a8ae952cb322e88d2a3e701065c835af

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: CODE
Unusual section name found: DATA
Unusual section name found: BSS
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • CallNextHookEx
Can take screenshots:
  • CreateCompatibleDC
  • GetDCEx
  • GetDC
Malicious VirusTotal score: 15/57 (Scanned on 2016-09-07 17:46:45) Bkav: W32.eHeur.Malware03
MicroWorld-eScan: Gen:Variant.Application.Bundler.DealPly.84
Arcabit: Trojan.Application.Bundler.DealPly.84
Invincea: backdoor.win32.hupigon.ck
Symantec: Heur.AdvML.B
BitDefender: Gen:Variant.Application.Bundler.DealPly.84
Ad-Aware: Gen:Variant.Application.Bundler.DealPly.84
F-Secure: Gen:Variant.Application.Bundler
Zillya: Trojan.DealPlyGen.Win32.1
Avira: ADWARE/DealPly.rsopq
Antiy-AVL: Trojan/Win32.TSGeneric
GData: Gen:Variant.Application.Bundler.DealPly.84
Rising: Malware.Generic!9FgXlMvQNxH@3 (thunder)
Ikarus: PUA.DealPly.Da
Qihoo-360: HEUR/QVM05.1.0000.Malware.Gen

Hashes

MD5 a8ae952cb322e88d2a3e701065c835af
SHA1 dd410cb8b34e51e1694be1a3c22c42e4d72ef22b
SHA256 0a3bb59c6bd6c99553cc62226269b1cbc5bbc4a815d5ed934fb9e2606bc49bc8
SHA3 619f1f70e359e3f3431943a2c778d00c3c5f378b3027c08f14d6199bc9cfb716
SSDeep 6144:UnxgGWA1d6HVJ2bBKYsy5syXum0zOOVZ6xaBgNwR1WMEBzyLDYtKP:Ux6WQAzum0dV8arRIMKc
Imports Hash bac7991c89fd1762cdb08f8e011631b8

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x55200
SizeOfInitializedData 0x8400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00056100 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x57000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 1.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x64000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 5090d6cc5347b7424c57a98950f43601
SHA1 952e10734c80814b293d9c88385bf72e0b4e4e4a
SHA256 144f5e5ce7963910b459563dcc86bccaca632e2c021a67cf06f169d6df1f2db9
SHA3 798ee3263142cda83e6028ebafaaeaca6629577b91e55de747f5f8bdf150fb39
VirtualSize 0x55174
VirtualAddress 0x1000
SizeOfRawData 0x55200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.82959

DATA

MD5 df1edfe71186c44b9c163cb6ae14cd70
SHA1 13c98a1d15c2c081999bc530eda994c64d4e9761
SHA256 6bcca397561d54d3197f97704ad53bbfcdd0df02e918e9378d51a81699dc2f8b
SHA3 8e0c64a334934ac313297a3ab982aa52d897161f49e591922a322fb9f12686a2
VirtualSize 0x5d0
VirtualAddress 0x57000
SizeOfRawData 0x600
PointerToRawData 0x55600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.79901

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470
VirtualSize 0x668
VirtualAddress 0x58000
SizeOfRawData 0
PointerToRawData 0x55c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.idata

MD5 113829163309aa0a2b417d58da40dc74
SHA1 c331d1f4025cdb86a829fe77fbb780e05a2f39af
SHA256 a60d8a1499dc0c57dcc6bd57a55353baeb1c56a4b5b625c2dbbc1def4d68dac7
SHA3 4cf8181cc770bd0b085cca711a19ac739c736d7341a61baf424638038dde20ab
VirtualSize 0x1566
VirtualAddress 0x59000
SizeOfRawData 0x1600
PointerToRawData 0x55c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.92572

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 c5d2460186f7233c927e7db2dcc703c0e500b653ca82273b7bfad8045d85a470
VirtualSize 0x8
VirtualAddress 0x5b000
SizeOfRawData 0
PointerToRawData 0x57200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rdata

MD5 7f0cb98f18f23e7b2324e96b772e0965
SHA1 786c227627f1440a20a8a7991ccc1241671e35a5
SHA256 10eddd568508309aae1f4133ee1658de2f80e45e51aa6ce473238be6a4f669e6
SHA3 b232c32875ff5e47d31ce9e7b0a134411b13f30e3a3f0d819b721179bb052959
VirtualSize 0x18
VirtualAddress 0x5c000
SizeOfRawData 0x200
PointerToRawData 0x57200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.204488

.reloc

MD5 abf82d4755b2dcbfe64bf2a74f4bb6a6
SHA1 1eb00a5e5ebffb7f6194502234eeb077b007ffeb
SHA256 e89ada27172a46f7b8b7e3f5f3e6b00035b4149ddbae7bdff496280ecc5a5472
SHA3 ce57c8978e0eafb24f4d95ee9348a3295b930a51321edfe700e103f04d2dfe74
VirtualSize 0x1f14
VirtualAddress 0x5d000
SizeOfRawData 0x2000
PointerToRawData 0x57400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.58937

.rsrc

MD5 c33137802b1c2f1c81f1b3cd8e645153
SHA1 5cd9c96582d32661cbe9e29cf592327b77580849
SHA256 3435754a2455ccfbbd3f157bc21717e59a2164eff83a2db703b4eb29f9445adf
SHA3 d021af233c29014855f83fc92508f8b15ceea4f0a82195bb60c750a47194d550
VirtualSize 0x4600
VirtualAddress 0x5f000
SizeOfRawData 0x4600
PointerToRawData 0x59400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 4.16764

Imports

kernel32.dll DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll MessageBoxA
oleaut32.dll VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysAllocStringLen
kernel32.dll (#2) DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
WideCharToMultiByte
TlsSetValue
TlsGetValue
MultiByteToWideChar
GetModuleHandleA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
ExitProcess
CreateFileA
CloseHandle
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetViewportOrgEx
SetTextColor
SetROP2
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RestoreDC
RectVisible
RealizePalette
MoveToEx
IntersectClipRect
GetWindowOrgEx
GetTextExtentPointA
GetStockObject
GetObjectA
GetDeviceCaps
GetDIBits
GetCurrentPositionEx
GetBitmapBits
ExcludeClipRect
EnumFontsA
DeleteObject
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreateFontIndirectA
CreateDIBitmap
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
user32.dll (#2) MessageBoxA
comctl32.dll ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Destroy
ImageList_Create

Delayed Imports

1

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 cd2320ff7b30ddc00a93f92b9e4588805bafef9048547fe5095834a0f3dd197f

2

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 1dafeb6306fbb014913cb74e5ed986d0b2af332b509c5671904101bdb2c40a6a

3

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 471f7e3e44602b9ec23bea4b6890289ecef21324f8253094dd9213cad4e67bf6

4

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 d851e9d23970990a481928f0d559e7de1c84b6f5aa4b39d9f5e6abd9126b9a91

5

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 827fe9002743a1f9f2c4306aecc48c4a5644a255d1adf8861db0b4774ca7b952

6

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 4950d186d15390d11ee67e28b3f5231214a04f8a8f42ec2e229a95b253cc95e7

1 (#2)

Type RT_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x468
Entropy 6.15758
MD5 43dac58ed6b49bb59e608d82c149bce4
SHA1 080a10efe1945df5bb76c12998cea297cb85adcb
SHA256 285bd44cb05141d4a3163addbe27bdb0832a3d1c5f3f9601a3fb21f050e3d583
SHA3 ca58b6008dae1aa0b16ab89d714e5d6be8661863285bc14b5904aad49a9bf10d

3841

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a8
Entropy 3.22081
MD5 f01ffe5f9df20131680ef1a53aadd9ff
SHA1 23cf08ab26c9636051ea04d0c0d1be2fba96dcb0
SHA256 c299a6cf7addd9334b3b04219ee11ab108b483ffb40e983beb7f45a77432d603
SHA3 0e95b9ee7310716db5a14522d5f0db3602e4d236a983850ac61bc080701524fd

3842

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x348
Entropy 3.27291
MD5 2c25bd791c90a5ecf4365f7eb3a72cc3
SHA1 0564aa754b6bdf629fbcfb082151a810f48e11ba
SHA256 8b87c30f3b0fbcaea400d453cb56fa8b55778c6b50cfc3c09fa5be5d4d16939d
SHA3 5e9b125dfbe4896cf4a6453d090e9408f4ead2e04bdea3b6dce49c9b2325418a

3843

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3ac
Entropy 3.31636
MD5 7d4fbb7d1b51a3a941daf9f69a6ba7f3
SHA1 2108559e4213e6c3737d0a245f2888ad10237703
SHA256 120f8d457f844894cdbcb38026d2397207a6a2d9d5e641093f6a8a06dd6e7c55
SHA3 cda872c44db3a906aae3eab57662b7a84513ae708e824bb7ad6170a6a6846ee1

3844

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3e2
Entropy 3.28917
MD5 3ff292d213f8ef99c3db7d542c1c0415
SHA1 753fe12c9d5e8e03a15be30f001950f4abd5cb26
SHA256 56db0b798b0e80b356030ae50b7d2b907abbdd2abc8606aed9f24dd3009c5a4d
SHA3 ca7bc2bf434331ccf698ed80f9a4a028e8f52c20c6ec4dea0be7b3eba6b233b1

3845

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x234
Entropy 3.35694
MD5 6bc9045d3b92758eeafb4816b4d60e17
SHA1 3cf4ac512f1a711717ab1bfe51d32f9826bae2f3
SHA256 3ee268dd760afa5b374e9e1fa310fd613b9892e9a88623f07417f6d2e6cf4476
SHA3 082590597ed56b16c04b85c2c5156d0cded05df9515b538cc0d9f2289626bf29

3846

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2da
Entropy 3.42579
MD5 8b77dd18ed20f370b5ec6e38d12f0218
SHA1 7092fd5387e77b320c54121bc9db3c86687c5fec
SHA256 1f30e1e2c78f01912cfc476a00ac7e9ce6968f87e8291ee6746353eef9943d98
SHA3 90fc03ee8b7edb8c61b8af1207b2379470b95fc8cfc97b9d1d2073e9e2d51e60

3847

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2fa
Entropy 3.27803
MD5 41f75583e05dbd1ab0bb046992ac530d
SHA1 95200008debd9acb496e2c3fc7f0af5e5d3d8499
SHA256 e4963e8ee4307eea5631f669f56538484b7a9a2e378a830c3bcfa92005795493
SHA3 64911cb55ea50ef61c98d48ffc1654ca263d752c3f53a7c0333f24ff14cc1192

3848

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x202
Entropy 3.37209
MD5 bd9d422d12c8d2d6bce01c239d7a5977
SHA1 2aff51ef0c0c574533f666052b9edd6a7d422753
SHA256 d5e02f9d82afd8fffb546c6a23310871b0876d9e1e377c672751c140f616c92b
SHA3 92206c90a6bf90c770ab8d4d03b8788f79329eee165d3e2d7af1939065edce1c

3849

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xc8
Entropy 3.46341
MD5 a99fa234d8179d01c5eb7f8031cfdabc
SHA1 b2681c2e7c9e2097112c61265fb60834f3abdcac
SHA256 d4937b6283c32913d90c594a20800b24e20471a8c1797b0b686235de32873c31
SHA3 83842a043c8fcc0881c2e6c37b3f5ccf058163e0b59ea32b1e91b258f457cf1b

3850

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1ec
Entropy 3.36478
MD5 a6012b964fe17d3c74db403f652ba738
SHA1 2d95dd18cd2e73fe596493aceb52839ac762a5a0
SHA256 b2fa909b44192a1bab395f4fd9de6148265075959544d0af8a04c9edb417fbb9
SHA3 d7f3b8b5f42150e46ca6e11b0bf31dd4b3e5243fb0a9a4e52e93dd2cc144fd38

3851

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x27a
Entropy 3.54267
MD5 3325091184a33aa03b0115a523051479
SHA1 c6cfc30590c7ee83b962f191d44fd4a23f1760ea
SHA256 0a067aa0656686a3572fe1e22527f03107fe0cb219d01033a7a4b5f9f83c8400
SHA3 7777b591da2be27183d60294c5f03c746c3f5a03e999130f9adc70f7c30dfef0

3852

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3aa
Entropy 3.33
MD5 0b3585fcbe9866f751de76c2a1212dbe
SHA1 e9a645f09af132045ec7e2bf3b792ce312ec9366
SHA256 0a7ebe55bf87141e5f2006967f980753de14573cfebc6f631408aa7e14908432
SHA3 1ea1ac2221403022758d138f2c3ea2b0c32e98e735ef72d8fe41332f3c801f3d

3853

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x7e
Entropy 2.54164
MD5 87d7ce102272b20feb5ccf0775e9464a
SHA1 8d9bd6389e6ec5ca78c65305b2b89fe5c4cd2a1a
SHA256 7cacb3a88c4d97346b7b6fe83db84d7c3c8737c3fe36b5043d7c9894c956798a
SHA3 23b95d13cc208bd6e5b57b185696c880c84120168670675d5675402873f2654f

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2f2
Entropy 3.21823
MD5 bbf4b644f9dd284b35eb31573d0df2f7
SHA1 4f9885ae629e83464e313af5254ef86f01accd0b
SHA256 2c0d32398e3c95657a577c044cc32fe24fa058d0c32e13099b26fd678de8354f
SHA3 ead4031fb130118ab0e727e2230d1c3780aeba20e35072f3fe64446811d20f60

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x30c
Entropy 3.31515
MD5 ac2a0551cb90f91d779ee8622682dfb1
SHA1 ff0db7d2f48d85ceb3539b21ebe9d0ca3443f1da
SHA256 840989e0a92f2746ae60b8e3efc1a39bcca17e82df3634c1643d76141fc75bb3
SHA3 1d2f00e1c5d3ebcd7b2c79e7579d0b8dffa74413acfbdeaf17531d445b87ac7d

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2ce
Entropy 3.25024
MD5 c99b474c52df3049dfb38b5308f2827d
SHA1 7375e693629ce6bbd1a0419621d094bcd2c67bb7
SHA256 26bda4da3649a575157a6466468a0a86944756643855954120fd715f3c9c7f78
SHA3 9eb2c054959ab75a61fce2afbf3d33dbf10de07d0f67b1658a23f590872580e0

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x68
Entropy 2.86149
MD5 aec4e28ea9db1361160cde225d158108
SHA1 249013a10cde021c713ba2dc8912f9e05be35735
SHA256 d786490af7fe66042fb4a7d52023f5a1442f9b5e65d067b9093d1a128a6af34c
SHA3 d9be38e75af58c5b4d702602a48c7bce0f7d0a46995727278fecaf7f19498e85

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xb4
Entropy 3.20731
MD5 c76a8843204c0572bca24ada35abe8c7
SHA1 066052030d0a32310da8cb5a51d0590960a65f32
SHA256 00a0794f0a493c167f64ed8b119d49bdc59f76bb35e5c295dc047095958ee2fd
SHA3 da42d88f88ece9fa99fa07624acf50e652a16febee3069bd23f9b59d36401ed0

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xae
Entropy 3.04592
MD5 4bd4f3f6d918ba49d8800ad83d277a86
SHA1 1f5e4c73965fea1d1f729efbe7568dcd081a2168
SHA256 34973a8a33b90ec734bd328198311f579666d5aeb04c94f469ebb822689de3c3
SHA3 cb9838217cf331f3a623ca3678d202510824d401515dae111c7c25e758a15df8

TBADAP

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xad
Entropy 5.36986
MD5 515b425138455e1e35c72927597f2c19
SHA1 cd685f878e4e9f00c2adc5160f48abd61d553135
SHA256 387369f5fa53cf11fbce470cd908ed28eeed0a03cf9f6dd70bc8c9d8d8a6215a
SHA3 704ce44ec4592fd84c76a6c7347e71d5837f1cb039bb75cd4f8d88fa48860c8a

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 ac55fd3f47159deddb52621de25ad96afc4708bf547ba0ffbe959259270cfbd3

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 274aad3386be6b264e99ff38aa473969117c861a5cd239441ded4e511187c97c

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 8177402f46c3117dab4e38a1288f1e4ceddc76252c744ade470a1c2d5ff05381

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 2868947de82fc70c2028052d8d8bb6f2b331b61e664334d14eedd179b424b3ca

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 35897e068a170a45c2d95c746f9bb49b0ad3df3474ad442abef72b7589087a6e

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 d4da59909598190860aaf8a952932eb5be369f2285910affe15f9367fe0602c8

MAINICON

Type RT_GROUP_ICON
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
Entropy 1.91924
Detected Filetype Icon file
MD5 80e042259a41ebc0811c1452ad59a73c
SHA1 055584d22b8401b73764107f541181855f8e4351
SHA256 daec50669948d7253812254df2aff0def2cad87d6e701c0eada57609a65b5cb1
SHA3 352830059eaa4dcbdd372bcc927d652837348ab26b8c5ca99c968108c38067a5

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x33c
Entropy 5.2891
MD5 c21660e4204ff6c2cfa5cc18ac13d96c
SHA1 0fe2f382cecaca7db628f60f848b89b17493bc93
SHA256 9ba0d9cc200ed03d2c23e944b72e26f30d2c9d3fcae9eef46449b137d05dbf05
SHA3 73e53d4eaf461b9d9b483f2eace91a18d087156860fa27a75f938c36080370d1

String Table contents

Cannot assign a %s to a %s
Cannot create file %s
Cannot open file %s
Stream read error
Stream write error
Out of memory while expanding memory stream
Can't write to a read-only resource stream
WriteObject called twice for the same instance
Class %s not found
Invalid stream format
Resource %s not found
Resource %s is of incorrect class
List index out of bounds
Operation not allowed on sorted string list
String list does not allow duplicates
Tab index out of bounds
A component named %s already exists
''%s'' is not a valid component name
A class named %s already exists
''%s'' is not a valid integer value
Line too long
Invalid property value
Invalid property path
Property does not exist
Property is read-only
Error reading %s.%s: %s
Ancestor for '%s' not found
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Bitmap is empty
Cannot change the size of an icon
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Too many images
Image dimensions do not match image list dimensions
Invalid ImageList
Unable to Replace Image
Invalid ImageList Index
Error creating window device context
Client of TDrag not initialized
Error creating window class
Error creating window
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Scrollbar property out of range
%s property out of range
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot have more than one MDI form per application
Cannot create form. No MDI forms are currently active
Invalid component registration
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Cannot drag a form
PutObject to undefined item
Could not load CARDS.DLL
Duplicate CardId found
An error returned from DDE ($0%x)
DDE Error - conversation not established ($0%x)
Error occurred when DDE ran out of memory ($0%x)
Unable to connect DDE conversation
FB
FG
BG
Cannot load older version of TShape
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Grid too large for operation
Too many rows or columns deleted
Grid index out of range
Fixed column count must be less than column count
Fixed row count must be less than row count
%s on line %d
Identifier expected
String expected
Number expected
''%s'' expected
%s expected
Invalid numeric value
Invalid string constant
Invalid property value
Invalid binary value
Outline index not found
Parent must be expanded
Invalid value for current item
Invalid input value
Invalid input value. Use escape key to abandon changes
Invalid outline index
Incorrect level assignment
Invalid selection
File load error
Line too long
Maximum outline depth exceeded
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
No help available
Help
&Abort
&Retry
&Ignore
&All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
(Unknown)
(None)
Value must be between %d and %d
Cannot create a default method name for an unnamed component
Invalid argument to date encode
Invalid argument to time encode
''%s'' is not a valid date
''%s'' is not a valid time
''%s'' is not a valid date and time
Invalid file name - %s
All files (*.*)|*.*
All
: [ - no volume label - ]
Unable to insert a line
The specified directory does not exist. Create it?
Select Directory
Directory &Name:
D&rives:
&Directories:
&Files: (*.*)
Ne&twork...
Color
ABCDEFGHIJKLMNOP
Invalid clipboard format
Clipboard does not support Icons
Default
Text exceeds memo capacity
Custom Colors
Operation not supported on selected printer
There is no default printer currently selected
Unable to write to %s
Bits index out of range
(Untitled)
Invalid data type for '%s'
Failed to create key %s
Failed to set data for '%s'
Failed to get data for '%s'
Synchronize called when main VCL thread in a WaitFor call
Unknown RichEdit conversion file extension (.%s)
Menu '%s' is already being used by another form
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Invalid variant type conversion
Invalid variant operation
Variant method calls not supported
Read
Write
Format result longer than 4096 characters
Format string too long
Error creating variant array
Variant is not an array
Variant array index out of bounds
External exception %x
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday

Version Info

TLS Callbacks

StartAddressOfRawData 0x45b000
EndAddressOfRawData 0x45b008
AddressOfIndex 0x4583d4
AddressOfCallbacks 0x45c010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section BSS has a size of 0! [*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0! [*] Warning: Section .tls has a size of 0!