Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2018-Sep-11 01:30:02 |
Detected languages |
English - United States
|
CompanyName | uWebb Software |
FileDescription | ThrottleStop |
FileVersion | 8.7.0.2 |
InternalName | ThrottleStop |
LegalCopyright | Copyright (C) 2018 |
OriginalFilename | ThrottleStop.EXE |
ProductName | ThrottleStop |
ProductVersion | 8.7.0.2 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: TechPowerUp LLC
Issuer: DigiCert SHA2 High Assurance Code Signing CA |
Safe | VirusTotal score: 0/69 (Scanned on 2018-10-02 20:10:04) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x118 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2018-Sep-11 01:30:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 12.0 |
SizeOfCode | 0x34600 |
SizeOfInitializedData | 0x3c800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000327D1 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x36000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.0 |
ImageVersion | 0.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x75000 |
SizeOfHeaders | 0x400 |
Checksum | 0x7841e |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
WinRing0.dll |
#83
#53 #23 #8 #7 #1 #22 #56 #21 |
---|---|
WINMM.dll |
timeBeginPeriod
timeGetDevCaps timeEndPeriod |
PSAPI.DLL |
EnumProcesses
EnumProcessModules GetModuleBaseNameW |
POWRPROF.dll |
CallNtPowerInformation
|
UxTheme.dll |
SetWindowTheme
|
mfc120u.dll |
#4109
#9279 #14454 #7806 #14448 #12412 #12413 #2444 #10260 #5262 #8206 #4546 #12736 #12799 #10314 #12122 #8268 #1467 #7542 #8352 #1177 #1437 #265 #266 #2343 #2347 #1648 #4280 #5019 #8064 #11965 #14180 #2967 #285 #1684 #1687 #1682 #1685 #5824 #4620 #4047 #12755 #14277 #14271 #8638 #8639 #2435 #8346 #970 #14537 #1444 #5796 #11847 #2857 #358 #12958 #4128 #887 #1386 #4842 #3764 #8655 #13991 #12899 #14094 #4442 #10919 #2130 #6492 #13516 #5574 #7946 #4182 #7951 #9013 #5887 #6731 #3212 #3321 #1428 #3761 #6402 #10895 #8920 #5865 #6128 #501 #1140 #4050 #6219 #509 #4051 #365 #4048 #6726 #3204 #3320 #13761 #290 #10618 #6853 #12818 #7825 #1992 #11858 #11857 #14326 #12402 #7884 #14526 #6251 #14528 #6253 #14527 #6252 #992 #6758 #3809 #5821 #12114 #8099 #12126 #12094 #5667 #10131 #6389 #2262 #9582 #9258 #5324 #1065 #362 #1105 #4606 #13907 #13153 #13149 #450 #3911 #2478 #6462 #6392 #3839 #2480 #6469 #3773 #8242 #8601 #12455 #2948 #1518 #5787 #4984 #2173 #9009 #1067 #3829 #2951 #8626 #4179 #3105 #6400 #7382 #12006 #6121 #13612 #2718 #9091 #12047 #1108 #8921 #10896 #11271 #10353 #4049 #458 #3361 #3362 #3122 #6434 #6032 #6123 #13616 #3263 #3260 #10136 #8092 #2719 #10166 #10168 #10167 #10165 #10169 #5557 #11600 #11601 #9020 #11964 #3795 #3790 #11811 #14447 #8846 #12095 #6875 #10309 #9349 #10883 #9137 #3224 #13738 #12134 #12132 #1711 #1723 #1731 #1727 #1736 #4879 #4920 #4887 #4899 #4895 #4891 #4928 #4916 #4883 #4932 #4905 #4867 #4874 #4909 #4459 #5693 #9574 #4451 #3013 #14449 #7807 #14455 #14367 #8636 #6774 #13404 #4434 #11592 #8699 #13563 #5838 #13997 #5327 #2640 #11999 #3898 #3329 #3330 #3223 #12043 #4843 #999 #5157 #5454 #5664 #9231 #5430 #5160 #5316 #5137 #7609 #7610 #7600 #5314 #8101 #9090 #3654 #3650 #3754 #3653 #3762 #2204 #4772 #12634 #1520 #1042 #286 #280 #296 #1658 #1506 #1508 #4621 #2367 |
MSVCR120.dll |
__crtTerminateProcess
__crtUnhandledException _crt_debugger_hook _controlfp_s _invoke_watson __crtSetUnhandledExceptionFilter _except_handler4_common _except1 _onexit __dllonexit _calloc_crt _unlock _lock ?terminate@@YAXXZ _commode _fmode __CxxFrameHandler3 _wcmdln _initterm _initterm_e __setusermatherr _configthreadlocale _cexit _exit __set_app_type __wgetmainargs _amsg_exit __crtGetShowWindowMode _XcptFilter sqrt fabs _time64 _localtime64_s malloc free exit wcsftime _snwprintf wcscpy memcpy memset wcstol ??1type_info@@UAE@XZ |
KERNEL32.dll |
GlobalAddAtomW
FormatMessageW GlobalDeleteAtom LocalFree OutputDebugStringW GetPrivateProfileIntW IsProcessorFeaturePresent IsDebuggerPresent GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId EncodePointer LoadLibraryA DeleteCriticalSection InitializeCriticalSectionEx DecodePointer ChangeTimerQueueTimer LoadLibraryW GetPrivateProfileStringW LocalAlloc GetProcAddress GetModuleHandleW FreeLibrary DeleteTimerQueueTimer CreateTimerQueueTimer GetSystemPowerStatus GetTickCount SetPriorityClass SetThreadPriority DeviceIoControl QueryPerformanceFrequency QueryPerformanceCounter GetLastError GetFullPathNameW Sleep GetCurrentProcess GetCurrentThread GetModuleFileNameW GetProcessAffinityMask SetThreadAffinityMask WritePrivateProfileStringW MulDiv CloseHandle OpenProcess CreateDirectoryW CreateFileW GetFileAttributesW |
USER32.dll |
InflateRect
ShowWindow SetForegroundWindow MessageBoxW FindWindowW RegisterWindowMessageW RegisterHotKey UnregisterHotKey PostQuitMessage SetWindowPos IsWindowVisible IsIconic GetKeyState GetSystemMenu CreatePopupMenu DestroyMenu InsertMenuW CopyRect RemoveMenu TrackPopupMenu DrawIcon DrawTextW GetDC ReleaseDC InvalidateRect GetClientRect GetCursorPos FillRect DestroyIcon CreateIconIndirect MonitorFromWindow GetMonitorInfoW LoadBitmapW GetWindowTextW GetSystemMetrics LoadIconW GetWindowRect OffsetRect EnableWindow KillTimer SetTimer ReleaseCapture GetFocus PostMessageW AppendMenuW SendMessageW SetCapture |
GDI32.dll |
SetTextColor
SetBkMode SelectObject PatBlt DeleteObject DeleteDC CreateFontIndirectW CreateCompatibleDC CreateCompatibleBitmap CreateBitmap GetDeviceCaps CreateFontW CreateSolidBrush |
ADVAPI32.dll |
AddAccessAllowedAce
SetSecurityInfo StartServiceW OpenServiceW OpenSCManagerW DeleteService CreateServiceW ControlService CloseServiceHandle InitializeAcl GetLengthSid CreateWellKnownSid |
SHELL32.dll |
SHGetPathFromIDListW
Shell_NotifyIconW ShellExecuteW SHBrowseForFolderW |
ole32.dll |
CLSIDFromString
CoCreateGuid |
&About... |
Open |
Save As |
All Files (*.*) |
Untitled |
an unnamed file |
&Hide |
No error message is available. |
Attempted an unsupported operation. |
A required resource was unavailable. |
Out of memory. |
An unknown error has occurred. |
Encountered an improper argument. |
Incorrect filename. |
Failed to open document. |
Failed to save document. |
Save changes to %1? |
Failed to create empty document. |
The file is too large to open. |
Could not start print job. |
Failed to launch help. |
Internal application error. |
Command failed. |
Insufficient memory to perform operation. |
System registry entries have been removed and the INI file (if any) was deleted. |
Not all of the system registry entries (or INI file) were removed. |
This program requires the file %s, which was not found on this system. |
This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
Enter an integer. |
Enter a number. |
Enter an integer between %1 and %2. |
Enter a number between %1 and %2. |
Enter no more than %1 characters. |
Select a button. |
Enter an integer between 0 and 255. |
Enter a positive integer. |
Enter a date and/or time. |
Enter a currency. |
Enter a GUID. |
Enter a time. |
Enter a date. |
Unexpected file format. |
%1 |
Cannot find this file. |
Verify that the correct path and file name are given. |
Destination disk drive is full. |
Unable to read from %1, it is opened by someone else. |
Unable to write to %1, it is read-only or opened by someone else. |
Encountered an unexpected error while reading %1. |
Encountered an unexpected error while writing %1. |
%1: %2 |
Continue running script? |
Dispatch exception: %1 |
Unable to read write-only property. |
Unable to write read-only property. |
Unable to load mail system support. |
Mail system DLL is invalid. |
Send Mail failed to send message. |
No error occurred. |
An unknown error occurred while accessing %1. |
%1 was not found. |
%1 contains an incorrect path. |
Could not open %1 because there are too many open files. |
Access to %1 was denied. |
An incorrect file handle was associated with %1. |
Could not remove %1 because it is the current directory. |
Could not create %1 because the directory is full. |
Seek failed on %1 |
Encountered a hardware I/O error while accessing %1. |
Encountered a sharing violation while accessing %1. |
Encountered a locking violation while accessing %1. |
Disk full while accessing %1. |
Attempted to access %1 past its end. |
No error occurred. |
An unknown error occurred while accessing %1. |
Attempted to write to the reading %1. |
Attempted to access %1 past its end. |
Attempted to read from the writing %1. |
%1 has a bad format. |
%1 contained an unexpected object. |
%1 contains an incorrect schema. |
pixels |
Uncheck |
Check |
Mixed |
One or more auto-saved documents were found. |
These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
Do you want to recover these auto-saved documents? |
Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
Recover the auto-saved documents |
Open the auto-saved versions instead of the explicitly saved versions |
Don't recover the auto-saved documents |
Use the last explicitly saved versions of the documents |
%s [Recovered] |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 8.7.0.2 |
ProductVersion | 8.7.0.2 |
FileFlags |
VS_FF_SPECIALBUILD
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | uWebb Software |
FileDescription | ThrottleStop |
FileVersion (#2) | 8.7.0.2 |
InternalName | ThrottleStop |
LegalCopyright | Copyright (C) 2018 |
OriginalFilename | ThrottleStop.EXE |
ProductName | ThrottleStop |
ProductVersion (#2) | 8.7.0.2 |
Resource LangID | English - United States |
---|
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x443420 |
SEHandlerTable | 0x43f490 |
SEHandlerCount | 86 |
XOR Key | 0xae4f23b5 |
---|---|
Unmarked objects | 0 |
221 (VS2013 build 21005) | 2 |
ASM objects (VS2013 build 21005) | 7 |
C objects (VS2013 build 21005) | 20 |
C++ objects (VS2013 build 21005) | 5 |
C++ objects (20806) | 5 |
221 (20806) | 2 |
ASM objects (VS2003 (.NET) build 3077) | 1 |
Imports (65501) | 22 |
Imports (VS2012 build 50727 / VS2005 build 50727) | 3 |
Total imports | 494 |
C++ objects (VS2013 UPD4 build 31101) | 12 |
Resource objects (VS2013 build 21005) | 1 |
Linker (VS2013 UPD4 build 31101) | 1 |