6b2ade22dee08ca975a9510f6932e5e3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2020-May-28 20:24:24
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts d:\dbs\el\apr\target\x86\ship\click2run\en-us\AdminBootstrapper.pdb
CompanyName Microsoft Corporation
FileDescription Microsoft Office
FileVersion 16.0.12827.20258
InternalName Bootstrapper.exe
LegalTrademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2 Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename Bootstrapper.exe
ProductName Microsoft Office
ProductVersion 16.0.12827.20258

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • %TEMP%
  • %Temp%
Accesses the WMI:
  • ROOT\CIMV2
Miscellaneous malware strings:
  • virus
References the BITS service
Contains domain names:
  • .corp.microsoft.com
  • 0020.a-msedge.net
  • PPC-powerpoint.officeapps.live.com
  • a-0020.a-msedge.net
  • a-msedge.net
  • adobe.com
  • akamaiedge.net
  • api.diagnostics.office.com
  • autodiscover-s.outlook.com
  • autodiscover.microsoft.com
  • contentstorage.osi.office.net
  • corp.microsoft.com
  • crl.microsoft.com
  • d.docs.live.net
  • data.microsoft.com
  • delve.office.com
  • diagnostics.office.com
  • docs.live.net
  • dscd.akamaiedge.net
  • e1723.dscd.akamaiedge.net
  • ecs.office.com
  • edog.officeapps.live.com
  • events.data.microsoft.com
  • go.microsoft.com
  • http://127.0.0.1
  • http://a-0020.a-msedge.net
  • http://a-0020.a-msedge.net/pr
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
  • http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
  • http://e1723.dscd.akamaiedge.net
  • http://e1723.dscd.akamaiedge.net/pr
  • http://ns.adobe.com
  • http://ns.adobe.com/photoshop/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
  • http://office.microsoft.com
  • http://officecdn.microsoft.com
  • http://officecdn.microsoft.com/db
  • http://officecdn.microsoft.com/pr
  • http://officecdn.microsoft.com/pr/0002c1ba-b76b-4af9-b1ee-ae2ad587371f
  • http://officecdn.microsoft.com/pr/39168D7E-077B-48E7-872C-B232C3E72675
  • http://officecdn.microsoft.com/pr/39168d7e-077b-48e7-872c-b232c3e72675
  • http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60
  • http://officecdn.microsoft.com/pr/5440fd1f-7ecb-4221-8110-145efaa6372f
  • http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6
  • http://officecdn.microsoft.com/pr/64256afe-f5d9-4f86-8936-8840a6a4f5be
  • http://officecdn.microsoft.com/pr/7ffbc6bf-bc32-4f92-8982-f9dd17fd3114
  • http://officecdn.microsoft.com/pr/b8f9b850-328d-4355-9145-c59439a0c4cf
  • http://officecdn.microsoft.com/pr/f2e724c1-748f-4b47-8fb8-8e0d210e9208
  • http://officecdn.microsoft.com/sg
  • http://purl.org
  • http://www.microsoft.com
  • http://www.microsoft.com/PKI/docs/CPS/default.htm0
  • http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
  • http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
  • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
  • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
  • http://www.microsoft.com/pkiops/docs/primarycps.htm0
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • http://www.w3.org/2000/09/xmldsig#
  • https://ecs.office.com
  • https://ecs.office.com/config/v2/Office
  • https://go.microsoft.com
  • https://go.microsoft.com/fwlink/?LinkId
  • https://mrodevicemgr.edog.officeapps.live.com
  • https://mrodevicemgr.edog.officeapps.live.com/mrodevicemgrsvc/api
  • https://mrodevicemgr.officeapps.live.com
  • https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api
  • https://msdn.microsoft.com
  • https://msdn.microsoft.com/en-us/library/windows/desktop/ms753129
  • https://nexus.officeapps.live.com
  • https://nexusrules.officeapps.live.com
  • https://officeredir.microsoft.com
  • https://officeredir.microsoft.com/r/rlidOfficeWebHelp?p1
  • https://support.microsoft.com
  • https://support.microsoft.com/kb/2739501
  • loki.delve.office.com
  • messaging.office.com
  • microsoft-my.sharepoint-df.com
  • microsoft-my.sharepoint.com
  • microsoft.com
  • microsoft.sharepoint.com
  • mrodevicemgr.edog.officeapps.live.com
  • mrodevicemgr.officeapps.live.com
  • msdn.microsoft.com
  • msedge.net
  • my.sharepoint-df.com
  • my.sharepoint.com
  • nexus.officeapps.live.com
  • nexusrules.officeapps.live.com
  • nleditor.osi.office.net
  • ns.adobe.com
  • ocws.officeapps.live.com
  • odc.officeapps.live.com
  • office.com
  • office.microsoft.com
  • office.net
  • office365.com
  • officeapps.live.com
  • officecdn.microsoft.com
  • officeredir.microsoft.com
  • ols.officeapps.live.com
  • osi.office.net
  • outlook.com
  • outlook.office365.com
  • powerpoint.officeapps.live.com
  • roaming.officeapps.live.com
  • s.outlook.com
  • self.events.data.microsoft.com
  • sharepoint-df.com
  • sharepoint.com
  • storage.live.com
  • substrate.office.com
  • support.microsoft.com
  • www.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegCreateKeyExW
  • RegCloseKey
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegEnumKeyExW
  • RegQueryInfoKeyW
  • RegEnumValueW
  • RegDeleteKeyW
  • RegGetValueW
  • RegSetValueExW
  • RegDeleteValueW
  • RegNotifyChangeKeyValue
  • RegEnumValueA
  • RegDeleteValueA
  • RegSetKeySecurity
Possibly launches other programs:
  • CreateProcessW
Uses Microsoft's cryptographic API:
  • CryptReleaseContext
  • CryptAcquireContextW
  • CryptDestroyHash
  • CryptGetHashParam
  • CryptCreateHash
  • CryptHashData
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualProtectEx
  • VirtualAlloc
  • VirtualProtect
Leverages the raw socket API to access the Internet:
  • FreeAddrInfoW
  • #115
  • GetAddrInfoW
  • #116
Functions related to the privilege level:
  • OpenProcessToken
  • CheckTokenMembership
  • AdjustTokenPrivileges
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceStatusEx
  • QueryServiceConfigW
  • ControlService
  • DeleteService
  • CreateServiceW
  • ChangeServiceConfigW
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Suspicious The file contains overlay data. 78736 bytes of data starting at offset 0x561338.
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA 2010
Suspicious VirusTotal score: 2/68 (Scanned on 2020-08-16 00:21:26) FireEye: Generic.mg.6b2ade22dee08ca9
CrowdStrike: win/malicious_confidence_60% (W)

Hashes

MD5 6b2ade22dee08ca975a9510f6932e5e3
SHA1 67227362d6c10237c796cfcc2f89b57a83aa4d7a
SHA256 e809df4fef74e7ec6f1858243e601c1ee5193903fea4f79f646390e7377e453f
SHA3 2910b208fbde3268437f0911d7d00279321da4a756668cb6cc4b269d69950085
SSDeep 98304:ApNruEhpMyLTiDW/D2KajH7ICxvwnOaZjY4tBbWYtePb3A9TGfJwwY2hoVL:IVuaMSGD9H7ICxvwnOaZjY06Yd9TGxwj
Imports Hash 6226c309096e84849fd1e7e04224e332

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x130

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2020-May-28 20:24:24
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x2f1400
SizeOfInitializedData 0x26be00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x002722A4 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2f4000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x560000
SizeOfHeaders 0x400
Checksum 0x566236
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 aabb8eaaf77f26a6aaf3fb699ecc5369
SHA1 fa9b64d1ae7dd823bdb2dc71818ced71dc9dd775
SHA256 de146871bec88fc2a157dcc45d41bfe609f88a185ae592fc6f7d1af5f11a41a2
SHA3 4f6c33b4a6f237dec4c9b2350d14346ae1bca53660af2243f5aa7b71443b0e43
VirtualSize 0x2f1224
VirtualAddress 0x1000
SizeOfRawData 0x2f1400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66137

.rdata

MD5 7ba7a29534fdf2c228c3e8a088686aac
SHA1 acb51be19d5f133bf5a54d60a96af6e47f25cb52
SHA256 2853fc43416175da6e3b0fd307506a2e4f4be3684717c66fedad8648d5001c94
SHA3 bfc12945a8e5719bc8e6595f9bd88c9f2ec036e8a936d9c5ad8434f4f74e9a13
VirtualSize 0x16197a
VirtualAddress 0x2f3000
SizeOfRawData 0x161a00
PointerToRawData 0x2f1800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.70889

.data

MD5 8a66839074c3ca65b61720bdad1e6493
SHA1 21dca0c3c29baa4e31de1d578a2e7fb355d22975
SHA256 684966d51cf1300c57fe37cb848f824a14e4f281a8a231ac4c14b33f5bd3beb9
SHA3 946d0b114a10129c887cc35a06bbb9e217711e4f047f021bc2c2adc53147ab5c
VirtualSize 0x22f44
VirtualAddress 0x455000
SizeOfRawData 0x22800
PointerToRawData 0x453200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.64719

.rsrc

MD5 5a56b915322ed4a6da38db9499df7f1b
SHA1 46e3949222d0914f1ee8145da0d4de2fc7ad2960
SHA256 08009cbe8ce22e6676b3456f25c755d7d4f266d848a2d227a442fc856f6bd531
SHA3 0278c2de57e6d50d01bb24f0b5ab05c69f723beb484110b64739aca374f04490
VirtualSize 0x9ed48
VirtualAddress 0x478000
SizeOfRawData 0x9ee00
PointerToRawData 0x475a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.33176

.reloc

MD5 73f46d7d9de8359044cdc2379bcdd0c5
SHA1 b0259c1831377e9023acc2a61c5f2fac5169b13c
SHA256 c5cb59d4a70c73224cc4373239307f6bab9a8727c6516f2834a9d21889d47b96
SHA3 cd0ee56b7407f1a93927042d6d8655d5963f3ac4358349899d42ce1cfb329ead
VirtualSize 0x485d4
VirtualAddress 0x517000
SizeOfRawData 0x48600
PointerToRawData 0x514800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.48405

Imports

ADVAPI32.dll RegCreateKeyExW
RegCloseKey
EventWriteTransfer
EventRegister
EventUnregister
RegQueryValueExW
RegOpenKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegEnumValueW
RegDeleteTreeW
RegDeleteKeyW
RegGetValueW
RegSetValueExW
RegDeleteValueW
GetTokenInformation
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
CryptReleaseContext
CryptAcquireContextW
CryptDestroyHash
CryptGetHashParam
CryptCreateHash
CryptHashData
RegNotifyChangeKeyValue
RevertToSelf
OpenThreadToken
OpenProcessToken
GetLengthSid
CopySid
InitializeAcl
AddAccessAllowedAce
AllocateAndInitializeSid
FreeSid
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
GetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertSidToStringSidA
CheckTokenMembership
CreateWellKnownSid
EqualSid
ImpersonateLoggedOnUser
LookupPrivilegeValueW
AdjustTokenPrivileges
OpenSCManagerW
CloseServiceHandle
OpenServiceW
QueryServiceStatusEx
QueryServiceConfigW
StartServiceW
ControlService
EnumDependentServicesW
DeleteService
CreateServiceW
ChangeServiceConfig2W
ChangeServiceConfigW
SetServiceObjectSecurity
RegEnumValueA
RegDeleteValueA
EventWrite
RegSetKeySecurity
GDI32.dll SetBkColor
SetTextColor
CreateSolidBrush
DeleteObject
GetDeviceCaps
CreateFontW
SelectObject
GetTextMetricsW
CreatePen
SetDCPenColor
Rectangle
GetTextExtentPoint32W
SetDCBrushColor
GetStockObject
OLEAUT32.dll #8
#9
#6
#2
KERNEL32.dll ReadConsoleW
GetCurrentProcess
GetModuleHandleExW
InitializeCriticalSectionEx
GetLastError
CompareStringEx
GetProcAddress
DeleteCriticalSection
FreeLibrary
FlsFree
FlsAlloc
IsWow64Process
CloseHandle
CreateThread
GetExitCodeThread
GetCurrentThreadId
GetModuleFileNameW
GetModuleHandleW
MultiByteToWideChar
FindClose
UnmapViewOfFile
CreateFileMappingA
MapViewOfFile
Sleep
GetStringTypeExW
GetUserDefaultLCID
LoadLibraryA
LCMapStringW
LocalFree
FormatMessageA
GetSystemTimeAsFileTime
TlsAlloc
TlsFree
FlsGetValue
TlsGetValue
FlsSetValue
TlsSetValue
GetTickCount64
K32GetProcessMemoryInfo
GlobalMemoryStatusEx
LeaveCriticalSection
EnterCriticalSection
RaiseException
WideCharToMultiByte
InitializeSRWLock
ReleaseSRWLockShared
AcquireSRWLockShared
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
GetProcessTimes
TerminateProcess
GetModuleFileNameA
GetShortPathNameA
K32GetModuleFileNameExW
CreateProcessW
LoadLibraryExW
FindResourceW
SizeofResource
LoadResource
VerSetConditionMask
VerifyVersionInfoW
OpenProcess
GetCurrentProcessId
GetStringTypeW
GetVersionExW
GetUserDefaultLocaleName
IsValidCodePage
SetLastError
GetSystemTime
SystemTimeToFileTime
FileTimeToSystemTime
GetCPInfoExW
GetDiskFreeSpaceExW
CreateFileW
DeviceIoControl
SetErrorMode
GetComputerNameW
MulDiv
FormatMessageW
GetLogicalProcessorInformation
GetNativeSystemInfo
GetSystemDirectoryW
HeapFree
OutputDebugStringA
GetModuleHandleA
LoadLibraryW
HeapAlloc
GetProcessHeap
CreateEventW
SetEvent
WaitForSingleObject
WaitForMultipleObjectsEx
CreateEventExW
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableSRW
CloseThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CreateThreadpoolTimer
CloseThreadpoolWait
SetThreadpoolWait
HeapSize
CreateThreadpoolWait
CreateThreadpoolWork
SubmitThreadpoolWork
ReleaseSemaphore
WaitForSingleObjectEx
QueryDepthSList
TryEnterCriticalSection
InitializeSListHead
InterlockedPushEntrySList
InterlockedPopEntrySList
RtlCaptureStackBackTrace
ReleaseMutex
TzSpecificLocalTimeToSystemTime
GetTempPathW
GetLongPathNameW
ResetEvent
QueryPerformanceCounter
QueryPerformanceFrequency
VirtualProtectEx
GetSystemInfo
GlobalFree
GlobalAlloc
ReadFile
WriteFile
GetFileSizeEx
LockResource
SetEndOfFile
SetFilePointerEx
GetOverlappedResult
FlushFileBuffers
CancelIoEx
GetFileAttributesExW
DeleteFileW
CreateDirectoryW
SetFileAttributesW
RemoveDirectoryW
GetDriveTypeW
FindFirstFileExW
FindNextFileW
GetFileType
CopyFileW
MoveFileExW
GetTempFileNameW
SetFileInformationByHandle
GetFileInformationByHandleEx
SignalObjectAndWait
GetProcessAffinityMask
GetLogicalProcessorInformationEx
CreateWaitableTimerW
SetWaitableTimerEx
CancelWaitableTimer
GetTickCount
WerRegisterMemoryBlock
WerUnregisterMemoryBlock
QueryFullProcessImageNameW
IsProcessorFeaturePresent
CreateIoCompletionPort
PostQueuedCompletionStatus
GetThreadIOPendingFlag
GetCurrentThread
GetQueuedCompletionStatus
IsDebuggerPresent
WaitForMultipleObjects
GetStartupInfoW
CreateMemoryResourceNotification
GetSystemPowerStatus
IsSystemResumeAutomatic
QueryUnbiasedInterruptTime
OutputDebugStringW
CreateMutexW
VirtualFree
ExpandEnvironmentStringsW
VirtualAlloc
OpenEventA
CreateEventA
OpenMutexA
CreateMutexA
OpenSemaphoreA
CreateSemaphoreA
OpenFileMappingA
LocalAlloc
GetThreadLocale
FindFirstFileW
lstrcmpW
GetFullPathNameW
ProcessIdToSessionId
GetCommandLineW
GetCurrentDirectoryW
SetEnvironmentVariableW
GetPriorityClass
GetExitCodeProcess
GetProcessId
K32EnumProcesses
GetTimeZoneInformation
IsValidLocale
GetLocaleInfoEx
LCIDToLocaleName
LocaleNameToLCID
GetLocaleInfoW
ResolveLocaleName
GetUserPreferredUILanguages
GetACP
LCMapStringEx
GetSystemDefaultLCID
EnumSystemLocalesEx
GetSystemDefaultLocaleName
GetUserGeoID
GetPhysicallyInstalledSystemMemory
GetProductInfo
SwitchToThread
GetConsoleMode
UnregisterWaitEx
VirtualProtect
FreeLibraryAndExitThread
GetThreadTimes
UnregisterWait
RegisterWaitForSingleObject
SetThreadAffinityMask
GetNumaHighestNodeNumber
ChangeTimerQueueTimer
GetThreadPriority
SetThreadPriority
CreateTimerQueue
InterlockedFlushSList
RtlUnwind
SetUnhandledExceptionFilter
UnhandledExceptionFilter
CompareStringW
GetCPInfo
InitializeCriticalSectionAndSpinCount
AreFileApisANSI
GetFileInformationByHandle
EncodePointer
DuplicateHandle
OpenThread
K32GetProcessImageFileNameW
GetSystemPreferredUILanguages
GetDateFormatW
GetTimeFormatW
DeleteTimerQueueTimer
CreateTimerQueueTimer
FreeConsole
WriteConsoleW
GetStdHandle
AllocConsole
AttachConsole
DecodePointer
ExitThread
ExitProcess
HeapReAlloc
EnumSystemLocalesW
SetStdHandle
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
VirtualQuery
LoadLibraryExA
GetConsoleCP
WaitForThreadpoolWaitCallbacks
GetLocalTime
ole32.dll IIDFromString
CoTaskMemAlloc
CoTaskMemFree
StringFromCLSID
CoCreateInstance
CoSetProxyBlanket
CoCreateFreeThreadedMarshaler
StringFromGUID2
CoCreateGuid
CoInitializeSecurity
CoUninitialize
CoInitializeEx
CreateStreamOnHGlobal
CoRegisterInitializeSpy
CoRevokeInitializeSpy
CoCancelCall
CLSIDFromString
CoEnableCallCancellation
CoDisableCallCancellation
WINTRUST.dll WTHelperGetProvSignerFromChain
WTHelperProvDataFromStateData
WinVerifyTrust
SETUPAPI.dll SetupIterateCabinetW
WS2_32.dll FreeAddrInfoW
#115
GetAddrInfoW
#116
gdiplus.dll GdipDeleteGraphics
GdipFillRectangleI
GdipDrawImageRectRectI
GdiplusStartup
GdipDrawImageRectI
GdipLoadImageFromStream
GdipCloneBrush
GdipFree
GdipAlloc
GdipCloneImage
GdipDisposeImage
GdipCreateBitmapFromScan0
GdipGetImageHeight
GdipGetImageWidth
GdipGetImageGraphicsContext
GdipCreateSolidFill
GdipDeleteBrush
GdipCreateFromHDC
RPCRT4.dll UuidToStringW
RpcStringFreeW
api-ms-win-core-winrt-string-l1-1-0.dll (delay-loaded) WindowsDuplicateString
WindowsCreateString
WindowsGetStringRawBuffer
WindowsCreateStringReference
WindowsConcatString
WindowsCompareStringOrdinal
WindowsDeleteString

Delayed Imports

Attributes 0x1
Name api-ms-win-core-winrt-string-l1-1-0.dll
ModuleHandle 0x46a540
DelayImportAddressTable 0x455000
DelayImportNameTable 0x45148c
BoundDelayImportTable 0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

ID_ANIMATEDLOGO

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x10041
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9646
Detected Filetype PNG graphic file
MD5 9d38627b453eea649aa16ddd7585b10c
SHA1 c4050350503722b2cee639524ad590eac25a49b3
SHA256 d565f5c0e5c1930759b9c340ae4a81ff1f216cdd72b7e0bb8a21b094012d8d0b
SHA3 9848e387a0a4ba7fbb0f3d86a77fa9ad962ea48ce62e2d8d436289309dc65890

ID_ANIMATEDLOGO_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x43e89
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99108
Detected Filetype PNG graphic file
MD5 84e2d38d3e5459921b8d18f9ed45ea77
SHA1 37ccc45dcedd849621669a1e81be3fc9dff9d983
SHA256 4bbef2ac9a4bc075b529b5eabf75928cea7ccf9cb178798a2afc379326edb7cd
SHA3 b184f6d9cc86ccd157f093b1bca8d97bb629e7f263c154bd900ada02efef3c33

ID_CLOSE

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xb1c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86982
Detected Filetype PNG graphic file
MD5 8a3a524d50d27342c2015f24c93eaede
SHA1 365e22497e357711340503dbefd1fb957c33e799
SHA256 cb8eef1aba4ccc718a120ba9d75021e29e30bb163c6991c512367cb4cbc2b7e7
SHA3 3a151703e1992d2d9e485da8c3ab9f4f4d59dd70c6da6bd191a29b23219a39d1

ID_CLOSE_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x401
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.17947
Detected Filetype PNG graphic file
MD5 981bc942f3a81146f9788ab21d260e1c
SHA1 af9cc3cd4085e2ad3bf5d217e0970fbdbe8ddd36
SHA256 07eac3dbb58c1d516cf86711586bdfe2d456a7081894880c92c989002ed254c3
SHA3 fb3b974895d03f819846e961ace6a92df33bf9fdad55509318c238bec7ed7340

ID_CLOSE_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xca
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.5187
Detected Filetype PNG graphic file
MD5 4024c548dc417ae6656ef019e1b2c57a
SHA1 5c2961bb227c77599022f9d62ce2f15c33ab6584
SHA256 05b9db2e7edd2dc2948d46cf87ff87354fd89031fc5472f1b3eb7c0861d14f87
SHA3 e990f2dd098155516a32ebc7b08da1aa310f3f92122e6c0538eb7147f37fe031

ID_CLOSE_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x795
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9285
Detected Filetype PNG graphic file
MD5 05c14bc2743fb16a8ebd20e9cf71fb22
SHA1 21191ac866d2df5d5a463c1fec6d90794f8a101c
SHA256 ac2290ea665d1ead4beebe738b3e9024c486a9e2d2d2dd7096626634365d8bdb
SHA3 e0082d4ba124241eeafed4ccb55f28af04cc3346d87a5f5a75b5bda253127c39

ID_CLOSE_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x87
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.75409
Detected Filetype PNG graphic file
MD5 b5d243a7ec81c69a7c10cec54a848358
SHA1 7837ff88e95765efa20d774e431254405c796fdd
SHA256 bd10d32df763e96fcea137b6076c7a4a70b4673f81cb6d258b1a3238a98f2a92
SHA3 877f0f02a6be4cab2d1299ea9e05e8fd226ee98ec86f38b589c0b135b5c2f2eb

ID_CLOSE_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x691
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.83285
Detected Filetype PNG graphic file
MD5 672a5f2db9bee1039d3fabbe6c30d051
SHA1 46bd71071a38d266938dafbff449b80cabc45859
SHA256 01f96dd81eae1498c3fac84d9215c2500cee2575fbd19674241acf668774dcda
SHA3 d80febdc48fcfae7c232ea9964b5ce6a338a7485aaee6e0bc0e1dbc822883484

ID_ERROR

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1f9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.18472
Detected Filetype PNG graphic file
MD5 f1d5fcc645a8e50f8a862fb012da45bf
SHA1 634a4f604b9c0e212805c03fa7f95dad1c80c116
SHA256 85b1ad1092503f19ae1f2f0cf76b40aa41b600a11d2c5f7bb71b8c832d0dbb51
SHA3 44d531b0fd83d07400f07927007d1f2428ce81a4780bc6b727f4bffabfb26b5e

ID_ERROR_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x34d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62896
Detected Filetype PNG graphic file
MD5 4f98bf250e9d690efbef11b8cf890d19
SHA1 a2e07f1922a8319527a923b6f269d39178acdcb4
SHA256 31205d4537fbf75212cd54a12776036587a69357e9927c1f73de2511b49b3c3e
SHA3 4c57217a4ea08ecb426731fb0f7cfff06d2c9aa11142594442b85497d0a112a6

ID_LOADINGDOTS

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ece
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.81657
Detected Filetype PNG graphic file
MD5 60389491858d9a3ac90bf48332065751
SHA1 8372c5481bf23362241045f019f4d01f2cacaf83
SHA256 3a9098cc54a61e1a0f06447b152774d9d882cd3c1b8022631f4fa95644038eae
SHA3 6bf15885bc86f8a5d03aa28db3e73a7c09f04f0c148e5bf39c4bd0e1cac110fa

ID_LOADINGDOTS_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x9293
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8088
Detected Filetype PNG graphic file
MD5 23249c1902e80757eaa02db8acf175b8
SHA1 a8c9f7d1efdef0e264b82a81e94dcd28a1f5f434
SHA256 8572468da49aa3c7cd2a93d0dc6d8517dd1149394da76c6128203c5d140ce786
SHA3 99e3c2ca54cbf4f59cb6100ea28c53d2a2a1aaf7952984b5f101da8828875916

ID_LOADINGDOTS_RTL

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x4078
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.82801
Detected Filetype PNG graphic file
MD5 29d51ec1d604be3633f4c850363cba95
SHA1 763e88c2f1539e4a92a88108b7f10a253b62d9dc
SHA256 749bc3fa158f6b9f451adb0469708270d7242faa799cd98b50f70edef1d84662
SHA3 c27efe4310bde57dda30ab6c531b0128ef816a94aac7f2baa1a58413e72c2a31

ID_LOADINGDOTS_RTL_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x9255
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8081
Detected Filetype PNG graphic file
MD5 6846b898d8e859dc6fc33f1d8f50237d
SHA1 ea6b9ba0f54eba82b3fc398c176338bef7698742
SHA256 0dea6867e0fbd22f33964c2c0452be01d7db3039f8090686eb0161cade6a6b09
SHA3 1e808fdcd14c39a25f6b474cafaa2b51eb9ba8908935dde982f7c057d1283e73

ID_LOGO

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1055
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.47575
Detected Filetype PNG graphic file
MD5 6867b640edd0bb840727b6eaa2608912
SHA1 45754e06971a91d55b514179c6f612a6687ff56f
SHA256 1ce452224e003f95125aa406869df69f5d1696165a11ab3bf824470f98783525
SHA3 e455a04e415d2495126f1f42ba0ab662b3583fd443265005e4be4e3034c2f980

ID_LOGO_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2739
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.85484
Detected Filetype PNG graphic file
MD5 e160d97445fbd281b861f5c3eba29829
SHA1 1fb155d86c626e1713676fb510f05deb40298684
SHA256 9f6d19bad29dc5945212e1f80d63c60bd16aa9dfc4587093b8ed34f8c1bbcc8b
SHA3 ea99d55bddcb8a55347ee3cd3fe043cc9a919f59ec66b439e18f14387e8c9980

ID_LOGO_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x15a7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.37074
Detected Filetype PNG graphic file
MD5 2430288bdbe8f624f20d4d8a76ea1494
SHA1 ed19753c6081045f62a6a036bb5af63ceee9c68d
SHA256 0ad7bbbb5b858893d9e3070dd733faa02bc702f8864f73621c80f4d5e6a3a11d
SHA3 4899836c647b8afc7b40ae0c1c5ff49c4440a28a72d310ea04967cff960e4af0

ID_LOGO_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1dad
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.80161
Detected Filetype PNG graphic file
MD5 81681c4d18f99726811c7057265cb749
SHA1 078f2b76bd85250cfe0c8b2753e54bc79c5bb550
SHA256 a96ea845b6a925cc792a841f0e377be1dbd1bfc44e073377e4d276e5b1dc314d
SHA3 94f3f4b72f9dcf5fcdb6f70187be100c46e64bfe24e6fdecb7535e118237e993

ID_LOGO_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x96d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.48455
Detected Filetype PNG graphic file
MD5 ec0bc36c11a9a27bfc735db908e7d3ca
SHA1 9f40bc2e6d7a90bca0743bafbcfbbf24ada35bb3
SHA256 72c91312db973d014ed69a093611bbad25f03b2bdf7a1f3e7cd319db6d2fef6e
SHA3 6b1ce782077af61965b21eee4cafd57f6c168cecd414ac970397d634058d3bfd

ID_LOGO_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xe7f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.44296
Detected Filetype PNG graphic file
MD5 52b4766097df7d9bd55d21edd2b0fc42
SHA1 6a350bd8011658588c6dbc8df502ac7840136121
SHA256 b7d8e6fec5643bd440bed4491f5c93a638487b34565c541a754ed90d60875196
SHA3 1c12fbe08384f0924a683f4368789207a791f7172def41169ff7038e2003d64f

ID_MINIMIZE

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0xafc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8627
Detected Filetype PNG graphic file
MD5 f7c36dcaa397714db9893819a27d71d4
SHA1 c336109f20e453dfe19864f60117762753ed5d25
SHA256 e553f843d67d4ed4f2f89a5d3eed2ca0e75c27f0a7e515b4010a749fc69f8c59
SHA3 384ec1b4e98c324940a679298ef5b2a2b6997db5d1fbdf28853751c1399c3e00

ID_MINIMIZE_192

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3be
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.88536
Detected Filetype PNG graphic file
MD5 448a9e62e5bc9e442c5911eda9f24280
SHA1 7d76380b21f480215f1cd614561cd8a93be5ca51
SHA256 efdbaa1686975466e8cfff8532d0dce7ba9e5c74c736c325b717c40608a4e33d
SHA3 ae8b77e622b510f040825b4655d6467b4246066401ab614c5b00abb0b494fb9d

ID_MINIMIZE_192_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x752
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.77166
Detected Filetype PNG graphic file
MD5 25707af4c81f3cf1332f076291247a11
SHA1 18354db798d0fa0355271b1a7fc443b8ca0ea9bc
SHA256 a6d9e0c48f94cd52edac8500ebeca8960fcfa1a11c7e2fd3e537383fc57e8eb2
SHA3 8e2af294c925dc153716112aab546e8aa8e8053b518c4d87deaecd4ee5960d19

ID_MINIMIZE_192_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x757
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.78077
Detected Filetype PNG graphic file
MD5 9fbe7a2dbb1194ba88d77a9ec31d15b6
SHA1 b747471b33531b85d1be642a413b4e49fe8b1a81
SHA256 8ec83498aa799ec33bc5b6da83ce6b1e394b383b5d8289bb98b137a374d71afc
SHA3 ac087624860fba6dccb70b558172a892c8c59747ebb2fc96a1deb9080c3d70af

ID_MINIMIZE_HC

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x675
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74918
Detected Filetype PNG graphic file
MD5 5c893fc0b39d10926e9fa04857f500af
SHA1 35b70117ba019e7a7720924a41dc0b1efcf8aa01
SHA256 de25d14b3719c1a706b647b7d24600572cd3cd238eb3e499c3e5a42e28a32400
SHA3 bb2f9f75b827c268dcf8bbd71b919f950b40eb2ba6707a720655b08af2121b48

ID_MINIMIZE_HCW

Type PNG
Language English - United States
Codepage Latin 1 / Western European
Size 0x674
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.74395
Detected Filetype PNG graphic file
MD5 579d08f1a225b89fd234a46de57885dc
SHA1 6e99af737190961e4ecc099b5a85ea4d31d429d5
SHA256 5ba5fcc7a89c3c2f519f364592a36c5fbf5309c89147d94dfa3b8b00897d17f6
SHA3 e5c0e18006a512609c40a8486492e38b0ee54f2b35c4f4fed510bde9f8176d7d

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.59532
MD5 7a4680e656a97a5629ddc0b9e833dcec
SHA1 e64c4fa2223fb1467f4788b070057208c7026e8d
SHA256 bc9a5e5323aa6671bd013ad69c3690458e5adb30b66eb42f9718b53f624281bc
SHA3 61ea07484c092db449f62a355d51f34c70cf153f9a540da90c2bd344b3466840

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.96082
MD5 adf967685fb02ec8139dad33cce79e13
SHA1 705685853bec5aa1dc677ded956619f6e819e1ec
SHA256 f4de764e0c25d509171cb6881129b0b38fbbc84e774a90108342f4ea55c0cf17
SHA3 f26a54701a41c2d920d32071d7943de833ea2d52a182e8748a3d75364beb8e07

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.20562
MD5 f03b1f73c59d6398864e2c7d4f9ed9cd
SHA1 7a437c011f94bec2154d7f359c78ab8e86c18403
SHA256 713831e4b06a6788b4b858e9799a1c84064cfe77ad38669d430e1fc20bf4a379
SHA3 5aecc613ae5e5c84bc90cdd4ee6361f092fd9f44c0a4ab018ce28700dc7858c6

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87138
MD5 3e88ed00604b1774eaeb59a6d3d2362f
SHA1 a357a7c0091da48964f5c44cb3d2bff9844bd3b1
SHA256 a881c2d07c959476d513e9d519b8aff6bad067d96fff6549e6e16c5b669fbb3e
SHA3 8f54c9857584733edf18deaf37340b3a0f49d5b200b46ee2fba91a690a05a2c7

188

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12518
MD5 3df3cda5f30d915a359d1eb470481ab5
SHA1 3d8087b81a688749531ae4ea83d190018da95522
SHA256 d2b177b57236975743f72cbee27a4aba3f9fb949657dfd2c3dedca095b1b0af5
SHA3 b606e3103ab0321b70d33f4eab9c0554edfb00b19279c35a3a40eb1e79e3043a

189

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x208
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2959
MD5 0199981cdc71c5ddbb8ce3a6ec695cf1
SHA1 22e7c8423c543dab7790663b3413c06da8e05105
SHA256 d34ce6edc93323c3c7eaf0442730be549d0776696a31130d3497a4031abdcff1
SHA3 897be1c3eb5cb5b2509788f9585da7461d15b00966f38477a61d9b9d4415d6c9

190

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x29a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22948
MD5 d1ee4fdba6f442f321a6e219dba2ef18
SHA1 6643b916e958f519b1b74dba992de7e2f0b5e747
SHA256 7f15f093aef4285e89a73527ded140838c115cb3a5e2f73da18b7ab4f24f7ffa
SHA3 96d162c78cf81d89789b0b0628aad55fc81f11819595fae480ba735f6659f821

191

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x47c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31548
MD5 4308d5fc5830812064f6b08eaaa070bd
SHA1 23ef68651599d3dda05373e15839127a9370bb3e
SHA256 c131ae7c2721d6e22383377086a4f9b6f0a0417af3a727e2a29cdabfc34bfdd2
SHA3 2e0e59f689c201c38a0cf9247095714aef032675348c186e303abfa22bba99f6

192

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11855
MD5 46cf861e68d440cf680044278c795ade
SHA1 2797556e82670fb292a75425e7a7cead356b32b0
SHA256 7176df2bf9df3deb3d59f573c0854ddf216eb9f9eced76bf35872d1f800336a9
SHA3 104ca5023666f1c897edf62f20d1c6e5b498fef560c77bb901d3b5004bcb3d87

193

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32803
MD5 3701b94066f1fe221579da2e3c5faded
SHA1 fa189fa85dad94a186fefeae6e66ccd9ce5fcabe
SHA256 0f34f76703781b711278a8ec7b10d964fc3511a2a3c8fe53abfa9188e504fd47
SHA3 22f719e912799dc30f1658273704c6eebcf3702103bc545b3ee4632694af3845

194

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x64a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23183
MD5 ddb844b3d4607e3185d1ae500dc49402
SHA1 f2972dea57f23127109b4936e785e37c0734d890
SHA256 fbed36628b0bd2970157389233e739c4c3d9641756dbbdb0ff02bb026235f256
SHA3 a5d005004727fa95f823ad9ab3aff75a842f7a1a5c547554ab5152154dcc06bf

195

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x880
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26523
MD5 543fb21ba3d9473d09623b78f90e6ed3
SHA1 345dbbcfaf139a5964299f2596436fe9d03d3782
SHA256 c717db7e814e0977cab9cdd56cbafe79c5044680fe9e39956b2fc1145621dae9
SHA3 9bcbe6a3f5512ecb4c20823e436a09a7812ebf88b0a52f0017c87b219150857c

196

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x848
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27139
MD5 723eadf768c1fcfb323689c0ea70b466
SHA1 2d434c8a87da1443036a849123f60e43aa78baeb
SHA256 f32b9f5c52d4f81bb228cb7f9327ca9f50164c46c25b5cf4f3dddd56caab6f8a
SHA3 ea2fa16c368c282e9af873b1c7700c62202a539e61aee0c82d3d0fd6486142d7

197

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x448
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28768
MD5 7b9ca3fc1b656189b0cb2b4d70cd15be
SHA1 884baab8554f0299a39d15c5287f0b714ab059c0
SHA256 729d6d06843784bd7e71ffd0f2f18d8c0f07caa1c9486c5546c170c727521155
SHA3 a606c0a00cda03cbae30b45869ec0c03f7d5d1cac13f0d999118efb411e92bb3

198

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x33c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26435
MD5 d49cba912846e47524d0ad6a3013f98b
SHA1 b7d75ef0545e4664c31d9cc6f01ce996d03d7889
SHA256 762fe6cc3ecd50c2108fc2f9d9d3c337f10af2470a0dc375889c1cdb977feba6
SHA3 88bdade0608e3d0f6427819b4e71334ba041766907bf7ed0e7a57d0a29e12803

199

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11742
MD5 f17b345b4528cf9fb84054c606a607d0
SHA1 c1040fbd4e63ec4259adcca47c39ae6b49f9e7c6
SHA256 2e7c2739acd229e1c47a8f125fb0ef7827709b150b5c8f716fca233d6e85f991
SHA3 e6eb5b25dfd4a555922f0ba95993e868d36d8830f38b6d8b069e1825300fd264

219

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xc4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88996
MD5 f92f645d0be5d63255c4a66295ee1452
SHA1 d7c4502b13d3e0f09ff00c948f83c9dfd57333fe
SHA256 256614043179483e6827fd3ae97ffb786d8b9439a66a90f2618684e241ce46d2
SHA3 bf85832bd85b7b67f80df0f40a9a74b9ded70c08a3715432bef13afa9cbfb5ff

220

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2471
MD5 c0ccb9206f22a9bc94448949e215fc3d
SHA1 ce8682e70c14796bb6d55c477ae61d6a777b0833
SHA256 8bf4c059054e9a799302bb76b7ef81773a6d18946f24ce7f901007b9cbd89774
SHA3 f772aa628d6c0b19aad304cbc1d0d424a33a9e0948d95d64b277bbf1eca1ba6f

232

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xbda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3228
MD5 47e93881a1b1e9f315514c2cfb1797e5
SHA1 e607fd4c09bc1ba880929e4f7ad9d124a4a6ed6f
SHA256 e15c13e11ad6492c98ae6fe5a76f5b44f6de4424f07ca92878800c24ad46ad1e
SHA3 869b31d937c500d0555c670462f2ce0b2ffc01d8360c80a868609fbf61537db3

251

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xcf4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35159
MD5 1afd6fc4bfea6c7f35d10ebe18c79117
SHA1 955ab9db351ba9bd69dd24887f9599c3d74d9d4b
SHA256 4b7bb198508e6198b957a28ffd0682009396603d86a1ef73751f752e0e08d6f0
SHA3 9be0ae2b73730506ef8a374082489fbc087b53a4d18c1e30855557e70a256688

252

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4de
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17849
MD5 2ac02fc9329b8fc75ff056fd7d60ed79
SHA1 1526d35944bd06d03a9b53aef509dc321dc33ddc
SHA256 8c750d2dd74fe3bd5d8734eef999cc0d028bab2e849798bc93415aeaaaa0970d
SHA3 73266712c38433f5f003e632e17943c5bb0fe8d4430c89139c29eb27f5da806a

253

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16378
MD5 eac94c31473ffb82af306002f503a163
SHA1 596d3bdb225c8c9c34318428573c38303b113529
SHA256 25a80ef8cccad954af40aa7a8998cbadb6af48766d43669c50f61310186891ca
SHA3 3969dd1466b8ef9761bf435d8c14110e930f6dae29e41265f405f7c4b4eb98dd

254

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x386
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19427
MD5 323a71b0ddd07893b4e09df73f220b6c
SHA1 40fcf9a990b95f864347cfa37a0d5c6816340646
SHA256 758591c6b373895b5ef55120b51fcf49d718c82959015957d40433dd74844329
SHA3 484ea1ad182939363542f2ba5b0ebfa15b2cd4136d919a9cab7f0cbb70ae73db

256

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x186
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97787
MD5 e7cd87614819a4476fd521d1d98bdb8b
SHA1 20c42a7f4e590eff323c8f3d71fc0b97ccc42e50
SHA256 afdfceed1af2669a81926a876fe6ad718c822d4deca2503176723a7cb0753e54
SHA3 2725418b79251ee128d72e2a72ec0112d9d351ff4cdb2ce7788b8ebb5bb3413e

257

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x178
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09025
MD5 351316a736815a32b74fda3543da6ae9
SHA1 562ca21c0e804b86a9bb2d64f422488501657465
SHA256 88b26acfbe05081ffcfedb7440d55edf15b7e16fa4595fc5e5c2013af5f10b9d
SHA3 3334d868534f5a6386acf10ed2691cd0f5f2235aaf6481cff8770b248f7a1c8f

258

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16124
MD5 e0196d889580d7d7de66dd9db0c5ec98
SHA1 215dcf144f73fcb603af2215a3f7dc3e841522e0
SHA256 db4efd3ca6b4eb30650c9fb83fee27b833f2ba000fa0e61a67f4cb7f1d150744
SHA3 dbfc8016d200266d29e758ddafb477fc151bc32b336de5f0cc962e87dcc9a149

259

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x852
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26196
MD5 58e5b5901c78a07d0cc9b6cfdee9258e
SHA1 9244acefca33ec6688b793c631d2b2cbd1cee579
SHA256 903f367f684972437298a02077da7d648288fc4696f1e621198328a5479537c4
SHA3 9ee5e15b0954016748faf085d75c89019b25ea59fe0121c64fe5a11e6430723e

313

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x15c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09767
MD5 5b7dba0875e258f1a06643bf0d198d3a
SHA1 3b048e7c6cc2356f7d63d23b1790860ea66c3cc1
SHA256 27eea2b9c524fb4672df5ca81694d0a5c3961303192cbfab200e916003df0242
SHA3 96c422288e90387539c457a7e2a2bec9acf9c0bf1e411f6cbbed92e25ea43f11

314

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x11a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02805
MD5 cea69c1d3e674e201dcb884d3054bb61
SHA1 c8cc3088d25d99b46145c90cb5359af0b77831fe
SHA256 e2d3c76ba9f4a80f1bcd793cadb97ede41369d9cb59a3ee3f129011a856aefd8
SHA3 4f835c157a39e6db03a505306632fff63aa0e94a4456a2287e180860a33c9730

315

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.58119
MD5 44ed5f6bd5f272b11983208f0c7e4423
SHA1 634583c110217a64d3f0427d93decb565ec7afbe
SHA256 8f4e822c8237aebece7d3178a627dbd532e3eaca8be16c3efe409ba7c8f28e20
SHA3 bb72dbae3e6cf28a30f3de7f65edede2f7702c1d67435d5efa7b6fd19a20f86a

316

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66974
MD5 8c44b06b6e358ed365e158f96709e08c
SHA1 6b7cd6cdf755a6ddac04dfc619088936b99f0399
SHA256 3f9209b92b4b7131210b6f3b4fae396e47fde8b42c2a8eda630a5cd9e1ebdaa7
SHA3 cd69fc7c5deaee874170d9c19e0fede1530c21b6f86f929968dda8c3049554f1

317

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x44
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91282
MD5 470daf878a1bca01998f968f1a9f625c
SHA1 c6261f85506f6c0b5684d35a7f649b7d115e2b46
SHA256 64ba67e5a985bd308d67bd8a1aad5a363a18dd65c9b6663e3b1b395e9e6324d8
SHA3 5a873bdb43b8044df3b12da0604cbac90e27d39bcc8ca16a74d8542351788c33

319

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x48
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.90196
MD5 1e49e5823e42f9cee7a945667256d68a
SHA1 588e2f5ccb076279f3757b2c7479e13df80c6ff9
SHA256 474a2055dbbdc5c4f651b4c07bf76fc8c848bbec9a7dd08c836da003ad0fbaa5
SHA3 27f5c311125fbacd48158730315c2adc3d51ef2b95f42549f31e2db778c1a9c4

322

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x54
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91316
MD5 ec893dc95e856f2c507d696172255ae2
SHA1 caa0e3a73190839a586fabb178af8c1855fa581e
SHA256 515aafaa198775a9690f1e4b520b0b3d7f7faeb003127e88d658b00faa3cd1ef
SHA3 0a1ea65e9fcf81919f491cc1a1e79ce5b3f951f25bd9cc4927403db3a8c5df84

376

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xab6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21875
MD5 2cd166ce766c70df37972e58cf6dd56d
SHA1 82933c2f3bdba048b97f8d1a48cc8f8aad5240c6
SHA256 1f0834e4388ee97722a094e77af2456c8c8987ed0dbc958777a4a9b575c7e126
SHA3 ecdb4cc602cfb1d82dcd89be7f20e921cc453ef5218308645c1cbefdf5e58c4b

377

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x980
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2276
MD5 62fda6be58093077851cc8fd01d59113
SHA1 119357bcbae8fde4a77e35c6a1b9faff409187c6
SHA256 6c9758203a71490a827690c1e0e8b940afb1af39f618bbb85a176ae039d18b05
SHA3 e821eddd7e4eaa2b6ba2361da6700be3c964754b4d660b21b6a9a4ee3981c01c

378

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x880
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24318
MD5 772300c2f284f990eb6047e10f5d2904
SHA1 4823e71f88df600a2bb7eb52f8144fef6530207c
SHA256 baaab2fe3d665df1ac0870fffe76bc63d671b31aa7699cc90f00a401c8c30daa
SHA3 aa6ee0af992783702ef79a0c2d74074977fd6848bd5033c45210f7903e31857e

379

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27442
MD5 6e9371d52645f4947dca307bf46823c6
SHA1 46eaf7ae8ea13922a4ea959571b2ad82ee02ea4b
SHA256 1ab9c0c4ff5b15f1c522d703d8be5896acc48c32dd1bd53c4480b056cfefcd45
SHA3 b6c0d2d038d5cd82191a25b2a4edd780512c54434c76a9c962dba1882c1adbf1

380

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x492
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36591
MD5 30ba0c8d42397467ff6ae1bc92282c38
SHA1 dab64bb9a2803f691f270a75d6b144d9fe1dd236
SHA256 862e507dedd49cde302fa60acc7d13a146e63d50e2c273794cbf04e0a7bcb5f6
SHA3 f60e4c7e37947cfcdf89908e34bdf239936c2183c3c49d46276a1a024f8af2ed

381

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa3c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37884
MD5 3ad9a0ae7ed9e2b87cc28dce58d9c9ae
SHA1 ce4a1d18fd0495ec68835ed0303fc470a6b5c95d
SHA256 b4e2b150f17612e0a68c9674304ab8a3bc9c7a3f03e7d0f50adae4f6e3115b9c
SHA3 9afe2191e1730de453f32abb76ad4891100e2a2e210b0195e67f33c2d58af1d4

382

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x906
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.47357
MD5 ed2372ec6b892e4588e5ce411e1c46e1
SHA1 42050bc04d36d3d41152f60971f66c4fc711192e
SHA256 9a159327811c0d7f397d78d2c70d51cc507426e2dea887ffa175b69476c72c5a
SHA3 608e98334f1b27f0688bc014e74cea2ad834a715c6724fafeaec6376413875d8

383

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xb78
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39967
MD5 267b2c051763f130609b37be105cce36
SHA1 37446811d1e4b716fc2fdf4c018447bd45e406b6
SHA256 7f847bd5b7b42c5fb26ecce3dcba58b35cbdb42242bd641a284f79639d598a25
SHA3 39c60a0911bc7cfe488580296d5c8d0adc19d973ba45e62455598a3e4f8c5ec9

384

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x90c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32675
MD5 64b30c55991a8d48fb511ac0976f53c7
SHA1 061a2f84e6a489dee64bcd17e771df06f701a44e
SHA256 c60d2c69e386541efed750fa6db0b81fbd8b6395f8d69228758da30208959b80
SHA3 51fcf00333470933964d727687b1c56084696fbfa04209eac5ae57db3f6778eb

438

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x64c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.17404
MD5 5073c8f4e06038444b893ac00c1b1b29
SHA1 941d7ff5dbca8feddc9e32b202ec04f4c1aa8df2
SHA256 cfee63bd76be7621cd6553247056417673c84fc075ca9304e9a8f3d031922adf
SHA3 a000223c716513639babb9aeda10b6181d2cf81e231a549c9c50be62cddff275

439

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x790
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20859
MD5 5bd7f701bfd06e2b2fb99aea6abd98d4
SHA1 0f8b21563c4eb5a17df6e7efc3179be8adc9119b
SHA256 a98658d4d40756e1db6c6b9df8874b83b4aac3e3785c8ea28b112fe85d7cb3a4
SHA3 cd93022311cc2424b5994560119aef9b0129a14f4142c31bc3c2e2a223650ada

440

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x68a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30968
MD5 61d77cb532538fd41cb4bf19611ec79e
SHA1 4a5520573c26aaf0771ad7bb5bbf14316a73da3a
SHA256 6656edeedcca38ff4bb87c92088e4961c360d0ed969a915693408932ab9d10d1
SHA3 4384ecbff749b2db543cb1f05f3302c4ea1bc15697a705def25d0a1a27ae5c74

449

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.95029
MD5 810a482d22f679d9e4196e8f66073a49
SHA1 6a4ecc33a8a26bded1dd37a940ab1b430d37b1e7
SHA256 615c3372f956fe6e17eaa83d3152eff1a565c716187b66948ab13dca084cee1a
SHA3 3724e173d24c01d72bb328cda62b655114de3cfd38cd80ceefcddea6ea72ca42

101

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65982
Detected Filetype Icon file
MD5 6fa39a5f6db3ad3489ae7c80de34d0af
SHA1 461e0c84813d6c2f9e33b08cb928a69d5f3e97cf
SHA256 d58d7d4bbc58f023d4bb203dd967e15f6681460612b02ad935e7ff3979dc6102
SHA3 5b2e3150d50439424a0da2167805f6606a0d1cabed9ce800c5e259a72a21d091

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x844
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.98652
MD5 353e5961233208b23fb35ef72f651a51
SHA1 9e06544335e21dab783f19ca7220cc3d03a63327
SHA256 558a3d85b6d7deaa114263cd833cbb18562e9fd8563b6beb69097170970f2e96
SHA3 680407dd4f53423bcc171bf61c4fa8d050708e45aae3fedbee71dbe902c03752

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x711
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33138
MD5 bc38fa7cc614038de0ca3b13773ef25a
SHA1 b6e08510d5f87d1e8bf7006aeaa970c11991313e
SHA256 0e89f24f5de4d9159a2380aa5df2520270a1e0bc4023a274329e772f8c5650f0
SHA3 9ce6c6b2369416662b87bd348ab54e6054cd966e0825bcd798ee8ce8c471d068

String Table contents

_scenario_admin_culture_en-us_lcid_1033_platform_x86_productreleaseid_none_
Something went wrong
&Close
Ready to uninstall?
&Uninstall
Uninstalling...
We're removing Office from your computer now.
Close
Done uninstalling!
Repairing Office
We're working on repairing your Office programs.
Repairing...
&Cancel
Save your work before continuing
We need to close the following apps:
C&ontinue
&Cancel
Welcome to your new Office!
We're getting things ready
%d%% - Streaming Office...
We tried to close the program called '%s', but weren't able to.
Please try closing this program yourself and retry once it has been closed. If this doesn't work, you may need to restart your computer.
Please close programs
&Yes
&No
Please save your work first, otherwise you may lose unsaved changes.
Other users have programs open on this computer, so closing these programs may cause them to lose unsaved changes.
We need to close some programs but weren't able to.
Please restart your computer and try again.
Microsoft Office
Streaming program features ...
Microsoft Office
Starting program ...
Office is installing in the background (%d%%)
Please don't go offline or restart your computer.
Office is installing in the background.
Click here for status.
Step 1 of 4
Step 2 of 4
Step 3 of 4
Step 4 of 4
Please reconnect to the internet
Office is still installing in the background and needs an internet connection to finish.
Please reconnect and your installation will pick up where it left off.
Installation is finished!
Your Office product is now completely installed.
You can now go offline or shut down.
Ready to start a Quick Repair?
This shouldn't take very long, but you won't be able to use your Office programs until we're done.
&Repair
Repairing...
We're repairing your Office programs and features.
This shouldn't take long. Thanks for being patient.
Working on it...
Done repairing!
We've finished repairing your Office programs and features.
You can now close this window and use your programs.
Close program?
This means you'll lose any unsaved changes.
Office is busy
We're sorry, %s can't be used right now because Office is busy. We're either updating or helping you add or remove some programs.
You can try using %s again after we're done. It shouldn't take long.
<a href="%s">You can go online to find more help.</a>
Error Code: %s
Microsoft Office Service
Manages resource coordination, background streaming, and system integration of Microsoft Office products and their related updates. This service is required to run during the use of any Microsoft Office program, during initial streaming installation and all subsequent updates.
How would you like to repair your Office programs?
Quick Repair
Online Repair
Fixes most issues quickly without the need for an internet connection.
Fixes all issues, but takes a little longer and requires an internet connection throughout. You can select this option if you are still having problems after a Quick Repair.
&Retry
&Uninstall
&Ignore
Office needs the installation disc
Microsoft Office is still installing in the background and requires the disc. Please insert the disc immediately.
Closing apps...
Please wait while we close your apps.
Uninstalling will remove all %s programs, so you won't be able to use them anymore.
We noticed you have other Office programs installed. These will stick around, but we recommend repairing them from 'Programs and Features' in the Control Panel once we're done.
Office is updating
Installing updates for Office
Office update complete
Office has been successfully updated.
Office updates are available
Updates are available for Office. Would you like to apply the update for build %s now?
Click here to install the Office updates.
We'll remove the programs and files you requested from your computer.
We've successfully removed %s from your computer.
It's not required right away, but we recommend that you restart your computer soon so we can tidy up a few remaining files.
Ready to start an Online Repair?
We'll download files to repair your installation. This may take some time and requires an internet connection.
If you're on a metered connection, this may charge extra. Please keep this in mind when getting online content.
Minimize
Click here to download them now.
Downloading Office updates...
You can keep using Office while we download in the background.
Office updates are available
New updates are available for Office. We can download them in the background and won't interrupt your work.
We noticed your internet connection may have a data limit, so you could be charged for the data used to download these updates.
Do you want to start downloading updates now?
Download updates for Office?
New updates for Microsoft Office are available. They will be downloaded in the background and will not interrupt your work in Office.
You may incur data charges if you download these updates.
Do you want to start downloading the updates now?
Always allow Office updates when connected to this network
Download Now
Postpone
Office may appear unresponsive...
We're streaming a few required files in the background. This shouldn't take long.
Office needs your attention
We need your permission to continue. Please click here to finish installing in the background.
Checking for updates
You're up to date!
The latest version of Office is installed on your computer.
The latest version of Office approved by your system admin is installed on your computer.
Applying updates...
Finalizing updates...
Microsoft Office Click-to-Run Service
Office Updates Available
We need to close your Office apps to install the updates.
Office will update in %s %s
We need to close your Office apps to install the updates.
You should save your work now.
If you select 'Postpone', the installation will be postponed for 2 hours.
Office is updating
1||2-
minute||minutes
second||seconds
Update now
Remind me later
Postpone
We need to close your Office apps to install the updates.
You should save your work now.
We need to close your Office apps to install the updates.
You should save your work now.
Last chance to postpone the installation for 2 hours.
Updates were installed
Your Office updates have been installed. You can use your Office apps now.
&Ok
Office will update soon
We can't start another Uninstall or Repair operation right now.
Please try again later. If the problem continues, restart your computer and try again.
<a href="%s">You can go online for more help</a>
Office Background Streaming
Office Automatic Updates
Office Subscription Maintenance
Updating Office, please wait a moment
Unable to start Office
We couldn't open Office because we're updating, adding or removing programs.
Please try again later.
<a href="%s">You can go online to find more help.</a>
Error Code: %s
All done!
Office is now installed.
We recommend that you restart your computer. Save and close any open files before you restart.
Background installation ran into a problem
Please make sure you're still connected to the internet, or try connecting to a different network.
We'll automatically resume installation as soon as possible, and you can keep working once we do.
<a href="%s">You can go online to find more help.</a>
Please make sure the Office installation disk is inserted and that there's enough space on your hard drive to install Office.
We'll automatically resume installation as soon as possible, and you can keep working once we do.
<a href="%s">You can go online to find more help.</a>
Please make sure you're still connected to the internet and that you have permission to install Office from this network location.
We'll automatically resume installation as soon as possible, and you can keep working once we do.
<a href="%s">You can go online to find more help.</a>
Please make sure there's enough space on your hard drive to install Office.
We'll automatically resume installation as soon as possible, and you can keep working once we do.
<a href="%s">You can go online to find more help.</a>
We need to remove some older Office apps
We'll have to remove the following product to complete the installation:
%s
This product doesn't work with your new Office.
<a href="%s">Learn why</a>
We'll have to remove the following products to complete the installation:
%s
These products don't work with your new Office.
<a href="%s">Learn why</a>
https://go.microsoft.com/fwlink/?LinkId=613501
&Install Anyway
&Cancel
Sorry, we ran into a problem.
We're sorry, we couldn't install Office because there isn't enough free space on your hard drive. We'll need %s MB of free disk space to install.
We're sorry, but Office needs Microsoft Windows 7 (or later) to install.
<a href="%s">Go online to look for additional help.</a>
We're sorry, Office (64-bit) couldn't be installed because 32-bit Office programs are already installed on your computer:
%s
If you need 64-bit Office, please uninstall the above programs first. Otherwise, we recommend installing the 32-bit version of Office instead.
<a href="%s">Go online to look for additional help.</a>
We're sorry, Office (32-bit) couldn't be installed because 64-bit Office programs are already installed on your computer:
%s
If you need 32-bit Office, please uninstall the above programs first. Otherwise, we recommend installing the 64-bit version of Office instead.
<a href="%s">Go online to look for additional help.</a>
An unexpected error occurred in the %s task. This is probably unrecoverable. You may need to clean up and attempt to reinstall. Visit http://c2r to learn how to submit your log files.
We ran into a problem. Please try installing Office again.
We're sorry, Office couldn't be uninstalled. Please try uninstalling Office again.
We're sorry - please try repairing again.
If a Quick Repair failed, you can do an Online Repair instead, or try restarting your computer before repairing.
%s
<a href="%s">Go online for additional help.</a>
Error Code: %d-%d %s
Sorry, Office ran into a problem because its system service is disabled. Please ensure the Office system service can run, then try again.
We couldn't start your program. Please try starting it again.
If it won't start, try repairing Office from 'Programs and Features' in the Control Panel.
<a href="%s">You can go online to find more help.</a>
Sorry, we can't find a required file. Please check that the installation source is reachable, then try again.
Sorry, we ran into a problem accessing a required file. Please check that the installation source has the correct permissions, then try again.
Sorry, we ran into a problem streaming Office. Please try again later.
Sorry, we ran into a problem. Please try again after restarting your computer.
We're sorry. We ran into a problem while installing and couldn't finish everything.
If another program is installing, please wait for it to finish then click Retry.
If you click Ignore, you might need to repair your Office from 'Programs and Features' in the Control Panel later.
We're sorry. We ran into a problem while installing and couldn't continue.
If another program is installing, please wait for it to finish and then click Retry.
&Cancel Installation
We are unable to configure the office package
We are unable to add and/or remove the products you are requesting. Please verify that you have the correct set of products.
Sorry, installation cannot continue because no compatible Office products are detected.
You're trying to install a version of Office that isn't compatible with another Office product. Office 2013 is not compatible with versions of Office 2016 prior to 16.0.7167.2040.
We are unable to install fonts
Sorry, we ran into a problem starting your program. Please try starting it again, or Repair Office from 'Programs and Features' in the Control Panel.
We're sorry, but Office needs to be repaired. Please Repair Office from 'Programs and Features' in the Control Panel.
<a href="%s">You can go online to find more help.</a>
Sorry, we weren't able to start your program. Please try starting it again.
If it still won't start, you can try repairing Office from 'Programs and Features' in the Control Panel.
Sorry, we weren't able to start your program. Please try starting it again, or try repairing Office from 'Programs and Features' in the Control Panel.
Sorry, we ran into a problem updating Office. Please try starting updates again. If you still see this message, you may also need to restart your computer before updating.
We're sorry, we ran into a problem while looking for updates. Please check your network connection and try again later.
We're sorry, we ran into a problem while downloading updates for Office. Please check your network connection and try again later.
We're sorry, we ran into a problem while updating Office. Please try again after restarting your computer. If you continue to experience problems, repair Office from 'Programs and Features' in the Control Panel.
We're sorry, but we ran into an error and couldn't start your program.
Please try starting your program again, or use the Repair option from the Programs and Features item in your Control Panel if it still won't start.
<a href="%s">You can go online to find more help.</a>
We couldn't start your program. Please try starting it again.
If it won't start, try repairing Office from 'Programs and Features' in the Control Panel.
<a href="%s">You can go online to find more help.</a>
Error Code: %s
Streaming
Office can't do that right now because your product is busy with another task. Please wait for this task to complete and try again.
<a href="%s">Go online to look for more help.</a>
We're sorry, but we are unable to start your program.
Please ensure it is not disabled by the system.
Online Repairs need the internet and it looks like you may not be connected.
You can try a Quick Repair while offline, or try an Online Repair again once you're connected.
<a href="%s">If you think you are connected, you can go online to get more help.</a>
Something went wrong
Please free up some disk space
Office needs a later version of Windows
We found a problem
We found a problem
Sorry, we couldn't install Office
Couldn't uninstall Office
Couldn't repair Office
Something went wrong
Couldn't stream Office
Access denied to installation source
Couldn't stream Office
System restart required
We couldn't install some Office features
We couldn't install Office
We found a problem
Please repair Office
Internet connection needed
Continuing could be expensive
You're connected to a network that limits downloads every month.
We need to stream some large files over your network connection to install Office, so we recommend installing while connected to an unrestricted network.
If you are sure you won't be charged or exceed your limits by dowloading a large amount, you can choose OK to download and install. Otherwise, you should Cancel and install when connected to a different network.
Stopping installation, continuing would be too expensive
We're sorry, but you're connected to a network that will charge you for every file you download.
We need to stream some large files over your network connection to install and we don't want you to get stuck with the bill.
Please retry installing when you are connected to a different, unrestricted network.
Administrative Privileges Required
Installation requires administrative privileges to make changes to your computer.
Please retry installing this product and give the required permission when prompted.
If you cannot give these permissions to install, ask your system administrator to help you.
Couldn't install
We're sorry, we had a problem installing your Office program(s).
Is your internet connection working? Do you have enough free space on your main hard drive?
Please try installing again after you've checked the above.
Office needs a newer version of Windows
We're sorry, we couldn't install your Office product because you don't have a modern Windows operating system.
You need Microsoft Windows 7 (or newer) to install this product.
Couldn't Install Office
We're sorry, Office couldn't be installed.
Please save the file you used to start this installation to a place you can find easily. Then use Windows Explorer to view that location and try installing Office again.
We found a problem!
We found a pre-release or Beta version of an Office product on your computer and can't install because of it.
Please Uninstall any pre-release Office software using the Programs and Features item in your Control Panel and try installing again.
We're sorry, but we can't verify the signature of files required to install your Office product.
We need to verify these signatures to keep your computer safe.
Please retry installing your product or, if installation continues to fail, try re-downloading your installer if you got it online. Make sure you only download Office products from a trusted source.
We found a problem!
We're sorry, Office does not work with Windows 8 Consumer Preview.
You need the full version of Windows 8.
We're sorry, Office (64-bit) couldn't be installed because you have these 32-bit Office programs installed on your computer:
%s
64-bit and 32-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 32-bit version of Office instead, or uninstall your other 32-bit Office programs and try this installation again.
We're sorry, Office (32-bit) couldn't be installed because you have these 64-bit Office programs installed on your computer:
%s
32-bit and 64-bit versions of Office programs don't get along, so you can only have one type installed at a time. Please try installing the 64-bit version of Office instead, or uninstall your other 64-bit Office programs and try this installation again.
We're sorry, we can't continue because we weren't able to download a required file. Please make sure you're connected to the internet or connect to a different network, then try again.
Please free up some disk space
We're sorry, we couldn't start installing Office because available disk space is too low.
Couldn't start Office installation
We're sorry, but we could not successfully start your Office installation. Please try again later.
Setup Failed
A newer version of Setup is required to install this product
We're sorry, but we could not start your Office installation. Another installation is in progress. Please try again later.
&Close
%s
<a href="%s">Go online for additional help.</a>
Invalid product %s specified.
Error configuring products!
We're getting things ready
We need to remove some older products
Some older products don’t work with Office 2016. Before installing the new Office, we need to remove:
%s
Important: Once we’ve removed these products, you won’t be able to install the old version again.
Remove and Continue
&Cancel
Couldn't Install Office
We are sorry, but we could not complete the installation.
We hit an issue trying to uninstall your previous Office version.
<a href="%s">Go online for additional help.</a>
https://support.microsoft.com/kb/2739501
Save your work before continuing
We need to close the following apps:
C&ontinue
&Cancel
Couldn't Install Office
We're sorry, Office (64-bit) couldn't be installed because your computer does not support 64-bit applications. Please try installing the 32-bit version of Office instead.
We're sorry, we had a problem installing your Office program(s).
Please make sure the Office installation disk is inserted. Do you have enough free space on your main hard drive?
Please try installing again after you've checked the above.
We found a problem!
We're sorry, Office Click-to-Run installer encountered a problem because you have these Windows Installer based Office programs installed on your computer:
%s
Click-to-Run and Windows Installer editions of Office programs don't get along for this version, so you can only have one type installed at a time. Please try installing the Windows Installer edition of Office instead, or uninstall your other Windows Installer based Office programs and try this installation again.
Microsoft Office
%s
<a href="%s">Go online for additional help.</a>
Error Code: %s
Client update needed.
We are sorry, but we could not complete the installation. Please try again later.
https://go.microsoft.com/fwlink/?LinkId=613501
<a href="%s">Learn more</a>
This installation requires a compatible Microsoft Office program installed on your computer.
Stop, you should wait to install Office 2016
We'll have to remove the following if you continue:
%s
These products don't work with Office 2016 right now. We're working on a solution.
<a href="%s">Learn why</a>
We'll have to remove the following if you continue:
%s
This product doesn't work with Office 2016 right now. We're working on a solution.
<a href="%s">Learn why</a>
I understand. I don't want to wait.
&Install Anyway
I'll &wait
Good News!
We're also upgrading:
%s
<a href="%s">Learn why</a>
&Install
&Cancel
Stop, you should wait to install Office 2016
You won't be able to receive mail from a current mailbox.
%s You may want to contact your mailbox provider or system administrator about this issue.
<a href="%s">Learn why</a>
Business Contact Manager will no longer work.
%s
<a href="%s">Learn why</a>
You won't be able to receive mail from a current mailbox. Business Contact Manager won't work.
%s You may want to contact your mailbox provider about these issues.
<a href="%s">Learn why</a>
Outlook 2016 is not compatible with Exchange 2007.
Outlook 2016 requires access to the AutoDiscover service for your Exchange service.
Business Contact Manager is not compatible with Outlook 2016.
&Install 32-bit
&Install 64-bit
This installation is for the 64-bit version of Office, but the following 32-bit Office applications are already installed on this computer:
%s
Want to install 32-bit Office, which will work with your 32-bit applications? Select "Install 32-bit". If you want the 64-bit version, select "Cancel", uninstall your 32-bit Office applications, and start this 64-bit installation again.
This installation is for the 32-bit version of Office, but the following 64-bit Office applications are already installed on this computer:
%s
Want to install 64-bit Office, which will work with your 64-bit applications? Select "Install 64-bit". If you want the 32-bit version, select "Cancel", uninstall your 64-bit Office applications, and start this 32-bit installation again.
Sorry, 64-bit and 32-bit Office can’t be installed together
%s
<a href="%s">Help: Installing 64-bit or 32-bit.</a>
Please Wait
Office is already being installed.
For install status, check the Office notification in the Windows taskbar.
We can't install
The following product(s) can’t be installed at the same time:
%s
We can't install
To install this product, first uninstall the following product(s) and try again.
%s
%s
<a href="%s">Go online for additional help</a>
You need Windows 10 to continue
This Office product requires Windows 10. Please upgrade Windows and try installing Office again.
%s
<a href="%s">Help: Upgrading Windows</a>
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.
We can't install
This product can't be installed on the selected update channel. Please contact your system administrator and try again.
Couldn't stream Office
Sorry, we can't find a required file. Please check that the installation source is reachable, then try again.
We found a problem!
We found an Office 2013 product on your computer and can't install because of it.
Please uninstall any Office 2013 products using the Programs and Features item in your Control Panel and try installing again.
Can't install this version of Office
Windows 10 in S mode doesn’t support this version of Office.
Use Office Version 1902 or later, or switch out of S mode.
Can't install this version of Office
This version of Office requires a newer version of Windows.
We recommend you move to Windows 10.
%s
%s
<a href="%s">Learn more</a>
Downloading office at %d Mbps. This is too slow to have a great streaming experience; programs may become unresponsive.
Downloading office at %d Mbps. Your network is the bottleneck for streaming. This is too slow to have a great streaming experience; programs may become unresponsive.
Downloading office at %d Mbps. Your CPU is the bottleneck for streaming. This is too slow to have a great streaming experience; programs may become unresponsive.
Downloading office at %d Mbps. Your hard drive is the bottleneck for streaming. This is too slow to have a great streaming experience; programs may become unresponsive.
Downloading office at %d Mbps. Your anti-virus software is the bottleneck for streaming. This is too slow to have a great streaming experience; programs may become unresponsive.
Downloading office at %d Mbps. This is a little slow for streaming; programs may be slow to respond.
Downloading office at %d Mbps. Your network is the bottleneck for streaming. This is a little slow for streaming; programs may be slow to respond.
Downloading office at %d Mbps. Your CPU is the bottleneck for streaming. This is a little slow for streaming; programs may be slow to respond.
Downloading office at %d Mbps. Your hard drive is the bottleneck for streaming. This is a little slow for streaming; programs may be slow to respond.
Downloading office at %d Mbps. Your anti-virus software is the bottleneck for streaming. This is a little slow for streaming; programs may be slow to respond.
Downloading office at %d Mbps.
Downloading office at %d Mbps. Your network is the bottleneck for streaming.
Downloading office at %d Mbps. Your CPU is the bottleneck for streaming.
Downloading office at %d Mbps. Your hard drive is the bottleneck for streaming.
Downloading office at %d Mbps. Your anti-virus software is the bottleneck for streaming.
Sorry, it looks like you're on a slow connection, so this might take a while.
Downloading
We were unable to download Office. Please check your internet connection and try again.
You have a newer version of Office installed
We have detected these newer versions of Office installed on your device.
%s
If you want to install an older version of Office, please remove these newer products and try again.
<a href="%s">Learn more about removing Office products</a>
&Close
https://support.microsoft.com/kb/2739501
We have detected newer versions of Office installed on your device.
If you want to install an older version of Office, please remove the newer products and try again.
<a href="%s">Learn more about removing Office products</a>
Microsoft Office Logo

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 16.0.12827.20258
ProductVersion 16.0.12827.20258
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
CompanyName Microsoft Corporation
FileDescription Microsoft Office
FileVersion (#2) 16.0.12827.20258
InternalName Bootstrapper.exe
LegalTrademarks1 Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2 Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename Bootstrapper.exe
ProductName Microsoft Office
ProductVersion (#2) 16.0.12827.20258
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2020-May-28 20:24:24
Version 0.0
SizeofData 280
AddressOfRawData 0x2f2108
PointerToRawData 0x2f1508
Referenced File d:\dbs\el\apr\target\x86\ship\click2run\en-us\AdminBootstrapper.pdb

IMAGE_DEBUG_TYPE_RESERVED

Characteristics 0
TimeDateStamp 2020-May-28 20:24:24
Version 576.27412
SizeofData 4
AddressOfRawData 0x2f2220
PointerToRawData 0x2f1620

TLS Callbacks

StartAddressOfRawData 0x809238
EndAddressOfRawData 0x809300
AddressOfIndex 0x86ae5c
AddressOfCallbacks 0x6f3f94
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00672EE4
0x00672F62

Load Configuration

Size 0xa0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0x800
EditList 0
SecurityCookie 0x8552e4
SEHandlerTable 0x805d04
SEHandlerCount 3355

RICH Header

XOR Key 0x74271c20
Unmarked objects 0
ASM objects (26715) 24
C++ objects (26715) 196
ASM objects (VS 2015/2017 runtime 26706) 25
C objects (VS 2015/2017 runtime 26706) 39
C objects (41204) 7
ASM objects (41204) 2
263 (26715) 2
C objects (26715) 37
262 (26715) 5
Imports (26715) 25
Total imports 844
C++ objects (VS 2015/2017 runtime 26706) 132
C++ objects (VS2017 v15.9.16-18 compiler 27034) 150
265 (VS2017 v15.9.16-18 compiler 27034) 1304
Resource objects (VS2017 v15.9.16-18 compiler 27034) 1
151 1
Linker (VS2017 v15.9.16-18 compiler 27034) 1

Errors

<-- -->