2cd6dc080a634beb490163f76199a013

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2020-Nov-06 09:07:43
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts d:\dbs\el\jan\target\x86\ship\click2run\en-us\SetupBootstrapper.pdb
CompanyName Microsoft Corporation
FileDescription Microsoft Office
FileVersion 16.0.12527.21330
InternalName Bootstrapper.exe
LegalTrademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2 Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename Bootstrapper.exe
ProductName Microsoft Office
ProductVersion 16.0.12527.21330

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Contains references to security software:
  • rshell.exe
Accesses the WMI:
  • ROOT\CIMV2
References the BITS service
Contains domain names:
  • .corp.microsoft.com
  • 0020.a-msedge.net
  • Cstatic.officecdn.microsoft.com
  • Dmicrosoft.sharepoint.com
  • PPC-powerpoint.officeapps.live.com
  • a-0020.a-msedge.net
  • a-msedge.net
  • adobe.com
  • akamaiedge.net
  • api.diagnostics.office.com
  • autodiscover-s.outlook.com
  • autodiscover.microsoft.com
  • config.edge.skype.net
  • contentstorage.osi.office.net
  • corp.microsoft.com
  • d.docs.live.net
  • data.microsoft.com
  • delve.office.com
  • diagnostics.office.com
  • docs.live.net
  • dscd.akamaiedge.net
  • e1723.dscd.akamaiedge.net
  • ecs.office.com
  • edge.skype.net
  • edog.officeapps.live.com
  • events.data.microsoft.com
  • go.microsoft.com
  • http://127.0.0.1
  • http://a-0020.a-msedge.net
  • http://a-0020.a-msedge.net/pr
  • http://e1723.dscd.akamaiedge.net
  • http://e1723.dscd.akamaiedge.net/pr
  • http://ns.adobe.com
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://officecdn.microsoft.com
  • http://officecdn.microsoft.com/db
  • http://officecdn.microsoft.com/pr
  • http://officecdn.microsoft.com/pr/0002c1ba-b76b-4af9-b1ee-ae2ad587371f
  • http://officecdn.microsoft.com/pr/39168d7e-077b-48e7-872c-b232c3e72675
  • http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60
  • http://officecdn.microsoft.com/pr/5440fd1f-7ecb-4221-8110-145efaa6372f
  • http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6
  • http://officecdn.microsoft.com/pr/64256afe-f5d9-4f86-8936-8840a6a4f5be
  • http://officecdn.microsoft.com/pr/7ffbc6bf-bc32-4f92-8982-f9dd17fd3114
  • http://officecdn.microsoft.com/pr/b8f9b850-328d-4355-9145-c59439a0c4cf
  • http://officecdn.microsoft.com/pr/f2e724c1-748f-4b47-8fb8-8e0d210e9208
  • http://officecdn.microsoft.com/sg
  • http://purl.org
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • http://www.w3.org/2000/09/xmldsig#
  • https://config.edge.skype.net
  • https://config.edge.skype.net/config/v2/Office
  • https://ecs.office.com
  • https://ecs.office.com/config/v2/Office
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?LinkId
  • https://mrodevicemgr.edog.officeapps.live.com
  • https://mrodevicemgr.edog.officeapps.live.com/mrodevicemgrsvc/api
  • https://mrodevicemgr.officeapps.live.com
  • https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api
  • https://msdn.microsoft.com
  • https://msdn.microsoft.com/en-us/library/windows/desktop/ms753129
  • https://nexus.officeapps.live.com
  • https://nexusrules.officeapps.live.com
  • https://officeredir.microsoft.com
  • https://officeredir.microsoft.com/r/rlidOfficeWebHelp?p1
  • https://support.microsoft.com
  • https://support.microsoft.com/kb/2739501
  • loki.delve.office.com
  • messaging.office.com
  • microsoft-my.sharepoint-df.com
  • microsoft-my.sharepoint.com
  • microsoft.com
  • mrodevicemgr.edog.officeapps.live.com
  • mrodevicemgr.officeapps.live.com
  • msdn.microsoft.com
  • msedge.net
  • my.sharepoint-df.com
  • my.sharepoint.com
  • nexus.officeapps.live.com
  • nexusrules.officeapps.live.com
  • nleditor.osi.office.net
  • ns.adobe.com
  • ocws.officeapps.live.com
  • odc.officeapps.live.com
  • office.com
  • office.net
  • office365.com
  • officeapps.live.com
  • officecdn.microsoft.com
  • officeredir.microsoft.com
  • ols.officeapps.live.com
  • osi.office.net
  • outlook.com
  • outlook.office365.com
  • powerpoint.officeapps.live.com
  • roaming.officeapps.live.com
  • s.outlook.com
  • self.events.data.microsoft.com
  • sharepoint-df.com
  • sharepoint.com
  • skype.net
  • storage.live.com
  • substrate.office.com
  • support.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegDeleteValueA
  • RegEnumValueA
  • RegSetValueExW
  • RegCreateKeyExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegQueryValueExW
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegEnumValueW
  • RegDeleteKeyW
  • RegGetValueW
  • RegDeleteValueW
  • RegNotifyChangeKeyValue
Possibly launches other programs:
  • CreateProcessW
Uses Microsoft's cryptographic API:
  • CryptAcquireContextW
  • CryptCreateHash
  • CryptHashData
  • CryptGetHashParam
  • CryptDestroyHash
  • CryptReleaseContext
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualProtectEx
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • FreeAddrInfoW
  • WSAStartup
  • GetAddrInfoW
Functions related to the privilege level:
  • OpenProcessToken
  • CheckTokenMembership
Interacts with services:
  • QueryServiceConfigW
  • QueryServiceStatusEx
  • OpenServiceW
  • OpenSCManagerW
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010
Safe VirusTotal score: 0/68 (Scanned on 2021-06-28 19:42:12) All the AVs think this file is safe.

Hashes

MD5 2cd6dc080a634beb490163f76199a013
SHA1 db4eb17b689ae7811c6e0b41bd73df83984682b3
SHA256 e6b5c8362f7ebcad6a5efef3772bfd4802ee6c34a617bbb8d2870b082fee3423
SHA3 811c6aba8f3dd0aed8ec167fb902ff95532e1616f515540c7258dd2db4811c4c
SSDeep 98304:QvCGznRkKoRSO0CBR/C8Wrrx88/DjyiI3qfYwY2h6E52:QvVnRwJDdvWrrfjPIRW6Ec
Imports Hash dddfef3c09fc10f189be88fe23b46958

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x138

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2020-Nov-06 09:07:43
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x2c1400
SizeOfInitializedData 0x246a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002465DF (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2c4000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x50b000
SizeOfHeaders 0x400
Checksum 0x511bb2
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 eaf075839bdd639cdd43069a0d8a2b7a
SHA1 3ffb1d203d1f37d92fd51c33c161517b789c8e5d
SHA256 b9c0c9da2e72c617a3d116f83d47c801107d7d000fbdc95783ad6da7ba7b01f4
SHA3 f0e3924a02f496707886af6b6a41404501353aa9eb4a3f98bd1d96ddda3bae29
VirtualSize 0x2c12e8
VirtualAddress 0x1000
SizeOfRawData 0x2c1400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.67284

.rdata

MD5 16693fd27d3090a1708a330f02ef7733
SHA1 dc7d8cafb40b613db172a05606cab4c8a81a30d7
SHA256 28a744342f1ede204cd030dff1eabc0b64a365b322367893c4b9e3154b4ba484
SHA3 b1c6224adb1f762eed444c27a9cfca80cb31e41942d653a0403055639ce59310
VirtualSize 0x14a8d2
VirtualAddress 0x2c3000
SizeOfRawData 0x14aa00
PointerToRawData 0x2c1800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.727

.data

MD5 6a3bd330dcd128648ad0727a1e09bab2
SHA1 2a742dd005a1c135233cceafe359b786377cd01b
SHA256 4b8d7196f4b7de4e0bbee4d348a9f27492c0a2d522de48da93ad643811d9b488
SHA3 0611c50de99eb5be0b2719c66f42d17fc815a236e59209f807e091ed6015fbe8
VirtualSize 0x221ec
VirtualAddress 0x40e000
SizeOfRawData 0x21c00
PointerToRawData 0x40c200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.65849

.rsrc

MD5 578e1a3c8b7bec9cb12e8757e7a3144e
SHA1 6e8bc6ca3426d758ee09a91fd1010635f9ff3c22
SHA256 afce24678f286ffa8ae774ddf2fdd7e8ee1396e8bce3ca7324110ae66a4e3fc9
SHA3 bef3920c7838aa49fb1e9fdbe5f48a32ac867b7390003421d6362a383d0f7769
VirtualSize 0x94f40
VirtualAddress 0x431000
SizeOfRawData 0x95000
PointerToRawData 0x42de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.47933

.reloc

MD5 bc51de0423367dfc8d7cade8e7fdfa60
SHA1 6128b961927238b1fd0eab5bb86f78ca31c5e577
SHA256 ff6c6e484e1326256086e793bb3bba0024f0ac9540ce57d9cf905ca9ce6dcab6
SHA3 5e220bfaa9d850b72899bfa16c8c3d94d6902782ccbda3b53d944761e6b717de
VirtualSize 0x44dd0
VirtualAddress 0x4c6000
SizeOfRawData 0x44e00
PointerToRawData 0x4c2e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.47576

Imports

GDI32.dll CreateSolidBrush
SetDCBrushColor
GetTextExtentPoint32W
Rectangle
SetDCPenColor
CreatePen
GetTextMetricsW
SelectObject
CreateFontW
GetStockObject
SetBkColor
SetTextColor
DeleteObject
GetDeviceCaps
OLEAUT32.dll VariantInit
VariantClear
SysFreeString
SysAllocString
ADVAPI32.dll QueryServiceConfigW
QueryServiceStatusEx
OpenServiceW
CloseServiceHandle
OpenSCManagerW
RegDeleteValueA
RegEnumValueA
ConvertSidToStringSidW
OpenProcessToken
GetTokenInformation
RegSetValueExW
RegCreateKeyExW
RegOpenKeyExW
RegCloseKey
CryptAcquireContextW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
EventWriteTransfer
EventRegister
EventUnregister
RegQueryValueExW
RegEnumKeyExW
RegQueryInfoKeyW
RegEnumValueW
RegDeleteTreeW
RegDeleteKeyW
RegGetValueW
RegDeleteValueW
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
RegNotifyChangeKeyValue
RevertToSelf
EventWrite
OpenThreadToken
GetLengthSid
CopySid
InitializeAcl
AddAccessAllowedAce
AllocateAndInitializeSid
FreeSid
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
GetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidA
CheckTokenMembership
CreateWellKnownSid
EqualSid
ImpersonateLoggedOnUser
KERNEL32.dll GetStdHandle
CloseHandle
GetLastError
GetModuleHandleA
GetModuleHandleW
GetProcAddress
LoadLibraryW
SetLastError
GetModuleFileNameW
OutputDebugStringA
CompareStringEx
LocalFree
HeapFree
GetProcessHeap
GetCurrentProcess
GetCurrentProcessId
CreateThread
GetCurrentThreadId
GetExitCodeThread
InitializeCriticalSectionEx
DeleteCriticalSection
MultiByteToWideChar
FindFirstFileExW
FindClose
IsWow64Process
ExpandEnvironmentStringsW
CreateMutexW
GlobalFree
RaiseException
DecodePointer
GetCommandLineW
GlobalMemoryStatusEx
GetNativeSystemInfo
VerSetConditionMask
VerifyVersionInfoW
GetUserDefaultLocaleName
FlsFree
FlsAlloc
LocaleNameToLCID
UnmapViewOfFile
CreateFileMappingA
MapViewOfFile
Sleep
GetStringTypeExW
GetUserDefaultLCID
LoadLibraryA
LCMapStringW
FreeLibrary
GetSystemTimeAsFileTime
TlsAlloc
TlsFree
FlsGetValue
TlsGetValue
FlsSetValue
TlsSetValue
GetTickCount64
GetModuleHandleExW
K32GetProcessMemoryInfo
LeaveCriticalSection
EnterCriticalSection
WideCharToMultiByte
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
GetProcessTimes
TerminateProcess
GetModuleFileNameA
GetShortPathNameA
K32GetModuleFileNameExW
CreateProcessW
LoadLibraryExW
FindResourceW
SizeofResource
LoadResource
OpenProcess
GetStringTypeW
GetVersionExW
IsValidCodePage
GetSystemTime
SystemTimeToFileTime
FileTimeToSystemTime
GetCPInfoExW
GetDiskFreeSpaceExW
CreateFileW
DeviceIoControl
SetErrorMode
GetComputerNameW
MulDiv
FormatMessageW
GetLogicalProcessorInformation
GetSystemDirectoryW
HeapAlloc
CreateEventW
SetEvent
ExitProcess
WaitForMultipleObjectsEx
CreateEventExW
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableSRW
CloseThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CreateThreadpoolTimer
CloseThreadpoolWait
SetThreadpoolWait
WaitForThreadpoolWaitCallbacks
CreateThreadpoolWait
CreateThreadpoolWork
SubmitThreadpoolWork
ReleaseSemaphore
WaitForSingleObjectEx
QueryDepthSList
TryEnterCriticalSection
InitializeSListHead
InterlockedPushEntrySList
InterlockedPopEntrySList
RtlCaptureStackBackTrace
ReleaseMutex
TzSpecificLocalTimeToSystemTime
GetTempPathW
GetLongPathNameW
ResetEvent
QueryPerformanceCounter
QueryPerformanceFrequency
VirtualProtectEx
GetSystemInfo
GlobalAlloc
ReadFile
WriteFile
GetFileSizeEx
LockResource
SetEndOfFile
SetFilePointerEx
GetOverlappedResult
FlushFileBuffers
CancelIoEx
GetFileAttributesExW
DeleteFileW
CreateDirectoryW
SetFileAttributesW
RemoveDirectoryW
GetDriveTypeW
FindNextFileW
GetFileType
CopyFileW
MoveFileExW
GetTempFileNameW
SetFileInformationByHandle
GetFileInformationByHandleEx
SignalObjectAndWait
GetProcessAffinityMask
GetLogicalProcessorInformationEx
CreateWaitableTimerW
SetWaitableTimerEx
CancelWaitableTimer
GetTickCount
WerRegisterMemoryBlock
WerUnregisterMemoryBlock
QueryFullProcessImageNameW
IsProcessorFeaturePresent
CreateIoCompletionPort
PostQueuedCompletionStatus
GetThreadIOPendingFlag
GetCurrentThread
GetQueuedCompletionStatus
IsDebuggerPresent
WaitForMultipleObjects
GetStartupInfoW
CreateMemoryResourceNotification
GetSystemPowerStatus
IsSystemResumeAutomatic
QueryUnbiasedInterruptTime
OutputDebugStringW
VirtualFree
VirtualAlloc
OpenEventA
CreateEventA
OpenMutexA
CreateMutexA
OpenSemaphoreA
CreateSemaphoreA
OpenFileMappingA
LocalAlloc
GetThreadLocale
FindFirstFileW
lstrcmpW
GetFullPathNameW
ProcessIdToSessionId
SetEnvironmentVariableW
GetPriorityClass
GetExitCodeProcess
GetTimeZoneInformation
IsValidLocale
GetLocaleInfoEx
LCIDToLocaleName
GetLocaleInfoW
ResolveLocaleName
GetUserPreferredUILanguages
GetACP
LCMapStringEx
GetSystemDefaultLCID
EnumSystemLocalesEx
GetSystemDefaultLocaleName
GetUserGeoID
GetPhysicallyInstalledSystemMemory
GetProductInfo
SwitchToThread
GetConsoleCP
ReadConsoleW
GetConsoleMode
UnregisterWaitEx
VirtualProtect
FreeLibraryAndExitThread
GetThreadTimes
UnregisterWait
RegisterWaitForSingleObject
SetThreadAffinityMask
GetNumaHighestNodeNumber
ChangeTimerQueueTimer
GetThreadPriority
SetThreadPriority
CreateTimerQueue
InterlockedFlushSList
RtlUnwind
SetUnhandledExceptionFilter
UnhandledExceptionFilter
CompareStringW
GetCPInfo
InitializeCriticalSectionAndSpinCount
EncodePointer
DuplicateHandle
AreFileApisANSI
GetFileInformationByHandle
OpenThread
GetDateFormatW
GetTimeFormatW
DeleteTimerQueueTimer
CreateTimerQueueTimer
HeapReAlloc
EnumSystemLocalesW
SetStdHandle
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
WriteConsoleW
VirtualQuery
LoadLibraryExA
HeapSize
WaitForSingleObject
GetLocalTime
ole32.dll IIDFromString
CoTaskMemFree
StringFromCLSID
CoCreateInstance
CoSetProxyBlanket
CoCreateFreeThreadedMarshaler
StringFromGUID2
CoCreateGuid
CoInitializeSecurity
CoInitializeEx
CoUninitialize
CoTaskMemAlloc
CreateStreamOnHGlobal
CoRegisterInitializeSpy
CoRevokeInitializeSpy
CoCancelCall
CLSIDFromString
CoEnableCallCancellation
CoDisableCallCancellation
WINTRUST.dll WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData
WinVerifyTrust
SETUPAPI.dll SetupIterateCabinetW
WS2_32.dll FreeAddrInfoW
WSAStartup
GetAddrInfoW
gdiplus.dll GdipFillRectangleI
GdipCreateSolidFill
GdipGetImageGraphicsContext
GdipDeleteBrush
GdipCloneBrush
GdipCreateFromHDC
GdipGetImageWidth
GdipDeleteGraphics
GdipDrawImageRectRectI
GdiplusStartup
GdipDrawImageRectI
GdipFree
GdipDisposeImage
GdipAlloc
GdipCloneImage
GdipLoadImageFromStream
GdipCreateBitmapFromScan0
GdipGetImageHeight
RPCRT4.dll RpcStringFreeW
UuidToStringW
api-ms-win-core-winrt-string-l1-1-0.dll (delay-loaded) WindowsConcatString
WindowsCreateStringReference
WindowsGetStringRawBuffer
WindowsCreateString
WindowsDuplicateString
WindowsCompareStringOrdinal
WindowsDeleteString

Delayed Imports

Attributes 0x1
Name api-ms-win-core-winrt-string-l1-1-0.dll
ModuleHandle 0x422b08
DelayImportAddressTable 0x40e000
DelayImportNameTable 0x40a60c
BoundDelayImportTable 0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

ID_ANIMATEDLOGO

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x10041
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9646
Detected Filetype PNG graphic file
MD5 9d38627b453eea649aa16ddd7585b10c
SHA1 c4050350503722b2cee639524ad590eac25a49b3
SHA256 d565f5c0e5c1930759b9c340ae4a81ff1f216cdd72b7e0bb8a21b094012d8d0b
SHA3 9848e387a0a4ba7fbb0f3d86a77fa9ad962ea48ce62e2d8d436289309dc65890

ID_ANIMATEDLOGO_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x43e89
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99108
Detected Filetype PNG graphic file
MD5 84e2d38d3e5459921b8d18f9ed45ea77
SHA1 37ccc45dcedd849621669a1e81be3fc9dff9d983
SHA256 4bbef2ac9a4bc075b529b5eabf75928cea7ccf9cb178798a2afc379326edb7cd
SHA3 b184f6d9cc86ccd157f093b1bca8d97bb629e7f263c154bd900ada02efef3c33

ID_CLOSE

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xb1c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86982
Detected Filetype PNG graphic file
MD5 8a3a524d50d27342c2015f24c93eaede
SHA1 365e22497e357711340503dbefd1fb957c33e799
SHA256 cb8eef1aba4ccc718a120ba9d75021e29e30bb163c6991c512367cb4cbc2b7e7
SHA3 3a151703e1992d2d9e485da8c3ab9f4f4d59dd70c6da6bd191a29b23219a39d1

ID_CLOSE_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x401
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.17947
Detected Filetype PNG graphic file
MD5 981bc942f3a81146f9788ab21d260e1c
SHA1 af9cc3cd4085e2ad3bf5d217e0970fbdbe8ddd36
SHA256 07eac3dbb58c1d516cf86711586bdfe2d456a7081894880c92c989002ed254c3
SHA3 fb3b974895d03f819846e961ace6a92df33bf9fdad55509318c238bec7ed7340

ID_CLOSE_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.5187
Detected Filetype PNG graphic file
MD5 4024c548dc417ae6656ef019e1b2c57a
SHA1 5c2961bb227c77599022f9d62ce2f15c33ab6584
SHA256 05b9db2e7edd2dc2948d46cf87ff87354fd89031fc5472f1b3eb7c0861d14f87
SHA3 e990f2dd098155516a32ebc7b08da1aa310f3f92122e6c0538eb7147f37fe031

ID_CLOSE_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x795
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9285
Detected Filetype PNG graphic file
MD5 05c14bc2743fb16a8ebd20e9cf71fb22
SHA1 21191ac866d2df5d5a463c1fec6d90794f8a101c
SHA256 ac2290ea665d1ead4beebe738b3e9024c486a9e2d2d2dd7096626634365d8bdb
SHA3 e0082d4ba124241eeafed4ccb55f28af04cc3346d87a5f5a75b5bda253127c39

ID_CLOSE_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x87
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.75409
Detected Filetype PNG graphic file
MD5 b5d243a7ec81c69a7c10cec54a848358
SHA1 7837ff88e95765efa20d774e431254405c796fdd
SHA256 bd10d32df763e96fcea137b6076c7a4a70b4673f81cb6d258b1a3238a98f2a92
SHA3 877f0f02a6be4cab2d1299ea9e05e8fd226ee98ec86f38b589c0b135b5c2f2eb

ID_CLOSE_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x691
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.83285
Detected Filetype PNG graphic file
MD5 672a5f2db9bee1039d3fabbe6c30d051
SHA1 46bd71071a38d266938dafbff449b80cabc45859
SHA256 01f96dd81eae1498c3fac84d9215c2500cee2575fbd19674241acf668774dcda
SHA3 d80febdc48fcfae7c232ea9964b5ce6a338a7485aaee6e0bc0e1dbc822883484

ID_ERROR

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1f9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.18472
Detected Filetype PNG graphic file
MD5 f1d5fcc645a8e50f8a862fb012da45bf
SHA1 634a4f604b9c0e212805c03fa7f95dad1c80c116
SHA256 85b1ad1092503f19ae1f2f0cf76b40aa41b600a11d2c5f7bb71b8c832d0dbb51
SHA3 44d531b0fd83d07400f07927007d1f2428ce81a4780bc6b727f4bffabfb26b5e

ID_ERROR_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x34d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62896
Detected Filetype PNG graphic file
MD5 4f98bf250e9d690efbef11b8cf890d19
SHA1 a2e07f1922a8319527a923b6f269d39178acdcb4
SHA256 31205d4537fbf75212cd54a12776036587a69357e9927c1f73de2511b49b3c3e
SHA3 4c57217a4ea08ecb426731fb0f7cfff06d2c9aa11142594442b85497d0a112a6

ID_LOADINGDOTS

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ece
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.81657
Detected Filetype PNG graphic file
MD5 60389491858d9a3ac90bf48332065751
SHA1 8372c5481bf23362241045f019f4d01f2cacaf83
SHA256 3a9098cc54a61e1a0f06447b152774d9d882cd3c1b8022631f4fa95644038eae
SHA3 6bf15885bc86f8a5d03aa28db3e73a7c09f04f0c148e5bf39c4bd0e1cac110fa

ID_LOADINGDOTS_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x9293
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8088
Detected Filetype PNG graphic file
MD5 23249c1902e80757eaa02db8acf175b8
SHA1 a8c9f7d1efdef0e264b82a81e94dcd28a1f5f434
SHA256 8572468da49aa3c7cd2a93d0dc6d8517dd1149394da76c6128203c5d140ce786
SHA3 99e3c2ca54cbf4f59cb6100ea28c53d2a2a1aaf7952984b5f101da8828875916

ID_LOADINGDOTS_RTL

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x4078
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.82801
Detected Filetype PNG graphic file
MD5 29d51ec1d604be3633f4c850363cba95
SHA1 763e88c2f1539e4a92a88108b7f10a253b62d9dc
SHA256 749bc3fa158f6b9f451adb0469708270d7242faa799cd98b50f70edef1d84662
SHA3 c27efe4310bde57dda30ab6c531b0128ef816a94aac7f2baa1a58413e72c2a31

ID_LOADINGDOTS_RTL_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x9255
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8081
Detected Filetype PNG graphic file
MD5 6846b898d8e859dc6fc33f1d8f50237d
SHA1 ea6b9ba0f54eba82b3fc398c176338bef7698742
SHA256 0dea6867e0fbd22f33964c2c0452be01d7db3039f8090686eb0161cade6a6b09
SHA3 1e808fdcd14c39a25f6b474cafaa2b51eb9ba8908935dde982f7c057d1283e73

ID_LOGO

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1055
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.47575
Detected Filetype PNG graphic file
MD5 6867b640edd0bb840727b6eaa2608912
SHA1 45754e06971a91d55b514179c6f612a6687ff56f
SHA256 1ce452224e003f95125aa406869df69f5d1696165a11ab3bf824470f98783525
SHA3 e455a04e415d2495126f1f42ba0ab662b3583fd443265005e4be4e3034c2f980

ID_LOGO_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2739
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85484
Detected Filetype PNG graphic file
MD5 e160d97445fbd281b861f5c3eba29829
SHA1 1fb155d86c626e1713676fb510f05deb40298684
SHA256 9f6d19bad29dc5945212e1f80d63c60bd16aa9dfc4587093b8ed34f8c1bbcc8b
SHA3 ea99d55bddcb8a55347ee3cd3fe043cc9a919f59ec66b439e18f14387e8c9980

ID_LOGO_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x15a7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.37074
Detected Filetype PNG graphic file
MD5 2430288bdbe8f624f20d4d8a76ea1494
SHA1 ed19753c6081045f62a6a036bb5af63ceee9c68d
SHA256 0ad7bbbb5b858893d9e3070dd733faa02bc702f8864f73621c80f4d5e6a3a11d
SHA3 4899836c647b8afc7b40ae0c1c5ff49c4440a28a72d310ea04967cff960e4af0

ID_LOGO_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1dad
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.80161
Detected Filetype PNG graphic file
MD5 81681c4d18f99726811c7057265cb749
SHA1 078f2b76bd85250cfe0c8b2753e54bc79c5bb550
SHA256 a96ea845b6a925cc792a841f0e377be1dbd1bfc44e073377e4d276e5b1dc314d
SHA3 94f3f4b72f9dcf5fcdb6f70187be100c46e64bfe24e6fdecb7535e118237e993

ID_LOGO_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x96d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.48455
Detected Filetype PNG graphic file
MD5 ec0bc36c11a9a27bfc735db908e7d3ca
SHA1 9f40bc2e6d7a90bca0743bafbcfbbf24ada35bb3
SHA256 72c91312db973d014ed69a093611bbad25f03b2bdf7a1f3e7cd319db6d2fef6e
SHA3 6b1ce782077af61965b21eee4cafd57f6c168cecd414ac970397d634058d3bfd

ID_LOGO_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe7f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.44296
Detected Filetype PNG graphic file
MD5 52b4766097df7d9bd55d21edd2b0fc42
SHA1 6a350bd8011658588c6dbc8df502ac7840136121
SHA256 b7d8e6fec5643bd440bed4491f5c93a638487b34565c541a754ed90d60875196
SHA3 1c12fbe08384f0924a683f4368789207a791f7172def41169ff7038e2003d64f

ID_MINIMIZE

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xafc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8627
Detected Filetype PNG graphic file
MD5 f7c36dcaa397714db9893819a27d71d4
SHA1 c336109f20e453dfe19864f60117762753ed5d25
SHA256 e553f843d67d4ed4f2f89a5d3eed2ca0e75c27f0a7e515b4010a749fc69f8c59
SHA3 384ec1b4e98c324940a679298ef5b2a2b6997db5d1fbdf28853751c1399c3e00

ID_MINIMIZE_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.88536
Detected Filetype PNG graphic file
MD5 448a9e62e5bc9e442c5911eda9f24280
SHA1 7d76380b21f480215f1cd614561cd8a93be5ca51
SHA256 efdbaa1686975466e8cfff8532d0dce7ba9e5c74c736c325b717c40608a4e33d
SHA3 ae8b77e622b510f040825b4655d6467b4246066401ab614c5b00abb0b494fb9d

ID_MINIMIZE_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x752
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.77166
Detected Filetype PNG graphic file
MD5 25707af4c81f3cf1332f076291247a11
SHA1 18354db798d0fa0355271b1a7fc443b8ca0ea9bc
SHA256 a6d9e0c48f94cd52edac8500ebeca8960fcfa1a11c7e2fd3e537383fc57e8eb2
SHA3 8e2af294c925dc153716112aab546e8aa8e8053b518c4d87deaecd4ee5960d19

ID_MINIMIZE_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x757
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.78077
Detected Filetype PNG graphic file
MD5 9fbe7a2dbb1194ba88d77a9ec31d15b6
SHA1 b747471b33531b85d1be642a413b4e49fe8b1a81
SHA256 8ec83498aa799ec33bc5b6da83ce6b1e394b383b5d8289bb98b137a374d71afc
SHA3 ac087624860fba6dccb70b558172a892c8c59747ebb2fc96a1deb9080c3d70af

ID_MINIMIZE_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x675
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74918
Detected Filetype PNG graphic file
MD5 5c893fc0b39d10926e9fa04857f500af
SHA1 35b70117ba019e7a7720924a41dc0b1efcf8aa01
SHA256 de25d14b3719c1a706b647b7d24600572cd3cd238eb3e499c3e5a42e28a32400
SHA3 bb2f9f75b827c268dcf8bbd71b919f950b40eb2ba6707a720655b08af2121b48

ID_MINIMIZE_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x674
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74395
Detected Filetype PNG graphic file
MD5 579d08f1a225b89fd234a46de57885dc
SHA1 6e99af737190961e4ecc099b5a85ea4d31d429d5
SHA256 5ba5fcc7a89c3c2f519f364592a36c5fbf5309c89147d94dfa3b8b00897d17f6
SHA3 e5c0e18006a512609c40a8486492e38b0ee54f2b35c4f4fed510bde9f8176d7d

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.59532
MD5 7a4680e656a97a5629ddc0b9e833dcec
SHA1 e64c4fa2223fb1467f4788b070057208c7026e8d
SHA256 bc9a5e5323aa6671bd013ad69c3690458e5adb30b66eb42f9718b53f624281bc
SHA3 61ea07484c092db449f62a355d51f34c70cf153f9a540da90c2bd344b3466840

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.96082
MD5 adf967685fb02ec8139dad33cce79e13
SHA1 705685853bec5aa1dc677ded956619f6e819e1ec
SHA256 f4de764e0c25d509171cb6881129b0b38fbbc84e774a90108342f4ea55c0cf17
SHA3 f26a54701a41c2d920d32071d7943de833ea2d52a182e8748a3d75364beb8e07

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.20562
MD5 f03b1f73c59d6398864e2c7d4f9ed9cd
SHA1 7a437c011f94bec2154d7f359c78ab8e86c18403
SHA256 713831e4b06a6788b4b858e9799a1c84064cfe77ad38669d430e1fc20bf4a379
SHA3 5aecc613ae5e5c84bc90cdd4ee6361f092fd9f44c0a4ab018ce28700dc7858c6

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87138
MD5 3e88ed00604b1774eaeb59a6d3d2362f
SHA1 a357a7c0091da48964f5c44cb3d2bff9844bd3b1
SHA256 a881c2d07c959476d513e9d519b8aff6bad067d96fff6549e6e16c5b669fbb3e
SHA3 8f54c9857584733edf18deaf37340b3a0f49d5b200b46ee2fba91a690a05a2c7

188

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.7745
MD5 0391de71a4784d04578522dc6731d97f
SHA1 c32c295d13e4ddec1d40d0c06aa1a1b11c0f70bb
SHA256 da41172119065bb8cc9f992bfeac65dbdd104b99c416aeee3707dcb745a9fec4
SHA3 eeefb993d6688de9738e21b6d8b46c38edd9a6e5f5137d0f654c821597bec714

376

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x7e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21432
MD5 55813f16063fd41aab4ac80a0baf866b
SHA1 83ebf88c51450fc7444da11d0c0f152fba11a4e7
SHA256 adb7c9fc08826aa17010ea21c8cef088f86263940cfbd1af4d86f178440d910b
SHA3 ab0734f7495ae9d272fbb334749f6833061b7945dd6d7da77c8a59b25bfddf9e

377

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x980
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2276
MD5 62fda6be58093077851cc8fd01d59113
SHA1 119357bcbae8fde4a77e35c6a1b9faff409187c6
SHA256 6c9758203a71490a827690c1e0e8b940afb1af39f618bbb85a176ae039d18b05
SHA3 e821eddd7e4eaa2b6ba2361da6700be3c964754b4d660b21b6a9a4ee3981c01c

378

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x880
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24318
MD5 772300c2f284f990eb6047e10f5d2904
SHA1 4823e71f88df600a2bb7eb52f8144fef6530207c
SHA256 baaab2fe3d665df1ac0870fffe76bc63d671b31aa7699cc90f00a401c8c30daa
SHA3 aa6ee0af992783702ef79a0c2d74074977fd6848bd5033c45210f7903e31857e

379

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27442
MD5 6e9371d52645f4947dca307bf46823c6
SHA1 46eaf7ae8ea13922a4ea959571b2ad82ee02ea4b
SHA256 1ab9c0c4ff5b15f1c522d703d8be5896acc48c32dd1bd53c4480b056cfefcd45
SHA3 b6c0d2d038d5cd82191a25b2a4edd780512c54434c76a9c962dba1882c1adbf1

380

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x492
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36591
MD5 30ba0c8d42397467ff6ae1bc92282c38
SHA1 dab64bb9a2803f691f270a75d6b144d9fe1dd236
SHA256 862e507dedd49cde302fa60acc7d13a146e63d50e2c273794cbf04e0a7bcb5f6
SHA3 f60e4c7e37947cfcdf89908e34bdf239936c2183c3c49d46276a1a024f8af2ed

381

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa3c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37884
MD5 3ad9a0ae7ed9e2b87cc28dce58d9c9ae
SHA1 ce4a1d18fd0495ec68835ed0303fc470a6b5c95d
SHA256 b4e2b150f17612e0a68c9674304ab8a3bc9c7a3f03e7d0f50adae4f6e3115b9c
SHA3 9afe2191e1730de453f32abb76ad4891100e2a2e210b0195e67f33c2d58af1d4

382

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4fe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36431
MD5 ee79aa73a53ca552e64aebb5bfa7b434
SHA1 949d17b059c6993fd01a680f478ab2c91e1c5f29
SHA256 74353cf33abe7823aa841d32c1c5d47d15e9a4b3613fe56cc6aa1ba455151eed
SHA3 018c76cb90dc8533d3129bc00dda6e4e47eb5f2027c14690a9a1971c0ac70487

383

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xb14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38772
MD5 8e3f279b6c9c611422615c061fedaeaa
SHA1 c7639af240725afdd08381994fb9378846672018
SHA256 5005211e6e86c8e34f36c96704dd3d90ef755aa5b8bfd0a0b71a553a893d9cfc
SHA3 b303261dbb76c6e86696927bb81c4ef79587de7d4e5f401a396b5365b8eefb73

384

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15703
MD5 980f091a52e526dbde5e484ba9edf61d
SHA1 b7b380121b3d9c0b817ec88ea0031f2ede0b042b
SHA256 c10fcbdb7ff577a64d028b3a0614b8ff1000e28b2d0a93c0b01942dee36bab99
SHA3 53c4a815a1e284e338942add40dbcff6c71aef372b115afc0e6840dbd92a7c44

IDI_SHELL

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65982
Detected Filetype Icon file
MD5 6fa39a5f6db3ad3489ae7c80de34d0af
SHA1 461e0c84813d6c2f9e33b08cb928a69d5f3e97cf
SHA256 d58d7d4bbc58f023d4bb203dd967e15f6681460612b02ad935e7ff3979dc6102
SHA3 5b2e3150d50439424a0da2167805f6606a0d1cabed9ce800c5e259a72a21d091

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x420
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37348
MD5 9564e3c8b5dc8270ed8b77e59f4a7f85
SHA1 5eac65056e1fdf191911fa02445e21d3e7e8a6d1
SHA256 15570213ed9c4e9d8f91beaf34556bb51738da29dc3508f159e079f304fe40f9
SHA3 1ac2d28ddec5843c01a4f78b63f4f7f0c267788af575f21268f22df463a832cd

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x711
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33138
MD5 bc38fa7cc614038de0ca3b13773ef25a
SHA1 b6e08510d5f87d1e8bf7006aeaa970c11991313e
SHA256 0e89f24f5de4d9159a2380aa5df2520270a1e0bc4023a274329e772f8c5650f0
SHA3 9ce6c6b2369416662b87bd348ab54e6054cd966e0825bcd798ee8ce8c471d068

String Table contents

_scenario_roaming_culture_en-us_lcid_1033_platform_x86_productreleaseid_none_
Continuing could be expensive
You're connected to a network that limits downloads every month.
We need to stream some large files over your network connection to install Office, so we recommend installing while connected to an unrestricted network.
If you are sure you won't be charged or exceed your limits by dowloading a large amount, you can choose Continue to download and install. Otherwise, you should Close and install when connected to a different network.
Administrative Privileges Required
Installation requires administrative privileges to make changes to your computer.
Please retry installing this product and give the required permission when prompted.
If you cannot give these permissions to install, ask your system administrator to help you.
Couldn't install
We're sorry, we had a problem installing your Office program(s).
Is your internet connection working? Do you have enough free space on your main hard drive?
Please try installing again after you've checked the above.
Office needs a newer version of Windows
We're sorry, we couldn't install your Office product because you don't have a modern Windows operating system.
You need Microsoft Windows 7 (or newer) to install this product.
Couldn't Install Office
We're sorry, Office couldn't be installed.
Please save the file you used to start this installation to a place you can find easily. Then use Windows Explorer to view that location and try installing Office again.
We found a problem!
We found a pre-release or Beta version of an Office product on your computer and can't install because of it.
Please Uninstall any pre-release Office software using the Programs and Features item in your Control Panel and try installing again.
We're sorry, but we can't verify the signature of files required to install your Office product.
We need to verify these signatures to keep your computer safe.
Please retry installing your product or, if installation continues to fail, try re-downloading your installer if you got it online. Make sure you only download Office products from a trusted source.
We found a problem!
We're sorry, Office does not work with Windows 8 Consumer Preview.
You need the full version of Windows 8.
We're sorry, Office (64-bit) couldn't be installed because you have these 32-bit Office programs installed on your computer:
%s
64-bit and 32-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 32-bit version of Office instead, or uninstall your other 32-bit Office programs and try this installation again.
We're sorry, Office (32-bit) couldn't be installed because you have these 64-bit Office programs installed on your computer:
%s
32-bit and 64-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 64-bit version of Office instead, or uninstall your other 64-bit Office programs and try this installation again.
We're sorry, we can't continue because we weren't able to download a required file. Please make sure you're connected to the internet or connect to a different network, then try again.
Please free up some disk space
We're sorry, we couldn't start installing Office because available disk space is too low.
Couldn't start Office installation
We're sorry, but we could not successfully start your Office installation. Please try again later.
Setup Failed
A newer version of Setup is required to install this product
We're sorry, but we could not start your Office installation. Another installation is in progress. Please try again later.
&Close
%s
<a href="%s">Go online for additional help.</a>
Invalid product %s specified.
Error configuring products!
We're getting things ready
We need to remove some older products
Some older products don’t work with Office 2016. Before installing the new Office, we need to remove:
%s
Important: Once we’ve removed these products, you won’t be able to install the old version again.
Remove and Continue
&Cancel
Couldn't Install Office
We are sorry, but we could not complete the installation.
We hit an issue trying to uninstall your previous Office version.
<a href="%s">Go online for additional help.</a>
https://support.microsoft.com/kb/2739501
Save your work before continuing
We need to close the following apps:
C&ontinue
&Cancel
Couldn't Install Office
We're sorry, Office (64-bit) couldn't be installed because your computer does not support 64-bit applications. Please try installing the 32-bit version of Office instead.
We're sorry, we had a problem installing your Office program(s).
Please make sure the Office installation disk is inserted. Do you have enough free space on your main hard drive?
Please try installing again after you've checked the above.
We found a problem!
We're sorry, Office Click-to-Run installer encountered a problem because you have these Windows Installer based Office programs installed on your computer:
%s
Click-to-Run and Windows Installer editions of Office programs don't get along for this version, so you can only have one type installed at a time. Please try installing the Windows Installer edition of Office instead, or uninstall your other Windows Installer based Office programs and try this installation again.
Microsoft Office
%s
<a href="%s">Go online for additional help.</a>
Error Code: %s
Client update needed.
We are sorry, but we could not complete the installation. Please try again later.
https://go.microsoft.com/fwlink/?LinkId=613501
<a href="%s">Learn more</a>
This installation requires a compatible Microsoft Office program installed on your computer.
Stop, you should wait to install Office 2016
You won't be able to receive mail from a current mailbox.
%s You may want to contact your mailbox provider or system administrator about this issue.
<a href="%s">Learn why</a>
Business Contact Manager will no longer work.
%s
<a href="%s">Learn why</a>
You won't be able to receive mail from a current mailbox. Business Contact Manager won't work.
%s You may want to contact your mailbox provider about these issues.
<a href="%s">Learn why</a>
Outlook 2016 is not compatible with Exchange 2007.
Outlook 2016 requires access to the AutoDiscover service for your Exchange service.
Business Contact Manager is not compatible with Outlook 2016.
&Install 32-bit
&Install 64-bit
This installation is for the 64-bit version of Office, but the following 32-bit Office applications are already installed on this computer:
%s
Want to install 32-bit Office, which will work with your 32-bit applications? Select "Install 32-bit". If you want the 64-bit version, select "Cancel", uninstall your 32-bit Office applications, and start this 64-bit installation again.
This installation is for the 32-bit version of Office, but the following 64-bit Office applications are already installed on this computer:
%s
Want to install 64-bit Office, which will work with your 64-bit applications? Select "Install 64-bit". If you want the 32-bit version, select "Cancel", uninstall your 64-bit Office applications, and start this 32-bit installation again.
Sorry, 64-bit and 32-bit Office can’t be installed together
%s
<a href="%s">Help: Installing 64-bit or 32-bit.</a>
Please Wait
Office is already being installed.
For install status, check the Office notification in the Windows taskbar.
We can't install
The following product(s) can’t be installed at the same time:
%s
We can't install
To install this product, first uninstall the following product(s) and try again.
%s
You need Windows 10 to continue
This Office product requires Windows 10. Please upgrade Windows and try installing Office again.
%s
<a href="%s">Help: Upgrading Windows</a>
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 16.0.12527.21330
ProductVersion 16.0.12527.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Microsoft Corporation
FileDescription Microsoft Office
FileVersion (#2) 16.0.12527.21330
InternalName Bootstrapper.exe
LegalTrademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2 Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename Bootstrapper.exe
ProductName Microsoft Office
ProductVersion (#2) 16.0.12527.21330
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-Nov-06 09:07:43
Version 0.0
SizeofData 280
AddressOfRawData 0x2c21cc
PointerToRawData 0x2c15cc
Referenced File d:\dbs\el\jan\target\x86\ship\click2run\en-us\SetupBootstrapper.pdb

IMAGE_DEBUG_TYPE_RESERVED

Characteristics 0
TimeDateStamp 2020-Nov-06 09:07:43
Version 576.27412
SizeofData 4
AddressOfRawData 0x2c22e4
PointerToRawData 0x2c16e4

TLS Callbacks

StartAddressOfRawData 0x7c63b0
EndAddressOfRawData 0x7c6478
AddressOfIndex 0x823288
AddressOfCallbacks 0x6c3e54
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00647235
0x006472B3

Load Configuration

Size 0xa0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x80e2cc
SEHandlerTable 0x7c2fb4
SEHandlerCount 3276

RICH Header

XOR Key 0x3d674ee6
Unmarked objects 0
ASM objects (26715) 24
C++ objects (26715) 196
ASM objects (VS 2015/2017 runtime 26706) 25
C objects (VS 2015/2017 runtime 26706) 39
C objects (41204) 7
ASM objects (41204) 2
263 (26715) 2
C objects (26715) 37
Imports (26715) 25
262 (26715) 5
Total imports 766
C++ objects (VS 2015/2017 runtime 26706) 132
C++ objects (VS2017 v15.9.16-18 compiler 27034) 148
265 (VS2017 v15.9.16-18 compiler 27034) 1277
Resource objects (VS2017 v15.9.16-18 compiler 27034) 1
151 1
Linker (VS2017 v15.9.16-18 compiler 27034) 1

Errors

<-- -->