af4281bc37655f099a651abd498ab8fa

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2013-Sep-19 00:45:48
Detected languages Dutch - Netherlands
English - United States
Russian - Russia
Comments This installation was built with Inno Setup.
CompanyName
FileDescription
FileVersion 6
LegalCopyright z10yded
ProductName
ProductVersion 1.02.0.0

Plugin Output

Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC+4 timezone.
Suspicious The file contains overlay data. 4107859 bytes of data starting at offset 0x25600.
The overlay data has an entropy of 7.99997 and is possibly compressed or encrypted.
Overlay data amounts for 96.4072% of the executable.
Suspicious VirusTotal score: 1/69 (Scanned on 2019-09-01 23:42:07) Tencent: Win32.Trojan.Bp-antiav.Oerb

Hashes

MD5 af4281bc37655f099a651abd498ab8fa
SHA1 3eff38556395006569969738b8c4e8b99b7547fd
SHA256 86e4dbdd0d025cdb8b3f136acb758c2cbbda68c39a1c8eb26e1d2a8b92d2fcf3
SHA3 26fde3e6f31324247d6c140ca415539b70ec659644daa6fe6457afe2dbddda12
SSDeep 98304:/NXGRhzum6JdZ/Jx0ZFmBPyc0wBTlPkMqZQt2bLg/3:1elh6JrBi7mBttNwit2bLgf
Imports Hash 9d8fb47598991ad8c0094898c32a6c3b

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2013-Sep-19 00:45:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x17e00
SizeOfInitializedData 0xd400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00018514 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x19000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x2f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 fad2de5b1e511481bef6c1634cf9a502
SHA1 8aef246c619e2e7cfc3891eabbc59f1377143565
SHA256 37d3b382d9ab3b5b4db6206ef22d33834ee69f83172ebdbe8b526ddd11d00bd9
SHA3 e7a1a39e241175d05f3a00dc05f33d39b55f2c9cd5bede35e3e925dafea77bf7
VirtualSize 0x16f5c
VirtualAddress 0x1000
SizeOfRawData 0x17000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.42532

.itext

MD5 573256293a791795c1564e63e8b3139b
SHA1 77c3a648d2558273c74931bf9cf1b2d1250d7646
SHA256 3a21ad1afdef3d7bf21baf78d37dcaedaaf401f71b19597b6fcda07b86b70a46
SHA3 4f24a76eb5765de56a6da103006bd72b7029c3a0b5292df35a52c1189ed88343
VirtualSize 0xce8
VirtualAddress 0x18000
SizeOfRawData 0xe00
PointerToRawData 0x17400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.81278

.data

MD5 bed4f3e110991ad51e2df04534b3977a
SHA1 60c730d0eb4c2c63e66b9d5f6d340b32662ad845
SHA256 5a6f8302e59dadc1771f556efeff8ea64245fe914ddc479996c2a4341db5f737
SHA3 d8c855423f51636e507f9a880ec5799b64ff22adfd39a195f86f4148875a91f6
VirtualSize 0xdc8
VirtualAddress 0x19000
SizeOfRawData 0xe00
PointerToRawData 0x18200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.70125

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x5794
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0x19000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 7d8bdf4b653273645431854c252903b3
SHA1 1f059dcac92b7f1c1068dcdfd93b722670715955
SHA256 52b359bc5d25efeae74ded352b473bcc13fa051ff643561092c5257702107983
SHA3 348d3aa433cf34ede00005137cd63f7d7ee5a48105353c59870b855e1d192d11
VirtualSize 0xfd6
VirtualAddress 0x20000
SizeOfRawData 0x1000
PointerToRawData 0x19000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.99821

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xc
VirtualAddress 0x21000
SizeOfRawData 0
PointerToRawData 0x1a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 16c0435a184caed1912ca229d5b53d7f
SHA1 0a0898f3f5cc3455a26be369a11abd15367fa488
SHA256 62122b7675daa9eb27ca80dcbac452a31e2d5d93393476852f5e8b7a12023613
SHA3 7a9fdf05a255dabf8e7cad6033da81f5857e7c648fd29d250203599f673080ea
VirtualSize 0x18
VirtualAddress 0x22000
SizeOfRawData 0x200
PointerToRawData 0x1a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.205446

.rsrc

MD5 7243e0797427c8398b192746ddd59c7c
SHA1 f3a49e4d0081ebfd805ed92bf46a706e055fe003
SHA256 d2b37d2bdc6ee02913c4887ed9ff97673263ee51cc9f2fd478aa317a51166576
SHA3 5e659a2291170654003849f265ec09627954b25139c7fa05fa7aaa2d324dc9d8
VirtualSize 0xb400
VirtualAddress 0x23000
SizeOfRawData 0xb400
PointerToRawData 0x1a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.16347

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen

Delayed Imports

1

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x128
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.25755
MD5 c5af786bfd9fd1c53c8fe9f0bd9ce38b
SHA1 4f6f7d9973b47063aa5353225a2bc5a76aa2a96a
SHA256 f59f62e7843b3ff992cf769a3c608acd4a85a38b3b302cda8507b75163659d7b
SHA3 e178a71f02edb18e31bf550d484b2cba8d865e1e9796065addb07855ce5627f9

2

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x568
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.47151
MD5 0a451222f7037983439a58e3b44db529
SHA1 6881cba71174502883d53a8885fb90dad81fd0c0
SHA256 dc785b2a3e4ea82bd34121cc04e80758e221f11ee686fcfd87ce49f8e6730b22
SHA3 d5599c242df5383add3fb330d42b31f1751594b36bbf52195e7d1dd564e7f0e3

3

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.91708
MD5 90ed3aac2a942e3067e6471b32860e77
SHA1 b849a2b9901473810b5d74e6703be78c3a7e64e3
SHA256 ca8fc96218d0a7e691dd7b95da05a27246439822d09b829af240523b28fd5bb3
SHA3 3f02085a0d69091556ede0b585f45145adce9849e175d8177c2f0fe0891a1bd8

4

Type RT_ICON
Language Dutch - Netherlands
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.91366
MD5 af05dd5bd4c3b1fc94922c75ed4f9519
SHA1 f54685a8a314e6f911c75cf7554796212fb17c3e
SHA256 3bbacbad1458254c59ad7d0fd9bea998d46b70b8f8dcfc56aad561a293ffdae3
SHA3 150dba8cc825d5c0e9ff3c59015533288d19931847210338a3ef7cdc390c0e78

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x5c
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 2.1727
MD5 94fab06e3562b73ba1fd1522f168009a
SHA1 55ad3082c8cdac86754fae5275f0c2689ffbe8a8
SHA256 182c618cef21201d43743bdd28428cc30c80a7e1d8e6c475d46a6109db4cb781
SHA3 28cfdedfe2aff7c1d9a89bd62754bc3792ced5bdd230c483a6558f579b747555

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x17c
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.35207
MD5 c2ee10e6493d7eccf2b7c819d85b224d
SHA1 d907796b3d8d32683db77a8adb5fa005ad172123
SHA256 fbc0dd182a9568eb8147e9d944aa79b2038f620ab95de7b9a11cba27f6786a2d
SHA3 aca1cbe61e02416a0f1880745f4eef747a2cb81779e5333387c485f97ef30af0

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.34698
MD5 f5b81c80af9a8173b32a363e721d0a86
SHA1 16ecf114b40ec23eb00c82f28e408ddbcf701fda
SHA256 07a699dfba3b6f2e997c6ee78a0e0e1dad18c948aff0f1767b28f5ee6e41fdc3
SHA3 9516ca5c26bf77d713578d01233ea75c2e697d877a6a220e0c60fd179f8885e1

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x1dc
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.38794
MD5 ecc0c32424a1be661ae60a256f7e2756
SHA1 a2a98e72ec3fb52ba5cbf030809df0f33a362ee6
SHA256 dcfadafed57c3c810dbc404ef823b0dc7dc240995d5c01678db52b4106e5bd9a
SHA3 aa0a993692bff12df436f9f28ab386485ee6d1a15e308de00eac06c64a6cdd1e

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x39c
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.29351
MD5 0b1533b447231c6319c4a10d84508e60
SHA1 f5477d91942bfe92a5dc3c46897a66fb663a124f
SHA256 6fa3bbc46b4cc3a979f4ebfc293c50453912eb51ef76d2ea3c7d3d86d7223e86
SHA3 aed1581927a66228d158a903e015bdfa9a12e44865ff24c991ba8e2c1a9de8c1

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x34c
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x294
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x82e8
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x18c
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 5.199
MD5 e40f4b382750f0f2b44e49a6489d8115
SHA1 30bcda5ae07ce70b517929b23ec37a9a4c1589d1
SHA256 57db77c2448cd1f4e2682cae5328229d53124e05458c0429bc852686ea5b78ac
SHA3 b95fde09369a9314192e9f98a22ed5d67bfbe75a9440f76d7774f5bbfb9c4414

11111

Type RT_RCDATA
Language Russian - Russia
Codepage UNKNOWN
Size 0x3a
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 5.53462
MD5 e5a05fc827c456ceb797b0e71e851add
SHA1 8e4b73e598b3ae4da53eafd2fe31d90a4da32bab
SHA256 92bee56c9185e9169aa39b39cbbe9b13915be92e9897f922cbde46fa050fc73d
SHA3 0270218f0abfbe3ba6f11c3e5c723d9a0f68472dcbc1becc9451ca57d1f4cba6

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3e
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 2.64576
Detected Filetype Icon file
MD5 f6262f462f61a1af1cac10cf4b790e5a
SHA1 4aa3239c2c59fa5f246b0dd68da564e529b98ff4
SHA256 44b095a62d7e401671f57271e6cada367bb55cf7b300ef768b3487b841facd3c
SHA3 f2a1d165133c29eba349014fa5f8059ddebe1aba5b220fb89f1a474e95c482ca

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x4b8
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 2.52452
MD5 db57c828532c0d703315f2a4ec0c57fb
SHA1 3589f4b552fb0d077ba4954ed514a29445b5979b
SHA256 9b71c7ffdfc5f7577fb35e6ca80806ab99c4f8d4ba1a1df0f7b8aac52ea4d7f5
SHA3 44288005862c3146c75b2527ddd263f8678c311d06cd8a645d7fa503e6132855

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x5a4
TimeDateStamp 2013-Sep-19 04:45:50
Entropy 5.08452
MD5 3005dd5c3434302be2a8f0b26f2ddb18
SHA1 e81221b09c9012b27b5aaf513a5dd74b08be9f6d
SHA256 5c0fe2a5fc29f15655d1cb9adcd9eefce554b133ca5715b010a014c9dfef5bd0
SHA3 18b2f14622c4985238f34e40b91637553c9711514c2cdc04722d6f75b987c0de

String Table contents

List index out of bounds (%d)
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Cannot assign a %s to a %s
Invalid file name - %s
List capacity out of bounds (%d)
List count out of bounds (%d)
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Sun
Mon
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6.0.0.0
ProductVersion 6.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName
FileDescription
FileVersion (#2) 6
LegalCopyright z10yded
ProductName
ProductVersion (#2) 1.02.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x421000
EndAddressOfRawData 0x42100c
AddressOfIndex 0x4197b4
AddressOfCallbacks 0x422010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->