342c5c70471a2064fe435da452ebc0fa

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2023-May-25 06:50:47
Detected languages English - United States
Debug artifacts F:\devops_yanfa\agent\workspace\p-a471706e12394fd1bdab9f540789e7cc\src\AniRemoverDevelop\bin\x64\pdb\CmdRemover.pdb

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info The PE is digitally signed. Signer: Wondershare Technology Group Co.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/72 (Scanned on 2023-11-17 10:41:04) All the AVs think this file is safe.

Hashes

MD5 342c5c70471a2064fe435da452ebc0fa
SHA1 0c84c01f5ada88b65713c9433129e08fb06c7c8d
SHA256 1ee3949e808313abf2c1a45a0640a115db83375dfe4009d55959483d2150dbb8
SHA3 769fb4d6970d7fcca4b5e40c013e6afbe76d62421320d9255d9c99a629b8773b
SSDeep 1536:ZZKKH8Ej0zDvZOcqVi3rsXwA6Et07TPxa7NoPxh:7DH8Ej0vZOcHAXwAn0fxa54xh
Imports Hash 6a72eb21397b54eb713ed8069399b475

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 2023-May-25 06:50:47
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x10000
SizeOfInitializedData 0xd600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000012A3 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x22000
SizeOfHeaders 0x400
Checksum 0x2b705
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c94bebd32af12fc6863416300f9d616a
SHA1 cd85c99dfb0dc9e132150c59d79d659f2e8fbca1
SHA256 eb7f65f717db947239fcf33f7f50b65c614c1e57853fe44df72da5aaf4365127
SHA3 1a27391f9860b7f6e4d47e4dd109fe2c53a9aa40c44d3bdb4074b5c8bca7ec8e
VirtualSize 0xfe91
VirtualAddress 0x1000
SizeOfRawData 0x10000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.08073

.rdata

MD5 d7e9dd9d48bdbb51b1474f6e5c8238e2
SHA1 14da2c1a6b797ed30be50b31edd9e35f132889eb
SHA256 4fd68c57e070cf67411762b3bb36ed1d1957bcbc15e14c98821a46fbec8c26cb
SHA3 7bb12288cc2be7ff08e5be5929f304b223f4cd2f53f2f0004b2a535ca7db819c
VirtualSize 0x7319
VirtualAddress 0x11000
SizeOfRawData 0x7400
PointerToRawData 0x10400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.01271

.data

MD5 6df5d82017ec462e0ce80549225a5996
SHA1 f53f0dc8e9a12865ac6a93177e23e0d70f973cce
SHA256 e6ebbca295ee559fd42918f0022094803a1fa695941d16dcc4e18b1de9398fe8
SHA3 67c6b387a6f6257fe1aa9ccf41dd01608c430906fd8b383d755f4c2134729929
VirtualSize 0xef1
VirtualAddress 0x19000
SizeOfRawData 0x800
PointerToRawData 0x17800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.66793

.pdata

MD5 15c6d9613e6fbbd896a7155b61968196
SHA1 703a93210f265f5a6e2bb0a4ccc59210c5ffa8c3
SHA256 2a52b85ede4940be55cdfd15b35d51d2b4599530bf95ee7e3efd959f7aa25f00
SHA3 10dde1d0f3786a2b6f493ea8c6dcccc8828d73d98c2a86234b716d15c3d6ebe4
VirtualSize 0x93c
VirtualAddress 0x1a000
SizeOfRawData 0xa00
PointerToRawData 0x18000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.79047

.idata

MD5 9a25f383f9fae4e78709bd1a25b4ddae
SHA1 82f938c2c000df1046b1cb2c268300f4f8d71d53
SHA256 35f840d673b66cf51808f85a7d7ba0ca15051c2abb24fb35d736a0e2342dd550
SHA3 a50290bc0b1b1185f166fb649249686b7e336896623a697210d329e895a7b1dc
VirtualSize 0x3a1a
VirtualAddress 0x1b000
SizeOfRawData 0x3c00
PointerToRawData 0x18a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.1079

.00cfg

MD5 e541cdb247354696155e26a6e2e5d2f4
SHA1 810eb2ef47f7ff13b417fce0f498d9099987015c
SHA256 6d7fecce6ffc6ced25467c438180398bd6d6748e65d80925fc1101a998a171d2
SHA3 b881227cd88edece92ace02ef5c8719805a52a032b7e9631657340c448aa6fb0
VirtualSize 0x151
VirtualAddress 0x1f000
SizeOfRawData 0x200
PointerToRawData 0x1c600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.330965

.rsrc

MD5 e75eda27d77762421a4aed099c2e9185
SHA1 0acda8c7ee97bc11d9f17bb9926fb3849c4d829b
SHA256 b2f0a3d2112d29216967042e233d87169db7aeee3c40cb923c56d4568a69786d
SHA3 4e0177ffaf6525977ab3d91fbe2a85261eaff397ea98977b907ca259baa82fe1
VirtualSize 0x570
VirtualAddress 0x20000
SizeOfRawData 0x600
PointerToRawData 0x1c800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.19048

.reloc

MD5 81e7e48777a60f4238bca05f576d6ef6
SHA1 b8aec6bbe57ad6d118082402265a7f8f55d47dcb
SHA256 653ed1926047e67180e8818c4148ec15070e118294da2aa5dd18fdd8ef5821a4
SHA3 c2340201e865ecc0a4ea380fc3ccf9682ea6343ee633094186f08734e7495606
VirtualSize 0x2f0
VirtualAddress 0x21000
SizeOfRawData 0x400
PointerToRawData 0x1ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.96176

Imports

WS_Log.DLL #51
#50
#2
SetGpuEncodeType
Commonlib.dll ?timerEvent@MediaEncodeTaskCls@@MEAAXPEAVQTimerEvent@@@Z
?qt_metacast@MediaEncodeTaskCls@@UEAAPEAXPEBD@Z
?qt_metacall@MediaEncodeTaskCls@@UEAAHW4Call@QMetaObject@@HPEAPEAX@Z
?SrcFileVideoFourccIsVP9@MediaInfoCls@@QEAA_NXZ
??0CompressControlMessage@@QEAA@PEAVBaseMessage@@@Z
??1CompressControlMessage@@UEAA@XZ
??0CompressStateMessage@@QEAA@PEAVBaseMessage@@@Z
??1CompressStateMessage@@UEAA@XZ
?UcWait@@YAX_J@Z
?GetAuidoChannelClsByChannel@AudioFourccCls@@QEAAPEAVAudioChannelCls@@H@Z
?GetInstance@FormatsManagerCls@@SAPEAV1@XZ
?GetAudioFourccByName@FormatsManagerCls@@QEAAPEAVAudioFourccCls@@VQString@@@Z
?onMessage@IPCChannel@@QEAAXAEBVQString@@@Z
??0UnixSocketChannel@@QEAA@AEBVQString@@_NPEAVQObject@@@Z
??1UnixSocketChannel@@UEAA@XZ
?FormatID@MediaEncodeTaskCls@@QEAAHXZ
?CompressPercent@MediaEncodeTaskCls@@QEAANXZ
?isAuthorized@MediaEncodeTaskCls@@QEAA_NXZ
?SrcVideoMediaLength@MediaEncodeTaskCls@@QEAANXZ
?StringFromFourCC@@YA?AVQString@@K@Z
?LoadFromJsonString@CompressControlMessage@@UEAA_NVQString@@@Z
?LoadFromJsonString@CompressStateMessage@@UEAA_NVQString@@@Z
?ParseJson@CompressControlMessage@@UEAAXVQJsonObject@@@Z
?ParseJson@CompressStateMessage@@UEAAXVQJsonObject@@@Z
?ToJsonObject@CompressControlMessage@@UEAA?AVQJsonObject@@XZ
?ToJsonObject@CompressStateMessage@@UEAA?AVQJsonObject@@XZ
?ToJsonString@CompressControlMessage@@UEAA?AVQString@@XZ
?ToJsonString@CompressStateMessage@@UEAA?AVQString@@XZ
?metaObject@CompressControlMessage@@UEBAPEBUQMetaObject@@XZ
?metaObject@CompressStateMessage@@UEBAPEBUQMetaObject@@XZ
?metaObject@IPCChannel@@UEBAPEBUQMetaObject@@XZ
?qt_metacall@CompressControlMessage@@UEAAHW4Call@QMetaObject@@HPEAPEAX@Z
?qt_metacall@CompressStateMessage@@UEAAHW4Call@QMetaObject@@HPEAPEAX@Z
?qt_metacall@IPCChannel@@UEAAHW4Call@QMetaObject@@HPEAPEAX@Z
?qt_metacast@CompressControlMessage@@UEAAPEAXPEBD@Z
?qt_metacast@CompressStateMessage@@UEAAPEAXPEBD@Z
?qt_metacast@IPCChannel@@UEAAPEAXPEBD@Z
?sendMsg@UnixSocketChannel@@UEAAXAEBVQString@@@Z
?staticMetaObject@IPCChannel@@2UQMetaObject@@B
??0MediaEncodeTaskCls@@QEAA@PEAVQObject@@@Z
??1MediaEncodeTaskCls@@UEAA@XZ
?parseJson@MediaEncodeTaskCls@@QEAAXVQJsonObject@@@Z
?LoadFromJsonFile@MediaEncodeTaskCls@@QEAA_NVQString@@@Z
??1LoggerService@@QEAA@XZ
?metaObject@MediaEncodeTaskCls@@UEBAPEBUQMetaObject@@XZ
COMSupport.dll #1
wsCUDA.dll #20
#23
#55
#21
#22
KERNEL32.dll GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
QueryPerformanceCounter
GetModuleHandleW
GetStartupInfoW
IsDebuggerPresent
IsProcessorFeaturePresent
TerminateProcess
GetCurrentProcess
CloseHandle
SetEvent
ResetEvent
WaitForSingleObject
CreateEventW
Sleep
RtlLookupFunctionEntry
SetUnhandledExceptionFilter
UnhandledExceptionFilter
RtlVirtualUnwind
RtlCaptureContext
ole32.dll CoUninitialize
CoInitialize
OLEAUT32.dll SysAllocString
Qt5Core.dll ??0QChar@@QEAA@UQLatin1Char@@@Z
??0QString@@QEAA@XZ
??0QString@@QEAA@AEBV0@@Z
??1QString@@QEAA@XZ
??4QString@@QEAAAEAV0@AEBV0@@Z
??4QString@@QEAAAEAV0@$$QEAV0@@Z
?arg@QString@@QEBA?AV1@AEBV1@HVQChar@@@Z
?indexOf@QString@@QEBAHAEBV1@HW4CaseSensitivity@Qt@@@Z
?trimmed@QString@@QEHAA?AV1@XZ
?append@QString@@QEAAAEAV1@AEBV1@@Z
?split@QString@@QEBA?AVQStringList@@VQChar@@V?$QFlags@W4SplitBehaviorFlags@Qt@@@@W4CaseSensitivity@Qt@@@Z
?toWCharArray@QString@@QEBAHPEA_W@Z
?toInt@QString@@QEBAHPEA_NH@Z
?number@QString@@SA?AV1@HH@Z
??8@YA_NAEBVQString@@0@Z
?toStdString@QString@@QEBA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
?toStdWString@QString@@QEBA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ
?fromAscii_helper@QString@@CAPEAU?$QTypedArrayData@G@@PEBDH@Z
?detach@QListData@@QEAAPEAUData@1@H@Z
?dispose@QListData@@QEAAXXZ
?dispose@QListData@@SAXPEAUData@1@@Z
?size@QListData@@QEBAHXZ
?at@QListData@@QEBAPEAPEAXH@Z
?begin@QListData@@QEBAPEAPEAXXZ
?end@QListData@@QEBAPEAPEAXXZ
?connectImpl@QObject@@CA?AVConnection@QMetaObject@@PEBV1@PEAPEAX01PEAVQSlotObjectBase@QtPrivate@@W4ConnectionType@Qt@@PEBHPEBU3@@Z
?start@QTime@@QEAAXXZ
?elapsed@QTime@@QEBAHXZ
??1QDebug@@QEAA@XZ
??6QDebug@@QEAAAEAV0@N@Z
??6QDebug@@QEAAAEAV0@PEBD@Z
??6QDebug@@QEAAAEAV0@AEBVQString@@@Z
??0QChar@@QEAA@H@Z
?createUuid@QUuid@@SA?AV1@XZ
?exists@QFile@@SA_NAEBVQString@@@Z
??0QFileInfo@@QEAA@AEBVQString@@@Z
??1QFileInfo@@QEAA@XZ
?exists@QFileInfo@@QEBA_NXZ
?toNativeSeparators@QDir@@SA?AVQString@@AEBV2@@Z
?instance@QCoreApplication@@SAPEAV1@XZ
?applicationDirPath@QCoreApplication@@SA?AVQString@@XZ
?quit@QCoreApplication@@SAXXZ
?childEvent@QObject@@MEAAXPEAVQChildEvent@@@Z
?connectNotify@QObject@@MEAAXAEBVQMetaMethod@@@Z
?customEvent@QObject@@MEAAXPEAVQEvent@@@Z
?disconnectNotify@QObject@@MEAAXAEBVQMetaMethod@@@Z
?event@QObject@@UEAA_NPEAVQEvent@@@Z
?eventFilter@QObject@@UEAA_NPEAV1@PEAVQEvent@@@Z
?timerEvent@QObject@@MEAAXPEAVQTimerEvent@@@Z
?info@QMessageLogger@@QEBA?AVQDebug@@XZ
??0QByteArray@@QEAA@PEBDH@Z
??1QByteArray@@QEAA@XZ
?data@QByteArray@@QEAAPEADXZ
?toUtf8@QString@@QEGBA?AVQByteArray@@XZ
??8QString@@QEBA_NPEBD@Z
??0QCoreApplication@@QEAA@AEAHPEAPEADH@Z
??1QCoreApplication@@UEAA@XZ
?arguments@QCoreApplication@@SA?AVQStringList@@XZ
?exec@QCoreApplication@@SAHXZ
??6QDebug@@QEAAAEAV0@AEBVQByteArray@@@Z
?errorString@QJsonParseError@@QEBA?AVQString@@XZ
??1QJsonDocument@@QEAA@XZ
?fromJson@QJsonDocument@@SA?AV1@AEBVQByteArray@@PEAUQJsonParseError@@@Z
?object@QJsonDocument@@QEBA?AVQJsonObject@@XZ
?codecForName@QTextCodec@@SAPEAV1@PEBD@Z
?setCodecForLocale@QTextCodec@@SAXPEAV1@@Z
?shared_null@QListData@@2UData@1@B
?debug@QMessageLogger@@QEBA?AVQDebug@@XZ
??0QMessageLogger@@QEAA@PEBDH0@Z
?toString@QUuid@@QEBA?AVQString@@XZ
??1Connection@QMetaObject@@QEAA@XZ
MSVCP140.dll ?_Xlength_error@std@@YAXPEBD@Z
VCRUNTIME140.dll _CxxThrowException
__std_exception_destroy
memcpy
memset
__std_exception_copy
memmove
__C_specific_handler
__current_exception
__current_exception_context
__std_type_info_destroy_list
__std_terminate
VCRUNTIME140_1.dll __CxxFrameHandler4
api-ms-win-crt-runtime-l1-1-0.dll _set_app_type
_get_initial_narrow_environment
_initterm
_seh_filter_dll
exit
_exit
_seh_filter_exe
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_cexit
_register_onexit_function
_initterm_e
terminate
_initialize_onexit_table
_crt_at_quick_exit
_execute_onexit_table
_beginthreadex
_crt_atexit
_initialize_narrow_environment
_invalid_parameter_noinfo_noreturn
_configure_narrow_argv
api-ms-win-crt-heap-l1-1-0.dll _callnewh
malloc
_set_new_mode
free
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-stdio-l1-1-0.dll _set_fmode
__p__commode
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06467
MD5 139fc2437354c15b9244734676966e39
SHA1 faa1dfedd581a6f2dc9da625fe20499faca64731
SHA256 97b1dfac60ade39e293fb39a093e1fd01fec5438549c9bb1e341c7fc82d102fb
SHA3 6330f9929dafb56cae559c0f98bb326a69d248932b418cfe5a481e93beb5b856

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2023-May-25 06:50:47
Version 0.0
SizeofData 140
AddressOfRawData 0x16998
PointerToRawData 0x15d98
Referenced File F:\devops_yanfa\agent\workspace\p-a471706e12394fd1bdab9f540789e7cc\src\AniRemoverDevelop\bin\x64\pdb\CmdRemover.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2023-May-25 06:50:47
Version 0.0
SizeofData 20
AddressOfRawData 0x16a24
PointerToRawData 0x15e24

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140019118

RICH Header

XOR Key 0xaa3d16a1
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 10
C++ objects (30034) 25
C objects (30034) 10
ASM objects (30034) 4
Imports (30034) 6
Imports (VS2019 Update 6 (16.6.1-5) compiler 28806) 2
C objects (27412) 1
Imports (27412) 6
Imports (VS2019 Update 11 (16.11.16-17) compiler 30146) 2
221 (VS2013 UPD5 build 40629) 7
Total imports 195
C++ objects (VS2019 Update 11 (16.11.16-17) compiler 30146) 4
Resource objects (VS2019 Update 11 (16.11.16-17) compiler 30146) 1
Linker (VS2019 Update 11 (16.11.16-17) compiler 30146) 1

Errors