlInsertElementGenericTableAvl RtlEnumerateGenericTableLikeADirectory RtlLengthSecurityDescriptor RtlAbsoluteToSelfRelativeSD RtlValidSecurityDescriptor RtlTimeToSecondsSince1980 NtAllocateVirtualMemory NtFreeVirtualMemory SeCaptureSubjectContext SeFreePrivileges SeReleaseSubjectContext PsAssignImpersonationToken RtlLengthSid RtlCreateAcl RtlAddAccessAllowedAce RtlCreateSecurityDescriptor RtlSetDaclSecurityDescriptor ZwOpenThreadTokenEx ZwOpenProcessTokenEx ZwQueryInformationToken SeQueryAuthenticationIdToken SeSetAuditParameter SeReportSecurityEventWithSubCategory SeAccessCheckEx SeAuditingWithTokenForSubcategory RtlIpv4StringToAddressW RtlIpv6StringToAddressW _wcsupr wcsstr RtlIpv4AddressToStringExW RtlIpv6AddressToStringExW RtlLengthRequiredSid RtlInitializeSid RtlSubAuthoritySid ObSetSecurityObjectByPointer RtlGetDaclSecurityDescriptor ZwOpenKey ZwQueryValueKey ZwQueryLicenseValue IoAllocateErrorLogEntry IoWriteErrorLogEntry ExpInterlockedFlushSList ExInitializeNPagedLookasideList ExDeleteNPagedLookasideList KeDelayExecutionThread KeInitializeTimer KeReleaseSpinLockFromDpcLevel KeReleaseSpinLock KeInitializeDpc KeInitializeEvent MmGetSystemRoutineAddress ExAllocatePoolWithTag IoFreeWorkItem ExReleaseFastMutex ExAcquireFastMutex __C_specific_handler |
---|---|
TDI.SYS |
TdiOpenNetbiosAddress
TdiRegisterPnPHandlers TdiCopyBufferToMdl TdiDeregisterPnPHandlers |
NETIO.SYS |
ConvertInterfaceGuidToLuid
NmrClientAttachProvider GetIfTable2 FreeMibTable NmrWaitForClientDeregisterComplete NmrDeregisterClient NmrRegisterClient ConvertInterfaceLuidToIndex |
msrpc.sys |
I_RpcExceptionFilter
RpcBindingSetOption RpcSsDestroyClientContext RpcBindingUnbind RpcBindingBind RpcAsyncInitializeHandle RpcBindingFree RpcBindingCreateW RpcAsyncCompleteCall RpcAsyncCancelCall Ndr64AsyncClientCall |
ksecdd.sys |
FreeCredentialsHandle
AcquireCredentialsHandleW ImpersonateSecurityContext AcceptSecurityContext FreeContextBuffer DeleteSecurityContext MapSecurityError AddCredentialsW |
Ordinal | 1 |
---|---|
Address | 0xddb0 |
Ordinal | 2 |
---|---|
Address | 0x2af0 |
Ordinal | 3 |
---|---|
Address | 0x12bf0 |
Ordinal | 4 |
---|---|
Address | 0x13070 |
Ordinal | 5 |
---|---|
Address | 0x28b0 |
Ordinal | 6 |
---|---|
Address | 0x13620 |
Ordinal | 7 |
---|---|
Address | 0x4310 |
Ordinal | 8 |
---|---|
Address | 0x4290 |
Ordinal | 9 |
---|---|
Address | 0xdc10 |
Ordinal | 10 |
---|---|
Address | 0xdb30 |
Ordinal | 11 |
---|---|
Address | 0x5180 |
Ordinal | 12 |
---|---|
Address | 0x60e0 |
Ordinal | 13 |
---|---|
Address | 0x2d70 |
Ordinal | 14 |
---|---|
Address | 0x4f90 |
Ordinal | 15 |
---|---|
Address | 0x6330 |
Ordinal | 16 |
---|---|
Address | 0x133f0 |
Ordinal | 17 |
---|---|
Address | 0x12af0 |
Ordinal | 18 |
---|---|
Address | 0x12a20 |
Ordinal | 19 |
---|---|
Address | 0x2b20 |
Ordinal | 20 |
---|---|
Address | 0x15070 |
Ordinal | 21 |
---|---|
Address | 0x5800 |
Ordinal | 22 |
---|---|
Address | 0x5290 |
Ordinal | 23 |
---|---|
Address | 0x127a0 |
Ordinal | 24 |
---|---|
Address | 0xdcb0 |
Ordinal | 25 |
---|---|
Address | 0x180e0 |
Ordinal | 26 |
---|---|
Address | 0x27910 |
Ordinal | 27 |
---|---|
Address | 0x26980 |
Ordinal | 28 |
---|---|
Address | 0x7390 |
Ordinal | 29 |
---|---|
Address | 0x6ba0 |
Ordinal | 30 |
---|---|
Address | 0xcad0 |
Ordinal | 31 |
---|---|
Address | 0x4090 |
Ordinal | 32 |
---|---|
Address | 0x116f0 |
Ordinal | 33 |
---|---|
Address | 0x11480 |
Ordinal | 34 |
---|---|
Address | 0x64e0 |
Ordinal | 35 |
---|---|
Address | 0x10f20 |
Ordinal | 36 |
---|---|
Address | 0xd0d0 |
Ordinal | 37 |
---|---|
Address | 0x3fb0 |
Ordinal | 38 |
---|---|
Address | 0xd360 |
Ordinal | 39 |
---|---|
Address | 0x27820 |
Ordinal | 40 |
---|---|
Address | 0x27690 |
Ordinal | 41 |
---|---|
Address | 0x27850 |
Ordinal | 42 |
---|---|
Address | 0x276c0 |
Ordinal | 43 |
---|---|
Address | 0x14370 |
Ordinal | 44 |
---|---|
Address | 0x10d40 |
Ordinal | 45 |
---|---|
Address | 0x6b90 |
Ordinal | 46 |
---|---|
Address | 0x10700 |
Ordinal | 47 |
---|---|
Address | 0x10760 |
Ordinal | 48 |
---|---|
Address | 0x4030 |
Ordinal | 49 |
---|---|
Address | 0x271c0 |
Ordinal | 50 |
---|---|
Address | 0x26870 |
Ordinal | 51 |
---|---|
Address | 0x27360 |
Ordinal | 52 |
---|---|
Address | 0x3fc0 |
Ordinal | 53 |
---|---|
Address | 0x5030 |
Ordinal | 54 |
---|---|
Address | 0xca50 |
Ordinal | 55 |
---|---|
Address | 0xca00 |
Ordinal | 56 |
---|---|
Address | 0x6d50 |
Ordinal | 57 |
---|---|
Address | 0xc8c0 |
Ordinal | 58 |
---|---|
Address | 0x3f00 |
Ordinal | 59 |
---|---|
Address | 0x10620 |
Ordinal | 60 |
---|---|
Address | 0x105b0 |
Ordinal | 61 |
---|---|
Address | 0x3ea0 |
Ordinal | 62 |
---|---|
Address | 0x4230 |
Ordinal | 63 |
---|---|
Address | 0x41d0 |
Ordinal | 64 |
---|---|
Address | 0xc830 |
Ordinal | 65 |
---|---|
Address | 0x3dc0 |
Ordinal | 66 |
---|---|
Address | 0xc8a0 |
Ordinal | 67 |
---|---|
Address | 0x10d90 |
Ordinal | 68 |
---|---|
Address | 0xd430 |
Ordinal | 69 |
---|---|
Address | 0xca80 |
Ordinal | 70 |
---|---|
Address | 0x23010 |
Ordinal | 71 |
---|---|
Address | 0x3c50 |
Ordinal | 72 |
---|---|
Address | 0xcf00 |
Ordinal | 73 |
---|---|
Address | 0xca30 |
Ordinal | 74 |
---|---|
Address | 0xcf90 |
Ordinal | 75 |
---|---|
Address | 0x50d0 |
Ordinal | 76 |
---|---|
Address | 0x25000 |
Ordinal | 77 |
---|---|
Address | 0x3860 |
Ordinal | 78 |
---|---|
Address | 0x3570 |
Ordinal | 79 |
---|---|
Address | 0xf830 |
Ordinal | 80 |
---|---|
Address | 0x4a70 |
Ordinal | 81 |
---|---|
Address | 0x4ea0 |
Ordinal | 82 |
---|---|
Address | 0x24bd0 |
Ordinal | 83 |
---|---|
Address | 0x29d20 |
Ordinal | 84 |
---|---|
Address | 0xf220 |
Ordinal | 85 |
---|---|
Address | 0x4ec0 |
Ordinal | 86 |
---|---|
Address | 0x29170 |
Ordinal | 87 |
---|---|
Address | 0x3740 |
Ordinal | 88 |
---|---|
Address | 0x3500 |
Ordinal | 89 |
---|---|
Address | 0xf1f0 |
Ordinal | 90 |
---|---|
Address | 0x36d0 |
Ordinal | 91 |
---|---|
Address | 0xf0d0 |
Ordinal | 92 |
---|---|
Address | 0xf290 |
Ordinal | 93 |
---|---|
Address | 0x5110 |
Ordinal | 94 |
---|---|
Address | 0xf770 |
Ordinal | 95 |
---|---|
Address | 0x6120 |
Ordinal | 96 |
---|---|
Address | 0xf790 |
Ordinal | 97 |
---|---|
Address | 0x23130 |
Ordinal | 98 |
---|---|
Address | 0xe7e0 |
Ordinal | 99 |
---|---|
Address | 0x6220 |
Ordinal | 100 |
---|---|
Address | 0x3040 |
Ordinal | 101 |
---|---|
Address | 0x17290 |
Ordinal | 102 |
---|---|
Address | 0x1d40 |
Ordinal | 103 |
---|---|
Address | 0x6130 |
Ordinal | 104 |
---|---|
Address | 0x23410 |
Ordinal | 105 |
---|---|
Address | 0xe9c0 |
Ordinal | 106 |
---|---|
Address | 0xe980 |
Ordinal | 107 |
---|---|
Address | 0x1180 |
Ordinal | 108 |
---|---|
Address | 0x36e0 |
Ordinal | 109 |
---|---|
Address | 0x1010 |
Ordinal | 110 |
---|---|
Address | 0x29590 |
Ordinal | 111 |
---|---|
Address | 0x282f0 |
Ordinal | 112 |
---|---|
Address | 0x27df0 |
Ordinal | 113 |
---|---|
Address | 0x28ca0 |
Ordinal | 114 |
---|---|
Address | 0x28b50 |
Ordinal | 115 |
---|---|
Address | 0x28890 |
Ordinal | 116 |
---|---|
Address | 0x28580 |
Ordinal | 117 |
---|---|
Address | 0x28070 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.1.7601.17514 |
ProductVersion | 6.1.7601.17514 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DRV
|
FileSubtype | VFT2_DRV_NETWORK |
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Server Network driver |
FileVersion (#2) | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | SRVNET.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRVNET.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.1.7601.17514 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:27:20 |
Version | 0.0 |
SizeofData | 35 |
AddressOfRawData | 0x18478 |
PointerToRawData | 0x17878 |
Referenced File | srvnet.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2010-Nov-20 09:27:20 |
Version | 565.6526 |
SizeofData | 4 |
AddressOfRawData | 0x18474 |
PointerToRawData | 0x17874 |
XOR Key | 0xd245d822 |
---|---|
Unmarked objects | 0 |
Total imports | 180 |
Imports (VS2008 SP1 build 30729) | 11 |
ASM objects (VS2008 SP1 build 30729) | 4 |
C objects (VS2008 SP1 build 30729) | 6 |
Exports (VS2008 SP1 build 30729) | 1 |
142 (VS2008 SP1 build 30729) | 52 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |