9a6b5f6c9c69c9a3902f4f9bae2a03b9

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-May-06 12:07:12
Detected languages English - United States
Process Default Language
Debug artifacts d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA1
Uses constants related to SHA256
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegCloseKey
Can create temporary files:
  • GetTempPathW
  • CreateFileW
  • CreateFileA
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Changes object ACLs:
  • SetFileSecurityW
Malicious The file contains overlay data. 203119 bytes of data starting at offset 0x33400.
The file contains a WinRAR compressed archive file after the PE data.
Malicious VirusTotal score: 11/52 (Scanned on 2016-08-09 12:48:56) K7GW: EmailWorm ( 004df05b1 )
K7AntiVirus: EmailWorm ( 004df05b1 )
Baidu: Win32.Trojan.WisdomEyes.151026.9950.9999
Symantec: Infostealer.Limitail
ESET-NOD32: a variant of MSIL/Injector.PWE
TrendMicro-HouseCall: TROJ_MOSERAN.BME
Sophos: Mal/RarMal-K
McAfee-GW-Edition: BehavesLike.Win32.Backdoor.gc
Avira: TR/Dropper.Gen
McAfee: Artemis!9A6B5F6C9C69
Qihoo-360: HEUR/QVM41.1.0000.Malware.Gen

Hashes

MD5 9a6b5f6c9c69c9a3902f4f9bae2a03b9
SHA1 9fdc9eea5c3ed311b8e525b1109ccf64a44b70e2
SHA256 394e43926fec7e038dbf21fd223c8df0e00a53be0d42bf0506ca2b3af2ad9440
SHA3 26e4f5e8ab05badb39bea37950cfbee5ec1111a2100e2cbbf1c8678e5ccb62e7
SSDeep 6144:4SUomEUi3+sMZ3xEYIrQ3XFhcab6moNyenai8hqLLPzOSoMw:pUomEFRu3xEPEoW6nEqaisqLbzDoMw
Imports Hash 031d703e579c1b0595487c17eb1f2a95

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xe8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2014-May-06 12:07:12
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 9.0
SizeOfCode 0x28600
SizeOfInitializedData 0xaa00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001D41B (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x2a000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x56000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0d2680623ee21ef164d1e5badd4a9069
SHA1 f636546786275cf43468db439129ab15a30e41bf
SHA256 1c88ae9276824c5acbfc06995211d67be9fd2f4554200b7cd176c7f00ff55421
SHA3 b997c57a757d56af976e70a590b231336c75eb49e0172cf1010d1623af4ae034
VirtualSize 0x28553
VirtualAddress 0x1000
SizeOfRawData 0x28600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.72377

.rdata

MD5 9dfce7fceb6345808dafd4693f9eba6c
SHA1 ad60658151481088e93bafa8ecc67bd541831a96
SHA256 30c4a46d9b249c42c7fcb75d25358d2a852b741c57ee6dee5d354b27138ea66c
SHA3 2e3695770ea10a580aa421c52be72037fb50a30a180dfa30e0b837b804f7d4d8
VirtualSize 0x4f53
VirtualAddress 0x2a000
SizeOfRawData 0x5000
PointerToRawData 0x28a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.35133

.data

MD5 599cdae4e964b67335324e67538c2a9c
SHA1 4191704d294fef46ee3b751bfeec22ff82c4c029
SHA256 bf2539a209de4ddb39835165e31e831ed02014191efecf7c3da9626aa80985c9
SHA3 d669746543b636c164d4d82e215991e8a338338c43a3b36466665e8981b74320
VirtualSize 0x218fc
VirtualAddress 0x2f000
SizeOfRawData 0x1600
PointerToRawData 0x2da00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.47003

.rsrc

MD5 69b892b761f0a069abf2fec1073249b1
SHA1 ade2539ce2fdd6815441a92a023e017fd8bbfc71
SHA256 bc1c4a4d8934e5b12c268f09b01ffe30b240faee6415ffa2b906300f177c3879
SHA3 b1e34a21678a17a07375d3f721c8e4498f216d2342c20ee2dca9d618952e3d24
VirtualSize 0x430c
VirtualAddress 0x51000
SizeOfRawData 0x4400
PointerToRawData 0x2f000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.79784

Imports

COMCTL32.dll InitCommonControlsEx
SHLWAPI.dll SHAutoComplete
KERNEL32.dll ReadFile
FlushFileBuffers
GetFileAttributesW
SetFileAttributesW
FindClose
FindNextFileW
FindFirstFileW
GetCurrentDirectoryW
GetFullPathNameW
GetModuleFileNameW
FindResourceW
GetModuleHandleW
FreeLibrary
GetProcAddress
LoadLibraryW
GetCurrentProcessId
GetLocaleInfoW
GetNumberFormatW
ExpandEnvironmentStringsW
WaitForSingleObject
GetDateFormatW
GetTimeFormatW
FileTimeToSystemTime
FileTimeToLocalFileTime
GetExitCodeProcess
GetTempPathW
MoveFileExW
Sleep
UnmapViewOfFile
MapViewOfFile
GetCommandLineW
CreateFileMappingW
GetTickCount
SetEnvironmentVariableW
OpenFileMappingW
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
CreateThread
GetProcessAffinityMask
CreateEventW
CreateSemaphoreW
ReleaseSemaphore
ResetEvent
SetEvent
SetThreadPriority
SystemTimeToFileTime
GetSystemTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
WideCharToMultiByte
SetFileTime
GetFileType
IsDBCSLeadByte
GetCPInfo
GlobalAlloc
SetCurrentDirectoryW
WriteConsoleW
GetConsoleOutputCP
WriteConsoleA
SetStdHandle
GetLocaleInfoA
GetStringTypeW
GetStringTypeA
LoadLibraryA
GetConsoleMode
GetConsoleCP
InitializeCriticalSectionAndSpinCount
QueryPerformanceCounter
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
GetModuleHandleA
LCMapStringW
LCMapStringA
IsValidCodePage
GetOEMCP
GetACP
GetModuleFileNameA
ExitProcess
HeapSize
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
VirtualAlloc
VirtualFree
HeapCreate
InterlockedDecrement
GetCurrentThreadId
InterlockedIncrement
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
GetStartupInfoA
SetEndOfFile
SetFilePointer
WriteFile
GetStdHandle
GetLongPathNameW
GetShortPathNameW
CompareStringW
MoveFileW
CreateFileW
CreateDirectoryW
DeviceIoControl
RemoveDirectoryW
DeleteFileW
CreateHardLinkW
GetCurrentProcess
CloseHandle
SetLastError
GetLastError
CreateFileA
MultiByteToWideChar
GetCommandLineA
RaiseException
GetSystemTimeAsFileTime
HeapAlloc
HeapReAlloc
HeapFree
RtlUnwind
USER32.dll EnableWindow
GetDlgItem
ShowWindow
SetWindowLongW
FindWindowExW
GetParent
MapWindowPoints
CreateWindowExW
UpdateWindow
LoadCursorW
RegisterClassExW
DefWindowProcW
DestroyWindow
CopyRect
IsWindow
OemToCharBuffA
LoadIconW
LoadBitmapW
PostMessageW
SetForegroundWindow
MessageBoxW
WaitForInputIdle
IsWindowVisible
DialogBoxParamW
DestroyIcon
SetFocus
GetClassNameW
SendDlgItemMessageW
EndDialog
GetDlgItemTextW
SetDlgItemTextW
wvsprintfW
SendMessageW
GetDC
ReleaseDC
PeekMessageW
GetMessageW
TranslateMessage
DispatchMessageW
LoadStringW
GetWindowRect
GetClientRect
SetWindowPos
GetWindowTextW
SetWindowTextW
GetSystemMetrics
GetWindow
GetWindowLongW
GetSysColor
GDI32.dll GetObjectW
DeleteObject
GetDeviceCaps
CreateDIBSection
COMDLG32.dll GetSaveFileNameW
CommDlgExtendedError
GetOpenFileNameW
ADVAPI32.dll RegOpenKeyExW
RegQueryValueExW
RegCreateKeyExW
RegSetValueExW
RegCloseKey
SetFileSecurityW
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
SHELL32.dll SHGetMalloc
SHGetSpecialFolderLocation
SHGetFileInfoW
ShellExecuteExW
SHChangeNotify
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ole32.dll CLSIDFromString
CoCreateInstance
OleInitialize
OleUninitialize
CreateStreamOnHGlobal
OLEAUT32.dll #8

Delayed Imports

101

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0xbb6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.19099
MD5 5c475f4b07e1e05af29d25e1700f7279
SHA1 b139902d2f9eae34727ba4f740b4b1e99d4bc4e8
SHA256 690c938562399f89ad78e3fde2a7edaee8ddf2fafef987a7b37e577a8f6126ea
SHA3 1d3dd19fbcc656a30478c2b4ba98485853b464fe09ea2debc4cfc64271677d1e
Preview

1

Type RT_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x11c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.78562
MD5 66fe9d6d25e61d657d31947094bed378
SHA1 3525455ce9449af144790156ce2464256c6e4e53
SHA256 b37ce71146b7fd29e08776b58a5d5aad590616a1b4cb9532c3ca48e8ffbd7947
SHA3 4ce163c63aea5cf8b8510037dbfe14418d76e77a7603ae7726519bf6476e9e27

ASKNEXTVOL

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x286
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42597
MD5 361be3e9f16096819f38433be227aeab
SHA1 303da809d3ec1bfc46b5fa4fde1733cfffdb9596
SHA256 887347f27d903f6652ba35c3dfae297c23435755a63e02a80259ee6dd0b8af86
SHA3 db76532737d079016d6f113bb1ac833820a004c041973cb70af7ed2cf185da55

GETPASSWORD1

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33944
MD5 331b55f85040e216e56c0b8e843438a8
SHA1 af4002fec283154f7d72fa3f363d28dbb1536f85
SHA256 2e11a1ed4f812e37fdb32a1310cdcca802c46497c27e33ab66ac127345463d31
SHA3 206eda4241a8bdb201359d75e1063c41ed5aba18392eea3d09b31bb5ed4f5f8c

LICENSEDLG

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16133
MD5 4da01a070e57545f97e0d84bcf1524e5
SHA1 eeeadb106e138aa26b66d276f84c8d076a31142e
SHA256 44e6a8daef1ac762f8016fc4c8aec52bad42f589b6d8a25d430a619610dd0028
SHA3 a018ce14f68b06cbed4adb1bf6714f3b6c1aa64fa2afa2215e037aa654f9fcee

RENAMEDLG

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x12e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.08925
MD5 23f9ee829c671147edcb4e5fc285dc76
SHA1 65f15e95491df6b271c340bc3cf6fc2a6e628a31
SHA256 30358e9c494ca9d125b34ccb93a2d8f1237042904f6fcecc2f5ca9a83b7dba9d
SHA3 830894d4015e75dd74224a9a6e70c573491f721f5d9526bbb9cbf766cf000092

REPLACEFILEDLG

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x338
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31987
MD5 822b9ba661d87f4dedeb47b67cdd4d5a
SHA1 b7902c16350bc2ee7fd78fbeb9461d2f123d59be
SHA256 a1141852e6fb28826de51733ee35fbfdcf74dd8eb7f73049c7c7ad6c21d0cb33
SHA3 712432c699365c95e1b04b3a44cebc97ce77f9824418dbb6784f0c653567325e

STARTDLG

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x252
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51642
MD5 14623c62285bf3fab07f52a8d4ee7758
SHA1 559c8c2d1ec322f7860a909c1d63b22e8e74dd42
SHA256 0f47dbda4a6e61d3288f63f249d25ab3f6e1fe497879a782d3eb1cd3922f3f4e
SHA3 c28724b596203a4f657d2ac87547e81631dd95cb46d7b43c9989c30b002f333a

7

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1586
MD5 2ee005bf14efd62d866ca276e73b47aa
SHA1 e098ed7de14a3221722e8c25ada1cb901ce85978
SHA256 450b4d82a86dba50acea995d6356e0174a242081f2c2438f6f88c29038f7097d
SHA3 3bd4b237507bdbc645d985837c718b5df99fa6c91e862fe59f7295cd82c7d0b0

8

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1cc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11685
MD5 91984a8521454b1758674f2f0765e695
SHA1 f48b0e0ca433d99226abe5cb9f1421b5dc204d31
SHA256 89051dca472bd5ebb7b344c05150755b6e3d32cb0dffea086c04186820b188d2
SHA3 c7c2157fcb23e3b9253e37f60afe11361c625e3d5e0535bbbf988387d2cd517c

9

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1ee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15447
MD5 bea5af210aba31a79a4329c4fe918826
SHA1 0639f7b55623ed115a7a2573862194ce497e135e
SHA256 4b330444367ebff69a042f9aaa930485c02a02e7efdad56db24cb2b76dc8f134
SHA3 0e3c015b6a949195bfecc1b2c288abf0b79803889b3a25c6558580c175e6a651

10

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99727
MD5 06aeb5ae44f152010b502d79d78da978
SHA1 765389e59fc961fb9782413bccd6218c0ed29c95
SHA256 1e87eca343221966ecd9472109f3baf9081c821e3f4e905aa34eb8bce73af4e7
SHA3 dda651f9f04eded147d6b4d66801eb000f7f83f5e6161c919beca8e51e7b6f8a

11

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x446
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2036
MD5 50607cbf5fa33da61e8d119c4a2c0c9b
SHA1 d38285a743fe1ebf62ecb612d62336060c865bc7
SHA256 06b2bd666ed1afbbfc9914b94d703087c18248c5fe28dead42e42f22c3984c5e
SHA3 9bc82cef576158d1c1bf6c60e77dae43a3c3ef80d1373ceafa46da206fd67cfe

12

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x166
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12889
MD5 70f271b2edd6a05942b95abced225c10
SHA1 dd3de2dc38efaf506c8c902edc3c6639651babbf
SHA256 d5755fffe2a9a4baf3593b8fba9a029b23bcc08e77c8d98e07b93baee6b9e6de
SHA3 99f9038fe42c25749482786e85b1f0ee5dda044080bf4ea4b311b333a3098c63

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95673
MD5 269a2d7069663060af7c9dd46b06fa63
SHA1 3addd59b10812bf9a9a37c28139b048acf8bb003
SHA256 a71a1445d83285856c39bf2f0caa19e88c9be65f0178a6878f321a925a21f97c
SHA3 9a7c6ec3de596dee9c3710ef77cb4693c3d5b584d842ccac347b066e46afbdf6

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77928
MD5 f2f57022da11e6b34117697226056e76
SHA1 94643fa46ab3195fa8fd17faed49d09a2c8d9fda
SHA256 71966cf60a28c1cdde4196d7909347e3f66661546af21edbacb15c7116944832
SHA3 c30201373f1a146121e6a60a036cdbbed0031c6ccae088ab15e9cd58c9339f61

15

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66523
MD5 89a43dafc107b44772a8981732b46a24
SHA1 3279b3c6f3470c0229fe6d68949357694bb7052e
SHA256 a8723b6cd67785f8b43dad75a1eb9b383db0e8a9a0b36378c2dcaef003aad4fd
SHA3 75e6b0a27466944416cc7a123168219c5c92a4eeef5f64eff9e9d38c46114620

100

Type RT_GROUP_ICON
Language Process Default Language
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.0815
Detected Filetype Icon file
MD5 4790a4a4256068af66677476c4f7b495
SHA1 b7391d4d17a57b07acb318b517a63da918eab9f6
SHA256 4bede24e58a4699c29f92e87d9c8d92c556297ce45acf1dc931efeadd4afc16c
SHA3 01100431c335b8d8500214cb408f59462e2a210a51159c4b4a9b45c56604f002

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x640
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.22792
MD5 d77609172db971b831b6fcd7f26b2ce3
SHA1 188e6d15191967f8deb3f41ec8e1af0af1684008
SHA256 c410d24baf3bcd455d35b9eb44ca14dee587be9e1e167fc6d8788ef56aa134fd
SHA3 6cf113ae7dab30eb9676fa517c0144356bd31e46107ae1cb4f462686e39236ac

String Table contents

Select destination folder
Extracting %s
Skipping %s
Unexpected end of archive
The file "%s" header is corrupt
Corrupt header is found
Main archive header is corrupt
The archive comment header is corrupt
The archive comment is corrupt
Not enough memory
Unknown method in %s
Cannot open %s
Cannot create %s
Cannot create folder %s
Checksum error in the encrypted file %s. Corrupt file or wrong password.
Checksum error in %s
Packed data checksum error in %s
Write error in the file %s. Probably the disk is full
Read error in the file %s
File close error
The required volume is absent
The archive is either in unknown format or damaged
Extracting from %s
Next volume
The archive header is corrupt
Close
Error
Errors encountered while performing the operation
Look at the information window for more details
bytes
modified on
folder is not accessible
Some files could not be created.
Please close all applications, reboot Windows and restart this installation
Some installation files are corrupt.
Please download a fresh copy and retry the installation
All files
<ul><li>Press <b>Install</b> button to start extraction.</li><br><br>
<ul><li>Press <b>Extract</b> button to start extraction.</li><br><br>
<li>Use <b>Browse</b> button to select the destination
folder from the folders tree. It can be also entered
manually.</li><br><br>
<li>If the destination folder does not exist, it will be
created automatically before extraction.</li></ul>
The archive is corrupt
Extracting files to %s folder
Extracting files to temporary folder
Extract
Extraction progress
Total path and file name length must not exceed %d characters
Unknown encryption method in %s
The specified password is incorrect.
Cannot copy %s to %s.
Cannot create symbolic link %s
Cannot create hard link %s
You may need to run this self-extracting archive as administrator

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2014-May-06 12:07:12
Version 0.0
SizeofData 81
AddressOfRawData 0x2cc28
PointerToRawData 0x2b628
Referenced File d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x42f298
SEHandlerTable 0x42cdb0
SEHandlerCount 38

RICH Header

XOR Key 0x16614bc7
Unmarked objects 0
ASM objects (VS2008 SP1 build 30729) 27
C objects (VS2008 SP1 build 30729) 143
Imports (VS2008 SP1 build 30729) 21
Total imports 232
C++ objects (VS2008 SP1 build 30729) 104
Exports (VS2008 SP1 build 30729) 1
Linker (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors