Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
Compilation Date | 2016-Jul-12 13:20:36 |
Detected languages |
English - United States
|
Debug artifacts |
P:\Target\x86\ship\lync\x-none\npmeetingjoinpluginoc.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | The plugin allows you to have a better experience with Microsoft Lync |
FileVersion | 15.0.4849.1000 |
InternalName | npMeetingJoinPluginOC |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | npMeetingJoinPluginOC.dll |
ProductName | Microsoft Office 2013 |
ProductVersion | 15.0.4849.1000 |
FileOpenName | Lync Plug-in for Firefox |
FileExtents | |
MIMEType | application/vnd.microsoft.communicator.ocsmeeting |
Info | Matching compiler(s): | Microsoft Visual Basic v5.0 - v6.0 |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA |
Safe | VirusTotal score: 0/63 (Scanned on 2017-07-06 01:31:42) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x108 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2016-Jul-12 13:20:36 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
Magic | PE32 |
---|---|
LinkerVersion | 10.0 |
SizeOfCode | 0x5800 |
SizeOfInitializedData | 0x1e00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000051D6 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x7000 |
ImageBase | 0x10000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 6.1 |
ImageVersion | 0.0 |
SubsystemVersion | 6.1 |
Win32VersionValue | 0 |
SizeOfImage | 0xb000 |
SizeOfHeaders | 0x400 |
Checksum | 0xc66f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
MSVCP100.dll |
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z |
---|---|
ADVAPI32.dll |
DeregisterEventSource
RegisterEventSourceW ReportEventW RegisterTraceGuidsW UnregisterTraceGuids GetTraceLoggerHandle GetTraceEnableLevel GetTraceEnableFlags TraceMessage RegQueryValueExW RegCloseKey RegOpenKeyExW |
KERNEL32.dll |
GetLastError
InitializeCriticalSectionAndSpinCount DeleteCriticalSection lstrlenW MultiByteToWideChar WideCharToMultiByte HeapAlloc HeapFree GetProcessHeap InitializeCriticalSectionEx RaiseException IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess InterlockedCompareExchange InterlockedExchange DecodePointer EncodePointer LoadLibraryExW GetProcAddress GetModuleHandleW GetModuleFileNameW WerRegisterMemoryBlock VirtualProtect OutputDebugStringA GetTickCount GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId HeapSetInformation QueryPerformanceCounter DisableThreadLibraryCalls Sleep |
OLEAUT32.dll |
#7
#4 #2 #6 #5 |
MSVCR100.dll |
_onexit
_crt_debugger_hook __clean_type_info_names_internal _except_handler4_common ?_type_info_dtor_internal_method@type_info@@QAEXXZ _lock __dllonexit _unlock ?terminate@@YAXXZ __CppXcptFilter _amsg_exit _initterm_e _initterm _encoded_null _malloc_crt memset vswprintf_s free calloc _vsnprintf __CxxFrameHandler3 _CxxThrowException ?what@exception@std@@UBEPBDXZ ??1exception@std@@UAE@XZ ??0exception@std@@QAE@ABV01@@Z ??0exception@std@@QAE@ABQBD@Z _recalloc |
ole32.dll |
CoCreateInstance
|
Ordinal | 1 |
---|---|
Address | 0x2007 |
Ordinal | 2 |
---|---|
Address | 0x2088 |
Ordinal | 3 |
---|---|
Address | 0x4511 |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 15.0.4849.1000 |
ProductVersion | 15.0.4849.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_DLL
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | The plugin allows you to have a better experience with Microsoft Lync |
FileVersion (#2) | 15.0.4849.1000 |
InternalName | npMeetingJoinPluginOC |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | npMeetingJoinPluginOC.dll |
ProductName | Microsoft Office 2013 |
ProductVersion (#2) | 15.0.4849.1000 |
FileOpenName | Lync Plug-in for Firefox |
FileExtents | |
MIMEType | application/vnd.microsoft.communicator.ocsmeeting |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Jul-12 13:20:36 |
Version | 0.0 |
SizeofData | 280 |
AddressOfRawData | 0x6634 |
PointerToRawData | 0x5a34 |
Referenced File | P:\Target\x86\ship\lync\x-none\npmeetingjoinpluginoc.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2016-Jul-12 13:20:36 |
Version | 565.7732 |
SizeofData | 4 |
AddressOfRawData | 0x6630 |
PointerToRawData | 0x5a30 |
Size | 0x48 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0 |
SEHandlerTable | 0x10001fb0 |
SEHandlerCount | 7 |
XOR Key | 0x3ce53a67 |
---|---|
Unmarked objects | 0 |
152 (20115) | 1 |
ASM objects (VS2010 SP1 build 40219) | 1 |
C++ objects (VS2010 SP1 build 40219) | 4 |
C objects (VS2010 SP1 build 40219) | 9 |
188 (30716) | 3 |
185 (30716) | 8 |
Imports (VS2010 SP1 build 40219) | 5 |
Total imports | 84 |
184 (30716) | 1 |
189 (30716) | 9 |
183 (30716) | 1 |
186 (30716) | 1 |