Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2001-May-14 17:16:24 |
Detected languages |
English - United States
|
Debug artifacts |
WpcMon.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Family Safety Monitor |
FileVersion | 10.0.19041.906 (WinBuild.160101.0800) |
InternalName | WpcMon.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WpcMon.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.19041.906 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Suspicious | The PE is possibly packed. |
Unusual section name found: .imrsiv
Unusual section name found: .didat |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011 |
Safe | VirusTotal score: 0/67 (Scanned on 2021-04-30 23:06:52) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 8 |
TimeDateStamp | 2001-May-14 17:16:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0xa4800 |
SizeOfInitializedData | 0x7ac00 |
SizeOfUninitializedData | 0x200 |
AddressOfEntryPoint | 0x0000000000097CC0 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | A.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x125000 |
SizeOfHeaders | 0x400 |
Checksum | 0x12d4c1 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
EventActivityIdControl
QueryServiceStatusEx GetLengthSid OpenServiceW EventUnregister UnregisterTraceGuids RegisterTraceGuidsW StartServiceW GetTraceEnableLevel IsValidSid GetTraceEnableFlags GetTraceLoggerHandle EventSetInformation TraceMessage OpenSCManagerW EventRegister CloseServiceHandle EventWriteTransfer RegCreateKeyExW RegOpenKeyExW RegCloseKey RegGetValueW RegEnumKeyExW RegEnumValueW RegDeleteTreeW RegDeleteValueW RegSetValueExW RegQueryValueExW DuplicateTokenEx SetTokenInformation OpenProcessToken OpenThreadToken GetTokenInformation GetSidLengthRequired ConvertStringSecurityDescriptorToSecurityDescriptorW CopySid ConvertSidToStringSidW ConvertStringSidToSidW LookupAccountNameW CreateWellKnownSid CreateProcessAsUserW IsTextUnicode |
---|---|
KERNEL32.dll |
GetErrorMode
GetProcAddress CreateMutexExW LocalFree AcquireSRWLockShared DeleteCriticalSection GetCurrentProcessId GetProcessHeap GetModuleHandleW SleepEx DebugBreak HeapSetInformation RegisterApplicationRestart IsDebuggerPresent ResolveDelayLoadedAPI HeapAlloc GetTickCount GetFileSizeEx SetFilePointerEx ReadFile CreateFileW GetComputerNameW CreateMutexW IsWow64Process GetCurrentThread ReleaseSRWLockShared CreateEventExW InitOnceInitialize InitOnceExecuteOnce GetThreadPreferredUILanguages GetPackagesByPackageFamily GetPackagePath PackageIdFromFullName FindFirstChangeNotificationW FindCloseChangeNotification FindNextChangeNotification GetFileAttributesW CreateDirectoryW GetFileAttributesExW LocaleNameToLCID FileTimeToLocalFileTime LocalFileTimeToFileTime GetDynamicTimeZoneInformation GetDateFormatEx GetTimeFormatEx GetTimeFormatW GetDateFormatW CompareFileTime FileTimeToSystemTime GetLocaleInfoEx OpenEventW IsThreadpoolTimerSet WaitForThreadpoolWaitCallbacks CallbackMayRunLong SetThreadpoolWait CreateThreadpoolWait TrySubmitThreadpoolCallback CloseThreadpool SetThreadpoolThreadMaximum SetThreadpoolThreadMinimum CreateThreadpool InitializeConditionVariable SleepConditionVariableSRW WakeAllConditionVariable CloseThreadpoolWait WaitForMultipleObjectsEx ConvertFiberToThread QueueUserAPC OpenThread MultiByteToWideChar WideCharToMultiByte SetThreadpoolTimer CloseHandle OpenSemaphoreW WaitForSingleObjectEx AcquireSRWLockExclusive InitOnceComplete CloseThreadpoolTimer OutputDebugStringW ReleaseSRWLockExclusive UpdateProcThreadAttribute GetLastError FormatMessageW ReleaseMutex GetCurrentThreadId WaitForSingleObject WaitForThreadpoolTimerCallbacks InitializeCriticalSectionEx SetErrorMode LeaveCriticalSection SetProcessShutdownParameters InitializeProcThreadAttributeList GetModuleHandleExW ReleaseSemaphore EnterCriticalSection SetLastError HeapFree CreateSemaphoreExW SetHandleInformation InitOnceBeginInitialize GetModuleFileNameA CreateThreadpoolTimer DelayLoadFailureHook |
msvcp_win.dll |
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?id@?$ctype@G@std@@2V0locale@2@A ??Bid@locale@std@@QEAA_KXZ ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z ?_Xbad_alloc@std@@YAXXZ ?id@?$collate@G@std@@2V0locale@2@A ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z ?tolower@?$ctype@G@std@@QEBAGG@Z ?tolower@?$ctype@G@std@@QEBAPEBGPEAGPEBG@Z ?flush@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@XZ ?setstate@?$basic_ios@GU?$char_traits@G@std@@@std@@QEAAXH_N@Z ?_Osfx@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAXXZ ?uncaught_exception@std@@YA_NXZ ?sputc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGG@Z ?widen@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAGD@Z ?sputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAA_JPEBG_J@Z ?put@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@G@Z ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ ??1?$basic_ostream@GU?$char_traits@G@std@@@std@@UEAA@XZ ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z ?in@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAG3AEAPEAG@Z ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ ?out@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBG1AEAPEBGPEAD3AEAPEAD@Z ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ ?always_noconv@codecvt_base@std@@QEBA_NXZ ?unshift@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ?_Fiopen@std@@YAPEAU_iobuf@@PEBGHH@Z ?id@?$codecvt@GDU_Mbstatet@@@std@@2V0locale@2@A ?_Getcat@?$codecvt@GDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ ?swap@?$basic_ostream@GU?$char_traits@G@std@@@std@@IEAAXAEAV12@@Z ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEBA?AVlocale@2@XZ ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ ??0_Lockit@std@@QEAA@H@Z ?_Init@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXXZ ??0?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@_N@Z ?_Gndec@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@K@Z ??0_Locinfo@std@@QEAA@PEBD@Z ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ ?_ReportUnobservedException@details@Concurrency@@YAXXZ ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z ??1_Lockit@std@@QEAA@XZ ??1_Locinfo@std@@QEAA@XZ ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ ?is@?$ctype@G@std@@QEBA_NFG@Z ?_Getcat@?$ctype@G@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?_Incref@facet@locale@std@@UEAAXXZ _Wcscoll _Wcsxfrm ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ _Cnd_destroy_in_situ _Cnd_broadcast _Mtx_unlock _Cnd_wait _Mtx_init_in_situ ?__ExceptionPtrRethrow@@YAXPEBX@Z ?__ExceptionPtrCurrentException@@YAXPEAX@Z _Mtx_lock ?__ExceptionPtrDestroy@@YAXPEAX@Z _Mtx_destroy_in_situ ?__ExceptionPtrToBool@@YA_NPEBX@Z ?_XGetLastError@std@@YAXXZ ?_Xlength_error@std@@YAXPEBD@Z ?_Throw_C_error@std@@YAXH@Z ??1facet@locale@std@@MEAA@XZ ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ ?_Xbad_function_call@std@@YAXXZ ?_Execute_once@std@@YAHAEAUonce_flag@1@P6AHPEAX1PEAPEAX@Z1@Z ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z _Cnd_init_in_situ ?__ExceptionPtrCreate@@YAXPEAX@Z ??0task_continuation_context@Concurrency@@AEAA@XZ ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z ??0facet@locale@std@@IEAA@_K@Z ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ ?_Xout_of_range@std@@YAXPEBD@Z ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z ?_Assign@_ContextCallback@details@Concurrency@@AEAAXPEAX@Z ?_IsCurrentOriginSTA@_ContextCallback@details@Concurrency@@CA_NXZ |
api-ms-win-crt-runtime-l1-1-0.dll |
_register_thread_local_exe_atexit_callback
_c_exit _initterm _initterm_e |
api-ms-win-crt-private-l1-1-0.dll |
_o__get_wide_winmain_command_line
_o__i64tow_s _o__initialize_onexit_table _o__initialize_wide_environment _o__invalid_parameter_noinfo _o__invalid_parameter_noinfo_noreturn _o__itoa_s _o__lock_file _o__purecall _o__register_onexit_function _o__seh_filter_exe _o__set_app_type _o__set_fmode _o__set_new_mode _o__ui64tow_s _o__unlock_file _o__wcsicmp _o__wcstoi64 _o__wcstoui64 _o_exit _o_fclose _o_fflush _o_fgetc _o_fgetpos _o_fgetwc _o_fputwc _o_free _o_fsetpos _o_fwrite _o_isspace _o_iswascii _o_iswdigit _o_iswlower _o_iswspace _o_iswxdigit _o_malloc _o_realloc _o_setvbuf _o_terminate _o_towlower _o_ungetc _o_ungetwc _o_wcscpy_s _o_wcsncpy_s _o_wcstol __C_specific_handler __CxxFrameHandler3 _CxxThrowException _o__fseeki64 _o__exit _o__errno wcschr strchr __std_type_info_compare _o___stdio_common_vswprintf _o___stdio_common_vsprintf_s _o___stdio_common_vsnwprintf_s _o___stdio_common_vsnprintf_s _o___std_type_info_name _o___std_exception_destroy _o___std_exception_copy _o___p__commode __std_terminate __CxxFrameHandler4 _o__crt_atexit _o__configure_wide_argv _o__configthreadlocale _o__cexit _o__callnewh memcmp memcpy memmove |
api-ms-win-crt-string-l1-1-0.dll |
strncmp
memset |
SHLWAPI.dll |
PathRemoveFileSpecW
SHCreateStreamOnFileEx SHStrDupW PathCombineW UrlEscapeW |
api-ms-win-core-com-l1-1-0.dll |
CoWaitForMultipleHandles
CLSIDFromString CoInitializeEx CoUninitialize CoCreateInstance CoTaskMemFree CoCreateFreeThreadedMarshaler CoTaskMemAlloc PropVariantClear |
api-ms-win-core-synch-l1-1-0.dll |
InitializeSRWLock
SetEvent InitializeCriticalSection CreateEventW InitializeCriticalSectionAndSpinCount ResetEvent |
api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlCaptureContext
RtlLookupFunctionEntry RtlVirtualUnwind |
api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter RaiseException |
api-ms-win-core-processthreads-l1-1-0.dll |
CreateThread
TlsSetValue TlsFree TlsGetValue GetCurrentProcess TerminateProcess TlsAlloc GetStartupInfoW |
api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
|
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
api-ms-win-core-sysinfo-l1-1-0.dll |
GetSystemTime
GetSystemTimeAsFileTime |
api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
|
api-ms-win-core-winrt-error-l1-1-0.dll |
RoOriginateError
GetRestrictedErrorInfo SetRestrictedErrorInfo |
api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsCreateString
WindowsDeleteString WindowsCreateStringReference WindowsGetStringRawBuffer |
api-ms-win-core-winrt-l1-1-0.dll |
RoUninitialize
RoActivateInstance RoGetActivationFactory RoInitialize |
api-ms-win-core-synch-l1-2-0.dll |
Sleep
|
api-ms-win-core-timezone-l1-1-0.dll |
SystemTimeToFileTime
|
api-ms-win-core-winrt-error-l1-1-1.dll |
RoOriginateLanguageException
RoGetMatchingRestrictedErrorInfo |
api-ms-win-core-libraryloader-l1-2-0.dll |
FreeLibrary
LoadLibraryExW |
api-ms-win-core-processenvironment-l1-1-0.dll |
ExpandEnvironmentStringsW
|
ntdll.dll |
EtwTraceMessage
RtlSubscribeWnfStateChangeNotification RtlUnsubscribeWnfNotificationWaitForCompletion NtQueryWnfStateData |
api-ms-win-shcore-scaling-l1-1-2.dll |
GetDpiForShellUIComponent
|
SHELL32.dll |
ShellExecuteExW
ShellExecuteW CommandLineToArgvW SHGetFolderPathW SHGetKnownFolderPath Shell_NotifyIconW |
RPCRT4.dll |
UuidCreate
|
api-ms-win-core-localization-l1-2-0.dll |
IdnToAscii
|
USERENV.dll |
CreateEnvironmentBlock
DestroyEnvironmentBlock |
api-ms-win-security-lsalookup-l2-1-0.dll |
LookupAccountSidW
|
samcli.dll |
NetUserGetInfo
|
IMM32.dll |
ImmDisableLegacyIME
|
api-ms-win-crt-math-l1-1-0.dll |
ceilf
|
OLEAUT32.dll (delay-loaded) |
VariantInit
SysFreeString SysAllocString VariantClear SysStringLen |
Attributes | 0x1 |
---|---|
Name | OLEAUT32.dll |
ModuleHandle | 0x106700 |
DelayImportAddressTable | 0x1112f8 |
DelayImportNameTable | 0xe1b90 |
BoundDelayImportTable | 0xe3708 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 10.0.19041.906 |
ProductVersion | 10.0.19041.906 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Family Safety Monitor |
FileVersion (#2) | 10.0.19041.906 (WinBuild.160101.0800) |
InternalName | WpcMon.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WpcMon.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 10.0.19041.906 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2001-May-14 17:16:24 |
Version | 0.0 |
SizeofData | 35 |
AddressOfRawData | 0xcef00 |
PointerToRawData | 0xccb00 |
Referenced File | WpcMon.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2001-May-14 17:16:24 |
Version | 0.0 |
SizeofData | 1236 |
AddressOfRawData | 0xcef24 |
PointerToRawData | 0xccb24 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2001-May-14 17:16:24 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0xcf3f8 |
PointerToRawData | 0xccff8 |
StartAddressOfRawData | 0x1400cf440 |
---|---|
EndAddressOfRawData | 0x1400cf448 |
AddressOfIndex | 0x1401066f4 |
AddressOfCallbacks | 0x1400ae878 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x118 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140105a28 |
GuardCFCheckFunctionPointer | 5369422880 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0xcaf3423e |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 66 |
C objects (27412) | 13 |
ASM objects (27412) | 3 |
Imports (27412) | 21 |
Total imports | 1684 |
264 (27412) | 106 |
C++ objects (27412) | 37 |
253 (27412) | 1 |
Resource objects (27412) | 1 |
Linker (27412) | 1 |