Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2022-Nov-11 09:21:24 |
Detected languages |
English - United States
|
Debug artifacts |
H:\Travaux\VB_VAC\VoiceMeeter\Project\voicemeeterpro_vc2010\x64\Release\VoicemeeterRemote64.pdb
|
Comments | VB-AUDIO Voicemeeter Remote API. |
CompanyName | VB-AUDIO Software |
FileDescription | VB-AUDIO Audio Remote Interface for Voicemeeter |
FileVersion | 1, 0, 3, 8 |
InternalName | vbvmr |
LegalCopyright | V.BurelĀ©2015-2022 |
OriginalFilename | VoicemeeterRemote.dll |
ProductName | VoicemeeterRemote |
ProductVersion | 1, 0, 3, 8 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: BUREL VINCENT
Issuer: GlobalSign GCC R45 EV CodeSigning CA 2020 |
Safe | VirusTotal score: 0/71 (Scanned on 2025-01-30 07:30:12) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2022-Nov-11 09:21:24 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x1a200 |
SizeOfInitializedData | 0xfc00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000000000000F350 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x180000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x31000 |
SizeOfHeaders | 0x400 |
Checksum | 0x2f111 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
SETUPAPI.dll |
SetupDiGetDeviceInterfaceDetailW
SetupDiEnumDeviceInterfaces SetupDiGetDeviceRegistryPropertyA SetupDiGetDeviceInterfaceAlias SetupDiDestroyDeviceInfoList SetupDiGetDeviceRegistryPropertyW SetupDiGetClassDevsA SetupDiOpenDeviceInterfaceRegKey |
---|---|
WINMM.dll |
waveOutGetDevCapsW
timeEndPeriod waveInGetNumDevs timeBeginPeriod waveInGetDevCapsW waveOutGetNumDevs |
KERNEL32.dll |
SetFilePointer
WriteFile CreateFileW CloseHandle GetProcAddress GetModuleFileNameA GetModuleHandleA QueryPerformanceCounter GetCurrentThread SetThreadPriority QueryPerformanceFrequency FreeLibrary WaitForSingleObject CreateEventA LoadLibraryA DeviceIoControl MapViewOfFile UnmapViewOfFile GetTickCount CreateFileMappingA CreateThread InitializeCriticalSection LeaveCriticalSection EnterCriticalSection DeleteCriticalSection GetStringTypeW LCMapStringW LoadLibraryW FlushFileBuffers SetStdHandle GetConsoleMode GetConsoleCP GetSystemTimeAsFileTime GetCurrentProcessId GetEnvironmentStringsW FreeEnvironmentStringsW FlsAlloc SetLastError FlsFree FlsGetValue IsValidCodePage GetOEMCP GetACP GetCPInfo GetModuleFileNameW ExitProcess GetModuleHandleW HeapDestroy RtlVirtualUnwind HeapCreate GetVersion HeapSetInformation GetStartupInfoW GetFileType GetStdHandle SetHandleCount InitializeCriticalSectionAndSpinCount GetLastError Sleep GetCurrentProcess MultiByteToWideChar WideCharToMultiByte OpenFile WriteConsoleW IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter HeapFree HeapAlloc HeapReAlloc GetCurrentThreadId FlsSetValue GetCommandLineA OpenFileMappingA HeapSize RtlUnwindEx EncodePointer DecodePointer RtlCaptureContext RtlLookupFunctionEntry TerminateProcess |
USER32.dll |
CharLowerBuffA
|
ADVAPI32.dll |
RegEnumKeyW
RegOpenKeyW RegQueryValueExW RegCloseKey RegEnumKeyA RegOpenKeyA RegOpenKeyExW RegOpenKeyExA RegQueryValueExA |
SHELL32.dll |
ShellExecuteA
|
ole32.dll |
PropVariantClear
CoInitialize CoUninitialize CoCreateInstance CLSIDFromString CoTaskMemFree |
Ordinal | 1 |
---|---|
Address | 0xe160 |
Ordinal | 2 |
---|---|
Address | 0xe4d0 |
Ordinal | 3 |
---|---|
Address | 0xe480 |
Ordinal | 4 |
---|---|
Address | 0xe590 |
Ordinal | 5 |
---|---|
Address | 0xc140 |
Ordinal | 6 |
---|---|
Address | 0xc380 |
Ordinal | 7 |
---|---|
Address | 0xa4b0 |
Ordinal | 8 |
---|---|
Address | 0xc090 |
Ordinal | 9 |
---|---|
Address | 0xbd90 |
Ordinal | 10 |
---|---|
Address | 0x9fc0 |
Ordinal | 11 |
---|---|
Address | 0x9ff0 |
Ordinal | 12 |
---|---|
Address | 0xd6e0 |
Ordinal | 13 |
---|---|
Address | 0xd7b0 |
Ordinal | 14 |
---|---|
Address | 0xd6c0 |
Ordinal | 15 |
---|---|
Address | 0xa440 |
Ordinal | 16 |
---|---|
Address | 0x9f20 |
Ordinal | 17 |
---|---|
Address | 0x9f30 |
Ordinal | 18 |
---|---|
Address | 0xa310 |
Ordinal | 19 |
---|---|
Address | 0xa2a0 |
Ordinal | 20 |
---|---|
Address | 0xa3a0 |
Ordinal | 21 |
---|---|
Address | 0xd680 |
Ordinal | 22 |
---|---|
Address | 0xd6a0 |
Ordinal | 23 |
---|---|
Address | 0xce50 |
Ordinal | 24 |
---|---|
Address | 0xa020 |
Ordinal | 25 |
---|---|
Address | 0xc400 |
Ordinal | 26 |
---|---|
Address | 0xc470 |
Ordinal | 27 |
---|---|
Address | 0xc690 |
Ordinal | 28 |
---|---|
Address | 0xc530 |
Ordinal | 29 |
---|---|
Address | 0xcd80 |
Ordinal | 30 |
---|---|
Address | 0xcd70 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.3.8 |
ProductVersion | 1.0.3.8 |
FileFlags | (EMPTY) |
FileOs | (EMPTY) |
FileType |
VFT_APP
|
Language | UNKNOWN |
Comments | VB-AUDIO Voicemeeter Remote API. |
CompanyName | VB-AUDIO Software |
FileDescription | VB-AUDIO Audio Remote Interface for Voicemeeter |
FileVersion (#2) | 1, 0, 3, 8 |
InternalName | vbvmr |
LegalCopyright | V.BurelĀ©2015-2022 |
OriginalFilename | VoicemeeterRemote.dll |
ProductName | VoicemeeterRemote |
ProductVersion (#2) | 1, 0, 3, 8 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2022-Nov-11 09:21:24 |
Version | 0.0 |
SizeofData | 120 |
AddressOfRawData | 0x1e5a4 |
PointerToRawData | 0x1cba4 |
Referenced File | H:\Travaux\VB_VAC\VoiceMeeter\Project\voicemeeterpro_vc2010\x64\Release\VoicemeeterRemote64.pdb |
XOR Key | 0xcdcb9885 |
---|---|
Unmarked objects | 0 |
C++ objects (VS2010 SP1 build 40219) | 37 |
C objects (VS2010 SP1 build 40219) | 123 |
ASM objects (VS2010 SP1 build 40219) | 11 |
C++ objects (VS2008 SP1 build 30729) | 1 |
C objects (VS2008 SP1 build 30729) | 1 |
Imports (VS2008 SP1 build 30729) | 19 |
Total imports | 211 |
175 (VS2010 SP1 build 40219) | 16 |
Exports (VS2010 SP1 build 40219) | 1 |
Resource objects (VS2010 SP1 build 40219) | 1 |
Linker (VS2010 SP1 build 40219) | 1 |