b3806cf4a8ab2cad2e83780b732f773b

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Sep-04 14:52:04
Detected languages English - United States
Debug artifacts C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb
CompanyName RealDefense LLC
FileDescription MyCleanPC Installer
FileVersion 3.9.9
InternalName MyCleanPCSetup
LegalCopyright RealDefense LLC
OriginalFileName MyCleanPCSetup.exe
ProductName MyCleanPC
ProductVersion 3.9.9

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to security software:
  • rshell.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Contains domain names:
  • download.microsoft.com
  • example.com
  • google.com
  • http://download.microsoft.com
  • http://download.microsoft.com/download/5/6/7/567758a3-759e-473e-bf8f-52154438565a/dotnetfx.exe
  • http://download.microsoft.com/download/a/3/f/a3f1bf98-18f3-4036-9b68-8e6de530ce0a/NetFx64.exe
  • http://www.example.com
  • http://www.google.com
  • http://www.yahoo.com
  • microsoft.com
  • www.example.com
  • www.google.com
  • www.yahoo.com
  • yahoo.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA256
Uses constants related to AES
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
  • LoadLibraryW
  • LoadLibraryExA
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • SwitchToThread
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Enumerates local disk drives:
  • GetDriveTypeW
  • GetLogicalDriveStringsW
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
Info The PE is digitally signed. Signer: RealDefense LLC
Issuer: DigiCert SHA2 Assured ID Code Signing CA
Malicious VirusTotal score: 3/70 (Scanned on 2021-01-14 00:00:24) ESET-NOD32: a variant of MSIL/PCCleaningUtility.D potentially unwanted
DrWeb: Program.Unwanted.4804
Malwarebytes: PUP.Optional.MyCleanPC

Hashes

MD5 b3806cf4a8ab2cad2e83780b732f773b
SHA1 7ac75b2fd54739d118e2dd7d9dc0218b81115424
SHA256 832dfa53011b38683fa21bcfea29f63309d28765d88200e8303340df72e9e78e
SHA3 a08cd7f10896a94dc0ac7fad649b7727d46d201da0306bd4eab079980f178d90
SSDeep 196608:q5RB2oBYx19v3eHwGqJRUiDVZx8wo1wzTOrI2Lic6Y29:q5g19pGqJRnp1nOrI2GBYa
Imports Hash 95b112150623822eaa67189ef4cbf07c

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x110

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2019-Sep-04 14:52:04
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x174000
SizeOfInitializedData 0xa5e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0012315A (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x175000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x21f000
SizeOfHeaders 0x400
Checksum 0x8faa2c
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9bf7947928f4c6aec415c9a2b840ff95
SHA1 964c0214b913e508e50e977cebdf99f712801ac6
SHA256 0c66a49d36b76f6caccccc365504856443383eaaa1a5542bd564185864517d50
SHA3 5073272a0d4ad0332ccdad8208cdcb44e0222b01b2815e07a25236cb0d53d358
VirtualSize 0x173e3f
VirtualAddress 0x1000
SizeOfRawData 0x174000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45637

.rdata

MD5 dfecfd51e4e6a97cea42aaf2878c6851
SHA1 b7a32cfbaefc4bfe676e312b004337c1cf42b7e9
SHA256 44a1e0972f015f358429fe04f16ef3dda8d9308d178c4fe5db63843d951485a1
SHA3 ebb12d0f44c860338d249c9faf4a009a56dd2980fb856ef94a4b8b02bd6537fa
VirtualSize 0x5dfb8
VirtualAddress 0x175000
SizeOfRawData 0x5e000
PointerToRawData 0x174400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.61105

.data

MD5 1735758f0ee3cde8a2564494828977f1
SHA1 1c46c6291cd08cc726b49c49ae6c77c1e0122e60
SHA256 2baa749393c3eb35dccf293f865501ceb4268b764d102e7fa8973c8ef1ae292a
SHA3 7457d8824220e8b6d48be18ff7844b9050ef116acc083cb6458597503520f4c6
VirtualSize 0x7158
VirtualAddress 0x1d3000
SizeOfRawData 0x5400
PointerToRawData 0x1d2400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.10003

.rsrc

MD5 49942d3d7301c9492f77df0d86b63dec
SHA1 ff6c04389aaad25564c7b14d16c761c7e1a2808f
SHA256 4e9b1dc456343633af5b7fa57107033ce41e17d55551911d35f02e7a0f01d3f9
SHA3 57e59310c00ea0aeaf49e1f2129cb4149d9497064090a16cbd8b4c814055f7e9
VirtualSize 0x293ac
VirtualAddress 0x1db000
SizeOfRawData 0x29400
PointerToRawData 0x1d7800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.46692

.reloc

MD5 4b21c53f3541a78f742349755171cf4b
SHA1 c06c5015c5fd29385b33ce01d4dd6b942574d55f
SHA256 724224eadd9f0d545148d48ec8aab42b0855c9494357a4b95105a523078cbf39
SHA3 f3945e9013945b6d3b2cbeea0e7793934720720f991c10ab0dd7d37b4d20836d
VirtualSize 0x1951c
VirtualAddress 0x205000
SizeOfRawData 0x19600
PointerToRawData 0x200c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.56121

Imports

KERNEL32.dll CreateFileW
CloseHandle
WriteFile
DeleteFileW
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
RemoveDirectoryW
GetTempPathW
GetTempFileNameW
CreateDirectoryW
MoveFileW
GetLastError
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
EnterCriticalSection
LeaveCriticalSection
GetModuleFileNameW
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
GetCurrentThreadId
RaiseException
SetLastError
GlobalUnlock
GlobalLock
GlobalAlloc
MulDiv
lstrcmpW
CreateEventW
SetEvent
InitializeCriticalSection
lstrcpynW
WaitForSingleObject
CreateThread
GetProcAddress
LoadLibraryExW
DecodePointer
Sleep
GetDiskFreeSpaceExW
GetExitCodeThread
GetCurrentProcessId
FreeLibrary
GetSystemDirectoryW
lstrlenW
VerifyVersionInfoW
VerSetConditionMask
lstrcmpiW
GetModuleHandleW
LoadLibraryW
GetDriveTypeW
CompareStringW
FindFirstFileW
FindNextFileW
GetLogicalDriveStringsW
GetFileSize
GetFileAttributesW
SetFileAttributesW
GetFileTime
CopyFileW
ReadFile
SetFilePointer
FindClose
MultiByteToWideChar
WideCharToMultiByte
GetCurrentProcess
GetSystemInfo
WaitForMultipleObjects
ReadConsoleW
VirtualProtect
VirtualQuery
LoadLibraryExA
GetStringTypeW
GetShortPathNameW
SetUnhandledExceptionFilter
FormatMessageW
GetEnvironmentVariableW
GetEnvironmentStringsW
LocalFree
LoadLibraryA
GetModuleFileNameA
GetFullPathNameW
GetCurrentThread
FlushFileBuffers
SetConsoleTextAttribute
GetStdHandle
GetConsoleScreenBufferInfo
OutputDebugStringW
CreateProcessW
GetExitCodeProcess
GetCommandLineW
SetCurrentDirectoryW
SetEndOfFile
EnumResourceLanguagesW
GetLocaleInfoW
GetSystemDefaultLangID
GetUserDefaultLangID
GetWindowsDirectoryW
GetSystemTime
SystemTimeToFileTime
FileTimeToSystemTime
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
ResetEvent
GlobalFree
GetPrivateProfileStringW
GetPrivateProfileSectionNamesW
WritePrivateProfileStringW
GetLocalTime
CreateNamedPipeW
ConnectNamedPipe
TerminateThread
LocalAlloc
CompareFileTime
CopyFileExW
OpenEventW
PeekNamedPipe
IsDebuggerPresent
EncodePointer
InitializeSListHead
InterlockedPopEntrySList
InterlockedPushEntrySList
FlushInstructionCache
IsProcessorFeaturePresent
VirtualAlloc
VirtualFree
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetCPInfo
LCMapStringW
WaitForSingleObjectEx
UnhandledExceptionFilter
TerminateProcess
GetStartupInfoW
QueryPerformanceCounter
RtlUnwind
QueryPerformanceFrequency
ExitProcess
GetModuleHandleExW
GetFileType
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetConsoleCP
GetConsoleMode
IsValidCodePage
GetACP
GetOEMCP
GetFileSizeEx
SetFilePointerEx
FindFirstFileExW
GetCommandLineA
FreeEnvironmentStringsW
SetStdHandle
WriteConsoleW
msi.dll (delay-loaded) #7
#62
#139
#54
#58
#147
#140
#221
#94
#51
#169
#80
#8
#224
#19
#96
#281
#137
#115
#166
#52
#150
#78
#141
#90
#204
#113
#16
#116
#67
#114
#120
#47
#26
#34
#145
#118
#103
#74
#20
#160
#159
#32
#186
#171
#48
#24
#70
#195
#205
#121
#158
#49
#125
#17
#92
#6

Delayed Imports

Attributes 0x1
Name msi.dll
ModuleHandle 0x1d8318
DelayImportAddressTable 0x1d81e8
DelayImportNameTable 0x1cff18
BoundDelayImportTable 0x1d1a04
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

221

Type IMAGE_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.25163
MD5 acd4cb4d2fec6d3a9d84ec0604cf6395
SHA1 ab50880af341a7e9c14b1a3dbade53fbb1457e48
SHA256 20895f5708984178014cd6bf23aceb4c926eeb8343641ec3c4b308e6fa5caded
SHA3 29e31e66854952190509557a2e5ff9a7262e02fa9c261bf443d76ef74e773ef9

222

Type IMAGE_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.25163
MD5 acd4cb4d2fec6d3a9d84ec0604cf6395
SHA1 ab50880af341a7e9c14b1a3dbade53fbb1457e48
SHA256 20895f5708984178014cd6bf23aceb4c926eeb8343641ec3c4b308e6fa5caded
SHA3 29e31e66854952190509557a2e5ff9a7262e02fa9c261bf443d76ef74e773ef9

210

Type RTF_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.80026
Detected Filetype RTF Document
MD5 140cef8568455018c9707c29186f66af
SHA1 33a40abf8c36c21d9a792da2dc37ece8f2339d2d
SHA256 2e35a88a738e5852baf8b0feb0c9ef4ac9ba931baeb30450772ea5ffca674828
SHA3 4999db068a3e3009734408a0ef73d333d387fc7bb468a48e9911c81a9ee3a22a

219

Type RTF_FILE
Language English - United States
Codepage Latin 1 / Western European
Size 0xa1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95447
Detected Filetype RTF Document
MD5 4608b9e7ddf0a829ad4dd98c2e718f84
SHA1 92a010a8dce3a2696e24a5b2d4527d81f9d6eac8
SHA256 1b3e7d6b884fb63d6a551237845821bc9c66c177757a863cebe379c2e7742abc
SHA3 ad9a298b36fa6bb7d671a1cc36470a73d86af7f51d3b5c2e9629e959c2251c0c

249

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x13e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.68257
MD5 b89c53234608d5520e4d31473d295903
SHA1 eb0793d7eb2f6e963a670facdbc9eb0005882350
SHA256 32673976ffb81636486cd895a3e78e45d812109fdc5c773bcd551316d0b35182
SHA3 babff1eae44a15d43d7d370045bcc0ad9ffe1db664c6acb086248acd1c31cdb0
Preview

255

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.675615
MD5 2487cd4b69093c5f2b5daae9a97b6b0d
SHA1 bd685319d12d18941e76c6c65e6a9eeb8b56ba40
SHA256 43175f041004354a75b7cc148dc6192777411006df824d83587098ae0e87959c
SHA3 5f6abbd150f4ae75ceea15f8b7e0271b64ae7a55866213bcfc7f86641b37793c
Preview

10106

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x48a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.91386
MD5 feb4796a8797e048f5309d841b9e680d
SHA1 2bd88e01b58b033fc830623f6d3f3bea30c16b10
SHA256 6e1084a05b9b8a00d2f8572cb70133f10d9ccbb1c6d6dcbbd9c4ae8a655add8a
SHA3 9b52aa7127a27d71df724bf20d4619005546e24be0d4faa1db0229424501c480
Preview

10107

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0xa6a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.79553
MD5 e907975955dd2be6b62fd46628cfedce
SHA1 b4694d36c14d72ba6eec14f70d02197019499ca8
SHA256 1bd86eecad0a5db654c729a450c8feeb821c41a06d4bca338d2121b7a010c603
SHA3 e788a5bc64147359c6343cec773fc54ea0bf9174bc37850d4708e3e5ba276527
Preview

10124

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x152
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49051
MD5 ff7110580b8339ae5c3177248cd86f28
SHA1 c86171d538549724740ed7d5bdd784edfbe282e7
SHA256 faf9686e3bcbf27686fa92a97fee9c72db32240fef4295aad14403935c9bab8f
SHA3 8cd6ba7864898ce057585c51629c03dc57c71ef1c8511faf0bcc8224a8e8c476
Preview

10125

Type RT_BITMAP
Language English - United States
Codepage Latin 1 / Western European
Size 0x828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.67246
MD5 9eb7f2c8f73508a28a7c701e35a9072f
SHA1 b01786342e84083bda8c94534c2ef2441f3ecb6d
SHA256 6ea607ae2e99a0d4d663d8f7d778228be0fcfc96f2f61b5e37641dc1512915bd
SHA3 10e1ccf1b01c53355dd05e1b1230116fda59dfcccb7e296383563cbb2fd69e9c
Preview

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4219
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92269
Detected Filetype PNG graphic file
MD5 f83ae523dacb18adb53124c75a27104f
SHA1 bd1202004e1ed256c7cee2662292ce251b7de169
SHA256 6d71e56307d23455a43e9b5ec46b2e2fcc122d5595d34081b5daf6f254693c27
SHA3 0b8a3e1097f66dc680b91f8596ea3f77a1683dd9d517bf10321802fc2bf15a79

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20203
MD5 26e637b4e79a76aba8e0445b07485422
SHA1 780a340de712afd0389af22de866c3f316631a4e
SHA256 921bcea8731b581e6cf969dcffc8efa05e77757bbfdefa686352abb12cf5c219
SHA3 36d0f14b23d1e7785a0c34a6f0be92093d0cef923cc42834ce4e06ac241592a1

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.64317
MD5 5912065c0786cb4d32696a1881537376
SHA1 c8ad41a9dc330aff67cda5659ad4f4432fc2884f
SHA256 797ae6ee57fc8787cc89dd7148705e0d848ee289b8a94ca84b1ca362a8ae97f3
SHA3 537736f5632d559b471c53adc661f5f8ab8f245c6fb1e3a01fb15e2249a13748

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.01395
MD5 88d4a4a8086589f9c30066c6e711256c
SHA1 0bc0fb3442e10d35454e348da46714eac4d840a3
SHA256 3bc64f74844b2eab99f1dc4cb0e754f8baef95d977395a11fbca90be9d4b44a4
SHA3 fc8c26290eb5b65de720d5351dc222f668746157edbb921b691b1f653d9f493d

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.14561
MD5 fd23ed9198da7eaa6437fe6be35dff54
SHA1 a448d6743a3255d721ecee176685cdbf569e3281
SHA256 5ab611793b968cc4f12f11e6679bd817059f8418e87967bf13af6936c4c2b2eb
SHA3 7d88a9c0e08b3e8e6e5228b42479ac1070445b46e7044210d4351d189fa61fd3

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.62589
MD5 bf2a3fcaf615a2720480596225ca9097
SHA1 2104aa4a633a7004210c3945d9c77a857866a4cd
SHA256 d500199623a84a8346cae46e365f6705ea4bd355e5efcf3425a40857001e2950
SHA3 025e01544099be09f839700b352658d0e10e1fbbf97de85b14939c8337343d73

213

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x5c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00642
MD5 abfffe4e3820ef1e6be1e3edbb928850
SHA1 62d1b7774375c47f1632cf5480ad314642a252fa
SHA256 3e47269c9d1e169a319f9149f3edcdf81c071134124d0d00a0f86ceab4107a1d
SHA3 15967e8ac79649521f57cb14973344ccece724deaa60d1f5790d23ea86cad023

214

Type RT_MENU
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.46729
MD5 2de7f9dea9df0162fb0829e4c918afb9
SHA1 5ccdd5f933a3b7a48886c58280d863377afa21a9
SHA256 49289cf8f62077d89ba6e8ac99f52b68d6471a1ea17e373c6042aacd07399b0e
SHA3 c51e51fea0d3c1a44327fcd4ff8b0d920438c8f86e51421753f8a83e7052bb63

201

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97566
MD5 b9b65d5665b18db6184ce81b485aa7a4
SHA1 a0927bb2b99bdefa1134023c23a5931fd6889a8e
SHA256 fd13c023359af19820646f58138d7cba69a82b5a55ce2f42d7dfdb34098ebdf7
SHA3 4eca1f6d50a21935c56a6a8965301a805ff1c91b079927c15838b0471f2afc6e

202

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2a6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41539
MD5 eb0e145cf85121d86fd50d9d8c907a10
SHA1 97b5961b46ff4366de4d0f01db92d72da12245a0
SHA256 ad1d4b5d0ccfc7e23f7e4120e57a840f4e60eaad2817a6d348064da78189115e
SHA3 7404649e829e2e189e8a09c0c2f010eb0e207468a1cba42591c8aca0c04ca1ed

203

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x3b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37343
MD5 b363180143ad11331e36957c97adf1d8
SHA1 8aeb68fc1d7997c14eb14cc74697e4f716b23293
SHA256 8995344377adca3633e297ef55e1e2ef45e973152d27860e6a732ff3807fc178
SHA3 1a26e31ff8a8ea45eb87cdfb318cb50c5e2dd6bcab572a6354b68adbf34906cf

206

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07552
MD5 22033b9a0e3bd4f361e5a92e01dde47e
SHA1 7abfabc5b58e4d95e97a7c35408f79deade739e9
SHA256 3addcedd607a71eec21678478de4a532aef743d19aba72e9f0e7dc4a9cf35536
SHA3 9df51edb3635b5054b22e7c25187ff17ba9d9b4e168aac0bcb8429f46b71bb3a

211

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x204
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40149
MD5 90b400d106635a3a5b671956fbceed8c
SHA1 0e541d3848dd6e009671ffc25d59b2dfee00de8e
SHA256 f94cbc8bd64f4e2fb6ff64b19a63707ed6848569e68172c927ee77e31568aabb
SHA3 fe88d8bdef7f0ce53856d49cda64f1a128eb1267c5e4c683c964b697b188867f

212

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x282
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34343
MD5 c094d1476a8b82860d976fb331ea1d6a
SHA1 f1f370efec5e41851bf4995cccb01a016c10bc21
SHA256 faa9574306006ba6a9be3d6d19ec334f94f0d35ab106fa3757cdfb91c0d1cceb
SHA3 9c34d169ba0d84bae90cfcd8f26755b3a944bd259a0514850613a344c469d5d4

216

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95251
MD5 3bef094dbf2ea14e852b5115dfc27c01
SHA1 e4543f8ee40821ff4bd5a159c6eac14740507600
SHA256 2d383bc8ee9892418d03cba3ba938ebc11483ceec2923a171aba8148e31a5d74
SHA3 9babb54cedea25fb8dee9c33d3cd6f98fd3c954e65d7a95e62807c4e21e23344

217

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x146
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02577
MD5 d2411f85ef7864376e51e9dde17be67f
SHA1 4660271ade07f24a20996964e2f82d697ba996dc
SHA256 7cfcbb32df3d4275599d0b293feed4ab24ceb065aa62eafebd109c03533a9531
SHA3 c88ac3822c822980bf676786b4b2ebd2f35e7a25de8b4a425312129196d886a8

218

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x226
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32165
MD5 b3cd660f4cf22085690d7e577416848c
SHA1 c41cd85fae30918284b544b1a260e2e6858531b6
SHA256 e85bd20dae0d64bd3f751c16133cbf3d75ecb771d756ececb430c9aa6ec910a9
SHA3 5a5513b94c5bf664ecedaa1ec6048a30c5de86c67bf7b16dbe024d0805422111

223

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x388
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35341
MD5 d1f000af3b5ee3f81773b8427e216c71
SHA1 eb391879ecc051b3c1d695318eedcb1b35be1430
SHA256 25a1b1f3952e5c00c460cfe5ec036b3ab42b6d5fab4e9c5d5b549875dfd7156e
SHA3 c9cfee0e040b78dd1e11ba3ecdec7dc82164bc331722b2af28ffc626bdc2a3d1

225

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11595
MD5 d586b4c2b2b822483a616c0131f3987a
SHA1 b4ed46162c1f453fe0d0f138d5038df718093881
SHA256 ad6fda587ab7a3f8424d37499a31fe22a168ae4dc28a75d355515ca684918405
SHA3 b2f7570787e13a977a90fbfd93c01ca6a9d36eca98bd680e552217efe1175a75

2000

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x136
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10615
MD5 e956f800d346d4d9836e188482c383b6
SHA1 33c2d6be547d8f6c9281d5c4b8a4f438dcab8c57
SHA256 2fdf71fc373ceeb67cdba7abdb6181b0b0f1fc6394abde884def028c01df22e7
SHA3 7a546374030dc54ede31055b791738fb0d2f0ade37b521511d93502e273f2da4

10123

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x4c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65407
MD5 1908f46cac6eaed1a2e79513bb135f67
SHA1 3ce39d89c18bc4f425582dfe56429bb1a06cf9c6
SHA256 477c4e79c878015fb0f6d7fab9bb703bb9cc1a072fadb6bd2c8c73c91baf757e
SHA3 15c0545ad62484a2e7f7f6660afe409e6e19dc1a3125250176660006781c82c7

9

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x45c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37783
MD5 c7348aa264060f3ab4e201d5bdb88fe6
SHA1 494f800e8011fedaea99b22a8f9b07c9c053d658
SHA256 f9fcc2ef47b098b85a50e480c3cd78c2fa8c4545db342b39025393599351de57
SHA3 26a4a5d6ba962e0b1b1a9f2b1aff101e80253e629619b7190ffe9e373b0b627a

10

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x760
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35254
MD5 76540f73e4f44f5742f792679aad0e7e
SHA1 4d86dfb93069823df2d18f9acc2c97558841e9fd
SHA256 696500e68ea8a157ab57f0ce0046a8cfe69317a897032b1f4a5f7cda05d5af18
SHA3 906be7ed66a8af5005f49c0a1996c87f4eda2b0724af5dd9c7a8e9625117f5ce

11

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x2f8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31743
MD5 29c8d9bfecdd111a60d028c6ded13548
SHA1 23055010ab79d42caa2df439cd430f1bbe541fb2
SHA256 dd1e05c4ba3d0764e0621a426bfe69ca3792b0da3f80ada3af9df40449e7790b
SHA3 947d738729615bc2c4439833736b5fbbaf24e9184aa3a7c21d5fd19edfb38ecc

12

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x598
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.23118
MD5 066e47920e63c033ef6fa01c4d9bda61
SHA1 6bee24a095cd99b626f0f401ed86f16ef6f3fd8b
SHA256 b9b343517562cbafe4a944cc8d12189cb7cf5a68fdc4a6520788890caf432db3
SHA3 e5341016a9d5ca4932f674a49ea82fc7c8a573b558e9261cea96dbdb819a212a

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x334
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35766
MD5 b2b3e06fe95ebb4236eb9a3686f9487a
SHA1 b8ba027f645425e4e3c4b1c1b5bd1bb85eff99db
SHA256 f56d3df6a367f3c4072fa0493a8994874970a1e362a97c39b3de1eb88ce8e222
SHA3 bf72a8e403ae6e0f6a3be80d0cb7512dd11f316a16870182b2e2cb19258ab47f

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x308
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16649
MD5 3be9a36a7f74b04a62a9523892acea11
SHA1 ce0c6f8120fd39bb9b4eb73b24372a8690a0adcb
SHA256 bbd9734f361616c3046606bab309ebcf80e2d330ce2b2d4c7be67bacdd4b1b60
SHA3 58681a73e0dc3d13fcaf01ff77e413f76b481e0ffdf509de3b4ca1f001371744

15

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x274
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16338
MD5 f16d63ceb9574f1cf089b7c135555554
SHA1 e8680a65d21de78604f7e077fc9918d8bc992e93
SHA256 63e35ada4a3b2149f713a72687104a4777914f2e7092869aa450531fb87eba5b
SHA3 0efefb9076c6ec19f978b3952f99dcc925767737444df05f8f958aa5b9f5f7eb

16

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x164
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04011
MD5 c1e0a4e1a928fc2e80c61135a4520e67
SHA1 064d477f7e1a96b07fdd2a5841f5d3db035c4f38
SHA256 90a773af7f8a0fb902848e606d94fdd1f0d0970d872892617788acc1b06e444b
SHA3 1da1c8a65ea4149c95a8777c4cce8821c038a06282db5fcb22bb653b230fa709

17

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x520
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.3657
MD5 f6d684601b6a329541b4d36003ad4e32
SHA1 9ae927f8cfc7d7cc9be5a74281d0cc2a698a0628
SHA256 79f41692abf816b5679673adb4746996ff01f4255b59061256e98c49da8332e7
SHA3 e28046989e54dd3853b87c54212d3ec1f9b0597863e58030fe0df60303ff57bc

18

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20151
MD5 dc0e178588fce9302d14064c390cf22d
SHA1 9546f46d3a79fd3c5a2da8fdca4654f0aa74d3d2
SHA256 472888fd1541a96cdf7cfd6b29b4610d32b85821d0316138dc49b21be65ec351
SHA3 4898046a334fc1b7a141d5dd621aacdc03c199e966f629527b310cf730669e06

634

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0751
MD5 7e73112de5acaa97c7213fc14d96ccc0
SHA1 bd5d869ed232c978594a3bd6d3df96d28502338b
SHA256 4d6ee08852cf885069655460144391767a8153c29cfb97cb5f67f2bd87413e05
SHA3 1807415824e80407ed8b84b3f89d24c637f24978808843c0dbfe4f586f75d850

4063

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x216
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35239
MD5 37d36ef637c1eedcbc9f55c93ca696f5
SHA1 52fde54dff5438759b55653e3847110153f582ee
SHA256 783d14215f20390eed1996c78ed95e304b7d66bbd1bdd1f343eb9b9be9e5e2c1
SHA3 ac12c5a4cf75a44feb5ceefdd56d1f0ba50112c165663682bdd7de83e53e5263

4064

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x574
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43466
MD5 7649cdfb71bacb86a9761c8c2bfa837b
SHA1 db0c9a91df3f6cd6d7c0801850fdf89e08520a63
SHA256 2a9b06c5a4e3455772dff524ce1986fecb18b699408cb0efa54e580453f69721
SHA3 c395b6cfbe183e4dd1d4172e80cbdfd58fe73101a969a444b3eec87690817831

4065

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x660
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44025
MD5 73f6cadef66fe41cd99e1f2dce0b273f
SHA1 7ebf195fca72736b475fbda3cc5a369157a8cbc5
SHA256 3224f6542bed9e3e7bc42c754f4864fabfc03e531bf18f76f0f5a35cf2fdb193
SHA3 cce6002143a84b79ce11029c3f9275dd0e9bc4bdeb73ab36285c6ccbf16bda71

4066

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90658
MD5 70dc3e3ea81ae31e077223f0c0544c9b
SHA1 b42b274b0aa0505bac290d22f45d7198463f40ec
SHA256 16664781c6daa6c0bbbb4177f38a69dda7e202f6f976734cbd906346f5e1441d
SHA3 e038315f2b387965823e3f1c0d7da3251cffe0878a98bd43d0e6f28c52f3548b

128

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77685
Detected Filetype Icon file
MD5 a8c9c6a0fce9d0f79fdc353af3bbae72
SHA1 f0075eca24f5f51d5ab60d3f9ebf96d5f6f3af42
SHA256 f71fd56f3c34b4678a7f627f6db10d8393cf0e4c8c6d837c7037765d5932c18a
SHA3 a3c8a47115a8185597b3065257189603c97d862cd860e5f73cd1a57fa360eca9

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x2d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35788
MD5 696237473e30f18aa486967c17491f43
SHA1 5be8bdecbd167a76c04e6865f24f0bc61ba3aaea
SHA256 4c01eed5de5985a980fc4e252a5cb25bba752d5c58a302a200acbc7a2129086a
SHA3 eabc768f201941a5349dcf37339f607d3a93aa10c3e46410eee01ee792accdc1

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x775
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.18998
MD5 78e38259eebbf0c526aafc73463a9e6b
SHA1 9502aa310e7e47fa97367c084356db446c924b0c
SHA256 b43343091e7afcfc5d59698191d4071591bd8543f3f14a390ca50f18f030bc22
SHA3 f231e74e096a09dc8fcc5b5a4002d3cfdf1f95c046b17a44c1c3053ef90af345

String Table contents

Setup
This archive is corrupted.
This archive has an unsupported version.
Windows Installer could not be started.
An error occurred while reading the file.
An error occurred while extracting.
Select the download folder.
%s can not be installed on systems with Windows Installer version smaller than %s.
Error
This package requires Windows Installer version "%s". You have "%s".
Please upgrade your Windows Installer.
Checking integrity (MD5)...
Corrupt file (wrong MD5 signature). File removed.
%s Options
Extracting the main application files...
URL
Status
Command Line:
%s [options]
options:
/? or /help - displays this message
/extract:<directory> - extracts all files in <directory>
/listlangs - list languages supported by this setup
/exenoui - launches the EXE setup without UI
/exebasicui - launches the EXE setup with basic UI
/exelang <langId> - launches the EXE setup using the specified language
/username - username used by the proxy
/password - password used by the proxy
/exelog<path_to_log_file> - creates a log file at specified path
/exenoupdates - does not check for a newer version
<msiOptions> - options for msiexec.exe on running the MSI package
Name
Action
Skip
Download
Install
Installed
Not Found
Open Site
Installing %s
Press the Next button to download the prerequisites.
Press the Next button to install the prerequisites.
Press the Next button to open the prerequisites' web sites.
Press the Finish button to install the main application.
Pause
Resume
Required: any.
%s Setup
Required: %s or lower.
Required: %s or higher.
Required: between %s and %s.
Found: nothing.
Found: %s.
Version
This prerequisite is mandatory. It must be installed and can not be unchecked.
Name
Press the Finish button when you are done and ready to install %s.
Press the Next button to install the prerequisites.
Status
Pending
Installing...
Installed
Error: %s
Installing %s from: %s
Some prerequisites could not be installed. Press Back to return to the prerequisites list.
After launching all packages some required prerequisites are still missing. Press Back to return to the prerequisites list.
All prerequisites have been installed successfully. Press Finish to install the main application.
Welcome to the %s Prerequisites Wizard
Prerequisite
Some prerequisites could not be downloaded. You can try again or remove them from the prerequisites list.
Pending
Finished
Wrong size
%d.%d KB/s
Some required prerequisites are still missing. You can try again or remove them from the prerequisites list.
%d hr %d min at %s/sec
%d min %d sec at %s/sec
%d sec at %s/sec
Size
Paused
Progress: %d%% (%s of %s)
Downloading: %s %d%% (%s of %s)
Download Finished
Paused
Opening site of %s
Downloading %s
Extracting files from archive...
Extracting file to %s
The %s file can't be unpacked. Error message: %s
The Java Runtime Environment version 1.5 or later must be installed in order to unpack JAR files.
Another instance of setup is already running.
Found an acceptable version.
Error: %s
You must reboot your computer in order to continue the installation. Press Yes to restart now or press No to abort the installation and manually restart later.
Confirmation
Unpacking file:%s
There is not enough space in folder:%s
Please free some space and press Retry or press Cancel to abort the installation.
Preparing...
%s Languages
Searching for prerequisites...
Install Location
Product Name
Question
An upgrade of the selected instance will be performed. Do you want to continue?
Upgrade all installed instances.
This package allows you to install multiple instances of %s. Please select the option you want and press OK to continue:
Evaluating launch conditions...
%s cannot be installed on systems without %s
Connect to %s
The server %s at %s requires a username and password. Please enter them below.
Cannot access URL: %s
Failed
There is a newer version of %s (%s).
Would you like to download and install it?
Checking for a newer version...
Failed to download newer version (Error: %s). Would you like to retry or proceed and install current version?
Failed to read from file "%s". Error: %s
Failed to write in file "%s". Error: %s
Instance
Default
Version
Setup package was encrypted using AES 256 algorithm. To continue the setup process, you should provide the password needed to decrypt the package.
A reboot was initiated. Application will close automatically.
Deleting extracted files...
Unmatching digital signature between EXE bootstraper and MSI database
Back
Next
Finish
Cancel
Downloaded file does not have expected size
%s mandatory prerequisite was not correctly installed.
Searching for installed AppX package...
Installing AppX package...
Removing AppX package...
Invalid command line
Unable to init windows application
Internal error
This installation package is not supported by this processor type. Contact your product vendor.
Advanced Installer
Unexpected exception.
The application ran into a problem that it couldn't handle.
Sorry for the inconvenience.
Exception (at %2!ls!:%3!ld!) - %1!ls!
STD Exception (at %2!ls!:%3!ld!) - %1!hs!
A COM API returned error: [0x%1!lX!].
%1!ls! %3!ls!:%4!ld! %2!ls!
Could not allocate memory.
Parse error in file: "%1!ls!" at line: [%2!ld!] column: [%3!ld!] (code: %4!ls!).
Unsupported file encoding.
File "%1!ls!" could not be read.
File not found: "%1!ls!".
Error opening file: "%1!ls!".
File "%1!ls!" could not be written.
Unsupported command file format. The supported file formats are: ANSI, Unicode Big Endian and Unicode Little Endian. The first line of the file must begin with "%1!ls!".
Value is missing for the parameter %s.
Invalid "%s" parameter value: "%s".
Unknown parameter:
Maybe you should use instead:
A required argument is missing: %s.
One of the following parameters is required:
Null pointer exception.
Error parsing XML file: "%1!ls!".
Invalid XPath expression: "%1!ls!".
Command "%s" is unknown. Maybe you should use instead "%s"
Invalid XSL transform.
Invalid input filtered.
Your input has been filtered because it contained invalid characters for this field.
Your input has been filtered.
The port number needs to be in 0-65564 range.
Error calling MSI API: %1!ld! Method: %2!ls! Table: %3!ls!.
Error calling MSI API: %1!ld! Method: %2!ls! Table: %3!ls!. Extended Error: %4!ls!.
Provide a valid Offline Registry handle.
Invalid hexadecimal string "%s" in registry value "%s".
The version is invalid!
Underscore can be used after every digit, except for the last one.
Invalid version format, expected: major, major.minor, major.minor.build or major.minor.build.revision.
Invalid version format, expected: major or major.minor.
Invalid dot sequence.
The version is not allowed to start with the dot character.
The version is not allowed to end with the dot character.
Each part of the version number must be an integer between 0 and

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.9.9.0
ProductVersion 3.9.9.0
FileFlags VS_FF_DEBUG
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName RealDefense LLC
FileDescription MyCleanPC Installer
FileVersion (#2) 3.9.9
InternalName MyCleanPCSetup
LegalCopyright RealDefense LLC
OriginalFileName MyCleanPCSetup.exe
ProductName MyCleanPC
ProductVersion (#2) 3.9.9
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-Sep-04 14:52:04
Version 0.0
SizeofData 75
AddressOfRawData 0x19e008
PointerToRawData 0x19d408
Referenced File C:\JobRelease\win\Release\stubs\x86\ExternalUi.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2019-Sep-04 14:52:04
Version 0.0
SizeofData 20
AddressOfRawData 0x19e054
PointerToRawData 0x19d454

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2019-Sep-04 14:52:04
Version 0.0
SizeofData 1072
AddressOfRawData 0x19e068
PointerToRawData 0x19d468

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2019-Sep-04 14:52:04
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x59e4a8
EndAddressOfRawData 0x59e4b0
AddressOfIndex 0x5d8a90
AddressOfCallbacks 0x5753a4
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0xa4
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x5d3074
SEHandlerTable 0x59c2f0
SEHandlerCount 1862

RICH Header

XOR Key 0x42eb0adf
Unmarked objects 0
ASM objects (26213) 14
C++ objects (26213) 179
C objects (26504) 19
ASM objects (26504) 23
C++ objects (26504) 98
C objects (26213) 26
Imports (26213) 3
263 (26213) 2
Total imports 669
265 (VS2019 Update 2 (16.2) compiler 27905) 290
Resource objects (VS2019 Update 2 (16.2) compiler 27905) 1
151 1
Linker (VS2019 Update 2 (16.2) compiler 27905) 1

Errors