5b5a46e9b0bdd2c6397f2e4bf55f22dd7f8ed05991821a4dc2697589d6fade84

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages Russian - Russia

Plugin Output

Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDCEx
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The PE header may have been manually modified. The resource timestamps differ from the PE header:
  • 2012-Dec-10 07:46:20
Malicious VirusTotal score: 3/55 (Scanned on 2015-11-15 03:18:39) Bkav: W32.HfsIemusi.7260
ByteHero: Trojan.Malware.Obscu.Gen.007
Qihoo-360: HEUR/QVM05.1.Malware.Gen

Hashes

MD5 a6342b64f433f8703807eadf2ba30167
SHA1 f0ce344d453075c9c1b70e520ec7adb0aa79957d
SHA256 5b5a46e9b0bdd2c6397f2e4bf55f22dd7f8ed05991821a4dc2697589d6fade84
SHA3 c3e4f9dcf76670889eadc4a684675404bda37b0ef4d064bf4cdc498906e62356
SSDeep 12288:JK4/0cLZjZ7Pe5Anpy5nZpOUaf8JGF7NdKbUJOUlAnZGw:JK48c77PeiyxOvrbtJOHnZT
Imports Hash e766d5e52c58b649519298d28a1b91dc

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x93c00
SizeOfInitializedData 0x1f600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00094A34 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x95000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x338b4000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 56047aad944f99a3ddadeabcacdfd36d
SHA1 ae1b85430813fa00ffc5c46781260a7922f22d69
SHA256 97b5afa7339cfec1e9fa80385930247f9ef4725979541a28ec63929494648c65
SHA3 20813fc90b491016dca6432bd4259c8a0759194fd0823524bf8c06653722b426
VirtualSize 0x93ac0
VirtualAddress 0x1000
SizeOfRawData 0x93c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.50502

DATA

MD5 987a0dc9ecc72e4a8bb629173f7782a0
SHA1 c86bf3d338fbd9a3209a7b03e27f0be61b279dd1
SHA256 9356b537a9d1bef41b52aeb39dacb14327fde97ee17e2bdedcac2e3857f63122
SHA3 8c5e22a8e296e8982bf7784512fce1bbb306437046b2542c815a9f06224a9373
VirtualSize 0x1f0c
VirtualAddress 0x95000
SizeOfRawData 0x2000
PointerToRawData 0x94000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.39325

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x337fba71
VirtualAddress 0x97000
SizeOfRawData 0
PointerToRawData 0x96000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 72c7cb0ef1c798b33a9a3567be36d45c
SHA1 13d1abc2161a69455c1a3a89dc504753ee05d87d
SHA256 2fead326a542c24c19044350539304bdbac25efffc4322cf581e4b9f80741d5f
SHA3 8679937442ca2a07f0122b663073787d9fde738d7e52f03cc509f185b5141b78
VirtualSize 0x2690
VirtualAddress 0x33893000
SizeOfRawData 0x2800
PointerToRawData 0x96000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.01979

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10
VirtualAddress 0x33896000
SizeOfRawData 0
PointerToRawData 0x98800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 4105e6c8daba7d7fd0a6f6df20a37335
SHA1 f0505827ce19f056f8f2efaf6af2f5af41d9339d
SHA256 11dbbe52027978f82ec643234d9d6d3142010370503743b84935093dec00e9dd
SHA3 e8a2619f9c0d270ca063dbdd00ccc8f7be60c7e72eead31091c8fa995ba54783
VirtualSize 0x18
VirtualAddress 0x33897000
SizeOfRawData 0x200
PointerToRawData 0x98800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.258612

.reloc

MD5 4f10deb7964941960c4053b53e307010
SHA1 8b8879800538fc954e113b581231de44ba263af8
SHA256 d4bcff8ab972ccd0349687349a269f8c47f0fea150397f3d992c3cfd791151b5
SHA3 59fc408ecfaa24ff1014fd6022bd0ebb7eb5ff3f708c6900c29156bf35a38f43
VirtualSize 0xb538
VirtualAddress 0x33898000
SizeOfRawData 0xb600
PointerToRawData 0x98a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.62122

.rsrc

MD5 7e9c8e1e4fe5d1370a974dd6078d6438
SHA1 be1e5b13ab39931ef559b7b0a3c119f5aeaab33a
SHA256 f287149069e0c9876a00cef4fa43f9af1b36c918688355540866c76e4fcf3d49
SHA3 c54868c79915ae7d49dd47a782dbacbb63582c2f8fad2b70fd185996ddfb3e11
VirtualSize 0xf600
VirtualAddress 0x338a4000
SizeOfRawData 0xf600
PointerToRawData 0xa4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 5.82811

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#3) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
version.dll VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
gdi32.dll UnrealizeObject
StretchBlt
StartPage
StartDocA
SetWindowOrgEx
SetWindowExtEx
SetWinMetaFileBits
SetViewportOrgEx
SetViewportExtEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetMapMode
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SetAbortProc
SelectPalette
SelectObject
SelectClipRgn
SaveDC
RestoreDC
Rectangle
RectVisible
RealizePalette
Polyline
PolyPolyline
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPointA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExtTextOutA
ExtCreatePen
ExcludeClipRect
EndPage
EndDoc
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateICA
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateDCA
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
user32.dll (#2) GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
kernel32.dll (#4) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_SetImageCount
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
winspool.drv OpenPrinterA
EnumPrintersA
DocumentPropertiesA
ClosePrinter
shell32.dll ShellExecuteA
kernel32.dll (#5) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
ExitThread
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle

Delayed Imports

1

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language UNKNOWN
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language Russian - Russia
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

1 (#2)

Type RT_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x3228
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 6.91747
MD5 e89e7f7bac47a4e542d9fef281023488
SHA1 f6c707e4c2393242344d4e6fa91db7e222f26260
SHA256 d5ba1b4ded64121de211c6a04c69d41e31cd6c79257fdcfc7e21b82b2cea8797
SHA3 f62e5370cf6db4bf11978e296722ab79127fb23ad6c5f8d4720027c7bf4a6230

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0x52
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

4072

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1b0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.15858
MD5 39173b174bcc60665b9cfc69b0d82153
SHA1 63939000cd47f0d798fe2148c9596b3cc8e38dba
SHA256 b046fdc0500cec8e92f4ed2959b3d89075290a8fb918d891caf619b395016c65
SHA3 96645fd6bfdd541a25e62c70b39ba2d6eaca85c2993fbec7099d14a90a174869

4073

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x368
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.24999
MD5 994ec5e8159361303a22e77b891e748f
SHA1 6e4c386291bfe32ad042fa3315ee4ca9bc11d4a1
SHA256 bca8268a2e88912a8524b08c5df90af39750edf2b7543148d99ff6f5afb28dde
SHA3 911ff8ba528c779ab8e9ca67d423effa4acad01c8af3e852488ae21e05322ca0

4074

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3f8
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.20632
MD5 8caf6e9f8981be656b83daa47e0aef07
SHA1 c8d0fb6fbabe022e471c2dc4c1283719db3a2e29
SHA256 5159d1131f3a8d9e44dff19d56fae947d79e80355e679d0e76a45fc61edfebea
SHA3 bf685238928167d265d7d0daa7d766a3c28f5d6d9a8c9cc1636187f986e2bde6

4075

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3ec
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.12812
MD5 635f7990bad80372aa3ff5bb5054d260
SHA1 2b7e576b5edaf882823256afa16f76eedb485334
SHA256 47b2d9fe86d6a105a4653e8e1cd95bcd0543ca0f807f06906b23a799535457cc
SHA3 e314a75d6dde584c8df9e5643e7a565677c316c4bfd6fad1f653fb3dd9cd6ef9

4076

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x310
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.23794
MD5 c8ff6b2131e4d8f93838cabf62848594
SHA1 83c6a10953a7f9205f7c7441b193b8bddff63bc8
SHA256 887a3761aac4c3b78c832448cf290c0b6fdbe8fcb77e727b64f2a7f1366e1c36
SHA3 140c9f4f18ed1074acbe9977f48e6ab37c25c2b91819ecd323e9126030b4605b

4077

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x340
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.26869
MD5 c90c49f1c6a0e7bcd009b6c3f0bef74d
SHA1 13c71d38513e544377954a1a484d2b4f6ad14071
SHA256 d65243c25d6e570a7ce419574a3397b8570899a9d23c8fca8f981e705d598224
SHA3 dde581e89a1d9af0f1c4ae7e8ff01e71d41decfbf430e964dd094baea1c63a0a

4078

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x430
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.24772
MD5 225e8ca388868ca75b2bb2a1afdeb14d
SHA1 3b50312cad154197b29da4f72fd1f135e17cac21
SHA256 b16c8f300da3625224c6c01c3e7d169d0b579acaf2f21040a3dae24f485da7b7
SHA3 3804ec7ac217f3889f067dcf52e6f2b90ba3dbe783425e68343c79c8b5514068

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x360
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.20257
MD5 6b531ac5dd4e1a976a6d390fbcb9eaad
SHA1 9bc8d05c5d294845086dceda3afbdfacc69de393
SHA256 d26d7f45831f290ba06d915ce4b818da4c04ea1e07f89a12e05cd3b2cd13ed64
SHA3 0b55b91e8ce6ac823b9d4ee5edd2680f8ea212585f3df062315f224451590ccc

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1dc
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.22434
MD5 6ef859958e2bb534c0e86d04a0a746eb
SHA1 ad23a6f206b6d755234ba42b27a767cdcf28a0ce
SHA256 7e9aed90ec7a49e868d27b3b5d32f073e49b3a73984d724c7f9ac1ec82f37eeb
SHA3 c92bde234ded18d2cb4114f6e31a3e51339b98967613ddf3ae5662e4a790db7f

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x154
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.2356
MD5 51f1a5aa4768fb165a9a0c882a795d6d
SHA1 d2aed9657f98d8878179beb59b94fef2a3639e27
SHA256 2da2a1c611ba7aafdced110f3ea2bf7d8a6f93edad178cd101e6a71ae28de721
SHA3 cd9a7188466573f0c8ac084e99ef2fa45bf69e77041ac3e8e247056aa4485012

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x268
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.2521
MD5 af6c18ec62748770aa051cba687efbc2
SHA1 a9197cb44c3b99f76d6cbf9d91b89e09ae88adc1
SHA256 8f692ef98a868dcbac3f26b2c1232aaeb715c5367491a2471a44abca07094dcb
SHA3 d57dbdd237438922758888fd1d647f408bfdbe0ff1d275203b4772b81360a203

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2dc
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.23105
MD5 65769a8f68dffae7e898ccb476cb8b7a
SHA1 870499a229d737eafc3f0ee804bc3359ac816c34
SHA256 905813db989ec3805f0dc8a3137c46c0a4853048ca8c3d789e63b8ca7f4f58c1
SHA3 8083dbb6468b3911880672d8f56d20f22cc2509caad477e4ff2dc1c8fdc38c53

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xdc
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.13634
MD5 c42c0aa94ab26289a81be89e5af50ed1
SHA1 6b294d264f62d913097b252acbdbcb4fe3ffae6e
SHA256 19c0ee380ecf5900102d22103000770990a0d26f1eca530d38e4f9a592ebe643
SHA3 680e52696356dfd5889f88114f887ba85527e46a2831b5e7359afdb3384e7fc6

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x18c
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.28273
MD5 d23613f67ecadb6d42d9419e7d07ae26
SHA1 639e44a01af0f4db1191368b4d762f74499647ab
SHA256 c9028e38e162fe1234e2f787a874a05a67c37f543fcce6af87e309ba04729fc9
SHA3 4cb8d4f183aef325ba8ca3bdc50838e12fe2551c9d3df75f0f7a4ed119491fc9

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x224
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.26079
MD5 0f2451e331c5e88bd99f0b3c38b931f1
SHA1 f8b06c9319b353b196c7b59dd695ef3f6a5d3688
SHA256 921b69c6ab217e399ba60a9748221ae1c2e64fc092d9d89339df94804c927082
SHA3 55c4322bc68c05ddd2491a5ae7db3367e16b33b590e64d2c641046764a5c9a54

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x404
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.19828
MD5 a48d3a2b67fc74f68ab0ece70b481b4c
SHA1 31ccb0b46df22b59d3d690c9cf1f1903fdf3d38d
SHA256 7cb45bee3e5f78dd8d4cf0354c31ca88530f669099497bac487ef08207efa085
SHA3 cc6c544b116ba294e1d3561ace65f56bba8abf76f8941b73163c25f16ae4a9dd

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3b4
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.21746
MD5 60465a13e841b30b5367884e1ccfd311
SHA1 e844cd98ad127408ce770e7fdcee7090a63a4af8
SHA256 b1f1981a0e87abb53172ddb02022a9526efe5d6e2ec6d5f67431d97fd70976eb
SHA3 201877f894e5486e310587b0d943766eb3aceff307fe8dff172b4cbcbaadb941

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c4
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.19507
MD5 3318d045750a863bd8aa6952ef960cd3
SHA1 e2b7366b0b7fc604c125d0eb7c9573c29a37d06f
SHA256 23f761c6e0580dff2fc49bc2440a7d24726f38124548ce9c6d27fbb0d085d786
SHA3 48f138264e801d447767fde383c1adf2a7f78b3b65df0634d15eefa3d2edddef

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x480
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.25257
MD5 ae559fec5de666033ae613c808cc46a5
SHA1 a12198f3856a37a8a56b866969c20eaedee35321
SHA256 34bb127545e25fd3ce43019023fbcf0061da2e602af2aeffa38b6d76155201a4
SHA3 91981610e1bfa23b19ca4655d15941bdfec0f7ceb39277f6ba64a0742a46bb35

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x160
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.09048
MD5 2ad84e91e86f84a9b5e9ad9e491ba5d1
SHA1 1567a4f258a43fbbfaa0b8691b5598e6f973a919
SHA256 ce3eacc4cca80b6c0d6d4fc6869d3e3001aed4991574ccab3cf88eeb80d8242c
SHA3 e92943522225039a56c4e52ea6b2d8cea2c8f8bca40c739f9e8418517e4c540a

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xec
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.0171
MD5 6df726e1c32fcc209b07058892dc17cd
SHA1 461e3ec886ac47995c794ad19d7c5c4f43d6c6cf
SHA256 5546566866f4492b408eb6e88129e980a245bf15887a12f3929dfc30cd96c8d1
SHA3 0f2c119ac9eb0e4070d31abe6e289238aff32aff5cfcc53f2c4f38619133103e

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.25818
MD5 c051d200f2cb26177ab1fe689b5855d5
SHA1 d689a757f6b1c3b4bac61e402fdabe3100822380
SHA256 43db115baa8926f5a11e2ee888444297ec14ffc24284678690c65bad78ab7c3a
SHA3 de0a0ed9bd58c0088fec270a58f42d76cab70549400f80d91ed3184415186459

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3d0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.18412
MD5 e374d658a83bec76ed34b22c7fdca7ad
SHA1 c6ed53cffc92bfcf7107f97c25833a274e8483bc
SHA256 7e4f7da8176f408a8e8e7ebd8f2f9da9ca23c95b6a6d5188a13b8f388332289a
SHA3 6c1130277bf61e21c2e24233b2e0d26855289b005a2594fc50995de2bb75ef19

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x374
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.26889
MD5 b45887b8d9abf1a457d523629b25b22d
SHA1 31a34e8bc7558179b576152b70aa2d304459f984
SHA256 022bdaba31b6eb8d40747bde00bab8d56b229e491b2363494bc504252c2d4657
SHA3 36097509b936d98240c7af8c1e519f9d9a944332dbab640d5f6a77b6c0a1934b

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c4
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 3.16875
MD5 157f87d5db4a374f2e2093affbffbb58
SHA1 c251ee03ddb5b18f2fe4b877699f940ec00b00c0
SHA256 86d431240ce976373228e9cb149ac93b1a3725c144ac504e36580aff617c4d86
SHA3 f9a669d47d99bbd3edf738fd0589769c1b986add971b2ee68cbe66d4a635c0e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x568
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.35755
MD5 36d68fbb9c31d361a3b0381728e9cd34
SHA1 7ff6a71a9ca248a6a1df2c795d4bf95e0b070b4f
SHA256 e604779566ca5275c70af26bf965e34ca08cce803bffc69c931de79da08aea65
SHA3 1bcf2d6d12431d7deec0b5122e32402067c84e88173c8765da0215272cb126b3

TFORM1

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x3895
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 4.7687
MD5 e93ac218cb88aa87a85a257b48db211d
SHA1 1aec2b690f39a945ecf11206dba9262a6e3fb55c
SHA256 11ce1af9cb6c3b0b82bead2a0654d92fab4ce3e426faf3faeef60c27db21595b
SHA3 279f0ca130409c64bd6db7aa80a4a6c646e2ea7aa04f9fe14b83f9b50381f3c3

TFORM2

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x247
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.7258
MD5 2c11002f6c60df65ad4380064cf3f2e8
SHA1 c85c98b9756a61e0824d8a6f04f01c3125c5d856
SHA256 2ad4e53c0495867990b988d38b1a973fbd2b39d12fab0e302a2046c0183d332f
SHA3 20e6cc95f0560b66546e2b4e3bbbe7973a07727bc75e9f50eb537f6220b07b0c

TFORM4

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e1
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.68449
MD5 b9072c958551f5f5e39920a8a79c3cf8
SHA1 b3b45b4921377160e2c32634f404ec54c7df4d04
SHA256 bd5f950db4dc50d448b527bff731e7cd311367f3e92c23d88784a013faf8d12b
SHA3 e48e80d8e69af634602af10c7c65160c3627e7e7444909948b2d27dfdd3a2434

TFORM5

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x640
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.70647
MD5 a63016b0871d3b1213a652d0e97da925
SHA1 4d896e01112f579640dcb5f99484dbf6d5a0f07f
SHA256 43bf733c4edb7954dcd962f3e6f92d07e63fe809cc9fc343770373aea3ccc6d4
SHA3 f02d0522c100866389c21994053179ae625aeaeda8364d37c65e4d70ef63a781

TFORM6

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x333
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.85783
MD5 f3a512ebcb7607646b12d006d60d019d
SHA1 e7178c8824aecaa8d67f52a2ce458c766d6b8761
SHA256 31c151f937298fdb5ee26fb52c9f6ca4f63c11d5752e344ec93f75e2ac3f69a2
SHA3 3a2a0d10f7388a9b3a91cd255bf2367371b9991288d8222d88422cdbab731b12

TFORM7

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x2b8
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.86738
MD5 6ecbc85738467b0be9cfdce34743c1d4
SHA1 618283bdb9529ba8e62cef5efb3cac4c036f036f
SHA256 b6b95a68385d9157171bfa303a21b17705c59c2a0a5e2963a436e9c62322b7ba
SHA3 279675e9e886fd4638119f02dcd6edc81fbbfa521bfac4e3641f137bd74dda7a

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 1.91924
Detected Filetype Icon file
MD5 da1a4e2bc252d81a7bee8207f398d70c
SHA1 e447bbc0d488bd520c3997146c266d86966129f4
SHA256 bd9e5e2d09143126611f9aba2c03e9e5d83a351eb43c69bf4b22b0d6500747f4
SHA3 91dccf0eb31d078f355cd011c264055421653bcdd15a40044a5600b0904685cb

1 (#3)

Type RT_MANIFEST
Language Russian - Russia
Codepage UNKNOWN
Size 0x2f0
TimeDateStamp 2012-Dec-10 07:46:20
Entropy 5.17015
MD5 e4c8a62db5113f6ecef8783d50f2f7f7
SHA1 3af0c70356976e15e7466aa0b39ebff654c02318
SHA256 6db2d03d69c169b420a447659d1b87487c4c1ed6acdd29fd0ff0499339c79d73
SHA3 d3525c8852a40d0763f57cc5611186ed68e94848ed2819546df4e22644a89442

String Table contents

Error binding data to SSL socket.
Mode has not been set.
Could not load SSL library.
SSL status: "%s"
Uneven size in DecodeToStream.
Uneven size in Encode.
Protocol field is empty
Host field is empty
General SOCKS server failure.
Connection not allowed by ruleset.
Network unreachable.
Host unreachable.
Connection refused.
TTL expired.
Command not supported.
Address type not supported.
Error accepting connection with SSL.
Error connecting with SSL.
SetCipher failed.
Error creating SSL context.
Could not load root certificate.
Could not load certificate.
Could not load key, check password.
Error geting SSL method.
Too many references, cannot splice.
Connection timed out.
Connection refused.
Too many levels of symbolic links.
File name too long.
Host is down.
No route to host.
Directory not empty
Host not found.
Request rejected or failed.
Request rejected because SOCKS server cannot connect.
Request rejected because the client program and identd report different user-ids.
Unknown socks error.
Socks server did not respond.
Invalid socks authentication method.
Authentication error to socks server.
Protocol not supported.
Socket type not supported.
Operation not supported on socket.
Protocol family not supported.
Address family not supported by protocol family.
Address already in use.
Cannot assign requested address.
Network is down.
Network is unreachable.
Net dropped connection or reset.
Software caused connection abort.
Connection reset by peer.
No buffer space available.
Socket is already connected.
Socket is not connected.
Cannot send or receive after socket is closed.
Socket Error # %d
%s
%s is not a valid IP address.
Interrupted system call.
Bad file number.
Access denied.
Bad address.
Invalid argument.
Too many open files.
Operation would block.
Operation now in progress.
Operation already in progress.
Socket operation on non-socket.
Destination address required.
Message too long.
Protocol wrong type for socket.
Bad protocol option.
Can not bind in port range (%d - %d)
Invalid Port Range (%d - %d)
Read Timeout
Max line length exceeded.
Error on call Winsock2 library function %s
Error on loading Winsock2 library (%s)
Resolving hostname %s.
Connecting to %s.
Connected.
Disconnecting.
Disconnected.
%s
Connect timed out.
Chunk Started
This authentication method is already registered with class name %s.
%s is not a valid service.
Failed to Save Stream
%d is an invalid PageIndex value. PageIndex must be between 0 and %d
Already connected.
Cannot allocate socket.
Connection Closed Gracefully.
Could not bind socket. Address and port are already in use.
Failed attempting to retrieve time zone information.
Not enough data in buffer.
Winsock Initialization Error.
Set Size Exceeded.
File "%s" not found
Only one TIdAntiFreeze can exist per application.
%d: Circular links are not allowed
IOHandler value is not valid
Not Connected
No data to read.
Scroll Bar
3D Dark Shadow
3D Light
Window Background
Window Frame
Window Text
No help keyword specified.
Failed to clear tab control
Failed to delete tab at index %d
Failed to retrieve tab at index %d
Failed to get object at index %d
Failed to set tab "%s" at index %d
Failed to set object at index %d
MultiLine must be True when TabPosition is tpLeft or tpRight
RichEdit line insertion error
Failed to Load Stream
Button Highlight
Button Shadow
Button Text
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Red
Lime
Yellow
Blue
Fuchsia
Aqua
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
- Dock zone has no control
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No topic-based help system installed
Black
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Down
Ins
Del
Shift+
Ctrl+
Alt+
Unable to insert a line
Invalid clipboard format
Clipboard does not support Icons
Cannot open clipboard
Text exceeds memo capacity
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
&Ignore
&All
N&o to All
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Enhanced Metafiles
Icons
Bitmaps
Invalid input value
Invalid input value. Use escape key to abandon changes
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Cannot drag a form
Metafiles
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer selected is not valid
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Tab position incompatible with current tab style
Tab style incompatible with current tab position
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Invalid property path
Invalid property value
Cannot insert or delete rows from grid
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
Too many rows or columns deleted
%s not in a class registration group
Property %s does not exist
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Fixed column count must be less than column count
Fixed row count must be less than row count
Cannot open file "%s". %s
Grid too large for operation
Grid index out of range
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
'%s' is not a valid integer value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation

Version Info

TLS Callbacks

StartAddressOfRawData 0x33c96000
EndAddressOfRawData 0x33c96010
AddressOfIndex 0x4950a4
AddressOfCallbacks 0x33c97010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.