58ccb46f63dc617ac25ab7ab4c6702bb

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2015-Nov-06 03:21:22
Detected languages Arabic - Saudi Arabia
CompanyName Microsoft Corporation
FileDescription إعداد Microsoft .NET Framework 4.5
FileVersion 14.0.1055.0 built by: NETFXREL2
InternalName NetFxRepair.dll
LegalCopyright © Microsoft Corporation. كافة الحقوق محفوظة.
OriginalFilename NetFxRepair.dll
ProductName Microsoft® .NET Framework 4.5
ProductVersion 14.0.1055.0

Plugin Output

Suspicious The PE is possibly packed. The PE only has 0 import(s).
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA
Safe VirusTotal score: 0/67 (Scanned on 2018-06-14 13:07:48) All the AVs think this file is safe.

Hashes

MD5 58ccb46f63dc617ac25ab7ab4c6702bb
SHA1 18e614e249726d7a2148eceaf0217537fafdb362
SHA256 5e2b3f9767ce19f9be49ab33d710938b00dbb0a7c8b50fb927fd2917b64d32eb
SHA3 a55bb2bcf948902e09a2d6521aec1af60c351d0967998b0ba9700fd134b2da6a
SSDeep 384:jWoQWYrL+BA0GftpBjRlKW+ILKHRN7bYOdla3OeUdCXTXGhDcXLz/:D+6FiJTmruOMXT2u7r
Imports Hash d41d8cd98f00b204e9800998ecf8427e

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xb8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 2
TimeDateStamp 2015-Nov-06 03:21:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0
SizeOfInitializedData 0xa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000 (Section: ?)
BaseOfCode 0x1000
BaseOfData 0x1000
ImageBase 0x10000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion A.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x3000
SizeOfHeaders 0x200
Checksum 0xe5a9
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 d78844d4a6c927b9c9772ce22000a6d3
SHA1 366863ccc5f5cd7ebfce3ab3958ae4c4ff957463
SHA256 f045043a164df9919df138e169a6083da3b21524500bcdf06a5529bd38c2864d
SHA3 2400e043eb9a60cc7b8651285d4284d4910e064968794b4940eca80823ba8519
VirtualSize 0x70
VirtualAddress 0x1000
SizeOfRawData 0x200
PointerToRawData 0x200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.984498

.rsrc

MD5 4b52ea167531895071f2bdd5700b7613
SHA1 6cbb492dc513d1b141b692858073d036b49f27c5
SHA256 a9f06dd04b0e02be50d4042083e966c21878031ceade2f03f89e03853b591479
SHA3 8330b3230c738e3edd01be31b01c52cecceab9faacb74ef6460b6a000f8f78e9
VirtualSize 0x1000
VirtualAddress 0x2000
SizeOfRawData 0x800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.25344

Imports

Delayed Imports

19

Type RT_STRING
Language Arabic - Saudi Arabia
Codepage Latin 1 / Western European
Size 0x248
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.81265
MD5 9a288fc88595be67a4d528b8b2c4fb0f
SHA1 6b55af9f61ec7de4283561c7d94f650213d9bd19
SHA256 3235d39825470e8c10b1125d6b7aafc022a99a10e3ee1432e4afbca00678fe22
SHA3 7771558d14a40bc476f771a713b4f69ea1cc1a684bb9cf8a9568d28562f8ddf2

20

Type RT_STRING
Language Arabic - Saudi Arabia
Codepage Latin 1 / Western European
Size 0x78
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20479
MD5 bab7bbe7fa4e77cc4cf5926cea373a1c
SHA1 4a58f149b6bb7a03bcd94f5191d1dfb4332a39c0
SHA256 65470573ac47dd4ea6fd9d4871f5c4dfc0ccea4e38ae9a4c83388e597a204176
SHA3 f19b5ceeb474a16cb76c7952078a6ce7a8c35dfd41faec7215706e82b376a1f7

1

Type RT_VERSION
Language Arabic - Saudi Arabia
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.68589
MD5 3043ee5ca2139473bce71e0f5dc75653
SHA1 184ddffc78b05b188d202c6edd9cbbbaa86011fe
SHA256 b29444044c0676650c9b454e270290c71f2eb2adaaf216663ebde381ac487915
SHA3 2e790f623cb54d354dd01916d656cba88c8ba110870ab213fdb2076c8830cedc

String Table contents

Microsoft .NET Framework
‏‏اكتشف الإعداد ضرورة إصلاح الإصدار 4.5 من .NET Framework. لا تقم بإعادة تشغيل الكمبيوتر حتى يكتمل الإعداد.
‏‏الرجاء إعادة تشغيل الكمبيوتر لإكمال التثبيت. إذا اخترت إعادة التشغيل لاحقًا، فقد لا تعمل التطبيقات التي تعتمد على .NET Framework بالشكل الصحيح.
‏‏إعادة التشغيل الآ&ن
‏‏إعادة التشغيل لا&حقًا

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 14.0.1055.0
ProductVersion 14.0.1055.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Arabic - Saudi Arabia
CompanyName Microsoft Corporation
FileDescription إعداد Microsoft .NET Framework 4.5
FileVersion (#2) 14.0.1055.0 built by: NETFXREL2
InternalName NetFxRepair.dll
LegalCopyright © Microsoft Corporation. كافة الحقوق محفوظة.
OriginalFilename NetFxRepair.dll
ProductName Microsoft® .NET Framework 4.5
ProductVersion (#2) 14.0.1055.0
Resource LangID Arabic - Saudi Arabia

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2015-Nov-06 03:21:22
Version 0.0
SizeofData 84
AddressOfRawData 0x101c
PointerToRawData 0x21c

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x8d39a6f1
Unmarked objects 0
Imports (40116) 1
151 1
240 (40116) 1

Errors