4325244a7c1b300cd6006c6d4d8ee6335c4b04284b3677748de614d6acfae86d

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2011-May-28 16:04:38
Detected languages English - United States
Debug artifacts d:\Projects\WinRAR\SFX\build\sfxzip32\Release\sfxzip.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegCloseKey
  • RegSetValueExW
  • RegQueryValueExW
  • RegCreateKeyExW
  • RegOpenKeyExW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • CreateFileA
Can take screenshots:
  • GetDC
  • CreateCompatibleDC
Info The PE is digitally signed. Signer: BitTorrent Inc
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/68 (Scanned on 2026-02-14 12:24:00) All the AVs think this file is safe.

Hashes

MD5 670665adc104762488096e84624fa384
SHA1 b76a77a5d1f061434e4dd2691e5cd5855a70359b
SHA256 4325244a7c1b300cd6006c6d4d8ee6335c4b04284b3677748de614d6acfae86d
SHA3 027b90c0747380320f20a40305d3d660dfcb18ad5189f595902ddff41f57bc7e
SSDeep 196608:Dtcf3YdAkSihw+MDq3dxfrZ28O/dDJz8Mpe8dmT88ejj41ZPTnUz:DtgISkSiyq388O/dDJz8H8dmhSAZPTnU
Imports Hash bf8e93937f9e7494ce0335cf5d059356

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2011-May-28 16:04:38
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0xce00
SizeOfInitializedData 0x23a00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00009AFD (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xe000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x34000
SizeOfHeaders 0x400
Checksum 0x77205b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 05c1b440d62b5e981c7ddd09850125b6
SHA1 cec484f0f9b200fad250604987238c5be999fb9e
SHA256 0be5cde3f4b6d65f6090114c063dbea09850990fbd25298194ce3dfbb29c8585
SHA3 b3e6669f1d0d961cba0cb885f745920d17591063bcdc65457a40ab3a03d430f9
VirtualSize 0xcc4b
VirtualAddress 0x1000
SizeOfRawData 0xce00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51141

.rdata

MD5 ed56cd9519d4cf09a0e9e8f637177276
SHA1 801e026fa8137b6b881cbf357e9d2891aaec7d37
SHA256 9465b77e07ba06e31a6b006fa0cda77fa3ce35e3bc980050cbdc3fb2677e3221
SHA3 44ec5afbc8a3bcaed807afcfc4b0f3a2d04a51ca6ae876ec56ecc065ec70d0df
VirtualSize 0x1b75
VirtualAddress 0xe000
SizeOfRawData 0x1c00
PointerToRawData 0xd200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.96682

.data

MD5 9600ec9057ed398cee93a5096d27d96c
SHA1 083c0ab3a494a5034a0a7490dcf5d5d13365c0e0
SHA256 666a125aeaa591f83a598dda63ee4b08c1afed77cb49df98640ce64a44d1a855
SHA3 bd7b33ac21174673a4ec3a8d25441ed7c5ad8e7edfa6d5687d1398529f201272
VirtualSize 0x1d9d8
VirtualAddress 0x10000
SizeOfRawData 0x200
PointerToRawData 0xee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.31952

.CRT

MD5 be71b421baf87591ba3ca2892560ca56
SHA1 acdf1eac2d6b4f0efae99a6e5e74ce5bbbd1d64b
SHA256 8d876af79f7443c86446c6c223bf8a915562024b7f999923019d9583a4f14024
SHA3 4245d067daabf47924e02454c1bf389c5f84f187dfbaae51636d3b73e520959e
VirtualSize 0x10
VirtualAddress 0x2e000
SizeOfRawData 0x200
PointerToRawData 0xf000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.219439

.rsrc

MD5 ae18f8125b0130dc7645ce37b50d98ff
SHA1 f7c96afa59c11fd1770291f9e7a0c9e43fbab2a9
SHA256 08a3dcf2f62ea478fd765d4dd4b7db275ca4037b1df5f7ec8b2c9bf153b00aaf
SHA3 733ce9fd838afb0af1c931e05574e577f3b89c05c5a080b4625de0fa12db4381
VirtualSize 0x4078
VirtualAddress 0x2f000
SizeOfRawData 0x4200
PointerToRawData 0xf200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.65485

Imports

COMCTL32.dll InitCommonControlsEx
#17
SHLWAPI.dll SHAutoComplete
KERNEL32.dll GetFileAttributesW
SetFileAttributesA
SetFileAttributesW
MoveFileW
DeleteFileW
DeleteFileA
CreateDirectoryA
CreateDirectoryW
FindClose
FindNextFileA
FindFirstFileA
FindNextFileW
FindFirstFileW
GetTickCount
WideCharToMultiByte
GlobalAlloc
GetVersionExW
GetFullPathNameA
GetFullPathNameW
GetModuleFileNameW
FindResourceW
GetModuleHandleW
HeapAlloc
GetProcessHeap
HeapFree
HeapReAlloc
CompareStringA
ExitProcess
GetFileAttributesA
GetNumberFormatW
DosDateTimeToFileTime
GetDateFormatW
GetTimeFormatW
FileTimeToSystemTime
FileTimeToLocalFileTime
ExpandEnvironmentStringsW
WaitForSingleObject
Sleep
GetTempPathW
MoveFileExW
UnmapViewOfFile
GetCommandLineW
MapViewOfFile
CreateFileMappingW
OpenFileMappingW
SetEnvironmentVariableW
GetProcAddress
LocalFileTimeToFileTime
SystemTimeToFileTime
MultiByteToWideChar
CompareStringW
IsDBCSLeadByte
GetCPInfo
SetCurrentDirectoryW
LoadLibraryW
FreeLibrary
WriteFile
SetFileTime
GetStdHandle
ReadFile
GetCurrentDirectoryW
CreateFileW
CreateFileA
GetFileType
SetFilePointer
CloseHandle
SetEndOfFile
SetLastError
GetLastError
GetLocaleInfoW
USER32.dll CharUpperA
OemToCharBuffA
wvsprintfA
wvsprintfW
ReleaseDC
GetDC
SendMessageW
SetDlgItemTextW
SetFocus
EndDialog
DestroyIcon
SendDlgItemMessageW
GetDlgItemTextW
GetClassNameW
DialogBoxParamW
IsWindowVisible
WaitForInputIdle
SetForegroundWindow
GetSysColor
PostMessageW
LoadBitmapW
CharToOemBuffA
CharToOemA
OemToCharA
FindWindowExW
UpdateWindow
SetWindowTextW
LoadCursorW
RegisterClassExW
SetWindowLongW
GetWindowLongW
DefWindowProcW
PeekMessageW
GetMessageW
TranslateMessage
DispatchMessageW
DestroyWindow
GetClientRect
IsWindow
MessageBoxW
ShowWindow
GetDlgItem
EnableWindow
LoadStringW
SetWindowPos
GetWindowTextW
GetSystemMetrics
GetWindow
CharUpperW
GetWindowRect
GetParent
MapWindowPoints
LoadIconW
CreateWindowExW
CopyRect
GDI32.dll CreateCompatibleDC
GetDeviceCaps
GetObjectW
CreateCompatibleBitmap
SelectObject
StretchBlt
DeleteObject
DeleteDC
ADVAPI32.dll RegCloseKey
RegSetValueExW
RegQueryValueExW
RegCreateKeyExW
RegOpenKeyExW
SHELL32.dll SHChangeNotify
ShellExecuteExW
SHFileOperationW
SHGetFileInfoW
SHGetSpecialFolderLocation
SHGetMalloc
SHBrowseForFolderW
SHGetPathFromIDListW
ole32.dll CreateStreamOnHGlobal
OleInitialize
CoCreateInstance
OleUninitialize
CLSIDFromString
OLEAUT32.dll VariantInit

Delayed Imports

101

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xbb6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.19099
MD5 5c475f4b07e1e05af29d25e1700f7279
SHA1 b139902d2f9eae34727ba4f740b4b1e99d4bc4e8
SHA256 690c938562399f89ad78e3fde2a7edaee8ddf2fafef987a7b37e577a8f6126ea
SHA3 1d3dd19fbcc656a30478c2b4ba98485853b464fe09ea2debc4cfc64271677d1e
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38234
MD5 77c64818523675c19429aee1ec8a0544
SHA1 1f5a7359bf9b3922504c21ce175e82adcbb0a051
SHA256 4436650a65c64265abf4b8726a33b15c2b2039fc65e120c7173bcba67feb852b
SHA3 e2b667fb70d551750e259d2d592fa87c3f4a0de6658f6cf74f11b79633c2697c

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.88998
MD5 de81bccb6410c9e4acb325f67f268bc5
SHA1 008016ff2382733c62fd44c4e21e87f689a25500
SHA256 7b0ae8f74efcb3e7caf1429f5bba76108251eea88f9581dcfeb52a886470f7bc
SHA3 ce2d055cf9b0345750de0b6284ce7dfd64fbc84fb6faf2304e0dfd644474a3f6

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.12176
MD5 e9356775b7b8159cfad335fa2c2b22d5
SHA1 7d1b798e8a87d7ef3b07c6eaf598d8b5d7169639
SHA256 439c8b79133224a07cbe1a6e0c30eef9cdcdec92dab8ead48374e516304ef165
SHA3 50c0778cbbb68c04de463c928f7e60696bc24bb02c390baa555756af8e773e4e

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.68705
MD5 41491a39d90ed5934e44c6a505f15ee5
SHA1 431fd71d8988019c76c464ea5a0c738b2d2671a8
SHA256 66548c9bb8b9c4ec76b076300868458c9a511cc86879915ebcbaf6f3e3a18334
SHA3 5b99077c1b6b71877c48f6d98bcc2cb38d4eb0920f6ebfe1632e6ee9e24e88f1

ASKNEXTVOL

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x286
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42597
MD5 361be3e9f16096819f38433be227aeab
SHA1 303da809d3ec1bfc46b5fa4fde1733cfffdb9596
SHA256 887347f27d903f6652ba35c3dfae297c23435755a63e02a80259ee6dd0b8af86
SHA3 db76532737d079016d6f113bb1ac833820a004c041973cb70af7ed2cf185da55

GETPASSWORD1

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33944
MD5 331b55f85040e216e56c0b8e843438a8
SHA1 af4002fec283154f7d72fa3f363d28dbb1536f85
SHA256 2e11a1ed4f812e37fdb32a1310cdcca802c46497c27e33ab66ac127345463d31
SHA3 206eda4241a8bdb201359d75e1063c41ed5aba18392eea3d09b31bb5ed4f5f8c

LICENSEDLG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16133
MD5 4da01a070e57545f97e0d84bcf1524e5
SHA1 eeeadb106e138aa26b66d276f84c8d076a31142e
SHA256 44e6a8daef1ac762f8016fc4c8aec52bad42f589b6d8a25d430a619610dd0028
SHA3 a018ce14f68b06cbed4adb1bf6714f3b6c1aa64fa2afa2215e037aa654f9fcee

RENAMEDLG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x12e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08925
MD5 23f9ee829c671147edcb4e5fc285dc76
SHA1 65f15e95491df6b271c340bc3cf6fc2a6e628a31
SHA256 30358e9c494ca9d125b34ccb93a2d8f1237042904f6fcecc2f5ca9a83b7dba9d
SHA3 830894d4015e75dd74224a9a6e70c573491f721f5d9526bbb9cbf766cf000092

REPLACEFILEDLG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31987
MD5 822b9ba661d87f4dedeb47b67cdd4d5a
SHA1 b7902c16350bc2ee7fd78fbeb9461d2f123d59be
SHA256 a1141852e6fb28826de51733ee35fbfdcf74dd8eb7f73049c7c7ad6c21d0cb33
SHA3 712432c699365c95e1b04b3a44cebc97ce77f9824418dbb6784f0c653567325e

STARTDLG

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x252
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.50842
MD5 70542c04588bb92dcf6e5ab5bd89e398
SHA1 5f539ec72c7ce389ef17c3b40871f55bd32f1a50
SHA256 67e646d5c7cbd41603c6896812ed061f6840aa9f0ff6cf45dbc6df84e6bda7e9
SHA3 ff267542512be19983ec68e667ec1e84237f2d7688379737a97da2d97d4d412b

7

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x22c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24143
MD5 fb61b3469ae245a497410d4de5b70d45
SHA1 fbc73ddd8d7c9099ab425bfb2c0776bb8251e8d9
SHA256 99dbe051efdcf261267620d163c0c2e02109d7b2207f70492b79245b7fc3219b
SHA3 ada313e02983cdccf389ba63e0ce66948cc82b05aa9a5085644923f1ea268cd2

8

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x3ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26996
MD5 e5e4a0e3ddcf397abd3e893553fac9df
SHA1 fe34997471a93c618fe95bdf2f5a417ce48ca5e1
SHA256 738c6ba33349b801c90054675829a3124619b82b3dc34963698b82a7178e701f
SHA3 ec2144d1874bf9ecce412f2723bf636b855d7906b4215ece5cea47e84d973d65

9

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x212
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04375
MD5 c1d1d43f5fa2588205da7bc620ee7020
SHA1 c68a9fcf6f70b5f17ea1adcd93f48b68da9407bc
SHA256 1c02c9c1f7683c2de81796ccbfd9aa13c8a4a9147d0cf146f76f9d5df50f8ca3
SHA3 066b9e7de99aea5ed745dac0ce210e3c2387d26ecc9245592073936b5031b80d

10

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16254
MD5 2cadeff6e3f3d3a7160b91229f4477b3
SHA1 425d09920e1a777057fa37bdb3813ffd20cc05f6
SHA256 f87a12acaa5aa1838955fb7c303d39ebd964aa4e42b1d7179efa28c94a68364a
SHA3 06794bad5c1f787fac9de402ba6e326ed9dba84f002752d71f36f8f5db114959

11

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x17c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06352
MD5 de4bf42a328a9ff77c6f877039c91143
SHA1 c8f74377f275bbea5387dfa9dc9c91921936a203
SHA256 2f851c6fa42c7c8c999a32a305f08f54dd725c2abc620fe6cf066847acb67bea
SHA3 fd4fd60db3ffaf392b61f35b8b67f06370c42d691fc0cacd81b46a7e1093d0f3

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64576
Detected Filetype Icon file
MD5 f6262f462f61a1af1cac10cf4b790e5a
SHA1 4aa3239c2c59fa5f246b0dd68da564e529b98ff4
SHA256 44b095a62d7e401671f57271e6cada367bb55cf7b300ef768b3487b841facd3c
SHA3 f2a1d165133c29eba349014fa5f8059ddebe1aba5b220fb89f1a474e95c482ca

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x5b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20816
MD5 f344a0bf9f43a86fa90c071d6b3f0118
SHA1 5758e9ddba79b73daf145cbaeaf1e237d7ac4f4f
SHA256 1f5f4c62718ed7ec7bcf171563cbb4da8a70e37c5a46e3140acdc149cf08b509
SHA3 e8ea44dec448da4efc7ccab112a288640105651d92439cfb3a6e264da95583e1

String Table contents

Select destination folder
Extracting %s
Skipping %s
Unexpected end of archive
The file "%s" header is corrupt
The archive comment header is corrupt
The archive comment is corrupt
Not enough memory
Unknown method in %s
Cannot open %s
Cannot create %s
Cannot create folder %s
CRC failed in the encrypted file %s. Corrupt file or wrong password.
CRC failed in %s
Packed data CRC failed in %s
Wrong password for %s
Write error in the file %s. Probably the disk is full
Read error in the file %s
File close error
The required volume is absent
The archive is either in unknown format or damaged
Extracting from %s
Next volume
The archive header is corrupt
Close
Error
Errors encountered while performing the operation
Look at the information window for more details
bytes
modified on
folder is not accessible
Some files could not be created.
Please close all applications, reboot Windows and restart this installation
Some installation files are corrupt.
Please download a fresh copy and retry the installation
All files
<ul><li>Press <b>Install</b> button to start extraction.</li><br><br>
<ul><li>Press <b>Extract</b> button to start extraction.</li><br><br>
<li>Use <b>Browse</b> button to select the destination
folder from the folders tree. It can be also entered
manually.</li><br><br>
<li>If the destination folder does not exist, it will be
created automatically before extraction.</li></ul>
The archive is corrupt
Extracting files to %s folder
Extracting files to temporary folder
Extract
Extraction progress
Total path and file name length must not exceed %d characters

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2011-May-28 16:04:38
Version 0.0
SizeofData 81
AddressOfRawData 0xfb24
PointerToRawData 0xed24
Referenced File d:\Projects\WinRAR\SFX\build\sfxzip32\Release\sfxzip.pdb

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xc9f3b167
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 21
Total imports 166
ASM objects (VS2008 build 21022) 6
C objects (VS2008 SP1 build 30729) 9
C++ objects (VS2008 SP1 build 30729) 37
Exports (VS2008 SP1 build 30729) 1
Linker (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.