37e50b4a02a520b97f6a69a495a6918fc43f9fe819a5c1cc4c23be8237d09f29

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Jul-12 07:26:53
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName FileOpen Systems Inc.
FileDescription FileOpen Client B1016
FileVersion 1.0.143.1016
LegalCopyright © 2012-2025 FileOpen Systems Inc.
OriginalFileName
ProductName FileOpen Client B1016
ProductVersion B1016

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • https://jrsoftware.org
  • jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: FileOpen Systems Inc.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/71 (Scanned on 2026-05-29 08:10:32) All the AVs think this file is safe.

Hashes

MD5 c51101f2937bdeccbe8e58bbdea45b9b
SHA1 23df6c38dd3ef649bb1b5ca294fc7a6b41954663
SHA256 37e50b4a02a520b97f6a69a495a6918fc43f9fe819a5c1cc4c23be8237d09f29
SHA3 376c8e1f43f5f1413b41552588b727c9f8051c394bd39b669e3abd80e045e91c
SSDeep 98304:UwREYdWfLVGxawBQno/6QKm9mt8vwVN5qj:sffxG3/v88v05G
Imports Hash 4fedeec03d85f2e0d9939674af913942

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 11
TimeDateStamp 2024-Jul-12 07:26:53
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xa7400
SizeOfInitializedData 0x9ea00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000A83BC (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xa9000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x154000
SizeOfHeaders 0x400
Checksum 0x4f1617
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b889d302f6fc48a904de33d8d947ae80
SHA1 631854a32b101ffb32be28f95233f07ada997f31
SHA256 551f3a998c5d32cff8f58dd5c34a7e2aa5f6311a3e08553f8afc7a5872f0830d
SHA3 ac1bce0d4ea256bb92c0d562c20ae8017fe9aaab961de462c3c5d4a82012f531
VirtualSize 0xa568c
VirtualAddress 0x1000
SizeOfRawData 0xa5800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37719

.itext

MD5 588dd0a8ab499300d3701cbd11b017d9
SHA1 daa72022eeba5d1f662627399109e1ad10259292
SHA256 a82d14af241c308c43746a82a65e8598ba048304ae22b4c5e4fcd981d24c48df
SHA3 690a6e1273561395a87c3b220233e3aecbfb33fd88b154f020cfe2d3c538d74e
VirtualSize 0x1b64
VirtualAddress 0xa7000
SizeOfRawData 0x1c00
PointerToRawData 0xa5c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.10926

.data

MD5 5c0c76e77aef52ebc6702430837ccb6e
SHA1 ba7dbb2689a94327d20535cad24689725d9f0dd8
SHA256 2a1b24bbf6a4c52410949a50d70d70c5b6b02b4c0c69794a20c8ae4cdf90c938
SHA3 c75b256a96d1484f217f88e80af6bb8222c4fdb10efee71fa5a6081ca1bd2e99
VirtualSize 0x3838
VirtualAddress 0xa9000
SizeOfRawData 0x3a00
PointerToRawData 0xa7800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.95916

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x7258
VirtualAddress 0xad000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 627340dff539ef99048969aa4824fb2d
SHA1 24cfe989547aa50de659512bce7e2a6e77786c59
SHA256 e7c1a2b5618072b58a6948a7c7e0d9f4a7bce8086f8957d45d287acab7351fc1
SHA3 ba6e203f0f1e298cc5762dd8fb3a28578674f4dd0dcaa08802b9986c38804e11
VirtualSize 0xfec
VirtualAddress 0xb5000
SizeOfRawData 0x1000
PointerToRawData 0xab200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.0204

.didata

MD5 fd11c1109737963cc6cb7258063abfd6
SHA1 f6b9fa45a8f34bd2cb9218ce88c11e20d3fc71a3
SHA256 da813677d0ab6c0ef688beb594ebd76cf4980cb614cee01b756efda9b3316742
SHA3 bbfadba84d740dfd46a08ed84111a5327ada5b7c1c883797e859c36cd7d0043e
VirtualSize 0x1a4
VirtualAddress 0xb6000
SizeOfRawData 0x200
PointerToRawData 0xac200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.72929

.edata

MD5 7de8ca0c7a61668a728fd3a88dc0942d
SHA1 ba95bf2c856634a9f69d90861654962600b646de
SHA256 78383375db293ffadb4418ce339ec010bc78832dfdb6cf8f58d535f7a38e41fd
SHA3 b8c408c4762e0631353f37bb98cdf3be3b97c15c108d3cd83c7c50f5e0a0ba72
VirtualSize 0x71
VirtualAddress 0xb7000
SizeOfRawData 0x200
PointerToRawData 0xac400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.30558

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x18
VirtualAddress 0xb8000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 d84006640084dc9f74a07c2ff9c7d656
SHA1 0379022c42b8971c66f5c503046d0ab125118679
SHA256 a1f69e8471e1728aef0f39cfe3f833c244d412e375d9538d47fca3cc8f148401
SHA3 064a2c4885c5e43b07674dc5448234cd0eeabfec6652ec78f6ba14b27207cbed
VirtualSize 0x5d
VirtualAddress 0xb9000
SizeOfRawData 0x200
PointerToRawData 0xac600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.38928

.reloc

MD5 a85fda2741bd9417695daa5fc5a9d7a5
SHA1 d8861390a8a272a201d4b448f959691be6c7a5e2
SHA256 328baa749f17c96617365ecfd123d0572805a715a5a56bb2fe227e467a55c5e5
SHA3 d10d2e04b54ff22a62bd97263bc6bd24f565af5263041bc63e085dd2dd902773
VirtualSize 0x10fa8
VirtualAddress 0xba000
SizeOfRawData 0x11000
PointerToRawData 0xac800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.70947

.rsrc

MD5 7c3352056e60e1dfd2b3d9c894ea942e
SHA1 70e8ad9515e7cf6b03531a7d63da4bb3979429d9
SHA256 0bb4a4f51feb696836ddfa8d6b8a80b9e788919a4a8eb8ebe812f96b3e446a1c
SHA3 272d37140592c073fa1c0447c02922ecfa41f0bbc5e768c243ae75baabd40b58
VirtualSize 0x88868
VirtualAddress 0xcb000
SizeOfRawData 0x88a00
PointerToRawData 0xbd800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.1674

Imports

kernel32.dll GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxW
DestroyWindow
CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SysAllocStringLen
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetLBound
SafeArrayGetUBound
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
VariantChangeType
SafeArrayCreate
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenThreadToken
AdjustTokenPrivileges
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
FreeSid
AllocateAndInitializeSid
EqualSid
RegQueryValueExW
GetTokenInformation
ConvertSidToStringSidW
RegCloseKey
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xb6080
DelayImportAddressTable 0xb6090
DelayImportNameTable 0xb60b4
BoundDelayImportTable 0xb60d8
UnloadDelayImportTable 0xb60f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xb063c

__dbk_fcall_wrapper

Ordinal 2
Address 0xfc10

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.60516
MD5 2224a8949a57fedb36aa741a70db31f2
SHA1 d62e7888a3e389d1ad60996d582b0ddf522ea6b7
SHA256 f02b8bae38fa2e7488eb4169215114952a7aab5b958c662e2ff504d7bb651604
SHA3 9beb0ac58512034d3700427cbaa27b58a36cfedd1ef5cd24fa92a4c802472b38

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.58114
MD5 4b36f98a98a35c35f6bb236d6e6896e5
SHA1 2805e9f96a1e6c41eb9e588335bff07c58758f35
SHA256 69b56029c18db9679e730cc9125df77029f2869b89b1d70fac6811307c823483
SHA3 a2b0d71fbf7b2c4f13b99616cfc2d46a9ae070ff8d49496de664419e0051a6cb

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.60438
MD5 940b533ccd960861a7b7e8f129d0a838
SHA1 23afd742c3e4ae86c63ccb2da287aa6cff713d5c
SHA256 2ac0f3247eb61e9cf856d656bcf7f93b3684b6aad24896fd1f4b51624c563564
SHA3 dad4d988108694886bb48f9a531720b6c922405b93eddf931eb5e7630571452e

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71844
MD5 de92f2cf60c92d060bc928069ccd3dc2
SHA1 9e72eb0a01e26edba44321b748443d85c7cc7cc8
SHA256 470269f5cd37a2bf64d64096631e566c16a2a1ed3553949626c65c264f8b55b4
SHA3 da914899fef8704beaa431c0719350fe8db791a311bee1466e5fcc17a09192e3

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82994
MD5 462d255e95038b71ca195c540d6dcfe4
SHA1 bec5aa4498dcded657974ba5dcf445d91fd567b7
SHA256 557d5cba2055710c80280f3e7a9bf73a5733cad4596ecba3e6c379b3b22eaefb
SHA3 99b0bb02b4e83ba0b6611205e076999b1a640f339c53701cfb4b4ebd3ffbf1f5

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13144
MD5 6ec503c67c7a349064562ddc9a8d46b4
SHA1 172d92dafc543694c30892d01165a689f47edc32
SHA256 72929a49331af2fcb0f871093dad73b81f54959759250bbc7791a0455822dbe8
SHA3 4d5c64781377a86ea728ffd08f9fa1b52b86d44a5bc5edc93d97aeb1da46da92

106

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3899
MD5 80be9ce14f35e7ab3bf08185419c135d
SHA1 00adf30dffa388407b2bc8c262b889e34f153e0d
SHA256 33d5c0f81c5a704b74206370d2a63e88155973bd54e4734f14c018e37cfb178c
SHA3 eab0622421d15a838ba73a983188366d755f66ce0ed6c3fbbe594ba95e2bc9d0

107

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.62234
MD5 16f1a60df8c75122dc0878cd688e0f82
SHA1 6b372ea7a00385a98c9ede2cbafda686cd4245ed
SHA256 a9b4789df209b55627d66482e684aca5d44eb027cc333fbb5b2ab964d87bf63c
SHA3 171fd0b345e3b0b61a2e9dff5873b529d4d2ebffd19b876474e9bc4a4b7e68ba

108

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x12428
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.39781
MD5 9260e882ed3ed989b7504dbee6f4a8a0
SHA1 72c30f0f6880ebf646c2509eff0c29d9a91aa95a
SHA256 f63ec2be522cba7c0c283c86f6b6f5bce49c5c6e87e39b1159aa093bc0f28543
SHA3 dac50025b8b6ac79b85d31e3916d6d32392a896b1b5a13fd3a0e2cdaecdf0481

109

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59715
MD5 95765a81f34b8ff3f7c9a920f699ee33
SHA1 44aca630a683397e75b27ef7a05c75e3c8efe4a0
SHA256 0fc6e08bf6ad2afd809656de7c842bec63a467a14ab41f697484e20f3b11c47c
SHA3 3034826fd19bff7ac324e7d615596045ee7b3b065a2faabc762920091796fed2

110

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2ca8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.72475
MD5 834f83b93f5f5ddc112a845b69b9b678
SHA1 57942fc2519ae6f6ae2f7e7b0e49a8c5b8980f8c
SHA256 fb9e03974260bf7f895f50fcd6bfa760390637851f1eda7017a890cd21fce99e
SHA3 a6f1abf339e22ff53d5ad997516286214dc6cfefec22429914a5586578981fca

111

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1628
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.68272
MD5 1afd0c733bc51ab69893996cbdb2e3bf
SHA1 6e13fba95b9d8cd1b9d92631b55b75aa663c050c
SHA256 ed9f9df03d5f2050358faa2c2d2298368f03924697afaed035c557bfa4e059a5
SHA3 1739e74b184bf40fa68781463a0bcd0ae92741ad6239e39263a83261a42b37fd

112

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.49685
MD5 ae829679273d43757d374662be60f210
SHA1 4255a2fc60083e4fbaa4a3c0fcd3c7fb545b7540
SHA256 35fbd87313f6dcbee126fd01e25652a00e031a914809c786ff59f9f74cb9176b
SHA3 6f6dd614aa6dcf1034aa5ff7c8c05c24a263ba4e2a192b59e4b597cb3b52c0d5

113

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.03842
MD5 950750ddde094522af2bef8833d898cf
SHA1 3263928827fa9e21e9cc9ebe644b77b8128daba8
SHA256 0a025e543c8f737717f3897bc4e269af7b5b13d7e409fae331801f7f87c1f670
SHA3 c4be2f8c171f6f6e879e9825d584ccfbf5690509a62c083f90cc292d818b52c5

114

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.81762
MD5 70e2bfdecda3e8dfe9770103a2f5bf5e
SHA1 fc1a1b0c920f6a580a94b81000d92398b7c8ebd9
SHA256 2e66826721b60ebe7255cf95dd43c2cdaa774652fc096d90610a2f7706ce3d6f
SHA3 6cebcc8b9887c461abdd142dac425edce18053d4a3b43c5da75033cacc96d779

115

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.23464
MD5 816fa5ca4a07b49b64fc34f53ca35e0f
SHA1 3836b4d768fa10dcc3aed55923558c7ba43380d4
SHA256 0e65035a75bea4e1d06be16a0ec4743884d127da541d28f8eb33d7b8d52afa17
SHA3 9affd38b20a7f379a8fa500699228056ff014f637989a2882ef7c863dd3ce590

116

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2868
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4051
MD5 27ab83031812ff6ce6d046a235d37ba8
SHA1 8dbb6a3492ba4d4b869b4905422634e7c39d07e7
SHA256 d448abafb158d0153f455e0c9ea4072bf9cfb130e1fd2941cecded5aec3a461b
SHA3 ba7d0006af281aaa5820986cd75824cbdaef19e565051df211edf8f3d8b9be8f

117

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xa68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4839
MD5 22e105a97d426b14f76b681849d26daf
SHA1 3c71ef99c157e7e574ddfeb47d8496eb185eb88b
SHA256 ef228fd0035036bb56cff9db46eea12b83c825d38085a0a97d8c628c0f1f92c6
SHA3 d559ec0852306f07e8734fd3cc89b05a0d325cf1a7a680bf393beafcdeae624a

118

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34939
MD5 5ca55381eeaa896485b003b483dd4c63
SHA1 70e46b1d1e584992ed4607638e91f5353e5ac586
SHA256 465fb3dbdf65d255e24e43615e35a33c2f2e2f2c0efaa74600bc3dc8ebd734c5
SHA3 c8748f669c7182b9b6523f2d30424f42ef9ee8d3d2558d1bc60bed51b5b03edb

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27436
MD5 16c83a530551674c0549067380ee799d
SHA1 fb015722bc9b8bd10e901b4a6063887e9075d9c8
SHA256 6bb30c8a1df395a8e73321f5feb010ad66b1440f85df19b0b66611d8c029730a
SHA3 5363ab577c0955f1c6ec3d3690ce43f74bf16e69a9dd6a3d60cec490d4655a27

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52568
MD5 6389af7862593e7ce4db180f39e50140
SHA1 88b9651a981bf3348a74e5ab7d73a68c00eacb34
SHA256 91a2703df665f2d3201c6a5071fafb0b9aef1f7cf2ee36c53ba1d463251b1d90
SHA3 b14fffd73c83498cf4e53e90f20804af158c45088ae7f345668efc50088a4508

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24973
MD5 c585062fd9508d9ef6eed11299d5cdb9
SHA1 a86d3099f1ff650e0fbbcfa50dcc7069eb12a9bd
SHA256 a33f03dda00385bdf0b927b77ab2d02256f5dbb3d1e973a4bacd49a8e835d497
SHA3 dbce279b2b5fa3baae5d5fc5c390abd14c3467917892d72491220e955459fe7b

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x44c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37757
MD5 fdf50a2ec296ee0c6f14f17dcbb4d033
SHA1 89e1dd972c2cf0f03819f154e20b41147317ab57
SHA256 86c9c0f8051440577615ce48dea198071272529bb7202e1be19cd89b54a41501
SHA3 e785bebb46272c3a4adc7ce895af83ab4c68bc9f3888bad61bf1f8ed09f1afba

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31895
MD5 4ac29bb5f7361e85771807112cd4ec93
SHA1 b164bf0882b60c0d7d4643495a2c1db5a20a1343
SHA256 2e6d8102640132ccabd2fa3c3a61c77c2b41a80d7f60013cf7149819c2b5c9d2
SHA3 ee5ab8846732cb786d250fc1780293072aff157ae61cf7f671eb4e6e29018bf7

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45
SHA1 30704560832bafa440df1fd20693653c2a30f815
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75
MD5 fa1c96712ab8720f82ad4095daf7cee5
SHA1 abe71b9873e6e494a7d9de8f1f1985c550fc6b59
SHA256 10ca7c7ba673f29383bc50d1becb5fbeddddecaa6109de088da9a94c74d4f1c4
SHA3 c3be1ab5871e6568c50c4c2dd73e7c8c09d9e9451b256e9871c537b6da54a299

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x310
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17718
MD5 b9e23c55f2dd32f84d54b7c723c182fe
SHA1 5e1e4f56e2e23a804ff69d8b87e2f09506c8fdae
SHA256 dfce236a2088f4fc6942fc74d8529e9285da32eddeecd9143c799861645ccfce
SHA3 1653b3bcabbe26085cae294ee9f3a1eee0185b53b620099373c89a329afb13c7

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56808
MD5 6715e7736fc2c9eb1ca30bf4d726fcd3
SHA1 76708f3186abd51e29918f7e85f8a2b3b8d572bf
SHA256 5122efd2ea4c1a6e31fd44dbdd27e5056f14cf69e889e525e4861189be004ddd
SHA3 edc0895fc53b6a1efaf53307b39d074d86e59baca419b0dcf6472701dfa51256

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36082
Detected Filetype Icon file
MD5 b0cc721091fa7043e3addf3d7f363750
SHA1 3c92c26408d6600f933d8358ff97f9083ab2b29d
SHA256 6da465ed50c7adb291c75b199d24aef8683cea61e07ea242c15fb88e3b210d54
SHA3 f759e583f6c09a1e95ecda692b65ea89693bf87af28de7368212be7a580fdb99

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80987
MD5 008c2a0bc0278b0b3da3b6eab3225d9f
SHA1 7afd93a3a4b1ea71eadadab021c100a6c77a004d
SHA256 6123165787c61319c4808f1192c60dbd39b10867ecd356eaf97f8aec683e6d61
SHA3 feca8961dd5b8be421a0ff7b3398debfa1bef456f1ed49a1cfced9c4c39d2b34

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89085
MD5 e07ab8c9030f776ce0f6d9040d41c616
SHA1 593953973c74066bcd09b22402948425dab9b12f
SHA256 75bb01fe4bafdef22d879aaea5b85d1165a30ec0e558536e1b4c6002c4730d5d
SHA3 51b78d43db0954fcaa7c6fd2558eece5eb98a1c5f6e95a3033891777bfd00a7c

String Table contents

Windows Server 2016
Windows Server 2019
Windows Server 2022
Windows 8
Windows 8.1
Windows 10
Windows 11
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Invalid argument
Source and Destination arrays must not be the same
Argument out of range
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%0:d). %2:s object range is 0..%1:d
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.143.1016
ProductVersion 1.0.143.1016
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName FileOpen Systems Inc.
FileDescription FileOpen Client B1016
FileVersion (#2) 1.0.143.1016
LegalCopyright © 2012-2025 FileOpen Systems Inc.
OriginalFileName
ProductName FileOpen Client B1016
ProductVersion (#2) B1016
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4b8000
EndAddressOfRawData 0x4b8018
AddressOfIndex 0x4a9c24
AddressOfCallbacks 0x4b9010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.