Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2009-Jul-14 01:09:34 |
Detected languages |
English - United States
|
Debug artifacts |
psapi.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Process Status Helper |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | PSAPI |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | PSAPI |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Safe | VirusTotal score: 0/68 (Scanned on 2021-05-22 18:09:15) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2009-Jul-14 01:09:34 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 9.1 |
SizeOfCode | 0xc00 |
SizeOfInitializedData | 0x800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00001438 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2000 |
ImageBase | 0x75bf0000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 6.1 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x5000 |
SizeOfHeaders | 0x400 |
Checksum | 0xccd3 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
KERNEL32.dll |
K32EnumProcesses
K32EnumProcessModules K32EnumProcessModulesEx K32GetModuleBaseNameA K32GetModuleBaseNameW K32GetModuleFileNameExA K32GetModuleFileNameExW K32GetModuleInformation K32EmptyWorkingSet K32QueryWorkingSet K32QueryWorkingSetEx K32InitializeProcessForWsWatch K32GetWsChanges K32GetWsChangesEx K32GetMappedFileNameW K32GetMappedFileNameA K32EnumDeviceDrivers K32GetDeviceDriverBaseNameA K32GetDeviceDriverBaseNameW K32GetDeviceDriverFileNameA K32GetDeviceDriverFileNameW K32GetProcessMemoryInfo K32GetPerformanceInfo K32EnumPageFilesW K32EnumPageFilesA K32GetProcessImageFileNameA K32GetProcessImageFileNameW DisableThreadLibraryCalls QueryPerformanceCounter GetTickCount GetCurrentThreadId GetCurrentProcessId GetSystemTimeAsFileTime |
---|
Ordinal | 1 |
---|---|
Address | 0x15ee |
Ordinal | 2 |
---|---|
Address | 0x14cc |
Ordinal | 3 |
---|---|
Address | 0x167e |
Ordinal | 4 |
---|---|
Address | 0x166e |
Ordinal | 5 |
---|---|
Address | 0x1408 |
Ordinal | 6 |
---|---|
Address | 0x15de |
Ordinal | 7 |
---|---|
Address | 0x1544 |
Ordinal | 8 |
---|---|
Address | 0x14e4 |
Ordinal | 9 |
---|---|
Address | 0x1514 |
Ordinal | 10 |
---|---|
Address | 0x164e |
Ordinal | 11 |
---|---|
Address | 0x165e |
Ordinal | 12 |
---|---|
Address | 0x163e |
Ordinal | 13 |
---|---|
Address | 0x162e |
Ordinal | 14 |
---|---|
Address | 0x15a4 |
Ordinal | 15 |
---|---|
Address | 0x152c |
Ordinal | 16 |
---|---|
Address | 0x15bc |
Ordinal | 17 |
---|---|
Address | 0x13f0 |
Ordinal | 18 |
---|---|
Address | 0x1420 |
Ordinal | 19 |
---|---|
Address | 0x1574 |
Ordinal | 20 |
---|---|
Address | 0x168e |
Ordinal | 21 |
---|---|
Address | 0x169e |
Ordinal | 22 |
---|---|
Address | 0x155c |
Ordinal | 23 |
---|---|
Address | 0x160e |
Ordinal | 24 |
---|---|
Address | 0x161e |
Ordinal | 25 |
---|---|
Address | 0x15fe |
Ordinal | 26 |
---|---|
Address | 0x158c |
Ordinal | 27 |
---|---|
Address | 0x14fc |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.1.7600.16385 |
ProductVersion | 6.1.7600.16385 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Process Status Helper |
FileVersion (#2) | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | PSAPI |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | PSAPI |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.1.7600.16385 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2009-Jul-13 23:15:50 |
Version | 0.0 |
SizeofData | 34 |
AddressOfRawData | 0x1b68 |
PointerToRawData | 0xf68 |
Referenced File | psapi.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2009-Jul-13 23:15:50 |
Version | 565.6526 |
SizeofData | 4 |
AddressOfRawData | 0x1b64 |
PointerToRawData | 0xf64 |
XOR Key | 0x947984e7 |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 3 |
Total imports | 33 |
Exports (VS2008 SP1 build 30729) | 1 |
C objects (VS2008 SP1 build 30729) | 3 |
Linker (VS2008 SP1 build 30729) | 1 |
Resource objects (VS2008 SP1 build 30729) | 1 |