Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Jun-05 08:23:04 |
Detected languages |
Chinese - Taiwan
English - United States |
Debug artifacts |
D:\OSCE-Common-MAIN_1.0\src\Setup\NTClientUninstaller\NTRmv\x64\Release\NTRmv.pdb
|
CompanyName | Trend Micro Inc. |
CoverageBuild | NO |
CompileOption | Release |
BuildType | Rel |
FileDescription | Trend Micro Common Client Uninstallation Service |
FileVersion | 14.0.0.3048 |
InternalName | Common Client NT uninstaller |
LegalCopyright | Copyright (C) 2019 Trend Micro Incorporated. All rights reserved. |
LegalTrademarks | Copyright (C) Trend Micro Inc. |
OriginalFilename | webntrmv.EXE |
PrivateBuild | Build 3048 - 6/5/2019 |
ProductName | Trend Micro OfficeScan (common client) |
ProductVersion | 14.0 |
SpecialBuild | 3048 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA256 Uses constants related to SHA512 Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Trend Micro
Issuer: VeriSign Class 3 Code Signing 2010 CA |
Safe | VirusTotal score: 0/68 (Scanned on 2019-08-13 22:05:19) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x168 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2019-Jun-05 08:23:04 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x357400 |
SizeOfInitializedData | 0x232600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00000000002C0C94 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x59b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x5b231a |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x200000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
PccWFWMo_64x.dll |
?WFW_Uninitialize@@YAHXZ
?WFW_RemovePort@@YAHJHPEB_W@Z ?WFW_Initialize@@YAHXZ |
---|---|
VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoA GetFileVersionInfoW GetFileVersionInfoSizeA |
ADVAPI32.dll |
RegEnumKeyExW
ImpersonateLoggedOnUser RegCloseKey RegCreateKeyExA RegOpenKeyExA RegQueryValueExA RegSetValueExA OpenProcessToken AllocateAndInitializeSid EqualSid FreeSid GetTokenInformation RegDeleteValueA RegDeleteKeyValueA CloseServiceHandle OpenSCManagerA RegDeleteKeyA RegDeleteKeyExA RegEnumKeyExA RegOpenKeyExW RegQueryValueExW OpenServiceA DeleteService QueryServiceStatus InitializeSecurityDescriptor SetSecurityDescriptorDacl OpenSCManagerW OpenServiceW StartServiceW ControlService RegDeleteValueW RegSetValueExW RegCreateKeyExW CryptAcquireContextA CryptReleaseContext CryptDestroyKey CryptSetKeyParam CryptGetHashParam RevertToSelf RegDeleteKeyW DuplicateTokenEx CryptImportKey CryptEncrypt CryptDecrypt CryptCreateHash CryptHashData CryptDestroyHash ChangeServiceConfigW ChangeServiceConfig2W RegEnumValueA RegQueryValueA RegEnumKeyA ConvertStringSidToSidW SetFileSecurityW InitializeAcl GetAce AddAccessAllowedAce RegEnumValueW RegDeleteKeyExW RegOpenCurrentUser |
CRYPT32.dll |
CryptMsgGetParam
CryptMsgControl CertFreeCertificateContext CryptQueryObject CertGetCertificateChain CertFreeCertificateChain CertVerifyCertificateChainPolicy CertGetNameStringW CertDeleteCertificateFromStore CertFindCertificateInStore CertCloseStore CertOpenStore CryptMsgClose CryptUnprotectData |
WININET.dll |
InternetReadFile
InternetOpenA InternetQueryOptionA InternetSetOptionA HttpOpenRequestA InternetCloseHandle HttpAddRequestHeadersA HttpSendRequestA InternetConnectA HttpQueryInfoA |
PSAPI.DLL |
GetModuleFileNameExW
|
SHLWAPI.dll |
PathRemoveFileSpecA
PathUnquoteSpacesA PathFindExtensionW PathCanonicalizeA PathCanonicalizeW PathFileExistsA PathFileExistsW PathIsDirectoryEmptyA PathRemoveBackslashA PathRemoveFileSpecW PathStripToRootA PathAddBackslashW SHDeleteKeyW StrFormatKBSizeA PathIsUNCA PathFindFileNameA PathFindExtensionA PathUnquoteSpacesW PathAddBackslashA PathFindFileNameW PathAppendA PathAppendW |
OfcPIPC_64x.dll |
OIPC_SendData
OIPC_Init OIPC_DeInit OIPC_FreeCommand OIPC_CmdDataCopy OIPC_CreateCommand |
KERNEL32.dll |
GetPrivateProfileSectionA
SystemTimeToTzSpecificLocalTime FileTimeToSystemTime SystemTimeToFileTime GetTimeZoneInformation GetEnvironmentVariableW GlobalUnlock GlobalHandle GlobalLock GetVersion GetPrivateProfileIntA GetUserDefaultLangID GetSystemDefaultLangID ReleaseMutex CreateMutexW GetStdHandle CreateNamedPipeW WaitForMultipleObjectsEx GetLocalTime GetComputerNameW ResetEvent MoveFileW MoveFileExW GetSystemTimeAsFileTime GetFileInformationByHandle GetCurrentThread SetThreadPriority GetACP GetDateFormatW GetTimeFormatW FormatMessageW GlobalSize MulDiv OutputDebugStringA FreeResource GetModuleHandleExW FindResourceA ActivateActCtx DeactivateActCtx FindActCtxSectionStringW QueryActCtxW GlobalDeleteAtom CompareStringA GlobalAddAtomA InitializeCriticalSectionAndSpinCount EncodePointer lstrcmpW GlobalFindAtomA GlobalGetAtomNameA TlsAlloc TlsGetValue TlsSetValue TlsFree GlobalReAlloc LocalReAlloc GlobalFlags GetLocaleInfoW GetSystemDefaultUILanguage GetUserDefaultUILanguage FlushFileBuffers GetFullPathNameA LockFile SetEndOfFile UnlockFile VirtualProtect GetOEMCP GetCPInfo SetErrorMode GetFileAttributesExA VerSetConditionMask VerifyVersionInfoA FindResourceExW GetProfileIntA SearchPathA GetUserDefaultLCID RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter IsProcessorFeaturePresent WaitForSingleObjectEx IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetVolumeInformationA WriteConsoleW SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW IsValidCodePage FindFirstFileExA EnumSystemLocalesW IsValidLocale GetConsoleCP ExitProcess SetStdHandle HeapQueryInformation VirtualQuery VirtualAlloc GetSystemInfo FreeLibraryAndExitThread ExitThread ReadConsoleW GetConsoleMode PeekNamedPipe GetFileType GetCommandLineW RtlPcToFileHeader RtlUnwindEx GetStringTypeExW LCMapStringW CompareStringW SwitchToThread QueryPerformanceFrequency AreFileApisANSI GetFileAttributesExW AcquireSRWLockShared AcquireSRWLockExclusive ReleaseSRWLockShared ReleaseSRWLockExclusive GetStringTypeW CreateFileMappingA GetThreadTimes Process32NextW Process32FirstW LoadLibraryExW GetCurrentThreadId GetPrivateProfileSectionW GetPrivateProfileIntW lstrlenW CreateFileMappingW DuplicateHandle CreateDirectoryW GetDriveTypeW LocalAlloc CreateProcessW GetExitCodeProcess SetFilePointer GetFileSize FindNextFileW FindFirstFileW GetFullPathNameW RemoveDirectoryW ExpandEnvironmentStringsW GetTickCount CopyFileW GetFileAttributesW GetOverlappedResult SleepEx CreateMailslotW OutputDebugStringW GetModuleHandleW GetFileTime FileTimeToLocalFileTime InitializeSListHead SetFilePointerEx GetFileSizeEx DeleteFileW ReadFile GetLogicalDriveStringsW QueryDosDeviceW CreateFileW DeviceIoControl GetVersionExW SetLastError GetSystemDirectoryW InitializeCriticalSectionEx GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc RaiseException DecodePointer MoveFileA QueryDosDeviceA GetPrivateProfileStringW GetPrivateProfileStringA OpenFileMappingA lstrlenA lstrcpyA lstrcpynA lstrcmpiA lstrcmpA LoadLibraryW GetModuleHandleA GetModuleFileNameW UnmapViewOfFile MapViewOfFile GetWindowsDirectoryW ResumeThread SuspendThread TerminateThread CreateThread TerminateProcess WaitForMultipleObjects CreateEventW GetTempFileNameA GetTempPathW SetFileAttributesA RemoveDirectoryA GetTempFileNameW GetCurrentDirectoryW GetCurrentDirectoryA SetCurrentDirectoryW Process32Next Process32First CreateToolhelp32Snapshot WideCharToMultiByte MultiByteToWideChar MoveFileExA CopyFileA WritePrivateProfileStringA GetStartupInfoA OpenMutexA WinExec GlobalFree GlobalAlloc LoadLibraryA FindResourceW SizeofResource LockResource LoadResource GetProcAddress GetModuleFileNameA FreeLibrary GetVersionExA OpenProcess CreateProcessA GetCurrentProcessId GetCurrentProcess OpenEventA CreateMutexA DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection GetDiskFreeSpaceExA FindNextFileA FindFirstFileA FindClose DeleteFileA SetCurrentDirectoryA ExpandEnvironmentStringsA GetCommandLineA CreateEventA WaitForSingleObject SetEvent GetLogicalDriveStringsA FormatMessageA LocalFree GetWindowsDirectoryA Sleep GetLastError CloseHandle GetTempPathA WriteFile GetFileAttributesA GetDriveTypeA CreateFileA CreateDirectoryA SetNamedPipeHandleState WaitNamedPipeW VerifyVersionInfoW GetVolumeNameForVolumeMountPointW RtlUnwind CreateActCtxW |
SETUPAPI.dll |
InstallHinfSectionW
|
USER32.dll |
IsZoomed
DrawFrameControl DrawEdge DrawStateA EmptyClipboard SetClipboardData CloseClipboard OpenClipboard SetParent SetWindowRgn SetClassLongPtrA EnumDisplayMonitors SetLayeredWindowAttributes NotifyWinEvent LoadCursorW InvertRect HideCaret EnableScrollBar GetIconInfo DrawIconEx LoadImageA IsRectEmpty DrawFocusRect WindowFromPoint ReleaseCapture SetCapture GetNextDlgGroupItem GetMenuDefaultItem CreatePopupMenu MapDialogRect GetAsyncKeyState GetMenuItemInfoA DestroyMenu LoadImageW TrackMouseEvent IntersectRect InflateRect CharUpperA DestroyIcon InvalidateRect DeleteMenu SystemParametersInfoA CopyImage RealChildWindowFromPoint LoadCursorA GetSysColorBrush GetSystemMetrics MapVirtualKeyA GetKeyNameTextA IsDialogMessageA SetWindowTextA UnionRect UpdateLayeredWindow MonitorFromPoint LoadAcceleratorsA TranslateAcceleratorA LoadMenuA InsertMenuItemA UnpackDDElParam ReuseDDElParam GetComboBoxInfo PostThreadMessageA WaitMessage GetKeyboardLayout IsCharLowerA MapVirtualKeyExA GetKeyboardState ToAsciiEx LoadAcceleratorsW CreateAcceleratorTableA DestroyAcceleratorTable CopyAcceleratorTableA SetRect GetSystemMenu SetMenuDefaultItem GetDoubleClickTime ModifyMenuA RegisterClipboardFormatA CharUpperBuffA IsClipboardFormatAvailable GetUpdateRect DrawMenuBar DefFrameProcA TranslateMDISysAccel SetCursorPos SubtractRect PostMessageA FindWindowA LoadStringW wsprintfA MessageBoxA LoadStringA OpenInputDesktop OpenWindowStationA CloseWindowStation SetProcessWindowStation SendMessageA BringWindowToTop SetTimer KillTimer EnableWindow GetClientRect GetWindowRect MessageBeep EnumWindows GetClassNameA GetWindowThreadProcessId LoadBitmapA LoadIconW DdeInitializeA DdeUninitialize DdeConnect DdeDisconnect DdeClientTransaction DdeCreateDataHandle DdeCreateStringHandleA DdeFreeStringHandle UnregisterClassA wsprintfW GetDC ReleaseDC GetMessageA TranslateMessage DispatchMessageA PeekMessageA IsWindowVisible GetActiveWindow GetKeyState ValidateRect GetCursorPos SetWindowsHookExA CallNextHookEx GetMenuStringA GetMenuState GetSubMenu GetMenuItemID GetMenuItemCount InsertMenuA AppendMenuA RemoveMenu UnhookWindowsHookEx GetFocus CheckMenuItem EnableMenuItem SetMenuItemBitmaps GetMenuCheckMarkDimensions SetMenuItemInfoA GetParent LoadBitmapW LoadMenuW CopyIcon FrameRect LockWindowUpdate DrawIcon IsWindow DestroyWindow CreateMenu GetWindowRgn DestroyCursor CheckDlgButton MoveWindow ShowWindow GetMonitorInfoA MonitorFromWindow WinHelpA GetScrollInfo SetScrollInfo LoadIconA GetWindow GetTopWindow GetClassLongPtrA GetClassLongA SetWindowLongPtrA GetWindowLongPtrA SetWindowLongA PtInRect EqualRect CopyRect MapWindowPoints AdjustWindowRectEx GetWindowTextLengthA GetWindowTextA RemovePropA GetPropA SetPropA ShowScrollBar GetScrollRange SetScrollRange GetScrollPos SetScrollPos ScrollWindow RedrawWindow SetForegroundWindow GetForegroundWindow UpdateWindow DefMDIChildProcA CreateDialogIndirectParamA EndDialog GetDlgItem GetNextDlgTabItem IsWindowEnabled SetActiveWindow GetWindowLongA GetDesktopWindow PostQuitMessage ShowOwnedPopups BeginDeferWindowPos SetCursor GetLastActivePopup DrawTextA DrawTextExA GrayStringA TabbedTextOutA GetWindowDC BeginPaint EndPaint ClientToScreen ScreenToClient TrackPopupMenu SetMenu GetMenu GetCapture SetFocus GetDlgCtrlID IsIconic EndDeferWindowPos GetSysColor FillRect SendDlgItemMessageA SetRectEmpty OffsetRect RegisterWindowMessageA GetMessagePos GetMessageTime DefWindowProcA CallWindowProcA RegisterClassA GetClassInfoA GetClassInfoExA CreateWindowExA IsMenu IsChild SetWindowPos GetWindowPlacement SetWindowPlacement DeferWindowPos |
GDI32.dll |
Polygon
Polyline CreateRoundRectRgn LPtoDP EnumFontFamiliesExA Rectangle GetRgnBox OffsetRgn RoundRect FillRgn FrameRgn GetBoundsRect PtInRegion CreateEllipticRgn SetPaletteEntries SetPixelV GetWindowOrgEx GetViewportOrgEx GetTextFaceA MoveToEx SetTextAlign SetTextColor SetROP2 SetPolyFillMode GetLayout SetLayout SetMapMode CreatePolygonRgn SetBkMode SetBkColor BitBlt CreateCompatibleDC CreateSolidBrush DeleteObject PatBlt SelectObject GetObjectA GetDeviceCaps CopyMetaFileA CreateDCA CreateBitmap CreateHatchBrush CreatePen CreatePatternBrush CreateRectRgn DeleteDC Escape ExcludeClipRect GetClipBox GetObjectType SetDIBColorTable CreateDIBSection StretchBlt SetPixel GetTextCharsetInfo EnumFontFamiliesA CreateDIBitmap CreateCompatibleBitmap GetBkColor RealizePalette GetSystemPaletteEntries GetPaletteEntries GetNearestPaletteIndex CreatePalette DPtoLP SetRectRgn GetWindowExtEx IntersectClipRect LineTo PtVisible RectVisible CombineRgn GetTextMetricsA GetTextExtentPoint32A CreateFontIndirectA CreateRectRgnIndirect ScaleWindowExtEx GetViewportExtEx ScaleViewportExtEx OffsetWindowOrgEx OffsetViewportOrgEx SetWindowOrgEx GetTextColor SetWindowExtEx SetViewportOrgEx RestoreDC SaveDC Ellipse SetViewportExtEx ExtTextOutA SelectClipRgn ExtSelectClipRgn ExtFloodFill SelectPalette GetPixel GetStockObject TextOutA |
MSIMG32.dll |
TransparentBlt
AlphaBlend |
WINSPOOL.DRV |
ClosePrinter
DocumentPropertiesA OpenPrinterA |
SHELL32.dll |
SHGetFolderPathW
SHGetFileInfoA SHGetFolderPathA SHCreateDirectoryExW SHGetPathFromIDListA SHGetSpecialFolderLocation SHGetDesktopFolder ShellExecuteA SHBrowseForFolderA DragQueryFileA DragFinish SHAppBarMessage ShellExecuteExW |
UxTheme.dll |
IsAppThemed
DrawThemeText DrawThemeParentBackground OpenThemeData CloseThemeData DrawThemeBackground GetThemePartSize GetThemeColor GetCurrentThemeName GetWindowTheme IsThemeBackgroundPartiallyTransparent GetThemeSysColor |
ole32.dll |
ReleaseStgMedium
CoTaskMemFree CoTaskMemAlloc StringFromGUID2 CoInitializeEx CLSIDFromProgID CoCreateInstance CoCreateGuid CoUninitialize OleCreateMenuDescriptor OleDestroyMenuDescriptor OleTranslateAccelerator IsAccelerator CoDisconnectObject CreateStreamOnHGlobal DoDragDrop OleGetClipboard CoLockObjectExternal RegisterDragDrop RevokeDragDrop CoInitialize OleLockRunning OleDuplicateData |
OLEAUT32.dll |
#9
#150 #4 #12 #161 #7 #184 #185 #8 #10 #114 #6 #2 |
gdiplus.dll |
GdipAlloc
GdipFree GdiplusStartup GdipCloneImage GdipDisposeImage GdipGetImageGraphicsContext GdipGetImageHeight GdipGetImagePixelFormat GdipGetImagePalette GdipGetImagePaletteSize GdiplusShutdown GdipCreateBitmapFromScan0 GdipBitmapLockBits GdipBitmapUnlockBits GdipDeleteGraphics GdipDrawImageI GdipCreateBitmapFromHBITMAP GdipCreateFromHDC GdipSetInterpolationMode GdipDrawImageRectI GdipCreateBitmapFromStream GdipGetImageWidth |
OLEACC.dll |
AccessibleObjectFromWindow
LresultFromObject CreateStdAccessibleObject |
IMM32.dll |
ImmReleaseContext
ImmGetOpenStatus ImmGetContext |
WINMM.dll |
PlaySoundA
|
WINTRUST.dll |
CryptCATAdminCalcHashFromFileHandle
CryptCATCatalogInfoFromContext WinVerifyTrust WTHelperGetProvSignerFromChain WTHelperGetProvCertFromChain CryptCATAdminEnumCatalogFromHash CryptCATAdminReleaseCatalogContext CryptCATAdminReleaseContext CryptCATAdminAcquireContext WTHelperProvDataFromStateData |
VSAPI64.dll |
#305
#289 #316 |
TmListenShare_64x.dll |
rtSetRegistryKeyValue2W
rtGetRegistryKeyValueW rtSetRegistryKeyValueW GetFileVersionBuildA |
FlowControl_64x.dll |
FlowEnabled
|
msi.dll |
#103
#125 #17 #8 #205 |
sqlite3.dll |
sqlite3_mprintf
sqlite3_free sqlite3_open16 sqlite3_errmsg sqlite3_prepare16_v2 sqlite3_bind_int sqlite3_bind_text sqlite3_bind_text16 sqlite3_column_name sqlite3_step sqlite3_column_int sqlite3_column_text16 sqlite3_column_type sqlite3_finalize sqlite3_reset sqlite3_next_stmt sqlite3_busy_timeout sqlite3_close sqlite3_column_count sqlite3_changes |
dbghelp.dll |
ImageNtHeader
|
Apex One Outlook Mail Scan |
Scanning... |
Open |
Save As |
All Files (*.*) |
Untitled |
an unnamed file |
&Hide |
No error message is available. |
Attempted an unsupported operation. |
A required resource was unavailable. |
Out of memory. |
An unknown error has occurred. |
Encountered an improper argument. |
Incorrect filename. |
Failed to open document. |
Failed to save document. |
Save changes to %1? |
Failed to create empty document. |
The file is too large to open. |
Could not start print job. |
Failed to launch help. |
Internal application error. |
Command failed. |
Insufficient memory to perform operation. |
System registry entries have been removed and the INI file (if any) was deleted. |
Not all of the system registry entries (or INI file) were removed. |
This program requires the file %Ts, which was not found on this system. |
This program is linked to the missing export %Ts in the file %Ts. This machine may have an incompatible version of %Ts. |
Enter an integer. |
Enter a number. |
Enter an integer between %1 and %2. |
Enter a number between %1 and %2. |
Enter no more than %1 characters. |
Select a button. |
Enter an integer between 0 and 255. |
Enter a positive integer. |
Enter a date and/or time. |
Enter a currency. |
Enter a GUID. |
Enter a time. |
Enter a date. |
Unexpected file format. |
%1 |
Cannot find this file. |
Verify that the correct path and file name are given. |
Destination disk drive is full. |
Unable to read from %1, it is opened by someone else. |
Unable to write to %1, it is read-only or opened by someone else. |
Encountered an unexpected error while reading %1. |
Encountered an unexpected error while writing %1. |
%1: %2 |
Continue running script? |
Dispatch exception: %1 |
Unable to read write-only property. |
Unable to write read-only property. |
Unable to load mail system support. |
Mail system DLL is invalid. |
Send Mail failed to send message. |
No error occurred. |
An unknown error occurred while accessing %1. |
%1 was not found. |
%1 contains an incorrect path. |
Could not open %1 because there are too many open files. |
Access to %1 was denied. |
An incorrect file handle was associated with %1. |
Could not remove %1 because it is the current directory. |
Could not create %1 because the directory is full. |
Seek failed on %1 |
Encountered a hardware I/O error while accessing %1. |
Encountered a sharing violation while accessing %1. |
Encountered a locking violation while accessing %1. |
Disk full while accessing %1. |
Attempted to access %1 past its end. |
No error occurred. |
An unknown error occurred while accessing %1. |
Attempted to write to the reading %1. |
Attempted to access %1 past its end. |
Attempted to read from the writing %1. |
%1 has a bad format. |
%1 contained an unexpected object. |
%1 contains an incorrect schema. |
pixels |
Uncheck |
Check |
Mixed |
One or more auto-saved documents were found. |
These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
Do you want to recover these auto-saved documents? |
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
Recover the auto-saved documents |
Open the auto-saved versions instead of the explicitly saved versions |
Don't recover the auto-saved documents |
Use the last explicitly saved versions of the documents |
%Ts [Recovered] |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 14.0.0.3048 |
ProductVersion | 14.0.0.3048 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Trend Micro Inc. |
CoverageBuild | NO |
CompileOption | Release |
BuildType | Rel |
FileDescription | Trend Micro Common Client Uninstallation Service |
FileVersion (#2) | 14.0.0.3048 |
InternalName | Common Client NT uninstaller |
LegalCopyright | Copyright (C) 2019 Trend Micro Incorporated. All rights reserved. |
LegalTrademarks | Copyright (C) Trend Micro Inc. |
OriginalFilename | webntrmv.EXE |
PrivateBuild | Build 3048 - 6/5/2019 |
ProductName | Trend Micro OfficeScan (common client) |
ProductVersion (#2) | 14.0 |
SpecialBuild | 3048 |
Resource LangID | Chinese - Taiwan |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Jun-05 08:23:04 |
Version | 0.0 |
SizeofData | 106 |
AddressOfRawData | 0x469bd4 |
PointerToRawData | 0x4683d4 |
Referenced File | D:\OSCE-Common-MAIN_1.0\src\Setup\NTClientUninstaller\NTRmv\x64\Release\NTRmv.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Jun-05 08:23:04 |
Version | 0.0 |
SizeofData | 20 |
AddressOfRawData | 0x469c40 |
PointerToRawData | 0x468440 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2019-Jun-05 08:23:04 |
Version | 0.0 |
SizeofData | 1004 |
AddressOfRawData | 0x469c54 |
PointerToRawData | 0x468454 |
StartAddressOfRawData | 0x14046a060 |
---|---|
EndAddressOfRawData | 0x14046a068 |
AddressOfIndex | 0x1404df8f0 |
AddressOfCallbacks | 0x14035b410 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
Callbacks | (EMPTY) |
Size | 0x100 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x1404cb958 |
XOR Key | 0xb615daff |
---|---|
Unmarked objects | 0 |
ASM objects (VS2017 v15.?.? build 25203) | 23 |
C++ objects (VS2017 v15.?.? build 25203) | 257 |
C++ objects (VS2015 build 23026) | 4 |
199 (41118) | 14 |
136 (VS2008 SP1 build 30729) | 1 |
C objects (VS2008 SP1 build 30729) | 10 |
C++ objects (VS2008 SP1 build 30729) | 1 |
C objects (VS 2015/2017 runtime 26706) | 38 |
ASM objects (VS 2015/2017 runtime 26706) | 10 |
C++ objects (VS2017 v15.6.6 compiler 26131) | 8 |
Imports (VS2017 v15.8.1 compiler 26726) | 8 |
135 (VS2008 SP1 build 30729) | 3 |
C++ objects (VS2015 UPD3.1 build 24215) | 51 |
C objects (VS2015 UPD3.1 build 24215) | 26 |
C objects (VS2017 v15.?.? build 25203) | 26 |
C++ objects (VS2015 UPD3 build 24210) | 2 |
C++ objects (VS2012 build 50727 / VS2005 build 50727) | 7 |
Imports (VS2008 SP1 build 30729) | 52 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 7 |
Total imports | 1192 |
C++ objects (VS 2015/2017 runtime 26706) | 445 |
C++ objects (VS2017 v15.8.1 compiler 26726) | 151 |
Resource objects (VS2017 v15.8.1 compiler 26726) | 1 |
151 | 1 |
Linker (VS2017 v15.8.1 compiler 26726) | 1 |