VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Keylogger
Spyware
Dropper
|
Threat Names: |
Gen:Variant.Razy.609636
Gen:Variant.Razy.484160
Mal/Generic-S
|
sqlbrowser.exe
Windows Exe (x86-32)
Created at 2020-02-10T09:47:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sqlbrowser.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40ad73 |
Size Of Code | 0xc000 |
Size Of Initialized Data | 0x1c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2000-11-30 11:08:30+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Data Access - ActiveX Data Objects Resources |
FileVersion | 6.1.7601.19091 (win7sp1_gdr.151208-06 |
InternalName | wmvenc |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | wmvencod.dl |
ProductName | Microsoft® Windows® O |
ProductVersion | 6.1.7601.1 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb202 | 0xc000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.06 |
.bdata | 0x40d000 | 0x4fa8 | 0x5000 | 0xd000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.76 |
.data | 0x412000 | 0x234c | 0x1000 | 0x12000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.04 |
KVXrR | 0x415000 | 0x7269 | 0x8000 | 0x13000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.61 |
WcxS | 0x41d000 | 0x6f6b | 0x7000 | 0x1b000 | IMAGE_SCN_TYPE_NOLOAD, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.74 |
.rsrc | 0x424000 | 0x3fd7 | 0x4000 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.22 |
.reloc | 0x428000 | 0x600 | 0x1000 | 0x26000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.09 |
Imports (11)
»
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LookupPrivilegeDisplayNameW | 0x0 | 0x40d000 | 0x11a64 | 0x11a64 | 0x193 |
QueryServiceStatus | 0x0 | 0x40d004 | 0x11a68 | 0x11a68 | 0x228 |
GetLengthSid | 0x0 | 0x40d008 | 0x11a6c | 0x11a6c | 0x136 |
KERNEL32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetProcessAffinityMask | 0x0 | 0x40d038 | 0x11a9c | 0x11a9c | 0x47e |
GetQueuedCompletionStatus | 0x0 | 0x40d03c | 0x11aa0 | 0x11aa0 | 0x25e |
lstrcpynW | 0x0 | 0x40d040 | 0x11aa4 | 0x11aa4 | 0x54b |
Sleep | 0x0 | 0x40d044 | 0x11aa8 | 0x11aa8 | 0x4b2 |
GetModuleFileNameW | 0x0 | 0x40d048 | 0x11aac | 0x11aac | 0x214 |
GetModuleFileNameA | 0x0 | 0x40d04c | 0x11ab0 | 0x11ab0 | 0x213 |
GetTempFileNameW | 0x0 | 0x40d050 | 0x11ab4 | 0x11ab4 | 0x283 |
lstrcmpiW | 0x0 | 0x40d054 | 0x11ab8 | 0x11ab8 | 0x545 |
GetConsoleFontSize | 0x0 | 0x40d058 | 0x11abc | 0x11abc | 0x1a4 |
GetDiskFreeSpaceExA | 0x0 | 0x40d05c | 0x11ac0 | 0x11ac0 | 0x1cd |
GetVolumeInformationA | 0x0 | 0x40d060 | 0x11ac4 | 0x11ac4 | 0x2a5 |
GetFileTime | 0x0 | 0x40d064 | 0x11ac8 | 0x11ac8 | 0x1f2 |
GetCPInfo | 0x0 | 0x40d068 | 0x11acc | 0x11acc | 0x172 |
FindResourceExA | 0x0 | 0x40d06c | 0x11ad0 | 0x11ad0 | 0x14c |
GetCommandLineW | 0x0 | 0x40d070 | 0x11ad4 | 0x11ad4 | 0x187 |
GDI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtFloodFill | 0x0 | 0x40d018 | 0x11a7c | 0x11a7c | 0x135 |
GetTextMetricsA | 0x0 | 0x40d01c | 0x11a80 | 0x11a80 | 0x225 |
GetRasterizerCaps | 0x0 | 0x40d020 | 0x11a84 | 0x11a84 | 0x209 |
GetDeviceGammaRamp | 0x0 | 0x40d024 | 0x11a88 | 0x11a88 | 0x1cc |
GetBrushOrgEx | 0x0 | 0x40d028 | 0x11a8c | 0x11a8c | 0x1ad |
GetSystemPaletteUse | 0x0 | 0x40d02c | 0x11a90 | 0x11a90 | 0x213 |
GetStockObject | 0x0 | 0x40d030 | 0x11a94 | 0x11a94 | 0x20d |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindTextW | 0x0 | 0x40d010 | 0x11a74 | 0x11a74 | 0x8 |
Secur32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FreeContextBuffer | 0x0 | 0x40d08c | 0x11af0 | 0x11af0 | 0x18 |
WinSCard.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SCardIntroduceCardTypeW | 0x0 | 0x40d0d8 | 0x11b3c | 0x11b3c | 0x1d |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstUrlCacheEntryW | 0x0 | 0x40d0d0 | 0x11b34 | 0x11b34 | 0x19 |
msvcrt.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
fseek | 0x0 | 0x40d0e0 | 0x11b44 | 0x11b44 | 0x4ac |
system | 0x0 | 0x40d0e4 | 0x11b48 | 0x11b48 | 0x531 |
fwrite | 0x0 | 0x40d0e8 | 0x11b4c | 0x11b4c | 0x4b1 |
towupper | 0x0 | 0x40d0ec | 0x11b50 | 0x11b50 | 0x53c |
fwprintf | 0x0 | 0x40d0f0 | 0x11b54 | 0x11b54 | 0x4af |
malloc | 0x0 | 0x40d0f4 | 0x11b58 | 0x11b58 | 0x4de |
memset | 0x0 | 0x40d0f8 | 0x11b5c | 0x11b5c | 0x4ee |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VarCyFromUI4 | 0xe3 | 0x40d078 | 0x11adc | 0x11adc | - |
USER32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTopWindow | 0x0 | 0x40d094 | 0x11af8 | 0x11af8 | 0x185 |
GetFocus | 0x0 | 0x40d098 | 0x11afc | 0x11afc | 0x12c |
GetKBCodePage | 0x0 | 0x40d09c | 0x11b00 | 0x11b00 | 0x13a |
GetAsyncKeyState | 0x0 | 0x40d0a0 | 0x11b04 | 0x11b04 | 0x107 |
keybd_event | 0x0 | 0x40d0a4 | 0x11b08 | 0x11b08 | 0x330 |
SetWindowContextHelpId | 0x0 | 0x40d0a8 | 0x11b0c | 0x11b0c | 0x2c1 |
DrawTextW | 0x0 | 0x40d0ac | 0x11b10 | 0x11b10 | 0xd0 |
LoadMenuA | 0x0 | 0x40d0b0 | 0x11b14 | 0x11b14 | 0x1f4 |
GetWindowRect | 0x0 | 0x40d0b4 | 0x11b18 | 0x11b18 | 0x19c |
GetKeyboardLayoutNameW | 0x0 | 0x40d0b8 | 0x11b1c | 0x11b1c | 0x141 |
IsZoomed | 0x0 | 0x40d0bc | 0x11b20 | 0x11b20 | 0x1e2 |
GetMenuDefaultItem | 0x0 | 0x40d0c0 | 0x11b24 | 0x11b24 | 0x14f |
GetMenuItemID | 0x0 | 0x40d0c4 | 0x11b28 | 0x11b28 | 0x152 |
DialogBoxParamW | 0x0 | 0x40d0c8 | 0x11b2c | 0x11b2c | 0xac |
POWRPROF.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsPwrHibernateAllowed | 0x0 | 0x40d080 | 0x11ae4 | 0x11ae4 | 0xf |
WriteGlobalPwrPolicy | 0x0 | 0x40d084 | 0x11ae8 | 0x11ae8 | 0x59 |
Memory Dumps (51)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Relevant Image |
![]() |
32-bit | 0x00409E3C |
![]() |
![]() |
...
|
buffer | 1 | 0x00260000 | 0x00265FFF | First Execution |
![]() |
32-bit | 0x00262679 |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040D03B |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040EBA4 |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x00402017 |
![]() |
![]() |
...
|
buffer | 1 | 0x00240000 | 0x00256FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00270000 | 0x00287FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
sqlbrowser.exe | 1 | 0x00400000 | 0x00428FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
dp1uhj~1:bin | 2 | 0x00400000 | 0x00428FFF | Relevant Image |
![]() |
32-bit | 0x00409E3C |
![]() |
![]() |
...
|
buffer | 2 | 0x003D0000 | 0x003D5FFF | First Execution |
![]() |
32-bit | 0x003D2679 |
![]() |
![]() |
...
|
dp1uhj~1:bin | 2 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
dp1uhj~1:bin | 2 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 23 | 0x00250000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00252679 |
![]() |
![]() |
...
|
vds.exe | 23 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
vds.exe | 23 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 2 | 0x00240000 | 0x00256FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x003E0000 | 0x003F7FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
q5v3jp~1:bin | 25 | 0x00400000 | 0x00428FFF | Relevant Image |
![]() |
32-bit | 0x00409E3C |
![]() |
![]() |
...
|
buffer | 25 | 0x00250000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00252679 |
![]() |
![]() |
...
|
q5v3jp~1:bin | 25 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040113A |
![]() |
![]() |
...
|
q5v3jp~1:bin | 25 | 0x00400000 | 0x00428FFF | Content Changed |
![]() |
32-bit | 0x0040BD8E |
![]() |
![]() |
...
|
buffer | 25 | 0x00230000 | 0x00246FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 23 | 0x00230000 | 0x00246FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 25 | 0x00260000 | 0x00277FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 67 | 0x00390000 | 0x00395FFF | First Execution |
![]() |
32-bit | 0x00392679 |
![]() |
![]() |
...
|
buffer | 67 | 0x00370000 | 0x00386FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 67 | 0x003A0000 | 0x003B7FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 68 | 0x00230000 | 0x00235FFF | First Execution |
![]() |
32-bit | 0x00232679 |
![]() |
![]() |
...
|
buffer | 69 | 0x00260000 | 0x00265FFF | First Execution |
![]() |
32-bit | 0x00262679 |
![]() |
![]() |
...
|
buffer | 79 | 0x00250000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00252679 |
![]() |
![]() |
...
|
buffer | 79 | 0x00230000 | 0x00246FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 79 | 0x00260000 | 0x00277FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 80 | 0x00250000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00252679 |
![]() |
![]() |
...
|
buffer | 69 | 0x00240000 | 0x00256FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 69 | 0x002F0000 | 0x00307FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 83 | 0x00250000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00252679 |
![]() |
![]() |
...
|
buffer | 90 | 0x00270000 | 0x00275FFF | First Execution |
![]() |
32-bit | 0x00272679 |
![]() |
![]() |
...
|
buffer | 91 | 0x00310000 | 0x00315FFF | First Execution |
![]() |
32-bit | 0x00312679 |
![]() |
![]() |
...
|
buffer | 96 | 0x003A0000 | 0x003A5FFF | First Execution |
![]() |
32-bit | 0x003A2679 |
![]() |
![]() |
...
|
buffer | 97 | 0x00390000 | 0x00395FFF | First Execution |
![]() |
32-bit | 0x00392679 |
![]() |
![]() |
...
|
buffer | 106 | 0x001C0000 | 0x001C5FFF | First Execution |
![]() |
32-bit | 0x001C2679 |
![]() |
![]() |
...
|
buffer | 106 | 0x00250000 | 0x00266FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 97 | 0x002F0000 | 0x00306FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 96 | 0x00380000 | 0x00396FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 91 | 0x002F0000 | 0x00306FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 90 | 0x001D0000 | 0x001E6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 83 | 0x00230000 | 0x00246FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 80 | 0x00230000 | 0x00246FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 68 | 0x00390000 | 0x003A6FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_32.db | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe:0 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41e582 |
Size Of Code | 0x1c600 |
Size Of Initialized Data | 0xc00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2015-06-20 05:07:19+00:00 |
Version Information (10)
»
Comments | Flavor=Retail |
CompanyName | Microsoft Corporation |
FileDescription | SMSvcHost.exe |
FileVersion | 4.6.81.0 built by: NETFXREL2 |
InternalName | SMSvcHost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | SMSvcHost.exe |
PrivateBuild | DDBLD031C |
ProductName | Microsoft® .NET Framework |
ProductVersion | 4.6.81.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1c5b8 | 0x1c600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.83 |
.rsrc | 0x420000 | 0x954 | 0xa00 | 0x1c800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.44 |
.reloc | 0x422000 | 0xc | 0x200 | 0x1d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1e555 | 0x1c755 | 0x0 |
Digital Signatures (2)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2015-06-04 17:42:45+00:00 |
Valid Until | 2016-09-04 17:42:45+00:00 |
Algorithm | sha1_rsa |
Serial Number | 33 00 00 01 0A 2C 79 AE D7 79 7B A6 AC 00 01 00 00 01 0A |
Thumbprint | 3B DA 32 3E 55 2D B1 FD E5 F4 FB EE 75 D6 D5 B2 B1 87 EE DC |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2010-08-31 22:19:32+00:00 |
Valid Until | 2020-08-31 22:29:32+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 33 26 1A 00 00 00 00 00 31 |
Thumbprint | 3C AF 9B A2 DB 55 70 CA F7 69 42 FF 99 10 1B 99 38 88 E2 57 |
C:\Windows\System32\vds.exe:0 | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x100000000 |
Entry Point | 0x10007546c |
Size Of Code | 0x7d800 |
Size Of Initialized Data | 0x5000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2010-11-20 09:47:12+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Virtual Disk Service |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | vds.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | vds.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x100001000 | 0x7d693 | 0x7d800 | 0x800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.2 |
.data | 0x10007f000 | 0x1578 | 0xa00 | 0x7e000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.28 |
.pdata | 0x100081000 | 0x2214 | 0x2400 | 0x7ea00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.51 |
.rsrc | 0x100084000 | 0x9e0 | 0xa00 | 0x80e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.6 |
.reloc | 0x100085000 | 0xb84 | 0xc00 | 0x81800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.78 |
Imports (28)
»
USER32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UnregisterDeviceNotification | 0x0 | 0x100001488 | 0x792a0 | 0x78aa0 | 0x30f |
DefWindowProcW | 0x0 | 0x100001490 | 0x792a8 | 0x78aa8 | 0x9c |
PeekMessageW | 0x0 | 0x100001498 | 0x792b0 | 0x78ab0 | 0x237 |
CharNextW | 0x0 | 0x1000014a0 | 0x792b8 | 0x78ab8 | 0x31 |
DispatchMessageW | 0x0 | 0x1000014a8 | 0x792c0 | 0x78ac0 | 0xaf |
GetMessageW | 0x0 | 0x1000014b0 | 0x792c8 | 0x78ac8 | 0x15f |
PostThreadMessageW | 0x0 | 0x1000014b8 | 0x792d0 | 0x78ad0 | 0x23d |
MessageBoxW | 0x0 | 0x1000014c0 | 0x792d8 | 0x78ad8 | 0x219 |
LoadStringW | 0x0 | 0x1000014c8 | 0x792e0 | 0x78ae0 | 0x1fe |
RegisterDeviceNotificationW | 0x0 | 0x1000014d0 | 0x792e8 | 0x78ae8 | 0x256 |
msvcrt.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memcmp | 0x0 | 0x1000014e0 | 0x792f8 | 0x78af8 | 0x47f |
_wcmdln | 0x0 | 0x1000014e8 | 0x79300 | 0x78b00 | 0x371 |
exit | 0x0 | 0x1000014f0 | 0x79308 | 0x78b08 | 0x420 |
_cexit | 0x0 | 0x1000014f8 | 0x79310 | 0x78b10 | 0xb3 |
_exit | 0x0 | 0x100001500 | 0x79318 | 0x78b18 | 0xff |
_XcptFilter | 0x0 | 0x100001508 | 0x79320 | 0x78b20 | 0x52 |
__C_specific_handler | 0x0 | 0x100001510 | 0x79328 | 0x78b28 | 0x53 |
__wgetmainargs | 0x0 | 0x100001518 | 0x79330 | 0x78b30 | 0x8f |
_ltow | 0x0 | 0x100001520 | 0x79338 | 0x78b38 | 0x1e1 |
swscanf_s | 0x0 | 0x100001528 | 0x79340 | 0x78b40 | 0x4cc |
wcscpy_s | 0x0 | 0x100001530 | 0x79348 | 0x78b48 | 0x4f3 |
towupper | 0x0 | 0x100001538 | 0x79350 | 0x78b50 | 0x4da |
wcsncmp | 0x0 | 0x100001540 | 0x79358 | 0x78b58 | 0x4f9 |
wcsstr | 0x0 | 0x100001548 | 0x79360 | 0x78b60 | 0x502 |
?terminate@@YAXXZ | 0x0 | 0x100001550 | 0x79368 | 0x78b68 | 0x30 |
_onexit | 0x0 | 0x100001558 | 0x79370 | 0x78b70 | 0x27f |
_lock | 0x0 | 0x100001560 | 0x79378 | 0x78b78 | 0x1d5 |
__dllonexit | 0x0 | 0x100001568 | 0x79380 | 0x78b80 | 0x6d |
_unlock | 0x0 | 0x100001570 | 0x79388 | 0x78b88 | 0x330 |
__set_app_type | 0x0 | 0x100001578 | 0x79390 | 0x78b90 | 0x80 |
_fmode | 0x0 | 0x100001580 | 0x79398 | 0x78b98 | 0x118 |
_commode | 0x0 | 0x100001588 | 0x793a0 | 0x78ba0 | 0xc4 |
__setusermatherr | 0x0 | 0x100001590 | 0x793a8 | 0x78ba8 | 0x82 |
_amsg_exit | 0x0 | 0x100001598 | 0x793b0 | 0x78bb0 | 0xa0 |
memcpy | 0x0 | 0x1000015a0 | 0x793b8 | 0x78bb8 | 0x480 |
memset | 0x0 | 0x1000015a8 | 0x793c0 | 0x78bc0 | 0x484 |
_purecall | 0x0 | 0x1000015b0 | 0x793c8 | 0x78bc8 | 0x28d |
??3@YAXPEAX@Z | 0x0 | 0x1000015b8 | 0x793d0 | 0x78bd0 | 0x15 |
_vsnwprintf | 0x0 | 0x1000015c0 | 0x793d8 | 0x78bd8 | 0x358 |
??2@YAPEAX_K@Z | 0x0 | 0x1000015c8 | 0x793e0 | 0x78be0 | 0x13 |
_wcsicmp | 0x0 | 0x1000015d0 | 0x793e8 | 0x78be8 | 0x379 |
_wcsnicmp | 0x0 | 0x1000015d8 | 0x793f0 | 0x78bf0 | 0x383 |
srand | 0x0 | 0x1000015e0 | 0x793f8 | 0x78bf8 | 0x4aa |
time | 0x0 | 0x1000015e8 | 0x79400 | 0x78c00 | 0x4d2 |
rand | 0x0 | 0x1000015f0 | 0x79408 | 0x78c08 | 0x495 |
_wtol | 0x0 | 0x1000015f8 | 0x79410 | 0x78c10 | 0x3f7 |
_initterm | 0x0 | 0x100001600 | 0x79418 | 0x78c18 | 0x16c |
ATL.DLL (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1e | 0x100001340 | 0x79158 | 0x78958 | - |
(by ordinal) | 0x14 | 0x100001348 | 0x79160 | 0x78960 | - |
(by ordinal) | 0x11 | 0x100001350 | 0x79168 | 0x78968 | - |
(by ordinal) | 0x10 | 0x100001358 | 0x79170 | 0x78970 | - |
(by ordinal) | 0x39 | 0x100001360 | 0x79178 | 0x78978 | - |
(by ordinal) | 0x12 | 0x100001368 | 0x79180 | 0x78980 | - |
(by ordinal) | 0x17 | 0x100001370 | 0x79188 | 0x78988 | - |
(by ordinal) | 0x20 | 0x100001378 | 0x79190 | 0x78990 | - |
ntdll.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlAcquireResourceExclusive | 0x0 | 0x100001610 | 0x79428 | 0x78c28 | 0x243 |
RtlDeleteResource | 0x0 | 0x100001618 | 0x79430 | 0x78c30 | 0x2e6 |
RtlConvertSharedToExclusive | 0x0 | 0x100001620 | 0x79438 | 0x78c38 | 0x29a |
RtlReleaseResource | 0x0 | 0x100001628 | 0x79440 | 0x78c40 | 0x459 |
RtlConvertExclusiveToShared | 0x0 | 0x100001630 | 0x79448 | 0x78c48 | 0x298 |
RtlAcquireResourceShared | 0x0 | 0x100001638 | 0x79450 | 0x78c50 | 0x244 |
RtlAdjustPrivilege | 0x0 | 0x100001640 | 0x79458 | 0x78c58 | 0x261 |
NtQueryVolumeInformationFile | 0x0 | 0x100001648 | 0x79460 | 0x78c60 | 0x1b1 |
RtlVirtualUnwind | 0x0 | 0x100001650 | 0x79468 | 0x78c68 | 0x4f1 |
RtlLookupFunctionEntry | 0x0 | 0x100001658 | 0x79470 | 0x78c70 | 0x402 |
RtlCaptureContext | 0x0 | 0x100001660 | 0x79478 | 0x78c78 | 0x27b |
RtlInitializeResource | 0x0 | 0x100001668 | 0x79480 | 0x78c80 | 0x3b3 |
API-MS-Win-Core-Debug-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OutputDebugStringW | 0x0 | 0x100001080 | 0x78e98 | 0x78698 | 0x3 |
API-MS-Win-Core-ErrorHandling-L1-1-0.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UnhandledExceptionFilter | 0x0 | 0x100001090 | 0x78ea8 | 0x786a8 | 0x6 |
SetUnhandledExceptionFilter | 0x0 | 0x100001098 | 0x78eb0 | 0x786b0 | 0x5 |
SetLastError | 0x0 | 0x1000010a0 | 0x78eb8 | 0x786b8 | 0x4 |
GetLastError | 0x0 | 0x1000010a8 | 0x78ec0 | 0x786c0 | 0x1 |
API-MS-Win-Core-File-L1-1-0.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDriveTypeW | 0x0 | 0x1000010b8 | 0x78ed0 | 0x786d0 | 0x1f |
QueryDosDeviceW | 0x0 | 0x1000010c0 | 0x78ed8 | 0x786d8 | 0x39 |
FindFirstVolumeW | 0x0 | 0x1000010c8 | 0x78ee0 | 0x786e0 | 0x13 |
RemoveDirectoryW | 0x0 | 0x1000010d0 | 0x78ee8 | 0x786e8 | 0x3e |
FindNextVolumeW | 0x0 | 0x1000010d8 | 0x78ef0 | 0x786f0 | 0x17 |
FindVolumeClose | 0x0 | 0x1000010e0 | 0x78ef8 | 0x786f8 | 0x18 |
DeleteVolumeMountPointW | 0x0 | 0x1000010e8 | 0x78f00 | 0x78700 | 0x8 |
DefineDosDeviceW | 0x0 | 0x1000010f0 | 0x78f08 | 0x78708 | 0x5 |
GetVolumePathNameW | 0x0 | 0x1000010f8 | 0x78f10 | 0x78710 | 0x35 |
WriteFile | 0x0 | 0x100001100 | 0x78f18 | 0x78718 | 0x49 |
SetFilePointerEx | 0x0 | 0x100001108 | 0x78f20 | 0x78720 | 0x44 |
CreateFileW | 0x0 | 0x100001110 | 0x78f28 | 0x78728 | 0x4 |
API-MS-Win-Core-Handle-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseHandle | 0x0 | 0x100001120 | 0x78f38 | 0x78738 | 0x0 |
API-MS-Win-Core-Heap-L1-1-0.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapAlloc | 0x0 | 0x100001130 | 0x78f48 | 0x78748 | 0x2 |
HeapSetInformation | 0x0 | 0x100001138 | 0x78f50 | 0x78750 | 0xa |
GetProcessHeap | 0x0 | 0x100001140 | 0x78f58 | 0x78758 | 0x0 |
HeapFree | 0x0 | 0x100001148 | 0x78f60 | 0x78760 | 0x6 |
API-MS-Win-Core-IO-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeviceIoControl | 0x0 | 0x100001158 | 0x78f70 | 0x78770 | 0x2 |
API-MS-Win-Core-LibraryLoader-L1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryExA | 0x0 | 0x100001168 | 0x78f80 | 0x78780 | 0xd |
FreeLibrary | 0x0 | 0x100001170 | 0x78f88 | 0x78788 | 0x3 |
GetProcAddress | 0x0 | 0x100001178 | 0x78f90 | 0x78790 | 0xc |
GetModuleHandleW | 0x0 | 0x100001180 | 0x78f98 | 0x78798 | 0xb |
GetModuleFileNameW | 0x0 | 0x100001188 | 0x78fa0 | 0x787a0 | 0x7 |
API-MS-Win-Core-LocalRegistry-L1-1-0.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegEnumKeyExW | 0x0 | 0x100001198 | 0x78fb0 | 0x787b0 | 0xb |
RegCloseKey | 0x0 | 0x1000011a0 | 0x78fb8 | 0x787b8 | 0x0 |
RegQueryValueExW | 0x0 | 0x1000011a8 | 0x78fc0 | 0x787c0 | 0x1e |
RegOpenKeyExW | 0x0 | 0x1000011b0 | 0x78fc8 | 0x787c8 | 0x19 |
RegCreateKeyExW | 0x0 | 0x1000011b8 | 0x78fd0 | 0x787d0 | 0x2 |
RegSetValueExW | 0x0 | 0x1000011c0 | 0x78fd8 | 0x787d8 | 0x25 |
RegDeleteValueW | 0x0 | 0x1000011c8 | 0x78fe0 | 0x787e0 | 0x8 |
API-MS-Win-Core-Misc-L1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FormatMessageW | 0x0 | 0x1000011d8 | 0x78ff0 | 0x787f0 | 0x4 |
Sleep | 0x0 | 0x1000011e0 | 0x78ff8 | 0x787f8 | 0x13 |
LocalFree | 0x0 | 0x1000011e8 | 0x79000 | 0x78800 | 0xb |
lstrlenW | 0x0 | 0x1000011f0 | 0x79008 | 0x78808 | 0x21 |
lstrcmpiW | 0x0 | 0x1000011f8 | 0x79010 | 0x78810 | 0x1b |
API-MS-Win-Core-ProcessEnvironment-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCommandLineW | 0x0 | 0x100001208 | 0x79020 | 0x78820 | 0x5 |
API-MS-Win-Core-ProcessThreads-L1-1-0.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentThreadId | 0x0 | 0x100001218 | 0x79030 | 0x78830 | 0xd |
CreateThread | 0x0 | 0x100001220 | 0x79038 | 0x78838 | 0x5 |
SetThreadToken | 0x0 | 0x100001228 | 0x79040 | 0x78840 | 0x27 |
OpenThreadToken | 0x0 | 0x100001230 | 0x79048 | 0x78848 | 0x1c |
GetCurrentProcess | 0x0 | 0x100001238 | 0x79050 | 0x78850 | 0xa |
TerminateProcess | 0x0 | 0x100001240 | 0x79058 | 0x78858 | 0x2a |
GetCurrentProcessId | 0x0 | 0x100001248 | 0x79060 | 0x78860 | 0xb |
GetStartupInfoW | 0x0 | 0x100001250 | 0x79068 | 0x78868 | 0x15 |
ResumeThread | 0x0 | 0x100001258 | 0x79070 | 0x78870 | 0x20 |
OpenProcessToken | 0x0 | 0x100001260 | 0x79078 | 0x78878 | 0x1a |
API-MS-Win-Core-Profile-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryPerformanceCounter | 0x0 | 0x100001270 | 0x79088 | 0x78888 | 0x0 |
API-MS-Win-Core-String-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WideCharToMultiByte | 0x0 | 0x100001280 | 0x79098 | 0x78898 | 0x7 |
API-MS-Win-Core-Synch-L1-1-0.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetEvent | 0x0 | 0x100001290 | 0x790a8 | 0x788a8 | 0x20 |
CreateEventW | 0x0 | 0x100001298 | 0x790b0 | 0x788b0 | 0x6 |
InitializeCriticalSection | 0x0 | 0x1000012a0 | 0x790b8 | 0x788b8 | 0xf |
DeleteCriticalSection | 0x0 | 0x1000012a8 | 0x790c0 | 0x788c0 | 0xd |
ReleaseSemaphore | 0x0 | 0x1000012b0 | 0x790c8 | 0x788c8 | 0x1d |
WaitForSingleObject | 0x0 | 0x1000012b8 | 0x790d0 | 0x788d0 | 0x28 |
EnterCriticalSection | 0x0 | 0x1000012c0 | 0x790d8 | 0x788d8 | 0xe |
LeaveCriticalSection | 0x0 | 0x1000012c8 | 0x790e0 | 0x788e0 | 0x13 |
API-MS-Win-Core-SysInfo-L1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | 0x0 | 0x1000012d8 | 0x790f0 | 0x788f0 | 0xe |
GetSystemTimeAsFileTime | 0x0 | 0x1000012e0 | 0x790f8 | 0x788f8 | 0xb |
API-MS-Win-Security-Base-L1-1-0.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSecurityDescriptorLength | 0x0 | 0x1000012f0 | 0x79108 | 0x78908 | 0x32 |
IsValidSid | 0x0 | 0x1000012f8 | 0x79110 | 0x78910 | 0x46 |
FreeSid | 0x0 | 0x100001300 | 0x79118 | 0x78918 | 0x28 |
AdjustTokenPrivileges | 0x0 | 0x100001308 | 0x79120 | 0x78920 | 0x13 |
DuplicateTokenEx | 0x0 | 0x100001310 | 0x79128 | 0x78928 | 0x23 |
MakeAbsoluteSD | 0x0 | 0x100001318 | 0x79130 | 0x78930 | 0x48 |
AddAccessAllowedAce | 0x0 | 0x100001320 | 0x79138 | 0x78938 | 0x7 |
GetLengthSid | 0x0 | 0x100001328 | 0x79140 | 0x78940 | 0x2d |
MakeSelfRelativeSD | 0x0 | 0x100001330 | 0x79148 | 0x78948 | 0x4a |
API-MS-WIN-Service-Core-L1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetServiceStatus | 0x0 | 0x100001000 | 0x78e18 | 0x78618 | 0x1 |
StartServiceCtrlDispatcherW | 0x0 | 0x100001008 | 0x78e20 | 0x78620 | 0x2 |
API-MS-WIN-Service-winsvc-L1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterServiceCtrlHandlerW | 0x0 | 0x100001068 | 0x78e80 | 0x78680 | 0x17 |
ControlService | 0x0 | 0x100001070 | 0x78e88 | 0x78688 | 0x2 |
API-MS-WIN-Service-Management-L1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseServiceHandle | 0x0 | 0x100001018 | 0x78e30 | 0x78630 | 0x0 |
OpenServiceW | 0x0 | 0x100001020 | 0x78e38 | 0x78638 | 0x5 |
OpenSCManagerW | 0x0 | 0x100001028 | 0x78e40 | 0x78640 | 0x4 |
CreateServiceW | 0x0 | 0x100001030 | 0x78e48 | 0x78648 | 0x2 |
DeleteService | 0x0 | 0x100001038 | 0x78e50 | 0x78650 | 0x3 |
API-MS-WIN-Service-Management-L2-1-0.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryServiceObjectSecurity | 0x0 | 0x100001048 | 0x78e60 | 0x78660 | 0x5 |
SetServiceObjectSecurity | 0x0 | 0x100001050 | 0x78e68 | 0x78668 | 0x7 |
ChangeServiceConfig2W | 0x0 | 0x100001058 | 0x78e70 | 0x78670 | 0x0 |
SETUPAPI.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CM_Query_And_Remove_SubTreeW | 0x0 | 0x100001428 | 0x79240 | 0x78a40 | 0xad |
CM_Get_DevNode_Status | 0x0 | 0x100001430 | 0x79248 | 0x78a48 | 0x54 |
SetupDiGetCustomDevicePropertyW | 0x0 | 0x100001438 | 0x79250 | 0x78a50 | 0x164 |
SetupDiCallClassInstaller | 0x0 | 0x100001440 | 0x79258 | 0x78a58 | 0x124 |
SetupDiGetDeviceInterfaceDetailW | 0x0 | 0x100001448 | 0x79260 | 0x78a60 | 0x16e |
SetupDiEnumDeviceInfo | 0x0 | 0x100001450 | 0x79268 | 0x78a68 | 0x142 |
SetupDiGetClassDevsW | 0x0 | 0x100001458 | 0x79270 | 0x78a70 | 0x156 |
SetupDiEnumDeviceInterfaces | 0x0 | 0x100001460 | 0x79278 | 0x78a78 | 0x143 |
SetupDiDestroyDeviceInfoList | 0x0 | 0x100001468 | 0x79280 | 0x78a80 | 0x13f |
CM_Get_Parent | 0x0 | 0x100001470 | 0x79288 | 0x78a88 | 0x82 |
CM_Reenumerate_DevNode_Ex | 0x0 | 0x100001478 | 0x79290 | 0x78a90 | 0xb8 |
OSUNINST.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsUninstallImageValid | 0x0 | 0x100001418 | 0x79230 | 0x78a30 | 0x2 |
vdsutil.dll (135)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?WaitForRundownProtectionRelease@@YAXPEAU_RUNDOWN_REF@@@Z | 0x0 | 0x100001678 | 0x79490 | 0x78c90 | 0xe2 |
??1CRtlMap@@UEAA@XZ | 0x0 | 0x100001680 | 0x79498 | 0x78c98 | 0x11 |
?RemoveAll@CRtlMap@@QEAAXH@Z | 0x0 | 0x100001688 | 0x794a0 | 0x78ca0 | 0xa1 |
?VdsInitializeCriticalSection@@YAKPEAU_RTL_CRITICAL_SECTION@@@Z | 0x0 | 0x100001690 | 0x794a8 | 0x78ca8 | 0xbd |
?GetEntryPointer@CRtlListIter@@QEAAPEAXXZ | 0x0 | 0x100001698 | 0x794b0 | 0x78cb0 | 0x4b |
?VdsTraceW@@YAXKPEAGZZ | 0x0 | 0x1000016a0 | 0x794b8 | 0x78cb8 | 0xcc |
?InsertTail@CRtlList@@QEAAHAEAVCRtlEntry@@@Z | 0x0 | 0x1000016a8 | 0x794c0 | 0x78cc0 | 0x6f |
?Begin@CRtlMap@@QEAA?AVCRtlMapIter@@XZ | 0x0 | 0x1000016b0 | 0x794c8 | 0x78cc8 | 0x2a |
?Next@CRtlMapIter@@QEAAAEAV1@XZ | 0x0 | 0x1000016b8 | 0x794d0 | 0x78cd0 | 0x8f |
?Uninitialize@CVdsPnPNotificationBase@@QEAAXXZ | 0x0 | 0x1000016c0 | 0x794d8 | 0x78cd8 | 0xb2 |
?Uninitialize@CVdsAsyncObjectBase@@SAXXZ | 0x0 | 0x1000016c8 | 0x794e0 | 0x78ce0 | 0xb1 |
?InsertTailPointer@CRtlList@@QEAAHPEAX@Z | 0x0 | 0x1000016d0 | 0x794e8 | 0x78ce8 | 0x70 |
?Remove@CRtlList@@QEAAXAEAVCRtlListIter@@@Z | 0x0 | 0x1000016d8 | 0x794f0 | 0x78cf0 | 0x9e |
?IsWinPE@@YAHXZ | 0x0 | 0x1000016e0 | 0x794f8 | 0x78cf8 | 0x82 |
?AcquireRundownProtection@@YAEPEAU_RUNDOWN_REF@@@Z | 0x0 | 0x1000016e8 | 0x79500 | 0x78d00 | 0x21 |
?Initialize@CVdsAsyncObjectBase@@SAKXZ | 0x0 | 0x1000016f0 | 0x79508 | 0x78d08 | 0x66 |
?Initialize@CVdsPnPNotificationBase@@QEAAKXZ | 0x0 | 0x1000016f8 | 0x79510 | 0x78d10 | 0x67 |
?ReleaseRundownProtection@@YAXPEAU_RUNDOWN_REF@@@Z | 0x0 | 0x100001700 | 0x79518 | 0x78d18 | 0x9d |
?InsertHeadPointer@CRtlList@@QEAAHPEAX@Z | 0x0 | 0x100001708 | 0x79520 | 0x78d20 | 0x6d |
?GetInterfaceDetailData@@YAKPEAXPEAU_SP_DEVICE_INTERFACE_DATA@@PEAPEAU_SP_DEVICE_INTERFACE_DETAIL_DATA_W@@@Z | 0x0 | 0x100001710 | 0x79528 | 0x78d28 | 0x52 |
?InvalidateDiskCache@@YAJPEAG@Z | 0x0 | 0x100001718 | 0x79530 | 0x78d30 | 0x72 |
??0CVdsWmiVariantObjectArrayEnum@@QEAA@XZ | 0x0 | 0x100001720 | 0x79538 | 0x78d38 | 0xc |
??1CVdsWmiVariantObjectArrayEnum@@QEAA@XZ | 0x0 | 0x100001728 | 0x79540 | 0x78d40 | 0x19 |
?VdsWmiConnectToNamespace@@YAJPEAGPEAPEAUIWbemLocator@@PEAPEAUIWbemServices@@@Z | 0x0 | 0x100001730 | 0x79548 | 0x78d48 | 0xce |
?Attach@CVdsWmiVariantObjectArrayEnum@@QEAAJPEAUtagVARIANT@@@Z | 0x0 | 0x100001738 | 0x79550 | 0x78d50 | 0x28 |
?Next@CVdsWmiVariantObjectArrayEnum@@QEAAJPEAPEAUIWbemClassObject@@@Z | 0x0 | 0x100001740 | 0x79558 | 0x78d58 | 0x90 |
?VdsWmiGetByteFromInstance@@YAJPEAUIWbemClassObject@@PEAGPEAE@Z | 0x0 | 0x100001748 | 0x79560 | 0x78d60 | 0xd5 |
?VdsWmiGetUlongFromInstance@@YAJPEAUIWbemClassObject@@PEAGPEAK@Z | 0x0 | 0x100001750 | 0x79568 | 0x78d68 | 0xda |
?VdsWmiGetObjectFromInstance@@YAJPEAUIWbemClassObject@@PEAGPEAPEAU1@@Z | 0x0 | 0x100001758 | 0x79570 | 0x78d70 | 0xd8 |
?VdsWmiCopyFromVariantByteArray@@YAJPEAUIWbemClassObject@@PEAGJPEAE@Z | 0x0 | 0x100001760 | 0x79578 | 0x78d78 | 0xcf |
?Detach@CVdsWmiVariantObjectArrayEnum@@QEAAJXZ | 0x0 | 0x100001768 | 0x79580 | 0x78d80 | 0x34 |
?Find@CRtlMap@@QEAAHAEAVCRtlEntry@@PEAV2@@Z | 0x0 | 0x100001770 | 0x79588 | 0x78d88 | 0x38 |
?VdsTrace@@YAXKPEADZZ | 0x0 | 0x100001778 | 0x79590 | 0x78d90 | 0xc7 |
?Insert@CRtlMap@@QEAAHAEAVCRtlEntry@@0@Z | 0x0 | 0x100001780 | 0x79598 | 0x78d98 | 0x6b |
?FindPtr@CRtlMap@@QEAAHAEAVCRtlEntry@@PEAPEAV2@@Z | 0x0 | 0x100001788 | 0x795a0 | 0x78da0 | 0x39 |
?Remove@CRtlMap@@QEAAHAEAVCRtlEntry@@@Z | 0x0 | 0x100001790 | 0x795a8 | 0x78da8 | 0x9f |
?OpenDevice@@YAKPEAGKPEAPEAX@Z | 0x0 | 0x100001798 | 0x795b0 | 0x78db0 | 0x93 |
?GetDeviceName@@YAKPEAXHKPEAG@Z | 0x0 | 0x1000017a0 | 0x795b8 | 0x78db8 | 0x43 |
?GetDeviceAndMediaType@@YAKPEAGPEAXPEAK2@Z | 0x0 | 0x1000017a8 | 0x795c0 | 0x78dc0 | 0x3f |
?GetDiskLayout@@YAKPEAXPEAPEAU_DRIVE_LAYOUT_INFORMATION_EX@@@Z | 0x0 | 0x1000017b0 | 0x795c8 | 0x78dc8 | 0x48 |
?GetPartitionInformation@@YAKPEAXPEAU_PARTITION_INFORMATION_EX@@@Z | 0x0 | 0x1000017b8 | 0x795d0 | 0x78dd0 | 0x59 |
?RegisterHandle@CVdsPnPNotificationBase@@QEAAKPEAXPEAPEAX@Z | 0x0 | 0x1000017c0 | 0x795d8 | 0x78dd8 | 0x9a |
?InitializeRundownProtection@@YAXPEAU_RUNDOWN_REF@@@Z | 0x0 | 0x1000017c8 | 0x795e0 | 0x78de0 | 0x68 |
?IsLoggingEnabledW@@YAEXZ | 0x0 | 0x1000017d0 | 0x795e8 | 0x78de8 | 0x7e |
?VdsTraceExW@@YAXKKPEAGZZ | 0x0 | 0x1000017d8 | 0x795f0 | 0x78df0 | 0xca |
?GuidToString@@YAJPEAU_GUID@@PEAGK@Z | 0x0 | 0x1000017e0 | 0x795f8 | 0x78df8 | 0x64 |
?InsertUnique@CRtlMap@@QEAAHAEAVCRtlEntry@@0@Z | 0x0 | 0x1000017e8 | 0x79600 | 0x78e00 | 0x71 |
?IsNoAutoMount@@YAHXZ | 0x0 | 0x1000017f0 | 0x79608 | 0x78e08 | 0x80 |
?IsEfiFirmware@@YAHXZ | 0x0 | 0x1000017f8 | 0x79610 | 0x78e10 | 0x7b |
?Clear@CPrvEnumObject@@QEAAXXZ | 0x0 | 0x100001800 | 0x79618 | 0x78e18 | 0x2c |
?LockDismountVolume@@YAKPEAXHE@Z | 0x0 | 0x100001808 | 0x79620 | 0x78e20 | 0x83 |
?GetDeviceNumber@@YAKPEAXPEAU_STORAGE_DEVICE_NUMBER@@@Z | 0x0 | 0x100001810 | 0x79628 | 0x78e28 | 0x44 |
?IsDriveLetter@@YAHPEAG@Z | 0x0 | 0x100001818 | 0x79630 | 0x78e30 | 0x7a |
?Next@CPrvEnumObject@@UEAAJKPEAPEAUIUnknown@@PEAK@Z | 0x0 | 0x100001820 | 0x79638 | 0x78e38 | 0x8d |
?Skip@CPrvEnumObject@@UEAAJK@Z | 0x0 | 0x100001828 | 0x79640 | 0x78e40 | 0xad |
?Reset@CPrvEnumObject@@UEAAJXZ | 0x0 | 0x100001830 | 0x79648 | 0x78e48 | 0xa4 |
?Clone@CPrvEnumObject@@UEAAJPEAPEAUIEnumVdsObject@@@Z | 0x0 | 0x100001838 | 0x79650 | 0x78e50 | 0x2d |
??0CVdsAsyncObjectBase@@QEAA@XZ | 0x0 | 0x100001840 | 0x79658 | 0x78e58 | 0x6 |
??1CVdsAsyncObjectBase@@QEAA@XZ | 0x0 | 0x100001848 | 0x79660 | 0x78e60 | 0x13 |
?SetCompletionStatus@CVdsAsyncObjectBase@@QEAAXJK@Z | 0x0 | 0x100001850 | 0x79668 | 0x78e68 | 0xa7 |
?Signal@CVdsAsyncObjectBase@@QEAAXXZ | 0x0 | 0x100001858 | 0x79670 | 0x78e70 | 0xac |
?VdsIscsiIpAddressToString@@YAJPEAU_VDS_IPADDRESS@@KPEAG@Z | 0x0 | 0x100001860 | 0x79678 | 0x78e78 | 0xc2 |
?VdsWmiFindInstanceOfClass@@YAJPEAUIWbemServices@@PEAG1PEAPEAUIWbemClassObject@@@Z | 0x0 | 0x100001868 | 0x79680 | 0x78e80 | 0xd3 |
?VdsWmiGetUlonglongFromInstance@@YAJPEAUIWbemClassObject@@PEAGPEA_K@Z | 0x0 | 0x100001870 | 0x79688 | 0x78e88 | 0xdb |
?QueryStatus@CVdsAsyncObjectBase@@UEAAJPEAJPEAK@Z | 0x0 | 0x100001878 | 0x79690 | 0x78e90 | 0x97 |
?VdsIscsiIpsecIdToIpAddress@@YAJEKPEAEPEAU_VDS_IPADDRESS@@@Z | 0x0 | 0x100001880 | 0x79698 | 0x78e98 | 0xc3 |
?VdsIscsiCheckEqualIpAddress@@YAHU_VDS_IPADDRESS@@0@Z | 0x0 | 0x100001888 | 0x796a0 | 0x78ea0 | 0xbf |
?VdsIscsiIpAddressToIpsecId@@YAJPEAU_VDS_IPADDRESS@@PEAEPEAKPEAPEAE@Z | 0x0 | 0x100001890 | 0x796a8 | 0x78ea8 | 0xc1 |
?WriteBootCode@@YAKPEAX@Z | 0x0 | 0x100001898 | 0x796b0 | 0x78eb0 | 0xe5 |
?CoFreeStringArray@@YAXPEAPEAGJ@Z | 0x0 | 0x1000018a0 | 0x796b8 | 0x78eb8 | 0x2e |
?GetFMIFSFormatEx2Routine@@YAP6AXPEAGW4_FMIFS_MEDIA_TYPE@@0PEAUFMIFS_FORMATEX2_PARAM@@P6AEW4_FMIFS_PACKET_TYPE@@KPEAX@Z@ZXZ | 0x0 | 0x1000018a8 | 0x796c0 | 0x78ec0 | 0x4d |
?GetFMIFSEnableCompressionRoutine@@YAP6AEPEAGG@ZXZ | 0x0 | 0x1000018b0 | 0x796c8 | 0x78ec8 | 0x4c |
?RemoveTempVolumeName@@YAXPEAG0@Z | 0x0 | 0x1000018b8 | 0x796d0 | 0x78ed0 | 0xa3 |
?MountVolume@@YAKPEAG@Z | 0x0 | 0x1000018c0 | 0x796d8 | 0x78ed8 | 0x8c |
?GetFileSystemRecognitionName@@YAJPEAXPEAPEAG@Z | 0x0 | 0x1000018c8 | 0x796e0 | 0x78ee0 | 0x51 |
?GetFMIFSGetDefaultFilesystemRoutine@@YAP6AEPEAUFMIFS_DEF_FS_PARAM@@PEAUFMIFS_DEF_FS_OUT@@PEAK@ZXZ | 0x0 | 0x1000018d0 | 0x796e8 | 0x78ee8 | 0x4e |
?AssignTempVolumeName@@YAJPEAGQEAG@Z | 0x0 | 0x1000018d8 | 0x796f0 | 0x78ef0 | 0x27 |
?GetVolumeName@@YAJPEAGK0@Z | 0x0 | 0x1000018e0 | 0x796f8 | 0x78ef8 | 0x5f |
?GetVolumeDiskExtentInfo@@YAKPEAXPEAPEAU_VOLUME_DISK_EXTENTS@@@Z | 0x0 | 0x1000018e8 | 0x79700 | 0x78f00 | 0x5d |
?GarbageCollectDriveLetters@@YAXXZ | 0x0 | 0x1000018f0 | 0x79708 | 0x78f08 | 0x3a |
?LockVolume@@YAKPEAXE@Z | 0x0 | 0x1000018f8 | 0x79710 | 0x78f10 | 0x84 |
?DeleteNetworkShare@@YAHPEAG@Z | 0x0 | 0x100001900 | 0x79718 | 0x78f18 | 0x33 |
?GetVolumeUniqueId@@YAKPEAU_VDS_VOLUME_PROP2@@@Z | 0x0 | 0x100001908 | 0x79720 | 0x78f20 | 0x62 |
?GetVolumeGuidPathnames@@YAJPEAGPEAKPEAPEAPEAG@Z | 0x0 | 0x100001910 | 0x79728 | 0x78f28 | 0x5e |
?DeleteBcdObjects@@YAJPEAU_VDS_PARTITION_IDENTITY@@@Z | 0x0 | 0x100001918 | 0x79730 | 0x78f30 | 0x32 |
?VdsIscsiCacheSessionDevices@@YAJPEAUIEnumWbemClassObject@@PEAPEAU_VDSISCSI_SESSION_DEVICES_CACHE@@@Z | 0x0 | 0x100001920 | 0x79738 | 0x78f38 | 0xbe |
?VdsWmiGetObjectInVariantObjectArray@@YAJPEAUIWbemClassObject@@PEAGJPEAPEAU1@@Z | 0x0 | 0x100001928 | 0x79740 | 0x78f40 | 0xd9 |
?VdsIscsiGetIpAddressFromInstance@@YAJPEAUIWbemClassObject@@PEAGPEAU_VDS_IPADDRESS@@@Z | 0x0 | 0x100001930 | 0x79748 | 0x78f48 | 0xc0 |
?VdsWmiCreateClassInstance@@YAJPEAUIWbemServices@@PEAGPEAPEAUIWbemClassObject@@@Z | 0x0 | 0x100001938 | 0x79750 | 0x78f50 | 0xd1 |
?VdsWmiSetUlongInInstance@@YAJPEAUIWbemClassObject@@PEAGK@Z | 0x0 | 0x100001940 | 0x79758 | 0x78f58 | 0xe0 |
?VdsWmiCreateVariantArray@@YAJGJPEAUtagVARIANT@@@Z | 0x0 | 0x100001948 | 0x79760 | 0x78f60 | 0xd2 |
?VdsWmiSetUlonglongInInstance@@YAJPEAUIWbemClassObject@@PEAG_K@Z | 0x0 | 0x100001950 | 0x79768 | 0x78f68 | 0xe1 |
?VdsWmiGetMethodArgumentObject@@YAJPEAUIWbemServices@@PEAG1PEAPEAUIWbemClassObject@@@Z | 0x0 | 0x100001958 | 0x79770 | 0x78f70 | 0xd7 |
?VdsWmiSetObjectInInstance@@YAJPEAUIWbemClassObject@@PEAG0@Z | 0x0 | 0x100001960 | 0x79778 | 0x78f78 | 0xde |
?VdsWmiCallMethod@@YAJPEAUIWbemServices@@PEAUIWbemClassObject@@PEAG1PEAPEAU2@@Z | 0x0 | 0x100001968 | 0x79780 | 0x78f80 | 0xcd |
?UnregisterHandle@CVdsPnPNotificationBase@@QEAAXPEAX@Z | 0x0 | 0x100001970 | 0x79788 | 0x78f88 | 0xb4 |
?GetMediaGeometryEx@@YAKPEAXPEAU_VDS_DISK_PROP2@@@Z | 0x0 | 0x100001978 | 0x79790 | 0x78f90 | 0x56 |
?IsDiskClustered@@YAKPEAXPEAE1@Z | 0x0 | 0x100001980 | 0x79798 | 0x78f98 | 0x76 |
?IsDiskReadOnly@@YAKPEAXPEAE@Z | 0x0 | 0x100001988 | 0x797a0 | 0x78fa0 | 0x78 |
?IsDiskCurrentStateReadOnly@@YAKPEAXPEAE@Z | 0x0 | 0x100001990 | 0x797a8 | 0x78fa8 | 0x77 |
?CreateDeviceInfoSet@@YAKPEAGPEAPEAXPEAU_SP_DEVINFO_DATA@@@Z | 0x0 | 0x100001998 | 0x797b0 | 0x78fb0 | 0x2f |
?GetDeviceRegistryProperty@@YAKPEAXPEAU_SP_DEVINFO_DATA@@KPEAPEAEK@Z | 0x0 | 0x1000019a0 | 0x797b8 | 0x78fb8 | 0x46 |
?VdsAllocateEmptyString@@YAPEAGXZ | 0x0 | 0x1000019a8 | 0x797c0 | 0x78fc0 | 0xb7 |
?GetDeviceRegistryProperty@@YAKKKPEAPEAEK@Z | 0x0 | 0x1000019b0 | 0x797c8 | 0x78fc8 | 0x45 |
?GetDeviceLocationEx@@YAKPEAXKPEAU_VDS_DISK_PROP2@@@Z | 0x0 | 0x1000019b8 | 0x797d0 | 0x78fd0 | 0x41 |
?VdsDoesDiskHaveArcPath@@YAKKPEAE@Z | 0x0 | 0x1000019c0 | 0x797d8 | 0x78fd8 | 0xba |
?GetBootFromDiskNumber@@YAJPEAK@Z | 0x0 | 0x1000019c8 | 0x797e0 | 0x78fe0 | 0x3c |
?GetDiskOfflineReason@@YAKPEAXPEAW4_VDS_DISK_OFFLINE_REASON@@@Z | 0x0 | 0x1000019d0 | 0x797e8 | 0x78fe8 | 0x49 |
?WaitImpl@CVdsAsyncObjectBase@@QEAAJPEAJ@Z | 0x0 | 0x1000019d8 | 0x797f0 | 0x78ff0 | 0xe3 |
VdsDisableCOMFatalExceptionHandling | 0x0 | 0x1000019e0 | 0x797f8 | 0x78ff8 | 0xea |
??1CGlobalResource@@QEAA@XZ | 0x0 | 0x1000019e8 | 0x79800 | 0x79000 | 0xe |
?UnInitializeGlobalResouce@@YAJXZ | 0x0 | 0x1000019f0 | 0x79808 | 0x79008 | 0xb0 |
?Initialize@CGlobalResource@@QEAAJXZ | 0x0 | 0x1000019f8 | 0x79810 | 0x79010 | 0x65 |
??0CGlobalResource@@QEAA@XZ | 0x0 | 0x100001a00 | 0x79818 | 0x79018 | 0x1 |
?RemoveEventSource@@YAKPEAG@Z | 0x0 | 0x100001a08 | 0x79820 | 0x79020 | 0xa2 |
?VdsHeapAlloc@@YAPEAXPEAXK_K@Z | 0x0 | 0x100001a10 | 0x79828 | 0x79028 | 0xbb |
?AddEventSource@@YAKPEAGPEAUHINSTANCE__@@@Z | 0x0 | 0x100001a18 | 0x79830 | 0x79030 | 0x23 |
?InitializeSecurityDescriptor@@YAKKPEAXPEAPEAU_ACL@@PEAPEAX22@Z | 0x0 | 0x100001a20 | 0x79838 | 0x79038 | 0x69 |
?LogInfo@@YAXPEAGKKPEAXK0PEAD@Z | 0x0 | 0x100001a28 | 0x79840 | 0x79040 | 0x89 |
?LogError@@YAXPEAGKKPEAXKK0PEAD@Z | 0x0 | 0x100001a30 | 0x79848 | 0x79048 | 0x87 |
?VdsHeapFree@@YAHPEAXK0@Z | 0x0 | 0x100001a38 | 0x79850 | 0x79050 | 0xbc |
?AllocateAndGetVolumePathName@@YAJPEBGPEAPEAG@Z | 0x0 | 0x100001a40 | 0x79858 | 0x79058 | 0x24 |
?VdsTraceEx@@YAXKKPEADZZ | 0x0 | 0x100001a48 | 0x79860 | 0x79060 | 0xc8 |
??0CRtlMap@@QEAA@KP6AXPEAVCRtlEntry@@@Z1@Z | 0x0 | 0x100001a50 | 0x79868 | 0x79068 | 0x4 |
??0CRtlList@@QEAA@P6AXPEAVCRtlEntry@@@Z@Z | 0x0 | 0x100001a58 | 0x79870 | 0x79070 | 0x3 |
??1CRtlList@@QEAA@XZ | 0x0 | 0x100001a60 | 0x79878 | 0x79078 | 0x10 |
?Begin@CRtlList@@QEAA?AVCRtlListIter@@XZ | 0x0 | 0x100001a68 | 0x79880 | 0x79080 | 0x29 |
?End@CRtlList@@QEAA?AVCRtlListIter@@XZ | 0x0 | 0x100001a70 | 0x79888 | 0x79088 | 0x37 |
?RemoveAll@CRtlList@@QEAAXXZ | 0x0 | 0x100001a78 | 0x79890 | 0x79090 | 0xa0 |
?GetEntry@CRtlListIter@@QEAAPEAVCRtlEntry@@XZ | 0x0 | 0x100001a80 | 0x79898 | 0x79098 | 0x4a |
?Next@CRtlListIter@@QEAAAEAV1@XZ | 0x0 | 0x100001a88 | 0x798a0 | 0x790a0 | 0x8e |
?Prev@CRtlListIter@@QEAAAEAV1@XZ | 0x0 | 0x100001a90 | 0x798a8 | 0x790a8 | 0x94 |
??0CVdsCallTracer@@QEAA@KPEBD@Z | 0x0 | 0x100001a98 | 0x798b0 | 0x790b0 | 0x7 |
??1CVdsCallTracer@@QEAA@XZ | 0x0 | 0x100001aa0 | 0x798b8 | 0x790b8 | 0x14 |
?Append@CPrvEnumObject@@QEAAJPEAUIUnknown@@@Z | 0x0 | 0x100001aa8 | 0x798c0 | 0x790c0 | 0x26 |
KERNEL32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForMultipleObjects | 0x0 | 0x100001388 | 0x791a0 | 0x789a0 | 0x503 |
CreateSemaphoreW | 0x0 | 0x100001390 | 0x791a8 | 0x789a8 | 0xad |
LoadLibraryW | 0x0 | 0x100001398 | 0x791b0 | 0x789b0 | 0x341 |
FindFirstVolumeMountPointW | 0x0 | 0x1000013a0 | 0x791b8 | 0x789b8 | 0x143 |
GetVolumeNameForVolumeMountPointW | 0x0 | 0x1000013a8 | 0x791c0 | 0x789c0 | 0x2b0 |
FindNextVolumeMountPointW | 0x0 | 0x1000013b0 | 0x791c8 | 0x789c8 | 0x14e |
RtlCompareMemory | 0x0 | 0x1000013b8 | 0x791d0 | 0x789d0 | 0x417 |
VirtualAlloc | 0x0 | 0x1000013c0 | 0x791d8 | 0x789d8 | 0x4f5 |
ReadFile | 0x0 | 0x1000013c8 | 0x791e0 | 0x789e0 | 0x3c0 |
GetFileAttributesW | 0x0 | 0x1000013d0 | 0x791e8 | 0x789e8 | 0x1ee |
VirtualFree | 0x0 | 0x1000013d8 | 0x791f0 | 0x789f0 | 0x4f8 |
GetCurrentThread | 0x0 | 0x1000013e0 | 0x791f8 | 0x789f8 | 0x1c9 |
GetSystemDirectoryW | 0x0 | 0x1000013e8 | 0x79200 | 0x78a00 | 0x275 |
DelayLoadFailureHook | 0x0 | 0x1000013f0 | 0x79208 | 0x78a08 | 0xce |
FindVolumeMountPointClose | 0x0 | 0x1000013f8 | 0x79210 | 0x78a10 | 0x156 |
SetVolumeMountPointW | 0x0 | 0x100001400 | 0x79218 | 0x78a18 | 0x4b5 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x100001408 | 0x79220 | 0x78a20 | 0x2b4 |
Exports (145)
»
Api name | EAT Address | Ordinal |
---|---|---|
??0?$CVdsCoTaskPtr@G@@QEAA@XZ | 0x661d0 | 0x1 |
??0?$CVdsHandleImpl@$0?0@@QEAA@XZ | 0x484ec | 0x2 |
??0?$CVdsHandleImpl@$0A@@@QEAA@XZ | 0x661d0 | 0x3 |
??0?$CVdsHeapPtr@D@@QEAA@XZ | 0x661d0 | 0x4 |
??0?$CVdsHeapPtr@G@@QEAA@XZ | 0x661d0 | 0x5 |
??0?$CVdsHeapPtr@J@@QEAA@XZ | 0x661d0 | 0x6 |
??0?$CVdsHeapPtr@UFMIFS_DEF_FS_OUT@@@@QEAA@XZ | 0x661d0 | 0x7 |
??0?$CVdsHeapPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x8 |
??0?$CVdsHeapPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x9 |
??0?$CVdsHeapPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAA@XZ | 0x661d0 | 0xa |
??0?$CVdsHeapPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0xb |
??0?$CVdsHeapPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0xc |
??0?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEAA@XZ | 0x661d0 | 0xd |
??0?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEAA@XZ | 0x661d0 | 0xe |
??0?$CVdsHeapPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0xf |
??0?$CVdsPtr@D@@QEAA@XZ | 0x661d0 | 0x10 |
??0?$CVdsPtr@G@@QEAA@XZ | 0x661d0 | 0x11 |
??0?$CVdsPtr@J@@QEAA@XZ | 0x661d0 | 0x12 |
??0?$CVdsPtr@UFMIFS_DEF_FS_OUT@@@@QEAA@XZ | 0x661d0 | 0x13 |
??0?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x14 |
??0?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x15 |
??0?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAA@XZ | 0x661d0 | 0x16 |
??0?$CVdsPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x17 |
??0?$CVdsPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x18 |
??0?$CVdsPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEAA@XZ | 0x661d0 | 0x19 |
??0?$CVdsPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEAA@XZ | 0x661d0 | 0x1a |
??0?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x661d0 | 0x1b |
??0CPrvEnumObject@@QEAA@XZ | 0x2ed2c | 0x1c |
??0CRtlSharedLock@@QEAA@XZ | 0x2ec1c | 0x1d |
??0CVdsCriticalSection@@QEAA@PEAU_RTL_CRITICAL_SECTION@@@Z | 0x2ecf8 | 0x1e |
??0CVdsPnPNotificationBase@@QEAA@XZ | 0x2ef40 | 0x1f |
??0CVdsUnlockIt@@QEAA@AEAJ@Z | 0x2ecd8 | 0x20 |
??1?$CVdsCoTaskPtr@G@@QEAA@XZ | 0x594f4 | 0x21 |
??1?$CVdsHandleImpl@$0?0@@QEAA@XZ | 0x7283c | 0x22 |
??1?$CVdsHandleImpl@$0A@@@QEAA@XZ | 0x4d050 | 0x23 |
??1?$CVdsHeapPtr@D@@QEAA@XZ | 0x4fe98 | 0x24 |
??1?$CVdsHeapPtr@G@@QEAA@XZ | 0x4fe98 | 0x25 |
??1?$CVdsHeapPtr@J@@QEAA@XZ | 0x4fe98 | 0x26 |
??1?$CVdsHeapPtr@UFMIFS_DEF_FS_OUT@@@@QEAA@XZ | 0x4fe98 | 0x27 |
??1?$CVdsHeapPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAA@XZ | 0x4fe98 | 0x28 |
??1?$CVdsHeapPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAA@XZ | 0x4fe98 | 0x29 |
??1?$CVdsHeapPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAA@XZ | 0x4fe98 | 0x2a |
??1?$CVdsHeapPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEAA@XZ | 0x4fe98 | 0x2b |
??1?$CVdsHeapPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x4fe98 | 0x2c |
??1?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEAA@XZ | 0x4fe98 | 0x2d |
??1?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEAA@XZ | 0x4fe98 | 0x2e |
??1?$CVdsHeapPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x4fe98 | 0x2f |
??1?$CVdsPtr@D@@QEAA@XZ | 0x3706c | 0x30 |
??1?$CVdsPtr@G@@QEAA@XZ | 0x3706c | 0x31 |
??1?$CVdsPtr@J@@QEAA@XZ | 0x3706c | 0x32 |
??1?$CVdsPtr@UFMIFS_DEF_FS_OUT@@@@QEAA@XZ | 0x3706c | 0x33 |
??1?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAA@XZ | 0x3706c | 0x34 |
??1?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAA@XZ | 0x3706c | 0x35 |
??1?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAA@XZ | 0x3706c | 0x36 |
??1?$CVdsPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEAA@XZ | 0x3706c | 0x37 |
??1?$CVdsPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x3706c | 0x38 |
??1?$CVdsPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEAA@XZ | 0x3706c | 0x39 |
??1?$CVdsPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEAA@XZ | 0x3706c | 0x3a |
??1?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAA@XZ | 0x3706c | 0x3b |
??1CPrvEnumObject@@QEAA@XZ | 0x2ed90 | 0x3c |
??1CRtlSharedLock@@QEAA@XZ | 0x2ec48 | 0x3d |
??1CVdsCriticalSection@@QEAA@XZ | 0x2ed1c | 0x3e |
??1CVdsDebugLog@@QEAA@XZ | 0x2eb38 | 0x3f |
??1CVdsPnPNotificationBase@@QEAA@XZ | 0x2ef88 | 0x40 |
??1CVdsUnlockIt@@QEAA@XZ | 0x2ece8 | 0x41 |
??4?$CVdsHandleImpl@$0?0@@QEAAPEAXPEAX@Z | 0x484fc | 0x42 |
??4?$CVdsHandleImpl@$0A@@@QEAAPEAXPEAX@Z | 0x4d018 | 0x43 |
??4?$CVdsHeapPtr@D@@QEAAPEADPEAD@Z | 0x484a0 | 0x44 |
??4?$CVdsHeapPtr@G@@QEAAPEAGPEAG@Z | 0x484a0 | 0x45 |
??4?$CVdsHeapPtr@J@@QEAAPEAJPEAJ@Z | 0x484a0 | 0x46 |
??4?$CVdsHeapPtr@UFMIFS_DEF_FS_OUT@@@@QEAAPEAUFMIFS_DEF_FS_OUT@@PEAU1@@Z | 0x484a0 | 0x47 |
??4?$CVdsHeapPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAAPEAU_AUCTION_THREAD_PARAMETER@@PEAU1@@Z | 0x484a0 | 0x48 |
??4?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEAAPEAU_MOUNTMGR_MOUNT_POINT@@PEAU1@@Z | 0x484a0 | 0x49 |
??4?$CVdsHeapPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEAAPEAU_MOUNTMGR_MOUNT_POINTS@@PEAU1@@Z | 0x484a0 | 0x4a |
??4?$CVdsHeapPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAAPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@PEAU1@@Z | 0x484a0 | 0x4b |
??8?$CVdsHandleImpl@$0?0@@QEBA_NPEAX@Z | 0x5951c | 0x4c |
??8?$CVdsHandleImpl@$0A@@@QEBA_NPEAX@Z | 0x5951c | 0x4d |
??8?$CVdsPtr@D@@QEBA_NPEAD@Z | 0x5951c | 0x4e |
??8?$CVdsPtr@G@@QEBA_NPEAG@Z | 0x5951c | 0x4f |
??8?$CVdsPtr@J@@QEBA_NPEAJ@Z | 0x5951c | 0x50 |
??8?$CVdsPtr@UFMIFS_DEF_FS_OUT@@@@QEBA_NPEAUFMIFS_DEF_FS_OUT@@@Z | 0x5951c | 0x51 |
??8?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEBA_NPEAU_AUCTION_THREAD_PARAMETER@@@Z | 0x5951c | 0x52 |
??8?$CVdsPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEBA_NPEAU_MOUNTMGR_MOUNT_POINT@@@Z | 0x5951c | 0x53 |
??8?$CVdsPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEBA_NPEAU_MOUNTMGR_MOUNT_POINTS@@@Z | 0x5951c | 0x54 |
??8?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEBA_NPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@@Z | 0x5951c | 0x55 |
??9?$CVdsHandleImpl@$0?0@@QEBA_NPEAX@Z | 0x708b8 | 0x56 |
??9?$CVdsPtr@G@@QEBA_NPEAG@Z | 0x708b8 | 0x57 |
??9?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEBA_NPEAU_DRIVE_LAYOUT_INFORMATION_EX@@@Z | 0x708b8 | 0x58 |
??A?$CVdsPtr@J@@QEAAAEAJJ@Z | 0x4fed8 | 0x59 |
??A?$CVdsPtr@UFMIFS_DEF_FS_OUT@@@@QEAAAEAUFMIFS_DEF_FS_OUT@@K@Z | 0x59544 | 0x5a |
??B?$CVdsHandleImpl@$0?0@@QEAAPEAXXZ | 0x59538 | 0x5b |
??B?$CVdsHandleImpl@$0A@@@QEAAPEAXXZ | 0x59538 | 0x5c |
??B?$CVdsPtr@G@@QEBAPEAGXZ | 0x59538 | 0x5d |
??B?$CVdsPtr@J@@QEBAPEAJXZ | 0x59538 | 0x5e |
??B?$CVdsPtr@UFMIFS_DEF_FS_OUT@@@@QEBAPEAUFMIFS_DEF_FS_OUT@@XZ | 0x59538 | 0x5f |
??B?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEBAPEAU_AUCTION_THREAD_PARAMETER@@XZ | 0x59538 | 0x60 |
??B?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEBAPEAU_CLEAN_DISK_HANDLER_PARAMETER@@XZ | 0x59538 | 0x61 |
??B?$CVdsPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEBAPEAU_FORMAT_VOLUME_THREAD_PARAMETER@@XZ | 0x59538 | 0x62 |
??B?$CVdsPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEBAPEAU_MOUNTMGR_MOUNT_POINT@@XZ | 0x59538 | 0x63 |
??B?$CVdsPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEBAPEAU_MOUNTMGR_MOUNT_POINTS@@XZ | 0x59538 | 0x64 |
??B?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEBAPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@XZ | 0x59538 | 0x65 |
??C?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEBAPEAU_AUCTION_THREAD_PARAMETER@@XZ | 0x59538 | 0x66 |
??C?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEBAPEAU_CLEAN_DISK_HANDLER_PARAMETER@@XZ | 0x59538 | 0x67 |
??C?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEBAPEAU_DRIVE_LAYOUT_INFORMATION_EX@@XZ | 0x59538 | 0x68 |
??C?$CVdsPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEBAPEAU_EXTEND_VOLUME_HANDLER_PARAMETER@@XZ | 0x59538 | 0x69 |
??C?$CVdsPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEBAPEAU_FORMAT_VOLUME_THREAD_PARAMETER@@XZ | 0x59538 | 0x6a |
??C?$CVdsPtr@U_MOUNTMGR_MOUNT_POINT@@@@QEBAPEAU_MOUNTMGR_MOUNT_POINT@@XZ | 0x59538 | 0x6b |
??C?$CVdsPtr@U_MOUNTMGR_MOUNT_POINTS@@@@QEBAPEAU_MOUNTMGR_MOUNT_POINTS@@XZ | 0x59538 | 0x6c |
??C?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEBAPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@XZ | 0x59538 | 0x6d |
??I?$CVdsHandleImpl@$0?0@@QEAAPEAPEAXXZ | 0x48538 | 0x6e |
??I?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAAPEAPEAU_DRIVE_LAYOUT_INFORMATION_EX@@XZ | 0x48538 | 0x6f |
??_FCRtlList@@QEAAXXZ | 0x2ec0c | 0x70 |
??_FCRtlMap@@QEAAXXZ | 0x2ebf4 | 0x71 |
?AcquireRead@CRtlSharedLock@@AEAAXXZ | 0x2ec68 | 0x72 |
?AcquireWrite@CRtlSharedLock@@AEAAXXZ | 0x2ec78 | 0x73 |
?AllowCancel@CVdsAsyncObjectBase@@QEAAXXZ | 0x2eef0 | 0x74 |
?Attach@?$CVdsPtr@G@@QEAAXPEAG@Z | 0x5952c | 0x75 |
?Attach@?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAAXPEAU_CLEAN_DISK_HANDLER_PARAMETER@@@Z | 0x5952c | 0x76 |
?Attach@?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAAXPEAU_DRIVE_LAYOUT_INFORMATION_EX@@@Z | 0x5952c | 0x77 |
?Attach@?$CVdsPtr@U_EXTEND_VOLUME_HANDLER_PARAMETER@@@@QEAAXPEAU_EXTEND_VOLUME_HANDLER_PARAMETER@@@Z | 0x5952c | 0x78 |
?Attach@?$CVdsPtr@U_FORMAT_VOLUME_THREAD_PARAMETER@@@@QEAAXPEAU_FORMAT_VOLUME_THREAD_PARAMETER@@@Z | 0x5952c | 0x79 |
?Attach@?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAAXPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@@Z | 0x5952c | 0x7a |
?Close@?$CVdsHandleImpl@$0?0@@QEAAXXZ | 0x7283c | 0x7b |
?CurrentThreadIsWriter@CRtlSharedLock@@QEAAHXZ | 0x2eca8 | 0x7c |
?Detach@?$CVdsHandleImpl@$0?0@@QEAAPEAXXZ | 0x594e4 | 0x7d |
?Detach@?$CVdsHandleImpl@$0A@@@QEAAPEAXXZ | 0x708c8 | 0x7e |
?Detach@?$CVdsPtr@G@@QEAAPEAGXZ | 0x708c8 | 0x7f |
?Detach@?$CVdsPtr@U_AUCTION_THREAD_PARAMETER@@@@QEAAPEAU_AUCTION_THREAD_PARAMETER@@XZ | 0x708c8 | 0x80 |
?Detach@?$CVdsPtr@U_CLEAN_DISK_HANDLER_PARAMETER@@@@QEAAPEAU_CLEAN_DISK_HANDLER_PARAMETER@@XZ | 0x708c8 | 0x81 |
?Detach@?$CVdsPtr@U_DRIVE_LAYOUT_INFORMATION_EX@@@@QEAAPEAU_DRIVE_LAYOUT_INFORMATION_EX@@XZ | 0x708c8 | 0x82 |
?Detach@?$CVdsPtr@U_SHRINK_VOLUME_THREAD_PARAMETER@@@@QEAAPEAU_SHRINK_VOLUME_THREAD_PARAMETER@@XZ | 0x708c8 | 0x83 |
?DisallowCancel@CVdsAsyncObjectBase@@QEAAXXZ | 0x2eefc | 0x84 |
?Downgrade@CRtlSharedLock@@AEAAXXZ | 0x2ec98 | 0x85 |
?GetOutputType@CVdsAsyncObjectBase@@QEAA?AW4_VDS_ASYNC_OUTPUT_TYPE@@XZ | 0x2eed8 | 0x86 |
?IsCancelRequested@CVdsAsyncObjectBase@@QEAAHXZ | 0x2eee4 | 0x87 |
?Release@CRtlSharedLock@@AEAAXXZ | 0x2ec58 | 0x88 |
?SetOutput@CVdsAsyncObjectBase@@QEAAXU_VDS_ASYNC_OUTPUT@@@Z | 0x2eec0 | 0x89 |
?SetOutputType@CVdsAsyncObjectBase@@QEAAXW4_VDS_ASYNC_OUTPUT_TYPE@@@Z | 0x2eeb4 | 0x8a |
?SetPositionToLast@CPrvEnumObject@@QEAAXXZ | 0x2ee70 | 0x8b |
?StartReferenceHistory@@YAKXZ | 0x7570c | 0x8c |
?StopReferenceHistory@@YAXXZ | 0x3706c | 0x8d |
?Upgrade@CRtlSharedLock@@AEAAXXZ | 0x2ec88 | 0x8e |
?ZeroAsyncOut@CVdsAsyncObjectBase@@QEAAXXZ | 0x2ef0c | 0x8f |
?m_NoDebuggerLogging@CVdsDebugLog@@QEAAHXZ | 0x2ebe8 | 0x90 |
?m_TracingLogEnabled@CVdsDebugLog@@QEAAHXZ | 0x2ebd8 | 0x91 |
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Binary |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.midwestsurinc | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_idx.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_96.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\Sey7C50.tmp | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.midwestsurinc_readme | Dropped File | Text |
Unknown
|
...
|
»