Static | ZeroBOX

PE Compile Time

2017-07-06 13:56:31

PDB Path

bthpan.pdb

PE Imphash

dfa790d8cf26fad6098be1e0a726129e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001695a 0x00016a00 6.42136234512
.rdata 0x00018000 0x00000f2c 0x00001000 4.97726651497
.data 0x00019000 0x000006a4 0x00000400 2.87325945535
.pdata 0x0001a000 0x00000c18 0x00000e00 4.52043289692
PAGE 0x0001b000 0x00001e0c 0x00002000 6.18926669393
INIT 0x0001d000 0x00000e6a 0x00001000 5.64868950233
.rsrc 0x0001e000 0x00000ff8 0x00001000 6.75075988019
.reloc 0x0001f000 0x000000d8 0x00000200 0.72155014879

Resources

Name Offset Size Language Sub-language File type
MOFDATA 0x0001e4d8 0x00000a31 LANG_ENGLISH SUBLANG_ENGLISH_US data
MUI 0x0001ef10 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0001e120 0x000003b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ntoskrnl.exe:
0x280f0 ZwSetValueKey
0x28100 IoBuildPartialMdl
0x28108 ZwQueryValueKey
0x28110 IoFreeMdl
0x28118 KeBugCheckEx
0x28120 ZwClose
0x28130 ExQueryDepthSList
0x28158 IoCancelIrp
0x28168 KeInitializeEvent
0x28170 KeSetEvent
0x28178 RtlUnicodeToUTF8N
0x28180 IoAllocateIrp
0x28188 IoFreeIrp
0x281a8 RtlInitString
0x281b0 KeReleaseSpinLock
0x281c0 IofCallDriver
0x281c8 IofCompleteRequest
0x281d8 RtlCompareMemory
0x281e8 ExFreePoolWithTag
0x281f0 IoWMIWriteEvent
0x28200 IoAllocateMdl
0x28210 ExFreePool
Library NDIS.SYS:
0x28000 NdisAllocatePacket
0x28008 NdisAllocateBuffer
0x28010 NdisFreePacketPool
0x28018 NdisFreeBufferPool
0x28040 NdisSetTimer
0x28048 NdisCancelTimer
0x28058 NdisWaitEvent
0x28068 NdisSetEvent
0x28078 NdisFreeMemory
0x280b8 NdisMSleep
0x280e0 NdisFreePacket

!This program cannot be run in DOS mode.
h.rdata
H.data
.pdata
B.reloc
L$ SUVWH
H!t$ H
VWATAUAVH
A^A]A\_^
SUVWATAUAVAWH
d$8;\$D
A_A^A]A\_^][
t$ WATAUAVAWH
A_A^A]A\_
WATAUH
A]A\_
WATAUAVAWH
WxA;T$
0A_A^A]A\_
VWATAUAVH
A^A]A\_^
t$ WATAUAVAWH
H9|$xuEH
A_A^A]A\_
|$ ATH
WATAUH
A]A\_
UVWATAVH
@A^A\_^]
t2A8[)r
s WATAUH
D$`fD; u
L9d$8t
s WATAUH
VWATAUAVH
0A^A]A\_^
h VWATH
WATAUAVAWH
A_A^A]A\_
D99vqI
UVWATAUAVAWH
A_A^A]A\_^]
t$ WATAUAVAWH
A_A^A]A\_
l$ VWATAUAWH
L9|$`t-
A_A]A\_^
UVWATAUAVAWH
`A_A^A]A\_^]
t$ WATAUAVAWH
C,tJE8K)rD
0A_A^A]A\_
WATAUH
A]A\_
t$ WATAWH
0A_A\_
UVWATAUH
@A]A\_^]
[ UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUH
@A]A\_^]
VWATAUAVH
A^A]A\_^
WATAVH
WATAUH
D$(BTPNH
WATAUH
@A]A\_
L$ ATH
UVWATAUAVAWH
@A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
SUVWATAUAVAWH
A_A^A]A\_^][
SUVWATAUAVAWH
HA_A^A]A\_^][
WATAUH
0A]A\_
UVWATAUAVAWH
l$HfA9F
PA_A^A]A\_^]
SUVWATAUAVAWH
~ L9vpt|H
8A_A^A]A\_^][
WATAUH
0A]A\_
UVWATAUAVAWH
t+A8S)r%I
t#A8S)r
A_A^A]A\_^]
X UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
Q,t)D8I)r#H
Q,t$D8I)r
t=@8h)rH
A_A^A]A\_^]
X UVWATAUAVAWH
@A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
@A_A^A]A\_^]
x ATAUAVH
A8z)rBA
r,tLA8z)rFA
@A^A]A\
UVWATAUAVAWH
0A_A^A]A\_^]
tMA8z)rGA
l$ VWATH
a,tjD8Q)rd
a,t"D8Q)r
UVWATAVH
A^A\_^]
p WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
fffffff
fffffff
DCB_STATE_NONE
DCB_STATE_IDLE
DCB_STATE_BUSY
DCB_STATE_HALT_WAIT
DCB_STATE_HALTING
DCB_STATE_HALTED
DCB_STATE_ZOMBIE
Unknown DCB State
DCB_EVENT_NONE
DCB_EVENT_DEVICE_ADD
DCB_EVENT_DEVICE_SURPRISE_REMOVE
DCB_EVENT_DEVICE_REMOVE_REQUEST
DCB_EVENT_DEVICE_REMOVE_COMPLETE
DCB_EVENT_DEVICE_REMOVE_DELAY_REQUEST
DCB_EVENT_DEVICE_REMOVE_DELAY_COMPLETE
DCB_EVENT_CCB_CONNECT_COMPLETE
DCB_EVENT_CCB_DISCONNECT_COMPLETE
Unknown DCB Event
CONN_EVENT_OPEN_INIT
CONN_EVENT_OPEN_FAIL
CONN_EVENT_OPEN_SUCCESS
CONN_EVENT_OPEN_FINALISE
CONN_EVENT_CLOSE_INIT
CONN_EVENT_CLOSE_ISSUE
CONN_EVENT_CLOSE_FAIL
CONN_EVENT_CLOSE_SUCCESS
CONN_EVENT_DESTROY_FORCE
Unknown Connection Event
CONN_STATE_CLOSED
CONN_STATE_OPENING
CONN_STATE_OPEN
CONN_STATE_CLOSE_WAIT
CONN_STATE_CLOSING
CONN_STATE_ZOMBIE
Unknown Connection State
BTHPAN_ROLE_NONE
BTHPAN_ROLE_NAP
BTHPAN_ROLE_GN
BTHPAN_ROLE_PANU
Unknown PAN Role
BNEP_EVENT_CONN_REQUEST_ACTIVE
BNEP_EVENT_CONN_REQUEST_PASSIVE
BNEP_EVENT_CONN_ESTABLISHED
BNEP_EVENT_CONN_REJECTED
BNEP_EVENT_CONN_DISCONNECT
BNEP_EVENT_CONN_DISCONNECT_COMPLETE
BNEP_EVENT_CONN_ROLE_CHANGE
Unknown BNEP Event
BNEP_STATE_CLOSED
BNEP_STATE_OPENING_ACTIVE
BNEP_STATE_OPENING_PASSIVE
BNEP_STATE_OPEN
BNEP_STATE_ZOMBIE
Unknown BNEP State
IRP_MJ_CREATE
IRP_MJ_CREATE_NAMED_PIPE
IRP_MJ_CLOSE
IRP_MJ_READ
IRP_MJ_WRITE
IRP_MJ_QUERY_INFORMATION
IRP_MJ_SET_INFORMATION
IRP_MJ_QUERY_EA
IRP_MJ_SET_EA
IRP_MJ_FLUSH_BUFFERS
IRP_MJ_QUERY_VOLUME_INFORMATION
IRP_MJ_SET_VOLUME_INFORMATION
IRP_MJ_DIRECTORY_CONTROL
IRP_MJ_FILE_SYSTEM_CONTROL
IRP_MJ_DEVICE_CONTROL
IRP_MJ_INTERNAL_DEVICE_CONTROL
IRP_MJ_SHUTDOWN
IRP_MJ_LOCK_CONTROL
IRP_MJ_CLEANUP
IRP_MJ_CREATE_MAILSLOT
IRP_MJ_QUERY_SECURITY
IRP_MJ_SET_SECURITY
IRP_MJ_POWER
IRP_MJ_SYSTEM_CONTROL
IRP_MJ_DEVICE_CHANGE
IRP_MJ_QUERY_QUOTA
IRP_MJ_SET_QUOTA
IRP_MJ_PNP
Unknown Major Function
IOCTL_PAN_CONNECT
IOCTL_PAN_DISCONNECT
IOCTL_PAN_CONFIG_SET
IOCTL_PAN_CONFIG_QUERY
IOCTL_PAN_ENUM_CONNECTIONS
IOCTL_PAN_ENUM_DEVICES
Unknown device control function
DriverUnload
MpInitialise
MpHalt
MpPnPEventNotify
MpRequestQueryComplete
Microsoft
MpQueryInformation
MpRequestSetComplete
MpSetInformation
MpSetInformationEpilogue
MpReturnPacket
MpReceiveComplete
MpSendComplete
MpSendPackets
MpShutdown
MpCheckForHang
MpMediaStatusIndicate
Connected
Disconnected
BthpanReqCreate
BthpanReqDestroy
BthpanReqCompleteByRcb
BthpanReqConnectIsMatched
BthpanReqDisconnectIsMatched
BthpanReqIsMatched
BthpanReqNwi
BthpanReqAdd
BthpanDcbCreate
BthpanDcbDestroy
BthpanAdapterRefDestroyReleased
BthpanHaltAdapter
BthpanAdapterRefHaltReleased
BthpanCcbConnect
BthpanCcbCreate
BthpanCcbDestroy
BthpanIfDisconnComplete
BthpanIfConnComplete
BthpanCountOpenCcbs
BthpanCcbCallbackReferenceOnlyCcb
BthpanCcbCallbackReferenceForTx
BthpanCcbCallbackReferenceForBroadcast
BthpanCcbCallbackCopyEnumSpecific
BthpanCcbCallbackCmpByRemoteAddr
BthpanCcbCallbackOpenCcbCount
BthpanTraverseCcbs
BthpanFindAndRefAdapterByName
BthpanAdapCallbackCopyEnumSpecific
BthpanAdapCallbackAdapterCount
BthpanAdapCallbackCmpByName
BthpanTraverseAdapters
BthpanValidateConnectRequest
BthpanValidateDisconnectRequest
BthpanCcbDisconnect
BthpanHalt
BthpanConfigStore
BthpanConfigLoad
BthpanConfigChange
BthpanConfigSet
BthpanConfigQuery
BthpanEnumCcbs
BthpanCcbRefDestroyReleased
BthpanEnumDevices
BthpanSendPacketRefPacketReleased
BthpanPacketSend
BthpanPacketSendComplete
BthpanPacketProcess
BthpanIfInitialize
BthpanIfDestroy
BthpanAdapterRegisterComplete
BthpanIfAdapterRegister
BthpanIfAdapterRemove
BthpanDcbMediaStatusIndicate
BthpanDcbStateChange
BthpanDcbTransition
BthpanDcbPowerStateSet
BthpanCcbCheckForHang
BthpanDcbCheckForHang
L2capifCcbInitialize
L2capifCancelPendingIrps
L2capifCcbRefDisconnectReleased
L2capifIndicationCallback
L2capifCcbChangeState
L2capifCcbConnect
L2capifCcbConnectComplete
L2capifCcbAccept
L2capifCcbAcceptComplete
L2capifCcbTransition
L2capifCcbDisconnectConnection
L2capifCcbDisconnectComplete
L2capifCcbSend
L2capifCcbSendComplete
L2capifCcbReceive
L2capifCcbReceiveComplete
L2capifCcbRxResumeNwi
L2capifCcbRxInitiate
L2capifCcbReturnPacket
L2capifCcbPacketIssueNwi
L2capifCcbPacketIssue
L2capifCcbReceiveRefPacketReleased
L2capifCcbDestroy
L2capIfInitialize
L2capIfDestroy
L2capIfAdapterRegister
L2capIfAdapterRemove
SdpAllocRecord
SdpFreeRecord
SdpSetDefaults
SdpBuildRecord
SdpPublishRecord
DupNdisString
FreeDupNdisString
BrbGetLocalAddr
BrbSyncComplete
BrbCallSync
BrbConnectComplete
BrbConnect
BrbAcceptComplete
BrbAccept
BrbDisconnectComplete
BrbDisconnect
BrbReceiveComplete
BrbReceive
BrbSendComplete
BrbSend
BrbDeregisterCallback
BrbL2CapServerInterface
BrbIfInitialize
BrbIfDestroy
BrbIfAdapterRegister
BrbIfAdapterRemove
BrbIrpContextGet
BrbIrpContextPut
BrbCallAsync
BrbAsyncComplete
SdpuSyncIrpCompletionRoutine
SdpuSyncCallBthport
SdpuServiceAdd
SdpuServiceDelete
RegOpenDeviceKey
RegCloseKey
RegReadValue
RegReadValueUint32
RegReadValueString
RegWriteValue
RegWriteValueUint32
RegWriteValueString
BnepCcbInitialize
BnepCcbDestroy
BnepChangeState
BnepTransitionContext
BnepIfDisconnComplete
BnepIfConnComplete
BnepCcbConnect
BnepGetHeaderInfo
BnepBookmarkIncomingPacket
BnepProcessIncomingPacket
BnepDataProcess
BnepDataSend
BnepDataSendComplete
BnepDataPacketConvertBnepToEth
BnepDataHdrConvertEthToBnep
BnepDataPacketConvertEthToBnep
BnepControlProcess
BnepControlSendRefPacketReleased
BnepControlSendComplete
BnepFilterCbInitialise
BnepFilterCbDestroy
BnepFilterRecvPass
BnepFilterSendPass
BnepFilterNetTypeSetTimeout
BnepFilterNetTypeSetProcess
BnepFilterNetTypeResponseProcess
BnepFilterNetTypeSetIssue
BnepFilterNetTypeResponseIssue
BnepFilterMulticastStartNwi
BnepFilterMulticastSetTimeout
BnepFilterMulticastSetProcess
BnepFilterMulticastResponseProcess
BnepFilterMulticastSetIssue
BnepFilterMulticastResponseIssue
BnepCommandNotUnderstoodIssue
BnepCommandNotUnderstoodProcess
BnepSetupConnectionRequestIssue
BnepSetupConnectionRequestProcess
BnepSetupConnectionRequestValidate
BnepSetupConnectionResponseTimeout
BnepSetupConnectionResponseIssue
BnepSetupConnectionResponseProcess
BnepUuidWrite
BnepUuidRead
BnepIfInitialize
BnepIfDestroy
BnepIfAdapterRegister
BnepIfAdapterRemove
IoctlInitialize
IoctlDestroy
IoctlDispatchMajor
IoctlDispatchDeviceControl
IoctlRequestComplete
PuPoolCBAlloc
PuPoolCBFree
PuPktCBAlloc
PuPktCBFree
PuPktCtor
PuPktDtor
PuPktGet
PuPktPut
PuInitialize
PuDestroy
SuInitialize
SuDestroy
bthpan.pdb
VWATAUAVH
D!S,L!S
A^A]A\_^
D$ BTPs
u&fD;G
VWATAUAVH
A^A]A\_^
WATAWH
t$ WATAUH
H fD9i
A]A\_
L$0H;L$8t
L;L$8t
9t$`vU
t$8f;8r\f;x
f;8rQA
{ H9?u
*H+L$0H
L$0H;L$8t
H;L$8t
VWATAUAVH
D$(BTPNH
A^A]A\_^
DriverEntry
RtlInitUnicodeString
ExAllocatePoolWithTag
IoWMIWriteEvent
ExFreePoolWithTag
MmGetSystemRoutineAddress
RtlCompareMemory
IoWMIRegistrationControl
IofCompleteRequest
IofCallDriver
KeAcquireSpinLockRaiseToDpc
KeReleaseSpinLock
RtlInitString
RtlAnsiStringToUnicodeString
RtlUnicodeStringToAnsiString
MmMapLockedPagesSpecifyCache
IoFreeIrp
IoAllocateIrp
RtlUnicodeToUTF8N
KeSetEvent
KeInitializeEvent
KeWaitForSingleObject
IoCancelIrp
ExInitializeNPagedLookasideList
ExDeleteNPagedLookasideList
ExpInterlockedPopEntrySList
ExpInterlockedPushEntrySList
ExQueryDepthSList
IoOpenDeviceRegistryKey
ZwClose
ZwQueryValueKey
ZwSetValueKey
MmBuildMdlForNonPagedPool
IoBuildPartialMdl
IoAllocateMdl
IoFreeMdl
KeBugCheckEx
ntoskrnl.exe
NdisInitializeWrapper
NdisMRegisterMiniport
NdisMRegisterUnloadHandler
NdisTerminateWrapper
NdisMSleep
NdisMSetAttributesEx
NdisMGetDeviceProperty
NdisOpenConfiguration
NdisReadConfiguration
NdisCloseConfiguration
NdisMIndicateStatus
NdisAllocateMemoryWithTag
NdisFreeMemory
NdisScheduleWorkItem
NdisSetEvent
NdisInitializeEvent
NdisWaitEvent
NdisInitializeTimer
NdisCancelTimer
NdisSetTimer
NdisMRegisterDevice
NdisMDeregisterDevice
NdisAllocatePacketPool
NdisAllocateBufferPool
NdisFreeBufferPool
NdisFreePacketPool
NdisAllocateBuffer
NdisAllocatePacket
NdisFreePacket
NDIS.SYS
ExFreePool
oA>LDx
q&:*?b
|(cp/?
F<c='xN
x&O5Q|
h^$|'d
7f8BOH
n<NULL>
MiniportName
ServiceId
ServiceLangT
ServiceName
ServiceDesc
e\DosDevices\BthPan
\Device\BthPan
PsGetVersion
WmiTraceMessage
WmiQueryTraceInformation
EtwRegisterClassicProvider
EtwUnregister
MOFDATA
MOFRESOURCE
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Bluetooth Personal Area Networking
FileVersion
6.1.7601.23863 (win7sp1_ldr.170705-1950)
InternalName
bthpan.sys
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
bthpan.sys
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7601.23863
VarFileInfo
Translation
MOFDATA
MOFDATA
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
TotalDefense Clean
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
APEX Clean
ESET-NOD32 Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
Webroot Clean
Avast Clean
Qihoo-360 Clean
No IRMA results available.