Static | ZeroBOX

PE Compile Time

2009-07-14 08:31:55

PDB Path

msconfig.pdb

PE Imphash

31e556ae7fe1ed4edcf727f836365d92

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032f34 0x00033000 5.98965718574
.data 0x00034000 0x00001308 0x00000a00 3.26622177677
.pdata 0x00036000 0x000022b0 0x00002400 5.36446324878
.rsrc 0x00039000 0x00013000 0x00012200 7.17600553213
.reloc 0x0004c000 0x00000998 0x00000a00 4.17979178245

Resources

Name Offset Size Language Sub-language File type
MUI 0x000393d4 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
REGISTRY 0x000394bc 0x000000b3 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a8fc 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0004ad64 0x000000bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0004ae20 0x000003a8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x100001000 RegCloseKey
0x100001008 RegQueryValueExW
0x100001010 RegSetValueExW
0x100001018 OpenSCManagerW
0x100001020 EnumServicesStatusW
0x100001028 OpenServiceW
0x100001030 CloseServiceHandle
0x100001038 ChangeServiceConfigW
0x100001040 QueryServiceConfigW
0x100001048 RegEnumKeyExW
0x100001050 RegOpenKeyExW
0x100001058 RegCreateKeyExW
0x100001060 RegQueryInfoKeyW
0x100001068 RegEnumValueW
0x100001070 RegDeleteValueW
0x100001078 OpenProcessToken
0x100001080 LookupPrivilegeValueW
0x100001088 AdjustTokenPrivileges
0x100001090 InitiateShutdownW
Library KERNEL32.dll:
0x100001118 DeleteFileW
0x100001120 MoveFileExW
0x100001128 FindResourceW
0x100001130 LoadResource
0x100001138 LockResource
0x100001140 SizeofResource
0x100001148 GlobalAlloc
0x100001150 GlobalLock
0x100001158 GlobalUnlock
0x100001160 GlobalFree
0x100001168 GetSystemInfo
0x100001178 GlobalMemoryStatusEx
0x100001180 GetCurrentProcess
0x100001188 FindFirstFileW
0x100001190 CopyFileW
0x100001198 FreeLibrary
0x1000011a0 FormatMessageW
0x1000011a8 LocalFree
0x1000011b0 HeapSetInformation
0x1000011c0 OpenProcess
0x1000011c8 GetCurrentProcessId
0x1000011d0 GetCurrentThreadId
0x1000011d8 GetCommandLineW
0x1000011e0 CompareStringW
0x1000011e8 SetFileAttributesW
0x1000011f0 CreateDirectoryW
0x1000011f8 CreateSemaphoreW
0x100001200 MultiByteToWideChar
0x100001208 WideCharToMultiByte
0x100001210 lstrcmpiW
0x100001218 lstrlenW
0x100001220 FindClose
0x100001228 RtlCompareMemory
0x100001230 FindNextFileW
0x100001238 GetDateFormatW
0x100001240 QueryDosDeviceW
0x100001248 LocalAlloc
0x100001250 UnhandledExceptionFilter
0x100001258 TerminateProcess
0x100001260 GetSystemTimeAsFileTime
0x100001268 GetTickCount
0x100001270 QueryPerformanceCounter
0x100001280 GetStartupInfoW
0x100001288 Sleep
0x100001298 VirtualAlloc
0x1000012a0 InterlockedPopEntrySList
0x1000012a8 GetProcessHeap
0x1000012b0 VirtualFree
0x1000012b8 HeapFree
0x1000012c0 HeapAlloc
0x1000012c8 GetNativeSystemInfo
0x1000012d0 CloseHandle
0x1000012d8 CreateThread
0x1000012e0 GetModuleHandleW
0x1000012e8 LoadLibraryW
0x1000012f0 GetProcAddress
0x100001300 GetTimeFormatW
0x100001308 GetLastError
0x100001310 FlushInstructionCache
Library GDI32.dll:
0x1000010f8 GetTextMetricsW
0x100001100 SelectObject
0x100001108 GetTextExtentPoint32W
Library USER32.dll:
0x1000018d8 SetCursor
0x1000018e0 LoadCursorW
0x1000018e8 GetFocus
0x1000018f0 ShowWindow
0x1000018f8 MessageBoxW
0x100001900 IsWindowEnabled
0x100001908 GetSystemMetrics
0x100001910 EndDialog
0x100001918 SetFocus
0x100001920 SetWindowTextW
0x100001928 LoadStringW
0x100001930 GetActiveWindow
0x100001938 GetDlgItem
0x100001940 GetDlgItemTextW
0x100001948 GetClientRect
0x100001950 SendMessageW
0x100001958 LoadIconW
0x100001960 CharNextW
0x100001968 FindWindowW
0x100001970 SetForegroundWindow
0x100001978 IsIconic
0x100001980 GetLastActivePopup
0x100001988 IsDlgButtonChecked
0x100001990 CheckDlgButton
0x100001998 SetDlgItemInt
0x1000019a0 SetDlgItemTextW
0x1000019a8 GetWindowTextLengthW
0x1000019b0 GetWindowTextW
0x1000019b8 SetWindowLongPtrW
0x1000019c0 GetDC
0x1000019c8 ReleaseDC
0x1000019d0 GetKeyState
0x1000019d8 CallWindowProcW
0x1000019e0 GetWindowLongPtrW
0x1000019e8 EnableWindow
Library MFC42u.dll:
0x100001320 None
0x100001328 None
0x100001330 None
0x100001338 None
0x100001340 None
0x100001348 None
0x100001350 None
0x100001358 None
0x100001360 None
0x100001368 None
0x100001370 None
0x100001378 None
0x100001380 None
0x100001388 None
0x100001390 None
0x100001398 None
0x1000013a0 None
0x1000013a8 None
0x1000013b0 None
0x1000013b8 None
0x1000013c0 None
0x1000013c8 None
0x1000013d0 None
0x1000013d8 None
0x1000013e0 None
0x1000013e8 None
0x1000013f0 None
0x1000013f8 None
0x100001400 None
0x100001408 None
0x100001410 None
0x100001418 None
0x100001420 None
0x100001428 None
0x100001430 None
0x100001438 None
0x100001440 None
0x100001448 None
0x100001450 None
0x100001458 None
0x100001460 None
0x100001468 None
0x100001470 None
0x100001478 None
0x100001480 None
0x100001488 None
0x100001490 None
0x100001498 None
0x1000014a0 None
0x1000014a8 None
0x1000014b0 None
0x1000014b8 None
0x1000014c0 None
0x1000014c8 None
0x1000014d0 None
0x1000014d8 None
0x1000014e0 None
0x1000014e8 None
0x1000014f0 None
0x1000014f8 None
0x100001500 None
0x100001508 None
0x100001510 None
0x100001518 None
0x100001520 None
0x100001528 None
0x100001530 None
0x100001538 None
0x100001540 None
0x100001548 None
0x100001550 None
0x100001558 None
0x100001560 None
0x100001568 None
0x100001570 None
0x100001578 None
0x100001580 None
0x100001588 None
0x100001590 None
0x100001598 None
0x1000015a0 None
0x1000015a8 None
0x1000015b0 None
0x1000015b8 None
0x1000015c0 None
0x1000015c8 None
0x1000015d0 None
0x1000015d8 None
0x1000015e0 None
0x1000015e8 None
0x1000015f0 None
0x1000015f8 None
0x100001600 None
0x100001608 None
0x100001610 None
0x100001618 None
0x100001620 None
0x100001628 None
0x100001630 None
0x100001638 None
0x100001640 None
0x100001648 None
0x100001650 None
0x100001658 None
0x100001660 None
0x100001668 None
0x100001670 None
0x100001678 None
0x100001680 None
0x100001688 None
0x100001690 None
0x100001698 None
0x1000016a0 None
0x1000016a8 None
0x1000016b0 None
0x1000016b8 None
0x1000016c0 None
0x1000016c8 None
0x1000016d0 None
0x1000016d8 None
0x1000016e0 None
0x1000016e8 None
0x1000016f0 None
0x1000016f8 None
0x100001700 None
0x100001708 None
0x100001710 None
0x100001718 None
0x100001720 None
0x100001728 None
0x100001730 None
0x100001738 None
0x100001740 None
0x100001748 None
0x100001750 None
0x100001758 None
0x100001760 None
0x100001768 None
0x100001770 None
0x100001778 None
0x100001780 None
0x100001788 None
0x100001790 None
0x100001798 None
0x1000017a0 None
0x1000017a8 None
0x1000017b0 None
0x1000017b8 None
0x1000017c0 None
0x1000017c8 None
0x1000017d0 None
0x1000017d8 None
0x1000017e0 None
0x1000017e8 None
0x1000017f0 None
0x1000017f8 None
0x100001800 None
0x100001808 None
0x100001810 None
0x100001818 None
0x100001820 None
0x100001828 None
0x100001830 None
0x100001838 None
0x100001840 None
0x100001848 None
0x100001850 None
0x100001858 None
0x100001860 None
0x100001868 None
0x100001870 None
0x100001878 None
Library msvcrt.dll:
0x100001a18 ??1type_info@@UEAA@XZ
0x100001a20 _unlock
0x100001a28 __dllonexit
0x100001a30 _lock
0x100001a38 _onexit
0x100001a40 _amsg_exit
0x100001a48 _initterm
0x100001a50 _wcmdln
0x100001a58 exit
0x100001a60 _cexit
0x100001a68 _exit
0x100001a70 _XcptFilter
0x100001a78 __C_specific_handler
0x100001a80 __wgetmainargs
0x100001a88 __CxxFrameHandler3
0x100001a90 ?terminate@@YAXXZ
0x100001a98 _CxxThrowException
0x100001aa8 iswdigit
0x100001ab0 wcsrchr
0x100001ab8 _wtoi
0x100001ac0 memmove
0x100001ac8 calloc
0x100001ad0 _vsnwprintf
0x100001ad8 _wtol
0x100001ae0 _itow_s
0x100001ae8 memcpy
0x100001af0 memcmp
0x100001af8 _snwscanf_s
0x100001b00 _wcsupr
0x100001b08 wcsnlen
0x100001b10 strncmp
0x100001b18 wcsncpy_s
0x100001b20 __set_app_type
0x100001b28 _fmode
0x100001b30 _commode
0x100001b38 _callnewh
0x100001b40 memset
0x100001b48 _ultow_s
0x100001b50 wcschr
0x100001b58 _wcsnicmp
0x100001b60 wcstoul
0x100001b68 swprintf_s
0x100001b70 wcscpy_s
0x100001b78 wcscat_s
0x100001b80 _wcsicmp
0x100001b88 ??0exception@@QEAA@XZ
0x100001b90 memmove_s
0x100001ba0 ??1exception@@UEAA@XZ
0x100001bb0 memcpy_s
0x100001bc0 _wcsicoll
0x100001bc8 wcstok
0x100001bd0 wcsstr
0x100001bd8 _wcslwr
0x100001be0 _purecall
0x100001be8 free
0x100001bf0 malloc
0x100001bf8 __setusermatherr
Library ATL.DLL:
0x1000010a0 None
0x1000010a8 None
0x1000010b0 None
0x1000010b8 None
0x1000010c0 None
0x1000010c8 None
0x1000010d0 None
0x1000010d8 None
0x1000010e0 None
0x1000010e8 None
Library SHELL32.dll:
0x1000018b8 ShellExecuteW
0x1000018c8 SHGetSpecialFolderPathW
Library OLEAUT32.dll:
0x100001888 SysAllocString
0x100001890 VariantChangeType
0x100001898 VariantClear
0x1000018a0 SysFreeString
0x1000018a8 VariantInit
Library ole32.dll:
0x100001dc0 CreateStreamOnHGlobal
0x100001dc8 CoInitializeEx
0x100001dd0 CoTaskMemFree
0x100001dd8 CoCreateInstance
0x100001de0 CoUninitialize
0x100001de8 CoInitialize
Library VERSION.dll:
0x1000019f8 VerQueryValueW
0x100001a00 GetFileVersionInfoW
0x100001a08 GetFileVersionInfoSizeW
Library ntdll.dll:
0x100001c08 RtlNtStatusToDosError
0x100001c10 RtlInitUnicodeString
0x100001c18 RtlCaptureContext
0x100001c20 RtlLookupFunctionEntry
0x100001c28 RtlVirtualUnwind
0x100001c30 WinSqmAddToStream
0x100001c38 NtResetEvent
0x100001c40 NtDeleteFile
0x100001c50 LdrGetDllHandle
0x100001c58 NtQueryInformationFile
0x100001c60 RtlStringFromGUID
0x100001c68 NtQuerySystemInformation
0x100001c70 RtlFreeHeap
0x100001c78 RtlFreeUnicodeString
0x100001c80 RtlGUIDFromString
0x100001c88 NtClose
0x100001c90 RtlAllocateHeap
0x100001c98 NtOpenFile
0x100001ca0 NtDeviceIoControlFile
0x100001ca8 NtWaitForSingleObject
0x100001cb0 NtCreateEvent
0x100001cb8 NtQueryKey
0x100001cc0 NtEnumerateKey
0x100001cc8 NtQueryAttributesFile
0x100001cd0 NtOpenKey
0x100001cd8 RtlCreateAcl
0x100001ce0 NtSaveKey
0x100001ce8 NtUnloadKey
0x100001cf0 RtlFreeSid
0x100001d00 NtDeleteValueKey
0x100001d08 NtLoadKey
0x100001d10 NtOpenThreadToken
0x100001d18 NtCreateKey
0x100001d20 NtCreateFile
0x100001d30 RtlAddAccessAllowedAceEx
0x100001d38 NtOpenProcessToken
0x100001d40 NtSetSecurityObject
0x100001d48 NtQueryValueKey
0x100001d50 NtSetValueKey
0x100001d58 NtAdjustPrivilegesToken
0x100001d60 NtDeleteKey
0x100001d70 RtlLengthSid
0x100001d88 NtAllocateUuids
0x100001d90 RtlInitAnsiString
0x100001d98 NtOpenSymbolicLinkObject
0x100001da0 LdrGetProcedureAddress
0x100001db0 WinSqmIncrementDWORD

!This program cannot be run in DOS mode.
`.data
.pdata
@.reloc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
MFC42u.dll
msvcrt.dll
ATL.DLL
SHELL32.dll
OLEAUT32.dll
ole32.dll
VERSION.dll
string too long
invalid string position
Fbad allocation
CPageServices
vector<T> too long
RegDeleteKeyExW
RegDeleteKeyW
CPageStartup
CPageGeneral
CPageTool
CPageBootIni
FveOpenVolumeW
FveGetStatus
FveCloseVolume
CMSConfigSheet
msconfig.pdb
H!\$8H!\$@H!\$H
P(!\$x
@SUVWATH
l$h+l$`A
A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
@SUVWATAUAVAWH
A_A^A]A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
PA_A^A]A\_^]
SVWATAUAVH
A^A]A\_^[
@VWATH
F8H9E8}
9E tCLcG
WATAVH
WATAUH
A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
VWATAUAVH
A^A]A\_^
SVWATH
xA\_^[
SUVWATAUAVAWH
A_A^A]A\_^][
WATAUH
VWATAUAVH
A^A]A\_^
x ATAUAVH
A^A]A\
UVWATAUAVAWH
0A_A^A]A\_^]
SUVWATAUAVAWH
l$X9~XtL
9~Xu:H
xA_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
@VWATH
WATAUH
@A]A\_
@SUVWATAUAVH
A^A]A\_^][
l$X+l$P
x ATAUAVH
A^A]A\
\$(H!\$0H!\$8
\$(H!\$0H!\$8
d$0D+d$(
SUVWATAUAVAWH
usf9;tn
A_A^A]A\_^][
VWATAUAVH
A^A]A\_^
tlH9X@tfH
WATAUAVAWH
fE9<$u
A_A^A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
SUVWATH
F8H9E8}
pA\_^][
UVWATAUH
0A]A\_^]
\$(D+\$ D
SUVWATAUH
A]A\_^][
SUVWATAUAVAWH
8A_A^A]A\_^][
@VWATH
\$ UVWH
x ATAUAVH
A^A]A\
UVWATAUAVAWH
A_A^A]A\_^]
l$ VWATAUAVH
A^A]A\_^
UVWATAUAVAWH
0A_A^A]A\_^]
9\$PrQD
t$ WATAUAVAWH
A_A^A]A\_
t$ WATAVH
|$00u?H
x ATAUAVH
A^A]A\H
L$ SUVWH
x ATAUAVH
A^A]A\
UVWATAUAVAWH
PA_A^A]A\_^]
SUVWATH
pA\_^][
SVWATAUAVAWH
A_A^A]A\_^[
UVWATAUH
A]A\_^]
UVWATAUAVAWH
T$0D9r
A_A^A]A\_^]
ATAUAVH
A^A]A\
|$ ATH
SUVWATH
PA\_^][
H!t$ A
x ATAUAVH
L91u$H
0A^A]A\
T$@@8jZulH
l$Zf9l$H
@SUVWATH
A\_^][
l$ VWATH
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAUAVH
0A^A]A\_^
H9t$8t
H!t$ H
UVWATAUAVAWH
t$H@8l$2t
t$@@8l$0t
t$8@8l$1t
A_A^A]A\_^]
WATAUH
A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
[ UVATH
[ UWATH
UVWATAUH
L9l$0t
PA]A\_^]
WATAUH
9t$pv@H
@A]A\_
k VWATAVAWH
H!|$@E3
H9|$@t
L$0H!|$(H
L$0H!|$(H!|$8H
A_A^A\_^
@SVATAUAVH
0A^A]A\^[
SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAWH
;l$xu/H
0A_A]A\_^][
D$`H9D$x
H!l$8L
!l$4E3
\$p;D$H
9|$4voH
ATAUAVH
A^A]A\
SUVWATH
D$8H9D$H
D$09D$@
A\_^][
UWATAUAVH
A^A]A\_]
@SUVWATH
A\_^][
H9l$ t
WATAUAVAWH
f9:tcD;
A;,$w*H
A_A^A]A\_
WATAUAVAWH
L9|$ t
A_A^A]A\_
WATAUH
A]A\_
H UVWH
VWATAUAVH
AVAUWVSH
[^_A]A^
L!l$XL!l$hL
A_A^A]A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
VWATAUAVH
@A^A]A\_^
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
D$8D9 u
L9d$Ht
L9d$@t
L9d$Pt
L9d$8t
A_A^A]A\_^]
p WATAUH
!8I!8A!9I
0A]A\_
UVWATAUAVAWH
D$0H!l$(H!l$PH!l$0H
D$puTI
A_A^A]A\_^]
UVWATAUAVAWH
D$((Y-
MD$h=#
A_A^A]A\_^]
UVWATAUAVAWH
PA_A^A]A\_^]
SVATAUAVAWH
A_A^A]A\^[
SVWATAUAVAWH
A_A^A]A\_^[
SVWATAUAVAWH
D$PL!l$`L!l$hL
pA_A^A]A\_^[
SVWATAUAVH
xA^A]A\_^[
@SVWATAUAVAWH
A_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
H9t$Pt
SVWATAUAVAWH
H!|$@H
D$(!|$ E3
`A_A^A]A\_^[
SVWATAUAVAWH
PA_A^A]A\_^[
l$8!D$<H
s WATAUH
WATAUH
@SUVWH
WATAUAVAWH
A_A^A]A\_
L$ SUVWH
D$P!D$(H
D$@!|$8H
D$P!D$(H
p WATAUH
p WATAUH
|$@!t$8H!t$0H
D$p!D$(H
!D$HH!D$@!D$8H!D$0H
WATAUH
0A]A\_
UVWATAUAVAWH
H+D$XI;
A_A^A]A\_^]
UVWATAUH
|$`D8l$1t
|$PD8l$0t
L9l$Ht
L9l$Xt
A]A\_^]
t$ WATAUH
SUVWATH
H9|$0t&eH
@A\_^][
l$ VWATH
l$ VWATH
UVWATAUAVAWH
L!d$`L!d$XH!|$8H!|$HH!|$@H!|$PL
A_A^A]A\_^]
l$ VWATH
WATAUH
0A]A\_
p WATAUAVAWH
A_A^A]A\_
x ATAUAVH
A^A]A\
{ ATAUAVH
H+D$0H;
A^A]A\
UVWATAUAVAWH
L9|$Xt
L9|$8t
L9|$@t
L9|$Ht
L9|$Pt
`A_A^A]A\_^]
WINDOWS
p WATAUAVAWH
A_A^A]A\_
xd!|$`H
\$ UVWH
h VWATH
h VWATH
L9d$Xt
WATAUH
H!|$pH
D$(!|$ E
^H9l$(t
D$@D!\$8L!\$0H
UVWATAUH
D9/vID
A]A\_^]
9 wsf9
LcA<E3
u*9Q<|%
AVAUWVSH
[^_A]A^
NtUnloadKey2
NtLoadKey2
WINDOWS
NtAddBootEntry
NtEnumerateBootEntries
NtDeleteBootEntry
NtQuerySystemEnvironmentValueEx
NtSetSystemEnvironmentValueEx
NtModifyBootEntry
NtSetBootEntryOrder
NtSetBootOptions
NtTranslateFilePath
NtQueryBootEntryOrder
NtQueryBootOptions
RegCloseKey
RegQueryValueExW
RegSetValueExW
OpenSCManagerW
EnumServicesStatusW
OpenServiceW
CloseServiceHandle
ChangeServiceConfigW
QueryServiceConfigW
RegEnumKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumValueW
RegDeleteValueW
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
InitiateShutdownW
ADVAPI32.dll
GetDateFormatW
GetLastError
GetTimeFormatW
ExpandEnvironmentStringsW
GetProcAddress
LoadLibraryW
GetModuleHandleW
CreateThread
CloseHandle
GetNativeSystemInfo
FindFirstFileW
FindNextFileW
FindClose
lstrlenW
CopyFileW
DeleteFileW
MoveFileExW
FindResourceW
LoadResource
LockResource
SizeofResource
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalFree
GetSystemInfo
GetPhysicallyInstalledSystemMemory
GlobalMemoryStatusEx
GetCurrentProcess
FlushInstructionCache
RtlCompareMemory
FreeLibrary
FormatMessageW
LocalFree
HeapSetInformation
RegisterApplicationRestart
OpenProcess
GetCurrentProcessId
GetCurrentThreadId
GetCommandLineW
CompareStringW
SetFileAttributesW
CreateDirectoryW
CreateSemaphoreW
MultiByteToWideChar
WideCharToMultiByte
lstrcmpiW
KERNEL32.dll
SelectObject
GetTextMetricsW
GetTextExtentPoint32W
GDI32.dll
EnableWindow
SendMessageW
GetClientRect
GetSystemMetrics
SetCursor
LoadCursorW
GetFocus
ShowWindow
MessageBoxW
IsWindowEnabled
IsDlgButtonChecked
EndDialog
SetFocus
SetWindowTextW
LoadStringW
GetActiveWindow
GetDlgItem
GetDlgItemTextW
CheckDlgButton
SetDlgItemInt
SetDlgItemTextW
GetWindowTextLengthW
GetWindowTextW
SetWindowLongPtrW
ReleaseDC
GetKeyState
CallWindowProcW
GetWindowLongPtrW
LoadIconW
CharNextW
FindWindowW
SetForegroundWindow
IsIconic
GetLastActivePopup
USER32.dll
MFC42u.dll
malloc
_purecall
_wcslwr
wcsstr
wcstok
_wcsicoll
??0exception@@QEAA@AEBV0@@Z
memcpy_s
?what@exception@@UEBAPEBDXZ
??1exception@@UEAA@XZ
??0exception@@QEAA@AEBQEBD@Z
memmove_s
??0exception@@QEAA@XZ
_wcsicmp
_itow_s
_vsnwprintf
calloc
memmove
wcsrchr
iswdigit
??0exception@@QEAA@AEBQEBDH@Z
_CxxThrowException
_callnewh
__CxxFrameHandler3
__wgetmainargs
__C_specific_handler
_XcptFilter
_cexit
_wcmdln
_initterm
_amsg_exit
__setusermatherr
_commode
_fmode
__set_app_type
?terminate@@YAXXZ
??1type_info@@UEAA@XZ
msvcrt.dll
_unlock
__dllonexit
_onexit
ATL.DLL
SHEvaluateSystemCommandTemplate
SHGetSpecialFolderPathW
ShellExecuteW
SHELL32.dll
OLEAUT32.dll
CoCreateInstance
CoTaskMemFree
CoInitialize
CoUninitialize
CreateStreamOnHGlobal
CoInitializeEx
ole32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
WinSqmIncrementDWORD
WinSqmAddToStream
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
RtlInitUnicodeString
RtlNtStatusToDosError
ntdll.dll
HeapAlloc
HeapFree
VirtualFree
GetProcessHeap
InterlockedPopEntrySList
VirtualAlloc
InterlockedPushEntrySList
GetStartupInfoW
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
LocalAlloc
QueryDosDeviceW
wcscat_s
wcscpy_s
swprintf_s
wcstoul
_wcsnicmp
wcschr
_ultow_s
wcsncpy_s
strncmp
wcsnlen
_wcsupr
_snwscanf_s
RtlStringFromGUID
NtQuerySystemInformation
RtlFreeHeap
RtlFreeUnicodeString
RtlGUIDFromString
NtClose
RtlAllocateHeap
NtOpenFile
NtDeviceIoControlFile
NtWaitForSingleObject
NtCreateEvent
NtQueryKey
NtEnumerateKey
NtQueryAttributesFile
NtOpenKey
RtlCreateAcl
NtSaveKey
NtUnloadKey
RtlFreeSid
RtlSetDaclSecurityDescriptor
NtDeleteValueKey
NtLoadKey
NtOpenThreadToken
NtCreateKey
NtCreateFile
RtlLengthSecurityDescriptor
RtlAddAccessAllowedAceEx
NtOpenProcessToken
NtSetSecurityObject
NtQueryValueKey
NtSetValueKey
NtAdjustPrivilegesToken
NtDeleteKey
RtlAllocateAndInitializeSid
RtlLengthSid
RtlCreateSecurityDescriptor
RtlSetOwnerSecurityDescriptor
NtAllocateUuids
RtlInitAnsiString
NtOpenSymbolicLinkObject
LdrGetProcedureAddress
NtQuerySymbolicLinkObject
NtQueryInformationFile
LdrGetDllHandle
NtQueryVolumeInformationFile
NtDeleteFile
NtResetEvent
memcmp
memcpy
memset
.?AVout_of_range@std@@
.?AVCObject@@
.?AVCCmdTarget@@
.?AVCWnd@@
.?AVCDialog@@
.?AVCAutoStartDlg@@
.?AVCPageBase@@
.?AVCPropertyPage@@
.?AVCPageServices@@
.PEAVCMemoryException@@
.?AVexception@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVCStartupDisabledStartup@CRestoreStartup@@
.?AVCStartupDisabledRegistry@CRestoreStartup@@
.?AVCStartupDisabled@CRestoreStartup@@
.?AVCRestoreStartup@@
.?AVCPageStartup@@
.?AVCStartupItemFolder@@
.?AVCStartupItem@@
.?AVCStartupItemRegistry@@
.?AVCPageGeneral@@
.?AVCToolItem@@
.?AVCPageTool@@
.?AVCMessageMap@ATL@@
.?AVCWindow@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AV?$CDialogImplBaseT@VCWindow@ATL@@@ATL@@
.?AV?$CAxDialogImpl@VCBootIniAdvancedDlg@@VCWindow@ATL@@@ATL@@
.?AVCBootIniAdvancedDlg@@
.?AVCPageBootIni@@
.?AVCPropertySheet@@
.?AVCMSConfigSheet@@
.?AV?$CAxDialogImpl@VCRebootDlg@@VCWindow@ATL@@@ATL@@
.?AVCRebootDlg@@
.?AVCWinThread@@
.?AVCWinApp@@
.?AVCMSConfigApp@@
`llh2''mk&ae_b]ga_YY&[ge'klk'aeY_[&bh_
NajlmYd9ddg[
DgY\DaZjYjq9
e]e[hq
Afl]jf]lGh]f9
@LLHJ=9<
Afl]jf]lGh]fMjd9
Afl]jf]lJ]Y\>ad]
Afl]jf]l;dgk]@Yf\d]
oafaf]l&\dd
ekn[jl&\dd
NoRemove AppID
{5EFA96D6-E7B1-48C9-940B-2FE1F09EAB16} = s 'MSConfig'
'MSConfig.EXE'
val AppID = s {5EFA96D6-E7B1-48C9-940B-2FE1F09EAB16}
wwwwxx
wwwwww
tDDDDDDDFGx
tDDDDDdwx
wwwwwp
wDDGww
!!! !" H
!!!"!!""##";
***%$*,,6666
(<<<==<
>@@@@=
NXYYYY?
nH[[[[Zw
G]]]a\w
Eaaax]u
Pyuyzxa
BGSS:P
CFUS*D
HM;<2345{
..1//0004\
,;M^v
-;NQ,
rY\a`_Cxxg
+O><415eFddGfzzyy
.//1Biw
nUNMRz
\\XYB8
(A11Cex
)22-/-.).)),((((
2222222222-2.-3
r)D~px8PZ#
'A(@03
eIQtc(Q6
#[sw2CN&
,PJ7NK
1[X+AY
)9?3[H
clNeza
'Rb+Z
a$rHfIcb
~7Vt2;
/87SLL2QR
C[kh>Z
!3RIE^
!Is*x/qH
")TUM]
IjEG+:
-#Ej|]#p
2eU#MM
Dc~8Z2
%!cM:h<]
w/P*|/
9UU7*|
i(>:]0
?i NK`
1lz}/B
qNrt-'
b1_r~o
%K+(ME^
Y(B:[pvr
^~W2P(K
YT}cj
<+K. oJ
(Sq'K)
66:lmu
m3'b4q
i$1qlCv
DYFDZ X
&Mcfs[
v.\3ISJ
B["ma
p`_lEk
gD&Ed1
,pFJyJJ
)OJ){B
??O$'Lg
lnv1Fr
dZ<JVM
<co/c>
szzzzv
&'&&n}
)B/^3*4MK
k>45M+
$d$$t~
<dWCW3
s|_&d2
)mzzZ\82
4MLLL@
{|1U8/
9PF N$!
,VVV`Y
t:XYYA
;wbzz:
]IDATe
VLMMarr
u][]]
uwwwXttt*ttt
E899a99:ZnnnZ
#FFFtyyy
@@B0ooq
JJL5jjlf
??A0[[^L}}
pps7tuxf
M++,K0001
222-[[Z
JJLP||
?>@8__ajxy|
322/ihi
##$#XX[Iy}
mshelp://windows/?id=bd9e1cb6-a66a-47a8-a4b6-ef7ea672ae4b
plugplay
sppsvc
profsvc
appinfo
dcomlaunch
HideEssentialServiceWarning
microsoft
MINUTE
SECOND
rundll32
SOFTWARE\Microsoft\Shared Tools\MSConfig
SOFTWARE\Microsoft\Shared Tools
MSConfig
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
Wadvapi32.dll
services
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
msconfig.exe
desktop.ini
startupreg
startupfolder
command
inimapping
backup
location
backupExtension
.Startup
.CommonStartup
Software\Microsoft\Windows\CurrentVersion\Run
\Disabled Startup
startup
Software\Microsoft\Windows\CurrentVersion\Setup\DisabledRunKeys
SOFTWARE\Microsoft\Shared Tools\MsConfig
NoRebootUI
general
%windir%\system32\MSCFGTLC.XML
//MSCONFIGTOOLS
DEFAULT_OPT
ADV_OPT
MSCFGTL.XML
%windir%\SYSTEM32
%ProgramFiles%
115200
COM%d:
fveapi.dll
.backup
bootini
commit
0123456789
%windir%\system32\msconfig
SeShutdownPrivilege
UnregServer
RegServer
%systemroot%\pss
MSConfigRunning
VarFileInfo\Translation
%04x%04x
040904B0
FileVersion
040904E4
04090000
FileDescription
CompanyName
ProductName
\%s\%s\%s
\??\%s
Objects
Description
Elements
\Registry\Machine\System\CurrentControlSet\BootConfigurationData
NewStoreRoot
System
KeyName
TreatAsSystem
BCD%08d
\Registry\Machine
Element
\Device\HarddiskVolume
\Device\Harddisk%lu\Partition%lu
GuidCache
FirmwareVariable
ntdll.dll
\??\PhysicalDrive%lu
\Registry\Machine\SYSTEM\CurrentControlSet\Control
SystemStartOptions
MININT
\Boot\BCD
\EFI\Microsoft\Boot\BCD
Timeout
BootNext
BCDOBJECT=
\ArcName\multi(0)disk(0)rdisk(0)
\Partition0
%s\Partition%lu
FirmwareBootDevice
multi(%d)disk(%d)rdisk(%d)
\ArcName\multi(0)disk(0)rdisk(1)
\Registry\Machine\SYSTEM\CurrentControlSet\Control\Syspart
SystemPartition
multi(%d)disk(%d)rdisk(%d)partition(%d)
\ArcName\
StringFileInfo
REGISTRY
REGISTRY
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
System Configuration Utility
FileVersion
6.1.7600.16385 (win7_rtm.090713-1255)
InternalName
msconfig.EXE
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
msconfig.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7600.16385
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.aec63ca0e90ee3b2
CAT-QuickHeal Clean
McAfee Artemis!AEC63CA0E90E
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W64/Agent.GEE.gen!Eldorado
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Fabookie!8.11C3D (CLOUD)
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Dropper.dh
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.67096588 (B)
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W64/Agent.ZX!tr
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
CrowdStrike Clean
No IRMA results available.