2000ecfd169bd3cf5580bef69b2787a1

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Jan-02 11:55:49
Detected languages English - United States
FileDescription Setup/Uninstall
FileVersion 51.1054.0.0
Comments This installation was built with Inno Setup.
CompanyName SmartPack UltraTool
LegalCopyright
OriginalFileName
ProductName HyperWare
ProductVersion 1.6.3

Plugin Output

Info Matching compiler(s): Borland Delphi v6.0 - v7.0
Microsoft Visual C++ 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regsvr32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • https://www.innosetup.com
  • https://www.innosetup.com/
  • https://www.remobjects.com
  • https://www.remobjects.com/ps
  • innosetup.com
  • remobjects.com
  • www.innosetup.com
  • www.remobjects.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • SwitchToThread
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegUnLoadKeyW
  • RegSaveKeyW
  • RegReplaceKeyW
  • RegCreateKeyExW
  • RegLoadKeyW
  • RegEnumKeyExW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegDeleteValueW
  • RegFlushKey
  • RegQueryValueExW
  • RegEnumValueW
  • RegCloseKey
  • RegRestoreKeyW
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • MapVirtualKeyW
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Has Internet access capabilities:
  • WinHttpGetIEProxyConfigForCurrentUser
  • WinHttpSetTimeouts
  • WinHttpSetStatusCallback
  • WinHttpConnect
  • WinHttpReceiveResponse
  • WinHttpQueryAuthSchemes
  • WinHttpGetProxyForUrl
  • WinHttpReadData
  • WinHttpCloseHandle
  • WinHttpQueryHeaders
  • WinHttpOpenRequest
  • WinHttpAddRequestHeaders
  • WinHttpOpen
  • WinHttpWriteData
  • WinHttpSetCredentials
  • WinHttpQueryDataAvailable
  • WinHttpSetOption
  • WinHttpSendRequest
  • WinHttpQueryOption
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • GetDC
  • GetDCEx
  • FindWindowW
  • BitBlt
  • CreateCompatibleDC
Reads the contents of the clipboard:
  • GetClipboardData
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource HELPER_EXE_AMD64 detected as a PE Executable.
Suspicious VirusTotal score: 2/72 (Scanned on 2026-02-20 14:51:23) APEX: Malicious
Trapmine: suspicious.low.ml.score

Hashes

MD5 2000ecfd169bd3cf5580bef69b2787a1
SHA1 1ed4cb678076735f36c4cb6cc1570b5930cc1c26
SHA256 1ad67bfe3cc29c116f267f80926f3b2733d88db2064bcb8bc1fe03d394537308
SHA3 b7cb61be04f5fc46bcee20ec28af85be80f553f963721c7a7a078e68b0951774
SSDeep 98304:B3U5HY/KwjoYY1j48UWm2eTMFdC+Jb333PN:24/1jorPmEhN
Imports Hash 5dc260b92d0617d4bcaf0f586084de6f

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 11
TimeDateStamp 2026-Jan-02 11:55:49
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x3aa600
SizeOfInitializedData 0x8dc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x003AB668 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x3ac000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x44b000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f8d7b835dd57c8ca4e6aeb3e37297e5d
SHA1 cf36b7b7d49c18cf8304152e0f68695540d54119
SHA256 2c44493ceae8996171d421bd13cfbc250b0f1f8ac7335f997d29a9293ee5d144
SHA3 329f682246bdb5378bfec9c6fc6af6140a70f5f83286d1ba82aed8eba76a4a83
VirtualSize 0x39fda0
VirtualAddress 0x1000
SizeOfRawData 0x39fe00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46708

.itext

MD5 6af3f0e75d4f70fef4d8259940ccecd9
SHA1 c4ee8be6255be78c17715800833f2a614fd388a8
SHA256 1e210e597daa24ae5a892a6ff0703fb753247341a8a000d70e99bca20e388e67
SHA3 22cdae4f5a65ad364fe12cbc41aa36e4bbabd7f96e8122ba1724ea395a474b63
VirtualSize 0xa684
VirtualAddress 0x3a1000
SizeOfRawData 0xa800
PointerToRawData 0x3a0200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.10572

.data

MD5 fe8cb28118962157fc6b03268f59daf7
SHA1 150b5c2cc8a4ed8a4459380a5831ede51f7e1d63
SHA256 d913c10cb7009dde7244d33ec5dd84d496c10236ed7090ff6375c27b094e898b
SHA3 10cf9ef97faa7a8cc1bc19e7d98c84776f828697f3187b8c0e53e7b5745fb05d
VirtualSize 0xb6a0
VirtualAddress 0x3ac000
SizeOfRawData 0xb800
PointerToRawData 0x3aaa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.232

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xb3cc
VirtualAddress 0x3b8000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 2f5e95d6a2b8fbaa46a8285c29f18de5
SHA1 f46e94a81ccccf615af2173941cdd9b9570f5556
SHA256 7f1b3fcbac5e19c7cd62b499fecd83fec118c0851a7df456f2607fa166297616
SHA3 84b77019cafbe386b668bbf70d944f5f0f7cb569606c55c3689e56ac5ae40e5f
VirtualSize 0x4216
VirtualAddress 0x3c4000
SizeOfRawData 0x4400
PointerToRawData 0x3b6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.03888

.didata

MD5 770476113b17f81723c78c1ad38b24a1
SHA1 25358bb2e0127c7263a843996fa2384d42e6e1ff
SHA256 979581ab5dade7de31f51a98a7f63baabe175e2de578438cebe5ed26c31afc79
SHA3 99787472857b17ab3c38eab9199e4f54ee2343ab72681ab541b028088408721c
VirtualSize 0xf34
VirtualAddress 0x3c9000
SizeOfRawData 0x1000
PointerToRawData 0x3ba600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.37838

.edata

MD5 aa1e15bb416eac66c7ea50160928e607
SHA1 2dcc31aa04b33f18fb763dd6cc9e84d1527b688c
SHA256 c4fd53af24fed8865e63e3ff0d1d781b2d5697370ba9cfd432ab9f1762ab0158
SHA3 3a712e06c28900584830ba73bc70aeabfe00e3549afa17817356f5811b4b8136
VirtualSize 0x6e
VirtualAddress 0x3ca000
SizeOfRawData 0x200
PointerToRawData 0x3bb600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.27638

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x5c
VirtualAddress 0x3cb000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 222e568f6f64f324d12aa33fb288e140
SHA1 52d3820be275e1bfb4c19154d273ebe0824260ad
SHA256 7e9fdb4383b46556bf15daa10c6e13ac9a1c4335fdd17e60726cc88a94e4d115
SHA3 621a4e3396b4bfb8c59b6f52dedb15e7d8aa357b8d5cd4ba3f86c41067f954bd
VirtualSize 0x5d
VirtualAddress 0x3cc000
SizeOfRawData 0x200
PointerToRawData 0x3bb800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.38461

.reloc

MD5 3d68019d1029351cea83d31b005c9bdb
SHA1 c15b3de16972bdd804b1dfece51f073941ffa44a
SHA256 34d70af9f30fbe10d442de271be57e4a9d1ed98e4d5f333b75c0f6392a96d9b8
SHA3 be06fe0e83e991516595f781b8754fba11c590de7cae06a5ca84b3d9715797b4
VirtualSize 0x4c664
VirtualAddress 0x3cd000
SizeOfRawData 0x4c800
PointerToRawData 0x3bba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.72782

.rsrc

MD5 9f0f4347b7d80372025e0384cb6b7a6b
SHA1 06919fa91da0d7485af32093a69daab426a64adc
SHA256 2c53ef20d0e4a4f93c31607022301162aacfed4da9463f446923d4c10a026729
SHA3 8277f6000df2baa7ce469e01dedc644db2ff3ad2a675e3126174155ec58fbfb5
VirtualSize 0x302b4
VirtualAddress 0x41a000
SizeOfRawData 0x30400
PointerToRawData 0x408200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.2709

Imports

mpr.dll WNetEnumResourceW
WNetGetUniversalNameW
WNetGetConnectionW
WNetCloseEnum
WNetOpenEnumW
shlwapi.dll SHAutoComplete
winspool.drv DocumentPropertiesW
ClosePrinter
OpenPrinterW
GetDefaultPrinterW
EnumPrintersW
comdlg32.dll GetSaveFileNameW
GetOpenFileNameW
comctl32.dll ImageList_GetImageInfo
FlatSB_SetScrollInfo
InitCommonControls
ImageList_DragMove
ImageList_Destroy
_TrackMouseEvent
ImageList_DragShowNolock
ImageList_Add
FlatSB_SetScrollProp
ImageList_GetDragImage
ImageList_Create
ImageList_EndDrag
ImageList_DrawEx
ImageList_SetImageCount
FlatSB_GetScrollPos
FlatSB_SetScrollPos
InitializeFlatSB
ImageList_Copy
FlatSB_GetScrollInfo
ImageList_Write
ImageList_DrawIndirect
ImageList_SetBkColor
ImageList_GetBkColor
ImageList_BeginDrag
ImageList_GetIcon
ImageList_Replace
ImageList_GetImageCount
ImageList_DragEnter
ImageList_GetIconSize
ImageList_SetIconSize
ImageList_Read
ImageList_DragLeave
ImageList_LoadImageW
ImageList_Draw
ImageList_Remove
ImageList_ReplaceIcon
ImageList_SetOverlayImage
shell32.dll SHGetFileInfoW
SHChangeNotify
Shell_NotifyIconW
SHAppBarMessage
ShellExecuteW
ShellExecuteExW
user32.dll MoveWindow
CopyImage
SetMenuItemInfoW
GetMenuItemInfoW
DefFrameProcW
ScrollWindowEx
GetDlgCtrlID
FrameRect
RegisterWindowMessageW
GetMenuStringW
FillRect
SendMessageA
EnumWindows
ShowOwnedPopups
GetClassInfoW
GetScrollRange
SetActiveWindow
GetActiveWindow
DrawEdge
GetKeyboardLayoutList
OemToCharBuffA
LoadBitmapW
EnumChildWindows
SendNotifyMessageW
GetScrollBarInfo
UnhookWindowsHookEx
SetCapture
GetCapture
ShowCaret
CreatePopupMenu
GetMenuItemID
CharLowerBuffW
PostMessageW
SetWindowLongW
IsZoomed
SetParent
DrawMenuBar
GetClientRect
IsChild
IsIconic
CallNextHookEx
ShowWindow
GetWindowTextW
SetForegroundWindow
IsDialogMessageW
DestroyWindow
RegisterClassW
EndMenu
CharNextW
GetFocus
GetDC
SetFocus
ReleaseDC
ExitWindowsEx
GetClassLongW
CharToOemBuffA
SetScrollRange
DrawTextW
PeekMessageA
MessageBeep
SetClassLongW
SetRectEmpty
RemovePropW
GetSubMenu
DestroyIcon
IsWindowVisible
DispatchMessageA
UnregisterClassW
GetTopWindow
SendMessageW
SendMessageTimeoutW
LoadStringW
CreateMenu
CharLowerW
SetWindowRgn
SetWindowPos
GetMenuItemCount
GetSysColorBrush
GetWindowDC
DrawTextExW
ReplyMessage
GetScrollInfo
SetWindowTextW
GetMessageExtraInfo
GetSysColor
EnableScrollBar
TrackPopupMenu
DrawIconEx
GetClassNameW
GetMessagePos
GetIconInfo
SetScrollInfo
GetKeyNameTextW
GetDesktopWindow
SetCursorPos
GetCursorPos
SetMenu
GetMenuState
GetMenu
SetRect
GetKeyState
ValidateRect
GetCursor
KillTimer
WaitMessage
TranslateMDISysAccel
GetWindowPlacement
CreateIconIndirect
CreateWindowExW
GetMessageW
GetDCEx
PeekMessageW
MonitorFromWindow
GetUpdateRect
SetTimer
WindowFromPoint
BeginPaint
RegisterClipboardFormatW
MapVirtualKeyW
OffsetRect
IsWindowUnicode
DispatchMessageW
CreateAcceleratorTableW
DefMDIChildProcW
WaitForInputIdle
GetSystemMenu
SetScrollPos
GetScrollPos
InflateRect
DrawFocusRect
ReleaseCapture
LoadCursorW
ScrollWindow
GetLastActivePopup
GetSystemMetrics
CharUpperBuffW
SetClipboardData
GetClipboardData
ClientToScreen
SetWindowPlacement
GetMonitorInfoW
CheckMenuItem
CharUpperW
DefWindowProcW
GetForegroundWindow
EnableWindow
GetWindowThreadProcessId
RedrawWindow
EndPaint
MsgWaitForMultipleObjectsEx
LoadKeyboardLayoutW
ActivateKeyboardLayout
GetParent
MonitorFromRect
InsertMenuItemW
GetPropW
MessageBoxW
SetPropW
UpdateWindow
MsgWaitForMultipleObjects
DestroyMenu
SetWindowsHookExW
EmptyClipboard
AdjustWindowRectEx
IsWindow
DrawIcon
EnumThreadWindows
InvalidateRect
GetKeyboardState
ScreenToClient
DrawFrameControl
SetCursor
CreateIcon
RemoveMenu
AppendMenuW
GetKeyboardLayoutNameW
OpenClipboard
TranslateMessage
MapWindowPoints
EnumDisplayMonitors
CallWindowProcW
CloseClipboard
DestroyCursor
CopyIcon
PostQuitMessage
ShowScrollBar
LoadImageW
EnableMenuItem
HideCaret
FindWindowExW
MonitorFromPoint
LoadIconW
SystemParametersInfoW
GetWindow
GetWindowLongW
GetWindowRect
InsertMenuW
IsWindowEnabled
IsDialogMessageA
FindWindowW
GetKeyboardLayout
DeleteMenu
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
oleaut32.dll SafeArrayPutElement
LoadTypeLib
GetErrorInfo
VariantInit
VariantClear
SysFreeString
SafeArrayAccessData
SysReAllocStringLen
SafeArrayCreate
SafeArrayGetElement
GetActiveObject
SysAllocStringLen
SafeArrayUnaccessData
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetUBound
SafeArrayGetLBound
RegisterTypeLib
VariantCopyInd
VariantChangeType
WTSAPI32.DLL WTSUnRegisterSessionNotification
WTSRegisterSessionNotification
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
RegSetValueExW
RegConnectRegistryW
OpenThreadToken
GetUserNameW
RegQueryInfoKeyW
RegUnLoadKeyW
RegSaveKeyW
EqualSid
RegReplaceKeyW
GetTokenInformation
RegCreateKeyExW
SetSecurityDescriptorDacl
RegLoadKeyW
RegEnumKeyExW
AdjustTokenPrivileges
RegDeleteKeyW
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
AllocateAndInitializeSid
FreeSid
RegDeleteValueW
RegFlushKey
RegQueryValueExW
RegEnumValueW
ConvertSidToStringSidW
RegCloseKey
InitializeSecurityDescriptor
RegRestoreKeyW
msvcrt.dll memcpy
memset
winhttp.dll WinHttpGetIEProxyConfigForCurrentUser
WinHttpSetTimeouts
WinHttpSetStatusCallback
WinHttpConnect
WinHttpReceiveResponse
WinHttpQueryAuthSchemes
WinHttpGetProxyForUrl
WinHttpReadData
WinHttpCloseHandle
WinHttpQueryHeaders
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpOpen
WinHttpWriteData
WinHttpSetCredentials
WinHttpQueryDataAvailable
WinHttpSetOption
WinHttpSendRequest
WinHttpQueryOption
kernel32.dll SetFileAttributesW
SetFileTime
GetACP
GetExitCodeProcess
CloseHandle
LocalFree
GetCurrentProcessId
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
SetHandleInformation
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
GetProcessHeap
ExitProcess
HeapAlloc
WriteProfileStringW
GetCPInfoExW
CompareStringOrdinal
GetLongPathNameW
RtlUnwind
SetFilePointerEx
GetCPInfo
EnumSystemLocalesW
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
GetModuleHandleW
FreeLibrary
TryEnterCriticalSection
HeapDestroy
CompareFileTime
ReadFile
CreateProcessW
TransactNamedPipe
GetLastError
GetModuleFileNameW
SetLastError
GlobalAlloc
GlobalUnlock
FindResourceW
OpenMutexW
CreateThread
CompareStringW
CopyFileW
GetFileSizeEx
CreateMutexW
LoadLibraryA
GetVolumeInformationW
ResetEvent
MulDiv
FreeResource
GetDriveTypeW
GetVersion
RaiseException
MoveFileW
GlobalAddAtomW
GetSystemTimeAsFileTime
FormatMessageW
OpenProcess
SwitchToThread
GetExitCodeThread
GetCurrentThread
GetLogicalDrives
LocalFileTimeToFileTime
SetNamedPipeHandleState
LoadLibraryExW
TerminateProcess
LockResource
FileTimeToSystemTime
GetShortPathNameW
GetCurrentThreadId
UnhandledExceptionFilter
MoveFileExW
PeekNamedPipe
GlobalFindAtomW
VirtualQuery
GlobalFree
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
ReleaseMutex
FlushFileBuffers
LoadResource
SuspendThread
GetTickCount
WritePrivateProfileStringW
GetTempFileNameW
GlobalDeleteAtom
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
SetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
GetCurrentProcess
GlobalLock
SetThreadPriority
VirtualAlloc
GetTempPathW
GetCommandLineW
GetSystemInfo
DuplicateHandle
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
DeviceIoControl
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
lstrcmpW
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
EnumResourceNamesW
GetSystemDirectoryW
DeleteFileW
FormatMessageA
GetEnvironmentVariableW
GetLocalTime
WaitForSingleObject
GetFileInformationByHandle
WriteFile
SetFileInformationByHandle
CreateNamedPipeW
ExitThread
CreatePipe
DeleteCriticalSection
GetDateFormatW
TlsGetValue
SetErrorMode
GetComputerNameW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetOverlappedResult
GetSystemDefaultUILanguage
EnumCalendarInfoW
GetProfileStringW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
GetPrivateProfileStringW
WaitForMultipleObjectsEx
GetThreadLocale
SetThreadLocale
ole32.dll StgCreateDocfileOnILockBytes
CoCreateInstance
CLSIDFromString
CoUninitialize
IsEqualGUID
OleInitialize
CoFreeUnusedLibraries
CreateILockBytesOnHGlobal
CLSIDFromProgID
CoInitializeEx
OleUninitialize
CoDisconnectObject
CoInitialize
CoTaskMemFree
CoTaskMemAlloc
StringFromCLSID
gdi32.dll Pie
SetBkMode
CreateCompatibleBitmap
GetEnhMetaFileHeader
RectVisible
AngleArc
ResizePalette
SetAbortProc
SetTextColor
StretchBlt
RoundRect
SelectClipRgn
RestoreDC
SetRectRgn
GetTextMetricsW
RemoveFontResourceW
GetWindowOrgEx
CreatePalette
PolyBezierTo
CreateICW
CreateDCW
GetStockObject
CreateSolidBrush
Polygon
MoveToEx
PlayEnhMetaFile
Ellipse
StartPage
GetBitmapBits
StartDocW
AbortDoc
GetSystemPaletteEntries
GetEnhMetaFileBits
AddFontResourceW
GetEnhMetaFilePaletteEntries
CreatePenIndirect
CreateFontIndirectW
PolyBezier
EndDoc
GetObjectW
GetWinMetaFileBits
SetROP2
GetEnhMetaFileDescriptionW
ArcTo
Arc
SelectPalette
ExcludeClipRect
MaskBlt
SetWindowOrgEx
EndPage
DeleteEnhMetaFile
Chord
SetDIBits
SetViewportOrgEx
CreateRectRgn
RealizePalette
SetDIBColorTable
GetDIBColorTable
CreateBrushIndirect
PatBlt
LineDDA
SetEnhMetaFileBits
Rectangle
SaveDC
DeleteDC
BitBlt
FrameRgn
GetDeviceCaps
GetTextExtentPoint32W
GetClipBox
IntersectClipRect
Polyline
CreateBitmap
SetWinMetaFileBits
CombineRgn
GetStretchBltMode
CreateDIBitmap
SetStretchBltMode
GetDIBits
CreateDIBSection
LineTo
GetRgnBox
EnumFontsW
CreateHalftonePalette
SelectObject
DeleteObject
ExtFloodFill
UnrealizeObject
CopyEnhMetaFileW
SetBkColor
CreateCompatibleDC
GetBrushOrgEx
GetCurrentPositionEx
GetNearestPaletteIndex
GetTextExtentPointW
ExtTextOutW
SetBrushOrgEx
GetPixel
GdiFlush
SetPixel
EnumFontFamiliesExW
StretchDIBits
GetPaletteEntries
ntdll.dll _allshl
_aullshr
kernel32.dll (delay-loaded) SetFileAttributesW
SetFileTime
GetACP
GetExitCodeProcess
CloseHandle
LocalFree
GetCurrentProcessId
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
SetHandleInformation
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
GetProcessHeap
ExitProcess
HeapAlloc
WriteProfileStringW
GetCPInfoExW
CompareStringOrdinal
GetLongPathNameW
RtlUnwind
SetFilePointerEx
GetCPInfo
EnumSystemLocalesW
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
GetModuleHandleW
FreeLibrary
TryEnterCriticalSection
HeapDestroy
CompareFileTime
ReadFile
CreateProcessW
TransactNamedPipe
GetLastError
GetModuleFileNameW
SetLastError
GlobalAlloc
GlobalUnlock
FindResourceW
OpenMutexW
CreateThread
CompareStringW
CopyFileW
GetFileSizeEx
CreateMutexW
LoadLibraryA
GetVolumeInformationW
ResetEvent
MulDiv
FreeResource
GetDriveTypeW
GetVersion
RaiseException
MoveFileW
GlobalAddAtomW
GetSystemTimeAsFileTime
FormatMessageW
OpenProcess
SwitchToThread
GetExitCodeThread
GetCurrentThread
GetLogicalDrives
LocalFileTimeToFileTime
SetNamedPipeHandleState
LoadLibraryExW
TerminateProcess
LockResource
FileTimeToSystemTime
GetShortPathNameW
GetCurrentThreadId
UnhandledExceptionFilter
MoveFileExW
PeekNamedPipe
GlobalFindAtomW
VirtualQuery
GlobalFree
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
ReleaseMutex
FlushFileBuffers
LoadResource
SuspendThread
GetTickCount
WritePrivateProfileStringW
GetTempFileNameW
GlobalDeleteAtom
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
SetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
GetCurrentProcess
GlobalLock
SetThreadPriority
VirtualAlloc
GetTempPathW
GetCommandLineW
GetSystemInfo
DuplicateHandle
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
DeviceIoControl
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
lstrcmpW
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
EnumResourceNamesW
GetSystemDirectoryW
DeleteFileW
FormatMessageA
GetEnvironmentVariableW
GetLocalTime
WaitForSingleObject
GetFileInformationByHandle
WriteFile
SetFileInformationByHandle
CreateNamedPipeW
ExitThread
CreatePipe
DeleteCriticalSection
GetDateFormatW
TlsGetValue
SetErrorMode
GetComputerNameW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetOverlappedResult
GetSystemDefaultUILanguage
EnumCalendarInfoW
GetProfileStringW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
GetPrivateProfileStringW
WaitForMultipleObjectsEx
GetThreadLocale
SetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0x3c91e0
DelayImportAddressTable 0x3c921c
DelayImportNameTable 0x3c9394
BoundDelayImportTable 0x3c950c
UnloadDelayImportTable 0x3c964c
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0x3bb648

__dbk_fcall_wrapper

Ordinal 2
Address 0x13100

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

1 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xa68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.74641
MD5 2073a3bce01223d897c6e67e18e677e7
SHA1 f12d3ad97307acd4b6283883ff2535a1162b847f
SHA256 dadedca04ae6f15e735054a8844a0bb8c303e28e6a20a7b54393218ac9dac901
SHA3 e46bdf2c29fbea8826e7fbe4a23b787838298a2c57522375d89b84e0dadafb64

2 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98658
MD5 54aab9687517924a6f0872d3db85eefa
SHA1 62922bb6f27fbb4249513a00d0249079706901df
SHA256 49e1fd7235582a5fcda21ad7019a28f07be0bf5758e58ce433622ad2c186890f
SHA3 f088eafbfb352a9b54edad9f0b94b7222fb44a8593945940d99d3dd13d26e8dc

3 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01586
MD5 57086a45c3525554f76a843b8ea0ceb0
SHA1 bb3b05066884d9c430e0b242802c280ac263b894
SHA256 aaa0ec91899e3916e363e4670f8073cdd5de32024c330183e3e06a5c402ee7ae
SHA3 c79a0a88119906e5258eff43faafc4b86f3f5b6bb2871cce6de3d9cf379d4c66

4 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.1704
MD5 c9113f4798daee1ff04397b4699fee20
SHA1 04a77a02cdada1d0adb3af383475cf77ed177e76
SHA256 029b2163ec401f4b713e6870760f636551fab3fa800dbb940d4b0c547a922072
SHA3 47db69117d269446375dfe691c9444c7f9bbd176e1d529ba1748f54262d34cb9

5 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1628
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.912
MD5 a3ecd0150aa90c103ffd60e970a79b04
SHA1 155aa3f218939e3accb8578679c03dcbc88f5e52
SHA256 5426a3cf123eedfefc4fc0e764de1bd8c8f69edf6e0c68af1984438b28074de3
SHA3 212acca720a6b223f41cece9fd8589bbd1a13bbda47f2594ef695cac349254ba

6 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.8663
MD5 c519cde0a3de8b3fae65ec263d0211f2
SHA1 b5ec2ab4e4b832bbce774c34b575512f417dbea1
SHA256 aaa4217a07f23dc3124979542a8e1105ae36b6bd6e2951fd33e37fb66bfa6e97
SHA3 d126ff50d5c59f801cea6ba3220990d077af1349152fea03feb60a7e4fe71b0d

7 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.49649
MD5 07484b7d7d2de97ae274c997b13fcd95
SHA1 505d59bc4593dc34851764ff10e31a163db98f2d
SHA256 eab50ea5ff7abfa5e9c64cc691ea9cce1cac6d3a913a599902f486a05ce951e6
SHA3 fe754e115793dab307b8d9c1cf7eed88457e4fbe84d43324f4ad20d29dbb95dc

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.972379
MD5 d4e7ffb2c44d42dd0361bdf025ddc1cf
SHA1 b2f0d88ce66caf4e0efca16007174289977cf11b
SHA256 37265ae581f5649902228e063059ee88f390f5b67176020840d586a5cd55bd24
SHA3 0f814a879813c5f3705704e6b19fa66a7839ebf98df1941ad9e76825050843d9

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x12e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.68913
Detected Filetype PNG graphic file
MD5 2bdb3ce74738954decb4aa7784bc1dad
SHA1 7c1a93a6508fd2ab9998c87735e2e4cefebfdfef
SHA256 463eae02434b126bc01fc4aa5b1efd88fcb53313b05d180a199bfe064273cefd
SHA3 974d364c75b622f15c6c3f9f6fe645353b7aeaaf881f9285c1a568181ea6512d

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.03031
MD5 2f8da60b986b88d85ae9bf8741138629
SHA1 35b96991f3c9de50adc6a854314d7c4b3b762b4c
SHA256 83e1da080a4c85ba6c53a8b73a88a43bda96f0af2f63565aeacc8020c57fb711
SHA3 422e7d3d156266b34b571d202b0d2dcd4c42ebf317ab5755e4d4ab84837f5ed4

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4506
MD5 b7a61dbaf8fed9e8fd55586271a7a2fe
SHA1 1bf83736a9459f39e8ad4415a8a55f0fd03031d9
SHA256 1b9e2b76fb8a6306d71a58e8277e61cf775b329f259833b48539dabc55564dde
SHA3 ad3d753b9786fa2d2920812cb8dfb9cc077f392df40690a3dcf584e51d55b6e9

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.25978
MD5 74fa412d3b673173879e1694849b16fe
SHA1 fd666f6bd32077a3b3ad97d4591ed6e170179911
SHA256 e1cdcfc343bd2be7111edf269de89a61f6bed13a5780a79fec57110350d2b175
SHA3 59c23cb88d5b074c0e9d5dbc3af87739c0d65b11acab261f17e191f3575af7f4

13

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88786
MD5 208b4b138664f95bc9c28daa5d6240b7
SHA1 79131678428163495ffee79cf6c3cd70a4622804
SHA256 c98be6a1843a183920435a4ebcfcd9e8b1595b05aa7eb74e646fde7e2a22145b
SHA3 5f193d529afeb126339e38e17cffc7868ea66de29a81db907d1c031d9c5822e3

14

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.05344
MD5 d5713882a8b6f713df1c8aa6762f83be
SHA1 befebb6517352cfd8c21d8ab2249fea3f0dff28c
SHA256 7e853df706ecefdc4ad8b97685119ae61115ca8911672ff3a0757d38fb7a569c
SHA3 99278911ebcb21da5cc6c41b059af7fce1bad4e4dfb8b6d222c315d96b4c4104

15

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.45638
MD5 2986557d8e8c923f1db3b41056be89d0
SHA1 51b1f09a77ebb315bc606af35bfbd8aa9f1e6a21
SHA256 dc546c3aea3e73773bbb992eb17f4f965b87003c3902d49d4eb440532e2832a0
SHA3 20c6460fa091d47cff1a30d6682a4ab858dfd231a6fbf26a91c04d898b9af7ff

16

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.0902
MD5 d1751213557a1a2cc6500a58c25693a9
SHA1 7efa6a56e03f04e892697d2204ffa03f9599c693
SHA256 16b5b33af995ba6f7ba17a0ed8a30570b24f257422c7475f5c1e3fc30bd77306
SHA3 7a56be9c3564f02b871679525fcef8540c698c1ffc8e68ba30c2b21f70f67749

17

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.92295
MD5 c813c833a2bc690da8d56628da4144c1
SHA1 1a7a277c24008f52c9560e199e4b6c3a96aa9dc7
SHA256 1da333a9e6dfb76adc631c000efc59402124c7cdf33267b01ba6d3ec39c8f862
SHA3 fec07b53319e489c688536a45aee183220abd3d5a8a634a62d58713a6ce332d8

18

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45859
MD5 fb4847ad3011aabe2dba0b47c42740e1
SHA1 3ca100e8f516e6016d9577c1e4427fc56a8d72e7
SHA256 6e848fee35ac9ac8da57fe79c21c324606f13a7a668f3ca6d17c00849184b8ec
SHA3 ad416d6806ebf4edc5654a949a5940887efe78358fc9209209b2bccc6e2909b9

19

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10973
MD5 56dcba26df873545ecdea341fd695d10
SHA1 c32ee64a7c49c389b70e81db3090b7210d367a5f
SHA256 ab79bec8fb0870ac60f81ed373ca70f0503eeed5957c3a574c29a92547a6873b
SHA3 8cd210ad63b74b51e0250b806c7ccc7501bcc1c5d00467f97b963e1b12a1e6f6

4066

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x81c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28018
MD5 3fc39b5b717d53ebc0ef967356933aca
SHA1 fa7aaaeec3d2c5a5ad9ab33bb13a0ee9a3c1f7d1
SHA256 b4b0960009e864722a00aea1b36a3afaffa45585411d5c47e49d02907d19335d
SHA3 08ec9c7209cd060868662b68a498bb99b861771fd656c1340609dcbe1f7292f8

4067

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xad0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26658
MD5 a601e2f517cb12c6285f7414d78a7a1b
SHA1 4852907c4038a2130416ca5a515f60e9c4577380
SHA256 75b4e54d4a8bbec0f1f44a250c149c53c7d8cb365427a6c9166cf2cf7c4419ff
SHA3 8774ed7bc54b2793fdead11bfafeeee36bb79f984fba3a14ff8c8de734579ab0

4068

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31456
MD5 b67a62a61d743dc15156194d3a4a67c0
SHA1 6edc126e4e84cd16c34b8319a942785b7e7257bf
SHA256 3d1f031cd8105e6ce60723cde841e5f83567550ecaafed32f56e6111d09b8105
SHA3 a1c2ba85d93f90694b3d54d4f23fc978bc5ca8adb2d56b8412ff42af6bb952f6

4069

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x218
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3863
MD5 d2c946a2409f84d19cf578d38c9abd4f
SHA1 9d5421713ae31d27c780232d3511a5653231ef82
SHA256 dda3a4bfc6785021a6dce1166a6f6404b3e3bb5d9d19f46f78dff0b539dffff6
SHA3 2b977b8b9224ff6663bcac2d3478a5b0f9ae88cd52751d2e3e32774fa6d7725b

4070

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34152
MD5 0273d351861cf1b4e4151c07b865dbb8
SHA1 f142ad7967bf152cc3f3814f83b1b870259f4b1d
SHA256 d04156b52deed7a929bac108287f5b67dfc9ed8ada2c7ee775728f9c0176e3c4
SHA3 114b1202c230b6e4809a4616d8fee2b6ef07daa82fc7a7c60941ef5d913625a7

4071

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x42c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28346
MD5 ff11271a95571e6f4965875cb9d6b116
SHA1 de6568423bc60c8f7b1473011fe49d217d6f676e
SHA256 f3ac5e5b32deb2f25bce78831b921604122da2cc59dbdd38ccf2ee4f5ae91cb4
SHA3 14c7bfedde3623edd8e37e746bf7c4ead118e3f4fb70fa0b390f7147e9023a17

4072

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34501
MD5 7552aecd13b7cd9039a538be60b6a317
SHA1 cb11c7ef3cbbe8ba7a8785e07a1e9532d0eaeb01
SHA256 38d1a0b721b385efd876c77f81ef1a0f8d5d38f6cc11fdc28439abcb3c437f62
SHA3 fd7f8ccddfc1c78767cfcd55cfad5dc9542b1924aab0f81ecf5fbc7f7c3fae88

4073

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18862
MD5 3dec8a8fc2112f1b522c27b633a14b99
SHA1 3e815ae95cbd040ffadb8feb2dfb33fc08e0184f
SHA256 6161a82da2a07fee6b5d039b9efda45b96e9ce4f8f0c85aa1e47a3dbd4c5b562
SHA3 a2d11d01cd078c9c4398fcc557bfc42338e88b72bee7407a09b636ea2ade6a07

4074

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34082
MD5 13d1a889ff8b49e913b18b677f539ddb
SHA1 81dbbf78807c0b8a993ea0801dbc1cf7a4aa0259
SHA256 41caa8e8a09de5403edac0c271fa3b702cb2fb9e144008246a0ae7faccc8ef82
SHA3 adc9bf26e60fc4bab198d3822c39422ee32772a7da8957dde8ef7ff7eae7d1bc

4075

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31095
MD5 39785ac96922e4ddda606e4842fc2fed
SHA1 9305d53f4d85b0132828d8bdda771b9fa1fdef80
SHA256 9e1885717551e18fb625c565011b10b5b7061e84e377288fff56a6f54c2788c2
SHA3 5fbba68be48f17ae6304ed4bb3589d79431ac4f7c028256636a5230746dbf1f6

4076

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48379
MD5 f3d34521fcb7b6517853412f01fdaf1b
SHA1 906364b239f9dc8e320a7c872dee6a483adcec97
SHA256 45b2c7a2c3f36ebc21ebf6dcd3424722970f3f183b704cf0e1adf00a0ce8f3ee
SHA3 6ed1011ceadd13b01574e1975f3f2fb7708a951519a61e8c2e8667b7753cf156

4077

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xfc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48702
MD5 f09129856bc06350c3cf136d50722917
SHA1 f92347b17397b121cbeaacca9fada741f43d5853
SHA256 46d3fd0ce3ada4ff2b73c35fbe472dadc5f53b2d6c66121f82bfee9e93bd12a6
SHA3 2edcb0cf28fb3af248d1832f00bafa006d62214c9839bd3d161f008d17115378

4078

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23911
MD5 898a281e18f513064b0ca44c8add4f16
SHA1 58dc33a5a3116c3858d945c667ad0ec76f7c7223
SHA256 38625ea45a0a7acc1f1c97cc50e4116c87149b3aa692bc506d614ec1a668ce4e
SHA3 f0a4d1bfeeb622851aaf75335e8443594429cf95a33bf78591e33094702e9001

4079

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33292
MD5 4d21267bfb885b48d593abf8bbdd43e5
SHA1 42fdbe1d3a2c8e2079f88e22ddd4ce6ceb19e7ed
SHA256 16a12c0e1e981afe8c3b818a1021f9aadb49a8c0093c341ce0c0304d0d3391a0
SHA3 ff0dccbba6ed0aa4fa3d1e5b5c34af38fb0c0c8939cb36bf9afb203fdcb5727f

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x394
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34188
MD5 2fef4b7dd48d29812bfb1ff93b125a94
SHA1 aa1cdf0f3d8e089d3f295e4ce1be3399b2b4ed77
SHA256 62006fd8024eb3c4011ee22f9acf72a675aa9289eb4c460d8b940dccec2e4c9f
SHA3 f1a238f2bc99d5ca5f8d9d63257e64acae6895def5a27e6b4daa1d3f0e283a71

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x578
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28039
MD5 4f22013432ec1b5313b680b87fc00021
SHA1 93dbbef772e75787939489ad652e7ae529353962
SHA256 75f6086995328ef43ae35ac59421c771208d7db10c3c6a729a3c4615b7fb4932
SHA3 eb908e51a7824fc20ace0815f25ced78fbb5e63b9bbf952829fc91dd76cbd179

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x310
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33435
MD5 c76e3587f3ceb050b20c3c691406bcca
SHA1 c324f89149420cd16e7045f47ec0882dc95bfc99
SHA256 9dc5bab3c1ff60955330fbc1b237f193d1c239fefd3cb1376d97f529c4f1e7d1
SHA3 1f1a6612ed2db275483f78983d8d96a0aa97e008a1b919029ea32de5d308d6df

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3d8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51661
MD5 295b8e307c2792e6d7869455346b8612
SHA1 60e9d36a460e94f250b283fc4ba8584ff5c0e67c
SHA256 593378aa6aca8101c548fc113e395dae4e3212f4fda2ace1ae1803b632c502ba
SHA3 a196037b3542beafc9dfdfd75c68118ad681490ca016856dc0d4d4d74f83a077

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x388
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28094
MD5 468ceec3d4d29a03bdb0d78aed7f4f80
SHA1 3c4c945c89c1adedd83b0c05dc46c1a04e14cb4e
SHA256 ee60ad90cff33124f7a3b34c65d4aabf5b8b25ec48e878771dc51e9648b4dc49
SHA3 306d080bc91caba6f5ff80d4eacadcb080a3b70942ce9710f215c9e42e1f135c

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x520
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31443
MD5 8b3fc70bf97c3ee1ce5f468a4c7f896d
SHA1 c89b596256a0961d41e44933c177297314a5bd9f
SHA256 af90082f3aab326b1d4c6843ec789c8f50ade834e18b9c90720cd7a29c407159
SHA3 ae2a56721d061aeae7233e236a086f7550c1857aedd9d084647f6056a1537f33

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26067
MD5 5f7f1162c474d4f0f5a1202c5e8f5348
SHA1 0d8314add4eb01a676ce5621cdcb7968d93b5567
SHA256 6c8989a921904a87e0defc60ceb3c93a33319f023b205637243dd8bec7e80b9a
SHA3 32ebed3dc1d9fe4778ff9023df3b6789d6cf1b83e0044c1bc54d8827d9c2b427

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x378
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26408
MD5 d573af986caffce8236cafbd105c219f
SHA1 3d89795dd70b5301e9048574123b3cebec494798
SHA256 6063e0de4369f8fa364ca527c963a95cda945f40501fca5707bff8c344468814
SHA3 a42012f074989ba89048c3f27efed4f51956a762bbf0bb997ad9babc4a70f69a

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29999
MD5 1ae6048c2074cae53bf08e034dfd01cf
SHA1 1a2b5e53736c0575ade646c6c868df1fb8cd8b78
SHA256 18f4de227b196853891e8623d188a8d540dd04b73b245c77d88b6b34a9f6e3d0
SHA3 405bc2a6a1e2b2c9af4230ed8518d7799d464729fe12718aa5a320b42e6aaada

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x43c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32572
MD5 b50c6bd62c4dbad2d64a6b05720f862a
SHA1 c1aac2eb287c027df5bc8134fc31d08dabbbcef3
SHA256 3ff1f54cd964f42d791ede63f4b19d5d05cf189946fe73411330745835e3a16a
SHA3 b2470b111049ce09d87c0433e31cf2dc59540ec5faa69251a79e45bb1bc46b29

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23392
MD5 c82c5bd41f34467617721afba76f3941
SHA1 5a9d07eb437d2bd3defbbb25216eb000b19ee64e
SHA256 fe86f912026ade5d1862e4f3e706c6ce1cf2ce1a41371d9ae5c9e1e9a8ee2a28
SHA3 a761387a82620c650e42951341e00bb51657ec8fa21650a882b8af728c95f357

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34269
MD5 62810907e7b23a396bd760ac66e05fff
SHA1 770c9eaee9795b7a88330d03f4237ea99fff17c1
SHA256 125ebf3d2ac46fce44b67cf20f794c2e00469b914797b7f0f4a4493ffee6f032
SHA3 9db19dd09d08b97172a4dba0186da341ed05b6d21741f42f88c0a4c70f44ef6e

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x274
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37656
MD5 eac6176077049b6cef3bd12bcdabc2c4
SHA1 d45fa6f8932c69d611c9b5e2df0e986d19914c73
SHA256 3fac74b62406d176e43e477b835cc16c309038c1cb63f926a310793cc41ba6cf
SHA3 c6ce0465c283ad02eeec9ba17bdb82e3309855503079498f8d2788ed3e101a58

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x414
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32985
MD5 841394712bdddbb9ab326971df10ba5c
SHA1 2e14a56e86eff2c643166f8a11bce2115607d7be
SHA256 a994360204f893513d5d8bf822748f74103155283d449c5c21457ad419ca607a
SHA3 9d5598522c98251f996ef21b17fdae90797f2ea2a3392eb5053b9fe5e15f8dc6

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x37c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33165
MD5 58435d9e3b56fea1cca741c7e22e62ff
SHA1 20dfdca4ca26f476b854393517912b1e9054e103
SHA256 fe1d67858c63d7aeecdd970c7768c9371586116778d688505e1cd5e71643ba79
SHA3 8813ce458900cbfba3e8614d41330487f9a42ee1d487a8c492919aae0856b5d4

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29074
MD5 04b914d9c0ed093e8b510b576b1a9881
SHA1 aeb5887cba5a8c919fbb673f12ba2e60fbb21ab9
SHA256 9451e219e58ee6293cb3bc533b231b45c71f6876ceeccd9f935d9186b0ab7f91
SHA3 be1dc190b7c85d4a3d34b1d4e4ab7c12586a334c3e29c002a90ff29fbb86a63d

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26783
MD5 1fd8a5a4e36cf57426403ffa1ee43706
SHA1 82c254864853d7a1896160e5f2bfb012d2669a7c
SHA256 72ad458e849fef28b490e14801cbd5990d1cd2bdcd848e3d5421410b3f2fc90e
SHA3 2da30e47bff548e0c29b4d52e11f8b7c8a358d5d306b5217d920e93df26a412f

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

HELPER_EXE_AMD64

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72037
Detected Filetype PE Executable
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
SHA3 711ebd07a2e4a2820eb2cbc94d8e731ecf51b395755a3b3747b2a932581b9df9

MSG_ERROR

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x148b
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93139
Detected Filetype PNG graphic file
MD5 50ea148a8b3f8e6e0bcf6b37918f4a93
SHA1 4d4a0a69e7f3f1a234cf4edcf3a897e18531b07e
SHA256 e74432afd4c7fe4cfb0cf8425ae298fcf425e0f0437510bde8546dbd02da0a2d
SHA3 de40febb93ab240fba58daff4f662e8f6889974a0fbadb23d2009c6efa445253

MSG_INFO

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x111e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.90721
Detected Filetype PNG graphic file
MD5 51ffac6dde5a49e226a5435dc08656a0
SHA1 2d4a625ab8c1c45ed5f0e2a4e4138077d5ee89e6
SHA256 25e3ec43b207e22a0ee7701b9525975043ec2817e492dd07eb40306b944374c4
SHA3 becc7f28397fc80e9d96cdd13bb0a732ea8935cbde51c448e367e6bdbcbf464e

MSG_WARNING

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0xd8c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89203
Detected Filetype PNG graphic file
MD5 481232c3ddd70cc57011d3d8ed8191ca
SHA1 8722e588f04dab44a4ec94e248d74d058f269220
SHA256 636f368c9f42323b69cdf2463823eadd363e91df7f37a9d0eb863708a7f3fb83
SHA3 1efc85d96c9733bb8129189eb537e3c4658563f0336bb33eba34707378eb9205

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xfc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.31593
MD5 94e7fad8acead53e77cef513a403dfad
SHA1 d10e19725d254afb35f7312bf01c3352fc5dfecf
SHA256 604e95c61ea0374e743b8e64f3034a86b58bbfccb3e0e6fa451385f0a5749ed0
SHA3 5981cd3331fb1d58814adc5db73d8c70985e9f345d36e4d7ac4b1adcb7f3ccbf

TNEWDISKFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x479
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.5275
MD5 f6bfdd1843e38cb20447b43933217681
SHA1 8db28960d93f3f4631b3399adf8b8dd2ea0aa517
SHA256 9ef4a1349bc893050921474ddef03d459a473b436a03d8ec8818e1b6fc1a22f3
SHA3 b698d333aadaa3918a9b4bd51d373d36c2322d9a2931e63409fb65e986b63c2e

TSELECTFOLDERFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3f9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.48915
MD5 a49ace10800f1933b84676ae618090b4
SHA1 cc9c699cfcf6105782e6face3256a3620d589b5a
SHA256 c61ee474c32c75ad73b957b4ecbc86dba1bd7cf00d16edfd105f14fdf13b8bd0
SHA3 77be1a20c5d0ed8253bb0bbaf9883675cd2ea75085eedeab7e996a023223ddfa

TSELECTLANGUAGEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4b5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49788
MD5 9dac8948402fbf21c84395c7f9822412
SHA1 760166ff50044bb72203df9410a4def596ffd1d5
SHA256 f365f114398d7979872e3db26354aa309aa90efdd3733c4a141e88cf43dd97b3
SHA3 26066fc6411dc534720a583cdeea78180f34d6090cc08a71ffc00e5e09cb1cd0

TUNINSTALLPROGRESSFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x7e5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.50579
MD5 b358d47e45d29a318b0fd5ef0ab0050b
SHA1 41a6c056b375eb61ff8921df5973b88a0e2595a6
SHA256 9c4b25447532431a9c943f68e8f76664bb920a9bfeac235b380d95ab7f67aff1
SHA3 9c69ce2b0efbbf6571c005cf795bfe2719a4b588c55057503accb09b3d711e23

TUNINSTALLSHAREDFILEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x557
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47826
MD5 d6c65331637b9076541bcff69e203d1e
SHA1 f85bee5a8808171eea4a3f377de05da483ab62cb
SHA256 82a9784b9a486e50293803591c0ed49294ded1eb91a5ff04907b79f7b3d15afd
SHA3 eb6352e026207af40666839c11c0090762e27ba1f5f356aa40e33268574f7418

TWIZARDFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a77
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.50362
MD5 9148fa3e7546cce65516921e44703f9d
SHA1 c28dd869d1fb4bbe4f813356e5a54eaa1af3d718
SHA256 95be63c04e7a088d7ceae3b73487d3c1065e205e016e5e6527d2a951c121670a
SHA3 dbadb9440a0f5ef0afe90fdd6a51b656562eecce79b0ad377aecd991a8721d18

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08095
Detected Filetype Icon file
MD5 ee0da5fbb3d343c27941fb3f8b77164a
SHA1 c2be29713ab52dcf391d34d14f367cbbab966cc0
SHA256 81341db39d8fdec0bd34960423a41a5e2ba5c5830b957f070d1563580b52011b
SHA3 f3d78fc2b713ea2475d919525d0e8019ea390471c9899df1b1345093fb558919

Z_GROUPICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59109
Detected Filetype Icon file
MD5 385cc21eaf20afcff5b3d979058aa923
SHA1 16535d9e11e3895a35d68f635b585c0cfb5e106e
SHA256 c58998b93f811c11c2d058d80cbbf38a68e5bbdc603db6d7080535ffaade94c7
SHA3 15e80be7cbd3a21026669102e727c4d2407216897a50b23e22a917c7d5e42dbe

Z_UNINSTALLICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63275
Detected Filetype Icon file
MD5 1a9f1478ad3d2e0d9c122a6fa764e416
SHA1 8e3ae2dfe0427cf7169772610d3ea37b1c45f9c4
SHA256 c5873a9933eaef91fc6630a099627fd7655defbe4bbd3224f6a50289347d0673
SHA3 55354deabda41a13ece280a66dabe9b1ec1b0c510155b804b34442c8e252f75a

1 (#3)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x514
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71044
MD5 d6d771778c9be37907981edeefebc77d
SHA1 83fea0dd1c7fd727decefdfc09ebb66cdae3761a
SHA256 aa3566bd8f0c525177c009297979a19365afbfbbc87282c964a1f77a03b91c15
SHA3 6536da926297419ca35e6af8779adcea1dd9fc5c464a70985ff1d860c8167868

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.19236
MD5 44ebd323d850f47e3767f1a9c1e78d7a
SHA1 c8a5269dfccb1d75fbd291d594d8af8b4058b4bc
SHA256 5b7e2d01e742ba2eebeffb94fa98154542180fe721c73dc573e0abc840e4eb03
SHA3 5ec674311c810d44c867649470d894a4bcce84d3d0c47a51dbb7754b12654e2d

String Table contents

The chunks must be compatible to be assigned.
This "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.
This "Portable Network Graphics" image contains no data.
The program tried to add a existent critical chunk to the current image which is not allowed.
It's not allowed to add a new chunk because the current image is invalid.
The png image could not be loaded from the resource ID.
Some operation could not be performed because the system is out of resources. Close some windows and try again.
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA)
This operation is not valid because the current image contains no valid header.
The new size provided for image resizing is invalid.
The "Portable Network Graphics" could not be created because invalid image type parameters have being provided.
The "Portable Network Graphics" image could not be loaded because it uses an invalid image bit depth.
Nil interface
Unknown method
Expected return address at stack base
This "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)
The "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corrupted
This "Portable Network Graphics" image is invalid because it has missing image parts.
Could not decompress the image because it contains invalid compressed data.
Description:
The "Portable Network Graphics" image contains an invalid palette.
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it again
This "Portable Network Graphics" image is not supported or it might be invalid.
(IHDR chunk is not the first)
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels.
There is no such palette entry.
This "Portable Network Graphics" image contains an unknown critical part which could not be decoded.
This "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.
This "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.
This "Portable Network Graphics" image uses an unknown color type which could not be decoded.
Out of Record Fields Range
Null Pointer Exception
Null variant error
Out Of Memory
Interface not supported
Unknown error
Invalid array
Unknown procedure
Not enough parameters
Invalid parameter
Too many parameters
Out of string range
Cannot cast an interface
Cannot cast an object
Capacity < Length
Can only remove last item from stack
Invalid Type
Internal error
Invalid Header
Invalid Opcode
Invalid Opcode Parameter
no Main Proc
Out of Global Vars range
Out of Proc Range
Out Of Range
Out Of Stack Range
Type Mismatch
Unexpected End Of File
Version error
divide by Zero
Math error
Could not call proc
Error adding header: (%d) %s
Error removing header: (%d) %s
Error reading data: (%d) %s
Error setting timeout for the request: (%d) %s
Error opening certificate file: (%d) %s
Certificate is not found in file: (%d) %s
Pair of extension and mime type already exists
Mime type cannot be empty
Value name cannot be empty
Quality weight is out of range
Invalid float
Unknown Identifier
Exception: %s
[Invalid]
No Error
Cannot Import %s
Parameter "%s" not found
Invalid relative URL path: "%s"
Maximum number of redirections (%d) exceeded
Error getting Server Certificate
Server Certificate Invalid or not present
Server Certificate not accepted
Empty certificate list
Unspecified certificate from client
Client rejected the certificate
Execution of request terminated with unknown error
Error querying headers: (%d) %s
Error obtaining session handle
Error sending data: (%d) %s
Error receiving data: (%d) %s
Error connecting to server: %s
Error opening request: (%d) %s
Cannot call BeginInvoke on a control with no parent or window handle
CardPanel card index is out of range
CardPanel.ActiveCard cannot be nil
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Scheme "%s" already registered for %s
Scheme "%s" is not registered
Credential without user and password
Platform-dependant function not implemented
Scheme-dependant function not implemented
Method already assigned
URL already assigned
Parameter index (%d) out of range (%d..%d)
Invalid URL: "%s"
Caption cannot be empty
Unable to load style '%s'
Unable to load styles: %s
Style '%s' already registered
Style class '%s' already registered
Style '%s' not found
Style class '%s' not found
Invalid style handle
Invalid style format
Class '%s' is already registered for '%s'
Class '%s' is not registered for '%s'
%s parameter cannot be nil
Feature not supported by this style
Style '%s' is not registered
Cannot unregister the system style
Style not registered
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Length of value array must be >= length of prompt array
Prompt array must not be empty
&Username
&Password
&Domain
Login
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
Cannot remove shell notification icon
%s requires Windows Vista or later
Button%d
RadioButton%d
Down
Ins
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
All
Unable to insert a line
Clipboard does not support Icons
Cannot open clipboard: %s
Text exceeds memo capacity
Operation not supported on selected printer
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
&All
N&o to All
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Enhanced Metafiles
Icons
Bitmaps
TIFF Images
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
Control '%s' is used on a not main thread
Cannot drag a form
Metafiles
Unable to Replace Image
Unable to Insert Image
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
. Path:
%s
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
%s property out of range
Icon image is not valid
Metafile is not valid
Invalid pixel format
Invalid image
Scan line index out of range
Cannot change the size of an icon
Cannot change the size of a WIC Image
Unknown picture file extension (.%s)
Unsupported clipboard format
Unsupported stream format
Out of system resources
Canvas does not allow drawing
Text format flag '%s' not supported
Invalid image frame index %d: there are %d frames (0-%d)
Invalid image size
Invalid ImageList
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Observer is not available
MD5: Cannot update a finalized hash
SHA1: Cannot update a finalized hash
SHA2: Cannot update a finalized hash
Error decoding URL style (%%XX) encoded string at position %d
Invalid URL encoded character (%s) at position %d
Cannot construct an ITask in this manner
At least one task in array nil
Cannot start a task that has already completed
One or more tasks were cancelled
One or more errors occurred
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Bitmap image is not valid
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server 2022
Windows 8
Windows 8.1
Windows 10
Windows 11
Cannot create instance of class %s
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Property '%s' is read-only
Property '%s' is write-only
RTTI objects cannot be manually destroyed by application code
Specified Login Credential Service not found
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Invalid Timespan format
Timespan element too long
No context-sensitive help installed
No help found for context %d
Unable to open Index
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Argument out of range
Argument must not be nil
Unbalanced stack or queue operation
Item not found
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Length of Strings and Objects arrays must be equal
Source and Destination arrays must not be the same
Class %s is not intended to be constructed
Invalid Timeout value: %s
SpinCount out of range. Must be between 0 and %d
Invalid Reset Count: %d
Invalid Count: %d
Invalid Decrement Count: %d
Invalid Increment Count: %d
Decrement amount will cause invalid results: Count: %d, CurCount: %d
Count already max: Amount: %d, CurCount: %d
Countdown already reached zero (0)
Timespan too long
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue
Value cannot be NaN
Negating the minimum value of a Timespan is invalid
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Cannot call CheckTerminated on an externally created thread
Cannot call SetReturnValue on an externally create thread
Parameter %s cannot be nil
Parameter %s cannot be a negative value
Input buffer exceeded for %s = %d, %s = %d
Invalid characters in path
?
The given "%s" local time is invalid (situated within the missing period prior to DST).
No help viewer that supports filters
Invalid argument
List index out of bounds (%d)
. %s range is 0..%d
. %s is empty
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format
'%s' is an invalid mask at (%d)
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Operation Cancelled
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
Can't write to a read-only aggregate stream
CheckSynchronize called from thread $%x, which is NOT the main thread
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
Monitor support function not initialized
%d exception(s):
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s' (offset %x). %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
<unknown>
'%s' is not a valid integer value
'%s' is not a valid integer value for %s type
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 51.1054.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription Setup/Uninstall
FileVersion (#2) 51.1054.0.0
Comments This installation was built with Inno Setup.
CompanyName SmartPack UltraTool
LegalCopyright
OriginalFileName
ProductName HyperWare
ProductVersion (#2) 1.6.3
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x7cb000
EndAddressOfRawData 0x7cb05c
AddressOfIndex 0x7acc30
AddressOfCallbacks 0x7cc010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!