| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2018-Jan-03 23:26:54 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\dvs\p4\build\sw\rel\gpu_drv\r390\r390_63\drivers\Monterey\NvFBCPlugin\_out\wddm2_amd64_release\NvFBCPlugin64.pdb
|
| CompanyName | NVIDIA Corporation |
| FileDescription | NVIDIA Frame Buffer Capture Library - Concurrency Manager Plugin, Version |
| FileVersion | 6.14.13.9065 |
| InternalName | NvFBCPlugin |
| LegalCopyright | (C) 2018 NVIDIA Corporation. All rights reserved. |
| OriginalFilename | NvFBCPlugin.dll |
| ProductName | NVIDIA Frame Buffer Capture Library |
| ProductVersion | 6.14.13.9065 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: NVIDIA Corporation
Issuer: VeriSign Class 3 Code Signing 2010 CA |
| Safe | VirusTotal score: 0/71 (Scanned on 2024-04-22 12:08:21) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2018-Jan-03 23:26:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 12.0 |
| SizeOfCode | 0x96200 |
| SizeOfInitializedData | 0x46200 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000006BA9C (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xe1000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xe2b99 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
LocalAlloc
CreateMutexA DeleteCriticalSection ReleaseMutex GetCurrentProcessId LocalFree SetEvent CreateEventA WaitForMultipleObjects OpenEventA GetFullPathNameW lstrcmpA FreeLibrary CreateProcessW LoadLibraryExW VerSetConditionMask OutputDebugStringW EnterCriticalSection InitializeCriticalSection GetFileAttributesW CreateProcessA CreateFileW VerifyVersionInfoW SetLastError GetProcAddress Sleep GetStringTypeW EnumSystemLocalesW GetUserDefaultLCID IsValidLocale GetLocaleInfoW LCMapStringW CompareStringW GetTimeFormatW GetDateFormatW GetModuleHandleW LeaveCriticalSection HeapReAlloc FlushFileBuffers GetModuleHandleA GetEnvironmentVariableA FileTimeToSystemTime GetSystemTimeAsFileTime OpenFileMappingA CloseHandle OutputDebugStringA QueryPerformanceFrequency QueryFullProcessImageNameA CreateFileMappingA GetLastError OpenProcess WaitForSingleObject QueryPerformanceCounter UnmapViewOfFile GetSystemDirectoryW MapViewOfFile SetEndOfFile WriteConsoleW SetStdHandle SetConsoleCtrlHandler HeapFree HeapAlloc IsDebuggerPresent IsProcessorFeaturePresent AreFileApisANSI MultiByteToWideChar ReadFile EncodePointer DecodePointer CreateThread ExitThread ResumeThread GetCommandLineA GetCurrentThreadId GetProcessHeap ExitProcess GetModuleHandleExW WideCharToMultiByte GetStdHandle WriteFile GetModuleFileNameW RtlUnwindEx RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter InitializeCriticalSectionAndSpinCount CreateEventW GetCurrentProcess TerminateProcess TlsAlloc TlsGetValue TlsSetValue TlsFree GetStartupInfoW GetTickCount CreateSemaphoreW GetConsoleCP GetConsoleMode MoveFileExW GetCurrentThread DeleteFileW CreateDirectoryW GetFileType SetFilePointerEx ReadConsoleW HeapSize RtlPcToFileHeader RaiseException IsValidCodePage GetACP GetOEMCP GetCPInfo GetModuleFileNameA GetEnvironmentStringsW FreeEnvironmentStringsW FatalAppExitA |
|---|---|
| USER32.dll |
DefWindowProcA
GetDesktopWindow EnumDisplayDevicesA CreateWindowExA DestroyWindow UnregisterDeviceNotification RegisterDeviceNotificationA RegisterClassA |
| GDI32.dll |
CreateDCA
|
| d3d9.dll |
Direct3DCreate9Ex
|
| ADVAPI32.dll |
BuildExplicitAccessWithNameA
SetSecurityInfo GetSecurityInfo LookupAccountSidA SetEntriesInAclA OpenProcessToken EventUnregister EventRegister EventWrite RegGetValueA RegCloseKey ConvertStringSecurityDescriptorToSecurityDescriptorA RegOpenKeyExA RegQueryValueExW RegQueryValueExA CreateWellKnownSid |
| SHELL32.dll |
SHGetFolderPathW
|
| SHLWAPI.dll |
PathFileExistsW
|
| Ordinal | 1 |
|---|---|
| Address | 0x6160 |
| Ordinal | 2 |
|---|---|
| Address | 0x6240 |
| Ordinal | 3 |
|---|---|
| Address | 0x6150 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.14.13.9065 |
| ProductVersion | 6.14.13.9065 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | NVIDIA Corporation |
| FileDescription | NVIDIA Frame Buffer Capture Library - Concurrency Manager Plugin, Version |
| FileVersion (#2) | 6.14.13.9065 |
| InternalName | NvFBCPlugin |
| LegalCopyright | (C) 2018 NVIDIA Corporation. All rights reserved. |
| OriginalFilename | NvFBCPlugin.dll |
| ProductName | NVIDIA Frame Buffer Capture Library |
| ProductVersion (#2) | 6.14.13.9065 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-03 23:26:54 |
| Version | 0.0 |
| SizeofData | 140 |
| AddressOfRawData | 0xa2f40 |
| PointerToRawData | 0xa1540 |
| Referenced File | C:\dvs\p4\build\sw\rel\gpu_drv\r390\r390_63\drivers\Monterey\NvFBCPlugin\_out\wddm2_amd64_release\NvFBCPlugin64.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2018-Jan-03 23:26:54 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xa2fcc |
| PointerToRawData | 0xa15cc |
| Size | 0x70 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1800c2170 |
| XOR Key | 0x5127913f |
|---|---|
| Unmarked objects | 0 |
| 199 (41118) | 1 |
| C++ objects (20806) | 50 |
| C objects (20806) | 147 |
| ASM objects (20806) | 13 |
| Imports (VS2017 v15.?.? build 25203) | 15 |
| Total imports | 146 |
| 229 (VS2013 UPD2 build 30501) | 12 |
| Exports (VS2013 UPD2 build 30501) | 1 |
| Resource objects (VS2013 build 21005) | 1 |
| Linker (VS2013 UPD2 build 30501) | 1 |
No comments yet.