| filename | nativewindow.dll | |
|---|---|---|
| size | 89800 (0x15ec8) | |
| md5 | fc0eb67d7fa7b42833dc813c61dc7674 | |
| type | PE32+ executable (DLL) (GUI) x86-64, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x100 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 199 | 41118 | 2 |
| 223 | 20806 | 1 |
| 224 | 20806 | 14 |
| 225 | 20806 | 14 |
| 221 | 20806 | 6 |
| 203 | 65501 | 12 |
| 221 | 31101 | 3 |
| 1 | 0 | 118 |
| 225 | 31101 | 4 |
| 220 | 31101 | 1 |
| 222 | 31101 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
| module_name | hint | ord | function_name |
|---|---|---|---|
| RmgrTools3.dll | 451 | void __cdecl memutil_free(void * __ptr64) ?memutil_free@@YAXPEAX@Z | |
| RmgrTools3.dll | 447 | void * __ptr64 __cdecl memutil_calloc(unsigned __int64, unsigned __int64, int) ?memutil_calloc@@YAPEAX_K0H@Z | |
| USER32.dll | 79 | CloseWindow | |
| USER32.dll | 551 | LoadIconW | |
| USER32.dll | 161 | DefWindowProcW | |
| USER32.dll | 849 | UnregisterClassW | |
| USER32.dll | 808 | ShowWindow | |
| USER32.dll | 791 | SetWindowPos | |
| USER32.dll | 295 | GetClientRect | |
| USER32.dll | 751 | SetParent | |
| KERNEL32.dll | 297 | EnterCriticalSection | |
| KERNEL32.dll | 1021 | OutputDebugStringW | |
| KERNEL32.dll | 1459 | VirtualQuery | |
| KERNEL32.dll | 279 | DisableThreadLibraryCalls | |
| KERNEL32.dll | 733 | GetSystemTimeAsFileTime | |
| KERNEL32.dll | 532 | GetCurrentThreadId | |
| KERNEL32.dll | 528 | GetCurrentProcessId | |
| KERNEL32.dll | 1072 | QueryPerformanceCounter | |
| KERNEL32.dll | 255 | DecodePointer | |
| KERNEL32.dll | 1092 | RaiseException | |
| KERNEL32.dll | 598 | GetLastError | |
| KERNEL32.dll | 827 | HeapDestroy | |
| KERNEL32.dll | 824 | HeapAlloc | |
| KERNEL32.dll | 831 | HeapReAlloc | |
| KERNEL32.dll | 828 | HeapFree | |
| KERNEL32.dll | 833 | HeapSize | |
| KERNEL32.dll | 681 | GetProcessHeap | |
| KERNEL32.dll | 850 | InitializeCriticalSectionEx | |
| KERNEL32.dll | 262 | DeleteCriticalSection | |
| KERNEL32.dll | 621 | GetModuleHandleW | |
| KERNEL32.dll | 933 | LeaveCriticalSection | |
| KERNEL32.dll | 780 | GetVersion | |
| KERNEL32.dll | 420 | FreeLibrary | |
| KERNEL32.dll | 617 | GetModuleFileNameW | |
| KERNEL32.dll | 1561 | lstrcpyW | |
| KERNEL32.dll | 1552 | lstrcatW | |
| KERNEL32.dll | 939 | LoadLibraryW | |
| KERNEL32.dll | 315 | EnumResourceLanguagesW | |
| KERNEL32.dll | 602 | GetLocaleInfoW | |
| KERNEL32.dll | 720 | GetSystemDefaultLangID | |
| KERNEL32.dll | 774 | GetUserDefaultLangID | |
| KERNEL32.dll | 880 | IsProcessorFeaturePresent | |
| KERNEL32.dll | 1501 | WideCharToMultiByte | |
| KERNEL32.dll | 980 | MultiByteToWideChar | |
| KERNEL32.dll | 938 | LoadLibraryExW | |
| KERNEL32.dll | 874 | IsDebuggerPresent | |
| KERNEL32.dll | 293 | EncodePointer | |
| KERNEL32.dll | 1061 | QueryActCtxW | |
| KERNEL32.dll | 362 | FindActCtxSectionStringW | |
| KERNEL32.dll | 248 | DeactivateActCtx | |
| KERNEL32.dll | 2 | ActivateActCtx | |
| KERNEL32.dll | 168 | CreateActCtxW | |
| KERNEL32.dll | 676 | GetProcAddress | |
| KERNEL32.dll | 849 | InitializeCriticalSectionAndSpinCount | |
| KERNEL32.dll | 1305 | SetLastError | |
| KERNEL32.dll | 1020 | OutputDebugStringA | |
| KERNEL32.dll | 620 | GetModuleHandleExW | |
| mfc120u.dll | 1486 | ||
| mfc120u.dll | 1484 | ||
| mfc120u.dll | 1636 | ||
| mfc120u.dll | 296 | ||
| mfc120u.dll | 286 | ||
| mfc120u.dll | 1030 | ||
| mfc120u.dll | 1498 | ||
| mfc120u.dll | 359 | ||
| mfc120u.dll | 13452 | ||
| mfc120u.dll | 1051 | ||
| mfc120u.dll | 2170 | ||
| mfc120u.dll | 7775 | ||
| MSVCR120.dll | 1829 | swscanf | |
| MSVCR120.dll | 1425 | _wtoi | |
| MSVCR120.dll | 348 | __C_specific_handler | |
| MSVCR120.dll | 859 | _lock | |
| MSVCR120.dll | 1223 | _unlock | |
| MSVCR120.dll | 1300 | _wcsicmp | |
| MSVCR120.dll | 415 | __dllonexit | |
| MSVCR120.dll | 1026 | _onexit | |
| MSVCR120.dll | 322 | _CRT_RTC_INITW | |
| MSVCR120.dll | 349 | __CppXcptFilter | |
| MSVCR120.dll | 498 | _amsg_exit | |
| MSVCR120.dll | 876 | _malloc_crt | |
| MSVCR120.dll | 737 | _initterm | |
| MSVCR120.dll | 738 | _initterm_e | |
| MSVCR120.dll | 307 | void __cdecl terminate(void) ?terminate@@YAXXZ | |
| MSVCR120.dll | 413 | __crt_debugger_hook | |
| MSVCR120.dll | 412 | __crtUnhandledException | |
| MSVCR120.dll | 411 | __crtTerminateProcess | |
| MSVCR120.dll | 381 | __crtCaptureCurrentContext | |
| MSVCR120.dll | 382 | __crtCapturePreviousContext | |
| MSVCR120.dll | 283 | public: void __cdecl type_info::_type_info_dtor_internal_method(void) __ptr64 ?_type_info_dtor_internal_method@type_info@@QEAAXXZ | |
| MSVCR120.dll | 379 | __clean_type_info_names_internal | |
| MSVCR120.dll | 1181 | _swprintf | |
| MSVCR120.dll | 354 | __CxxFrameHandler3 | |
| MSVCR120.dll | 325 | _CxxThrowException | |
| MSVCR120.dll | 730 | _hypot | |
| MSVCR120.dll | 1616 | free | |
| MSVCR120.dll | 1719 | memmove | |
| MSVCR120.dll | 1805 | strlen | |
| MSVCR120.dll | 1721 | memset | |
| MSVCR120.dll | 1717 | memcpy | |
| MSVCR120.dll | 1038 | _purecall | |
| MSVCR120.dll | 1050 | _recalloc | |
| MSVCR120.dll | 1720 | memmove_s | |
| MSVCR120.dll | 521 | _calloc_crt | |
| ADVAPI32.dll | 596 | RegCloseKey | |
| ADVAPI32.dll | 645 | RegOpenKeyExW | |
| ADVAPI32.dll | 658 | RegQueryValueExW | |
| SHLWAPI.dll | 75 | PathFindExtensionW | |
| OLEAUT32.dll | 6 | ||
| MSVCP120.dll | 713 | void __cdecl std::_Xbad_alloc(void) ?_Xbad_alloc@std@@YAXXZ | |
| MSVCP120.dll | 716 | void __cdecl std::_Xlength_error(char const * __ptr64) ?_Xlength_error@std@@YAXPEBD@Z | |
| MSVCP120.dll | 688 | char const * __ptr64 __cdecl std::_Syserror_map(int) ?_Syserror_map@std@@YAPEBDH@Z | |
| MSVCP120.dll | 717 | void __cdecl std::_Xout_of_range(char const * __ptr64) ?_Xout_of_range@std@@YAXPEBD@Z | |
| MSVCP120.dll | 118 | public: __cdecl std::locale::id::id(unsigned __int64) __ptr64 ??0id@locale@std@@QEAA@_K@Z | |
| MSVCP120.dll | 709 | char const * __ptr64 __cdecl std::_Winerror_map(int) ?_Winerror_map@std@@YAPEBDH@Z | |
| VERSION.dll | 8 | GetFileVersionInfoW | |
| VERSION.dll | 7 | GetFileVersionInfoSizeW | |
| VERSION.dll | 16 | VerQueryValueW |
StringTable 040904B0
| CompanyName | Bentley Systems, Incorporated |
| FileDescription | nativewindow for Windows |
| FileVersion | 99.99.99.99 (Debug) |
| InternalName | nativewindow.dll |
| LegalCopyright | Copyright © 2015 Bentley Systems, Incorporated. All rights reserved. |
| OriginalFilename | nativewindow.dll |
| ProductName | PseudoStation |
| ProductVersion | 99.99.99.99 (Debug) |
| PrivateBuild | Built by Michael.Butvinnik on BUTVM8064VILL (Debug) FOR INTERNAL USE ONLY |
VS_FIXEDFILEINFO
| FileVersion | 99.99.99.99 |
| ProductVersion | 99.99.99.99 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0xb |
| FileOS | 0x40004 |
| FileType | 2 |
| FileSubtype | 0 |
Signers (1)
issuer: /CN=\x00*\x00*\x00*\x00 \x00B\x00e\x00n\x00t\x00l\x00e\x00y\x00 \x00I\x00n\x00t\x00e\x00r\x00n\x00a\x00l\x00 \x00D\x00e\x00v\x00e\x00l\x00o\x00p\x00e\x00r\x00 \x00B\x00u\x00i\x00l\x00d\x00 \x00*\x00*\x00*
serial: -1CD2352519767E57BD00894295EAFA08
Certificates (1)
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
(Negative)1c:d2:35:25:19:76:7e:57:bd:00:89:42:95:ea:fa:08
Signature Algorithm: md5WithRSAEncryption
Issuer: CN=\x00*\x00*\x00*\x00 \x00B\x00e\x00n\x00t\x00l\x00e\x00y\x00 \x00I\x00n\x00t\x00e\x00r\x00n\x00a\x00l\x00 \x00D\x00e\x00v\x00e\x00l\x00o\x00p\x00e\x00r\x00 \x00B\x00u\x00i\x00l\x00d\x00 \x00*\x00*\x00*
Validity
Not Before: Oct 10 19:48:23 2012 GMT
Not After : Dec 31 23:59:59 2039 GMT
Subject: CN=\x00*\x00*\x00*\x00 \x00B\x00e\x00n\x00t\x00l\x00e\x00y\x00 \x00I\x00n\x00t\x00e\x00r\x00n\x00a\x00l\x00 \x00D\x00e\x00v\x00e\x00l\x00o\x00p\x00e\x00r\x00 \x00B\x00u\x00i\x00l\x00d\x00 \x00*\x00*\x00*
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (1024 bit)
Modulus:
00:be:6f:43:a1:9d:75:8b:5e:64:f5:d9:f6:40:63:
eb:43:fd:b6:21:bb:8e:ec:4f:7b:04:46:3e:db:29:
26:12:6b:85:6a:11:f6:06:9a:be:21:1d:60:78:f7:
42:0b:3b:5a:f2:6f:e1:51:31:59:0a:83:de:34:85:
3a:06:ec:3b:4c:74:2f:ce:32:17:cf:97:5b:53:99:
6a:70:68:7d:d2:3d:66:d8:2a:e9:c6:27:87:fa:6e:
ab:a3:d5:17:9d:82:59:40:1e:64:88:c9:13:28:c0:
f0:f2:c8:3e:64:28:79:fe:ce:01:c1:03:87:9f:1b:
42:d5:9e:ee:df:5b:5f:f5:1f
Exponent: 65537 (0x10001)
X509v3 extensions:
2.5.29.1:
0....c.&4....").\f5...]0[1Y0W..U...P.*.*.*. .B.e.n.t.l.e.y. .I.n.t.e.r.n.a.l. .D.e.v.e.l.o.p.e.r. .B.u.i.l.d. .*.*.*...-......B.v.j...
Signature Algorithm: md5WithRSAEncryption
Signature Value:
bc:3a:db:78:22:f7:14:f0:be:4b:61:92:6e:ec:9f:74:42:2f:
f2:48:db:98:44:aa:cf:59:06:83:2f:06:97:37:f7:f1:d7:c3:
89:42:39:de:38:11:6b:39:15:df:e4:16:91:ee:a5:6d:09:49:
8c:cf:14:44:c9:eb:e1:15:11:b7:55:33:6c:08:90:f8:d4:c2:
c2:e2:68:8f:8f:77:3e:e8:34:8b:eb:ec:e6:29:81:55:6f:a1:
c5:ab:f0:fd:bc:3c:57:31:d4:06:c8:45:8d:26:91:b6:22:83:
98:a2:e3:28:01:e4:ac:32:1b:3d:79:ac:9e:e8:9d:07:9c:f6:
3a:eb
pkcs7-signedData
- 1
- SHA1: nil
- 1.3.6.1.4.1.311.2.1.4
- #0
- 1.3.6.1.4.1.311.2.1.15
- :
- SHA1
53 22 31 6f 44 6f 4c a0 93 fb 20 e1 ec 39 65 c0 |S"1oDoL... ..9e.| eb 04 c2 93 |.... |
- 1.3.6.1.4.1.311.2.1.15
- #0
- #2
- 2
- -38309844129301339938521727223437392392
- RSA-MD5: nil
- CN:
00 2a 00 2a 00 2a 00 20 00 42 00 65 00 6e 00 74 |.*.*.*. .B.e.n.t| 00 6c 00 65 00 79 00 20 00 49 00 6e 00 74 00 65 |.l.e.y. .I.n.t.e| 00 72 00 6e 00 61 00 6c 00 20 00 44 00 65 00 76 |.r.n.a.l. .D.e.v| 00 65 00 6c 00 6f 00 70 00 65 00 72 00 20 00 42 |.e.l.o.p.e.r. .B| 00 75 00 69 00 6c 00 64 00 20 00 2a 00 2a 00 2a |.u.i.l.d. .*.*.*|
- 2012-10-10 19:48:23 UTC: 2039-12-31 23:59:59 UTC
- CN:
00 2a 00 2a 00 2a 00 20 00 42 00 65 00 6e 00 74 |.*.*.*. .B.e.n.t| 00 6c 00 65 00 79 00 20 00 49 00 6e 00 74 00 65 |.l.e.y. .I.n.t.e| 00 72 00 6e 00 61 00 6c 00 20 00 44 00 65 00 76 |.r.n.a.l. .D.e.v| 00 65 00 6c 00 6f 00 70 00 65 00 72 00 20 00 42 |.e.l.o.p.e.r. .B| 00 75 00 69 00 6c 00 64 00 20 00 2a 00 2a 00 2a |.u.i.l.d. .*.*.*|
- #5
- rsaEncryption: nil
- BE:6F:43:A1:9D:75:8B:5E:64:F5:D9:F6:40:63:EB:43:
FD:B6:21:BB:8E:EC:4F:7B:04:46:3E:DB:29:26:12:6B:
85:6A:11:F6:06:9A:BE:21:1D:60:78:F7:42:0B:3B:5A:
F2:6F:E1:51:31:59:0A:83:DE:34:85:3A:06:EC:3B:4C:
74:2F:CE:32:17:CF:97:5B:53:99:6A:70:68:7D:D2:3D:
66:D8:2A:E9:C6:27:87:FA:6E:AB:A3:D5:17:9D:82:59:
40:1E:64:88:C9:13:28:C0:F0:F2:C8:3E:64:28:79:FE:
CE:01:C1:03:87:9F:1B:42:D5:9E:EE:DF:5B:5F:F5:1F: 0x010001
- 2.5.29.1
63 7f 26 34 8c b3 c0 8e 22 29 0b 5c 66 35 d1 cc |c.&4....").\f5..|
- CN:
00 2a 00 2a 00 2a 00 20 00 42 00 65 00 6e 00 74 |.*.*.*. .B.e.n.t| 00 6c 00 65 00 79 00 20 00 49 00 6e 00 74 00 65 |.l.e.y. .I.n.t.e| 00 72 00 6e 00 61 00 6c 00 20 00 44 00 65 00 76 |.r.n.a.l. .D.e.v| 00 65 00 6c 00 6f 00 70 00 65 00 72 00 20 00 42 |.e.l.o.p.e.r. .B| 00 75 00 69 00 6c 00 64 00 20 00 2a 00 2a 00 2a |.u.i.l.d. .*.*.*|
e3 2d ca da e6 89 81 a8 42 ff 76 bd 6a 15 05 f8 |.-......B.v.j...|
- CN:
- RSA-MD5:
bc 3a db 78 22 f7 14 f0 be 4b 61 92 6e ec 9f 74 |.:.x"....Ka.n..t| 42 2f f2 48 db 98 44 aa cf 59 06 83 2f 06 97 37 |B/.H..D..Y../..7| f7 f1 d7 c3 89 42 39 de 38 11 6b 39 15 df e4 16 |.....B9.8.k9....| 91 ee a5 6d 09 49 8c cf 14 44 c9 eb e1 15 11 b7 |...m.I...D......| 55 33 6c 08 90 f8 d4 c2 c2 e2 68 8f 8f 77 3e e8 |U3l.......h..w>.| 34 8b eb ec e6 29 81 55 6f a1 c5 ab f0 fd bc 3c |4....).Uo......<| 57 31 d4 06 c8 45 8d 26 91 b6 22 83 98 a2 e3 28 |W1...E.&.."....(| 01 e4 ac 32 1b 3d 79 ac 9e e8 9d 07 9c f6 3a eb |...2.=y.......:.|
- 2
- 1
- #0
- CN:
00 2a 00 2a 00 2a 00 20 00 42 00 65 00 6e 00 74 |.*.*.*. .B.e.n.t| 00 6c 00 65 00 79 00 20 00 49 00 6e 00 74 00 65 |.l.e.y. .I.n.t.e| 00 72 00 6e 00 61 00 6c 00 20 00 44 00 65 00 76 |.r.n.a.l. .D.e.v| 00 65 00 6c 00 6f 00 70 00 65 00 72 00 20 00 42 |.e.l.o.p.e.r. .B| 00 75 00 69 00 6c 00 64 00 20 00 2a 00 2a 00 2a |.u.i.l.d. .*.*.*|
- -38309844129301339938521727223437392392
- CN:
- SHA1: nil
- #2
- 1.3.6.1.4.1.311.2.1.12
- nil
- contentType: 1.3.6.1.4.1.311.2.1.4
- messageDigest:
5d 72 4e b3 3e 51 ea 3a 87 eb 07 05 1a af f8 0b |]rN.>Q.:........| 83 56 59 f2 |.VY. |
- 1.3.6.1.4.1.311.2.1.12
- rsaEncryption:
69 9d 77 3f 03 fe 9e 80 ba 76 f7 a5 8c 02 9b 91 |i.w?.....v......| dd 6b b4 f9 1d e9 c1 cb 8d 8b 2c d9 52 b8 8d 91 |.k........,.R...| cd 41 69 a1 0b 90 7b 1c cd 1f ea f3 99 30 86 ef |.Ai...{......0..| a2 7a f9 8a e6 1c d2 d7 02 8d e4 6e 35 f7 f1 c5 |.z.........n5...| be a6 13 1f bf d5 2d 1a a4 c6 3f 76 0d c9 4a 21 |......-...?v..J!| 59 d0 f6 82 79 01 bf 6b 5a 15 83 5d 94 6b f3 6a |Y...y..kZ..].k.j| 8c fe de 05 13 cf 1e fc f3 92 90 b0 00 b1 01 c1 |................| 23 2c 54 95 4c 03 90 fe e7 33 3b ff 71 be 2f 9e |#,T.L....3;.q./.|
- #0
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )