PE Compile Time

2014-12-21 08:43:37

PDB Path

c:\Projects\VS2005\RegFromApp\x64\Release\RegFromApp.pdb

PE Imphash

cf1dc379315e990203818f00336d1d1f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c6e3 0x0000c800 6.10908463411
.rdata 0x0000e000 0x000035e8 0x00003600 4.72716219857
.data 0x00012000 0x000017c0 0x00000400 2.67180945689
.pdata 0x00014000 0x00000954 0x00000a00 4.44128181216
.rsrc 0x00015000 0x0000515c 0x00005200 4.8980415305

Resources

Name Offset Size Language Sub-language File type
BIN 0x000167e8 0x00001a00 LANG_ENGLISH SUBLANG_ENGLISH_US PE32+ executable (DLL) (GUI) x86-64, for MS Windows
BIN 0x000167e8 0x00001a00 LANG_ENGLISH SUBLANG_ENGLISH_US PE32+ executable (DLL) (GUI) x86-64, for MS Windows
RT_CURSOR 0x000181e8 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0001885c 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 14 x 14 x 4, image size 112, resolution 3780 x 3780 px/m
RT_BITMAP 0x0001885c 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 14 x 14 x 4, image size 112, resolution 3780 x 3780 px/m
RT_BITMAP 0x0001885c 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 14 x 14 x 4, image size 112, resolution 3780 x 3780 px/m
RT_ICON 0x00018d44 0x00000128 LANG_HEBREW SUBLANG_DEFAULT Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors
RT_ICON 0x00018d44 0x00000128 LANG_HEBREW SUBLANG_DEFAULT Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors
RT_ICON 0x00018d44 0x00000128 LANG_HEBREW SUBLANG_DEFAULT Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors
RT_MENU 0x0001914c 0x000001c4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0001914c 0x000001c4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000197a0 0x000001e2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000197a0 0x000001e2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000197a0 0x000001e2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000197a0 0x000001e2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00019c38 0x00000064 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00019c38 0x00000064 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00019c38 0x00000064 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00019c38 0x00000064 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x00019c9c 0x00000040 LANG_HEBREW SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00019cdc 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00019d14 0x00000014 LANG_HEBREW SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00019d14 0x00000014 LANG_HEBREW SUBLANG_DEFAULT data
RT_VERSION 0x00019d28 0x000002c8 LANG_HEBREW SUBLANG_DEFAULT data
RT_MANIFEST 0x00019ff0 0x0000016c LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x14000e488 _initterm
0x14000e490 __wgetmainargs
0x14000e498 _wcmdln
0x14000e4a0 exit
0x14000e4a8 _cexit
0x14000e4b0 _exit
0x14000e4b8 _c_exit
0x14000e4c0 _XcptFilter
0x14000e4c8 __C_specific_handler
0x14000e4d0 _onexit
0x14000e4d8 __dllonexit
0x14000e4e0 _wtol
0x14000e4e8 strlen
0x14000e4f0 _wcslwr
0x14000e4f8 _itow
0x14000e500 _wcsnicmp
0x14000e508 wcscmp
0x14000e510 ??3@YAXPEAX@Z
0x14000e518 __setusermatherr
0x14000e520 _commode
0x14000e528 _fmode
0x14000e530 __set_app_type
0x14000e538 malloc
0x14000e540 _wcsicmp
0x14000e548 _memicmp
0x14000e550 free
0x14000e558 wcschr
0x14000e560 modf
0x14000e568 ??2@YAPEAX_K@Z
0x14000e570 wcstoul
0x14000e578 strcpy
0x14000e580 memcmp
0x14000e588 wcsrchr
0x14000e590 wcslen
0x14000e598 memcpy
0x14000e5a0 _wtoi
0x14000e5a8 _purecall
0x14000e5b0 wcscpy
0x14000e5b8 memset
0x14000e5c0 _snwprintf
0x14000e5c8 wcsncat
0x14000e5d0 wcscat
Library COMCTL32.dll:
0x14000e000 None
0x14000e008 ImageList_Create
0x14000e010 ImageList_SetImageCount
0x14000e018 ImageList_AddMasked
0x14000e020 CreateToolbarEx
0x14000e028 CreateStatusWindowW
0x14000e030 ImageList_ReplaceIcon
Library KERNEL32.dll:
0x14000e080 WideCharToMultiByte
0x14000e088 SetErrorMode
0x14000e090 GetCurrentProcessId
0x14000e098 ExitProcess
0x14000e0a0 EnumResourceNamesW
0x14000e0a8 GetPrivateProfileIntW
0x14000e0b8 GetPrivateProfileStringW
0x14000e0c0 GetVersionExW
0x14000e0c8 FormatMessageW
0x14000e0d0 CreateRemoteThread
0x14000e0d8 EnumResourceTypesW
0x14000e0e0 GetStartupInfoW
0x14000e0e8 ResumeThread
0x14000e0f0 FreeLibrary
0x14000e0f8 LoadLibraryW
0x14000e100 GetProcAddress
0x14000e108 CloseHandle
0x14000e110 DeleteFileW
0x14000e118 WriteProcessMemory
0x14000e120 OpenProcess
0x14000e128 VirtualFreeEx
0x14000e130 Sleep
0x14000e138 ReadProcessMemory
0x14000e140 FlushFileBuffers
0x14000e148 GetTempPathW
0x14000e150 GetLastError
0x14000e158 VirtualAllocEx
0x14000e160 CreateProcessW
0x14000e168 GetCurrentProcess
0x14000e170 WaitForSingleObject
0x14000e178 GetModuleHandleW
0x14000e180 GetFileAttributesW
0x14000e188 WriteFile
0x14000e190 GetModuleFileNameW
0x14000e198 GetWindowsDirectoryW
0x14000e1a0 CreateFileW
0x14000e1a8 FindResourceW
0x14000e1b0 LocalFree
0x14000e1b8 LoadResource
0x14000e1c0 LockResource
0x14000e1c8 LoadLibraryExW
0x14000e1d0 SizeofResource
Library USER32.dll:
0x14000e218 TranslateMessage
0x14000e220 DispatchMessageW
0x14000e228 IsDialogMessageW
0x14000e230 SetTimer
0x14000e238 ChildWindowFromPoint
0x14000e240 SetCursor
0x14000e248 LoadCursorW
0x14000e250 GetSysColorBrush
0x14000e258 ShowWindow
0x14000e260 EndPaint
0x14000e268 GetMessageW
0x14000e270 DrawFrameControl
0x14000e278 SetWindowTextW
0x14000e280 UpdateWindow
0x14000e288 SetDlgItemTextW
0x14000e290 BeginPaint
0x14000e298 GetDlgItemTextW
0x14000e2a0 GetClientRect
0x14000e2a8 GetSystemMetrics
0x14000e2b0 DeferWindowPos
0x14000e2b8 CreateWindowExW
0x14000e2c0 SendDlgItemMessageW
0x14000e2c8 EndDialog
0x14000e2d0 GetWindowRect
0x14000e2d8 GetDlgItem
0x14000e2e0 InvalidateRect
0x14000e2e8 TranslateAcceleratorW
0x14000e2f0 SetMenu
0x14000e2f8 SetWindowPos
0x14000e300 GetWindowPlacement
0x14000e308 LoadAcceleratorsW
0x14000e310 DefWindowProcW
0x14000e318 SendMessageW
0x14000e320 PostMessageW
0x14000e328 RegisterClassW
0x14000e330 MessageBoxW
0x14000e338 LoadIconW
0x14000e340 LoadImageW
0x14000e348 SetWindowLongW
0x14000e350 GetWindowLongW
0x14000e358 EndDeferWindowPos
0x14000e360 BeginDeferWindowPos
0x14000e368 PeekMessageW
0x14000e370 CheckMenuItem
0x14000e378 GetMenuStringW
0x14000e380 CheckMenuRadioItem
0x14000e388 GetSysColor
0x14000e390 MapWindowPoints
0x14000e398 GetParent
0x14000e3a0 GetMenu
0x14000e3a8 GetDC
0x14000e3b0 EnableMenuItem
0x14000e3b8 GetSubMenu
0x14000e3c0 ReleaseDC
0x14000e3c8 GetClassNameW
0x14000e3d0 MoveWindow
0x14000e3d8 SetFocus
0x14000e3e0 GetMenuItemCount
0x14000e3e8 GetDlgCtrlID
0x14000e3f0 DestroyMenu
0x14000e3f8 DialogBoxParamW
0x14000e400 CreateDialogParamW
0x14000e408 EnumChildWindows
0x14000e410 LoadStringW
0x14000e418 DestroyWindow
0x14000e420 GetWindowTextW
0x14000e428 LoadMenuW
0x14000e430 ModifyMenuW
0x14000e438 GetMenuItemInfoW
0x14000e440 DestroyIcon
0x14000e448 DrawTextExW
0x14000e450 KillTimer
0x14000e458 PostQuitMessage
0x14000e460 GetWindow
Library GDI32.dll:
0x14000e040 SetBkMode
0x14000e048 DeleteObject
0x14000e050 SetTextColor
0x14000e058 CreateFontIndirectW
0x14000e060 SetBkColor
0x14000e068 SelectObject
0x14000e070 GetDeviceCaps
Library comdlg32.dll:
0x14000e470 GetSaveFileNameW
0x14000e478 GetOpenFileNameW
Library SHELL32.dll:
0x14000e1e0 DragQueryFileW
0x14000e1e8 DragAcceptFiles
0x14000e1f0 DragFinish
0x14000e1f8 ExtractIconExW
0x14000e200 SHGetFileInfoW
0x14000e208 ShellExecuteW
Library ole32.dll:
0x14000e5e0 CoUninitialize
0x14000e5e8 CoInitialize

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
WATAUH
0A]A\_
x ATAUAVH
A^A]A\
x ATAUAWH
@A_A]A\
t$ WATAWH
WATAUAVAWH
L9d$PA
u"L9d$Xu
A_A^A]A\_
t$ WATAU
WATAUH
A]A\_
x ATAUAVH
+L$DD+L$@
A^A]A\
WATAUH
@A]A\_
t$ WATAUAVAWH
D$Zs'3
A_A^A]A\_
x ATAUAVH
0A^A]A\
SUVWATAUAVAWH
XA_A^A]A\_^][
;QH}3
| ;Q(}
L$DD+D$H
~ 9yP~
x ATAUAWH
A_A]A\
l$ VWATAUAVH
A^A]A\_^
t$ WATAUAVAWH
A_A^A]A\_
uTf!T$ H
9Ypt 9YP~
UVWATAUH
@A]A\_^]
x ATAUAVH
9u@~^L
A^A]A\
WATAUH
x ATAUAVH
A^A]A\
WATAUAVAWH
A_A^A]A\_
WATAUH
9i@~AL
UVWATAUAVAWH
A_A^A]A\_^]
WATAUH
0A]A\_H
WATAUH
D+d$TH
l$\+t$@+l$T+\$D
UVWATAUH
E9kH~9H
A]A\_^]
udf!D$0H
f!t$0H
l$ VWATAUAVH
0A^A]A\_^
|$ ATH
LcD$ H
x ATAUAVH
A^A]A\
LcL$0LcD$8H
WATAUH
ATAUAWH
@A_A]A\
L$ UVWATAUAVAWH
t"IcD$
`A_A^A]A\_^]
9sx~^3
VWATAUAVH
A^A]A\_^
x ATAUAWH
@A_A]A\
8"u8fff
InitCommonControlsEx
StartHook
StopHook
GetModule
LoadLibraryW
FreeLibrary
GetProcAddress
GetModuleHandleW
GetLastError
IsWow64Process
ChangeWindowMessageFilter
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
CreateToolhelp32Snapshot
Module32First
Module32Next
Process32First
Process32Next
GetModuleBaseNameW
EnumProcessModules
GetModuleFileNameExW
EnumProcesses
GetModuleInformation
LdrGetProcedureAddress
SHGetSpecialFolderPathW
SHAutoComplete
c:\Projects\VS2005\RegFromApp\x64\Release\RegFromApp.pdb
wcscat
wcsncat
_snwprintf
memset
wcscpy
_purecall
memcpy
wcslen
wcsrchr
memcmp
strcpy
wcstoul
??2@YAPEAX_K@Z
wcschr
_memicmp
_wcsicmp
malloc
??3@YAXPEAX@Z
wcscmp
_wcsnicmp
_wcslwr
strlen
msvcrt.dll
__dllonexit
_onexit
__C_specific_handler
_XcptFilter
_c_exit
_cexit
_wcmdln
__wgetmainargs
_initterm
__setusermatherr
_commode
_fmode
__set_app_type
ImageList_ReplaceIcon
ImageList_Create
ImageList_SetImageCount
ImageList_AddMasked
CreateToolbarEx
CreateStatusWindowW
COMCTL32.dll
FreeLibrary
LoadLibraryW
GetProcAddress
CloseHandle
DeleteFileW
WriteProcessMemory
OpenProcess
ResumeThread
VirtualFreeEx
ReadProcessMemory
FlushFileBuffers
GetTempPathW
GetLastError
VirtualAllocEx
CreateProcessW
GetCurrentProcess
WaitForSingleObject
GetModuleHandleW
GetFileAttributesW
WriteFile
GetModuleFileNameW
GetWindowsDirectoryW
CreateFileW
FindResourceW
LocalFree
LoadResource
LockResource
LoadLibraryExW
SizeofResource
FormatMessageW
GetVersionExW
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileIntW
EnumResourceNamesW
WideCharToMultiByte
SetErrorMode
GetCurrentProcessId
ExitProcess
CreateRemoteThread
EnumResourceTypesW
GetStartupInfoW
KERNEL32.dll
ChildWindowFromPoint
SetCursor
LoadCursorW
GetSysColorBrush
ShowWindow
EndPaint
GetWindow
DrawFrameControl
SetWindowTextW
UpdateWindow
SetDlgItemTextW
BeginPaint
GetDlgItemTextW
GetClientRect
GetSystemMetrics
DeferWindowPos
CreateWindowExW
SendDlgItemMessageW
EndDialog
GetWindowRect
GetDlgItem
InvalidateRect
TranslateAcceleratorW
SetMenu
SetWindowPos
GetWindowPlacement
LoadAcceleratorsW
DefWindowProcW
SendMessageW
PostMessageW
RegisterClassW
MessageBoxW
LoadIconW
LoadImageW
SetWindowLongW
GetWindowLongW
EndDeferWindowPos
BeginDeferWindowPos
PeekMessageW
CheckMenuItem
GetMenuStringW
CheckMenuRadioItem
GetSysColor
MapWindowPoints
GetParent
GetMenu
EnableMenuItem
GetSubMenu
ReleaseDC
GetClassNameW
MoveWindow
SetFocus
GetMenuItemCount
GetDlgCtrlID
DestroyMenu
DialogBoxParamW
CreateDialogParamW
EnumChildWindows
LoadStringW
DestroyWindow
GetWindowTextW
LoadMenuW
ModifyMenuW
GetMenuItemInfoW
DestroyIcon
DrawTextExW
KillTimer
PostQuitMessage
GetMessageW
SetTimer
IsDialogMessageW
DispatchMessageW
TranslateMessage
USER32.dll
DeleteObject
SetBkMode
CreateFontIndirectW
SetTextColor
GetDeviceCaps
SelectObject
SetBkColor
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
comdlg32.dll
ShellExecuteW
SHGetFileInfoW
ExtractIconExW
DragFinish
DragAcceptFiles
DragQueryFileW
SHELL32.dll
CoUninitialize
CoInitialize
ole32.dll
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
ntdll.dll
NtSetValueKey
NtQueryObject
NtOpenKey
NtClose
NtQueryValueKey
NtDeleteValueKey
_stricmp
memcmp
malloc
msvcrt.dll
_initterm
_adjust_fdiv
GetCurrentProcess
WriteProcessMemory
VirtualProtectEx
LoadLibraryW
GetVersionExW
GetProcAddress
GetCurrentProcessId
GetModuleHandleW
KERNEL32.dll
PostMessageW
SendMessageW
USER32.dll
memset
RegFromAppHelper.dll
GetModule
StartHook
StopHook
f:\Projects\VS2005\RegFromApp\release\RegFromAppHelper.pdb
W0^0o0
1'1-131P1
1"272S2y2
41484Q4j4
5"5(5/555<5B5I5O5V5\5e5k5
6(6.646:6H6P6Y6a6n6v6
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
VWATAUAVH
PHcB<E3
A^A]A\_^
VWATAUAV
L$8H!D$8H
D$(!\$ D
D!l$@H
A^A]A\_^
WATAUAVAWH
0A_A^A]A\_
ntdll.dll
NtSetValueKey
NtQueryObject
NtOpenKey
NtClose
NtQueryValueKey
NtDeleteValueKey
f:\Projects\VS2005\RegFromApp\x64\Release\RegFromAppHelper.pdb
_stricmp
memcmp
malloc
msvcrt.dll
_initterm
GetCurrentProcess
WriteProcessMemory
VirtualProtectEx
GetProcAddress
GetCurrentProcessId
GetModuleHandleW
LoadLibraryW
GetVersionExW
KERNEL32.dll
SendMessageW
PostMessageW
USER32.dll
memset
RegFromAppHelper.dll
GetModule
StartHook
StopHook
wwwwwp
wwwwwwwwp
wwwww~gwwwwwwwwwwwwwwwwwwp
wwwwwN
xwwwwwpwwwww~fwwwwwwwwwwwwwwwwwwxwwwwww
wwwwwwwwwwwwwx
pwwwpw~fhwwr
wwwwww
'wwwww
hwwr'wwwwww
wwwwwx
hwwwwwwwwwwwwwwwwwx
wwwwwwwwx
xwwwwp
wwwwwwwwwwwwwwwwwx
wwwwwwwwx
wwwwwwwwwwwwwwwwwwwwwwwwwwx
wwwwwwwwwwwwww
""""""
wwwwwwwx ww
DDDDDDD
DDDDDDH"
DDDDDDH/
DDDDDDD
wwwwwwwx
DDDDDD
wwwwww
DDDDDD
wwwwww
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="amd64" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD`
AddTrust AB1&0$
AddTrust External TTP Network1"0
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
100510000000Z
150510235959Z0~1
Greater Manchester1
Salford1
COMODO CA Limited1$0"
COMODO Time Stamping Signer0
GS@(YC
1http://crl.usertrust.com/UTN-USERFirst-Object.crl05
http://ocsp.usertrust.com0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110824000000Z
200530104838Z0{1
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
140912000000Z
190912235959Z0
525831
Gush Dan1
Ramat Gan1
5 Hashoshanim st.1
Nir Sofer1
Nir Sofer0
z<%()S
https://secure.comodo.net/CPS0A
0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
http://ocsp.comodoca.com0
support@nirsoft.net0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 2
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object
141221064619Z0#
MS Sans Serif
RegFromApp
RegFileVersion
AddOnlyModifiedValues
DisplayMode
ProcessPath
ProcessParams
StartImmediately
ListViewSortProcess
comctl32.dll
Error: Cannot load the common control classes.
RegFromAppHelper.dll
kernel32.dll
"%s" %s
netmsg.dll
Unknown Error
Error %d: %s
%2.2X
%s (%s)
kernel32
caption
menu_%d
dialog_%d
strings
general
sysdatetimepick32
charset
TranslatorName
TranslatorURL
Version
_lng.ini
%-18s: %s
%%-%d.%ds
<td bgcolor=#%s nowrap>%s
<td bgcolor=#%s>%s
&nbsp;
<tr><td%s nowrap><b>%s</b><td bgcolor=#%s%s>%s
bgcolor="%s"
<table border="1" cellpadding="5">
nowrap
<font color="%s">%s</font>
</table><p>
<item>
<%s>%s</%s>
</item>
<?xml version="1.0" encoding="ISO-8859-1" ?>
user32.dll
/nosaveload
report.html
Fixedsys
%s - %s
General
WinPos
/runprocess
/processparams
/startimmediately
/attachprocess
/autosave
SeDebugPrivilege
/savelangfile
/deleteregkey
{Unknown}
Exception %8.8X at address %16.16I64X in module %s
Registers:
EAX=%16.16I64X EBX=%16.16I64X ECX=%16.16I64X EDX=%16.16I64X
ESI=%16.16I64X EDI=%16.16I64X EBP=%16.16I64X ESP=%16.16I64X
EIP=%16.16I64X
Stack Data: %s
Code Data: %s
advapi32.dll
psapi.dll
\systemroot
ntdll.dll
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
\REGISTRY\MACHINE
\REGISTRY\USER
_CLASSES
HKEY_CURRENT_USER\Software\Classes
dword:%8.8x
hex(%x):
Windows Registry Editor Version 5.00
REGEDIT4
shell32.dll
Wshlwapi.dll
%2.2X%2.2X%2.2X
&quot;
size="%d"
color="#%s"
</font>
advapi32.dll
kernel32.dll
kernelbase.dll
ntdll.dll
advapi32.dll
kernel32.dll
kernelbase.dll
ntdll.dll
&Start With Existing Process
Start &New Process
Ctrl+N
&Clear
Ctrl+X
Save &As
Ctrl+S
Ctrl+C
Select &All
Ctrl+A
Deselect All
Ctrl+D
&Options
&RegEdit File Version
Version 4
Version 5
&Display Mode
Show &Last Modified Values
Show &Original Values
Add Only &Modified Values
&About
Popup1
&Save Selected Items
Ctrl+S
&Copy Selected Items
Ctrl+C
HTML Report - All Items
HTML Report - Selected Items
Choose Colum&ns
&Auto Size Columns
Ctrl+Plus
&Properties
Alt+Enter
&Refresh
Exception !
MS Sans Serif
Copy Exception
Continue
Terminate Application
The following application error has occurred:
If this problem persists, copy the above exception information to the clipboard, and send it to the author of this software.
MS Sans Serif
Translation:
Select process to inspect
MS Shell Dlg
Cancel
SysListView32
Start New Process
MS Shell Dlg
Cancel
Process:
Browse...
Parameters:
Start tracing immediately
Select a filename to save
Select a process file to open7Failed to connect the selected process. Error code: %d=Failed to start with the new selected process. Error code: %dSIn order to trace 32-bit programs, you have to use the 32-bit version of RegFromApp
Loading... %d
Windows Registry File
Item Name
Process ID
Process Name
Process Path
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
NirSoft
FileDescription
RegFromApp
FileVersion
InternalName
RegFromApp
LegalCopyright
Copyright
2008 - 2014 Nir Sofer
OriginalFilename
RegFromApp.exe
ProductName
RegFromApp
ProductVersion
VarFileInfo
Translation
<<<Obsolete>>
Antivirus Result
Bkav None
Lionic None
Elastic None
ClamAV None
CMC None
CAT-QuickHeal None
Skyhigh None
ALYac None
Cylance None
Zillya None
Sangfor None
CrowdStrike None
Alibaba None
K7GW None
K7AntiVirus None
huorong None
Baidu None
VirIT None
Paloalto None
Symantec None
tehtris None
ESET-NOD32 None
APEX None
Avast None
Cynet None
Kaspersky None
BitDefender None
ViRobot None
MicroWorld-eScan None
Tencent None
Sophos None
F-Secure None
DrWeb None
VIPRE None
TrendMicro None
McAfeeD None
Trapmine None
CTX None
Emsisoft None
Ikarus None
GData None
Jiangmin None
Webroot None
Varist None
Avira None
Antiy-AVL None
Kingsoft None
Gridinsoft None
Xcitium None
Arcabit None
SUPERAntiSpyware None
ZoneAlarm None
Microsoft None
Google None
AhnLab-V3 None
Acronis None
VBA32 None
TACHYON None
Malwarebytes None
Panda None
Zoner None
TrendMicro-HouseCall None
Rising None
Yandex None
TrellixENS None
SentinelOne None
MaxSecure None
Fortinet None
AVG None
DeepInstinct None
alibabacloud None
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Clean
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Clean
G Data Antivirus (Windows) Clean
WithSecure (Linux) Clean
ESET Security (Windows) Clean
DrWeb Antivirus (Linux) Clean
ClamAV (Linux) Clean
eScan Antivirus (Linux) Clean
Kaspersky Standard (Windows) Clean
Emsisoft Commandline Scanner (Windows) Clean
Cuckoo

We're processing your submission... This could take a few seconds.