filename | apphelp.dll | |
---|---|---|
size | 576000 (0x8ca00) | |
md5 | 919899e1bfc7a239a2ed278cd8494806 | |
type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xe8 |
Rich Header
lib id | version | times used |
---|---|---|
147 | 30729 | 38 |
1 | 0 | 259 |
239 | 40116 | 5 |
241 | 40116 | 6 |
242 | 40116 | 8 |
238 | 40116 | 1 |
251 | 40116 | 79 |
237 | 40116 | 1 |
240 | 40116 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
module_name | hint | ord | function_name |
---|---|---|---|
ntdll.dll | 1795 | ZwOpenProcessToken | |
ntdll.dll | 1841 | ZwQueryInformationToken | |
ntdll.dll | 1785 | ZwOpenKey | |
ntdll.dll | 1870 | ZwQueryValueKey | |
ntdll.dll | 1659 | ZwCreateKey | |
ntdll.dll | 970 | RtlGetFullPathName_UEx | |
ntdll.dll | 1838 | ZwQueryInformationProcess | |
ntdll.dll | 1942 | ZwSetInformationProcess | |
ntdll.dll | 1269 | RtlSecondsSince1970ToTime | |
ntdll.dll | 148 | LdrResSearchResource | |
ntdll.dll | 2173 | strncmp | |
ntdll.dll | 1938 | ZwSetInformationFile | |
ntdll.dll | 1879 | ZwReadFile | |
ntdll.dll | 732 | RtlCompareMemory | |
ntdll.dll | 1012 | RtlImageDirectoryEntryToData | |
ntdll.dll | 226 | NtApphelpCacheControl | |
ntdll.dll | 1191 | RtlQueryEnvironmentVariable_U | |
ntdll.dll | 851 | RtlDosPathNameToNtPathName_U_WithStatus | |
ntdll.dll | 775 | RtlCreateEnvironmentEx | |
ntdll.dll | 1287 | RtlSetEnvironmentVar | |
ntdll.dll | 1324 | RtlSizeHeap | |
ntdll.dll | 836 | RtlDestroyEnvironment | |
ntdll.dll | 483 | NtReadFile | |
ntdll.dll | 618 | NtWriteFile | |
ntdll.dll | 2155 | qsort | |
ntdll.dll | 2213 | wcsspn | |
ntdll.dll | 2092 | _vscwprintf | |
ntdll.dll | 967 | RtlGetFileMUIPath | |
ntdll.dll | 439 | NtQueryInformationFile | |
ntdll.dll | 574 | NtSetValueKey | |
ntdll.dll | 304 | NtDeleteValueKey | |
ntdll.dll | 1005 | RtlGetVersion | |
ntdll.dll | 1865 | ZwQuerySystemInformation | |
ntdll.dll | 850 | RtlDosPathNameToNtPathName_U | |
ntdll.dll | 261 | NtCreateKey | |
ntdll.dll | 544 | NtSetInformationKey | |
ntdll.dll | 301 | NtDeleteKey | |
ntdll.dll | 691 | RtlAppendUnicodeStringToString | |
ntdll.dll | 1716 | ZwEnumerateValueKey | |
ntdll.dll | 1369 | RtlUnicodeStringToInteger | |
ntdll.dll | 1970 | ZwSetValueKey | |
ntdll.dll | 1479 | SbSelectProcedure | |
ntdll.dll | 442 | NtQueryInformationProcess | |
ntdll.dll | 2117 | atol | |
ntdll.dll | 2078 | _strnicmp | |
ntdll.dll | 1333 | RtlSubAuthorityCountSid | |
ntdll.dll | 1334 | RtlSubAuthoritySid | |
ntdll.dll | 787 | RtlCreateServiceSid | |
ntdll.dll | 1160 | RtlNtStatusToDosError | |
ntdll.dll | 883 | RtlEqualSid | |
ntdll.dll | 959 | RtlGetDaclSecurityDescriptor | |
ntdll.dll | 1008 | RtlIdentifierAuthoritySid | |
ntdll.dll | 2207 | wcsncmp | |
ntdll.dll | 64 | EtwEventWriteNoRegistration | |
ntdll.dll | 425 | NtQueryAttributesFile | |
ntdll.dll | 456 | NtQueryObject | |
ntdll.dll | 2107 | _wcsupr_s | |
ntdll.dll | 674 | RtlAddVectoredExceptionHandler | |
ntdll.dll | 2076 | _strlwr | |
ntdll.dll | 2180 | strstr | |
ntdll.dll | 2099 | _wcslwr | |
ntdll.dll | 678 | RtlAllocateAndInitializeSid | |
ntdll.dll | 718 | RtlCheckTokenMembership | |
ntdll.dll | 939 | RtlFreeSid | |
ntdll.dll | 130 | LdrLoadDll | |
ntdll.dll | 2162 | sscanf_s | |
ntdll.dll | 124 | LdrGetProcedureAddressEx | |
ntdll.dll | 123 | LdrGetProcedureAddress | |
ntdll.dll | 1120 | RtlLengthRequiredSid | |
ntdll.dll | 386 | NtOpenFile | |
ntdll.dll | 464 | NtQuerySecurityObject | |
ntdll.dll | 986 | RtlGetOwnerSecurityDescriptor | |
ntdll.dll | 423 | NtProtectVirtualMemory | |
ntdll.dll | 1049 | RtlInitializeSRWLock | |
ntdll.dll | 107 | LdrEnumerateLoadedModules | |
ntdll.dll | 646 | RtlAcquireSRWLockExclusive | |
ntdll.dll | 1245 | RtlReleaseSRWLockExclusive | |
ntdll.dll | 647 | RtlAcquireSRWLockShared | |
ntdll.dll | 1246 | RtlReleaseSRWLockShared | |
ntdll.dll | 1675 | ZwCreateSection | |
ntdll.dll | 1771 | ZwMapViewOfSection | |
ntdll.dll | 1999 | ZwUnmapViewOfSection | |
ntdll.dll | 1835 | ZwQueryInformationFile | |
ntdll.dll | 1848 | ZwQueryKey | |
ntdll.dll | 1654 | ZwCreateFile | |
ntdll.dll | 2198 | wcscat_s | |
ntdll.dll | 2202 | wcscpy_s | |
ntdll.dll | 884 | RtlEqualString | |
ntdll.dll | 2168 | strcpy_s | |
ntdll.dll | 1019 | RtlInitAnsiString | |
ntdll.dll | 2165 | strchr | |
ntdll.dll | 2159 | sprintf_s | |
ntdll.dll | 1636 | ZwClose | |
ntdll.dll | 1228 | RtlReAllocateHeap | |
ntdll.dll | 2199 | wcschr | |
ntdll.dll | 2189 | toupper | |
ntdll.dll | 1389 | RtlUpcaseUnicodeChar | |
ntdll.dll | 1390 | RtlUpcaseUnicodeString | |
ntdll.dll | 1474 | RtlxAnsiStringToUnicodeSize | |
ntdll.dll | 178 | NlsMbCodePageTag | |
ntdll.dll | 1027 | RtlInitString | |
ntdll.dll | 943 | RtlGUIDFromString | |
ntdll.dll | 1288 | RtlSetEnvironmentVariable | |
ntdll.dll | 2212 | wcsrchr | |
ntdll.dll | 1367 | RtlUnicodeStringToAnsiString | |
ntdll.dll | 709 | RtlCaptureContext | |
ntdll.dll | 848 | RtlDoesFileExists_U | |
ntdll.dll | 792 | RtlCreateUnicodeString | |
ntdll.dll | 2101 | _wcsnicmp | |
ntdll.dll | 2095 | _vsnwprintf | |
ntdll.dll | 126 | LdrInitShimEngineDynamic | |
ntdll.dll | 687 | RtlAnsiStringToUnicodeString | |
ntdll.dll | 1020 | RtlInitAnsiStringEx | |
ntdll.dll | 710 | RtlCaptureStackBackTrace | |
ntdll.dll | 1119 | RtlLeaveCriticalSection | |
ntdll.dll | 871 | RtlEnterCriticalSection | |
ntdll.dll | 1347 | RtlTimeToTimeFields | |
ntdll.dll | 2093 | _vsnprintf | |
ntdll.dll | 2075 | _stricmp | |
ntdll.dll | 2178 | strrchr | |
ntdll.dll | 2110 | _wtoi | |
ntdll.dll | 819 | RtlDeleteCriticalSection | |
ntdll.dll | 1037 | RtlInitializeCriticalSection | |
ntdll.dll | 109 | LdrFindEntryForAddress | |
ntdll.dll | 60 | EtwEventWrite | |
ntdll.dll | 59 | EtwEventUnregister | |
ntdll.dll | 55 | EtwEventEnabled | |
ntdll.dll | 57 | EtwEventRegister | |
ntdll.dll | 1030 | RtlInitUnicodeString | |
ntdll.dll | 2098 | _wcsicmp | |
ntdll.dll | 2214 | wcsstr | |
ntdll.dll | 116 | LdrGetDllHandle | |
ntdll.dll | 238 | NtClose | |
ntdll.dll | 895 | RtlExpandEnvironmentStrings_U | |
ntdll.dll | 474 | NtQueryValueKey | |
ntdll.dll | 389 | NtOpenKey | |
ntdll.dll | 859 | RtlDuplicateUnicodeString | |
ntdll.dll | 1330 | RtlStringFromGUID | |
ntdll.dll | 692 | RtlAppendUnicodeToString | |
ntdll.dll | 765 | RtlCopyUnicodeString | |
ntdll.dll | 930 | RtlFormatCurrentUserKeyPath | |
ntdll.dll | 256 | NtCreateFile | |
ntdll.dll | 934 | RtlFreeAnsiString | |
ntdll.dll | 936 | RtlFreeHeap | |
ntdll.dll | 681 | RtlAllocateHeap | |
ntdll.dll | 941 | RtlFreeUnicodeString | |
ntdll.dll | 1159 | RtlNtPathNameToDosPathName | |
ntdll.dll | 2151 | memmove | |
ntdll.dll | 1443 | RtlpEnsureBufferSize | |
ntdll.dll | 2185 | swprintf_s | |
ntdll.dll | 1031 | RtlInitUnicodeStringEx | |
ntdll.dll | 2042 | _chkstk | |
ntdll.dll | 2148 | memcmp | |
ntdll.dll | 2149 | memcpy | |
ntdll.dll | 2153 | memset | |
ntdll.dll | 1388 | RtlUnwind | |
api-ms-win-core-appcompat-l1-1-1.dll | 4 | BaseFlushAppcompatCache | |
api-ms-win-core-appcompat-l1-1-1.dll | 5 | BaseFreeAppCompatDataForProcess | |
api-ms-win-core-appcompat-l1-1-1.dll | 7 | BaseIsAppcompatInfrastructureDisabled | |
api-ms-win-core-appcompat-l1-1-1.dll | 8 | BaseReadAppCompatDataForProcess | |
api-ms-win-core-handle-l1-1-0.dll | CloseHandle | ||
api-ms-win-core-file-l1-2-1.dll | 89 | WriteFile | |
api-ms-win-core-file-l1-2-1.dll | 42 | GetFileAttributesW | |
api-ms-win-core-file-l1-2-1.dll | 20 | FindFirstFileW | |
api-ms-win-core-file-l1-2-1.dll | 9 | DeleteFileW | |
api-ms-win-core-file-l1-2-1.dll | 49 | GetFinalPathNameByHandleW | |
api-ms-win-core-file-l1-2-1.dll | 38 | GetDriveTypeW | |
api-ms-win-core-file-l1-2-1.dll | 83 | SetFilePointer | |
api-ms-win-core-file-l1-2-1.dll | 12 | FindClose | |
api-ms-win-core-file-l1-2-1.dll | 26 | FindNextFileW | |
api-ms-win-core-file-l1-2-1.dll | 60 | GetTempPathW | |
api-ms-win-core-file-l1-2-1.dll | 55 | GetLongPathNameW | |
api-ms-win-core-file-l1-2-1.dll | 6 | CreateFileW | |
api-ms-win-core-processthreads-l1-1-2.dll | 75 | TerminateProcess | |
api-ms-win-core-processthreads-l1-1-2.dll | 47 | OpenProcess | |
api-ms-win-core-processthreads-l1-1-2.dll | 17 | GetCurrentThreadId | |
api-ms-win-core-processthreads-l1-1-2.dll | 13 | GetCurrentProcessId | |
api-ms-win-core-processthreads-l1-1-2.dll | 3 | CreateProcessW | |
api-ms-win-core-processthreads-l1-1-2.dll | 12 | GetCurrentProcess | |
api-ms-win-core-processthreads-l1-1-2.dll | 30 | GetProcessTimes | |
api-ms-win-core-processthreads-l1-1-2.dll | 6 | CreateThread | |
api-ms-win-core-processthreads-l1-1-2.dll | 19 | GetExitCodeProcess | |
api-ms-win-core-processthreads-l1-1-2.dll | 51 | ProcessIdToSessionId | |
api-ms-win-core-synch-l1-2-0.dll | 13 | CreateWaitableTimerExW | |
api-ms-win-core-synch-l1-2-0.dll | 42 | SetWaitableTimer | |
api-ms-win-core-synch-l1-2-0.dll | 17 | EnterCriticalSection | |
api-ms-win-core-synch-l1-2-0.dll | 29 | LeaveCriticalSection | |
api-ms-win-core-synch-l1-2-0.dll | 25 | InitializeCriticalSectionAndSpinCount | |
api-ms-win-core-synch-l1-2-0.dll | 54 | WaitForSingleObject | |
api-ms-win-core-synch-l1-2-0.dll | 32 | OpenMutexW | |
api-ms-win-core-libraryloader-l1-2-0.dll | 19 | GetModuleHandleW | |
api-ms-win-core-libraryloader-l1-2-0.dll | 31 | SizeofResource | |
api-ms-win-core-libraryloader-l1-2-0.dll | 23 | LoadLibraryExW | |
api-ms-win-core-libraryloader-l1-2-0.dll | 1 | DisableThreadLibraryCalls | |
api-ms-win-core-libraryloader-l1-2-0.dll | 28 | LockResource | |
api-ms-win-core-libraryloader-l1-2-0.dll | 20 | GetProcAddress | |
api-ms-win-core-libraryloader-l1-2-0.dll | 25 | LoadResource | |
api-ms-win-core-libraryloader-l1-2-0.dll | 15 | GetModuleFileNameW | |
api-ms-win-core-libraryloader-l1-2-0.dll | 11 | FreeLibrary | |
api-ms-win-core-libraryloader-l1-2-0.dll | 18 | GetModuleHandleExW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 11 | GetEnvironmentVariableW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 21 | SetEnvironmentVariableW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 9 | GetEnvironmentStringsW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 3 | FreeEnvironmentStringsW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 7 | GetCurrentDirectoryW | |
api-ms-win-core-processenvironment-l1-2-0.dll | 1 | ExpandEnvironmentStringsW | |
api-ms-win-core-errorhandling-l1-1-1.dll | 5 | GetLastError | |
api-ms-win-core-errorhandling-l1-1-1.dll | 17 | UnhandledExceptionFilter | |
api-ms-win-core-errorhandling-l1-1-1.dll | 15 | SetUnhandledExceptionFilter | |
api-ms-win-core-errorhandling-l1-1-1.dll | 13 | SetLastError | |
api-ms-win-core-sysinfo-l1-2-1.dll | 20 | GetSystemTimeAsFileTime | |
api-ms-win-core-sysinfo-l1-2-1.dll | 24 | GetTickCount | |
api-ms-win-core-sysinfo-l1-2-1.dll | 15 | GetSystemDirectoryW | |
api-ms-win-core-sysinfo-l1-2-1.dll | 25 | GetTickCount64 | |
api-ms-win-core-sysinfo-l1-2-1.dll | 23 | GetSystemWindowsDirectoryW | |
api-ms-win-core-debug-l1-1-1.dll | 4 | DebugBreak | |
api-ms-win-core-debug-l1-1-1.dll | 6 | OutputDebugStringA | |
api-ms-win-core-profile-l1-1-0.dll | QueryPerformanceCounter | ||
api-ms-win-eventing-provider-l1-1-0.dll | 4 | EventSetInformation | |
api-ms-win-eventing-provider-l1-1-0.dll | 3 | EventRegister | |
api-ms-win-eventing-provider-l1-1-0.dll | 5 | EventUnregister | |
api-ms-win-eventing-provider-l1-1-0.dll | 9 | EventWriteTransfer | |
api-ms-win-eventing-provider-l1-1-0.dll | 6 | EventWrite | |
KERNEL32.dll | 948 | LocalFree | |
KERNEL32.dll | 238 | CreateToolhelp32Snapshot | |
KERNEL32.dll | 1402 | Thread32Next | |
KERNEL32.dll | 1401 | Thread32First | |
KERNEL32.dll | 1502 | Wow64RevertWow64FsRedirection | |
KERNEL32.dll | 1498 | Wow64DisableWow64FsRedirection | |
KERNEL32.dll | 1023 | PackageIdFromFullName | |
KERNEL32.dll | 944 | LocalAlloc | |
KERNEL32.dll | 650 | GetPackageFullName | |
KERNEL32.dll | 889 | IsWow64Process | |
api-ms-win-security-base-l1-2-0.dll | 42 | EqualSid | |
api-ms-win-security-base-l1-2-0.dll | 45 | GetAce | |
api-ms-win-security-base-l1-2-0.dll | 46 | GetAclInformation | |
api-ms-win-security-base-l1-2-0.dll | 54 | GetSecurityDescriptorDacl | |
api-ms-win-security-base-l1-2-0.dll | 22 | AllocateAndInitializeSid | |
api-ms-win-core-registry-l1-1-0.dll | RegCloseKey | ||
api-ms-win-core-registry-l1-1-0.dll | 18 | RegGetKeySecurity | |
api-ms-win-core-libraryloader-l1-2-1.dll | 9 | FindResourceW | |
api-ms-win-core-localization-obsolete-l1-3-0.dll | 8 | GetUserDefaultUILanguage | |
api-ms-win-core-localization-l1-2-1.dll | 61 | VerLanguageNameW | |
api-ms-win-core-localization-l1-2-1.dll | 39 | IsDBCSLeadByte | |
api-ms-win-core-string-l1-1-0.dll | 7 | WideCharToMultiByte |
StringTable 040904B0
CompanyName | Microsoft Corporation |
FileDescription | Application Compatibility Client Library |
FileVersion | 10.0.10240.16384 (th1.150709-1700) |
InternalName | Apphelp |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | Apphelp |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.10240.16384 |
VS_FIXEDFILEINFO
FileVersion | 10.0.10240.16384 |
ProductVersion | 10.0.10240.16384 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x40004 |
FileType | 2 |
FileSubtype | 0 |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK