Static | ZeroBOX

PE Compile Time

2066-04-07 04:58:09

PDB Path

shrpubw.pdb

PE Imphash

521c24cdd31ac7eeae6ae8e5130a93f2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007a5c 0x00007c00 5.63266529445
.rdata 0x00009000 0x00005222 0x00005400 3.93720305754
.data 0x0000f000 0x00000c30 0x00000400 3.33036900467
.pdata 0x00010000 0x000005f4 0x00000600 4.38824158612
.rsrc 0x00011000 0x00000a70 0x00000c00 4.27359910311
.reloc 0x00012000 0x000003b4 0x00000400 5.27271209285

Resources

Name Offset Size Language Sub-language File type
MUI 0x00011988 0x000000e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000115f8 0x00000390 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000110f0 0x00000504 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x14000a0b8 RegQueryValueExW
0x14000a0c0 RegCloseKey
0x14000a0c8 FreeSid
0x14000a0d0 GetLengthSid
0x14000a0d8 AddAccessAllowedAce
0x14000a0e0 InitializeAcl
0x14000a0f0 RegOpenKeyExW
0x14000a0f8 MakeSelfRelativeSD
0x14000a100 AllocateAndInitializeSid
0x14000a108 LookupAccountNameW
0x14000a110 MapGenericMask
0x14000a128 RegOpenKeyExA
0x14000a138 RegConnectRegistryW
0x14000a140 RegQueryValueExA
Library KERNEL32.dll:
0x14000a190 LocalAlloc
0x14000a198 GlobalAlloc
0x14000a1a0 CreateDirectoryW
0x14000a1a8 GetComputerNameExW
0x14000a1b0 lstrcmpiW
0x14000a1b8 LocalFree
0x14000a1c0 GetFileAttributesW
0x14000a1c8 GetDriveTypeW
0x14000a1d0 GetLogicalDriveStringsW
0x14000a1d8 FormatMessageW
0x14000a1e0 GetProcAddress
0x14000a1f0 LoadLibraryExA
0x14000a1f8 TerminateProcess
0x14000a200 GetCurrentProcess
0x14000a208 UnhandledExceptionFilter
0x14000a210 RtlVirtualUnwind
0x14000a218 RtlLookupFunctionEntry
0x14000a220 RtlCaptureContext
0x14000a228 GetTickCount
0x14000a230 GetSystemTimeAsFileTime
0x14000a238 GetCurrentThreadId
0x14000a240 HeapSetInformation
0x14000a250 GetComputerNameW
0x14000a258 GetLastError
0x14000a260 Sleep
0x14000a268 GetStartupInfoW
0x14000a278 GetModuleHandleW
0x14000a280 QueryPerformanceCounter
0x14000a288 GetCurrentProcessId
0x14000a290 FreeLibrary
0x14000a298 LoadLibraryW
Library GDI32.dll:
0x14000a170 CreateFontIndirectW
0x14000a178 GetDeviceCaps
0x14000a180 DeleteObject
Library USER32.dll:
0x14000a708 SystemParametersInfoW
0x14000a710 MessageBoxW
0x14000a718 RegisterClipboardFormatW
0x14000a720 EnableWindow
0x14000a728 SendMessageW
0x14000a730 GetParent
0x14000a738 GetActiveWindow
0x14000a740 ReleaseDC
0x14000a748 PostMessageW
0x14000a750 LoadImageW
0x14000a758 GetDC
Library MFC42u.dll:
0x14000a2a8 None
0x14000a2b0 None
0x14000a2b8 None
0x14000a2c0 None
0x14000a2c8 None
0x14000a2d0 None
0x14000a2d8 None
0x14000a2e0 None
0x14000a2e8 None
0x14000a2f0 None
0x14000a2f8 None
0x14000a300 None
0x14000a308 None
0x14000a310 None
0x14000a318 None
0x14000a320 None
0x14000a328 None
0x14000a330 None
0x14000a338 None
0x14000a340 None
0x14000a348 None
0x14000a350 None
0x14000a358 None
0x14000a360 None
0x14000a368 None
0x14000a370 None
0x14000a378 None
0x14000a380 None
0x14000a388 None
0x14000a390 None
0x14000a398 None
0x14000a3a0 None
0x14000a3a8 None
0x14000a3b0 None
0x14000a3b8 None
0x14000a3c0 None
0x14000a3c8 None
0x14000a3d0 None
0x14000a3d8 None
0x14000a3e0 None
0x14000a3e8 None
0x14000a3f0 None
0x14000a3f8 None
0x14000a400 None
0x14000a408 None
0x14000a410 None
0x14000a418 None
0x14000a420 None
0x14000a428 None
0x14000a430 None
0x14000a438 None
0x14000a440 None
0x14000a448 None
0x14000a450 None
0x14000a458 None
0x14000a460 None
0x14000a468 None
0x14000a470 None
0x14000a478 None
0x14000a480 None
0x14000a488 None
0x14000a490 None
0x14000a498 None
0x14000a4a0 None
0x14000a4a8 None
0x14000a4b0 None
0x14000a4b8 None
0x14000a4c0 None
0x14000a4c8 None
0x14000a4d0 None
0x14000a4d8 None
0x14000a4e0 None
0x14000a4e8 None
0x14000a4f0 None
0x14000a4f8 None
0x14000a500 None
0x14000a508 None
0x14000a510 None
0x14000a518 None
0x14000a520 None
0x14000a528 None
0x14000a530 None
0x14000a538 None
0x14000a540 None
0x14000a548 None
0x14000a550 None
0x14000a558 None
0x14000a560 None
0x14000a568 None
0x14000a570 None
0x14000a578 None
0x14000a580 None
0x14000a588 None
0x14000a590 None
0x14000a598 None
0x14000a5a0 None
0x14000a5a8 None
0x14000a5b0 None
0x14000a5b8 None
0x14000a5c0 None
0x14000a5c8 None
0x14000a5d0 None
0x14000a5d8 None
0x14000a5e0 None
0x14000a5e8 None
0x14000a5f0 None
0x14000a5f8 None
0x14000a600 None
0x14000a608 None
0x14000a610 None
0x14000a618 None
0x14000a620 None
0x14000a628 None
0x14000a630 None
0x14000a638 None
0x14000a640 None
0x14000a648 None
0x14000a650 None
0x14000a658 None
0x14000a660 None
0x14000a668 None
0x14000a670 None
0x14000a678 None
0x14000a680 None
0x14000a688 None
0x14000a690 None
Library msvcrt.dll:
0x14000a7a8 _wcsnicmp
0x14000a7b0 ??1type_info@@UEAA@XZ
0x14000a7b8 memset
0x14000a7c0 __set_app_type
0x14000a7c8 __wgetmainargs
0x14000a7d0 exit
0x14000a7d8 _amsg_exit
0x14000a7e0 __dllonexit
0x14000a7e8 _unlock
0x14000a7f0 _lock
0x14000a7f8 ?terminate@@YAXXZ
0x14000a800 _commode
0x14000a808 _fmode
0x14000a810 _wcmdln
0x14000a818 __C_specific_handler
0x14000a820 _initterm
0x14000a828 __setusermatherr
0x14000a830 _cexit
0x14000a838 _XcptFilter
0x14000a840 memmove
0x14000a848 _onexit
0x14000a850 memcpy
0x14000a858 wcschr
0x14000a860 wcsrchr
0x14000a868 iswspace
0x14000a870 free
0x14000a878 wcsncmp
0x14000a880 calloc
0x14000a888 __CxxFrameHandler3
0x14000a890 _exit
0x14000a898 towupper
0x14000a8a0 wcscmp
Library COMCTL32.dll:
0x14000a150 DestroyPropertySheetPage
0x14000a158 PropertySheetW
0x14000a160 None
Library netutils.dll:
0x14000a8b0 NetpwPathType
0x14000a8b8 NetpIsRemote
0x14000a8c0 NetpwNameValidate
0x14000a8c8 NetApiBufferFree
Library srvcli.dll:
0x14000a8d8 NetServerDiskEnum
0x14000a8e0 NetpsNameValidate
0x14000a8e8 NetShareAdd
0x14000a8f0 NetShareSetInfo
0x14000a8f8 NetShareEnum
0x14000a900 NetShareGetInfo
0x14000a908 NetServerGetInfo
Library ACLUI.dll:
0x14000a0a8 None
Library WS2_32.dll:
0x14000a768 WSAStringToAddressW
0x14000a770 WSACleanup
0x14000a778 WSAStartup
Library SHELL32.dll:
0x14000a6a0 SHGetPathFromIDListW
0x14000a6a8 SHGetMalloc
0x14000a6b0 None
0x14000a6b8 None
0x14000a6c0 None
0x14000a6c8 None
0x14000a6d0 None
0x14000a6d8 None
0x14000a6e0 SHChangeNotify
0x14000a6e8 SHBrowseForFolderW
0x14000a6f8 SHGetDesktopFolder
Library api-ms-win-core-com-l1-1-0.dll:
0x14000a788 CoInitializeEx
0x14000a790 CoUninitialize
0x14000a798 CoCreateInstance

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
UAVAWH
@USVWAVAWH
t+fD9;t%H
fD9>tDA
fD9<Gu
8A_A^_^[]
UATAVH
UVWATAUAVAWH
}PfD9o
@A_A^A]A\_^]
UAVAWH
fD9|$P
D$ E9x
t0f9\$ t.f9t)A
|$ f9\$ t]H
UVWAVAWH
A_A^_^]
fD94Gu
UVWATAUAVAWH
t^f9tYfD
@A_A^A]A\_^]
UVWATAUAVAWH
9}Pv=A
pA_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UWAUAVAWH
H9uDH
A_A^A]_]
USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
SUVWAVH
A^_^][
x ATAVAWH
A_A^A\
UAVAWH
L$ USVWH
UVWAVAWH
fD9<Ju
PA_A^_^]
u$L97t
WAVAWH
0A_A^_
SVWAVH
8A^_^[
u*9Q<|%
LcA<E3
u HcA<H
H3E H3E
RtlIsDosDeviceName_U
CWizWelcome
CWizFolder
CWizClient0
CacheSettingsDlg2
CWizPerm
#CWizFinish
CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32
hhctrl.ocx
shrpubw.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.rdata$brc
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIY
.CRT$XIZ
.gfids
.giats
.rdata
.rdata$r
.rdata$zzzdbg
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.data$brc
.data$r$brc
.pdata
.rsrc$01
.rsrc$02
RegConnectRegistryW
RegOpenKeyExW
RegQueryValueExW
RegCloseKey
FreeSid
GetLengthSid
AddAccessAllowedAce
InitializeAcl
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
MakeSelfRelativeSD
AllocateAndInitializeSid
LookupAccountNameW
MapGenericMask
GetSecurityDescriptorLength
GetSecurityDescriptorControl
ADVAPI32.dll
FreeLibrary
LocalFree
HeapSetInformation
RegisterApplicationRestart
GetComputerNameW
GetLastError
LoadLibraryW
GetProcAddress
GetLogicalDriveStringsW
GetDriveTypeW
GetFileAttributesW
CreateDirectoryW
LocalAlloc
GlobalAlloc
FormatMessageW
GetComputerNameExW
lstrcmpiW
KERNEL32.dll
GetDeviceCaps
CreateFontIndirectW
DeleteObject
GDI32.dll
PostMessageW
LoadImageW
SystemParametersInfoW
ReleaseDC
GetActiveWindow
GetParent
SendMessageW
EnableWindow
RegisterClipboardFormatW
MessageBoxW
USER32.dll
MFC42u.dll
__CxxFrameHandler3
calloc
wcsncmp
iswspace
wcsrchr
wcschr
_wcsnicmp
towupper
_XcptFilter
_amsg_exit
__wgetmainargs
__set_app_type
_cexit
__setusermatherr
_initterm
__C_specific_handler
_wcmdln
_fmode
_commode
msvcrt.dll
?terminate@@YAXXZ
_unlock
__dllonexit
_onexit
??1type_info@@UEAA@XZ
DestroyPropertySheetPage
PropertySheetW
COMCTL32.dll
NetApiBufferFree
NetpwPathType
NetpIsRemote
NetpwNameValidate
netutils.dll
NetServerGetInfo
NetShareGetInfo
NetpsNameValidate
NetShareAdd
NetShareSetInfo
NetServerDiskEnum
NetShareEnum
srvcli.dll
ACLUI.dll
WSAStringToAddressW
WS2_32.dll
SHGetPathFromIDListW
SHGetMalloc
SHGetDesktopFolder
SHGetSpecialFolderLocation
SHBrowseForFolderW
SHChangeNotify
SHELL32.dll
CoInitializeEx
CoUninitialize
CoCreateInstance
api-ms-win-core-com-l1-1-0.dll
RegOpenKeyExA
RegQueryValueExA
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
GetTickCount
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
LoadLibraryExA
ExpandEnvironmentStringsA
memcpy
memmove
memset
wcscmp
.?AVCCmdTarget@@
.?AVCObject@@
.?AVCWinApp@@
.?AVCWinThread@@
.?AVCShrwizApp@@
.?AVCDialog@@
.?AVCWnd@@
.?AVCPropertyPageEx@@
.?AVCPropertyPage@@
.?AVCWizWelcome@@
.PEAVCException@@
.?AVCWizFolder@@
.?AVCWizClient0@@
.?AVCWizPerm@@
.?AVCWizFinish@@
.?AVCFileSecurityDataObject@@
.?AVCShareSecurityInformation@@
.?AUISecurityInformation@@
.?AUIDataObject@@
.?AUIUnknown@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="amd64"
name="Microsoft.Windows.storage.shrpubw"
type="win32"
<description>shrpubw</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="amd64"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
<autoElevate>true</autoElevate>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
SYSTEM\CurrentControlSet\Control\ProductOptions
ProductSuite
Small Business
ntdll.dll
/html/a42d60db-0585-4eac-88d0-b7d61991948f.htm
file_srv.chm
\\?\UNC
FileMgmt.dll
everyone
administrators
SBS Folder Operators
system
interactive
Shell IDList Array
netmsg.dll
.ipv6-literal.net
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Share Creation Wizard
FileVersion
10.0.19041.1 (WinBuild.160101.0800)
InternalName
SHRWIZ
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
shrpubw.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
DeepInstinct Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.