Static | ZeroBOX

PE Compile Time

2024-09-08 01:13:56

PDB Path

PrintUI.pdb

PE Imphash

de8c59512ca98fb3e224769147985370

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000e10 0x00001000 5.47597639167
.rdata 0x00002000 0x00000ed6 0x00001000 4.02044429866
.data 0x00003000 0x00000680 0x00001000 0.0487306524296
.pdata 0x00004000 0x000000e4 0x00001000 0.31629775775
.rsrc 0x00005000 0x0000d2e8 0x0000e000 6.27679348459
.reloc 0x00013000 0x00000030 0x00001000 0.117880236865

Resources

Name Offset Size Language Sub-language File type
MUI 0x00012218 0x000000d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00011980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00011de8 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00011e80 0x00000398 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00005330 0x000005a8 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x140002150 RegQueryValueExW
0x140002158 RegDeleteValueW
0x140002160 RegOpenKeyExW
0x140002168 RegSetValueExW
0x140002170 RegCreateKeyExW
0x140002178 RegDeleteKeyExW
0x140002180 RegCloseKey
Library KERNEL32.dll:
0x1400021a0 HeapSetInformation
0x1400021a8 GetProcAddress
0x1400021b0 FreeLibrary
0x1400021b8 GetCurrentProcessId
0x1400021c0 GetLastError
0x1400021c8 GetCommandLineW
0x1400021d0 LoadLibraryW
0x1400021d8 QueryPerformanceCounter
0x1400021e0 GetModuleHandleW
0x1400021f0 GetStartupInfoW
0x1400021f8 Sleep
0x140002200 GetSystemTimeAsFileTime
0x140002208 GetTickCount
0x140002210 UnhandledExceptionFilter
0x140002218 GetCurrentProcess
0x140002220 TerminateProcess
0x140002228 GetCurrentThreadId
Library GDI32.dll:
0x140002190 GetStockObject
Library USER32.dll:
0x140002238 RegisterClassW
0x140002240 CreateWindowExW
0x140002248 DestroyWindow
0x140002250 DefWindowProcW
0x140002258 LoadCursorW
Library msvcrt.dll:
0x140002268 _fmode
0x140002270 _commode
0x140002278 ?terminate@@YAXXZ
0x140002280 __C_specific_handler
0x140002288 __wgetmainargs
0x140002290 _amsg_exit
0x140002298 _XcptFilter
0x1400022a0 iswspace
0x1400022a8 _wcmdln
0x1400022b0 _initterm
0x1400022b8 __setusermatherr
0x1400022c0 _cexit
0x1400022c8 _exit
0x1400022d0 exit
0x1400022d8 __set_app_type
0x1400022e0 memset
Library ntdll.dll:
0x1400022f0 RtlCaptureContext
0x1400022f8 RtlLookupFunctionEntry
0x140002300 RtlVirtualUnwind

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
q0R^G'
u.L93t
p0R^G'
q0R^G'
u*9Q<|%
LcA<E3
H3E H3E
UAVAWH
PrintUIEntryW
PrintUI.pdb
.text$mn
.text$mn$00
.text$x
.rdata$brc
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIY
.CRT$XIZ
.gehcont
.gfids
.giats
.rdata
.rdata$voltmd
.rdata$zzzdbg
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.rsrc$01
.rsrc$02
RegQueryValueExW
RegDeleteValueW
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
RegDeleteKeyExW
RegCloseKey
ADVAPI32.dll
GetCommandLineW
GetLastError
LoadLibraryW
HeapSetInformation
GetProcAddress
FreeLibrary
KERNEL32.dll
GetStockObject
GDI32.dll
LoadCursorW
RegisterClassW
CreateWindowExW
DestroyWindow
DefWindowProcW
USER32.dll
iswspace
_XcptFilter
_amsg_exit
__wgetmainargs
__set_app_type
_cexit
__setusermatherr
_initterm
__C_specific_handler
_wcmdln
_fmode
_commode
msvcrt.dll
?terminate@@YAXXZ
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
GetTickCount
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
memset
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
processorArchitecture="amd64"
version="5.1.0.0"
name="Microsoft.Windows.PrintScan.PrintUIExe" type="win32" />
<description>Change Printing Settings</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
processorArchitecture="amd64"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<autoElevate xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</autoElevate>
</windowsSettings>
</application>
</assembly>
ppSe6SepprRW
wrVw'Ww%rww
sVWruwwSewuww
wwwwwwwwwwwww
wwwwwwwwwwwwx
wwwwwwww
wt5gqecrt7
w5wwwWwvx
wwwwwwwwx
xwwwwww
wwwwxw
wwwwwwp
v<A<<i
v<<<6<v
<<<<;h
#$$$$$"""
h6<;6h|
#%%%+%-+--%-%++%%$%--$$x
h;6<<<
A-+-1111115115111-.2212--A
A66;<<<<A<A<<;666<A<<<919
cihmoooooockhAkokhkhhh<9x
vvwy||
vvvvvxxoris
y}}w{v
bA:9=F
D@;<>`
-g_uS~
k8Kgu,
g82S~S2
g523am%
p522Om
!!!!
W,(*.2222.,,(..,!3y
\KKKQQQNK8KQK8822a
g___f_\Wg_WWWSSKW
uuutmmmgggggm~

!""""!
""""""
>DFTdVdfdVVu
Caiii
J166F&
N311A.
X=X*,[
Ow[:6J*?
(4ec[&
S/Dm7jw
>}:R`o
FEBH4$
<B_t}cO
cccLLL0>>
BM~!@)
"KKK,//
u+cccd2
nA/?Vi
V*Tk5&&&
^kb[&V
%Ccs^c
KKKms2xc/
7QBbYM
OAU4dMFRd\
"k\`:{
e!Ia\m
q.NNaZUdM'
|)hVaV)
%TMFWe
[>_$_(
FFFV-5\
,ILOO6
F+nUU)
keYIGw[
*PU4UC
updddM8P
{}||<O0
<CAhWc
n)wkYv4
%&(#EJN
NNNZ+++
:zzz+|||
:::#777jRRR
Software\Microsoft\Windows\CurrentVersion\PrinterInstallation
UIEntry
StubPrintWindow
printui.dll
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Change Printing Settings
FileVersion
10.0.22621.608 (WinBuild.160101.0800)
InternalName
printui
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
printui.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.22621.608
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Cybereason Clean
Avast Clean
No IRMA results available.