0a12aecddd2fb9e591989d7babc3fb23

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages English - United States
Russian - Russia

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VirtualPC presence:
  • 0f 3f 07 0b
May have dropper capabilities:
  • CurrentControlSet\Services
Accesses the WMI:
  • root\CIMV2
  • root\Security
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
  • RegSetValueExA
  • RegSetKeySecurity
  • RegQueryValueExW
  • RegQueryInfoKeyA
  • RegOpenKeyExW
  • RegFlushKey
  • RegEnumValueA
  • RegEnumKeyExA
  • RegDeleteKeyA
  • RegCreateKeyExA
  • RegCreateKeyExW
  • RegSetValueExW
  • RegEnumKeyExW
Can create temporary files:
  • CreateFileA
  • GetTempPathA
  • CreateFileW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeA
  • GetLogicalDriveStringsW
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDCEx
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The PE header may have been manually modified. The resource timestamps differ from the PE header:
  • 2017-Jun-06 21:04:24
Malicious VirusTotal score: 39/67 (Scanned on 2018-10-28 09:42:04) MicroWorld-eScan: Trojan.GenericKD.31204955
McAfee: PUP-XBT-YU
K7AntiVirus: Adware ( 004f3a421 )
K7GW: Adware ( 004f3a421 )
Arcabit: Trojan.Generic.D1DC265B
Invincea: heuristic
F-Prot: W32/InstallMonster.HK.gen!Eldorado
Symantec: PUA.Gen.2
Avast: Win32:InstallMonstr-LG [PUP]
ClamAV: Win.Malware.Agent-6598770-0
Kaspersky: not-a-virus:AdWare.Win32.DLBoost.asbl
BitDefender: Trojan.GenericKD.31204955
NANO-Antivirus: Trojan.Win32.InstallMonster.euxpvo
Ad-Aware: Trojan.GenericKD.31204955
Emsisoft: Application.InstallMon (A)
F-Secure: Trojan.GenericKD.31204955
DrWeb: Trojan.InstallMonster.2222
McAfee-GW-Edition: BehavesLike.Win32.AdwareIMonster.vc
Sophos: Install Monster (PUA)
SentinelOne: static engine - malicious
Cyren: W32/InstallMonster.HK.gen!Eldorado
Webroot: Pua.Downloadmanager
Fortinet: Riskware/InstallMonster
Antiy-AVL: GrayWare[AdWare]/Win32.InstallMonstr.qj
Endgame: malicious (high confidence)
Microsoft: Trojan:Win32/Bitrep.A
ZoneAlarm: not-a-virus:AdWare.Win32.DLBoost.asbl
AhnLab-V3: PUP/Win32.InstallMonster.R201980
VBA32: AdWare.DLBoost
ALYac: Trojan.GenericKD.31204955
MAX: malware (ai score=84)
ESET-NOD32: a variant of Win32/InstallMonstr.QJ potentially unwanted
Rising: PUF.InstallMonstr!1.AB36 (CLASSIC)
Ikarus: PUA.Installmonstr
GData: Win32.Application.InstallMonstr.S
AVG: Win32:InstallMonstr-LG [PUP]
Cybereason: malicious.bb8559
Panda: Trj/Genetic.gen
CrowdStrike: malicious_confidence_100% (D)

Hashes

MD5 0a12aecddd2fb9e591989d7babc3fb23
SHA1 6cf8e8dbb8559d502ba08f46880a186f81e4cbf5
SHA256 7b047e635e11ff911d9dba1ef516a35f48dc691b050476228e6adac97267b5f8
SHA3 f8da9758b9b6112dd20c9405c83d13581eebd933639a65163d56f0d1143a516f
SSDeep 49152:cQTg20ITS/PPs/1kS4eKRL/SRsj0Zuur1T75YqVUrmNF98z:cq/qPPslzKx/dJg1ErmNO
Imports Hash 897202118dbcc03cd179dbe9178c8f57

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x135600
SizeOfInitializedData 0x282200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x001361A8 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x137000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x3c5000
SizeOfHeaders 0x400
Checksum 0x3c2456
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 69ee777de7cceb598ada3062e50359ca
SHA1 1b8ab402add0f894dfdd1bcd25f0337eba57ca06
SHA256 3c752f2db408ee594eccb46edab3c7c7078d2b570532933f4629050be04e2084
SHA3 5cfc65b38f272e07700ce253ef1d7eba1446e5caa0dcba32fd4ba33b138af937
VirtualSize 0x1354b4
VirtualAddress 0x1000
SizeOfRawData 0x135600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.56449

DATA

MD5 a3291fe73052a5a63943a3ff219a2bd2
SHA1 48cabd1c6887b443f438ee603634e2215b5a6a08
SHA256 907b82691b1eeae0c1336ac5fc7a8855e643e9328d383bcdb297d976349cce8f
SHA3 cda70e9ad7efbbf436aaa066f4ee2b4a606a1bfd7a69145ec9ad4bab0560848c
VirtualSize 0xd1d90
VirtualAddress 0x137000
SizeOfRawData 0xd1e00
PointerToRawData 0x135a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.5578

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x7961
VirtualAddress 0x209000
SizeOfRawData 0
PointerToRawData 0x207800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 3a8212c16dc0dab404d8c64e43de02d6
SHA1 8670da6a1f55a5f2318c1d034185d1d35f53bf94
SHA256 df08ef4ce853a5de3d17dcae9ee8d766d39a750b969705c1617c84d049baf987
SHA3 195d6fb920d756a1f9fd6add222decbf7e0b74f4eb5c052f5cb07d32ae917fe2
VirtualSize 0x3102
VirtualAddress 0x211000
SizeOfRawData 0x3200
PointerToRawData 0x207800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.9984

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x30
VirtualAddress 0x215000
SizeOfRawData 0
PointerToRawData 0x20aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 f570677b06e6a67b45b43855046c1bbb
SHA1 d62a58b8a0829e07ba0a0e806b12b4e4e0c07beb
SHA256 018ff1a6f8d9d56764e9017a4816b7041001b3665aa8a9d7831692614c15df30
SHA3 60578635d06bd2546f554992ab1367bc03dbab73ae89520155bbf46d1b477bbb
VirtualSize 0x18
VirtualAddress 0x216000
SizeOfRawData 0x200
PointerToRawData 0x20aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.210826

.reloc

MD5 9934c11ac2a2f7e3e8c2ddaeb522070b
SHA1 539dd473bb6f76a9aee354035994eb2de6f68ad7
SHA256 b926c838902b3c21db857d5fd1d546c8ff62126261aad9ff635550ec41a98229
SHA3 94717220f0d4121aabdb288574889c6b66b8bcc2c0468fc7dea8594dbb094a0e
VirtualSize 0x14a30
VirtualAddress 0x217000
SizeOfRawData 0x14c00
PointerToRawData 0x20ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.70264

.rsrc

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1983d9
VirtualAddress 0x22c000
SizeOfRawData 0x198400
PointerToRawData 0x21f800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#3) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
mpr.dll WNetGetLastErrorW
version.dll VerQueryValueA
GetFileVersionInfoSizeW
GetFileVersionInfoSizeA
GetFileVersionInfoW
GetFileVersionInfoA
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RestoreDC
RectVisible
RealizePalette
Polyline
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileDescriptionA
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExcludeClipRect
DeleteObject
DeleteEnhMetaFile
DeleteDC
DeleteColorSpace
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateEnhMetaFileA
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileW
CopyEnhMetaFileA
CloseEnhMetaFile
BitBlt
user32.dll (#2) GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
ole32.dll CoTaskMemFree
StringFromCLSID
kernel32.dll (#4) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll (#2) CoTaskMemFree
StringFromCLSID
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
shell32.dll SHFileOperationA
kernel32.dll (#5) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
comctl32.dll ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
shell32.dll (#2) SHFileOperationA
Advapi32.dll RegCreateKeyExW
RegSetValueExW
kernel32.dll (#6) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#3) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
comdlg32.dll GetSaveFileNameA
GetOpenFileNameA
Netapi32.dll Netbios
Advapi32.dll (#2) RegCreateKeyExW
RegSetValueExW
kernel32.dll (#7) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryA
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
SetLastError
GetLastError
GetCurrentDirectoryA
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle

Delayed Imports

CASE

Type UNICODE
Language UNKNOWN
Codepage UNKNOWN
Size 0x4190
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 4.09928
MD5 86a2b5da28870e7638540ffcd49341a1
SHA1 2fad491a9619e26927a422b0cbd878bf3e633226
SHA256 d24d10aa8999ac94dc60dd99cd4e2edb40358f1267f3c70723c1728c40c95271
SHA3 a5694c840ac7fd48c20ed32ca54f26615b33cbd09ba8bbf8c2bcb1437449860f

COMBINE

Type UNICODE
Language UNKNOWN
Codepage UNKNOWN
Size 0x6ec
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.60459
MD5 c6b7608e0caf6afb1fc942f5dee3708a
SHA1 4cf4d95b415a040ff9272b483a96d4efbad4ae7c
SHA256 cfb8ec1f5a7e3b9160099e62537010127ede855e52f19278eccc7761da2dbdd1
SHA3 52ff0a17df14d86322dc8aa4a618ead6f872b705f7e05d91537d33fef701c8c3

DECOMPOSE

Type UNICODE
Language UNKNOWN
Codepage UNKNOWN
Size 0x5eec
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.06774
MD5 3e62fe3bc0f6c464262de79020465af5
SHA1 20a022fd45f934d3eafba430052648a73b4448a8
SHA256 de0d03291d26cae44596e0aa34d165394ff65a044b83ee4dae2aac7196097180
SHA3 810fb635c85f064c8e6e1e6dc9be5083f58948504952104c8172f619642c84b9

NUMBERS

Type UNICODE
Language UNKNOWN
Codepage UNKNOWN
Size 0xd70
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.39289
MD5 7d57648dca40b6f5e982f63ad485f2bb
SHA1 f9889a326d293f28580440935c08a83c28e80c5e
SHA256 72ed1665ee6d5c3a862e163409afe9ec7952dda04e745baf7073fd7118770997
SHA3 857058fbd825b97e1d89a2475d6b3bcc2e636133616a76dd5b3c9e276e62c62b

TYPE

Type UNICODE
Language UNKNOWN
Codepage UNKNOWN
Size 0x5624
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 4.44271
MD5 6494f26cb7d7caff98e500c7fa4e6fcd
SHA1 c2ab6595d53d2fc972a86ab985b98786510cdb9a
SHA256 1c23a98a45321c8ddf2c753e349f5330b96641b3f1cbe42dec35ea855895cb85
SHA3 ab54c87bd20da47618169acefc05f1c512eaf93047696cb6c5ef84f638362c75

CASE (#2)

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x723f
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 4.42598
MD5 24d510e4fc4bd85c9064e6cd4a6b5afe
SHA1 d9bd6c6b5e29d1e41534dac21a5881a1c961e897
SHA256 26ad8bd8e5e67fa91f5e84623f14dfa392eba1b7742c1430f24039a16228f0a2
SHA3 f33d5bd4df78a4e6c6cae587a3fd472128a7e762b7220cf3df4de548a874b559

CATEGORIES

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x7ebd
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 5.82676
MD5 64e533870c8b0e09d45b521bf2bbf562
SHA1 dc83a87afb6920f5340d91ff33c448ca9ae611f1
SHA256 e0a16eb6441e280225f96b9fecb22f42ff8f3891f2c26121d96991b74f88e9c9
SHA3 188d4c7604149550429d9dd0c56c92c25832e75425e003b4f3bdce49e484eadc

COMBINING

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x6a8
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 5.64793
MD5 92b770f8767debee4096fdb237a0e331
SHA1 44b4b1b24fd27c5532c27354074475a25150dc2a
SHA256 85090d58aceb2ef630709a15e01e216740e85279abd5022b20b388a07015c4db
SHA3 c68fd53d4af572acaeaf779ba3b8ac2b2f073f0902b12bda8b5c04f290bab38b

COMPOSITION

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xaf7d
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 5.13011
MD5 d6a2d4f8bacc42075bddd385565d494f
SHA1 32da92b5cae2067dbcdb0284c68e6710734a3b0f
SHA256 5b94876780408f50c0e7a298f9cb060f5bbcbc2ddf8894fb0edfa3a6b24d35cd
SHA3 82df0975d82895e5e5c076880e7285580be5f914ec70d70bc380d87260396ca3

DECOMPOSITION

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xd3cf
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 5.25261
MD5 74c37ea07bbe396f54f821f0a4707db4
SHA1 ad519c7d336dd4b3289f74a1769620abb2d8ee58
SHA256 4956615fe2817e88bbe53190d14a4b8f104706547b7eaf1852d686d86c7a9f2c
SHA3 576530b8ee2de38f88ff69e38b911f71f4c845f63228db5061c74694dc17ca7a

NUMBERS (#2)

Type UNICODEDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x14c5
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 5.4372
MD5 1a4b45b0e942c8d84c4ac8e01738d994
SHA1 739bcfafdc2a7267efa1f21eff7e13b14934d7df
SHA256 e0a96e22539e1496f5f9f3e47571d941ced573df20ea575ec0f426e05f1ea378
SHA3 adf64b4d4900cd48baf0f26a316cc3b36b4bb3773c8263930dc4b1f7ff531485

1

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

1 (#2)

Type RT_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.07781
MD5 8e8d4663aeb7887b56999c3c0f4929ce
SHA1 65b78002862cbeeabb693a5a4755a2e7ad7e6c5a
SHA256 8ee6bd18892dd6b622021f993eed0ae443f174cbcf560b96efabfe6a05e6193d
SHA3 cc3e32afec39c1e5b57bd45fd5cddf683090d724dbb0276fd02c267ace5e70e9

2 (#2)

Type RT_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.99797
MD5 8f826fd1e27818339c268b2694ff6ddb
SHA1 734f4c07bc91832dadcd967a248ab0377e3270bd
SHA256 27d3d56432f2858f6069e2716ee219f30f5abce25e28aa6a6fe9b53b403880c3
SHA3 10874942dc0c37b4bdd52b89266d4205d2708abca7c10a3fcca8b75d4e2df724

3 (#2)

Type RT_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47824
MD5 4d30313ea04ba78b8e535a8fedbf55cd
SHA1 653a8bc7d446554e3ba0b10961c9d94b7c348e14
SHA256 48c623e3cbaa9794a0a29f6987ef2605ca7ba8984a30042d5d6530a50094fefe
SHA3 cd987def87fbc5800efb73a27e7f3192cce5bd15e5fe089500e8005b4e4fca61

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0x52
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

4056

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x360
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.24232
MD5 6aa8a9f45b47687a604e368a6499c58e
SHA1 ed7d05f5d88146b8ff9e442b9c0e306fa796eef8
SHA256 7f694570d35cdf59c0fc9d41d14e10c7d9533cff0a63b4669a1cb1fdcc7f0757
SHA3 a528e60e82b841116af88851d5dee003d99a77904d7b8f9365a3d0330a3a8dda

4057

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.23967
MD5 0b85a4752315da9aa81dcd6003a240a3
SHA1 58a4d8fe6f7d098749fc3ae2ed9c32604c2a4ff8
SHA256 b87d9e4ac3b1cc6dd6f560a7ebd6d88c0566b46280ed7139d62e4daf7420587c
SHA3 cb10d5742a110f93e368730fbf8e101dbc96f30383813c523dc670b1b59d7084

4058

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x16c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.26382
MD5 d11277bf2bdc0dbf1c69f796ccc6efde
SHA1 ae6775367ec3deb15bceda12f638d0a01ca152da
SHA256 5e26d28ace953abeb69a73a7e2ecac51a6dee3f2155d675283e27fbf67c13621
SHA3 7b1a893c28b75a9857bbe28a789ff0405f94c41da1fa621bfbc41506428218c7

4059

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x204
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.24369
MD5 9c3ebfceaf83318f29f5bedadf1d16e3
SHA1 02dc00b6b9f9d1c08e67bc250b18978732958b0e
SHA256 891c487fb37fcf4418a45dab55b603ade59a9d49ec27a62d18158e7cc5e9a285
SHA3 90bdcc6a6ef3fbcf87b3f9948ad770b6d8bfbdd6f3b3afd371fe585a40fe0f8a

4060

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x24c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.27262
MD5 54a74428cf471fa3d76b734f5b9187ab
SHA1 81145ea5ac853cd7bdc8561502572808ad0a12c8
SHA256 4f15d58a3df96437a322c34aff5230e1f1d3df33c446fe1167a6066b008bbabf
SHA3 e290141f5a9c3b6f7917fb5e98b8a406c228221785dd64a3889893c9b2628ac4

4061

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.10555
MD5 4db0c662b2f1091a09ca8796fbb5178e
SHA1 445b4eeaa37d24c42f2403c0566ce2884dba7e02
SHA256 560b073323f1ae8c193ede3cd59bff0ec2cd137b37c900c836bec34f7027c064
SHA3 fbb685fbf2183438c67c1e55c4a1e28d210df84260aef45ee1fd9d86dc7c5f6e

4062

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x12c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.15845
MD5 54dc1e9e36f3302097acbe6f5d3b61c8
SHA1 9a9155254373b3c54e3a126633b8f170b300b7f3
SHA256 3cbfc49b1e88ba6658742d4ddbdfa4dd3f26e2d5a3a462df04ae99f601fb6c68
SHA3 ce6760d51b1b02f9beb4b18a25a18d697a2da13bf2e813fce74ff7adf30c082c

4063

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2ec
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.25915
MD5 6857a67a33a8dfb0c2363ba7b03ccd9f
SHA1 33283b57c500505b3fd55e094a01bb3aebe50b8e
SHA256 9f684d713fb13d9054be4711b2e62ead4a7835f41419e635ff901dce526113a0
SHA3 d3a9970c38b440a091ebef54bf3c000b9d73fe1d0f7bf4ebffdc57760e9e3107

4064

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x41c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.22311
MD5 3789e4df7d923a99ae8477fcb689be71
SHA1 429d493d1fc73ca37d6e28c85d820a9ca4edf2e8
SHA256 dea402ccc10fda380bfc94d3a014034f8dfbb6bac44904a44e06338bc6ef32c6
SHA3 ed138c960f300f71ab635f1789803a946d1fd99c2187a50318fdd7a3a8110366

4065

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3fc
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.31151
MD5 2c072cdeec9b45112dc210839d02333a
SHA1 babed6cd82302ed55cc4dffda4721b8a179d91c5
SHA256 140e4b8a6a6777ac82692f24af9c9e427d82a20d4c71aeaefe03e52570a57d68
SHA3 ea43bc87b7fc57aacc1ee397b33310bea18ba29c3b63319e122ad313f0df66a6

4066

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xf6c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.11908
MD5 ad9c19f8fd82b59e9c5135d430a462a0
SHA1 4ae0c73b9593649188ee6a630540cd8a0bec1eba
SHA256 d203a6034234dd42c05a44c721b93d2fa039e45780a9859f2a78db7ad52bcad1
SHA3 7527eee0cd96ce581266e9b89cce57250ea5411b8570d71749a639d8129bbe1b

4067

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xb30
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.17898
MD5 e110ab63a6cda658fb6ce2e9d03d1c81
SHA1 68b30fd15e5fe09c2e67092acd9f82a75f283756
SHA256 657ba2f2f09af84d6425719b46763ffb445d7b464ea2c2d1d6e22564971b216d
SHA3 e7622c9c008d45f66dd9447d4969d23a2d9d997c7c66073a89a8812b2009f6d5

4068

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xa4c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.15752
MD5 e2c7cd8b8b2d4651b47159f09147a090
SHA1 0c9cc6e94e1e13950359ee59aa6cc0cae568a77d
SHA256 1561a7f6b11476ea77def71fa26859da139db69dfdfed8ef56d4a99565089ac9
SHA3 91654a7fed743a814f4351754c52d7d7c43a012bc61b1f0b15f0b97e28e2c08d

4069

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x940
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.15828
MD5 e80b26ad454a93596e4b10fc3511819f
SHA1 d93e2ca9eb0d91168ede64a9a22ed7c5c2d9d6e9
SHA256 d77346aacee59c4ad28c420775e5694c26a0a481a62bafd249754cb7a93ffd57
SHA3 17eb00d2faf9cb12fe5503630513268ca315588e2faf4dbe20d96a938b00e446

4070

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x730
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.14079
MD5 4af17cca9eb698df289eff61274a584f
SHA1 7fab9a74902929e41bfb717006b9817a93cfc4a7
SHA256 200976b3dafd035806fd56bdd46e2c1944bbf18003811376ec607cd2dfe12659
SHA3 bdcdedb00df5a0f854aa027be32636c0f5514a268bb460acfcfe48a88abba3a7

4071

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x258
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.2451
MD5 e376520354674df7845386ececa214de
SHA1 1b2350d06dc2a29ab591376ff7932bf302d2c374
SHA256 17d937a86a8d9396f8cba50d8b2f74f33e2978fd78891ca034340f854b86ac74
SHA3 175080d612f253ab3a5a1dc91e665bd2e47d1148ef9705ed562b040c1436b93f

4072

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x528
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.31989
MD5 54fe80bc1682b73f325d4eb3cb951bcf
SHA1 5212958f8259ac70c237eacc990cd3f7ccc86c93
SHA256 4b79e81ec4c5416e60eec1a9fcf94632bb0df34ba8633038736c8ad5f97d83d1
SHA3 2cd4c48294183fbfc188ddac14cda85744c2c0f8644c9c6056171ca9b2c88a50

4073

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x764
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.28561
MD5 08cc3922c0c898a7d31ac6e0f8b9005d
SHA1 42f7b83a67a9cc9fac361e748dee88edaa028e8e
SHA256 98de66ce975dede82bd50eca7fa34b3cef9fe5511651ddeed1761a7047f03964
SHA3 ca7624389d7f5b0f91cae6f55db3d43955f78f5a6c20209420e95829bd943050

4074

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x87c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.26011
MD5 4a5210f91d3d5b6a81fe627f72845785
SHA1 f4c7edeac081001ad608c2a63c99af6fe42347f7
SHA256 1f15c5940aa0dd7475f67a774aa6b222e0d13978a45a21fbec4c2bd6e2d438ca
SHA3 f817cd782821e021f2d3edde3be202ebad6bc8d3c450b62459538381d479c881

4075

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x898
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.23504
MD5 15e69447b798114b9ff2059fa3d6e36d
SHA1 5f9670a51bb09be36c7f77a2b2b874ab498844f2
SHA256 2a9e250d16847a5b4c8b2944cdfa76a3cc5176c34a5d6190d899415ac5cd2829
SHA3 f8d7aca0ae2d7dbe92c7f64ffdb641600d203991ee9ebc13a6c87e5c6941a96d

4076

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x7e0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.28409
MD5 5780ec5954c4f6e25cf11a4c881a6034
SHA1 fa82a4728e703468fca1010f71f992af298588c5
SHA256 c2d07ac300e64cefdaee64a4e4979179b6d56637705eb5ded8712d6f8386e206
SHA3 cb4bd8d12031f865e89b658160d67f25b7d7db0e31948e850460ffac069fd096

4077

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x91c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.20307
MD5 567915678b5f88c171d7011946229ab4
SHA1 11eafcbf5c33c9cdc56b9569c975ab1eaa47aed8
SHA256 5511afe42a0da277401a10b26739bbaad99fa12ec4f7ebec23cf0b9dc5e6cb82
SHA3 d41a8ca04807a0bbc8389821bade48f4bac972e2e966d21a9bccd7fba236cf96

4078

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xa28
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.1926
MD5 2f23e7818b29ccd8ae6156ac3331cbc1
SHA1 651bf0060340c77133d5bdb4d93c53b3b80f994c
SHA256 cdfdb161a2da7fca6b0e7207c9625f5b6a4dab7a7fca139be1ba6c7f639c04d5
SHA3 843924b24eb297074c971488bfe706a99bf9a5ae16ec160cdd4b73dd1929ae0d

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x68c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.34129
MD5 944531aca0a9a54969ad6df5af1f54a6
SHA1 f71f0a65d1cde77b647cb3c1f3bd1511d13f045b
SHA256 c91069379c0e062b73e84ec11cb91cf32277366cece4212df7c706cba2c16abf
SHA3 196b9fc91e9865563510a6d9f8faa10b909650ffb86047cf1074e1a3d07e5ae5

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x46c
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.28779
MD5 3548f7c4bcdbb09232dba797129a445b
SHA1 6471e99b64312995445c2f8fd03025468c3c50d8
SHA256 8587bf789ccbcfde74227611e8620852943e4f833d4ae9bc38bf1d559c5da42b
SHA3 94e025663a5b78e6f87bba5f01994b499a481cfff1c37b3eb25d8e7f06e54272

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x464
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.35586
MD5 36a703c0114f5023e3ae13dec5d75bbc
SHA1 b174cc722cec8e6f31e81df3be9a448039486cf4
SHA256 28e5bc49012222884dc9564f18324354ce515b92d2bcd62bb180bc286536ed85
SHA3 db18f84506c7d6429dc10c85f80ffc7f923427277507d6693f18f4ad1f3c4be7

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x390
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.24062
MD5 4cb908f047b0672337792239133b5172
SHA1 6b97d302c4dc39c52944d823483e8b5977c121f8
SHA256 a2ce338553160da458ab0e0fa23ff47c887b9be18f44b246802ba75f17f2b3bd
SHA3 ec8fbc445ba9dd89f2f4dc07a5a2c75054b0b3ef79e65f82766d6fdb8bc7ad8a

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x420
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.26201
MD5 9ba481240a136a629bd7a2493a970c15
SHA1 3ea5c593a0519debfe2fab1b43a0e60e54b460c6
SHA256 afeb65aa9c2ba3fc907053c2b0a67410681703e5829861cda50c2a84b5871468
SHA3 39710a0152b7038f4e1959d697f7ace77944c7bfe5cb7e1c416af56e5b213088

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x418
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.29231
MD5 eebe2403f99b5ffde3022d43d9ac2fbd
SHA1 af73a8d209ee83529286ea62e96a154234b31136
SHA256 b68723bfe4382d9f5d89916027cc5c476d0c7b226d0fa959bdbcb368fb08b445
SHA3 95f294ce9e98db103557978c22a75d84a7b5e3f847865b3750159d5043e7b0ce

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x394
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.13672
MD5 70f2e94e5235722ee60ceab0a348a3aa
SHA1 c8e25087f7e2ed2fbef2cbfff9b489d5194ceba1
SHA256 24a597408e6f7ffb4d31766e03b1ab0499117cb57680485046f9475eaf295542
SHA3 c046377fdea871dfb3a79510996a58bca74100f1914ecdf7ea8ba3421953b40d

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x398
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.16365
MD5 09a8c5c784f8a6455ea2c9783f5f7a49
SHA1 2dc5f267c7a3f55c7187473cb006c6249e0658f1
SHA256 3a5335d10f1d922d32e79f71a4e6b4ce4062acc3cbfe4bbb4eab8819e11900c4
SHA3 2afd0b83d1c47fdbfad55d04ed875e9ff387dc7a95cd127e4b58dfb183083a92

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x300
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.29821
MD5 3a14b33b3ae4ff4b8e2b617818ce4b5b
SHA1 1130267c3ec9254aad5173bc07eac81e67a4c8aa
SHA256 59c0f9b38ab6597dd17dce460bc916544fdaa1d60b1a725c3cec5e8daae5951e
SHA3 2c6e8396e09b62e94d24fcdf35f0c018b66e32dea1291924af634fb341d2cf5d

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x364
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.19506
MD5 25b68a1e29b338d4a44e746046dee7aa
SHA1 d1dfcb562a569431367588d6d7d3721eabc0ea26
SHA256 8f8b6b50ddb2b14820b88e5a96d198f7d5e891b2ae63ce96c5d862ac46916c4e
SHA3 f6780fc6583c7d96bdebbaff85a59b5b847a470339d3ab18335b14f2ce34756a

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.2473
MD5 892d25bd6bef8c269fc90191d1428b7a
SHA1 dd5ad3da0c97f242c8c2ed572bb1a4879e9eb6ac
SHA256 ba2767c0647566b4d4cb1899fdef6571b495f36ee522fc4867abb45131cd7a88
SHA3 c09f6ef1abdf1b65e08a6a56d0f5c7e166cb3a93b4a5d6c06ff850f7476ed6d3

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x374
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.25246
MD5 f688f35e311fdb2e373ab0ab1d5d52bb
SHA1 00d186488ecc36ade025cb63b1743573e0628d1b
SHA256 7f4902d1959e79f5816454e6798a5d72b772cefe4b3bb8dbfffafb1834568697
SHA3 f61402701fbaca88c86a1efbcdc58cef081eb98e0483f8afb0949b1848db6115

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.97649
MD5 edacfeae8b456a96821e97ae18c4a691
SHA1 38e59e8842a2a59f0be1a408b0273bb7c642c51b
SHA256 05460789da581e375d4a9626e7dc592714a2cc7535497a08dbbb78521fc7a964
SHA3 53315876399bdf8a02d6dea55a8cfd9457c7b00d79a2d3c28baefe7c14a764a2

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xbc
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 2.76133
MD5 55fa4cc1ed4ce4e726d0098875d2b5cb
SHA1 7dae1a9180164a1813efd50041ffbe048ad7beef
SHA256 8a87da2d7d96cc00a994fd755cac4285d1d05f578c6f7f9292bda53cb182b0b8
SHA3 88e01c5611f4ad1b44a969f2e270f7f19121f86a4491490bd526bd3829e9c1b7

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x368
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.26968
MD5 3eeb9f878a484bb3eb0713dc4af9ec4f
SHA1 5ee6a53027e6106d384d247720a884ed92524bd3
SHA256 28fa1bdd9fde66292bf9e89d02f8ee2fe49a9fdcade6cf07d917ee59075c345e
SHA3 2e5307906661bb4299d3c6d917bdb906367754852933203c0e50f7cdcb4c25bf

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x474
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.23624
MD5 d7a6d355a467e15abceef59e8c9f87ef
SHA1 b71f12bea0229e4f500d5118135409c3c918ceae
SHA256 51cf391690f8db60567754d81583046e7ffc9c96720d0d60e057fd271ae922be
SHA3 6130172d0e1f1324fb3303be1f30b7f1b883dca1b05cd1311b2e5e348209f436

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x374
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.23377
MD5 91c23b7f8181f49aa1dcebedf7a4d136
SHA1 61de02376e68fa9931cbe4cbb16a00b69ea74c36
SHA256 61abfbcbe22fbb5d51758a2f948daab6e90261696713ec6b92ebce15a019e539
SHA3 d85863a16d4ea779ff5c81c89524addd92319198fe453fab4f8f88536bace098

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2f0
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.19607
MD5 429857b519ace0b56bc4f4b57199f2c2
SHA1 80db0a7a791362f08cfab371a398a0feef0eee84
SHA256 70d5daf1d42ac9206cd03e7814c9df0e951f60bdc786572c7227bbee617341e5
SHA3 16537b2ee68384ee6fd2e56b9567c9cec290e3cd76d3abb46ad2efa4cd294e9d

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

NOTER

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x80eca
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 3.58354
MD5 aac16f23ebdf1ce7dcceddf071433caa
SHA1 ba03a547b89ae2df7257f6ab6745111403fdf710
SHA256 a0b0c3fd59aaa34fe65efee8926849416b28c6f332787752858be3510f7f2a19
SHA3 dd903ab9da1ec4b2fc8b26253358048db2a81b5f5f996344031bd59988516d7d

PLATFORMTARGETS

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

ROLOTAQ

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xc9507
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xa62
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

MAINICON

Type RT_GROUP_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x30
TimeDateStamp 2017-Jun-06 21:04:24
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

1 (#3)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x2f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x479
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a

String Table contents

3D Dark Shadow
3D Light
Window Background
Window Frame
Window Text
OLE control activation failed
Could not obtain OLE control window handle
License information for %s is invalid
License information for %s not found. You cannot use this control in design mode
Unable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid class reference for TAppletApplication
Invalid stream operation
Error
Button Shadow
Button Text
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Scroll Bar
Lime
Yellow
Blue
Fuchsia
Aqua
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
Button Highlight
- Dock zone has no control
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No topic-based help system installed
No help keyword specified.
Black
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Red
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
Clipboard does not support Icons
Text exceeds memo capacity
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
&Retry
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
Cannot make a visible window modal
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
Cannot change the size of an icon
Invalid operation on TOleGraphic
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Unknown error
SSPI %s returns error #%d(0x%x): %s
SSPI interface has failed to initialise properly
No PSecPkgInfo specified
No credential handle acquired
Can not change credentials after handle aquired. Use Release first
Unknown credentials use
Do AcquireCredentialsHandle first
CompleteAuthToken is not supported
BCD overflow
%s is not a valid BCD value
Could not parse SQL TimeStamp string
Invalid SQL date/time values
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
The smartcard certificate used for authentication was not trusted. Please contact your system administrator.
The smartcard certificate used for authentication has expired. Please contact your system administrator.
The Kerberos subsystem encountered an error. A service for user protocol request was made against a domain controller which does not support service for user.
An attempt was made by this server to make a Kerberos constrained delegation request for a target outside of the server's realm. This is not supported, and indicates a misconfiguration on this server's allowed to delegate to list. Please contact your administrator.
The revocation status of the domain controller certificate used for smartcard authentication could not be determined. There is additional information in the system event log. Please contact your system administrator.
An untrusted certificate authority was detected while processing the domain controller certificate used for authentication. There is additional information in the system event log. Please contact your system administrator.
The domain controller certificate used for smartcard logon has expired. Please contact your system administrator with the contents of your system event log.
The domain controller certificate used for smartcard logon has been revoked. Please contact your system administrator with the contents of your system event log.
A signature operation must be performed before the user can authenticate.
One or more of the parameters passed to the function was invalid.
Client policy does not allow credential delegation to target server.
Client policy does not allow credential delegation to target server with NLTM only authentication.
The recipient rejected the renegotiation request.
The required security context does not exist.
The PKU2U protocol encountered an error while attempting to utilize the associated certificates.
The identity of the server computer could not be verified.
The client certificate does not contain a valid UPN, or does not match the client name in the logon request. Please contact your administrator.
Smartcard logon is required and was not used.
A system shutdown is in progress.
An invalid request was sent to the KDC.
The KDC was unable to generate a referral for the service requested.
The encryption type requested is not supported by the KDC.
An unsupported preauthentication mechanism was presented to the Kerberos package.
The requested operation cannot be completed. The computer must be trusted for delegation and the current user account must be configured to allow delegation.
Client's supplied SSPI channel bindings were incorrect.
The received certificate was mapped to multiple accounts.
SEC_E_NO_KERB_KEY
The certificate is not valid for the requested usage.
The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you.
The smartcard certificate used for authentication has been revoked. Please contact your system administrator. There may be additional information in the event log.
An untrusted certificate authority was detected While processing the smartcard certificate used for authentication. Please contact your system administrator.
The revocation status of the smartcard certificate used for authentication could not be determined. Please contact your system administrator.
An unknown error occurred while processing the certificate.
The received certificate has expired.
The specified data could not be encrypted.
The specified data could not be decrypted.
The client and server cannot communicate, because they do not possess a common algorithm.
The security context could not be established due to a failure in the requested quality of service (e.g. mutual authentication or delegation).
A security context was deleted before the context was completed. This is considered a logon failure.
The client is trying to negotiate a context and the server requires user-to-user but didn't send a TGT reply.
Unable to accomplish the requested task because the local machine does not have any IP addresses.
The supplied credential handle does not match the credential associated with the security context.
The crypto system or checksum function is invalid because a required function is unavailable.
The number of maximum ticket referrals has been exceeded.
The local machine must be a Kerberos KDC (domain controller) and it is not.
The other end of the security negotiation is requires strong crypto but it is not supported on the local machine.
The KDC reply contained more than one principal name.
Expected to find PA data for a hint of what etype to use, but it was not found.
The function completed successfully, but must be called again to complete the context
The function completed successfully, but CompleteToken must be called
The function completed successfully, but both CompleteToken and this function must be called to complete the context
The logon was completed, but no network authority was available. The logon was made using locally known information
The requested security package does not exist
The context has expired and can no longer be used.
The supplied message is incomplete. The signature was not verified.
The credentials supplied were not complete, and could not be verified. The context could not be initialized.
The buffers supplied to a function was too small.
The credentials supplied were not complete, and could not be verified. Additional information can be returned from the context.
The context data must be renegotiated with the peer.
The target principal name is incorrect.
There is no LSA mode context associated with this context.
The clocks on the client and server machines are skewed.
The certificate chain was issued by an untrusted authority.
The message received was unexpected or badly formatted.
The function requested is not supported
The specified target is unknown or unreachable
The Local Security Authority cannot be contacted
The requested security package does not exist
The caller is not the owner of the desired credentials
The security package failed to initialize, and cannot be installed
The token supplied to the function is invalid
The security package is not able to marshall the logon buffer, so the logon attempt has failed
The per-message Quality of Protection is not supported by the security package
The security context does not allow impersonation of the client
The logon attempt failed
The credentials supplied to the package were not recognized
No credentials are available in the security package
The message or signature supplied for verification has been altered
The message supplied for verification is out of sequence
No authority could be contacted for authentication.
%s Alert
%s Read Alert
%s Write Alert
Accept Loop
Accept Error
Accept Failed
Accept Exit
Connect Loop
Connect Error
Connect Failed
Connect Exit
Handshake Start
Handshake Done
Successfull API call
Not enough memory is available to complete this request
The handle specified is invalid
Invalid MMF name "%s"
The MMF named "%s" cannot be created empty
Win32 error: %s (%u)%s%s
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
DCOM not installed
DAX Error
COM Server Warning
There are still active COM objects in this application. One or more clients may have references to these objects, so manually closing
this application may cause those client application(s) to fail.
Are you sure you want to close this application?
Failed to load %s.
Mode has not been set.
Could not load SSL library.
SSL status: "%s"
3rd-level cache: 2 MByte, 8-way set associative, 64 byte line size
3rd-level cache: 4 MByte, 8-way set associative, 64 byte line size
3rd-level cache: 1.5 MByte, 12-way set associative, 64 byte line size
3rd-level cache: 3 MByte, 12-way set associative, 64 byte line size
3rd-level cache: 6 MByte, 12-way set associative, 64 byte line size
3rd-level cache: 2 MByte, 16-way set associative, 64 byte line size
3rd-level cache: 4 MByte, 16-way set associative, 64 byte line size
3rd-level cache: 8 MByte, 16-way set associative, 64 byte line size
3rd-level cache: 12 MByte, 24-way set associative, 64 byte line size
3rd-level cache: 18 MByte, 24-way set associative, 64 byte line size
3rd-level cache: 24 MByte, 24-way set associative, 64 byte line size
64-Byte Prefetching
128-Byte Prefetching
CPUID leaf 2 does not report cache descriptor information, use CPUID leaf 4 to query cache parameters
Windows 8.1
Windows Server 2012 R2
2nd-level cache: 1 MBytes, 8-way associative, 32 byte line size
2nd-level cache: 2 MBytes, 8-way associative, 32 byte line size
2nd-level cache: 512 KByte, 4-way set associative, 64 byte line size
2nd-level cache: 1 MByte, 8-way set associative, 64 byte line size
Instruction TLB: 4 KByte pages, 4-way set associative, 128 entries
Instruction TLB: 2 MByte pages, 4-way, 8 entries or 4 MByte pages, 4-way, 4 entries
Instruction TLB: 4 KByte pages, 4-way set associative, 64 entries
Data TLB: 4 KByte pages, 4-way set associative, 128 entries
Data TLB1: 4 KByte pages, 4-way set associative, 256 entries
Data TLB1: 4 KByte pages, 4-way set associative, 64 entries
Data TLB: 4 KByte and 4 MByte pages, 4-way set associative, 8 entries
Shared 2nd-Level TLB: 4 KByte pages, 4-way associative, 512 entries
3rd-level cache: 512 KByte, 4-way set associative, 64 byte line size
3rd-level cache: 1 MByte, 4-way set associative, 64 byte line size
3rd-level cache: 2 MByte, 4-way set associative, 64 byte line size
3rd-level cache: 1 MByte, 8-way set associative, 64 byte line size
1st-level data cache: 32 KBytes, 4-way set associative, 64 byte line size
Trace cache: 12 K-Ops, 8-way set associative
Trace cache: 16 K-Ops, 8-way set associative
Trace cache: 32 K-Ops, 8-way set associative
Trace cache: 64 K-Ops, 8-way set associative
Instruction TLB: 2M/4M pages, fully associative, 8 entries
2nd-level cache: 1 MBytes, 4-way set associative, 64 bytes line size
2nd-level cache: 128 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 256 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 512 KBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 1 MBytes, 8-way set associative, 64 bytes line size, 2 lines per sector
2nd-level cache: 2 MBytes, 8-way set associative, 64 byte line size
2nd-level cache: 512 KBytes, 2-way set associative, 64 byte line size
2nd-level cache: 512 KBytes, 8-way set associative, 64 byte line size
2nd-level cache: 256 KBytes, 8-way associative, 32 byte line size
2nd-level cache: 512 KBytes, 8-way associative, 32 byte line size
2nd-level cache: 6MByte, 24-way set associative, 64 byte line size
Instruction TLB: 4 KByte pages, 32 Entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 64 Entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 128 Entries
Instruction TLB: 4 KByte and 2 MByte or 4 MByte pages, 256 Entries
Instruction TLB: 2-MByte or 4-MByte pages, fully associative, 7 entries
Data TLB0: 4 MByte pages, 4-way set associative, 16 entries
Data TLB0: 4 KByte pages, 4-way associative, 16 entries
Data TLB0: 4 KByte pages, fully associative, 16 entries
Data TLB0: 2 MByte or 4 MByte pages, 4-way set associative, 32 entries
Data TLB: 4 KByte and 4 MByte pages, 64 Entries
Data TLB: 4 KByte and 4 MByte pages, 128 Entries
Data TLB: 4 KByte and 4 MByte pages, 256 Entries
1st-level data cache: 16 KByte, 8-way set associative, 64 byte line size
1st-level data cache: 8 KBytes, 4-way set associative, 64 byte line size
1st-level data cache: 16 KBytes, 4-way set associative, 64 byte line size
2nd-level cache: 384 KBytes, 6-way set associative, sectored cache, 64-byte line size
2nd-level cache: 512 KBytes, 4-way set associative, sectored cache, 64-byte line size
No 2nd-level cache or, if processor contains a valid 2nd-level cache, no 3rd-level cache
2nd-level cache: 128 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 256 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 512 KBytes, 4-way set associative, 32 byte line size
2nd-level cache: 1 MBytes, 4-way set associative, 32 byte line size
2nd-level cache: 2 MBytes, 4-way set associative, 32 byte line size
3rd-level cache: 4 MBytes, 4-way set associative, 64 byte line size
3rd-level cache: 8 MBytes, 4-way set associative, 64 byte line size
3rd-level cache: 8 MByte, 8-way set associative, 64 byte line size
2nd-level cache: 4 MBytes, 16-way set associative, 64 byte line size
3rd-level cache: 6MByte, 12-way set associative, 64 byte line size
3rd-level cache: 8MByte, 16-way set associative, 64 byte line size
3rd-level cache: 12MByte, 12-way set associative, 64 byte line size
3rd-level cache: 16MByte, 16-way set associative, 64 byte line size
1st level data cache: 8 KBytes, 2-way set associative, 32 byte line size
Instruction TLB: 4 MByte pages, 4-way set associative, 4 entries
1st level data cache: 16 KBytes, 4-way set associative, 32 byte line size
1st level data cache: 16 KBytes, 4-way set associative, 64 byte line size
1st level data cache: 24 KBytes, 6-way set associative, 64 byte line size
2nd level cache: 256 KBytes, 8-way set associative, 64 byte line size
3rd level cache: 512 KBytes, 4-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 1 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 2 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
3rd level cache: 4 MBytes, 8-way set associative, 64 byte line size, 2 lines per sector
1st level data cache: 32 KBytes, 8-way set associative, 64 byte line size
1st level instruction cache: 32 KBytes, 8-way set associative, 64 byte line size
2nd-level cache: 128 KBytes, 4-way set associative, sectored cache, 64-byte line size
2nd-level cache: 192 KBytes, 6-way set associative, sectored cache, 64-byte line size
2nd-level cache: 128 KBytes, 2-way set associative, sectored cache, 64-byte line size
2nd-level cache: 256 KBytes, 4-way set associative, sectored cache, 64-byte line size
Missing a Low Surrogate in UTF-16 sequence
Failed to get ANSI replacement character
Unable to open key "%s\%s" for read
Unable to open key "%s\%s" and access value "%s"
"%s\%s\%s" is of wrong kind or size
"%s" does not match RootKey
Failed to create mutex
Null descriptor
Instruction TLB: 4 KByte pages, 4-way set associative, 32 entries
Instruction TLB: 4 MByte pages, 4-way set associative, 2 entries
Data TLB: 4 KByte pages, 4-way set associative, 64 entries
Data TLB: 4 MByte pages, 4-way set associative, 8 entries
Data TLB1: 4 MByte pages, 4-way set associative, 32 entries
1st level instruction cache: 8 KBytes, 4-way set associative, 32 byte line size
1st level instruction cache: 16 KBytes, 4-way set associative, 32 byte line size
1st level instruction cache: 32 KBytes, 4-way set associative, 64 byte line size
SetCipher failed.
Error creating SSL session.
Error creating SSL context.
Could not load root certificate.
Could not load certificate.
Could not load key, check password.
Could not load DH Parameters.
Error getting SSL method.
Error setting File Descriptor for SSL
Error binding data to SSL socket.
EOF was observed that violates the protocol
Protocol field is empty
Host field is empty
Character Index %d out of Range, Length = %d
Character at Index %d is not a valid UTF-16 High Surrogate
Character at Index %d is not a valid UTF-16 Low Surrogate
The IOHandler already has a different Intercept assigned
Transparent proxy cannot bind.
UDP Not supported by this proxy.
Buffer terminator must be specified.
Buffer start position is invalid.
Reply Code is not valid: %s
Reply Code already exists: %s
IOHandler value is not valid
Algorithm %s not permitted in FIPS mode
Chunk Started
Not Acceptable
Unknown Protocol
Request method requires HTTP version 1.1
Unsupported hash algorithm. This implementation supports only MD5 encoding.
Error accepting connection with SSL.
Error connecting with SSL.
Address type not supported.
%s: Circular links are not allowed
Not enough data in buffer. (%d/%d)
Too much data in buffer.
File "%s" not found
Not Connected
Object type not supported.
No data to read.
Read timed out.
Max line read attempts exceeded.
Max line length exceeded.
Set LargeStream to True to send streams greater than 2GB
Data is too large for stream
Connect timed out.
Already connected.
Maximum number of line allowed exceeded
Set Size Exceeded.
UDP is not support in this SOCKS version.
Request rejected or failed.
Request rejected because SOCKS server cannot connect.
Request rejected because the client program and identd report different user-ids.
Unknown socks error.
Socks server did not respond.
Invalid socks authentication method.
Authentication error to socks server.
General SOCKS server failure.
Connection not allowed by ruleset.
Network unreachable.
Host unreachable.
Connection refused.
TTL expired.
Command not supported.
No route to host.
Directory not empty
Host not found.
Stack Class is undefined.
Stack already created.
Only one TIdAntiFreeze can exist per application.
Cannot change IPVersion when connected
Can not bind in port range (%d - %d)
Connection Closed Gracefully.
Could not bind socket. Address and port are already in use.
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid IPv6 address
The requested IPVersion / Address family is not supported.
Not all bytes sent.
Package Size Too Big.
Cannot assign requested address.
Network is down.
Network is unreachable.
Net dropped connection or reset.
Software caused connection abort.
Connection reset by peer.
No buffer space available.
Socket is already connected.
Socket is not connected.
Cannot send or receive after socket is closed.
Too many references, cannot splice.
Connection timed out.
Connection refused.
Too many levels of symbolic links.
File name too long.
Host is down.
Invalid argument.
Too many open files.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Destination address required.
Message too long.
Protocol wrong type for socket.
Bad protocol option.
Protocol not supported.
Socket type not supported.
Operation not supported on socket.
Protocol family not supported.
Address family not supported by protocol family.
Address already in use.
Invalid destination index (%d)
Invalid codepage (%d)
Failed attempting to retrieve time zone information.
Error on call to Winsock2 library function %s
Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
Connected.
Disconnecting.
Disconnected.
%s
Socket Error # %d
%s
Interrupted system call.
Bad file number.
Access denied.
Buffer fault.
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Invalid count (%d)
Cannot open file "%s". %s
Invalid stream format
'%s' is an invalid mask at (%d)
''%s'' is not a valid component name
Invalid property value
Invalid property element: %s
Invalid property path
Invalid property type: %s
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error

Version Info

TLS Callbacks

StartAddressOfRawData 0x615000
EndAddressOfRawData 0x615030
AddressOfIndex 0x5370a4
AddressOfCallbacks 0x616010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Could not read a WIN_CERTIFICATE's header. [!] Error: Could not read a VS_VERSION_INFO header! [*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .rsrc is larger than the executable! [*] Warning: Section .rsrc is larger than the executable! [!] Error: Could not read a VS_VERSION_INFO header! [*] Warning: Could not parse a VERSION_INFO resource! [*] Warning: Resource PLATFORMTARGETS is empty! [*] Warning: Resource ROLOTAQ is empty! [*] Warning: Resource TMAINFORM is empty! [*] Warning: Resource 32761 is empty! [*] Warning: Resource 32762 is empty! [*] Warning: Resource 32763 is empty! [*] Warning: Resource 32764 is empty! [*] Warning: Resource 32765 is empty! [*] Warning: Resource 32766 is empty! [*] Warning: Resource 32767 is empty! [*] Warning: Resource 0 is empty! [*] Warning: Resource is empty! [*] Warning: Section .rsrc is larger than the executable!
<-- -->