Static | ZeroBOX

PE Compile Time

2018-12-31 21:28:58

PDB Path

E:\Projects\NSudo\Output\Release\x64\NSudo.pdb

PE Imphash

55fa9bd502457bea13d3626a68dc1cad

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001cf48 0x0001d000 6.2744600215
.rdata 0x0001e000 0x0000c706 0x0000c800 4.53478916561
.data 0x0002b000 0x00001740 0x00000c00 3.94759244951
.pdata 0x0002d000 0x00001a1c 0x00001c00 5.05313540375
.rsrc 0x0002f000 0x000113f8 0x00011400 5.42503679752
.reloc 0x00041000 0x000002cc 0x00000400 4.33913742193

Resources

Name Offset Size Language Sub-language File type
CONFIG 0x0002f568 0x0000033f LANG_NEUTRAL SUBLANG_NEUTRAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
STRING 0x0003c9f0 0x000000b2 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL UTF-8 Unicode (with BOM) text, with CRLF line terminators
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a1b0 0x0000129b LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_DIALOG 0x0002f8a8 0x00000180 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_DIALOG 0x0002f8a8 0x00000180 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0003b450 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003f8d8 0x000002e8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003fbc0 0x00000835 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x14001e100 DeleteCriticalSection
0x14001e108 WaitForSingleObjectEx
0x14001e110 GetCurrentProcess
0x14001e118 GetCurrentThreadId
0x14001e120 ResumeThread
0x14001e128 SetPriorityClass
0x14001e130 OpenProcess
0x14001e138 FreeLibrary
0x14001e140 LoadLibraryW
0x14001e148 MulDiv
0x14001e150 CopyFileW
0x14001e158 MoveFileExW
0x14001e168 TerminateProcess
0x14001e170 LoadLibraryExA
0x14001e178 VirtualFree
0x14001e180 VirtualAlloc
0x14001e188 FlushInstructionCache
0x14001e198 InterlockedPopEntrySList
0x14001e1a0 GetProcessHeap
0x14001e1a8 HeapFree
0x14001e1b0 HeapAlloc
0x14001e1b8 OutputDebugStringW
0x14001e1c0 InitializeSListHead
0x14001e1c8 EnterCriticalSection
0x14001e1d0 LeaveCriticalSection
0x14001e1d8 DecodePointer
0x14001e1e0 RaiseException
0x14001e1e8 SetFileAttributesW
0x14001e1f0 GetFileAttributesW
0x14001e1f8 DeleteFileW
0x14001e208 GetCommandLineW
0x14001e210 SizeofResource
0x14001e218 LockResource
0x14001e220 LoadResource
0x14001e228 FindResourceExW
0x14001e238 SleepEx
0x14001e240 SetLastError
0x14001e248 CloseHandle
0x14001e250 VerifyVersionInfoW
0x14001e258 GetModuleHandleW
0x14001e260 VerSetConditionMask
0x14001e268 MultiByteToWideChar
0x14001e270 GetProcAddress
0x14001e278 GetModuleFileNameW
0x14001e280 GetTickCount64
0x14001e288 QueryPerformanceCounter
0x14001e290 GetLastError
0x14001e298 GetSystemTimeAsFileTime
0x14001e2a0 GetCurrentProcessId
0x14001e2b0 GetStartupInfoW
0x14001e2c0 UnhandledExceptionFilter
0x14001e2c8 IsDebuggerPresent
0x14001e2d0 RtlVirtualUnwind
0x14001e2d8 RtlLookupFunctionEntry
0x14001e2e0 RtlCaptureContext
0x14001e2e8 EncodePointer
0x14001e2f0 InitOnceExecuteOnce
Library USER32.dll:
0x14001e318 EndPaint
0x14001e320 GetWindowTextW
0x14001e328 GetClientRect
0x14001e330 BeginPaint
0x14001e338 LoadImageW
0x14001e340 MonitorFromWindow
0x14001e350 GetDC
0x14001e358 SetWindowLongPtrW
0x14001e360 UnregisterClassW
0x14001e368 DialogBoxParamW
0x14001e370 SendMessageW
0x14001e378 SetWindowTextW
0x14001e380 DrawIconEx
0x14001e388 EndDialog
0x14001e390 GetDlgItem
Library GDI32.dll:
0x14001e0f0 GetDeviceCaps
Library COMDLG32.dll:
0x14001e0e0 GetOpenFileNameW
Library ADVAPI32.dll:
0x14001e000 RegDeleteTreeW
0x14001e008 RegSetValueExW
0x14001e010 RegOpenKeyExW
0x14001e018 RegCreateKeyExW
0x14001e020 RegCloseKey
0x14001e028 SetTokenInformation
0x14001e030 RevertToSelf
0x14001e038 InitializeAcl
0x14001e040 GetTokenInformation
0x14001e048 GetLengthSid
0x14001e050 GetAce
0x14001e058 FreeSid
0x14001e060 EqualSid
0x14001e068 DuplicateTokenEx
0x14001e070 CreateRestrictedToken
0x14001e078 AllocateAndInitializeSid
0x14001e080 AdjustTokenPrivileges
0x14001e088 AddAce
0x14001e090 AddAccessAllowedAce
0x14001e098 OpenProcessToken
0x14001e0a0 SetThreadToken
0x14001e0a8 CreateProcessAsUserW
0x14001e0b0 StartServiceW
0x14001e0b8 QueryServiceStatusEx
0x14001e0c0 OpenServiceW
0x14001e0c8 OpenSCManagerW
0x14001e0d0 CloseServiceHandle
Library SHELL32.dll:
0x14001e300 DragQueryFileW
0x14001e308 DragFinish
Library ole32.dll:
0x14001e5f0 CoInitializeEx
Library WTSAPI32.dll:
0x14001e3b8 WTSQueryUserToken
0x14001e3c0 WTSEnumerateProcessesW
0x14001e3c8 WTSFreeMemory
Library USERENV.dll:
0x14001e3a0 DestroyEnvironmentBlock
0x14001e3a8 CreateEnvironmentBlock
Library msvcrt.dll:
0x14001e3f8 abort
0x14001e400 fseek
0x14001e408 __C_specific_handler
0x14001e410 _cexit
0x14001e420 __setusermatherr
0x14001e428 _initterm
0x14001e430 _initterm_e
0x14001e438 exit
0x14001e440 _exit
0x14001e448 _c_exit
0x14001e450 __wgetmainargs
0x14001e458 atexit
0x14001e460 _wcmdln
0x14001e468 _lock
0x14001e470 _unlock
0x14001e478 _fseeki64
0x14001e480 ?terminate@@YAXXZ
0x14001e488 _strtoi64
0x14001e490 _strtoui64
0x14001e498 ??0exception@@QEAA@XZ
0x14001e4a8 ??1exception@@UEAA@XZ
0x14001e4b8 _XcptFilter
0x14001e4c0 fsetpos
0x14001e4c8 fwrite
0x14001e4d0 memmove
0x14001e4d8 memcpy
0x14001e4e0 ??2@YAPEAX_K@Z
0x14001e4e8 memset
0x14001e4f0 setlocale
0x14001e4f8 ??3@YAXPEAX@Z
0x14001e500 memcmp
0x14001e508 localeconv
0x14001e510 ungetc
0x14001e518 setvbuf
0x14001e520 fread
0x14001e528 fputc
0x14001e530 fgetpos
0x14001e538 fgetc
0x14001e540 fflush
0x14001e548 fclose
0x14001e550 strtod
0x14001e558 _set_fmode
0x14001e560 malloc
0x14001e568 free
0x14001e570 _wcsicmp
0x14001e578 wcsrchr
0x14001e580 _errno
0x14001e588 ??_V@YAXPEAX@Z
0x14001e590 __CxxFrameHandler3
0x14001e598 _CxxThrowException
0x14001e5a0 _wcsnicmp
0x14001e5a8 _iob
0x14001e5b0 _vsnprintf
0x14001e5b8 __set_app_type
0x14001e5c0 _commode
0x14001e5c8 wcslen
0x14001e5d0 __dllonexit
0x14001e5d8 wcsstr
0x14001e5e0 _wfsopen
Library msvcp60.dll:
0x14001e3d8 _Toupper
0x14001e3e0 _Tolower
0x14001e3e8 _Getctype

!This program cannot be run in DOS mode.
oRichlA
`.rdata
@.data
.pdata
@.rsrc
@.reloc
SVWATAUAVAWH
@A_A^A]A\_^[
@SVWATAUAVAWH
H;8uVI
pA_A^A]A\_^[
@SVWATAUAVAWH
tCL;0u/L
`A_A^A]A\_^[
UVWAVAWH
A_A^_^]
UVWAVAWH
A_A^_^]
UVWAVAWH
A_A^_^]
l$ VWATAVAWH
A_A^A\_^
@SUVWATAVAWH
A_A^A\_^][
t$ WAVAWH
A_A^_
UVWATAUAVAWH
pA_A^A]A\_^]
@USVWATAUAVAWH
H;|$(u
fF9,Bu
fF9,Bu
|$0H;]
fB9<pu
A_A^A]A\_^[]
t$ WAVAWH
A_A^_
UVWAVAWH
A_A^_^]
@VWAVH
@USVWAVH
A^_^[]
VWATAVAWH
|$8!|$HE3
A_A^A\_^
fB94Bu
fB94@u
WAVAWH
fE9<@u
0A_A^_
fB94Ju
UVWAVH
VWATAVAWH
0A_A^A\_^
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
PA_A^A\_^
@SVWATAUAVAWH
`A_A^A]A\_^[
VWATAVAWH
PA_A^A\_^
VWATAVAWH
PA_A^A\_^
VWATAVAWH
PA_A^A\_^
WATAUAVAWH
A_A^A]A\_
@SVWATAUAVAWH
vb'vb'v
`A_A^A]A\_^[
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
PA_A^A\_^
WATAUAVAWH
A_A^A]A\_
2333333
@SVWATAUAVAWH
L9d$@s
L;d$@s
t$ 8T$0I
A_A^A]A\_^[
@SVWATAUAVAWH
L9d$@s
L;d$@s
t$ 8T$0I
A_A^A]A\_^[
VWAUAVAWH
t@L;*u,H
pA_A^A]_^
VWAUAVAWH
t@L;*u,H
pA_A^A]_^
UVWAVAWH
A_A^_^]
UVWATAUAVAWH
A_A^A]A\_^]
l$ VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
UVWAVAWH
A_A^_^]
@SUVWATAUAVAWH
HA_A^A]A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
VWAUAVAWH
PA_A^A]_^
t$ WAVAWH
@A_A^_
t$ WAVAWH
@A_A^_
t$ WAVAWH
@A_A^_
@USVWAVH
A^_^[]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UWAUAVAWH
A_A^A]_]
UVWATAUAVAWH
A_A^A]A\_^]
u`8X$t
u`8X$t
USVWATAVAWH
`A_A^A\_^[]
SUVWAVH
0A^_^][
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
9y@~(3
xe;{@}`H
@USVWAVH
A^_^[]
x ATAVAWH
A_A^A\
UAVAWH
UWATAVAWH
A_A^A\_]
UWAUAVAWH
A_A^A]_]
UATAUAVAWH
L$`H9q
A_A^A]A\]
t$ UWATAUAVH
A^A]A\_]
@USVWATAUAVAWH
fF9,Gu
A_A^A]A\_^[]
@SUVWATAVAWH
@A_A^A\_^][
@SUVWH
@SUVWAVH
@A^_^][
\$ UVWATAUAVAWH
PA_A^A]A\_^]
fB9<@u
@USVWAVH
A^_^[]
MH;E/w
UWATAVAWH
A_A^A\_]
UAVAWH
x ATAVAWH
A_A^A\
t$ WAVAWH
A_A^_
t$ WAVAWH
A_A^_
tpH91uk
vb'vb'v
UVWAVAWH
A_A^_^]
UVWAVAWH
A_A^_^]
UVWAVAWH
A_A^_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWAVAWH
A_A^_^]
` UAVAWH
@USVWATAUAVAWH
\$ L9g
A_A^A]A\_^[]
D$0H9Q
ATAVAWH
0A_A^A\
S H;S(t^H
t$ UWAVH
USVWAVH
A^_^[]
UWATAVAWH
A_A^A\_]
teL9Chu
WAVAWH
@A_A^_
UWATAVAWH
A_A^A\_]
@SUVWAVH
L90u"H
0A^_^][
UVWAVAWH
3333333
A_A^_^]
3333333
UVWAVAWH
3333333
A_A^_^]
3333333
M7H;M?s H
|$ AVH
SVWAVH
\$`fff
8A^_^[
WAVAWH
PA_A^_
u3HcH<H
8H1D$0
H1D$0H
D$0H3L$0H3
\$ UVWH
string too long
vector<T> too long
map/set<T> too long
Message.Success
Message.PrivilegeNotHeld
Message.InvalidCommandParameter
Message.InvalidTextBoxParameter
Message.CreateProcessFailed
bad cast
bad locale name
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
[json.exception.
parse error
parse_error
, column
at line
invalid_iterator
type_error
out_of_range
other_error
NSudo.VersionText
NSudo.LogoText
NSudo.String.Links
NSudo.String.CommandLineHelp
Translations
ShortCutList_V2
ContextMenu
ItemName
ItemDescriptionID
ItemCommandParameters
HasLUAShield
GetDpiForMonitor
EnableAllPrivileges
WarningText
SettingsGroupText
Static.User
Static.Open
Button.About
Button.Browse
Button.Run
System
CurrentProcess
CurrentUser
cannot get value
cannot use key() for non-object iterators
cannot compare iterators of different containers
<U+%.4X>
syntax error
while parsing
; last read: '
unexpected
; expected
961c151d2e87f2686a955a9be24d316f1362bf21 3.4.0
invalid BOM; must be 0xEF 0xBB 0xBF if given
invalid literal
<uninitialized>
true literal
false literal
null literal
string literal
number literal
<parse error>
end of input
'[', '{', or a literal
unknown token
invalid string position
invalid number; expected digit after '-'
invalid number; expected digit after '.'
invalid number; expected '+', '-', or digit after exponent
invalid number; expected digit after exponent sign
invalid string: missing closing quote
invalid string: '\u' must be followed by 4 hex digits
invalid string: surrogate U+DC00..U+DFFF must be followed by U+DC00..U+DFFF
invalid string: surrogate U+DC00..U+DFFF must follow U+D800..U+DBFF
invalid string: forbidden character after backslash
invalid string: control character U+0000 (NUL) must be escaped to \u0000
invalid string: control character U+0001 (SOH) must be escaped to \u0001
invalid string: control character U+0002 (STX) must be escaped to \u0002
invalid string: control character U+0003 (ETX) must be escaped to \u0003
invalid string: control character U+0004 (EOT) must be escaped to \u0004
invalid string: control character U+0005 (ENQ) must be escaped to \u0005
invalid string: control character U+0006 (ACK) must be escaped to \u0006
invalid string: control character U+0007 (BEL) must be escaped to \u0007
invalid string: control character U+0008 (BS) must be escaped to \u0008 or \b
invalid string: control character U+0009 (HT) must be escaped to \u0009 or \t
invalid string: control character U+000A (LF) must be escaped to \u000A or \n
invalid string: control character U+000B (VT) must be escaped to \u000B
invalid string: control character U+000C (FF) must be escaped to \u000C or \f
invalid string: control character U+000D (CR) must be escaped to \u000D or \r
invalid string: control character U+000E (SO) must be escaped to \u000E
invalid string: control character U+000F (SI) must be escaped to \u000F
invalid string: control character U+0010 (DLE) must be escaped to \u0010
invalid string: control character U+0011 (DC1) must be escaped to \u0011
invalid string: control character U+0012 (DC2) must be escaped to \u0012
invalid string: control character U+0013 (DC3) must be escaped to \u0013
invalid string: control character U+0014 (DC4) must be escaped to \u0014
invalid string: control character U+0015 (NAK) must be escaped to \u0015
invalid string: control character U+0016 (SYN) must be escaped to \u0016
invalid string: control character U+0017 (ETB) must be escaped to \u0017
invalid string: control character U+0018 (CAN) must be escaped to \u0018
invalid string: control character U+0019 (EM) must be escaped to \u0019
invalid string: control character U+001A (SUB) must be escaped to \u001A
invalid string: control character U+001B (ESC) must be escaped to \u001B
invalid string: control character U+001C (FS) must be escaped to \u001C
invalid string: control character U+001D (GS) must be escaped to \u001D
invalid string: control character U+001E (RS) must be escaped to \u001E
invalid string: control character U+001F (US) must be escaped to \u001F
invalid string: ill-formed UTF-8 byte
vector<bool> too long
cannot use operator[] with a string argument with
object key
object separator
number overflow parsing '
object
excessive array size:
excessive object size:
string
boolean
discarded
number
iterator does not fit current value
iterator out of range
cannot use erase() with
type must be string, but is
type must be boolean, but is
bad function call
unknown error
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
atlthunk.dll
AtlThunk_AllocateData
AtlThunk_InitData
AtlThunk_DataToCode
AtlThunk_FreeData
E:\Projects\NSudo\Output\Release\x64\NSudo.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zzzdbg
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
GetLastError
QueryPerformanceCounter
GetTickCount64
GetModuleFileNameW
GetProcAddress
MultiByteToWideChar
VerSetConditionMask
GetModuleHandleW
VerifyVersionInfoW
CloseHandle
SetLastError
SleepEx
GetSystemWindowsDirectoryW
FindResourceExW
LoadResource
LockResource
SizeofResource
GetCommandLineW
ExpandEnvironmentStringsW
DeleteFileW
GetFileAttributesW
SetFileAttributesW
DecodePointer
RaiseException
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
WaitForSingleObjectEx
GetCurrentProcess
GetCurrentThreadId
ResumeThread
SetPriorityClass
OpenProcess
FreeLibrary
LoadLibraryW
MulDiv
CopyFileW
MoveFileExW
KERNEL32.dll
SendMessageW
DialogBoxParamW
EndDialog
GetDlgItem
SetWindowTextW
LoadImageW
UnregisterClassW
BeginPaint
EndPaint
GetWindowTextW
GetClientRect
SetWindowLongPtrW
DrawIconEx
MonitorFromWindow
ChangeWindowMessageFilter
USER32.dll
GetDeviceCaps
GDI32.dll
GetOpenFileNameW
COMDLG32.dll
CloseServiceHandle
OpenSCManagerW
OpenServiceW
QueryServiceStatusEx
StartServiceW
CreateProcessAsUserW
SetThreadToken
OpenProcessToken
AddAccessAllowedAce
AddAce
AdjustTokenPrivileges
AllocateAndInitializeSid
CreateRestrictedToken
DuplicateTokenEx
EqualSid
FreeSid
GetAce
GetLengthSid
GetTokenInformation
InitializeAcl
RevertToSelf
SetTokenInformation
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegSetValueExW
RegDeleteTreeW
ADVAPI32.dll
DragQueryFileW
DragFinish
SHELL32.dll
CoInitializeEx
ole32.dll
WTSEnumerateProcessesW
WTSFreeMemory
WTSQueryUserToken
WTSAPI32.dll
CreateEnvironmentBlock
DestroyEnvironmentBlock
USERENV.dll
??2@YAPEAX_K@Z
memcpy
memmove
memset
wcsstr
wcslen
_wcsnicmp
_CxxThrowException
__CxxFrameHandler3
??_V@YAXPEAX@Z
_errno
wcsrchr
_wcsicmp
malloc
strtod
fclose
fflush
fgetpos
fsetpos
_fseeki64
fwrite
setvbuf
ungetc
localeconv
_Getctype
_Tolower
_Toupper
memcmp
??3@YAXPEAX@Z
setlocale
_wfsopen
__C_specific_handler
_cexit
??0exception@@QEAA@AEBQEBD@Z
__setusermatherr
_initterm
_initterm_e
_set_fmode
_c_exit
__wgetmainargs
atexit
_wcmdln
_unlock
__dllonexit
msvcrt.dll
?terminate@@YAXXZ
_strtoi64
_strtoui64
??0exception@@QEAA@XZ
??0exception@@QEAA@AEBV0@@Z
??1exception@@UEAA@XZ
?what@exception@@UEBAPEBDXZ
msvcp60.dll
_XcptFilter
InitOnceExecuteOnce
EncodePointer
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
HeapAlloc
HeapFree
GetProcessHeap
InterlockedPopEntrySList
InterlockedPushEntrySList
FlushInstructionCache
VirtualAlloc
VirtualFree
LoadLibraryExA
_vsnprintf
__set_app_type
_commode
TerminateProcess
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV_Ref_count_base@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AVcodecvt_base@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AVinvalid_iterator@detail@nlohmann@@
.?AVexception@detail@nlohmann@@
.?AVparse_error@detail@nlohmann@@
.?AVout_of_range@detail@nlohmann@@
.?AVtype_error@detail@nlohmann@@
.?AVother_error@detail@nlohmann@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AUinput_adapter_protocol@detail@nlohmann@@
.?AVinput_stream_adapter@detail@nlohmann@@
.?AVinput_buffer_adapter@detail@nlohmann@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVCMessageMap@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AVCWindow@ATL@@
.?AV?$CDialogImplBaseT@VCWindow@ATL@@@ATL@@
.?AVCNSudoMainWindow@@
.?AV?$CDialogImpl@VCNSudoMainWindow@@VCWindow@ATL@@@ATL@@
.?AV?$_Ref_count_obj@Vinput_stream_adapter@detail@nlohmann@@@std@@
.?AV?$_Ref_count_obj@Vinput_buffer_adapter@detail@nlohmann@@@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
"ContextMenu": [
"HasLUAShield": true,
"ItemCommandParameters": "-U:T",
"ItemDescriptionID": "ContextMenu.TI",
"ItemName": "NSudo.RunAs.TrustedInstaller"
},
"HasLUAShield": true,
"ItemCommandParameters": "-U:T -P:E",
"ItemDescriptionID": "ContextMenu.TI.EnableAllPrivileges",
"ItemName": "NSudo.RunAs.TrustedInstaller.EnableAllPrivileges"
},
"HasLUAShield": true,
"ItemCommandParameters": "-U:S",
"ItemDescriptionID": "ContextMenu.System",
"ItemName": "NSudo.RunAs.System"
},
"HasLUAShield": true,
"ItemCommandParameters": "-U:S -P:E",
"ItemDescriptionID": "ContextMenu.System.EnableAllPrivileges",
"ItemName": "NSudo.RunAs.System.EnableAllPrivileges"
bIDATx
vN@Sf]
bIvi:o
`geDwz
#P7)IB_
|U@Rpe
"Translations": {
"Button.About": "
(&A)",
"Button.Browse": "
(&B)",
"Button.Run": "
(&R)",
"ContextMenu.System": "
System
"ContextMenu.System.EnableAllPrivileges": "
System
"ContextMenu.TI": "
TrustedInstaller
"ContextMenu.TI.EnableAllPrivileges": "
TrustedInstaller
"CurrentProcess": "
"CurrentUser": "
"Default": "
"EnableAllPrivileges": "
(&E)",
"LanguageID": "zh-Hans",
"Message.CreateProcessFailed": "
"Message.InvalidCommandParameter": "
"Message.InvalidTextBoxParameter": "
"Message.PrivilegeNotHeld": "
SE_DEBUG_NAME
"Message.Success": "
"SettingsGroupText": "
"Static.Open": "
(&O):",
"Static.User": "
(&U):",
"System": "System",
"TI": "TrustedInstaller",
"WarningText": "
GitHub
https://github.com/M2Team/NSudo
MDL
https://forums.mydigitallife.net/threads/59268/
Mouri_Naruto@Outlook.com
: NSudo [
T TrustedInstaller
S System
C
P
D
E
D
S
H
M
L
-Priority:[
Idle
BelowNormal
Normal
AboveNormal
High
RealTime
-Priority
-ShowWindowMode:[
Show
Hide
Maximize
Minimize
-ShowWindowMode
-Wait
NSudo
-CurrentDirectory:[
NSudo
-CurrentDirectory
-UseCurrentConsole
-UseCurrentConsole
-Version
NSudo
-Help
-Install
Windows
-Uninstall
Windows
1.
1.
"--"
"/U:T"
"-U=T"
1.
NSudoC
TrustedInstaller
NSudo -U:T -P:E cmd
"Translations": {
"Button.About": "
(&A)",
"Button.Browse": "
(&B)",
"Button.Run": "
(&R)",
"ContextMenu.System": "
System
"ContextMenu.System.EnableAllPrivileges": "
System
"ContextMenu.TI": "
TrustedInstaller
"ContextMenu.TI.EnableAllPrivileges": "
TrustedInstaller
"CurrentProcess": "
"CurrentUser": "
"Default": "
"EnableAllPrivileges": "
(&E)",
"LanguageID": "zh-Hant",
"Message.CreateProcessFailed": "
"Message.InvalidCommandParameter": "
"Message.InvalidTextBoxParameter": "
"Message.PrivilegeNotHeld": "
SE_DEBUG_NAME
"Message.Success": "
"SettingsGroupText": "
"Static.Open": "
(&O):",
"Static.User": "
(&U):",
"System": "System",
"TI": "TrustedInstaller",
"WarningText": "
GitHub
https://github.com/M2Team/NSudo
MDL
https://forums.mydigitallife.net/threads/59268/
Mouri_Naruto@Outlook.com
: NSudo [
T TrustedInstaller
S System
C
P
D
E
D
S
H
M
L
-Priority:[
Idle
BelowNormal
Normal
AboveNormal
High
RealTime
-Priority
-ShowWindowMode:[
Show
Hide
Maximize
Minimize
-ShowWindowMode
-Wait
NSudo
-CurrentDirectory:[
NSudo
-CurrentDirectory
-UseCurrentConsole
-UseCurrentConsole
-Version
NSudo
-Help
-Install
Windows
-Uninstall
Windows
1.
1.
"--"
"/U:T"
"-U=T"
1.
NSudoC
TrustedInstaller
NSudo -U:T -P:E cmd
"Translations": {
"Button.About": "&About",
"Button.Browse": "&Browse",
"Button.Run": "&Run",
"ContextMenu.System": "Run As System",
"ContextMenu.System.EnableAllPrivileges": "Run As System (Enable All Privileges)",
"ContextMenu.TI": "Run As TrustedInstaller",
"ContextMenu.TI.EnableAllPrivileges": "Run As TrustedInstaller (Enable All Privileges)",
"CurrentProcess": "Current Process",
"CurrentUser": "Current User",
"Default": "Default",
"EnableAllPrivileges": "&Enable All Privileges",
"LanguageID": "en",
"Message.CreateProcessFailed": "Error: Failed to create a process.",
"Message.InvalidCommandParameter": "Error: Invalid command line parameters, Please modify.(Show help by -? parameter)",
"Message.InvalidTextBoxParameter": "Error: Please enter the command line or select a shortcut command in the drop-down box.",
"Message.PrivilegeNotHeld": "Error: Failed to get SE_DEBUG_NAME privilege.(Please run as Administrator)",
"Message.Success": "The operation completed successfully.",
"SettingsGroupText": "Mode Settings",
"Static.Open": "&Open:",
"Static.User": "&User: ",
"System": "System",
"TI": "TrustedInstaller",
"WarningText": "Warning: Please use NSudo CAREFULLY !"
Communication:
GitHub: https://github.com/M2Team/NSudo
MDL Post: https://forums.mydigitallife.net/threads/59268/
E-mail: Mouri_Naruto@Outlook.com
Format: NSudo [ Options and parameters ] Command line or ShortCut Command
Options:
-U:[ Option ] Create a process with specified user option.
Available options:
T TrustedInstaller
S System
C Current User
P Current Process
D Current Process (Drop right)
PS: This is a mandatory parameter.
-P:[ Option ] Create a process with specified privilege option.
Available options:
E Enable All Privileges
D Disable All Privileges
PS: If you want to use the default privileges to create a process, please do
not include the "-P" parameter.
-M:[ Option ] Create a process with specified Integrity Level option.
Available options:
S System
H High
M Medium
L Low
PS: If you want to use the default Integrity Level to create a process, please
do not include the "-M" parameter.
-Priority:[ Option ] Create a process with specified [rocess priority option.
Available options:
Idle
BelowNormal
Normal
AboveNormal
High
RealTime
PS: If you want to use the default Process Priority to create a process, please
do not include the "-Priority" parameter.
-ShowWindowMode:[ Option ] Create a process with specified window mode option.
Available options:
Show
Hide
Maximize
Minimize
PS: If you want to use the default window mode to create a process, please do
not include the "-ShowWindowMode" parameter.
-Wait Make NSudo wait for the created process to end before exiting.
PS: If you don't want to wait, please do not include the "-Wait" parameter.
-CurrentDirectory:[ DirectoryPath ] Set the current directory for the process.
PS: If you want to use the NSudo's current directory, please do not include the
"-CurrentDirectory" parameter.
-UseCurrentConsole Create a process with the current console window.
PS: If you want to create a process with the new console window, please do not
include the "-UseCurrentConsole" parameter.
-Version Show version information of NSudo.
-? Show this content.
-H Show this content.
-Help Show this content.
Context Menu:
-Install Copy NSudo to the Windows directory and add the context menu.
-Uninstall Remove NSudo in the Windows directory and the context menu.
1. All NSudo command arguments is case-insensitive.
2. You can use the "/" or "--" override "-" and use the "=" override ":" in
the command line parameters. For example, "/U:T" and "-U=T" are
equivalent.
3. To ensure the best experience, NSudoC does not support context menu.
Example:
If you want to run Command Prompt with TrustedInstaller, enable all
privileges and the default Integrity Level.
NSudo -U:T -P:E cmd
"Translations": {
"Button.About": "&A propos",
"Button.Browse": "&Parcourir",
"Button.Run": "&Ex
cuter",
"ContextMenu.System": "Ex
cuter en tant que Syst
"ContextMenu.System.EnableAllPrivileges": "Ex
cuter en tant que Syst
me (Activer tous les privil
ges)",
"ContextMenu.TI": "Ex
cuter en tant que TrustedInstaller",
"ContextMenu.TI.EnableAllPrivileges": "Ex
cuter en tant que TrustedInstaller (Activer tous les privil
ges)",
"CurrentProcess": "Processus courant",
"CurrentUser": "Utilisateur actuel",
"Default": "D
faut",
"EnableAllPrivileges": "&Activer tous les privil
"LanguageID": "fr",
"Message.CreateProcessFailed": "Erreur: La cr
ation du processus a
"Message.InvalidCommandParameter": "Erreur: Param
tres de commande invalides, veuillez les modifier.(Entrez -? pour afficher l'aide)",
"Message.InvalidTextBoxParameter": "Erreur: Veuillez entrer la ligne de commande, ou s
lectionnez un raccourci dans le menu d
roulant.",
"Message.PrivilegeNotHeld": "Erreur: Impossible d'obtenir le privil
ge SE_DEBUG_NAME.(Veuillez
cuter en tant qu'administrateur)",
"Message.Success": "Op
ration termin
e avec succ
"SettingsGroupText": "Param
tres",
"Static.Open": "&Ouvrir:",
"Static.User": "&Utilisateur: ",
"System": "Syst
"TI": "TrustedInstaller",
"WarningText": "Attention: Veuillez utiliser NSudo PRUDEMMENT !"
Communication:
GitHub: https://github.com/M2Team/NSudo
Fil de discussion MDL: https://forums.mydigitallife.net/threads/59268/
E-mail: Mouri_Naruto@Outlook.com
Format: NSudo [Options et param
tres] Ligne de commande ou Raccourci
Options:
-U: [Option] Cr
e un processus avec une option d'utilisateur sp
Options disponibles:
T TrustedInstaller
S Syst
C Utilisateur actuel
P Processus actuel
D Processus actuel (moindre privil
ge: privil
ges strictement n
cessaires
cution du code)
PS: Ce param
tre est obligatoire.
-P: [Option] Cr
e un processus avec une option de privil
Options disponibles:
E Activer tous les privil
D D
sactiver tous les privil
PS: Si vous souhaitez cr
er un processus avec les privil
ges par d
faut,
n'incluez pas le param
tre "-P".
-M: [Option] Cr
e un processus avec une option de niveau d'int
Options disponibles:
S Syst
H Haut
M Moyen
L Faible
PS: Si vous souhaitez cr
er un processus avec le niveau d
faut, n'incluez pas le param
tre "-M".
-Priority: [Option] Cr
e un processus avec une option de priorit
Options disponibles:
Idle Inactif
BelowNormal Inf
rieure
la normale
Normal Normale
AboveNormal Sup
rieure
la normale
High Haute
RealTime Temps r
PS: Si vous souhaitez cr
er un processus avec la priorit
par d
faut, n'incluez
pas le param
tre "-Priority".
-ShowWindowMode: [Option] Cr
er un processus avec l'option de mode de fen
sp
Options disponibles:
Show Montrer
Hide Cacher
Maximize Maximiser
Minimize Minimiser
PS: Si vous souhaitez cr
er un processus avec le mode de fen
tre par d
faut,
n'incluez pas le param
tre "-ShowWindowMode".
-Wait NSudo attend que le processus cr
se termine avant de quitter.
PS: Si vous ne voulez pas que Nsudo attende la fin du processus, n'incluez pas
le param
tre "-Wait".
-CurrentDirectory: [DirectoryPath] D
finit le r
pertoire actuel du processus.
PS: Si vous souhaitez utiliser le r
pertoire actuel de NSudo, n'incluez pas le
tre "-CurrentDirectory".
-UseCurrentConsole Cr
e un processus dans la fen
tre de console actuelle.
PS: Si vous souhaitez cr
er un processus dans une nouvelle fen
tre de console,
n'incluez pas le param
tre "-UseCurrentConsole".
-Version Affiche les informations de version de NSudo.
-? Affiche l'aide.
-H Affiche l'aide.
-Help Affiche l'aide.
Menu contextuel:
-Install Copie NSudo dans le r
pertoire de Windows, et ajoute le menu
contextuel.
-Uninstall Supprime NSudo du r
pertoire de Windows ainsi que le menu
contextuel.
1. Tous les arguments de commande de NSudo sont insensibles
la casse.
2. Vous pouvez utiliser "-" ou "/ " , et remplacer ":" par " =" dans
les param
tres de ligne de commande. Par exemple, "/ U: T" et "-U = T"
sont
quivalents.
3. Afin d'assurer la meilleure exp
rience possible, NSudoC ne prend pas en
charge le menu contextuel.
Exemple:
Si vous souhaitez ex
cuter un invit
de commande en tant que
TrustedInstaller, activez toutes les privil
ges et le niveau d'int
par d
NSudo -U: T -P: E cmd
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">True/PM</dpiAware><dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness></windowsSettings></application><ms_compatibility:compatibility xmlns:ms_compatibility="urn:schemas-microsoft-com:compatibility.v1" xmlns="urn:schemas-microsoft-com:compatibility.v1"><ms_compatibility:app
user32.dll
HasLUAShield
command
winlogon.exe
WinSta0\Default
String
M2-Team NSudo 6.2.1812.31
M2-Team NSudo 6.2.1812.31
M2-Team. All rights reserved.
2\NSudo.json
Config
\NSudo.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CommandStore\shell
cmd /c start "NSudo.ContextMenu.Launcher"
-ShowWindowMode=Hide
*\shell\NSudo
SubCommands
MUIVerb
Position
Version
Install
Uninstall
Priority
BelowNormal
Normal
AboveNormal
RealTime
CurrentDirectory
ShowWindowMode
Maximize
Minimize
UseCurrentConsole
TrustedInstaller
SHCore.dll
NSudo -ShowWindowMode=Hide
cmd /c start "NSudo.Launcher"
ERROR : Unable to initialize critical section in CAtlBaseModule
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
CONFIG
STRING
MS Shell Dlg
MS Shell Dlg
VS_VERSION_INFO
StringFileInfo
000004b0
CompanyName
M2-Team
FileDescription
NSudo for Windows
FileVersion
6.2.1812.31
InternalName
LegalCopyright
M2-Team and Contributors. All rights reserved.
OriginalFilename
NSudo.exe
ProductName
ProductVersion
6.2.1812.31
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
Cybereason Clean
Avast Clean
Qihoo-360 Clean
No IRMA results available.