Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
Compilation Date | 2020-Apr-10 11:22:02 |
Detected languages |
English - United States
|
Debug artifacts |
D:\Builds\tools\objects\nisomedriver\winxpK\i386\msvc-10.0\debug\nisomedriver.pdb
|
CompanyName | National Instruments Corporation |
LegalCopyright | Copyright © 2000-2020 National Instruments Corporation. All Rights Reserved. |
ProductName | NISOMEDRIVER |
OriginalFilename | nisomedriver.sys |
FileDescription | Some Friendly Description of nisomedriver |
ProductVersion | 1.0.0a0 debug build |
FileVersion | 1.0.0a0 debug build |
InternalName | NISOMEDRIVER 1.0.0a0 debug build |
Comments | 2020/04/10 14:20:27, nisomedriver/winxpK/i386/msvc-10.0/debug |
PrivateBuild | alpha build |
Info | Matching compiler(s): | Microsoft Visual C++ |
Suspicious | The PE is possibly packed. |
Unusual section name found: PAGE
Section INIT is both writable and executable. |
Suspicious | The PE contains functions most legitimate programs don't use. |
Functions which can be used for anti-debugging purposes:
|
Info | The PE is digitally signed. |
Signer: NITestingCert
Issuer: NITestingCert |
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 8 |
TimeDateStamp | 2020-Apr-10 11:22:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x20000 |
SizeOfInitializedData | 0x1b600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0003C000 (Section: INIT) |
BaseOfCode | 0x1000 |
BaseOfData | 0x21000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 1.0 |
SubsystemVersion | 5.1 |
Win32VersionValue | 0 |
SizeOfImage | 0x41000 |
SizeOfHeaders | 0x400 |
Checksum | 0x41657 |
Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ntoskrnl.exe |
IoGetDeviceProperty
IoDeleteDevice IoDetachDevice IoAttachDeviceToDeviceStack IoInitializeRemoveLockEx IoCreateDevice KeSetEvent KeInitializeEvent ExAllocatePoolWithTag KeInitializeMutex ExFreePoolWithTag RtlFreeUnicodeString memcpy _aulldiv _aullrem _allmul _purecall IoAllocateWorkItem IoFreeWorkItem IoReleaseRemoveLockAndWaitEx ObfDereferenceObject ProbeForWrite ObReferenceObjectByHandle ExEventObjectType _except_handler3 KeWaitForSingleObject IoQueueWorkItem RtlInitUnicodeString IoOpenDeviceRegistryKey PoSetPowerState PoRequestPowerIrp IoOpenDeviceInterfaceRegistryKey IoRegisterDeviceInterface RtlAnsiStringToUnicodeString RtlInitAnsiString IoSetDeviceInterfaceState RtlEqualUnicodeString KeInsertQueueDpc IoBuildSynchronousFsdRequest KeReleaseMutex memset PsReferencePrimaryToken IoGetRequestorProcess PsDereferenceImpersonationToken SeTokenIsAdmin PsReferenceImpersonationToken MmFreePagesFromMdl MmAllocatePagesForMdl MmFreeContiguousMemory MmAllocateContiguousMemory MmBuildMdlForNonPagedPool MmSizeOfMdl MmUnlockPages PsGetProcessId ProbeForRead PsGetCurrentProcessId MmMapLockedPagesSpecifyCache IoBuildPartialMdl ZwClose ZwMapViewOfSection ZwOpenSection ZwOpenProcess MmUnmapLockedPages ZwUnmapViewOfSection MmMapIoSpace MmUnmapIoSpace KeInitializeSemaphore KeReleaseSemaphore KeQueryTimeIncrement _alldiv KeTickCount KeGetCurrentThread memmove ZwQueryValueKey ZwSetValueKey ZwDeleteKey ZwDeleteValueKey ZwOpenKey ZwCreateKey DbgPrint _vsnprintf _wcsupr wcstombs IofCallDriver IoReleaseRemoveLockEx IoAcquireRemoveLockEx PsDereferencePrimaryToken IofCompleteRequest IoGetDeviceNumaNode RtlAnsiCharToUnicodeChar KeBugCheckEx MmGetSystemRoutineAddress IoConnectInterrupt IoDisconnectInterrupt KeQueryActiveProcessors |
---|---|
HAL.DLL |
ExAcquireFastMutex
KeQueryPerformanceCounter KfReleaseSpinLock KeGetCurrentIrql KfAcquireSpinLock ExReleaseFastMutex |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 1.0.0.16384 |
ProductVersion | 1.0.0.16384 |
FileFlags |
VS_FF_DEBUG
VS_FF_PRERELEASE
|
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | National Instruments Corporation |
LegalCopyright | Copyright © 2000-2020 National Instruments Corporation. All Rights Reserved. |
ProductName | NISOMEDRIVER |
OriginalFilename | nisomedriver.sys |
FileDescription | Some Friendly Description of nisomedriver |
ProductVersion (#2) | 1.0.0a0 debug build |
FileVersion (#2) | 1.0.0a0 debug build |
InternalName | NISOMEDRIVER 1.0.0a0 debug build |
Comments | 2020/04/10 14:20:27, nisomedriver/winxpK/i386/msvc-10.0/debug |
PrivateBuild | alpha build |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Apr-10 11:22:02 |
Version | 0.0 |
SizeofData | 106 |
AddressOfRawData | 0x38724 |
PointerToRawData | 0x36d24 |
Referenced File | D:\Builds\tools\objects\nisomedriver\winxpK\i386\msvc-10.0\debug\nisomedriver.pdb |
XOR Key | 0xc87ecd0e |
---|---|
Unmarked objects | 0 |
C objects (VS2008 SP1 build 30729) | 13 |
C++ objects (VS2008 SP1 build 30729) | 4 |
Total imports | 101 |
Imports (VS2003 (.NET) build 4035) | 5 |
C++ objects (VS2010 SP1 build 40219) | 28 |
C objects (VS2010 SP1 build 40219) | 4 |
Resource objects (VS2010 SP1 build 40219) | 1 |
Linker (VS2010 SP1 build 40219) | 1 |