0010281897fbf8f8742e70e5219abeeeac1b7702e3f709de1590e4cd969d3de7

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-12 21:18:08
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
CompanyName IP Davydov Egor Denisovich
FileDescription Touch Skins Desktop
FileVersion v1.15
InternalName touchskins
OriginalFilename touchskins.exe
ProductName Touch Skins
ProductVersion 1.15.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • birthpopuptypesapplyImagebeinguppernoteseveryshowsmeansextramatchtrackknownearlybegansuperpapernorthlearngivennamedendedTermspartsGroupbrandusingwomanfalsereadyaudiotakeswhile.com
  • example.com
  • genretrucklooksValueFrame.net
  • http://www.C
  • http://www.a
  • http://www.css
  • http://www.hortcut
  • http://www.icon
  • http://www.interpretation
  • http://www.language
  • http://www.style
  • http://www.text-decoration
  • http://www.w3.org
  • http://www.w3.org/shortcut
  • http://www.wencodeURIComponent
  • http://www.years
  • https://curl.se
  • https://touchskins.io
  • https://www.World
  • https://www.recent
  • memtest86.com
  • sourceware.org
  • thing.org
  • www.memtest86.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Uses constants related to AES
Uses known Diffie-Helman primes
Uses known Mersenne Twister constants
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • NtQuerySystemInformation
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegGetValueW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessWithTokenW
  • CreateProcessW
  • ShellExecuteA
  • ShellExecuteW
Uses Windows's Native API:
  • NtClose
  • NtCreateFile
  • NtCreateThreadEx
  • NtDeviceIoControlFile
  • NtQuerySystemInformation
  • ntohs
Uses Microsoft's cryptographic API:
  • CryptAcquireContextA
  • CryptAcquireContextW
  • CryptCreateHash
  • CryptDestroyHash
  • CryptDestroyKey
  • CryptEncrypt
  • CryptGenRandom
  • CryptGetHashParam
  • CryptHashData
  • CryptImportKey
  • CryptReleaseContext
  • CryptDecodeObjectEx
  • CryptQueryObject
  • CryptStringToBinaryW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • WS2_32.dll
Functions related to the privilege level:
  • OpenProcessToken
Interacts with services:
  • ControlService
  • EnumServicesStatusExA
  • OpenSCManagerA
  • OpenServiceA
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • Process32First
  • Process32Next
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
  • CertOpenSystemStoreA
Info The PE is digitally signed. Signer: IP Davydov Egor Denisovich
Issuer: GlobalSign GCC R45 CodeSigning CA 2020
Safe VirusTotal score: 0/71 (Scanned on 2026-08-21 16:53:39) All the AVs think this file is safe.

Hashes

MD5 b5a2cb4f2d7d72f9cd1d5388d56b5e1d 🔍
SHA1 bdbb2815739bbac2434ce1b8bcb425db41595bfe 🔍
SHA256 0010281897fbf8f8742e70e5219abeeeac1b7702e3f709de1590e4cd969d3de7 🔍
SHA3 33882b89bdb6c1c5b50776374145757a0f84ff972e0e12417f80063b6cb6532d 🔍
SSDeep 98304:d4qX9Ejp3r+3AQSJBJHQ6mZ4VIPexp7g5hjFuZN:d4O90aNwXlGhY3 🔍
Imports Hash 7c087a47350a0fc6943ca63cc6a62368 🔍

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2026-Aug-12 21:18:08
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x443600
SizeOfInitializedData 0x16ac00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000406730 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x5c2000
SizeOfHeaders 0x400
Checksum 0x5bf83a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 640ae6837878c6aa3d43a4f8182347c8 🔍
SHA1 52984a7532c8995ac6b9e0eea15f602cc85bcf2f 🔍
SHA256 67f5489b814d9371d2f30f48470a022899694e02d2ccd2a37d480be3a8e82177 🔍
SHA3 feca22a63b32e35ab663e833838cf5d7876e29c90e06aee12a864fa41a2515f1 🔍
VirtualSize 0x4435b6
VirtualAddress 0x1000
SizeOfRawData 0x443600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45763

.rdata

MD5 5adb6ff47234ad814d2c8680b51dee65 🔍
SHA1 1be9433da77c93ac4751a81213b32071a9e678e6 🔍
SHA256 839b910551421566472df0908410423db7f048105ca61f9962a638b2bd1b76cd 🔍
SHA3 b732db50d8258f32feaa568b7132f604426e71dd3ef725cb1d251973d5278971 🔍
VirtualSize 0x13daa8
VirtualAddress 0x445000
SizeOfRawData 0x13dc00
PointerToRawData 0x443a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.79747

.data

MD5 b9a1110055f7ab3315a89e5d44ef7733 🔍
SHA1 744fb852003c96227f10eee7bb0801f5a488dcb4 🔍
SHA256 58102e938e6f6d3da31d1d55427f2a1d691ad45ef4254ea1c85da1862c27079b 🔍
SHA3 78062d3d21c952bfa209085e5ba2e6c80a067bd0d092f4ef7f36e6607ec0a2da 🔍
VirtualSize 0x14660
VirtualAddress 0x583000
SizeOfRawData 0x6800
PointerToRawData 0x581600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.56698

.pdata

MD5 603534b57eeff198db3051c582afb512 🔍
SHA1 db94817a9dadbaf7dc17232f0a7dddd3fdcf2d57 🔍
SHA256 4f2d072646ecfd9fbcb99f0962752ea99415640e38b2e5bef967751ceb13daf5 🔍
SHA3 06d91491c5876d87766cba51fb77afc2d0b9aa2ae4deda7b1be070f0357802d5 🔍
VirtualSize 0x17e20
VirtualAddress 0x598000
SizeOfRawData 0x18000
PointerToRawData 0x587e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.28905

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x5b0000
SizeOfRawData 0x200
PointerToRawData 0x59fe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.tls

MD5 62eaca200eb0b642942495bbd5cd5705 🔍
SHA1 43897c54ee1045d01b62e6c7440e1fb3fc74ca6d 🔍
SHA256 27eabfda338e44146ec94a4a5b6a3cd29b8066a87b964dc257d887bfcaba9e15 🔍
SHA3 5088045a7c09a5e9cdf0d770988c3c07f27e8c8bebe987c971b24e544bf35c09 🔍
VirtualSize 0x32
VirtualAddress 0x5b1000
SizeOfRawData 0x200
PointerToRawData 0x5a0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.136464

_RDATA

MD5 9fe1d934f73de9a033242eac7dacebdb 🔍
SHA1 aa8aabf3021fa0fb190ea2532f68cdd95a9bd9ad 🔍
SHA256 4a21a1ca9b4569ad87a482a474204ffbb3cf18472220b8d3590b00eaa9ccd909 🔍
SHA3 eab5e7cfb8f0d7ef43348f7ced9d528b35b85549506dc51c091a4db917aa8afa 🔍
VirtualSize 0x1f4
VirtualAddress 0x5b2000
SizeOfRawData 0x200
PointerToRawData 0x5a0200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.17965

.rsrc

MD5 d3c0b4b12bba6504118e1332bfd46f31 🔍
SHA1 e7bb876234effe5acbf755c14a35b937805c3fd7 🔍
SHA256 5780b1ec440cb205b659d52948dda4cd50087d2845b41288d35cd0a8ae4971f4 🔍
SHA3 93b76a3f9c9f3e970a1ba5d9936df1fdfeb29b02d2c47bfae22e1fcc377660c0 🔍
VirtualSize 0xa808
VirtualAddress 0x5b3000
SizeOfRawData 0xaa00
PointerToRawData 0x5a0400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.23211

.reloc

MD5 439445abc9e55da72dc3143a985e5998 🔍
SHA1 6d7e0fac7445790dd1e4d2dc874ecb59859bcb42 🔍
SHA256 c3e8ab48771cb47d6b0d09d8c16f6355fea69d89979ac046847a1b95574bc722 🔍
SHA3 dae55da41296355873c9e0a71769997e85d2e341b0cb46e77cd1837d5e9cb43e 🔍
VirtualSize 0x36a4
VirtualAddress 0x5be000
SizeOfRawData 0x3800
PointerToRawData 0x5aae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43447

Imports

ADVAPI32.dll CloseServiceHandle
ControlService
CreateProcessWithTokenW
CryptAcquireContextA
CryptAcquireContextW
CryptCreateHash
CryptDestroyHash
CryptDestroyKey
CryptEncrypt
CryptGenRandom
CryptGetHashParam
CryptHashData
CryptImportKey
CryptReleaseContext
EnumServicesStatusExA
EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
GetTokenInformation
GetUserNameW
OpenProcessToken
OpenSCManagerA
OpenServiceA
RegCloseKey
RegCreateKeyExW
RegDeleteTreeA
RegGetValueW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
d3d11.dll D3D11CreateDeviceAndSwapChain
ntdll.dll NtClose
NtCreateFile
NtCreateThreadEx
NtDeviceIoControlFile
NtQuerySystemInformation
RtlCaptureContext
RtlInitUnicodeString
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
VerSetConditionMask
WS2_32.dll WSACleanup
WSACloseEvent
WSACreateEvent
WSAEnumNetworkEvents
WSAEventSelect
WSAGetLastError
WSAIoctl
WSAResetEvent
WSASetEvent
WSASetLastError
WSAStartup
WSAWaitForMultipleEvents
__WSAFDIsSet
accept
bind
closesocket
connect
freeaddrinfo
getaddrinfo
gethostbyname
gethostname
getpeername
getsockname
getsockopt
htonl
htons
inet_ntop
inet_pton
ioctlsocket
listen
ntohs
recv
recvfrom
select
send
sendto
setsockopt
socket
KERNEL32.dll AcquireSRWLockExclusive
CloseHandle
CompareStringEx
CompareStringW
CopyFileW
CreateDirectoryW
CreateEventA
CreateFileA
CreateFileMappingA
CreateFileMappingW
CreateFileW
CreateMutexA
CreateProcessW
CreateThread
CreateToolhelp32Snapshot
DecodePointer
DeleteCriticalSection
DeleteFileW
DuplicateHandle
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
ExitThread
FileTimeToSystemTime
FindClose
FindFirstFileA
FindFirstFileExW
FindFirstFileW
FindNextFileA
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FormatMessageA
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetDateFormatW
GetDriveTypeW
GetEnvironmentStringsW
GetEnvironmentVariableA
GetEnvironmentVariableW
GetExitCodeThread
GetFileAttributesExW
GetFileAttributesW
GetFileInformationByHandle
GetFileSizeEx
GetFileType
GetFullPathNameW
GetLastError
GetLocaleInfoA
GetLocaleInfoEx
GetLocaleInfoW
GetLogicalProcessorInformationEx
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemDirectoryA
GetSystemDirectoryW
GetSystemTimeAsFileTime
GetSystemTimePreciseAsFileTime
GetTickCount
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultUILanguage
GetWindowsDirectoryW
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitOnceBeginInitialize
InitOnceComplete
InitializeCriticalSection
InitializeCriticalSectionEx
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
K32EnumProcessModulesEx
K32GetModuleBaseNameA
LCMapStringEx
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
LocalAlloc
LocalFree
MapViewOfFile
MoveFileExW
MultiByteToWideChar
OpenMutexA
OpenProcess
OutputDebugStringA
OutputDebugStringW
PeekNamedPipe
Process32First
Process32Next
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadConsoleW
ReadFile
ReleaseMutex
ReleaseSRWLockExclusive
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
Sleep
SleepConditionVariableSRW
SleepEx
SystemTimeToTzSpecificLocalTime
TerminateProcess
TryAcquireSRWLockExclusive
UnhandledExceptionFilter
UnmapViewOfFile
VerifyVersionInfoW
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
lstrlenA
USER32.dll ClientToScreen
CloseClipboard
CreateWindowExA
DefWindowProcA
DestroyWindow
DispatchMessageA
EmptyClipboard
EnumDisplayDevicesW
EnumDisplaySettingsW
GetCapture
GetClientRect
GetClipboardData
GetCursorPos
GetDC
GetDesktopWindow
GetForegroundWindow
GetKeyState
GetKeyboardLayout
GetMessageExtraInfo
GetWindowRect
IsWindowUnicode
LoadCursorA
LoadIconA
MessageBoxA
MonitorFromWindow
OpenClipboard
PeekMessageA
PostQuitMessage
RegisterClassExA
ReleaseCapture
ReleaseDC
ScreenToClient
SetCapture
SetClassLongPtrA
SetClipboardData
SetCursor
SetCursorPos
SetForegroundWindow
SetProcessDPIAware
SetWindowPos
ShowWindow
TrackMouseEvent
TranslateMessage
UnregisterClassA
UpdateWindow
WaitForInputIdle
SHELL32.dll CommandLineToArgvW
SHGetKnownFolderPath
ShellExecuteA
ShellExecuteExA
ShellExecuteW
ole32.dll CoInitializeEx
CoTaskMemFree
CoUninitialize
StringFromGUID2
SHLWAPI.dll PathCanonicalizeW
dbghelp.dll SymCleanup
SymFromAddr
SymFromName
SymGetLineFromAddr64
SymGetOptions
SymInitialize
SymInitializeW
SymLoadModuleExW
SymSetOptions
GDI32.dll CreateRectRgn
DeleteObject
GetDeviceCaps
CRYPT32.dll CertAddCertificateContextToStore
CertCloseStore
CertCreateCertificateChainEngine
CertEnumCertificatesInStore
CertFindCertificateInStore
CertFindExtension
CertFreeCertificateChain
CertFreeCertificateChainEngine
CertFreeCertificateContext
CertGetCertificateChain
CertGetNameStringW
CertOpenStore
CertOpenSystemStoreA
CryptDecodeObjectEx
CryptQueryObject
CryptStringToBinaryW
PFXImportCertStore
IMM32.dll ImmGetContext
ImmReleaseContext
ImmSetCandidateWindow
ImmSetCompositionWindow
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmEnableBlurBehindWindow
DwmGetColorizationColor
DwmIsCompositionEnabled
bcrypt.dll BCryptGenRandom

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xa2a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0261
MD5 4557136a937216454f404cdbb2d4e793 🔍
SHA1 9a1ab9de2d12bdf6c06986162558e2f02ac19e85 🔍
SHA256 2664a54b8b0e77acc8a279df98ce878d798c9adbe49093d4931e6b2f9f7987ea 🔍
SHA3 c1ac811de4228eb659994037cbb6e424b606b65a8c3f4b86df038c8fcdecaeba 🔍

101

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 cfdfff5c426386435243667a4b1c93b6 🔍
SHA1 64c56e559dadef8a5f100e4e425bef2339f1fc9f 🔍
SHA256 1f54b022880a2321ba94e759de3304c3940e8d0be20a8cd32ef5bd7880559afa 🔍
SHA3 a97179d75bc9ab1d093731491909479a9b811bd81cff240d9def36cc8321a068 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x2c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35476
MD5 81c66684bc55adc6b1f9559e1b2b0736 🔍
SHA1 2dd3b215f7544d60066d3068411566e998a6eff9 🔍
SHA256 51587c8f2e8bfaac2ca7bea949e41cef29b73c90cb07a7622d206b5053aba689 🔍
SHA3 897bc9a303ef114ad0aacc701285210d026719b2299121bb68791d4d841922d0 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.69958
MD5 90f737e4b755f2b64400295bcd1ea45b 🔍
SHA1 1e4860322acf7345dc475bf766f18b87a2b3fa5c 🔍
SHA256 7217e97adba147797eea3111892da065eec4af2ad69c75650c33e4ff5af4a5b2 🔍
SHA3 dfc62b050bb8954118644f5d1027259e2164a33ec5ec906f0741693f7af17c48 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.15.0.0
ProductVersion 1.15.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName IP Davydov Egor Denisovich
FileDescription Touch Skins Desktop
FileVersion (#2) v1.15
InternalName touchskins
OriginalFilename touchskins.exe
ProductName Touch Skins
ProductVersion (#2) 1.15.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x1405b1000
EndAddressOfRawData 0x1405b1031
AddressOfIndex 0x1405960c4
AddressOfCallbacks 0x14055ee18
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001403EA390

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140583f00

RICH Header

Errors

Leave a comment

No comments yet.