7046d66fccd3baf83353d6ba00267ef82b6ce822239672ce9a5c0824dda99721

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2016-Apr-14 06:30:19
Detected languages Chinese - PRC
English - United States
Debug artifacts Embedded COFF debugging symbols

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Microsoft Visual C++ 8.0
MSVC++ v.8 (procedure 1 recognized - h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • OpenLibSys.org
  • crl.globalsign.net
  • crl.microsoft.com
  • globalsign.net
  • http://crl.globalsign.net
  • http://crl.globalsign.net/ObjectSign.crl0
  • http://crl.globalsign.net/Root.crl0
  • http://crl.globalsign.net/RootSignPartners.crl0
  • http://crl.globalsign.net/primobject.crl0
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
  • microsoft.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Suspicious The PE is possibly packed. Unusual section name found: .xdata
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • FindWindowW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegDeleteKeyExW
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegEnumKeyExW
  • RegEnumValueW
  • RegFlushKey
  • RegLoadKeyW
  • RegOpenKeyExW
  • RegQueryInfoKeyW
  • RegQueryValueExW
  • RegReplaceKeyW
  • RegRestoreKeyW
  • RegSaveKeyW
  • RegSetValueExW
  • RegUnLoadKeyW
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetForegroundWindow
  • MapVirtualKeyW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Interacts with services:
  • CreateServiceW
  • DeleteService
  • OpenSCManagerW
  • OpenServiceW
Enumerates local disk drives:
  • GetDriveTypeW
  • GetLogicalDriveStringsW
  • GetVolumeInformationW
Can take screenshots:
  • BitBlt
  • CreateCompatibleDC
  • FindWindowW
  • GetDC
  • GetDCEx
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC+8 timezone.
Suspicious The file contains overlay data. 1950862 bytes of data starting at offset 0x6b1a00.
Suspicious VirusTotal score: 1/72 (Scanned on 2026-03-24 15:16:14) Rising: HackTool.VulnDriver/x64!1.D7DB (CLASSIC)

Hashes

MD5 3925905025d80a25d3f611524ffa28f3
SHA1 9b321acae7b7ccacf2f9944b08399896721ecec0
SHA256 7046d66fccd3baf83353d6ba00267ef82b6ce822239672ce9a5c0824dda99721
SHA3 d639444f4b33b2aab493ecdcc1a9a303bf6f24f7924715d0a8c9af41b82a55e0
SSDeep 98304:8gGee/Xm+xBCUNlS376zA2BHpT7Hjxn825gsa+:8gULN
Imports Hash 42e448b441b1d14b70104c6db29f727d

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x200

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 12
TimeDateStamp 2016-Apr-14 06:30:19
PointerToSymbolTable 0x6b1a00
NumberOfSymbols 22172
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32+
LinkerVersion 8.0
SizeOfCode 0x320000
SizeOfInitializedData 0x21f000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000003640 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x70b000
SizeOfHeaders 0x610
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 e0a799a6c08a5317259e4a757dc39c95
SHA1 b02bc26b69545e419eeca77f3b10073e4df1294b
SHA256 e1bf0659a18f93ec8eb5a1a7e19b953d82a72b9629d6b789b0cc1e4e710cf0b2
SHA3 6099829a2d8ff942c900e5523032a51737db04840d11374db96ac6cb871b3e7f
VirtualSize 0x31fba0
VirtualAddress 0x1000
SizeOfRawData 0x31fc00
PointerToRawData 0x800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.09637

.rodata

MD5 de0f0c23021ae78c79ee4ce98140bd6e
SHA1 34a5b8f1aff57ff54c9c5cf8ba1a711a43b21fa9
SHA256 29a13e33623f5b5c72e2109c2556139b7187ad9720341f432e4e22be2545549a
SHA3 e79a199fe3875f6e530d7cc0cc237f4292ed7d83b3cb37dd5beafe53f1448cd3
VirtualSize 0x21e130
VirtualAddress 0x321000
SizeOfRawData 0x21e200
PointerToRawData 0x320400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.59945

.data

MD5 cba1b303b8a97cda6c30144918a214ea
SHA1 b1e974a1c78c7ec1b219b5fb8b09b6de7c2e3d38
SHA256 6ab0d60b3da8f91cfc350e11ad3c1f1b05f26917328bc13137aef2d78b97816c
SHA3 e6862c0d5ee3f32a078d73c68549b03f0239125828cf923c98745d1323df69ed
VirtualSize 0x7388c
VirtualAddress 0x540000
SizeOfRawData 0x21c00
PointerToRawData 0x53e600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.7159

.tls

MD5 3d496946426588d19a54e41d386c4e4e
SHA1 513630a1ce9fb7e8b616261a36d80e2006e94561
SHA256 c8ee2b797dd9b492af1ae1f02df98103f1a52643f6690f70b5e23c88a1aa06bd
SHA3 9b0f0672df701a6a09b18330d644aec0074f712559b26a3aa388be95a353ddc2
VirtualSize 0x300
VirtualAddress 0x5b4000
SizeOfRawData 0x400
PointerToRawData 0x560200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.367089

.pdata

MD5 b304dde22aea087bcc700f4f417018f2
SHA1 614ae93b7b302e6549d90faf7c746aefb8fa0429
SHA256 d19351feeb1a316328d61fe866846e08c535badb2aee2622e65015defe7a21ff
SHA3 1f35346c7435e7160c09bef920ad14299b92cdae6ce96a1e321d2d2c035afd80
VirtualSize 0x6d2f0
VirtualAddress 0x5b5000
SizeOfRawData 0x6d400
PointerToRawData 0x560600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.12256

.xdata

MD5 f21fcb94128cb9d0738a2a29d7361a2c
SHA1 a529b0610e321470d49e681539e8452b4d9cc4db
SHA256 e38cfa6474069d82aa68b8087dfbd49c70047e9d4c61f4b5198d698de98f2e8c
SHA3 19a30449d1f698879a10de4f26e626c5e98c3f1481a4297c1954305e1c04918e
VirtualSize 0x73f90
VirtualAddress 0x623000
SizeOfRawData 0x74000
PointerToRawData 0x5cda00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.48825

.rdata

MD5 c68cafdfb4ba553cfba941bfb3132f03
SHA1 7f3235da125cec53c95bf1954e6cf5317444cc2e
SHA256 a78bdf6f48a71b8efa79978dcd9cab21660aeb57b0c038cd24466affb69aa7ed
SHA3 17dfbf495febd3876f05077af71565ece10b45338a1187b71d78f8ed1ceb4a60
VirtualSize 0x28
VirtualAddress 0x697000
SizeOfRawData 0x200
PointerToRawData 0x641a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.199776

.idata

MD5 9a21ef4abcfb9d6e6f35ebf9148ec810
SHA1 060c6271544e08cb7bf55ec813269b938c1ee3c0
SHA256 7815234d2ff664bb742613d08db4de051992d257f825c61391c1e08b8662a88c
SHA3 a4e71ea76298ea4dbd406a690e82bcb165d55cd3b7f782e4897fe2c50a036c49
VirtualSize 0x5507
VirtualAddress 0x698000
SizeOfRawData 0x5600
PointerToRawData 0x641c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.33568

.didata

MD5 967a9aa2184dee3315532a282d2781f2
SHA1 0826920763d1876517da1cd88320dd0001854c68
SHA256 bd2416430a6b29f4e31ad63a305ce7186bcb9bc574f3a5bd1da5493f6a3af74e
SHA3 7648d1bfb7c286848ed4520b7b6ab93b734735bd2ad4a39f0af224a6b8301594
VirtualSize 0x1362
VirtualAddress 0x69e000
SizeOfRawData 0x1400
PointerToRawData 0x647200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.77155

.edata

MD5 26a78081f352d6e4ee0e37e38e29bede
SHA1 f73abfb72e8ee56608aea9496ccb263d10e83d64
SHA256 6579583788174c35e78fbf9627822877464f6da35d7e7bc356d69fec7c6e9e24
SHA3 f05855759b3e22100328708c0e6bc1d1e165fab871f89f43fbb0046d2300c2e4
VirtualSize 0x51
VirtualAddress 0x6a0000
SizeOfRawData 0x200
PointerToRawData 0x648600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.849817

.rsrc

MD5 4233b90604956ca3cb416b0ab1639f5e
SHA1 2080e70f47a8be53e2ac0b26919a2c15e9452f9b
SHA256 70b422b07407d112293f3a29dcbff57b35f42dce24107e9b0f2554c27f8dbc15
SHA3 8bc6c53bf4f77a8fb9adeda0b01835a76846d6e276895549671b7b37131d1ed8
VirtualSize 0x2fa00
VirtualAddress 0x6a1000
SizeOfRawData 0x2fa00
PointerToRawData 0x648800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.16347

.reloc

MD5 50341cb69d9ba0b782a65f454e8b2297
SHA1 b6718cf80b099b6c436d1ea70ddb523a526c4f8b
SHA256 f152490d7fcca3134b05648ee5da5004e51141fc175273c9d4cf960c0a9557d4
SHA3 afc36db40d13845157399bbec1bbc30fff1a2b25647ce45e05bf67667fe8e7f9
VirtualSize 0x39658
VirtualAddress 0x6d1000
SizeOfRawData 0x39800
PointerToRawData 0x678200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.52254

Imports

SETUPAPI (EMPTY)
ADVAPI32 CloseServiceHandle
CreateServiceW
DeleteService
DeregisterEventSource
OpenSCManagerW
OpenServiceW
RegCloseKey
RegConnectRegistryW
RegCreateKeyExW
RegDeleteKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyExW
RegEnumValueW
RegFlushKey
RegLoadKeyW
RegOpenKeyExW
RegQueryInfoKeyW
RegQueryValueExW
RegReplaceKeyW
RegRestoreKeyW
RegSaveKeyW
RegSetValueExW
RegUnLoadKeyW
RegisterEventSourceW
RegisterServiceCtrlHandlerW
ReportEventW
SetServiceStatus
StartServiceCtrlDispatcherW
KERNEL32 AddVectoredExceptionHandler
CloseHandle
CompareStringA
CompareStringW
CreateDirectoryA
CreateEventW
CreateFileA
CreateFileMappingW
CreateFileW
CreateThread
DeleteCriticalSection
DeleteFileA
EnterCriticalSection
EnumCalendarInfoW
EnumResourceNamesW
EnumSystemLocalesW
ExitProcess
ExitThread
FillConsoleOutputAttribute
FillConsoleOutputCharacterA
FindClose
FindFirstFileW
FindResourceA
FindResourceW
FormatMessageW
FreeLibrary
FreeResource
GetACP
GetCPInfo
GetCPInfoExW
GetCommandLineA
GetCommandLineW
GetComputerNameW
GetConsoleCP
GetConsoleOutputCP
GetConsoleScreenBufferInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatA
GetDateFormatW
GetDiskFreeSpaceW
GetDriveTypeW
GetEnvironmentStrings
GetExitCodeThread
GetFileAttributesA
GetFileAttributesW
GetFileSize
GetFileType
GetFinalPathNameByHandleW
GetFullPathNameW
GetLargestConsoleWindowSize
GetLastError
GetLocalTime
GetLocaleInfoA
GetLocaleInfoW
GetLogicalDriveStringsW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemDefaultLangID
GetSystemDefaultUILanguage
GetSystemInfo
GetSystemTimes
GetSystemWow64DirectoryA
GetThreadLocale
GetThreadPriority
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultUILanguage
GetVersion
GetVersionExA
GetVersionExW
GetVolumeInformationW
GlobalAddAtomW
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomW
GlobalFree
GlobalLock
GlobalSize
GlobalUnlock
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
InitializeCriticalSection
IsDBCSLeadByteEx
IsDebuggerPresent
IsValidLocale
LCMapStringA
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
LoadResource
LocalAlloc
LocalFileTimeToFileTime
LocalFree
LockResource
MapViewOfFile
MulDiv
MultiByteToWideChar
QueryDosDeviceW
QueryPerformanceCounter
RaiseException
ReadFile
RemoveDirectoryA
RemoveVectoredExceptionHandler
ResetEvent
ResumeThread
RtlCaptureContext
RtlUnwind
SetConsoleCtrlHandler
SetConsoleCursorInfo
SetConsoleCursorPosition
SetConsoleScreenBufferSize
SetConsoleWindowInfo
SetEndOfFile
SetErrorMode
SetEvent
SetFileAttributesW
SetFilePointer
SetFileTime
SetHandleCount
SetLastError
SetThreadLocale
SetThreadPriority
SizeofResource
Sleep
SuspendThread
SwitchToThread
SystemTimeToFileTime
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryEnterCriticalSection
UnhandledExceptionFilter
UnmapViewOfFile
VerSetConditionMask
VerifyVersionInfoW
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
VirtualQueryEx
WaitForMultipleObjectsEx
WaitForSingleObject
WideCharToMultiByte
WriteFile
lstrcmpW
lstrlenW
KERNEL32 (#2) AddVectoredExceptionHandler
CloseHandle
CompareStringA
CompareStringW
CreateDirectoryA
CreateEventW
CreateFileA
CreateFileMappingW
CreateFileW
CreateThread
DeleteCriticalSection
DeleteFileA
EnterCriticalSection
EnumCalendarInfoW
EnumResourceNamesW
EnumSystemLocalesW
ExitProcess
ExitThread
FillConsoleOutputAttribute
FillConsoleOutputCharacterA
FindClose
FindFirstFileW
FindResourceA
FindResourceW
FormatMessageW
FreeLibrary
FreeResource
GetACP
GetCPInfo
GetCPInfoExW
GetCommandLineA
GetCommandLineW
GetComputerNameW
GetConsoleCP
GetConsoleOutputCP
GetConsoleScreenBufferInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatA
GetDateFormatW
GetDiskFreeSpaceW
GetDriveTypeW
GetEnvironmentStrings
GetExitCodeThread
GetFileAttributesA
GetFileAttributesW
GetFileSize
GetFileType
GetFinalPathNameByHandleW
GetFullPathNameW
GetLargestConsoleWindowSize
GetLastError
GetLocalTime
GetLocaleInfoA
GetLocaleInfoW
GetLogicalDriveStringsW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemDefaultLangID
GetSystemDefaultUILanguage
GetSystemInfo
GetSystemTimes
GetSystemWow64DirectoryA
GetThreadLocale
GetThreadPriority
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultUILanguage
GetVersion
GetVersionExA
GetVersionExW
GetVolumeInformationW
GlobalAddAtomW
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomW
GlobalFree
GlobalLock
GlobalSize
GlobalUnlock
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
InitializeCriticalSection
IsDBCSLeadByteEx
IsDebuggerPresent
IsValidLocale
LCMapStringA
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
LoadResource
LocalAlloc
LocalFileTimeToFileTime
LocalFree
LockResource
MapViewOfFile
MulDiv
MultiByteToWideChar
QueryDosDeviceW
QueryPerformanceCounter
RaiseException
ReadFile
RemoveDirectoryA
RemoveVectoredExceptionHandler
ResetEvent
ResumeThread
RtlCaptureContext
RtlUnwind
SetConsoleCtrlHandler
SetConsoleCursorInfo
SetConsoleCursorPosition
SetConsoleScreenBufferSize
SetConsoleWindowInfo
SetEndOfFile
SetErrorMode
SetEvent
SetFileAttributesW
SetFilePointer
SetFileTime
SetHandleCount
SetLastError
SetThreadLocale
SetThreadPriority
SizeofResource
Sleep
SuspendThread
SwitchToThread
SystemTimeToFileTime
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryEnterCriticalSection
UnhandledExceptionFilter
UnmapViewOfFile
VerSetConditionMask
VerifyVersionInfoW
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
VirtualQueryEx
WaitForMultipleObjectsEx
WaitForSingleObject
WideCharToMultiByte
WriteFile
lstrcmpW
lstrlenW
VERSION GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
WINSPOOL.DRV ClosePrinter
DocumentPropertiesW
EnumPrintersW
GetDefaultPrinterW
OpenPrinterW
COMCTL32 FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_SetScrollInfo
FlatSB_SetScrollPos
FlatSB_SetScrollProp
ImageList_Add
ImageList_BeginDrag
ImageList_Copy
ImageList_Create
ImageList_Destroy
ImageList_DragEnter
ImageList_DragLeave
ImageList_DragMove
ImageList_DragShowNolock
ImageList_Draw
ImageList_DrawEx
ImageList_EndDrag
ImageList_GetBkColor
ImageList_GetDragImage
ImageList_GetIcon
ImageList_GetIconSize
ImageList_GetImageCount
ImageList_GetImageInfo
ImageList_LoadImageW
ImageList_Read
ImageList_Remove
ImageList_Replace
ImageList_ReplaceIcon
ImageList_SetBkColor
ImageList_SetIconSize
ImageList_SetImageCount
ImageList_SetOverlayImage
ImageList_Write
InitCommonControls
InitializeFlatSB
_TrackMouseEvent
GDI32 AbortDoc
AngleArc
Arc
ArcTo
BitBlt
Chord
CloseEnhMetaFile
CombineRgn
CopyEnhMetaFileW
CreateBitmap
CreateBrushIndirect
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
CreateDIBSection
CreateDIBitmap
CreateEllipticRgn
CreateEnhMetaFileW
CreateFontIndirectW
CreateHalftonePalette
CreateICW
CreatePalette
CreatePenIndirect
CreateRectRgn
CreateRoundRectRgn
CreateSolidBrush
DeleteDC
DeleteEnhMetaFile
DeleteObject
Ellipse
EndDoc
EndPage
EnumFontFamiliesExW
EnumFontsW
ExcludeClipRect
ExtCreatePen
ExtCreateRegion
ExtFloodFill
ExtTextOutW
FrameRgn
GdiFlush
GetBitmapBits
GetBrushOrgEx
GetClipBox
GetCurrentObject
GetCurrentPositionEx
GetDIBColorTable
GetDIBits
GetDeviceCaps
GetEnhMetaFileBits
GetEnhMetaFileDescriptionW
GetEnhMetaFileHeader
GetEnhMetaFilePaletteEntries
GetObjectW
GetPaletteEntries
GetPixel
GetRgnBox
GetStockObject
GetSystemPaletteEntries
GetTextColor
GetTextExtentPoint32W
GetTextExtentPointW
GetTextMetricsW
GetViewportOrgEx
GetWinMetaFileBits
GetWindowOrgEx
IntersectClipRect
LPtoDP
LineTo
MaskBlt
MoveToEx
PatBlt
Pie
PlayEnhMetaFile
PolyBezier
PolyBezierTo
PolyPolyline
Polygon
Polyline
RealizePalette
RectVisible
Rectangle
RestoreDC
RoundRect
SaveDC
SelectClipRgn
SelectObject
SelectPalette
SetAbortProc
SetBkColor
SetBkMode
SetBrushOrgEx
SetDIBColorTable
SetDIBits
SetEnhMetaFileBits
SetGraphicsMode
SetMapMode
SetPixel
SetROP2
SetStretchBltMode
SetTextColor
SetViewportExtEx
SetViewportOrgEx
SetWinMetaFileBits
SetWindowExtEx
SetWindowOrgEx
SetWorldTransform
StartDocW
StartPage
StretchBlt
StretchDIBits
UnrealizeObject
MSIMG32 (EMPTY)
SHELL32.DLL Shell_NotifyIconW
USER32 ActivateKeyboardLayout
AdjustWindowRectEx
BeginPaint
CallNextHookEx
CallWindowProcW
CharLowerBuffA
CharLowerBuffW
CharLowerW
CharNextW
CharUpperBuffA
CharUpperBuffW
CharUpperW
CheckMenuItem
ChildWindowFromPoint
ClientToScreen
CloseClipboard
CopyIcon
CopyImage
CountClipboardFormats
CreateAcceleratorTableW
CreateCaret
CreateIcon
CreateIconIndirect
CreateMenu
CreatePopupMenu
CreateWindowExW
DefFrameProcW
DefMDIChildProcW
DefWindowProcW
DeleteMenu
DestroyCaret
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
DispatchMessageA
DispatchMessageW
DrawEdge
DrawFocusRect
DrawFrameControl
DrawIcon
DrawIconEx
DrawMenuBar
DrawTextExW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableScrollBar
EnableWindow
EndMenu
EndPaint
EnumChildWindows
EnumClipboardFormats
EnumDisplayMonitors
EnumThreadWindows
EnumWindows
FillRect
FindWindowExW
FindWindowW
FrameRect
GetActiveWindow
GetCapture
GetCaretPos
GetClassInfoExW
GetClassInfoW
GetClassNameW
GetClientRect
GetClipboardData
GetCursor
GetCursorPos
GetDC
GetDCEx
GetDesktopWindow
GetDlgCtrlID
GetDoubleClickTime
GetFocus
GetForegroundWindow
GetIconInfo
GetKeyNameTextW
GetKeyState
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayoutNameW
GetKeyboardState
GetLastActivePopup
GetMenu
GetMenuItemCount
GetMenuItemID
GetMenuItemInfoW
GetMenuItemRect
GetMenuState
GetMenuStringW
GetMessageExtraInfo
GetMessagePos
GetMessageTime
GetMessageW
GetMonitorInfoW
GetParent
GetPropW
GetScrollBarInfo
GetScrollInfo
GetScrollPos
GetScrollRange
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemMenu
GetSystemMetrics
GetTopWindow
GetUpdateRect
GetWindow
GetWindowDC
GetWindowPlacement
GetWindowRect
GetWindowTextW
GetWindowThreadProcessId
HideCaret
InsertMenuItemW
InsertMenuW
InvalidateRect
IsCharAlphaNumericW
IsCharAlphaW
IsChild
IsClipboardFormatAvailable
IsDialogMessageA
IsDialogMessageW
IsIconic
IsWindow
IsWindowEnabled
IsWindowUnicode
IsWindowVisible
IsZoomed
KillTimer
LoadBitmapW
LoadCursorW
LoadIconW
LoadKeyboardLayoutW
LoadStringW
LockWindowUpdate
MapVirtualKeyW
MapWindowPoints
MessageBeep
MessageBoxA
MessageBoxW
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MoveWindow
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
OffsetRect
OpenClipboard
PeekMessageA
PeekMessageW
PostMessageW
PostQuitMessage
RedrawWindow
RegisterClassW
RegisterClipboardFormatW
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
RemoveMenu
RemovePropW
ScreenToClient
ScrollWindow
ScrollWindowEx
SendMessageA
SendMessageW
SetActiveWindow
SetCapture
SetCaretPos
SetClipboardData
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetKeyboardState
SetMenu
SetMenuItemInfoW
SetParent
SetPropW
SetRect
SetScrollInfo
SetScrollPos
SetScrollRange
SetTimer
SetWindowPlacement
SetWindowPos
SetWindowRgn
SetWindowTextW
SetWindowsHookExW
ShowCaret
ShowOwnedPopups
ShowScrollBar
ShowWindow
SystemParametersInfoW
TrackMouseEvent
TrackPopupMenu
TranslateMDISysAccel
TranslateMessage
UnhookWindowsHookEx
UnregisterClassW
UpdateWindow
ValidateRect
WaitMessage
WinHelpW
WindowFromPoint
USER32 (#2) ActivateKeyboardLayout
AdjustWindowRectEx
BeginPaint
CallNextHookEx
CallWindowProcW
CharLowerBuffA
CharLowerBuffW
CharLowerW
CharNextW
CharUpperBuffA
CharUpperBuffW
CharUpperW
CheckMenuItem
ChildWindowFromPoint
ClientToScreen
CloseClipboard
CopyIcon
CopyImage
CountClipboardFormats
CreateAcceleratorTableW
CreateCaret
CreateIcon
CreateIconIndirect
CreateMenu
CreatePopupMenu
CreateWindowExW
DefFrameProcW
DefMDIChildProcW
DefWindowProcW
DeleteMenu
DestroyCaret
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
DispatchMessageA
DispatchMessageW
DrawEdge
DrawFocusRect
DrawFrameControl
DrawIcon
DrawIconEx
DrawMenuBar
DrawTextExW
DrawTextW
EmptyClipboard
EnableMenuItem
EnableScrollBar
EnableWindow
EndMenu
EndPaint
EnumChildWindows
EnumClipboardFormats
EnumDisplayMonitors
EnumThreadWindows
EnumWindows
FillRect
FindWindowExW
FindWindowW
FrameRect
GetActiveWindow
GetCapture
GetCaretPos
GetClassInfoExW
GetClassInfoW
GetClassNameW
GetClientRect
GetClipboardData
GetCursor
GetCursorPos
GetDC
GetDCEx
GetDesktopWindow
GetDlgCtrlID
GetDoubleClickTime
GetFocus
GetForegroundWindow
GetIconInfo
GetKeyNameTextW
GetKeyState
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardLayoutNameW
GetKeyboardState
GetLastActivePopup
GetMenu
GetMenuItemCount
GetMenuItemID
GetMenuItemInfoW
GetMenuItemRect
GetMenuState
GetMenuStringW
GetMessageExtraInfo
GetMessagePos
GetMessageTime
GetMessageW
GetMonitorInfoW
GetParent
GetPropW
GetScrollBarInfo
GetScrollInfo
GetScrollPos
GetScrollRange
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemMenu
GetSystemMetrics
GetTopWindow
GetUpdateRect
GetWindow
GetWindowDC
GetWindowPlacement
GetWindowRect
GetWindowTextW
GetWindowThreadProcessId
HideCaret
InsertMenuItemW
InsertMenuW
InvalidateRect
IsCharAlphaNumericW
IsCharAlphaW
IsChild
IsClipboardFormatAvailable
IsDialogMessageA
IsDialogMessageW
IsIconic
IsWindow
IsWindowEnabled
IsWindowUnicode
IsWindowVisible
IsZoomed
KillTimer
LoadBitmapW
LoadCursorW
LoadIconW
LoadKeyboardLayoutW
LoadStringW
LockWindowUpdate
MapVirtualKeyW
MapWindowPoints
MessageBeep
MessageBoxA
MessageBoxW
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MoveWindow
MsgWaitForMultipleObjects
MsgWaitForMultipleObjectsEx
OffsetRect
OpenClipboard
PeekMessageA
PeekMessageW
PostMessageW
PostQuitMessage
RedrawWindow
RegisterClassW
RegisterClipboardFormatW
RegisterWindowMessageW
ReleaseCapture
ReleaseDC
RemoveMenu
RemovePropW
ScreenToClient
ScrollWindow
ScrollWindowEx
SendMessageA
SendMessageW
SetActiveWindow
SetCapture
SetCaretPos
SetClipboardData
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetKeyboardState
SetMenu
SetMenuItemInfoW
SetParent
SetPropW
SetRect
SetScrollInfo
SetScrollPos
SetScrollRange
SetTimer
SetWindowPlacement
SetWindowPos
SetWindowRgn
SetWindowTextW
SetWindowsHookExW
ShowCaret
ShowOwnedPopups
ShowScrollBar
ShowWindow
SystemParametersInfoW
TrackMouseEvent
TrackPopupMenu
TranslateMDISysAccel
TranslateMessage
UnhookWindowsHookEx
UnregisterClassW
UpdateWindow
ValidateRect
WaitMessage
WinHelpW
WindowFromPoint
IMM32 (EMPTY)
OLE32 CoCreateInstance
CoGetClassObject
CoInitialize
CoTaskMemAlloc
CoTaskMemFree
CoUninitialize
CreateStreamOnHGlobal
IsAccelerator
IsEqualGUID
OleDraw
OleInitialize
OleRegEnumVerbs
OleSetMenuDescriptor
OleUninitialize
ProgIDFromCLSID
StringFromCLSID
OLEAUT32 GetActiveObject
GetErrorInfo
SafeArrayCreate
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayPtrOfIndex
SysAllocStringLen
SysFreeString
SysReAllocStringLen
VariantChangeType
VariantClear
VariantCopy
VariantInit
UXTHEME (EMPTY)
DWMAPI (EMPTY)
WTSAPI32 (EMPTY)
WINDOWSCODECS (EMPTY)
SHELL32 (EMPTY)
WS2_32 socket
setsockopt
send
select
recv
listen
getsockname
connect
closesocket
bind
accept
__WSAFDIsSet
WSAStartup
WSASetServiceW
WSALookupServiceNextW
WSALookupServiceEnd
WSALookupServiceBeginW
WSAGetLastError
WSACleanup
BTHPROPS (EMPTY)
BLUETOOTHAPIS (EMPTY)
SETUPAPI (delay-loaded) (EMPTY)

Delayed Imports

Attributes 0x1
Name SETUPAPI
ModuleHandle 0x69e1a0
DelayImportAddressTable 0x69e1a8
DelayImportNameTable 0x69e1e0
BoundDelayImportTable 0x69e218
UnloadDelayImportTable 0x69e250
TimeStamp 1970-Jan-01 00:00:00

__CPPdebugHook

Ordinal 1
Address 0x5b3510

150

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x5e00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.85426
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 f4caf3f72aeca602a39e9e4660db7fc2
SHA1 f936b929311c40ddcd1f3420658c68c16a8425e2
SHA256 96258a1913b75c67f670ae9dca46714c9fdde5d97c08fdab988fb25a3545dd97
SHA3 a9b66ffede0af47a172a02b2e645fbd1e795dbb1ceb432192cb4f380badf58df

151

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x1a00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 4.08492
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 b6027ce413281bb2f2373919c9d06e33
SHA1 692e876fb0de46c4817545069e50bbe0a3b4268d
SHA256 1ef4493dd12ab068e3ac20d310a8b2cd27cd6cfda57581a7d34358a7d6075644
SHA3 484f5f815ad5de08ada7fe0fa8546a8f5b0d74462aa75d6058e924889eb4fd67

152

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x1a00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 4.09406
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 cf06cc695805b27fe440014e71941b20
SHA1 817bb46fc28ed45f4c4142f946518f39b888bec7
SHA256 2d8e3146a575e76d7bbe5d723a90710a68d66b1ead56cacda2e48e8ba1faffae
SHA3 0b789eb65d418c68d79a519fbe27014ce01b82c8613d2eac33a8f9ae12e20c22

160

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x6e00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.71227
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 ef6af03f493723328b2efe7d80b3d66b
SHA1 f7be11aac95cf0b3d33fe61831f000562b9f2ae8
SHA256 252d85c71015b4a6bd28175db81b997d90e735e176b14f3302af860e21cf55aa
SHA3 0b71b46a89bb779e318d0b0ba054b3e9931131a45bea04cdbfba9f80abc0b673

161

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x4400
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.53638
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 6be083fb0146ae1b92f95711acf3602b
SHA1 be44490085cf66ab25479edf88dc4f43a3b3b3b0
SHA256 0ac97ecfa01ee4a5e48cdd4d2d13ec3cfde5888b67037a3087454ca41ea78353
SHA3 66deb5f2f25e41b303a83491bc3d9d13a701ad3cac88084e86acf658f6763ba3

162

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x4400
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.24265
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 20da80c8b0731a13b52f4cd8119bea3b
SHA1 60142410b9e566ba2788e6054c7077128d3f9cbc
SHA256 50749ad744e14d6532d74c3ea4e77d30f0671da0bfae2c3b602452203a31deca
SHA3 860eedff1b273cf2e4d0a7fa325ace3a4a9c5b377341b33929cca2afa6738039

163

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x3e00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.13677
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 3a81d957156bc10aedd578d320b7fe31
SHA1 5907611a86d96f6377a5337283226331a57bbc62
SHA256 9a2725260df9daa0cfb6f7df403e9808fad9384f1aa7068a6b11eb009c6a9734
SHA3 65542f94e822750d46eb68ce35ba7533a0feeee9445fc57070fee5651b5e900d

164

Type AVI
Language English - United States
Codepage UNKNOWN
Size 0x3e00
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 5.2156
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 558bfc62dff03e03ec6ccea17310189b
SHA1 c1ee9d6b1b54199836471f7d519d62117ae4def0
SHA256 95b25ea0301061b6e8e2bf26f8074668f126009620dbb3b24fe2cf6335d40a17
SHA3 ce806c9e33bb34440e95110f7bdb1f22a041af181e8d4dc0aca2d157c95d3e8f

1

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.61679
MD5 c68fb06fd82eca9bfbf1ac7bd2c9140c
SHA1 ed6692f8bc77ea73fad92d754ede56781769ea23
SHA256 30df4ddb7d7ff020b05c161b16bafa7002c89871d8b05d132b9c06af0a21b693
SHA3 82c58a119e8e2a673482c184b659246eef0213f392df7af92269c62ff73d66a8

2

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

8

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.43756
MD5 df5063cb4158142c360e426e5a8e08cb
SHA1 bddf0a9d921b0da7e4c4738ecdd27365a7b9784c
SHA256 c82ecfabf27fa9f37678775660e2b970779861385298bf52d149b658cec8f602
SHA3 b5526ea14184acba3ddfaf235a250e01d2060932cd02f63ea5eebc00ad08d0e3

9

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.04346
MD5 a440656922669daf4993dbd440932af3
SHA1 d0bb837b11876a06cf4e3f087b87790df12807e2
SHA256 875ea419a7ebf3324e1d0bd63ba3d301036f6a5cbc42c1ecc5fe900d276e8264
SHA3 f4213071786daaf079a6c90022a9e8d479009a5048ebbb88141a84df7ddc8fe6

10

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.42907
MD5 50a1dc4230899e1475915ad11ab1f85a
SHA1 9b00915b09022dcb24e91ed3c94bc9a6ca38da86
SHA256 cef1eaf60866952ac2222f36eb08af541b48316a9073ee5da3cb068cd98374f9
SHA3 18dba21b59c53fcdf0fcad18d9eb7ec83cf9647b32c7ffcfe48a2fa9b9666c14

11

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.32763
MD5 f2fed1133cdf790a77b3786de26b510a
SHA1 5656dde6242556280b9c30be4162a3673b2b282c
SHA256 05d728edd80343cc9bae57a8098fc38bb8b60d292739b96b78cdb8277c9d7d40
SHA3 dc50d6bb152283eff8e384fc531ff744aa61169a99393133c1b8d9f932114c83

12

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.78594
MD5 80b8439e01a057b8fa41cf8bc67bb19a
SHA1 b4fcbb995d6d58bcc0a7d6d2e6446c3a11572ce0
SHA256 f692757693f3578a21696158b3945a4475465696601f7922fea61a426be2a06f
SHA3 46f355565aa021d81f7deff92bd6488ea3fe7a472b9de30e2aa2dff8da3eb7c0

13

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.42077
MD5 7765e2c2b58939b4adb74465501ffcc3
SHA1 325a3752a4b130a8e6db6ce957caf2b685cca4c5
SHA256 bd3363519ae87900f8c67ccce4e15b3c4d0e6e11d035fb355ad0d9137bacc9d8
SHA3 aa552ed7c060a7af64db35b67968099ba98038c8b529c6f16dbab787aea311e0

14

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.41724
MD5 86b4ad7aee87135e5d04c499414342bb
SHA1 171adce80e6562fe9e0fb29249fa33d5c8fef7b5
SHA256 f3115e9a1c23401434690cf11ce5208111f743c9f0e0d81abd9d4b7a121a338b
SHA3 8e61f94ec2102ec9943a28749fa1b0ed0a3a43a08f6923849bcfa61b0224e3a9

15

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.81491
MD5 ff43eaab521694d0356618a92cd83b55
SHA1 f1ed8d456a5a3d87d1a8349e992c99e22bf3624e
SHA256 cfc4ff9e46fbb61f61b68f36adc6593b137233d1cbaa50fe37e5653f0cb20396
SHA3 7069692bfbe0c043b33390a40f8033c3d0aa3092c3b1ca1b01fc899dc760ec48

16

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.32763
MD5 9e06919010ab20c398c320dea36e6788
SHA1 23072d74870761a6f35e09e279c8eed2819552b9
SHA256 e30dc2ed3240f70017446eeecb310c41da3ba1097732bf59bdf2ee0700b4a693
SHA3 86aa066a4359c14e0a42614ab4fa6ae9dc3f7a188bcd8802ac95cc35184651ca

17

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.42077
MD5 ddf277a7c2a0cc92602c1fc6cc41fdf2
SHA1 edff404d3233bb791d0d200c84cccfb179f17deb
SHA256 b530cc50ebb623863c4d6143a573f53cd29becbfefea637cbed14d8d0de0d510
SHA3 5b11eb08a426d45095db16f67f05a644c6d0d9d9345e27344f0234f76ffba09e

18

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.41724
MD5 f45d40722430a40d99e3d1ff556b2f30
SHA1 3630fd4bd5e9fa14aa26ab1fc585a3bb3aab5ff3
SHA256 d691990ee812037578a9127ec31cbea9f5bcd4ec8430709b05b1e32aba4988a9
SHA3 f59ca4e92b75af7c4f35ba72f993a756e94fb128e53de5b81f1ce0be4ff9c271

19

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

BBABORT

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

PREVIEWGLYPH

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.85172
MD5 48276e8432af5a23af78e1d23de8ef5a
SHA1 12fb57606d03e3fe28263e3e9e96b4eedc79aef7
SHA256 78507a772de646626b196a743cee75b298a68c33a0fd482842071519d59037b2
SHA3 1cf31d53c7ea5dbe90181cb2db39ce6cd21484f5495b0af59f5c6164d9b3d3d0
Preview

SBDOWN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.28705
MD5 372ea2329f5c5a6c29196e03e71de00b
SHA1 d7a585e1edb7c62768dacfe26798e55b511d55b3
SHA256 3c7f5cac97792de3f170817f22f39e5b445fba8d8145955b23c935182c8e4298
SHA3 bf9ab5624ee10a4cec783425216c02d544efba66a5668befba1e03a0432ddc30
Preview

SBDOWNDIS

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.55093
MD5 076639bb603dae1467cb61d73a67e683
SHA1 bff89ff7834926b314b18b0e60604873dd643d1c
SHA256 29c983e34fc768f686c16900a24ad9dca799eca387e71199fbea774b3944d832
SHA3 9d9890d24a1698cf13510c1f7d2b95231290f9eee4af42253c2be425df819f0a
Preview

SBDOWNDN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.84775
MD5 01d37a35531d3df7949802d2dee9878f
SHA1 733b1e71a54ea8b36f4a5a4e15070152e65bf328
SHA256 680e6da5d4a113df2627287a0bf6915991c6aa539d962c2ed1c2421b18178406
SHA3 ec461f191a8c726f7cc8871a0599f6aa1fb507dac76f9623742113dbc603aa6b
Preview

SBLEFT

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.0184
MD5 6e130919054451be4dd51f0d3160e9cd
SHA1 01779869586aefc17fabc5412221514fc421a85b
SHA256 37e98a6df94b14c92da5eb339a3365e669786f34196649ec5fe6e04505fa0a19
SHA3 86e3b302319471f81d80a495fc158eb06193161e5582be62b051d77276f06d6a
Preview

SBLEFTDIS

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.79554
MD5 2402f84c8bee09653500e5538446cd86
SHA1 d8fbbaf46d79923f5dd6069f7a4e45049bb4c564
SHA256 7da4bb3fe703b367e7f0a01c0dcf43cdf578ed8f1a07a0f594a22718c0ad4a62
SHA3 0fccf29c1001562cb04a9b5f8b82bc967ec068cd24885fe6f3df3519586c2f36
Preview

SBLEFTDN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.40721
MD5 fb52c89c475873558ae7d58e0c0aa955
SHA1 20bba50c75b87cc1334d62a2b3a635e2cb561d61
SHA256 42d747007b6d8ab3a9380ee243049c6ef572adf9277935e7418f357935d1b1ca
SHA3 c70c0de136bd87c585916f005df088fc3da6a6b3f6900bf0699ab6108ae2a03d
Preview

SBRIGHT

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.00455
MD5 51d7356f76495c1434c8c477f277a5a7
SHA1 4c1105bbce122022ddeb938cf78c47bb0c4d5929
SHA256 66332d4088b908862bfbaf05c7991e4e3acd8df08f7abb408255f6e4b735b8db
SHA3 f661c7fae5e00e0d21dcfe88565f84070f7e43f1c4a3712aee5cbd5a39d5bf04
Preview

SBRIGHTDIS

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.86813
MD5 4f53cb32fd6dafe1e0588870c6e3d499
SHA1 7078fd4b832d5c9debfa12a0dcd34c135d4ed603
SHA256 843699413d07bbbb7a562c65050eeb594656c90d0d22a643ce5f3296ee8389cb
SHA3 1750b51acaa6cda31a44a887cd20bc3e53bf392184071e0073a3ebe55b84ff51
Preview

SBRIGHTDN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.00311
MD5 5502a87a103544c3a32b5bf50e7485f7
SHA1 b8e234470a118fe264aca4975604f318144e62df
SHA256 97bec1fa4bb509ac16a0d8a542724f28767957ae485101c4e050f5424dad2619
SHA3 e8597406bd06454cd4450a7778753af6e2ce2fa231c255eb88ba75d354cf4fbb
Preview

SBUP

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.86818
MD5 4f2e14e3b20093eeeafce0ad53f9cb9c
SHA1 1c390e1f219783b1ec3b840a4ea2ff12b2861eda
SHA256 0b762a6b66676f0a0fa7ba53320c7d3409ca493e9bcc7351f43228e22e8ec57b
SHA3 6afefb00e5f2a083b97981cf9f10d5cba8b94583962c6b9a443085411dec9880
Preview

SBUPDIS

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.9418
MD5 0e39e030e1c059bd9f76222f6fc34a20
SHA1 c9493d205b0309a039fc923ced56565997afa5c6
SHA256 06e4c223c6f0962a7b28f6ad379a6c423974a2bb4044ef2049c4ede23d949bb9
SHA3 f20e49f1d8cf75821e0a9cf53277b8066769317344172a10c77983c729f2deb0
Preview

SBUPDN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.84775
MD5 ace6b8c036aff98cb16c5fa59bfde599
SHA1 04eed9c3a7ffaad8fe76bcb45ca13a07d27f4844
SHA256 f491aceaf96e418dc8f5be46c97945af59cc2ecd9e5bf6baa5b70125c758db07
SHA3 961ee15df4deae350b9ed966cdb04f763da0eaa50c035bc1483ce86e36ba2d65
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.51496
MD5 132718a1e829dd084cedc5f8fffe0fc5
SHA1 46083c45471698ee5c56f381e414afbcfc1ee0d9
SHA256 ceded0319639767aade4d1fe2b343f3afc5afac3672258ffc7eb9f9378ff5df9
SHA3 b39e179052823c94be3a743fde34777cad44f1902863c83547b2806ac3b4e725

2 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb68
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 0.79113
MD5 53eab99bac007796730c138b90fd1f84
SHA1 d7e9ec66c06794abe2c957cbf252c64321f07d40
SHA256 88609bd7b4d8da667ac0139c6d2313b199680e8ee11673cf32030639f4aa9c0b
SHA3 61edf4013a0073c6aee2eec9904db42f1656c39356bf702180c723f2a7e1e785

3 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb68
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 0.792273
MD5 0eb8846ca8b8785b9651319510da0e12
SHA1 54359ebee87960f3884d9446a96e5c076b7e7289
SHA256 32ebe1fa07f4e6430bca10f8c86c6425c46b2a1f511b40aa8e01f8fb94ec4a7e
SHA3 fc457f646a2239e60ba22edde9af3f0c61aeb363194674d586f2fa03ab709e37

4 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xb68
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 1.00297
MD5 781337d59bd69bb2cda1f198b34b7232
SHA1 b32269b26f78a7654b44f03507732241e3e95415
SHA256 57faf57a5d7f772b09c06179c0a40b4d596ed5b9976aefd8cc5799f65c38dddb
SHA3 4fe3ddb0d7bce9d76e138afe5b549852adb257a29a316e9f84a426716498d651

DLGTEMPLATE

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0x52
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.5627
MD5 db949b51eec31f37281a7fa424a3e158
SHA1 f61214ce31a91d174e77f12c90f18ddd4e265a1d
SHA256 771f64afb45a9edc8c4f6c5b2039f9b32623cea53bf0cab5bf1f371cc5d1abe4
SHA3 4a2bc09771734352d594a48fe2249ca0697c471d80a4001f60c6d86c46b6319e

TEXTFILEDLG

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0x52
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.61605
MD5 ac5eefd684bd75f9ded1d0e368f566da
SHA1 33dd756799618130fd3c1097be1638f47ada0f90
SHA256 26be3f5d9e8788884e3d857861b2666da59e7e80dfaa6e7e52832428980204fc
SHA3 bb30afb20c2bc5d31729c46212a31568a47a85da5d4bed5e936bee775915da30

4067

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2a8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.1269
MD5 89662088f1caf25af11f04ae4539ad20
SHA1 9f0c9680fb5dd1278a58523975a92379e32526dd
SHA256 777443954feb2da01d28c0a59e1f01e5aae13377288efa86febf69ec690a1d67
SHA3 334f5c6a590a6d0a5281e45ad1572f61cd7d72a65d3eac3dcaaadc93123e3ff6

4068

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3e4
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.10914
MD5 2b54e25a24c2d3bd9275caf8c1855bcb
SHA1 6a16f0c0e1327d5221975c261a77447b7d734d2f
SHA256 58476de1b42e85b6a0e680c347bd3167e68f6f6f520fc2b7986460631ccf7c37
SHA3 ac0be1c208a46ab51b8abeae823272e7cf154d25827a4da6c094b3e34688be3e

4069

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4f8
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.19325
MD5 89d79d641af0a16fdd3e6b2a358dd6cc
SHA1 87fbe51f0d1459f88643602dc0a9170f0ff24176
SHA256 be536e85e1efc94e7d6e363c12de053be6fae9c7747ef5615ec74efec9249352
SHA3 4156f3973377b0289285e2e806b94cc5f1f18d67958ed503d4bdc613812059bd

4070

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3bc
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.25677
MD5 465a24a1af069d38279bd63401b13b8b
SHA1 ef1ef7bbadb4b7b9cf3708568c719f05194c23e6
SHA256 09cc96bc6ed1b324804786620f977af39fd5c9207d4f5655d70bd97261dc462c
SHA3 087c78dbe328e1d84767fa55a362f1a1460ad89668b47b473d57f7a3e4140e7d

4071

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.33144
MD5 bdb8588d84ed4c6f5e528b3cc43ab790
SHA1 57cdc15193c2e8900326ea4b95f1f3f58e4f1d9e
SHA256 9100638a5b5ffc9cfaa55bf1e19738cda57fb03c434cfe5a65c30969ea8ec4f7
SHA3 5dfd0ebf1feeac575d91fa301125ea86ffdb902cb3aacbd2d14bf7286b7726f5

4072

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.23255
MD5 d50ab2f3e3dd22b5e8773aedff7f3650
SHA1 4c6ddb1a6af41480aba02d55f88b5fd55c907f80
SHA256 332a794c40b9c5faf00b7836426bdee9f166c1412c32077661b15f9b62460c0f
SHA3 5ed5fd9613ff0c5a3f25119f841833538f64e11046e1c5262f87e2e57cf8b520

4073

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2fc
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.20971
MD5 736b372e23d47f515e3c16170ed54632
SHA1 b7254e87b3132c267e93ef5229fefdfb78bcc9f2
SHA256 f605b6ec2c54f0055ba3d858c707b3e8e38650a468f5e0685e1b3e3b75b8d585
SHA3 6e3ef945f729c0db486a588af9217421f495cfa4705fb89d21e823fda2fdea1e

4074

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.11458
MD5 3dff6bc51ca85f3d4d71c914f178f8f3
SHA1 2ec24685acf02d52dffcf53ad19302b3a103dd91
SHA256 f792e407c4f7e88af5c62a68038225c71bd54135186e0b98ad422795393ba8ab
SHA3 c2ed195bf7614d4a4e49b0695e8b121f3535453f91227cdf70aaf62ceed2e9ac

4075

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x17c
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.24704
MD5 e2bdb4cd68c87b9297039f7923427fc6
SHA1 f7b6d06ddb8823352656d0f4712480959e7fdb2a
SHA256 c80e8dd4351d6b37bb6d7650dab01f950eacea8c61e4313b8eed61c78a47d14b
SHA3 4a739c87ff36a63e70b532a4c5802506519b43a1d21bacb4465d826f48baaeb4

4076

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2a0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.18751
MD5 fecd4dfbb987ae8a29b916e020b040aa
SHA1 72d21f7c1cbbe3ea668b20fb944cce02e7160712
SHA256 e691b25a71747f55a5dbe5dada5c5b7311fbf73585a929aa8226036265ead1e2
SHA3 c9b95fe5c4e8857b4a41e3e5d650bc5edfbcad0abfde338b25eb922e69d1aced

4077

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x330
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.22009
MD5 eca5578f84d1c9c860af36f133585ce1
SHA1 69c5ba32d2497c56cda8a7c5e7544aa0a4e562c3
SHA256 b767dd7c97707196d5d3cb39252f03cb834d869e20c760270ea9bcd0500b1605
SHA3 65f5f35fcdd2ad8833636ab937c30e042682f8875ccba278c7dc5cc7ada3af3a

4078

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x430
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.2207
MD5 03c4f8bbd2dbd7fed3e72a847e640fec
SHA1 8fa2f1f488750a9ca796a9c6c77c60479f541bf8
SHA256 5f848571f33f70201b399c919c2818e1dc87210875c0a2068fb3e82196868ed8
SHA3 004648005a9ead7355c820a07492189bce9a9d5dc64558ea4ec331f3cff2cb15

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x380
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.24498
MD5 a96119df9260753220437ef5f7a75998
SHA1 da7febaa28a6c414c257c3d7c92be030f2e4588c
SHA256 aa836287e4e8061c10743fccce63ccab2e9d7044802d1ec4f72b020c0e0bc428
SHA3 1619c88e86f48eaa65df25b7718e6151030e45cca74538d68c034f1c3937bdf1

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x394
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.23088
MD5 43fdd832c9a2a399bc1bb1fc0e957d72
SHA1 18182b7d9779608f488b2ff3752e2679c3976c72
SHA256 a6c75a59c38799cbced2754f15d5a38ef4b6ea5c9d8c1cb411d3d0bc05163eb7
SHA3 b67ac86f3f02ea301ab7519098d0c2c92515de5783eb782a9171240ad58ca3b8

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.01073
MD5 ff91ae4b02540155fba71086488a6305
SHA1 38d3bb70f85acefb824e2d4f6bca9bbf040d4f7b
SHA256 21e5d0e9ad97e712f845942dfa558cb7186ce160e8586e743a96610fcd7790cf
SHA3 99914b36fb842da8e950feac44e71872ef2a32d4cfcd0ec29227971ca3dae454

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xbc
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.80014
MD5 d403ecb2e79bb6d225675000eb5ba0a8
SHA1 dd6bc5d698469b9454f661165a40c00cbebf4d7d
SHA256 7723a1a9d4c6bb26e866699606b976646714de2cf376f33ff22e17017af53cec
SHA3 d750bf4a63c12d1eab6e46704265a7633ca81882b24f2dd0aa8d67b2cb177a2a

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x348
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.2537
MD5 aca50134550fc111254c7e049b39f4a7
SHA1 295d931c252fac8b61fc1f11eeca17c201a11abc
SHA256 ce7771530345557230d69850482e85c1c858ef704caca9bee2a726fc9e77636a
SHA3 d0edb82ddc8277f3bf785d0c4939da54c6453dced5fdad4ddff4d5b14b6530d8

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4b0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.23613
MD5 c3a23fec55a1cbf30867d6da543f0e2f
SHA1 90abc6ffa66d76d7240fbf4ee00da4d3599f8e4f
SHA256 6f876af3a247100f64e89691e229fe4c4c107dbcb77817bb3f343699d2a5214e
SHA3 09431546bc6b1cece202a72602745b5318a81437ff144c84fa5a2548fc0dcad1

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x324
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.26823
MD5 97c4d522ebe8b9eb5ff29b66d1907b5c
SHA1 6917c0aeed1fef292ce4524a256eb1a9223c1009
SHA256 c9fe9a50bcc4f24eb0f88ec5495fdf3047a96f62a102c4b45660dccbb70732f4
SHA3 2fca8ed9b60fdab04c864665b5a375f29e2aec38584a43b6cd03508422d8b3c8

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c4
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.18814
MD5 8ace0d98ddee3dcab8db612c66b30fc9
SHA1 be318c01bff08fed92a98a0e51febf5a0193a045
SHA256 8de156d1ee516d34b076a8ffffc6a090ff4be26f65efa7b8de3868ecd7982ce9
SHA3 362823cc816dc4959cef36a2d4232726d1eb0d772ac303f1fc4080a3b6b33071

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x448
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.19792
MD5 e9995e785b8f39f648c1f6c93f39f2b6
SHA1 a455873d7ab5dcae2282971d95207cd0ba8f95a8
SHA256 6b85135a8c998b2c6da1c7c37052f9910c34b2a99bd1f8452cfb78659fa12ab7
SHA3 ddca3662d4d43dec9e6bc3debcd1efdd8c519c92947f9824824816fc5f5d8e49

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x378
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.2509
MD5 4b5d8307639484c6a2a4cd29ff238c6d
SHA1 b0b4605fb58488ef4102499ffe27509de4f32311
SHA256 96c3790d9399817144097a11856e63201bfd2ff7c97e3b785e4f3fdc01b02950
SHA3 9ebbb0e4d6e1619ef57112df00a51b196c2fb154c25d7062bb1aa9c69c0fcf62

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x444
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.38542
MD5 d550ebb373499003f1722ba9e803acc2
SHA1 5a4a39359216fab86029e0d86ff1733e5d7f96b3
SHA256 b3b75931dd32a72e5a002d50d30550a6978ed81ad6643c7624762f1a1c12b0ad
SHA3 723db82bc96daed6cf8083853dfad819fe543bf675f6482547d2323a66b1636c

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x5cc
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.24022
MD5 7c0bda8f9c6cd06fbb401c8d0e2cf6fb
SHA1 a79fc4a4c3af45fcac064ccb313e3c84651a1bc9
SHA256 424244843cf5c170ef7390e0de60ac010c01bc06b5b1b8fa142b5492e660e8d0
SHA3 4ca1d23c2d3d4c410dc085ffb8b1d8c92f05ecf7a6f6afee2b9aa2b5663e4093

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x604
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.26399
MD5 8666e8fa34982c59476d5d85201fe00b
SHA1 7210ca1042174c026c0e264fea8ed832e31f536f
SHA256 6f3b69378382b79333b93c5f6449f2f48827d2cc8614a2f643b42960c82068e5
SHA3 86772285181497cc4b4e4785159d2ef878a3fc5a9f15bfde0e1794fd961cefe6

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x318
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.125
MD5 d52e7ae8413b9ed91e0dc0959ada8950
SHA1 48f173e6bc5697c545bc5f5998af5c4bacb78fb9
SHA256 70d08fd0aee4caf92381eb22b780df740e42600fe34ee0bc7a7e23266eba82ea
SHA3 1efdcdbbefa4cd3455f80c53803670d65ce099fc4a3af86cf280df3648a98c31

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x394
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.2685
MD5 7749acd89c449663d424bd3407b5af4f
SHA1 08f2fa85ff033d039e16a24a4eb38610a0d3b594
SHA256 af5c9b37976baaccd57b5d71d0bcea7347760451e4154a5365793056c2d4c3fb
SHA3 f3a57ef795aeddcbc771c9a1bef5f1ef2bc8ea6d0d5774b9d9756c38d37c3ab6

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3ec
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.26391
MD5 e9083f9c327ffa82955120106d9af141
SHA1 713442b8e4407e6bc4402a76cfdcb63f1d9e6065
SHA256 522fb0d6387fca6e95331ff785d10d8e5d608be693576fe0c550d4ac0c27f4cf
SHA3 355627967e63b5b3de15dae7cc72bdb1e2cb9c58f88cbd3064ad4132174a3c25

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x5c0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.31775
MD5 8d3de9b23b032b4943a1c786a92a4cc2
SHA1 d1fa008ece92b87b3dbd2a7cbcc548e742a17f89
SHA256 ad39da7159acdeccd9be49a777340c26f9278b3eff572f6ad2c11140383bdf91
SHA3 9319abf40b25c00e8c2fa4464493ea15629f71f5fba1d8bc8f74790272629a03

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x4b0
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 3.2429
MD5 126229ac04cdbe55a520e602cf222c5d
SHA1 dbcc079cfef198f8df7375b52f76df3677f48e9a
SHA256 61119db7f511dca591f855c5e36a4f4b7c21bb65e148b80f1944ac390976ec08
SHA3 3e828268a9e376bea19fc7351d19d337a3303fc835a8cb9f382d92df5d2f4e9c

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PLATFORMTARGETS

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 1
MD5 598f4fe64aefab8f00bcbea4c9239abf
SHA1 688934845f22049cb14668832efa33d45013b6b9
SHA256 9b4fb24edd6d1d8830e272398263cdbf026b97392cc35387b991dc0248a628f9
SHA3 2951e8c89ecc8e8aa730f646caa10afd48f0be1353aaf5cc35815497dc6ba0db

RESOURCE_1

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x2fe
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.54545
Detected Filetype Icon file
MD5 e2a4fc8c10c57e8448acafff5492a165
SHA1 238f599d5d4b649ecf53005d028c7e68e180d37b
SHA256 01aa48440c921a817157ce9a81175bd6a35b3891da6e4fa81945c962e264ae96
SHA3 cc2a48d0a949d6becc29f3d02c18ce8bcc5b74f4405a783e7844ff6105717228

CAT_DRAG_COPY

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

PAN_ALL

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 1cd71148c4a650e298e26668e22c3733
SHA1 5aeaabee3ae2ad999e9ed91c85119a42c83473c6
SHA256 4ecc7f2578fd7b137c04f85ffcbd67d6eab0bc8b1df4246cebd2a2aa517f3c60
SHA3 89ccb4ca5392e186b8eeb9848f78a12843e40792c3500e104225869bf9be1894
Preview

PAN_DOWN

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 1529a8ec9965ecf3256d6d4550712406
SHA1 9bd0fc7e667f3d49f5098ecc2bff01987f3e1503
SHA256 12a5b9052dd16bed260343bc4352d436167c991c54497c5af441304646549386
SHA3 0799f15ab0007d5497ea80dbae86635472c9d085ffbb6c095b71d1e8acebc81b
Preview

PAN_DOWNLEFT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 8e242da1769c2307f276e393dec0e7d9
SHA1 da604259954e8cda5931a679e081bfad9a9fd772
SHA256 ee63d4681e7622067fd29005c6cc67b456031eb723c7239f05f1cb097af0ef98
SHA3 e6021bdef60731a607f9445b3c004fcdac812f44b42aeb8e32fee72204be4572
Preview

PAN_DOWNRIGHT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 87f676ebb80763bfd77a413c2fb00f0d
SHA1 23736a18a1d4330cb9ea762fb7deaef881b6ec2c
SHA256 da738753c27f2708bd2257f8cac3385a4ccb0df1341b76acfda07fa980cfb4bd
SHA3 d90e5655540ffc0671429e2c3ff78ba0f7a100727622de4185f897a4aa996c3b
Preview

PAN_LEFT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 b3dbdfe1835416bbc3f5065baca9aca9
SHA1 334d5af1355f6a13c35be4ad16e76baaecf209f1
SHA256 ec26c438d10e3e84ec855c47f07a176e6c11bbfae1557d526490711b80f087fe
SHA3 2409b439f48a139d3764b226eda46c6a629d5bd208991369ae0c85e37c17c71d
Preview

PAN_LEFTRIGHT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 ebb32ed08b06ab16f79c997b7963c57c
SHA1 c87e290caff3cf222d5ec678a51927ff22637949
SHA256 9c17b4621412d6ded24a76aed74d4425ae61f86b6d4092ca1e28ca66b7c71399
SHA3 fb70f94bf4a64a26f2d83b588fe2a233796083fd03aae7835387aeba2646b847
Preview

PAN_RIGHT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 e6a3323fcb21bc5b90ee077f41a24061
SHA1 91e468b891f8306afeb6ac33bc31d67efb2cbe9d
SHA256 a92f60b25322592e7ddd13d88e4006c097666f4d87c8cb0c21ffdccd53b31d78
SHA3 ffc4266780334ccca3790e5f703fab0a138d252e16d1ad1145c1929f51d31d38
Preview

PAN_UP

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 5df05404b0dab444d7bc0fe0bee0d519
SHA1 ecbc2591eaf234bcc87df4731b5e26266728ff6d
SHA256 28b8110695851e5280ff55cb78507b03e8b74dd370b8e122179c82b56f7e5f37
SHA3 f18323f0f4e67af79d43a527df26273c9f7e53e73b1ba51cd426cff3412927d2
Preview

PAN_UPDOWN

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 d1c93cf23f34157f8c97800528b9bb99
SHA1 ab9e40c42ad0de11e11fdde5de49bd0adaa9bc2b
SHA256 8a495f17bc472bfc5e6923d9efa687848fac027ad60694f9c3f10a4f7b194924
SHA3 10b44e07ad4f8d644f73b4d71370ae8c337e8bfdac89efebff20378ad61e0758
Preview

PAN_UPLEFT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 22a9b94eda22d068a6823a72268fdada
SHA1 7923c0aa606f67498391ecdb828292fcc3bc3ed6
SHA256 a2f0549cca7170ae03ba042464efe62365fba38c20049e439871c9e5ce0f914f
SHA3 565227501bdf04ce5d2afeb14e48062d4cdd6de7b76c62d26a15f6e4a34ba5c1
Preview

PAN_UPRIGHT

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 446e8ff2a515c84d93ca4cbcf405d300
SHA1 98de0236185240e011430a5dd8e262ed8f991ec2
SHA256 ef309b720f166673cad840a88e7636e9161ad91415cc7c176010cebba07757e5
SHA3 d345fed6ee7f3afa40aba48106f47450bde6ac4c3d47db78cbfb11e4368be613
Preview

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 8408eef234acfcac8a26e706cc35d85c
SHA1 5ecdc1e1be3f1e941b1ca11b45943aafe135c517
SHA256 3f02dcac38fffe306e1825846e2bc0458ee712696310d051e3a69ebda8330cc3
SHA3 0406ff4480e84661d58a225cdf84931c95f7ebf6fea388a3cb6bedbc0343b421
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

VCL_EW

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.0815
Detected Filetype Icon file
MD5 859d5194a49b67839a83efbfd87c7984
SHA1 dd3d0bf40c1c08c1d531bc73beadaba4ec4082a2
SHA256 4c53fdf53f97d577a88d4486fb2990face2ea49ead439709428feda69a58f26d
SHA3 af6c2c75de1a6ed83bf7c409e505bc11c758b006796315ef042818b2facba4d5

VCL_NESW

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.0815
Detected Filetype Icon file
MD5 4f787fb22e2442c14e66dd3be2a96c2c
SHA1 dacdbeb5c8213cd46a94afd3cefbd26220b1bc99
SHA256 03f3c5ecd5a1d11bc0fb01fda97f81c2894ec7178e3b878f9d27506263923846
SHA3 ce1c9c3489f928c87c89a2e3799f508a462da89f10815ce8faeb64f0eef04521

VCL_NS

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 2.0815
Detected Filetype Icon file
MD5 add3166eba1b25956172b8c80eddfc2b
SHA1 1811a0ed5b4f4694772c27d27c337a38670072eb
SHA256 ce661a77befb715b41c454a9fd8b7bd72e020fca0638c7af037b92a38c6108e1
SHA3 c3ea547c6984554ae9224c0ac7e06030adc560f769f8abe5ae0ced83165b40ec

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 4.91044
MD5 3e61c1bfa57cb253097009ddb67c96f7
SHA1 d0e17d1120bed634f53e30dd64cc139f7a5ad2ee
SHA256 730a3143b221f90d5d6260a13f3716c1577bced065725cfab11cc2a14fc597cf
SHA3 f1ad763a7ffee36f4acb928396b8e4c2eb9b64307a956cbe579cf15882927224

1 (#4)

Type RT_MANIFEST
Language Chinese - PRC
Codepage UNKNOWN
Size 0x20c
TimeDateStamp 2016-Apr-14 14:30:20
Entropy 4.91044
MD5 3e61c1bfa57cb253097009ddb67c96f7
SHA1 d0e17d1120bed634f53e30dd64cc139f7a5ad2ee
SHA256 730a3143b221f90d5d6260a13f3716c1577bced065725cfab11cc2a14fc597cf
SHA3 f1ad763a7ffee36f4acb928396b8e4c2eb9b64307a956cbe579cf15882927224

String Table contents

This control requires version 4.70 or greater of COMCTL32.DLL
Date exceeds maximum of %s
Date is less than minimum of %s
You must be in ShowCheckbox mode to set to this date
Failed to set calendar date or time
Failed to set maximum selection range
Failed to set calendar min/max range
Failed to set calendar selected range
Failed to clear tab control
Failed to delete tab at index %d
Failed to retrieve tab at index %d
Failed to get object at index %d
Failed to set tab "%s" at index %d
Failed to set object at index %d
MultiLine must be True when TabPosition is tpLeft or tpRight
Invalid item level assignment
Invalid level (%d) for item "%s"
Invalid index
Unable to insert an item
Invalid owner
RichEdit line insertion error
Failed to Load Stream
Failed to Save Stream
%s is already associated with %s
Invalid style format
VCL Style File
Class '%s' is already registered for '%s'
Class '%s' is not registered for '%s'
%s parameter cannot be nil
A StyleHook class has not been registered for %s
Feature not supported by this style
Style '%s' is not registered
Cannot unregister the system style
Style not registered
'%s' is not a valid property value
OLE control activation failed
Could not obtain OLE control window handle
License information for %s is invalid
License information for %s not found. You cannot use this control in design mode
Unable to retrieve a pointer to a running object registered with OLE for %s/%s
UTF-7
Cannot remove shell notification icon
%s requires Windows Vista or later
Button%d
RadioButton%d
Caption cannot be empty
CategoryPanel must have a CategoryPanelGroup as its parent
Only CategoryPanels can be inserted into a CategoryPanelGroup
No help keyword specified.
Unable to load style '%s'
Unable to load styles: %s
Style '%s' already registered
Style class '%s' already registered
Style '%s' not found
Style class '%s' not found
Invalid style handle
Multiselect mode must be on for this feature
Length of value array must be >= length of prompt array
Prompt array must not be empty
&Username
&Password
&Domain
Login
Separator
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
No OnGetItem event handler assigned
ANSI
ASCII
Unicode
Big Endian Unicode
UTF-8
start
stop
pause
continue
interrogate
shutdown
Service failed in custom message(%d): %s
Service installed successfully
Service "%s" failed to install with error: "%s"
Service uninstalled successfully
Service "%s" failed to uninstall with error: "%s"
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Del
Shift+
Ctrl+
Alt+
Value must be between %d and %d
All
Unable to insert a line
Invalid clipboard format
Clipboard does not support Icons
Cannot open clipboard: %s
Text exceeds memo capacity
Operation not supported on selected printer
There is no default printer currently selected
Menu '%s' is already being used by another form
Service failed on %s: %s
execute
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Invalid input value
Invalid input value. Use escape key to abandon changes
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
&Ignore
&Retry
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
TIFF Images
Grid too large for operation
Too many rows or columns deleted
Grid index out of range
Fixed column count must be less than column count
Fixed row count must be less than row count
Cannot insert or delete rows from grid
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Icon image is not valid
Metafile is not valid
Invalid pixel format
Invalid image
Scan line index out of range
Cannot change the size of an icon
Cannot change the size of a WIC Image
Invalid operation on TOleGraphic
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Text format flag '%s' not supported
Invalid image size
Invalid ImageList
Unable to Replace Image
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Invalid encoding name
No mapping for the Unicode character exists in the target multi-byte code page
Tab position incompatible with current tab style
Tab style incompatible with current tab position
Bitmap image is not valid
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Jan
Feb
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Execution
Invalid access
Format string too long
Error creating variant or safe array
Out of memory
I/O error %d
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
No multi cast observer with ID %d was added to the observer collection
Observer is not available
Invalid date string: %s
Invalid time string: %s
Invalid time Offset string: %s
Manual construction of TDeviceInfo is not supported
Attribute '%s' already exists
Device '%s' already exists
<unknown>
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
'%s' is not a valid GUID value
Invalid argument to time encode
Invalid argument to date encode
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows 8
Windows 8.1
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No help found for %s
Argument out of range
Item not found
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Parameter count exceeded
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Byte array for GUID must be exactly %d bytes long
Specified Login Credential Service not found
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
High surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properly
Low surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly
Length of Strings and Objects arrays must be equal
Invalid Timeout value: %s
Timespan too long
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue
Value cannot be NaN
Negating the minimum value of a Timespan is invalid
Invalid Timespan format
Timespan element too long
No context-sensitive help installed
No help found for context %d
Unable to open Index
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Cannot call CheckTerminated on an externally created thread
Cannot call SetReturnValue on an externally create thread
Parameter %s cannot be nil
Parameter %s cannot be a negative value
Input buffer exceeded for %s = %d, %s = %d
Invalid characters in path
The drive cannot be found
The specified file was not found
The given "%s" local time is invalid (situated within the missing period prior to DST).
No help viewer that supports filters
String index out of range (%d). Must be >= %d and <= %d
Invalid UTF32 character value. Must be >= 0 and <= $10FFFF, excluding surrogate pair ranges
%s on line %d
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
String expected
%s expected
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Invalid file name - %s
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
Invalid string constant
Line too long
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Number expected
ANSI or UTF8 encoding expected
DCOM not installed
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
''%s'' expected
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Identifier expected
Invalid binary value
Can't create client socket
Can't connect to device: (%d) %s
Can't send data: (%d) %s
Bluetooth: WSALookupServiceBegin error: (%d) %s
Unable to create server socket: the specified GUID is in use
Format type (%d) for Integer conversion is not supported
Format type (%d) for Single conversion is not supported
Can't get list of LE devices: (%d) %s
Bluetooth: Create LE device handle error: (%d) %s
Bluetooth: BluetoothGATTGetServices res: %d(%X) error: (%d) %s
Bluetooth: BluetoothGATTGetIncludedServices error: (%d) %s
SetupDiGetClassDevs error: (%d) %s
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Operation not supported with this descriptor kind: %s
Invalid service name, you must provide one.
Not Implemented
Channel is closed, can't read data
Error sending data over current channel
Error getting service list: (%d) %s
Error getting device info: (%d) %s
Error trying to accept connections
Unable to create server socket
Can't create server socket: %s
Service registration error(%d): %s
Service %s is already added to this server
Error calling setsockopt SO_RCVTIMEO: %s
Bluetooth: Unable to initialize Winsock
Bluetooth: Unable to clean up Winsock
Error calling setsockopt: %s

Version Info

TLS Callbacks

StartAddressOfRawData 0x9b4000
EndAddressOfRawData 0x9b4300
AddressOfIndex 0x940110
AddressOfCallbacks 0xa97020
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: COFF String Table's reported size is bigger than the remaining bytes!
Leave a comment

No comments yet.