2271e19c8501aa3eaaaa35be2cefb2f5

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Apr-14 16:10:23
Detected languages English - United States
FileDescription Setup/Uninstall
FileVersion 51.1052.0.0
Comments This installation was built with Inno Setup.
CompanyName By DFT PRO inc
LegalCopyright
OriginalFileName
ProductName DFTPRO
ProductVersion 3.4.4

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regsvr32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • https://www.innosetup.com
  • https://www.innosetup.com/
  • https://www.remobjects.com
  • https://www.remobjects.com/ps
  • innosetup.com
  • remobjects.com
  • www.innosetup.com
  • www.remobjects.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • SwitchToThread
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegCreateKeyExW
  • RegEnumKeyExW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegDeleteValueW
  • RegFlushKey
  • RegEnumValueW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
  • CreateProcessW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • CallNextHookEx
  • GetForegroundWindow
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Has Internet access capabilities:
  • WinHttpGetIEProxyConfigForCurrentUser
  • WinHttpSetTimeouts
  • WinHttpSetStatusCallback
  • WinHttpConnect
  • WinHttpReceiveResponse
  • WinHttpQueryAuthSchemes
  • WinHttpGetProxyForUrl
  • WinHttpReadData
  • WinHttpCloseHandle
  • WinHttpQueryHeaders
  • WinHttpOpenRequest
  • WinHttpAddRequestHeaders
  • WinHttpOpen
  • WinHttpWriteData
  • WinHttpSetCredentials
  • WinHttpQueryDataAvailable
  • WinHttpSetOption
  • WinHttpSendRequest
  • WinHttpQueryOption
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • BitBlt
  • CreateCompatibleDC
Queries user information on remote machines:
  • NetWkstaGetInfo
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource HELPER_EXE_AMD64 detected as a PE Executable.
Suspicious The file contains overlay data. 25571 bytes of data starting at offset 0x313000.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 2271e19c8501aa3eaaaa35be2cefb2f5
SHA1 2a40223c39924e82a6e8b3b3aaa9d9c9be6bd6bc
SHA256 8a2885f73ca8a1904865bc3aca43223cc077e85ab26239f89c8768212ae236ed
SHA3 e8c8c4bea6e298fb97def870205ea5e88dee0418e9924214ca487f8d8db4f077
SSDeep 49152:mdx4HDQNJL0VR6SgMt+k4RiP+RmXMjiINiMq95FoHVHNTQTEjE333t0U:nHDYsqiPRhINnq95FoHVBE333t5
Imports Hash e6ca0c8c79f98b918c9f8a8c40d054ae

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 10
TimeDateStamp 2022-Apr-14 16:10:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x2c4200
SizeOfInitializedData 0x4ea00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002C5660 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x2c6000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 6.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x321000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0a67372f181115b7cebfbbcdb1006d83
SHA1 23297e45172ade3c4959a230710695d7e36a1743
SHA256 3e70807b6273ba32a3ed24480f0439bf0626d69d0d88c813f620b05b5925bf0e
SHA3 065d6c2e177e1a25d6d40742f4c846b5ccf80424835f3191c02391db30ce1300
VirtualSize 0x2c1610
VirtualAddress 0x1000
SizeOfRawData 0x2c1800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39853

.itext

MD5 16393e4e7bec78a4bcae5ae55f8f292c
SHA1 5ed0b544df09bc1565bedb07c3cd839dc5cf5677
SHA256 acf7cca6916c3cabbf19d8d193d8de33d9aff6fc095cd5408a88f9d11115284d
SHA3 7adb88f483e1d9ccf27ae277adc82f51cef4440319314fbcb100e587af0b1815
VirtualSize 0x2890
VirtualAddress 0x2c3000
SizeOfRawData 0x2a00
PointerToRawData 0x2c1c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.10194

.data

MD5 042a801fd25918b12ad83daff139f4d4
SHA1 98a6e76b8539d7588b8dd7ad0e1e95487bde567f
SHA256 cc73de2790257081196cdb75a83030413c03426f04ee0e3f4bc270aa7f0bad2a
SHA3 fd4cb437979e3b5f164732fc3ea09ca844048cd08b031027c53dbd42b0bb8df4
VirtualSize 0x91e0
VirtualAddress 0x2c6000
SizeOfRawData 0x9200
PointerToRawData 0x2c4600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.26396

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x7900
VirtualAddress 0x2d0000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 03081ba482d19e9b1cd93a470ca85644
SHA1 5d6a0a0e322e774ea4370d2d6ffd0b144cd98fcc
SHA256 a2428128bf78e08569cc1e2f89e35fcd9853a916a25b4d4a63b0df6f94c660da
SHA3 88f039ff72a508eb2f807727732d40eb6a8022b2b9ed2f002f83ba2d23ae61f3
VirtualSize 0x39ba
VirtualAddress 0x2d8000
SizeOfRawData 0x3a00
PointerToRawData 0x2cd800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.28895

.didata

MD5 c332bb295f400e296d2b360ecd996bd0
SHA1 6c559afe60e71f8e3dd1bf625bc4263d665da7d9
SHA256 2ed9d1e0091ecbe0e0eecc4ea29f992ae1ceea8bc6c539a81d5c5cb6ac2a22c8
SHA3 01f2e367169c8a71fce9eecf0266dda64e3672e222194b7ac1f3a88dc73e7cd4
VirtualSize 0xbde
VirtualAddress 0x2dc000
SizeOfRawData 0xc00
PointerToRawData 0x2d1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.38805

.edata

MD5 c2fbf23dade9282f5d6f41b22deec17c
SHA1 af9177e2cf6ddc4004570d897558452aedc9d8af
SHA256 8ad7f0ca636b9c08e1418b4f8f720e21299bcc0b4e4ccb342464ddc7e6750f08
SHA3 826f1ffd6f4b96f9e4e4852d15005fdeb42d4d7e0e8814fb2cae618e6b6f6abb
VirtualSize 0x97
VirtualAddress 0x2dd000
SizeOfRawData 0x200
PointerToRawData 0x2d1e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.85122

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x4c
VirtualAddress 0x2de000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 b334cafcb8aaba886c7aff7f26845b05
SHA1 2b06ae4fd33b8af38cbecf4e701447f5aa330349
SHA256 fd0bc774f01c895b33a5a87f342cc9d1fdf4bbfadc0c1c0c7568f83069aa6253
SHA3 26117430d1b4dba1e97e33d882820f931761da34c3f446bc0dc496ccade7823c
VirtualSize 0x5d
VirtualAddress 0x2df000
SizeOfRawData 0x200
PointerToRawData 0x2d2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.36269

.rsrc

MD5 0648c49319f691dd8e3b17bb3f8ff358
SHA1 7520b9398025799a51034bd2f5217785bb96b605
SHA256 fae3c9e60c6d6c962533a1ad4c3c42a3d59edad8ba7d454437b1475609fc1274
SHA3 f1c2e7bfa86182014b9ac3c134672601076cc09afeeb3fc37eecc757f5dea3b8
VirtualSize 0x40cd0
VirtualAddress 0x2e0000
SizeOfRawData 0x40e00
PointerToRawData 0x2d2200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.88563

Imports

mpr.dll WNetEnumResourceW
WNetGetUniversalNameW
WNetGetConnectionW
WNetCloseEnum
WNetOpenEnumW
comdlg32.dll GetSaveFileNameW
GetOpenFileNameW
comctl32.dll FlatSB_SetScrollInfo
InitCommonControls
ImageList_DragMove
ImageList_Destroy
_TrackMouseEvent
ImageList_DragShowNolock
ImageList_Add
FlatSB_SetScrollProp
ImageList_GetDragImage
ImageList_Create
ImageList_EndDrag
ImageList_DrawEx
ImageList_SetImageCount
FlatSB_GetScrollPos
FlatSB_SetScrollPos
InitializeFlatSB
FlatSB_GetScrollInfo
ImageList_Write
ImageList_SetBkColor
ImageList_GetBkColor
ImageList_BeginDrag
ImageList_GetIcon
ImageList_GetImageCount
ImageList_DragEnter
ImageList_GetIconSize
ImageList_SetIconSize
ImageList_Read
ImageList_DragLeave
ImageList_Draw
ImageList_Remove
shell32.dll SHBrowseForFolderW
SHGetMalloc
SHGetFileInfoW
SHChangeNotify
Shell_NotifyIconW
ShellExecuteW
SHGetPathFromIDListW
ShellExecuteExW
user32.dll CopyImage
CreateWindowExW
GetMenuItemInfoW
SetMenuItemInfoW
DefFrameProcW
GetDCEx
GetMessageW
PeekMessageW
MonitorFromWindow
GetDlgCtrlID
ScrollWindowEx
SetTimer
WindowFromPoint
BeginPaint
RegisterClipboardFormatW
FrameRect
MapVirtualKeyW
OffsetRect
IsWindowUnicode
RegisterWindowMessageW
FillRect
GetMenuStringW
DispatchMessageW
SendMessageA
DefMDIChildProcW
EnumWindows
GetClassInfoW
GetSystemMenu
WaitForInputIdle
ShowOwnedPopups
GetScrollRange
GetScrollPos
SetScrollPos
GetActiveWindow
SetActiveWindow
DrawEdge
InflateRect
GetKeyboardLayoutList
OemToCharBuffA
LoadBitmapW
DrawFocusRect
EnumChildWindows
GetScrollBarInfo
SendNotifyMessageW
ReleaseCapture
UnhookWindowsHookEx
LoadCursorW
GetCapture
SetCapture
CreatePopupMenu
ScrollWindow
ShowCaret
GetMenuItemID
GetLastActivePopup
CharLowerBuffW
GetSystemMetrics
SetWindowLongW
PostMessageW
DrawMenuBar
SetParent
IsZoomed
CharUpperBuffW
GetClientRect
IsChild
ClientToScreen
SetWindowPlacement
IsIconic
CallNextHookEx
GetMonitorInfoW
ShowWindow
CheckMenuItem
CharUpperW
DefWindowProcW
GetForegroundWindow
SetForegroundWindow
GetWindowTextW
EnableWindow
DestroyWindow
IsDialogMessageW
EndMenu
RegisterClassW
CharNextW
GetWindowThreadProcessId
RedrawWindow
GetDC
GetFocus
SetFocus
EndPaint
ExitWindowsEx
ReleaseDC
MsgWaitForMultipleObjectsEx
LoadKeyboardLayoutW
GetClassLongW
ActivateKeyboardLayout
GetParent
CharToOemBuffA
DrawTextW
SetScrollRange
InsertMenuItemW
PeekMessageA
GetPropW
SetClassLongW
MessageBoxW
MessageBeep
SetPropW
SetRectEmpty
UpdateWindow
RemovePropW
GetSubMenu
MsgWaitForMultipleObjects
DestroyMenu
DestroyIcon
SetWindowsHookExW
IsWindowVisible
DispatchMessageA
UnregisterClassW
GetTopWindow
SendMessageW
AdjustWindowRectEx
DrawIcon
IsWindow
EnumThreadWindows
InvalidateRect
GetKeyboardState
DrawFrameControl
ScreenToClient
SendMessageTimeoutW
BringWindowToTop
SetCursor
CreateIcon
CreateMenu
LoadStringW
CharLowerW
SetWindowPos
SetWindowRgn
GetMenuItemCount
RemoveMenu
AppendMenuW
GetSysColorBrush
GetKeyboardLayoutNameW
GetWindowDC
TranslateMessage
DrawTextExW
MapWindowPoints
EnumDisplayMonitors
CallWindowProcW
DestroyCursor
ReplyMessage
GetScrollInfo
SetWindowTextW
GetMessageExtraInfo
EnableScrollBar
GetSysColor
TrackPopupMenu
DrawIconEx
PostQuitMessage
GetClassNameW
ShowScrollBar
EnableMenuItem
GetIconInfo
GetMessagePos
LoadImageW
SetScrollInfo
GetKeyNameTextW
GetDesktopWindow
GetCursorPos
SetCursorPos
HideCaret
GetMenu
GetMenuState
SetMenu
SetRect
GetKeyState
FindWindowExW
MonitorFromPoint
SystemParametersInfoW
LoadIconW
GetCursor
GetWindow
GetWindowLongW
GetWindowRect
InsertMenuW
KillTimer
WaitMessage
IsWindowEnabled
IsDialogMessageA
TranslateMDISysAccel
GetWindowPlacement
FindWindowW
DeleteMenu
GetKeyboardLayout
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
oleaut32.dll SafeArrayPutElement
LoadTypeLib
GetErrorInfo
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
SafeArrayCreate
SafeArrayGetElement
GetActiveObject
SysAllocStringLen
SafeArrayPtrOfIndex
SafeArrayGetUBound
SafeArrayGetLBound
VariantCopy
RegisterTypeLib
VariantChangeType
VariantCopyInd
advapi32.dll RegSetValueExW
ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenThreadToken
GetUserNameW
RegQueryInfoKeyW
EqualSid
GetTokenInformation
RegCreateKeyExW
SetSecurityDescriptorDacl
RegEnumKeyExW
AdjustTokenPrivileges
RegDeleteKeyW
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
FreeSid
AllocateAndInitializeSid
RegDeleteValueW
RegFlushKey
RegEnumValueW
RegQueryValueExW
ConvertSidToStringSidW
RegCloseKey
InitializeSecurityDescriptor
netapi32.dll NetWkstaGetInfo
NetApiBufferFree
msvcrt.dll memcpy
winhttp.dll WinHttpGetIEProxyConfigForCurrentUser
WinHttpSetTimeouts
WinHttpSetStatusCallback
WinHttpConnect
WinHttpReceiveResponse
WinHttpQueryAuthSchemes
WinHttpGetProxyForUrl
WinHttpReadData
WinHttpCloseHandle
WinHttpQueryHeaders
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpOpen
WinHttpWriteData
WinHttpSetCredentials
WinHttpQueryDataAvailable
WinHttpSetOption
WinHttpSendRequest
WinHttpQueryOption
kernel32.dll SetFileAttributesW
SetFileTime
GetACP
GetExitCodeProcess
IsBadWritePtr
CloseHandle
LocalFree
GetCurrentProcessId
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
HeapAlloc
ExitProcess
WriteProfileStringW
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
GetModuleHandleW
FreeLibrary
HeapDestroy
CompareFileTime
ReadFile
CreateProcessW
TransactNamedPipe
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
OpenMutexW
CreateThread
CompareStringW
CopyFileW
CreateMutexW
LoadLibraryA
ResetEvent
MulDiv
FreeResource
GetDriveTypeW
GetVersion
RaiseException
MoveFileW
GlobalAddAtomW
GetSystemTimeAsFileTime
FormatMessageW
OpenProcess
SwitchToThread
GetExitCodeThread
OutputDebugStringW
GetCurrentThread
GetLogicalDrives
LocalFileTimeToFileTime
SetNamedPipeHandleState
LoadLibraryExW
TerminateProcess
LockResource
FileTimeToSystemTime
GetShortPathNameW
GetCurrentThreadId
UnhandledExceptionFilter
MoveFileExW
GlobalFindAtomW
VirtualQuery
GlobalFree
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
ReleaseMutex
FlushFileBuffers
LoadResource
SuspendThread
GetTickCount
WritePrivateProfileStringW
GetFileSize
GlobalDeleteAtom
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
SetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
GetCurrentProcess
SetThreadPriority
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
DeviceIoControl
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
lstrcmpW
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetEnvironmentVariableW
GetLocalTime
WaitForSingleObject
WriteFile
CreateNamedPipeW
ExitThread
DeleteCriticalSection
GetDateFormatW
TlsGetValue
SetErrorMode
GetComputerNameW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetOverlappedResult
GetSystemDefaultUILanguage
EnumCalendarInfoW
GetProfileStringW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
IsDBCSLeadByte
CreateEventW
GetPrivateProfileStringW
WaitForMultipleObjectsEx
GetThreadLocale
SetThreadLocale
ole32.dll StgCreateDocfileOnILockBytes
CoCreateInstance
CLSIDFromString
CoUninitialize
IsEqualGUID
OleInitialize
CoFreeUnusedLibraries
CreateILockBytesOnHGlobal
CLSIDFromProgID
OleUninitialize
CoDisconnectObject
CoInitialize
CoTaskMemFree
CoTaskMemAlloc
StringFromCLSID
gdi32.dll Arc
Pie
SetBkMode
SelectPalette
CreateCompatibleBitmap
ExcludeClipRect
RectVisible
SetWindowOrgEx
MaskBlt
AngleArc
Chord
SetTextColor
StretchBlt
SetDIBits
SetViewportOrgEx
CreateRectRgn
RealizePalette
SetDIBColorTable
GetDIBColorTable
RoundRect
RestoreDC
SetRectRgn
GetTextMetricsW
RemoveFontResourceW
GetWindowOrgEx
CreatePalette
CreateBrushIndirect
PatBlt
LineDDA
PolyBezierTo
GetStockObject
CreateSolidBrush
Polygon
Rectangle
MoveToEx
DeleteDC
SaveDC
BitBlt
Ellipse
FrameRgn
GetDeviceCaps
GetBitmapBits
GetTextExtentPoint32W
GetClipBox
Polyline
IntersectClipRect
GetSystemPaletteEntries
CreateBitmap
AddFontResourceW
CreateDIBitmap
GetStretchBltMode
CreateDIBSection
CreatePenIndirect
SetStretchBltMode
GetDIBits
CreateFontIndirectW
PolyBezier
LineTo
GetRgnBox
EnumFontsW
CreateHalftonePalette
DeleteObject
SelectObject
ExtFloodFill
UnrealizeObject
SetBkColor
CreateCompatibleDC
GetObjectW
GetBrushOrgEx
GetCurrentPositionEx
SetROP2
GetTextExtentPointW
ExtTextOutW
SetBrushOrgEx
GetPixel
ArcTo
GdiFlush
SetPixel
EnumFontFamiliesExW
GetPaletteEntries
kernel32.dll (delay-loaded) SetFileAttributesW
SetFileTime
GetACP
GetExitCodeProcess
IsBadWritePtr
CloseHandle
LocalFree
GetCurrentProcessId
SizeofResource
VirtualProtect
TerminateThread
QueryPerformanceFrequency
IsDebuggerPresent
FindNextFileW
GetFullPathNameW
VirtualFree
HeapAlloc
ExitProcess
WriteProfileStringW
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetTimeZoneInformation
FileTimeToLocalFileTime
GetModuleHandleW
FreeLibrary
HeapDestroy
CompareFileTime
ReadFile
CreateProcessW
TransactNamedPipe
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
OpenMutexW
CreateThread
CompareStringW
CopyFileW
CreateMutexW
LoadLibraryA
ResetEvent
MulDiv
FreeResource
GetDriveTypeW
GetVersion
RaiseException
MoveFileW
GlobalAddAtomW
GetSystemTimeAsFileTime
FormatMessageW
OpenProcess
SwitchToThread
GetExitCodeThread
OutputDebugStringW
GetCurrentThread
GetLogicalDrives
LocalFileTimeToFileTime
SetNamedPipeHandleState
LoadLibraryExW
TerminateProcess
LockResource
FileTimeToSystemTime
GetShortPathNameW
GetCurrentThreadId
UnhandledExceptionFilter
MoveFileExW
GlobalFindAtomW
VirtualQuery
GlobalFree
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
ReleaseMutex
FlushFileBuffers
LoadResource
SuspendThread
GetTickCount
WritePrivateProfileStringW
GetFileSize
GlobalDeleteAtom
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
SetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
GetCurrentProcess
SetThreadPriority
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
DeviceIoControl
LCMapStringW
GetDiskFreeSpaceW
VerSetConditionMask
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
lstrcmpW
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetEnvironmentVariableW
GetLocalTime
WaitForSingleObject
WriteFile
CreateNamedPipeW
ExitThread
DeleteCriticalSection
GetDateFormatW
TlsGetValue
SetErrorMode
GetComputerNameW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetOverlappedResult
GetSystemDefaultUILanguage
EnumCalendarInfoW
GetProfileStringW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
IsDBCSLeadByte
CreateEventW
GetPrivateProfileStringW
WaitForMultipleObjectsEx
GetThreadLocale
SetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0x2dc1a0
DelayImportAddressTable 0x2dc1d4
DelayImportNameTable 0x2dc2f8
BoundDelayImportTable 0x2dc41c
UnloadDelayImportTable 0x2dc510
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0x2d3640

__dbk_fcall_wrapper

Ordinal 2
Address 0x10a7c

TMethodImplementationIntercept

Ordinal 3
Address 0xb5e78

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

15

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98162
MD5 021aad439483b0897b0e5108a2064660
SHA1 76c83d89cc9d9fe34260501d207efc77e170827f
SHA256 5293b8b39263b8fbbecc9aa638c0376160fb5f99574669a7333c97721c78457c
SHA3 124be6134bb06d30b1893da14246b7dddfa667dad2b4723e8fbc8c42716b67a9

16

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.60733
MD5 7310107fdd353aa98d6765d1af76a144
SHA1 ebd5244728eac57efaccd1f44a4da69530be7236
SHA256 f592f54ac383a4ea1479a726088d4431238b269379984d7a03ebd2cb1357d459
SHA3 85bc750e860988c63923e04581ce7c24c9f4fbdc72b64d236a1b57611227493b

17

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25842
MD5 54e7869fcf014f1492795e74595b1111
SHA1 2dba60b1ee874676af72ca1a0fbcaa1fabe7c9be
SHA256 24449e3c723bb17681538cdd32145fab62870ac720e2d3a030050119c736a7b8
SHA3 9cd3ccd7b059fefb3912e6a69d8083e803a4e7fb28e90caa0adb45ceeae88d97

18

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.54436
MD5 6a45048ca28ca8c54d6dc0c1e9a2970a
SHA1 b4bf87ccabb4e2096eb1738bd2cd3f423d507a9e
SHA256 2f468cee1b02e9825c68ffb34a7ae2b966a2d16e50205f004af01949ed9ae3a8
SHA3 212d2e05385b663968de7aafa0a8ac0884dfc7855c16f02e49dfe2d633eef748

19

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14627
MD5 facfe9ff10f3fc6ef54d2f2a81132961
SHA1 eb0444c5dab9308a83a1b13bf01cef074937030a
SHA256 63e8da1ae9d6ee798d62fbd5e2aa556a52ed17cefce8dfac1eadbfea1b1ee79a
SHA3 571efbedb7aedc4b61f0cf318dc88474e4d28b4254b32e9f1c5ae9851d683562

20

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.05344
MD5 d5713882a8b6f713df1c8aa6762f83be
SHA1 befebb6517352cfd8c21d8ab2249fea3f0dff28c
SHA256 7e853df706ecefdc4ad8b97685119ae61115ca8911672ff3a0757d38fb7a569c
SHA3 99278911ebcb21da5cc6c41b059af7fce1bad4e4dfb8b6d222c315d96b4c4104

21

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.45638
MD5 2986557d8e8c923f1db3b41056be89d0
SHA1 51b1f09a77ebb315bc606af35bfbd8aa9f1e6a21
SHA256 dc546c3aea3e73773bbb992eb17f4f965b87003c3902d49d4eb440532e2832a0
SHA3 20c6460fa091d47cff1a30d6682a4ab858dfd231a6fbf26a91c04d898b9af7ff

22

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.0902
MD5 d1751213557a1a2cc6500a58c25693a9
SHA1 7efa6a56e03f04e892697d2204ffa03f9599c693
SHA256 16b5b33af995ba6f7ba17a0ed8a30570b24f257422c7475f5c1e3fc30bd77306
SHA3 7a56be9c3564f02b871679525fcef8540c698c1ffc8e68ba30c2b21f70f67749

23

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90691
MD5 279abe44d7a158f298cce4d434323720
SHA1 6e35a8bc9ebde976d4ef03334681fe5161f9996b
SHA256 a2e8a2b7f8d4ad62dec70bc30e16d04f775bc93ce0edfb85fb210ab2e1f001ed
SHA3 bb50c6db71e3cf136c35d677713ec6a3a5454f21b99e931f6df397ea80674d6b

24

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.95949
MD5 0ad6fe1d939e1eb200a28ca263148f68
SHA1 1b695dea96deabff8adef7028b4ff680d6d9e468
SHA256 613d4dfaff6199b032b8432f6e21badb1550c2230dd9a30020f5be96c0bb4545
SHA3 1d4c1e1493d0546f506966930178276a4a3b23efcc89207e0ca1c6413f93d10f

25

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.12964
MD5 be86be28be6ecfd8c75ff62e11250211
SHA1 45974d1544d94c685b70276bdc4181e9192935a9
SHA256 2feff613466ca2e073609057b14481edc4349b3fae126370fdc8d380ae269776
SHA3 c892f62fb8f3550a17a557856f04037be08bb6b4a673dab406d12d2ab1868a35

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x36f5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97243
Detected Filetype PNG graphic file
MD5 0e49a42f4fc830a373e96acfdeb27f94
SHA1 68f50453ca1c3ee4f56b88c45cd955a3cfe861d6
SHA256 d878b65c4e3b893948f663daf902e2e32c274cc492292829550a171e52cea581
SHA3 ae7c9455e1760ce4da447c88c3a4da8e7ee334f0ef58503ebc35e6898e22dd79

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53566
MD5 76c14ee7b724b5ec91aece5cd8c4b091
SHA1 2df0e534222497fa7f03d381e7125fc786550f31
SHA256 4a28f44357768b04113bfa45deb4617f1124ed5380a9bb276c8379b1dc46646b
SHA3 5f5713f29414d230ae301332e3fda35a3d95bb5240511d4158bac8c6e1ab3590

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.8603
MD5 2346530f8606021b38cf3e27a34417b4
SHA1 35da1d243aec3b89528250ccbfca3b51855a1c47
SHA256 579e7daee039ccf1bcec504ec95c10813229f76d4a6a1b990d9674470cbab678
SHA3 32e74377eef3b6ae41558dd50c5c90afb44d7d7877b014768116a645bce62cfc

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.0884
MD5 4229d8587b36503ab1d77187870ab21b
SHA1 069f3e7aaaa5890786346c5c5f2b71b3d9b793ff
SHA256 3a18d99f6ec9786eac5047f42e098931d749b28effa65ffae12e9278221d5a4e
SHA3 2d92fb2b8be078601c34eadbec1af201f5756008e490454c215d72db4c3e6ed8

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.34723
MD5 a51c2a2f5eeb1fc060a9d5faafb74643
SHA1 3ffab1d3cdd0125582d4acdb5742a90560ecda9f
SHA256 996c7a52e5b92df659986b1e36a15f4c4aefe2cd0ccc9804ad2694f4e7f3315e
SHA3 0e933d90607d8311b97c6241e73da4d35be3a945ba78db2b9b9a4ec6561875d3

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.93105
MD5 ce6c6ee22ce58bdaf3cc63de9a154709
SHA1 ecb3480582c4cbc96e24cc8f1f1350cab1e9ee51
SHA256 3cdadd17265c012f5a9cb5faa0d9d3eef872a72459b945fa9064416ec34dd70b
SHA3 47beac12f74cb49d0e3c9f1f05086ce11583566d6e839f80a401f387c4df771a

4073

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04851
MD5 cabfb08210aa9f02e1d72bc0554971eb
SHA1 29442bcb70e2ea4989cd8dcab9e0e0bc1c905084
SHA256 b944a6941e34fe246c7d29eb962dda8a8aba7cdacd374e4a6e3f199cbb1f6197
SHA3 eef8de4f69b4c54382b70b281fff3e841e4dd40e5d06e2255696c6ae537f4829

4074

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x440
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29087
MD5 95795db77bf870e0de11ad6a6c2a23b7
SHA1 b9cd4a8847117367be81c4c8f80c87e6c3adb963
SHA256 9585f8b4737c1cf57f899f6211fe40a3c6d74b7d928d9daf0a43fc863e1c59d2
SHA3 6005e1e7309ef0666f5bb2d163dfe4dd1bd642ae1942cdbf12c6c8b30ced6b93

4075

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33956
MD5 7b3afa3b240f42a8cd70815294d5a1b0
SHA1 f35bc29afbf6738782ab44a417ecae200fe4056d
SHA256 6a4656e966f45d47373559f5abc22d1acdc96fbde8b4023284793f792786d090
SHA3 e63c7a17b082f6bd92d2d095cb59d9f55457be38522bee9066a68b1143feb6a7

4076

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x214
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39375
MD5 7826661ed18db1b3f75c32839b8b878d
SHA1 83a5b1ff03f565ac0e36af6a0331d562bb42f98f
SHA256 dc8a1bf74cff782fa1516494c206a6f9c555836274232628d474d394f00b2574
SHA3 f42aa53aa0e97281f6924f5feed131c688450448dff4285bd2452dbe364fa5e6

4077

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33492
MD5 8fbdf1d495ad0ebe240253681c1e1177
SHA1 81ea6c56e59c23def9e6517b437c8401982d9027
SHA256 693f70295602c17527027d767215544b13ad6972af412670d550508e0d329eaa
SHA3 c91a099a123b2b2121d119081b19b2d82817170606d36e5757c4ef949e4663d3

4078

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34082
MD5 13d1a889ff8b49e913b18b677f539ddb
SHA1 81dbbf78807c0b8a993ea0801dbc1cf7a4aa0259
SHA256 41caa8e8a09de5403edac0c271fa3b702cb2fb9e144008246a0ae7faccc8ef82
SHA3 adc9bf26e60fc4bab198d3822c39422ee32772a7da8957dde8ef7ff7eae7d1bc

4079

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40812
MD5 e3bb73c693ff26cca4144eb8bd05f922
SHA1 dde0510ffacb6964da8099c7535033ff953f5fde
SHA256 841066038bd077ba897490bef005459b08b2c7f8edbe2157cedd406879759e6a
SHA3 ae94014fbbd6088e78f9f90d23f2e6c26c7b95ff53a43ea08b184feba358e395

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44749
MD5 8f4c350205eeb5123c7d1677adcd8122
SHA1 e770c0fe1c87b940391f133e81d60d5dcddd4cda
SHA256 61cd7802614e0f37f75ac4683ff6cc07a6307c0731f514ff63d64968a34c1b0e
SHA3 c898abf8dd3cb4ffcd79ef008c3d38dc31a30ec36d78fb9d7397cc9cd5408451

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34572
MD5 ad2d5b381924690939fb569e9556c8c3
SHA1 3544de06fc20f84c5b6024053ac07aa55065b966
SHA256 b38e1f6994567fa5cc4e8001cbef60146a0c32c54780d38642436d85cbeb632f
SHA3 be0d14d095819beb54e828b33a9273b81b94f943ee4c72321fa1a0cf7eb8ecd2

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33548
MD5 3304257a00d08ecababb143ec350206e
SHA1 2da930ab79740aaf76c58b0887899291bdee15d0
SHA256 65a8c1bd07037e8b89bfcd029969b4b55770746b36fec88ffdbed7cf74209335
SHA3 ec8759b3b1f291e9362fc9fe531815ddcb4e10003489df07978d0cdb56bddfa0

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30343
MD5 cfdffa327adb5e58db28f80d7b000303
SHA1 ac313b0c4c0023321b9faa5bc3ebcbd53aee5859
SHA256 f2cc5c13793dc9eadb1ec3b4ab45366489518a96a23afee03113c0ca72864f57
SHA3 64e787fc51a8fc055955fb7de2f1700401130c551fb3c6eb0aa04b2175a00d0c

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x418
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32233
MD5 37e54241e06152b212dfeafa20371fb5
SHA1 e9f339b7b0730ce1176c402eb2c7396fef28c04f
SHA256 4ce9bce465d96624238c59cb9ed32774a779b6f610af3e1d5126a1e44afbe871
SHA3 2384d463bf230f76e84cef98d2b2dcf1ff197f705769bae165f9028c142fd624

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x370
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53223
MD5 7be5b5fb5865324b9b6b593fa9ba8982
SHA1 22d85e5530107939bc6945e697fe0c55927460f9
SHA256 b9303214db5d78c5ebf99748d074ab16c0a8ad42d072fd7f4557d4eefbff8cb6
SHA3 b710c3900961ca681cb15bee68fb1526839715080722eb0e869aa21a065763a0

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x39c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28912
MD5 eba2601af0f7908232f37cb97b02decc
SHA1 23aa70f2ae7e22f6235ef6450a6c117e6c88c94d
SHA256 112ae19b5719e3866d0e12a8bde451ee9e76aea2c4c8587eebdcafe9831ba235
SHA3 cc96d8ae07e76962e2b933f8a64de1464e86dd2eb1f1c8900ee9d4e1be0c942c

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25858
MD5 cac852e23271e1cf240aa450808bc888
SHA1 fe5041ea25eccfd9cba8aa0daf964c096b9574a4
SHA256 1c3d02ee3e42f9812e5ba9b83a6fdf9fe941af82873707092648620bd58ec83a
SHA3 412f8fea901bd2aef70ed9e21e740d8592ee738e6b2a0cde24925b7ed58e973b

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x384
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33416
MD5 325248260df216f5c130453fa7150a48
SHA1 1a9f3f595fe248e649b4a5cdecb32eef0728da5a
SHA256 c3f502f982a5c1513322eb81f2edd3de05aa4bf411484c07a4e90bf67c9fdf9e
SHA3 5d47c3a060dc947fddc78a99e794039c16b475799073565055944d9d5e5fa75a

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x454
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32464
MD5 af7562962fd02ab991e91f0c92828c1e
SHA1 24cafc0f676f8601339f07f529ec50b8f11b7cdd
SHA256 9b32484fe8b4405a50386d453697186d415ff25be90fa6c43066238b43454eb4
SHA3 c8f0936a2ab616655e7de53d843b5b2dc4d3d9ff6071a3cb96d14756e2bbf1e5

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x210
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33048
MD5 9acd1f175ddbe1e53f1757ad92f2bb9f
SHA1 ae9e14ad03a412c8ea4f854f0918ab706829f6db
SHA256 be6a3c265a4275d030dc0331d1307fe1d528f7f2f579028d1293a98c334e9251
SHA3 5ffa238b05e1d787dee4e6d7287ae80fba1e87765ed6ed46329b00139c126b10

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3597
MD5 7e273c4bbf7dd1965240b2c2dcee0b69
SHA1 1e8af06c09789193e7e67153298502b7a2706d39
SHA256 e3ae1b4e55d951ce7a60dcab94b51a8115acf178bc1b5918e85e1f5330661d93
SHA3 2f20bdd55689f11018f0ead872c1b493cc7ec1a08da090e69f279603e2d2c983

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4421
MD5 2dcc7981d984da46ba1a0dccfcbc0782
SHA1 f162a256c8186a5e59ab35ab32477bdddbb39c70
SHA256 37fd0eb104204b5b0d7d89bcea8488cdbb181d00f959ada72b6f05cfe581e078
SHA3 4653abd504829760736451c0b03976e01f030dcd5a06ac4b5b1ef2fc35af32db

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29873
MD5 63a468240dd8f9d0005db790213b02d8
SHA1 ef213a97dd0f8d6acce1bb26b5cc5a519d2f9913
SHA256 1689edcabba87b8268f5302fc915295d70d23cb61de6fd777fcf9f6f6bb3c219
SHA3 89b7bb424c41a4144a3141c73e9b71b94a3a8702f74edd693b4e4656abc456bd

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31046
MD5 1a014230116fb4df9645648f3db6d77c
SHA1 e3ac6ff1f89e3e505f3ffc37c69be4b1114b3597
SHA256 7ba277096fcf162a436cfa21787041416810bf661906a1d7ede353922b407682
SHA3 a253c36d6faeb7223882330dde38517d993d2c4d51bd03a288daa33e2b205811

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x314
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31552
MD5 9afd6552b747d94f46ba1e18e845e2b2
SHA1 8f06a4b8f88318d39b11e9762ad81b9bebd67ca6
SHA256 9ffae64881c8e4a56c9b996144eb90957b61452c6a43dbbfee15e6012be73d94
SHA3 41904031012059038b409b60587708a30f2f796a2edf0de5cbd30f85271f0f34

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27218
MD5 fa0dc10a870a7c66015cb9f6e820aa31
SHA1 7762d7092a8e5c97713064e0d56742d153b2fbd8
SHA256 19d18d73cd09c40ca0485180c72e3ab44c94695ee8b9a6905ce11ce63446a65f
SHA3 11a8f657613d4f89dc0cb92774c152416abdcdbd2b072b45bee1772afddb495c

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

HELPER_EXE_AMD64

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72037
Detected Filetype PE Executable
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
SHA3 711ebd07a2e4a2820eb2cbc94d8e731ecf51b395755a3b3747b2a932581b9df9

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb70
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.39215
MD5 cc26fc49586c3af12c2c901184cf7bc3
SHA1 a549810df261ba254e502194f767b2d48f33e064
SHA256 4d01dc3a888e62344289fe42965eb747e1c6790a50bb6bf8d6ca692582e128c3
SHA3 0c127927b2121aa49b4bfd0fddaf983a7d274c36307aa6c18204bbe24e6afdaa

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x147
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.39435
MD5 029b9105e39c1f39805e361577dd794d
SHA1 d5bd8dff00ca74afe7816080d386fd98035bd55a
SHA256 23406afc23700bef0bac0e9c6aeeacc80961128d0d1978dde67540fd7cb448e6
SHA3 67bb2b6a610a9715d084ee36246325ee7a9dc490baef8048c1ef7d0b140f75b0

TNEWDISKFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x480
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.53036
MD5 cd6fe7256253935c36120f997ddb2b70
SHA1 f07f7ba148e69421f2f4a9b3401b1b133f290bda
SHA256 ab29a97f5fc3001f63e5176beed6699932d904c3b3bd07c61c61e4d4fd9d48a0
SHA3 5c01d6d6198b7289f0c912ec013fc5c842d01242082f099bd00868d37fe2b299

TSELECTFOLDERFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49474
MD5 d7e117405612c053028101915644f4b4
SHA1 ef6108d09dc73384134b82da7b5f76b95170fb5c
SHA256 6ffcd80f9a3c0fb1f9bd69559c135420a79f9e15caa74cab557dee8a89768e75
SHA3 e877a8b16c76687f0537e4f4b4d2326ce1f4ebb67c952488a2cce4163cc13fc6

TSELECTLANGUAGEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4b5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49456
MD5 be6079d41e21e7457e8ed6bfbc0167af
SHA1 ff13169b8f1b29d56429e44c55525d56869494f1
SHA256 f8790d64397a78267ff7d49cf2cb8a4ab1b79df7a030b2c3da96c898064a1a1e
SHA3 853651bbce894b07a4dbd62cbacdda79c45ef0883be41f4590761d5f508c2483

TUNINSTALLPROGRESSFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x7e3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51979
MD5 f7a5f4b87af861d5c60b2898854c9953
SHA1 715d394ee42606a2a5ddbb10aaa38e38d6bf12b5
SHA256 9eb4161fbe46020d1a0b2095585a7494a49d0968654e9e8418c92062e908f61c
SHA3 1ddf8ed94114b9750d5b952b60e3f45e46aab91c8855b30bf644361129921b28

TUNINSTSHAREDFILEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x55c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.48903
MD5 8906bfbc73188bd25f8906c08a08f03e
SHA1 c2984f995f3fd17060b8bca2d0f1e15c3e16b351
SHA256 6dcad927676c61747c2df03d6ba7878d6ce2040e4e0dc88d27f55e9905c8cd77
SHA3 73449e4dc3639e57ec83b59f0d7bf22cb0b1de7b75ed85a2940cd8457d38d109

TWIZARDFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ac9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.50583
MD5 854596016dd31807e541bb2d53a8da65
SHA1 646c65ffc3558e6182a8fd03fcdb925cd797d8b4
SHA256 0949b9d51c1dcd8c45992afda3e937b3c2db300ea67a0838036eaba86390d232
SHA3 9e1d20c2ec48fda6458cd0a60e191dc3bf93c90782334efabbe1f9f5c08aaf69

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87162
Detected Filetype Icon file
MD5 5e93c0cb46ded3490512ebae2b273cb3
SHA1 f55a2358eb555ba1819668de02df218a0ef56268
SHA256 2619ed9d2a2ab58ac845c32a30688cd73321aa112ad5783ed601a8952ff48141
SHA3 0e3eb229a2b4b05bd5d2a67796ca3a444d979585f38c3bfc508024dbb01c3011

Z_DIRICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59109
Detected Filetype Icon file
MD5 46d643f46cdfcc61ce12fb98ddbde450
SHA1 ea6353ecc7e2d4324bf1ae1571acbbe780d3ad73
SHA256 f8dd253cdfbdbbe80276826653a5aab7b8b9161e4727ce102a4053500999a414
SHA3 caae2fc04f005dc5805d3022582a187963572f256855fd7baa5326d7034cc3fe

Z_DISKICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56354
Detected Filetype Icon file
MD5 2f28415af73aed21e3ee3a0999745c18
SHA1 4de4fb68bee456189562ed3ef2bf1b64430a113f
SHA256 22d1da5d73b234bd2c440a4e8e21a6c7d1ee38852b9ff11b42e17006c4512018
SHA3 94ad221c451135c6ad9ec138f6a27cbafec9074f2f52ecd8fd680b30c5360a6e

Z_GROUPICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63275
Detected Filetype Icon file
MD5 ffed49eacf713db3265830d742c985a8
SHA1 ba4e88561038381c2a28bb53c77154ee03585fc8
SHA256 462b3d8563ee3a3f4bd6968d8ad372fae01e60ef08daaffae170d871add3d232
SHA3 c421b04fadd2cdac10913ce976e2b14b73c17e9a1c8559b35e19be37d8bdbc17

Z_STOPICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.55963
Detected Filetype Icon file
MD5 4af18dc1bbc7c186e8c4a9d9ac324b70
SHA1 fe0833f71cf3491d029c7998a6f5aa699db254be
SHA256 dae5fdfddb19dd44a5d7bd299d64a202512fdbc88da7cbdbae4f4734da4f9bf8
SHA3 8662b58a86a7e995c9f7b7ea1955610a57896517eb1177a4a65bc4dcf9fb0ddd

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x514
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67962
MD5 1f8bffe5be9e84eb3d19b871594b9924
SHA1 c25cdfc0fd9bbf3e7400ff6d739aea2c5e680d40
SHA256 523d0ab556b39198c125666b7822b3e3f4e1c5cccbbc3388a0dcaf54039bd35f
SHA3 ac506305e1d11ed7ab182d70e3803cf97b3ba36077a4a2e4a78507b259a3add1

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x765
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1883
MD5 b600174b76059d432a205957f9e6dd87
SHA1 0ab8d8ece213974bc7ad3036b42c3ac416ffd111
SHA256 70f1422a4c288192971ccca7861b8a2045a7a5e5eaf7dda57c243e844c939258
SHA3 adb6d450ea12501fc9e910a7810465df13de5a7094653e34fb18e6578fb089b5

String Table contents

Error sending data: (%d) %s
Error receiving data: (%d) %s
Error connecting to server: %s
Error opening request: (%d) %s
Error adding header: (%d) %s
Error removing header: (%d) %s
Error reading data: (%d) %s
Error setting timeout for the request: (%d) %s
Credential without user and password
Platform-dependant function not implemented
Scheme-dependant function not implemented
Method already assigned
URL already assigned
Invalid URL: "%s"
Maximum number of redirections (%d) exceeded
Error getting Server Certificate
Server Certificate Invalid or not present
Server Certificate not accepted
Empty certificate list
Unspecified certificate from client
Client rejected the certificate
Execution of request terminated with unknown error
Error querying headers: (%d) %s
Error obtaining session handle
Could not call proc
Out of Record Fields Range
Null Pointer Exception
Null variant error
Out Of Memory
Interface not supported
Unknown error
Invalid array
Out of string range
Cannot cast an interface
Cannot cast an object
Capacity < Length
Nil interface
Unknown method
Expected return address at stack base
Scheme "%s" already registered for %s
Cannot Import %s
Invalid Type
Internal error
Invalid Header
Invalid Opcode
Invalid Opcode Parameter
no Main Proc
Out of Global Vars range
Out of Proc Range
Out Of Range
Out Of Stack Range
Type Mismatch
Unexpected End Of File
Version error
divide by Zero
Math error
Caption cannot be empty
Style '%s' already registered
Class '%s' is already registered for '%s'
Class '%s' is not registered for '%s'
%s parameter cannot be nil
Feature not supported by this style
Cannot call BeginInvoke on a control with no parent or window handle
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Invalid float
Unknown Identifier
Exception: %s
[Invalid]
No Error
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Length of value array must be >= length of prompt array
Prompt array must not be empty
&Username
&Password
&Domain
Login
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
Cannot remove shell notification icon
%s requires Windows Vista or later
Button%d
RadioButton%d
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
Unable to insert a line
Clipboard does not support Icons
Text exceeds memo capacity
Menu '%s' is already being used by another form
Docked control must have a name
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
. Path:
%s
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
%s property out of range
SHA2: Cannot update a finalized hash
Error decoding URL style (%%XX) encoded string at position %d
Invalid URL encoded character (%s) at position %d
Cannot start a task that has already completed
One or more errors occurred
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Bitmap image is not valid
Icon image is not valid
Invalid pixel format
Scan line index out of range
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Text format flag '%s' not supported
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8
Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Observer is not available
Invalid date string: %s
Invalid time string: %s
Invalid time Offset string: %s
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Source and Destination arrays must not be the same
Invalid Timeout value: %s
SpinCount out of range. Must be between 0 and %d
Timespan too long
Value cannot be NaN
No context-sensitive help installed
No help found for context %d
Unable to open Index
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Argument out of range
Unbalanced stack or queue operation
Item not found
Duplicates not allowed
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Parameter %s cannot be nil
Parameter %s cannot be a negative value
Invalid characters in path
The given "%s" local time is invalid (situated within the missing period prior to DST).
No help viewer that supports filters
Invalid argument
Index out of range (%d). Must be >= 0 and < %d
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to get data for '%s'
Resource %s not found
%s.Seek not implemented
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Operation Cancelled
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
'%s' is not a valid integer value
'%s' is not a valid integer value for %s type
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 51.1052.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription Setup/Uninstall
FileVersion (#2) 51.1052.0.0
Comments This installation was built with Inno Setup.
CompanyName By DFT PRO inc
LegalCopyright
OriginalFileName
ProductName DFTPRO
ProductVersion (#2) 3.4.4
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x6de000
EndAddressOfRawData 0x6de04c
AddressOfIndex 0x6c6c24
AddressOfCallbacks 0x6df010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->