Lines Matching +full:0 +full:x40004000

26 0	string	\xCF\xAD\x12\xFE
28 >0x7C ulelong >0 MS Outlook Express DBX file
33 >>4 byte =0xC5 \b, message database
34 >>4 byte =0xC6 \b, folder database
35 >>4 byte =0xC7 \b, account information
36 >>4 byte =0x30 \b, offline database
38 >>20 ulequad !0x0000000500000005 \b, version
47 >>0x7C ulelong x \b, ~ %u bytes
49 >>0x5c ulelong x \b, highest ID %#x
51 >>0xC4 ulelong x \b, %u item
53 >>0xC4 ulelong !1 \bs
55 >>0xE4 ulelong >0 \b, index pointer %#x
67 0 ubelong 0x0DF0ADBA MS Outlook Nickfile
76 # Unknown2; probably a version indicator like: 1 0
91 >20 uleshort =0x001F
108 0 string PAGE
128 >>32 ulelong !0x14c \b, MachineImageType %#x
133 # BugcheckParameter1 like: 0
135 # BugcheckParameter2 like: 0
137 # BugcheckParameter3 like: 0
139 # BugcheckParameter4 like: 0
145 >>0x05c byte 0 \b, no PAE
146 >>0x05c byte 1 \b, PAE
162 >>0xf88 lelong 1 \b, full dump
163 >>0xf88 lelong 2 \b, kernel dump
164 >>0xf88 lelong 3 \b, small dump
166 >>0xf88 lelong >3 \b, dump type (%#x)
170 >>0x068 lelong x \b, %d pages
192 >>48 ulelong !0x8664 \b, MachineImageType %#x
212 # WinDumpPhyMemDesc64 NumberOfRuns like: 6 7 0x45474150
214 # WinDumpPhyMemDesc64 unused like: 0 0x45474150
235 #>>3872 ulequad x \b, ExceptionInformation[0] %#llx
238 >>0xf98 ulelong x \b,
239 >>>0xf98 lelong 5 full dump
240 >>>0xf98 lelong 6 kernel dump
241 >>>0xf98 lelong 4 small dump
243 >>>0xf98 default x DumpType
244 >>>>0xf98 ulelong x (%#x)
247 >>0x090 lequad x \b, %lld pages
258 0 string ElfFile\0 MS Windows
263 >0x24 ulelong =0x00030001 Vista-8.1 Event Log
264 >0x24 ulelong !0x00030001 10-11 Event Log, version
265 >>0x26 uleshort x %u
266 >>0x24 uleshort x \b.%u
267 >0x2a leshort x \b, %d chunks
268 >>0x10 lelong x \b (no. %d in use)
269 >0x18 lelong >1 \b, next record no. %d
270 >0x18 lelong =1 \b, empty
271 >0x78 lelong &1 \b, DIRTY
272 >0x78 lelong &2 \b, FULL
283 0 ubyte 0
285 >0 search/0x699087/b .\0e\0t\0l\0\0\0
287 >>0 use trace-etl
289 0 name trace-etl
290 >0 ubyte x Windows Event Trace Log
296 >0 search/0x2b4/sb :\0\x5c\0
297 # like: "c:\Windows\Logs\NetSetup\service.0.etl" "C:\Windows\System32\LogFiles\WMI\Wifi.etl"
304 0 string $SDI
310 # MDBtype: 0~Unspecified 1~RAM 2~ROM
311 >>8 ulequad !0 \b, MDBtype %#llx
313 >>16 ulequad !0 \b, BootCodeOffset %#llx
315 >>24 ulequad !0 \b, BootCodeSize %#llx
317 >>32 ulequad !0 \b, VendorID %#llx
319 >>40 ulequad !0 \b, DeviceID %#llx
321 >>48 ulequad !0 \b, DeviceModel %#llx
322 >>>56 ulequad !0 \b%llx
324 >>64 ulequad !0 \b, DeviceRole %#llx
325 # Reserved1; reserved fields and gaps between BLOBs are padded with \0
326 #>>72 ulequad !0 \b, Reserved1 %#llx
328 >>80 ulequad !0 \b, RuntimeGUID %#llx
329 >>>88 ulequad !0 \b%llx
331 >>96 ulequad !0 \b, RuntimeOEMrev %#llx
333 #>>104 ulequad !0 \b, Reserved2 %#llx
335 >>112 ulequad !0 \b, PageAlignment %llu
337 #>>120 ulequad !0 \b, Reserved3 %#llx
339 >>0x1f8 ulequad x \b, checksum %#llx
340 # BLOBtype[8] \0-padded: PART, WIM , BOOT, LOAD, DISK
341 >>0x400 string >\0 \b, type %-3.8s
342 # 0~non-filesystem 7~NTFS 6~BIGFAT
343 >>>0x420 ulequad !0 (%#llx)
345 >>>0x408 ulequad !0 %#llx attributes
347 >>>0x410 ulequad x at %#llx
349 >>>0x418 ulequad >0 %llu bytes
350 >>>>(0x410.l) indirect x
352 >>0x440 string >\0 \b, type %-3.8s
353 >>>0x428 ulequad !0 (%#llx)
355 >>>0x448 ulequad !0 %#llx attributes
357 >>>0x450 ulequad x at %#llx
358 >>>0x458 ulequad >0 %llu bytes
359 >>>>(0x450.l) indirect x
361 >>0x480 string >\0 \b, type %-3.8s
369 0 ulelong <5
371 >8 ulelong =0x00010000
372 >>0 use bootstat-dat
374 0 name bootstat-dat
375 >0 ulelong x Windows boot log
381 >0 ulelong >2 \b, version %u
383 >4 ulelong !0x10 \b, header size %#x
384 #>4 ulelong !0x10 \b, header size %u
385 # apparently the size of the file: always 0x00010000~64KiB
387 >8 ulelong !0x00010000 \b, file size %#x
389 >0xc ulelong x \b, %#x valid bytes
391 >(0x4.l-1) ubyte x
392 >>&0 use bootstat-entry
394 >(0x4.l-1) ubyte x
396 >>&(&0x18.l-1) ubyte x
397 >>>&0 use bootstat-entry
399 # >(0x4.l-1) ubyte x
400 # >>&(&0x18.l-1) ubyte x
401 # >>>&(&0x18.l-1) ubyte x
402 # >>>>&0 use bootstat-entry
404 0 name bootstat-entry
405 #>0x00 ubequad x \b, ENTRY %16.16llx
407 #>0x18 ulelong x \b; entry size %u
408 >0x18 ulelong x \b; entry size %#x
410 >0x00 ulelong x \b, %#x seconds
412 >0x04 ulelong !0 \b, not null %u
414 >0x08 ubequad !0 \b, GUID %#16.16llx
415 >>0x10 ubequad x \b%16.16llx
417 >0x1C ulelong !1 \b, severity %#x
419 >0x20 ulelong !2 \b, version %u
421 #>0x24 ulelong x \b, event %#x
422 >0x24 ulelong !1
423 >>0x24 ulelong !0x11 \b, event %#x
425 #>0x28 ubequad x \b, data %#16.16llx
426 >0x24 ulelong =0x1 \b, Init
427 # always 0, significance unknown
428 >>0x34 uleshort !0 \b, not null %u
430 >>0x36 uleshort !7 \b, not seven %u
432 >>0x28 uleshort x %u
434 >>0x2A uleshort x \b-%u
436 >>0x2C uleshort x \b-%u
438 >>0x2E uleshort x %u
440 >>0x30 uleshort x \b:%u
442 >>0x32 uleshort x \b:%u
444 >0x24 ulelong =0x11 \b, launched
445 # type of start: 0 normally, 1 or 2 maybe in a recovery sequence
446 >>0x38 uleshort !0 \b, type %u
449 >>0x3C lestring16 x %s
457 0 lestring16 Version=
466 0 string \120\115\103\103 MS Windows 3.1 group files
476 0 name help-ver-date
478 >0 leshort 0x036C
522 >>>>>14 pstring/h >\0 \b, title "%s"
528 0 lelong 0x00035f3f
530 # file header magic 0x293B at DirectoryStart+9
531 >(4.l+9) uleshort 0x293B MS
535 >>0xD4 string =\x62\x6D\x66\x01\x00 Windows help annotation
538 >>0xD4 string !\x62\x6D\x66\x01\x00
541 >>>(4.l+0x65) search/26 |Pete Windows help Global Index
547 >>>(4.l+0x65) default x
549 # brute search for Magic 0x036C with matching Major maximal 13 iterations
551 >>>>16 search/0x1bbc370/s \x6c\x03
552 >>>>>&0 use help-ver-date
555 >>>>>>&-2 search/0x1c4b6f0/s \x6c\x03
556 >>>>>>>&0 use help-ver-date
559 >>>>>>>>&0 search/0x34ab80/s \x6c\x03
560 >>>>>>>>>&0 use help-ver-date
562 >>>>>>>>>>&0 search/0x473ab0/s \x6c\x03
563 >>>>>>>>>>>&0 use help-ver-date
565 >>>>>>>>>>>>&0 search/0x739680/s \x6c\x03
566 >>>>>>>>>>>>>&0 use help-ver-date
568 >>>>>>>>>>>>>>&0 search/0x76c030/s \x6c\x03
569 >>>>>>>>>>>>>>>&0 use help-ver-date
571 >>>>>>>>>>>>>>>>&0 search/0x805c80/s \x6c\x03
573 >>>>>>>>>>>>>>>>>&0 use help-ver-date
575 >>>>>>>>>>>>>>>>>>&0 search/0x805c80/s \x6c\x03
576 >>>>>>>>>>>>>>>>>>>&0 use help-ver-date
578 >>>>>>>>>>>>>>>>>>>>&0 search/0xb63480/s \x6c\x03
579 >>>>>>>>>>>>>>>>>>>>>&0 use help-ver-date
581 >>>>>>>>>>>>>>>>>>>>>>&0 search/0xb7fe80/s \x6c\x03
582 >>>>>>>>>>>>>>>>>>>>>>>&0 use help-ver-date
584 >>>>>>>>>>>>>>>>>>>>>>>>&0 search/0xb8ade0/s \x6c\x03
585 >>>>>>>>>>>>>>>>>>>>>>>>>&0 use help-ver-date
587 >>>>>>>>>>>>>>>>>>>>>>>>>>&0 search/0x371d4/s \x6c\x03
588 >>>>>>>>>>>>>>>>>>>>>>>>>>>&0 use help-ver-date
590 >>>>>>>>>>>>>>>>>>>>>>>>>>>>&0 search/0x371d4/s \x6c\x03
591 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>&0 use help-ver-date
594 >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>8 lelong !0xFFffFFff Windows Multimedia Viewer Book
598 >>>>16 search/0x49AF/s \x6c\x03
614 ## file header magic 0x293B
616 ## file header Flags 0x0402
621 #>>(4.l+15) string >\0 \b, Structure_"%-.16s"
622 ## MustBeZero 0
628 ## MustBeNegOne 0xffff
632 ## NLevels 0x0001
641 >(4.l+9) uleshort !0x293B MS Windows Multimedia Viewer Book
650 0 regex \^(:|;)
652 >0 search/45 :Base
653 >>&0 use cnt-name
655 >0 search/45 :Base
656 >0 default x
658 >>0 search/45 :Title
659 >>>&0 use cnt-name
662 0 name cnt-name
664 >0 string \040
674 0 string tfMR MS Windows help Full Text Search index
678 >16 string >\0 for "%s"
682 0 string gfMR MS Windows help Full Text search Group
686 >16 string >\0 for "%s"
695 0 string HyperTerminal\040
714 0 string \114\0\0\0\001\024\002\0\0\0\0\0\300\0\0\0\0\0\0\106 MS Windows shortcut
738 #>>>&0 string x '%s'
751 #>>>&0 string x '%s'
761 #>>>&0 string x '%s'
773 >20 lelong&262144 0
774 # look for BlockSize 60h, TrackerDataBlock BlockSignature A0000003h, it length 58h and Version 0
775 >>76 search/1972 \x60\x00\x00\x00\x03\x00\x00\xa0\x58\x00\x00\x00\0\0\0\0
777 >>>&0 string x \b, MachineID %0.16s
792 >20 lelong&2097152 0
799 >>>&0 guid x KnownFolderID %s
833 >28 leqwdate !0 \b, ctime=%s
835 >36 leqwdate !0 \b, atime=%s
837 >44 leqwdate !0 \b, mtime=%s
847 >64 uleshort >0 \b, hot key
850 # modifier keys: 0x01~HOTKEYF_SHIFT 0x02~HOTKEYF_CONTROL 0x04~HOTKEYF_ALT
855 #>66 uleshort !0 \b, reserved %#x
857 #>68 ulelong !0 \b, reserved2 %#x
859 #>72 ulelong !0 \b, reserved3 %#x
867 >>(78.s+78) uleshort >0
870 >>>&(&-2.s-2) uleshort >0
873 >>>>&(&-2.s-2) uleshort >0
878 >>20 lelong&1 =0
882 >>>76 uleshort >0
890 0 name lnk-item
891 # size value 0x0000 means TerminalID; indicates the end of the item IDs list
892 >0 uleshort >0
893 #>>0 uleshort x \b, ItemIDSize %#4.4x
897 >>2 ubyte =0x1f \b, Root folder
902 >>2 ubyte =0x2f \b, Volume
908 0 name lnk-info
910 >0 ulelong x \b, LinkInfoSize %#x
940 0 lelong 0x4E444221
948 #>>4 ulelong !0 \b, CRC %#x
954 >>8 leshort 0x4142 Personal Address Book
961 #>>8 leshort 0x4D53 \b, PST~
963 >>8 leshort 0x4D53 Personal Storage
968 >>8 leshort 0x4F53 Offline Storage
974 >>10 leshort <0x10 \b<=2002, ANSI,
975 >>10 leshort >0x14 \b>=2003, Unicode,
984 >>16 ulelong !0 \b, dwReserved1=%#x
986 >>20 ulelong !0 \b, dwReserved2=%#x
990 #>>>24 ulelong !0 \b, bidNextB=%#x
992 #>>>28 ulelong !0 \b, bidNextP=%#x
994 >>>32 ulelong !0 \b, dwUnique=%#x
998 >>>164 ulelong !0 \b, dwReserved=%#x
1003 # bSentinel; MUST be set to 0x80
1004 >>>460 ubyte !0x80 \b, bSentinel=%#x
1005 # bCryptMethod: 0~No encryption 1~encryption with permutation 2~encryption with cyclic 16~encryptio…
1006 >>>461 ubyte >0 \b, bCryptMethod=%u
1009 # bidUnused; Unused 8 bytes padding (Unicode only); sometimes like: 0x0000000100000004
1010 >>>24 ulequad !0x0000000100000004 \b, bidUnused=%#16.16llx
1012 >>>40 ulelong !0 \b, dwUnique=%#x
1017 # bSentinel; MUST be set to 0x80
1018 >>>512 ubyte !0x80 \b, bSentinel=%#x
1019 # bCryptMethod; Encryption type like: 0 1 2 16
1020 >>>513 ubyte >0 \b, bCryptMethod=%u
1027 0 string \164\146\115\122\012\000\000\000\001\000\000\000 MS Windows help cache
1032 0 string Client\ UrlCache\ MMF Internet Explorer cache file
1033 >20 string >\0 version %s
1039 0 string regf MS Windows registry file, NT/2000 or above
1040 0 string CREG MS Windows 95/98/ME registry file
1041 0 string SHCC3 MS Windows 3.1 registry file
1050 0 string REGEDIT
1057 >>0 string REGEDIT4 (Win95 or above)
1059 0 string Windows\ Registry\ Editor\
1060 >&0 string Version\ 5.00\r\n\r\n Windows Registry text (Win2K or above)
1065 >0x32 lestring16 Version\ 5.00\r\n\r\n Windows Registry little-endian text (Win2K or above)
1067 #>&0 lestring16 Version\ 5.00\r\n\r\n Windows Registry little-endian text (Win2K or above)
1075 0 string WINE\ REGISTRY\ Version\ WINE registry text
1077 >&0 string x \b, version %s
1084 #0 regex/s \\`(\\r\\n|;|[[])
1086 0 ubeshort 0x0D0A
1087 >0 use ini-file
1089 0 string ;
1096 >>0 use ini-file
1098 0 string [
1099 >0 use ini-file
1101 0 name ini-file
1103 >0 search/8192 [
1109 >>&0 regex/c \^autorun
1113 >>>&0 string =]\r\n[ Total commander directory treeinfo.wc
1118 >>>&0 string !]\r\n[ Microsoft Windows Autorun file
1123 >>&0 regex/c \^(version|strings)] Windows setup INFormation
1128 >>&0 regex/c \^(WinsockCRCList|OEMCPL)] Windows setup INFormation
1134 >>&0 regex/1024c \^(\\.ShellClassInfo|DeleteOnCopy|LocalizedFileNames)] Windows desktop.ini
1138 >>&0 regex/c \^don't\ load] Windows CONTROL.INI
1141 >>&0 regex/c \^(ndishlp\\$|protman\\$|NETBEUI\\$)] Windows PROTOCOL.INI
1146 >>&0 regex/c \^(windows|Compatibility|embedding)] Windows WIN.INI
1150 >>&0 regex/c \^(boot|386enh|drivers)] Windows SYSTEM.INI
1154 >>&0 regex/c \^SafeList] Windows IOS.INI
1158 >>&0 regex/c \^boot\x20loader] Windows boot.ini
1162 >>&0 regex/c \^menu] MS-DOS CONFIG.SYS
1169 >>&0 regex/c \^Paths]\r\n MS-DOS MSDOS.SYS
1172 >>&0 regex/c \^options]\r\n Microsoft HTML Help Project
1181 >>&0 regex/c \^Windows\ (Latin|Cyrillic) Windows codepage translator
1190 >>&0 regex/c \^Shell]\r\n Windows Explorer Shell Command File
1197 >>>>&0 string x "%s"
1202 >>&0 regex/c \^SCF]\r\n VIA setup configuration
1211 >>&0 regex/c \^Languages] InstallShield Language Identifier
1220 >>&0 regex/c \^TagInfo] TagInfo
1229 >>&0 string Flatpak\ Ref] Flatpak repository reference
1239 >>&0 string CloneCD] CloneCD CD-image Description
1244 >>&0 default x
1245 #>>>&0 string/c x UNKNOWN [%s
1247 >>>&0 search/8192 [
1249 >>>>&0 string/c version Windows setup INFormation
1255 >>>>&0 string FileExplorer] cdrtfe Project
1259 >>>>&0 default x
1260 >>>>>&0 ubyte x
1271 #>>>&0 default x Generic INItialization configuration
1272 #>>>>0 string x \b, 1st line "%s"
1274 0 ubeshort =0xFFFE
1277 >2 search/0x384A E\0N\0D\0\040\0C\0A\0T\0E\0G\0O\0R\0Y\0
1278 >>0 use windows-adm
1281 # UTF-16 BOM followed by CR~0D00 , comment~semicolon~3B00 , section~bracket~5B00
1282 >>0 ubelong&0xFFff89FF =0xFFFE0900
1301 >>>>>&0 search/8192 \x0A\x00\x5b
1313 0 search/0x4E CLASS\040
1314 >&0 string MACHINE
1315 >>0 use windows-adm
1316 >&0 string USER
1317 >>0 use windows-adm
1319 0 name windows-adm Windows Policy Administrative Template
1323 >0 ubeshort =0xFFFE
1326 >>>2 search/0x3A \r\0\n\0
1327 >>>>&0 lestring16 x \b, 2nd line "%s"
1329 >0 ubeshort !0xFFFE
1330 >>0 string x \b, 1st line "%s"
1331 #>>>&0 ubequad x \b, 2ND %16.16llx
1333 >>>&2 beshort =0x0D0A
1334 >>>>&0 beshort !0x0D0A \b, 3th line
1337 >>>&2 beshort !0x0D0A \b, 2nd line
1346 0 leshort&0xFcFc =0x0000
1348 >0 leshort&0x0303 !0x0000
1350 >>2 uleshort >0
1353 #>>>>0x59 search/18 :
1355 …e (money-256.tga XING_B_UCM8.tga x-fmt-367-signature-id-604.tga) with "invalid low section name" \0
1356 >>>>(20.l) ubelong >0x40004000
1357 >>>>>0 use PreCompiledInf
1358 0 name PreCompiledInf
1359 >0 uleshort x Windows Precompiled iNF
1365 >0 ubyte x \b.%u
1366 >0 uleshort =0x0101 (Windows
1367 >>4 ulelong&0x00000001 !0x00000001 95-98)
1368 >>4 ulelong&0x00000001 =0x00000001 XP)
1369 >0 uleshort =0x0301 (Windows Vista-8.1)
1370 >0 uleshort =0x0302 (Windows 10 older)
1371 >0 uleshort =0x0303 (Windows 10-11)
1374 # PNF_FLAG_IS_UNICODE 0x00000001
1375 # PNF_FLAG_HAS_STRINGS 0x00000002
1376 # PNF_FLAG_SRCPATH_IS_URL 0x00000004
1377 # PNF_FLAG_HAS_VOLATILE_DIRIDS 0x00000008
1378 # PNF_FLAG_INF_VERIFIED 0x00000010
1379 # PNF_FLAG_INF_DIGITALLY_SIGNED 0x00000020
1380 # UNKNOWN8 0x00000080
1381 # UNKNOWN 0x00000100
1382 # UNKNOWN1 0x01000000
1383 # UNKNOWN2 0x02000000
1384 >4 ulelong&0x03000180 >0 \b, flags
1386 >4 ulelong&0x00000001 0x00000001 \b, unicoded
1387 >4 ulelong&0x00000002 0x00000002 \b, has strings
1388 >4 ulelong&0x00000004 0x00000004 \b, src URL
1389 >4 ulelong&0x00000008 0x00000008 \b, volatile dir ids
1390 >4 ulelong&0x00000010 0x00000010 \b, verified
1391 >4 ulelong&0x00000020 0x00000020 \b, digitally signed
1392 # >4 ulelong&0x00000080 0x00000080 \b, UNKNOWN8
1393 # >4 ulelong&0x00000100 0x00000100 \b, UNKNOWN
1394 # >4 ulelong&0x01000000 0x01000000 \b, UNKNOWN1
1395 # >4 ulelong&0x02000000 0x02000000 \b, UNKNOWN2
1397 # many 0, 1 lmouusb.PNF, 2 linkfx10.PNF , f webfdr16.PNF
1402 # only found values lower 0x0000ffff ??
1404 # only found positive values lower 0x00ffFFff for InfVersionDataOffset
1406 >4 ulelong&0x00000001 =0x00000001
1409 >4 ulelong&0x00000001 !0x00000001
1415 >0 uleshort <0x0102
1416 # only found values lower 0x00ffFFff
1431 >>>4 ulelong&0x00000001 =0x00000001
1432 #>>>>(68.l) ubequad =0x43003a005c005700
1435 >>>>(68.l) ubequad !0x43003a005c005700
1437 >>>4 ulelong&0x00000001 !0x00000001
1442 # found OsLoaderPathOffset values often 0 , once 70h corelist.PNF, once 68h ASCII machine.PNF
1443 >>>72 ulelong >0 \b,
1444 >>>>4 ulelong&0x00000001 =0x00000001
1446 >>>>4 ulelong&0x00000001 !0x00000001
1453 >>>78 uleshort !0x409 \b, LanguageID %x
1454 #>>>78 uleshort =0x409 \b, LanguageID %x
1455 # InfSourcePathOffset often 0
1456 >>>80 ulelong >0 \b, at %#x
1457 >>>>4 ulelong&0x00000001 =0x00000001
1459 >>>>4 ulelong&0x00000001 !0x00000001
1460 >>>>>(80.l) string >\0 SourcePath "%s"
1461 # OriginalInfNameOffset often 0
1462 >>>84 ulelong >0 \b, at %#x
1463 >>>>4 ulelong&0x00000001 =0x00000001
1465 >>>>4 ulelong&0x00000001 !0x00000001
1466 >>>>>(84.l) string >\0 InfName "%s"
1469 >0 uleshort >0x0101
1471 >>>4 ulelong&0x00000001 0x00000001
1473 #>>>>(80.l) ubequad =0x43003a005c005700
1475 >>>>(80.l) ubequad !0x43003a005c005700
1477 # language id: 0 407h~german 409h~English_US
1478 >>90 uleshort !0x409 \b, LanguageID %x
1479 #>>90 uleshort =0x409 \b, LanguageID %x
1480 >>92 ulelong >0 \b, at %#x
1481 >>>4 ulelong&0x00000001 0x00000001
1491 0 string TAPE
1493 >20 ulequad 0
1495 >>28 uleshort 0
1497 >>>36 ulelong 0
1499 >>>>4 ulelong&0xFFfcFFe0 0 Windows NTbackup archive
1514 #>>>>>4 ulelong&0x00000001 !0 \b, continued
1516 >>>>>4 ulelong&0x00000004 !0 \b, compressed
1518 >>>>>4 ulelong&0x00000008 !0 \b, End Of Medium hit
1519 >>>>>4 ulelong&0x00020000 0
1521 >>>>>>4 ulelong&0x00010000 !0 \b, with catalog
1523 >>>>>4 ulelong&0x00020000 !0 \b, with file catalog
1535 >>>>>62 uleshort >0 \b, %#x encrypted
1542 >>>>>68 uleshort >0
1544 >>>>>>70 uleshort >0
1545 # 0~, 1~ANSI, 2~UNICODE
1548 >>>>>>>>(70.s) string >\0 \b, name: %s
1553 #>>>>>72 uleshort >0
1555 >>>>>74 uleshort >0
1558 >>>>>>>(74.s) string >\0 \b, label: %s
1561 # size of password name (0,1Ch)
1562 #>>>>>76 uleshort >0 \b, password size %4.4x
1566 >>>>>80 uleshort >0
1568 >>>>>>82 uleshort >0
1571 >>>>>>>>(82.s) string >\0 \b: %s
1588 0 string JASC-PAL\r\n PaintShop Pro color palette
1603 0 string Inno\ Setup\ Uninstall\ Log\ (b) InnoSetup Log
1608 >0x1c string >\0 \b%.7s
1609 # AppName[0x80] like "Minimal SYStem", ClamWin Free Antivirus , ...
1610 >0xc0 string x %s
1611 # AppId[0x80] is similar to AppName or
1613 >0x40 ubyte 0x7b
1614 >>0x40 string x %-.38s
1616 >0x140 ulelong x \b, version %#x
1618 #>0x144 ulelong x \b, %#4.4x records
1620 >0x148 ulelong x \b, %u bytes
1622 #>0x14c ulelong x \b, flags %8.8x
1623 # Reserved: array[0..26] of Longint
1625 >0x140 ulelong <1000
1627 >>0x1d6 pstring x \b, %s
1629 >>>&0 pstring x \b\%s
1631 >>>>&0 pstring x \b, "%s"
1633 >0x140 ulelong >999
1635 >>0x1db lestring16 x \b, %-.9s
1637 >>0x1db search/43 \xFF\xFF\xFF
1639 >>>&0 lestring16 x \b\%-.9s
1640 >>>&0 search/43 \xFF\xFF\xFF
1642 >>>>&0 lestring16 x \b, %-.42s
1647 0 string Inno\ Setup\ Messages\ (
1648 # null padded til 0x40 boundary
1649 >0x38 quad 0 InnoSetup messages
1653 # version like 5.1.1 5.1.11 5.5.0 5.5.3 6.0.0
1654 >>0x15 string x \b, version %.5s
1656 >>>0x1a ubyte !0x29 \b%c
1658 >>0x40 ulelong x \b, %u messages
1660 #>>0x44 ulelong x \b, TotalSize %u
1662 #>>0x48 ulelong x \b, NotTotalSize %u
1664 #>>0x4C ulelong x \b, CRC %#x
1665 >>0x40 ulelong x
1667 >>>0x1c search/2 (u) (UTF-16),
1668 >>>>0x50 lestring16 x %s
1670 >>>0x1c default x (ASCII),
1671 >>>>0x50 string x %s
1680 0 string MSWIM\000\000\000
1681 >0 use wim-archive
1683 0 string WLPWM\000\000\000
1684 >0 use wim-archive
1685 0 name wim-archive
1687 >0 string x Windows imaging
1693 >16 ulelong &0x00000008 (SWM
1700 >16 ulelong ^0x00000008
1713 >0 string/b WLPWM\000\000\000 \b, wimlib pipable format
1722 # 1-based index of the bootable image of the WIM, or 0 if no image is bootable
1723 >0x78 ulelong >0 \b, bootable no. %u
1726 #define FLAG_HEADER_COMPRESSION 0x00000002
1727 #define FLAG_HEADER_READONLY 0x00000004
1728 #define FLAG_HEADER_SPANNED 0x00000008
1729 #define FLAG_HEADER_RESOURCE_ONLY 0x00000010
1730 #define FLAG_HEADER_METADATA_ONLY 0x00000020
1731 #define FLAG_HEADER_WRITE_IN_PROGRESS 0x00000040
1732 #define FLAG_HEADER_RP_FIX 0x00000080 reparse point fixup
1733 #define FLAG_HEADER_COMPRESS_RESERVED 0x00010000
1734 #define FLAG_HEADER_COMPRESS_XPRESS 0x00020000
1735 #define FLAG_HEADER_COMPRESS_LZX 0x00040000
1736 #define FLAG_HEADER_COMPRESS_LZMS 0x00080000
1737 #define FLAG_HEADER_COMPRESS_XPRESS2 0x00100000 wimlib-1.13.0\include\wimlib\header.h
1739 >16 ulelong &0x00100000 \b, XPRESS2
1740 >16 ulelong &0x00080000 \b, LZMS
1741 >16 ulelong &0x00040000 \b, LZX
1742 >16 ulelong &0x00020000 \b, XPRESS
1743 >16 ulelong &0x00000002 compressed
1744 >16 ulelong &0x00000004 \b, read only
1745 >16 ulelong &0x00000010 \b, resource only
1746 >16 ulelong &0x00000020 \b, metadata only
1747 >16 ulelong &0x00000080 \b, reparse point fixup
1748 #>16 ulelong &0x00010000 \b, RESERVED
1749 # dwCompressionSize; Uncompressed chunk size for resources or 0 if uncompressed
1750 #>20 ulelong >0 \b, chunk size %u bytes
1758 #>0x50 ulelong x \b, at %#8.8x
1759 # NOT WORKING \xff\xfe<\0W\0I\0M\0
1760 #>(0x50.l) ubequad x \b, xml=%16.16llx
1762 #>0x60 ubequad x \b, rhBootMetadata %#16.16llx
1764 #>0x7c ubequad x \b, rhIntegrity %#16.16llx
1766 #>148 ubequad !0 \b,unused %#16.16llx
1774 0 string 1giM Windows Easy Transfer migration data
1778 >0x18 string =MRTS without password
1780 >>0x1c ulelong+0x38 x \b, at %#x
1782 >>(0x1c.l+0x38) ubyte x
1785 >0x18 string !MRTS with password
1787 >0x18 search/29/b MRTS
1789 #>>&0 ulelong x \b, 1st length %u
1796 0 string ID;P Microsoft SYLK program
1797 >4 string >0 \b, created by %s
1805 0 ubelong =0xDC058340
1806 >4 ubyte =0 Windows Performance Monitor Alert
1820 0 ubelong 0xB8C90C00 InstallShield Script
1832 >1 search/0x121/s SRCDIR \b, variable names:
1837 >>>&0 leshort x #%u
1840 >>>>&0 leshort x #%u
1843 #>>>>>&0 leshort x #%u
1846 #>>>>>>&0 leshort x #%u
1849 #>>>>>>>&0 leshort x #%u
1852 #>>>>>>>>&0 leshort x #%u
1855 >0 ubelong x ...
1863 0 string screen\040mode\040id:i: Remote Desktop Protocol connection
1871 0 guid 7B5C52E4-D88C-4DA7-AEB1-5378D02996D3 Microsoft OneNote
1874 0 guid 43FF2FA1-EFD9-4C76-9EE2-10EA5722765F Microsoft OneNote Revision Store File
1879 0 string XBF\0
1880 >12 ulelong <0xFF
1881 >>16 ulelong <0xFF Microsoft XAML Binary Format
1889 0 string MetaView\x20Service\x20Assurance\x20Export\x20File MetaView SAS export
1896 0 string PReg
1913 0 string SLTG
1917 0 string MSFT\x02\x00\x01\x00 Type Library (MSFT format)