| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| Compilation Date | 2012-Jul-26 02:33:40 |
| Detected languages |
English - United States
|
| Debug artifacts |
win32k.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Multi-User Win32 Driver |
| FileVersion | 6.2.9200.16384 (win8_rtm.120725-1247) |
| InternalName | win32k.sys |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | win32k.sys |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 6.2.9200.16384 |
| Info | Matching compiler(s): | Microsoft Visual C++ v6.0 DLL |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to MD5 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .kbdfall
Unusual section name found: PAGE Section INIT is both writable and executable. |
| Malicious | The PE contains functions mostly used by malware. |
Functions which can be used for anti-debugging purposes:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2020-07-13 23:22:50) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 9 |
| TimeDateStamp | 2012-Jul-26 02:33:40 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.2 |
| SizeOfCode | 0x2e5a00 |
| SizeOfInitializedData | 0x67a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00189ADA (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x2e5000 |
| ImageBase | 0x10000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.2 |
| ImageVersion | 6.2 |
| SubsystemVersion | 6.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x351000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x34bc9a |
| Subsystem |
IMAGE_SUBSYSTEM_NATIVE
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ntoskrnl.exe |
memset
_chkstk memcpy PsGetCurrentThreadWin32Thread ExAllocatePoolWithQuotaTag ObfDereferenceObject PsGetCurrentProcessId ObfReferenceObject PsSetProcessWin32Process PsGetThreadWin32Thread ExEnterCriticalRegionAndAcquireFastMutexUnsafe PsReferenceKernelStack ExReleaseFastMutexUnsafeAndLeaveCriticalRegion PsSetThreadWin32Thread memcmp PsDereferenceKernelStack PsGetCurrentProcess ExRaiseDatatypeMisalignment ExFreePool ExRaiseStatus ProbeForWrite ObReferenceObjectByHandle ExRaiseAccessViolation RtlInitUnicodeString ZwAllocateVirtualMemory SeCaptureSecurityDescriptor RtlNtStatusToDosError ZwFreeVirtualMemory SeReleaseSecurityDescriptor RtlEqualUnicodeString ObQueryNameInfo ObOpenObjectByPointer ExDesktopObjectType ObCloseHandle RtlCopyUnicodeString PsGetCurrentProcessWin32Process PsProcessType PsGetProcessSessionId ExQueryFastCacheDevLicense PsGetProcessDebugPort PsGetProcessPeb RtlAreAnyAccessesGranted PsLookupProcessByProcessId PsJobType ExEnterCriticalRegionAndAcquireResourceExclusive PsGetJobLock PsGetJobUIRestrictionsClass ExAllocatePoolWithTag ExReleaseResourceAndLeaveCriticalRegion RtlIntegerToUnicodeString RtlIntegerToUnicode PsGetThreadProcessId PsGetThreadId SeCreateClientSecurity KeGetCurrentThread SeTokenType PsDereferencePrimaryToken PsDereferenceImpersonationToken InterlockedExchange ExEventObjectType PsGetThreadProcess KeEnterCriticalRegion KeLeaveCriticalRegion KeWaitForSingleObject ZwSetEvent RtlQueryElevationFlags ZwQueryInformationToken ZwClose EtwWrite SeTokenObjectType PsReferencePrimaryToken RtlQueryPackageIdentity KeInitializeEvent ObDeleteCapturedInsertInfo MmCreateSection MmMapViewInSessionSpace MmUnmapViewInSessionSpace ExInitializeResourceLite ExDeleteResourceLite ZwCreateDirectoryObject RtlUnicodeStringToInteger MmMapViewOfSection ZwOpenKey KeBugCheckEx ZwCreateEvent RtlDeleteRegistryValue RtlQueryRegistryValues RtlCompareUnicodeString NlsMbCodePageTag NlsAnsiCodePage ZwQueryValueKey ExWindowStationObjectType ExIsResourceAcquiredExclusiveLite PsIsSystemThread SeSinglePrivilegeCheck InterlockedCompareExchange PsIsProtectedProcess PsAcquireProcessExitSynchronization KeStackAttachProcess KeUnstackDetachProcess PsReleaseProcessExitSynchronization SeQueryInformationToken PsQueryProcessAttributesByToken RtlImageNtHeader PsGetProcessSectionBaseAddress RtlCompareMemory RtlConvertSidToUnicodeString ZwQueryInformationProcess RtlFreeUnicodeString PsGetProcessJob PsGetProcessWin32WindowStation KeSetEvent PsGetProcessInheritedFromUniqueProcessId SeQueryAuthenticationIdToken PsSetProcessWindowStation PsGetThreadSessionId PsLookupThreadByThreadId KeClearEvent KeQuerySystemTime PsGetProcessCreateTimeQuadPart ZwTerminateProcess PsGetProcessId InterlockedPopEntrySList InterlockedPushEntrySList ExDeletePagedLookasideList RtlInitializeBitMap KeSetKernelStackSwapEnable RtlFreeHeap PsGetProcessCommonJob ExInitializePagedLookasideList KeWaitForMultipleObjects PsIsThreadTerminating PsGetCurrentProcessSessionId ZwOpenProcess PsReleaseProcessWakeCounter PsGetProcessExitStatus PsGetProcessExitProcessCalled ObReferenceObjectByPointer RtlInitAnsiString PsGetProcessImageFileName RtlAnsiStringToUnicodeString PsThreadType ExQueryFastCacheAppOrigin ZwPowerInformation KeCancelTimer RtlDestroyAtomTable RtlDestroyHeap EtwUnregister KeRemoveSystemServiceTable MmUserProbeAddress KeAddSystemServiceTable PsEstablishWin32Callouts DbgkLkmdRegisterCallback EtwRegister MmPageEntireDriver KeQueryInterruptTime ExInitializeRundownProtection IoCreateDriver RtlGetIntegerAtom KeDelayExecutionThread ZwQueryDefaultLocale InterlockedDecrement ZwQueryKey ZwSetDefaultLocale ZwSetDefaultUILanguage ZwQueryDefaultUILanguage ExRaiseHardError ExIsResourceAcquiredSharedLite ExEnterPriorityRegionAndAcquireResourceExclusive PsEnterPriorityRegion ExEnterPriorityRegionAndAcquireResourceShared ExEnterCriticalRegionAndAcquireResourceShared ExReleaseResourceAndLeavePriorityRegion PsLeavePriorityRegion KeInitializeApc KeInsertQueueApc KeReleaseSemaphore IoGetRelatedDeviceObject KeInitializeTimerEx ZwDeviceIoControlFile KeResetEvent RtlAllocateHeap PsGetCurrentThreadId InitSafeBootMode KeTickCount KeQueryTimeIncrement ZwSetInformationThread ZwSetInformationProcess ObCheckCreateObjectAccess ObCreateObject ObGetObjectSecurity ObAssignSecurity ObReleaseObjectSecurity RtlMapGenericMask KeAttachProcess KeDetachProcess ObOpenObjectByName PsIsSystemProcess MmUnmapViewOfSection PsGetProcessSessionIdEx KePulseEvent ObFindHandleForObject RtlSetBits RtlClearBits RtlAppendUnicodeToString RtlAppendUnicodeStringToString ZwDuplicateObject RtlLengthRequiredSid RtlSubAuthoritySid RtlInitializeSid ZwSetSecurityObject RtlLengthSid RtlCopySid ExFreePoolWithTag RtlCreateAcl RtlAddAce RtlSetDaclSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSetGroupSecurityDescriptor SeExports ObReferenceObjectByName RtlAreAllAccessesGranted SeCreateAccessState ObCheckObjectAccess SeDeleteAccessState SeCaptureSubjectContext SeLockSubjectContext SePrivilegeCheck SePrivilegeObjectAuditAlarm SeUnlockSubjectContext SeReleaseSubjectContext ObGetObjectType ObSetHandleAttributes ZwOpenThreadTokenEx ZwOpenProcessTokenEx PsReferenceImpersonationToken SeTokenIsRestricted KeInitializeSemaphore LpcRequestPort LpcRequestWaitReplyPort RtlCreateAtomTable RtlAddAtomToAtomTable RtlPinAtomInAtomTable ZwOpenDirectoryObject ExAcquireRundownProtection ObInsertObject SeAssignSecurity ObSetSecurityDescriptorInfo SeDeassignSecurity ExReleaseRundownProtection IoQueryDeviceDescription KeSaveFloatingPointState KeRestoreFloatingPointState PoSetUserPresent PoLatencySensitivityHint ExWaitForRundownProtectionRelease ExRundownCompleted PsCreateSystemThread ZwQueryObject IoWMIOpenBlock IoWMIQueryAllData KeInitializeTimer PoRequestShutdownEvent KeTestAlertThread IoDriverObjectType RtlCheckTokenMembership LpcPortObjectType ZwSetSystemInformation PsGetThreadFreezeCount ZwYieldExecution RtlUnicodeStringToAnsiString RtlIntegerToChar PsChargeProcessWakeCounter PsGetProcessPriorityClass PsSetProcessPriorityClass PsSetProcessPriorityByClass IoGetDeviceObjectPointer IoBuildDeviceIoControlRequest IofCallDriver ZwUpdateWnfStateData IoAllocateErrorLogEntry IoWriteErrorLogEntry InterlockedIncrement IoGetStackLimits RtlMultiByteToUnicodeN MmSystemRangeStart ZwEnumerateValueKey KeSetPriorityThread RtlUnicodeToMultiByteN RtlGetThreadLangIdByIndex KeSetTimer KeSetCoalescableTimer KeAlertThread RtlFormatCurrentUserKeyPath ZwSetValueKey ExGetExclusiveWaiterCount ExGetSharedWaiterCount ExAllocatePoolWithTagPriority NlsOemCodePage RtlCreateAtomTableEx RtlAddAtomToAtomTableEx RtlLookupAtomInAtomTable RtlDeleteAtomFromAtomTable RtlQueryAtomInAtomTable ZwQueryInformationFile ZwReadFile ZwOpenSymbolicLinkObject ZwQuerySymbolicLinkObject IoFileObjectType ObQueryNameString ZwCreateFile SeImpersonateClientEx ZwCreateKey NtClose EtwEventEnabled RtlMultiByteToUnicodeSize RtlUnicodeToMultiByteSize KeUserModeCallback IoUnregisterPlugPlayNotification IoRegisterPlugPlayNotification RtlWalkFrameChain IoWMIHandleToInstanceName IoWMIQuerySingleInstance ZwCancelIoFile IoBuildSynchronousFsdRequest ZwOpenFile IoOpenDeviceRegistryKey _purecall MmSectionObjectType IoGetDevicePropertyData ZwQueryLicenseValue ZwQuerySystemInformation RtlAddAccessAllowedAce MmCommitSessionMappedView RtlCreateHeap ExCompositionSurfaceObjectType IoInvalidateDeviceRelations RtlOpenCurrentUser PoUserShutdownInitiated PsGetCurrentThreadProcessId PoUserShutdownCancelled RtlFindMessage RtlStringFromGUID RtlGUIDFromString RtlAnsiCharToUnicodeChar RtlWriteRegistryValue ZwEnumerateKey ZwOpenEvent ZwAlpcSendWaitReceivePort ZwAlpcConnectPort ZwWaitForSingleObject ZwDeleteKey DbgPrint RtlInitializeGenericTable ExAcquireResourceExclusiveLite ExReleaseResourceLite ExAcquireResourceSharedLite RtlLookupElementGenericTable RtlInsertElementGenericTable RtlDeleteElementGenericTable RtlEnumerateGenericTableWithoutSplaying ExfAcquirePushLockExclusive ExfTryToWakePushLock InterlockedExchangeAdd ExInterlockedFlushSList ExfAcquirePushLockShared ExfReleasePushLockShared RtlEnumerateGenericTable ExSemaphoreObjectType ExSystemExceptionFilter ZwWaitForMultipleObjects RtlNumberGenericTableElements RtlGetElementGenericTable ZwClearEvent MmGetSystemRoutineAddress ExAcquireSharedStarveExclusive KeInitializeGuardedMutex KeAcquireGuardedMutex KeReleaseGuardedMutex PsGetCurrentThreadTeb DbgPrintEx vsprintf_s MmSecureVirtualMemory MmUnsecureVirtualMemory RtlInsertElementGenericTableAvl RtlLookupElementGenericTableAvl RtlDeleteElementGenericTableAvl ExSystemTimeToLocalTime RtlFillMemoryUlong ExIsProcessorFeaturePresent KeExpandKernelStackAndCallout RtlTimeToTimeFields KeReadStateEvent swprintf_s RtlUnicodeToCustomCPN RtlInitCodePageTable RtlGetDefaultCodePage ZwDeleteFile RtlCustomCPToUnicodeN LdrResFindResource LdrResFindResourceDirectory KeReleaseMutex RtlFindClearBits RtlClearAllBits RtlEqualSid strncmp toupper wcsncpy_s IoGetAttachedDeviceReference IoGetDeviceProperty wcscpy_s IoGetDeviceInterfaces IoOpenDeviceInterfaceRegistryKey IoCreateFile MmHighestUserAddress PsGetCurrentThreadProcess IoSetThreadHardErrorMode ZwQueryVolumeInformationFile ZwSetInformationFile ZwCreateSection RtlPrefixString KeAreApcsDisabled ObDuplicateObject PsGetCurrentThreadPreviousMode ZwUnmapViewOfSection MmMapViewInSessionSpaceEx PsGetCurrentThreadWin32ThreadAndEnterCriticalRegion RtlInitializeGenericTableAvl ZwMapViewOfSection RtlEnumerateGenericTableAvl RtlCreateRegistryKey wcscspn wcsspn MmQuerySystemSize RtlCaptureStackBackTrace MmPrefetchVirtualAddresses RtlGetNtGlobalFlags LpcRequestWaitReplyPortEx RtlAppendStringToString wcscat_s ZwResetEvent KeInitializeMutex RtlUpcaseUnicodeString RtlExtendedLargeIntegerDivide ZwSecureConnectPort IoQueueThreadIrp IoBuildAsynchronousFsdRequest RtlFindMostSignificantBit IoUnregisterPlugPlayNotificationEx MmIsVerifierEnabled MmAddVerifierThunks RtlRandom RtlCreateSecurityDescriptor PsGetProcessWin32Process _aullshr _aulldiv _allshr _allshl _allmul _alldvrm _alldiv ZwLoadDriver ZwUnloadDriver KdDebuggerEnabled KeIsAttachedProcess RtlUnwind |
|---|---|
| msrpc.sys |
RpcAsyncCancelCall
RpcAsyncCompleteCall RpcBindingCreateW NdrAsyncClientCall I_RpcGetCompleteAndFreeRoutine RpcBindingUnbind RpcBindingBind RpcAsyncInitializeHandle I_RpcExceptionFilter RpcBindingFree RpcBindingCopy |
| watchdog.sys |
SMgrRegisterGdiCallout
WdDiagNotifyUser WdLogEvent5_WdLowResource WdLogNewEntry5_WdLowResource WdLogEvent5_WdTrace WdLogNewEntry5_WdTrace WdLogEvent5_WdEvent WdLogNewEntry5_WdEvent WdLogEvent5_WdWarning WdLogNewEntry5_WdWarning WdLogEvent5_WdAssertion WdLogNewEntry5_WdAssertion WdInitialize WdLogEvent5_WdError WdLogNewEntry5_WdError SMgrNotifySessionChange |
| HIDPARSE.SYS |
HidP_GetUsagesEx
HidP_GetUsages HidP_SetUsageValue HidP_SetUsages HidP_GetSpecificValueCaps HidP_GetCollectionDescription HidP_GetCaps HidP_GetLinkCollectionNodes HidP_FreeCollectionDescription HidP_GetSpecificButtonCaps HidP_GetUsageValueArray HidP_MaxUsageListLength HidP_GetUsageValue |
| cng.sys |
SystemPrng
BCryptOpenAlgorithmProvider BCryptGetProperty BCryptCreateHash BCryptHashData BCryptFinishHash BCryptCloseAlgorithmProvider BCryptDestroyHash BCryptImportKeyPair BCryptVerifySignature BCryptDestroyKey |
| HAL.dll |
KeQueryPerformanceCounter
|
| Ordinal | 1 |
|---|---|
| Address | 0x225c0d |
| Ordinal | 2 |
|---|---|
| Address | 0x225ae2 |
| Ordinal | 3 |
|---|---|
| Address | 0x225b29 |
| Ordinal | 4 |
|---|---|
| Address | 0x225b9b |
| Ordinal | 5 |
|---|---|
| Address | 0x225f3e |
| Ordinal | 6 |
|---|---|
| Address | 0x2261a1 |
| Ordinal | 7 |
|---|---|
| Address | 0x2260a7 |
| Ordinal | 8 |
|---|---|
| Address | 0x146fe |
| Ordinal | 9 |
|---|---|
| Address | 0x226242 |
| Ordinal | 10 |
|---|---|
| Address | 0xeda35 |
| Ordinal | 11 |
|---|---|
| Address | 0xeda53 |
| Ordinal | 12 |
|---|---|
| Address | 0x2263cf |
| Ordinal | 13 |
|---|---|
| Address | 0x2269fb |
| Ordinal | 14 |
|---|---|
| Address | 0x163fcb |
| Ordinal | 15 |
|---|---|
| Address | 0x826b9 |
| Ordinal | 16 |
|---|---|
| Address | 0x226a3b |
| Ordinal | 17 |
|---|---|
| Address | 0xbb82 |
| Ordinal | 18 |
|---|---|
| Address | 0xf0c06 |
| Ordinal | 19 |
|---|---|
| Address | 0x22885e |
| Ordinal | 20 |
|---|---|
| Address | 0x2266ac |
| Ordinal | 21 |
|---|---|
| Address | 0x226a65 |
| Ordinal | 22 |
|---|---|
| Address | 0x135035 |
| Ordinal | 23 |
|---|---|
| Address | 0x80905 |
| Ordinal | 24 |
|---|---|
| Address | 0x135fdc |
| Ordinal | 25 |
|---|---|
| Address | 0x310c3f |
| ForwardName | NTOSKRNL.KeBugCheckEx |
| Ordinal | 26 |
|---|---|
| Address | 0xd5fd2 |
| Ordinal | 27 |
|---|---|
| Address | 0xcfa40 |
| Ordinal | 28 |
|---|---|
| Address | 0x22c172 |
| Ordinal | 29 |
|---|---|
| Address | 0x22cf49 |
| Ordinal | 30 |
|---|---|
| Address | 0x82679 |
| Ordinal | 31 |
|---|---|
| Address | 0x67ca3 |
| Ordinal | 32 |
|---|---|
| Address | 0x2345e9 |
| Ordinal | 33 |
|---|---|
| Address | 0x10eae2 |
| Ordinal | 34 |
|---|---|
| Address | 0x22d29b |
| Ordinal | 35 |
|---|---|
| Address | 0x7ebaa |
| Ordinal | 36 |
|---|---|
| Address | 0x2357d9 |
| Ordinal | 37 |
|---|---|
| Address | 0x37d8 |
| Ordinal | 38 |
|---|---|
| Address | 0x80ae5 |
| Ordinal | 39 |
|---|---|
| Address | 0x235b96 |
| Ordinal | 40 |
|---|---|
| Address | 0x22d08d |
| Ordinal | 41 |
|---|---|
| Address | 0x226a31 |
| Ordinal | 42 |
|---|---|
| Address | 0x7eaf1 |
| Ordinal | 43 |
|---|---|
| Address | 0x2360fb |
| Ordinal | 44 |
|---|---|
| Address | 0x82860 |
| Ordinal | 45 |
|---|---|
| Address | 0x109c9d |
| Ordinal | 46 |
|---|---|
| Address | 0xfcaf2 |
| Ordinal | 47 |
|---|---|
| Address | 0x23638a |
| Ordinal | 48 |
|---|---|
| Address | 0x310c55 |
| ForwardName | NTOSKRNL.DbgBreakPoint |
| Ordinal | 49 |
|---|---|
| Address | 0x226889 |
| Ordinal | 50 |
|---|---|
| Address | 0x18bba8 |
| Ordinal | 51 |
|---|---|
| Address | 0x235a6b |
| Ordinal | 52 |
|---|---|
| Address | 0x22d066 |
| Ordinal | 53 |
|---|---|
| Address | 0x226a12 |
| Ordinal | 54 |
|---|---|
| Address | 0x22d31f |
| Ordinal | 55 |
|---|---|
| Address | 0x85f7a |
| Ordinal | 56 |
|---|---|
| Address | 0x2360d6 |
| Ordinal | 57 |
|---|---|
| Address | 0x85a74 |
| Ordinal | 58 |
|---|---|
| Address | 0x22690c |
| Ordinal | 59 |
|---|---|
| Address | 0xf19ff |
| Ordinal | 60 |
|---|---|
| Address | 0x85bca |
| Ordinal | 61 |
|---|---|
| Address | 0x236356 |
| Ordinal | 62 |
|---|---|
| Address | 0x226788 |
| Ordinal | 63 |
|---|---|
| Address | 0x237aae |
| Ordinal | 64 |
|---|---|
| Address | 0x2287ae |
| Ordinal | 65 |
|---|---|
| Address | 0x237bc8 |
| Ordinal | 66 |
|---|---|
| Address | 0x22d0d5 |
| Ordinal | 67 |
|---|---|
| Address | 0x91ee6 |
| Ordinal | 68 |
|---|---|
| Address | 0x237c60 |
| Ordinal | 69 |
|---|---|
| Address | 0x237c9f |
| Ordinal | 70 |
|---|---|
| Address | 0x47b64 |
| Ordinal | 71 |
|---|---|
| Address | 0x23b632 |
| Ordinal | 72 |
|---|---|
| Address | 0x22d568 |
| Ordinal | 73 |
|---|---|
| Address | 0x1850a8 |
| Ordinal | 74 |
|---|---|
| Address | 0x23d44e |
| Ordinal | 75 |
|---|---|
| Address | 0x19e229 |
| Ordinal | 76 |
|---|---|
| Address | 0xf0cf6 |
| Ordinal | 77 |
|---|---|
| Address | 0x23d516 |
| Ordinal | 78 |
|---|---|
| Address | 0x2287ca |
| Ordinal | 79 |
|---|---|
| Address | 0x226675 |
| Ordinal | 80 |
|---|---|
| Address | 0x7924b |
| Ordinal | 81 |
|---|---|
| Address | 0x22d374 |
| Ordinal | 82 |
|---|---|
| Address | 0x310c6c |
| ForwardName | NTOSKRNL.PsGetCurrentProcessId |
| Ordinal | 83 |
|---|---|
| Address | 0x310c8b |
| ForwardName | NTOSKRNL.PsGetCurrentThreadId |
| Ordinal | 84 |
|---|---|
| Address | 0x23e189 |
| Ordinal | 85 |
|---|---|
| Address | 0x22d597 |
| Ordinal | 86 |
|---|---|
| Address | 0x22d673 |
| Ordinal | 87 |
|---|---|
| Address | 0x237bc8 |
| Ordinal | 88 |
|---|---|
| Address | 0x2268f1 |
| Ordinal | 89 |
|---|---|
| Address | 0x237bd9 |
| Ordinal | 90 |
|---|---|
| Address | 0x237bb6 |
| Ordinal | 91 |
|---|---|
| Address | 0x23e1a6 |
| Ordinal | 92 |
|---|---|
| Address | 0x237bc8 |
| Ordinal | 93 |
|---|---|
| Address | 0xdd2ae |
| Ordinal | 94 |
|---|---|
| Address | 0x22d2d7 |
| Ordinal | 95 |
|---|---|
| Address | 0x82638 |
| Ordinal | 96 |
|---|---|
| Address | 0x237ccc |
| Ordinal | 97 |
|---|---|
| Address | 0x237bc8 |
| Ordinal | 98 |
|---|---|
| Address | 0xd1e50 |
| Ordinal | 99 |
|---|---|
| Address | 0x23b4bd |
| Ordinal | 100 |
|---|---|
| Address | 0x226961 |
| Ordinal | 101 |
|---|---|
| Address | 0x22d24f |
| Ordinal | 102 |
|---|---|
| Address | 0x226b31 |
| Ordinal | 103 |
|---|---|
| Address | 0x97b6c |
| Ordinal | 104 |
|---|---|
| Address | 0xf102a |
| Ordinal | 105 |
|---|---|
| Address | 0x8265c |
| Ordinal | 106 |
|---|---|
| Address | 0x3329e |
| Ordinal | 107 |
|---|---|
| Address | 0x23b73b |
| Ordinal | 108 |
|---|---|
| Address | 0x23d5b6 |
| Ordinal | 109 |
|---|---|
| Address | 0x23d5ce |
| Ordinal | 110 |
|---|---|
| Address | 0x228893 |
| Ordinal | 111 |
|---|---|
| Address | 0x235b70 |
| Ordinal | 112 |
|---|---|
| Address | 0xf5413 |
| Ordinal | 113 |
|---|---|
| Address | 0x187cf3 |
| Ordinal | 114 |
|---|---|
| Address | 0x22cfe9 |
| Ordinal | 115 |
|---|---|
| Address | 0x23e084 |
| Ordinal | 116 |
|---|---|
| Address | 0x23d860 |
| Ordinal | 117 |
|---|---|
| Address | 0x2d79c |
| Ordinal | 118 |
|---|---|
| Address | 0x23d4fa |
| Ordinal | 119 |
|---|---|
| Address | 0x2265e3 |
| Ordinal | 120 |
|---|---|
| Address | 0xf346 |
| Ordinal | 121 |
|---|---|
| Address | 0xfcaff |
| Ordinal | 122 |
|---|---|
| Address | 0x23ffff |
| Ordinal | 123 |
|---|---|
| Address | 0x12010a |
| Ordinal | 124 |
|---|---|
| Address | 0x226777 |
| Ordinal | 125 |
|---|---|
| Address | 0x22d784 |
| Ordinal | 126 |
|---|---|
| Address | 0x1490d5 |
| Ordinal | 127 |
|---|---|
| Address | 0x22d2fb |
| Ordinal | 128 |
|---|---|
| Address | 0xa5689 |
| Ordinal | 129 |
|---|---|
| Address | 0x21c05 |
| Ordinal | 130 |
|---|---|
| Address | 0x226831 |
| Ordinal | 131 |
|---|---|
| Address | 0x310ca9 |
| ForwardName | NTOSKRNL.ProbeForWrite |
| Ordinal | 132 |
|---|---|
| Address | 0x23e1bd |
| Ordinal | 133 |
|---|---|
| Address | 0x22bdbb |
| Ordinal | 134 |
|---|---|
| Address | 0x235c09 |
| Ordinal | 135 |
|---|---|
| Address | 0x226748 |
| Ordinal | 136 |
|---|---|
| Address | 0x226737 |
| Ordinal | 137 |
|---|---|
| Address | 0x226496 |
| Ordinal | 138 |
|---|---|
| Address | 0x8289f |
| Ordinal | 139 |
|---|---|
| Address | 0x22cf30 |
| Ordinal | 140 |
|---|---|
| Address | 0x22d147 |
| Ordinal | 141 |
|---|---|
| Address | 0x2269e4 |
| Ordinal | 142 |
|---|---|
| Address | 0x163fef |
| Ordinal | 143 |
|---|---|
| Address | 0x22653f |
| Ordinal | 144 |
|---|---|
| Address | 0x22656f |
| Ordinal | 145 |
|---|---|
| Address | 0x226815 |
| Ordinal | 146 |
|---|---|
| Address | 0x22cf62 |
| Ordinal | 147 |
|---|---|
| Address | 0xe5d21 |
| Ordinal | 148 |
|---|---|
| Address | 0x19b4ef |
| Ordinal | 149 |
|---|---|
| Address | 0x2418db |
| Ordinal | 150 |
|---|---|
| Address | 0x237ba4 |
| Ordinal | 151 |
|---|---|
| Address | 0x97b31 |
| Ordinal | 152 |
|---|---|
| Address | 0x241a76 |
| Ordinal | 153 |
|---|---|
| Address | 0xe3a5c |
| Ordinal | 154 |
|---|---|
| Address | 0x4bc22 |
| Ordinal | 155 |
|---|---|
| Address | 0x7777 |
| Ordinal | 156 |
|---|---|
| Address | 0x49ea3 |
| Ordinal | 157 |
|---|---|
| Address | 0x22d203 |
| Ordinal | 158 |
|---|---|
| Address | 0x172628 |
| Ordinal | 159 |
|---|---|
| Address | 0x7f2e8 |
| Ordinal | 160 |
|---|---|
| Address | 0x226766 |
| Ordinal | 161 |
|---|---|
| Address | 0x22d1b7 |
| Ordinal | 162 |
|---|---|
| Address | 0x23b61a |
| Ordinal | 163 |
|---|---|
| Address | 0x228893 |
| Ordinal | 164 |
|---|---|
| Address | 0x235b36 |
| Ordinal | 165 |
|---|---|
| Address | 0xf10bc |
| Ordinal | 166 |
|---|---|
| Address | 0x22cfb8 |
| Ordinal | 167 |
|---|---|
| Address | 0x23e0dd |
| Ordinal | 168 |
|---|---|
| Address | 0x23d7f5 |
| Ordinal | 169 |
|---|---|
| Address | 0xb2124 |
| Ordinal | 170 |
|---|---|
| Address | 0x310cc0 |
| ForwardName | NTOSKRNL.MmUnsecureVirtualMemory |
| Ordinal | 171 |
|---|---|
| Address | 0x7de74 |
| Ordinal | 172 |
|---|---|
| Address | 0x22cf7f |
| Ordinal | 173 |
|---|---|
| Address | 0x188d01 |
| Ordinal | 174 |
|---|---|
| Address | 0x237b93 |
| Ordinal | 175 |
|---|---|
| Address | 0x22d16b |
| Ordinal | 176 |
|---|---|
| Address | 0x225c0d |
| Ordinal | 177 |
|---|---|
| Address | 0x225c54 |
| Ordinal | 178 |
|---|---|
| Address | 0x225c29 |
| Ordinal | 179 |
|---|---|
| Address | 0x225ae2 |
| Ordinal | 180 |
|---|---|
| Address | 0x225afe |
| Ordinal | 181 |
|---|---|
| Address | 0x3e8f8 |
| Ordinal | 182 |
|---|---|
| Address | 0x225a00 |
| Ordinal | 183 |
|---|---|
| Address | 0x225a94 |
| Ordinal | 184 |
|---|---|
| Address | 0x225c9f |
| Ordinal | 185 |
|---|---|
| Address | 0x225c7f |
| Ordinal | 186 |
|---|---|
| Address | 0x2259e7 |
| Ordinal | 187 |
|---|---|
| Address | 0x225a48 |
| Ordinal | 188 |
|---|---|
| Address | 0x2259ce |
| Ordinal | 189 |
|---|---|
| Address | 0x225a10 |
| Ordinal | 190 |
|---|---|
| Address | 0x225b29 |
| Ordinal | 191 |
|---|---|
| Address | 0x225b70 |
| Ordinal | 192 |
|---|---|
| Address | 0x225b45 |
| Ordinal | 193 |
|---|---|
| Address | 0x225acc |
| Ordinal | 194 |
|---|---|
| Address | 0x225cc8 |
| Ordinal | 195 |
|---|---|
| Address | 0x225caf |
| Ordinal | 196 |
|---|---|
| Address | 0x225b9b |
| Ordinal | 197 |
|---|---|
| Address | 0x225be2 |
| Ordinal | 198 |
|---|---|
| Address | 0x225bb7 |
| Ordinal | 199 |
|---|---|
| Address | 0x245df1 |
| Ordinal | 200 |
|---|---|
| Address | 0x245d36 |
| Ordinal | 201 |
|---|---|
| Address | 0x245ed0 |
| Ordinal | 202 |
|---|---|
| Address | 0x245eb9 |
| Ordinal | 203 |
|---|---|
| Address | 0x151c7 |
| Ordinal | 204 |
|---|---|
| Address | 0x245e23 |
| Ordinal | 205 |
|---|---|
| Address | 0x245cf1 |
| Ordinal | 206 |
|---|---|
| Address | 0x245e66 |
| Ordinal | 207 |
|---|---|
| Address | 0x245d90 |
| Ordinal | 208 |
|---|---|
| Address | 0x245da6 |
| Ordinal | 209 |
|---|---|
| Address | 0x21b965 |
| Ordinal | 210 |
|---|---|
| Address | 0x21b88e |
| Ordinal | 211 |
|---|---|
| Address | 0x97de |
| Ordinal | 212 |
|---|---|
| Address | 0x2287e1 |
| Ordinal | 213 |
|---|---|
| Address | 0x24686f |
| Ordinal | 214 |
|---|---|
| Address | 0x235f2d |
| Ordinal | 215 |
|---|---|
| Address | 0x1073d0 |
| Ordinal | 216 |
|---|---|
| Address | 0x246977 |
| Ordinal | 217 |
|---|---|
| Address | 0x235f43 |
| Ordinal | 218 |
|---|---|
| Address | 0x235eeb |
| Ordinal | 219 |
|---|---|
| Address | 0x235f0b |
| Ordinal | 220 |
|---|---|
| Address | 0x2361b7 |
| Ordinal | 221 |
|---|---|
| Address | 0x24699b |
| Ordinal | 222 |
|---|---|
| Address | 0x49565 |
| Ordinal | 223 |
|---|---|
| Address | 0x310ce1 |
| ForwardName | NTOSKRNL.RtlAnsiCharToUnicodeChar |
| Ordinal | 224 |
|---|---|
| Address | 0x310d03 |
| ForwardName | NTOSKRNL.RtlMultiByteToUnicodeN |
| Ordinal | 225 |
|---|---|
| Address | 0x310d23 |
| ForwardName | NTOSKRNL.RtlRaiseException |
| Ordinal | 226 |
|---|---|
| Address | 0x310d3e |
| ForwardName | NTOSKRNL.RtlUnicodeToMultiByteN |
| Ordinal | 227 |
|---|---|
| Address | 0x310d5e |
| ForwardName | NTOSKRNL.RtlUnicodeToMultiByteSize |
| Ordinal | 228 |
|---|---|
| Address | 0x310d81 |
| ForwardName | NTOSKRNL.RtlUnwind |
| Ordinal | 229 |
|---|---|
| Address | 0x310d94 |
| ForwardName | NTOSKRNL.RtlUpcaseUnicodeChar |
| Ordinal | 230 |
|---|---|
| Address | 0x310db2 |
| ForwardName | NTOSKRNL.RtlUpcaseUnicodeToMultiByteN |
| Ordinal | 231 |
|---|---|
| Address | 0x4cb40 |
| Ordinal | 232 |
|---|---|
| Address | 0x247f13 |
| Ordinal | 233 |
|---|---|
| Address | 0x247e43 |
| Ordinal | 234 |
|---|---|
| Address | 0x24302b |
| Ordinal | 235 |
|---|---|
| Address | 0x24443b |
| Ordinal | 236 |
|---|---|
| Address | 0x24441a |
| Ordinal | 237 |
|---|---|
| Address | 0x247e2a |
| Ordinal | 238 |
|---|---|
| Address | 0x1935f4 |
| Ordinal | 239 |
|---|---|
| Address | 0xeda35 |
| Ordinal | 240 |
|---|---|
| Address | 0x2362b0 |
| Ordinal | 241 |
|---|---|
| Address | 0x23628e |
| Ordinal | 242 |
|---|---|
| Address | 0x225d30 |
| Ordinal | 243 |
|---|---|
| Address | 0x225ce1 |
| Ordinal | 244 |
|---|---|
| Address | 0x8c02e |
| Ordinal | 245 |
|---|---|
| Address | 0x247f4c |
| Ordinal | 246 |
|---|---|
| Address | 0x248001 |
| Ordinal | 247 |
|---|---|
| Address | 0x9eb90 |
| Ordinal | 248 |
|---|---|
| Address | 0x247fed |
| Ordinal | 249 |
|---|---|
| Address | 0x310dd8 |
| ForwardName | NTOSKRNL._abnormal_termination |
| Ordinal | 250 |
|---|---|
| Address | 0x310df7 |
| ForwardName | NTOSKRNL._except_handler2 |
| Ordinal | 251 |
|---|---|
| Address | 0x310e11 |
| ForwardName | NTOSKRNL._global_unwind2 |
| Ordinal | 252 |
|---|---|
| Address | 0x310e2a |
| ForwardName | NTOSKRNL._itoa |
| Ordinal | 253 |
|---|---|
| Address | 0x310e39 |
| ForwardName | NTOSKRNL._itow |
| Ordinal | 254 |
|---|---|
| Address | 0x310e48 |
| ForwardName | NTOSKRNL._local_unwind2 |
| 0:Western |
| 2:Symbol |
| 77:Mac |
| 128:Japanese |
| 129:Hangul |
| 130:Hangul(Johab) |
| 134:CHINESE_GB2312 |
| 136:CHINESE_BIG5 |
| 161:Greek |
| 162:Turkish |
| 163:Vietnamese |
| 177:Hebrew |
| 178:Arabic |
| 186:Baltic |
| 204:Cyrillic |
| 222:Thai |
| 238:Central European |
| 255:OEM/DOS |
| 256:Other |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.2.9200.16384 |
| ProductVersion | 6.2.9200.16384 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DRV
|
| FileSubtype | VFT2_DRV_SYSTEM |
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Multi-User Win32 Driver |
| FileVersion (#2) | 6.2.9200.16384 (win8_rtm.120725-1247) |
| InternalName | win32k.sys |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | win32k.sys |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 6.2.9200.16384 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2012-Jul-26 02:33:40 |
| Version | 0.0 |
| SizeofData | 35 |
| AddressOfRawData | 0x2deb34 |
| PointerToRawData | 0x2ddf34 |
| Referenced File | win32k.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2012-Jul-26 02:33:40 |
| Version | 565.30117 |
| SizeofData | 8 |
| AddressOfRawData | 0x2deb2c |
| PointerToRawData | 0x2ddf2c |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x303718 |
| SEHandlerTable | 0x2f7020 |
| SEHandlerCount | 3 |
| XOR Key | 0x2e0f0899 |
|---|---|
| Unmarked objects | 0 |
| Total imports | 537 |
| 185 (30716) | 13 |
| 189 (30716) | 9 |
| 188 (30716) | 28 |
| 184 (30716) | 1 |
| 187 (30716) | 18 |
| 197 (30716) | 460 |
| 183 (30716) | 1 |
| 186 (30716) | 1 |