461e1396f108dc4ae335d201924cfc2d

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2017-May-14 18:40:26
Detected languages Chinese - PRC
English - United States
Debug artifacts f:\MyProject\MyProgram\bdhscheck\src\c\WinFwTest\Release\蓝盾NSA免疫加固工具.pdb
CompanyName 蓝盾技术
FileDescription 蓝盾技术
FileVersion 1.0.0.1
InternalName 蓝盾NSA免疫加固工具.exe
LegalCopyright 蓝盾技术 All rights reserved.
OriginalFilename 蓝盾NSA免疫加固工具.exe
ProductName 蓝盾NSA免疫加固工具
ProductVersion 1.0.0.1

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Can access the registry:
  • RegQueryValueA
  • RegOpenKeyA
  • RegEnumKeyA
  • RegDeleteKeyA
  • RegSetValueExA
  • RegCreateKeyExA
  • RegOpenKeyExA
  • RegQueryValueExA
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetForegroundWindow
  • MapVirtualKeyA
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Interacts with services:
  • OpenServiceA
  • QueryServiceStatus
  • ChangeServiceConfigA
  • OpenSCManagerA
Enumerates local disk drives:
  • GetVolumeInformationA
Can take screenshots:
  • GetDCEx
  • GetDC
  • BitBlt
  • CreateCompatibleDC
Info The PE is digitally signed. Signer: \xE8\x93\x9D\xE7\x9B\xBE\xE4\xBF\xA1\xE6\x81\xAF\xE5\xAE\x89\xE5\x85\xA8\xE6\x8A\x80\xE6\x9C\xAF\xE8\x82\xA1\xE4\xBB\xBD\xE6\x9C\x89\xE9\x99\x90\xE5\x85\xAC\xE5\x8F\xB8
Issuer: VeriSign Class 3 Code Signing 2010 CA
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 461e1396f108dc4ae335d201924cfc2d
SHA1 84c146582fb29bee705a4ede5f96265274a6ddae
SHA256 a43594df66ce4e77a1f493e8b595f7848231bb78715b7706e3f6693c9ea6867b
SHA3 2d295c9e9259b5512bbebda031550d4b88148b8f078406ee438c643cae45a653
SSDeep 24576:Jobr421DMLVpg92fU/HxxCtdShZcDcTt+WEs9/zwn+cVEGTVDvMBJzlZ:Ko21wVpg91ZxCTgm1TFvMBJzlZ
Imports Hash 1911b38a1bb6d3c0f7b28959d2aa1786

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2017-May-14 18:40:26
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x123c00
SizeOfInitializedData 0xa1800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0002C1A0 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x125000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x1ce000
SizeOfHeaders 0x400
Checksum 0x1d2f60
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 51e55ebd074befa8225c2b2383b61d84
SHA1 75dd4d89137361b0415758eebf269eb4464d97c0
SHA256 6037da8bfc5f26442d6501d8ca1c7ba8e9120539f330eade5bd44b0cf1276bc4
SHA3 f5dff08a7756b2105bd24db7f08627050211ea68236fd4800c33b283a177b0ef
VirtualSize 0x123b14
VirtualAddress 0x1000
SizeOfRawData 0x123c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50391

.rdata

MD5 42a49e31e757074b015d4ae6e73d3d24
SHA1 b3b3ea57eccdc3124af954028275871d1b9a906c
SHA256 bd022036c20b372c542bdbf3ac8d78594e63af37e380dc1395ee810810322a8b
SHA3 ed3df57844442ce588f882a221b67f5b6a12eb281ca58dff1031f5aa90aa7cb4
VirtualSize 0x4a3e2
VirtualAddress 0x125000
SizeOfRawData 0x4a400
PointerToRawData 0x124000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.59497

.data

MD5 c3a223df4f02131bff73f6d0e6f946a7
SHA1 721f236703859212a525db035053f8cceb221c84
SHA256 f1a0644ee3287f82059f98608324f1e414ef85f38ba345d7cc1a381100c2f200
SHA3 5be842878afe19085f9a5ee66654b7b825c37d33c8f769ea0c54f2624e672445
VirtualSize 0xc23c
VirtualAddress 0x170000
SizeOfRawData 0x7800
PointerToRawData 0x16e400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.9849

.rsrc

MD5 b34afeb5634138cd0a6478b081013445
SHA1 3071c6eb07f3fd84f2e4c41ab9fa1de3f944c3ea
SHA256 7631c95583e076d359db92712e02019232f8f958cc6afaf999688453da375dca
SHA3 1f42ec251d487320d9e17d9a415ce11e36ef50f50dfe86be44a155712b686c99
VirtualSize 0x2c76c
VirtualAddress 0x17d000
SizeOfRawData 0x2c800
PointerToRawData 0x175c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.23173

.reloc

MD5 de24fbc41a6a8c562c6a69fba3e9adae
SHA1 9c01a3e13bc979f64884a62b7e2e9bd6905b8139
SHA256 60e91eca31030303928dccb0e29164072f6da8e9f70a9b612b84e93d47f89274
SHA3 2640594139f11e66d59455154fa33c6738f431217c4905bf1ef20923b40a47c7
VirtualSize 0x232d8
VirtualAddress 0x1aa000
SizeOfRawData 0x23400
PointerToRawData 0x1a2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.80491

Imports

KERNEL32.dll GetProcessHeap
CompareStringW
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
LCMapStringW
LCMapStringA
GetConsoleMode
GetConsoleCP
GetTimeZoneInformation
GetStringTypeW
GetStringTypeA
InitializeCriticalSectionAndSpinCount
GetSystemTimeAsFileTime
QueryPerformanceCounter
VirtualFree
HeapCreate
GetFileType
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetStdHandle
IsValidCodePage
GetACP
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
HeapSize
CreateThread
ExitProcess
HeapReAlloc
VirtualQuery
GetSystemInfo
VirtualAlloc
lstrcpynA
GetExitCodeThread
TerminateThread
ResetEvent
EnumResourceTypesA
EnumResourceNamesA
VirtualProtect
RaiseException
RtlUnwind
HeapFree
HeapAlloc
GetCommandLineA
GetFileTime
GetFileSizeEx
GetFileAttributesA
FileTimeToLocalFileTime
GetTickCount
SetErrorMode
CreateFileA
GetFullPathNameA
GetVolumeInformationA
FindFirstFileA
FindClose
GetCurrentProcess
DuplicateHandle
GetFileSize
SetEndOfFile
UnlockFile
LockFile
FlushFileBuffers
SetFilePointer
WriteFile
ReadFile
lstrcmpiA
GetCurrentDirectoryA
GetOEMCP
GetCPInfo
FileTimeToSystemTime
GetThreadLocale
TlsFree
DeleteCriticalSection
LocalReAlloc
TlsSetValue
TlsAlloc
InitializeCriticalSection
GlobalHandle
GlobalReAlloc
EnterCriticalSection
TlsGetValue
LeaveCriticalSection
InterlockedIncrement
GetModuleHandleW
GlobalFlags
InterlockedDecrement
GetModuleFileNameW
CreateEventA
SetEvent
WaitForSingleObject
ResumeThread
SetThreadPriority
WritePrivateProfileStringA
GetCurrentThread
ConvertDefaultLocale
EnumResourceLanguagesA
GetLocaleInfoA
InterlockedExchange
lstrcmpA
GetCurrentThreadId
GlobalGetAtomNameA
GlobalAddAtomA
GlobalFindAtomA
GlobalDeleteAtom
CompareStringA
lstrcmpW
GlobalAlloc
FormatMessageA
MultiByteToWideChar
LoadLibraryA
lstrlenA
GetCurrentProcessId
GetModuleFileNameA
GetModuleHandleA
SetLastError
GlobalLock
GlobalUnlock
GlobalFree
FreeResource
GetSystemDirectoryA
GetVersionExA
GetExitCodeProcess
CreateProcessA
GetStartupInfoA
FindResourceA
LoadResource
LockResource
SizeofResource
WideCharToMultiByte
LocalFree
LocalAlloc
GetLastError
Sleep
MulDiv
CloseHandle
FreeLibrary
GetProcAddress
SetEnvironmentVariableA
USER32.dll EnableMenuItem
CheckMenuItem
SendDlgItemMessageA
WinHelpA
IsChild
GetCapture
SetWindowsHookExA
CallNextHookEx
GetClassLongA
GetClassNameA
SetPropA
GetPropA
RemovePropA
GetFocus
SetFocus
GetWindowTextLengthA
GetWindowTextA
GetForegroundWindow
BeginDeferWindowPos
EndDeferWindowPos
GetTopWindow
LockWindowUpdate
GetDCEx
GetClientRect
PostThreadMessageA
UnhookWindowsHookEx
ModifyMenuA
GetMessagePos
MapWindowPoints
TrackPopupMenu
GetKeyState
SetMenu
SetForegroundWindow
IsWindowVisible
UpdateWindow
PostMessageA
CreateWindowExA
GetClassInfoExA
GetClassInfoA
RegisterClassA
AdjustWindowRectEx
IsDialogMessageA
SetWindowTextA
MoveWindow
LoadBitmapA
GetMenuCheckMarkDimensions
SetMenuItemBitmaps
GetMessageTime
UnionRect
SetParent
GetSystemMenu
FillRect
EnableWindow
RegisterWindowMessageA
PeekMessageA
TranslateMessage
DispatchMessageA
LoadIconA
SendMessageA
IsIconic
ShowWindow
PostQuitMessage
MapDialogRect
GetSystemMetrics
DrawIcon
GetSysColor
RedrawWindow
EndDialog
GetNextDlgTabItem
GetParent
IsWindowEnabled
GetDlgItem
GetWindowLongA
IsWindow
DestroyWindow
CreateDialogIndirectParamA
SetActiveWindow
GetActiveWindow
GetDesktopWindow
TabbedTextOutA
DrawTextA
DrawTextExA
GrayStringA
ScreenToClient
ClientToScreen
SetWindowContextHelpId
ValidateRect
GetCursorPos
GetMessageA
SetCursor
ShowOwnedPopups
InflateRect
GetSysColorBrush
LoadCursorA
GetMenuItemInfoA
DestroyMenu
SetCapture
WindowFromPoint
ReleaseCapture
WaitMessage
DeleteMenu
CharNextA
CopyAcceleratorTableA
IsRectEmpty
SetRect
InvalidateRect
InvalidateRgn
GetNextDlgGroupItem
MessageBeep
DestroyIcon
CharUpperA
UnregisterClassA
SetRectEmpty
TranslateAcceleratorA
BringWindowToTop
CreatePopupMenu
InsertMenuItemA
LoadAcceleratorsA
LoadMenuA
ReuseDDElParam
UnpackDDElParam
RegisterClipboardFormatA
SetTimer
KillTimer
MapVirtualKeyA
GetDC
ReleaseDC
EqualRect
DeferWindowPos
CopyRect
PtInRect
GetDlgCtrlID
DefWindowProcA
CallWindowProcA
GetMenu
SetWindowLongA
SetWindowPos
OffsetRect
IntersectRect
SystemParametersInfoA
GetWindowPlacement
GetWindowRect
GetWindow
DrawFrameControl
DrawFocusRect
SendMessageTimeoutA
DrawIconEx
InvertRect
DrawStateA
GetIconInfo
CopyIcon
CreateIconIndirect
CreateIconFromResourceEx
LoadImageA
LookupIconIdFromDirectoryEx
GetMenuStringW
SetWindowRgn
GetWindowRgn
SetWindowLongW
GetWindowLongW
IsWindowUnicode
GetDoubleClickTime
DrawEdge
IsClipboardFormatAvailable
HideCaret
ShowCaret
GetCursor
IsMenu
GetMenuDefaultItem
SetCursorPos
ToAsciiEx
GetKeyboardState
GetKeyboardLayoutList
GetTabbedTextExtentA
DefFrameProcA
DrawMenuBar
TranslateMDISysAccel
GetMenuState
GetMenuStringA
GetMenuItemID
InsertMenuA
GetMenuItemCount
GetSubMenu
GetWindowThreadProcessId
GetLastActivePopup
MessageBoxA
EndPaint
BeginPaint
GetWindowDC
GDI32.dll GetWindowExtEx
BitBlt
GetPixel
PtVisible
RectVisible
TextOutA
ExtTextOutA
Escape
SelectObject
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
SetWindowExtEx
ScaleWindowExtEx
GetCurrentPositionEx
PolyBezierTo
ExtSelectClipRgn
CreatePatternBrush
GetViewportExtEx
CreateCompatibleDC
CreatePen
GetTextExtentPoint32A
GetTextMetricsA
CreateRectRgnIndirect
SetRectRgn
CombineRgn
GetMapMode
PatBlt
CreateRectRgn
GetBkColor
GetTextColor
GetRgnBox
GetCharWidthA
CreateFontA
StretchDIBits
CreateCompatibleBitmap
CreateBitmap
GetClipRgn
SelectClipRgn
MoveToEx
LineTo
IntersectClipRect
ExcludeClipRect
GetClipBox
SetMapMode
SetTextColor
SetStretchBltMode
SetBkMode
SetBkColor
Polygon
StretchBlt
SetPixel
GetCurrentObject
CreateDIBSection
ExtCreateRegion
EnumFontFamiliesExA
GetDIBits
Polyline
GetViewportOrgEx
GetBitmapBits
PtInRegion
CreatePolygonRgn
RoundRect
GetWindowOrgEx
GetTextExtentPoint32W
GetTextAlign
ExtTextOutW
Ellipse
StrokePath
FillPath
StrokeAndFillPath
EndPath
CloseFigure
BeginPath
RestoreDC
SaveDC
CreateFontIndirectA
GetObjectA
GetStockObject
DeleteDC
CreateSolidBrush
DeleteObject
CreateDCA
DPtoLP
GetDeviceCaps
COMDLG32.dll GetFileTitleA
WINSPOOL.DRV DocumentPropertiesA
ClosePrinter
OpenPrinterA
ADVAPI32.dll OpenServiceA
QueryServiceStatus
CloseServiceHandle
StartServiceA
ChangeServiceConfigA
RegQueryValueA
RegOpenKeyA
RegEnumKeyA
RegDeleteKeyA
OpenSCManagerA
RegSetValueExA
RegCreateKeyExA
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
SHELL32.dll SHAppBarMessage
ShellExecuteA
DragQueryFileA
DragFinish
SHLWAPI.dll PathIsUNCA
PathStripToRootA
PathFindFileNameA
PathFindExtensionA
StrStrW
oledlg.dll #8
#1
ole32.dll CoRevokeClassObject
OleInitialize
CoFreeUnusedLibraries
OleUninitialize
CreateILockBytesOnHGlobal
StgCreateDocfileOnILockBytes
StgOpenStorageOnILockBytes
CoGetClassObject
CoDisconnectObject
CLSIDFromString
CLSIDFromProgID
OleIsCurrentClipboard
CoTaskMemAlloc
CoTaskMemFree
CoInitialize
CoCreateInstance
CoUninitialize
OleFlushClipboard
CoRegisterMessageFilter
CoInitializeEx
OLEAUT32.dll #16
#424
#420
#10
#161
#4
#149
#150
#7
#12
#9
#8
#6
#2
#184
#185
WINMM.dll PlaySoundA
COMCTL32.dll ImageList_GetIconSize
ImageList_DrawEx
ImageList_Destroy
_TrackMouseEvent
ImageList_GetImageCount
OLEACC.dll (delay-loaded) LresultFromObject
CreateStdAccessibleObject

Delayed Imports

Attributes 0x1
Name OLEACC.dll
ModuleHandle 0x17af94
DelayImportAddressTable 0x177770
DelayImportNameTable 0x16c9c4
BoundDelayImportTable 0x16ca00
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

15

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02695
MD5 cab67e9ca149fb79ab4473998412b951
SHA1 2e793d35537bfb5d3f042ed0626d3b119d50519a
SHA256 fbeb3be87e80cb8e1d2af3d8140796c1bb80c6c7056f60897088ff9e355c3867
SHA3 0e72f5537421764effb2ed98e536358bb7e86eed7b0936e606e8d45559685684

16

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74274
MD5 9fa8a914823ac7e5370652146901f4f1
SHA1 eb3224109abb341b6e464d2606fdbed1a7160bc6
SHA256 f64ccc0582bc7c66af8b40049e485e8e241335261ec95ace909293ba50b2e4a3
SHA3 bb348af06514e27cd1fa21ad524dfd037edcd3b36ef4cc6ab24c4a8ec38995ff

17

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34038
MD5 d78a341fa7444ba9ccb74ad0c943d0ac
SHA1 a3fdcb001587c47b72f06441087455e8027baca1
SHA256 652988945185cf5d604d9b48de66288d82d8ed0acdd134398e90d002d2d9fc72
SHA3 2ddf8193c735adcec9a83d3a9032dc70796778b1d0c967a43789f1a6bb3da15f

18

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34004
MD5 07618c451f53db89991c3fb7c567a568
SHA1 0d5cd2bb85bb88024b832f68bdbadd1e69938138
SHA256 0b0e16c38a3d5a85566e67b1d9a7e720e4dee27e163b06099d3d7dfa5dbed9ee
SHA3 f4d98de638008ce348a7ef0cb3feb13207cf5b3eaea4f1ee1d71b3a22397fba4

19

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.51649
MD5 9936fbf67a1d9f755c37852015d09527
SHA1 426016ba6a10cc2634ab7357e4223793c51aa304
SHA256 368f9cb089d206a8b61251f0c85eeda97ee08a56b33be8579246e964d3af6169
SHA3 6bdb1e7d667efe7812e162384a6341edec73311ee7dfcb122adf0cc0f08e7a8f

20

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45401
MD5 ffacff1dbee315221fd131e951d8e151
SHA1 d2eb9800a1f60d3ea7225fec706d809cf477885b
SHA256 6440c3a38dcfb81d45bc6be31b776fdae116dd7a2933b407b67132f6cfa0e6eb
SHA3 dbe125dd582d83c13a62c87798c900fdc43d97b581935e320c14f9cc761a3868

21

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34864
MD5 fa681900dd51c997aa67a2c5a4704099
SHA1 b48ebfd25835cb260b5e4f8e7085ea3da102c48a
SHA256 9882a8462ce9de3cc9a5d0ca48c8c4f7ca97f1f846f0c10e6655e33c9734b152
SHA3 157fb750ffc808227ced340c81ed1c1c1e15b05dd0e831678b871515870e0a8b

22

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34505
MD5 0a12283479aa8a8677dd27bb0f584a34
SHA1 63679153c4d14fc591d1286cc98ff5044a5b589d
SHA256 322e92d75b3fec9e16b81466f4cf111d298b80812d5b238f4ee032c025a02050
SHA3 d6fc5e08b9d51b2cc80c1a2a34ca495e28edd0ca1bc65f317958b773c675de7e

23

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.34864
MD5 d0293b6f84ea96f2662fa2f8e2fd44de
SHA1 240ad776d40208f067dda60701affa3d162cb3bb
SHA256 8db6df648274a0fc3d28430367216e1c17c364ca613066cbb0e133637e92ba62
SHA3 d92c1c2bfba803073152e14d6846474d13ccef3f04aa8670540389efa7c7d995

24

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.31114
MD5 49ca9d25ceb458297ddf84fff64c8d55
SHA1 fbd6d992b7e2a59c9e24372ea8d30a5dcdbd46f9
SHA256 f9c81ce9b4176b305c554a15f0ca2b98b11be76c1f13ef22169999aa07e9612f
SHA3 03f7002b636940864ef7d399ba60fb8de3f455da32f311ee39cdf6602c5d348b

25

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33609
MD5 27fc5529ad790189bbf410c7e3a70fb7
SHA1 ea2456c9b26f884a7f7abb051f460ec98cb9451c
SHA256 601635482a9b1864ea0c61ce0282c5c9fe1d014aa95dbb4f60770f1c2b6df3da
SHA3 24ab306744896452b2a7f7055c97671ab0aad3965342b3d0cead7a6cb640238d

26

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81313
MD5 858a63dc597812b0885e8a8f9689227c
SHA1 0a816cd0e6f10038f43bde278eb613f1c7281b33
SHA256 2bf742d2beb4c56dd6eb68347dd8ee28da85bed9e6d165b36c6edb91da01d5d6
SHA3 6974d714fd124f0de87b6f088039e52bcf3123b5e6ae24c7c61864b70b894963

27

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81491
MD5 ff43eaab521694d0356618a92cd83b55
SHA1 f1ed8d456a5a3d87d1a8349e992c99e22bf3624e
SHA256 cfc4ff9e46fbb61f61b68f36adc6593b137233d1cbaa50fe37e5653f0cb20396
SHA3 7069692bfbe0c043b33390a40f8033c3d0aa3092c3b1ca1b01fc899dc760ec48

28

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10016
MD5 4bfaa5ad112338fc90bf84b1ba21859d
SHA1 f175fb276720b4f98bc75dd3edc8c53ed563bdf4
SHA256 c4a6e3a7a346baecb09a0c49268eb44f388382a7866a4e912b53d48fa3b34c26
SHA3 eb1f5efadebebc4b756ef49661343ee08641f53184ad8ee83e33d6665028a00d

29

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.97052
MD5 654a61b5fd300aaf86c52a3c48035005
SHA1 e16bdc1b4309abd682e2d0b52aaf370a77ad6a86
SHA256 f273e554605a89aa0994c9d42bc2569be3db5b19b2900dacb30f3218ed1174a0
SHA3 50582dc2bd6d1a2632564b2d3c6fdc1877e401924754069bc2dfccf3e2896340

30

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.22699
MD5 b6946159ef4680b2b03d58bdf3dc83f6
SHA1 b949690a6e071a1fe43cb83a15d5104d1fa9fe0d
SHA256 ebaf4bcc0f0d7ca9a3458ea52520d2dd10811069241940b9b2e79ac1a4c3ca5c
SHA3 4b1152fe0fd4581cc8716682bff8f14d7c903ab6b5414d52876bd37fc58eb0c5

30994

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.23666
MD5 8cf65be17e506ff24c2177078f88b56e
SHA1 3e397dc7597caeb844df0ea760b64231c8ce3dbf
SHA256 e7c0005285d1ab59732d5f99f77a9bdd6342b01cf44437ebd7a07611a227e272
SHA3 7da4c7aab356574679f0f9107740f01647864c846c04f699deef67577fd6aded
Preview

30996

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87621
MD5 5a9c81cdbf480cf01daa71ba0e233c5f
SHA1 28e04c01584654e1974347d1baa462b2784e9c47
SHA256 abdf36bde89a26349f5741c17c235dacea88d441d8662ba16a598dc50c3c4864
SHA3 99dec83590ac444359a5a6f8924dae5615d93f4df527e10a8a61319ce3a5beaf
Preview

1

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.55217
MD5 882fe897aa0e5c40634c172a22acc98c
SHA1 62b3b62655481e072eea4bdfd71f906c02f7146b
SHA256 0c5b7409089a881eab816d79180f6ca05daf11de28b5e223387cea88377d5bd6
SHA3 6414485a8e9f1570c42f0dfaae41e072c8ceed814e04ecf3e3b385455cc9c580

2

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75319
MD5 8da1e30b59fc3e3169f7c3082b5919a9
SHA1 a3782a5fa8c590126b18f4794f5b6765892c8363
SHA256 84d740ff290d33e79cbefb59fb54a01701fdd7067c9179b61022f1da81eca995
SHA3 eb5b93a569f86bc5681c9ce2a3bdf7d8ccc14c1320a60ef3711972474551b34b

3

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.6425
MD5 398c8b58549bca44daec8b97087b97d9
SHA1 631651d89a7be292c443ca548dfd365c0e04eb56
SHA256 3804f0dec171b8e24d4831f8f4a053c4b0f2073091b45d9f7a2c24b0925ee5e5
SHA3 498ae94f314ba47e02b1ef7d79caeec830c00bf3821bda9310cd68e2542ba553

4

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23092
MD5 44f56c345b783f31717f396672ac30b2
SHA1 b121dc80da2b02436d95e6823d08f4b2aaf4afbf
SHA256 708e8125f87da7aa98c5f684fa3a9eef815128f35d7ab405740a2a03c1d029bb
SHA3 609731f5add56ef50a68ae0f84d8326b7127978b7528120ffc977792653f394a

5

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25838
MD5 c418dc7f308f3df2a62988b2b1f6b69e
SHA1 06bc0f4ce8e48b6e30e9fabb084f1bee58ccac96
SHA256 800bece7694b517b94dadbc73ea006ff4f84adb6efd2a8e93ab4aaa0abb2f28d
SHA3 e2114650099d52007fc41b640911ee2a4a86f9d87380d03608e090859f3b1100

6

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.75882
MD5 c07c7b774e51dd9c8443260f51db7bf8
SHA1 c47008586068e817da25925cf4210f5e26f2ab68
SHA256 e7a93858294b6ddfe16223a1b3c2c47ba0ae2512cd6de5157eee45d712acfd25
SHA3 95acd59ce89c90650e78e1eb1d557c15a70112119492df8306e7c65394a3c148

7

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.79129
MD5 7cce79b6e671a925005a28bc135ab45b
SHA1 d42701161f85fe7fac040271a28373aebb948879
SHA256 75c82cdc31db816bbe3bbe98c7c3ca460c8ba274eafeffa4424c2d980d9d40d7
SHA3 baca84ad0db7ce7fbfe267ad60eccf8b980d7f20f1e8bca04cc5c3d825d69086

8

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.94501
MD5 5c0849e037bbd514500db3d60e34d56f
SHA1 ba43f712c86bf60de7194dcccd016bed190dc36d
SHA256 eb4530bd1fed452052b1b1a993f1912e4c9ab4ec428c828d8cb7570df30733b4
SHA3 6438ba53b97cca7491df1db3df94531f0d2f96ef0af456e44f26418d17b35222

9

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.75095
MD5 42e9eafd4a02d9ec7e0049fdcc38e779
SHA1 16a522d66434c1e55b13e7ff76236eb7e2e80831
SHA256 481462c89ff55b252a1efc19d6627548286d4213ba5f4ed0adadb97a5389e7d6
SHA3 7f8ba4a26bfb9c1d66e9f177cd403446c5de99813620534b4056ab3a0fe7a06b

10

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.88239
MD5 ae23abb3457b1a678e7906c79a8b3442
SHA1 ea1ed0226ba503d8c6cac735a878d9162b6da723
SHA256 e4a5c08da68f59fbfcf4431b14d8457119ff5ca17f9ff26c9f5b95e390da1eb2
SHA3 294ee8101b389118e9188382c13b0e951121cb5106e1ced4bbda3471439a3727

11

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92081
MD5 eaaf04289ea9a9e1749922e25e99779e
SHA1 388e671da855d44d654537789c4830f55b1db438
SHA256 b1919f1deb5bb4f0dc923ee6661bf2ca372c8a54a111c6e71b0e175cdbb886b2
SHA3 be56ca92e4ff079192efb2235d793bc666cef0f34efccb518659607c33cee7f3

12

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.9278
MD5 5b925cb7c874f9268dfa1839253e29c4
SHA1 cdfc48df6d152d1d6672cce0be5f1024cd6bb4cc
SHA256 630f337937ac9ee61dcf5394022e6a00f4f100ddbb3dc674d083466172311c53
SHA3 fa11d5fa21cc8ec9fa2a0b471b8d4d378c9f62cac5a0186618a95fed6245d423

13

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87445
MD5 215c814268dd6294825f4c86c6b36ad9
SHA1 9c74c93813893c64e39e1bb838fbb68f804be5b2
SHA256 7a075fefceb77d685648ef3ca64a88f1a49fe3305b47e726d7c0bd82dbb8ddd0
SHA3 d997170f0e479312e35157c2900cac08cae8bb5e8260829ca25611ae7b1d4afd

14

Type RT_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.11503
MD5 b9e0ff7b97e91ee3fb544be534a8466c
SHA1 9af02e79658d3f076d0a557f97aa2cb4dcc0d41e
SHA256 a5cd26b8e11561fbc8aab9f551eb77dc8c625cfde26476a729ef66e998b4feba
SHA3 7352a6412fb5c65fb91fc66af4f6503e4e67fb7ec427397fd6ce641ba6d829da

102

Type RT_DIALOG
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x394
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.48408
MD5 a846c09e66f0bc5408a5daea5fd74d4f
SHA1 88636acb131902bdaaf08f797750cd2369be5b09
SHA256 13f9d9565e320ea39e727f481d86b6a40f459c9173ac42c585d964cdd1fca267
SHA3 16e61f5d2f8b452e49c3789dbcb4c355dabb53960518f8a1c9d3d60a7c425b21

30721

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06676
MD5 ad7b15160c8bf80910606d417f40fef5
SHA1 9752acb8e012635c4356f7f2a20191d656b53faf
SHA256 6e113fd8e9f3156ae68251c6076beb9b59fe29e589d06398e7019802521f69d3
SHA3 50c74f1eeba91cb4ecc237c0b18cd2f6c0e2b6064e8d13ce1a779160c03b5d48

30734

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x34
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.41669
MD5 72723d63b211c60717138184c1675b66
SHA1 ecd2be6587bb32a080e51b5c3f3a816e8b637c85
SHA256 4cf716efaf68e0cb2ec45ec55d291050b5712b05653cae68edbb999f803d2a98
SHA3 6031fa1100e39d04c89ed42890fe9833adb0503fe1857940533b7356aec9d306

3841

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x82
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.81705
MD5 8bb814f43734537868736a6df5dcc012
SHA1 3ae7a8f8678bc2aed76f745960730097032389b6
SHA256 d91dc4e26fd86def5ee907c72f32457bea07d21fa618012245f641d08501548d
SHA3 73fabbc3aad03738eda288b6d45b076e7f94f1ff8de37df5ac4d6e7dc7a48f98

3842

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.960953
MD5 0131ce1c2237957b6926d5097b0af63d
SHA1 2ce37b98065cc4de92e99eb0777e0e1159102068
SHA256 05e0d5787611ed4f643733e3e6e62d00f426422b5d3e443ceebac22e9d294bc4
SHA3 9ee7bcb02f48332a4fac72465297312ef9c765b03edf2ab24a4b3de0840bda6c

3843

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x184
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08634
MD5 58655591099de216feb4cc512012d318
SHA1 4001db00e1535b26b506e6d033e9759351ae6874
SHA256 9665348f07508c6c2a568fc90ec4c04736668adc3521e311a4c7659973d92313
SHA3 296c00546a67204c06806ff85a9e3e065559b2b85b22fec4166afc19cad4b6f9

3857

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4e6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25779
MD5 3c0e880ffca8f519b51579c8c0825858
SHA1 24a521aba0485f373d4d8993d704c86e556bcbf1
SHA256 0519d7704cb64bab3aeca7c3b96affd55641099a2a162e88537cb1b8dbfcd540
SHA3 6d04d7acb581fbf887f75a077583ce66c949d3f197bfb8445aab6ff2ba93fc01

3858

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x264
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11275
MD5 3dbecd982474b9072ecd4aefe7406857
SHA1 ee81b0d03aebe1cde90de59031771f416d29eef2
SHA256 eaa0b4fe4704e193dd2ed1f8de1cb20e1001034fdb30307ee44aa664966d4ffc
SHA3 9053da012393a18a8a9012e2ab17735c7c864f0463086c9439c3a74a37ed7ee7

3859

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2da
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16694
MD5 9e3221160c33e15054ff236daf2263d7
SHA1 cf41e0cdd3377698f819c4ef95ab56de40c57a5a
SHA256 cffcd4956911b3d50eef378cb051e598baba0db48246b07780af03b01c67c64d
SHA3 663e17de8922b049f83fdeca37a68d626bb83566bc377d85be42c653707a2b74

3860

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.71087
MD5 5988b72b85cd1c121906b20e7526fdf2
SHA1 45efa4995e9c25a32e3f47a15b63a813cc6e8fc4
SHA256 35b5abb90316b4017d5531e031cbf15bae6e8dd46f6dd221701693a22a7795be
SHA3 afa115b83c9f9b2f16ce1e14424b4e2cf6216cbcee84835e0b5cec4a23510a93

3865

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63903
MD5 5fbbd2a5f564e043553889eec9147920
SHA1 2ddafabdf2bf5b62090419f07f731c4d02f0d987
SHA256 1b8660b0c53b94f3e029de58e56d08c8097a080244e9dc65d4155a9b603820d8
SHA3 1a90cf149f1fc5cfa9cd3f82f9a079ec48c7f7ce76dc4be601e538ae5c052ab9

3866

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87807
MD5 a0838b75a6ffc345212d18178663bb7d
SHA1 a90a0eccdf4cc4c50f430195695a3b65adefe5e8
SHA256 31bff9afbf08a8869318cd946a1d73a4425afefc5693c6e06671bde1e86de1dc
SHA3 ad576d2bedb8e173fb207310f244bee3ad8c898a2101cb67da930fadf80ec7d0

3867

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24671
MD5 7e0e2d984d6d743b4d90b04758507505
SHA1 bec6af6197b875caf3064c7e053b64044904c1bb
SHA256 2b5551644093e58a4af74928fb744bd735fa2ef5f99824e6918ff9f6a33a3803
SHA3 08f040ebd50cc1809f91378999331d0d19e7364612041db3805a0ff1d37050e5

3868

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10695
MD5 cd11e247927c7360d3447bbb2e01d326
SHA1 0e6b76a1cf9824dac91fad3a346388589987cb9a
SHA256 e9212b16f2d3292d0b0eb67134a70778ff1b0aede4918831e5bdba3f950db2a7
SHA3 7a0a3e741ea89b752fca14451f1e9b9ac5600d99a7408d04c7835e30688f8fcf

3869

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.07875
MD5 4b18eed800e2806db8e0aacb95fd54f2
SHA1 8b09634f818d6823f6466717f3863cbb466d97c1
SHA256 0714c554acd308b38c3d6319f7e470f76a16d712f696545eacac2bdc725dfb95
SHA3 067dea0fda55e331beab407da1e0e79a9d71fe8a8d0c965384d459ce0a8d499a

3887

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x42
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.95964
MD5 c65b487f823c0a91a2eec94148eb1ff6
SHA1 3fd26a7911c5c5d45d0dfc94dfd2fd11a1fd1574
SHA256 1f1b61a7f04edc3691a6c9350132b09929d5bfa1c900f6ff500e55c5ebc63212
SHA3 e89fdaf864b56d3012a7c4518ff3db5dee97ab11fa819b22076973a8f607d95f

30977

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.19569
Detected Filetype Cursor file
MD5 4411d5205fccb9f6f346a2e71bc323c2
SHA1 cd3ca1ae43b600a1bbbf1b7f68f8b3256262de62
SHA256 685f7696b8ceef18c313834e7143e74e981d61df0634c856e43700ce807fae85
SHA3 407fd3d0fe65e95fef14e0c5ceba028115917b089bf4ce727b39ecf71feb936e
Preview

30998

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 690a20e696fc4e33ffb377a8ef54fb97
SHA1 972159605fa069921dbdee9b7a35879e6f1928a6
SHA256 6c2ef97bca5cdc6aa6de65b1f1ae8328bcb3494a16025eee870231d991e2cd56
SHA3 fd9d56519b5bf976a4ae748fe0c51dcd47ac27ce6a7c271fa2bbb3e00f473b22
Preview

30999

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 8e242da1769c2307f276e393dec0e7d9
SHA1 da604259954e8cda5931a679e081bfad9a9fd772
SHA256 ee63d4681e7622067fd29005c6cc67b456031eb723c7239f05f1cb097af0ef98
SHA3 e6021bdef60731a607f9445b3c004fcdac812f44b42aeb8e32fee72204be4572
Preview

31000

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1e219dd609ce399df95ba7af59ef113f
SHA1 436a16dd20d5e3ec42342a4d005a664cd227f517
SHA256 8f51832638675f16ec5f251ab59251b3f85d84e5129025d44c45b3191b331c58
SHA3 9e44adcf523bb484f416a99197d947211027feae6b6665b457883e548218befd
Preview

31001

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 79bc23c45190436b2c51ff2941fa8720
SHA1 0a8234176fad8831709703a0a34337a08987a983
SHA256 b328fe22a904a2e7e1341a95dbf00e2fdffc9ab350bc64c5ee348d3007c2b479
SHA3 b897f30ec85dad865a74be84cd616e0066da486befd0983d87e2b6f5d66a6c6b
Preview

31002

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 b17264d20faaa8ae0bcfffd2a28b5821
SHA1 cc3a0c683d3a70e81de9bd8dca7c7da25df1ec9a
SHA256 04fe4c49379fb61d65560745031cf797d5234fbc2886e1ee5245141e3f71cdba
SHA3 b9748f87bc9a8bad6f25bd2088709ce4bf07c044674cd302e3cc76e3bc878a83
Preview

31003

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 8408eef234acfcac8a26e706cc35d85c
SHA1 5ecdc1e1be3f1e941b1ca11b45943aafe135c517
SHA256 3f02dcac38fffe306e1825846e2bc0458ee712696310d051e3a69ebda8330cc3
SHA3 0406ff4480e84661d58a225cdf84931c95f7ebf6fea388a3cb6bedbc0343b421
Preview

31004

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 2fbccba7b754792dfc2070456e66fbd7
SHA1 6017f22c993c7d724876e35e8c54e7c4603eafae
SHA256 60a0a8bc0169228c8af42c377d93a218ccc9712a17b76ef014f81e156a36c66f
SHA3 f1edf8c8df156e449682ec443c0a87232b94e17062148388949ba84b7eb55227
Preview

31005

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 87f676ebb80763bfd77a413c2fb00f0d
SHA1 23736a18a1d4330cb9ea762fb7deaef881b6ec2c
SHA256 da738753c27f2708bd2257f8cac3385a4ccb0df1341b76acfda07fa980cfb4bd
SHA3 d90e5655540ffc0671429e2c3ff78ba0f7a100727622de4185f897a4aa996c3b
Preview

31006

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 459379b9418ad5b62b1bf409300acb32
SHA1 5363fc84172d6b624542a0b52edbbfe21e2443ae
SHA256 1085b7390dbd2b2006f85619521047c6ca58a8b274196eeed48e74ad8a1b746a
SHA3 2b8f3218d3da7e4ee463a712c6c3b8f5b58cc6799a84f5e582b6a40da38a2bfc
Preview

31007

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 eaf1b83c561a97555fc0cde38891a389
SHA1 29eca824a284b26bb760963ad84bce64799dc770
SHA256 b077d477d0775d0b86be9bedee8ec134bdc213d6941e9ae60adcf8bdd18623cc
SHA3 2f4c2fa13d5c6dda7479c65d1e74e7d1977e50560f25c62b466daad9e75722ae
Preview

31008

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 79ae5478465a9feb537afcca01f560d8
SHA1 48a70a0e9667e0f1726a2bac4c971616e1980c1a
SHA256 90b143ec83ef48639ea48969a1d0850aa14b573b48dadef87e4230e42bdb5971
SHA3 db5dc137de891f95ecec33bb5ab37284a6b6e93c595a6892970111442b14c483
Preview

31009

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 d3d02cf14dbfe1523c1ef143cea3eb85
SHA1 af4b9b5a7c69ac8682ec367b7873e0ddbc5acf40
SHA256 a9453e1af624a62f80defdca32aacf5bb0e031e40db0bcaba38707b209354914
SHA3 71fc8dced4a4b7c0d8aee098303fa90f4832bb4092bf96393fbb47d267e2ea5b
Preview

31010

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 c8872a05e76e0ef00f1eae141c9035b7
SHA1 dd2072409381c136906a4ec3e7a313d469061703
SHA256 6963da9b0f501c836ec1faa3291509c14f590e21c9dab60334935b82bf96ed2c
SHA3 f0a5677f68149eadaf661d29b05e710554d8701e3eb134487273b48b45995b69
Preview

31011

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 975596b334c3811a6899d17dc1083c83
SHA1 77adb688a202706cd60619067d29413db049e2c3
SHA256 749de8c6268f233434feebbff1f5f5539d32cb07e993e3683224a191a035362e
SHA3 f71229575da7bdbcc657ce7b3d0ea4a9395a2a1c748478c6d01ff7cc47ba620c
Preview

128

Type RT_GROUP_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0xae
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06492
Detected Filetype Icon file
MD5 9f09cf7bb38a28604b82294714b5aff8
SHA1 92235b3d49fd27218a58fbfad27ad6a619b54ffb
SHA256 d2d8ccd68849e94ea6b84f6835d0fe98ffa5c11e74a1138529e3c0b8d8edfe60
SHA3 31d634f42904a006333aee6a5258ab8c02eb1729897f4083ef50dad9565e0da3

129

Type RT_GROUP_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 508d76515c0fda7c5a2658410a6e6d8f
SHA1 d94946f2eda18279e4d19fb873ac50ecedad7a21
SHA256 4c1af557de608cfba2d64f9d2d55849efc0c50b6557fc21c1ec2017cdb025c11
SHA3 ababb9605d8500131a2394c629903105c8ab6c43df4d110bf3ea543e7664e7ef

131

Type RT_GROUP_ICON
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 bbcb9203bb9474bb57fadd22b9c17f60
SHA1 4c325935f5261050ab09019ba34d9fa11ca86ecd
SHA256 46ecba999e6b9d80f61dc63fc75784280010ed11fad46a53cf64a6186638e0bb
SHA3 6547aaf12356af8ed280250094b29e8ecf0d4d25ff6b05b56f3087446065e0d0

1 (#2)

Type RT_VERSION
Language Chinese - PRC
Codepage Latin 1 / Western European
Size 0x2b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81899
MD5 82a31345decf24cc006e8d3201351526
SHA1 45f92119f7d31bb8eae0d0f396c13b51f98befd1
SHA256 e55ad8b20051602440dbceabf859ede58c975e0ed60e257bc88f8a831eff0813
SHA3 b90a017e7922b6f19d910d94a45032a644575d8771b6322be3c58641379a9f10

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x165
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.77792
MD5 b9b507d6297b2d514477db4ae0d55ea6
SHA1 e8c4b4e815c1788b3bab96fc44560d7282282fe1
SHA256 ec5d04c8ef3fe0e571c8e604bf146b393108cee11f1ad3d665b7501ec20d37d0
SHA3 85e8c59b71094f3ffe0990fe28a56df78d58756dc3a423284dff50f92ed7fa6f

String Table contents

Open
Save As
All Files (*.*)
Untitled
an unnamed file
&Hide
No error message is available.
Attempted an unsupported operation.
A required resource was unavailable.
Out of memory.
An unknown error has occurred.
Encountered an improper argument.
Incorrect filename.
Failed to open document.
Failed to save document.
Save changes to %1?
Failed to create empty document.
The file is too large to open.
Could not start print job.
Failed to launch help.
Internal application error.
Command failed.
Insufficient memory to perform operation.
System registry entries have been removed and the INI file (if any) was deleted.
Not all of the system registry entries (or INI file) were removed.
This program requires the file %s, which was not found on this system.
This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Enter an integer.
Enter a number.
Enter an integer between %1 and %2.
Enter a number between %1 and %2.
Enter no more than %1 characters.
Select a button.
Enter an integer between 0 and 255.
Enter a positive integer.
Enter a date and/or time.
Enter a currency.
Enter a GUID.
Enter a time.
Enter a date.
Unexpected file format.
%1
Cannot find this file.
Verify that the correct path and file name are given.
Destination disk drive is full.
Unable to read from %1, it is opened by someone else.
Unable to write to %1, it is read-only or opened by someone else.
Encountered an unexpected error while reading %1.
Encountered an unexpected error while writing %1.
%1: %2
Continue running script?
Dispatch exception: %1
Unable to read write-only property.
Unable to write read-only property.
Unable to load mail system support.
Mail system DLL is invalid.
Send Mail failed to send message.
No error occurred.
An unknown error occurred while accessing %1.
%1 was not found.
%1 contains an incorrect path.
Could not open %1 because there are too many open files.
Access to %1 was denied.
An incorrect file handle was associated with %1.
Could not remove %1 because it is the current directory.
Could not create %1 because the directory is full.
Seek failed on %1
Encountered a hardware I/O error while accessing %1.
Encountered a sharing violation while accessing %1.
Encountered a locking violation while accessing %1.
Disk full while accessing %1.
Attempted to access %1 past its end.
No error occurred.
An unknown error occurred while accessing %1.
Attempted to write to the reading %1.
Attempted to access %1 past its end.
Attempted to read from the writing %1.
%1 has a bad format.
%1 contained an unexpected object.
%1 contains an incorrect schema.
pixels
Uncheck
Check
Mixed

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.1
ProductVersion 1.0.0.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Chinese - PRC
CompanyName 蓝盾技术
FileDescription 蓝盾技术
FileVersion (#2) 1.0.0.1
InternalName 蓝盾NSA免疫加固工具.exe
LegalCopyright 蓝盾技术 All rights reserved.
OriginalFilename 蓝盾NSA免疫加固工具.exe
ProductName 蓝盾NSA免疫加固工具
ProductVersion (#2) 1.0.0.1
Resource LangID Chinese - PRC

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2017-May-14 18:40:26
Version 0.0
SizeofData 113
AddressOfRawData 0x156220
PointerToRawData 0x155220
Referenced File f:\MyProject\MyProgram\bdhscheck\src\c\WinFwTest\Release\蓝盾NSA免疫加固工具.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x571610
SEHandlerTable 0x560d40
SEHandlerCount 710

RICH Header

XOR Key 0x9adf4418
Unmarked objects 0
C objects (VS2008 SP1 build 30729) 20
C++ objects (VS2008 SP1 build 30729) 130
C objects (VS2012 build 50727 / VS2005 build 50727) 14
Imports (VS2012 build 50727 / VS2005 build 50727) 27
Total imports 735
ASM objects (VS2008 build 21022) 45
C objects (VS2008 build 21022) 174
C++ objects (VS2008 build 21022) 217
138 (VS2008 build 21022) 10
Linker (VS2008 build 21022) 1
Resource objects (VS2008 build 21022) 1

Errors

<-- -->