Static | ZeroBOX

PE Compile Time

2089-06-29 19:28:50

PDB Path

TSSysprep.pdb

PE Imphash

e16a254190b5318d0665c0fdf2746840

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007d1c 0x00008000 5.88100332881
fothk 0x00009000 0x00001000 0x00001000 0.0159201832656
.rdata 0x0000a000 0x000054c2 0x00006000 4.13921335033
.data 0x00010000 0x00000c20 0x00001000 0.419412229052
.pdata 0x00011000 0x0000051c 0x00001000 1.71834086915
.rsrc 0x00012000 0x00000428 0x00001000 1.12584131455
.reloc 0x00013000 0x00000220 0x00001000 1.07103160178

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00012060 0x000003c4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library msvcrt.dll:
0x18000af10 _snwprintf_s
0x18000af18 ??3@YAXPEAX@Z
0x18000af20 _vsnwprintf_s
0x18000af28 ??1type_info@@UEAA@XZ
0x18000af30 _callnewh
0x18000af38 _purecall
0x18000af50 ??1exception@@UEAA@XZ
0x18000af60 _CxxThrowException
0x18000af68 memcpy
0x18000af70 memmove
0x18000af78 ??_V@YAXPEAX@Z
0x18000af80 _onexit
0x18000af88 __dllonexit
0x18000af90 _unlock
0x18000af98 _lock
0x18000afa0 __C_specific_handler
0x18000afa8 _initterm
0x18000afb0 malloc
0x18000afb8 free
0x18000afc0 _amsg_exit
0x18000afc8 _XcptFilter
0x18000afd8 __CxxFrameHandler3
0x18000afe0 memset
Library WDSCORE.dll:
0x18000aec8 CurrentIP
0x18000aed0 WdsSetupLogMessageW
0x18000aed8 ConstructPartialMsgVW
Library ntdll.dll:
0x18000aff0 RtlCaptureContext
0x18000aff8 RtlVirtualUnwind
0x18000b000 RtlLookupFunctionEntry
Library KERNEL32.dll:
0x18000ad58 GetSystemFirmwareTable
0x18000ad60 GetLastError
0x18000ad68 Sleep
0x18000ad70 TerminateProcess
0x18000ad78 GetCurrentProcess
0x18000ad88 WideCharToMultiByte
0x18000ad90 UnhandledExceptionFilter
0x18000ad98 GetTickCount
0x18000ada0 GetSystemTimeAsFileTime
0x18000ada8 GetCurrentThreadId
0x18000adb0 GetCurrentProcessId
0x18000adb8 QueryPerformanceCounter
0x18000adc0 LocalFree
0x18000adc8 SetLastError
0x18000add0 OutputDebugStringW
0x18000add8 LoadLibraryW
0x18000ade0 GetProcAddress
0x18000ade8 FreeLibrary
0x18000adf0 CloseHandle
0x18000adf8 RaiseException
0x18000ae00 WriteFile
0x18000ae08 SetFilePointer
0x18000ae10 CreateFileW
0x18000ae18 GetVersionExW
Library CRYPT32.dll:
0x18000ad20 CertCloseStore
0x18000ad30 CertOpenStore
Library SHLWAPI.dll:
0x18000aea8 SHGetValueW
0x18000aeb0 SHDeleteKeyW
0x18000aeb8 SHDeleteValueW
Library api-ms-win-core-com-l1-1-0.dll:
0x18000aee8 CoUninitialize
0x18000aef0 CoCreateInstance
0x18000aef8 CoSetProxyBlanket
0x18000af00 CoInitializeEx
Library ADVAPI32.dll:
0x18000abf8 GetAclInformation
0x18000ac00 GetAce
0x18000ac08 EqualSid
0x18000ac10 DeleteAce
0x18000ac28 RegDeleteKeyW
0x18000ac30 RegEnumKeyExW
0x18000ac40 RegQueryInfoKeyW
0x18000ac58 RegOpenKeyExW
0x18000ac60 RegCloseKey
0x18000ac68 RegCreateKeyExW
0x18000ac70 RegSetValueExW
0x18000ac78 GetTokenInformation
0x18000ac88 MakeAbsoluteSD
0x18000ac90 MakeSelfRelativeSD
0x18000ac98 RegQueryValueExW
0x18000aca0 AddAccessAllowedAce
0x18000aca8 IsValidAcl
0x18000acb0 GetLengthSid
0x18000acb8 AddAccessAllowedAceEx
0x18000acc0 InitializeAcl
0x18000acc8 FreeSid
0x18000acd0 OpenProcessToken
0x18000ace0 AddAce
0x18000acf8 AllocateAndInitializeSid
0x18000ad10 RegDeleteValueW
Library OLEAUT32.dll:
0x18000ae28 SysFreeString
0x18000ae30 SafeArrayUnlock
0x18000ae38 SafeArrayGetUBound
0x18000ae40 VariantInit
0x18000ae48 SafeArrayDestroy
0x18000ae50 SafeArrayRedim
0x18000ae58 VariantClear
0x18000ae60 SafeArrayAccessData
0x18000ae68 SafeArrayCreate
0x18000ae70 SafeArrayUnaccessData
0x18000ae78 SafeArrayLock
0x18000ae80 SysAllocString
0x18000ae88 SafeArrayGetVartype
0x18000ae90 SafeArrayCopy
0x18000ae98 SafeArrayGetLBound
Library CRYPTBASE.dll:
0x18000ad48 SystemFunction036

Exports

Ordinal Address Name
1 0x1800024b0 AppsrvSysPrepGeneralize
2 0x1800029a0 AppsrvSysPrepSpecializeOffline
3 0x180002b80 AppsrvSysPrepSpecializeOnline
4 0x180002e50 CBrokerSysPrepGeneralize
5 0x180003340 CBrokerSysPrepSpecializeOffline
6 0x180003520 CBrokerSysPrepSpecializeOnline
7 0x180003820 LSMSysPrepBackup
8 0x1800039f0 LSMSysPrepRestoreOffline
9 0x180003bb0 LSMSysPrepRestoreOnline
10 0x180003d70 RCMSysPrepGeneralize
11 0x180003f20 RdpSysPrepGeneralize
12 0x1800040f0 RdpSysPrepRestoreOffline
13 0x1800043d0 RdpSysPrepRestoreOnline
!This program cannot be run in DOS mode.
`fothk
`.rdata
@.data
.pdata
@.rsrc
@.reloc
ATAVAWH
A_A^A\
LcA<E3
SVWAVH
8A^_^[
H!t$HE3
x ATAUAWH
H!l$HL
H!l$HE3
A_A]A\
H!t$HE3
x ATAUAWH
H!l$HL
H!l$HE3
A_A]A\
H!t$HE3
x ATAUAWH
!l$PE3
H!l$HM
A_A]A\
WATAUH
UVWATAUAVAWH
A_A^A]A\_^]
UATAVH
UWATAVAWH
A_A^A\_]
UWATAVAWH
A_A^A\_]
D$p!\$PI
L$ UWATAVAWH
;}H|FH
0A_A^A\_]
@SUVWATAVAWH
PA_A^A\_^][
UVWATAUH
`A]A\_^]
9\$8vLL
UVWATAUAVAWH
0A_A^A]A\_^]
USVWATAVAWH
pA_A^A\_^[]
9\$(voL
UVWATAUH
`A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
L$ USVWATAVAW
fD94Ku
fD94xu
fD94xu
A_A^A\_^[]
x UATAUAVAWH
A_A^A]A\]
E(=csm
E8=csm
EH=csm
EX=csm
Eh=csm
Ex=csm
bad allocation
generic
unknown error
iostream
iostream stream error
system
invalid string position
string too long
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
Entering LSMSysPrepBackup
Deleting Lanatable key FAILED: %d
LSMSysPrepBackup completed
Entering LSMSysPrepRestoreOffline
LSMSysPrepRestoreOffline call with invalid parameter
Leaving LSMSysPrepRestoreOffline, status 0x%08x
Entering LSMSysPrepRestoreOnline
bOfflineRan is FALSE
Leaving LSMSysPrepRestoreOnline, status 0x%08x
Entering RCMSysPrepGeneralize
ResetTSSelfSignedCertificate() FAILED: %d.
Leaving RCMSysPrepGeneralize
Entering RdpSysPrepRestoreOnline, bOffLineRan is %d
Deleting MSLicensing key FAILED: %d
SetupMSLicensingKey() FAILED
Leaving RdpSysPrepRestore, err = 0x%08x
Entering RdpSysPrepRestoreOffline
RdpSysPrepRestoreOffline call with invalid parameter
Leaving RdpSysPrepRestoreOffline, status 0x%08x
Entering RdpSysPrepGeneralize
Leaving RdpSysPrepGeneralize
ResetTSRDSAppXKeys on AUINSTALLAGENT_REG_STAGINGINPROGRESS FAILED: %d
ResetTSRDSAppXKeys deleted AUINSTALLAGENT_REG_STAGINGINPROGRESS succeeded
ResetTSRDSAppXKeys open AUINSTALLAGENT_REG_CONTROL_USER FAILED: %d
GetNextSubKey FAILED: %d
MachineControlKey open AUINSTALLAGENT_REGISTRY_CONTROL FAILED: %d
ResetTSRDSAppXKeys...
ResetTSRDSAppXKeys status 0x%08x
Failed to read "SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\SelfSignedCertificate" registry value: %d
Failed to delete the default Remote Desktop certificate: %X
WARNING: Failed to modify global DCOM ACL for RDS Remote Access Servers, error: 0x%x
WARNING: Failed to modify global DCOM ACL for RDS Management Servers, error: 0x%x
Failed to adjust WMI namespace ACL for RDS Remote Access Servers group, error: 0x%x
Failed to adjust WMI namespace ACL for RDS Management Servers group, error: 0x%x
Entering %s.
Leaving %s - dwReturn 0x%X.
AppsrvSysPrepSpecializeOffline call with invalid parameter
WARNING: Failed to modify global DCOM ACL for RDS Endpoint Servers, error: 0x%x
Failed to adjust CB WMI namespace ACL for RDS Endpoint group, error: 0x%x
Failed to adjust CB WMI namespace ACL for RDS Management Servers group, error: 0x%x
CBrokerSysPrepSpecializeOffline call with invalid parameter
bOfflineran is FALSE
System
AllocateAndInitializeSid
SetEntriesInAclW
SetSecurityInfo
FreeSid
RSDS-o
TSSysprep.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.rdata$brc
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIZ
.gehcont
.gfids
.giats
.rdata
.rdata$voltmd
.rdata$zzzdbg
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$brc
.data$r$brc
.pdata
.rsrc$01
.rsrc$02
TSSysprep.dll
AppsrvSysPrepGeneralize
AppsrvSysPrepSpecializeOffline
AppsrvSysPrepSpecializeOnline
CBrokerSysPrepGeneralize
CBrokerSysPrepSpecializeOffline
CBrokerSysPrepSpecializeOnline
LSMSysPrepBackup
LSMSysPrepRestoreOffline
LSMSysPrepRestoreOnline
RCMSysPrepGeneralize
RdpSysPrepGeneralize
RdpSysPrepRestoreOffline
RdpSysPrepRestoreOnline
__CxxFrameHandler3
_XcptFilter
_amsg_exit
malloc
_initterm
__C_specific_handler
msvcrt.dll
_unlock
__dllonexit
_onexit
ConstructPartialMsgVW
WdsSetupLogMessageW
CurrentIP
WDSCORE.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
GetLastError
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
GetTickCount
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
KERNEL32.dll
CertDeleteCertificateFromStore
CertCloseStore
CertFindCertificateInStore
CertOpenStore
CRYPT32.dll
SHDeleteKeyW
SHGetValueW
SHDeleteValueW
SHLWAPI.dll
CoUninitialize
CoCreateInstance
CoSetProxyBlanket
CoInitializeEx
api-ms-win-core-com-l1-1-0.dll
??3@YAXPEAX@Z
??_V@YAXPEAX@Z
_snwprintf_s
_vsnwprintf_s
_callnewh
_purecall
??0exception@@QEAA@AEBQEBD@Z
??0exception@@QEAA@AEBQEBDH@Z
??0exception@@QEAA@AEBV0@@Z
??1exception@@UEAA@XZ
?what@exception@@UEBAPEBDXZ
_CxxThrowException
memcpy
memmove
??1type_info@@UEAA@XZ
LocalFree
SetLastError
OutputDebugStringW
LoadLibraryW
GetProcAddress
FreeLibrary
CloseHandle
RaiseException
WriteFile
SetFilePointer
CreateFileW
GetVersionExW
WideCharToMultiByte
GetSecurityDescriptorLength
SetSecurityDescriptorControl
InitializeSecurityDescriptor
DeleteAce
EqualSid
GetAce
GetAclInformation
GetSecurityDescriptorDacl
SetSecurityDescriptorDacl
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
RegSetValueExW
GetTokenInformation
SetSecurityDescriptorGroup
MakeAbsoluteSD
MakeSelfRelativeSD
RegQueryValueExW
AddAccessAllowedAce
IsValidAcl
GetLengthSid
AddAccessAllowedAceEx
InitializeAcl
FreeSid
OpenProcessToken
IsValidSecurityDescriptor
AddAce
GetSecurityDescriptorOwner
GetSecurityDescriptorGroup
AllocateAndInitializeSid
SetSecurityDescriptorOwner
GetSecurityDescriptorSacl
RegDeleteValueW
RegEnumKeyExW
RegDeleteKeyW
ADVAPI32.dll
OLEAUT32.dll
GetSystemFirmwareTable
RegQueryInfoKeyW
SystemFunction036
CRYPTBASE.dll
memset
.?AVbad_alloc@std@@
.?AVexception@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
LSMSysPrepBackup
termsrv\setup\tssysprep\sysprep.cpp
SYSTEM\CurrentControlSet\Control\Terminal Server\Lanatable
LSMSysPrepRestoreOffline
xLSMSysPrepRestoreOnline
RCMSysPrepGeneralize
RdpSysPrepRestoreOnline
SOFTWARE\Microsoft\MSLicensing
xRdpSysPrepRestoreOffline
Microsoft\MSLicensing
xRdpSysPrepGeneralize
Microsoft\AllUserInstallAgent
StagingInProgress
ResetTSRDSAppXKeysWithRegKey
Microsoft\Windows\CurrentVersion\AppReadiness
ResetTSRDSAppXKeys
SOFTWARE
SelfSignedCertificate
SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations
ResetTSSelfSignedCertificate
SelfSignedCertStore
AppsrvSysPrepSpecializeGeneralize_AdjustDCOMSecurity
AppsrvSysPrepSpecializeGeneralize_AdjustNamespaceSecurity
AppsrvSysPrepSpecializeGeneralize
AppsrvSysPrepGeneralize
AppsrvSysPrepSpecializeOffline
AppsrvSysPrepSpecializeOnline
CBrokerSysPrepSpecializeGeneralize_AdjustDCOMSecurity
CBrokerSysPrepSpecializeGeneralize_AdjustNamespaceSecurity
CBrokerSysPrepSpecializeGeneralize
CBrokerSysPrepGeneralize
CBrokerSysPrepSpecializeOffline
CBrokerSysPrepSpecializeOnline
FAILED to add Terminal Services MSLicensing HWID
FAILED to add Terminal Services MSLicensing key
advapi32.dll
AddSidToObjectsSecurityDescriptor: Can't get proc SetSecurityInfo
dStore
Microsoft\MSLicensing\HardwareID
ClientHWID
SYSTEM
Software
INTERACTIVE
__SystemSecurity
WARNING: Failed to Initialize COM, error: 0x%x
termsrv\setup\acl\acl.cpp
WARNING: Failed to AllocateAndInitializeSid, error: 0x%x
ROOT\cimv2\TerminalServices
WARNING: Failed to get WMI Namespace Security Descriptor, error: 0x%x
WARNING: Failed to modify WMI Namespace Security Descriptor, error: 0x%x
WARNING: Failed to set WMI Namespace Security Descriptor, error: 0x%x
Microsoft\OLE
AdjustDCOMSecurityEx call with invalid parameter, error: 0x%x
MachineAccessRestriction
WARNING: Failed to modify global DCOM ACL MachineAccessRestriction, error: 0x%x
MachineLaunchRestriction
WARNING: Failed to modify global DCOM ACL MachineLaunchRestriction, error: 0x%x
********Terminating Log.
clientcore\termsrv\setup\lib\logmsg.cpp
%s(%d)
Software\Microsoft\MSLicensing\Store
Software\Microsoft\MSLicensing\HardwareID
Client HWID
ForceRHWID
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Remote Desktop Session Host Server Sysprep
FileVersion
10.0.27823.1000 (WinBuild.160101.0800)
InternalName
TSSysprep
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
TSSysprep.dll
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.27823.1000
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.