| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2019-Mar-23 23:18:48 |
| Detected languages |
English - United States
|
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip NSIS Plug-in |
| FileVersion | 19.00.0.0 |
| InternalName | nsis7z |
| LegalCopyright | Copyright (c) 1999-2016 Igor Pavlov, Nik Medved, Marek Mizanin, Stuart Welch |
| OriginalFilename | nsis7z.dll |
| ProductName | 7-Zip |
| ProductVersion | 19.00.0.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to AES |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Safe | VirusTotal score: 0/72 (Scanned on 2026-04-19 20:35:26) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x110 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2019-Mar-23 23:18:48 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x50e00 |
| SizeOfInitializedData | 0x1fe00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00041918 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x52000 |
| ImageBase | 0x10000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x74000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
LocalFree
FormatMessageW GetFileInformationByHandle SetLastError DeviceIoControl GetModuleHandleW GetProcAddress HeapAlloc HeapFree GetProcessHeap GetSystemTimeAsFileTime GetStdHandle WaitForMultipleObjects GetTickCount GetConsoleMode AreFileApisANSI SetFileApisToOEM SetFileApisToANSI GlobalAlloc GlobalFree lstrcpynW lstrcpyW MultiByteToWideChar WideCharToMultiByte FreeLibrary GetModuleFileNameW LoadLibraryExW GetCurrentDirectoryW CreateDirectoryW CreateSemaphoreW RemoveDirectoryW SetFileAttributesW SetFileTime GetTempPathW GetCurrentProcessId GetCurrentThreadId MoveFileW FindClose FindFirstFileW FindNextFileW GetFileAttributesW GetModuleHandleA SetEndOfFile GetCurrentProcess GetSystemInfo GlobalMemoryStatus GetProcessAffinityMask IsProcessorFeaturePresent WriteConsoleW HeapSize GetStringTypeW DecodePointer SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW GetCommandLineA WaitForSingleObject CreateEventW ReleaseSemaphore ResetEvent SetEvent InitializeCriticalSection DeleteCriticalSection LeaveCriticalSection EnterCriticalSection GetVersionExW VirtualFree VirtualAlloc GetLastError CloseHandle WriteFile SetFilePointer ReadFile GetFileSize CreateFileW DeleteFileW GetCPInfo GetOEMCP GetACP IsValidCodePage FindFirstFileExW SetFilePointerEx GetFileSizeEx GetConsoleCP FlushFileBuffers GetFileType HeapReAlloc LCMapStringW UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter InitializeSListHead RtlUnwind RaiseException InterlockedFlushSList EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree CreateThread ExitThread FreeLibraryAndExitThread GetModuleHandleExW ExitProcess |
|---|---|
| USER32.dll |
SendMessageW
FindWindowExW SetWindowTextW GetDlgItem wsprintfW CharUpperW |
| ADVAPI32.dll |
SetFileSecurityW
LookupPrivilegeValueW AdjustTokenPrivileges OpenProcessToken |
| OLEAUT32.dll |
VariantClear
SysAllocStringLen SysStringLen SysFreeString VariantCopy |
| Ordinal | 1 |
|---|---|
| Address | 0x2dbdf |
| Ordinal | 2 |
|---|---|
| Address | 0x2dc90 |
| Ordinal | 3 |
|---|---|
| Address | 0x2dd4b |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 19.0.0.0 |
| ProductVersion | 19.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Igor Pavlov |
| FileDescription | 7-Zip NSIS Plug-in |
| FileVersion (#2) | 19.00.0.0 |
| InternalName | nsis7z |
| LegalCopyright | Copyright (c) 1999-2016 Igor Pavlov, Nik Medved, Marek Mizanin, Stuart Welch |
| OriginalFilename | nsis7z.dll |
| ProductName | 7-Zip |
| ProductVersion (#2) | 19.00.0.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2019-Mar-23 23:18:48 |
| Version | 0.0 |
| SizeofData | 724 |
| AddressOfRawData | 0x5e06c |
| PointerToRawData | 0x5d26c |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x100652b4 |
| SEHandlerTable | 0x1005dd50 |
| SEHandlerCount | 199 |
| XOR Key | 0x3258fc08 |
|---|---|
| Unmarked objects | 0 |
| ASM objects (26213) | 12 |
| C++ objects (26213) | 152 |
| C++ objects (VS 2015/2017 runtime 26706) | 35 |
| C objects (VS 2015/2017 runtime 26706) | 16 |
| ASM objects (VS 2015/2017 runtime 26706) | 20 |
| C objects (26213) | 19 |
| Imports (26213) | 15 |
| Total imports | 190 |
| C objects (VS2017 v15.9.5-6 compiler 27026) | 43 |
| C++ objects (VS2017 v15.9.5-6 compiler 27026) | 131 |
| Exports (VS2017 v15.9.5-6 compiler 27026) | 1 |
| Resource objects (VS2017 v15.9.5-6 compiler 27026) | 1 |
| 151 | 1 |
| Linker (VS2017 v15.9.5-6 compiler 27026) | 1 |
No comments yet.