| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2092-Oct-21 20:38:28 |
| Detected languages |
English - United States
|
| Debug artifacts |
autochk.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Auto Check Utility |
| FileVersion | 10.0.22621.2506 (WinBuild.160101.0800) |
| InternalName | AutoChk |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | AutoChk.Exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.22621.2506 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to SHA1 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
| Safe | VirusTotal score: 0/68 (Scanned on 2024-04-28 23:40:43) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xe0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2092-Oct-21 20:38:28 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x9b000 |
| SizeOfInitializedData | 0x66000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000092F0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x102000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x10e93b |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x2000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ntdll.dll |
NtWriteFile
_wcsicmp NtOpenKey RtlPublishWnfStateData NtQuerySymbolicLinkObject LdrSetMUICacheType RtlSetSystemBootStatus RtlInitUnicodeString RtlGetSystemBootStatus RtlPrefixUnicodeString NtSerializeBoot NtClose RtlEqualUnicodeString NtFsControlFile wcsstr NtQueryDirectoryObject NtCreateFile NtOpenFile NtQueryValueKey NtTerminateProcess RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind RtlUnhandledExceptionFilter memset DbgPrintEx NtOpenSymbolicLinkObject NtQuerySystemTime RtlCompareUnicodeString NtOpenDirectoryObject __C_specific_handler RtlFreeAnsiString RtlAllocateHeap RtlNormalizeProcessParams RtlUnicodeStringToAnsiString isspace _vsnprintf _vsnwprintf RtlMultiByteToUnicodeN RtlOemToUnicodeN RtlSetLastWin32ErrorAndNtStatusFromNtStatus RtlUnicodeToMultiByteN RtlUnicodeToOemN wcsspn _wtol _wtoi64 _wcsupr _wcslwr wcschr NtDeviceIoControlFile RtlQueryRegistryValuesEx RtlWriteRegistryValue RtlGetPersistedStateLocation wcscpy_s wcscat_s NtQueryInformationFile NtQueryVolumeInformationFile wcstoul _wcstoui64 NtReadFile RtlRaiseStatus qsort NtDelayExecution NtQuerySystemInformation RtlSizeHeap RtlFreeHeap NtDrawText swprintf_s NtCreateEvent NtClearEvent NtSetThreadExecutionState NtWaitForMultipleObjects NtCancelIoFile RtlNumberGenericTableElementsAvl RtlDosPathNameToNtPathName_U_WithStatus RtlFreeUnicodeString NtOpenProcessToken NtAdjustPrivilegesToken NtShutdownSystem RtlExpandEnvironmentStrings_U NtSetInformationFile RtlValidRelativeSecurityDescriptor RtlGetVersion RtlTimeToTimeFields VerSetConditionMask RtlVerifyVersionInfo NtDisplayString RtlRandomEx NtQueryPerformanceCounter isprint RtlAcquireSRWLockExclusive RtlReleaseSRWLockExclusive RtlEnterCriticalSection RtlTryEnterCriticalSection RtlLeaveCriticalSection RtlDeleteCriticalSection RtlInitializeSRWLock RtlInitializeCriticalSection NtFreeVirtualMemory NtSetEvent RtlCaptureStackBackTrace NtAllocateVirtualMemory NtWaitForSingleObject NtResetEvent wcsncmp RtlFindMessage RtlInitUTF8StringEx RtlInitAnsiStringEx RtlUTF8StringToUnicodeString RtlAnsiStringToUnicodeString RtlFormatMessage RtlDeleteSecurityObject RtlLengthRequiredSid RtlInitializeSid RtlSubAuthoritySid RtlLengthSid RtlCopySid RtlAddAce RtlCreateAcl RtlQueryInformationAcl RtlCreateSecurityDescriptor RtlSetGroupSecurityDescriptor RtlSetDaclSecurityDescriptor RtlNewSecurityObject RtlValidSecurityDescriptor RtlLengthSecurityDescriptor RtlAddAccessAllowedAce RtlInitializeGenericTable RtlInsertElementGenericTable RtlInitializeBitMap RtlSetBits RtlLookupElementGenericTable RtlClearBits RtlFindSetBits RtlDeleteElementGenericTable RtlEnumerateGenericTableWithoutSplaying RtlNumberOfSetBits RtlInitializeGenericTableAvl RtlEnumerateGenericTableAvl RtlLookupFirstMatchingElementGenericTableAvl RtlEnumerateGenericTableWithoutSplayingAvl RtlDeleteElementGenericTableAvl RtlLookupElementGenericTableFullAvl RtlInsertElementGenericTableFullAvl RtlDeleteElementGenericTableAvlEx RtlInsertElementGenericTableAvl RtlLookupElementGenericTableAvl RtlSystemTimeToLocalTime RtlCrc64 RtlUpcaseUnicodeString RtlComputeCrc32 DbgPrint NtOpenThreadToken _wcsnicmp RtlDosPathNameToNtPathName_U RtlCreateSystemVolumeInformationFolder EtwEventUnregister EtwEventRegister EtwEventSetInformation EtwEventWriteTransfer NtFlushBuffersFile __chkstk memcmp memcpy memmove wcscmp |
|---|---|
| bcd.dll |
BcdCloseObject
BcdGetElementData BcdOpenObject BcdOpenStore BcdForciblyUnloadStore |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.22621.2506 |
| ProductVersion | 10.0.22621.2506 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Auto Check Utility |
| FileVersion (#2) | 10.0.22621.2506 (WinBuild.160101.0800) |
| InternalName | AutoChk |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | AutoChk.Exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.22621.2506 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2092-Oct-21 20:38:28 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0xa20f0 |
| PointerToRawData | 0xa20f0 |
| Referenced File | autochk.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2092-Oct-21 20:38:28 |
| Version | 0.0 |
| SizeofData | 556 |
| AddressOfRawData | 0xa2114 |
| PointerToRawData | 0xa2114 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2092-Oct-21 20:38:28 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0xa2340 |
| PointerToRawData | 0xa2340 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400a8150 |
| GuardCFCheckFunctionPointer | 5369354872 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xf9320f08 |
|---|---|
| Unmarked objects | 0 |
| Imports (30795) | 5 |
| Total imports | 182 |
| C objects (30795) | 7 |
| ASM objects (30795) | 3 |
| C objects (LTCG) (30795) | 115 |
| Resource objects (30795) | 1 |
| Linker (30795) | 1 |