| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2037-Jun-18 20:15:49 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
D:\dbs\sh\odct\0905_112315_0\client\onedrive\Product\StandaloneUpdater\exe\obj\amd64\OneDriveStandaloneUpdater.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Standalone Updater |
| InternalName | OneDriveStandaloneUpdater.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | OneDriveStandaloneUpdater.exe |
| ProductName | Microsoft OneDrive |
| FileVersion | 24.166.0818.0003 |
| ProductVersion | 24.166.0818.0003 |
| SpecialBuild | b/build/84e690d0-e12e-e41c-50fb-a841e09085a1 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Tries to detect virtualized environments:
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010 |
| Safe | VirusTotal score: 0/74 (Scanned on 2024-09-06 08:15:53) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x130 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2037-Jun-18 20:15:49 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x2de800 |
| SizeOfInitializedData | 0x128a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000036380 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x40d000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x40f86f |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
ExitProcess
GetModuleFileNameW GetStdHandle WriteFile FindFirstFileExW IsValidCodePage GetACP GetOEMCP GetCPInfo GetCommandLineA MultiByteToWideChar WideCharToMultiByte GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW FlsAlloc FlsGetValue FlsSetValue FlsFree GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType SetStdHandle GetStringTypeW GetTimeZoneInformation FlushFileBuffers GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx ReadFile ReadConsoleW CreateFileW WriteConsoleW LoadLibraryExW TlsFree TlsSetValue TlsGetValue TlsAlloc EncodePointer SetLastError InterlockedPushEntrySList RtlUnwindEx RtlPcToFileHeader CompareFileTime FindClose FindNextFileW FindFirstFileW GetFileAttributesExW RemoveDirectoryW Process32NextW OpenProcess Process32FirstW CreateToolhelp32Snapshot LocalFree OpenMutexW FileTimeToSystemTime FileTimeToLocalFileTime IsWow64Process GetTickCount64 GetVolumePathNameW Sleep GetCommandLineW GetModuleHandleExW FreeLibrary GetEnvironmentVariableW InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter TerminateProcess GetCurrentProcess IsProcessorFeaturePresent GetStartupInfoW SetUnhandledExceptionFilter UnhandledExceptionFilter GetProcAddress GetModuleHandleW CreateEventW WaitForSingleObjectEx ResetEvent SetEvent InitializeCriticalSectionAndSpinCount CloseHandle LeaveCriticalSection EnterCriticalSection RaiseException OutputDebugStringW IsDebuggerPresent SystemTimeToTzSpecificLocalTime PeekNamedPipe GetDriveTypeW FreeLibraryAndExitThread DeleteCriticalSection InitializeCriticalSectionEx GetProcessHeap HeapSize HeapFree HeapReAlloc HeapAlloc HeapDestroy ResumeThread ExitThread CreateThread RtlUnwind LoadLibraryExA VirtualQuery VirtualProtect InitializeCriticalSection HeapCreate GetDiskFreeSpaceW LockFile GetFullPathNameA UnmapViewOfFile HeapValidate GetTempPathA FormatMessageW GetDiskFreeSpaceA GetFileAttributesA FlushViewOfFile CreateFileA LoadLibraryA DeleteFileA GetSystemInfo HeapCompact UnlockFile CreateFileMappingW MapViewOfFile GetSystemPowerStatus GetModuleFileNameA OutputDebugStringA CompareStringEx LCMapStringEx InitOnceExecuteOnce CreateHardLinkW AreFileApisANSI SetEndOfFile GetCurrentDirectoryW GetLocaleInfoEx AcquireSRWLockShared ReleaseSRWLockShared SleepConditionVariableSRW SleepConditionVariableCS WakeAllConditionVariable WakeConditionVariable InitializeConditionVariable GetNativeSystemInfo GetExitCodeThread SwitchToThread TryEnterCriticalSection AcquireSRWLockExclusive ReleaseSRWLockExclusive InitializeSRWLock FormatMessageA QueryPerformanceFrequency GetDllDirectoryW CreateEventExW GetLastError DecodePointer DeleteFileW GetSystemTime LocalAlloc CreateDirectoryW GetFullPathNameW GetTempFileNameW SetFileTime GetTempPathW CopyFileW MoveFileExW SystemTimeToFileTime LockFileEx UnlockFileEx DeviceIoControl LoadLibraryW WerRegisterFile WerUnregisterFile GetTickCount K32GetModuleFileNameExW WaitForSingleObject WaitForMultipleObjects QueueUserWorkItem CreateMutexW GetVersionExW MoveFileW LCIDToLocaleName GetUserGeoID GetUserDefaultLocaleName GetComputerNameW ReleaseMutex FindFirstVolumeW FindNextVolumeW FindVolumeClose GetDiskFreeSpaceExW GetFileAttributesW GetFileInformationByHandle GetFileSize GetFinalPathNameByHandleW GetLongPathNameW SetFileAttributesW SetFileInformationByHandle SetFilePointer GetCompressedFileSizeW FindFirstFileNameW SetHandleInformation CreatePipe CreateIoCompletionPort GetQueuedCompletionStatus PostQueuedCompletionStatus GlobalAlloc GlobalUnlock GlobalLock GlobalFree ReadDirectoryChangesW CreateSymbolicLinkW CompareStringOrdinal GetPrivateProfileStringW WritePrivateProfileStringW SetDllDirectoryW ReplaceFileW RegisterApplicationRestart GetFileInformationByHandleEx OpenFileById GetProcessTimes GetExitCodeProcess CreateProcessW SetProcessShutdownParameters GetSystemTimes SetThreadInformation GetProductInfo VerifyVersionInfoW ReadProcessMemory ExpandEnvironmentStringsW WaitForMultipleObjectsEx |
|---|---|
| USER32.dll |
TranslateMessage
DispatchMessageW RegisterPowerSettingNotification UnregisterPowerSettingNotification RegisterClassW CreateWindowExW DestroyWindow ShowWindow OpenClipboard CloseClipboard SetClipboardData GetMessageW SendMessageTimeoutW PeekMessageW PostQuitMessage MsgWaitForMultipleObjectsEx SetCursor LoadCursorW PostThreadMessageW GetWindowThreadProcessId GetClassNameW EnumWindows PostMessageW RegisterClipboardFormatW SystemParametersInfoW |
| OLEAUT32.dll |
SetErrorInfo
GetErrorInfo GetRecordInfoFromTypeInfo LoadRegTypeLib LoadTypeLib VarBstrCmp VariantChangeType VariantClear VariantInit SysAllocStringByteLen SysStringByteLen SysStringLen SysAllocStringLen SysAllocString SysFreeString |
| ntdll.dll |
RtlLookupFunctionEntry
RtlCaptureContext VerSetConditionMask RtlVirtualUnwind |
| SHLWAPI.dll |
PathIsDirectoryW
SHSetValueW SHRegGetValueW SHRegGetPathW PathRemoveFileSpecW AssocQueryStringW StrStrIW PathIsPrefixW #219 PathFileExistsW SHCreateStreamOnFileEx PathIsRelativeW PathFindFileNameW PathStripPathW SHCreateStreamOnFileW SHGetValueA SHGetValueW SHRegGetUSValueW PathIsDirectoryEmptyW SHDeleteKeyW SHRegGetBoolUSValueW SHDeleteValueW |
| VERSION.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
| USERENV.dll |
GetProfileType
GetDefaultUserProfileDirectoryW CreateEnvironmentBlock |
| ADVAPI32.dll |
OpenProcessToken
EventUnregister EventWriteTransfer GetUserNameW RegOpenKeyExW RegQueryValueExW RegCloseKey RegCreateKeyExW RegSetValueExW GetTokenInformation RegGetValueA CreateProcessAsUserW CreateProcessWithTokenW SetFileSecurityW ConvertStringSecurityDescriptorToSecurityDescriptorW GetNamedSecurityInfoW StartServiceW StartServiceCtrlDispatcherW SetServiceStatus RegisterServiceCtrlHandlerW QueryServiceStatusEx QueryServiceStatus QueryServiceConfigW OpenServiceW OpenSCManagerW DeleteService CreateServiceW ControlService CryptAcquireContextW CryptReleaseContext CryptGetHashParam CryptCreateHash CryptHashData CryptDestroyHash AdjustTokenPrivileges AllocateAndInitializeSid FreeSid LookupPrivilegeValueW SetEntriesInAclW SetNamedSecurityInfoW ImpersonateLoggedOnUser RevertToSelf RegDeleteValueW RegEnumKeyExW RegEnumValueW RegQueryInfoKeyW RegSetKeyValueW RegGetValueW LookupAccountNameW CryptDestroyKey CryptSetHashParam CryptImportKey CreateWellKnownSid DuplicateTokenEx GetAclInformation RegCreateKeyTransactedW RegDeleteKeyExW RegEnumKeyW RegLoadKeyW RegUnLoadKeyW RegDeleteTreeW ChangeServiceConfigW ChangeServiceConfig2W CloseServiceHandle ConvertSidToStringSidW EventRegister |
| SHELL32.dll |
ShellExecuteExW
SHGetFolderPathAndSubDirW SHCreateDirectoryExW SHGetSpecialFolderPathW CommandLineToArgvW SHCreateItemFromParsingName SHParseDisplayName SHChangeNotify SHFileOperationW SHLoadNonloadedIconOverlayIdentifiers SHGetKnownFolderPath SHGetFolderPathW SHSetKnownFolderPath SHAssocEnumHandlers #526 |
| ole32.dll |
CoSetProxyBlanket
CreateBindCtx CoWaitForMultipleHandles CoInitialize CLSIDFromString StringFromCLSID CoTaskMemAlloc StringFromGUID2 CoCreateInstance CoInitializeEx CoUninitialize CoCreateGuid CreateItemMoniker GetRunningObjectTable CoTaskMemFree CoCreateFreeThreadedMarshaler |
| WINHTTP.dll |
WinHttpConnect
WinHttpCrackUrl WinHttpGetIEProxyConfigForCurrentUser WinHttpGetProxyForUrl WinHttpSetCredentials WinHttpSetOption WinHttpQueryHeaders WinHttpReceiveResponse WinHttpSendRequest WinHttpOpen WinHttpQueryDataAvailable WinHttpReadData WinHttpOpenRequest WinHttpCloseHandle |
| RstrtMgr.DLL |
RmRegisterResources
RmGetList RmEndSession RmStartSession |
| WINTRUST.dll |
WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData WinVerifyTrustEx |
| WTSAPI32.dll |
WTSQueryUserToken
WTSEnumerateSessionsW WTSFreeMemory WTSQuerySessionInformationW |
| bcrypt.dll |
BCryptGenerateSymmetricKey
BCryptCloseAlgorithmProvider BCryptEncrypt BCryptGenRandom BCryptSetProperty BCryptDestroyKey BCryptOpenAlgorithmProvider |
| CRYPT32.dll |
CertVerifyCertificateChainPolicy
CertFindExtension CryptStringToBinaryW CryptBinaryToStringW CertFreeCertificateChain |
| RPCRT4.dll |
RpcBindingSetAuthInfoExW
RpcStringFreeW UuidToStringW RpcExceptionFilter RpcBindingFree RpcBindingFromStringBindingW RpcBindingVectorFree RpcEpRegisterW RpcStringBindingComposeW RpcEpUnregister RpcServerInqCallAttributesW RpcServerInqBindings RpcServerRegisterIfEx RpcServerUnregisterIf RpcServerUseProtseqW |
| Secur32.dll |
GetUserNameExW
|
| urlmon.dll |
URLOpenStreamW
|
| WININET.dll |
InternetCloseHandle
InternetSetStatusCallbackW HttpOpenRequestA HttpAddRequestHeadersA InternetReadFile HttpSendRequestW HttpQueryInfoA InternetQueryOptionW InternetOpenW InternetCrackUrlA InternetConnectA InternetCheckConnectionW |
| WS2_32.dll |
listen
closesocket htonl htons socket WSAStartup WSAGetLastError bind send accept setsockopt |
| IPHLPAPI.DLL |
GetAdaptersInfo
|
| api-ms-win-core-winrt-string-l1-1-0.dll (delay-loaded) |
WindowsCreateString
WindowsDeleteString WindowsCreateStringReference |
| Attributes | 0x1 |
|---|---|
| Name | api-ms-win-core-winrt-string-l1-1-0.dll |
| ModuleHandle | 0x3e6268 |
| DelayImportAddressTable | 0x404028 |
| DelayImportNameTable | 0x3b73a0 |
| BoundDelayImportTable | 0x3b7460 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x3e5800 |
| Ordinal | 2 |
|---|---|
| Address | 0x15ffb0 |
| Ordinal | 3 |
|---|---|
| Address | 0x15ffb0 |
| Ordinal | 4 |
|---|---|
| Address | 0x15ffc0 |
| Ordinal | 5 |
|---|---|
| Address | 0x15ffc0 |
| Ordinal | 6 |
|---|---|
| Address | 0x15ffd0 |
| Ordinal | 7 |
|---|---|
| Address | 0x160090 |
| Ordinal | 8 |
|---|---|
| Address | 0x91d80 |
| Ordinal | 9 |
|---|---|
| Address | 0x167a40 |
| Ordinal | 10 |
|---|---|
| Address | 0x167a90 |
| Ordinal | 11 |
|---|---|
| Address | 0x167ac0 |
| Ordinal | 12 |
|---|---|
| Address | 0x167b10 |
| Ordinal | 13 |
|---|---|
| Address | 0x167c10 |
| Ordinal | 14 |
|---|---|
| Address | 0x167c70 |
| Ordinal | 15 |
|---|---|
| Address | 0x16ce00 |
| Ordinal | 16 |
|---|---|
| Address | 0x16ce50 |
| Ordinal | 17 |
|---|---|
| Address | 0x16cec0 |
| Ordinal | 18 |
|---|---|
| Address | 0x16cf30 |
| Ordinal | 19 |
|---|---|
| Address | 0x16cfa0 |
| Ordinal | 20 |
|---|---|
| Address | 0x16ce00 |
| Ordinal | 21 |
|---|---|
| Address | 0x16d010 |
| Ordinal | 22 |
|---|---|
| Address | 0x16d090 |
| Ordinal | 23 |
|---|---|
| Address | 0x16d0c0 |
| Ordinal | 24 |
|---|---|
| Address | 0x16d0f0 |
| Ordinal | 25 |
|---|---|
| Address | 0x16d120 |
| Ordinal | 26 |
|---|---|
| Address | 0x16d150 |
| Ordinal | 27 |
|---|---|
| Address | 0x16d180 |
| Ordinal | 28 |
|---|---|
| Address | 0x16d150 |
| Ordinal | 29 |
|---|---|
| Address | 0x16d1b0 |
| Ordinal | 30 |
|---|---|
| Address | 0x16d1e0 |
| Ordinal | 31 |
|---|---|
| Address | 0x16d270 |
| Ordinal | 32 |
|---|---|
| Address | 0x16d2b0 |
| Ordinal | 33 |
|---|---|
| Address | 0x16d2e0 |
| Ordinal | 34 |
|---|---|
| Address | 0x16d350 |
| Ordinal | 35 |
|---|---|
| Address | 0x16d350 |
| Ordinal | 36 |
|---|---|
| Address | 0x16d380 |
| Ordinal | 37 |
|---|---|
| Address | 0x16d3a0 |
| Ordinal | 38 |
|---|---|
| Address | 0x16d3e0 |
| Ordinal | 39 |
|---|---|
| Address | 0x16d420 |
| Ordinal | 40 |
|---|---|
| Address | 0x16d500 |
| Ordinal | 41 |
|---|---|
| Address | 0x16d5e0 |
| Ordinal | 42 |
|---|---|
| Address | 0x16d650 |
| Ordinal | 43 |
|---|---|
| Address | 0x160100 |
| Ordinal | 44 |
|---|---|
| Address | 0x160100 |
| Ordinal | 45 |
|---|---|
| Address | 0x160110 |
| Ordinal | 46 |
|---|---|
| Address | 0x1601b0 |
| Ordinal | 47 |
|---|---|
| Address | 0x16a8b0 |
| Ordinal | 48 |
|---|---|
| Address | 0x91f10 |
| Ordinal | 49 |
|---|---|
| Address | 0x160200 |
| Ordinal | 50 |
|---|---|
| Address | 0x160200 |
| Ordinal | 51 |
|---|---|
| Address | 0x160200 |
| Ordinal | 52 |
|---|---|
| Address | 0x160210 |
| Ordinal | 53 |
|---|---|
| Address | 0x160210 |
| Ordinal | 54 |
|---|---|
| Address | 0x160240 |
| Ordinal | 55 |
|---|---|
| Address | 0x160240 |
| Ordinal | 56 |
|---|---|
| Address | 0x160250 |
| Ordinal | 57 |
|---|---|
| Address | 0x160250 |
| Ordinal | 58 |
|---|---|
| Address | 0x160260 |
| Ordinal | 59 |
|---|---|
| Address | 0x160260 |
| Ordinal | 60 |
|---|---|
| Address | 0x160270 |
| Ordinal | 61 |
|---|---|
| Address | 0x160370 |
| Ordinal | 62 |
|---|---|
| Address | 0x160430 |
| Ordinal | 63 |
|---|---|
| Address | 0x160ea0 |
| Ordinal | 64 |
|---|---|
| Address | 0x16d660 |
| Ordinal | 65 |
|---|---|
| Address | 0x16d680 |
| Ordinal | 66 |
|---|---|
| Address | 0x16d690 |
| Ordinal | 67 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 68 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 69 |
|---|---|
| Address | 0x93240 |
| Ordinal | 70 |
|---|---|
| Address | 0x168030 |
| Ordinal | 71 |
|---|---|
| Address | 0x16d6d0 |
| Ordinal | 72 |
|---|---|
| Address | 0x160820 |
| Ordinal | 73 |
|---|---|
| Address | 0xa48b0 |
| Ordinal | 74 |
|---|---|
| Address | 0x160830 |
| Ordinal | 75 |
|---|---|
| Address | 0x160860 |
| Ordinal | 76 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 77 |
|---|---|
| Address | 0x160870 |
| Ordinal | 78 |
|---|---|
| Address | 0x160880 |
| Ordinal | 79 |
|---|---|
| Address | 0x17420 |
| Ordinal | 80 |
|---|---|
| Address | 0x17420 |
| Ordinal | 81 |
|---|---|
| Address | 0x160b30 |
| Ordinal | 82 |
|---|---|
| Address | 0x160be0 |
| Ordinal | 83 |
|---|---|
| Address | 0x168160 |
| Ordinal | 84 |
|---|---|
| Address | 0x168180 |
| Ordinal | 85 |
|---|---|
| Address | 0x1681c0 |
| Ordinal | 86 |
|---|---|
| Address | 0x16d6e0 |
| Ordinal | 87 |
|---|---|
| Address | 0x16d720 |
| Ordinal | 88 |
|---|---|
| Address | 0x16d7a0 |
| Ordinal | 89 |
|---|---|
| Address | 0x16d800 |
| Ordinal | 90 |
|---|---|
| Address | 0x16d860 |
| Ordinal | 91 |
|---|---|
| Address | 0x16d8c0 |
| Ordinal | 92 |
|---|---|
| Address | 0x16d920 |
| Ordinal | 93 |
|---|---|
| Address | 0x16d930 |
| Ordinal | 94 |
|---|---|
| Address | 0x16d940 |
| Ordinal | 95 |
|---|---|
| Address | 0x16d950 |
| Ordinal | 96 |
|---|---|
| Address | 0x16d960 |
| Ordinal | 97 |
|---|---|
| Address | 0x16d970 |
| Ordinal | 98 |
|---|---|
| Address | 0x16d960 |
| Ordinal | 99 |
|---|---|
| Address | 0x16d980 |
| Ordinal | 100 |
|---|---|
| Address | 0x16d9b0 |
| Ordinal | 101 |
|---|---|
| Address | 0x16da10 |
| Ordinal | 102 |
|---|---|
| Address | 0x16da50 |
| Ordinal | 103 |
|---|---|
| Address | 0x16da90 |
| Ordinal | 104 |
|---|---|
| Address | 0x16dac0 |
| Ordinal | 105 |
|---|---|
| Address | 0x16dad0 |
| Ordinal | 106 |
|---|---|
| Address | 0x160c70 |
| Ordinal | 107 |
|---|---|
| Address | 0x17420 |
| Ordinal | 108 |
|---|---|
| Address | 0x160c80 |
| Ordinal | 109 |
|---|---|
| Address | 0x160d10 |
| Ordinal | 110 |
|---|---|
| Address | 0x17420 |
| Ordinal | 111 |
|---|---|
| Address | 0x17420 |
| Ordinal | 112 |
|---|---|
| Address | 0x17420 |
| Ordinal | 113 |
|---|---|
| Address | 0x17420 |
| Ordinal | 114 |
|---|---|
| Address | 0x17420 |
| Ordinal | 115 |
|---|---|
| Address | 0x17420 |
| Ordinal | 116 |
|---|---|
| Address | 0x160d80 |
| Ordinal | 117 |
|---|---|
| Address | 0x160e10 |
| Ordinal | 118 |
|---|---|
| Address | 0x17420 |
| Ordinal | 119 |
|---|---|
| Address | 0x17420 |
| Ordinal | 120 |
|---|---|
| Address | 0x160ea0 |
| Ordinal | 121 |
|---|---|
| Address | 0x16db00 |
| Ordinal | 122 |
|---|---|
| Address | 0x16e020 |
| Ordinal | 123 |
|---|---|
| Address | 0x16a940 |
| Ordinal | 124 |
|---|---|
| Address | 0x17420 |
| Ordinal | 125 |
|---|---|
| Address | 0x16e070 |
| Ordinal | 126 |
|---|---|
| Address | 0x1683a0 |
| Ordinal | 127 |
|---|---|
| Address | 0x2f51d0 |
| Ordinal | 128 |
|---|---|
| Address | 0x2f6348 |
| Ordinal | 129 |
|---|---|
| Address | 0x2f51e8 |
| Ordinal | 130 |
|---|---|
| Address | 0x3315b0 |
| Ordinal | 131 |
|---|---|
| Address | 0x331cd0 |
| Ordinal | 132 |
|---|---|
| Address | 0x330d08 |
| Ordinal | 133 |
|---|---|
| Address | 0x330d50 |
| Ordinal | 134 |
|---|---|
| Address | 0x330f30 |
| Ordinal | 135 |
|---|---|
| Address | 0x330f18 |
| Ordinal | 136 |
|---|---|
| Address | 0x330db8 |
| Ordinal | 137 |
|---|---|
| Address | 0x330bb0 |
| Ordinal | 138 |
|---|---|
| Address | 0x330870 |
| Ordinal | 139 |
|---|---|
| Address | 0x3308a0 |
| Ordinal | 140 |
|---|---|
| Address | 0x166720 |
| Ordinal | 141 |
|---|---|
| Address | 0x16a9f0 |
| Ordinal | 142 |
|---|---|
| Address | 0x1667d0 |
| Ordinal | 143 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 144 |
|---|---|
| Address | 0x1614f0 |
| Ordinal | 145 |
|---|---|
| Address | 0x161500 |
| Ordinal | 146 |
|---|---|
| Address | 0x161510 |
| Ordinal | 147 |
|---|---|
| Address | 0x82430 |
| Ordinal | 148 |
|---|---|
| Address | 0x161620 |
| Ordinal | 149 |
|---|---|
| Address | 0x166870 |
| Ordinal | 150 |
|---|---|
| Address | 0x1668f0 |
| Ordinal | 151 |
|---|---|
| Address | 0x182c50 |
| Ordinal | 152 |
|---|---|
| Address | 0x179ed0 |
| Ordinal | 153 |
|---|---|
| Address | 0x17a090 |
| Ordinal | 154 |
|---|---|
| Address | 0x16b090 |
| Ordinal | 155 |
|---|---|
| Address | 0x16b0d0 |
| Ordinal | 156 |
|---|---|
| Address | 0x82440 |
| Ordinal | 157 |
|---|---|
| Address | 0x82450 |
| Ordinal | 158 |
|---|---|
| Address | 0x17a480 |
| Ordinal | 159 |
|---|---|
| Address | 0x82460 |
| Ordinal | 160 |
|---|---|
| Address | 0x824d0 |
| Ordinal | 161 |
|---|---|
| Address | 0x8e9c0 |
| Ordinal | 162 |
|---|---|
| Address | 0x168580 |
| Ordinal | 163 |
|---|---|
| Address | 0xa85c0 |
| Ordinal | 164 |
|---|---|
| Address | 0xa5da0 |
| Ordinal | 165 |
|---|---|
| Address | 0x16aac0 |
| Ordinal | 166 |
|---|---|
| Address | 0x16ad10 |
| Ordinal | 167 |
|---|---|
| Address | 0x82c10 |
| Ordinal | 168 |
|---|---|
| Address | 0x168590 |
| Ordinal | 169 |
|---|---|
| Address | 0x1685a0 |
| Ordinal | 170 |
|---|---|
| Address | 0x168810 |
| Ordinal | 171 |
|---|---|
| Address | 0x168820 |
| Ordinal | 172 |
|---|---|
| Address | 0x168580 |
| Ordinal | 173 |
|---|---|
| Address | 0x168830 |
| Ordinal | 174 |
|---|---|
| Address | 0x825f0 |
| Ordinal | 175 |
|---|---|
| Address | 0x82610 |
| Ordinal | 176 |
|---|---|
| Address | 0x168850 |
| Ordinal | 177 |
|---|---|
| Address | 0x168860 |
| Ordinal | 178 |
|---|---|
| Address | 0x16ad20 |
| Ordinal | 179 |
|---|---|
| Address | 0x16e250 |
| Ordinal | 180 |
|---|---|
| Address | 0x82640 |
| Ordinal | 181 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 182 |
|---|---|
| Address | 0x82650 |
| Ordinal | 183 |
|---|---|
| Address | 0x82660 |
| Ordinal | 184 |
|---|---|
| Address | 0x16b190 |
| Ordinal | 185 |
|---|---|
| Address | 0x16b1c0 |
| Ordinal | 186 |
|---|---|
| Address | 0x166ab0 |
| Ordinal | 187 |
|---|---|
| Address | 0x82670 |
| Ordinal | 188 |
|---|---|
| Address | 0x161630 |
| Ordinal | 189 |
|---|---|
| Address | 0x161720 |
| Ordinal | 190 |
|---|---|
| Address | 0x161820 |
| Ordinal | 191 |
|---|---|
| Address | 0x161910 |
| Ordinal | 192 |
|---|---|
| Address | 0x161a00 |
| Ordinal | 193 |
|---|---|
| Address | 0x161af0 |
| Ordinal | 194 |
|---|---|
| Address | 0x161be0 |
| Ordinal | 195 |
|---|---|
| Address | 0x161cd0 |
| Ordinal | 196 |
|---|---|
| Address | 0x82680 |
| Ordinal | 197 |
|---|---|
| Address | 0x161dc0 |
| Ordinal | 198 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 199 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 200 |
|---|---|
| Address | 0x161eb0 |
| Ordinal | 201 |
|---|---|
| Address | 0x161fa0 |
| Ordinal | 202 |
|---|---|
| Address | 0x162090 |
| Ordinal | 203 |
|---|---|
| Address | 0x162180 |
| Ordinal | 204 |
|---|---|
| Address | 0x162270 |
| Ordinal | 205 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 206 |
|---|---|
| Address | 0x168870 |
| Ordinal | 207 |
|---|---|
| Address | 0x162360 |
| Ordinal | 208 |
|---|---|
| Address | 0x168880 |
| Ordinal | 209 |
|---|---|
| Address | 0x162420 |
| Ordinal | 210 |
|---|---|
| Address | 0x162550 |
| Ordinal | 211 |
|---|---|
| Address | 0x162640 |
| Ordinal | 212 |
|---|---|
| Address | 0x162770 |
| Ordinal | 213 |
|---|---|
| Address | 0x162860 |
| Ordinal | 214 |
|---|---|
| Address | 0x162950 |
| Ordinal | 215 |
|---|---|
| Address | 0x1689c0 |
| Ordinal | 216 |
|---|---|
| Address | 0x1689d0 |
| Ordinal | 217 |
|---|---|
| Address | 0x1689e0 |
| Ordinal | 218 |
|---|---|
| Address | 0x1689f0 |
| Ordinal | 219 |
|---|---|
| Address | 0x168a30 |
| Ordinal | 220 |
|---|---|
| Address | 0x168a80 |
| Ordinal | 221 |
|---|---|
| Address | 0x168ad0 |
| Ordinal | 222 |
|---|---|
| Address | 0x168b20 |
| Ordinal | 223 |
|---|---|
| Address | 0x168b70 |
| Ordinal | 224 |
|---|---|
| Address | 0x162a40 |
| Ordinal | 225 |
|---|---|
| Address | 0x162a50 |
| Ordinal | 226 |
|---|---|
| Address | 0x162a60 |
| Ordinal | 227 |
|---|---|
| Address | 0x162a70 |
| Ordinal | 228 |
|---|---|
| Address | 0x162a80 |
| Ordinal | 229 |
|---|---|
| Address | 0x162a90 |
| Ordinal | 230 |
|---|---|
| Address | 0x168bc0 |
| Ordinal | 231 |
|---|---|
| Address | 0x168c10 |
| Ordinal | 232 |
|---|---|
| Address | 0x168c60 |
| Ordinal | 233 |
|---|---|
| Address | 0x168d60 |
| Ordinal | 234 |
|---|---|
| Address | 0x168db0 |
| Ordinal | 235 |
|---|---|
| Address | 0x168e10 |
| Ordinal | 236 |
|---|---|
| Address | 0x162aa0 |
| Ordinal | 237 |
|---|---|
| Address | 0x168e60 |
| Ordinal | 238 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 239 |
|---|---|
| Address | 0x168eb0 |
| Ordinal | 240 |
|---|---|
| Address | 0x168ec0 |
| Ordinal | 241 |
|---|---|
| Address | 0x162ab0 |
| Ordinal | 242 |
|---|---|
| Address | 0x162ba0 |
| Ordinal | 243 |
|---|---|
| Address | 0x162c90 |
| Ordinal | 244 |
|---|---|
| Address | 0x162d70 |
| Ordinal | 245 |
|---|---|
| Address | 0x162e60 |
| Ordinal | 246 |
|---|---|
| Address | 0x162f50 |
| Ordinal | 247 |
|---|---|
| Address | 0x18ea0 |
| Ordinal | 248 |
|---|---|
| Address | 0x24d70 |
| Ordinal | 249 |
|---|---|
| Address | 0x169060 |
| Ordinal | 250 |
|---|---|
| Address | 0x16e4a0 |
| Ordinal | 251 |
|---|---|
| Address | 0x16e550 |
| Ordinal | 252 |
|---|---|
| Address | 0x16e5b0 |
| Ordinal | 253 |
|---|---|
| Address | 0x16e740 |
| Ordinal | 254 |
|---|---|
| Address | 0x169440 |
| Ordinal | 255 |
|---|---|
| Address | 0x3e57b0 |
| Ordinal | 256 |
|---|---|
| Address | 0x169460 |
| Ordinal | 257 |
|---|---|
| Address | 0x165aa0 |
| Ordinal | 258 |
|---|---|
| Address | 0x16e860 |
| Ordinal | 259 |
|---|---|
| Address | 0x16e8b0 |
| Ordinal | 260 |
|---|---|
| Address | 0x16f160 |
| Ordinal | 261 |
|---|---|
| Address | 0x16f180 |
| Ordinal | 262 |
|---|---|
| Address | 0x169730 |
| Ordinal | 263 |
|---|---|
| Address | 0x15d340 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 24.166.818.3 |
| ProductVersion | 24.166.818.3 |
| FileFlags |
VS_FF_SPECIALBUILD
|
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Standalone Updater |
| InternalName | OneDriveStandaloneUpdater.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | OneDriveStandaloneUpdater.exe |
| ProductName | Microsoft OneDrive |
| FileVersion (#2) | 24.166.0818.0003 |
| ProductVersion (#2) | 24.166.0818.0003 |
| SpecialBuild | b/build/84e690d0-e12e-e41c-50fb-a841e09085a1 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2037-Jun-18 20:15:49 |
| Version | 0.0 |
| SizeofData | 139 |
| AddressOfRawData | 0x37b534 |
| PointerToRawData | 0x37a134 |
| Referenced File | D:\dbs\sh\odct\0905_112315_0\client\onedrive\Product\StandaloneUpdater\exe\obj\amd64\OneDriveStandaloneUpdater.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2037-Jun-18 20:15:49 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x37b5c0 |
| PointerToRawData | 0x37a1c0 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2037-Jun-18 20:15:49 |
| Version | 0.0 |
| SizeofData | 1372 |
| AddressOfRawData | 0x37b5d4 |
| PointerToRawData | 0x37a1d4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2037-Jun-18 20:15:49 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x37bb30 |
| PointerToRawData | 0x37a730 |
| StartAddressOfRawData | 0x14037bb80 |
|---|---|
| EndAddressOfRawData | 0x14037bcc0 |
| AddressOfIndex | 0x1403e0338 |
| AddressOfCallbacks | 0x1402e1ab8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks |
0x000000014015D100
0x000000014015D180 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1403c3018 |
| GuardCFCheckFunctionPointer | 5371727848 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x6d926225 |
|---|---|
| Unmarked objects | 0 |
| C++ objects (29395) | 203 |
| C objects (27049) | 9 |
| C++ objects (27049) | 59 |
| C++ objects (LTCG) (VS2022 Update 3 (17.3.0-3) compiler 31629) | 11 |
| C objects (VS2022 Update 3 (17.3.0) compiler 31616) | 19 |
| ASM objects (VS2022 Update 3 (17.3.0) compiler 31616) | 8 |
| C++ objects (VS2022 Update 3 (17.3.0) compiler 31616) | 121 |
| ASM objects (29395) | 14 |
| C objects (29395) | 30 |
| C objects (CVTCIL) (29395) | 2 |
| Imports (29395) | 45 |
| Total imports | 538 |
| C++ objects (VS2022 Update 3 (17.3.0-3) compiler 31629) | 155 |
| Exports (VS2022 Update 3 (17.3.0-3) compiler 31629) | 1 |
| Resource objects (VS2022 Update 3 (17.3.0-3) compiler 31629) | 1 |
| Linker (VS2022 Update 3 (17.3.0-3) compiler 31629) | 1 |
No comments yet.