| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-23 21:12:12 |
| Detected languages |
English - United States
|
| Debug artifacts |
app.pdb
|
| CompanyName | microsoft |
| FileDescription | WindowsAudioSvc |
| FileVersion | 0.1.0 |
| ProductName | WindowsAudioSvc |
| ProductVersion | 0.1.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses constants related to SHA256 Uses constants related to RC5 or RC6 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .taubndl |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-08-23 22:02:05) | All the AVs think this file is safe. |
| MD5 | 57676e300a2a1212e592ed9f98e7e07a 🔍 |
|---|---|
| SHA1 | ddeb11c8e8187661182d092c0441a2bbe178c8cb 🔍 |
| SHA256 | e36ec50b3b2f36f74f6594e0e54925ec1e2ce0e7497e855c1a3229c3062d05f3 🔍 |
| SHA3 | 183bb0defb51fe2a6a019dc7d8db24261f4ab09d1901bc4102ed67915574cfc4 🔍 |
| SSDeep | 98304:egOyNvV+XpHqFUTrSaOUX83eiQbGstIVg+53L1V/MtUKJIJ3+et/UtfN:egaXpHqFUTrSaOUX8A47127 🔍 |
| Imports Hash | 6fbd76e39135f751e10bcc0cbd5a3d76 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Aug-23 21:12:12 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x879e00 |
| SizeOfInitializedData | 0x410600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000008521E0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc8f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e51c66f759ea7cd30bacdee42e630c01 🔍 |
|---|---|
| SHA1 | 9a8dcb1b9e59f3fbd6e614cc37b8a472c554aacd 🔍 |
| SHA256 | 8605c9d28d6a497a3fe7c5aceb6244a344525ca7b564b90c7ce2bae01992eec6 🔍 |
| SHA3 | 4785f88629adec76b616f4b4cf6741739bacd52b00ba5978fbe408303d9978fb 🔍 |
| VirtualSize | 0x879d60 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x879e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.20638 |
| MD5 | e9358bf9289c5822b209459ceb445197 🔍 |
|---|---|
| SHA1 | fc5febe399cb2021eacdceafff6c5c2160d54cb3 🔍 |
| SHA256 | 2fcac367466b7365fd316931d200a254892ddbf9774efff938cd681f2d969ce6 🔍 |
| SHA3 | e56b8bde2cf72951a179988e3e26191c5a09597e82001137c4b0e1f7506974f0 🔍 |
| VirtualSize | 0x3894c6 |
| VirtualAddress | 0x87b000 |
| SizeOfRawData | 0x389600 |
| PointerToRawData | 0x87a200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.15314 |
| MD5 | fdf5f332f0ecebf8e92f352ee16911f2 🔍 |
|---|---|
| SHA1 | 628e0fdb04bc31dd6c59e95ae1ede401c238503a 🔍 |
| SHA256 | 635d6971df206cee32a109b467d3fbd274b0ce285d1eaafb916dbb3055d83927 🔍 |
| SHA3 | 06098aadba8245d058b56b6f36a875889c5dd2d2b728426291343050734bf753 🔍 |
| VirtualSize | 0x6448 |
| VirtualAddress | 0xc05000 |
| SizeOfRawData | 0x3a00 |
| PointerToRawData | 0xc03800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 3.16883 |
| MD5 | df12d13937021641df3fe6700b1fc097 🔍 |
|---|---|
| SHA1 | 4aa2f497aa061a5c07fe3a6116f18db3c94fbe65 🔍 |
| SHA256 | 8a8f01d1d103addaf9d8a78e6b4d0fc270b00bb46077adf0cf99510c5812c1eb 🔍 |
| SHA3 | cd74ec2a814785068a39c40247887f0ec6144d1a54efa5f5399ffe836e5d8ba6 🔍 |
| VirtualSize | 0x77db4 |
| VirtualAddress | 0xc0c000 |
| SizeOfRawData | 0x77e00 |
| PointerToRawData | 0xc07200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.56539 |
| MD5 | 1114e7baf8c73897216dc5a8a88449bf 🔍 |
|---|---|
| SHA1 | f7a17f4a09f28b58a8879fa5380fd43ecfc0e636 🔍 |
| SHA256 | 55437f725701d5212b5dab1c56ec7ff678647626c51abde9c3044f694f2873f5 🔍 |
| SHA3 | f66324d728cb98818710f4764f17f52a5ed6490df693548302fd38fe9a2233f3 🔍 |
| VirtualSize | 0x10 |
| VirtualAddress | 0xc84000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0xc7f000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0.122276 |
| MD5 | ef7b013cbd11fb481ba267f9a5eff4ed 🔍 |
|---|---|
| SHA1 | abe5d407c7de91f5dd20e0b1e2aa99fe17531ced 🔍 |
| SHA256 | 1bb227a7aff494c49733234321158e8e1a15ff24e623f89712573eab2e9f0dab 🔍 |
| SHA3 | 86deeb444c8b2cb7658799b16a7ca01e0d7258ea41be3a102eb0a00c6e4a8da7 🔍 |
| VirtualSize | 0x1538 |
| VirtualAddress | 0xc85000 |
| SizeOfRawData | 0x1600 |
| PointerToRawData | 0xc7f200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.78794 |
| MD5 | eba691fd0dd97d5cd3adf8586207265c 🔍 |
|---|---|
| SHA1 | 1751c7afb62bca8237c5cff5d4dd6ea684cdc4a6 🔍 |
| SHA256 | 13d631a67c8612d055aa2c8baf9bf4c02c48ce28871825035e99e7cc5aa30bdd 🔍 |
| SHA3 | 1d2265e4467283ec18a6a9fad68bd27f7718faae53b24639d499036047b3472d 🔍 |
| VirtualSize | 0x72b4 |
| VirtualAddress | 0xc87000 |
| SizeOfRawData | 0x7400 |
| PointerToRawData | 0xc80800 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.45003 |
| KERNEL32.dll |
GetCurrentThreadId
GetModuleHandleW GetUserDefaultUILanguage LCIDToLocaleName SetPriorityClass TlsSetValue TlsGetValue TlsAlloc InitializeCriticalSectionAndSpinCount EncodePointer Process32FirstW RtlPcToFileHeader RtlUnwindEx IsDebuggerPresent InitializeSListHead GetSystemTimeAsFileTime SleepConditionVariableSRW WakeAllConditionVariable AcquireSRWLockExclusive ReleaseSRWLockExclusive IsProcessorFeaturePresent SetUnhandledExceptionFilter UnhandledExceptionFilter Process32NextW CreateToolhelp32Snapshot GetExitCodeProcess OpenProcess RaiseException CloseHandle TlsFree |
|---|---|
| kernel32.dll |
SetFileCompletionNotificationModes
PostQueuedCompletionStatus GetProcessHeap CreateFileW GetQueuedCompletionStatusEx GetProcAddress GetFileAttributesW GetEnvironmentVariableW FindNextFileW QueryPerformanceFrequency GetTempPathW WaitForMultipleObjects IsThreadAFiber FlsSetValue GetModuleHandleExW FlsAlloc FlsFree HeapAlloc CreateWaitableTimerExW GetConsoleOutputCP WriteConsoleW MultiByteToWideChar SetEnvironmentVariableW DeleteFileW GetFileInformationByHandle LoadLibraryW HeapFree GetFinalPathNameByHandleW ReleaseMutex CreateMutexA WaitForSingleObjectEx WideCharToMultiByte SwitchToThread GetSystemInfo ExitProcess FindClose FindFirstFileExW GetCommandLineW GetCurrentDirectoryW WaitForSingleObject SetThreadStackGuarantee AddVectoredExceptionHandler SetFilePointerEx CreateDirectoryW GetEnvironmentStringsW TerminateProcess GetProcessId CreateProcessW GetWindowsDirectoryW GetSystemDirectoryW GetFileInformationByHandleEx SetFileTime CancelIo GetSystemTimePreciseAsFileTime lstrlenW RtlVirtualUnwind GetCurrentProcess DuplicateHandle SetHandleInformation GetConsoleMode Sleep GetModuleHandleA OutputDebugStringA OutputDebugStringW GetModuleFileNameW LoadLibraryExW FreeLibrary RtlLookupFunctionEntry GetLastError RtlCaptureContext WriteFileEx SleepEx ReadFileEx GetCurrentProcessId CreateEventW CreateThread QueryPerformanceCounter HeapReAlloc GetStdHandle SetFileInformationByHandle MoveFileExW GetFullPathNameW GetCurrentThread ReadFile SetLastError LoadLibraryA DeleteCriticalSection FreeEnvironmentStringsW LoadLibraryExA GetOverlappedResult FormatMessageW SetWaitableTimer CompareStringOrdinal CreateIoCompletionPort GetTimeZoneInformationForYear |
| advapi32.dll |
RegCloseKey
SystemFunction036 RegOpenKeyExW RegQueryValueExW |
| shell32.dll |
SHGetKnownFolderPath
DragFinish DragQueryFileW SHAppBarMessage IsUserAnAdmin ShellExecuteW SHCreateItemFromParsingName |
| comctl32.dll |
SetWindowSubclass
RemoveWindowSubclass DefSubclassProc TaskDialogIndirect |
| shlwapi.dll |
SHCreateMemStream
|
| ole32.dll |
CoUninitialize
CoCreateInstance OleInitialize RegisterDragDrop RevokeDragDrop CoTaskMemAlloc CoCreateFreeThreadedMarshaler CoInitializeEx |
| combase.dll |
CoTaskMemFree
|
| secur32.dll |
FreeContextBuffer
AcceptSecurityContext EncryptMessage DecryptMessage QueryContextAttributesW ApplyControlToken InitializeSecurityContextW FreeCredentialsHandle AcquireCredentialsHandleA DeleteSecurityContext |
| crypt32.dll |
CertDuplicateStore
CertFreeCertificateChain CertEnumCertificatesInStore CertAddCertificateContextToStore CertVerifyCertificateChainPolicy CertOpenStore CertDuplicateCertificateChain CertFreeCertificateContext CertDuplicateCertificateContext CertGetCertificateChain CertCloseStore |
| bcrypt.dll |
BCryptGenRandom
|
| bcryptprimitives.dll |
ProcessPrng
|
| ntdll.dll |
NtDeviceIoControlFile
RtlGetVersion NtWriteFile NtCreateFile NtReadFile NtCreateNamedPipeFile NtOpenFile NtCancelIoFileEx RtlNtStatusToDosError |
| user32.dll |
GetMessageW
GetWindowThreadProcessId GetWindowTextW FlashWindowEx TranslateMessage IsWindowVisible PostMessageW EnumWindows DestroyWindow DrawTextW GetWindowTextLengthW OffsetRect GetMenuBarInfo DestroyMenu TrackPopupMenu PostQuitMessage SetMenu RemoveMenu AppendMenuW InsertMenuW DrawIconEx CheckMenuItem SetMenuItemInfoW CreateAcceleratorTableW DestroyAcceleratorTable DrawMenuBar GetMenuItemInfoW CreatePopupMenu CreateMenu GetAsyncKeyState MapVirtualKeyW PostThreadMessageW GetKeyboardState GetMenu CreateIcon MapVirtualKeyExW GetKeyboardLayout ToUnicodeEx GetKeyState SystemParametersInfoA SetPropW SendInput SetForegroundWindow SetWindowTextW ClipCursor GetClipCursor ShowCursor SetWindowLongW EnableMenuItem GetSystemMenu EnumDisplayMonitors MonitorFromPoint SetWindowDisplayAffinity GetRawInputData DestroyIcon ReleaseCapture SetCapture MsgWaitForMultipleObjectsEx RegisterRawInputDevices DispatchMessageW GetWindowDC RedrawWindow DefWindowProcW RegisterWindowMessageA GetWindow SetParent ChangeDisplaySettingsExW MapWindowPoints SetFocus ShowWindow PeekMessageW SetWindowPlacement ReleaseDC EnableWindow IsWindowEnabled IsProcessDPIAware GetDC GetWindowRect SetWindowLongPtrW GetParent GetWindowLongPtrW FindWindowExW SetWindowRgn GetForegroundWindow GetActiveWindow UpdateWindow InvalidateRect SetCursorPos AdjustWindowRect CloseTouchInputHandle GetTouchInputInfo TrackMouseEvent SystemParametersInfoW FillRect GetMonitorInfoW MonitorFromRect MonitorFromWindow GetCursorPos ClientToScreen GetClientRect GetWindowLongW ScreenToClient GetUpdateRect ValidateRect RegisterTouchWindow GetSystemMetrics IsWindow AdjustWindowRectEx IsIconic SendMessageW EnumChildWindows DispatchMessageA GetMessageA CreateWindowExW RegisterClassExW TranslateAcceleratorW SetCursor LoadCursorW InvalidateRgn SetWindowPos GetWindowPlacement |
| api-ms-win-core-synch-l1-2-0.dll |
WaitOnAddress
WakeByAddressSingle WakeByAddressAll |
| gdi32.dll |
CreateRectRgn
CreateCompatibleDC DeleteObject CreateDIBSection SelectObject SetBkMode SetTextColor BitBlt CombineRgn GetDeviceCaps DeleteDC CreateSolidBrush |
| dwmapi.dll |
DwmGetWindowAttribute
DwmEnableBlurBehindWindow DwmSetWindowAttribute |
| oleaut32.dll |
SysStringLen
SysFreeString SetErrorInfo GetErrorInfo |
| ADVAPI32.dll |
EventRegister
EventWriteTransfer EventUnregister RegGetValueW EventSetInformation |
| ws2_32.dll |
WSAStartup
WSACleanup freeaddrinfo setsockopt getaddrinfo closesocket getpeername getsockname getsockopt WSAGetLastError WSASend ioctlsocket connect recv send WSASocketW bind shutdown WSAIoctl |
| api-ms-win-crt-math-l1-1-0.dll |
round
trunc ceil __setusermatherr pow roundf floor |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_callnewh _set_new_mode free calloc |
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
_configure_narrow_argv __p___argv _initialize_onexit_table __p___argc _register_onexit_function _set_app_type _crt_atexit _seh_filter_exe terminate _exit exit abort _initterm_e _initterm _register_thread_local_exe_atexit_callback _get_initial_narrow_environment _wassert _initialize_narrow_environment _cexit |
| api-ms-win-crt-string-l1-1-0.dll |
strcmp
wcslen _wcsicmp wcscmp strcpy_s wcsncat wcsncmp strlen |
| api-ms-win-crt-convert-l1-1-0.dll |
wcstol
_wtoi _ultow_s |
| api-ms-win-crt-stdio-l1-1-0.dll |
__p__commode
_set_fmode |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Type |
RT_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x10a8 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 5.78038 |
| MD5 | 1b7d6c18537e00b103c3e8e6d5b125e5 🔍 |
| SHA1 | b5bc2f21404b477103b88b98e20cfb3864e76011 🔍 |
| SHA256 | 8675f5a9128679c4b5900ed109b88a71e39e00d16e12e4bb0db5bf3d7ed2c5b5 🔍 |
| SHA3 | 186e5d2b435268466f2f483dfc35416480a705ffed5ca153c62bc5c1de9846bb 🔍 |
| Type |
RT_GROUP_ICON
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 1.7815 |
| Detected Filetype | Icon file |
| MD5 | 3c68f77c35c26ff079a1c410ee44fa62 🔍 |
| SHA1 | 0b40150c95fc2c6414c90d44ee78b8d8814b3393 🔍 |
| SHA256 | a14e70ed824f3f17d3a51136aa08839954d6d3ccadaa067415c7bfc08e6636b0 🔍 |
| SHA3 | 590dcbf2ec3f485a6c24e3e627f383ee7588eb49978321f12c07d8190a6c1396 🔍 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x1f4 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.1823 |
| MD5 | da2ff670189c9e27e14a4d9483ed5d37 🔍 |
| SHA1 | 394892349d801090afbd7a8d1cdb4d654a287889 🔍 |
| SHA256 | 0e3e5c5b51a992fb6661649b7d25aefc2069ca1673c852b87a90323669e1095d 🔍 |
| SHA3 | 4734294cb9e5f7f8e51a5d9d9da1f5b6d16b81aa21dbf6279b2b0684b0341b8e 🔍 |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x14e |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.96056 |
| MD5 | 01e4c8c046a47771f13cd120b53303e7 🔍 |
| SHA1 | 2a4224d31c916a5cff4f2636a3cb47fdd84a5cc9 🔍 |
| SHA256 | b1cb832f790c153aa0e9a66f76e75460263cf1d41971d2dbcc9a4d87ec18b7d8 🔍 |
| SHA3 | 680120ec819e7ba66519d9a8a3e446973c4cb28aa0146c91cceaa8c8fadc90ae 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 0.1.0.0 |
| ProductVersion | 0.1.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| CompanyName | microsoft |
| FileDescription | WindowsAudioSvc |
| FileVersion (#2) | 0.1.0 |
| ProductName | WindowsAudioSvc |
| ProductVersion (#2) | 0.1.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-23 21:12:12 |
| Version | 0.0 |
| SizeofData | 32 |
| AddressOfRawData | 0xa2117c |
| PointerToRawData | 0xa2037c |
| Referenced File | app.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-23 21:12:12 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0xa2119c |
| PointerToRawData | 0xa2039c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-23 21:12:12 |
| Version | 0.0 |
| SizeofData | 1048 |
| AddressOfRawData | 0xa211b0 |
| PointerToRawData | 0xa203b0 |
| StartAddressOfRawData | 0x140a21610 |
|---|---|
| EndAddressOfRawData | 0x140a21810 |
| AddressOfIndex | 0x140c0b2b0 |
| AddressOfCallbacks | 0x14087bdb8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140c087c0 |
| XOR Key | 0x834d48c1 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 14 |
| ASM objects (35207) | 9 |
| C objects (35207) | 13 |
| C++ objects (35207) | 47 |
| C objects (35228) | 84 |
| Imports (33145) | 5 |
| Total imports | 521 |
| Unmarked objects (#2) | 552 |
| Resource objects (35228) | 1 |
| Linker (35228) | 1 |
No comments yet.