2c1277bc87735109a5e4ef340cc81be1

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jul-10 19:09:32
Detected languages English - United States
Russian - Russia

Plugin Output

Suspicious PEiD Signature: UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX v2.0 -> Markus, Laszlo & Reiser (h)
UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX -> www.upx.sourceforge.net
UPX Protector v1.0x (2)
UPX V2.00-V2.90 -> Markus Oberhumer & Laszlo Molnar & John Reiser
UPX 2.00-3.0X -> Markus Oberhumer & Laszlo Molnar & John Reiser
Suspicious The PE is packed with UPX Unusual section name found: UPX0
Section UPX0 is both writable and executable.
Unusual section name found: UPX1
Section UPX1 is both writable and executable.
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegFlushKey
Possibly launches other programs:
  • ShellExecuteW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 2c1277bc87735109a5e4ef340cc81be1
SHA1 60c02e5928ced0d4f1cc0b7569fec69cf11597a2
SHA256 79aeb6904a71ef7201364321ef7f42ffd37ffbb6b8d904b6441001e64c57b9e5
SHA3 1a28d8842997901446a3bdaf9471c2f894c27aafa17b8eb955a67b068c8a7f53
SSDeep 6144:JBhHmiOQQdUJe+0kdRujnTaT9WTv+cqHmqYtMrzbYLqT4L:JfHSpdJewjWHrYg4mT4
Imports Hash 83eceaca031d4cfad850d3c83a2f5ed1

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2018-Jul-10 19:09:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x3b000
SizeOfInitializedData 0xd000
SizeOfUninitializedData 0x6e000
AddressOfEntryPoint 0x000A97F0 (Section: UPX1)
BaseOfCode 0x6f000
BaseOfData 0xaa000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xb7000
SizeOfHeaders 0x1000
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

UPX0

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x6e000
VirtualAddress 0x1000
SizeOfRawData 0
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

UPX1

MD5 9447af99b7a7b1f08609a19bfb2737fe
SHA1 f4c7ed763f8a8ebbc597570944239ce2c1133a07
SHA256 27d160b77745012d61358908048d42d599afce77ce57ef77f32c06476b9c3792
SHA3 433a84179e58ea45ebbf55e6eb042f0047a4053386359af946c9f967482c03eb
VirtualSize 0x3b000
VirtualAddress 0x6f000
SizeOfRawData 0x3aa00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.92486

.rsrc

MD5 d0e8ec823b6b300d55dea92e04df80f9
SHA1 5a43ea08d17ca30e22554abc1b9431f05c2cdbef
SHA256 6a9da2a5f0a246e4678480c155dbbdf7a9f8de4b2d4b9b4b2b3dea1066e8f045
SHA3 08eced4002d37a0c876092b4470a831d04e5c74b6b905c63d2c545e9ebca8ef5
VirtualSize 0xd000
VirtualAddress 0xaa000
SizeOfRawData 0xd000
PointerToRawData 0x3ae00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.90048

Imports

KERNEL32.DLL LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
advapi32.dll RegFlushKey
comctl32.dll ImageList_Add
comdlg32.dll GetOpenFileNameA
gdi32.dll SaveDC
mpr.dll WNetOpenEnumA
ole32.dll CoTaskMemFree
oleaut32.dll VariantCopy
shell32.dll ShellExecuteW
user32.dll GetDC
version.dll VerQueryValueA

Delayed Imports

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x1d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

1 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41379
MD5 415a0d6b306cd7a9172ac93c70e185cc
SHA1 6fe1a5b8a5c2c160837df3c7ad3b41879aa6d67b
SHA256 c37e276d8ec69edf754098250e4b9b96917c6aa0d02312eab8a1849b76a39181
SHA3 16972fe22bbce1d86cbec4c5dfda6a719db139bc17606e79e9e3c226e4bda4b3

2 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.62878
MD5 79340bd3bd5b689b44f9e73b3de47322
SHA1 7c89083e1930f67e30c6b1c9cb54e179d2094759
SHA256 c838dc1c657c358133b8e6cf3ab70869f0c58d807281135836a1718845bcb549
SHA3 61d2900c2d07bfd36e7b0ce04261a151108daa3a7364c6d08ad19baa5712523c

3 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.69216
MD5 46bfbb46981667a0fd72e5e7b22445af
SHA1 cffb13126184c3def53669d62fbe17bc977746ca
SHA256 6f4b7d5df0b21731c475eb3771ab24fbcdb6f3d0654e0dd56d28efe8c023072a
SHA3 f9e9ce0a5c97067e394b1db7a0ce02606de18d3b91a98c0aa23f5106b28e83df

4 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23467
MD5 d356130991b3675d2ffd3f6d9a668c50
SHA1 127f5d14a221e98d3a5b5a781f11209194850a2d
SHA256 60acdedda68848fe962876e4c86c50e45fc0bfc5f1109e832bcf2642fe6bcad0
SHA3 ece81499d3f298996735e11c07d4466dc64a968bec55c68e6f34345976399e5e

5 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.99492
MD5 779650dbb87b97429c3526148076713a
SHA1 648980ece9bbb241b92e9d93aa319e687b538ce1
SHA256 87bd20aed05eb2b364a9399dac33bfb8828d2cea19db67583fc05b5b5874b331
SHA3 7ded283fbfe4017c427a847862b823c1e0aedb30dc09a9bd1d89e76891cb49c2

6 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.66251
MD5 1758fc1e854a666b7d1c1f3a1104106f
SHA1 a674ec9379522e430cf39bf60914a3fbf3caefe1
SHA256 0620e28c0f1a7e318cacda88e5920fbb7adae781f9a7254de336730585a41d14
SHA3 8cdb03fddf3d8113c1cf6713dbfc7e83baf8e864f04b088c1507d7cabcf8f586

7 (#2)

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.00899
MD5 05acb00d68d397dee41e24554ed94937
SHA1 47463ee81085e0701b83573facbc0799a7b67a35
SHA256 625c0ccda3b8b022dc4a3fd8c2b28d2b9a3242b318565344d0cce489f5efd7ea
SHA3 da885ae4247333a1a8d1f67d1e6ef1877b8ec84cee686f6712a1e9568d47743b

8

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.48229
MD5 a364ed497197e5394bfcc903a23e3f51
SHA1 b15ad7de876bf0b83c9e87e8b15b962d95bff4e1
SHA256 e380878ddb4cdac46c6b2d70636106a6b8bfb6eb66fce883789ffdb91a5b0734
SHA3 2a3218ccf6e124d84e555c1ca1ee66b68c56a5c145b269f5ae3d8203721e6f13

9

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.24671
MD5 b100ae3ca932ada49839770a305fbf51
SHA1 9357664281776f84f3089c437c92f5cced7f6c4f
SHA256 96db209f4d0be0dd9b6fd8ab533c3eae5d5f2dfc5ed64850809ef95498a36f14
SHA3 607d58b384fd9ed02118f7c7e47b9f9866c58bc5b5875bff8dd4d289734a9d29

10

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.62628
MD5 0cc3d77a3060fed902ca716abd4f0be0
SHA1 5343da3140c098551913a7f36fe725d8a86745f8
SHA256 981b591b7c49633f195296494c17cc463233673180ee2bc74483fc5e2ff5d14e
SHA3 d6e0bf45309d6c52e6f900bdb909496b14c0c1ed38073ff967001cd76274593d

11

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.88444
MD5 356df15d7810e72ffe9cb391e0c073f3
SHA1 a3e420aca5d8056806e9239ca756333d6586920d
SHA256 ca248c78de86fd53c73dd6c4ae04ffe795f3e97c470d8259a64b40b1267af3fa
SHA3 df42f5fd091988569e8955690313124741837f4708fe4bf0a2dfc748ecf235fc

12

Type RT_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92641
MD5 e78d3bc94246df96486a28191a90b3c0
SHA1 eef8c41021a438ba289750e7eb25fb6b1041f1f6
SHA256 33fa965e5118081dcb30cd8e40c741d5740b6e5529f5e6417b331f6692cc734d
SHA3 69a1acfd52469c35298debde4c231526e3a7d3826b64e37fdfb55fe4030c1c46

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x52
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

TEXTFILEDLG

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x52
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.61605
MD5 ac5eefd684bd75f9ded1d0e368f566da
SHA1 33dd756799618130fd3c1097be1638f47ada0f90
SHA256 26be3f5d9e8788884e3d857861b2666da59e7e80dfaa6e7e52832428980204fc
SHA3 bb30afb20c2bc5d31729c46212a31568a47a85da5d4bed5e936bee775915da30

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88808
MD5 cede19abc2133be645edf233663f08e3
SHA1 bc0b6cfc86ecbaaf40bd82f5401cd274015a24b0
SHA256 66bce5bf011accb6bba8df8a2e24c74157519acb74ed44f0f9e6fb2c4a2219ff
SHA3 2806eab89b7b8212db3102d45fee68dd6c36670f47d53d2cd76081978d30550f

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x384
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41938
MD5 6e51ef013e649c89d429a22a9dbbaef1
SHA1 c006efcf5d488bea67c2152aaf002f0630c5353d
SHA256 18f023ca72b91d9141f342e0a32879c2be09e70534c24475286c3e21f8f97d04
SHA3 a49100e4149c886124344928f0c403165549ed87c571d4c4be51a1f9d0e930de

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.4177
MD5 45bcbf6ea5b52aeb28d3ffb7689c8c2b
SHA1 69ebfe30bba38952cbfe9bcdff55040dfa4fcd44
SHA256 1c01171aff3d3f6ac787048b7e27125a92438141baae300f6f74738a6e5c8cb7
SHA3 f1329802782c4d8576544dfb1e3b64ee2a7fb753811399de8cfa45731e17a27a

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46332
MD5 c626504b61470105c37f2eb714852416
SHA1 909611050b2c835ed480b12b16652584cf59077f
SHA256 c7e93652bf50229b89e363c92b6668d0c6547e6f539ad5352393cebb0a15d69a
SHA3 14ff6ff345cd29610ce9a072a590574b1de6edd5ee688d70c9182ff874013284

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41741
MD5 e7c89d121d545f81412ed24f4fa9bdc8
SHA1 67a908d7164e64f664267f0499eff833862758d6
SHA256 690d40c14621ca430796ac86f75122bcc98ec1938610eee12f2a476a65feb70a
SHA3 9d13dbc9b98c094a29e2f9695b69f0c4faffc4cea6c7c2a1d78c61bddfa52472

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31405
MD5 7d44f62f730a84e4e1caa7d82999357e
SHA1 3e10d193560bbad7e866cc02d2a3f39f49df6c67
SHA256 ffd9b056960ea522c3f93d0a883c880b646cc6012dc6153f896d3a06a01671e8
SHA3 6281241f35c0667ae86500ec48c55b251ee58918071adc78a733da21dc1c2a25

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x394
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26174
MD5 0856ed5a7c5fcc2caa3f73a9abf9d400
SHA1 1af57d999c778392e331280c3544c4c165b0bed1
SHA256 3b1f89d98d3ef7ab26a63745130ad46c5773496cf6f47ceab77cc291e47b9cd8
SHA3 c9dfc434567d645fe502d1618c8f026f43042bacf0abeeab83b3b21addc0c221

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x388
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28765
MD5 02f031e23a1037c1688a1d2c6407c2ff
SHA1 ec38a983a58f0118a3d196fb02ea1f17fbeac7a8
SHA256 d6bcdff73ced352f6a37135ba149af7160dd8f3a01efa92505af4b7a3c5377dd
SHA3 cc78e910656adc75e30f1e457198920c6f70a46cf60d05f6094c98da0a373d68

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3f0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34898
MD5 66547609d18b7d3b7e3331d7f5e837d3
SHA1 37d14aab80286483a519c1c58b7e1d5b42755085
SHA256 dc60627c4638683ea9b0874a7fd61373112398bc637687aa42b97ba1b14c04ef
SHA3 e4be11083714b2952a28f65023e6bd2b99403cbdf23d794756eb106e11d641ce

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x190
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30363
MD5 b0c0bcd09e259310ec1414303f8085f8
SHA1 26c3ebe479bf7d292d429ab3126f99d9d296f199
SHA256 367dfc77d6f740d954f9073067dc8c668d29c64af6cc3dc003f66781c907764b
SHA3 f201a218bf6fa7f52067bd8f7463034586ad6774ccba8c4336372b178e686423

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34698
MD5 f5b81c80af9a8173b32a363e721d0a86
SHA1 16ecf114b40ec23eb00c82f28e408ddbcf701fda
SHA256 07a699dfba3b6f2e997c6ee78a0e0e1dad18c948aff0f1767b28f5ee6e41fdc3
SHA3 9516ca5c26bf77d713578d01233ea75c2e697d877a6a220e0c60fd179f8885e1

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41282
MD5 75e63954a131c97042c0f133de0c5432
SHA1 d18b56cc5ad95316b65392dc277ebb53a3ff25ae
SHA256 d14cf3dfe03eb5e1d1dea9dae8c3716c41107979ddf121a7be2560f39c5385f3
SHA3 3c67db998d05dab318ad7b90ce7a5451e0e051613335f6061707bbb7be46847e

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24976
MD5 2c93cb43901306d692f408a6c05c5781
SHA1 6332a68da8548c21570647294ed18666f5591f84
SHA256 6b96d88f3182ca0a51213c6378b452178c3d17ab9eb99516f862f306a1efe878
SHA3 5397683f4647bd87f84bfc3a6798b2dffa7c3025720f22d372558d1940da2150

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x320
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36348
MD5 72a98934bad9a77bb506253ca96a377c
SHA1 c29a58fb7ea7a4697e93505480c41ea312336d01
SHA256 190ded281b8e85f67de35d162aaf032712b956ce4e30184c870749e11309a7c5
SHA3 22d8ea6cc04819d1535b2b9334692ce915998e424df8677cd1e90d3d98f42e70

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32228
MD5 cf91e6edbe1f30f41f42d1e1d9df228c
SHA1 392f1b2b7b5e2deded4f6c529241d4ffa9f2c4dc
SHA256 407743f3bfd7bdf398a523a3c844fb0857f6564fdd87e718b45765624e4ae688
SHA3 81435931740ab143fb57f26c98c5304c22ae51a7988e029f99d3a39015c6677e

CONFIG

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.71074
MD5 ac57ab2a2aae8670aafe846e66980bf5
SHA1 c38e1da9e64b0da48013ab92d6d6fa3acddf631a
SHA256 271859f80805adf66cf10c8c387edf64715c5fc214874bb077df18c940c332cf
SHA3 37ef4cf55fa3d0aaa207ae7bd68cc96c16e474b26032a7df74c7b3af92a84438

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x314
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.31732
MD5 4ed9d6b2c756b909b7c6e8743d83fe44
SHA1 b1b338669e4244bafaf1b61537cd1921a719dd69
SHA256 d9e05286128189887478371d4241aec0a1318b01f89c6a4d17a0369d86504cb3
SHA3 9a54cad3b2f6443bae678698a34d25e3276a6217cf7ea5796678d510d86dc41b

TFORM_DECRYPTER

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5b3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.51353
MD5 1d926e40870c67f47a6a267cde1ece67
SHA1 03a6e27a5777900d52480b713553f9c93122fbea
SHA256 610bb0df5f86e572d529e8be0ee0f0a1c30ae8cf68189d552d576feaa3f2f89e
SHA3 cb6858bf374df4d3fc904fdc33b627e29b9ee79d5fe955a10702e211fc6d71dd

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language Russian - Russia
Codepage Latin 1 / Western European
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90461
Detected Filetype Icon file
MD5 8adaa49b9b44e71762214079b5f90ae1
SHA1 45d640fc3d91a433489bcc23e174f2619bee5bf5
SHA256 e7774e604717e54fb0d4cc353b6f43eecf1ed2c98e00417e5ee3af2854741f02
SHA3 62ed443f34ee1d766d76d0b86302e5932744f11be6f9b6c68aa1dfb15f2737e5

String Table contents

JPEG error #%d
JPEG Image File
Invalid buffer size for decryption
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
ANSI
ASCII
Unicode
Big Endian Unicode
UTF-8
UTF-7
%s requires Windows Vista or later
Cannot change the size of a JPEG image
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Unable to insert a line
Clipboard does not support Icons
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Tab
Esc
Enter
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
OK
Cancel
No topic-based help system installed
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Invalid pixel format
Scan line index out of range
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to get data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No help found for context
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
'%s' is not a valid integer value
'%s' is not a valid GUID value
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero

Version Info

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: Could not reach the TLS callback table. [*] Warning: Section UPX0 has a size of 0!