Static | ZeroBOX

PE Compile Time

1973-11-14 14:02:32

PDB Path

TsUsbHub.pdb

PE Imphash

f89b87f1cd5b01b40e1dc570592e728d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00016869 0x00016a00 6.12305614674
.rdata 0x00018000 0x00002db0 0x00002e00 5.15629773499
.data 0x0001b000 0x00000590 0x00000200 1.84006055595
.pdata 0x0001c000 0x0000156c 0x00001600 4.92147772115
.idata 0x0001e000 0x00000ae0 0x00000c00 4.50337293895
PAGE 0x0001f000 0x00001ce1 0x00001e00 6.01640774284
INIT 0x00021000 0x0000044e 0x00000600 5.10919410358
GFIDS 0x00022000 0x00000460 0x00000600 3.56345479431
.rsrc 0x00023000 0x00001b60 0x00001c00 3.53918573372
.reloc 0x00025000 0x00001208 0x00001400 6.24702309567

Resources

Name Offset Size Language Sub-language File type
MUI 0x00024a68 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
WEVT_TEMPLATE 0x00023cd8 0x00000cf2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000249d0 0x00000096 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MESSAGETABLE 0x00023548 0x00000790 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000231a0 0x000003a4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ntoskrnl.exe:
0x1c001e038 EtwWriteTransfer
0x1c001e040 RtlCompareMemory
0x1c001e050 IoFileObjectType
0x1c001e058 RtlGUIDFromString
0x1c001e060 _vsnwprintf
0x1c001e070 IoWMIRegistrationControl
0x1c001e098 wcsncmp
0x1c001e0a0 RtlStringFromGUID
0x1c001e0a8 IoGetDeviceProperty
0x1c001e0b0 IoSetDevicePropertyData
0x1c001e0b8 IofCompleteRequest
0x1c001e0c0 IoGetDevicePropertyData
0x1c001e0c8 KfRaiseIrql
0x1c001e0d0 KeLowerIrql
0x1c001e0d8 RtlInitializeBitMap
0x1c001e0e0 _purecall
0x1c001e0e8 RtlInitUnicodeString
0x1c001e0f0 DbgPrintEx
0x1c001e0f8 RtlCopyUnicodeString
0x1c001e100 ExFreePool
0x1c001e118 ObfDereferenceObject
0x1c001e120 ExDeleteResourceLite
0x1c001e130 KeEnterCriticalRegion
0x1c001e138 KeLeaveCriticalRegion
0x1c001e140 ExReleaseResourceLite
0x1c001e148 KeInitializeMutex
0x1c001e150 KeReleaseMutex
0x1c001e158 KeWaitForSingleObject
0x1c001e160 KeSetEvent
0x1c001e168 ZwCreateFile
0x1c001e170 IoCancelIrp
0x1c001e178 ZwClose
0x1c001e180 IoGetRelatedDeviceObject
0x1c001e188 KeInitializeEvent
0x1c001e198 IofCallDriver
0x1c001e1a0 ExQueueWorkItem
0x1c001e1a8 MmUnlockPages
0x1c001e1b0 IoFreeMdl
0x1c001e1b8 IoFreeIrp
0x1c001e1c0 _wcsicmp
0x1c001e1d0 RtlCheckTokenMembership
0x1c001e1d8 RtlLengthRequiredSid
0x1c001e1e0 RtlSubAuthoritySid
0x1c001e1e8 RtlInitializeSid
0x1c001e1f0 EtwRegister
0x1c001e1f8 EtwUnregister
0x1c001e200 ExFreePoolWithTag
0x1c001e208 ExInitializeResourceLite
0x1c001e210 ExAllocatePoolWithTag
0x1c001e218 RtlAreBitsSet
0x1c001e220 RtlClearBits
0x1c001e228 RtlFindClearBitsAndSet
Library HAL.dll:
Library WDFLDR.SYS:
0x1c001e010 WdfVersionUnbind
0x1c001e018 WdfVersionBind
0x1c001e020 WdfVersionUnbindClass
0x1c001e028 WdfVersionBindClass

!This program cannot be run in DOS mode.
pRich{
h.rdata
H.data
.pdata
H.idata
bGFIDS
B.rsrc
B.reloc
H9E8w<H
UVWATAUAVAWH
A_A^A]A\_^]
R$fA;Z*
L$ UVWATAUAVAWH
pA_A^A]A\_^]
l$ VWAUAVAWH
HH9H@w
0A_A^A]_^
UATAUAVAWH
A_A^A]A\]
@USVWAUAVAWH
tJ@8y)r
t'@8y)r!
0A_A^A]_^[]
UVWATAUAVAWH
A8@@u.H
fE9,Dt(H
fE9,Ft+H
A_A^A]A\_^]
L$ SUVWH
L$ SUVWH
t$ WATAWH
A_A\_
BHL;CHu2H
GXL;CXu
\$ UVWATAUAVAWH
@8y)r}
A_A^A]A\_^]
WATAUAVAWH
}GfD9~
}NfD9~
A_A^A]A\_
k VWATAVAWH
0A_A^A\_^
@USVWAVAWH
@8wbuL
XA_A^_^[]
UVWATAUAVAWH
B"D8b u
PA_A^A]A\_^]
WAVAWH
0A_A^_
x AUAVAWH
0A_A^A]
+_T+]0
UVWATAUAVAWH
`A_A^A]A\_^]
]`fA;^`vuI
E9FTtL
WATAUAVAWH
A_A^A]A\_
p WAVAWH
@A_A^_
p WAVAWH
0A_A^_
h VWAUAVAWH
A_A^A]_^
X UVWAVAWH
@A_A^_^]
WAVAWH
0A_A^_
WAVAWH
0A_A^_
@8h0t$H
D$(ListH
D$(EvntH
t$ UWATAVAWH
y:D9d$`u
A_A^A\_]
VWATAVAWH
D9d$hu
0A_A^A\_^
WAVAWH
A_A^_
tNH!\$0L
USVWATAUAVAWH
A_A^A]A\_^[]
@USWAVAWH
U@!}8L
@A_A^_[]
@USWATAVH
PA^A\_[]
@USWATAVH
PA^A\_[]
@USWATAVH
PA^A\_[]
UVWAUAWH
`A_A]_^]
@USVWAVH
PA^_^[]
x ATAVAWH
A_A^A\
p AWE3
WATAUAVAWH
fD9)t|A
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WAVAWH
E(D8q(
A_A^_
UVWATAUAVAWH
@A_A^A]A\_^]
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
WAVAWH
9_$tKH
0A_A^_
L$P;H$v
WAVAWH
9_$tKH
0A_A^_
L$P;H$v
x ATAVAWH
0A_A^A\
WATAUAVAWH
l$p;k$
A_A^A]A\_
T$P;P$v
L$P;H$v
9Z$tHH
WAVAWH
9_$tKH
0A_A^_
w(M96tA3
w(M96tS3
w(M96tS3
WAVAWH
2;Ahv"A
A_A^_
FHD;Hhv
u#L92E
x?L93t:A
fD94Bu
H VWATAVAWH
u,H92D
A_A^A\_^
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
WATAUAVAWH
@8|$xt
0A_A^A]A\_
WAVAWH
WAVAWH
0A_A^_
USVWATAUAVAWH
hA_A^A]A\_^[]
|$ UATAUAVAWH
CPD!kXH
A_A^A]A\]
x UATAUAVAWH
A_A^A]A\]
L$ UVWATAUAVAWH
`A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
|$ UATAUAVAWH
t';^,r
A_A^A]A\]
UVWAVAWH
0A_A^_^]
|$ UATAUAVAWH
A_A^A]A\]
|$ UAVAWH
WAVAWH
D9~0t#H
A_A^_
WATAUAVAWH
0A_A^A]A\_
-fffffff
fffffff
fffffff
fffffff
.fffffff
fffffff
fffffff
fffffff
FCUsbHub
CSession
CDeviceSink
CUsbHubPdo
CUsbHubPdoRequest
clientcore\termsrv\devices\urbdr\busdriver\CSession.h
R!clientcore\termsrv\devices\urbdr\busdriver\buspdo.cpp
xclientcore\termsrv\devices\urbdr\busdriver\pdousb.cpp
clientcore\termsrv\devices\urbdr\busdriver\requestcallback.cpp
8qj}8xT>n
DriverEntry failed 0x%x for driver %wZ
FxStubBindClasses: invalid driver image, the address of symbol __KMDF_CLASS_BIND_START 0x%p is greater than the address of symbol __KMDF_CLASS_BIND_END 0x%p, status 0x%x
FxStubBindClasses: invalid driver image.
Not enough space for WDF_CLASS_BIND_INFO.Size field.
FxStubBindClasses: WDF_CLASS_BIND_INFO 0x%p, class %S, size 0x%x incorrect, expected 0x%Ix, status 0x%x
FxStubBindClasses: invalid driver image.
Not enough space for WDF_CLASS_BIND_INFO.
FxStubBindClasses: ClientBindClass %p, WDF_CLASS_BIND_INFO 0x%p, class %S, returned status 0x%x
FxStubBindClasses: VersionBindClass WDF_CLASS_BIND_INFO 0x%p, class %S, returned status 0x%x
FxStubInitTypes: invalid driver image, the address of symbol __KMDF_TYPE_INIT_START 0x%p is greater than the address of symbol __KMDF_TYPE_INIT_END 0x%p, status 0x%x
FxStubInitTypes: WDF_OBJECT_CONTEXT_TYPE_INFO 0x%p, size 0x%x incorrect, expected 0x%x, status 0x%x
%CRIMObjManager
RimChannel.Lock
CRIMObjectPool
CRIMStreamProxy
CRIMStream
TsUsbHub.pdb
.text$mn
.text$mn$00
.text$mn$21
.rdata$brc
.giats
.rdata
.rdata$zzzdbg
.xdata
.data$brc
.kmdfclassbind$a
.kmdfclassbind$c
.kmdfclassbind$d
.kmdftypeinit$a
.kmdftypeinit$c
.pdata
.idata$5
.00cfg
.idata$2
.idata$3
.idata$4
.idata$6
.gfids
.rsrc$01
.rsrc$02
ExAllocatePoolWithTag
ExFreePoolWithTag
EtwUnregister
EtwRegister
ObfDereferenceObject
RtlInitUnicodeString
_purecall
EtwWriteTransfer
RtlCompareMemory
ObReferenceObjectByHandle
IoFileObjectType
RtlGUIDFromString
_vsnwprintf
MmGetSystemRoutineAddress
IoWMIRegistrationControl
RtlQueryFeatureConfigurationChangeStamp
RtlQueryFeatureConfiguration
RtlRegisterFeatureConfigurationChangeNotification
RtlUnregisterFeatureConfigurationChangeNotification
wcsncmp
RtlStringFromGUID
IoGetDeviceProperty
IoSetDevicePropertyData
IofCompleteRequest
IoGetDevicePropertyData
KfRaiseIrql
KeLowerIrql
ntoskrnl.exe
KeQueryPerformanceCounter
HAL.dll
DbgPrintEx
RtlCopyUnicodeString
ExFreePool
ExInitializeNPagedLookasideList
ExDeleteNPagedLookasideList
ExInitializeResourceLite
ExDeleteResourceLite
ExAcquireResourceExclusiveLite
KeEnterCriticalRegion
KeLeaveCriticalRegion
ExReleaseResourceLite
KeInitializeMutex
KeReleaseMutex
KeWaitForSingleObject
KeSetEvent
ZwCreateFile
IoCancelIrp
ZwClose
IoGetRelatedDeviceObject
KeInitializeEvent
IoBuildAsynchronousFsdRequest
IofCallDriver
ExQueueWorkItem
MmUnlockPages
IoFreeMdl
IoFreeIrp
_wcsicmp
MmMapLockedPagesSpecifyCache
RtlCheckTokenMembership
RtlLengthRequiredSid
RtlSubAuthoritySid
RtlInitializeSid
WdfVersionUnbind
WdfVersionBind
WdfVersionUnbindClass
WdfVersionBindClass
WDFLDR.SYS
RtlAreBitsSet
RtlClearBits
RtlInitializeBitMap
RtlFindClearBitsAndSet
t$ WATAUAVAWH
A_A^A]A\_
D$ H!D$ H
UVWAVAWH
A_A^_^]
\$ UVWATAUAVAWH
A_A^A]A\_^]
` UAVAWH
L97u9H
]+]A]W]
S2TmT}T
U<UQVyV
P)Q\QuQ
U9UWUuUGVcV
\"]>]N]h]
PAP\PLQjQ|Q
S*SJShS
V&VKVqV
V<WYWqW
Y)YOYqY
Z3ZIZ`ZvZ
\&\=\U\
]1]H]`]
^%^@^^^
Q<Q`QwQ
T*TJThT
[:[Z[x[
_*_J_h_
Z'[K[q[
\7\I\f\
+PKPkP
Q'Q\R~R
S[TzTJU
WIWbWrW
Z[3[p[
QrQHRiR
\+];]V]p]
^3_[_q_
U?VTVdV
W2XBXiX
Y3YHY ZCZ
^<^Q^a^
P)POPqP
Q3QIQ`QvQ
FRCSMTLU
tsusb-session%u-%u&%u&%s
PsGetVersion
WmiTraceMessage
WmiQueryTraceInformation
EtwRegisterClassicProvider
EtwUnregister
SymbolicName
KmdfLibrary
(null)
\Device\DrDynVc\%d\%d\%s
USB\ROOT_HUB
USB\ROOT_HUB20
USB\Class_09
WEVT_TEMPLATE
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Remote Desktop USB Hub
FileVersion
10.0.19041.1586 (WinBuild.160101.0800)
InternalName
TsUsbHub.sys
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
TsUsbHub.sys
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.1586
VarFileInfo
Translation
Warning
Information
Verbose
Microsoft-Windows-TerminalServices-ServerUSBDevices
Analytic
Operational
Failed to create Physical Device Object for device %1.
Driver for device %1 failed to load. Timeout period has expired.
Device %1 is not supported on this machine, a generic driver is loaded.
Redirection of additional supported devices is disabled by policy.
Device %1 is successfully installed
Client requests to redirect device %1. NtStatus = %2.
Client requests to remove a redirected device %1. NtStatus = %2.
Dynamic virtual channel %1 is connected. NtStatus = %2.
Dynamic virtual channel %1 is disconnected. NtStatus = %2.
Redirected device %1 name is %2.
Redirected device %1 is starting. NtStatus = %2
Redirected device %1 is stopping. NtStatus = %2
Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin
Microsoft-Windows-TerminalServices-ServerUSBDevices/Analytic
Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational
Microsoft-Windows-TerminalServices-ServerUSBDevices/Debug
EventXML
Event_NS
message
message
EventData
EventXML
Event_NS
deviceName
deviceName
EventXML
Event_NS
objectPointer
objectPointer
EventXML
Event_NS
objectPointer
ntStatus
objectPointer
ntStatus
EventXML
Event_NS
objectPointer
nameString
objectPointer
nameString
Microsoft-Windows-TerminalServices-ServerUSBDevices
win:Error
win:Warning
win:Informational
win:Verbose
Remote Desktop USB Hub%Remote Desktop USB Redirection Driver
WEVT_TEMPLATE
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.