7eb21486d4d98a880e391651f849237b

Summary

Architecture UNKNOWN
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2009-Apr-21 15:19:41
Detected languages English - United States
FileDescription Bi soft
FileVersion 1, 0, 0, 1
InternalName Bisoft®
LegalCopyright Copyright (C) 2009
OriginalFilename Setup.exe
ProductName HLM
ProductVersion 1, 0, 0, 1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VirtualPC presence:
  • 0f 3f 07 0b
Suspicious The PE is possibly packed. Unusual section name found: \x00
Section \x00 is both writable and executable.
Unusual section name found: .idata
Unusual section name found: Themida
Section Themida is both writable and executable.
The PE only has 3 import(s).
Info The PE's resources present abnormal characteristics. Resource 3 is possibly compressed or encrypted.
Resource 3858 is possibly compressed or encrypted.
Resource 3859 is possibly compressed or encrypted.
Resource 3867 is possibly compressed or encrypted.
Resource 3868 is possibly compressed or encrypted.
Malicious VirusTotal score: 23/40 (Scanned on 2009-05-03 18:12:10) McAfee+Artemis: Generic Downloader.x!d
CAT-QuickHeal: TrojanDownloader.Bagle.asc
McAfee: Generic Downloader.x!d
K7AntiVirus: Trojan.Win32.Malware.1
TheHacker: Trojan/Downloader.Bagle.asc
VirusBuster: Trojan.DL.Bagle.AAVY
F-Prot: W32/Heuristic-210!Eldorado
Avast: Win32:Beagle-AEV
eSafe: Win32.NewMalware.Jn
ClamAV: Trojan.Packed-142
Kaspersky: Trojan-Downloader.Win32.Bagle.asf
F-Secure: Trojan-Downloader.Win32.Bagle.asf
DrWeb: Trojan.Packed.650
Sophos: Mal/Generic-A
Authentium: W32/Heuristic-210!Eldorado
Prevx1: High Risk Cloaked Malware
Microsoft: TrojanDownloader:Win32/Bagle.ABM
GData: Win32:Beagle-AEV
AhnLab-V3: Win-Trojan/Bagle.843776.D
PCTools: Packed/Themida.RGa
Ikarus: Trojan-Downloader.Win32.Bagle
AVG: Win32/Themida
Panda: Trj/CI.A

Hashes

MD5 7eb21486d4d98a880e391651f849237b
SHA1 47827a95bc51501f6c057dc33521404526f1d3af
SHA256 f9bba89f26dcedfa355a0360df34283c811269cebc34336bb41a20521dbd5042
SHA3 718c8c6c3de0a96dc2354c7e6902bf0f1a5a6c55aa0a3b44a8b78e324dd7cccc
SSDeep 24576:SP12cmvudu1R134Tc84X6pzhevpK0/OrkdE:SHdu1RdQhCg0E
Imports Hash 0d135341487931f418d4b36250261725

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine UNKNOWN
NumberofSections 4
TimeDateStamp 2009-Apr-21 15:19:41
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 7.0
SizeOfCode 0x43000
SizeOfInitializedData 0x42000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00087014 (Section: Themida )
BaseOfCode 0x1000
BaseOfData 0x44000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x1000
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x1d0000
SizeOfHeaders 0x1000
Checksum 0xd27cb
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

\x00

MD5 5a01bb111ab0c530c1a962fb041e4807
SHA1 4eac87f96fd46c2319db6237c8be88279f2696ab
SHA256 a8f7020157c327810a84b2d5046300769f431ed81eeebfe79c960d3bcfdd8cf7
SHA3 70c56fc7bcc5253279aac31b043cd7e22a1f3e81c43f479bedd8bfd0b3b43517
VirtualSize 0x80000
VirtualAddress 0x1000
SizeOfRawData 0x3a000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.98622

.rsrc

MD5 5d8544da942b6dd1e8dcecb41e9e7091
SHA1 c8128fa76ec529822f46f3059a9ba193ca83c4f5
SHA256 a6f5d17e97bf2f14abea83cc8cf068715d6fe3aad4aa58c04ce3553a6a583b89
SHA3 57612d51b4c9dbdc315a8124f987101b2d6f2db6da7179c16f2c9aa2ea2585ca
VirtualSize 0x4ff0
VirtualAddress 0x81000
SizeOfRawData 0x3000
PointerToRawData 0x3b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.2186

.idata

MD5 f86ed708397314de04aaf3f89190333b
SHA1 b597e0b3c2c05ceda4484b69780dc2f862c61f85
SHA256 dbed5ef54afc523cf630c6a2e3afafd3325c80e1f65afcf9f2a7260eaf530a65
SHA3 f5a6579ab4a04983242730fd13ec6283b9a4f6c45481827cf282fbbf24505e9f
VirtualSize 0x1000
VirtualAddress 0x86000
SizeOfRawData 0x1000
PointerToRawData 0x3e000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.233265

Themida

MD5 47c93775bd1391991159acbff4d1f6d9
SHA1 4ac76a27df436f79ae25fd39b653f921526166ab
SHA256 ddaabc0435b2d1658c1a67ee5158e2b634388fceaf0582a2bc4388331cf5eab1
SHA3 fe54b262ac271056d2dcc75ae762a30be5963c7c73099a0aae372d6cefbf3d67
VirtualSize 0x149000
VirtualAddress 0x87000
SizeOfRawData 0x8f000
PointerToRawData 0x3f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 7.87491

Imports

KERNEL32.dll CreateFileA
lstrcpy
COMCTL32.dll InitCommonControls

Delayed Imports

3

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.09206
MD5 80847c272c45c9cc3ed2e71edde71651
SHA1 056ceda7b8de6eb52ee1390508c67d07bf8b5ef6
SHA256 2a01d1f1ca8c9db76aac089f6ffb1790b75cbb736f4a905f38736c651bae9a02
SHA3 07a20d9f45ae906d1e3f99e7713176a501d4479efdefdd83a7d6144ad119eade

4

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0xb4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.6591
MD5 69c2376099ba77cedcdab14fe0db248c
SHA1 0d7e46008ea7d11c340e163266a53204bc1b4025
SHA256 cb277ec3ae5b4332749bb2b44e91236d1bf1445974c60736159f11210548a1e3
SHA3 96580e838dc3485d3256fa708a0a74c32a1a2d6ad1299f6c3a7480854ac7f4e5

5

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

6

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

7

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

8

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

9

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

10

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

11

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

12

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

13

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

14

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.1758
MD5 615763984b6d8c5b8f7df3dccee05819
SHA1 1b164920dfbe68abe491b663c01b2f088e8f4cf4
SHA256 548ff854ec923cc524d95de2a4261a2abf685153b6e84fc410548f3f1a92382c
SHA3 d878168abfbc90f43d31043ac724d2cff86f2903f16753e01d33b3b6c27ab57d

15

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.394372
MD5 99e0a084e0a58a4054ffa7bfd6c96440
SHA1 99652add57e3ecbcad5b10b9a3fddc2f542f91e9
SHA256 2cd5c16aa577ef422fdebcf399737ee9c95101ff38e9c52d386dd83943decf5a
SHA3 3c27e32c150b04f38d1866e24bdb4d503e8cb8829ed6c58032b7cb085eb6dd90

16

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

17

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

18

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a2a5bb0f1f0a8eb31a3c60a6ad28543f
SHA1 80ae948ca52e33a2dcd21779fa392266aa4cd8e1
SHA256 9575b2125169377b2ade7b401ea36c81228331d971f49664d9648d4f255d4868
SHA3 013abf10282fa58151b0e6c5359f78e6ffbc5426ff76f3229c8eacbaf1973e38

30994

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 0e2e640b11f60ae0769bca010bdc6ecc
SHA1 420f079c4fa62bd56442cbd687964bfa1b423a20
SHA256 d81bfb50e59a9abbe66f6ae0c6b45c7b9c0bc6eead2cf982118ac4d62b6ffeda
SHA3 845cbd3db6727d0f00f11759a3fd45b054c34b907de9ede31a7bfcd5fe9aa76e
Preview

30996

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 53e079183ddf7a114aed02f9f4d3efbd
SHA1 df6b573dde3185f29911af037f70a9319d40fb77
SHA256 7119f314d3837dac54bf984118de657f6f1e6dfd2a2b2a20510454f762dddf11
SHA3 71f6a6adba30bf6537cd7df2ef26312fb14317f64db2363aa229ada218776be7
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.22742
MD5 65764dd20f6f7abbea36baae2afb2ace
SHA1 b1beacde0a86e5adcdfef48fe117ad583dc173af
SHA256 e7d994be1732f91df0d8963c018cc5ff1ad5795eb4b30d1d2bf0ad793436e54f
SHA3 dc8856912f216b3d5d70be4427152d6fc6894e542fc317ecc4ab34fd3f355bd9

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.12391
MD5 7a35beb961387df8aa2041151810fe8b
SHA1 d0a5b7576ddbeb84c72d579ce0cd50347d8b19a8
SHA256 7ada9d096a0372274aad7b179a4e6eacb8f154f9de9beccc07162b558335b95d
SHA3 d6e2e710593c37e8b00cd8950281452782bf9d74c4ffac2527095b44d2379d58

172

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x62
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.01247
MD5 bbf7c8ba64638fb632c08a3a2a711db7
SHA1 8c68c4748076b6fc17855d6a1f2deb77965d1860
SHA256 097dcd11224bff7e14c9096a3b36b29e268388025419c18886123dc7da6a0223
SHA3 8f7daf547bf80c6e019d56891adb079ee397fbc32e0161f88186566d75b6fcc7

173

Type RT_MENU
Language English - United States
Codepage UNKNOWN
Size 0x58
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.04733
MD5 be497fd7ae9fcd93090780395802066b
SHA1 0d99b68f4313f500f33df2d093cb66e69e15b2f3
SHA256 df8c6b0e6dd97d771e550a66754affe9ec021b417a2610c8f888f188b41f3e35
SHA3 20e7b38e476ffd4a671103863347ff918ee6261fd55b44fc5267274a7a3dec3f

100

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.6721
MD5 a020032c5640f337240442f16e2250bc
SHA1 88b86657148cb1b8380352746153fe3e964245dc
SHA256 54a20d95b042f8ff1d661e9a37f84bdb500f64a0242b45c4d2921ae11646a23f
SHA3 672b375cbfa077231a108ca9d8cca725f139f6ecfb99c17bdb6dd9c3cc256abe

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.68477
MD5 6f7ba571ca7288cb15f441e458b9cf97
SHA1 0f5283d0a51a2c5637761f66c66c7d3cc8056fba
SHA256 0da61e7288e6922676753e14b5fe2d2be588fef0679e1242cf0f811ac3299ae8
SHA3 d6a5f7770c2fb5f63773c66d60f61324cdff29b2c9d8b1db4667e2640f361c07

104

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xd0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.77682
MD5 a7f1617b2eb3fe4f425c20eaa2fdc0a9
SHA1 35991fa430e439772c64f254fb9638d324c1343b
SHA256 c6fc4dc0abe18b0b11138e810ad5fa09b772d04984f3bd25acc4c2869630e7cf
SHA3 de76dcf2ab9e7d48828d6dbcf12a4301ca76bdaff8c58d007dd088e95e105007

30721

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 5ccb2c1dfcfbff9adba49b72793b8762
SHA1 c4db4f62b1c1a64f19f83c69735270c2f50d0570
SHA256 c4fcd50d9f0c893c46288b57d8e62b18523145956b249b6ecd6c21718be49065
SHA3 2a7a702bedde59e1204f341499e4a0f15ab4857fcb2ee48ce17b945ca29d933d

7 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x3c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a302a771ee0e3127b8950f0a67d17e49
SHA1 fb3d8fb74570a077e332993f7d3d27603501b987
SHA256 5dcc1b5872dd9ff1c234501f1fefda01f664164e1583c3e1bb3dbea47588ab31
SHA3 286e4ac4211e7ad56db02532a197cea507f6c19ab8e5d6213be5a14f21ac2149

3841

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x82
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 b93d9b41abd4ab965ea782b4be302a12
SHA1 5d45a50bfe5e9b6ecad8ee68f17e71a69869d335
SHA256 e55a5c27736a8761c8e96acec072102325e08cb2d0dbb4d4702cfe38f8ab0709
SHA3 5a30e96b0984e8237b6c70c81960ceabf30cc8823fa2766239bde4c3ed7db6ca

3842

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 c183857770364b05c2011bdebb914ed3
SHA1 040e5ac904de86328cca053a15596e118fc5da24
SHA256 094c4931fdb2f2af417c9e0322a9716006e8211fe9017f671ac6e3251300acca
SHA3 729e62ace660b283ddd5b0ecc9805db459a3375c8e0a2a3b80274d24bdd9142c

3843

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x192
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 28bd444caa20e5092d21f0b7b4b032f7
SHA1 1e48b6032154b884bb7016b0abc5129f7aa7761d
SHA256 645c0f377debd8df3a455c47dd552bac806a6092e929b5580ff8ce25fcdd8e09
SHA3 b600955cb93bbb5b8bde357a9f21549fbda1f0d3609387eda63d725d085d0bcd

3857

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x4e2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.187501
MD5 f3964e5127b98e66917902797d032368
SHA1 2cb1f1364eed32751706e81d240a3a6d520be35a
SHA256 53950077116bd93a8c98c2e63fd5984984e379b36c1206b8df4e7d88f01d37d9
SHA3 7b2f079f7cd01b627f4bd9ad3325778fc3381b6fa05c69eb1b4f3d98492ab464

3858

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x31a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.54132
MD5 e75d0ab4adcc90c885eb00a27b29d505
SHA1 62266b01478bc2eaee1fca624827f56be8fa7fa3
SHA256 042d767e80fcd0798f61d64bd82838517e783ffd7905326fc697b66590e453ac
SHA3 61f68a65d591c70d202609498f6e4ee1e1126ebe5a7da4af137c492b74f339ee

3859

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.01283
MD5 7bf80daf3c0b54db19e0cb199483f469
SHA1 d14af884756e115d85fdd9a08bd3d0c61413500c
SHA256 c66b332aba7d4718ab9ff3b8627d97f23f8ff9b334c6b80c3a1b63465a62bc2c
SHA3 bbacf6013cd08d81f939fea68756d8a20b4e06724d661d5456e7adbede287bed

3860

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x8a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.39707
MD5 556f99975ca439637d1c2f4270dac8c7
SHA1 799b42f95b6568f69d045f1cdc2f107362d4a36d
SHA256 aec8d3bec386f631dfd72886721760808f50f43d48dc82c4bea7cf026b8e82dd
SHA3 4e20c49de0eec30c088948eab3ae03f4af00285cdabee2dd3e8236f0f3526de6

3865

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.73561
MD5 a824600fab014854dab483bdf628139b
SHA1 dc434731572a93d34db11050869f4cf83b15c322
SHA256 f9fdce1058d23f0c7766c4a06b3952966936fb2df4c2e938085c88c9a1a77319
SHA3 c151ad72f103361ca0464f42ccded5104a40df2325ed28271a728284c1a0a74e

3866

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.89787
MD5 8dbbd4c9e623fa363fc145b338fe68bd
SHA1 0780db1dc5ed50353b4c0e535a2d75f586679dc3
SHA256 e7a4bc890eb4180b9a846da8f289e03ffff273c9a53ec8b96547476cc88820f4
SHA3 8cf69694591115c0bbf0456e56eda1f066078d6b1d91d608f2b8fde67c9e8bee

3867

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x4c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.714
MD5 2b452be378d224a2ed4337d3aa1d48f5
SHA1 62600e40c539a509d26f13da1fd547b147064bd5
SHA256 ca2d3df32d2d4c19069e6f205a10617f53dc6f9b2f1313e345e1fe02285a7884
SHA3 61964da69b61fb07496b914f70ece670c8c863573047a5d84232ab862c834e61

3868

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x264
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.5591
MD5 47704c550117fde87b444243a63e69c4
SHA1 ed8fef50595c53bc55b5487d19b9123cf9160170
SHA256 1263eb8d84045ff38945614b1d800a16e497c1c7da17ec0b749fc3884e1b476e
SHA3 ceeabaef7d79cd7d3930225e5e014b1f0e8f04624cbef6997302874d0c8d2e48

3869

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.36852
MD5 ca8c98f3a10203f07b6e70d5b138b02a
SHA1 ecaf3d9254dcdc9edcfdacf65f30a2ff0629e484
SHA256 bdc4fd1ab50ab9d5f42107b0c66b6fc3a134e7d57656697a360e733478968ffa
SHA3 1a96809cb119d9c9846cc78a4a118d3983464a66692fc319b69e9735cf0e7e25

3887

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x42
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.65788
MD5 8a14c620f5493253775e92178ce046b3
SHA1 9275310848ffc4aa76a1a72570c0fb8404f69d7d
SHA256 af353b7dd3d7724a402b6470c5aaf96d7ba1e177d93324eeb06d3f26fedf19f5
SHA3 baeda4458dad47922585dd817bb1c7624652415170bc1efc793bcbb3ee34c649

30977

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 0b91f1d54f932dc6382dc69f197900cf
SHA1 3173532552077d0d796c3628ac35c76343dc3a04
SHA256 eb142b0cae0baa72a767ebc0823d1be94e14c5bfc52d8e417fc4302fceb6240c
SHA3 7b8f2bd58baea4bd5b7a3da6b659b65aa1eaf5e6308428e9dcf989cdcc97bed5
Preview

30998

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

30999

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31000

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31001

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31002

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31003

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31004

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31005

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31006

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31007

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31008

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.72193
MD5 7ecb45683e9fb71417385657b6e175e1
SHA1 2df29a28c1eeb6ec38609112e74e6973d290ec84
SHA256 4b7b92ad58221546f019da8f0790975dd732952a113ddc655fa9325388c006ee
SHA3 6719f6de789160ba15cebb90fb7647a3e3b83fe6b38e08cff88355fe5cc923d8

31009

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31010

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

31011

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 441018525208457705bf09a8ee3c1093
SHA1 6768033e216468247bd031a0a2d9876d79818f8f
SHA256 de47c9b27eb8d300dbb5f2c353e632c393262cf06340c4fa7f1b40c4cbd36f90
SHA3 f3683c9e3da9a7f90397767215345efe3be07565f14ab80d102f50644b98fbfa
Preview

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x22
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.32824
Detected Filetype Icon file
MD5 98abddcf0c1dc29c999864264b78c981
SHA1 848c0e5121dad30e7b7381e85ddfeea5672366e7
SHA256 d58a6a1ee3d9ae7bb5bb4b019a84495af9b55381f295dc7beeaf222d58bd4c36
SHA3 791bcb018a1e72465a6006dbcdf1423c8740cdc634f355903df3c7738ba27552

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x268
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34248
MD5 a62d4de32bc5d7bedff675e2c92b81bc
SHA1 c5e7e563c085827b4448adf6bae28bf6d90e7c32
SHA256 c42f7ea11c1a8c0ee48f3dfc29a9d4f9706b3c86e4accbd06b40773255609861
SHA3 d7006182a33cc04f2e88e40ee2a66261c0a8e805ab5394ba0cea8a6942ab561d

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x1b7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.04045
MD5 155dfe558f02bc0ff02b942831c08ec0
SHA1 a96b19cefb8937e3f8f06cbc369e0322ed57d211
SHA256 4cb7ce734df435d89ce0d5a6e4d7d453a4a39ddf3afb91fb434eaae889c1bea9
SHA3 6c0290daab16f5b3a136ca97f9833a7b70102883d2c8d10ee4d42d794ce73c65

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.0.1
ProductVersion 1.0.0.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileDescription Bi soft
FileVersion (#2) 1, 0, 0, 1
InternalName Bisoft®
LegalCopyright Copyright (C) 2009
OriginalFilename Setup.exe
ProductName HLM
ProductVersion (#2) 1, 0, 0, 1
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xb3819ffc
Unmarked objects 0
18 (8444) 1
C objects (2179) 11
Imports (9210) 4
19 (8078) 23
Imports (2067) 2
Imports (2179) 23
Total imports 654
ASM objects (VS2003 (.NET) build 3077) 28
C objects (VS2003 (.NET) build 3077) 135
39 (8491) 9
C++ objects (VS2003 (.NET) build 3077) 145
94 (VS2003 (.NET) build 3052) 1
Linker (VS2003 (.NET) build 3077) 1

Errors

[*] Warning: Could not read the name of the DLL to be delay-loaded! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [*] Warning: Couldn't convert a string from a RT_STRING resource to UTF-8! [!] Error: The number of ICON_DIRECTORY_ENTRIES is bigger than the number of resources in the file. [*] Warning: Resource 31008 is empty!
<-- -->