| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2022-Apr-21 11:21:39 |
| Detected languages |
English - United States
|
| CompanyName | Microsoft Corporation |
| FileDescription | Version Checking and File Installation Libraries |
| FileVersion | 6.3.9600.17415 (winblue_r4.141028-1500) |
| InternalName | version |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | VERSION.DLL |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 6.3.9600.17415 |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2026-02-23 06:31:08) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x80 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2022-Apr-21 11:21:39 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x2e00 |
| SizeOfInitializedData | 0x1e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001000 (Section: .code) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 4.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x9000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| msvcrt.dll |
memset
wcscmp memmove strlen strcpy wcslen wcscpy wcsncpy wcscat malloc free |
|---|---|
| KERNEL32.dll |
HeapCreate
HeapDestroy DisableThreadLibraryCalls GetSystemDirectoryW GetModuleHandleW VirtualProtect ExitProcess UnregisterWait CloseHandle EnterCriticalSection LeaveCriticalSection HeapFree TlsFree DeleteCriticalSection TlsAlloc InitializeCriticalSection TlsGetValue HeapAlloc GetCurrentProcess GetCurrentThread DuplicateHandle RegisterWaitForSingleObject TlsSetValue GetModuleFileNameW FreeLibrary LoadLibraryW WideCharToMultiByte GetProcAddress HeapReAlloc AllocConsole GetStdHandle GetConsoleScreenBufferInfo SetConsoleCtrlHandler SetConsoleTitleW FlushFileBuffers SetConsoleMode ReadConsoleW ReadFile GetLastError WriteConsoleW WriteFile MultiByteToWideChar |
| Ordinal | 1 |
|---|---|
| Address | 0x112b |
| Ordinal | 2 |
|---|---|
| Address | 0x16e3 |
| Ordinal | 3 |
|---|---|
| Address | 0x158c |
| Ordinal | 4 |
|---|---|
| Address | 0x15a2 |
| Ordinal | 5 |
|---|---|
| Address | 0x117c |
| Ordinal | 6 |
|---|---|
| Address | 0x15b8 |
| Ordinal | 7 |
|---|---|
| Address | 0x15ce |
| Ordinal | 8 |
|---|---|
| Address | 0x121a |
| Ordinal | 9 |
|---|---|
| Address | 0x1141 |
| Ordinal | 10 |
|---|---|
| Address | 0x10e9 |
| Ordinal | 11 |
|---|---|
| Address | 0x1115 |
| Ordinal | 12 |
|---|---|
| Address | 0x125c |
| Ordinal | 13 |
|---|---|
| Address | 0x1272 |
| Ordinal | 14 |
|---|---|
| Address | 0x10d3 |
| Ordinal | 15 |
|---|---|
| Address | 0x10ff |
| Ordinal | 16 |
|---|---|
| Address | 0x1230 |
| Ordinal | 17 |
|---|---|
| Address | 0x1246 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 6.3.9600.17415 |
| ProductVersion | 6.3.9600.17415 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Version Checking and File Installation Libraries |
| FileVersion (#2) | 6.3.9600.17415 (winblue_r4.141028-1500) |
| InternalName | version |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | VERSION.DLL |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 6.3.9600.17415 |
| Resource LangID | English - United States |
|---|
No comments yet.