Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2013-Aug-22 09:10:08 |
Detected languages |
English - United States
|
Debug artifacts |
spoolsv.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Spooler SubSystem App |
FileVersion | 6.3.9600.16384 (winblue_rtm.130821-1623) |
InternalName | spoolsv.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | spoolsv.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.3.9600.16384 |
Info | Interesting strings found in the binary: |
Contains domain names:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Safe | VirusTotal score: 0/71 (Scanned on 2020-11-20 17:42:39) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x100 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2013-Aug-22 09:10:08 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 11.3 |
SizeOfCode | 0xa5400 |
SizeOfInitializedData | 0x1d600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000052E0C (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x7ff6d8830000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.3 |
ImageVersion | 6.3 |
SubsystemVersion | 6.3 |
Win32VersionValue | 0 |
SizeOfImage | 0xc6000 |
SizeOfHeaders | 0x400 |
Checksum | 0xca79e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0xc000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
USER32.dll |
DispatchMessageW
PeekMessageW TranslateMessage MsgWaitForMultipleObjects UnregisterDeviceNotification RegisterDeviceNotificationW SendNotifyMessageW UnregisterPowerSettingNotification RegisterPowerSettingNotification |
---|---|
msvcrt.dll |
_commode
_unlock memcpy __dllonexit _onexit _fmode _lock __CxxFrameHandler3 _strnicmp __C_specific_handler _initterm __setusermatherr _cexit _exit exit __set_app_type __getmainargs _amsg_exit wcsncmp memmove _XcptFilter _wcsnicmp _vsnwprintf wcsstr ??3@YAXPEAX@Z _purecall ?terminate@@YAXXZ strchr wcschr towlower _stricmp _wcsicmp ??2@YAPEAX_K@Z towupper memset |
ntdll.dll |
RtlIpv4AddressToStringW
NtOpenProcessToken NtClose NtSetInformationThread NtOpenThreadToken RtlIpv4StringToAddressExW RtlIpv6StringToAddressExW EtwEventEnabled RtlReportException TpAllocPool TpReleaseAlpcCompletion TpWaitForAlpcCompletion TpReleaseIoCompletion TpWaitForIoCompletion TpReleaseTimer TpWaitForTimer TpReleaseWait TpWaitForWait TpReleaseWork TpWaitForWork TpAllocAlpcCompletion TpStartAsyncIoOperation TpAllocIoCompletion TpSetTimer TpAllocTimer TpAllocWait TpPostWork TpAllocWork RtlNtStatusToDosError TpSimpleTryPost TpSetWait TpCallbackMayRunLong TpReleasePool RtlVirtualUnwind RtlLookupFunctionEntry RtlCaptureContext RtlValidRelativeSecurityDescriptor EtwEventWrite NtQuerySystemInformation EtwGetTraceLoggerHandle EtwUnregisterTraceGuids EtwEventUnregister WinSqmIsOptedIn WinSqmSetDWORD WinSqmAddToStreamEx WinSqmIncrementDWORD EtwRegisterTraceGuidsW EtwTraceMessage EtwEventRegister EtwGetTraceEnableFlags EtwGetTraceEnableLevel RtlIpv6AddressToStringW |
api-ms-win-core-synch-l1-2-0.dll |
ReleaseMutex
AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeCriticalSection CreateMutexW AcquireSRWLockShared InitializeSRWLock SetEvent CreateEventW OpenEventW EnterCriticalSection ReleaseSRWLockShared LeaveCriticalSection WaitForSingleObject Sleep InitializeCriticalSectionAndSpinCount |
api-ms-win-core-libraryloader-l1-2-0.dll |
GetModuleHandleW
DisableThreadLibraryCalls |
api-ms-win-core-processthreads-l1-1-2.dll |
TerminateProcess
GetCurrentProcess ExitThread GetCurrentThreadId TlsAlloc CreateThread TlsGetValue CreateProcessAsUserW TlsSetValue SetPriorityClass TlsFree SetThreadToken OpenProcess GetCurrentProcessId OpenProcessToken GetCurrentThread OpenThreadToken ExitProcess |
api-ms-win-core-errorhandling-l1-1-1.dll |
SetLastError
GetLastError RaiseException SetErrorMode SetUnhandledExceptionFilter GetErrorMode UnhandledExceptionFilter |
api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
DuplicateHandle |
api-ms-win-service-core-l1-1-1.dll |
SetServiceStatus
StartServiceCtrlDispatcherW RegisterServiceCtrlHandlerExW |
api-ms-win-core-sysinfo-l1-2-1.dll |
GetSystemWindowsDirectoryW
GetSystemTimeAsFileTime GetVersionExW GetSystemTime GetTickCount |
api-ms-win-core-heap-l1-2-0.dll |
HeapDestroy
GetProcessHeap HeapSetInformation HeapCreate |
api-ms-win-core-registry-l1-1-0.dll |
RegQueryInfoKeyW
RegGetKeySecurity RegDeleteTreeW RegDeleteKeyExW RegCloseKey RegCreateKeyExW RegEnumValueW RegOpenKeyExW RegGetValueW RegSetKeySecurity RegOpenCurrentUser RegDeleteValueW RegQueryValueExW RegDisablePredefinedCacheEx RegSetValueExW RegEnumKeyExW |
api-ms-win-core-debug-l1-1-1.dll |
OutputDebugStringW
DebugBreak IsDebuggerPresent |
RPCRT4.dll |
RpcBindingFromStringBindingW
RpcStringBindingComposeW I_RpcExceptionFilter RpcServerSubscribeForNotification RpcServerUnsubscribeForNotification Ndr64AsyncClientCall NdrClientCall3 RpcBindingServerFromClient RpcBindingFree RpcStringBindingParseW RpcObjectSetType RpcServerInqBindingHandle RpcBindingVectorFree RpcBindingToStringBindingW RpcServerInterfaceGroupDeactivate RpcServerInterfaceGroupActivate RpcServerInterfaceGroupCreateW RpcEpRegisterW RpcServerTestCancel RpcServerRegisterAuthInfoW RpcSsContextLockExclusive RpcServerInqBindings RpcImpersonateClient RpcServerInqDefaultPrincNameW RpcServerRegisterIf RpcRevertToSelf I_RpcSessionStrictContextHandle I_RpcBindingIsClientLocal RpcRaiseException NdrServerCallAll RpcStringFreeW RpcMgmtSetServerStackSize RpcServerRegisterIf2 RpcAsyncCompleteCall RpcRevertToSelfEx RpcSmDestroyClientContext I_RpcBindingInqTransportType RpcAsyncAbortCall NdrAsyncServerCall NdrServerCall2 Ndr64AsyncServerCallAll |
api-ms-win-security-base-l1-2-0.dll |
CopySid
DuplicateToken AddAccessDeniedAceEx GetLengthSid AddAce GetSecurityDescriptorDacl RevertToSelf IsWellKnownSid CreateWellKnownSid InitializeAcl GetAce SetSecurityDescriptorDacl InitializeSecurityDescriptor FreeSid GetAclInformation AddAccessAllowedAceEx SetTokenInformation ImpersonateLoggedOnUser GetSidSubAuthority GetSidSubAuthorityCount EqualSid DuplicateTokenEx GetTokenInformation CheckTokenMembership AllocateAndInitializeSid |
api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
KERNEL32.dll |
GetProcAddress
LocalFree SetThreadpoolTimer AddVectoredExceptionHandler ResetEvent HeapAlloc FreeLibrary LoadLibraryExW HeapFree GetModuleHandleExW DeleteCriticalSection GetComputerNameW lstrcmpiW QueueUserWorkItem ResolveDelayLoadedAPI CreateThreadpoolTimer WaitForThreadpoolTimerCallbacks CloseThreadpoolTimer GetTickCount64 LoadLibraryW LocalAlloc |
api-ms-win-core-string-l1-1-0.dll |
CompareStringW
WideCharToMultiByte |
api-ms-win-core-file-l1-2-1.dll |
DeleteFileW
CreateFileW ReadFile GetTempFileNameW |
api-ms-win-core-file-l2-1-1.dll |
MoveFileExW
|
api-ms-win-core-console-l1-1-0.dll |
SetConsoleCtrlHandler
|
DNSAPI.dll |
DnsQuery_W
DnsFree |
api-ms-win-power-base-l1-1-0.dll |
GetPwrCapabilities
|
POWRPROF.dll |
PowerDeterminePlatformRole
|
api-ms-win-core-com-l1-1-1.dll (delay-loaded) |
IIDFromString
CoGetObjectContext CoTaskMemFree StringFromCLSID CoCreateInstance CoCreateGuid CoInitializeEx CoUninitialize StringFromIID CoFreeUnusedLibrariesEx |
Attributes | 0x1 |
---|---|
Name | api-ms-win-core-com-l1-1-1.dll |
ModuleHandle | 0xa76d0 |
DelayImportAddressTable | 0xa7000 |
DelayImportNameTable | 0xa1c10 |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x8ff64 |
Ordinal | 2 |
---|---|
Address | 0x1b80 |
Ordinal | 3 |
---|---|
Address | 0x90bc4 |
Ordinal | 4 |
---|---|
Address | 0x95390 |
Ordinal | 5 |
---|---|
Address | 0x90c88 |
Ordinal | 6 |
---|---|
Address | 0x90d14 |
Ordinal | 7 |
---|---|
Address | 0x59f8 |
Ordinal | 8 |
---|---|
Address | 0x90dc4 |
Ordinal | 9 |
---|---|
Address | 0xa6f0 |
Ordinal | 10 |
---|---|
Address | 0x4b724 |
Ordinal | 11 |
---|---|
Address | 0x954e0 |
Ordinal | 12 |
---|---|
Address | 0x90ea0 |
Ordinal | 13 |
---|---|
Address | 0x771b4 |
Ordinal | 14 |
---|---|
Address | 0x733f8 |
Ordinal | 15 |
---|---|
Address | 0x73534 |
Ordinal | 16 |
---|---|
Address | 0x74bfc |
Ordinal | 17 |
---|---|
Address | 0x3eb88 |
Ordinal | 18 |
---|---|
Address | 0x3e64c |
Ordinal | 19 |
---|---|
Address | 0x75818 |
Ordinal | 20 |
---|---|
Address | 0x2c90 |
Ordinal | 21 |
---|---|
Address | 0x74fc |
Ordinal | 22 |
---|---|
Address | 0xb508 |
Ordinal | 23 |
---|---|
Address | 0x76280 |
Ordinal | 24 |
---|---|
Address | 0x7651c |
Ordinal | 25 |
---|---|
Address | 0x76640 |
Ordinal | 26 |
---|---|
Address | 0x76740 |
Ordinal | 27 |
---|---|
Address | 0x8534 |
Ordinal | 28 |
---|---|
Address | 0x768cc |
Ordinal | 29 |
---|---|
Address | 0x42568 |
Ordinal | 30 |
---|---|
Address | 0x3e744 |
Ordinal | 31 |
---|---|
Address | 0x76aa8 |
Ordinal | 32 |
---|---|
Address | 0x48718 |
Ordinal | 33 |
---|---|
Address | 0x92118 |
Ordinal | 34 |
---|---|
Address | 0x910ec |
Ordinal | 35 |
---|---|
Address | 0x89790 |
Ordinal | 36 |
---|---|
Address | 0x93024 |
Ordinal | 37 |
---|---|
Address | 0x95004 |
Ordinal | 38 |
---|---|
Address | 0x930b0 |
Ordinal | 39 |
---|---|
Address | 0x9313c |
Ordinal | 40 |
---|---|
Address | 0x91128 |
Ordinal | 41 |
---|---|
Address | 0x911fc |
Ordinal | 42 |
---|---|
Address | 0x3db50 |
Ordinal | 43 |
---|---|
Address | 0x91310 |
Ordinal | 44 |
---|---|
Address | 0x91430 |
Ordinal | 45 |
---|---|
Address | 0x8e38 |
Ordinal | 46 |
---|---|
Address | 0x90140 |
Ordinal | 47 |
---|---|
Address | 0x86918 |
Ordinal | 48 |
---|---|
Address | 0x86974 |
Ordinal | 49 |
---|---|
Address | 0x87b00 |
Ordinal | 50 |
---|---|
Address | 0x1fdc |
Ordinal | 51 |
---|---|
Address | 0x1f00 |
Ordinal | 52 |
---|---|
Address | 0x95598 |
Ordinal | 53 |
---|---|
Address | 0x35b4 |
Ordinal | 54 |
---|---|
Address | 0x480c4 |
Ordinal | 55 |
---|---|
Address | 0x17f0 |
Ordinal | 56 |
---|---|
Address | 0x48acc |
Ordinal | 57 |
---|---|
Address | 0x956a4 |
Ordinal | 58 |
---|---|
Address | 0x956c8 |
Ordinal | 59 |
---|---|
Address | 0x956e0 |
Ordinal | 60 |
---|---|
Address | 0x95780 |
Ordinal | 61 |
---|---|
Address | 0x92d0 |
Ordinal | 62 |
---|---|
Address | 0x88da0 |
Ordinal | 63 |
---|---|
Address | 0x1a20 |
Ordinal | 64 |
---|---|
Address | 0x29f0 |
Ordinal | 65 |
---|---|
Address | 0x93228 |
Ordinal | 66 |
---|---|
Address | 0x45c54 |
Ordinal | 67 |
---|---|
Address | 0x914ac |
Ordinal | 68 |
---|---|
Address | 0x9331c |
Ordinal | 69 |
---|---|
Address | 0x950b8 |
Ordinal | 70 |
---|---|
Address | 0x93398 |
Ordinal | 71 |
---|---|
Address | 0x914e8 |
Ordinal | 72 |
---|---|
Address | 0x91570 |
Ordinal | 73 |
---|---|
Address | 0x8800 |
Ordinal | 74 |
---|---|
Address | 0x9514c |
Ordinal | 75 |
---|---|
Address | 0x9015c |
Ordinal | 76 |
---|---|
Address | 0x90198 |
Ordinal | 77 |
---|---|
Address | 0x917cc |
Ordinal | 78 |
---|---|
Address | 0x918a0 |
Ordinal | 79 |
---|---|
Address | 0x45f24 |
Ordinal | 80 |
---|---|
Address | 0x901d4 |
Ordinal | 81 |
---|---|
Address | 0x1190 |
Ordinal | 82 |
---|---|
Address | 0xedd0 |
Ordinal | 83 |
---|---|
Address | 0x1200 |
Ordinal | 84 |
---|---|
Address | 0x1320 |
Ordinal | 85 |
---|---|
Address | 0xee4c |
Ordinal | 86 |
---|---|
Address | 0x87b58 |
Ordinal | 87 |
---|---|
Address | 0x3ebd4 |
Ordinal | 88 |
---|---|
Address | 0x3e6ac |
Ordinal | 89 |
---|---|
Address | 0x9195c |
Ordinal | 90 |
---|---|
Address | 0x42350 |
Ordinal | 91 |
---|---|
Address | 0x9348c |
Ordinal | 92 |
---|---|
Address | 0xd40c |
Ordinal | 93 |
---|---|
Address | 0xa4a4 |
Ordinal | 94 |
---|---|
Address | 0x919ac |
Ordinal | 95 |
---|---|
Address | 0x91a7c |
Ordinal | 96 |
---|---|
Address | 0x90210 |
Ordinal | 97 |
---|---|
Address | 0x9024c |
Ordinal | 98 |
---|---|
Address | 0xebf4 |
Ordinal | 99 |
---|---|
Address | 0x902c8 |
Ordinal | 100 |
---|---|
Address | 0x4158 |
Ordinal | 101 |
---|---|
Address | 0x5c08 |
Ordinal | 102 |
---|---|
Address | 0x92154 |
Ordinal | 103 |
---|---|
Address | 0x2c30 |
Ordinal | 104 |
---|---|
Address | 0x90304 |
Ordinal | 105 |
---|---|
Address | 0x92dc4 |
Ordinal | 106 |
---|---|
Address | 0x41ed4 |
Ordinal | 107 |
---|---|
Address | 0x91ba0 |
Ordinal | 108 |
---|---|
Address | 0x91bd0 |
Ordinal | 109 |
---|---|
Address | 0x8f698 |
Ordinal | 110 |
---|---|
Address | 0x95a1c |
Ordinal | 111 |
---|---|
Address | 0x91e28 |
Ordinal | 112 |
---|---|
Address | 0x9120 |
Ordinal | 113 |
---|---|
Address | 0x90350 |
Ordinal | 114 |
---|---|
Address | 0xb59c |
Ordinal | 115 |
---|---|
Address | 0x7670 |
Ordinal | 116 |
---|---|
Address | 0x33f0 |
Ordinal | 117 |
---|---|
Address | 0x2e50 |
Ordinal | 118 |
---|---|
Address | 0xecb8 |
Ordinal | 119 |
---|---|
Address | 0x2030 |
Ordinal | 120 |
---|---|
Address | 0x48718 |
Ordinal | 121 |
---|---|
Address | 0x1db0 |
Ordinal | 122 |
---|---|
Address | 0x47bac |
Ordinal | 123 |
---|---|
Address | 0xb170 |
Ordinal | 124 |
---|---|
Address | 0x46214 |
Ordinal | 125 |
---|---|
Address | 0x1c80 |
Ordinal | 126 |
---|---|
Address | 0x1c80 |
Ordinal | 127 |
---|---|
Address | 0x1200 |
Ordinal | 128 |
---|---|
Address | 0x1200 |
Ordinal | 129 |
---|---|
Address | 0x2bf8 |
Ordinal | 130 |
---|---|
Address | 0x53b0 |
Ordinal | 131 |
---|---|
Address | 0x869fc |
Ordinal | 132 |
---|---|
Address | 0x86a7c |
Ordinal | 133 |
---|---|
Address | 0x91f38 |
Ordinal | 134 |
---|---|
Address | 0x4d3c |
Ordinal | 135 |
---|---|
Address | 0x9038c |
Ordinal | 136 |
---|---|
Address | 0x2980 |
Ordinal | 137 |
---|---|
Address | 0x3758 |
Ordinal | 138 |
---|---|
Address | 0x45e10 |
Ordinal | 139 |
---|---|
Address | 0x3db00 |
Ordinal | 140 |
---|---|
Address | 0x92198 |
Ordinal | 141 |
---|---|
Address | 0x874b0 |
Ordinal | 142 |
---|---|
Address | 0x874c8 |
Ordinal | 143 |
---|---|
Address | 0x921d0 |
Ordinal | 144 |
---|---|
Address | 0xee44 |
Ordinal | 145 |
---|---|
Address | 0x87ba8 |
Ordinal | 146 |
---|---|
Address | 0x87570 |
Ordinal | 147 |
---|---|
Address | 0x88f50 |
Ordinal | 148 |
---|---|
Address | 0x8905c |
Ordinal | 149 |
---|---|
Address | 0x3840 |
Ordinal | 150 |
---|---|
Address | 0x89558 |
Ordinal | 151 |
---|---|
Address | 0x920f0 |
Ordinal | 152 |
---|---|
Address | 0x41e70 |
Ordinal | 153 |
---|---|
Address | 0x1e60 |
Ordinal | 154 |
---|---|
Address | 0x9519c |
Ordinal | 155 |
---|---|
Address | 0x1c80 |
Ordinal | 156 |
---|---|
Address | 0x92e10 |
Ordinal | 157 |
---|---|
Address | 0x3700 |
Ordinal | 158 |
---|---|
Address | 0x672c |
Ordinal | 159 |
---|---|
Address | 0x91fb0 |
Ordinal | 160 |
---|---|
Address | 0x3ea0 |
Ordinal | 161 |
---|---|
Address | 0x3a80 |
Ordinal | 162 |
---|---|
Address | 0x1200 |
Ordinal | 163 |
---|---|
Address | 0x92e38 |
Ordinal | 164 |
---|---|
Address | 0x82d0 |
Ordinal | 165 |
---|---|
Address | 0x9200c |
Ordinal | 166 |
---|---|
Address | 0x423f0 |
Ordinal | 167 |
---|---|
Address | 0x89190 |
Ordinal | 168 |
---|---|
Address | 0x8fec8 |
Ordinal | 169 |
---|---|
Address | 0x8f728 |
Ordinal | 170 |
---|---|
Address | 0x9220c |
Ordinal | 171 |
---|---|
Address | 0x7864 |
Ordinal | 172 |
---|---|
Address | 0x92078 |
Ordinal | 173 |
---|---|
Address | 0x3eab0 |
Ordinal | 174 |
---|---|
Address | 0x936a8 |
Ordinal | 175 |
---|---|
Address | 0x90408 |
Ordinal | 176 |
---|---|
Address | 0x9274 |
Ordinal | 177 |
---|---|
Address | 0x8630 |
Ordinal | 178 |
---|---|
Address | 0x41ca0 |
Ordinal | 179 |
---|---|
Address | 0x3ef48 |
Ordinal | 180 |
---|---|
Address | 0x90444 |
Ordinal | 181 |
---|---|
Address | 0x10314 |
Ordinal | 182 |
---|---|
Address | 0x46110 |
Ordinal | 183 |
---|---|
Address | 0x5128 |
Ordinal | 184 |
---|---|
Address | 0xee9c |
Ordinal | 185 |
---|---|
Address | 0x92260 |
Ordinal | 186 |
---|---|
Address | 0x1ed0 |
Ordinal | 187 |
---|---|
Address | 0x7d00 |
Ordinal | 188 |
---|---|
Address | 0x1068c |
Ordinal | 189 |
---|---|
Address | 0x922e8 |
Ordinal | 190 |
---|---|
Address | 0xdcec |
Ordinal | 191 |
---|---|
Address | 0x923a8 |
Ordinal | 192 |
---|---|
Address | 0x88104 |
Ordinal | 193 |
---|---|
Address | 0x4c340 |
Ordinal | 194 |
---|---|
Address | 0x878c0 |
Ordinal | 195 |
---|---|
Address | 0x881f8 |
Ordinal | 196 |
---|---|
Address | 0x87f1c |
Ordinal | 197 |
---|---|
Address | 0x876c4 |
Ordinal | 198 |
---|---|
Address | 0x876d0 |
Ordinal | 199 |
---|---|
Address | 0x87780 |
Ordinal | 200 |
---|---|
Address | 0x877b0 |
Ordinal | 201 |
---|---|
Address | 0x87af0 |
Ordinal | 202 |
---|---|
Address | 0xb8e0 |
Ordinal | 203 |
---|---|
Address | 0x877bc |
Ordinal | 204 |
---|---|
Address | 0x42650 |
Ordinal | 205 |
---|---|
Address | 0x3e7a4 |
Ordinal | 206 |
---|---|
Address | 0x87bb0 |
Ordinal | 207 |
---|---|
Address | 0x1fa0 |
Ordinal | 208 |
---|---|
Address | 0x86be4 |
Ordinal | 209 |
---|---|
Address | 0x790c |
Ordinal | 210 |
---|---|
Address | 0x7a20 |
Ordinal | 211 |
---|---|
Address | 0x9074c |
Ordinal | 212 |
---|---|
Address | 0x1c54 |
Ordinal | 213 |
---|---|
Address | 0x92540 |
Ordinal | 214 |
---|---|
Address | 0x920b4 |
Ordinal | 215 |
---|---|
Address | 0x3df70 |
Ordinal | 216 |
---|---|
Address | 0x8350 |
Ordinal | 217 |
---|---|
Address | 0x8f6ec |
Ordinal | 218 |
---|---|
Address | 0x70684 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.3.9600.16384 |
ProductVersion | 6.3.9600.16384 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Spooler SubSystem App |
FileVersion (#2) | 6.3.9600.16384 (winblue_rtm.130821-1623) |
InternalName | spoolsv.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | spoolsv.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.3.9600.16384 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2013-Aug-22 09:10:08 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0xa20c0 |
PointerToRawData | 0xa14c0 |
Referenced File | spoolsv.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2013-Aug-22 09:10:08 |
Version | 565.30117 |
SizeofData | 8 |
AddressOfRawData | 0xa20b8 |
PointerToRawData | 0xa14b8 |
Size | 0x94 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x7ff6d88d76c8 |
XOR Key | 0x5d054d7f |
---|---|
Unmarked objects | 0 |
Imports (VS2008 SP1 build 30729) | 42 |
ASM objects (65501) | 1 |
C++ objects (65501) | 2 |
C objects (65501) | 24 |
Imports (65501) | 11 |
Total imports | 338 |
216 (65501) | 158 |
Exports (65501) | 1 |
Resource objects (65501) | 1 |
Linker (65501) | 1 |