19ee58283482c47506cd7762482063a6

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2010-Aug-26 15:22:36
Detected languages English - United States
Debug artifacts c:\bld_area\NMR_r1.5_42\bin\bin.iru\NPE.pdb
CompanyName Symantec Corporation
FileDescription Norton Power Eraser
FileVersion 1.5.0.42
InternalName NMR
LegalCopyright Copyright (c) 1997-2010 Symantec Corporation
OriginalFilename NPE.exe
ProductName Norton Power Eraser
ProductVersion 1.5

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ v6.0 DLL
Microsoft Visual C++ 6.0 - 8.0
MASM/TASM - sig2(h)
MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regsvr32.exe
  • rundll32.exe
Contains references to internet browsers:
  • iexplore.exe
May have dropper capabilities:
  • %TEMP%
  • CurrentControlSet\Services
  • CurrentVersion\Run
Miscellaneous malware strings:
  • Virus
  • cmd.exe
  • virus
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to Blowfish
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
  • RegDeleteKeyW
  • RegQueryInfoKeyW
  • RegEnumKeyExW
  • RegSetValueExW
  • RegCreateKeyExW
  • RegDeleteValueW
  • RegEnumValueW
  • SHDeleteEmptyKeyW
  • SHDeleteKeyW
Possibly launches other programs:
  • CreateProcessA
  • CreateProcessAsUserW
  • ShellExecuteW
Uses Microsoft's cryptographic API:
  • CryptCATAdminCalcHashFromFileHandle
  • CryptCATAdminReleaseCatalogContext
  • CryptCATAdminEnumCatalogFromHash
  • CryptCATCatalogInfoFromContext
  • CryptCATAdminReleaseContext
  • CryptCATAdminAcquireContext
  • CryptVerifyMessageSignature
  • CryptMemFree
  • CryptMemRealloc
  • CryptMemAlloc
  • CryptDecodeObjectEx
  • CryptMsgOpenToDecode
  • CryptMsgClose
  • CryptMsgUpdate
  • CryptMsgGetParam
  • CryptMsgControl
  • CryptReleaseContext
  • CryptAcquireContextW
Can create temporary files:
  • CreateFileW
  • CreateFileA
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetAsyncKeyState
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Has Internet access capabilities:
  • WinHttpSendRequest
  • WinHttpReceiveResponse
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpCrackUrl
  • WinHttpSetOption
  • WinHttpSetStatusCallback
  • WinHttpGetProxyForUrl
  • WinHttpSetCredentials
  • WinHttpTimeFromSystemTime
  • WinHttpAddRequestHeaders
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpQueryHeaders
  • WinHttpOpen
  • InternetErrorDlg
  • InternetOpenA
  • InternetQueryOptionA
  • InternetOpenW
  • InternetSetOptionA
  • InternetGetLastResponseInfoA
  • InternetConnectA
  • InternetCombineUrlA
  • InternetCloseHandle
  • InternetReadFile
  • InternetConnectW
Leverages the raw socket API to access the Internet:
  • #16
  • #23
  • #52
  • #8
  • #21
  • #9
  • #3
  • #19
  • #1
  • #22
  • #18
  • #56
  • #4
  • #111
  • #12
  • #55
  • WSAStringToAddressW
  • #115
  • #116
  • #57
  • WSAAddressToStringW
  • #112
  • #51
  • #15
  • #11
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateTokenEx
  • AdjustTokenPrivileges
  • DuplicateToken
  • CheckTokenMembership
Interacts with services:
  • OpenServiceW
  • OpenSCManagerW
  • CreateServiceW
Enumerates local disk drives:
  • GetLogicalDriveStringsW
  • GetVolumeInformationW
  • GetDriveTypeW
Manipulates other processes:
  • EnumProcesses
  • ReadProcessMemory
  • OpenProcess
  • Process32NextW
  • Process32FirstW
Changes object ACLs:
  • SetNamedSecurityInfoW
Can take screenshots:
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertOpenStore
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource 10001 is possibly compressed or encrypted.
Resource 10100 detected as a PE Executable.
Resource 10101 detected as a PE Executable.
Resource 10200 detected as a PE Executable.
Resource 10201 detected as a PE Executable.
Info The PE is digitally signed. Signer: Symantec Corporation
Issuer: VeriSign Class 3 Code Signing 2004 CA
Safe VirusTotal score: 0/65 (Scanned on 2019-02-23 00:17:34) All the AVs think this file is safe.

Hashes

MD5 19ee58283482c47506cd7762482063a6
SHA1 dcd1edabb900203d6f411308f7dd8012760a5a04
SHA256 c87eb20e913f0f54fa9d516b2d41c5a614b12811b97bc7b6ca8ff454b7c99634
SHA3 fa24f804b860e5848849d7dfd014769172ff26d74ffc8494dca0b075701f8242
SSDeep 98304:s0b/nvuLNQHd+BCywa26np4nk9JZhrdf0H+9jKEe5Zus8SJhlA5bOrqNuRE6YAuR:5Gg8Yywry4nGvMH+cEUus8u5rqNX6iNv
Imports Hash 1e31f6e5106645d0bda592f618474cd4

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2010-Aug-26 15:22:36
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x372e00
SizeOfInitializedData 0x1ff400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00311B7A (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x374000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x57b000
SizeOfHeaders 0x400
Checksum 0x57a066
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a67061e87cfd650d5061ca519b012318
SHA1 86e9420c07613ff77d823fbff20c9fdcd224e608
SHA256 eacb4b3384f08d9beddf06422844f33c1f72a65b7cd5ba4eb7364e81a3f0f208
SHA3 de075fd0302f09ea547217db684ae64b9e6e730ebe4aaf37d44d3c5924a34c66
VirtualSize 0x372d8c
VirtualAddress 0x1000
SizeOfRawData 0x372e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.73552

.rdata

MD5 7f88f4705ccbe90b31c87114f99b4c3e
SHA1 f099ea7940a5d49756087d128097bc81c92d9938
SHA256 807abab0fa409439f2750bfb2d67801b4ce8febb774b615cbad45f47b03207a2
SHA3 d4c4222eab95539cd3b512749f8c1538d08b327571ab3c8f6caf16b3e3ca7f9f
VirtualSize 0xa9d70
VirtualAddress 0x374000
SizeOfRawData 0xa9e00
PointerToRawData 0x373200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.80911

.data

MD5 5851492b0e6eb2e86377d52d1d47ff5a
SHA1 6d45017d4cf2d784657cb76baad5081e13dc257d
SHA256 b93cd5f826159bef066c377b7491129aef9e6e4af90eeac3574eddcd7c4bf3b5
SHA3 52a838e22960037ac0398e302da7a6e510b954292f8fdaa3ed9b71b3b0534258
VirtualSize 0x297c8
VirtualAddress 0x41e000
SizeOfRawData 0x23800
PointerToRawData 0x41d000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.32751

.rsrc

MD5 fea1e80b0df52693a40489745bc7b249
SHA1 976d416828b8dfb74c02678b7abf81fad9ce6f8e
SHA256 88d214adc83e83021863a3272498d61ca015a5668141d5fcc4eea59d5c52b92e
SHA3 add62c242a3cd78e1003eb162bddd2367ce94251ac625e10ad25627f7c419747
VirtualSize 0xf93fc
VirtualAddress 0x448000
SizeOfRawData 0xf9400
PointerToRawData 0x440800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.36402

.reloc

MD5 8b2d3a7ff1df345429662fa3ea101412
SHA1 e115098489953dae9c09d58724ffbd13ded41069
SHA256 a2940adce405bfa0a491632a995e4d4c515d7b21e59299e89b03f3cde40d50cc
SHA3 cbb04abb6a59cc631c823fdfbe7cbea899f6388b8f2ff44bb75ae9c2b0558bb4
VirtualSize 0x38888
VirtualAddress 0x542000
SizeOfRawData 0x38a00
PointerToRawData 0x539c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.00177

Imports

WINHTTP.dll WinHttpSendRequest
WinHttpReceiveResponse
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpCrackUrl
WinHttpSetOption
WinHttpSetStatusCallback
WinHttpGetProxyForUrl
WinHttpSetCredentials
WinHttpTimeFromSystemTime
WinHttpAddRequestHeaders
WinHttpOpenRequest
WinHttpCloseHandle
WinHttpConnect
WinHttpQueryHeaders
WinHttpOpen
NETAPI32.dll NetUseGetInfo
NetApiBufferFree
NetShareGetInfo
PSAPI.DLL EnumProcesses
WS2_32.dll #16
#23
#52
#8
#21
#9
#3
#19
#1
#22
#18
#56
#4
#111
#12
#55
WSAStringToAddressW
#115
#116
#57
WSAAddressToStringW
#112
#51
#15
#11
WINTRUST.dll CryptCATAdminCalcHashFromFileHandle
CryptCATAdminReleaseCatalogContext
CryptCATAdminEnumCatalogFromHash
CryptCATCatalogInfoFromContext
CryptCATAdminReleaseContext
CryptCATAdminAcquireContext
WinVerifyTrust
CRYPT32.dll CryptVerifyMessageSignature
CertFreeCertificateContext
CertCompareIntegerBlob
CryptMemFree
CertNameToStrW
CertVerifyValidityNesting
CryptMemRealloc
CryptMemAlloc
CryptDecodeObjectEx
CertFindExtension
CertGetIntendedKeyUsage
CertGetIssuerCertificateFromStore
CertCompareCertificate
CertDuplicateCertificateContext
CertAddCertificateContextToStore
CertCreateCertificateContext
CertCloseStore
CryptMsgOpenToDecode
CryptMsgClose
CryptMsgUpdate
CryptMsgGetParam
CryptMsgControl
CertOpenStore
CertGetNameStringW
DNSAPI.dll DnsFree
DnsQuery_W
KERNEL32.dll InterlockedExchangeAdd
SetUnhandledExceptionFilter
ReleaseMutex
CreateMutexW
OpenMutexW
ReleaseSemaphore
CreateSemaphoreW
MapViewOfFileEx
GetSystemTime
GetVolumeNameForVolumeMountPointW
SetFileAttributesW
DeviceIoControl
SetFilePointerEx
InterlockedCompareExchange
CreateWaitableTimerW
QueueUserWorkItem
GetPrivateProfileSectionW
CompareStringA
QueryDosDeviceW
LoadLibraryA
GetSystemDirectoryA
GetLogicalDriveStringsW
BackupRead
BackupWrite
CompareFileTime
GetVolumeInformationW
FindFirstFileExW
GetModuleFileNameA
FormatMessageA
ReadProcessMemory
LCMapStringW
LCMapStringA
CreateMutexA
CreateFileMappingA
FlushViewOfFile
GetThreadLocale
GetVersionExA
GetCurrencyFormatW
SetThreadLocale
CreateEventA
IsProcessorFeaturePresent
GetLocaleInfoA
FindResourceA
MulDiv
TlsSetValue
InterlockedExchange
GlobalSize
GlobalAlloc
GlobalLock
GlobalUnlock
WaitForMultipleObjectsEx
WaitForMultipleObjects
CreateEventW
ResetEvent
SetEvent
DuplicateHandle
HeapReAlloc
VirtualAlloc
HeapSize
VirtualFree
GetCurrentThread
GetVersionExW
GetSystemInfo
lstrcpyW
SetEndOfFile
GetFileSize
FlushFileBuffers
ReadFile
CreateThread
ExitThread
TerminateThread
ResumeThread
IsDebuggerPresent
Sleep
GetShortPathNameW
GetLongPathNameW
GetCurrentDirectoryW
GetCommandLineW
OutputDebugStringW
WriteFile
SetFilePointer
TerminateProcess
GetSystemTimeAsFileTime
GetLocalTime
RemoveDirectoryW
MoveFileExW
FindNextFileW
FindFirstFileW
FindClose
lstrlenA
GetSystemDirectoryW
GetProcAddress
LoadLibraryW
GlobalFree
DeleteFileW
FileTimeToLocalFileTime
SystemTimeToFileTime
GetLocaleInfoW
GetNumberFormatW
GetTimeFormatW
GetDateFormatW
GetDriveTypeW
OpenProcess
GetCurrentProcessId
Process32NextW
ProcessIdToSessionId
Process32FirstW
CreateToolhelp32Snapshot
ExpandEnvironmentStringsW
GetSystemDefaultLangID
HeapFree
GetProcessHeap
HeapAlloc
GetCurrentProcess
WTSGetActiveConsoleSessionId
GetExitCodeThread
FileTimeToSystemTime
GetFileTime
UnmapViewOfFile
MapViewOfFile
CreateFileMappingW
GetFileSizeEx
CreateFileW
CompareStringW
LocalFree
LocalLock
FormatMessageW
LocalAlloc
WaitForSingleObject
CloseHandle
GetTickCount
WideCharToMultiByte
LockResource
SetErrorMode
GetCurrentThreadId
CreateDirectoryW
DeleteCriticalSection
InitializeCriticalSection
GetModuleFileNameW
GetModuleHandleW
FindResourceW
LoadResource
SizeofResource
GetLastError
EnterCriticalSection
RaiseException
LeaveCriticalSection
lstrcmpiW
lstrlenW
FindResourceExW
GetFileAttributesW
FreeLibrary
GetUserDefaultUILanguage
GetSystemDefaultUILanguage
GetEnvironmentStrings
FreeEnvironmentStringsA
SetEnvironmentVariableA
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
TlsGetValue
TlsFree
TlsAlloc
SetLastError
AllocConsole
FlushInstructionCache
HeapDestroy
RtlUnwind
VirtualProtect
VirtualQuery
ExitProcess
DeleteFileA
MoveFileA
GetTimeFormatA
GetDateFormatA
CreateProcessA
GetCPInfo
GetStringTypeW
GetStdHandle
HeapCreate
GetACP
GetOEMCP
IsValidCodePage
FreeEnvironmentStringsW
LoadLibraryExW
GetExitCodeProcess
CreatePipe
GetStringTypeA
IsValidLocale
EnumSystemLocalesA
GetUserDefaultLCID
CreateFileA
GetFileAttributesA
InitializeCriticalSectionAndSpinCount
GetModuleHandleA
GetConsoleMode
GetConsoleCP
GetTimeZoneInformation
QueryPerformanceCounter
GetStartupInfoA
GetFileType
SetHandleCount
GetEnvironmentStringsW
MultiByteToWideChar
InterlockedDecrement
InterlockedIncrement
GetTempPathA
GetTempFileNameA
GetComputerNameA
UnhandledExceptionFilter
SetWaitableTimer
GetStartupInfoW
USER32.dll IsWindow
wsprintfW
GetDesktopWindow
GetSystemMenu
GetMenuItemCount
EnableMenuItem
CharNextW
PostMessageW
SendMessageW
DestroyWindow
GetCursorPos
TrackPopupMenu
LoadIconW
DestroyIcon
RegisterWindowMessageW
CopyRect
IsClipboardFormatAvailable
OpenClipboard
GetClipboardData
CloseClipboard
DrawIconEx
GetGuiResources
SetWindowLongW
GetWindowLongW
DefWindowProcW
CallWindowProcW
SystemParametersInfoW
SetWindowPos
ShowWindow
EnableWindow
GetFocus
SetFocus
SetClipboardData
EmptyClipboard
KillTimer
RedrawWindow
RegisterClassExW
GetClassInfoExW
LoadCursorW
CreateWindowExW
CallNextHookEx
SetWindowsHookExW
UnhookWindowsHookEx
GetActiveWindow
GetDialogBaseUnits
CreateDialogIndirectParamW
DialogBoxIndirectParamW
AdjustWindowRectEx
GetClientRect
GetParent
GetWindowRect
GetMonitorInfoW
MonitorFromWindow
GetWindow
SetTimer
SetWindowTextW
FlashWindow
CountClipboardFormats
GetWindowThreadProcessId
EndDialog
GetMenuState
PostMessageA
MessageBoxA
LoadCursorA
RegisterClassExA
RegisterClassA
UnregisterClassA
RegisterClassW
UnregisterClassW
RegisterWindowMessageA
ReleaseDC
BeginPaint
EndPaint
FillRect
SendMessageA
SetCapture
GetCapture
ReleaseCapture
ClientToScreen
GetWindowLongA
GetDlgCtrlID
UpdateWindow
GetSysColor
GetAsyncKeyState
GetKeyState
GetWindowDC
InflateRect
OffsetRect
GetClassLongA
DefWindowProcA
GetScrollInfo
GetDoubleClickTime
ScreenToClient
WindowFromPoint
InvalidateRect
MoveWindow
GetWindowPlacement
IsWindowEnabled
SetWindowsHookExA
GetUpdateRect
DrawTextA
PeekMessageA
CreateCursor
SetCursor
LoadCursorFromFileA
NotifyWinEvent
IsWindowVisible
GetWindowTextW
SetWindowLongA
IsChild
CreateWindowExA
SetActiveWindow
GetDC
SystemParametersInfoA
SetScrollInfo
BeginDeferWindowPos
DeferWindowPos
EndDeferWindowPos
ScrollDC
ValidateRect
ScrollWindowEx
SetForegroundWindow
GetKeyboardLayout
CreateCaret
DestroyCaret
SetCaretPos
SendMessageTimeoutA
RegisterClipboardFormatW
EnumClipboardFormats
LoadStringW
MapWindowPoints
GetSystemMetrics
PostQuitMessage
ExitWindowsEx
CharPrevW
DispatchMessageW
MessageBeep
DrawFrameControl
GetSysColorBrush
DrawEdge
DrawTextW
InvertRect
GetIconInfo
CreateIconFromResourceEx
GetCaretBlinkTime
AnimateWindow
MsgWaitForMultipleObjectsEx
PeekMessageW
GetMessageW
TranslateMessage
DispatchMessageA
IsWindowUnicode
GetMessageA
ADVAPI32.dll MakeAbsoluteSD
ControlTraceW
RegOpenKeyExW
RegQueryValueExW
RegCloseKey
GetTraceLoggerHandle
GetTraceEnableLevel
IsTextUnicode
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
RegDeleteKeyW
RegQueryInfoKeyW
RegEnumKeyExW
RegSetValueExW
RegCreateKeyExW
RegDeleteValueW
ImpersonateLoggedOnUser
OpenProcessToken
GetUserNameA
RevertToSelf
GetTokenInformation
LookupAccountSidW
ConvertSidToStringSidW
GetLengthSid
SetTokenInformation
DuplicateTokenEx
CreateProcessAsUserW
ConvertStringSidToSidW
InitializeSecurityDescriptor
CreateWellKnownSid
SetEntriesInAclW
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetSecurityDescriptorDacl
FreeSid
AllocateAndInitializeSid
SetNamedSecurityInfoW
OpenThreadToken
RegEnumValueW
LookupPrivilegeValueW
AdjustTokenPrivileges
StartServiceW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
DuplicateToken
CopySid
IsValidSid
GetSidSubAuthority
InitializeSid
GetSidLengthRequired
CheckTokenMembership
CreateServiceW
ReadEncryptedFileRaw
CloseEncryptedFileRaw
OpenEncryptedFileRawW
WriteEncryptedFileRaw
CryptReleaseContext
CryptAcquireContextW
GetSecurityDescriptorControl
GetSecurityDescriptorSacl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
MakeSelfRelativeSD
GetSecurityDescriptorLength
ConvertStringSecurityDescriptorToSecurityDescriptorW
InitializeAcl
AddAce
GetAclInformation
GetAce
TraceMessage
SHELL32.dll ShellExecuteW
SHParseDisplayName
SHOpenFolderAndSelectItems
SHBrowseForFolderW
SHGetPathFromIDListW
SHGetSpecialFolderPathA
ShellExecuteExW
SHGetSpecialFolderPathW
SHGetFolderPathA
SHGetFileInfoW
DragQueryFileW
ShellExecuteExA
SHGetFolderPathW
#680
ole32.dll OleRun
StgCreateStorageEx
StgOpenStorageEx
PropVariantClear
PropVariantCopy
CoCreateGuid
StringFromGUID2
OleSaveToStream
GetHGlobalFromStream
CreateStreamOnHGlobal
ReleaseStgMedium
RevokeDragDrop
RegisterDragDrop
OleInitialize
OleLoadFromStream
CoUninitialize
CoInitializeEx
CoInitializeSecurity
CoCreateInstance
CoTaskMemRealloc
CoTaskMemAlloc
CoTaskMemFree
OLEAUT32.dll #20
#19
#77
#15
#21
#148
#22
#40
#411
#23
#16
#150
#149
#11
#8
#9
#2
#184
#185
#6
#277
#200
#27
#4
#24
SHLWAPI.dll PathSkipRootW
PathFindExtensionW
UrlCanonicalizeW
PathRemoveFileSpecW
PathRemoveBackslashW
PathIsUNCServerW
PathAppendW
SHDeleteEmptyKeyW
SHDeleteKeyW
PathIsUNCW
PathIsFileSpecW
PathAddBackslashW
WININET.dll HttpOpenRequestA
InternetErrorDlg
HttpSendRequestA
InternetOpenA
InternetQueryOptionA
InternetOpenW
InternetSetOptionA
InternetGetLastResponseInfoA
InternetConnectA
HttpQueryInfoA
InternetCombineUrlA
InternetCloseHandle
HttpOpenRequestW
HttpAddRequestHeadersW
HttpSendRequestW
InternetReadFile
InternetConnectW
OLEACC.dll AccessibleObjectFromWindow
LresultFromObject
IMM32.dll ImmAssociateContextEx
ImmGetCompositionStringW
ImmNotifyIME
ImmGetContext
ImmAssociateContext
ImmReleaseContext
ImmIsIME
ImmSetCandidateWindow
WINMM.dll timeGetTime
timeKillEvent
PlaySoundA
timeSetEvent
timeGetDevCaps
WTSAPI32.dll WTSQueryUserToken
USERENV.dll GetAllUsersProfileDirectoryW
UnloadUserProfile
IPHLPAPI.DLL GetAdaptersInfo
VERSION.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
RPCRT4.dll UuidCreateSequential
GDI32.dll GetObjectA
SetBkColor
SetTextColor
CreateSolidBrush
SetWindowOrgEx
GetViewportExtEx
GetWindowExtEx
GetMapMode
LPtoDP
BitBlt
DeleteDC
SelectObject
RestoreDC
SetLayout
CreateCompatibleDC
EndDoc
IntersectClipRect
StartDocA
GetDeviceCaps
StartPage
EndPage
SetTextAlign
GetTextAlign
TextOutA
TextOutW
GetPixel
RoundRect
RectVisible
CreatePen
CreatePatternBrush
GetTextExtentExPointW
Rectangle
SetBkMode
CreateBitmap
SetPixel
SetBrushOrgEx
CreateHatchBrush
GetTextExtentPoint32A
PatBlt
GetTextExtentPoint32W
GetWindowOrgEx
DPtoLP
SetWindowExtEx
SetViewportExtEx
SetStretchBltMode
StretchDIBits
GetDIBits
StretchBlt
CreateDIBSection
CreateDIBPatternBrushPt
EnumFontFamiliesExW
AddFontMemResourceEx
EnumFontFamiliesExA
CreateFontA
SetMapMode
SetViewportOrgEx
GetStockObject
DeleteObject
GetTextMetricsA
GetGlyphOutlineW
GetKerningPairsA
CreateCompatibleBitmap
CreateRectRgnIndirect
CombineRgn
ExcludeClipRect
GetClipBox
SaveDC
GetCurrentObject
COMDLG32.dll GetOpenFileNameW
GetSaveFileNameW
PrintDlgA
COMCTL32.dll ImageList_DrawEx
ImageList_GetImageInfo
ImageList_GetIconSize
urlmon.dll FindMimeFromData

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.02102
MD5 670d5bda0f13a798a221c15859e6fd83
SHA1 b55246990b2a71758e3dc15c52555724989da267
SHA256 c72a1574a6b85a799f5fb4a084855a739bf26f1a1b834a96ee08b6a95d982817
SHA3 9caa7899834f392f62cb9a8603de21530d81c9e2d55f4fbf3ced1f52a3d9bb3a

8

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.08495
MD5 5108f623c6d5adbc39e9da8d6e5fa16d
SHA1 ab647085a2ce832cf5c010d450b60ec8037fd0e0
SHA256 bef1a91a6a869a0b22feae1491996f96bc9809880264f6a495fb8e03b23600ff
SHA3 1349342ea9912c2fd1a61cbaee744f8bbb8cb49fc3f2d10d8206928bcc265a3d

9

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38376
MD5 17c442878512578eea1b0a6b1a339680
SHA1 c88f206e91267e87713a1ecc12afdf2126b518bc
SHA256 2dc04e6dba964a4db1f2edf96f702523c44aa41a0e054454a02bf0cb93636829
SHA3 77bcf7ce1b1a105b7fc7f1c940d3498bbc23a2c63aeca58b3b309832154e30db

10

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x33a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14393
MD5 4d994185f444daa85b603e3d9d69d6de
SHA1 3253bdd2a32bea5cda94b6151c2c1a651f9cf6bc
SHA256 30997b7e37bf10a5316483cdc60a8caf7af9ba398e69d01bba02132a0a76b63f
SHA3 703d588bc2d6da931b175a6d9cb5f06e29c0f52b041378c5beef0b199d9646b8

15

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.69073
MD5 f9380e2e6d6107ff0ccb7b08b7134df2
SHA1 aeb09b4ea1282069df2a9b20e00342f99ed15f55
SHA256 afa96ed4013bba960ff1d939c4c728461b10595eb9dcbbaa1613d1fa7f7e5cf0
SHA3 002dc47381f6ab29a40e1dbb6b3a7d6b866b25ce278e0631ab88998ca8ce7655

16

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x15a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50123
MD5 324519201e084b2d8343505ccf30b67f
SHA1 f9a21ea77ac1473a7ecc9c14959dc2ecb9309eeb
SHA256 4feaf65620d9f8f3e48b6885a1816db2c57bf2244f400dc396455e64afff950d
SHA3 e47609300adfdccaa0ae918e6f2d60f0b6f0970b6edb7f928c2d64b0d5c96ad9

17

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xf06
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51734
MD5 f4907ba987c4d1a810ccec96ce5d17bd
SHA1 7f56fc8135914271e24c8647d64a2de1afc56b3d
SHA256 ece03d6e7a5f290a59e907dd1c379381210edfceb471221d84852b627c33d009
SHA3 f728b9f8bbc4d20978dc0af383b3899b62501cff4b22eaf28adf3d2910ff49ae

18

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x332
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28401
MD5 cace5f481a36c3e20d8d1e03f75aa89f
SHA1 feb176ac8a2f3313871680801ce24367e06852cd
SHA256 cb8d6748477efe85b3d6907512836d142374d9ca2aa5a5d5419d24bab253786b
SHA3 0d2301b3e905a92ffd69913db1d42e945fd19401910af388b403341ff59218e8

19

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27522
MD5 a85734e36aeb99a99b848b3e3cdb6d46
SHA1 20fae3bbf6c5a22322ed2d2051752e45dd1004a7
SHA256 39ba340d04c05332b56dc7a4bcd841750a1dd3c833b45fd99250721a21d05220
SHA3 ccd0885e45b009a50c3742174ad0f2a3557beda41aff4fd227ab218b3eed5ebf

22

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03871
MD5 9c8a5c4d5b01c55f3e7ebe0db10e7447
SHA1 91bd3cec019258dddd9799ee3644fc8d147683c1
SHA256 3d9e5041122f273293e0458c04bce31e300c4f69e0012ab4ba28f229369e2712
SHA3 16aac67e0a880851ccd5a01cad64bee9dec8a61ca589771c70defbad5f59f85f

23

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x276
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04216
MD5 6a99ff65c61d39005ba272943880ad35
SHA1 176d3fb2962dfd88f6017c0276a3dacdc6507843
SHA256 aff5830c1b9ff32987ca93ee8c6c1700479c3be4295da9cb2672da6c8d056829
SHA3 071518b558b795916e1d9311115fd8450d139ee594d0d467fd52dfd1005db9b1

26

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x500
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09326
MD5 5dee57f21ea0a6bde584b02ed7e1eef1
SHA1 16325f66131bece2016a6afe8272136bcd59051d
SHA256 a230a125df9a6563edcb9d570bcd8b40fc4d323a2adf788405d390ae3985b993
SHA3 af5f24a9439aa9cbbba191e8185f0df9ae5c0771e490b3844f5954d61dce2856

32

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x91a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41488
MD5 a472c458be590f5ba2c178802d8c7c9a
SHA1 2d9a7781aa6723bdbc819c264a087346de56fa32
SHA256 b05e29506aa903280e8ec4606b02e3d8d1da95db4e65ca84c1316810278a73dc
SHA3 98009a59ae2d53d78a7acb8de6377b831b1b1b275321eed92382106b524feaf0

33

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xb6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.72862
MD5 66df205a6ad7e099591c650586eb56c8
SHA1 7391a69b59630f9cb7a6f7d976bb91551d718da3
SHA256 444428a74bbd59aff3c7a4a2878fdd577f6bd2d4d3b40e096fa1d326de377c6b
SHA3 2f89e272690ed512e60bcd2aad91eb4890dc4bf5987d2e8cbe6ef6d968ed3fda

10001

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7aed
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.98697
MD5 6799ad32494ee51a27b0a278892b4ffc
SHA1 81b000da7f8c9676a8fc6a5ea8fac0d56631ecfd
SHA256 25451d77d08e6f27a22b401a65ee7ddb0eb0137022692a99ff235b84b27be385
SHA3 dca42f9cdff8c802cbd688ec8df3f3109b9879d3f47ac857921e260c719c27e5

10100

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xf830
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.53183
Detected Filetype PE Executable
MD5 d5aaac2d54a7cfbd8bb478cf0fd1f46c
SHA1 d8f528fddb688124dd699c093e3e66bb1e40e816
SHA256 78cf2a0c048aba3e97fa0a9aa403e8024c3e6d8e3aefb2cdb39eb4587e0072c5
SHA3 336f2a12e56d3dd8ba084d28871f7a30d1cfb88c5734307defa23a522ffec87d

10101

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x13030
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.23321
Detected Filetype PE Executable
MD5 440b18ffbf810e71c4dffb35288f76a2
SHA1 c1f06c393a535c930f0fe56cd4c2dc9332aada26
SHA256 204cb3d7809aad7e72ae354cc976fccc8f71e3859692b2aa7a5dede388b845e6
SHA3 0fdc08344c869f03f63fa7e42831a2d493e447f7b9e147a9f4576c4dd04c3d74

10200

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xb630
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.46663
Detected Filetype PE Executable
MD5 2d6b7efda9d4a44c7c5bdfe8d0bbc839
SHA1 bb8b5a4496d3c5e614b15fa612566c9ef788c156
SHA256 0b1e1bb34eb6fc2c1e3f6176b20b72bde45a0e2bea9ea9342cf8d3e57289e7dd
SHA3 b80106277917210572abf2eccbf4a63b9297436f60c0b695ec9faede0f5f2057

10201

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x10830
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.38017
Detected Filetype PE Executable
MD5 9adb715717b397e61d79a4bb18f3a536
SHA1 0c16ace197cf7182e4f158ed668d0aca505ca0c1
SHA256 a0243ff1e2352e1eeea1e8c87749d4c888bf36fa4605ef0808040d3f128d7428
SHA3 2716b69c71e6428bdc894bcc0c8fa3286bd2c2e932077329903ac23c9ffadc0c

600

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Icon file
MD5 3e1d980f0dc747eec9d946c155cb1498
SHA1 15414ced0202f709d400c957d441a8856dde8479
SHA256 027e12c81d53ebb492d0e1ce8166c0c004e135274105fb79465b6b97bc6c71cd
SHA3 11e83c27ff3b8cca2c537273338202138c94fb4b10a6b2daf0f7d23d177cc049

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38561
MD5 8cde9a3bc9ad8d0e79f469261b50f94b
SHA1 42de70ccd0d1ee5c053584b191e6f7bc909bec3e
SHA256 1e8c39dfd288519df419bb61fe66171980e6700b653b28478579e6997d1c1f5e
SHA3 f6b625f887e6ca15f1130d07d96a46ecfdc3ba7958b60d3fe4201985cb5e8c27

ACTBUTTON_47PX_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x162
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.12717
Detected Filetype PNG graphic file
MD5 aa5d7cff47944980df6982bf2dd8fd12
SHA1 fa430454cb28c44d030e655f2562d2e6ef424bac
SHA256 4433b40bea5a491f37cb2bf3d585e9ab00b7a8c9b32109216225e330922614ae
SHA3 0f6b58e6a7ae7990585cd5066dc603a946a5b80643923e2c83e135204843dad6

ACTBUTTON_47PX_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x14d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.10322
Detected Filetype PNG graphic file
MD5 5019b13fb227c5fba8fcc34a9ff9deb2
SHA1 956c93ed8448ff9201d3eb30669331cc5d6bc430
SHA256 0f696537bf43116e467fd4f98a92abcff6010acacb8203008b2cd5efb9023700
SHA3 0156df1306d3ae9ff6121ff8eeaddaee1fe60eeacd647b196e1aa8b544f45fdf

ACTBUTTON_47PX_SELECTOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x162
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.16428
Detected Filetype PNG graphic file
MD5 3dcadecf7edd1b7694ac34858a46f421
SHA1 021a72f4fc79dadc73aaf55137d70a7370dccb41
SHA256 c33fc236cfc2552b61f9acd263673a90e8cce17e5f322a26413af69eeca309f4
SHA3 a83791491f260b01208d6d59d4d9e5940e0b380fdf146180ac6b9e780cc3da60

AGE_MATURE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xfb3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91688
Detected Filetype PNG graphic file
MD5 0beaaf5f1aa94761d7602f0496b24146
SHA1 ecfd5c460ef584ba1d39f51368f76f10b4d4984c
SHA256 2b963382bb60343437fb4b128b330ff502f3d9a1717e5fd8d72e44bf9ef7e37d
SHA3 7030a8a844e71358af8c2e02e293e67638e6241c27f599b4587b26c783c45d39

AGE_NEW.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x120c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93066
Detected Filetype PNG graphic file
MD5 fde116bf5709e699e36fcaeb4d53b37f
SHA1 c217dbef72630abfb173e57254a4ef4f98228b53
SHA256 f421823679cc4b2ad10ad2c50313b398bae312aa3ca1ee4352143be332a8a344
SHA3 bd26630e6934e7829b82f9e0d9b1a002d3e33018db6a8094a87aa1dd67742105

AGE_UNKNOWN.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x115f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92014
Detected Filetype PNG graphic file
MD5 157d7c4c6bb30b23d1a1b8cf72bcf4ee
SHA1 a22dbe96a623b85d5f60eb7365ea5d16c5c4b9b3
SHA256 2fc666a4d2572617dc912d237fdd20b9b8548dc39ae5a14ccd015524b71ad7d5
SHA3 0e619c67e5473c242791910d826a999c59245affcfa4da7368938670ff8dcea4

AGE_VERY_NEW.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x11aa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92908
Detected Filetype PNG graphic file
MD5 e83267809c8837e550995ba70c8ce64d
SHA1 5a124cb6e0671dce9f7bac58acc32125b250d227
SHA256 55eb7d0ac010f2fcb3b7b58ecb5136ab6465384d90f6275e4661ab3f0f4527b3
SHA3 fba8b6551f97d6270db1e19ba6a9f2e028990eec29add416c89f06444e3311d5

ANIME_INFINITEBAR.GIF

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a9e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9204
Detected Filetype GIF graphic file
MD5 2bd6bb2c69ff6f4b1671db0fd12d3bb8
SHA1 6e9b5959e3e7358baf4a6dc0ed60fe310af89e87
SHA256 5db67b741ef94a07b15ce35362da2527e52ebcb1bb709ed39dc258842b9988f3
SHA3 5a7ebbec4267f3e748c7ebc69c430b71a6dd9e47c11224d0752ff574718532a9

ANIME_PROGRESSBAR_EMPTY.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x10f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.33405
Detected Filetype PNG graphic file
MD5 0963aa55267787ee27df23484617c0ac
SHA1 b36e47799a2737cd0858e4cea0c460d5cf5496b2
SHA256 de26e4fef3e0f40da5df6482ee1bf9122a7c0a468fd83590a0d2f32ec6f7a151
SHA3 34c02a98dd892077a8ec73bf5c8aa6d77a1e9ba05d5618ef9000c5a3e7a8e21b

ANIME_PROGRESSBAR_FILL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xc5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.07493
Detected Filetype PNG graphic file
MD5 bfa6e3df3b410005190593074b12e413
SHA1 1704f07ee540910b1db56444214f0991cb54660a
SHA256 d7001024286214de150c422347c9848374fe013ac0a7518df5530a2a0f39648b
SHA3 39508ebb8b140bbc91df772ec655c69c340efe249a8fc74e1d92e0b443cd69da

APPCARD.TXT

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x51c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20936
MD5 3384a0b0cbbed3f3f56f9d051ec0ebf6
SHA1 cd83300b57e0bc896c4a52ca096cd52d35c3bfa2
SHA256 629f6b3bf3a4ff2347acccd06813d9dc92aaea9ff7b2ab0da6c727b32647c6e4
SHA3 a440d183021f6f40db45e75dd5b1b1ea315cc72f101fada28bf73b4d26bc8f8d

ARROW_BOTTOM.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb03
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86137
Detected Filetype PNG graphic file
MD5 4743fad53322cdc2605ea8041ea86543
SHA1 d4481d9bdaa04d39751c49735291d055dea57cbe
SHA256 58bbda4413932624e7ef9bb32345749efdbfd3bfba8a01fa2586a0ac6063e4eb
SHA3 0d4dbcbb4dbd101046aea79ef424d93cd1a138ff97c63b6d83d8092321d48533

ARROW_RIGHT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xafd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86644
Detected Filetype PNG graphic file
MD5 958bbc4e8bea2a1f8accccb00790c191
SHA1 158f60c5f0e817e6f7d1985ab79f576eae620b7e
SHA256 578c35290f5e268f1e7f31b34e5f37c9884e4289b2d94d20cb0962663deda096
SHA3 9881d14f06a5ce6ce2bf299406538da1e47d2d774292bfb094804963d0142440

ATTENTION.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x6bf
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86859
Detected Filetype PNG graphic file
MD5 d1d519e8a31cd3257693d34a0c747b81
SHA1 4ba7c8df8b82c8e6449f782bffd2a3249ec9c086
SHA256 1b1b5c20f16253f1eca2466b6b34d5620e1320417b5c0e47b4baeaa5753eaabc
SHA3 5258748244ee2cc06f867c62ea3e3b54e6393c1883c3efa92dfa845e362ea80e

BACKGROUND_DROPDOWN_MENU.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x8fe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88973
Detected Filetype PNG graphic file
MD5 3df9f24fd15009ac6b1c449914dc0f6d
SHA1 7b2eb19efce70e32590f3351decb5b9f4b60b87a
SHA256 caf216356df78db45e543196f773b34ad68f943e220697275792481ed4298de5
SHA3 5072cece1449ce93e5a829156a90b7c07e5e1d01aacd6e048a4deb95a3562002

BEHAVIOR-EDIT-MENU.HTM

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2b1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01689
MD5 67c25ce86850a235dbcd4fdfe34de160
SHA1 50c0bcb3141bdb9feb39b139173610b9edf4f92c
SHA256 07d407f5d4c1ca24412def47615a26e43236958867e9e81967b45015b1d8f490
SHA3 5867497c32b20cbc2e7be214aa526439b3e35959ec85ae447ab0cf20f11c1fab

BEHAVIOR-TEXT-MENU.HTM

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.96556
MD5 fcdf5160b35be156d7f28ea24b762659
SHA1 1dd510487cebf60832ea5eb4a95d7e44d812306e
SHA256 660944e0be1a2a258374a7cddf8e0ca57bd28663758d1a56d3210f544e3110c9
SHA3 5f6c36fb19e71cd843884420de3b5045823bdbb5d13eae29fa2c355905336113

BLANK_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.31983
Detected Filetype PNG graphic file
MD5 539e1734a2fd4452ab89286ac8bf5f2e
SHA1 352c220b3f28d3e61b33d19d307d84f2304905bc
SHA256 8fc864b800261016f847837f7039914dcab1adacafac82f40bf4eddcf8ac907c
SHA3 68d65477897120951181c9cdf56e3017f8d501a678a43c083964f0d194a09dc7

BLANK_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x117
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.76569
Detected Filetype PNG graphic file
MD5 06201e554a786597babda5677a500aec
SHA1 e7f8f1b67cdbbbe6160e153766348d1e731cad40
SHA256 8a6fc57fec9dcc3eac9476fa4cce5e64b32ecabf35916afa74e30b655e55d1d7
SHA3 39e41a924482155bbc0181a63cafbc3ad0c7714ed7bed5077a115a047813e8d0

BLANK_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x135
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.01006
Detected Filetype PNG graphic file
MD5 159947a1b0f2f846c17b0d3fc11a0ab4
SHA1 e8ce3b80af6735f537f3ba74f812453f360e2480
SHA256 d4a5bfee2c5327b1922fbe1babdd97ffe8438485f421c0153617aadefef4ae4a
SHA3 6db778ec9cc057fde2a0389a9baf9d473c1d8cddaf9fe11ff1986d00965a9216

BLANK_NORMAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x114
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.81302
Detected Filetype PNG graphic file
MD5 352fb92a4ef14303354ca3cc4c071786
SHA1 0cac80aab69e38deb5fe3a2a52c26a327e54ee11
SHA256 b9b8a2ec2aad5d62dbb947ab97699b35aca185f3397bd6bdfeb3fda266931e85
SHA3 966d23551a59dc28d1740d7a89f9b051bf88e62b499091e50a37aebf9ebb364f

BUTTON_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xc91
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88415
Detected Filetype PNG graphic file
MD5 66667b027db3a61f3a8d47a2f3e20671
SHA1 41e964df7d54ca0d00500d95d65c8d92db4104b5
SHA256 d053aaf47d16ded944c66c019acea98b312ee29dacd12c278eb6406d89434219
SHA3 7f5140620797b9a43c2b93fe0208c9baa5440787a774b170481f2cc6c8948560

BUTTON_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbff
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8776
Detected Filetype PNG graphic file
MD5 6fa5c0621d198644cf9286f5a2a4dcf3
SHA1 e03134fe18d73cad097a7f71857a95853c346dda
SHA256 073dbbdf3910798f300828d58234aac20b808b2bc4e963f1afd42f41b539518c
SHA3 2ca4d4765fa5520d65f25b09aa844598c7ede3674b6fc34a0545ff343c96e923

BUTTON_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbd1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87193
Detected Filetype PNG graphic file
MD5 bd8efa1ccb9c2b21f245706a817eaa5b
SHA1 a73acdf2cedfb4158f4faa2e3c17bd39acf6ab27
SHA256 4169372de8ef0a314546dc1c33839170634f7b71cae80896eaee60dc6d633e77
SHA3 f0a65a7cce8533bdf965f873b7b34e8b439e3664a118399b3d37f4b401979df2

BUTTON_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbfd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87523
Detected Filetype PNG graphic file
MD5 3b5055aa99425073dccac5fc2acbfb53
SHA1 607aff4879088c48887e5083da4b07dbefa874b1
SHA256 423d0a81d81a476ccfba8772acfcdbe8e7f7b5ef20370e1c10f34ae4daddb976
SHA3 ba92b9e9307148521b3b9e57775daac4cc32055957683d15d245502646cbc04f

CENTER_FRAME.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1402
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.10497
Detected Filetype PNG graphic file
MD5 b748f3fddb58bb291016af76b91e5ff9
SHA1 254dc9adebfac2d6f6037a62d58520e4db3cf7fd
SHA256 a7e9894a0727480aa8858439267bb3893456b533311f3f02d9574a8dfdc3b34f
SHA3 8f7c59036b890c885cd7e431651cd9a9c286a0fd729f139e13faa564a38ec47f

CHECKBOX_CHECKED_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2eb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67577
Detected Filetype PNG graphic file
MD5 9cf6fe13af12ead7c10a827100cb12d5
SHA1 091ae6aa141203a86b461b21bcae07858b5aefe5
SHA256 70adcc8522448dbeb578658e8e5da1c44174f5d87b3e511a25f65fe452781600
SHA3 5f64b99ee4c6755cb30a3146fb32f703be6a924a721c63ad387f9f89fb5889f2

CHECKBOX_CHECKED_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x31b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.66372
Detected Filetype PNG graphic file
MD5 a6bfceb5bc8f6e774d0de084c7c1b34a
SHA1 878cc08d86b90ac16b5ecffb5d3456bc717e29c1
SHA256 e85fccf906bf5c865fba83055a95498041a32aec9126409ce7f176e120c602f0
SHA3 b09de7ddff32b94339e5e1ed08cdd216c9d9c7df2eabaea49b1a5beeb51c5162

CHECKBOX_CHECKED_ON_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x332
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.65111
Detected Filetype PNG graphic file
MD5 ae12273bf2e41fd5becf85dc4722204f
SHA1 adc8bcf870f358555d2e2d0c60fe86d5f78fabe7
SHA256 e2843daf81259b7965199acb5d75c7a68a9d9ab19c4c2e5bcac4a990b045fb82
SHA3 502e20e8db1809c8d2cafd2b6b927c945741673e43859ca2b4da7983e02352d0

CHECKBOX_CLICKED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x30e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63276
Detected Filetype PNG graphic file
MD5 8f0286f5f5ca451cb5e911316323e5d6
SHA1 30a574acb88b4df4687c12c2c23658f0895dbe88
SHA256 43ad4ee60c8959f55f6a9a362ce9441a58ce16a9a465983fa7ff331b84b3248e
SHA3 443a280a9e3c3864108fa078f95023191520c54e8d9eca676761e3581ee33a3a

CHECKBOX_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x259
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.55548
Detected Filetype PNG graphic file
MD5 e370029af3951fd3e1e97e7adfc86d42
SHA1 ee1e5a7aa7a5c69d011503a796ed7a83368ae67c
SHA256 c2a06cd64bc3dda2ac530383fe0678d47b51aab5a24956daf5996e2cf7be64c0
SHA3 21fbb1f6d47c22c92a2ce6dc372f3a648626ddd64a4b15d170a07268502c873b

CHECKBOX_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x298
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.59807
Detected Filetype PNG graphic file
MD5 a5ae70dd73b79b8d6fbc3ad8444aa41c
SHA1 081c3fdf6903dea682991d6ac9eae47e5a4a8403
SHA256 d0e9116fcf76811400b6b9d03ef32d99f4c93e726c5af943e09b9162bc1f5f09
SHA3 75a8b1fe50de3e4962cac85a1245d232f55c0f64362490743cf0c988ef5cdaae

CHECKBOX_PARTIAL_CHECKED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2ff
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.65116
Detected Filetype PNG graphic file
MD5 5855c9d9b466030c697d0a4b96b55668
SHA1 b82ce015965131fef5dbf9a68161b0259adc4e30
SHA256 9e206fc1da1da1878ca72a76ce45dcf20cf4cd592456a17613a6c43c90009dea
SHA3 dbef353393cb2e8105109fbb19dc690e78ceb493f0fda0035ab36446f0de9e8d

CHECKBOX_SELECTED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x30e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.63276
Detected Filetype PNG graphic file
MD5 8f0286f5f5ca451cb5e911316323e5d6
SHA1 30a574acb88b4df4687c12c2c23658f0895dbe88
SHA256 43ad4ee60c8959f55f6a9a362ce9441a58ce16a9a465983fa7ff331b84b3248e
SHA3 443a280a9e3c3864108fa078f95023191520c54e8d9eca676761e3581ee33a3a

CHECKBOX_SELECTED_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62297
Detected Filetype PNG graphic file
MD5 396f943313b1ed4d8b00259ef2675933
SHA1 be0a7ae6b1e7756feea89556dc35cfa8131dc8e2
SHA256 b26efb5e5279e78932b739980a4cf4e4f40a058289e03fe6dbf6d4ed045b695a
SHA3 f3baa7a775a3f4dc251051986d2286ff5d3bd205b5a9b63f44adf9334556efbf

CHECKBOX_UNCHECKED_DISABLED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x23f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.52096
Detected Filetype PNG graphic file
MD5 1d4e68b9817fa10d98439c1c7aac2dac
SHA1 dce2c7feb6152d865f3edba660c82111c4d06415
SHA256 cd8b5dd8ab6a16d08ed954c125d144519c7683b39982c60edaa20c500764fab2
SHA3 1017929b8b3699cf731c84f1be5bc028c3e6e4fab73e8ab7431bda717ee226b0

CHECKBOX_UNCHECKED_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x253
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.57785
Detected Filetype PNG graphic file
MD5 66364f367c2d8ce08205cbee4a420fd3
SHA1 3e3e0229c5feedf0f205572fd806a5aebcf17afd
SHA256 ebd3b7aae8c6c76fcc5c57506c0f888928fa91c592bdc8335ffb8016556f5c4c
SHA3 67ce59dc05b863db3eda49d30295990dc15b917454c0602a585bc2a8634fcd4f

CHECKBOX_UNCHECKED_ON_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x264
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.56694
Detected Filetype PNG graphic file
MD5 9efcc803dc11378ca259f0c92c6b63cc
SHA1 3ca29e45fe423125d860ad76591a9ebc22d4cd9f
SHA256 04ee656996c22c310cab850bb89aa6d6f12f1583d233ef9cc7b07fc42feb6565
SHA3 2564cbce07b33ceecae7d35cccf9ec65f1963fd830a0ba22443ecd914d1920b3

CLOSE_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xc79
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88615
Detected Filetype PNG graphic file
MD5 63821da2f4d0014157ddb91169a1ccd3
SHA1 189cfc1c77cb1cfa309ca1479599ddf7bf890a83
SHA256 b2f07a45af354fd8246743bfd0a3eb7737797fab75166262edfa2e4b0065a384
SHA3 e8d27c280c159facc2fd904ca37401bd5e66b492ef3edd9bb3aa9dfd677175a5

CLOSE_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb85
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87418
Detected Filetype PNG graphic file
MD5 ed0a0417fe932bd7402d6b5670b9cf6f
SHA1 c3e461b313f2670cbd25dfee25c4cd1b9a419389
SHA256 851a4b36f9f32dcb2e18b46a6ad112d278a8a9c0287a210b82b72ac11fa352f4
SHA3 a5332942000959568f3df4f259f23e8e780b0ef3124414db8b2b06007667a669

CLOSE_DISABLE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbaf
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87914
Detected Filetype PNG graphic file
MD5 fa049d642b4f40cea19a7276336dfc7f
SHA1 7357b5db424f4c1c13c554b11d8b7a1b969d71e0
SHA256 22d5849e65da79809aac4fe85c6aff81481ed5f6b65a5fb3bc66aa803554dc26
SHA3 5c324048bf72b88ea819856121ae968f54ca7cbf5f0ce3208fca2676464ad308

CLOSE_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87821
Detected Filetype PNG graphic file
MD5 cb588a4b4d758556328df94d662ceed2
SHA1 13d5765c81e773f08db387fa742e67a2db572bbf
SHA256 e04a33a4583d5daebb345d557339101a37cdf1ca32465b894ef5e90f60e64630
SHA3 1fd9041ce8f65569fc895803b852d9ddb219705ce11e31b9d552c41906f9d6bd

CROSS_MARK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xd6f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88983
Detected Filetype PNG graphic file
MD5 e5230b5a64aaa5f5f254ff61cb2ec524
SHA1 4725a83341a9b731342b90a39e979bb4261b8664
SHA256 87e0095828091bb2b4a9bec90f11c93a7f0d5b44df5cb7949e150e5235c1affd
SHA3 7a25aca66ed7ae87ea04b25a521e149c3458ed4cf8e5b5c5b7ea1a5f58f3db77

DEFAULT_LEFT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb72
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86787
Detected Filetype PNG graphic file
MD5 40f34c9bcefab109474add7d5bfb9900
SHA1 48d6148333d86a88434b8be3b2a7749783e544f6
SHA256 dbbba0a1815af7de2acdf777c982889bc1c83bd329ad15e722d3888dfc1e1490
SHA3 2538eb6f311c2b414a9fc65b5b1f6f1b6566e1b0d3e9270e6b91a4fb826e1702

DEFAULT_RIGHT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb70
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87299
Detected Filetype PNG graphic file
MD5 b8f16d00507e71dfa29bbff288f71898
SHA1 0f3bd4f38be07471ab5d81bc70bd72b3a83abd33
SHA256 a25cde4e023bb793dbd3a71985fa6dc6da81e9e72598fa704e57916f4a379344
SHA3 d0202c5614b4950dbfbb5bd0eec36151cca9e2c2e879351c63b8690780b1b3e3

DISABLE_LEFT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb5b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87017
Detected Filetype PNG graphic file
MD5 3bae1d262a00b8fed2ab668adace73ab
SHA1 1664d66260a47c4bed3e97f77f8af9b808a074e9
SHA256 3092f5db852697c4f9af6b6c10d6ec2fabce6ea6098d3e2068d7a0d94a1095be
SHA3 6e60d69ee39674bb0551f86fab67684f66d75608be74d60d25f1610848966701

DISABLE_RIGHT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87256
Detected Filetype PNG graphic file
MD5 f6743a8054c49e10247d63d7487acd56
SHA1 be66fc5113aa0ce2b0ad994fda1213e2d5c03be2
SHA256 f9113e268781e944cdea44a4f85ff61e12302caeab616cb9b9614220216e7dd6
SHA3 68a92ee4f2a036254a99ecca7aeff1fdcb23fbcc5aa0be1ec7ea9bcc992b8390

DROPDOWN.CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2186
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89184
MD5 711ae8667dda24b8a93ee9a643cbe45a
SHA1 51c9d1c770f66ffe8842b79e3df37b4e853b3e0d
SHA256 c8a5ae6cb6194dbfdbb58d38fbd027a8a2009cbfbccc83d9ca48071360f1b85a
SHA3 07679cee743251c1e2f05600e897d637a0a3fe92a4e76bda90baa6b125c5db14

DROPDOWN_COMBOBOX_BUTTON_GRADIENT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x124
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.82528
Detected Filetype PNG graphic file
MD5 4b46f114d10fa0c24185b8de3dd6ad15
SHA1 6a6c57244255636b988a2a23bd88501e90ee42e0
SHA256 56ee406e4ebef4f0a23e72933328c4ba17d86d335c58759f6589376d90869986
SHA3 e212f3cfa728dfdf2a7c4c18f9c5bd98c3d9f88f542c64cc087e57dc1e9297e2

DROPDOWN_COMBOBOX_BUTTON_OUTLINE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xc9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.3864
Detected Filetype PNG graphic file
MD5 a7e53a233c6e7d414c6e3aea15d07ef8
SHA1 48a380e74c89f8b12158b5f9e00ed3b24c8a384b
SHA256 4ab66829dca14b3fddd1ea98aa65198f573a12e10cc7822bdacb2157bc954006
SHA3 06790a4449a2db38b26ad9715e600bf0a8d1b95a6008cde436a6416a37e3705f

DROPDOWN_MENU_FIELD_NORMAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x204
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.4024
Detected Filetype PNG graphic file
MD5 0188ad696084e001bf10732403d449af
SHA1 784a76a2922b064f8d1b03030638c999137ceb10
SHA256 671cbd2588f28de768a977bfd53f5167234091bc38620142058a4e1e0c9b1a60
SHA3 1e48185a892e2afadd6f38590e96bf4e17aae03a1dda82b57d00917f06e9d2ae

EN_EULA.HTM

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x11709
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.84291
MD5 bcf542637959047ec697a0a3ff25514d
SHA1 e9153de6049c697169cb85b758019080b6af81db
SHA256 8d84318b743272c8f6b3f2d63070150598220bd3c35a992a4606ccd1b86af01f
SHA3 f75ec1b26781a814032a9d95bffa681589061fd3c72abec83df694b03133ba72

ERROR_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1034
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90777
Detected Filetype PNG graphic file
MD5 3fa7687a556fbd99f7b565a2d4d0ceba
SHA1 d771d3a8742bd72fdba801359f2a1049ff716e83
SHA256 6854ddeed7aa0995c5376fb1724f3d9b72ff236761f77f423ff3e321f12eae38
SHA3 4b208b721f07762fc69b2a1fc38118f2ee90866cdc4a8e15f8f598b940e27ea0

FILE_INSIGHT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xf52
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90937
Detected Filetype PNG graphic file
MD5 4c880cb960383125468a32eccad24f19
SHA1 ada35a48d212b66790a5dc17a2caddf283143035
SHA256 07ec67ec45a6c44a6da35000b8c350c21f72c2236de592c63d77ab64cf7c3b16
SHA3 fc927f4d6eb4cb33898719594c8f54826b1ae3bf559da0f86ccafc46d36fc232

FOOTER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x22ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93752
Detected Filetype PNG graphic file
MD5 2e095275853a898738067955212cd772
SHA1 b552507fb5e69123fe6fbc3605ca719cb3cafc2e
SHA256 70000daaeceb5b96e6aefbb8d7ffe3fb774069b78bd63e9e2c13f9b32ecae389
SHA3 42abd085ac03539b054c3a42548061401d306cd9f83064383426e1ca9a8b3c8a

FOOTER_RESIZE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x24d8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94312
Detected Filetype PNG graphic file
MD5 3180c3219937b9cdb548cbf84dce7ecf
SHA1 ac09a84fc95b2c1ebb90830c8be2f83113208103
SHA256 7e5d29f8d8d84128c73281343ae90f138dc15454dc864d0861fafe016ea6ff98
SHA3 fac5416292b3f65a5e075274e45926bc6a50199430cc7abccf6fc71b236c37b6

GRID.TIS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x213d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06111
MD5 73af4ddf4f3ff5de275c06598a071cdf
SHA1 9fe78fc88189f52895b95f3c27e3f3f62df892b5
SHA256 cf5408dc2352a0134f9c9535afb474776bbdb75f46153e6ad85205b35af4f388
SHA3 810011f619b4f02d925278006c01b2f5daf7c058783ea01864a14137f33ed511

HEADER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbd9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76552
Detected Filetype PNG graphic file
MD5 38a38ab3a2789da81b58394d1acad2a0
SHA1 5ae0f94898f39ca8b4e2dc6e69a5e67fecc0611a
SHA256 3d2e3b95ada07255b8e63b726ae4827b7b7ffedd5e6a6001b0c6ecf9cee28bf3
SHA3 672b8dfd8aadb2c3685f613eba22f64c0509c89944a80b2416c0ca81ba022f02

HOVER_LEFT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb6f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87303
Detected Filetype PNG graphic file
MD5 e1bcbe93eb4e77a60144bb5733d3ac71
SHA1 9b1d42db43564f833d4594277946d7ada99c5032
SHA256 47fa824ff75c9e0be8e42eccca325fa4d8066101b88ea85539be07623cada0c0
SHA3 19fbd6d254fd4402aff816926c35bfc7822d7ba57a50a1199fa7b3bd224d56e3

HOVER_RIGHT_BG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb6b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87555
Detected Filetype PNG graphic file
MD5 56557b1db0630edd072a0b6a5e0149b2
SHA1 781bff37e69fc1e71369d8a4dbf87314a3352b81
SHA256 2760b1167f0aab00fefa4723968dcccac7b34ca75e2f8106b2595395db88956d
SHA3 f1d761cd734a79f537bc437e4fb8f12e4243f7cd04f48322af4d25acf5520e90

ICO_BAD.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x169
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.08782
Detected Filetype PNG graphic file
MD5 7e3731370fdcb5b1f815a8646d2139a2
SHA1 b571a9e3d07a23e31da1c76d8c2b8a4a5174c979
SHA256 b764e35d5ce948f1500ac514c8bc065c09a0ea234e39f66075a4a45c10091869
SHA3 5d84591364c058166c9b0bf9df34486fc94330cbd9a172c6d53d7fac6cddbc0f

ICO_GOOD.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x16a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.13001
Detected Filetype PNG graphic file
MD5 863d7ae214200e25a17dab98329e0e81
SHA1 d64dfd3bb2e53ac642acf19bc832eb729bb6b12e
SHA256 6f143b65e5fd2ff0f2f902b321b382fd626e7f59e3dd70e348b59c4d378abad2
SHA3 daedd9e3db769a0d9fbba79929958e4f5cecf48c239f911d65c071b5d4731322

INFO.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x2ab
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.53642
Detected Filetype PNG graphic file
MD5 f6fd968c6302a564047668dd348664db
SHA1 30cceb45eed9de638ce1c17f9f80efac15bad310
SHA256 09a753f229e4e93ee206c36c16a51c35fc79cfba4e74054364c118c8884611cc
SHA3 5623d6585eac4344385df1e4e5feffd3a1c840d0b0a5a15e3f2d90832550318c

INFOBG.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x556
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.67503
Detected Filetype PNG graphic file
MD5 073ed6bd300e86dda55f2f537e00be3e
SHA1 229299823092dfd2b86822c20333791ba337b124
SHA256 0ed10d1ea12435264f7d79df7671720a6e58888cafa0003634fa22e545d797d9
SHA3 e3c90aae022a18b5a0774c04992f6260eee311f13ecfefa7cf63c019329ccbb3

INFOPOPUP.TIS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x122f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91504
MD5 5b40439bc31a4343e8f6ed3873e3c00a
SHA1 183c2be146153d9e005bf7a031cdd2badb015d61
SHA256 08733f9c34f4d96ed8080e6b6941c22429227eef7f5481249e3d11edd8c60ca0
SHA3 2b283248d7ff554f2e70b7bb6bd45c553cd1fcb6f807bc7d07d03c1c2ce4f13f

LOADER_GREYBG.GIF

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x6fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.21301
Detected Filetype GIF graphic file
MD5 cbe77093a8969ca28f5413b56c9b6769
SHA1 0e7d5a9dd2d9393a95638e8269927143ee57f508
SHA256 4aa8d654b62b615038e99d9b4999af7f446cf30f5bb68581a56112848b522b20
SHA3 92decd63fad6186effaea669ff41c44e9bdfaea535fb22e57fa74eb98d27ee9f

LOADER_WHITEBG.GIF

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x745
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.41646
Detected Filetype GIF graphic file
MD5 ecf7822898bafd83bce4cec9963338ef
SHA1 ea145e89ec159055ada3c3a7247eaf44d07f18e4
SHA256 dd7ce21f914600298e515f0cf0cbb9192711638e7f9f0899311bf0367a1c2a00
SHA3 5299e3ecb56dd214a0c8d2584d281fe73f38ddd908e2dcb61db0b26923dc7c0f

LOGO_NIS2010_BETA.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.74654
Detected Filetype PNG graphic file
MD5 6f1a75d66751136fe3838de575512f28
SHA1 f25b4950c1a897f2a1610133556f04b8217cf8b1
SHA256 2b59dbde2e0478231d9dd0b0a6733495781c63d7ca80ef9dfffffbb38dffb69b
SHA3 f3e45c1b0a36c838dffd9155528a3b4a7df9bd82f7c08954007c625067a44c28

MASTER-CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x9704
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72348
MD5 e6a015df0583f7b3f6eea201a8e163c9
SHA1 c776679cee1a538ac12c7875cd6d87ee4a6031b1
SHA256 019f7fec2861cf5401367b92e1e3fe56395df15a53d9678f8166b8f7c0510a63
SHA3 0f91eb38033eb1072ce9c48cbda02cf69c0d2f93d74faa2f3e6f181e04536400

MAXIMIZE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb9f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87402
Detected Filetype PNG graphic file
MD5 75082d1f3205bcb4e78d36f6cb247372
SHA1 a547cdff2ff2434d37505de92b7b3df3fe657dfb
SHA256 5c1a7aef46b2ec2589f0bdf6359c3cf34256ee2f624867e18cf608c2b5a8762a
SHA3 29db7442fdc33a8b0864a14dd8b58ef4bf1427878ab635ecb6cf97d0fbce4a67

MB.HTML

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x3b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.37769
MD5 bcc4112caaea63dc81dfff57f0a0371a
SHA1 7460228542cae779a006660ab298299cd77ca259
SHA256 35f14380b8eb7363e9f1bc2e42aead1696dc5984c290ccfd3dd9f8d10166a506
SHA3 a7a7bd44ea3974e05700761a05f33ff2cbb940d95477f723e53b458073d7a11f

MBCENTER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xee0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85236
Detected Filetype PNG graphic file
MD5 9b6665617ddad33c0de0e5463e32cb94
SHA1 277e6cf153eb4f27bf404f1cf3171821ba420039
SHA256 7572198d36ab6393e82e11ba2bd73ea72311a68486879985f6673f836ffd43a2
SHA3 6997f52a93847b2b5f015606d8164823a45537b587ed77b10a30b1ce45d7b152

MBFOOTER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1afa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93451
Detected Filetype PNG graphic file
MD5 2bf8cbaaaf83208225a3aa74b4e6ed17
SHA1 49b5fce737b98c1be01d5c17e78bb455a873d3c3
SHA256 37b80cd32a80f6cdbb08a1b359cb01ec10cb79c525243b610eb24e745d3c3b3e
SHA3 3ab305e4d828fc2c884906730d0fdf5581c4561a7334a254feb9571a6abf60fa

MBHEADER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xbb2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85154
Detected Filetype PNG graphic file
MD5 f65d4f17ce85d9f0243202b0374e974e
SHA1 ea6fc708ef7179065fb2778a1b8189de9ab41b61
SHA256 19242f894864a192f01211809b95822676773e4e906fdcfd511e7fd5966de915
SHA3 a5370d05d74c085ad1eec4d3a2c218ec952f5c4c1352f90436b51fea3162e7c8

MINI_CLICK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb6a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87082
Detected Filetype PNG graphic file
MD5 a608f209e52e8d61007f780be502421c
SHA1 9fffd0733f30585d91207d8f8dc1ca43578d2598
SHA256 86563c8cfb19f9b2bb490aff30977070f754f4a05c6199314dec5c8a643948ee
SHA3 58c2a880c62a1a33f264ecc811a513c3c95b7e17bb32914264793e54a80736d8

MINI_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb33
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87115
Detected Filetype PNG graphic file
MD5 67964d95030d0284c67f31a2c7e0cea3
SHA1 440bb09cf16624fe56f8acf25601d61c270f5e66
SHA256 516b072315b63ad82a208790bcf45b8c129d551b7f30b9e2fe0908c586fc20d0
SHA3 f5ed3735ef3d7bbb606b376a12f950ee04f0294911e891bcf8d158d4fe69ca8d

MINI_DISABLE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb35
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87136
Detected Filetype PNG graphic file
MD5 305faa2121034081c97a6448c47371ae
SHA1 6f46ae540b41ec7f3a5dd4aa261b7d0b94b4736b
SHA256 9f417c391365de192a8db8a650376d305a8f1c7c63ca37bfac22ecb1d1e4fed4
SHA3 364c7f4540710f01de02db8df6e0319caf9e22a961b6a8cf9f245d6a2f4675cb

MINI_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87145
Detected Filetype PNG graphic file
MD5 1f3b0e053c9c8e12b3d859c748bc97b7
SHA1 3edd4a4710806e0facc1a8a482530aba51c95189
SHA256 bf52e1f3eea4586637d59c4e02716567414b6d656249028b7d585ea1e96ff6b4
SHA3 7373db8644b6c8eebf887d697307e2895ea83e708364e04f72b6987cfabbe3d2

NMR_32.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x11af
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92806
Detected Filetype PNG graphic file
MD5 4c29e875eb5b6c7869d319febd9e874a
SHA1 fa47b71808737239f10683d54a5e57ce9dab23a4
SHA256 bf7f8fd0d9935d31f94defe63635955fa4730fb94cf7f142b9811dc256009932
SHA3 c0f2601f4af6cc5a7847761d37cf187c606349d1a7faa36bb9c7b7a4797f3479

PREVALENCE_HIGH.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1101
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9243
Detected Filetype PNG graphic file
MD5 1c396c59c76da09c03c4faf20a4b86b7
SHA1 34089e0df2947692e6a923365ea6097451a827ce
SHA256 459e73e87b5355e691d21c446742e4c9eaecb4d9de44a1f45eb113483e0e485f
SHA3 458be4eafd5164323133074e77403ff3f13fd332e5e0ba0a616980cf5e8e6924

PREVALENCE_LOW.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xf9d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91373
Detected Filetype PNG graphic file
MD5 82cd9bd4926443025bb1ae1548f66f1d
SHA1 4e91098e227855cadc1154d000c27ad5eec815c2
SHA256 c79159c280fb66e842dbfa724ee2995c64f36b1f4d2956753e7a000ce226806c
SHA3 d07ad2de44ff132df97850ac68886053bce60b4e81904e2480fb50199dabdeb8

PREVALENCE_MEDIUM.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1056
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.923
Detected Filetype PNG graphic file
MD5 5f83b5ad2ad07e5c68ca2abf4866f557
SHA1 afc3e1b320260ea4c6ea9f58a71b133e74aa6c55
SHA256 3d8b4f17019deb7fc43fa84a1e7c8024e29b25862902d284497be4835a4491ed
SHA3 58386357cd4ede032137c9982cf6db8b17c0bf013af8b567ef7be397bf999e91

PREVALENCE_UNKNOWN.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xfa3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91217
Detected Filetype PNG graphic file
MD5 8a0a833a9ec97756df2d426b317fa611
SHA1 ab485d6e21610b78abeae7ff634cad46aa525aca
SHA256 58eb936484afcada00fd731c7c711615c6810c3396937b4ec7ba04250d4bf2ca
SHA3 e2bbcb548ab36f48b3096802a1eb82560f2050b0ebd6d1483f67bc4b27bb99e2

PREVIOUS_REPAIR_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x111e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92396
Detected Filetype PNG graphic file
MD5 7a932dea876b66b6e3c937814f0d28ec
SHA1 b1ec9c6ff69d21756a61ac52a0d5ec7436c1784b
SHA256 1afdda81c49c36ef7e61007bf5748dd03eb22fa2e0d0b39367a9bd4000e48745
SHA3 687ae1fb45aef81249565cce087464eec443a876950758153dc5e0c38dc06ca8

PRE_RELEASE_ICON_UPDATE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x719
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87158
Detected Filetype PNG graphic file
MD5 c979b3b5814935980e1f5b5cf3249113
SHA1 c20863117adbb135af5ff6ffd965f2b6d00bbed0
SHA256 904138016e362a2d3860597d1dab35e661ee369f98b7eaade5b7d4b3f1328781
SHA3 3b89528eedd10e4a78ca454d8414e4ed87ff846cdad7f200e54479a26c910318

REMOVAL_RESULT_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1002
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91679
Detected Filetype PNG graphic file
MD5 5a6affda5aa5e24749c0500bc9546377
SHA1 cefa90f96300ef0aa2d0cb9cc002a93d21c3fd41
SHA256 1449abd99de3908614bd6b069d99500ee02e8ca8a47dc9c431c69a7ec0f4ef67
SHA3 087ac46dc7fff46b4345f77a4aa94d3c0ef896ead4fa919df5f773104c6131ea

REPUTATION_BAD.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xedb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91098
Detected Filetype PNG graphic file
MD5 e668f42a9e746657e04b42586c608522
SHA1 c98401c0c68f3b08c776ff5c17632d6889b856ff
SHA256 950c4ed932f0e62a81468ae12dffbae97247a7167f4ee27111efd7c5cb955130
SHA3 55dad54e9ed76b5210049dbe48ed5112b68124613d7d9ec75d4f246216809e65

REPUTATION_FAVORABLE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xf23
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91085
Detected Filetype PNG graphic file
MD5 5491b534d6c879b30477793afde682d1
SHA1 5f35bbe722487407d82b9aa05dfea4134844993c
SHA256 abf11d1425ba60e252e6a2ef1e84bbb7ebe2ac31a4173e1f1093fe68b16f1507
SHA3 7733e6df2ec45baf7606cd2726bf0fde65b81f7546b96d1c69ba9563d2236ba4

REPUTATION_GOOD.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xee1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89944
Detected Filetype PNG graphic file
MD5 424b928bacd48d3c06c7b5d44178f2e6
SHA1 db0aa01ab5acc03fb45eea3a3bbcd347244089fc
SHA256 19621a3cd70f6e9cac057c48aa23cdc24f55ef8984af4d76379d5cd35583f60c
SHA3 08ef7daad2b4150758a1a65b9a4569cb72bc54f5befb825462fe096c6add70b1

REPUTATION_NORTON_TRUSTED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xfac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91544
Detected Filetype PNG graphic file
MD5 90a56b69efc75d226ba78576f3664e21
SHA1 97f4bb1dc7872b379d44db05a4b30c8104b98eb7
SHA256 f660181cd85768d8fe07e22ce8fb6958cf137e0bf96b3ba592b5394ab96f12c2
SHA3 0c6a240451127218c78c87371956a7c34ef10ece616341184eb462e1cebad554

REPUTATION_POOR.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xefa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91026
Detected Filetype PNG graphic file
MD5 e42b30e1a6df51894239c85b418d3368
SHA1 9357dbd3612256006b18bc76af1c320d09ed723a
SHA256 4fca29f8b9e06783ed8f7007660aa55b7747b7bf3687dde957defb56a2d84dee
SHA3 3d2833baf3d9e7a32fca987f7b56a835476c02eaded6a84679be736bf663866b

REPUTATION_UNPROVEN.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xf76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90086
Detected Filetype PNG graphic file
MD5 6395faf1e1440231f0a05a69a6d1739f
SHA1 c171fc235a7ab94179eabc58141e02c2094f745e
SHA256 9a91d9091044f87151f6a0e946702e194f05aa578187aeef526a99e423a1ca67
SHA3 b3417bcb729b9a7905af242a1a6d49700d3094ec2076a3898316e3610a1ab307

REVIEW_PAST_UNDO_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1c23
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95181
Detected Filetype PNG graphic file
MD5 99d8ab6a83dab39fcfa72bc181e0710a
SHA1 81c1fbadeec954035ef650a7c9366e29c34513fc
SHA256 4f16c87134821751650ae541a803e65b5fcaa1033f002cd47597246e43a9a707
SHA3 17d4be6e1b5a095349497c4949743ea63650b202caff2740f1329deb2b4e7725

REVIEW_PAST_UNDO_ICON_DISABLE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1bba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94848
Detected Filetype PNG graphic file
MD5 7e2c1cc39b1a538c178d21e3a950fea6
SHA1 82b8f16f27c4ba3178022b033d3160894e25c9bd
SHA256 1c0824b4639f23ca93f411f773727bc98897d9b936542714b3573f10b09e94de
SHA3 de17be4680290bcc879b555f23fb5db955621b20ed10f82e02ccc6bb81fe4a24

SAFEWEBICON_UNTESTED.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x88f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88297
Detected Filetype PNG graphic file
MD5 b58ea97e8f08bae328f61facef224874
SHA1 827d6621f4b77be40fbfb3da226b588a571e35e2
SHA256 f4310dac360259c4c5b27762aa206732be3b7fcbc99697df822cc96a05c24de1
SHA3 44aa69627a384879f55ca5d7834be50296708d33732c71d4ebb887310353a386

SAFEWEB_RULE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x13f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.32971
Detected Filetype PNG graphic file
MD5 c16ae276e1dc528ccee8d6c0a402dce3
SHA1 7bbc9cc593d2a3b08546cf47f51ec2554407b284
SHA256 f9213f6210822c33ccd41c543bcd5d2f857f53da07d0bd1ad87f6e784a5e8ee3
SHA3 8d444a6f51a18f213967a37c087d47d1369d832161798d3b704e2fa4cbce45cf

SCAN_COMPLETE_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xfc2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90974
Detected Filetype PNG graphic file
MD5 63522974eb8fcd92ed6973268341f18a
SHA1 4318037b6e43a65748984d334874cb7d639ccf6f
SHA256 93a34947f43721af9912b9e355876e07d38879cc7970d36e5b9a04958a87751c
SHA3 c348e458d62b589ac9fead901b698dce2baad95cea364ac00154e14e4b88d896

SCAN_DROPDOWN_ARR_BOTTOM.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb32
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86423
Detected Filetype PNG graphic file
MD5 29d46a6687a401966c17ea6d9c87b175
SHA1 d3e675a56fd61b3dcce0c0bd6f3c266814a788da
SHA256 73e7877beb8e81b0ee2739c954fdcfbd2a5362a923c0a6ac77f66ab5b15f88a3
SHA3 24ac165a558276d32d561f805cc9eef178b584e78f9352b0bc9e2abb9151c714

SCAN_DROPDOWN_ARR_DISABLE_SAT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb2e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86297
Detected Filetype PNG graphic file
MD5 9a0822812940689886f84223c694f959
SHA1 dd85445215047514d31f587269b09ddcf6236cbf
SHA256 2e982871b8fd90c147541506ed76f820a1e0e7e3f7f271b5e573fe266e68cfc4
SHA3 04110f75dd0ae46e7db99e60ce8d48d6967d724e4d2ffe20bd3b6bd49d37cb23

SCAN_DROPDOWN_ARR_RIGHT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xb2e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86953
Detected Filetype PNG graphic file
MD5 1a0e7499794fa3818b135e26c659c3c0
SHA1 d4cd49bac5caa4913a55120e8d2b50ed6ed1b62a
SHA256 0cd31bf7366a21d7e5b92fb095dc969c98ca7404b9cf247f95cc7eff43b5f896
SHA3 e5bd69ce8afdaf3959f948bd6526923632345583839eefbccb04ccd4fbc92a1b

SCAN_DROP_DOWN_MENU.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xdff
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89647
Detected Filetype PNG graphic file
MD5 8adb97fc571d761d900d1c9dd20658a1
SHA1 1228f6a5e4a6042046d427ffa09366054c644493
SHA256 6d14ead04aa924b48733927a7391643f062c15ad9c5506d12856d12bb3057912
SHA3 c5b86f0922f9bb48eb28986bf04ac7f7ad0799107d798ef84566445e41834d5b

SCAN_FOR_RISK_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1bf6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94592
Detected Filetype PNG graphic file
MD5 c18b74ad62bfeffacbdea8981bd34f37
SHA1 6a3a4336a6fdfb1f8734beb3519d8f70c0b88abe
SHA256 0e94140e5cb0ee83ff845032738ab7cba57defe8a56000b14fdbb42dd01b8f51
SHA3 f415f49ba5b29edf9e21f6163963b9d9caf12fd5e911cfe5b56280eb4a433b9b

SCAN_FOR_RISK_ICON_DISABLE.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b9d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93125
Detected Filetype PNG graphic file
MD5 13b68c2aca2555ea83be9837bb6589cc
SHA1 57b78833bb83142f072e1efe4665d8b8cd8dfc62
SHA256 c4ac1574542f5e0293544a56e8538325b6d759d162e3fd6a638d217f856b6915
SHA3 980915ef220e5b87327ed26185ac5a0d9d46c2b6adc51a889ace0b6e813e5b37

SCROLLBUTTONDOWN_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x20c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.44526
Detected Filetype PNG graphic file
MD5 7cf43c47648880d01cec65a2a7e93dba
SHA1 da2cfbba2fcd016631a665afee700b863c1e19b8
SHA256 5c44a8d024407bab2ad69e24debbffea794193bb05ff1300fe09f59939669a59
SHA3 75e1ab406e329f841d54a3db29d39df8ad301e432ed82915394a480279d061aa

SCROLLBUTTONDOWN_DEFAULT_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.43543
Detected Filetype PNG graphic file
MD5 922ec773386cf160d1fbe8beccbae50c
SHA1 14d15f7d161eeaf4f1a6a484253a8a0b3f98cf95
SHA256 0232c29ea03b64563d93f10bc2b5470675f019b29ce40a3c109d33aa96184485
SHA3 7b9275baae5f7fb46a2494acadbdd6677bd69272fcbd0e37643a501b8f44188e

SCROLLBUTTONDOWN_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x255
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.47926
Detected Filetype PNG graphic file
MD5 0359f07fc2e50693165d48ac72be57db
SHA1 bd2f63be87011d971eaa1aea043e2e7086583e58
SHA256 2510c7d5f344ce7b3f6237b9d68331cb4b87a264bbde0049f7bc2715f12393ce
SHA3 27c807330900c1d0f5fb6f226a9474d24d8c4fa8d3ac2069b82d82fd0397ab98

SCROLLBUTTONDOWN_HOVER_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x215
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.44311
Detected Filetype PNG graphic file
MD5 929f676ec21269a129b27529c0276936
SHA1 5d7895334dc4af978e2143c87116c91e6ec28b8a
SHA256 c2c1b64ba6fc2d9abe9cc8078002f97d1f57204efbc8b0ca41fc27faf0c27e47
SHA3 27b344180a70011e958687a9530a5a5de1d848fefdaa487657bc238e1e7a7b82

SCROLLBUTTONUP_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x213
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.435
Detected Filetype PNG graphic file
MD5 e83a6ceaba3ae5c9f058bf1bbf23c488
SHA1 1455a146ede4baed8adee1e2cb9f564cac88e134
SHA256 008c0c3e562064d53175d034ab80f59336f52f32dc1641dfa160cd64d66804b4
SHA3 38c04f6027e8932850d36cb3a9ad5a8f95aaa643402380064d2c39277ad4bae6

SCROLLBUTTONUP_DEFAULT_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.4203
Detected Filetype PNG graphic file
MD5 ab5330b4eabfa07b08826fe70563a29d
SHA1 9ae72890c99c72e9d5594d4d7a138ae36785d738
SHA256 0391e07425d3237da123443ac45d0c2fe424ef1384c83baaf44e44384b710019
SHA3 db22337918f78116ddca3b196d69a13f50b46c9af77a7ffb225a1cc44fd9caf8

SCROLLBUTTONUP_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x24f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.54399
Detected Filetype PNG graphic file
MD5 18185b486885f57dbc46abd4de746677
SHA1 ad3a608993b634ab084538e937ee0e497c9bc681
SHA256 4c6b92c72d7c13afc3c1f4203e15b9bb4cc52c218e77dad5d33d54f4aae52e47
SHA3 3a2f879d7eb2540e7a16c3ee51cd211f8809d56d1f40d742640c9400a8237e3d

SCROLLBUTTONUP_HOVER_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x216
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.46997
Detected Filetype PNG graphic file
MD5 9031149af807d713a840a44622559c13
SHA1 f21b8a70621b43583ed7e54901b716830c642cbe
SHA256 ffaa7da166101df1c898f974987ca24493b149d07dd28bff5ae4a644ffc54c57
SHA3 c903d2db42e7b78643497cb7099a52795e6cbbc680e00707ff47fae33afbc073

SCROLLBUTTON_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x155
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.01863
Detected Filetype PNG graphic file
MD5 356cb9ba9dc810403eb9d0dd46d5400b
SHA1 03d03ac3349c9d2a018c9c2a40e12f4629618802
SHA256 97071dbd3b49e4083cb3517a506a32f0c7c78e85fc1347e3e219a9f1e06d9e73
SHA3 d448a0dfe31eb4f0c307c5e859dcfd970894f00876267b5d2d5c64e70b05044e

SCROLLBUTTON_DEFAULT_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x145
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.98517
Detected Filetype PNG graphic file
MD5 3c4a7de25cd734bdbbf9459a2891f39c
SHA1 dd3d01d4b834d141cf92a66fd794cea137236797
SHA256 dfd378dcbd876e513346020e096ca67ca37ca843127fa9b0005f78d4437c7f20
SHA3 fc2dd631f1afa7f7cf6bde437543e4ce18401b651bb81d9cfb57a8b4938990c4

SCROLLBUTTON_HOVER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x311
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.61208
Detected Filetype PNG graphic file
MD5 5095d0cf165c1cf8c6e361eba0b97db1
SHA1 c6ca69d7c24fd9aa1c5c75329d935f330e818634
SHA256 cb8c84e466c54a84c9725a338ff9258f3a22312dcfd3e2ec30842d8e17ece15a
SHA3 d6027e5da8b66069597987864504aac7e650eea06276f755cbc4fa7ae6a75fc8

SCROLLBUTTON_HOVER_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x301
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70582
Detected Filetype PNG graphic file
MD5 ad040769fe948618edc9b472c69c4040
SHA1 37b8758d08e15c7b99b380915491b9f842e5b6ef
SHA256 2015d4b1019f6a6144eb921addbbb723c0f4b4249dfa07ba94dae48d0bce9a60
SHA3 950a1e622dc1f8c64b0fff60d8bface7c01657b8b510b248131a1e19577f3b55

SCROLLRAIL_DEFAULT.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x116
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.84488
Detected Filetype PNG graphic file
MD5 6124aedf5f7743e5bf02375d11988a4f
SHA1 43ecf83b1fc596573a8202dfb50e17703d39501d
SHA256 83f76fd2f64204d3c55fdb983e2152bc7e61e0e0d00559c02a9c821a7bb6aaef
SHA3 a6eeb8b076c737dc7be1bbaae15beb45871c9c543bfb93340a42355946185154

SCROLLRAIL_DEFAULT_HORIZONTAL.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x13c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.03613
Detected Filetype PNG graphic file
MD5 171a35c5ade3fe60399bce022fdef528
SHA1 bd212446ef89c5160a02217ae4d42625f79593fd
SHA256 893360444d4d282db09c77265589dd770ce73466646160701809e8a66159662f
SHA3 8c528c3f6145e9db1ee73b3bf565146dad850b5b4854ae21d958d32562aea2a2

SETTINGS_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1160
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92297
Detected Filetype PNG graphic file
MD5 6a5cc448716f56a6cc042270d8f3203c
SHA1 2f45ebb48bb957abc7666c296fd1dddf12b5a08d
SHA256 2d13a421efe03a315d2b52263185eeb35352acf3685631cb95f9aac317d63d01
SHA3 c6b229b16cf9d22393f379c8f56d86d7e7b40b4df1f2236ea37c473dac2c5cb7

SMR.CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xaab0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.90109
MD5 174fc50fa61acd29b75788905578c1d4
SHA1 d1db00564670d89d671f3eda1c02abdb6a612d8e
SHA256 cf3672e9ff9e6f95444a303a6610c48cfea3129709fdef6dfa31b496155f66e8
SHA3 199e22698f57553a0433204dea635cf3347da9eca1fe36ce171d3e1a7eddcbce

SMR.HTML

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x6a4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.20564
MD5 a6ff55dc5e0f45523cb4db47339922b2
SHA1 1f54843f9beb9c6d32b2eae79c3224fc8f6281cc
SHA256 d3f2123238b6d4542731a349f76532a016566cb3d8180371e32d745fb6c537bf
SHA3 df753890df7cbc5f0af8363b3e50f63a5cfd413d4c7573af8e3fa76f82d904ad

SMR_ABOUT.CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x7bf
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.06146
MD5 55a45d7f05339b7b1fbdbdb16ebe0879
SHA1 17a00f87156cf02687ac3415e14fceea9f5851bf
SHA256 996b1df131de8931ab0bda78f19788d9242e470a849f5c1d2ba444c8c5752e97
SHA3 135753f8b6ae088af81961f7313ee2714516e7b133bbae7893fdec8422e0a790

SMR_RULES.CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x9f79
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.99208
MD5 10b0892f0926fe6e360c5c6952d52c15
SHA1 317db385b9a1a88a7746497fae952eb2f932f093
SHA256 6e7dc8ab5c5445c0ea0a3144f38937884632807b02e0d5a8f22593c374e5985a
SHA3 678279d18f6db3dee5dc11df3a561cc86c1f09a3e3a331c6ed60ae5eab839fe8

SMR_SCROLLBAR.CSS

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x10cd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98348
MD5 a4d54a6f5ad928f3e4203f33fc0c5b7d
SHA1 a3504563018e0e4f502ba7c7d69be7c1bd1ef653
SHA256 f8624142ba57f88a5441c7f56e73023c825f00b86459cd3c028db37fcf1fc8b6
SHA3 17044b908b0996cade9da9faa526f0407892d7be3292ee43f35621f8a2d11c0c

STRINGS.TXT

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27411
MD5 da0e07cfd895a93e053de7d5779b99b3
SHA1 1c3548f98d8e46d053d5b1c5b8810cd9bca3b6d3
SHA256 55eb52336968a607675f5a89dff021edbbd1cfa95c4519c1507376267049cddc
SHA3 e48df819e13f55f83f733bd57a603b06d408b2d81ba1610910f8babf922257c1

SUBHEADER.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1038
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87378
Detected Filetype PNG graphic file
MD5 3f1267de3a685608942524211687331f
SHA1 2c3bc17fac27b193f5ea6a49787eed691d06aaad
SHA256 93bdec87af1e38871e9ba65e1ac9601b64e9a2566c51b40db2f7912dda876e05
SHA3 9da7e4934488554ec0366dac706b7181f468cf9a4ef8eb6e9c7cd7682524bf19

TICK_MARK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xd43
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.88918
Detected Filetype PNG graphic file
MD5 22bef9c9816abd75ecde1f9b84acc72b
SHA1 00728ce3cd8418b5f52d3709d33967a62238ab78
SHA256 b88d3bd0512e92bad754b895e8116bf51e399992a7eeb719a3c30b8987cd71e4
SHA3 aac53b8e0758379a53df20c8b29f216aa93abcfbc4b25f0ae33b0d9e1ac0ed71

TRUSTICON_UNKNOWN.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x161
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.55695
Detected Filetype PNG graphic file
MD5 5c4b6646c4275a712934fc629d1b1bd1
SHA1 241994a9fa2e3068b53f12fe483e87e37b24395e
SHA256 6f12d51140218992f4faa4956dace6ffb53d5c4033566e3d5930b6c9d3916b73
SHA3 27fdcdf170806b8889fd6b566399dab9dbc8d1662657cace5a7973b29e07a9cd

UNDO_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xfcb
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91555
Detected Filetype PNG graphic file
MD5 50b7a58b5152eaa6a8fc8a10dbf4de83
SHA1 8e1daf1ee2345774476075f9bd4b09ca83df8748
SHA256 f795456d754952f919fa0dc0e82762a4e72359261561ee8ca63636cd88aaee32
SHA3 e8c645964fb023bd97eb0af58f0995abaa35e54d315ed1e9709407f29c0c328d

USER_ICON.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0xf9b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91114
Detected Filetype PNG graphic file
MD5 aa1d8dfd80eda6c70693ea866ecc83ae
SHA1 5fb0e43e2d7e1fd6427bff5a51145a70939278e3
SHA256 e457837b73a1bd4a8ad0e404fb5c08e86226bb4e77cfd83ba8a0e8f045aecc26
SHA3 0b7aabdd85b5fffd41b7e0276de7ae1ff9bf5c12f475608d1dff6f33640baae2

WHITE_BLOCK.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x23c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.29483
Detected Filetype PNG graphic file
MD5 0f5a7d9ebc1cd70fb53095b4250f570f
SHA1 d126c2022641bc1aa80f9173fb572870da26149c
SHA256 f8f7c31fbf5931ab74d846832c70dd0792d88912c6a6f9cf71d08d265df708c8
SHA3 c57e40cd8fbff8c53458cb5d8651d103a96b8d4fcdf1417207d6d5e6770579dc

YELLOW_BACKGROUND.PNG

Type RT_HTML
Language English - United States
Codepage Latin 1 / Western European
Size 0x1cd7f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99717
Detected Filetype PNG graphic file
MD5 df4b3440230359cc9a6979bc0ef0d5e7
SHA1 ad5fe626a32d715092f86b62d6be7b2eeb843871
SHA256 e5421b7ca10e6bd50974ee929a34060b95bd62d47080a25c49f42d49a1a0ca2d
SHA3 5bba2e07353ef1989954435e24f8d5c0b2b03325ed94ef294f627329739f5aa8

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x279
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01229
MD5 4e541c7ed18bbd039cc07dae957bfdac
SHA1 d4ef75f89eaea2b6e3884217ccf61011ce1c61c7
SHA256 7adafc350f7d7969a17f134f00b95b9f453051a23ceca97d55d1e932e62fb9b6
SHA3 f7e0ea394babb32601d20d53da6081bdd233f0de4115cec964301030b7923d6d

String Table contents

Unknown
Norton Power Eraser
Checking for New Version
Checking for updates...
Gathering load points:
Examining load points:
Processing data...
Evaluating file:
Removing item:
Submitting item:
Processing scan results...
Restoring item:
Error Aborting...
Saving Remediation Event...
Deleting History Item...
Warning, Reputation Info Not Available...
Optical drives cannot be scanned.
Invalid directory specified
Folder Path cannot exceed 220 characters. Please choose another folder.
Aggressive mode should only be used after all other options to clean up your system have been tried. Are you sure you want to scan in Aggressive mode?
Norton Power Eraser
Your computer is still infected. If you wait to restart, the threats may not be removed. Are you sure you want to restart later?
EN
Process
Service
File
Registry Key
Registry Value
Unspecified
Driver
Service
Process
LSP
Network Plugin
Shortcut
Autorun File
Startup Item
BHO
Browser Toolbar
Browser Plugin
Shell Extension
Explorer Plugin
DNS Entry
Network Settings
File
System Settings
Directory
www.norton.com/smr2011
http://security.symantec.com/pfb/pFeedback_form.asp?go=pfb&products=NMR&versions=1.5.0.x&oslocale=ENU#
<h1 >FILE INSIGHT</h1>
<ul titlearea>
<li>
<div>
<img type="icon" filename="%s" />
<h3 id="filename" fileorpath>%s</h3>
<span><a id="appcard_locatefile" href="#">Locate this file</a></span>
</div>
</li>
</ul>
<div overflowHandler>
<ul blinds>
<li FileDetails>
<div class="caption">
<div class="captionHeader">
<h3 id="appcardreputationdetails">Reputation Details</h3>
</div>
</div>
<div class="details" tabindex=-1>
<div general>
<label>Signature: </label>
<div id="signature" fileorpath>%s</div>
<label>Installed:</label>
<div id="installed" >%s</div>
<div>Startup Item: <span id="startup"></span></div>
</div>
<ul id="trustlevel" what>
<li>
<h3 id="prevalence" ></h3>
<label prevalencelabel>%s</label>
</li>
<li>
<h3 id="age" ></h3>
<label agelabel>%s</label>
</li>
<li>
<h3 id="trust"></h3>
<label></label><br/>
</li>
</ul>
</div>
</li>
<li SideEffects>
<div class="caption">
<div class="captionHeader">
<h3 id="appcardthreatdetails">Threat Details</h3>
</div>
<p fileorpath>
</p>
</div>
<div id="appcardurl" class="details" tabindex=-1>
<div url fileorpath>
<ul url="">%s</ul>
<p></p>
</div>
</div>
</li>
</ul>
</div>
Number of users in the Norton Community that have used this file: <em>Unknown</em>
<em>Fewer than 10 users</em> in the Norton Community have used this file.
<em>Fewer than 100 users</em> in the Norton Community have used this file.
<em>Hundreds of users</em> in the Norton Community have used this file.
<em>Thousands of users</em> in the Norton Community have used this file.
<em>Tens of thousands</em> of users in the Norton Community have used this file.
<em>Hundreds of thousands</em> of users in the Norton Community have used this file.
<em>Millions of users</em> in the Norton Community have used this file.
This file release is currently <em>not known.</em>
This file was released <em>less than 1 week ago.</em>
This file was released <em>more than 7 days ago.</em>
This file was released <em>more than 31 days ago.</em>
Warning:
Error:
Selected directory may contain critical files. <br>Are you sure that you would like to proceed?
YES
NO
Log file for this session does not exist
Log can not be viewed
Specified log location is not valid
http://security.symantec.com/nbrt/?ssdcat=221&lcid=1033&origin=unk&env=production&tooltype=NMR
If you delete the log history you will not be able to undo any previous fix sessions. Are you sure you want to delete the log history?
This program supports Windows XP, Windows Vista, and Windows 7. You are attempting to run this program on an unsupported operating system.
The Fix or Undo you ran is incomplete. Please restart your computer to complete the process.
You must be logged in as an administrator to run Norton Power Eraser.
System Restore point cannot be created.
System Restore point cannot be created because the Windows System Restore Service is stopped. Use the Administrative Tools in your Control Panel to start System Restore Service and try again.
The definitions needed for the scan are corrupt. Restart the scan to download new definitions.
The definitions needed for the scan could not be downloaded. Please try again later.
Norton Power Eraser has experienced an engine failure. Please download a new copy.
Cannot undo this session.
Cannot undo this session.
The definitions needed for the scan could not be downloaded. Please try again later.
The scan cannot run because Norton Power Eraser cannot access the Symantec server. Check your network connection or try again later.
Unspecified error
Cannot undo this session. The original location of these files no longer exists.
Select the folder you want to scan, and then click Ok.
Select the folder you want to save your logs to, and then click Ok.
risks removed
View
This file may not be malicious. We recommend removal only if a Remote Scan determines that the file is bad.
Are you sure you want to continue?
%s at %s
Not Available
All files have already been sent for Remote Scan
Files will be sent to Symantec Servers for analysis. Are you sure you want to remote scan this item?
All files will be sent to Symantec Servers for analysis. Are you sure you want to remote scan all the items?
<thead><tr><th class="tablerisk">teststring</th><th class="tabletype"></th><th class="tablemode"></th><th class="tabledeepscan"><a id="deepscanallfileslink" href="#" >Scan all files</a><div><span text></span><widget type="info" align=6><menu class="popup"><p></p></menu></widget></div></th> <th><button id="itemcheckbox_normal_checkall" type="checkbox" %hs >&nbsp;</button><span class="tablefix">Q</span><widget type="info" align="6" ><menu class="popup" ><p>text</p></menu></widget></th></tr></thead><tbody id="tablebody"></tbody>
http://liveupdate.symantec.com/upgrade/NMR/English/NMR.txt
This file may not be malicious.
Are you sure you want to remove this item?

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.5.0.42
ProductVersion 1.5.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Symantec Corporation
FileDescription Norton Power Eraser
FileVersion (#2) 1.5.0.42
InternalName NMR
LegalCopyright Copyright (c) 1997-2010 Symantec Corporation
OriginalFilename NPE.exe
ProductName Norton Power Eraser
ProductVersion (#2) 1.5
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2010-Aug-26 15:22:36
Version 0.0
SizeofData 68
AddressOfRawData 0x3e0240
PointerToRawData 0x3df440
Referenced File c:\bld_area\NMR_r1.5_42\bin\bin.iru\NPE.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x81f990
SEHandlerTable 0x7e2f80
SEHandlerCount 2794

RICH Header

XOR Key 0xdd0540b5
Unmarked objects 0
150 (20413) 5
ASM objects (VS2008 SP1 build 30729) 71
C++ objects (VS2008 build 21022) 5
C objects (VS2012 build 50727 / VS2005 build 50727) 8
Imports (VS2012 build 50727 / VS2005 build 50727) 57
Total imports 750
C objects (VS2008 SP1 build 30729) 310
C objects (VS2003 (.NET) build 3077) 21
ASM objects (VS2012 build 50727 / VS2005 build 50727) 55
Unmarked objects (#2) 230
C++ objects (VS2008 SP1 build 30729) 347
138 (VS2008 SP1 build 30729) 344
Linker (VS2008 build 21022) 1
151 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

<-- -->