filename | sysmon.ocx | |
---|---|---|
size | 407040 (0x63600) | |
md5 | 48433ffc1be7c854827de53baf0f3c0f | |
type | PE32+ executable (DLL) (GUI) x86-64, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xe8 |
Rich Header
lib id | version | times used |
---|---|---|
261 | 26715 | 3 |
260 | 26715 | 27 |
259 | 26715 | 3 |
1 | 0 | 367 |
257 | 26715 | 27 |
256 | 26715 | 1 |
265 | 26715 | 58 |
255 | 26715 | 1 |
258 | 26715 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Sections
Data Directory
module_name | hint | ord | function_name |
---|---|---|---|
msvcrt.dll | 75 | _CxxThrowException | |
msvcrt.dll | 1087 | floor | |
msvcrt.dll | 1154 | log10 | |
msvcrt.dll | 1170 | memcpy | |
msvcrt.dll | 1174 | memset | |
msvcrt.dll | 656 | _onexit | |
msvcrt.dll | 123 | __dllonexit | |
msvcrt.dll | 833 | _unlock | |
msvcrt.dll | 486 | _lock | |
msvcrt.dll | 47 | void __cdecl terminate(void) ?terminate@@YAXXZ | |
msvcrt.dll | 18 | public: virtual __cdecl type_info::~type_info(void) __ptr64 ??1type_info@@UEAA@XZ | |
msvcrt.dll | 381 | _initterm | |
msvcrt.dll | 174 | _amsg_exit | |
msvcrt.dll | 85 | _XcptFilter | |
msvcrt.dll | 1193 | realloc | |
msvcrt.dll | 1281 | wcschr | |
msvcrt.dll | 13 | public: __cdecl exception::exception(void) __ptr64 ??0exception@@QEAA@XZ | |
msvcrt.dll | 871 | _vsnprintf_s | |
msvcrt.dll | 91 | __CxxFrameHandler3 | |
msvcrt.dll | 12 | public: __cdecl exception::exception(class exception const & __ptr64) __ptr64 ??0exception@@QEAA@AEBV0@@Z | |
msvcrt.dll | 17 | public: virtual __cdecl exception::~exception(void) __ptr64 ??1exception@@UEAA@XZ | |
msvcrt.dll | 1100 | free | |
msvcrt.dll | 1158 | malloc | |
msvcrt.dll | 1259 | towlower | |
msvcrt.dll | 1030 | _wtoi64 | |
msvcrt.dll | 1296 | wcsrchr | |
msvcrt.dll | 1029 | _wtoi | |
msvcrt.dll | 1246 | swscanf_s | |
msvcrt.dll | 1299 | wcsspn | |
msvcrt.dll | 1286 | wcscspn | |
msvcrt.dll | 1236 | strstr | |
msvcrt.dll | 680 | _resetstkoflw | |
msvcrt.dll | 1300 | wcsstr | |
msvcrt.dll | 1302 | wcstok | |
msvcrt.dll | 670 | _purecall | |
msvcrt.dll | 873 | _vsnwprintf | |
msvcrt.dll | 42 | public: char const * __ptr64 __cdecl type_info::name(void)const __ptr64 ?name@type_info@@QEBAPEBDXZ | |
msvcrt.dll | 87 | __C_specific_handler | |
msvcrt.dll | 1171 | memcpy_s | |
msvcrt.dll | 1179 | pow | |
ATL.DLL | 41 | ||
ATL.DLL | 30 | ||
ntdll.dll | 747 | RtlCaptureContext | |
ntdll.dll | 1532 | RtlVirtualUnwind | |
ntdll.dll | 1720 | WinSqmSetDWORD | |
ntdll.dll | 1700 | WinSqmAddToStream | |
ntdll.dll | 1716 | WinSqmIncrementDWORD | |
ntdll.dll | 1699 | WinSqmAddToAverageDWORD | |
ntdll.dll | 1235 | RtlLookupFunctionEntry | |
KERNEL32.dll | 134 | CloseHandle | |
KERNEL32.dll | 846 | HeapAlloc | |
KERNEL32.dll | 699 | GetProcessHeap | |
KERNEL32.dll | 853 | HeapReAlloc | |
KERNEL32.dll | 850 | HeapFree | |
KERNEL32.dll | 203 | CreateFileW | |
KERNEL32.dll | 1606 | lstrcmpiW | |
KERNEL32.dll | 2 | ActivateActCtx | |
KERNEL32.dll | 259 | DeactivateActCtx | |
KERNEL32.dll | 967 | LoadLibraryW | |
KERNEL32.dll | 375 | FindActCtxSectionStringW | |
KERNEL32.dll | 176 | CreateActCtxW | |
KERNEL32.dll | 1343 | SetLastError | |
KERNEL32.dll | 634 | GetModuleFileNameW | |
KERNEL32.dll | 637 | GetModuleHandleExW | |
KERNEL32.dll | 1092 | QueryActCtxW | |
KERNEL32.dll | 1051 | OutputDebugStringA | |
KERNEL32.dll | 693 | GetProcAddress | |
KERNEL32.dll | 822 | GlobalAlloc | |
KERNEL32.dll | 833 | GlobalLock | |
KERNEL32.dll | 840 | GlobalUnlock | |
KERNEL32.dll | 716 | GetProfileIntW | |
KERNEL32.dll | 1226 | ResetEvent | |
KERNEL32.dll | 1549 | WideCharToMultiByte | |
KERNEL32.dll | 1010 | MultiByteToWideChar | |
KERNEL32.dll | 242 | CreateThread | |
KERNEL32.dll | 477 | GetCommandLineW | |
KERNEL32.dll | 829 | GlobalFree | |
KERNEL32.dll | 390 | FindFirstFileW | |
KERNEL32.dll | 379 | FindClose | |
KERNEL32.dll | 594 | GetFileSize | |
KERNEL32.dll | 1143 | ReadFile | |
KERNEL32.dll | 1569 | WriteFile | |
KERNEL32.dll | 485 | GetComputerNameW | |
KERNEL32.dll | 552 | GetDateFormatW | |
KERNEL32.dll | 787 | GetTimeFormatW | |
KERNEL32.dll | 368 | FileTimeToSystemTime | |
KERNEL32.dll | 155 | CompareStringW | |
KERNEL32.dll | 1009 | MulDiv | |
KERNEL32.dll | 429 | FormatMessageW | |
KERNEL32.dll | 433 | FreeLibrary | |
KERNEL32.dll | 619 | GetLocaleInfoW | |
KERNEL32.dll | 666 | GetNumberFormatW | |
KERNEL32.dll | 412 | FindResourceW | |
KERNEL32.dll | 970 | LoadResource | |
KERNEL32.dll | 990 | LockResource | |
KERNEL32.dll | 360 | ExpandEnvironmentStringsW | |
KERNEL32.dll | 1303 | SetCurrentDirectoryW | |
KERNEL32.dll | 546 | GetCurrentThreadId | |
KERNEL32.dll | 633 | GetModuleFileNameA | |
KERNEL32.dll | 263 | DebugBreak | |
KERNEL32.dll | 638 | GetModuleHandleW | |
KERNEL32.dll | 898 | IsDebuggerPresent | |
KERNEL32.dll | 1052 | OutputDebugStringW | |
KERNEL32.dll | 1208 | ReleaseSemaphore | |
KERNEL32.dll | 1204 | ReleaseMutex | |
KERNEL32.dll | 1511 | WaitForSingleObjectEx | |
KERNEL32.dll | 1044 | OpenSemaphoreW | |
KERNEL32.dll | 542 | GetCurrentProcessId | |
KERNEL32.dll | 217 | CreateMutexExW | |
KERNEL32.dll | 235 | CreateSemaphoreExW | |
KERNEL32.dll | 804 | GetVersionExW | |
KERNEL32.dll | 1419 | Sleep | |
KERNEL32.dll | 1468 | UnhandledExceptionFilter | |
KERNEL32.dll | 1403 | SetUnhandledExceptionFilter | |
KERNEL32.dll | 541 | GetCurrentProcess | |
KERNEL32.dll | 1434 | TerminateProcess | |
KERNEL32.dll | 1104 | QueryPerformanceCounter | |
KERNEL32.dll | 752 | GetSystemTimeAsFileTime | |
KERNEL32.dll | 1387 | SetThreadPriority | |
KERNEL32.dll | 191 | CreateEventW | |
KERNEL32.dll | 1316 | SetEvent | |
KERNEL32.dll | 782 | GetTickCount | |
KERNEL32.dll | 1510 | WaitForSingleObject | |
KERNEL32.dll | 1430 | SystemTimeToFileTime | |
KERNEL32.dll | 616 | GetLocalTime | |
KERNEL32.dll | 960 | LeaveCriticalSection | |
KERNEL32.dll | 309 | EnterCriticalSection | |
KERNEL32.dll | 871 | InitializeCriticalSection | |
KERNEL32.dll | 273 | DeleteCriticalSection | |
KERNEL32.dll | 615 | GetLastError | |
KERNEL32.dll | 1603 | lstrcmpW | |
ADVAPI32.dll | 652 | RegOpenKeyExW | |
ADVAPI32.dll | 603 | RegCloseKey | |
ADVAPI32.dll | 612 | RegCreateKeyExW | |
ADVAPI32.dll | 289 | EventRegister | |
ADVAPI32.dll | 291 | EventUnregister | |
ADVAPI32.dll | 292 | EventWrite | |
ADVAPI32.dll | 665 | RegQueryValueExW | |
USER32.dll | 77 | ClientToScreen | |
USER32.dll | 400 | GetParent | |
USER32.dll | 167 | DefWindowProcW | |
USER32.dll | 488 | GetWindowLongW | |
USER32.dll | 885 | SetWindowLongW | |
USER32.dll | 450 | GetSysColor | |
USER32.dll | 650 | MessageBoxW | |
USER32.dll | 571 | IsRectEmpty | |
USER32.dll | 91 | CopyRect | |
USER32.dll | 454 | GetSystemMetrics | |
USER32.dll | 343 | GetFocus | |
USER32.dll | 212 | DrawFrameControl | |
USER32.dll | 222 | DrawTextW | |
USER32.dll | 210 | DrawFocusRect | |
USER32.dll | 656 | MoveWindow | |
USER32.dll | 360 | GetKeyState | |
USER32.dll | 760 | ReleaseCapture | |
USER32.dll | 613 | LoadStringW | |
USER32.dll | 209 | DrawEdge | |
USER32.dll | 815 | SetDlgItemInt | |
USER32.dll | 780 | SendDlgItemMessageW | |
USER32.dll | 333 | GetDlgItemInt | |
USER32.dll | 587 | IsWindowVisible | |
USER32.dll | 610 | LoadMenuW | |
USER32.dll | 233 | EnableMenuItem | |
USER32.dll | 449 | GetSubMenu | |
USER32.dll | 930 | TrackPopupMenu | |
USER32.dll | 178 | DestroyMenu | |
USER32.dll | 592 | LoadAcceleratorsW | |
USER32.dll | 555 | IsChild | |
USER32.dll | 583 | IsWindowEnabled | |
USER32.dll | 936 | TranslateMessage | |
USER32.dll | 189 | DispatchMessageW | |
USER32.dll | 934 | TranslateAcceleratorW | |
USER32.dll | 942 | UnionRect | |
USER32.dll | 667 | OpenClipboard | |
USER32.dll | 310 | GetClipboardData | |
USER32.dll | 79 | CloseClipboard | |
USER32.dll | 232 | EmptyClipboard | |
USER32.dll | 801 | SetClipboardData | |
USER32.dll | 920 | SystemParametersInfoW | |
USER32.dll | 239 | EnableWindow | |
USER32.dll | 335 | GetDlgItemTextW | |
USER32.dll | 853 | SetPropW | |
USER32.dll | 432 | GetPropW | |
USER32.dll | 767 | RemovePropW | |
USER32.dll | 106 | CreateDialogParamW | |
USER32.dll | 286 | GetAncestor | |
USER32.dll | 326 | GetDialogBaseUnits | |
USER32.dll | 884 | SetWindowLongPtrW | |
USER32.dll | 559 | IsDialogMessageW | |
USER32.dll | 817 | SetDlgItemTextW | |
USER32.dll | 71 | CheckRadioButton | |
USER32.dll | 279 | FrameRect | |
USER32.dll | 581 | IsWindow | |
USER32.dll | 594 | LoadBitmapW | |
USER32.dll | 444 | GetScrollPos | |
USER32.dll | 858 | SetScrollRange | |
USER32.dll | 445 | GetScrollRange | |
USER32.dll | 777 | ScrollWindow | |
USER32.dll | 857 | SetScrollPos | |
USER32.dll | 962 | UpdateWindow | |
USER32.dll | 560 | IsDlgButtonChecked | |
USER32.dll | 695 | PtInRect | |
USER32.dll | 114 | CreatePopupMenu | |
USER32.dll | 539 | InsertMenuItemW | |
USER32.dll | 638 | MapWindowPoints | |
USER32.dll | 931 | TrackPopupMenuEx | |
USER32.dll | 282 | GetActiveWindow | |
USER32.dll | 590 | KillTimer | |
USER32.dll | 871 | SetTimer | |
USER32.dll | 793 | SetCapture | |
USER32.dll | 544 | InvalidateRect | |
USER32.dll | 887 | SetWindowPos | |
USER32.dll | 543 | IntersectRect | |
USER32.dll | 521 | InflateRect | |
USER32.dll | 267 | EqualRect | |
USER32.dll | 118 | CreateWindowExW | |
USER32.dll | 598 | LoadCursorW | |
USER32.dll | 732 | RegisterClassW | |
USER32.dll | 904 | ShowWindow | |
USER32.dll | 842 | SetParent | |
USER32.dll | 820 | SetFocus | |
USER32.dll | 734 | RegisterClipboardFormatW | |
USER32.dll | 854 | SetRect | |
USER32.dll | 947 | UnregisterClassW | |
USER32.dll | 181 | DestroyWindow | |
USER32.dll | 325 | GetDesktopWindow | |
USER32.dll | 322 | GetDC | |
USER32.dll | 66 | CheckDlgButton | |
USER32.dll | 761 | ReleaseDC | |
USER32.dll | 272 | FillRect | |
USER32.dll | 666 | OffsetRect | |
USER32.dll | 307 | GetClientRect | |
USER32.dll | 479 | GetWindowDC | |
USER32.dll | 332 | GetDlgItem | |
USER32.dll | 821 | SetForegroundWindow | |
USER32.dll | 685 | PostMessageW | |
USER32.dll | 495 | GetWindowRect | |
USER32.dll | 487 | GetWindowLongPtrW | |
USER32.dll | 244 | EndPaint | |
USER32.dll | 17 | BeginPaint | |
USER32.dll | 474 | GetWindow | |
USER32.dll | 805 | SetCursor | |
USER32.dll | 789 | SendMessageW | |
USER32.dll | 855 | SetRectEmpty | |
GDI32.dll | 889 | SetMapMode | |
GDI32.dll | 31 | CloseMetaFile | |
GDI32.dll | 382 | DeleteMetaFile | |
GDI32.dll | 793 | RectVisible | |
GDI32.dll | 914 | SetWindowOrgEx | |
GDI32.dll | 913 | SetWindowExtEx | |
GDI32.dll | 910 | SetViewportOrgEx | |
GDI32.dll | 909 | SetViewportExtEx | |
GDI32.dll | 697 | GetStockObject | |
GDI32.dll | 41 | CreateBitmap | |
GDI32.dll | 79 | CreatePen | |
GDI32.dll | 74 | CreateMetaFileW | |
GDI32.dll | 804 | RestoreDC | |
GDI32.dll | 811 | SaveDC | |
GDI32.dll | 737 | LPtoDP | |
GDI32.dll | 794 | Rectangle | |
GDI32.dll | 78 | CreatePatternBrush | |
GDI32.dll | 49 | CreateCompatibleDC | |
GDI32.dll | 926 | TextOutW | |
GDI32.dll | 720 | GetTextFaceW | |
GDI32.dll | 52 | CreateDCW | |
GDI32.dll | 722 | GetTextMetricsW | |
GDI32.dll | 739 | LineTo | |
GDI32.dll | 757 | MoveToEx | |
GDI32.dll | 380 | DeleteDC | |
GDI32.dll | 860 | SelectObject | |
GDI32.dll | 466 | ExtTextOutW | |
GDI32.dll | 531 | GdiFlush | |
GDI32.dll | 55 | CreateDIBSection | |
GDI32.dll | 714 | GetTextExtentPoint32W | |
GDI32.dll | 905 | SetTextAlign | |
GDI32.dll | 83 | CreateRectRgn | |
GDI32.dll | 34 | CombineRgn | |
GDI32.dll | 907 | SetTextColor | |
GDI32.dll | 858 | SelectClipRgn | |
GDI32.dll | 617 | GetClipBox | |
GDI32.dll | 769 | PatBlt | |
GDI32.dll | 867 | SetBkColor | |
GDI32.dll | 48 | CreateCompatibleBitmap | |
GDI32.dll | 630 | GetDeviceCaps | |
GDI32.dll | 680 | GetObjectW | |
GDI32.dll | 67 | CreateFontIndirectW | |
GDI32.dll | 90 | CreateSolidBrush | |
GDI32.dll | 717 | GetTextExtentPointW | |
GDI32.dll | 383 | DeleteObject | |
GDI32.dll | 786 | Polyline | |
GDI32.dll | 868 | SetBkMode | |
ole32.dll | 473 | ReleaseStgMedium | |
ole32.dll | 171 | CreateStreamOnHGlobal | |
ole32.dll | 524 | StringFromGUID2 | |
ole32.dll | 140 | CoTaskMemFree | |
ole32.dll | 168 | CreateOleAdviseHolder | |
ole32.dll | 158 | CreateBindCtx | |
ole32.dll | 442 | OleRegEnumVerbs | |
ole32.dll | 444 | OleRegGetUserType | |
ole32.dll | 443 | OleRegGetMiscStatus | |
ole32.dll | 105 | CoLockObjectExternal | |
ole32.dll | 81 | CoGetMalloc | |
ole32.dll | 160 | CreateDataAdviseHolder | |
ole32.dll | 43 | CoCreateInstance | |
ole32.dll | 195 | GetRunningObjectTable | |
ole32.dll | 161 | CreateDataCache | |
ole32.dll | 472 | RegisterDragDrop | |
ole32.dll | 475 | RevokeDragDrop | |
ole32.dll | 542 | WriteFmtUserTypeStg | |
OLEAUT32.dll | 411 | ||
OLEAUT32.dll | 24 | ||
OLEAUT32.dll | 23 | ||
OLEAUT32.dll | 16 | ||
OLEAUT32.dll | 161 | ||
OLEAUT32.dll | 162 | ||
OLEAUT32.dll | 185 | ||
OLEAUT32.dll | 184 | ||
OLEAUT32.dll | 416 | ||
OLEAUT32.dll | 4 | ||
OLEAUT32.dll | 417 | ||
OLEAUT32.dll | 147 | ||
OLEAUT32.dll | 6 | ||
OLEAUT32.dll | 2 | ||
OLEAUT32.dll | 421 | ||
OLEAUT32.dll | 420 | ||
OLEAUT32.dll | 29 | ||
OLEAUT32.dll | 8 | ||
OLEAUT32.dll | 12 | ||
OLEAUT32.dll | 7 | ||
OLEAUT32.dll | 9 | ||
pdh.dll | 89 | PdhParseCounterPathW | |
pdh.dll | 48 | PdhGetCounterInfoW | |
pdh.dll | 95 | PdhRemoveCounter | |
pdh.dll | 15 | PdhCalculateCounterFromRawValue | |
pdh.dll | 27 | PdhEnumLogSetNamesW | |
pdh.dll | 44 | PdhExpandWildCardPathHW | |
pdh.dll | 16 | PdhCloseLog | |
pdh.dll | 101 | PdhSetDefaultRealTimeDataSource | |
pdh.dll | 21 | PdhComputeCounterStatistics | |
pdh.dll | 72 | PdhGetRawCounterValue | |
pdh.dll | 20 | PdhCollectQueryDataWithTime | |
pdh.dll | 103 | PdhSetQueryTimeRange | |
pdh.dll | 10 | PdhBindInputDataSourceW | |
pdh.dll | 51 | PdhGetDataSourceTimeRangeH | |
pdh.dll | 81 | PdhMakeCounterPathW | |
pdh.dll | 34 | PdhEnumObjectItemsHW | |
pdh.dll | 38 | PdhEnumObjectsHW | |
pdh.dll | 94 | PdhRelogW | |
pdh.dll | 107 | PdhTranslateLocaleCounterW | |
pdh.dll | 105 | PdhTranslate009CounterW | |
pdh.dll | 68 | PdhGetLogFileTypeW | |
pdh.dll | 17 | PdhCloseQuery | |
pdh.dll | 18 | PdhCollectQueryData | |
pdh.dll | 30 | PdhEnumMachinesHW | |
pdh.dll | 86 | PdhOpenQueryH | |
pdh.dll | 3 | PdhAddCounterW | |
SHELL32.dll | 7 | CommandLineToArgvW | |
SHELL32.dll | 40 | DragQueryFileW | |
SHELL32.dll | 36 | DragFinish | |
SHELL32.dll | 35 | DragAcceptFiles | |
ODBC32.dll | 31 | ||
ODBC32.dll | 24 | ||
ODBC32.dll | 157 | ||
ODBC32.dll | 75 | ||
pdhui.dll | 3 | PdhUiBrowseCountersExHW |
ord | entry_va | function_name | |
---|---|---|---|
1 | 0x7d80 | DllCanUnloadNow | |
2 | 0x7ae0 | DllGetClassObject | |
3 | 0x56d0 | DllRegisterServer | |
4 | 0x56d0 | DllUnregisterServer |
StringTable 040904B0
CompanyName | Microsoft Corporation |
FileDescription | System Monitor Control |
FileVersion | 10.0.18362.1 (WinBuild.160101.0800) |
InternalName | SYSMON.OCX |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SYSMON.OCX |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.18362.1 |
OleSelfRegister |
VS_FIXEDFILEINFO
FileVersion | 10.0.18362.1 |
ProductVersion | 10.0.18362.1 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 2 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK