| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2021-Jul-08 01:54:13 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\p4_2006\sw\devrel\Playpen\dkirill\plankeShim\_out\wddm2_amd64_release\nvngx.pdb
|
| CompanyName | NVIDIA Corporation |
| FileDescription | NGX Runtime Library |
| FileVersion | 30.0.14.9516 |
| InternalName | nvngx.dll |
| LegalCopyright | (C) 2021 NVIDIA Corporation. All rights reserved. |
| OriginalFilename | nvngx.dll |
| ProductName | NGX |
| ProductVersion | 30.0.14.9516 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: NVIDIA Corporation
Issuer: Symantec Class 3 SHA256 Code Signing CA - G2 |
| Safe | VirusTotal score: 0/70 (Scanned on 2026-09-11 00:28:04) | All the AVs think this file is safe. |
| MD5 | 0d41bdecbe2251604c1eeeab044c39bb 🔍 |
|---|---|
| SHA1 | 8673561076da429d12efaf791c19341ed4f08e75 🔍 |
| SHA256 | d9a017986bcca5abac34b4d4a6af38e29fb3588688a4b8c13a83f3ecb852b83f 🔍 |
| SHA3 | 3c05bc02ec2ce8a6a680aafedf0c7c2e3add754445c31c9f83484ad6885d6b7c 🔍 |
| SSDeep | 3072:fxHLJEWBBKxkIMOBDo/XGeQoi6C9WLlTbKopA6Nkg7wf0ZxnfIDCZVYQFm0bz18m:prJja2DSd/YlTbKopoD4ztnfnzMC 🔍 |
| Imports Hash | 51bd6f417580951602d2824e9a4544a5 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2021-Jul-08 01:54:13 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x57e00 |
| SizeOfInitializedData | 0x1d000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000001DAE8 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x78000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x842d3 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | e93612cf5bcbe0909666e85dde796100 🔍 |
|---|---|
| SHA1 | bc528a4c771b453d975f172c418e270a42ae37e1 🔍 |
| SHA256 | d34132e7acb6d2b4c40a4f237f7e93e659e9a7e8591c58a01eea3957d5a8c1b3 🔍 |
| SHA3 | 31688a77653de84c0a223a58838e6f2e78392fc18829d62c3d82fd073f3ff071 🔍 |
| VirtualSize | 0x57e00 |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x57e00 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.49495 |
| MD5 | 0aa7ca3699f32d43f7aca1c433dcc932 🔍 |
|---|---|
| SHA1 | 5c96b2aaee318868bec9a3910e87fb3132c23ed7 🔍 |
| SHA256 | a4c53a77d3e9b05ac9a8ae31d5a6ed1ed3926ffbb6a6938c5a2bfaf742a9f1dd 🔍 |
| SHA3 | e997f801d4a5775a0f2bd02c926f9c40e98f82d703ed19bc80b8266b8c2221ae 🔍 |
| VirtualSize | 0x13ffc |
| VirtualAddress | 0x59000 |
| SizeOfRawData | 0x14000 |
| PointerToRawData | 0x58200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.21134 |
| MD5 | 9fbd8c6de4642f02ee298700d041cea6 🔍 |
|---|---|
| SHA1 | 05ab56eb9669bcb8140d62f953bcd375331908cb 🔍 |
| SHA256 | cbb6848949097389675bf45b258742d51298cbb0d0bfd7627097d14655126b38 🔍 |
| SHA3 | c8958f64db38fe204a670b0f745fa4522679e461377b6a67f8a6a018af1df369 🔍 |
| VirtualSize | 0x2f28 |
| VirtualAddress | 0x6d000 |
| SizeOfRawData | 0xe00 |
| PointerToRawData | 0x6c200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 2.18055 |
| MD5 | 7e76aed13b86523568de6f67bf27e114 🔍 |
|---|---|
| SHA1 | 755c08fd4d13c7fffabd7602561f25f1c0cca8c3 🔍 |
| SHA256 | 073fe850fed1f10f001e7ba1b379bf9e5d77b73eb49dfd146034a379c9c2c796 🔍 |
| SHA3 | 3ee06a13a5ca4620e26e8f3753bca343a8c3fabe67eb410f2d37d32796e5e4d7 🔍 |
| VirtualSize | 0x4e48 |
| VirtualAddress | 0x70000 |
| SizeOfRawData | 0x5000 |
| PointerToRawData | 0x6d000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 5.74465 |
| MD5 | 512d07c1e3ee46d7c978df0c73a02370 🔍 |
|---|---|
| SHA1 | 12715304c3c9ca74c8c31a2157652ebb7d1f65ac 🔍 |
| SHA256 | cbf7bf0dad5dbb9abad26df7e7286bf0d72b5cb98210998dddf6167b779f225c 🔍 |
| SHA3 | f50c25f6775e12bc9e2b3929c1d6f330782c8b9f1adb75382756442f6c0e2061 🔍 |
| VirtualSize | 0x94 |
| VirtualAddress | 0x75000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x72000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 1.10464 |
| MD5 | 961ef9480a579c3dd891d1170f877aef 🔍 |
|---|---|
| SHA1 | 92cd526f08d2e6129a9a1783257d49b9a546efe2 🔍 |
| SHA256 | cc693ac8744f80048f382012e9c690890da3f6593a7c598f44cb3a8733296da1 🔍 |
| SHA3 | 9509a0d97173e0699ba7ddf8aaac4b3e04731d5c23a5967060922a05b248c389 🔍 |
| VirtualSize | 0x370 |
| VirtualAddress | 0x76000 |
| SizeOfRawData | 0x400 |
| PointerToRawData | 0x72200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 2.98606 |
| MD5 | 78d32ab75b038e3eeddfbc2533b4b3a1 🔍 |
|---|---|
| SHA1 | 341d5ee6caed4d220284b4490ae663e90f93bdc6 🔍 |
| SHA256 | 881ff31fe4f399d8a827504d57515f8cddc27bab7d9cb6e31eefd87b8aedf56c 🔍 |
| SHA3 | 6c4c1dc83dfb96cb22e5dc42e762c023fb3e65c89f319cde7fd46423afbda1cc 🔍 |
| VirtualSize | 0x908 |
| VirtualAddress | 0x77000 |
| SizeOfRawData | 0xa00 |
| PointerToRawData | 0x72600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.42257 |
| KERNEL32.dll |
VerSetConditionMask
CreateFileW GetFileAttributesW GetFullPathNameW OutputDebugStringW CloseHandle GetLastError SetLastError CreateProcessA CreateProcessW GetSystemDirectoryW FreeLibrary GetModuleFileNameW GetModuleHandleW GetProcAddress LoadLibraryExW LocalAlloc LocalFree lstrcmpA VerifyVersionInfoW FileTimeToSystemTime CreateThread GetModuleHandleExA GetCurrentThread GetCurrentThreadId RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent GetStringTypeW HeapAlloc HeapFree EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetDateFormatW GetTimeFormatW CompareStringW LCMapStringW GetLocaleInfoW IsValidLocale GetUserDefaultLCID EnumSystemLocalesW IsValidCodePage GetACP GetOEMCP GetCPInfo MultiByteToWideChar ExitProcess GetModuleHandleExW SetConsoleCtrlHandler GetProcessHeap WideCharToMultiByte HeapSize HeapReAlloc GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId InitializeSListHead WriteConsoleW RtlUnwindEx InterlockedPushEntrySList InterlockedFlushSList EncodePointer RaiseException RtlPcToFileHeader FindClose FindFirstFileExW FindNextFileW GetCommandLineA GetCommandLineW GetEnvironmentStringsW FreeEnvironmentStringsW SetEnvironmentVariableW GetStdHandle GetFileType SetStdHandle FlushFileBuffers WriteFile GetConsoleOutputCP GetConsoleMode GetFileSizeEx SetFilePointerEx ReadFile ReadConsoleW RtlUnwind |
|---|
| Ordinal | 1 |
|---|---|
| Address | 0x9d30 |
| Ordinal | 2 |
|---|---|
| Address | 0x9d77 |
| Ordinal | 3 |
|---|---|
| Address | 0x9dbe |
| Ordinal | 4 |
|---|---|
| Address | 0x9e05 |
| Ordinal | 5 |
|---|---|
| Address | 0x9e4c |
| Ordinal | 6 |
|---|---|
| Address | 0x9e93 |
| Ordinal | 7 |
|---|---|
| Address | 0x9eda |
| Ordinal | 8 |
|---|---|
| Address | 0x9f21 |
| Ordinal | 9 |
|---|---|
| Address | 0x9f68 |
| Ordinal | 10 |
|---|---|
| Address | 0x9faf |
| Ordinal | 11 |
|---|---|
| Address | 0x9ff6 |
| Ordinal | 12 |
|---|---|
| Address | 0xa03d |
| Ordinal | 13 |
|---|---|
| Address | 0xa084 |
| Ordinal | 14 |
|---|---|
| Address | 0xa0cb |
| Ordinal | 15 |
|---|---|
| Address | 0xa112 |
| Ordinal | 16 |
|---|---|
| Address | 0xa159 |
| Ordinal | 17 |
|---|---|
| Address | 0xa1a0 |
| Ordinal | 18 |
|---|---|
| Address | 0xa1e7 |
| Ordinal | 19 |
|---|---|
| Address | 0xa22e |
| Ordinal | 20 |
|---|---|
| Address | 0xa275 |
| Ordinal | 21 |
|---|---|
| Address | 0xa2bc |
| Ordinal | 22 |
|---|---|
| Address | 0xa303 |
| Ordinal | 23 |
|---|---|
| Address | 0xa34a |
| Ordinal | 24 |
|---|---|
| Address | 0xa391 |
| Ordinal | 25 |
|---|---|
| Address | 0xa3d8 |
| Ordinal | 26 |
|---|---|
| Address | 0xa41f |
| Ordinal | 27 |
|---|---|
| Address | 0xa466 |
| Ordinal | 28 |
|---|---|
| Address | 0xa4ad |
| Ordinal | 29 |
|---|---|
| Address | 0xa4f4 |
| Ordinal | 30 |
|---|---|
| Address | 0xa53b |
| Ordinal | 31 |
|---|---|
| Address | 0xa582 |
| Ordinal | 32 |
|---|---|
| Address | 0xa5c9 |
| Ordinal | 33 |
|---|---|
| Address | 0xa610 |
| Ordinal | 34 |
|---|---|
| Address | 0xa657 |
| Ordinal | 35 |
|---|---|
| Address | 0xa69e |
| Ordinal | 36 |
|---|---|
| Address | 0xa6e5 |
| Ordinal | 37 |
|---|---|
| Address | 0xa72c |
| Ordinal | 38 |
|---|---|
| Address | 0xa773 |
| Ordinal | 39 |
|---|---|
| Address | 0xa7ba |
| Ordinal | 40 |
|---|---|
| Address | 0xa801 |
| Ordinal | 41 |
|---|---|
| Address | 0xa848 |
| Ordinal | 42 |
|---|---|
| Address | 0xa88f |
| Ordinal | 43 |
|---|---|
| Address | 0xa8d6 |
| Ordinal | 44 |
|---|---|
| Address | 0xa91d |
| Ordinal | 45 |
|---|---|
| Address | 0xa964 |
| Ordinal | 46 |
|---|---|
| Address | 0xa9ab |
| Ordinal | 47 |
|---|---|
| Address | 0xa9f2 |
| Ordinal | 48 |
|---|---|
| Address | 0xaa39 |
| Ordinal | 49 |
|---|---|
| Address | 0xaa80 |
| Ordinal | 50 |
|---|---|
| Address | 0xaac7 |
| Ordinal | 51 |
|---|---|
| Address | 0xab0e |
| Ordinal | 52 |
|---|---|
| Address | 0xab55 |
| Ordinal | 53 |
|---|---|
| Address | 0xab9c |
| Ordinal | 54 |
|---|---|
| Address | 0xabe3 |
| Ordinal | 55 |
|---|---|
| Address | 0xac2a |
| Ordinal | 56 |
|---|---|
| Address | 0xac71 |
| Ordinal | 57 |
|---|---|
| Address | 0xacb8 |
| Ordinal | 58 |
|---|---|
| Address | 0xacff |
| Ordinal | 59 |
|---|---|
| Address | 0xad46 |
| Type |
RT_VERSION
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x310 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 3.49989 |
| MD5 | e4269e1486a58825ffbc4ecd658069e5 🔍 |
| SHA1 | efa44ff2c281a6d5b807a69ff04275a9055b61f9 🔍 |
| SHA256 | 1e9606f4189a4bd81f9ba60c3b42c8a77f9427a529b9718492bec41d9e3c33da 🔍 |
| SHA3 | bd0ac592c869190f04253cc165f95a47642cab1fc0aca65c260047f936a81225 🔍 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 30.0.14.9516 |
| ProductVersion | 30.0.14.9516 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | NVIDIA Corporation |
| FileDescription | NGX Runtime Library |
| FileVersion (#2) | 30.0.14.9516 |
| InternalName | nvngx.dll |
| LegalCopyright | (C) 2021 NVIDIA Corporation. All rights reserved. |
| OriginalFilename | nvngx.dll |
| ProductName | NGX |
| ProductVersion (#2) | 30.0.14.9516 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Jul-08 01:54:13 |
| Version | 0.0 |
| SizeofData | 107 |
| AddressOfRawData | 0x657f4 |
| PointerToRawData | 0x649f4 |
| Referenced File | C:\p4_2006\sw\devrel\Playpen\dkirill\plankeShim\_out\wddm2_amd64_release\nvngx.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Jul-08 01:54:13 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x65860 |
| PointerToRawData | 0x64a60 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2021-Jul-08 01:54:13 |
| Version | 0.0 |
| SizeofData | 820 |
| AddressOfRawData | 0x65874 |
| PointerToRawData | 0x64a74 |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18006d7e8 |
| XOR Key | 0x1e716b87 |
|---|---|
| Unmarked objects | 0 |
| Imports (29395) | 3 |
| Total imports | 97 |
| C objects (27412) | 11 |
| ASM objects (27412) | 5 |
| C++ objects (27412) | 136 |
| C++ objects (VS 2015/2017/2019 runtime 29118) | 29 |
| C objects (VS 2015/2017/2019 runtime 29118) | 16 |
| ASM objects (VS 2015/2017/2019 runtime 29118) | 9 |
| C++ objects (VS2019 Update 8 (16.8.2) compiler 29334) | 2 |
| ASM objects (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
| Exports (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
| Resource objects (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
| Linker (VS2019 Update 8 (16.8.2) compiler 29334) | 1 |
No comments yet.