30fe82f8975b5322a7474023c18ad7de01bc4ec2cefc444ae65d8bb3f1948d7a

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2021-Oct-12 23:41:32
Detected languages English - United States
Debug artifacts C:\Users\root\Documents\Visual Studio 2019\Projects\Win11DisableRoundedCorners\x64\Release\Win11DisableOrRestoreRoundedCorners.pdb
CompanyName VALINET Solutions SRL
FileDescription Disables or restores rounded corners in Windows 11
FileVersion 1.0.0.3
InternalName Win11DisableRoundedCorners.exe
LegalCopyright Copyright (C) 2006-2021 VALINET Solutions SRL. All rights reserved.
OriginalFilename Win11Dis.exe
ProductName Win11DisableRoundedCorners
ProductVersion 1.0.0.3

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • microsoft.com
  • msdl.microsoft.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Possibly launches other programs:
  • CreateProcessA
Has Internet access capabilities:
  • InternetOpenA
  • InternetCloseHandle
  • InternetConnectA
  • InternetReadFile
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetNamedSecurityInfoA
Safe VirusTotal score: 0/71 (Scanned on 2026-04-26 00:50:34) All the AVs think this file is safe.

Hashes

MD5 0238f27a51b67a3630c4833e2a84a4d7
SHA1 0d792e375976af68d033d889c560afaf75b49c88
SHA256 30fe82f8975b5322a7474023c18ad7de01bc4ec2cefc444ae65d8bb3f1948d7a
SHA3 d27abc718da2d9b491684520aff88a1cce6d1f9a50ddde55fe97d47bfc677b7c
SSDeep 3072:SikYR6rMK2E5ypkAM5ZMtc/LhmGG91sa5wq:horMR6DHMtCf
Imports Hash 24501b8834ce268c66bd0690b5a3d16e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2021-Oct-12 23:41:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x16600
SizeOfInitializedData 0x10000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000029A0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8559413f787eb12c0cd700bc23fbff57
SHA1 d0e555e9ad5a3cb25770338a14e57485640e6a50
SHA256 0007117f4fae2f6cfe090bc3b74659402cfaacbe1a9382aa4d69c2909df3302a
SHA3 e92230ba36143c34fbaf8d36cab336e83b6eaa1045b23f394034d4eed51151c4
VirtualSize 0x165d0
VirtualAddress 0x1000
SizeOfRawData 0x16600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49417

.rdata

MD5 7db23e48536e9785e617147fa4e4581f
SHA1 d3b93d64dbaa11baafcbca7f419558debffaf6bd
SHA256 41ab484840265fb1daad58921fb4b197bfb206b6b029f1a1f689e1ff8d61b4c1
SHA3 16be7808b5a6ba224160da82aab3df3ddc9cd4a5f711ef150c1e0c3ab36e342a
VirtualSize 0xba18
VirtualAddress 0x18000
SizeOfRawData 0xbc00
PointerToRawData 0x16a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.94561

.data

MD5 66d90ab6af1b7d2d9ec02c57cf065733
SHA1 4f08cb188a76b878a34be7412b15680b7c4b3b01
SHA256 6ac0f83393aefea7bc2057e6a17ef65a114fbff2e7b4bd5729cecc05d28bdac4
SHA3 9ffafcd3c5c24d7663f8978ffc924cd0471fb087491bdb4dac82fa36a0da9af2
VirtualSize 0x1c98
VirtualAddress 0x24000
SizeOfRawData 0xc00
PointerToRawData 0x22600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.7455

.pdata

MD5 8dcbe6d946fd62513b7b4882950f2027
SHA1 2ab288803f2f6d44df7b546ad9288baf2137218b
SHA256 517e9d8418a30a203a5e5c3ac0a384cc7912c22bffc1b6629ea6f6579b74df8f
SHA3 e19be857020ccaf1753f4ab5579b4702869a187f99198d244054cef641ef2e44
VirtualSize 0x1404
VirtualAddress 0x26000
SizeOfRawData 0x1600
PointerToRawData 0x23200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.82557

_RDATA

MD5 7ccb554f176815625d3723e42954167c
SHA1 d7de7806b07cefb24786f3afcecf99f630196165
SHA256 57ef3763107fd0e59d1acd49ecb59ec7c9424038168556edb6f9493c6dc3c1e6
SHA3 19f8b680907a4101c0103b72b588c1ba6a60739038653427a839d9032f5808bd
VirtualSize 0xfc
VirtualAddress 0x28000
SizeOfRawData 0x200
PointerToRawData 0x24800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.97379

.rsrc

MD5 54f2dbe6059f9f9d691527e0f2a896f2
SHA1 e734960b500b4b8fbbd47396923b733cbfcaf3eb
SHA256 fe26f6d2692915289bfd9badc4996e9126b418861fe79923d9d09ddeae9fc317
SHA3 c8a699080fdac513ddfc72ee14a4b8ee0a1ec6a625bae80a0940b9641abd7de7
VirtualSize 0x5f0
VirtualAddress 0x29000
SizeOfRawData 0x600
PointerToRawData 0x24a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.09452

.reloc

MD5 eaba67d7d56b32e5c710b4726cbd4275
SHA1 5dd82aa889966e79b00820d952cf3c13ceb87483
SHA256 5da77170e4de158c070ad204c3c1ea8bf6bb3337fe78b4d4fb37f0e338699b82
SHA3 892e69988a212644d33cee014befb1f3073055bdddf90a6253084f2fd59237c1
VirtualSize 0x660
VirtualAddress 0x2a000
SizeOfRawData 0x800
PointerToRawData 0x25000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.87702

Imports

KERNEL32.dll UnmapViewOfFile
GetModuleHandleA
Sleep
CopyFileA
GetLastError
CreateFileA
GetSystemDirectoryA
WaitForSingleObject
CloseHandle
GetSystemInfo
CreateFileMappingA
LocalFree
CreateProcessA
MapViewOfFile
SetEndOfFile
FindClose
VirtualAlloc
GetCurrentProcess
VirtualFree
FindFirstFileA
MoveFileA
DeleteFileA
GetModuleFileNameA
WriteConsoleW
HeapReAlloc
HeapSize
FlushFileBuffers
GetProcessHeap
GetStringTypeW
SetStdHandle
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
MultiByteToWideChar
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
FindNextFileW
FindFirstFileExW
GetFileSizeEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
ExitProcess
GetModuleHandleExW
ReadFile
GetConsoleCP
GetStdHandle
WriteFile
GetModuleFileNameW
GetCommandLineA
GetCommandLineW
SetFilePointerEx
GetConsoleMode
ReadConsoleW
GetFileType
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
WideCharToMultiByte
CreateFileW
SetConsoleMode
ReadConsoleInputW
GetConsoleOutputCP
ADVAPI32.dll AdjustTokenPrivileges
SetNamedSecurityInfoA
AllocateAndInitializeSid
LookupPrivilegeValueA
OpenProcessToken
FreeSid
SetEntriesInAclA
WININET.dll InternetOpenA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
HttpOpenRequestA
dbghelp.dll SymInitialize
SymGetOptions
SymLoadModuleEx
SymGetModuleInfo64
SymGetLineFromAddr64
SymUnloadModule64
SymEnumSymbols
SymSetOptions
SymCleanup
SHLWAPI.dll PathStripPathA
PathRemoveFileSpecA

Delayed Imports

1

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42588
MD5 428841b019be7aeb495614bfe02648f6
SHA1 24824e718bd73b69999c77aea76f2a94574810e3
SHA256 62af42b8cf3188469b909873e76b27509d603b0a3a4946bb2235f8a6dc2dcba7
SHA3 b507004a0c49074f7061316216dab080ab7ce2a3d4f5c81ae45d18a7f4d56719

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.3
ProductVersion 1.0.0.3
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName VALINET Solutions SRL
FileDescription Disables or restores rounded corners in Windows 11
FileVersion (#2) 1.0.0.3
InternalName Win11DisableRoundedCorners.exe
LegalCopyright Copyright (C) 2006-2021 VALINET Solutions SRL. All rights reserved.
OriginalFilename Win11Dis.exe
ProductName Win11DisableRoundedCorners
ProductVersion (#2) 1.0.0.3
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2021-Oct-12 23:41:32
Version 0.0
SizeofData 155
AddressOfRawData 0x21750
PointerToRawData 0x20150
Referenced File C:\Users\root\Documents\Visual Studio 2019\Projects\Win11DisableRoundedCorners\x64\Release\Win11DisableOrRestoreRoundedCorners.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2021-Oct-12 23:41:32
Version 0.0
SizeofData 20
AddressOfRawData 0x217ec
PointerToRawData 0x201ec

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2021-Oct-12 23:41:32
Version 0.0
SizeofData 720
AddressOfRawData 0x21800
PointerToRawData 0x20200

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2021-Oct-12 23:41:32
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140024008

RICH Header

XOR Key 0x40ac298f
Unmarked objects 0
C objects (27412) 11
ASM objects (27412) 5
C++ objects (27412) 150
C++ objects (30034) 37
C objects (30034) 16
ASM objects (30034) 9
Imports (27412) 11
Total imports 132
C objects (LTCG) (VS2019 Update 11 (16.11.0-3) compiler 30133) 1
Resource objects (VS2019 Update 11 (16.11.0-3) compiler 30133) 1
151 1
Linker (VS2019 Update 11 (16.11.0-3) compiler 30133) 1

Errors

Leave a comment

No comments yet.