9ee05d69b5d6acf1232f3032fb0e106c2c3ba71897f20efeaead10d378b22070

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_NATIVE
Compilation Date 2026-Mar-03 14:46:47
Detected languages English - United States
Debug artifacts denuvo-anti-cheat.pdb
Comments Denuvo Anti-Cheat Driver v6.13
CompanyName Denuvo GmbH
FileDescription Denuvo Anti-Cheat Driver
FileVersion 6.13.2.9798
InternalName Denuvo Anti-Cheat Driver
LegalCopyright © Denuvo GmbH. All rights reserved.
OriginalFilename denuvo-anti-cheat.sys
ProductName Denuvo Anti-Cheat Driver
ProductVersion 6.13.2.9798

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to AES
Suspicious The PE is possibly packed. Unusual section name found: PAGE
Unusual section name found:
Unusual section name found:
Unusual section name found:
Unusual section name found:
Malicious The PE contains functions mostly used by malware. Functions which can be used for anti-debugging purposes:
  • ZwQuerySystemInformation
Uses Windows's Native API:
  • ZwOpenProcess
  • ZwOpenProcessTokenEx
  • ZwQueryInformationToken
  • ZwCreateFile
  • ZwWriteFile
  • ZwFlushBuffersFile
  • ZwOpenFile
  • ZwQueryInformationFile
  • ZwReadFile
  • ZwQueryVirtualMemory
  • ZwDeviceIoControlFile
  • ZwQuerySystemInformation
  • ZwClose
Functions related to the privilege level:
  • ZwOpenProcessTokenEx
Info The PE is digitally signed. Signer: Microsoft Windows Hardware Compatibility Publisher
Issuer: Microsoft Windows Third Party Component CA 2014
Safe VirusTotal score: 0/69 (Scanned on 2026-06-16 17:27:51) All the AVs think this file is safe.

Hashes

MD5 2c1d8577d79caa5efd92df063b0b35e0
SHA1 97c5d64446669fcbbc79bd12a69583909bed8d81
SHA256 9ee05d69b5d6acf1232f3032fb0e106c2c3ba71897f20efeaead10d378b22070
SHA3 9190c0817f104a1e5bdef979cee3fc03ea5b2f708fc5efd6817bc4570080067c
SSDeep 98304:P/m/Zo+zdp/3gFyqDbAibNyvSbl+arU18H:Pe/aCpYFfb3b40sarUaH
Imports Hash 5eac7046c2d362fce69d1329a0ecbda6

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 16
TimeDateStamp 2026-Mar-03 14:46:47
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x4f5a00
SizeOfInitializedData 0xc000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001184 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion A.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x507000
SizeOfHeaders 0x600
Checksum 0x4ae21d
Subsystem IMAGE_SUBSYSTEM_NATIVE
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 339fa6619342676dbb45e80015505a29
SHA1 755363215645a70991fe07c80aa751d6a796ff81
SHA256 1078a59b40c2b22803bec3eb93155771ed268f2d7b7ec6306521fd949f90c41f
SHA3 465131908e843fc56e9ec5438cd356037409a6d70416d0586a3e74a335a376ee
VirtualSize 0xb9000
VirtualAddress 0x1000
SizeOfRawData 0xb8c00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 6.78109

.rdata

MD5 21c4c59181c8dfb304e6a7588f491a2b
SHA1 d2a6db208fdcfa56e56d87b4ab4eaabe29505d9a
SHA256 8b6bcaa08a97eb1df036c98cb4a9290c9ef91d56057441cf82870bd9963609a1
SHA3 6f5f7472454f38e983d55bf092cd67b03f80808f477b2960abd2b4b799011fb7
VirtualSize 0x3d000
VirtualAddress 0xba000
SizeOfRawData 0x3c400
PointerToRawData 0xb9200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 7.25938

.data

MD5 95252771d14e08bf9c31489a682546fd
SHA1 09c0e73d152de31a340f8a15a3244f26012d4854
SHA256 0fd6f4f77838f6af17a260716a85f5c9711a0082d4337c07b7f90163dcb689be
SHA3 c6cf35e7a407068264ad106f00259023c438fae2739c48bbc2e5e01f1fcb8e6b
VirtualSize 0x55000
VirtualAddress 0xf7000
SizeOfRawData 0x600
PointerToRawData 0xf5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.88099

.pdata

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x9000
VirtualAddress 0x14c000
SizeOfRawData 0x200
PointerToRawData 0xf5c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 0

PAGE

MD5 61edbc7e370f5d9b205fb85ae355689f
SHA1 4ff3079a046453bd832cedcaf9d0ad356002cd5e
SHA256 ebe0fe3498f9183327ad7e6753daee87d776ac0aaa9d9c5a08bad52cf51b5998
SHA3 eb904cc296a81297725850f73f0392a625ea4fbd0e4b952637c70c83aec4b60e
VirtualSize 0x1000
VirtualAddress 0x155000
SizeOfRawData 0x600
PointerToRawData 0xf5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 4.80399

.edata

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x1000
VirtualAddress 0x156000
SizeOfRawData 0x200
PointerToRawData 0xf6400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

INIT

MD5 7874634ea3fe479af39b2d7a7def5d09
SHA1 bd9ce79aae399adb2bbfb78107f58554839126ae
SHA256 84dba296e8c6b8268a83cda33778cd217833a980766e74fa1cee633e17189b04
SHA3 a1b96ce0827e1d89621756a437e16ff60af211366f2968536ff4db7921cdb841
VirtualSize 0x2000
VirtualAddress 0x157000
SizeOfRawData 0x1400
PointerToRawData 0xf6600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.21005

.rsrc

MD5 0c11878639777fdfa0384a6d4960e6b2
SHA1 7ec2bcff503322e277a6b1d79ac107b772263bcd
SHA256 6d1d7925176445700f2811392543222d6c40902996b62928d818d914b77e87ae
SHA3 255c75b370dcf6348badcc1bb8c6f7cb1d21528de76f8e4daf4d3c1c3670b93b
VirtualSize 0x1000
VirtualAddress 0x159000
SizeOfRawData 0x600
PointerToRawData 0xf7a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.98754

.reloc

MD5 7e272053fb5497d098c4898c549aca10
SHA1 4c71ef9093195f8ca3b51bc002183a0941d16bc3
SHA256 fcf4f7fc65b7db7b992dcd11b687d160797f1fb6ac00d3a53dd61e509ca16e96
SHA3 75cd0afd2aac2589dc2d10e413be1a8e166c2a6826b1917c778f3357e7684e88
VirtualSize 0x3000
VirtualAddress 0x15a000
SizeOfRawData 0x2600
PointerToRawData 0xf8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.39106

Section_10

MD5 60e0e83af1c8e69cce96b8dba6e7a580
SHA1 2aed07a9bb8ff19af6ea4316a7ec16ba2f7fc947
SHA256 050171391c2963cde27aae81e7fc38315ad2dd9666bb6f791d572c4974026c16
SHA3 0072fc8bc42954257c6f94dc9db32d145e09ba9a2c26c830b73b36d99fdca00d
VirtualSize 0x393718
VirtualAddress 0x15d000
SizeOfRawData 0x393800
PointerToRawData 0xfa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 6.73606

Section_11

MD5 a69c27fd0fa4a08063b50b74ac265e9f
SHA1 34511e25d9b83d00226200ba05ed4fc407e29f54
SHA256 3a4a4006fd44edf53c9ed9078c771d0f53f2ed8941964ad0c7bd2d1fa478d2a4
SHA3 64cca7ef12a0aeeb02dd7bb60eb8a85fe192e6cb8fd54d6eae291c1e0a1cfea8
VirtualSize 0x16a8
VirtualAddress 0x4f1000
SizeOfRawData 0x1800
PointerToRawData 0x48de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 5.36109

Section_12

MD5 d2d3a1f0e6bd7be708453d2fe590314a
SHA1 0565e80f404e59b1c9d14f5cc42b6d373e2e8b38
SHA256 c3c9a2eded8044c3893b2489fd95c3e7d223debe35d7e7888c66e55b8b4895aa
SHA3 cfb82b0f9f838590249033939a2e5ddca60fbb0d7602ba6036966212e7c23fa2
VirtualSize 0x47f8
VirtualAddress 0x4f3000
SizeOfRawData 0x4800
PointerToRawData 0x48f600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.5869

Section_13

MD5 1c1d8d1463eb7db8017fd5df879d168f
SHA1 a92914928ecd6e13ead510abfbf654c1b44e8b49
SHA256 2be70a591207411eb8cf660cfd12e24d17fafe671537b2bae4edc2ffc5c40b41
SHA3 c04b741939805c49f2c64e5c470771983a0c2d3df7b95bebdb1be07c9b2aedeb
VirtualSize 0x8c
VirtualAddress 0x4f8000
SizeOfRawData 0x200
PointerToRawData 0x493e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 1.50546

.rdata (#2)

MD5 fdf69b8d972df9033c987725dc37c932
SHA1 26a8fc37ecf43b04c2b91a1ccf8ed7f0a9a9cffb
SHA256 b3d577dc61874f8a0182c734e98147b64835c963e396dfc7e65ba7b587be455d
SHA3 2ec491d8bdfb581a5da48e49f81fe5fe2a993e675412ee818187238033f096fb
VirtualSize 0xf4
VirtualAddress 0x4f9000
SizeOfRawData 0x200
PointerToRawData 0x494000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 1.89339

.pdata (#2)

MD5 57a98b59a7b7d60ef7a574b100ba8a49
SHA1 0dbabcdb62629e331237592c6f415d95eab9b82d
SHA256 f97922b13b694916d4b41651f826ed5cbdc9c6bfa5ca01cabe2e2e74d8bf7b14
SHA3 58f731419c50ef9ee3b92da4529b292f48d6a6361ac3bfb333e2d3a96ba2db63
VirtualSize 0x8ab4
VirtualAddress 0x4fa000
SizeOfRawData 0x8c00
PointerToRawData 0x494200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_NOT_PAGED
IMAGE_SCN_MEM_READ
Entropy 6.09775

.reloc (#2)

MD5 d3ff40f2ac8ee6409fb8fa78293c45a5
SHA1 bb714244b3c0cc1d7423bb516908194275a2a6e9
SHA256 4afc83ae78b35c346d435fd2fad47eabd4386e727024d9ce2861796efae04924
SHA3 2e374c071d004c7b3132a1949e1ac62edf87b4489525785a02995c8c2287a875
VirtualSize 0x3164
VirtualAddress 0x503000
SizeOfRawData 0x3200
PointerToRawData 0x49ce00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.47718

Imports

WDFLDR.SYS WdfVersionBindClass
WdfVersionUnbindClass
WdfVersionBind
WdfVersionUnbind
ntoskrnl.exe KdRefreshDebuggerNotPresent
ZwOpenProcess
RtlConvertSidToUnicodeString
ZwOpenProcessTokenEx
ZwQueryInformationToken
KdDebuggerEnabled
KeInitializeMutex
KeReleaseMutex
KeAcquireSpinLockRaiseToDpc
KeReleaseSpinLock
ExAcquireFastMutex
ExReleaseFastMutex
ExUuidCreate
RtlRandomEx
RtlInitUnicodeString
RtlQueryRegistryValues
RtlWriteRegistryValue
RtlCreateRegistryKey
ZwCreateFile
ZwWriteFile
ZwFlushBuffersFile
towlower
RtlGUIDFromString
IofCompleteRequest
IoCreateDevice
IoCreateSymbolicLink
IoDeleteDevice
IoDeleteSymbolicLink
PsGetCurrentProcessId
RtlDowncaseUnicodeChar
RtlUnicodeToUTF8N
KeDeregisterBugCheckReasonCallback
KeRegisterBugCheckReasonCallback
ExCreateCallback
ExRegisterCallback
ExUnregisterCallback
MmIsAddressValid
IoGetStackLimits
ObOpenObjectByPointer
DbgPrintEx
KeBugCheckEx
memchr
RtlInitAnsiString
PsGetProcessCreateTimeQuadPart
RtlFreeUnicodeString
KeDelayExecutionThread
MmMapIoSpace
MmUnmapIoSpace
KeQueryActiveProcessorCountEx
ZwOpenFile
ZwQueryInformationFile
ZwReadFile
MmGetPhysicalAddress
KeStackAttachProcess
KeUnstackDetachProcess
PsGetProcessSectionBaseAddress
RtlPcToFileHeader
KeEnterCriticalRegion
KeLeaveCriticalRegion
ExAcquireResourceSharedLite
ExReleaseResourceLite
MmLockPagableDataSection
MmUnlockPagableImageSection
PsGetProcessId
PsGetThreadProcessId
PsGetThreadProcess
PsProcessType
PsThreadType
ExInitializeResourceLite
ExAcquireResourceExclusiveLite
ExDeleteResourceLite
SeLocateProcessImageName
IoFileObjectType
ExAcquireSpinLockExclusive
ExReleaseSpinLockExclusive
IoFreeIrp
ObRegisterCallbacks
ObUnRegisterCallbacks
PsSetCreateProcessNotifyRoutineEx
PsSetLoadImageNotifyRoutine
PsRemoveLoadImageNotifyRoutine
IoGetInitialStack
PsGetCurrentThreadTeb
ZwQueryVirtualMemory
ZwDeviceIoControlFile
IoAllocateIrp
IoReuseIrp
MmBuildMdlForNonPagedPool
IoAllocateMdl
IoFreeMdl
RtlCopyUnicodeString
ZwQuerySystemInformation
ObfDereferenceObject
RtlTimeToTimeFields
KeGetCurrentProcessorNumberEx
KeSetSystemAffinityThreadEx
KeRevertToUserAffinityThreadEx
KfRaiseIrql
KeLowerIrql
RtlCheckRegistryKey
KeSetEvent
KeInitializeEvent
ZwClose
ObReferenceObjectByHandle
PsTerminateSystemThread
PsCreateSystemThread
KeWaitForSingleObject
KeSetPriorityThread
ExFreePoolWithTag
ExAllocatePoolWithTag
IoGetCurrentProcess
RtlGetEnabledExtendedFeatures
KeRestoreExtendedProcessorState
KeSaveExtendedProcessorState
__C_specific_handler
__chkstk
RtlGetVersion
MmGetSystemRoutineAddress
_purecall
PsLookupProcessByProcessId
RtlAnsiStringToUnicodeString
RtlUnicodeToMultiByteN
RtlAnsiCharToUnicodeChar
PsGetVersion
ExAllocatePoolWithQuotaTag
HAL.dll KeQueryPerformanceCounter
NETIO.SYS WskRegister
WskCaptureProviderNPI
WskDeregister
WskReleaseProviderNPI
cng.sys BCryptVerifySignature
BCryptDestroyKey
BCryptImportKeyPair
BCryptDestroyHash
BCryptFinishHash
BCryptHashData
BCryptCreateHash
BCryptGetProperty
BCryptCloseAlgorithmProvider
BCryptSetProperty
BCryptOpenAlgorithmProvider
BCryptGenRandom
FLTMGR.SYS FltCreateFile
FltGetFileNameInformation
FltReleaseFileNameInformation
FltClose
FltReadFile
FltStartFiltering
FltUnregisterFilter
FltRegisterFilter
FltQueryInformationFile

Delayed Imports

1

Type RT_MESSAGETABLE
Language English - United States
Codepage UNKNOWN
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19321
MD5 fa41733fb15303611660f921db3140fc
SHA1 25ef319f5d0e762a325a1fffe2f2480fa1a01a86
SHA256 65a5547726eb0151ae1cc978c44cc7e57637560b5fc8663fcbf6be1a6b024b7e
SHA3 a38342882fb424b6b9a60900e9fcb99bb249314ab07fcc563b9b6d133f3e0caf

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48961
MD5 6a3b339b5f5e9bb1966256eb6fae4a36
SHA1 1326ab53616857861cc17b71db708c23ebaf39ea
SHA256 3e807c9db530d259b56e2fe957befe53e6044abada4d76ff9a05f26397d7435e
SHA3 624eed9b4b78e11d7692762a538308cdbb18782fdd275387366b7ff402923389

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6.13.2.9798
ProductVersion 6.13.2.9798
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Denuvo Anti-Cheat Driver v6.13
CompanyName Denuvo GmbH
FileDescription Denuvo Anti-Cheat Driver
FileVersion (#2) 6.13.2.9798
InternalName Denuvo Anti-Cheat Driver
LegalCopyright © Denuvo GmbH. All rights reserved.
OriginalFilename denuvo-anti-cheat.sys
ProductName Denuvo Anti-Cheat Driver
ProductVersion (#2) 6.13.2.9798
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Mar-03 14:46:47
Version 0.0
SizeofData 142
AddressOfRawData 0x4f9050
PointerToRawData 0x494050
Referenced File denuvo-anti-cheat.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Mar-03 14:46:47
Version 0.0
SizeofData 20
AddressOfRawData 0xeecac
PointerToRawData 0xedeac

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Mar-03 14:46:47
Version 0.0
SizeofData 584
AddressOfRawData 0xeecc0
PointerToRawData 0xedec0

TLS Callbacks

Load Configuration

Size 0x118
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400f7410

RICH Header

Errors

Leave a comment

No comments yet.