a45a81ae12a248f299a0cbea732ee6338dd765e1f1156f58929f59ca3311ef97

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-May-22 12:17:58
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName xana研究室
FileDescription ZipFix JP Setup
FileVersion
LegalCopyright © 2026 xana研究室
OriginalFileName
ProductName ZipFix JP
ProductVersion 0.1.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 8.0
Info Interesting strings found in the binary: Contains domain names:
  • https://jrsoftware.org
  • jrsoftware.org
Info Cryptographic algorithms detected in the binary: Uses constants related to SHA256
Uses constants related to SHA512
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 9166234 bytes of data starting at offset 0xd6c00.
The overlay data has an entropy of 7.99997 and is possibly compressed or encrypted.
Overlay data amounts for 91.244% of the executable.
Malicious VirusTotal score: 4/70 (Scanned on 2026-10-11 15:04:59) APEX: Malicious
Cylance: Unsafe
Skyhigh: BehavesLike.Win32.ObfuscatedPoly.tc
VBA32: Trojan.Wacatac

Hashes

MD5 6e7bf929dc3a680674abfd20e38adeac 🔍
SHA1 89bb342ac1aa38c5cdc85b50a90270908951be84 🔍
SHA256 a45a81ae12a248f299a0cbea732ee6338dd765e1f1156f58929f59ca3311ef97 🔍
SHA3 af4de1daabf1c0c7191d2a5a976a32b62502f020385cbfc193b6c01903426500 🔍
SSDeep 196608:bvCBDB5st0oKXysQz2ZBGkiFmeADDVSkPHBkkLmU56ahVxNPPwNJ9/3:bqp4SpiRqZk7+4k515vPPwNJ9P 🔍
Imports Hash f5a88a72e4e02b464d0e185d6666dbe7 🔍

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 11
TimeDateStamp 2026-May-22 12:17:58
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xb1400
SizeOfInitializedData 0x25400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000B1E60 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xb3000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xe5000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 cbd2562218f4af87ebd2d427b1739b38 🔍
SHA1 477ca92c2a06cad5e179d11aa60441086afbdb8e 🔍
SHA256 d78d21bb76d0a9e42fe0e97355ccdbacb1eb71afc1db8ca1719323b3df582a32 🔍
SHA3 e0ffb027178cf42ed670c11a830b776678ec988be5558f661c7523ca94aac9e1 🔍
VirtualSize 0xaf80c
VirtualAddress 0x1000
SizeOfRawData 0xafa00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.38362

.itext

MD5 cf1af4b55684ed040ce1bbd7f61e0612 🔍
SHA1 af6a5c7a136572f0a4266cf3901ed9b2d717383a 🔍
SHA256 a01c87dd7c465d0284faabb9f3e7446455e686aed92b7cc650b069f745fdf5e9 🔍
SHA3 d1bfb3b0d34747ab0f21c092ca21b1b092c1b8a0d688e9a9514a6c800f0f4435 🔍
VirtualSize 0x18cc
VirtualAddress 0xb1000
SizeOfRawData 0x1a00
PointerToRawData 0xafe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.04225

.data

MD5 572b4d77ead34ac8988afd3cc57c4cef 🔍
SHA1 c4a373ded38cc27d8ea87f5dfab12654ba4fe45f 🔍
SHA256 5b07276392772754d8d1ecf8aa5c95fb19dfd9ba88a80d70b4feb98d1cab1456 🔍
SHA3 1bed3bb20db4ca8559bb3c2cca1803b90cc5ddf2833b75c033f73f071f7d0f9b 🔍
VirtualSize 0x3f3c
VirtualAddress 0xb3000
SizeOfRawData 0x4000
PointerToRawData 0xb1800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.18411

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x734c
VirtualAddress 0xb7000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 4a48c59cbaa4d331b6913c45047362ef 🔍
SHA1 8c5a78fa720cc93e9b5ab451be530c0c84425c99 🔍
SHA256 c2ec0144d84e181582727d377a1c4787841f218cde892c6410b2bf2aa5282e24 🔍
SHA3 e7a4d51c328d2ca4a380f8fc51f4ff3459b370e320b1ec364aec5b0fe79d3a42 🔍
VirtualSize 0x1068
VirtualAddress 0xbf000
SizeOfRawData 0x1200
PointerToRawData 0xb5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.82301

.didata

MD5 f4dcdcd030805001df20b0fdd6c46cb2 🔍
SHA1 ac47351a0f50c3ae9ce8e7fa8400b7bca5bf384e 🔍
SHA256 765efef8ba3c2190fa77d62cbd7680c9edff090998e151fd42538ecf6301dc58 🔍
SHA3 49e9435be9c72e87a457614ddacc3f661087a1a645c02b87cafce95bada22156 🔍
VirtualSize 0x1a4
VirtualAddress 0xc1000
SizeOfRawData 0x200
PointerToRawData 0xb6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.76418

.edata

MD5 962159c3600d79cc1a32bd757eb6ad75 🔍
SHA1 12791257f253a68866a2bb98c0246c2742bc5400 🔍
SHA256 70e6c5912a8eaed543dfce36ee14f14061932f12455c1ef4f394238ee0f7e3d1 🔍
SHA3 a7a5e30935f7889977319db4443bf73b7eb9b0948d91c051bc203b1ed7e375a8 🔍
VirtualSize 0x71
VirtualAddress 0xc2000
SizeOfRawData 0x200
PointerToRawData 0xb6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.33502

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x18
VirtualAddress 0xc3000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 4077d1dbe397a22f8d8c62a9ac2f87a2 🔍
SHA1 08fb7c36e037736171d75dff700936dd50e1e966 🔍
SHA256 f8bc31927074957901bc7975eec99aa54e759a66cbe2ca8bbbb16a2705caeedc 🔍
SHA3 1981e561224a7385c57d6d862c53ea310e35d45aa22680f9fefc822eb03d448c 🔍
VirtualSize 0x5d
VirtualAddress 0xc4000
SizeOfRawData 0x200
PointerToRawData 0xb6e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.38146

.reloc

MD5 aa09d180bcb91ff38898ab2932fb8c55 🔍
SHA1 e97b93417956f4e6813d6d419b8a2856b357509b 🔍
SHA256 f6b86339ea9e79135202d66903e14a64c88b3d9ba3f0c7a6cb124412d44e637b 🔍
SHA3 15f759eb5f9d3a631ebefb8bad9ca1a10a1ba44ad659e75be02a5d910ff023d6 🔍
VirtualSize 0x11fec
VirtualAddress 0xc5000
SizeOfRawData 0x12000
PointerToRawData 0xb7000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.70174

.rsrc

MD5 aed24c30f99b65a233c1476d5efe2baf 🔍
SHA1 c9c3c6ccc01172bbf9007cf63c83c9d6f097068a 🔍
SHA256 ed7ee7475416f6f0273776ab63f8a27d393dc40268a4231358fd655c649611dc 🔍
SHA3 202550c43ce787cc2ae894453d41773b67d2889366887ba14f2e5051689518ba 🔍
VirtualSize 0xdba0
VirtualAddress 0xd7000
SizeOfRawData 0xdc00
PointerToRawData 0xc9000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.44642

Imports

kernel32.dll GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
CompareStringOrdinal
RtlUnwind
SetFilePointerEx
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
GetFileSizeEx
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
LoadResource
SuspendThread
GetTickCount
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
GetTempPathW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
SetEndOfFile
QueryPerformanceCounter
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxW
DestroyWindow
CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SafeArrayPutElement
VariantInit
VariantClear
SysFreeString
SafeArrayAccessData
SysReAllocStringLen
SafeArrayCreate
SafeArrayGetElement
SysAllocStringLen
SafeArrayUnaccessData
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetUBound
SafeArrayGetLBound
VariantChangeType
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenThreadToken
AdjustTokenPrivileges
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
FreeSid
AllocateAndInitializeSid
EqualSid
RegQueryValueExW
GetTokenInformation
ConvertSidToStringSidW
RegCloseKey
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
CompareStringOrdinal
RtlUnwind
SetFilePointerEx
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
GetFileSizeEx
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
LoadResource
SuspendThread
GetTickCount
GetStartupInfoW
GetFileAttributesW
GetCurrentDirectoryW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
GetTempPathW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
SetEndOfFile
QueryPerformanceCounter
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xc1080
DelayImportAddressTable 0xc1090
DelayImportNameTable 0xc10b4
BoundDelayImportTable 0xc10d8
UnloadDelayImportTable 0xc10f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xba63c

__dbk_fcall_wrapper

Ordinal 2
Address 0xe578

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x315
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.66526
Detected Filetype PNG graphic file
MD5 9dd998b98e53404c5df8cc19f0b0d77a 🔍
SHA1 2900ef3516723f783aa2dd8ab7afb5b68ac8c3c6 🔍
SHA256 f53639a57e9b822a3c85c942eb7531ebf29037b54a767972f3244c562b7e16ef 🔍
SHA3 b710172ef2f7d4906f6ad818a15dd7e82fd13375ceba4bc63d1aee43d7738102 🔍

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x538
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.81216
Detected Filetype PNG graphic file
MD5 8e49f1a4f660f280b1ebcd61965ecf6f 🔍
SHA1 26cde2f311708113dc39e540a469bc2e7145b78c 🔍
SHA256 7d9e4e4b0d18f699c51f0b9637faa20e74430db49536631d6e6938af7fd68902 🔍
SHA3 00c22543f237d185f344c9f04fd8d3126619c2b649719bba686bdbaa89c32b67 🔍

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x73d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87227
Detected Filetype PNG graphic file
MD5 ba9adcf8c005ceca03b16abb9795965a 🔍
SHA1 c190490314b78a7e591ee450e7fd9e11ae96170f 🔍
SHA256 d033bc92db2b5295705ce1d1ea60d0d36c6ece0c65211655da279d704d45d5d0 🔍
SHA3 616be200c4c23e120340d83879361a55a32dc56023dd1f67d19d714cdeb43228 🔍

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xdac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93315
Detected Filetype PNG graphic file
MD5 8ba7e2e060f3ae2623bd07e117e77d1c 🔍
SHA1 7155131f5ef0f9cf2fd9fe6554efc29329194d74 🔍
SHA256 f96ec588895fec5c9054cabc6b8be6716bd15eb14f92f20279cd29439d8a208e 🔍
SHA3 788394bb762c167c3bef70c2d4f43264776c365b6e1c05e63083b4eae1d72153 🔍

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1266
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.95022
Detected Filetype PNG graphic file
MD5 c551245e2fd08d45fcf519a81579f6ba 🔍
SHA1 b14a9f632359d914cb974a34f3e7f30f5e664f11 🔍
SHA256 9ad1ae9eec893e304d8834500a4ae384289a94d8088297ade7594f0e81fcf906 🔍
SHA3 258488ff5b02122f49104883d6a296ecb006c865cdaf04d98735451d6da9a31e 🔍

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2704
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97408
Detected Filetype PNG graphic file
MD5 7915175d3a0b65213e400dc4dbba92c9 🔍
SHA1 9665abd760054f54abb213553a0f87884618fe3c 🔍
SHA256 84f050e3c2212a6e5681236b0cfa66612f713215ed6c6353dba882f1dd1d10e6 🔍
SHA3 bcc925dbe6fb96a497cdeb026557279835647667ab96d2df87eae128cc1371ca 🔍

106

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4aa6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97463
Detected Filetype PNG graphic file
MD5 d3b14dc43f870986f83f0758c444a876 🔍
SHA1 88adfaa408e0bf2f19d22befdd70a131b009eb3b 🔍
SHA256 97040cd41c7777fc04d6b25b90027056c818405cd72d133d52e18d2d23236b59 🔍
SHA3 356b7b50f1183dcc581bd7c0bd5d64b7e5eb0a8c097a708e8a5405ed6fef2d56 🔍

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x24c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11364
MD5 bfdeec9b9c10f5470a9b6f2b15ae368d 🔍
SHA1 e2f1e0f6fc1d4586803b19cb384bfe0f4edc81f4 🔍
SHA256 9a932d990ffa1c05ffff03182707adaf9b0c6c13c3a9d09019cfb606c060c46f 🔍
SHA3 c1d8379e018b7922875978f62f488fce6aceadbfe2ded0b50db83877632233dc 🔍

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32885
MD5 f96fdce1c116135874fb82281b493ac0 🔍
SHA1 562daa783cc168f8e46b1a798879583176af22cc 🔍
SHA256 3ab3b2c63dc1c1810fca5518c1bb174be9ebf36547ed1feae9e357ccf8bc3ef1 🔍
SHA3 05d0914dffa4501268059355b689944d50e9aa4a986777d770f0e713d1a8d59c 🔍

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51239
MD5 7ee56b85a64cd12875800e5eb0f8a8cc 🔍
SHA1 aedd1bec33089176851004b6593393629eb0fa6f 🔍
SHA256 dc6b3544e2299b1708bb325f9eecdb6d3a7c96755eab1d83ea51fc8b5102715c 🔍
SHA3 5b5c207556b66f9b50ed909ae8d9a80068adcd483f406df26c87f8151450bc20 🔍

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24302
MD5 44f76d42ead76c495e69824f453e64ec 🔍
SHA1 3fb0774ab962aa9cc511af9e8836164c477b9d9e 🔍
SHA256 98ffaee3d049334960e4f4bac5dd69ae5ea0e8a8f154a71ce30230508692db8d 🔍
SHA3 cbb48eb071e2f28c8b7c315c9192c0a8de0a4c75bcc188e12c72e8bad4b3230e 🔍

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34822
MD5 ba10a3e64b7ee79204e6728702cebcf5 🔍
SHA1 7c7298de979e3bb2f128be40f110a376be3350fc 🔍
SHA256 c0dce66eaf68d1a945a6c5ec96a54baeb9bf8ff533392a1c1d66cc0ac4f7e3fd 🔍
SHA3 3bce8f10959f4d33092d14e38f0d70b276193106f38f6066c66fdec4f62571ba 🔍

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb 🔍
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd 🔍
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97 🔍
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7 🔍

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af 🔍
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b 🔍
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654 🔍
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c 🔍

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a 🔍
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d 🔍
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46 🔍
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967 🔍

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32419
MD5 91f002a78decfcd89251e544aa2d1825 🔍
SHA1 20d0672f8144b8f614127b2bc03f4b447b823a7a 🔍
SHA256 5eb28cbb468ee711930c5100d15732fee3066a1b49d989207611a66ec2fbee1e 🔍
SHA3 206eb7f338ff610b7c3aed4b945f089c0d66e6e64e1c857552a91d8021a1127b 🔍

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45 🔍
SHA1 30704560832bafa440df1fd20693653c2a30f815 🔍
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12 🔍
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6 🔍

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443 🔍
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2 🔍
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445 🔍
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627 🔍

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48 🔍
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920 🔍
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae 🔍
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56 🔍

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8 🔍
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b 🔍
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610 🔍
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb 🔍

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x490
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.23345
MD5 c61832360a56f86ecd590fbf994e6fbc 🔍
SHA1 65a2b990dbc551553ffac59f8daf0887a94ed1ec 🔍
SHA256 26d0d87ff8246c5685cb81279d76592cb6f8699ebcec378e1dd2d48a23946c55 🔍
SHA3 649a1230f6fee999aef6681f468921101c9d59db4c6ec369525fc40a17cabd15 🔍

11111

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x40
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.59435
MD5 b5bf6fa01a8763a455fe36262e6f32d1 🔍
SHA1 677ac8793c9dabc204ceaee58891fab0cf35472c 🔍
SHA256 6e20d1e86794f58b46060286abdfd95708f17aff8cadbac1cdc4c40160e6a9cf 🔍
SHA3 11b564ceff46d433080aaee22ce523d462216944158a55415807479851ee08d0 🔍

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.74189
Detected Filetype Icon file
MD5 286c53b1d31cd9bebe7a321333a0448a 🔍
SHA1 3b5408794eaefa8b0d9c19af0d949758e49ae176 🔍
SHA256 280a8783e058e0a26ced9701cd54fdc81daa68c50509f3cf919d77279a84b48d 🔍
SHA3 a3a00de64f7378e1c55fe4271c5d922d5d511d2043d2c61babc30a956890c96c 🔍

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.59946
MD5 ac0b5f3fc2738f7ad4fb2ea04063bea4 🔍
SHA1 82c2de254decb19330850b6664d29c323c118cc8 🔍
SHA256 2f445fbde2de3c1da2793a9a08154ca85b0607daf46eb9227228be9ec2c73420 🔍
SHA3 e7c0e21c618195376ed80e568bd5363a440cc4ed01e4d7ea0d8f6b5b6d076fba 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89085
MD5 e07ab8c9030f776ce0f6d9040d41c616 🔍
SHA1 593953973c74066bcd09b22402948425dab9b12f 🔍
SHA256 75bb01fe4bafdef22d879aaea5b85d1165a30ec0e558536e1b4c6002c4730d5d 🔍
SHA3 51b78d43db0954fcaa7c6fd2558eece5eb98a1c5f6e95a3033891777bfd00a7c 🔍

String Table contents

No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
SHA2: Cannot update a finalized hash
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server 2022
Windows 8
Windows 8.1
Windows 10
Windows 11
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Property '%s' is read-only
Property '%s' is write-only
RTTI objects cannot be manually destroyed by application code
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Error reading %s%s%s: %s
Stream read error
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Invalid argument
Source and Destination arrays must not be the same
SpinCount out of range. Must be between 0 and %d
Argument out of range
Duplicates not allowed
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
. %s range is 0..%d
. %s is empty
Out of memory while expanding memory stream
%s has not been registered as a COM class
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s' (offset %x). %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName xana研究室
FileDescription ZipFix JP Setup
FileVersion (#2)
LegalCopyright © 2026 xana研究室
OriginalFileName
ProductName ZipFix JP
ProductVersion (#2) 0.1.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4c3000
EndAddressOfRawData 0x4c3018
AddressOfIndex 0x4b3c14
AddressOfCallbacks 0x4c4010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.