a79445103abf7d91bafb2dca89d07926

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-Nov-26 10:19:52
Detected languages English - United States
CompanyName Clickteam
FileDescription Clickteam Fusion Stand Alone Application
FileVersion 3.0.283.5
InternalName StdRt.exe
LegalCopyright Copyright © 1996-2014 Clickteam
OriginalFilename StdRt.exe

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • LoadLibraryW
  • GetProcAddress
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetAsyncKeyState
  • CallNextHookEx
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The file contains overlay data. 8312918 bytes of data starting at offset 0xf8600.
The overlay data has an entropy of 7.98455 and is possibly compressed or encrypted.
Overlay data amounts for 89.0963% of the executable.
Malicious VirusTotal score: 9/70 (Scanned on 2019-02-20 02:57:13) Cylance: Unsafe
Rising: Malware.Obscure/Heur!1.A89E (CLASSIC)
McAfee-GW-Edition: BehavesLike.Win32.Dropper.rc
Trapmine: malicious.moderate.ml.score
Jiangmin: Trojan.Generic.bvzww
Microsoft: PUA:Win32/Presenoker
McAfee: Artemis!A79445103ABF
VBA32: BScope.Trojan.Downloader
Paloalto: generic.ml

Hashes

MD5 a79445103abf7d91bafb2dca89d07926
SHA1 ad12120ea9e3b6ae6ba9d2168ec80a8905929f58
SHA256 729781c7545947c3613596f41e6c134b2c6e71c0211e2f2de60ba78451915f5d
SHA3 654d9519bd04a3abfdc87403a7aea75c6e38907efe3dfabb1650d850951b8c76
SSDeep 196608:JGPFyDDwRv5DFUhA7gHeUEn/qhSpQtfygOogk8pmitNXrd/:oPFyDDwRvl6hb+eSil4XZ
Imports Hash d641eb4f03c12649b9fd5b492a38f6f8

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2014-Nov-26 10:19:52
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0x7f600
SizeOfInitializedData 0x7b000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0006E1B5 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x81000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0xfd000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9a816e778f997d89d144d49c8d20d271
SHA1 2794d3c69ccb9496acc3d6dcea29a93ad451e4dd
SHA256 e747ab704e2d9ec8fb0698ad87b9c5c2dc75c3561d259ddbc91a3d97d589730f
SHA3 e755c6e5f3c2df12f5ef88c7576c5acb5b0ad5faff9b08efd9b3420e302b9d6e
VirtualSize 0x7f4eb
VirtualAddress 0x1000
SizeOfRawData 0x7f600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.51248

.rdata

MD5 536efe48f9df8defe2195cf4ae9cfb63
SHA1 3f047a57352cb6df4aaf5434313ea8a7a4603ca5
SHA256 6796d9603f3ac8acf01909880fdb72c74acb7ce6a4ed421bb2e02cb598c599af
SHA3 c3336d327a893bb513d6b3a1b45ff18d55dcdc4b0fffaf24ecdd15b1f481aa95
VirtualSize 0x20584
VirtualAddress 0x81000
SizeOfRawData 0x20600
PointerToRawData 0x7fa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.36742

.data

MD5 8bf81d57dac98c67a42524544e7cee5a
SHA1 33c0b54ea1e923d7a4459598256ef59ce762db1a
SHA256 29170e097399ccd05d35f8f68aa13c1a57ce13ee3229134f2087a4dc308fd348
SHA3 91a49ef373626b8ad1b4d1c2ea1cac3a365b87164802d1b312bce9dadc483730
VirtualSize 0x7d10
VirtualAddress 0xa2000
SizeOfRawData 0x5a00
PointerToRawData 0xa0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.70475

.rsrc

MD5 bfcefae268135f31bf0bd0f12f36ae92
SHA1 42b8e50606fb129340a2fd6649087f36123c1f37
SHA256 748a8ce924636f225528bc29a032083be0c264fb04ce08dff6f909b68e4e87f2
SHA3 5e6afdd967b87b16d7a771bd27428b17ff244cbb52cb7a55d5aa4983b6bc7e0f
VirtualSize 0x49e78
VirtualAddress 0xaa000
SizeOfRawData 0x4a000
PointerToRawData 0xa5a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.8187

.reloc

MD5 74964c6991449ea5cbd370fb49ebaee3
SHA1 2278bd93733ccc6296faf90c2039eef99bbf8523
SHA256 a52a388049f78567b4e460ac0655fde65d3c3d400e647b836fb07f1ac45c6699
SHA3 cb26f47f2a0b8377dba823cb9e71144473e942c3759d2a275eff9b029ae2ec87
VirtualSize 0x8bd0
VirtualAddress 0xf4000
SizeOfRawData 0x8c00
PointerToRawData 0xefa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.12326

Imports

COMCTL32.dll #17
WINMM.dll joyGetDevCapsW
timeEndPeriod
timeBeginPeriod
timeGetTime
joyGetPosEx
KERNEL32.dll GetVersionExW
GlobalDeleteAtom
GlobalAddAtomW
GetModuleHandleW
lstrlenW
GetLocaleInfoA
LockResource
VirtualProtect
VirtualQuery
SetLastError
LoadResource
SizeofResource
FindResourceA
FindResourceW
IsBadReadPtr
IsBadWritePtr
SetFilePointerEx
OutputDebugStringW
LoadLibraryExW
GetConsoleMode
GetConsoleCP
LeaveCriticalSection
EnterCriticalSection
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetSystemTimeAsFileTime
GetCurrentProcessId
QueryPerformanceCounter
GetModuleFileNameA
DeleteCriticalSection
GetTempFileNameW
GetStringTypeW
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
InterlockedIncrement
GetStartupInfoW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
TerminateProcess
GetCurrentProcess
InitializeCriticalSectionAndSpinCount
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetStdHandle
GetModuleHandleExW
ExitProcess
InterlockedDecrement
GetProcessHeap
GetCommandLineA
HeapCompact
HeapSize
SetEnvironmentVariableW
RtlUnwind
DeleteFileW
HeapReAlloc
IsProcessorFeaturePresent
IsDebuggerPresent
DecodePointer
EncodePointer
HeapAlloc
HeapFree
LoadLibraryExA
InterlockedExchange
RaiseException
GetVersion
GlobalFree
FindNextFileW
FindFirstFileW
GetCurrentDirectoryW
GetTempPathW
FileTimeToSystemTime
FileTimeToLocalFileTime
GetSystemTime
FindClose
SetErrorMode
WideCharToMultiByte
GetCommandLineW
GetExitCodeProcess
GlobalUnlock
GlobalLock
GlobalAlloc
CreateFileW
CreateDirectoryW
SetCurrentDirectoryW
CloseHandle
SetFilePointer
ReadFile
WriteFile
Sleep
GetLastError
MultiByteToWideChar
RemoveDirectoryW
GetModuleFileNameW
LoadLibraryW
GetCurrentThreadId
GetProcAddress
FreeLibrary
LCMapStringW
SetStdHandle
WriteConsoleW
FlushFileBuffers
GetFileType
USER32.dll ModifyMenuW
DrawTextW
GetTabbedTextExtentW
BeginPaint
EndPaint
GetUpdateRect
FillRect
PtInRect
DefMDIChildProcW
SystemParametersInfoW
IntersectRect
DrawFocusRect
InvertRect
SetRect
CreateDialogParamA
CreateDialogParamW
CreateDialogIndirectParamA
CreateDialogIndirectParamW
DialogBoxParamA
DialogBoxIndirectParamA
DialogBoxIndirectParamW
LoadMenuA
LoadMenuW
LoadStringA
SetLastErrorEx
GetMenuStringW
LoadMenuIndirectW
GetInputState
MapVirtualKeyW
SendDlgItemMessageW
GetDlgItemTextW
SetDlgItemTextW
GetMenuItemCount
EndDialog
GetWindowPlacement
PostQuitMessage
DrawEdge
GetKeyboardLayout
RemovePropW
SetPropW
GetFocus
IsIconic
CallWindowProcW
UnionRect
GetPropW
SetScrollRange
SetScrollPos
DestroyWindow
CreateWindowExW
GetParent
GetMonitorInfoW
MonitorFromWindow
LoadStringW
LoadImageW
LoadIconW
GetWindow
GetTopWindow
GetClassNameW
GetDesktopWindow
SetWindowLongW
GetSysColor
MessageBoxW
RedrawWindow
UpdateWindow
GetSystemMetrics
GetMenuItemID
DestroyMenu
DrawMenuBar
GetDlgItem
SetFocus
DialogBoxParamW
EndDeferWindowPos
DeferWindowPos
BeginDeferWindowPos
RegisterClassExW
RegisterClassW
OemToCharA
GetAsyncKeyState
GetActiveWindow
ShowCursor
GetWindowRect
ReleaseCapture
SetCapture
GetKeyState
GetWindowLongW
MapWindowPoints
AdjustWindowRectEx
GetClientRect
SetWindowTextW
LockWindowUpdate
IsZoomed
IsWindowVisible
SetWindowPos
SendMessageW
IsDialogMessageW
SetTimer
InvalidateRect
EnableMenuItem
CheckMenuItem
GetMenu
IsClipboardFormatAvailable
EmptyClipboard
GetClipboardData
SetClipboardData
CloseClipboard
OpenClipboard
ShowWindow
PostMessageW
wsprintfW
ScreenToClient
ClientToScreen
GetCursorPos
SetCursorPos
GetKeyboardState
CopyRect
TranslateMDISysAccel
CreateIconIndirect
DestroyIcon
CallNextHookEx
UnhookWindowsHookEx
SetWindowsHookExW
ReleaseDC
GetDC
DeleteMenu
GetSubMenu
GetMenuState
KillTimer
MsgWaitForMultipleObjects
PeekMessageW
DispatchMessageW
TranslateMessage
GetMessageW
SetWindowPlacement
GDI32.dll SetDIBits
GetDeviceCaps
RealizePalette
SelectPalette
CreateFontIndirectW
GetObjectW
CreatePen
CreateRectRgn
CreateSolidBrush
ExcludeClipRect
GetClipRgn
GetStockObject
LineTo
Rectangle
SelectClipRgn
DeleteObject
SetBkMode
SetTextColor
MoveToEx
GetTextExtentPointW
CreateHatchBrush
GetCharWidthW
GetNearestPaletteIndex
SetBkColor
SetPolyFillMode
SetROP2
SetTextAlign
GetTextMetricsW
TextOutW
DPtoLP
LPtoDP
Polygon
CreatePalette
CreateCompatibleBitmap
SelectObject
CreateBitmap
COMDLG32.dll GetSaveFileNameW
GetOpenFileNameW
SHELL32.dll DragQueryFileW
DragAcceptFiles
ShellExecuteExW
MMFS2.dll (delay-loaded) #43
#74
#81
#187
#83
#82
#78
#76
#79
#80
#979
#97
#65
#64
#66
#255
#281
#570
#333
#688
#3
#19
#31
#121
#120
#192
#831
#425
#423
#430
#431
#419
#1033
#172
#286
#249
#276
#366
#253
#279
#370
#764
#765
#176
#1068
#1072
#168
#153
#50
#34
#411
#766
#47
#786
#77
#95
#94
#98
#91
#70
#101
#102
#103
#105
#106
#107
#169
#170
#264
#494
#554
#876
#1048
#1036
#981
#564
#517
#536
#433
#422
#1031
#1049
#686
#280
#478
#468
#11
#67
#62
#51
#63
#17
#16
#124
#125
#832
#959
#945
#32
#173
#174
#372
#610
#493
#355
#585
#520
#487
#341
#417
#342
#344
#343
#849
#448
#756
#445
#443
#703
#701
#742
#361
#753
#571
#587
#1000
#982
#568
#123
#59
#60
#61
#1077
#195
#196
#198
#199
#191
#201
#184
#204
#205
#203
#811
#810
#803
#802
#809
#807
#814
#812
#800
#798
#806
#804
#797
#799
#808
#801
#805
#813
#1071
#826
#827
#828
#829
#830
#755
#795
#1054
#389
#69
#6
#7
#175
#177
#162
#158
#163
#825
#185
#186
#183
#189
#1069
#1073
#254
#785
#722
#228
#328
#467
#9
#42
#155
#171
#75
#84
#90
#92
#73
#71
#104
#789
#790
#111
#114
#113
#108
#110
#109
#115
#117
#116
#46
#245
#274
#363
#713
#241
#272
#645
#356
#584
#519
#234
#268
#232
#267
#236
#269
#573
#620
#762
#476
#972
#412
#414
#677
#611
#413
#416
#415
#678
#681
#680
#612
#691
#739
#137
#834
#837
#1010
#1008
#997
#996
#998
#1011
#859
#976
#878
#882
#985
#893
#894
#895
#986
#896
#974
#991
#913
#994
#929
#1006
#948
#953
#954
#1007
#975
#1080
#14
#18
#35
#794
#1053
#984
#1037
#819
#820
#68
#28
#30
#118
#122
#484
#682
#2
#5
#4
#1070
#23
#57
#58
#373
#740
#546
#418
#750
#695
#1055
#27
#29
#39
#1081
#1029
#72

Delayed Imports

Attributes 0x1
Name MMFS2.dll
ModuleHandle 0xa7e68
DelayImportAddressTable 0xa74d0
DelayImportNameTable 0x9f2dc
BoundDelayImportTable 0x9f7d0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.87607
MD5 28c7927f8b3eddd86f41266f37ece17c
SHA1 599722991f4af95927d4d93770f1db3ade03ff9b
SHA256 da5fd2892e50f82ff160d5ef24379b170881d8d6848d5a0e25124e72139bd02f
SHA3 4ba6e74bc00229c297a41aa9dbc1104eaac6887bf3c5fe177614dd0be7b86f68

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.11862
MD5 b627194ea0093fd8538d7b29c18c6f04
SHA1 24ad329618818d236680da0d3e88673e8b057cac
SHA256 13bc8b95364397e823b39f4700c255bef57bbc0ce50abce065f46ebbbd56267d
SHA3 b240cafd1319bd30d91cec6de2368a5e7728cc28e23626254ee8dfab8252f12d

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.4494
MD5 d92ffd946fe1374db5695f4ecb909cde
SHA1 dc686a2d79e1b2bcf74be2c3b505a4a037fb541d
SHA256 3d9dbcb474d2276be9d7402bd4b9043597ee9d9b94d24d6c246c23be1bc11508
SHA3 8dca1958be34798b1d83a17c6fad4313698354a922752e521451ddb7a134fe01

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.35641
MD5 1edb9a506680c20822f7eb6343162d7d
SHA1 aeb117b781f87d2861effbd397bf33e8b6a88e44
SHA256 20fcb5f2b1d149c618cb7f347fa44c95db546e2d6cbb6e7fe03b69ed2dc40617
SHA3 4e1a4fcb023a635974423316c4d2a78b0fecddbd8f83bb2c3fabe796f181fe8d

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8559
MD5 fd12f72b04b64b177106ae7bfc5e0cc2
SHA1 d732265b8b463f34aea44fd559b8fb955c2bc7a3
SHA256 e079c323b8c53c2d8dc49c31f8f773ed2cab147a1d7ac648adba5a41b578c242
SHA3 a237f3fd6c17f0317d2160b392e5fcebd273fffbb754c40f49994541b0d7a376

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2482
MD5 428f90287fabd58696d1d57130a326aa
SHA1 88af0e231f082777540cc36dec79dbc138c4a3fd
SHA256 d43a907f90ce88d2976ec25e4d5a14669450a60096a65264b909a0d07f8b3f3c
SHA3 06a8af160778e706fc03fcfa02956b92c613c96358cd58cc595a5580070b4af0

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.54007
MD5 7c4faa499326ef025d169643c0926d2e
SHA1 3acf399d38012d6ff0d32eab805331e12a409e19
SHA256 6bb6f990482b8ff42dfd9781391c1b17072cc5ecfae899f7c20c82a36cad0015
SHA3 1febdcdfa6d05dbb4ca172a6eba9d6b9d38e9096a46cad60347784c40e913c36

8

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65016
MD5 6782642f42715188acbc6d01dac0e325
SHA1 2b0fd12894f719ca9c44a392139274802b58c908
SHA256 2212a1644d626d2a9c1b603d67cab94fef4e5b67b3bafbe343f8e6c5893b22f6
SHA3 035002b75015a3b0b2a3e9c68d4c75753acdf0d418aa077e78e61846de9ef958

9

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.69131
MD5 56b1238dc7de7a673e088af5b59e6f3b
SHA1 e12fe749eddf43a6f669088644463760c8ffe2d9
SHA256 114f2aa7cdc8632c0b4ded43b32c43a0046dd045ff0a5b83df4906ed06261ac1
SHA3 4744739ada41edb000b7e0c769e401da00afcd675b8d1cb24ec143eb4e4457d5

10

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85402
MD5 d65e0d1e515233affd8310d68768e64a
SHA1 96ccc2fb6e1279bf45fe728193e5827195c45605
SHA256 9ecfe9ba84499cf16976cd51ef5d157233323af29c4de732675be0020c1370d0
SHA3 fdbd2e786f3b26aabcd2c95b1d3d6d5a429014f36efba1e7561559718cfb9628

700

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x72
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16984
MD5 1c978effa5e126d2e952836d4233ec49
SHA1 932e970505fe597bf790eeb8e05573124f6dcf17
SHA256 2a791416c3db74cc78f93a6362848fc45a205bd85acb367a7a1c7bea617c161a
SHA3 54d1b6d2d5e05760dee04c33f1254732b3a5cf0c1eda2d86cd1142271eb881d6

701

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x322
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18215
MD5 c6faa1175dddd3a6a03328c9797012ab
SHA1 9cb62752d1882ff99cf2188529bf6cacb58780a9
SHA256 b719ff52bf975f4b4fd709c07b525bafdc388fb44e87ca1d1fc6eb2f284d93c5
SHA3 e7a457de2f1715b8194cbaa406c6bf74f86673c45ec771215992507f37e63636

702

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x44
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.58858
MD5 ce04779c07f942dad8af2dc5574860bd
SHA1 30ed8fa5b592c3c1f20cc7b867b28842cf912db6
SHA256 98ba3a2076b30d208cb4581d49ad49170a9b4b742bcd7f0158994ae1620609d2
SHA3 0f9b397c6b5daca1604159785953aeefe66846567aba2c0cbb6b2727a8f3b3f9

703

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13521
MD5 e711c6d2a34afc7fd85ca790c0f3d6e2
SHA1 d4c8718c53bb3b8e64c4b359320f95436a5dba88
SHA256 ff74074fa53bfe627e8b2f69497257bfb55a78d9817bb4e73a9503c01ef158b8
SHA3 cdbc184ac675ed8b2f4cc35634aeca8c8f44aee9cfc08aa851da984e4c0dbc7b

704

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x242
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27571
MD5 1a25fb2122ff6998b2d271a7b9f59409
SHA1 281545b19a5c2bd79ca06cb0f49f52b638a8ab03
SHA256 1adfa6830dbeb9c0a5fbbcfe73d2431202cc76727c9342222ac30d37129e1621
SHA3 a51ca6b61ba6381f05b875794c2dea88b3ca1184c4c3d650cf3abf970f8933b8

705

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xc2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10029
MD5 2c8dae3f2ebee11656424bbdd09aa3f1
SHA1 fef7cf598624755c622bf314dda3fd424f73a9b0
SHA256 b0818ed82b064a204a8fdfc9073c44d7a94567fe7f964de2636e14a8f5a29744
SHA3 2a88d48cf06a4acaa96aa1b4702fe95e8198cccb1919d9a001ac6690dbc64018

1 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x1e2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14519
MD5 3ff959ef91f3c55c9f1119778fbea2bb
SHA1 5615da34f8b2eaba2ca10848d7f3ca9afd4fcfab
SHA256 23ba722192ac40a5039731f03c056946b69e3bdc15af1fe18d5541ebc11daf62
SHA3 3ac43d9d0de35211f8278d63a6913508c9ef18d139b213321946d049a5c1ac5a

2 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x278
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11186
MD5 33e8240b109a790e9bbc46792613413b
SHA1 edff04d3de82d4babf4ecc5a3f82398dc52355d8
SHA256 b5bb73243c6dc9da75abe39185bcf00a4d6ba578d949d75145b97e6e3c80d80b
SHA3 994fc53673c985eafb69c01d44d8462d070a0d340e8e54d9f31048254d95edd1

7 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x144
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.53307
MD5 bc2661f0faad769fffc33aae5f3652c8
SHA1 9951563713cdbf84d240ae77ec7a74036b0c7862
SHA256 3c8b9116d953ccddc9d4138a2e087f69abdad85015b34de9d6db923222949624
SHA3 168f7dfdb45037c156c332ba9b3d55fc241812a9c67172977b0f7ad96a15e8c9

8 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43545
MD5 880e75819c4fa31d7ad496fd4151534c
SHA1 43ba921b2f22d5c8035499f803db316fb255e7ac
SHA256 b3e0e114380cc4b2adc008da6be8e0f36a73a64ca32259e8e56ce31b1997543c
SHA3 09b16f8e5c2772afcd44ca05c14a0e555e525995d528b78f1f73617cb7b14750

9 (#2)

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2f2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10268
MD5 85ffc151a140eaa4b12f953d82ec786e
SHA1 5878d9d96978cd0a34d4452eb8800ea2c3b4a75c
SHA256 c73f5e14a595dfede62ac2edbf2258574a0b0e746624a7fa33f966ad866b5a1d
SHA3 915d32e48833778e30343362d670e57b2de7bb07fe8f8fba4848a37c6fae1726

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x92
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.88162
Detected Filetype Icon file
MD5 f31e83f3983ae6f10ef166a7a686c680
SHA1 54a844e25e8e2d64e6433dddffd8aeabf71fee22
SHA256 aebb98855fa8fc3adb0efcf4888a7354e50ed0e47688f6b6ad5e18a1db6399b7
SHA3 0073688807fe663926033471fd618b74f20dbd650604fbf8289887fb22248950

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41185
MD5 33a6882327ae3649c6583e20cc61ea54
SHA1 e8bfd57905017cb881c2316142768625b493aa3e
SHA256 55975bc132c7346ef5731ad0605f801ffb8c00917495fcc84d092646d14ce7bb
SHA3 f0907c99ff8f927b8dda27cbfafcaeade25dd483fa0a52bcf981a20b590300b4

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x30f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1507
MD5 33b411279f3512677863e64e039c835f
SHA1 2789b7f646cb28c6e28c759ebe89e056230b910b
SHA256 d9978defaff0d56f25f4912612b96cfdd1049e3e6ceb5c8b6048f303cff41e14
SHA3 5f3696a7d224bfb3d1d8f9383bd66904f2adbf0783aeea02dcaae09f851cd28e

String Table contents

Window initialization error.
Application initialization error.
Error while opening file.
Not enough memory!
File error!
Cannot find %s!
There is not enough available space in the temporary drive. Free some disk space and try again.
This application has been built with an incompatible version of Multimedia Fusion or The Games Factory.
This is not an application file!
Cannot load %s. This object might need an external program or library not yet installed.
Joystick not connected or driver not installed.
Cannot initialize Application.
Frame %d
Don't play samples.
Play samples.
Don't play music.
Play music.
%d (Num. keypad)
Backspace
Tab
Clear
Enter
Shift
Control
Space bar
Page Up
Page Down
End
Home
Left Arrow
Up Arrow
Right Arrow
Down Arrow
Select
Execute
Ins
Del
Escape
Heap
Video
Sound
Mb
An error has occured while reading the file.
This file is not a MMF application position file.
This file was not saved by this application.
This file was saved with an incompatible version of MMF runtime.
This file was saved by a incompatible version of the application.
The current frame is not the same as the saved one.
An error has occured while writing the file.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.0.283.5
ProductVersion 3.0.283.5
FileFlags (EMPTY)
FileOs VOS_DOS
VOS_DOS_WINDOWS16
VOS_DOS_WINDOWS32
VOS_OS232
VOS_OS232_PM32
VOS_WINCE
VOS__PM32
VOS__WINDOWS16
FileType VFT_APP
Language English - United States
CompanyName Clickteam
FileDescription Clickteam Fusion Stand Alone Application
FileVersion (#2) 3.0.283.5
InternalName StdRt.exe
LegalCopyright Copyright © 1996-2014 Clickteam
OriginalFilename StdRt.exe
Resource LangID English - United States

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x4a6110
SEHandlerTable 0x49e600
SEHandlerCount 36

RICH Header

XOR Key 0x169bc9b0
Unmarked objects 0
199 (41118) 2
ASM objects (50929) 63
C objects (50929) 166
C++ objects (50929) 61
C objects (VS2012 UPD3 build 60610) 5
Imports (VS2008 SP1 build 30729) 15
Total imports 616
C++ objects (VS2012 UPD3 build 60610) 8
C++ objects (VS2012 UPD4 build 61030) 36
Resource objects (VS2012 UPD4 build 61030) 1
Linker (VS2012 UPD4 build 61030) 1

Errors

<-- -->