b764dacf3964a8559fd80a4c697fdab1618294b402f5c4ef49f6d0f782f09123

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1992-Jun-19 22:22:17
Detected languages Russian - Russia

Plugin Output

Info Matching compiler(s): Borland Delphi 5 -> Portions Copyright (c) 1983,99 Borland (h)
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Can access the registry:
  • RegQueryValueExA
  • RegOpenKeyExA
  • RegCloseKey
Uses functions commonly found in keyloggers:
  • MapVirtualKeyA
  • GetForegroundWindow
  • CallNextHookEx
Can take screenshots:
  • CreateCompatibleDC
  • BitBlt
  • GetDCEx
  • GetDC
  • FindWindowA
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The PE header may have been manually modified. The resource timestamps differ from the PE header:
  • 2000-Oct-05 08:53:02
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 154d516cbf80cb057dcf5198dfbe7200
SHA1 bb31165c99b8db7c13c98d6e4681e91201e22af9
SHA256 b764dacf3964a8559fd80a4c697fdab1618294b402f5c4ef49f6d0f782f09123
SHA3 0a7b771f093b46e5c2157aa1845c066e58289e83866c62aa0b35c01ab30e00c0
SSDeep 6144:h/IOnPH59lVnfKEuP891VTbHy11Cx82ujIbo5YRU9uZ4Ul:hAOnhJfL1TwLdMboSyYn
Imports Hash 10d1e7f7f153da6a0a0fa9873f8925b8

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 1992-Jun-19 22:22:17
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x42200
SizeOfInitializedData 0x1b000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00043128 (Section: CODE)
BaseOfCode 0x1000
BaseOfData 0x44000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 1.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x63000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

CODE

MD5 7994211bb65da4f8370a27f9f3c86284
SHA1 80214321fe5bb033d8a3be25671e0f0016ded20a
SHA256 cfed88b219e4fe561c6199e1305b71d4a4e39cd2130922b71ca70d2501c959da
SHA3 ac3da618a9fb507391e1b93cd8494fde1b5feb9b9dd9a903afb67188b1dd25b2
VirtualSize 0x42170
VirtualAddress 0x1000
SizeOfRawData 0x42200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52239

DATA

MD5 6cadaa0a05d3089aa8f46b5a9a687f68
SHA1 50f966cc8597739693c77ae787e1fd42fccc8bec
SHA256 bbc6e6c3f1f4ed7919a3f7b61633d756f8a95ce88005448d06d5be2d4b0b52b5
SHA3 02ed320a242a14517db729cc126b7fdfc5e0caa41cdaccf5283bb6d180bf3b65
VirtualSize 0xd64
VirtualAddress 0x44000
SizeOfRawData 0xe00
PointerToRawData 0x42600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.9129

BSS

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x84d
VirtualAddress 0x45000
SizeOfRawData 0
PointerToRawData 0x43400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 fdfe50bb7ba4b4f9ceaf806503461fe2
SHA1 c695fd1c8d18004500c2635f72d5b564494a3f15
SHA256 3ee87e5f2452aff92c08a09efc1db543bf3e62d833bee8208da6ef47162753b4
SHA3 4f9c30ebb2f5c7461c44a4d738a3ce147d63555dd69d3694fab57300797d31ba
VirtualSize 0x1efc
VirtualAddress 0x46000
SizeOfRawData 0x2000
PointerToRawData 0x43400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.80969

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x10
VirtualAddress 0x48000
SizeOfRawData 0
PointerToRawData 0x45400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 44ca386e1091f31db72cc5a81fb5e8e3
SHA1 5411698440448009f8a585de9db60ecb2ff40e62
SHA256 a64c121441212204b5e7f09781636dfff532d271f3b1c3018e120a8cb2452d4e
SHA3 f5afef5140f5312b9d22e779e115453f8a4ee2058cff8f85bfa6158860aaa536
VirtualSize 0x18
VirtualAddress 0x49000
SizeOfRawData 0x200
PointerToRawData 0x45400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.200582

.reloc

MD5 f8da0f8bffcdc0990299941d0ed83266
SHA1 c5c931955b51997cdd6a49573e540346b2c5f7cb
SHA256 39b1d89db306a148c8545b2730b22f6502bf9a929bd746078f3b72060f815e27
SHA3 09c2857481c39590b1780ff8a42e70613c74b14d665d79945338be2248673fca
VirtualSize 0x48d4
VirtualAddress 0x4a000
SizeOfRawData 0x4a00
PointerToRawData 0x45600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.62285

.rsrc

MD5 3ffd73224f9070f3b1d518e19ddc0241
SHA1 13ef3aca57d058e97ad4eaf2290f50c1e0bd5ad1
SHA256 682305cfbc25f2faca152d0c0f4a4869e0ec84ae9c009bb3b23df9a694fd6a8e
SHA3 14c6b96d85728554f3f741a92d813e1d3554bbbd625d52e2b6f4eb26c4807eba
VirtualSize 0x13600
VirtualAddress 0x4f000
SizeOfRawData 0x13600
PointerToRawData 0x4a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 3.28308

Imports

kernel32.dll GetCurrentThreadId
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
lstrcpyA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll VariantChangeTypeEx
VariantCopyInd
VariantClear
SysStringLen
SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll (#2) GetCurrentThreadId
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
lstrcpyA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll (#2) RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll (#3) GetCurrentThreadId
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
lstrcpyA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RestoreDC
Rectangle
RectVisible
RealizePalette
PlayEnhMetaFile
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsA
GetTextExtentPointA
GetTextExtentPoint32A
GetSystemPaletteEntries
GetStockObject
GetPixel
GetPaletteEntries
GetObjectA
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
ExcludeClipRect
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectA
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileA
BitBlt
user32.dll (#2) GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
ole32.dll IsEqualGUID
comctl32.dll ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_SetDragCursorImage
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Remove
ImageList_DrawEx
ImageList_Draw
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create

Delayed Imports

1

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

Bitmap1

Type RT_BITMAP
Language Russian - Russia
Codepage UNKNOWN
Size 0x10428
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.75107
MD5 539d9cab093e04905b3d464bb191dbeb
SHA1 e128aa9a3bab95be8516047ede24e1edd983e0ec
SHA256 68ade045300620581330bc1b7cff2f1786e8011a4f862478e53f9fdee55e0f59
SHA3 aa0593c29e1fe2e5032fb08797045749d1c1f89bc1fbcd6f14d9075581b4358c
Preview

1 (#2)

Type RT_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.58136
MD5 ed02d63ac65d81c88fcdbe419dd3f119
SHA1 6ac248df375b7b0b7c63d47341017f543b2219eb
SHA256 e0c6ffcdd20d0f7f827555eccf5ffb26487871081ff2f19b49b95de58485f177
SHA3 77d7f0cf2ff687386e2ebe923fd77154f6f1311b1c18a557e293324f8a4c5e7d

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x6c
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.40601
MD5 d65f06475a7678e467e466e2c28665f9
SHA1 06534ea72200c3df08101a42bd8aa844d1fb6ff4
SHA256 637b450b12cea0c63adab53bc472a8a8a2bd2dbe9736d6ee17b3be93c7fd6a90
SHA3 d6d195d3263cc2f71509b85bc4c1457dfd8a64ba8537068518d690c1be1e4a81

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x240
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.23812
MD5 81d46d17982cdf0a4bd59a9753b003ed
SHA1 11477d149a44f844d396e19b0c2c935aeb27097f
SHA256 20501959b2d7c705c0238057026952e15a23185e49422e1a267e1c6888643e6b
SHA3 37d95b33005ac4604b98136f7da17a0a3c2e59bfb3ff2bc0084a3066a9cb5a34

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe8
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.10555
MD5 4db0c662b2f1091a09ca8796fbb5178e
SHA1 445b4eeaa37d24c42f2403c0566ce2884dba7e02
SHA256 560b073323f1ae8c193ede3cd59bff0ec2cd137b37c900c836bec34f7027c064
SHA3 fbb685fbf2183438c67c1e55c4a1e28d210df84260aef45ee1fd9d86dc7c5f6e

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x24c
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.23129
MD5 c774e98888aae16364d9cf836ad71192
SHA1 05ee1a3c81c941c237cab8b4ec2d3837d5635c1a
SHA256 4e620d2383ff0dc6cad8d0d111f925f5483d8f2e1b03d5aa98549c3d2272354d
SHA3 869174da8f9c4aa084dcdc3299d4725338dec1281e979b3186e722098d71ff27

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3f8
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.20722
MD5 9b7d8a5610d062054ddd1f2d932b9cb3
SHA1 f38ded7258b11103866d7494d54cbb9c58c7f94d
SHA256 6cf25d91ddf2e65f395b176076374b77a4ad8dc42e876c8dd0743ad43cb1c740
SHA3 33f526db46c40d248561b1c45f8042d0ca8dcfb02efe049f22e12c75ca6a139a

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x39c
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.20322
MD5 b4f6cb8e7b3a347224ed5f33c3153239
SHA1 6561ff93b167cf6e9dc316677503c853e06e96c5
SHA256 8018bbe646f2742abfd3187c0657dc7c01bad3a451d59bc12a6a919c603b808b
SHA3 f5abf93accea762a7946ac1422f2b2b6d6237d3ba83ee81a427818d68e94e946

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x354
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.16353
MD5 d8a954d760d326307a6caed641434d57
SHA1 e4033ac40088278132a8db8a37e04068f52d41a2
SHA256 a9f8541b062effd97d495db5e70264ad0668ddfbb1ebb556a868c71f8cfc5cff
SHA3 0a60fb34ed3842d8ef70c2b2319a5a0bd75e4a1b98026243ca9bcf16e669d5c8

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xf4
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.94341
MD5 aead513017e6566240e7ac86b5480759
SHA1 648ee52447fd9b798760ba8dc84fda558d30f287
SHA256 0bab6e5a1259540a8def510ea55891a64d06c7c40dbbe8eab251f5d60993aabe
SHA3 9e2d3b1ee751fdb86e8834cea1ccd92a2af585a66b9319c1fb664369f5ef8180

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xc4
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.8794
MD5 654a3b0e552431bce845d4873d01d0cf
SHA1 9b3d44f51cea9362bcf7c258974a4a767df915cf
SHA256 580d974dbf7953e0e47920170ddb9e8dba22e8f3561e059ce4f3774056c876a1
SHA3 40a1765801c78b03ba59f217f7767147f65598ecf74ebe7fb848546b5ce9ee6c

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2d4
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.25775
MD5 e95b19d0a5edb7c40d8b6ff36df477ae
SHA1 de7ab8b2a8c45e0e3976eb3caff7a5cd075c421c
SHA256 95030eb4bbae2cb52584bfaebada17fc810099492c89713c3bdeb74f8bc7955e
SHA3 8c779debbecc5c4c7e7007d8edbdf7919cde6a9819a7a082a15420574a49107a

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x35c
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.24062
MD5 e3d4d35e9836f20ed9ca1b1a0763cc41
SHA1 fa5f723b3a087489a3b9ee2b07bf841a89955dbe
SHA256 f00071bb1b5f37d12500223b2e453a83710d906a00965283f873a3867fc02e32
SHA3 7d6bfbcca04170557f700febbc2e13c54d90dcd0a7d8b9c0ea6e2862e3af603f

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2b4
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 3.18591
MD5 fe522eba644ae5f88eb858b4cb3a5829
SHA1 61656d4304b98eb2715ee0c24e5b60009f1a278b
SHA256 ce28bb03eda08a374750ce5be8f32f5739cfed85bf3b6d667be80938fd92615b
SHA3 55193077c744d8c6053726c9f617bb72428265da1e3b006434ca6997b39ec067

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x184
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 5.16667
MD5 92234c743b01b6ee87173e583fac0235
SHA1 317db782b0bc3caefa5248e6a852d13a87b21da2
SHA256 0e4a1b25eba434b259c54135c3321e077d6b9b107fd4a66b465f247b98f1e0d1
SHA3 8a2f3f08c309d089fe969993594b0244cc78cbdfff7361f2a6bea8a3b757497c

TFORM1

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x149
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 5.49563
MD5 bc14ea002234ef7fa043c638a3e14edd
SHA1 3250d6fe02c5e853ba3a852c0b1eb0315b238de7
SHA256 2bd52990b6f93820cb8e5ee16158af1f98409a03da8ff45975b7d1d80b7a25ea
SHA3 6485bf7e16d9c1cae364b81602d2550364d7875c194cdcf664b9e0f6c2557e14

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language Russian - Russia
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2000-Oct-05 08:53:02
Entropy 2.06096
Detected Filetype Icon file
MD5 59517c0a5976f364558b42dbb1cabbc8
SHA1 cf9a68a0b175f131381d3d29245441a6f9d53e3d
SHA256 ff04c16f07007618c7723eb538f879f89e297950bfa77ed55d1a19776f312a37
SHA3 5b15005fa45f38fa9716594a7860ddc29a2ef7e6921e99c6e8f3ac5bef203fd6

String Table contents

List does not allow duplicates ($0%x)
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Clipboard does not support Icons
Bits index out of range
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
String list does not allow duplicates
A component named %s already exists
''%s'' is not a valid component name
A class named %s already exists
Invalid property value
Invalid property path
Property does not exist
Property is read-only
Error reading %s%s%s: %s
Ancestor for '%s' not found
Bitmap image is not valid
Icon image is not valid
Metafile is not valid
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Friday
Saturday
Cannot assign a %s to a %s
Cannot create file %s
Cannot open file %s
Stream read error
Stream write error
Out of memory while expanding memory stream
Can't write to a read-only resource stream
Class %s not found
Invalid stream format
Resource %s not found
List index out of bounds (%d)
List capacity out of bounds (%d)
List count out of bounds (%d)
Operation not allowed on sorted string list
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
Error creating variant array
Variant is not an array
Variant array index out of bounds
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Win32 Error. Code: %d.
%s
A Win32 API function failed
Jan
Feb
Mar
Apr
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Invalid variant type conversion
Invalid variant operation
Variant method calls not supported
Read
Write
'%s' is not a valid integer value
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow

Version Info

TLS Callbacks

StartAddressOfRawData 0x448000
EndAddressOfRawData 0x448010
AddressOfIndex 0x4454d0
AddressOfCallbacks 0x449010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section BSS has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.