filename | wcp.dll | |
---|---|---|
size | 3158384 (0x303170) | |
md5 | 2b046b69c2add76a535f117c66da740f | |
type | PE32 executable (DLL) (console) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | scan pending | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xf8 |
Rich Header
lib id | version | times used |
---|---|---|
257 | 30795 | 12 |
147 | 30729 | 99 |
1 | 0 | 1606 |
259 | 30795 | 12 |
261 | 30795 | 20 |
256 | 30795 | 1 |
264 | 30795 | 423 |
253 | 30795 | 1 |
260 | 30795 | 12 |
255 | 30795 | 1 |
258 | 30795 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
TLS
raw start | raw end | index | callbks | zero fill | flags | |
---|---|---|---|---|---|---|
0x102cbd2c | 0x102cbd38 | 0x102e0614 | 0x10012818 | 0 | 0x300000 |
module_name | hint | ord | function_name |
---|---|---|---|
api-ms-win-crt-runtime-l1-1-0.dll | 56 | _initterm | |
api-ms-win-crt-runtime-l1-1-0.dll | 57 | _initterm_e | |
api-ms-win-crt-private-l1-1-0.dll | 354 | _o__i64tow_s | |
api-ms-win-crt-private-l1-1-0.dll | 355 | _o__initialize_narrow_environment | |
api-ms-win-crt-private-l1-1-0.dll | 356 | _o__initialize_onexit_table | |
api-ms-win-crt-private-l1-1-0.dll | 358 | _o__invalid_parameter_noinfo | |
api-ms-win-crt-private-l1-1-0.dll | 641 | _o__register_onexit_function | |
api-ms-win-crt-private-l1-1-0.dll | 648 | _o__seh_filter_dll | |
api-ms-win-crt-private-l1-1-0.dll | 733 | _o__ui64tow_s | |
api-ms-win-crt-private-l1-1-0.dll | 736 | _o__ultow | |
api-ms-win-crt-private-l1-1-0.dll | 737 | _o__ultow_s | |
api-ms-win-crt-private-l1-1-0.dll | 764 | _o__wcsicmp | |
api-ms-win-crt-private-l1-1-0.dll | 768 | _o__wcslwr | |
api-ms-win-crt-private-l1-1-0.dll | 774 | _o__wcsnicmp | |
api-ms-win-crt-private-l1-1-0.dll | 784 | _o__wcstoi64 | |
api-ms-win-crt-private-l1-1-0.dll | 791 | _o__wcstoui64 | |
api-ms-win-crt-private-l1-1-0.dll | 795 | _o__wcsupr | |
api-ms-win-crt-private-l1-1-0.dll | 1155 | memmove | |
api-ms-win-crt-private-l1-1-0.dll | 900 | _o_bsearch | |
api-ms-win-crt-private-l1-1-0.dll | 926 | _o_fflush | |
api-ms-win-crt-private-l1-1-0.dll | 945 | _o_free | |
api-ms-win-crt-private-l1-1-0.dll | 980 | _o_iswctype | |
api-ms-win-crt-private-l1-1-0.dll | 1018 | _o_malloc | |
api-ms-win-crt-private-l1-1-0.dll | 1029 | _o_memcpy_s | |
api-ms-win-crt-private-l1-1-0.dll | 1051 | _o_qsort | |
api-ms-win-crt-private-l1-1-0.dll | 1088 | _o_strcpy_s | |
api-ms-win-crt-private-l1-1-0.dll | 1112 | _o_tolower | |
api-ms-win-crt-private-l1-1-0.dll | 1113 | _o_toupper | |
api-ms-win-crt-private-l1-1-0.dll | 1120 | _o_wcscat_s | |
api-ms-win-crt-private-l1-1-0.dll | 1123 | _o_wcscpy_s | |
api-ms-win-crt-private-l1-1-0.dll | 1126 | _o_wcsncpy_s | |
api-ms-win-crt-private-l1-1-0.dll | 1132 | _o_wcstok_s | |
api-ms-win-crt-private-l1-1-0.dll | 1138 | _o_wcstoul | |
api-ms-win-crt-private-l1-1-0.dll | 50 | _except_handler4_common | |
api-ms-win-crt-private-l1-1-0.dll | 234 | _o__execute_onexit_table | |
api-ms-win-crt-private-l1-1-0.dll | 232 | _o__errno | |
api-ms-win-crt-private-l1-1-0.dll | 207 | _o__crt_atexit | |
api-ms-win-crt-private-l1-1-0.dll | 200 | _o__configure_narrow_argv | |
api-ms-win-crt-private-l1-1-0.dll | 187 | _o__cexit | |
api-ms-win-crt-private-l1-1-0.dll | 162 | _o__aligned_malloc | |
api-ms-win-crt-private-l1-1-0.dll | 161 | _o__aligned_free | |
api-ms-win-crt-private-l1-1-0.dll | 155 | _o___stdio_common_vswscanf | |
api-ms-win-crt-private-l1-1-0.dll | 154 | _o___stdio_common_vswprintf_s | |
api-ms-win-crt-private-l1-1-0.dll | 152 | _o___stdio_common_vswprintf | |
api-ms-win-crt-private-l1-1-0.dll | 151 | _o___stdio_common_vsscanf | |
api-ms-win-crt-private-l1-1-0.dll | 148 | _o___stdio_common_vsprintf | |
api-ms-win-crt-private-l1-1-0.dll | 147 | _o___stdio_common_vsnwprintf_s | |
api-ms-win-crt-private-l1-1-0.dll | 146 | _o___stdio_common_vsnprintf_s | |
api-ms-win-crt-private-l1-1-0.dll | 142 | _o___stdio_common_vfwprintf | |
api-ms-win-crt-private-l1-1-0.dll | 136 | _o___std_type_info_destroy_list | |
api-ms-win-crt-private-l1-1-0.dll | 1162 | wcsrchr | |
api-ms-win-crt-private-l1-1-0.dll | 1159 | strstr | |
api-ms-win-crt-private-l1-1-0.dll | 1161 | wcschr | |
api-ms-win-crt-private-l1-1-0.dll | 1163 | wcsstr | |
api-ms-win-crt-private-l1-1-0.dll | 1158 | strrchr | |
api-ms-win-crt-private-l1-1-0.dll | 86 | _o___acrt_iob_func | |
api-ms-win-crt-private-l1-1-0.dll | 1157 | strchr | |
api-ms-win-crt-private-l1-1-0.dll | 1153 | memcmp | |
api-ms-win-crt-private-l1-1-0.dll | 1154 | memcpy | |
api-ms-win-crt-string-l1-1-0.dll | 130 | memmove_s | |
api-ms-win-crt-string-l1-1-0.dll | 131 | memset | |
api-ms-win-crt-string-l1-1-0.dll | 142 | strncmp | |
api-ms-win-crt-string-l1-1-0.dll | 169 | wcsnlen | |
RPCRT4.dll | 542 | UuidFromStringW | |
RPCRT4.dll | 528 | RpcStringFreeW | |
RPCRT4.dll | 546 | UuidToStringW | |
api-ms-win-core-registry-l1-1-0.dll | 3 | RegCreateKeyExW | |
api-ms-win-core-registry-l1-1-0.dll | 15 | RegFlushKey | |
api-ms-win-core-registry-l1-1-0.dll | 40 | RegSetValueExW | |
api-ms-win-core-registry-l1-1-0.dll | 33 | RegQueryValueExW | |
api-ms-win-core-registry-l1-1-0.dll | 18 | RegGetValueW | |
api-ms-win-core-registry-l1-1-0.dll | RegCloseKey | ||
api-ms-win-core-registry-l1-1-0.dll | 9 | RegDeleteValueW | |
api-ms-win-core-registry-l1-1-0.dll | 28 | RegOpenKeyExW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 7 | GetModuleFileNameA | |
api-ms-win-core-libraryloader-l1-1-0.dll | 12 | GetModuleHandleW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 8 | GetModuleFileNameW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 10 | GetModuleHandleExA | |
api-ms-win-core-libraryloader-l1-1-0.dll | 19 | LockResource | |
api-ms-win-core-libraryloader-l1-1-0.dll | 2 | FindResourceExW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 16 | LoadResource | |
api-ms-win-core-libraryloader-l1-1-0.dll | 4 | FreeLibrary | |
api-ms-win-core-libraryloader-l1-1-0.dll | 13 | GetProcAddress | |
api-ms-win-core-libraryloader-l1-1-0.dll | 11 | GetModuleHandleExW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 15 | LoadLibraryExW | |
api-ms-win-core-libraryloader-l1-1-0.dll | 22 | SizeofResource | |
api-ms-win-eventing-provider-l1-1-0.dll | 5 | EventUnregister | |
api-ms-win-eventing-provider-l1-1-0.dll | 9 | EventWriteTransfer | |
api-ms-win-eventing-provider-l1-1-0.dll | 3 | EventRegister | |
api-ms-win-eventing-provider-l1-1-0.dll | EventActivityIdControl | ||
api-ms-win-core-rtlsupport-l1-1-0.dll | 1 | RtlCaptureStackBackTrace | |
api-ms-win-core-profile-l1-1-0.dll | QueryPerformanceCounter | ||
api-ms-win-core-processthreads-l1-1-0.dll | 12 | GetCurrentThread | |
api-ms-win-core-processthreads-l1-1-0.dll | 47 | TlsSetValue | |
api-ms-win-core-processthreads-l1-1-0.dll | 13 | GetCurrentThreadId | |
api-ms-win-core-processthreads-l1-1-0.dll | 11 | GetCurrentProcessId | |
api-ms-win-core-processthreads-l1-1-0.dll | 26 | OpenProcessToken | |
api-ms-win-core-processthreads-l1-1-0.dll | 44 | TlsAlloc | |
api-ms-win-core-processthreads-l1-1-0.dll | 5 | CreateThread | |
api-ms-win-core-processthreads-l1-1-0.dll | 10 | GetCurrentProcess | |
api-ms-win-core-processthreads-l1-1-0.dll | 45 | TlsFree | |
api-ms-win-core-processthreads-l1-1-0.dll | 42 | TerminateProcess | |
api-ms-win-core-processthreads-l1-1-0.dll | 2 | CreateProcessW | |
api-ms-win-core-processthreads-l1-1-0.dll | 28 | OpenThreadToken | |
api-ms-win-core-processthreads-l1-1-0.dll | 46 | TlsGetValue | |
api-ms-win-core-processthreads-l1-1-0.dll | 14 | GetExitCodeProcess | |
api-ms-win-core-sysinfo-l1-1-0.dll | 10 | GetSystemTimeAsFileTime | |
api-ms-win-core-sysinfo-l1-1-0.dll | 7 | GetSystemInfo | |
api-ms-win-core-sysinfo-l1-1-0.dll | 17 | GetVersionExW | |
api-ms-win-core-sysinfo-l1-1-0.dll | 20 | GlobalMemoryStatusEx | |
api-ms-win-core-sysinfo-l1-1-0.dll | 14 | GetTickCount64 | |
api-ms-win-core-interlocked-l1-1-0.dll | InitializeSListHead | ||
api-ms-win-core-debug-l1-1-0.dll | DebugBreak | ||
api-ms-win-core-debug-l1-1-0.dll | 3 | OutputDebugStringW | |
api-ms-win-core-debug-l1-1-0.dll | 1 | IsDebuggerPresent | |
api-ms-win-core-errorhandling-l1-1-0.dll | 6 | UnhandledExceptionFilter | |
api-ms-win-core-errorhandling-l1-1-0.dll | 1 | GetLastError | |
api-ms-win-core-errorhandling-l1-1-0.dll | 4 | SetLastError | |
api-ms-win-core-errorhandling-l1-1-0.dll | 5 | SetUnhandledExceptionFilter | |
api-ms-win-core-errorhandling-l1-1-0.dll | 2 | RaiseException | |
api-ms-win-core-processthreads-l1-1-1.dll | 9 | IsProcessorFeaturePresent | |
api-ms-win-core-com-l1-1-0.dll | 61 | CoTaskMemAlloc | |
api-ms-win-core-com-l1-1-0.dll | 62 | CoTaskMemFree | |
api-ms-win-core-localization-l1-2-0.dll | 7 | FormatMessageW | |
api-ms-win-core-heap-l1-1-0.dll | 2 | HeapAlloc | |
api-ms-win-core-heap-l1-1-0.dll | 6 | HeapFree | |
api-ms-win-core-heap-l1-1-0.dll | GetProcessHeap | ||
api-ms-win-core-synch-l1-1-0.dll | 23 | OpenSemaphoreW | |
api-ms-win-core-synch-l1-1-0.dll | 26 | ReleaseSRWLockExclusive | |
api-ms-win-core-synch-l1-1-0.dll | 29 | ResetEvent | |
api-ms-win-core-synch-l1-1-0.dll | AcquireSRWLockExclusive | ||
api-ms-win-core-synch-l1-1-0.dll | 6 | CreateEventW | |
api-ms-win-core-synch-l1-1-0.dll | 38 | WaitForMultipleObjectsEx | |
api-ms-win-core-synch-l1-1-0.dll | 1 | AcquireSRWLockShared | |
api-ms-win-core-synch-l1-1-0.dll | 16 | InitializeCriticalSectionAndSpinCount | |
api-ms-win-core-synch-l1-1-0.dll | 31 | SetEvent | |
api-ms-win-core-synch-l1-1-0.dll | 27 | ReleaseSRWLockShared | |
api-ms-win-core-synch-l1-1-0.dll | 28 | ReleaseSemaphore | |
api-ms-win-core-synch-l1-1-0.dll | 25 | ReleaseMutex | |
api-ms-win-core-synch-l1-1-0.dll | 40 | WaitForSingleObjectEx | |
api-ms-win-core-synch-l1-1-0.dll | 14 | EnterCriticalSection | |
api-ms-win-core-synch-l1-1-0.dll | 17 | InitializeCriticalSectionEx | |
api-ms-win-core-synch-l1-1-0.dll | 9 | CreateMutexExW | |
api-ms-win-core-synch-l1-1-0.dll | 13 | DeleteCriticalSection | |
api-ms-win-core-synch-l1-1-0.dll | 19 | LeaveCriticalSection | |
api-ms-win-core-synch-l1-1-0.dll | 11 | CreateSemaphoreExW | |
api-ms-win-core-synch-l1-1-0.dll | 39 | WaitForSingleObject | |
api-ms-win-core-handle-l1-1-0.dll | CloseHandle | ||
api-ms-win-core-handle-l1-1-0.dll | 2 | DuplicateHandle | |
api-ms-win-core-threadpool-l1-2-0.dll | 6 | CloseThreadpoolTimer | |
api-ms-win-core-threadpool-l1-2-0.dll | 34 | WaitForThreadpoolTimerCallbacks | |
api-ms-win-core-threadpool-l1-2-0.dll | 26 | SetThreadpoolTimer | |
api-ms-win-core-threadpool-l1-2-0.dll | 12 | CreateThreadpoolTimer | |
api-ms-win-core-synch-l1-2-0.dll | 9 | Sleep | |
api-ms-win-core-sysinfo-l1-2-0.dll | 3 | GetProductInfo | |
api-ms-win-core-sysinfo-l1-2-0.dll | 1 | GetNativeSystemInfo | |
api-ms-win-core-sysinfo-l1-2-0.dll | 8 | VerSetConditionMask | |
api-ms-win-eventing-legacy-l1-1-0.dll | 5 | FlushTraceW | |
api-ms-win-core-heap-obsolete-l1-1-0.dll | 12 | LocalReAlloc | |
api-ms-win-core-heap-obsolete-l1-1-0.dll | 10 | LocalFree | |
api-ms-win-core-heap-obsolete-l1-1-0.dll | 8 | LocalAlloc | |
api-ms-win-security-base-l1-1-0.dll | 55 | GetSidLengthRequired | |
api-ms-win-security-base-l1-1-0.dll | 31 | CreateWellKnownSid | |
api-ms-win-security-base-l1-1-0.dll | 56 | GetSidSubAuthority | |
api-ms-win-security-base-l1-1-0.dll | 41 | GetAce | |
api-ms-win-security-base-l1-1-0.dll | 58 | GetTokenInformation | |
api-ms-win-security-base-l1-1-0.dll | 65 | InitializeSid | |
api-ms-win-security-base-l1-1-0.dll | 70 | IsValidSid | |
api-ms-win-security-base-l1-1-0.dll | 63 | InitializeAcl | |
api-ms-win-security-base-l1-1-0.dll | 88 | SetPrivateObjectSecurityEx | |
api-ms-win-security-base-l1-1-0.dll | 45 | GetLengthSid | |
api-ms-win-security-base-l1-1-0.dll | 69 | IsValidSecurityDescriptor | |
api-ms-win-security-base-l1-1-0.dll | 33 | DestroyPrivateObjectSecurity | |
api-ms-win-security-base-l1-1-0.dll | 50 | GetSecurityDescriptorLength | |
api-ms-win-security-base-l1-1-0.dll | 92 | SetSecurityDescriptorGroup | |
api-ms-win-security-base-l1-1-0.dll | 74 | MakeSelfRelativeSD | |
api-ms-win-security-base-l1-1-0.dll | 7 | AddAccessAllowedAce | |
api-ms-win-security-base-l1-1-0.dll | 29 | CreatePrivateObjectSecurityWithMultipleInheritance | |
api-ms-win-security-base-l1-1-0.dll | 64 | InitializeSecurityDescriptor | |
api-ms-win-security-base-l1-1-0.dll | 47 | GetSecurityDescriptorControl | |
api-ms-win-security-base-l1-1-0.dll | 93 | SetSecurityDescriptorOwner | |
api-ms-win-security-base-l1-1-0.dll | 91 | SetSecurityDescriptorDacl | |
api-ms-win-core-kernel32-legacy-l1-1-0.dll | 38 | LoadLibraryA | |
api-ms-win-core-kernel32-legacy-l1-1-0.dll | 39 | LoadLibraryW | |
api-ms-win-security-provider-l1-1-0.dll | 1 | GetNamedSecurityInfoW | |
api-ms-win-core-file-l1-1-0.dll | 62 | SetEndOfFile | |
api-ms-win-core-file-l1-1-0.dll | 57 | ReadFile | |
api-ms-win-core-file-l1-1-0.dll | 34 | GetFileAttributesW | |
api-ms-win-core-file-l1-1-0.dll | 7 | DeleteFileW | |
api-ms-win-core-file-l1-1-0.dll | 4 | CreateFileW | |
api-ms-win-core-file-l1-1-0.dll | 41 | GetFinalPathNameByHandleW | |
api-ms-win-core-file-l1-1-0.dll | 64 | SetFileAttributesW | |
api-ms-win-core-file-l1-1-0.dll | 72 | WriteFile | |
api-ms-win-core-file-l1-1-0.dll | 24 | FlushFileBuffers | |
api-ms-win-core-file-l1-1-0.dll | 67 | SetFilePointerEx | |
api-ms-win-core-file-l1-1-0.dll | 37 | GetFileSizeEx | |
api-ms-win-core-namedpipe-l1-1-0.dll | 2 | CreatePipe | |
api-ms-win-core-processenvironment-l1-1-0.dll | 11 | GetEnvironmentVariableW | |
api-ms-win-core-kernel32-legacy-l1-1-1.dll | 14 | VerifyVersionInfoW | |
api-ms-win-core-string-l1-1-0.dll | 2 | CompareStringW | |
api-ms-win-core-file-l2-1-0.dll | 6 | MoveFileExW | |
api-ms-win-service-management-l1-1-0.dll | 5 | OpenServiceW | |
api-ms-win-service-management-l1-1-0.dll | 3 | DeleteService | |
api-ms-win-service-management-l1-1-0.dll | 4 | OpenSCManagerW | |
api-ms-win-service-management-l1-1-0.dll | CloseServiceHandle | ||
api-ms-win-service-management-l1-1-0.dll | 6 | StartServiceW | |
api-ms-win-service-winsvc-l1-1-0.dll | 2 | ControlService | |
api-ms-win-service-winsvc-l1-1-0.dll | 20 | QueryServiceStatus | |
api-ms-win-security-lsalookup-l2-1-0.dll | 1 | LookupAccountSidW | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 1 | CryptAcquireContextW | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 15 | CryptExportKey | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 6 | CryptDestroyHash | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 20 | CryptGetHashParam | |
api-ms-win-security-cryptoapi-l1-1-0.dll | CryptAcquireContextA | ||
api-ms-win-security-cryptoapi-l1-1-0.dll | 3 | CryptCreateHash | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 27 | CryptReleaseContext | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 7 | CryptDestroyKey | |
api-ms-win-security-cryptoapi-l1-1-0.dll | 24 | CryptHashData | |
api-ms-win-core-string-obsolete-l1-1-0.dll | 1 | lstrcmpA | |
api-ms-win-core-localization-obsolete-l1-2-0.dll | CompareStringA | ||
api-ms-win-core-libraryloader-l1-1-1.dll | 1 | EnumResourceLanguagesExW | |
api-ms-win-core-file-l1-2-0.dll | 1 | GetTempPathW | |
api-ms-win-security-lsapolicy-l1-1-0.dll | 15 | LsaQueryInformationPolicy | |
api-ms-win-security-lsapolicy-l1-1-0.dll | 1 | LsaClose | |
api-ms-win-security-lsapolicy-l1-1-0.dll | 13 | LsaOpenPolicy | |
api-ms-win-security-lsapolicy-l1-1-0.dll | 5 | LsaFreeMemory | |
ntdll.dll | 940 | RtlDuplicateUnicodeString | |
ntdll.dll | 754 | RtlAppendUnicodeStringToString | |
ntdll.dll | 966 | RtlEqualUnicodeString | |
ntdll.dll | 1040 | RtlGetControlSecurityDescriptor | |
ntdll.dll | 1268 | RtlMakeSelfRelativeSD | |
ntdll.dll | 1428 | RtlSetControlSecurityDescriptor | |
ntdll.dll | 748 | RtlAnsiCharToUnicodeChar | |
ntdll.dll | 1535 | RtlUnicodeToMultiByteN | |
ntdll.dll | 1223 | RtlIsTextUnicode | |
ntdll.dll | 1536 | RtlUnicodeToMultiByteSize | |
ntdll.dll | 823 | RtlConvertSidToUnicodeString | |
ntdll.dll | 217 | NtAllocateLocallyUniqueId | |
ntdll.dll | 497 | NtQueryInformationToken | |
ntdll.dll | 1243 | RtlLengthRequiredSid | |
ntdll.dll | 1024 | RtlFreeSid | |
ntdll.dll | 1506 | RtlTimeToTimeFields | |
ntdll.dll | 435 | NtOpenKey | |
ntdll.dll | 931 | RtlDosPathNameToNtPathName_U | |
ntdll.dll | 125 | LdrGetDllHandleEx | |
ntdll.dll | 1273 | RtlMultiByteToUnicodeN | |
ntdll.dll | 1274 | RtlMultiByteToUnicodeSize | |
ntdll.dll | 1015 | RtlFormatCurrentUserKeyPath | |
ntdll.dll | 1553 | RtlUpcaseUnicodeChar | |
ntdll.dll | 937 | RtlDowncaseUnicodeChar | |
ntdll.dll | 35 | DbgPrintEx | |
ntdll.dll | 1368 | RtlReAllocateHeap | |
ntdll.dll | 802 | RtlCompareMemory | |
ntdll.dll | 1269 | RtlMapGenericMask | |
ntdll.dll | 1086 | RtlGetSaclSecurityDescriptor | |
ntdll.dll | 1079 | RtlGetOwnerSecurityDescriptor | |
ntdll.dll | 741 | RtlAllocateAndInitializeSid | |
ntdll.dll | 713 | RtlAddAccessAllowedAce | |
ntdll.dll | 1062 | RtlGetGroupSecurityDescriptor | |
ntdll.dll | 964 | RtlEqualSid | |
ntdll.dll | 523 | NtQuerySystemInformation | |
ntdll.dll | 506 | NtQueryLicenseValue | |
ntdll.dll | 1569 | RtlValidAcl | |
ntdll.dll | 212 | NtAdjustPrivilegesToken | |
ntdll.dll | 1456 | RtlSetSaclSecurityDescriptor | |
ntdll.dll | 1573 | RtlValidSid | |
ntdll.dll | 351 | NtDuplicateToken | |
ntdll.dll | 609 | NtSetInformationThread | |
ntdll.dll | 1440 | RtlSetGroupSecurityDescriptor | |
ntdll.dll | 989 | RtlFindAceByType | |
ntdll.dll | 848 | RtlCreateEnvironmentEx | |
ntdll.dll | 976 | RtlExpandEnvironmentStrings_U | |
ntdll.dll | 1287 | RtlNtStatusToDosError | |
ntdll.dll | 702 | RtlAbsoluteToSelfRelativeSD | |
ntdll.dll | 1415 | RtlRunOnceComplete | |
ntdll.dll | 1414 | RtlRunOnceBeginInitialize | |
ntdll.dll | 1003 | RtlFindNextForwardRunClear | |
ntdll.dll | 1293 | RtlNumberOfSetBits | |
ntdll.dll | 1158 | RtlInitializeSRWLock | |
ntdll.dll | 530 | NtQueryVolumeInformationFile | |
ntdll.dll | 1386 | RtlReleaseSRWLockExclusive | |
ntdll.dll | 708 | RtlAcquireSRWLockExclusive | |
ntdll.dll | 838 | RtlCopyUnicodeString | |
ntdll.dll | 122 | LdrGetDllHandle | |
ntdll.dll | 616 | NtSetIoCompletion | |
ntdll.dll | 673 | NtWaitForMultipleObjects | |
ntdll.dll | 291 | NtCreateIoCompletion | |
ntdll.dll | 287 | NtCreateEvent | |
ntdll.dll | 1711 | TpSimpleTryPost | |
ntdll.dll | 553 | NtRemoveIoCompletion | |
ntdll.dll | 593 | NtSetEvent | |
ntdll.dll | 62 | EtwEventWrite | |
ntdll.dll | 59 | EtwEventRegister | |
ntdll.dll | 684 | NtYieldExecution | |
ntdll.dll | 808 | RtlComputeCrc32 | |
ntdll.dll | 480 | NtQueryDirectoryFile | |
ntdll.dll | 726 | RtlAddAuditAccessObjectAce | |
ntdll.dll | 725 | RtlAddAuditAccessAceEx | |
ntdll.dll | 717 | RtlAddAccessDeniedAceEx | |
ntdll.dll | 715 | RtlAddAccessAllowedObjectAce | |
ntdll.dll | 718 | RtlAddAccessDeniedObjectAce | |
ntdll.dll | 1008 | RtlFirstFreeAce | |
ntdll.dll | 1110 | RtlHashUnicodeString | |
ntdll.dll | 484 | NtQueryEaFile | |
ntdll.dll | 1384 | RtlReleaseRelativeName | |
ntdll.dll | 592 | NtSetEaFile | |
ntdll.dll | 934 | RtlDosPathNameToRelativeNtPathName_U_WithStatus | |
ntdll.dll | 903 | RtlDeleteSecurityObject | |
ntdll.dll | 528 | NtQueryValueKey | |
ntdll.dll | 1048 | RtlGetDaclSecurityDescriptor | |
ntdll.dll | 867 | RtlCreateUnicodeStringFromAsciiz | |
ntdll.dll | 1362 | RtlRaiseException | |
ntdll.dll | 34 | DbgPrint | |
ntdll.dll | 1363 | RtlRaiseStatus | |
ntdll.dll | 1242 | RtlLeaveCriticalSection | |
ntdll.dll | 1021 | RtlFreeHeap | |
ntdll.dll | 1145 | RtlInitializeCriticalSection | |
ntdll.dll | 1446 | RtlSetLastWin32ErrorAndNtStatusFromNtStatus | |
ntdll.dll | 952 | RtlEnterCriticalSection | |
ntdll.dll | 111 | LdrDisableThreadCalloutsForDll | |
ntdll.dll | 494 | NtQueryInformationProcess | |
ntdll.dll | 1303 | RtlPcToFileHeader | |
ntdll.dll | 744 | RtlAllocateHeap | |
ntdll.dll | 895 | RtlDeleteCriticalSection | |
ntdll.dll | 438 | NtOpenKeyTransactedEx | |
ntdll.dll | 295 | NtCreateKey | |
ntdll.dll | 841 | RtlCreateAcl | |
ntdll.dll | 634 | NtSetValueKey | |
ntdll.dll | 604 | NtSetInformationKey | |
ntdll.dll | 454 | NtOpenThreadToken | |
ntdll.dll | 376 | NtFsControlFile | |
ntdll.dll | 350 | NtDuplicateObject | |
ntdll.dll | 364 | NtFlushBuffersFile | |
ntdll.dll | 1138 | RtlInitUnicodeStringEx | |
ntdll.dll | 473 | NtQueryAttributesFile | |
ntdll.dll | 720 | RtlAddAce | |
ntdll.dll | 342 | NtDeleteValueKey | |
ntdll.dll | 1047 | RtlGetCurrentTransaction | |
ntdll.dll | 622 | NtSetSecurityObject | |
ntdll.dll | 338 | NtDeleteFile | |
ntdll.dll | 1280 | RtlNewSecurityObjectEx | |
ntdll.dll | 296 | NtCreateKeyTransacted | |
ntdll.dll | 714 | RtlAddAccessAllowedAceEx | |
ntdll.dll | 601 | NtSetInformationFile | |
ntdll.dll | 1326 | RtlQueryInformationAcl | |
ntdll.dll | 496 | NtQueryInformationThread | |
ntdll.dll | 1606 | RtlpApplyLengthFunction | |
ntdll.dll | 517 | NtQuerySecurityObject | |
ntdll.dll | 1031 | RtlGetAce | |
ntdll.dll | 358 | NtEnumerateValueKey | |
ntdll.dll | 680 | NtWriteFile | |
ntdll.dll | 1068 | RtlGetLengthWithoutLastFullDosOrNtPathElement | |
ntdll.dll | 355 | NtEnumerateKey | |
ntdll.dll | 1432 | RtlSetCurrentTransaction | |
ntdll.dll | 1448 | RtlSetOwnerSecurityDescriptor | |
ntdll.dll | 445 | NtOpenProcessToken | |
ntdll.dll | 339 | NtDeleteKey | |
ntdll.dll | 505 | NtQueryKey | |
ntdll.dll | 538 | NtReadFile | |
ntdll.dll | 1288 | RtlNtStatusToDosErrorNoTeb | |
ntdll.dll | 1027 | RtlFreeUnicodeString | |
ntdll.dll | 1244 | RtlLengthSecurityDescriptor | |
ntdll.dll | 847 | RtlCreateEnvironment | |
ntdll.dll | 912 | RtlDestroyEnvironment | |
ntdll.dll | 1437 | RtlSetEnvironmentVariable | |
ntdll.dll | 334 | NtDelayExecution | |
ntdll.dll | 129 | LdrGetProcedureAddress | |
ntdll.dll | 178 | LdrUnloadDll | |
ntdll.dll | 139 | LdrLoadDll | |
ntdll.dll | 1137 | RtlInitUnicodeString | |
ntdll.dll | 1245 | RtlLengthSid | |
ntdll.dll | 755 | RtlAppendUnicodeToString | |
ntdll.dll | 805 | RtlCompareUnicodeString | |
ntdll.dll | 861 | RtlCreateServiceSid | |
ntdll.dll | 1492 | RtlSubAuthoritySid | |
ntdll.dll | 1491 | RtlSubAuthorityCountSid | |
ntdll.dll | 835 | RtlCopySid | |
ntdll.dll | 1433 | RtlSetDaclSecurityDescriptor | |
ntdll.dll | 860 | RtlCreateSecurityDescriptor | |
ntdll.dll | 750 | RtlAnsiStringToUnicodeString | |
ntdll.dll | 1124 | RtlInitAnsiString | |
ntdll.dll | 404 | NtLoadKey2 | |
ntdll.dll | 436 | NtOpenKeyEx | |
ntdll.dll | 1159 | RtlInitializeSid | |
ntdll.dll | 368 | NtFlushKey | |
ntdll.dll | 661 | NtUnloadKey2 | |
ntdll.dll | 289 | NtCreateFile | |
ntdll.dll | 509 | NtQueryObject | |
ntdll.dll | 575 | NtRollbackTransaction | |
ntdll.dll | 267 | NtCommitTransaction | |
ntdll.dll | 324 | NtCreateTransaction | |
ntdll.dll | 498 | NtQueryInformationTransaction | |
ntdll.dll | 444 | NtOpenProcess | |
ntdll.dll | 491 | NtQueryInformationFile | |
ntdll.dll | 432 | NtOpenFile | |
ntdll.dll | 1505 | RtlTimeToSecondsSince1980 | |
ntdll.dll | 675 | NtWaitForSingleObject | |
ntdll.dll | 1320 | RtlQueryEnvironmentVariable_U | |
ntdll.dll | 525 | NtQuerySystemTime | |
ntdll.dll | 262 | NtClose | |
ntdll.dll | 345 | NtDeviceIoControlFile | |
ntdll.dll | 2080 | ZwQuerySystemInformation | |
ntdll.dll | 1029 | RtlGUIDFromString | |
ntdll.dll | 1488 | RtlStringFromGUID | |
ntdll.dll | 2030 | ZwQueryAttributesFile | |
ntdll.dll | 2232 | ZwWaitForSingleObject | |
ntdll.dll | 2062 | ZwQueryKey | |
ntdll.dll | 2107 | ZwReleaseMutant | |
ntdll.dll | 1989 | ZwOpenFile | |
ntdll.dll | 1997 | ZwOpenMutant | |
ntdll.dll | 1821 | ZwClose | |
ntdll.dll | 1854 | ZwCreateKey | |
ntdll.dll | 1960 | ZwLoadKey | |
ntdll.dll | 1900 | ZwDeleteValueKey | |
ntdll.dll | 1897 | ZwDeleteKey | |
ntdll.dll | 1913 | ZwEnumerateKey | |
ntdll.dll | 2085 | ZwQueryValueKey | |
ntdll.dll | 2179 | ZwSetSecurityObject | |
ntdll.dll | 2217 | ZwUnloadKey | |
ntdll.dll | 2191 | ZwSetValueKey | |
ntdll.dll | 1992 | ZwOpenKey | |
ntdll.dll | 1780 | ZwAllocateUuids | |
ntdll.dll | 2077 | ZwQuerySymbolicLinkObject | |
ntdll.dll | 1903 | ZwDeviceIoControlFile | |
ntdll.dll | 2039 | ZwQueryDirectoryObject | |
ntdll.dll | 2009 | ZwOpenSymbolicLinkObject | |
ntdll.dll | 1108 | RtlGetVersion | |
ntdll.dll | 1985 | ZwOpenDirectoryObject | |
ntdll.dll | 2051 | ZwQueryInformationProcess | |
ntdll.dll | 2048 | ZwQueryInformationFile | |
ntdll.dll | 2001 | ZwOpenProcess | |
ntdll.dll | 446 | NtOpenProcessTokenEx | |
ntdll.dll | 455 | NtOpenThreadTokenEx | |
ntdll.dll | 1121 | RtlImpersonateSelf | |
ntdll.dll | 452 | NtOpenSymbolicLinkObject | |
ntdll.dll | 520 | NtQuerySymbolicLinkObject | |
ntdll.dll | 475 | NtQueryBootEntryOrder | |
ntdll.dll | 476 | NtQueryBootOptions | |
ntdll.dll | 657 | NtTranslateFilePath | |
ntdll.dll | 428 | NtOpenDirectoryObject | |
ntdll.dll | 482 | NtQueryDirectoryObject | |
ntdll.dll | 353 | NtEnumerateBootEntries | |
ntdll.dll | 61 | EtwEventUnregister | |
ntdll.dll | 512 | NtQueryPerformanceCounter | |
bcrypt.dll | 13 | BCryptDestroyHash | |
bcrypt.dll | 39 | BCryptOpenAlgorithmProvider | |
bcrypt.dll | 6 | BCryptCreateHash | |
bcrypt.dll | 35 | BCryptHashData | |
bcrypt.dll | 33 | BCryptGetProperty | |
bcrypt.dll | 2 | BCryptCloseAlgorithmProvider | |
bcrypt.dll | 27 | BCryptFinishHash | |
CRYPT32.dll | 15 | CertAddStoreToCollection | |
CRYPT32.dll | 60 | CertFreeCTLContext | |
CRYPT32.dll | 8 | CertAddEncodedCertificateToStore | |
CRYPT32.dll | 177 | CryptMsgClose | |
CRYPT32.dll | 71 | CertGetEnhancedKeyUsage | |
CRYPT32.dll | 188 | CryptMsgUpdate | |
CRYPT32.dll | 69 | CertGetCertificateChain | |
CRYPT32.dll | 64 | CertFreeCertificateContext | |
CRYPT32.dll | 183 | CryptMsgGetAndVerifySigner | |
CRYPT32.dll | 57 | CertFindSubjectInCTL | |
CRYPT32.dll | 185 | CryptMsgOpenToDecode | |
CRYPT32.dll | 18 | CertCloseStore | |
CRYPT32.dll | 184 | CryptMsgGetParam | |
CRYPT32.dll | 25 | CertCreateCTLContext | |
CRYPT32.dll | 161 | CryptHashCertificate2 | |
CRYPT32.dll | 61 | CertFreeCertificateChain | |
CRYPT32.dll | 167 | CryptImportPublicKeyInfoEx | |
CRYPT32.dll | 89 | CertOpenStore | |
CRYPT32.dll | 118 | CertVerifyCertificateChainPolicy | |
CRYPT32.dll | 79 | CertGetSubjectCertificateFromStore | |
CRYPT32.dll | 132 | CryptDecodeObject | |
OLEAUT32.dll | 200 | ||
OLEAUT32.dll | 6 |
StringTable 040904B0
CompanyName | Microsoft Corporation |
FileDescription | Windows Componentization Platform Servicing API |
FileVersion | 10.0.22621.1906 (WinBuild.160101.0800) |
InternalName | WCPDll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | wcp.dll |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.22621.1906 |
VS_FIXEDFILEINFO
FileVersion | 10.0.22621.1906 |
ProductVersion | 10.0.22621.1906 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 1 |
FileSubtype | 0 |
Signers (1)
issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows Production PCA 2011
serial: 33000004158295A1A3D82E2857000000000415
Certificates (2)
Certificate: Data: Version: 3 (0x2) Serial Number: 33:00:00:04:15:82:95:a1:a3:d8:2e:28:57:00:00:00:00:04:15 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011 Validity Not Before: Feb 3 00:05:42 2023 GMT Not After : Feb 1 00:05:42 2024 GMT Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:f8:f6:2a:d0:be:d5:e2:cd:fe:36:f1:d7:55:85: 04:4a:9f:83:87:3d:c3:26:16:f0:a9:61:1e:cc:b6: d8:88:0c:33:a5:85:c0:17:9e:09:77:e9:af:80:12: 21:7a:70:95:f9:bf:f8:41:af:40:1b:e7:66:08:85: 6a:01:e1:56:69:71:5f:17:c0:22:80:d1:0d:0f:38: 15:9a:a1:b8:61:b3:f9:b0:87:70:53:29:39:9a:33: d6:43:30:99:fc:df:da:b8:e8:ed:5b:68:4a:6f:db: 9b:d2:14:7b:aa:0c:f9:0e:ec:0d:e7:2c:73:92:7b: 4e:d0:cf:b2:4d:40:53:d8:1b:02:bf:a1:02:69:1e: 3d:a6:57:ae:68:65:f9:c0:41:17:ab:2f:8d:5e:e9: cf:e8:a6:d2:75:81:72:52:4d:5b:9e:4a:f1:05:5e: ab:e5:6c:cd:2e:33:11:26:4e:6c:0a:51:86:81:e1: 69:6a:fc:03:be:3a:ee:5a:cf:83:3d:36:20:7c:1a: 35:4c:fa:7e:bc:72:3f:f1:70:f8:f0:f8:50:48:62: e6:2f:ef:08:33:fe:b9:b5:37:8e:04:df:29:8d:cf: ed:82:c9:30:7c:69:08:e5:92:43:32:3d:ca:b7:b2: a0:28:eb:5e:8d:c2:3c:50:b3:47:35:1b:e2:34:40: 84:6f Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Extended Key Usage: 1.3.6.1.4.1.311.10.3.6, Code Signing X509v3 Subject Key Identifier: 62:BB:E5:49:30:B4:04:62:37:6C:B3:20:90:44:8F:8D:75:70:6F:32 X509v3 Subject Alternative Name: DirName:/OU=Microsoft Corporation/serialNumber=229879\+500174 X509v3 Authority Key Identifier: A9:29:02:39:8E:16:C4:97:78:CD:90:F9:9E:4F:9A:E1:7C:55:AF:53 X509v3 CRL Distribution Points: Full Name: URI:http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl Authority Information Access: CA Issuers - URI:http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt X509v3 Basic Constraints: critical CA:FALSE Signature Algorithm: sha256WithRSAEncryption Signature Value: 30:e9:1c:73:87:9b:64:54:d8:c1:5e:15:11:60:c3:b4:f0:42: c3:a3:cd:d3:2a:af:15:6d:19:67:d1:95:f2:e1:27:9e:25:f4: 9e:61:0c:52:b1:ce:86:2f:b0:76:ce:10:e2:65:1a:9c:64:27: 5f:a3:d9:5f:c0:79:d3:83:9e:5f:2d:97:42:d0:bc:c6:a2:2e: b0:06:b3:5b:04:cd:3f:5e:40:9e:3a:99:1b:e3:85:41:14:14: b5:cf:a5:e3:3a:7d:9a:49:5a:ab:53:a2:e6:3c:15:96:93:a4: bd:bd:61:17:a3:99:bd:fe:bb:b8:d1:c1:85:c6:6d:3b:fe:42: dc:d8:f8:91:f7:a3:f3:6f:f3:c0:78:8e:cc:45:95:39:a0:8c: b0:05:fe:76:92:18:2d:b0:db:58:94:d3:83:55:66:47:2e:f7: 46:67:f4:31:2e:97:2c:ce:c1:1a:23:dc:4f:5e:48:08:02:f1: fe:35:3b:3b:37:a2:c3:4d:dc:d0:92:e8:3d:e1:20:37:9d:57: 6e:83:aa:96:89:69:fb:77:66:8a:cc:18:97:53:cb:16:e7:6c: 88:be:99:9f:e1:13:42:98:6d:fa:30:09:f3:42:26:ad:ec:b3: 87:e3:0d:98:32:46:14:35:dc:89:64:df:63:ce:7e:b8:2b:f2: f1:d6:c1:30
Certificate: Data: Version: 3 (0x2) Serial Number: 61:07:76:56:00:00:00:00:00:08 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010 Validity Not Before: Oct 19 18:41:42 2011 GMT Not After : Oct 19 18:51:42 2026 GMT Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:dd:0c:bb:a2:e4:2e:09:e3:e7:c5:f7:96:69:bc: 00:21:bd:69:33:33:ef:ad:04:cb:54:80:ee:06:83: bb:c5:20:84:d9:f7:d2:8b:f3:38:b0:ab:a4:ad:2d: 7c:62:79:05:ff:e3:4a:3f:04:35:20:70:e3:c4:e7: 6b:e0:9c:c0:36:75:e9:8a:31:dd:8d:70:e5:dc:37: b5:74:46:96:28:5b:87:60:23:2c:bf:dc:47:a5:67: f7:51:27:9e:72:eb:07:a6:c9:b9:1e:3b:53:35:7c: e5:d3:ec:27:b9:87:1c:fe:b9:c9:23:09:6f:a8:46: 91:c1:6e:96:3c:41:d3:cb:a3:3f:5d:02:6a:4d:ec: 69:1f:25:28:5c:36:ff:fd:43:15:0a:94:e0:19:b4: cf:df:c2:12:e2:c2:5b:27:ee:27:78:30:8b:5b:2a: 09:6b:22:89:53:60:16:2c:c0:68:1d:53:ba:ec:49: f3:9d:61:8c:85:68:09:73:44:5d:7d:a2:54:2b:dd: 79:f7:15:cf:35:5d:6c:1c:2b:5c:ce:bc:9c:23:8b: 6f:6e:b5:26:d9:36:13:c3:4f:d6:27:ae:b9:32:3b: 41:92:2c:e1:c7:cd:77:e8:aa:54:4e:f7:5c:0b:04: 87:65:b4:43:18:a8:b2:e0:6d:19:77:ec:5a:24:fa: 48:03 Exponent: 65537 (0x10001) X509v3 extensions: 1.3.6.1.4.1.311.21.1: ... X509v3 Subject Key Identifier: A9:29:02:39:8E:16:C4:97:78:CD:90:F9:9E:4F:9A:E1:7C:55:AF:53 1.3.6.1.4.1.311.20.2: . .S.u.b.C.A X509v3 Key Usage: Digital Signature, Certificate Sign, CRL Sign X509v3 Basic Constraints: critical CA:TRUE X509v3 Authority Key Identifier: D5:F6:56:CB:8F:E8:A2:5C:62:68:D1:3D:94:90:5B:D7:CE:9A:18:C4 X509v3 CRL Distribution Points: Full Name: URI:http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl Authority Information Access: CA Issuers - URI:http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt Signature Algorithm: sha256WithRSAEncryption Signature Value: 14:fc:7c:71:51:a5:79:c2:6e:b2:ef:39:3e:bc:3c:52:0f:6e: 2b:3f:10:13:73:fe:a8:68:d0:48:a6:34:4d:8a:96:05:26:ee: 31:46:90:61:79:d6:ff:38:2e:45:6b:f4:c0:e5:28:b8:da:1d: 8f:8a:db:09:d7:1a:c7:4c:0a:36:66:6a:8c:ec:1b:d7:04:90: a8:18:17:a4:9b:b9:e2:40:32:36:76:c4:c1:5a:c6:bf:e4:04: c0:ea:16:d3:ac:c3:68:ef:62:ac:dd:54:6c:50:30:58:a6:eb: 7c:fe:94:a7:4e:8e:f4:ec:7c:86:73:57:c2:52:21:73:34:5a: f3:a3:8a:56:c8:04:da:07:09:ed:f8:8b:e3:ce:f4:7e:8e:ae: f0:f6:0b:8a:08:fb:3f:c9:1d:72:7f:53:b8:eb:be:63:e0:e3: 3d:31:65:b0:81:e5:f2:ac:cd:16:a4:9f:3d:a8:b1:9b:c2:42: d0:90:84:5f:54:1d:ff:89:ea:ba:1d:47:90:6f:b0:73:4e:41: 9f:40:9f:5f:e5:a1:2a:b2:11:91:73:8a:21:28:f0:ce:de:73: 39:5f:3e:ab:5c:60:ec:df:03:10:a8:d3:09:e9:f4:f6:96:85: b6:7f:51:88:66:47:19:8d:a2:b0:12:3d:81:2a:68:05:77:bb: 91:4c:62:7b:b6:c1:07:c7:ba:7a:87:34:03:0e:4b:62:7a:99: e9:ca:fc:ce:4a:37:c9:2d:a4:57:7c:1c:fe:3d:dc:b8:0f:5a: fa:d6:c4:b3:02:85:02:3a:ea:b3:d9:6e:e4:69:21:37:de:81: d1:f6:75:19:05:67:d3:93:57:5e:29:1b:39:c8:ee:2d:e1:cd: e4:45:73:5b:d0:d2:ce:7a:ab:16:19:82:46:58:d0:5e:9d:81: b3:67:af:6c:35:f2:bc:e5:3f:24:e2:35:a2:0a:75:06:f6:18: 56:99:d4:78:2c:d1:05:1b:eb:d0:88:01:9d:aa:10:f1:05:df: ba:7e:2c:63:b7:06:9b:23:21:c4:f9:78:6c:e2:58:17:06:36: 2b:91:12:03:cc:a4:d9:f2:2d:ba:f9:94:9d:40:ed:18:45:f1: ce:8a:5c:6b:3e:ab:03:d3:70:18:2a:0a:6a:e0:5f:47:d1:d5: 63:0a:32:f2:af:d7:36:1f:2a:70:5a:e5:42:59:08:71:4b:57: ba:7e:83:81:f0:21:3c:f4:1c:c1:c5:b9:90:93:0e:88:45:93: 86:e9:b1:20:99:be:98:cb:c5:95:a4:5d:62:d6:a0:63:08:20: bd:75:10:77:7d:3d:f3:45:b9:9f:97:9f:cb:57:80:6f:33:a9: 04:cf:77:a4:62:1c:59:7e
undefined method `first' for #
offset | size | type | comment | |
---|---|---|---|---|
0 | 3148800 | DLL | 10/03/2077 05:55:42 | # |
15c1 | 15 | HTM | # | |
300c00 | 9584 | PKCS7 | Authenticode Signature | # |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] can't find file_offset of VA 0x2e0614