| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2024-Jun-04 20:20:26 |
| Detected languages |
English - United States
|
| TLS Callbacks | 1 callback(s) detected. |
| Debug artifacts |
C:\actions-runner\_work\client\client\host\build\MinSizeRel\host.pdb
|
| CompanyName | Wolfram Research |
| FileDescription | Wolfram App 14.3 and English Documentation |
| FileVersion | 6.2.42.0 |
| InternalName | host.exe |
| LegalCopyright | 2025 |
| OriginalFilename | host.exe |
| ProductName | Wolfram App 14.3 and English Documentation |
| ProductVersion | 14.3.0 |
| Info | Matching compiler(s): |
Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to SHA512 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Wolfram Research
Issuer: DigiCert G5 CS RSA4096 SHA384 2021 CA1 |
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-16 16:55:04) | All the AVs think this file is safe. |
| MD5 | 0e20f77c5f6becfbb8a706b67a3a4580 🔍 |
|---|---|
| SHA1 | 953f596f4e4e0d532a185f66342aeb6fab731468 🔍 |
| SHA256 | c3fb587b417986545369540d14eab98298c5eb9370676d21bbcd56f3a24865e7 🔍 |
| SHA3 | 4ade0d55a85dda07f78dbb5f21695cb144df99b375ddbc08b8843732c7feacf9 🔍 |
| SSDeep | 49152:1HsZUJBqJ9LW9Ryw3V6+o7HkzNdsyp8i8IxTqkDT4qm6FeVrcc7eKN:1HU/9SbVV697HkJdsyp8KeVcc7e6 🔍 |
| Imports Hash | 377bb246ae624f3e2fc13a452200dbdc 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x140 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2024-Jun-04 20:20:26 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x19a200 |
| SizeOfInitializedData | 0x9ea00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0016A4ED (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x19c000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x240000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x2a8563 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | 05428c099be1db69b56135a3cc2c0c8e 🔍 |
|---|---|
| SHA1 | 6f6845781bd65b946e11dc85b6f6844d67dd2cb0 🔍 |
| SHA256 | 9ac92466ee96ca95d06922387d766cfa02541bc31524564bda0e884405cecf3b 🔍 |
| SHA3 | e6288f95d22be5eb68c943014718d42a5eaa18d4bd1ae41f2dd8efef3b15773a 🔍 |
| VirtualSize | 0x19a108 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x19a200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.64682 |
| MD5 | 88360d1920b68860e5f21d59b9a58b9b 🔍 |
|---|---|
| SHA1 | 090389d67cfa434c38206d7b2f216d468678f446 🔍 |
| SHA256 | 517e733ebe05bae20c1b4073f5b46eb613b0d5e42e55273d457bb8dd661bcc28 🔍 |
| SHA3 | 08e09a3bd45bf35f8319c7283581064c735493bf06aba5ba9e612e1b3390b0db 🔍 |
| VirtualSize | 0x51b38 |
| VirtualAddress | 0x19c000 |
| SizeOfRawData | 0x51c00 |
| PointerToRawData | 0x19a600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.87037 |
| MD5 | e55c4f3381b6f83a3d742c5df6eb01f9 🔍 |
|---|---|
| SHA1 | 5c5dcb3dd2565c543cc55087db092f0493f227c3 🔍 |
| SHA256 | 047dde13543af1b37520d83018577bc2c042e5b67fc13de617cc4f38c3a51984 🔍 |
| SHA3 | dfabab4c79a67d6d14614180c32cf6eb802298f7aced5578637c93a6b2086feb 🔍 |
| VirtualSize | 0xb71c |
| VirtualAddress | 0x1ee000 |
| SizeOfRawData | 0x7600 |
| PointerToRawData | 0x1ec200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 4.16375 |
| MD5 | d1fdc91b96008e788fa04083a6f3c5e7 🔍 |
|---|---|
| SHA1 | 12c8d42a2f8b91f60a8b80980f87ef221b7cda37 🔍 |
| SHA256 | cf4676e1fd1e3e490f80af0bb97b3fe0a31916fe7b461bd048bcf0734dd4eb6d 🔍 |
| SHA3 | af3cd04cdcd4a5b1e1ff29b80c7fe2cd4450e3f856071bfb07a43ffa108a2a1a 🔍 |
| VirtualSize | 0x2e8dc |
| VirtualAddress | 0x1fa000 |
| SizeOfRawData | 0x2ea00 |
| PointerToRawData | 0x1f3800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.02983 |
| MD5 | ef7550385cd696f09599519b79435bbc 🔍 |
|---|---|
| SHA1 | 96f8c30d1bd147bd23c8a1012f48bf2a511a2811 🔍 |
| SHA256 | cf0ac5d3322380fd4448c6cfa299f4517646356ec8494f069a660a1ddb70c9c3 🔍 |
| SHA3 | 7ac64a80286933be95a5c4b146a43fdefe96fb131840b1b5f306887e6f5ae7be 🔍 |
| VirtualSize | 0x16c30 |
| VirtualAddress | 0x229000 |
| SizeOfRawData | 0x16e00 |
| PointerToRawData | 0x222200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.80962 |
| dbghelp.dll |
SymInitialize
SymGetLineFromAddr64 SymFromAddr SymCleanup SymSetSearchPathW SymGetSearchPathW SymSetOptions |
|---|---|
| VERSION.dll |
VerQueryValueA
GetFileVersionInfoExW GetFileVersionInfoSizeExW VerQueryValueW GetFileVersionInfoSizeW GetFileVersionInfoW |
| WINHTTP.dll |
WinHttpOpen
WinHttpCloseHandle WinHttpGetProxyForUrl WinHttpSetStatusCallback |
| KERNEL32.dll |
IsBadReadPtr
FlushInstructionCache WriteConsoleW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA GetOEMCP GetACP IsValidCodePage HeapSize HeapReAlloc EnumSystemLocalesW IsValidLocale GetLocaleInfoW LCMapStringW GetTimeZoneInformation ReadConsoleW FreeLibraryAndExitThread ExitThread SetStdHandle GetCurrentProcess TerminateProcess GetModuleHandleW GlobalAlloc GlobalFree CompareStringW DeleteFileW GetLastError SetEnvironmentVariableW VerSetConditionMask GetCommandLineW VerifyVersionInfoW GetFileAttributesW GetModuleFileNameW OutputDebugStringA OutputDebugStringW GetProcAddress LoadLibraryExW LoadLibraryW FreeLibrary GetEnvironmentVariableW GetStdHandle CreateFileA CreateFileW QueryDosDeviceW WriteFile IsDebuggerPresent CloseHandle HeapAlloc HeapFree GetProcessHeap DeviceIoControl WaitForSingleObject GetExitCodeProcess CreateProcessW GetProcessId InitializeProcThreadAttributeList DeleteProcThreadAttributeList UpdateProcThreadAttribute OpenProcess GlobalMemoryStatusEx GetSystemDirectoryW GetWindowsDirectoryW CreateFileMappingW MapViewOfFile FreeResource GetModuleHandleA LoadResource LockResource SizeofResource FindResourceW LocalAlloc LocalFree SetThreadExecutionState MoveFileWithProgressW AllocConsole FreeConsole SetConsoleCtrlHandler SetConsoleTitleW CreateToolhelp32Snapshot Process32FirstW Process32NextW SetCurrentDirectoryW GetCurrentDirectoryW CreateDirectoryW FindClose FindFirstFileW FindNextFileW GetDiskFreeSpaceW GetFileAttributesExW GetLongPathNameW RemoveDirectoryW SetEndOfFile SetFileAttributesW SetFileInformationByHandle SetFileTime GetTempPathW RaiseException GetOverlappedResult Sleep GetCurrentProcessId GetCurrentThread GetCurrentThreadId SetThreadPriority GetNativeSystemInfo VirtualQuery UnmapViewOfFile FormatMessageA CopyFileExW MoveFileExW FileTimeToSystemTime SystemTimeToFileTime GetFileInformationByHandleEx GetLocaleInfoEx ReadFile SetFilePointerEx CreateIoCompletionPort GetQueuedCompletionStatus PostQueuedCompletionStatus MulDiv IsProcessorFeaturePresent GetTickCount64 InitializeCriticalSection EnterCriticalSection LeaveCriticalSection DeleteCriticalSection FlushFileBuffers SetHandleInformation CreatePipe ConnectNamedPipe DisconnectNamedPipe PeekNamedPipe CreateNamedPipeW WaitNamedPipeW SetLastError SetEvent ResetEvent CreateEventW ReleaseSemaphore CreateSemaphoreW RtlCaptureContext SetUnhandledExceptionFilter CreateThread TerminateThread VirtualQueryEx DuplicateHandle SetNamedPipeHandleState TransactNamedPipe WaitForMultipleObjects UnregisterWait RegisterWaitForSingleObject TerminateJobObject GetModuleHandleExW SetInformationJobObject GetUserDefaultLangID GetUserDefaultLCID GetUserDefaultLocaleName EnumSystemLocalesEx HeapDestroy GetTickCount TryAcquireSRWLockExclusive ReleaseSRWLockExclusive UnregisterWaitEx IsWow64Process GetThreadId GetThreadPriority GetFileType HeapSetInformation SetProcessDEPPolicy VirtualAllocEx GetVersionExW GetProductInfo AssignProcessToJobObject WriteProcessMemory ReadProcessMemory GetCurrentProcessorNumber SetThreadAffinityMask VirtualFree GetProcessHeaps AcquireSRWLockExclusive GetSystemTimeAsFileTime QueryPerformanceFrequency QueryPerformanceCounter GetLocalTime CreateJobObjectW QueryInformationJobObject VirtualProtectEx ExpandEnvironmentStringsW CreateMutexW VirtualFreeEx GetProcessHandleCount TlsGetValue lstrlenW DebugBreak TlsAlloc TlsFree TlsSetValue GetFileSizeEx RtlCaptureStackBackTrace CreateRemoteThread GetSystemInfo WideCharToMultiByte MultiByteToWideChar FindFirstFileExW SleepConditionVariableSRW WakeAllConditionVariable GetConsoleMode VirtualProtect LoadLibraryExA UnhandledExceptionFilter GetStartupInfoW InitializeSListHead InitializeCriticalSectionEx EncodePointer DecodePointer LCMapStringEx GetStringTypeW GetCPInfo RtlUnwind InitializeCriticalSectionAndSpinCount ExitProcess GetConsoleOutputCP |
| msi.dll (delay-loaded) |
#137
#88 #141 #169 |
| Attributes | 0x1 |
|---|---|
| Name | msi.dll |
| ModuleHandle | 0x1f8848 |
| DelayImportAddressTable | 0x1f54d0 |
| DelayImportNameTable | 0x1eac38 |
| BoundDelayImportTable | 0x1ebdf4 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x2c600 |
| Ordinal | 2 |
|---|---|
| Address | 0x2f1c |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x528 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.25115 |
| MD5 | 19b7c4525a649ebeddf91729dec89571 🔍 |
| SHA1 | 957875c86d70893af6db78eb4d27005caa0f5726 🔍 |
| SHA256 | a98ba32b7357101c8a4b8f14cdc231f3503ba7e5b5a8b6e7671a06966e67a018 🔍 |
| SHA3 | 2939d5f71f62a3508b1700f145dc85e8c82987948490cc23e002c409540118be 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1428 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.92384 |
| MD5 | 3c0a6f121d4d690a959907ae7b34fd18 🔍 |
| SHA1 | e8fefb1baa51aa7b726a7b6f7ac0c05effd621eb 🔍 |
| SHA256 | 6e203b9a77d4107606ee73156cd8257de0f8ccdb970d6c9c8cbbbcee78123a06 🔍 |
| SHA3 | 714d37b8431bd80c974f7fc18d3899c8a504381e5b619c11bcb689416f08ec48 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x2d28 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.57569 |
| MD5 | 8d0e1401c337ce5d6e854d093e9df825 🔍 |
| SHA1 | ea91121bae5b57908d0e2c5c9396b1f6ad2b2874 🔍 |
| SHA256 | cbbe6650a5979fc15535c9bed0e3dca790e5cabb353123e1238a8b5783a8ed67 🔍 |
| SHA3 | 6b196275e15732a92f2591f540c3e5fccde08096747135bb66cdef660971dc98 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x5028 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.36278 |
| MD5 | 3ca3efce693e8021b043b73a1779e10e 🔍 |
| SHA1 | ce60d2d31848a3238271dc497332fa42ad996b8d 🔍 |
| SHA256 | eff587c5fcdc11e7e5f5253b24b5d15c94068fe2190b1697ac4e0992720527dd 🔍 |
| SHA3 | febb3be0d357fdd281c3cd87a8acdbd5c395b5f4ca00ae00017d546648696d4a 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0xb428 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.06935 |
| MD5 | 62e521dea1f1457d145d65a7bf10c464 🔍 |
| SHA1 | 5a3ad4ca89e29fcfcf360365759b2558873d3b2e 🔍 |
| SHA256 | e96964a123d6aed5b6c3b91f175148ea8883d73413ba2feabc6c5636630d88cb 🔍 |
| SHA3 | 262d32f8502d8ad4a6aa14bf803840c80d652965589a4180383f9052dbc27fb6 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14028 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.92868 |
| MD5 | 48b377773f598dac36d365aa20f2ae51 🔍 |
| SHA1 | 2c32ec2c47858d6c619bacb7a9bd6426b1977832 🔍 |
| SHA256 | 860391862a5d105fec0b8655042b9059f0b8dde00a708bcd793678ffb2cdedef 🔍 |
| SHA3 | dbdbcf0c803f7422a9f0fe54b631742167b5bd474f7880386a8d15be3531e8cb 🔍 |
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x4fc5 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 7.96687 |
| Detected Filetype | PNG graphic file |
| MD5 | a52d9a88c61a2fa544dfb597dad0fd60 🔍 |
| SHA1 | c63de02779c80a6f0d1fde6709809094bff02754 🔍 |
| SHA256 | 3f8d35a15b27bb7d3386d1ea98684cab4cff8e4660c595a85a2b8a5db2fee2b5 🔍 |
| SHA3 | 3229402910b44d04f95203bfc2179789fc99e9f18036517668bf8428cd26179e 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x68 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 2.59156 |
| Detected Filetype | Icon file |
| MD5 | 775174f9685c5d4c3665ad71ce2a6c4f 🔍 |
| SHA1 | f454f0760c1339b2ea55cd9d4465ae0adcef863b 🔍 |
| SHA256 | 7effc995f6572b78bb732b265dcd18e2bb2a72d8d7d7db1fb3ab93f2244dd733 🔍 |
| SHA3 | 78ed3b1343e3e5cdcb0a2236bf0bf64d4f6b8794f070b1cd7b092c34ed325d60 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x320 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.37347 |
| MD5 | a10d91a931492728a43deff7201f6fcd 🔍 |
| SHA1 | a829cc6b0b98182a68905296934e0b1ca0491099 🔍 |
| SHA256 | ae6a559743993d680f4251ef9a68e12d8e82a25686605eebe35c9e2b17b32bd8 🔍 |
| SHA3 | 03637773880dfed4d0e0f6a2e999c6def019f5561725b36048d85b6f431ce108 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x849 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.19828 |
| MD5 | 24df96f0bd1599ea292b31e08638e220 🔍 |
| SHA1 | f4f95df802df110791417d7b6a3d0c7d56a98f57 🔍 |
| SHA256 | dc8a34780223d90b5208ba5da5792035b009016e99ac9e4a2e3cda1338317d6d 🔍 |
| SHA3 | a9e10d68a0d421126899524be4f45ffc210d8ddde6a0e65e5ef338380ef012a6 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.2.42.0 |
| ProductVersion | 14.3.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Wolfram Research |
| FileDescription | Wolfram App 14.3 and English Documentation |
| FileVersion (#2) | 6.2.42.0 |
| InternalName | host.exe |
| LegalCopyright | 2025 |
| OriginalFilename | host.exe |
| ProductName | Wolfram App 14.3 and English Documentation |
| ProductVersion (#2) | 14.3.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-04 20:20:26 |
| Version | 0.0 |
| SizeofData | 93 |
| AddressOfRawData | 0x1e94ac |
| PointerToRawData | 0x1e7aac |
| Referenced File | C:\actions-runner\_work\client\client\host\build\MinSizeRel\host.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-04 20:20:26 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x1e950c |
| PointerToRawData | 0x1e7b0c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2024-Jun-04 20:20:26 |
| Version | 0.0 |
| SizeofData | 1248 |
| AddressOfRawData | 0x1e9520 |
| PointerToRawData | 0x1e7b20 |
| StartAddressOfRawData | 0x5e9a10 |
|---|---|
| EndAddressOfRawData | 0x5e9a1c |
| AddressOfIndex | 0x5f8be8 |
| AddressOfCallbacks | 0x59c444 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks |
0x0043BC50
|
| Size | 0xc0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x5f4100 |
| SEHandlerTable | 0x5e922c |
| SEHandlerCount | 19 |
| XOR Key | 0x6b448d71 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (30795) | 26 |
| C++ objects (30795) | 193 |
| 253 (33731) | 1 |
| ASM objects (33731) | 25 |
| C objects (33731) | 20 |
| C++ objects (33731) | 86 |
| C objects (CVTCIL) (30795) | 1 |
| C objects (30795) | 43 |
| C++ objects (CVTCIL) (30795) | 1 |
| Imports (30795) | 15 |
| Total imports | 620 |
| Unmarked objects (#2) | 330 |
| C++ objects (33808) | 7 |
| C objects (33808) | 277 |
| Exports (33808) | 1 |
| Resource objects (33808) | 1 |
| 151 | 1 |
| Linker (33808) | 1 |
No comments yet.