Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Nov-06 09:07:43 |
Detected languages |
English - United States
|
TLS Callbacks | 2 callback(s) detected. |
Debug artifacts |
d:\dbs\el\jan\target\x86\ship\click2run\en-us\SetupBootstrapper.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Office |
FileVersion | 16.0.12527.21330 |
InternalName | Bootstrapper.exe |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | Bootstrapper.exe |
ProductName | Microsoft Office |
ProductVersion | 16.0.12527.21330 |
Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
Contains domain names:
|
Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to MD5 Uses constants related to SHA1 Microsoft's Cryptography API |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010 |
Safe | VirusTotal score: 0/68 (Scanned on 2021-06-28 19:42:12) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x138 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 5 |
TimeDateStamp | 2020-Nov-06 09:07:43 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
|
Magic | PE32 |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x2c1400 |
SizeOfInitializedData | 0x246a00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x002465DF (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x2c4000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x50b000 |
SizeOfHeaders | 0x400 |
Checksum | 0x511bb2 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
GDI32.dll |
CreateSolidBrush
SetDCBrushColor GetTextExtentPoint32W Rectangle SetDCPenColor CreatePen GetTextMetricsW SelectObject CreateFontW GetStockObject SetBkColor SetTextColor DeleteObject GetDeviceCaps |
---|---|
OLEAUT32.dll |
VariantInit
VariantClear SysFreeString SysAllocString |
ADVAPI32.dll |
QueryServiceConfigW
QueryServiceStatusEx OpenServiceW CloseServiceHandle OpenSCManagerW RegDeleteValueA RegEnumValueA ConvertSidToStringSidW OpenProcessToken GetTokenInformation RegSetValueExW RegCreateKeyExW RegOpenKeyExW RegCloseKey CryptAcquireContextW CryptCreateHash CryptHashData CryptGetHashParam CryptDestroyHash CryptReleaseContext EventWriteTransfer EventRegister EventUnregister RegQueryValueExW RegEnumKeyExW RegQueryInfoKeyW RegEnumValueW RegDeleteTreeW RegDeleteKeyW RegGetValueW RegDeleteValueW IsValidSid GetSidSubAuthorityCount GetSidSubAuthority RegNotifyChangeKeyValue RevertToSelf EventWrite OpenThreadToken GetLengthSid CopySid InitializeAcl AddAccessAllowedAce AllocateAndInitializeSid FreeSid InitializeSecurityDescriptor SetSecurityDescriptorDacl GetSecurityDescriptorDacl ConvertStringSecurityDescriptorToSecurityDescriptorW ConvertSidToStringSidA CheckTokenMembership CreateWellKnownSid EqualSid ImpersonateLoggedOnUser |
KERNEL32.dll |
GetStdHandle
CloseHandle GetLastError GetModuleHandleA GetModuleHandleW GetProcAddress LoadLibraryW SetLastError GetModuleFileNameW OutputDebugStringA CompareStringEx LocalFree HeapFree GetProcessHeap GetCurrentProcess GetCurrentProcessId CreateThread GetCurrentThreadId GetExitCodeThread InitializeCriticalSectionEx DeleteCriticalSection MultiByteToWideChar FindFirstFileExW FindClose IsWow64Process ExpandEnvironmentStringsW CreateMutexW GlobalFree RaiseException DecodePointer GetCommandLineW GlobalMemoryStatusEx GetNativeSystemInfo VerSetConditionMask VerifyVersionInfoW GetUserDefaultLocaleName FlsFree FlsAlloc LocaleNameToLCID UnmapViewOfFile CreateFileMappingA MapViewOfFile Sleep GetStringTypeExW GetUserDefaultLCID LoadLibraryA LCMapStringW FreeLibrary GetSystemTimeAsFileTime TlsAlloc TlsFree FlsGetValue TlsGetValue FlsSetValue TlsSetValue GetTickCount64 GetModuleHandleExW K32GetProcessMemoryInfo LeaveCriticalSection EnterCriticalSection WideCharToMultiByte InitializeSRWLock ReleaseSRWLockShared AcquireSRWLockShared ReleaseSRWLockExclusive AcquireSRWLockExclusive GetProcessTimes TerminateProcess GetModuleFileNameA GetShortPathNameA K32GetModuleFileNameExW CreateProcessW LoadLibraryExW FindResourceW SizeofResource LoadResource OpenProcess GetStringTypeW GetVersionExW IsValidCodePage GetSystemTime SystemTimeToFileTime FileTimeToSystemTime GetCPInfoExW GetDiskFreeSpaceExW CreateFileW DeviceIoControl SetErrorMode GetComputerNameW MulDiv FormatMessageW GetLogicalProcessorInformation GetSystemDirectoryW HeapAlloc CreateEventW SetEvent ExitProcess WaitForMultipleObjectsEx CreateEventExW WakeConditionVariable WakeAllConditionVariable SleepConditionVariableSRW CloseThreadpoolTimer SetThreadpoolTimer WaitForThreadpoolTimerCallbacks CreateThreadpoolTimer CloseThreadpoolWait SetThreadpoolWait WaitForThreadpoolWaitCallbacks CreateThreadpoolWait CreateThreadpoolWork SubmitThreadpoolWork ReleaseSemaphore WaitForSingleObjectEx QueryDepthSList TryEnterCriticalSection InitializeSListHead InterlockedPushEntrySList InterlockedPopEntrySList RtlCaptureStackBackTrace ReleaseMutex TzSpecificLocalTimeToSystemTime GetTempPathW GetLongPathNameW ResetEvent QueryPerformanceCounter QueryPerformanceFrequency VirtualProtectEx GetSystemInfo GlobalAlloc ReadFile WriteFile GetFileSizeEx LockResource SetEndOfFile SetFilePointerEx GetOverlappedResult FlushFileBuffers CancelIoEx GetFileAttributesExW DeleteFileW CreateDirectoryW SetFileAttributesW RemoveDirectoryW GetDriveTypeW FindNextFileW GetFileType CopyFileW MoveFileExW GetTempFileNameW SetFileInformationByHandle GetFileInformationByHandleEx SignalObjectAndWait GetProcessAffinityMask GetLogicalProcessorInformationEx CreateWaitableTimerW SetWaitableTimerEx CancelWaitableTimer GetTickCount WerRegisterMemoryBlock WerUnregisterMemoryBlock QueryFullProcessImageNameW IsProcessorFeaturePresent CreateIoCompletionPort PostQueuedCompletionStatus GetThreadIOPendingFlag GetCurrentThread GetQueuedCompletionStatus IsDebuggerPresent WaitForMultipleObjects GetStartupInfoW CreateMemoryResourceNotification GetSystemPowerStatus IsSystemResumeAutomatic QueryUnbiasedInterruptTime OutputDebugStringW VirtualFree VirtualAlloc OpenEventA CreateEventA OpenMutexA CreateMutexA OpenSemaphoreA CreateSemaphoreA OpenFileMappingA LocalAlloc GetThreadLocale FindFirstFileW lstrcmpW GetFullPathNameW ProcessIdToSessionId SetEnvironmentVariableW GetPriorityClass GetExitCodeProcess GetTimeZoneInformation IsValidLocale GetLocaleInfoEx LCIDToLocaleName GetLocaleInfoW ResolveLocaleName GetUserPreferredUILanguages GetACP LCMapStringEx GetSystemDefaultLCID EnumSystemLocalesEx GetSystemDefaultLocaleName GetUserGeoID GetPhysicallyInstalledSystemMemory GetProductInfo SwitchToThread GetConsoleCP ReadConsoleW GetConsoleMode UnregisterWaitEx VirtualProtect FreeLibraryAndExitThread GetThreadTimes UnregisterWait RegisterWaitForSingleObject SetThreadAffinityMask GetNumaHighestNodeNumber ChangeTimerQueueTimer GetThreadPriority SetThreadPriority CreateTimerQueue InterlockedFlushSList RtlUnwind SetUnhandledExceptionFilter UnhandledExceptionFilter CompareStringW GetCPInfo InitializeCriticalSectionAndSpinCount EncodePointer DuplicateHandle AreFileApisANSI GetFileInformationByHandle OpenThread GetDateFormatW GetTimeFormatW DeleteTimerQueueTimer CreateTimerQueueTimer HeapReAlloc EnumSystemLocalesW SetStdHandle GetOEMCP GetCommandLineA GetEnvironmentStringsW FreeEnvironmentStringsW WriteConsoleW VirtualQuery LoadLibraryExA HeapSize WaitForSingleObject GetLocalTime |
ole32.dll |
IIDFromString
CoTaskMemFree StringFromCLSID CoCreateInstance CoSetProxyBlanket CoCreateFreeThreadedMarshaler StringFromGUID2 CoCreateGuid CoInitializeSecurity CoInitializeEx CoUninitialize CoTaskMemAlloc CreateStreamOnHGlobal CoRegisterInitializeSpy CoRevokeInitializeSpy CoCancelCall CLSIDFromString CoEnableCallCancellation CoDisableCallCancellation |
WINTRUST.dll |
WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData WinVerifyTrust |
SETUPAPI.dll |
SetupIterateCabinetW
|
WS2_32.dll |
FreeAddrInfoW
WSAStartup GetAddrInfoW |
gdiplus.dll |
GdipFillRectangleI
GdipCreateSolidFill GdipGetImageGraphicsContext GdipDeleteBrush GdipCloneBrush GdipCreateFromHDC GdipGetImageWidth GdipDeleteGraphics GdipDrawImageRectRectI GdiplusStartup GdipDrawImageRectI GdipFree GdipDisposeImage GdipAlloc GdipCloneImage GdipLoadImageFromStream GdipCreateBitmapFromScan0 GdipGetImageHeight |
RPCRT4.dll |
RpcStringFreeW
UuidToStringW |
api-ms-win-core-winrt-string-l1-1-0.dll (delay-loaded) |
WindowsConcatString
WindowsCreateStringReference WindowsGetStringRawBuffer WindowsCreateString WindowsDuplicateString WindowsCompareStringOrdinal WindowsDeleteString |
Attributes | 0x1 |
---|---|
Name | api-ms-win-core-winrt-string-l1-1-0.dll |
ModuleHandle | 0x422b08 |
DelayImportAddressTable | 0x40e000 |
DelayImportNameTable | 0x40a60c |
BoundDelayImportTable | 0 |
UnloadDelayImportTable | 0 |
TimeStamp | 1970-Jan-01 00:00:00 |
_scenario_roaming_culture_en-us_lcid_1033_platform_x86_productreleaseid_none_ |
Continuing could be expensive |
You're connected to a network that limits downloads every month. |
We need to stream some large files over your network connection to install Office, so we recommend installing while connected to an unrestricted network. |
If you are sure you won't be charged or exceed your limits by dowloading a large amount, you can choose Continue to download and install. Otherwise, you should Close and install when connected to a different network. |
Administrative Privileges Required |
Installation requires administrative privileges to make changes to your computer. |
Please retry installing this product and give the required permission when prompted. |
If you cannot give these permissions to install, ask your system administrator to help you. |
Couldn't install |
We're sorry, we had a problem installing your Office program(s). |
Is your internet connection working? Do you have enough free space on your main hard drive? |
Please try installing again after you've checked the above. |
Office needs a newer version of Windows |
We're sorry, we couldn't install your Office product because you don't have a modern Windows operating system. |
You need Microsoft Windows 7 (or newer) to install this product. |
Couldn't Install Office |
We're sorry, Office couldn't be installed. |
Please save the file you used to start this installation to a place you can find easily. Then use Windows Explorer to view that location and try installing Office again. |
We found a problem! |
We found a pre-release or Beta version of an Office product on your computer and can't install because of it. |
Please Uninstall any pre-release Office software using the Programs and Features item in your Control Panel and try installing again. |
We're sorry, but we can't verify the signature of files required to install your Office product. |
We need to verify these signatures to keep your computer safe. |
Please retry installing your product or, if installation continues to fail, try re-downloading your installer if you got it online. Make sure you only download Office products from a trusted source. |
We found a problem! |
We're sorry, Office does not work with Windows 8 Consumer Preview. |
You need the full version of Windows 8. |
We're sorry, Office (64-bit) couldn't be installed because you have these 32-bit Office programs installed on your computer: |
%s |
64-bit and 32-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 32-bit version of Office instead, or uninstall your other 32-bit Office programs and try this installation again. |
We're sorry, Office (32-bit) couldn't be installed because you have these 64-bit Office programs installed on your computer: |
%s |
32-bit and 64-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 64-bit version of Office instead, or uninstall your other 64-bit Office programs and try this installation again. |
We're sorry, we can't continue because we weren't able to download a required file. Please make sure you're connected to the internet or connect to a different network, then try again. |
Please free up some disk space |
We're sorry, we couldn't start installing Office because available disk space is too low. |
Couldn't start Office installation |
We're sorry, but we could not successfully start your Office installation. Please try again later. |
Setup Failed |
A newer version of Setup is required to install this product |
We're sorry, but we could not start your Office installation. Another installation is in progress. Please try again later. |
&Close |
%s |
<a href="%s">Go online for additional help.</a> |
Invalid product %s specified. |
Error configuring products! |
We're getting things ready |
We need to remove some older products |
Some older products don’t work with Office 2016. Before installing the new Office, we need to remove: |
%s |
Important: Once we’ve removed these products, you won’t be able to install the old version again. |
Remove and Continue |
&Cancel |
Couldn't Install Office |
We are sorry, but we could not complete the installation. |
We hit an issue trying to uninstall your previous Office version. |
<a href="%s">Go online for additional help.</a> |
https://support.microsoft.com/kb/2739501 |
Save your work before continuing |
We need to close the following apps: |
C&ontinue |
&Cancel |
Couldn't Install Office |
We're sorry, Office (64-bit) couldn't be installed because your computer does not support 64-bit applications. Please try installing the 32-bit version of Office instead. |
We're sorry, we had a problem installing your Office program(s). |
Please make sure the Office installation disk is inserted. Do you have enough free space on your main hard drive? |
Please try installing again after you've checked the above. |
We found a problem! |
We're sorry, Office Click-to-Run installer encountered a problem because you have these Windows Installer based Office programs installed on your computer: |
%s |
Click-to-Run and Windows Installer editions of Office programs don't get along for this version, so you can only have one type installed at a time. Please try installing the Windows Installer edition of Office instead, or uninstall your other Windows Installer based Office programs and try this installation again. |
Microsoft Office |
%s |
<a href="%s">Go online for additional help.</a> |
Error Code: %s |
Client update needed. |
We are sorry, but we could not complete the installation. Please try again later. |
https://go.microsoft.com/fwlink/?LinkId=613501 |
<a href="%s">Learn more</a> |
This installation requires a compatible Microsoft Office program installed on your computer. |
Stop, you should wait to install Office 2016 |
You won't be able to receive mail from a current mailbox. |
%s You may want to contact your mailbox provider or system administrator about this issue. |
<a href="%s">Learn why</a> |
Business Contact Manager will no longer work. |
%s |
<a href="%s">Learn why</a> |
You won't be able to receive mail from a current mailbox. Business Contact Manager won't work. |
%s You may want to contact your mailbox provider about these issues. |
<a href="%s">Learn why</a> |
Outlook 2016 is not compatible with Exchange 2007. |
Outlook 2016 requires access to the AutoDiscover service for your Exchange service. |
Business Contact Manager is not compatible with Outlook 2016. |
&Install 32-bit |
&Install 64-bit |
This installation is for the 64-bit version of Office, but the following 32-bit Office applications are already installed on this computer: |
%s |
Want to install 32-bit Office, which will work with your 32-bit applications? Select "Install 32-bit". If you want the 64-bit version, select "Cancel", uninstall your 32-bit Office applications, and start this 64-bit installation again. |
This installation is for the 32-bit version of Office, but the following 64-bit Office applications are already installed on this computer: |
%s |
Want to install 64-bit Office, which will work with your 64-bit applications? Select "Install 64-bit". If you want the 32-bit version, select "Cancel", uninstall your 64-bit Office applications, and start this 32-bit installation again. |
Sorry, 64-bit and 32-bit Office can’t be installed together |
%s |
<a href="%s">Help: Installing 64-bit or 32-bit.</a> |
Please Wait |
Office is already being installed. |
For install status, check the Office notification in the Windows taskbar. |
We can't install |
The following product(s) can’t be installed at the same time: |
%s |
We can't install |
To install this product, first uninstall the following product(s) and try again. |
%s |
You need Windows 10 to continue |
This Office product requires Windows 10. Please upgrade Windows and try installing Office again. |
%s |
<a href="%s">Help: Upgrading Windows</a> |
We can't install |
This product can't be installed on the selected update channel. Please contact your system administrator and try again. |
We can't install |
This product can't be installed on the selected update channel. Please contact your system administrator and try again. |
We can't install |
This product can't be installed on the selected update channel. Please contact your system administrator and try again. |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 16.0.12527.21330 |
ProductVersion | 16.0.12527.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | UNKNOWN |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Office |
FileVersion (#2) | 16.0.12527.21330 |
InternalName | Bootstrapper.exe |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | Bootstrapper.exe |
ProductName | Microsoft Office |
ProductVersion (#2) | 16.0.12527.21330 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Nov-06 09:07:43 |
Version | 0.0 |
SizeofData | 280 |
AddressOfRawData | 0x2c21cc |
PointerToRawData | 0x2c15cc |
Referenced File | d:\dbs\el\jan\target\x86\ship\click2run\en-us\SetupBootstrapper.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Nov-06 09:07:43 |
Version | 576.27412 |
SizeofData | 4 |
AddressOfRawData | 0x2c22e4 |
PointerToRawData | 0x2c16e4 |
StartAddressOfRawData | 0x7c63b0 |
---|---|
EndAddressOfRawData | 0x7c6478 |
AddressOfIndex | 0x823288 |
AddressOfCallbacks | 0x6c3e54 |
SizeOfZeroFill | 0 |
Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
Callbacks |
0x00647235
0x006472B3 |
Size | 0xa0 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0x800 |
EditList | 0 |
SecurityCookie | 0x80e2cc |
SEHandlerTable | 0x7c2fb4 |
SEHandlerCount | 3276 |
XOR Key | 0x3d674ee6 |
---|---|
Unmarked objects | 0 |
ASM objects (26715) | 24 |
C++ objects (26715) | 196 |
ASM objects (VS 2015/2017 runtime 26706) | 25 |
C objects (VS 2015/2017 runtime 26706) | 39 |
C objects (41204) | 7 |
ASM objects (41204) | 2 |
263 (26715) | 2 |
C objects (26715) | 37 |
Imports (26715) | 25 |
262 (26715) | 5 |
Total imports | 766 |
C++ objects (VS 2015/2017 runtime 26706) | 132 |
C++ objects (VS2017 v15.9.16-18 compiler 27034) | 148 |
265 (VS2017 v15.9.16-18 compiler 27034) | 1277 |
Resource objects (VS2017 v15.9.16-18 compiler 27034) | 1 |
151 | 1 |
Linker (VS2017 v15.9.16-18 compiler 27034) | 1 |