Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2025-Feb-20 07:07:03 |
Detected languages |
English - United States
|
Debug artifacts |
C:\__w\1\b\x64\MicrosoftStartFeedProvider.pdb
|
CompanyName | Microsoft Corporation |
FileVersion | 1.1.282.0 |
InternalName | MicrosoftStartFeedProvider.exe |
LegalCopyright | ©Microsoft Corporation. All rights reserved. |
OriginalFilename | MicrosoftStartFeedProvider.exe |
ProductName | Microsoft\MicrosoftStartFeedProvider |
ProductVersion | 1.1.282.0 |
Info | Matching compiler(s): | MASM/TASM - sig1(h) |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
Info | Cryptographic algorithms detected in the binary: |
Uses known Mersenne Twister constants
Microsoft's Cryptography API |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/73 (Scanned on 2025-03-12 16:24:52) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 7 |
TimeDateStamp | 2025-Feb-20 07:07:03 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x108a00 |
SizeOfInitializedData | 0x72e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000000E1DD0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x180000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
FormatMessageW
IsDebuggerPresent SetLastError GetLastError CloseHandle GetProcAddress GetModuleHandleW SetEvent CreateEventExW GetModuleFileNameA CreateSemaphoreExW HeapFree ReleaseSemaphore GetModuleHandleExW WaitForSingleObject ReleaseMutex WaitForSingleObjectEx OpenSemaphoreW HeapAlloc CreateMutexExW GetCurrentProcessId GetProcessHeap WideCharToMultiByte DebugBreak InitOnceComplete InitOnceBeginInitialize SetThreadpoolWait WaitForThreadpoolWaitCallbacks CloseThreadpoolWait CreateThreadpoolWait SetThreadpoolWaitEx CreateThreadpoolTimer SetThreadpoolTimerEx SetThreadpoolTimer CloseThreadpoolTimer InterlockedFlushSList EncodePointer GetSystemTimePreciseAsFileTime CreateEventW MultiByteToWideChar FileTimeToSystemTime GetFileSizeEx SystemTimeToFileTime InitializeCriticalSectionEx GetThreadPreferredUILanguages GetCurrentThreadId ResetEvent Sleep WaitForMultipleObjects GetSystemTimeAsFileTime AcquireSRWLockShared ReleaseSRWLockShared ConnectNamedPipe CreateNamedPipeW ReadFile InitializeCriticalSection DeleteCriticalSection TerminateProcess OpenProcess CompareStringOrdinal EnterCriticalSection LeaveCriticalSection GetCurrentPackageId CreateFileW CreateDirectoryW FindClose DeleteFileW FindNextFileW FindFirstFileExW FindFirstFileW GetExitCodeThread AcquireSRWLockExclusive ReleaseSRWLockExclusive CreateThread CreateSemaphoreW WriteFile SetFilePointer GetLogicalProcessorInformation GetPhysicallyInstalledSystemMemory SleepConditionVariableSRW GetTickCount64 WakeAllConditionVariable RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess IsProcessorFeaturePresent GetStartupInfoW QueryPerformanceCounter InitializeSListHead GetUserDefaultGeoName OutputDebugStringW LoadLibraryExW InterlockedPushEntrySList TrySubmitThreadpoolCallback |
---|---|
api-ms-win-core-com-l1-1-0.dll |
CoWaitForMultipleObjects
CoRegisterClassObject CoGetApartmentType CoAddRefServerProcess CoRevokeClassObject CoReleaseServerProcess CoInitializeEx CoUninitialize CoCreateFreeThreadedMarshaler CoGetObjectContext |
api-ms-win-core-errorhandling-l1-1-0.dll |
RaiseException
|
api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemInfo
|
api-ms-win-core-memory-l1-1-0.dll |
VirtualQuery
VirtualProtect |
api-ms-win-core-libraryloader-l1-2-0.dll |
LoadLibraryExA
FreeLibrary |
MSVCP140.dll |
?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAPEAV12@PEA_W_J@Z ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@G@Z ?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z ?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ ?setg@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXPEA_W00@Z ?setp@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXPEA_W00@Z ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ ??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z _Xtime_get_ticks ?_Xout_of_range@std@@YAXPEBD@Z ?_Xruntime_error@std@@YAXPEBD@Z ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z ?_Makeloc@_Locimp@locale@std@@CAPEAV123@AEBV_Locinfo@3@HPEAV123@PEBV23@@Z ?_Getname@_Locinfo@std@@QEBAPEBDXZ ??1_Locinfo@std@@QEAA@XZ ??1_Lockit@std@@QEAA@XZ ??0_Locinfo@std@@QEAA@HPEBD@Z ??0_Lockit@std@@QEAA@H@Z ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@_N@Z ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ ??Bid@locale@std@@QEAA_KXZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ _Query_perf_counter _Query_perf_frequency ?id@?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@2V0locale@2@A ?_Getcat@?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?put@?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@2@V32@AEAVios_base@2@_WPEBUtm@@PEB_W4@Z ?imbue@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z ?seekp@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_JH@Z ?widen@?$ctype@_W@std@@QEBA_WD@Z ?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?id@?$ctype@_W@std@@2V0locale@2@A ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@K@Z ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_N@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@H@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@N@Z _Thrd_detach _Cnd_do_broadcast_at_thread_exit _Lock_shared_ptr_spin_lock _Unlock_shared_ptr_spin_lock ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@I@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@J@Z ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ _Thrd_join _Thrd_id ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?tolower@?$ctype@_W@std@@QEBA_W_W@Z ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?id@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ?_Getcat@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?get@?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$istreambuf_iterator@DU?$char_traits@D@std@@@2@V32@0AEAVios_base@2@AEAHPEAUtm@@PEBD4@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z ??1?$basic_ostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ??0?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@_N@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@_K@Z ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAHXZ ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAAXXZ _Mtx_lock ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z ?_Throw_Cpp_error@std@@YAXH@Z _Mtx_unlock _Cnd_broadcast _Cnd_wait ?_Random_device@std@@YAIXZ _Cnd_register_at_thread_exit _Cnd_unregister_at_thread_exit ?_Syserror_map@std@@YAPEBDH@Z ?_Xlength_error@std@@YAXPEBD@Z ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z ?__ExceptionPtrDestroy@@YAXPEAX@Z ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ ?_ReportUnobservedException@details@Concurrency@@YAXXZ ?__ExceptionPtrRethrow@@YAXPEBX@Z ??0task_continuation_context@Concurrency@@AEAA@XZ ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?__ExceptionPtrCurrentException@@YAXPEAX@Z ?good@ios_base@std@@QEBA_NXZ ?__ExceptionPtrCreate@@YAXPEAX@Z ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z ?_Xbad_alloc@std@@YAXXZ ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ _Thrd_yield ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ ?__ExceptionPtrToBool@@YA_NPEBX@Z ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAGXZ ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_Xbad_function_call@std@@YAXXZ ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAAXAEBVlocale@2@@Z ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z ?uncaught_exception@std@@YA_NXZ |
ole32.dll |
CoTaskMemFree
PropVariantClear CoTaskMemAlloc CoCreateGuid |
VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
VCRUNTIME140.dll |
memcpy
__std_exception_destroy __std_exception_copy __std_terminate __C_specific_handler __current_exception __current_exception_context _CxxThrowException memset memcmp memmove _purecall |
api-ms-win-crt-runtime-l1-1-0.dll |
_invalid_parameter_noinfo_noreturn
_register_thread_local_exe_atexit_callback _c_exit _exit _invalid_parameter_noinfo _errno _beginthreadex exit _initterm_e _initterm _get_wide_winmain_command_line _initialize_wide_environment _configure_wide_argv terminate _set_app_type _seh_filter_exe _cexit _initialize_onexit_table _register_onexit_function _crt_atexit abort |
api-ms-win-crt-stdio-l1-1-0.dll |
__stdio_common_vswprintf_s
__stdio_common_vswprintf __p__commode _set_fmode |
api-ms-win-crt-string-l1-1-0.dll |
isspace
toupper wcsncmp wcsnlen iswspace _wcsicmp _wcsnicmp |
api-ms-win-crt-heap-l1-1-0.dll |
malloc
free _callnewh _set_new_mode |
api-ms-win-crt-time-l1-1-0.dll |
_gmtime64_s
|
api-ms-win-crt-convert-l1-1-0.dll |
wcstombs_s
_ltoa_s |
api-ms-win-crt-math-l1-1-0.dll |
ceilf
__setusermatherr |
api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
USER32.dll |
MonitorFromWindow
GetMonitorInfoW SetWindowPos RegisterClassExW CreateWindowExW GetShellWindow RegisterPowerSettingNotification UnregisterPowerSettingNotification PostThreadMessageW MessageBoxW PostQuitMessage DefWindowProcW GetWindowLongPtrW IsWindowVisible GetWindow DestroyWindow DispatchMessageW TranslateMessage GetMessageW SetWindowLongPtrW PostMessageW SystemParametersInfoW GetSysColor LoadCursorW AllowSetForegroundWindow |
Wldp.dll |
WldpQueryWindowsLockdownMode
|
api-ms-win-core-registry-l1-1-0.dll |
RegQueryValueExW
RegCloseKey RegGetValueW RegQueryInfoKeyW RegOpenKeyExW RegEnumValueW |
api-ms-win-core-registry-l2-1-0.dll |
RegEnumKeyW
RegOpenKeyW |
CRYPT32.dll |
CryptBinaryToStringW
|
OLEAUT32.dll |
SysStringLen
GetErrorInfo SafeArrayUnaccessData SafeArrayAccessData SafeArrayGetUBound SafeArrayGetLBound SafeArrayDestroy SafeArrayPutElement SysAllocString SysFreeString SafeArrayLock SafeArrayCreateVector SafeArrayUnlock SetErrorInfo |
api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressAll |
api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
|
api-ms-win-core-winrt-error-l1-1-0.dll |
RoFailFastWithErrorContext
RoTransformError |
api-ms-win-core-com-l1-1-1.dll |
RoGetAgileReference
|
SHLWAPI.dll (delay-loaded) |
SHRegGetUSValueW
SHRegCreateUSKeyW SHRegSetUSValueW AssocQueryStringW SHRegCloseUSKey SHRegOpenUSKeyW SHRegGetBoolUSValueW SHRegEnumUSValueW SHRegWriteUSValueW |
Attributes | 0x1 |
---|---|
Name | SHLWAPI.dll |
ModuleHandle | 0x16f130 |
DelayImportAddressTable | 0x17c000 |
DelayImportNameTable | 0x14bfe0 |
BoundDelayImportTable | 0x14c0e8 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.1.282.0 |
ProductVersion | 1.1.282.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileVersion (#2) | 1.1.282.0 |
InternalName | MicrosoftStartFeedProvider.exe |
LegalCopyright | ©Microsoft Corporation. All rights reserved. |
OriginalFilename | MicrosoftStartFeedProvider.exe |
ProductName | Microsoft\MicrosoftStartFeedProvider |
ProductVersion (#2) | 1.1.282.0 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Feb-20 07:07:03 |
Version | 0.0 |
SizeofData | 70 |
AddressOfRawData | 0x132ec8 |
PointerToRawData | 0x131cc8 |
Referenced File | C:\__w\1\b\x64\MicrosoftStartFeedProvider.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Feb-20 07:07:03 |
Version | 0.0 |
SizeofData | 1048 |
AddressOfRawData | 0x132f10 |
PointerToRawData | 0x131d10 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2025-Feb-20 07:07:03 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
StartAddressOfRawData | 0x140133348 |
---|---|
EndAddressOfRawData | 0x140133350 |
AddressOfIndex | 0x14016f750 |
AddressOfCallbacks | 0x14010af28 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x140 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140151040 |
GuardCFCheckFunctionPointer | 5369801728 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xd513f59c |
---|---|
Unmarked objects | 0 |
C objects (34321) | 10 |
ASM objects (34321) | 6 |
Imports (34321) | 6 |
C objects (30795) | 1 |
Imports (VS2008 SP1 build 30729) | 44 |
C++ objects (34321) | 42 |
Imports (30795) | 9 |
Total imports | 418 |
C++ objects (LTCG) (34436) | 46 |
Resource objects (34436) | 1 |
151 | 1 |
Linker (34436) | 1 |