| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2011-Mar-30 11:39:58 |
| Detected languages |
English - United States
|
| Debug artifacts |
DSETUP.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Direct driver preloader |
| FileVersion | 4.9.0.0904 |
| InternalName | dsetup.dll |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | dsetup.dll |
| ProductName | Microsoft® DirectX for Windows® |
| ProductVersion | 4.9.0.0904 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA |
| Safe | VirusTotal score: 0/72 (Scanned on 2026-03-24 22:57:45) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf0 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 4 |
| TimeDateStamp | 2011-Mar-30 11:39:58 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x12a00 |
| SizeOfInitializedData | 0x4e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00006BBC (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 5.1 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1a000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x23415 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x1000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
GetCurrentDirectoryW
LocalFree LocalAlloc lstrcmpA WideCharToMultiByte GetSystemDefaultLCID LoadLibraryW GetModuleFileNameW MultiByteToWideChar CompareStringA CreateDirectoryA GetWindowsDirectoryA FormatMessageA GetCommandLineA HeapFree HeapReAlloc HeapAlloc GetLocalTime GetModuleHandleA ExitProcess TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError InterlockedDecrement GetCurrentThreadId SetHandleCount GetStdHandle GetFileType GetStartupInfoA DeleteCriticalSection GetModuleFileNameA FreeEnvironmentStringsA GetEnvironmentStrings FreeEnvironmentStringsW GetEnvironmentStringsW HeapDestroy HeapCreate VirtualFree QueryPerformanceCounter GetTickCount GetCurrentProcessId GetSystemDirectoryA TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter LeaveCriticalSection EnterCriticalSection VirtualAlloc RtlUnwind WriteFile InitializeCriticalSection GetModuleHandleW GetCPInfo GetACP GetOEMCP Sleep SetFilePointer GetConsoleCP GetConsoleMode SetStdHandle FlushFileBuffers CreateFileA GetLocaleInfoA GetStringTypeA GetStringTypeW LCMapStringA LCMapStringW WriteConsoleA GetConsoleOutputCP WriteConsoleW SetEndOfFile GetProcessHeap ReadFile VirtualProtect GetSystemInfo VirtualQuery SetCurrentDirectoryA GetVersionExA LoadLibraryA GetProcAddress SetCurrentDirectoryW OutputDebugStringA CreateMutexA GetLastError CloseHandle GetSystemTimeAsFileTime FreeLibrary |
|---|---|
| USER32.dll |
GetKeyboardType
DestroyWindow SetFocus CreateDialogParamA SetDlgItemTextA MessageBoxA PeekMessageA GetMessageA TranslateMessage DispatchMessageA |
| ADVAPI32.dll |
RegCloseKey
RegOpenKeyExA RegDeleteKeyA RegEnumKeyExA RegQueryInfoKeyA RegSetValueExA RegCreateKeyExA RegSetValueExW RegCreateKeyExW RegQueryValueExA |
| WINMM.dll |
mmioRead
mmioDescend mmioClose mmioOpenA |
| VERSION.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
| ole32.dll |
StringFromGUID2
|
| Ordinal | 1 |
|---|---|
| Address | 0x41c4 |
| Ordinal | 2 |
|---|---|
| Address | 0x4278 |
| Ordinal | 3 |
|---|---|
| Address | 0x51b3 |
| Ordinal | 4 |
|---|---|
| Address | 0x57d6 |
| Ordinal | 5 |
|---|---|
| Address | 0x4f9c |
| Ordinal | 6 |
|---|---|
| Address | 0x473a |
| Ordinal | 7 |
|---|---|
| Address | 0x5d97 |
| Ordinal | 8 |
|---|---|
| Address | 0x505a |
| Ordinal | 9 |
|---|---|
| Address | 0x432c |
| Ordinal | 10 |
|---|---|
| Address | 0x419c |
| Ordinal | 11 |
|---|---|
| Address | 0x3ca8 |
| Ordinal | 12 |
|---|---|
| Address | 0x3d6d |
| Ordinal | 13 |
|---|---|
| Address | 0x3ed3 |
| Ordinal | 14 |
|---|---|
| Address | 0x4e80 |
| Ordinal | 15 |
|---|---|
| Address | 0x4769 |
| Ordinal | 16 |
|---|---|
| Address | 0x4ec7 |
| Ordinal | 17 |
|---|---|
| Address | 0x4f0e |
| Ordinal | 18 |
|---|---|
| Address | 0x4f55 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.9.0.904 |
| ProductVersion | 4.9.0.904 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS_OS232
VOS_OS232_PM32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DRV
|
| FileSubtype | VFT2_DRV_INSTALLABLE |
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Direct driver preloader |
| FileVersion (#2) | 4.9.0.0904 |
| InternalName | dsetup.dll |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | dsetup.dll |
| ProductName | Microsoft® DirectX for Windows® |
| ProductVersion (#2) | 4.9.0.0904 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2011-Mar-30 11:39:58 |
| Version | 0.0 |
| SizeofData | 35 |
| AddressOfRawData | 0x36e8 |
| PointerToRawData | 0x2ae8 |
| Referenced File | DSETUP.pdb |
| Size | 0x48 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x10014010 |
| SEHandlerTable | 0x10003710 |
| SEHandlerCount | 3 |
| XOR Key | 0x2b16f0cf |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 13 |
| Total imports | 137 |
| ASM objects (VS2012 build 50727 / VS2005 build 50727) | 17 |
| C++ objects (VS2012 build 50727 / VS2005 build 50727) | 30 |
| C objects (VS2012 build 50727 / VS2005 build 50727) | 108 |
| Exports (VS2010 build 30319) | 1 |
| C objects (VS2010 build 30319) | 3 |
| Resource objects (VS2010 build 30319) | 1 |
| Linker (VS2010 build 30319) | 1 |
No comments yet.