8f860c4136f998c05b26fdcaa42699c0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2010-Apr-10 16:57:59
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName J.C. Kessels
FileDescription MyDefrag Installer
FileVersion 4.0.0.0
LegalCopyright Copyright (c) 2009 J.C. Kessels
ProductName MyDefrag v4.3.1
ProductVersion 4.0.0.0

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 1623878 bytes of data starting at offset 0x70000.
The overlay data has an entropy of 7.9999 and is possibly compressed or encrypted.
Overlay data amounts for 77.9725% of the executable.
Safe VirusTotal score: 0/71 (Scanned on 2020-06-27 20:53:31) All the AVs think this file is safe.

Hashes

MD5 8f860c4136f998c05b26fdcaa42699c0
SHA1 fa7db4626f9e7a534df9226cdcdab4dc6d289350
SHA256 30e125a33f0043d7174c9cdf958a4b6be6eeed289156c47a95cd94d8a89afc31
SHA3 8bdca5939886d712d73e8a701d315f9290274a2ccb537737819372b8ff8cb175
SSDeep 24576:v7h0fEgf7H+akUGd4eyOG1RU+66EGfcNLrV3NBmpleUuKIn/+Z:Thkd+XdP2MQmFlNBvU/In/+Z
Imports Hash 9d8fb47598991ad8c0094898c32a6c3b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 9
TimeDateStamp 2010-Apr-10 16:57:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x15400
SizeOfInitializedData 0x5a800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000163C4 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x17000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x7c000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 56a7bbd83cbecd82973190d78cb5b764
SHA1 935f4fa2ca00d0686a96a44f8669d33d6d8fa128
SHA256 07653dc5f9f108aa149a8bfd5a542d679496b51cdddbce1ebc13fcf5229ee17d
SHA3 53ebeafe13fe20c2b2b92c1e8a8515ffc56ad797a91b85b786e8f012eecffc44
VirtualSize 0x1468c
VirtualAddress 0x1000
SizeOfRawData 0x14800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.46621

.itext

MD5 3b2998f31be8bd3fa8d83fc3250aa123
SHA1 70a2ebe4468a29ac3fc15dd20efaaab039e6feb9
SHA256 9beba2c8576307cee9b65c2a4f45fdf63e338af73dffd9d060592e2896e72d6b
SHA3 d315cf949c5cbd2ecac3205abb91d3350e692d2f8801bd15d91b6004588d3159
VirtualSize 0xb34
VirtualAddress 0x16000
SizeOfRawData 0xc00
PointerToRawData 0x14c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.79471

.data

MD5 37918bc8ca30a05654d6fbef198e0b30
SHA1 1e778c76577dd2032d76d6ef6c303d5590755e5b
SHA256 f98a8996726ebb02a6e05bc8be4abc697358217df4b656009575b85787d6f874
SHA3 49c3e38d48fa8ccdfbe389bf847e24eee8d2518b62c5570568b0ffc159691ae8
VirtualSize 0xd9c
VirtualAddress 0x17000
SizeOfRawData 0xe00
PointerToRawData 0x15800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.67747

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x5714
VirtualAddress 0x18000
SizeOfRawData 0
PointerToRawData 0x16600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 b47eaca4c149ee829de76a342b5560d5
SHA1 56a0ec8ac42ef35b0ee132508701868d83befc42
SHA256 1ea5a02fe0fde79fdd2d25e4a9b685d18118b74dcc53bbba9d54df63a6fd53c0
SHA3 a6c4a3115f9b16fd917a83f2157a158c28362886cd7414b31f05d345ab308a17
VirtualSize 0xf9e
VirtualAddress 0x1e000
SizeOfRawData 0x1000
PointerToRawData 0x16600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.96778

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0x1f000
SizeOfRawData 0
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3746f5876803f8f30db5bb2deb8772ae
SHA1 65e8dad930c8c32d40ca9aff4890630f20d87074
SHA256 9c8a4b346c5df43a9f90f5d15227c2dea3e7dfabfbe8402bcba85c3b2e9c84ae
SHA3 956c3695e53f796282349fc0b391c557d3f9bef6abb0d58045dacccc70b3a4cf
VirtualSize 0x18
VirtualAddress 0x20000
SizeOfRawData 0x200
PointerToRawData 0x17600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.190489

.reloc

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x1944
VirtualAddress 0x21000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ

.rsrc

MD5 98ae1e6905684429ccac3a57d05314d7
SHA1 445cd3aa963ccb27858a16e2b38d04661fb11317
SHA256 d43561502a56ed2519087bb7d71039844f21802235c437651d29acdd564ae298
SHA3 8cd95bdc596a90f97edaf3514931c6b1ba6cc90d81c887663a45def9ae21bb0a
VirtualSize 0x586a0
VirtualAddress 0x23000
SizeOfRawData 0x58800
PointerToRawData 0x17800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.7316

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xa68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97305
MD5 ae6532cddd36089cc4c2090dc9053177
SHA1 b67e9152ca75de2f6ca7f1941aa0bd8472f03082
SHA256 a0430b1c953f94ded53f54e0358fdc98c5eed6d73b9fe77f599e7523f5998868
SHA3 162429e41c593ac70839e6d4e32a1ae2a86aa294d52f0c924652846163d5905a

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00621
MD5 9e06bf67cc5969a9c4438ce8024fd302
SHA1 14d15d46cde121fc36bdc577092cdcd5e1a73b1c
SHA256 765cf6b223236757fb914cc32f1f011f402cdeb2af690084f7556af0605fbc43
SHA3 b76853573a493699335106b98d3e7c1663e3ade2b221524a7d42f91e7edd9300

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3672
MD5 48f6ef9bb5b3a7680bdc7915788cf627
SHA1 d713571c0fe8192f9deadbc7999e3fbf043dd1f9
SHA256 78b5f3f107c17083a69700a47871979d3f39a7fdaafba4fc24f1c6cc39548c06
SHA3 a8832d7c66e62a100dd61bfb7c67372b2cdb61a60d2ad04c29e1e2a018535c4e

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53872
MD5 40ad2bedbceb5733fbac64172c46c78c
SHA1 7d7bd9880269639c356ff5ba8383d1132df137fe
SHA256 84959500addb224214b42e814b993dad8550c5c79bfa7a951d0f884825bb61f8
SHA3 91ece45cfab25949579da0552a16cb64b015635fa9b2d9502c515200c0fff0fd

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1628
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.79322
MD5 d71a7c188a699682735668089262a276
SHA1 2d813df3c439b477a35c6d49ba2a02eb0cad1e9f
SHA256 51ef4f724266b4697a5fe9d4b7e7dd0c060d1f80ed5455639b3c8a2fc5995e44
SHA3 a9ec33751f71cb0eebd44af30603d0b5f2448dc0a0e03240e91e306e1c35d6eb

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05263
MD5 db5e6ea264bb68b25953f1ef4cc61b17
SHA1 50ddfb91240a81dfc3a9931d70a9c4da455d7ebc
SHA256 b963a1d50d5fa1901d6c4e5111213d09a40c285b8489140f1935614e6b0d035e
SHA3 d1a22b61c2f70b6aa97385915b51f0e2510e6a8e2437eac603bd031f91b710da

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.66628
MD5 615f0d4a836768d60385b5b704ad3363
SHA1 debd5c7446cbfdb620cbb3c94e104032403126d6
SHA256 a44a1ab9a0ecfa9d67359ed46bf1ceab437b03c8af539dcdc468b15051d2896e
SHA3 82bcb3d12cc0b3d3dee7bdfa40927fc35778ab3cf1b8dea9065b0ff4da87bbbb

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.92866
MD5 6bf3ce32e8a1cf79c90ad771080c013d
SHA1 dca7df78485c5e8b8d414fd78c42937a5c3274c9
SHA256 cfad7ed405c92524d3f314f4c2e0236b25447aa880c579193148cb83c2632075
SHA3 c0022d15db1288db53f732dd29c6cf600921537b37c47e54e4cb006d93bf12ed

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25538
MD5 212140ff58a770099916edddc5f772f1
SHA1 fe2e33be1e1f37460690e59d1fca67e04a6e8cc8
SHA256 64d9f44ddc5b3745c12e3a6b083d5d669f4eec5f89b1cb7ff46c028fc9f9011c
SHA3 2909df726e3659205528240acc55e0dbd31188364f32cf4f21075731013df0dc

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.74585
MD5 7cc4565cb139748fc6039cee5f87e8a9
SHA1 356930075e9474c54e7df4962d3d824cb15eb173
SHA256 583efe8aaf0daf4cd1d427ee4ce1a5fb9d90103427f254cfbd61a3e986780868
SHA3 7ac93a8486f659293da7b320162e5c4ba634608f3d960a4ed5340b2cdfe63065

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.84517
MD5 7de412c136b5af7352506dcb2fada0a4
SHA1 e09bc2155eb1c3f8687505a15d636d99caa81339
SHA256 9efbb7a75cc3849aeb9316aab408d857daaeb0074c85991bac00d2ce1e42e69c
SHA3 9f503bee05a0cebe1f30569de1b5ca12099efd819293f7a850252b47bf17c863

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.54848
MD5 a77da242d08726868f024838cfd37770
SHA1 d89c165307484d827b8e6e918567fb78a76c51e3
SHA256 b6d56cb9aeaf44b0979f98cc8f30bc5ce2896cc93a665f6134405c1e01197620
SHA3 2cc57cc2bc10d8315dd0962efe173c03c3a84ca9f32fd363fdaa4c04c4f88072

13

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.18172
MD5 81691863e7a4b6a61964e952cfe7b1d9
SHA1 ff2777fa6e53c9c24aed534920ed842be381d90e
SHA256 670d353d3c27fb741423c2ba16562619eea49546daddf660ebeddfe6b321907e
SHA3 0fc6d2a0fb0b509899e727fefabf1300f5b43c2a895bb2b59aae73f517ec319e

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13038
MD5 d2772bcc007d8465cf41352da64ed008
SHA1 3cb80c1ec7e649f89f425b6d7fdd11dd5333e052
SHA256 57fbdcb9b1d61d1269f5e9bc3e4f325029bd89778123d7703251761eebe26dea
SHA3 28c495a2cc8d92c07ea21db55f8e6ea142d60465f042d175b590db37884f5eb4

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36196
MD5 1bb1699f3e79a261a1cb71a60a1ace7c
SHA1 268f9a2602e1187b881d96db521e82c8d051d656
SHA256 a073bc06540956a93a3ef6eaa7d558de6f92de721edd29d6a93551a0fab23c08
SHA3 a0d833ced8297a2d82be5b80dd79fa9f61b84033377016f4c588ff2cfc168cf9

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x174
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34841
MD5 b6bedb71d6a6fa5215e4afdd1e983bdc
SHA1 7541a76c3ab32506ab00c3ab56076bf01532b267
SHA256 203e2c213958348f4911dd2e3188ea694f7d1d97f9ea9a82f89f5ee7af8c9607
SHA3 3ad5273f1d88b58db23b17b0ecd52f1280b9c279f64aad4404f5487b5d8f264e

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x39c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29351
MD5 0b1533b447231c6319c4a10d84508e60
SHA1 f5477d91942bfe92a5dc3c46897a66fb663a124f
SHA256 6fa3bbc46b4cc3a979f4ebfc293c50453912eb51ef76d2ea3c7d3d86d7223e86
SHA3 aed1581927a66228d158a903e015bdfa9a12e44865ff24c991ba8e2c1a9de8c1

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x194
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.25293
MD5 56a9f3c23ae215d7610440b21143adad
SHA1 eeb6c98cc1272fc93bd51a8d5fc6a4e0d6d142eb
SHA256 70b5b92db4b1175df56958af1c84bb8b9f964564093620193163dbc8b7acc6bb
SHA3 cd080119297e8bc03fc48cf02ce5b302d0a92c328b1b6fe3aab06b78b4ef3867

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.59457
MD5 67e22ef957a94b267d650324d6f887b4
SHA1 126d77312227cda0675200ef8a1de11900032027
SHA256 d4a5aeb18aacce9ac5743dbccb7fd9cb11d8fbb3c897f6825bf6924b13c0ff33
SHA3 d210360889747223be24ab4a9634c4fabc039697be63b68742a1cb6551576d36

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05766
Detected Filetype Icon file
MD5 1036dfd4c5277f5b03e9e0c311ecade4
SHA1 d8aa4df579b5ac8165b088133012d38bb7e5a05f
SHA256 9c6ab09fc1653b09159204f9df4b0c39d3736157f7088bd0325f477fd7d41992
SHA3 fa24ddbd4fe58d827bc4a78c2803dabc6762a8d1f86f81b92dc8516ea84b9b7a

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82245
MD5 6a358fefba6725b9f8393373e3a84735
SHA1 6f71b41854bb89ae9e2caa78bd972aa10d82a6b3
SHA256 eac248e0d123dd75c9ef8619536f91f6a4690d34a0afb580b221ea657e63e840
SHA3 9f674c7833c05731686b55dec0e64e259b464bdba2a124f0cfad5656172b156c

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x560
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.05007
MD5 8d7accca43bc3864983dbbb9af490005
SHA1 07ae72350bcbfedb5015a78efd74fcfd3bab11ac
SHA256 ec233469005d39f4f2673be991a0415318631a59c5976c35d4dd22db45226fd0
SHA3 d340127cbdd815e5c2dd4b44e8755c28512ad5e969b757cfcec6612b00e9d186

String Table contents

Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid file name - %s
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 4.0.0.0
ProductVersion 4.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName J.C. Kessels
FileDescription MyDefrag Installer
FileVersion (#2) 4.0.0.0
LegalCopyright Copyright (c) 2009 J.C. Kessels
ProductName MyDefrag v4.3.1
ProductVersion (#2) 4.0.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x41f000
EndAddressOfRawData 0x41f008
AddressOfIndex 0x4177b4
AddressOfCallbacks 0x420010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: directory 5 has a size of 0! This PE may have been manually crafted! [!] Error: Could not reach the requested directory (offset=0x0). [*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .reloc has a size of 0!