Static | ZeroBOX

PE Compile Time

1992-05-06 22:57:58

PDB Path

WdBoot.pdb

PE Imphash

5fee9881decbcd99afe063c90fd54a26

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00002017 0x00002400 6.00638062161
fothk 0x00004000 0x00001000 0x00001000 0.0159201832656
.rdata 0x00005000 0x000010fc 0x00001400 4.26296092983
.data 0x00007000 0x00000200 0x00000400 0.257627446997
.pdata 0x00008000 0x00000420 0x00000800 2.51393964384
.idata 0x00009000 0x000006cc 0x00000800 3.98618493063
PAGE 0x0000a000 0x00002f98 0x00003000 6.30120946223
INIT 0x0000d000 0x00001342 0x00001400 6.11912796158
GFIDS 0x0000f000 0x00000030 0x00000400 0.209541281087
.rsrc 0x00010000 0x00000688 0x00000800 3.01181678322
.reloc 0x00011000 0x00000388 0x00000400 4.40424560705

Resources

Name Offset Size Language Sub-language File type
MSELAMCERTINFOID 0x000104c0 0x000001c6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00010100 0x000003c0 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ntoskrnl.exe:
0x1c0009058 ExFreePoolWithTag
0x1c0009060 IoWMIRegistrationControl
0x1c0009068 InitSafeBootMode
0x1c0009070 InitializeSListHead
0x1c0009078 CmRegisterCallback
0x1c0009080 ZwClose
0x1c0009088 ZwOpenKey
0x1c0009090 ZwQueryValueKey
0x1c00090a0 CmCallbackGetKeyObjectID
0x1c00090b0 ZwDeleteValueKey
0x1c00090b8 RtlInitAnsiString
0x1c00090c0 ZwSetValueKey
0x1c00090c8 RtlCompareMemory
0x1c00090d8 ExNotifyCallback
0x1c00090e0 wcsstr
0x1c00090e8 RtlCopyUnicodeString
0x1c00090f0 RtlInitUnicodeString
0x1c00090f8 ExCreateCallback
0x1c0009100 ObfDereferenceObject
0x1c0009108 CmUnRegisterCallback
0x1c0009110 RtlUpcaseUnicodeChar
0x1c0009118 ExpInterlockedFlushSList
0x1c0009120 RtlEqualUnicodeString
0x1c0009128 __C_specific_handler
0x1c0009130 ZwQuerySystemInformation
0x1c0009140 PsGetVersion
0x1c0009148 ExAllocatePoolWithTag
Library cng.sys:
0x1c0009000 BCryptCreateHash
0x1c0009008 BCryptHashData
0x1c0009010 BCryptImportKeyPair
0x1c0009018 BCryptDestroyHash
0x1c0009028 BCryptFinishHash
0x1c0009038 BCryptVerifySignature
0x1c0009040 BCryptGetProperty
0x1c0009048 BCryptDestroyKey

!This program cannot be run in DOS mode.
hfothk
h.rdata
H.data
.pdata
H.idata
bGFIDS
B.rsrc
B.reloc
L$ VWAVH
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
t$ WATAUAVAWH
0A_A^A]A\_
WAVAWH
@A_A^_
|$ ATAVAWH
A_A^A\
-fffffff
fffffff
fffffff
fffffff
.fffffff
fffffff
fffffff
AQAPRQPH
0XYZAXAY
ffffff
a?,F.f
STF>U\C]K
RSDSnS
WdBoot.pdb
.text$mn
.text$mn$00
.text$mn$21
.rdata$brc
.gehcont
.rdata
.rdata$zzzdbg
.xdata
.data$brc
.pdata
.idata$5
.00cfg
.idata$2
.idata$3
.idata$4
.idata$6
PAGE$x
.gfids
.rsrc$01
.rsrc$02
RtlEqualUnicodeString
RtlUpcaseUnicodeChar
CmUnRegisterCallback
ObfDereferenceObject
ExCreateCallback
RtlInitUnicodeString
RtlCopyUnicodeString
wcsstr
ExNotifyCallback
MmGetSystemRoutineAddress
ZwQueryValueKey
ExFreePoolWithTag
IoWMIRegistrationControl
InitSafeBootMode
InitializeSListHead
CmRegisterCallback
ZwClose
ZwOpenKey
ExpInterlockedFlushSList
ExpInterlockedPushEntrySList
CmCallbackGetKeyObjectID
RtlAnsiStringToUnicodeString
ZwDeleteValueKey
RtlInitAnsiString
ZwSetValueKey
RtlCompareMemory
ntoskrnl.exe
BCryptDestroyKey
BCryptGetProperty
BCryptVerifySignature
BCryptOpenAlgorithmProvider
BCryptFinishHash
BCryptCloseAlgorithmProvider
BCryptDestroyHash
BCryptImportKeyPair
BCryptHashData
BCryptCreateHash
cng.sys
__C_specific_handler
ZwQuerySystemInformation
ExAllocatePoolWithQuotaTag
PsGetVersion
ExAllocatePoolWithTag
UVWAVAWH
@A_A^_^]
t$ WATAUAVAWH
A_A^A]A\_
WATAVH
0A^A\_
x UAVAWH
x UAVAWH
tm9~ thI
tk9Y tfH
USVWATAVAWH
pA_A^A\_^[]
WAVAWH
fD;|$0u
@A_A^_
p WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
0A_A^A]A\_^]
\$0uLE3
t$ WAVAWH
UVWAVAWH
A_A^_^]
UVWAVAWH
@A_A^_^]
t$ UWAVH
rE9} w@
|$ UAVAWH
@USVWAUAVAWH
PA_A^A]_^[]
|$ AVH
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20100
230808183421Z
240807183421Z0
Washington1
Redmond1
Microsoft Corporation1>0<
5Microsoft Windows Early Launch Anti-malware Publisher0
Microsoft Corporation1
229895+5013900
Ehttp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0Z
>http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
100706204017Z
250706205017Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20100
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
#Vx"&6
7Z>@B1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2010
http://www.microsoft.com0
weA0Xd
20231106235413.248Z0
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:DC00-05E0-D9471%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
230525191221Z
240201191221Z0
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:DC00-05E0-D9471%0#
Microsoft Time-Stamp Service0
28??v}X
$QfgY$0
Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l
Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0
~~+M!
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
3http://www.microsoft.com/pkiops/Docs/Repository.htm0
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
as.,k{n?,
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1'0%
nShield TSS ESN:DC00-05E0-D9471%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
20231106121836Z
20231107121836Z0t0:
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
<Xsp(6
PWZOM*
ExAllocatePool2
PsGetVersion
WmiTraceMessage
WmiQueryTraceInformation
EtwRegisterClassicProvider
EtwUnregister
\Callback\WdEbNotificationCallback
\Callback\MpEbNotificationCallback
IoRegisterBootDriverCallback
IoUnregisterBootDriverCallback
WdBoot
\Registry\Machine\ELAM
Windows Defender
Microsoft Antimalware Platform
Measured
Signatures
\Registry\Machine\SYSTEM\CurrentControlSet\Control
SystemStartOptions
TESTSIGNING
Microsoft Primitive Provider
ObjectLength
HashDigestLength
RSAPUBLICBLOB
WdFilter.sys
MpFilter.sys
ElamInfo
\Registry\Machine\System\ControlSet
\Registry\Machine\System\CurrentControlSet\
RtlQueryModuleInformation
MSELAMCERTINFOID
MICROSOFTELAMCERTIFICATEINFO
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Microsoft Corporation
FileDescription
Microsoft antimalware boot driver
InternalName
WdBoot
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
WdBoot.sys
ProductName
Microsoft
Windows
Operating System
FileVersion
4.18.23110.3 (9ebb3643d539a6fc4659898b1df3124d5da4c0a9)
ProductVersion
4.18.23110.3
VarFileInfo
Translation
f6f717a43ad9abddc8cefdde1c505462535e7d1307e630f9544a2d14fe8bf26e
1.3.6.1.4.1.311.76.8.1;1.3.6.1.4.1.311.76.11.1
4e80be107c860de896384b3eff50504dc2d76ac7151df3102a4450637a032146
1.3.6.1.4.1.311.76.8.1;1.3.6.1.4.1.311.76.11.1
Legal_Policy_Statement
Microsof
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Paloalto Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.