Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
Compilation Date | 2015-Jul-10 03:15:41 |
Detected languages |
English - United States
|
Debug artifacts |
srvnet.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Server Network driver |
FileVersion | 10.0.10240.16384 (th1.150709-1700) |
InternalName | SRVNET.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRVNET.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.10240.16384 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Suspicious | The PE is possibly packed. |
Unusual section name found: ALMOSTRO
Unusual section name found: PAGE Unusual section name found: GFIDS |
Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
Safe | VirusTotal score: 0/65 (Scanned on 2018-06-02 06:12:32) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 12 |
TimeDateStamp | 2015-Jul-10 03:15:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x2c200 |
SizeOfInitializedData | 0xee00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000003E030 (Section: INIT) |
BaseOfCode | 0x1000 |
ImageBase | 0x1c0000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x42000 |
SizeOfHeaders | 0x400 |
Checksum | 0x41df6 |
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntoskrnl.exe |
DbgPrint
KeStackAttachProcess RtlGUIDFromString KeClearEvent IoQueueThreadIrp ObfReferenceObject IofCallDriver RtlUpcaseUnicodeString NtDeviceIoControlFile IoFreeMdl MmProbeAndLockPages MmUnlockPages RtlCaptureStackBackTrace RtlCopyUnicodeString IoAllocateMdl RtlAnsiStringToUnicodeString RtlFreeUnicodeString IoReuseIrp IoGetActivityIdThread KeGetCurrentNodeNumber EtwProviderEnabled KeBugCheckEx _wcsicmp RtlQueryRegistryValues RtlIpv4AddressToStringW RtlIpv4AddressToStringA IoClearActivityIdThread IoSetActivityIdThread RtlIpv6AddressToStringW RtlIpv6AddressToStringA IoQueueWorkItemEx IoUninitializeWorkItem RtlIpv6StringToAddressW RtlIpv4StringToAddressW IoInitializeWorkItem RtlFreeOemString ZwOpenFile IoSizeofWorkItem ExQueueWorkItem MmUnmapLockedPages ExpInterlockedPushEntrySList ExpInterlockedPopEntrySList MmBuildMdlForNonPagedPool MmSizeOfMdl ExQueryDepthSList IofCompleteRequest MmMapLockedPagesSpecifyCache ExGetPreviousMode KeAcquireSpinLockRaiseToDpc KeInitializeSpinLock ExAllocatePoolWithTagPriority KeAcquireSpinLockAtDpcLevel KeCancelTimer ExInitializeResourceLite IoQueueWorkItem IoCreateDevice ExDeleteResourceLite RtlCompareMemory KeQueryMaximumProcessorCountEx KeWaitForSingleObject KeQueryActiveProcessorCountEx KeQueryTimeIncrement ExReleaseResourceLite IoAllocateWorkItem IoGetCurrentProcess ExAcquireResourceSharedLite KeDelayExecutionThread KeInitializeTimer ObfDereferenceObject IoAllocateIrp IoFreeIrp KeReadStateQueue ObReferenceObjectByHandle ZwClose NtCreateFile EtwWrite KeUnstackDetachProcess RtlEqualUnicodeString RtlUnicodeStringToOemString ZwDeviceIoControlFile RtlRunOnceExecuteOnce RtlRunOnceInitialize VerSetConditionMask RtlVerifyVersionInfo ExInitializePagedLookasideList PoCreatePowerRequest PoDeletePowerRequest ExDeletePagedLookasideList ZwCreateEvent ZwFsControlFile ZwWaitForSingleObject PoSetPowerRequest PoClearPowerRequest qsort bsearch ZwOpenKey ZwEnumerateValueKey RtlCompareUnicodeString RtlInitializeGenericTableAvl RtlIsGenericTableEmptyAvl RtlEnumerateGenericTableAvl RtlDeleteElementGenericTableAvl RtlLookupElementGenericTableAvl RtlInsertElementGenericTableAvl RtlValidRelativeSecurityDescriptor RtlEnumerateGenericTableLikeADirectory RtlLengthSecurityDescriptor KeAcquireGuardedMutex KeReleaseGuardedMutex KeInitializeGuardedMutex ExInitializeRundownProtection ExWaitForRundownProtectionRelease ExAcquireRundownProtection ExReleaseRundownProtection RtlLengthSid RtlCopySid ZwCreateKey ZwSetValueKey RtlAbsoluteToSelfRelativeSD RtlValidSecurityDescriptor IoWMIWriteEvent RtlTimeToSecondsSince1980 RtlPrefixUnicodeString _wcsupr wcsstr RtlIpv4AddressToStringExW RtlIpv6AddressToStringExW RtlLengthRequiredSid RtlInitializeSid RtlSubAuthoritySid RtlCreateAcl RtlAddAccessAllowedAce RtlCreateSecurityDescriptor RtlSetDaclSecurityDescriptor ObSetSecurityObjectByPointer RtlGetDaclSecurityDescriptor SeCaptureSubjectContext SeReleaseSubjectContext SeFreePrivileges PsAssignImpersonationToken ZwOpenThreadTokenEx ZwOpenProcessTokenEx ZwQueryInformationToken SeQueryAuthenticationIdToken SeSetAuditParameter SeReportSecurityEventWithSubCategory SeAccessCheckEx SeAuditingWithTokenForSubcategory RtlInitAnsiString LsaRegisterLogonProcess RtlInitString LsaLookupAuthenticationPackage LsaDeregisterLogonProcess NtAllocateLocallyUniqueId NtAllocateVirtualMemory LsaLogonUser NtFreeVirtualMemory LsaFreeReturnBuffer KfRaiseIrql KeLowerIrql ZwQueryValueKey ZwQueryLicenseValue IoAllocateErrorLogEntry IoWriteErrorLogEntry ExpInterlockedFlushSList ExInitializeNPagedLookasideList ExDeleteNPagedLookasideList ExFlushLookasideListEx ExInitializeLookasideListEx ExDeleteLookasideListEx KeEnterCriticalRegion KeReleaseSpinLockFromDpcLevel KeReleaseSpinLock EtwRegister KeInitializeDpc KeInitializeEvent MmGetSystemRoutineAddress IoFreeWorkItem KeSetEvent IoDeleteDevice RtlInitUnicodeString KeSetCoalescableTimer KeLeaveCriticalRegion ExFreePoolWithTag EtwUnregister IoWMIRegistrationControl KeQueryHighestNodeNumber ExAllocatePoolWithTag ExAcquireResourceExclusiveLite IoGetRelatedDeviceObject ExAcquireSpinLockExclusive ExReleaseSpinLockShared ExReleasePushLockSharedEx ExReleaseSpinLockExclusive ExReleasePushLockExclusiveEx ExAcquirePushLockSharedEx ExAcquirePushLockExclusiveEx ExAcquireSpinLockShared ExReleasePushLockEx __C_specific_handler |
---|---|
TDI.SYS |
TdiOpenNetbiosAddress
TdiRegisterPnPHandlers TdiCopyBufferToMdl TdiCopyMdlToBuffer TdiDeregisterPnPHandlers |
NETIO.SYS |
NsiGetAllParameters
NmrRegisterClient NmrDeregisterClient NmrWaitForClientDeregisterComplete NmrClientAttachProvider NsiDeregisterChangeNotification GetUnicastIpAddressTable ConvertInterfaceLuidToIndex NsiAllocateAndGetTable ConvertInterfaceGuidToLuid NotifyUnicastIpAddressChange FreeMibTable NsiRegisterChangeNotification GetIfTable2 GetUnicastIpAddressEntry NsiFreeTable CancelMibChangeNotify2 |
msrpc.sys |
RpcBindingCreateW
RpcBindingSetOption RpcSsDestroyClientContext RpcBindingUnbind RpcBindingBind RpcAsyncInitializeHandle I_RpcExceptionFilter RpcBindingFree RpcAsyncCompleteCall RpcAsyncCancelCall Ndr64AsyncClientCall |
ksecdd.sys |
BCryptHashData
BCryptFinishHash BCryptDuplicateKey BCryptGenerateSymmetricKey BCryptCloseAlgorithmProvider BCryptDecrypt BCryptKeyDerivation BCryptDestroyKey BCryptCreateHash BCryptGetProperty AcquireCredentialsHandleW MapSecurityError FreeCredentialsHandle ImpersonateSecurityContext BCryptDestroyHash BCryptOpenAlgorithmProvider BCryptEncrypt BCryptSetProperty BCryptGenRandom |
Ordinal | 1 |
---|---|
Address | 0xb9e0 |
Ordinal | 2 |
---|---|
Address | 0xb990 |
Ordinal | 3 |
---|---|
Address | 0x329a0 |
Ordinal | 4 |
---|---|
Address | 0x33220 |
Ordinal | 5 |
---|---|
Address | 0x18130 |
Ordinal | 6 |
---|---|
Address | 0x18140 |
Ordinal | 7 |
---|---|
Address | 0xda30 |
Ordinal | 8 |
---|---|
Address | 0xdbc0 |
Ordinal | 9 |
---|---|
Address | 0x18150 |
Ordinal | 10 |
---|---|
Address | 0x18160 |
Ordinal | 11 |
---|---|
Address | 0x31fa0 |
Ordinal | 12 |
---|---|
Address | 0xd180 |
Ordinal | 13 |
---|---|
Address | 0x7410 |
Ordinal | 14 |
---|---|
Address | 0x181b0 |
Ordinal | 15 |
---|---|
Address | 0x7990 |
Ordinal | 16 |
---|---|
Address | 0x185e0 |
Ordinal | 17 |
---|---|
Address | 0x18ad0 |
Ordinal | 18 |
---|---|
Address | 0x18f20 |
Ordinal | 19 |
---|---|
Address | 0x3a940 |
Ordinal | 20 |
---|---|
Address | 0xa540 |
Ordinal | 21 |
---|---|
Address | 0x2840 |
Ordinal | 22 |
---|---|
Address | 0x9a60 |
Ordinal | 23 |
---|---|
Address | 0xa120 |
Ordinal | 24 |
---|---|
Address | 0x18250 |
Ordinal | 25 |
---|---|
Address | 0x182f0 |
Ordinal | 26 |
---|---|
Address | 0x5350 |
Ordinal | 27 |
---|---|
Address | 0x7190 |
Ordinal | 28 |
---|---|
Address | 0x18930 |
Ordinal | 29 |
---|---|
Address | 0x2e350 |
Ordinal | 30 |
---|---|
Address | 0x3a990 |
Ordinal | 31 |
---|---|
Address | 0x328a0 |
Ordinal | 32 |
---|---|
Address | 0xdb40 |
Ordinal | 33 |
---|---|
Address | 0x5480 |
Ordinal | 34 |
---|---|
Address | 0x32790 |
Ordinal | 35 |
---|---|
Address | 0xb080 |
Ordinal | 36 |
---|---|
Address | 0x2e410 |
Ordinal | 37 |
---|---|
Address | 0x3b0f0 |
Ordinal | 38 |
---|---|
Address | 0x3b4f0 |
Ordinal | 39 |
---|---|
Address | 0x2dc60 |
Ordinal | 40 |
---|---|
Address | 0x3b8e0 |
Ordinal | 41 |
---|---|
Address | 0x9b30 |
Ordinal | 42 |
---|---|
Address | 0x3c70 |
Ordinal | 43 |
---|---|
Address | 0x3fa0 |
Ordinal | 44 |
---|---|
Address | 0x2ec10 |
Ordinal | 45 |
---|---|
Address | 0x4a60 |
Ordinal | 46 |
---|---|
Address | 0x8e60 |
Ordinal | 47 |
---|---|
Address | 0x3d90 |
Ordinal | 48 |
---|---|
Address | 0x9ce0 |
Ordinal | 49 |
---|---|
Address | 0xa200 |
Ordinal | 50 |
---|---|
Address | 0x183d0 |
Ordinal | 51 |
---|---|
Address | 0x3a9a0 |
Ordinal | 52 |
---|---|
Address | 0x32490 |
Ordinal | 53 |
---|---|
Address | 0x7b60 |
Ordinal | 54 |
---|---|
Address | 0x19480 |
Ordinal | 55 |
---|---|
Address | 0x33100 |
Ordinal | 56 |
---|---|
Address | 0x5d90 |
Ordinal | 57 |
---|---|
Address | 0xbd30 |
Ordinal | 58 |
---|---|
Address | 0x2df70 |
Ordinal | 59 |
---|---|
Address | 0x318a0 |
Ordinal | 60 |
---|---|
Address | 0xb030 |
Ordinal | 61 |
---|---|
Address | 0x1c170 |
Ordinal | 62 |
---|---|
Address | 0x4830 |
Ordinal | 63 |
---|---|
Address | 0xbee0 |
Ordinal | 64 |
---|---|
Address | 0xc8e0 |
Ordinal | 65 |
---|---|
Address | 0x1c5a0 |
Ordinal | 66 |
---|---|
Address | 0xb090 |
Ordinal | 67 |
---|---|
Address | 0x1c8a0 |
Ordinal | 68 |
---|---|
Address | 0x1c7d0 |
Ordinal | 69 |
---|---|
Address | 0x2c00 |
Ordinal | 70 |
---|---|
Address | 0x2dd80 |
Ordinal | 71 |
---|---|
Address | 0x320a0 |
Ordinal | 72 |
---|---|
Address | 0xd240 |
Ordinal | 73 |
---|---|
Address | 0xabb0 |
Ordinal | 74 |
---|---|
Address | 0x1c920 |
Ordinal | 75 |
---|---|
Address | 0xac30 |
Ordinal | 76 |
---|---|
Address | 0x1bf60 |
Ordinal | 77 |
---|---|
Address | 0xd9f0 |
Ordinal | 78 |
---|---|
Address | 0x3bc00 |
Ordinal | 79 |
---|---|
Address | 0x31e00 |
Ordinal | 80 |
---|---|
Address | 0x32640 |
Ordinal | 81 |
---|---|
Address | 0x2eaa0 |
Ordinal | 82 |
---|---|
Address | 0x2fac0 |
Ordinal | 83 |
---|---|
Address | 0x2efd0 |
Ordinal | 84 |
---|---|
Address | 0x32f30 |
Ordinal | 85 |
---|---|
Address | 0x3bc50 |
Ordinal | 86 |
---|---|
Address | 0x7b20 |
Ordinal | 87 |
---|---|
Address | 0x30fa0 |
Ordinal | 88 |
---|---|
Address | 0x335b0 |
Ordinal | 89 |
---|---|
Address | 0x32830 |
Ordinal | 90 |
---|---|
Address | 0x1bfa0 |
Ordinal | 91 |
---|---|
Address | 0x14a0 |
Ordinal | 92 |
---|---|
Address | 0x335a0 |
Ordinal | 93 |
---|---|
Address | 0x1c930 |
Ordinal | 94 |
---|---|
Address | 0x3bc60 |
Ordinal | 95 |
---|---|
Address | 0x5560 |
Ordinal | 96 |
---|---|
Address | 0x2ea40 |
Ordinal | 97 |
---|---|
Address | 0x1c960 |
Ordinal | 98 |
---|---|
Address | 0x5fd0 |
Ordinal | 99 |
---|---|
Address | 0x71d0 |
Ordinal | 100 |
---|---|
Address | 0x29c0 |
Ordinal | 101 |
---|---|
Address | 0x29b0 |
Ordinal | 102 |
---|---|
Address | 0x7430 |
Ordinal | 103 |
---|---|
Address | 0x72c0 |
Ordinal | 104 |
---|---|
Address | 0x1ca90 |
Ordinal | 105 |
---|---|
Address | 0x6ce0 |
Ordinal | 106 |
---|---|
Address | 0x7930 |
Ordinal | 107 |
---|---|
Address | 0x7130 |
Ordinal | 108 |
---|---|
Address | 0x3ba10 |
Ordinal | 109 |
---|---|
Address | 0xdb60 |
Ordinal | 110 |
---|---|
Address | 0x78e0 |
Ordinal | 111 |
---|---|
Address | 0x326a0 |
Ordinal | 112 |
---|---|
Address | 0x3bc70 |
Ordinal | 113 |
---|---|
Address | 0x2dd60 |
Ordinal | 114 |
---|---|
Address | 0x31c80 |
Ordinal | 115 |
---|---|
Address | 0x5c30 |
Ordinal | 116 |
---|---|
Address | 0x3bb80 |
Ordinal | 117 |
---|---|
Address | 0x2e980 |
Ordinal | 118 |
---|---|
Address | 0x7450 |
Ordinal | 119 |
---|---|
Address | 0x1c000 |
Ordinal | 120 |
---|---|
Address | 0x1360 |
Ordinal | 121 |
---|---|
Address | 0xda70 |
Ordinal | 122 |
---|---|
Address | 0x2ff30 |
Ordinal | 123 |
---|---|
Address | 0x8ac0 |
Ordinal | 124 |
---|---|
Address | 0x7b70 |
Ordinal | 125 |
---|---|
Address | 0x1b70 |
Ordinal | 126 |
---|---|
Address | 0x13ed0 |
Ordinal | 127 |
---|---|
Address | 0x7ad0 |
Ordinal | 128 |
---|---|
Address | 0x32dd0 |
Ordinal | 129 |
---|---|
Address | 0xd6b0 |
Ordinal | 130 |
---|---|
Address | 0x156d0 |
Ordinal | 131 |
---|---|
Address | 0xb570 |
Ordinal | 132 |
---|---|
Address | 0xdbf0 |
Ordinal | 133 |
---|---|
Address | 0x2d940 |
Ordinal | 134 |
---|---|
Address | 0xdae0 |
Ordinal | 135 |
---|---|
Address | 0x2db30 |
Ordinal | 136 |
---|---|
Address | 0xb290 |
Ordinal | 137 |
---|---|
Address | 0x2bb0 |
Ordinal | 138 |
---|---|
Address | 0x98f0 |
Ordinal | 139 |
---|---|
Address | 0x33270 |
Ordinal | 140 |
---|---|
Address | 0x95e0 |
Ordinal | 141 |
---|---|
Address | 0x1b40 |
Ordinal | 142 |
---|---|
Address | 0x7b50 |
Ordinal | 143 |
---|---|
Address | 0x13fb0 |
Ordinal | 144 |
---|---|
Address | 0xd1f0 |
Ordinal | 145 |
---|---|
Address | 0x7b30 |
Ordinal | 146 |
---|---|
Address | 0xc380 |
Ordinal | 147 |
---|---|
Address | 0x5ad0 |
Ordinal | 148 |
---|---|
Address | 0xdbd0 |
Ordinal | 149 |
---|---|
Address | 0x6d90 |
Ordinal | 150 |
---|---|
Address | 0xb070 |
Ordinal | 151 |
---|---|
Address | 0xdb70 |
Ordinal | 152 |
---|---|
Address | 0x335c0 |
Ordinal | 153 |
---|---|
Address | 0x33010 |
Ordinal | 154 |
---|---|
Address | 0x168f0 |
Ordinal | 155 |
---|---|
Address | 0x143d0 |
Ordinal | 156 |
---|---|
Address | 0x37f20 |
Ordinal | 157 |
---|---|
Address | 0x16910 |
Ordinal | 158 |
---|---|
Address | 0x16920 |
Ordinal | 159 |
---|---|
Address | 0x6e60 |
Ordinal | 160 |
---|---|
Address | 0x8ca0 |
Ordinal | 161 |
---|---|
Address | 0xdb80 |
Ordinal | 162 |
---|---|
Address | 0x33580 |
Ordinal | 163 |
---|---|
Address | 0x32a70 |
Ordinal | 164 |
---|---|
Address | 0xdbe0 |
Ordinal | 165 |
---|---|
Address | 0xd820 |
Ordinal | 166 |
---|---|
Address | 0x377c0 |
Ordinal | 167 |
---|---|
Address | 0x7a90 |
Ordinal | 168 |
---|---|
Address | 0x2b60 |
Ordinal | 169 |
---|---|
Address | 0x1be0 |
Ordinal | 170 |
---|---|
Address | 0xaee0 |
Ordinal | 171 |
---|---|
Address | 0x39490 |
Ordinal | 172 |
---|---|
Address | 0x37f40 |
Ordinal | 173 |
---|---|
Address | 0x39ae0 |
Ordinal | 174 |
---|---|
Address | 0x383c0 |
Ordinal | 175 |
---|---|
Address | 0x386e0 |
Ordinal | 176 |
---|---|
Address | 0x30cc0 |
Ordinal | 177 |
---|---|
Address | 0x37f60 |
Ordinal | 178 |
---|---|
Address | 0x380c0 |
Ordinal | 179 |
---|---|
Address | 0x38990 |
Ordinal | 180 |
---|---|
Address | 0x38c40 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.10240.16384 |
ProductVersion | 10.0.10240.16384 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DRV
|
FileSubtype | VFT2_DRV_NETWORK |
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Server Network driver |
FileVersion (#2) | 10.0.10240.16384 (th1.150709-1700) |
InternalName | SRVNET.SYS |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SRVNET.SYS |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.10240.16384 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2015-Jul-10 03:15:41 |
Version | 0.0 |
SizeofData | 35 |
AddressOfRawData | 0x1ff64 |
PointerToRawData | 0x1eb64 |
Referenced File | srvnet.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2015-Jul-10 03:15:41 |
Version | 0.0 |
SizeofData | 1248 |
AddressOfRawData | 0x1ff9c |
PointerToRawData | 0x1eb9c |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1c00243e8 |
GuardCFCheckFunctionPointer | 7516362760 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x33c8b620 |
---|---|
Unmarked objects | 0 |
Total imports | 253 |
239 (40116) | 11 |
242 (40116) | 4 |
241 (40116) | 5 |
238 (40116) | 1 |
251 (40116) | 72 |
Imports (40116) | 1 |
240 (40116) | 1 |