3bd46ce6820367bf536146aac24689d9a8aa6b526017e881b68ab30738da1894

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-25 03:33:04
Detected languages English - United States
Debug artifacts E:\repo_Branded\Wacom\Win\Utils\Build\repo_Branded\Wacom\Win\x64\Release\WTabletServicePro.pdb
CompanyName Wacom Co. Ltd.
FileVersion 6.4.14-1
LegalCopyright Copyright (c) 1998 - 2026 Wacom Co. Ltd.
ProductVersion 6.4.14-1
FileDescription Tablet Service
InternalName WTabletService
OriginalFilename WTabletService.exe
ProductName WTablet Service

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • MSInfo32.exe
Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
May have dropper capabilities:
  • CurrentControlSet\Services
Accesses the WMI:
  • ROOT\CIMV2
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • download.microsoft.com
  • https://download.microsoft.com
  • https://download.microsoft.com/download/B/4/1/B4119C11-0423-477B-80EE-7A474314B347/NDP452-KB2901954-Web.exe
  • microsoft.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegOpenKeyExW
  • RegQueryInfoKeyW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessAsUserW
  • ShellExecuteW
Uses Windows's Native API:
  • NtClose
  • NtCreateFile
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • DuplicateTokenEx
  • OpenProcessToken
Interacts with services:
  • ControlService
  • CreateServiceW
  • DeleteService
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceStatus
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
Changes object ACLs:
  • SetSecurityInfo
Info The PE is digitally signed. Signer: Wacom Co.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/70 (Scanned on 2026-08-26 17:14:35) All the AVs think this file is safe.

Hashes

MD5 10b45a72820dda46cec836d47318c17d 🔍
SHA1 932dd34c5e007d5f809d18d669ddf68a1f452194 🔍
SHA256 3bd46ce6820367bf536146aac24689d9a8aa6b526017e881b68ab30738da1894 🔍
SHA3 74de9a92f2946aff553dd29f4b2ed120c64bde9553192c699e7534813aa62715 🔍
SSDeep 49152:fUuaoJ3l09xctl1h3N3ipZDNVokW0QvjI0:l3E5QT 🔍
Imports Hash 9a5ffb84349f46b71016504a50d2c7a3 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 10
TimeDateStamp 2026-Aug-25 03:33:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x232e00
SizeOfInitializedData 0xa3400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001776 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x2dc000
SizeOfHeaders 0x400
Checksum 0x2dbed6
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 855ed6a0eacede671280e8af5c7191a5 🔍
SHA1 cb0cf99b074f6e93c1a8aa2e417fe7fc861ee4e1 🔍
SHA256 e1c9abdda0d9e8860987f0137f714dff096229d70bd14646d832b777b4e6e6b2 🔍
SHA3 b7c782acf9199af2d3a6d7d936a9e98801ef3e8ecebe41e57a03d9c16b2a270b 🔍
VirtualSize 0x232cf3
VirtualAddress 0x1000
SizeOfRawData 0x232e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.71515

.rdata

MD5 3028b1da4821b4d7d4d7956f48eb1171 🔍
SHA1 7aac8843bca4dda72be305ff23bf5177f29b1af8 🔍
SHA256 4097de6d30dbba506947cee89e9b537cc9c5d6d2317285109e78e2f3eebba5fa 🔍
SHA3 6611b1bccc78b15f4831307707f03f353697ed50eea0a11f7671220ee5390907 🔍
VirtualSize 0x7ed71
VirtualAddress 0x234000
SizeOfRawData 0x7ee00
PointerToRawData 0x233200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.20847

.data

MD5 20bd9708ebb5084c6200298375506cb7 🔍
SHA1 5d62aef89200e4149b2a49ffb029e1dbb7c348e7 🔍
SHA256 736193a00ef520220ae60ed3623bd1f942d6a3b800c171f8e840f86cbb6858e3 🔍
SHA3 aebb66ddbfea374ac3e567dd11829a3a08c32efe351e705f87ac40df89aa2a3d 🔍
VirtualSize 0x7090
VirtualAddress 0x2b3000
SizeOfRawData 0x4600
PointerToRawData 0x2b2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.18825

.pdata

MD5 b2c9679bc1fbbe8e62852929b1ade3ad 🔍
SHA1 4bf581244fe7006c40e25eb4c7ffdad041fa47f8 🔍
SHA256 15f36c4934ef7c7e6cd8652dbd857b882d694c2537bfb26ebd832ca2b89790b3 🔍
SHA3 9ebd2c8fc5d76b3d898df22019cb90dfa81b2a315de87c466390c4ea3bd3a958 🔍
VirtualSize 0x144b4
VirtualAddress 0x2bb000
SizeOfRawData 0x14600
PointerToRawData 0x2b6600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.8782

.idata

MD5 a8e0c7f6600aac4a58e5c20174ccc2b8 🔍
SHA1 3b8dc63df049e09b4606d679e690cb20828d933c 🔍
SHA256 6c88a837a12f82d93a9d0186bec661599d955e629258f92ec8de1343e338c21b 🔍
SHA3 fd1c06d42e354166d5e9fac9cd2680363d5adbdcd691a8d473cdf5a1f21161ac 🔍
VirtualSize 0x3e68
VirtualAddress 0x2d0000
SizeOfRawData 0x4000
PointerToRawData 0x2cac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.9229

.00cfg

MD5 330d619db55cfc304228e810eddb51df 🔍
SHA1 cf05090032d368495e35505cb203b84c98e720ba 🔍
SHA256 ebd693c8246d0894f788b67576d9122d4b465079d6b21da1b42a38e0f70564f7 🔍
SHA3 f76d5d8ea505e948af2eac45be3f19a1c6e28c8291f354d20a86a8f872237a7b 🔍
VirtualSize 0x175
VirtualAddress 0x2d4000
SizeOfRawData 0x200
PointerToRawData 0x2cec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.411681

.tls

MD5 c573bd7cea296a9c5d230ca6b5aee1a6 🔍
SHA1 04a0b9fde89c71864acaf5e74689fe4c269bd7a8 🔍
SHA256 13bde09a110c13b533dc985f3e2c475b6f6bcf514d1a23fce5b784a653548e91 🔍
SHA3 3679da6860e8ab20485113de9ac22dfe22ddc29d53f14ddc33a648aa98196361 🔍
VirtualSize 0x309
VirtualAddress 0x2d5000
SizeOfRawData 0x400
PointerToRawData 0x2cee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0111738

.fptable

MD5 0f343b0931126a20f133d67c2b018a3b 🔍
SHA1 60cacbf3d72e1e7834203da608037b1bf83b40e8 🔍
SHA256 5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef 🔍
SHA3 6841b2c10aa6e5f7a384143e4de58fbc9aa28a4b742e9ad4ed14ba148a723a43 🔍
VirtualSize 0x233
VirtualAddress 0x2d6000
SizeOfRawData 0x400
PointerToRawData 0x2cf200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 634bec274d7381442ba8187ce2eece24 🔍
SHA1 371d79ba023245a17df5167a4db94879723c090f 🔍
SHA256 1135342086859e2b0231a196056f55235e9be491a572866599c0c8792c0c02ec 🔍
SHA3 794158ce3ad54d7417c062b78ff20024f33925096be6ee436090588eb59e719c 🔍
VirtualSize 0xd06
VirtualAddress 0x2d7000
SizeOfRawData 0xe00
PointerToRawData 0x2cf600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.47067

.reloc

MD5 222caf29e99f19716227d4fe7e9899d2 🔍
SHA1 38c4d948a7486a20a486dcc61e544923893a3ca0 🔍
SHA256 6daeda8358865c162fcae3dca0552e03814982215e107d1e91ae00ebddee8f4a 🔍
SHA3 5af2b13ead6fd0a99af8fb401051ead2f52fe27b8c4d9d10643848e72081ba2d 🔍
VirtualSize 0x354a
VirtualAddress 0x2d8000
SizeOfRawData 0x3600
PointerToRawData 0x2d0400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.93208

Imports

libxml2.dll xmlCheckVersion
xmlXPathEvalExpression
xmlXPathFreeContext
xmlXPathNewContext
xmlXPathCastToString
xmlXPathCastNodeToString
xmlXPathCastToNumber
xmlXPathFreeObject
xmlSaveClose
xmlSaveDoc
xmlSaveToBuffer
xmlSaveToFilename
xmlReadMemory
xmlReadFile
xmlCleanupParser
xmlGetCharEncodingName
xmlEncodeSpecialChars
xmlResetError
xmlGetLastError
xmlNextElementSibling
xmlRemoveProp
xmlNodeGetContent
xmlNodeAddContent
xmlNodeSetContent
xmlHasProp
xmlGetProp
xmlSetProp
xmlFreeNode
xmlAddChild
xmlNodeSetName
xmlDocSetRootElement
xmlDocGetRootElement
xmlGetLineNo
xmlCopyNode
xmlNewCDataBlock
xmlNewComment
xmlNewDocComment
xmlNewChild
xmlNewNode
xmlNewDocNode
xmlFreeDoc
xmlNewDoc
xmlNewNs
xmlBufferLength
xmlBufferContent
xmlBufferFree
xmlBufferCreate
xmlValidateNMToken
xmlValidateName
xmlValidateQName
xmlValidateNCName
xmlStrcasecmp
xmlFree
SHLWAPI.dll PathIsRootW
PathFileExistsW
PathRemoveFileSpecW
PathStripPathW
PathIsUNCW
WTSAPI32.dll WTSQueryUserToken
WTSFreeMemory
WTSEnumerateSessionsW
USERENV.dll CreateEnvironmentBlock
DestroyEnvironmentBlock
MPR.dll WNetGetUniversalNameW
ntdll.dll RtlUnwindEx
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlCaptureContext
RtlVirtualUnwind
NtClose
NtCreateFile
RtlInitUnicodeString
RtlUnwind
KERNEL32.dll GetStringTypeW
FormatMessageA
HeapReAlloc
IsValidCodePage
GetACP
GetOEMCP
SetConsoleCtrlHandler
GetTimeZoneInformation
SetEndOfFile
FindFirstFileExW
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
InitializeCriticalSectionEx
GetLocaleInfoEx
EncodePointer
DecodePointer
LCMapStringEx
CompareStringEx
GetCPInfo
WakeAllConditionVariable
SleepConditionVariableSRW
WriteConsoleW
HeapSize
SetStdHandle
OutputDebugStringW
OutputDebugStringA
GetCurrentProcessId
GetCurrentThreadId
GetLocalTime
GetLastError
InitializeSRWLock
ReleaseSRWLockExclusive
ReleaseSRWLockShared
AcquireSRWLockExclusive
AcquireSRWLockShared
TryAcquireSRWLockExclusive
TryAcquireSRWLockShared
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
DeleteCriticalSection
FreeLibrary
GetModuleHandleW
GetProcAddress
LoadLibraryW
GetUserDefaultUILanguage
GetSystemDefaultLCID
GetUserDefaultLCID
FreeResource
LoadResource
LockResource
SizeofResource
FindResourceW
GlobalAlloc
InitializeSListHead
FindResourceExA
MultiByteToWideChar
WideCharToMultiByte
ExpandEnvironmentStringsW
FindClose
FindFirstFileW
FindNextFileW
CloseHandle
QueryPerformanceCounter
QueryPerformanceFrequency
WaitForSingleObject
Sleep
GetCurrentProcess
TerminateProcess
OpenProcess
GetCommandLineA
GetSystemInfo
GetCurrentDirectoryW
CreateDirectoryW
CreateFileW
DeleteFileW
GetFileAttributesW
GetFileSizeEx
GetShortPathNameW
RemoveDirectoryW
SetFileAttributesW
GetTempPathW
DuplicateHandle
RaiseException
SetLastError
SetEvent
ResetEvent
ReleaseSemaphore
ReleaseMutex
WaitForMultipleObjectsEx
CreateMutexW
OpenMutexW
CreateEventW
OpenEventW
OpenSemaphoreW
CreateSemaphoreExW
GetExitCodeProcess
CreateThread
GetCurrentThread
SetThreadPriority
TerminateThread
GetExitCodeThread
ProcessIdToSessionId
GetProcessId
GetSystemDirectoryW
GetWindowsDirectoryW
GetModuleFileNameW
LocalFree
FormatMessageW
lstrlenW
QueryFullProcessImageNameW
CopyFileW
MoveFileExW
ReadConsoleW
SystemTimeToFileTime
WTSGetActiveConsoleSessionId
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
K32EnumProcesses
K32EnumProcessModules
K32GetModuleFileNameExW
SetUnhandledExceptionFilter
GetStartupInfoW
GetSystemTimeAsFileTime
InterlockedPushEntrySList
InterlockedFlushSList
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
IsProcessorFeaturePresent
ExitProcess
GetModuleHandleExW
GetStdHandle
WriteFile
IsDebuggerPresent
UnhandledExceptionFilter
HeapFree
HeapAlloc
GetFileType
IsThreadAFiber
VirtualProtect
LoadLibraryExW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
EnumSystemLocalesW
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
SetFilePointerEx
FindResourceA
FileTimeToSystemTime
USER32.dll GetProcessWindowStation
GetThreadDesktop
CloseDesktop
DefWindowProcW
PeekMessageW
DispatchMessageW
TranslateMessage
PhysicalToLogicalPoint
RegisterWindowMessageW
GetWindowLongPtrW
GetGUIThreadInfo
MonitorFromWindow
SystemParametersInfoA
GetWindowThreadProcessId
GetClassNameW
EnumWindows
FindWindowW
PostMessageW
PostThreadMessageW
IsWindowVisible
IsIconic
MsgWaitForMultipleObjectsEx
IsWindowEnabled
GetForegroundWindow
GetUserObjectInformationW
SetForegroundWindow
GetWindowTextW
GetCursorPos
LogicalToPhysicalPoint
WindowFromPoint
GetDesktopWindow
ADVAPI32.dll DuplicateTokenEx
CreateProcessAsUserW
SetTokenInformation
RegCloseKey
RegCreateKeyExW
ChangeServiceConfig2W
CloseServiceHandle
ControlService
CreateServiceW
DeleteService
OpenSCManagerW
OpenServiceW
QueryServiceStatus
RegisterServiceCtrlHandlerExW
SetServiceStatus
StartServiceCtrlDispatcherW
StartServiceA
StartServiceW
AllocateAndInitializeSid
EqualSid
FreeSid
GetSecurityDescriptorSacl
GetTokenInformation
ImpersonateLoggedOnUser
InitializeSecurityDescriptor
RevertToSelf
SetSecurityDescriptorDacl
DeregisterEventSource
RegisterEventSourceW
ReportEventA
LookupAccountSidW
RegOpenCurrentUser
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyExW
OpenProcessToken
RegEnumValueW
RegOpenKeyExW
RegQueryInfoKeyW
RegQueryValueExW
RegSetValueExW
ConvertStringSecurityDescriptorToSecurityDescriptorW
SetEntriesInAclW
SetSecurityInfo
SHELL32.dll SHGetKnownFolderPath
ShellExecuteW
SHFileOperationW
ShellExecuteExW
SHGetPropertyStoreForWindow
SHGetFolderPathW
ole32.dll CoTaskMemFree
CoInitializeSecurity
CoSetProxyBlanket
CoCreateInstance
CoInitializeEx
CoUninitialize
OLEAUT32.dll VariantClear
SetErrorInfo
GetErrorInfo
SysFreeString
SysAllocString
CreateErrorInfo
VariantInit
VariantChangeType

Delayed Imports

1

Type RT_MESSAGETABLE
Language UNKNOWN
Codepage UNKNOWN
Size 0x74
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.26599
MD5 098ea628aeb58c89acf454271827001b 🔍
SHA1 86be0dedc3675c46ea175eac2666166d653650a6 🔍
SHA256 72c9cb601eea8ebecb57a57abd4cb805f6e74bc95fdb529e2fc62f4a105ecba6 🔍
SHA3 6eb43d4f246a6b9c23fd3314de7bcca78fd02463b37f84de14be1947b62efb8c 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41286
MD5 775bb7e874c23f6514f430e5cf23010d 🔍
SHA1 634328883af9c284e9a69c85aef53c6802bd4af2 🔍
SHA256 c779e197e6bf2409605e5df16ee2fe156ab414b67f5fedadf079ad7b51cae3aa 🔍
SHA3 82af0ac903964dbdb9cc6dba281df96e1365285b2c3c459c129e1891938db444 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x492
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.02997
MD5 a074006936a131775670f1de01d86ee1 🔍
SHA1 23fababa7407bbcefe8a2d0b5232413a2e12bda4 🔍
SHA256 94b01abc34bbaf6ce6adcd8f0922454583ae5717948e54a4873329adce40402c 🔍
SHA3 ad05c5f6c9f07a338b2e99e448d00fef08faaf9e8d30a7876dc8f4d3ea34363b 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6.4.14.1
ProductVersion 6.4.14.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Wacom Co. Ltd.
FileVersion (#2) 6.4.14-1
LegalCopyright Copyright (c) 1998 - 2026 Wacom Co. Ltd.
ProductVersion (#2) 6.4.14-1
FileDescription Tablet Service
InternalName WTabletService
OriginalFilename WTabletService.exe
ProductName WTablet Service
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-25 03:33:04
Version 0.0
SizeofData 119
AddressOfRawData 0x287d70
PointerToRawData 0x286f70
Referenced File E:\repo_Branded\Wacom\Win\Utils\Build\repo_Branded\Wacom\Win\x64\Release\WTabletServicePro.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-25 03:33:04
Version 0.0
SizeofData 20
AddressOfRawData 0x287de8
PointerToRawData 0x286fe8

TLS Callbacks

StartAddressOfRawData 0x1402d5000
EndAddressOfRawData 0x1402d5208
AddressOfIndex 0x1402b8774
AddressOfCallbacks 0x140234e48
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1402b3540

RICH Header

XOR Key 0xfd2a09ee
Unmarked objects 0
C++ objects (33145) 179
ASM objects (35721) 8
C objects (35721) 15
ASM objects (33145) 10
C objects (CVTCIL) (33145) 1
C objects (33145) 28
Imports (33145) 22
Imports (36248) 3
Total imports 330
C++ objects (35721) 92
C++ objects (36248) 28
Resource objects (36248) 1
151 1
Linker (36248) 1

Errors

Leave a comment

No comments yet.