a0946c28b5e2eba1d0c270dc6699fe2c

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2012-Feb-24 19:19:59
Detected languages English - United States
Comments A build of the PortableApps.com Launcher for Foxit Reader Portable, allowing it to be run from a removable drive. For additional details, visit PortableApps.com
CompanyName PortableApps.com
FileDescription Foxit Reader Portable (PortableApps.com Launcher)
FileVersion 2.2.1.0
InternalName PortableApps.com Launcher
LegalCopyright PortableApps.com
LegalTrademarks PortableApps.com is a Trademark of Rare Ideas, LLC.
OriginalFilename FoxitReaderPortable.exe
ProductName Foxit Reader Portable
ProductVersion 2.2.1.0

Plugin Output

Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryW
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExW
Can access the registry:
  • RegEnumKeyW
  • RegOpenKeyExW
  • RegCloseKey
  • RegDeleteKeyW
  • RegDeleteValueW
  • RegCreateKeyExW
  • RegSetValueExW
  • RegQueryValueExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Manipulates other processes:
  • OpenProcess
Can shut the system down or lock the screen:
  • ExitWindowsEx
Safe VirusTotal score: 0/67 (Scanned on 2019-09-19 16:01:15) All the AVs think this file is safe.

Hashes

MD5 a0946c28b5e2eba1d0c270dc6699fe2c
SHA1 fbb756c143968d64fcf8aac2d9e29cd9eb0d919b
SHA256 337813587de14e828ce21f8994853411b3ffdece066f88fb01a360a2e4fed4ab
SHA3 5dccb6cf56c678884f70d36c3ce0bc36b6bc836ed01f32f5a9413089dc571244
SSDeep 3072:RweqOYEUXPncWdeTq3SRgeQhi/Qm0+aKcL6+LMfhVsjNXRCPRL0l:mEUXEWden+ij0+cLvLmhVull
Imports Hash 9676d3254c05a4258dfb3154ab9a7a37

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 6
TimeDateStamp 2012-Feb-24 19:19:59
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 10.0
SizeOfCode 0x7000
SizeOfInitializedData 0x6ce00
SizeOfUninitializedData 0x4200
AddressOfEntryPoint 0x000039E3 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x1e7000
SizeOfHeaders 0x400
Checksum 0x40e19
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f569e353af0ed51bf4c216faa9bed4e7
SHA1 6a44a12f5af7cce9abbd9cd636f52401b2120209
SHA256 43b1b548befd5d2a4638048c6f234cbb66fa07c1fd709bbc3e73bb4d642da595
SHA3 2a5b3f035f6962e7f8bbe2adb74570e17e1925c226adfc81c2a4375bea2310a9
VirtualSize 0x6f10
VirtualAddress 0x1000
SizeOfRawData 0x7000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.49788

.rdata

MD5 91eee43954e068e650f7b73a8b0e6915
SHA1 b547eb6e6cac33ee3733ac68385899629a5e5f17
SHA256 e0f96857d54993cd0a9a734ab76698d270a5311129cc442a3344bb196b9afe4a
SHA3 0e15cfd9c8ce1462c26fb202da97515881abdf0e9729f0cadfda0e8fbe60c89b
VirtualSize 0x2a92
VirtualAddress 0x8000
SizeOfRawData 0x2c00
PointerToRawData 0x7400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.39389

.data

MD5 db9f7acbf1c3ddfe255077b699955dfa
SHA1 53188fc5923c982a5f95f3d84c9e65d33d887d59
SHA256 6db33451a2c8a909671725fe9d9e735e8c3bc704954f014503d33963aca37551
SHA3 defd360cc2dc6f7f28b1998314c9492a9f450dc1fad927840058dee2eb8cb32d
VirtualSize 0x67ebc
VirtualAddress 0xb000
SizeOfRawData 0x200
PointerToRawData 0xa000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.47278

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x159000
VirtualAddress 0x73000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 121eae2d0241c56c240ff1eca431a5de
SHA1 4c0ec22ca4678689c4edbeba43096f6e2778d5a2
SHA256 21b720319de20c6f433ebe22bc81c8644b31ec58be93e05afc8c6a0352553a99
SHA3 017715ef2c3e8c8effb508cd8435bc79d42dc8f8200ab0b7f5fccf8a19b04a5a
VirtualSize 0x197c8
VirtualAddress 0x1cc000
SizeOfRawData 0x19800
PointerToRawData 0xa200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.14357

.reloc

MD5 bc9d33414d3674330e48232b29535563
SHA1 4666124cb3595ebc07e08f3897be0534f3d2b447
SHA256 f00acb40edbe825a88e6f655a81c63ae6f322e537dabf596f210877bf06d51fe
SHA3 26d8eb69fd641c384135072ca69fcf572d03e2685039b07752af0b63eb0c6c08
VirtualSize 0xf8a
VirtualAddress 0x1e6000
SizeOfRawData 0x1000
PointerToRawData 0xb400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 2.50128

Imports

KERNEL32.dll SetFileTime
CompareFileTime
SearchPathW
GetShortPathNameW
GetFullPathNameW
MoveFileW
SetCurrentDirectoryW
GetFileAttributesW
GetLastError
CreateDirectoryW
SetFileAttributesW
Sleep
GetTickCount
CreateFileW
GetFileSize
GetModuleFileNameW
GetCurrentProcess
CopyFileW
ExitProcess
GetWindowsDirectoryW
GetTempPathW
GetCommandLineW
SetErrorMode
CloseHandle
lstrlenW
lstrcpynW
GetDiskFreeSpaceW
GlobalUnlock
GlobalLock
CreateThread
LoadLibraryW
CreateProcessW
lstrcmpiA
GetTempFileNameW
lstrcatW
GetProcAddress
LoadLibraryA
GetModuleHandleA
OpenProcess
lstrcpyW
GetVersionExW
GetSystemDirectoryW
GetVersion
lstrcpyA
RemoveDirectoryW
lstrcmpA
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalAlloc
WaitForSingleObject
GetExitCodeProcess
GlobalFree
GetModuleHandleW
LoadLibraryExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
WideCharToMultiByte
lstrlenA
MulDiv
WriteFile
ReadFile
MultiByteToWideChar
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW
lstrcpynA
USER32.dll GetAsyncKeyState
IsDlgButtonChecked
ScreenToClient
GetMessagePos
CallWindowProcW
IsWindowVisible
LoadBitmapW
CloseClipboard
SetClipboardData
EmptyClipboard
OpenClipboard
TrackPopupMenu
GetWindowRect
AppendMenuW
CreatePopupMenu
GetSystemMetrics
EndDialog
EnableMenuItem
GetSystemMenu
SetClassLongW
IsWindowEnabled
SetWindowPos
DialogBoxParamW
CheckDlgButton
CreateWindowExW
SystemParametersInfoW
RegisterClassW
SetDlgItemTextW
GetDlgItemTextW
MessageBoxIndirectW
CharNextA
CharUpperW
CharPrevW
wvsprintfW
DispatchMessageW
PeekMessageW
wsprintfA
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
LoadCursorW
SetCursor
GetWindowLongW
GetSysColor
CharNextW
GetClassInfoW
ExitWindowsEx
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
GetClientRect
FillRect
DrawTextW
EndPaint
FindWindowExW
GDI32.dll SetBkColor
GetDeviceCaps
DeleteObject
CreateBrushIndirect
CreateFontIndirectW
SetBkMode
SetTextColor
SelectObject
SHELL32.dll SHBrowseForFolderW
SHGetPathFromIDListW
SHGetFileInfoW
ShellExecuteW
SHFileOperationW
SHGetSpecialFolderLocation
ADVAPI32.dll RegEnumKeyW
RegOpenKeyExW
RegCloseKey
RegDeleteKeyW
RegDeleteValueW
RegCreateKeyExW
RegSetValueExW
RegQueryValueExW
RegEnumValueW
COMCTL32.dll ImageList_AddMasked
ImageList_Destroy
#17
ImageList_Create
ole32.dll CoTaskMemFree
OleInitialize
OleUninitialize
CoCreateInstance
VERSION.dll GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97866
MD5 354eaf6fbb17d586f4c89f7f27964488
SHA1 0dd4d083f34e5602462a06e47ee1c70acbb3cd9e
SHA256 c5d209abc10426bc13ac0e884522f4e0508a380b3378da51fdc8dc2c44751f1a
SHA3 617e6e580bef791bb50b4a0eed7e78fcc39ff63c9ea40addf34c425760cb3d27

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38772
MD5 1b50c398e30b58fcc9de1d164bb5cdd1
SHA1 149094df1be76bef9e4b7041c0a89537f854e25b
SHA256 caaed36a4ec0968f72b51c2dd953045d4e56ecdd55f0bc6c06d658d8b83edb63
SHA3 39e4cc579fe95d4518061e7f5827fb4344ed385252aee30f889a444d1a08e82f

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1e0c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.76872
Detected Filetype PNG graphic file
MD5 2bdf2b3422a1a947f551d7102284113b
SHA1 235da5c0b534ffbf1bf7c557e4c8ff3fd71fdc96
SHA256 c6eaaad3fa6616f8d4f927679d2137f4d7e1eae26d2abe4e42f6b5c9e08df7bd
SHA3 8550fe8849b36391595ea0ef7cbe6fa121eca6d81f077464412b16d24f4f135f

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.94442
MD5 26a8d90e581881dc89d7025c92ac41c1
SHA1 f6288cb886bbcf0e3245feb633d0bb84ae829941
SHA256 e86725be9a146df1fcab1295cbd14f26f62887ae01f985846be6ceafc17f50dc
SHA3 00a5d09a5c8afa5fa2280bb1dd1e68557d0024d3fee2e87066ed7d9f4c978186

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95001
MD5 f63114bfa6fe72825bc4555d47d6f02b
SHA1 35351c451bbdb607271ddf689ae2777ab3e85e74
SHA256 907efb8ee923c08a50a11a593753d597bc434e0758a79f1d6ac42b7f271ad06e
SHA3 63b98af667b82bc85be9ffad80fd2227f671a45e1f3c65a64670e0aa30edd9e7

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40613
MD5 be4508ee111554c0c44bee5b24e0bbbd
SHA1 0bbca811e9854a274cb32b9a6fd8e398c36b2e61
SHA256 c8ce974f7a6aa46d59be4061498bf2341f501c41db11d2f0220ae8d2acdf4b80
SHA3 e34d650aa6aa8602d492035c69737918a55d0bea1e44a146b5e30fb9779a9b54

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.15929
MD5 e4c26e826dad6eb93439578d60474b20
SHA1 3cbc1fe680143429138b896ba3b4793a76127ed7
SHA256 62c57ab32d3c2d0a7b8fb9cd4ca332b87417844a92d04514e5df3afb719e977f
SHA3 21e89cbcec2b9cadbc701968f6284b1a6b52e6bc3696f4ab88dc8e9565674a3b

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.04177
MD5 a1a64c1ba05a1b7d03ace7c2125c0e8a
SHA1 028eeebd1afc65d1972b1caa0d29cecfb012dc7e
SHA256 ca69d2c3267e207eb4a77aa3b081bca3780094ac5e2c711af4d27be8ebfa7bb7
SHA3 fbae149d014810db7c3ca687b8de09b6580180a245f77e18a3a6154eaae51760

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66174
MD5 3409f314895161597f3c395cc5f65525
SHA1 1a99d016d65e567f24449d9362afb6ac44006d0b
SHA256 fecdb955f8d7f1c219ff8167f90b64f3cb52e53337494577ff73c0ac1dafcd96
SHA3 b3b19241cc6454389e45833e50b742ae1927a5f161017350a99f2cbc66914f26

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87228
MD5 342ad3fc8890c3e322fa5c9cea16b6fc
SHA1 b9f3b3e8f818601b3887ce5d611d511f4663613a
SHA256 a8d9dbff8670eb6b79b028eb3242433e9e9da289d816f86e7d2d5b661e74cc5e
SHA3 c783f4139d925ff3c102b8a8292dcd6af12cc809d76b1d7f3f1e354c39901220

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48825
MD5 6be4e1387d369cf86e68eacbdd0e81dd
SHA1 351970fe2681b9b35b5d59ad052011ed96a96e17
SHA256 85025c8556952f6a651c2468c8a0d58853b0ba482be9ad5cd3060f216540dfc0
SHA3 45e552e173141e06d113209b6cc915042ad0b4d5531464b8dbe5637029f489cb

205

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x100
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87985
MD5 8121841afe19a32ba08aa6ee8ae633f1
SHA1 f50d72b3863f3d65849bc7b8a85c1038dfcce859
SHA256 089e6abe6b7e194f43f8d36a068b4ba5e3112217043088592b371c5d89708d6c
SHA3 69fa08c1c1cad64652364536fdbc64dd87bfc44dee8d14df3e39dcf32162bdac

206

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12941
MD5 c16b08dfa3a7525464d2e2952bd37806
SHA1 4734dce252cba65b8f56fa1e8d3a5203ed81a79e
SHA256 499e4b981149851d28dd2dd0c9f5106deb13939568caeae625558721a61c1642
SHA3 e7d3991084295de0615cf1a31b4cfbbc63d87966cdd5038a668e01133bf19a13

211

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x60
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64136
MD5 86969b39fd9c7b78bccf1518d791a0df
SHA1 f54f0afdbf4d29666da3fb80b2e2d2ccdbbb82f5
SHA256 5c61adc8f8344dbaa38031f74c99816c9c833b7d4d036d00aa3ac17d1f46eccf
SHA3 1708eb8a8bdddefe0080b6541df4c2391550177ef97ad5fee5f567a5da5d53c6

305

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73942
MD5 abae527be44293e0a188879151cc5a20
SHA1 3b770af49624138072781fc9c0303c166d04eae9
SHA256 499bf86593c386a11511de4d919f58a343ea26d4897fc31fe3efe7e19ead81ae
SHA3 b70b8c2ca48176b558cfe97dd802817e925bddc1f956b35c07f450b8e0537820

306

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01048
MD5 e27ebf6762e99552aea6f1a7877cc738
SHA1 0b550db1e9416e8440ca080fe950f7421196e77c
SHA256 7ab3236260ca1c38a3d94a4dc6b90db51690c8c72baa908d5a7ddd834d435db3
SHA3 b8ddfe3fdb6dd592229a0c725c25d5e41ae53496f8068c8d68697191f246f7b7

311

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x58
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.76109
MD5 076eaa29cb0fd488dbf28132ba9053ce
SHA1 4ed7d9235080ca286344b50642c16cfe8bf1adda
SHA256 fb1541fab691418f4ba1d7881ee001103522cc5bc7e351b993c04cf0b4bc1385
SHA3 bfb755e23413508cb86824e402871098d7f3f998e137ff56be87aa36e045a57c

405

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.55952
MD5 42ffea438086bc96d67864e42e213d98
SHA1 5e388ef762ebb9fa076c6f46d718966eb6670f99
SHA256 dc6a29809f8a42a0c1dcb4fd797e8a467c980de166cc66a83a32192b2f53a1da
SHA3 a244963fa8137eb43b42900bd1d9a79a717373ad6adb98790040a9682ed77460

406

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82795
MD5 916138140d4f7a4c7eb9154fd19cf69b
SHA1 a1438202241ca82b79cf26a3290f0504e4776487
SHA256 957bfd5d7e56d54206473412dec1388fcc63d069b5bf1591329c5b7a14c37c1a
SHA3 143554d0fab54938c7d840ea33a1c782434b18fcba1a057cc67358e5ce787120

411

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.36476
MD5 a6e82d7b05a5b3f5961b64f1642a06ee
SHA1 12b290ffc5492d4ee7fcb2398411f5cd8e2f63fd
SHA256 e9c101b10de7cb49faad8c6cbc66a8c98b63d107c92fbd6160bf711149450786
SHA3 aa6c8ba15c0f1fd950ab322991aff62e650279e97a3f3c6b885148ed427c7059

505

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65896
MD5 98d883153a1e14132992b81a092bf62b
SHA1 376d6a0a41e9be87867c385cd863356e67d971de
SHA256 e3aa57e918a071442241e7c37c02556d35d02656b68150f906dcc836bd324217
SHA3 b810f2d3359a586b971fb26bb4f74d455495d4afc86d31563f34848030cd8d65

506

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92746
MD5 c59875269fdeef231fa68e660d25cd24
SHA1 284f7b3262e1e5d020261903d3e726ba4f8f62e8
SHA256 5ef03c55601452fd55173e5c809fc3b59181da0433e414a3cba02191f03d7d4c
SHA3 6417beeef3db1414f3022eed328210bda7c0d47de77240acedc317f561a2a816

511

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x50
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.63292
MD5 9fd86d0859f2cb45a303f2eccbb728ef
SHA1 e5ee9f452cb943e5c3b21783da7abf4a748d9ca2
SHA256 66c5a54fc613b3a72b0ce1651649944bfbef2d0c2068f2ecba821ed82188496c
SHA3 7fe952e87ecbbdf41b8934c0cd40f81161a5b312c4640e037bd47dca5b16717d

103

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.78418
Detected Filetype Icon file
MD5 b7c932aa82be75358446c90be7016829
SHA1 b1a4692b773f2a27714c8047e7e108f7b9974ec6
SHA256 72cd544523dfb69ea3b7c3f417f0633641a2aeb89aeb1604948555b46d426752
SHA3 868b011bbd632282246acb7c0c68cd1307889bb2b62394090c7bb3febbbf7f3a

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x53c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37907
MD5 bbfeeb32bf7c574aa2fe3592068c841f
SHA1 316ac171ae8c5058bb0f0337629a9b69b35a3732
SHA256 4f9df89064f4ab71b3a7b824b63b8515d4087916907cce4fefbf26904f30a460
SHA3 6e00ff7da9ca9112d2b278b717408ed4d071fbc1b835cea51c7095242195147d

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3bd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2266
MD5 88bcc530888c0d0b5552dd967d52393e
SHA1 d90928970280132a4aed5afbaf9fda980584bfc3
SHA256 64882145025814a4e15eeaaf4eb019b718d1d2c93a682a87e15d6c48762c0ae9
SHA3 41d8feb92cf7623b2638862adafcdfb68229dceaa607c804d69bd0e917182b8d

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 2.2.1.0
ProductVersion 2.2.1.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments A build of the PortableApps.com Launcher for Foxit Reader Portable, allowing it to be run from a removable drive. For additional details, visit PortableApps.com
CompanyName PortableApps.com
FileDescription Foxit Reader Portable (PortableApps.com Launcher)
FileVersion (#2) 2.2.1.0
InternalName PortableApps.com Launcher
LegalCopyright PortableApps.com
LegalTrademarks PortableApps.com is a Trademark of Rare Ideas, LLC.
OriginalFilename FoxitReaderPortable.exe
ProductName Foxit Reader Portable
ProductVersion (#2) 2.2.1.0
Resource LangID UNKNOWN

TLS Callbacks

Load Configuration

RICH Header

Errors

[!] Error: Could not read an IMAGE_BASE_RELOCATION! [*] Warning: Section .ndata has a size of 0!
<-- -->