b9989255e9a05e629830050301cd5602

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jun-14 13:27:46
Detected languages English - United States
FileDescription Setup/Uninstall
FileVersion 51.1052.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regsvr32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • http://www.innosetup.com
  • http://www.innosetup.com/
  • http://www.remobjects.com
  • http://www.remobjects.com/ps
  • innosetup.com
  • remobjects.com
  • www.innosetup.com
  • www.remobjects.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • SwitchToThread
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • CallNextHookEx
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource HELPER_EXE_AMD64 detected as a PE Executable.
Resource SHFOLDERDLL detected as a PE Executable.
Malicious The PE's digital signature is invalid. Signer: Wondershare Technology Group Co.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
The file was modified after it was signed.
Suspicious VirusTotal score: 1/71 (Scanned on 2025-02-04 19:52:55) Bkav: W32.AIDetectMalware

Hashes

MD5 b9989255e9a05e629830050301cd5602
SHA1 e5479990a7d98af30f3d040272f78107d2cc7e45
SHA256 fa58cc4df62fd8e5de30cad2539f99725a3122c9b3639f241df11a363f1099bd
SHA3 45e6f58991dfa8eec655dc0d656959d01ca91910efc2379406d05b7c2fe6df02
SSDeep 24576:JnbbPImgK4brDi4IxgRqzwqNb+Yz73P2EMZbG0JEtyOuTSC2F5XM/Gqx9VQFW:pHeKh4nqzF3PYdStyOuTSC2F5XM/rV
Imports Hash e428ae536c05073ea98aa32599bfeb43

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2018-Jun-14 13:27:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x101600
SizeOfInitializedData 0x64c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x001025D8 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x103000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x172000
SizeOfHeaders 0x400
Checksum 0x173098
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 a14240bafc6b4266f43c022ed40dfce9
SHA1 081e5fcaf0e9ac7d1bba6da93e520e25274c93cc
SHA256 e34700cb1c5b05dcbc4c5b3ef8a7223d512fbd300884a5213b875d559ad6eba6
SHA3 515dd6c0f3ac16f1970040bff38ecc44e2813d849a2e0a6a6614500831f3c85b
VirtualSize 0xffdc8
VirtualAddress 0x1000
SizeOfRawData 0xffe00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.47452

.itext

MD5 8e0d52126a75001416d71c23878be2c1
SHA1 58942009a5f95573599c17fc3c02e88568f3fe28
SHA256 bec67027d73eb610b7043cef07a5bf4581ec22bb2c6bf221ec571a3d3806df94
SHA3 83739883aab0f638d8054d73488007f929445e39e16f52d248fa0d2d8c409604
VirtualSize 0x17f4
VirtualAddress 0x101000
SizeOfRawData 0x1800
PointerToRawData 0x100200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.00373

.data

MD5 c2acc8e96fc244753abd1d87bb624bc0
SHA1 e3ad9a93700d51bcd0e4c88f43e8a81c8fe077ca
SHA256 8e049cd27681c78899d55171db49c0d02a01c706baea0687daa9a7c8e1c83a65
SHA3 57c54bf5f00cdfa906db9d2e23bf666479364b27aa1513e56fa8190c031432e9
VirtualSize 0x308c
VirtualAddress 0x103000
SizeOfRawData 0x3200
PointerToRawData 0x101a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.35756

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x6198
VirtualAddress 0x107000
SizeOfRawData 0
PointerToRawData 0x104c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 0e1e8128f777a5ff18a144305a4fb39c
SHA1 0837933e1062797063f79c2e08e27d6fbf3ffbfa
SHA256 975f8de2ac6e6f9203df3d49d18e330c16fbb204c6901e8946e372e292a4a5d6
SHA3 995910f2ac2ab55a600baa3ab3e0e995099c17ee5de7e67a6ef76391cbdc7621
VirtualSize 0x3840
VirtualAddress 0x10e000
SizeOfRawData 0x3a00
PointerToRawData 0x104c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.20488

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3c
VirtualAddress 0x112000
SizeOfRawData 0
PointerToRawData 0x108600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 9cf98ea6bb17a35d99fa770a2e9a8ff0
SHA1 33911fa22d9ebf13c7c3406427ad35d5889e1528
SHA256 2ed4a7822e3593b8b08e02c329dcb27458c0783cf94e70876ac52d8dfa6d0b3c
SHA3 d64198fe5b6b9755d8fe68777485ded06ddb0a1747a2059b8cbb9fcf82235262
VirtualSize 0x18
VirtualAddress 0x113000
SizeOfRawData 0x200
PointerToRawData 0x108600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.210826

.rsrc

MD5 653af6fce9e368ad6ebc3fffd0484856
SHA1 49417341623808db14b16f51a0deed0c73c1d813
SHA256 8b641789ad49734bade4c1bcc8abc1d5aedd0d9957895136ddea6861045325fa
SHA3 4a98d7e912b5a56dd810af0dff506b16c06e62737f1e67b8bd6adc88e1f53a6b
VirtualSize 0x5dc40
VirtualAddress 0x114000
SizeOfRawData 0x5de00
PointerToRawData 0x108800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.40081

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
msimg32.dll AlphaBlend
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RoundRect
RestoreDC
RemoveFontResourceW
Rectangle
RectVisible
RealizePalette
Polyline
Pie
PatBlt
MoveToEx
MaskBlt
LineTo
LineDDA
IntersectClipRect
GetWindowOrgEx
GetTextMetricsW
GetTextExtentPointW
GetTextExtentPoint32W
GetSystemPaletteEntries
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectW
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
GdiFlush
FrameRgn
ExtTextOutW
ExtFloodFill
ExcludeClipRect
EnumFontsW
Ellipse
DeleteObject
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectW
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
Chord
BitBlt
Arc
AddFontResourceW
version.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
mpr.dll WNetOpenEnumW
WNetGetUniversalNameW
WNetGetConnectionW
WNetEnumResourceW
WNetCloseEnum
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CLSIDFromProgID
CLSIDFromString
StringFromCLSID
CoCreateInstance
CoFreeUnusedLibraries
CoUninitialize
CoInitialize
IsEqualGUID
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll (#2) InitCommonControls
shell32.dll ShellExecuteExW
ShellExecuteW
SHGetFileInfoW
ExtractIconW
shell32.dll (#2) ShellExecuteExW
ShellExecuteW
SHGetFileInfoW
ExtractIconW
comdlg32.dll GetSaveFileNameW
GetOpenFileNameW
ole32.dll (#2) OleUninitialize
OleInitialize
CoTaskMemFree
CLSIDFromProgID
CLSIDFromString
StringFromCLSID
CoCreateInstance
CoFreeUnusedLibraries
CoUninitialize
CoInitialize
IsEqualGUID
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
oleaut32.dll (#4) SysFreeString
SysReAllocStringLen
SysAllocStringLen

Delayed Imports

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

DISKIMAGE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27885
MD5 9f36c65260f5b9b63749b80e87baa108
SHA1 606acb721dc20da5f8e1feb0a3d174cefbee4eda
SHA256 5ef379b2771118b2ce2d78c915d48230d8f9d4e4905e62a9b7f150c009c7bc67
SHA3 eab22bc47d1eacf9a480dc79e6e8f754469badd850d0a591a4324406100b190c
Preview

STOPIMAGE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34815
MD5 f21ffbe1149520d40d1a034da636c6fd
SHA1 db7c7bc0cd61d73be92b71bbb535a172f77ef2b5
SHA256 ea9b569ac7e3d063e22795d5f428289938caa4b74272a8870ebbca46f21b929b
SHA3 f56506ed838ee62feb25b27b2446acb95fc801a8430101566713d7e1f3262c30
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.70131
MD5 365fc015ed989a6d1b0666a217d3b6c1
SHA1 29c26c8541c94bf72dde504948a5d7b59a9038fe
SHA256 bfc6ceb5ea7dab295e7a0847b07c9a0d1c22613bcc51454f149e8cd47bce1d42
SHA3 1b740e1a35f25a6bd1a785c2e4d94e9ad3acce391fddcf5b086a8c527971ebbd

2 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.23564
MD5 babc1c0b461e8aeddfceb9ecbdb3748e
SHA1 dac0315ab102d70815eb076170e66d918370ecee
SHA256 5be10602a58d8a8318efd0d901f9506cccae4534075ed7149e2b994bbe982645
SHA3 83d9eccc8f5abc7bdd447b5b128cc2bf3159bd61684075a0215be8f0ff2d405c

3 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.31174
MD5 9ae98bfbf20742335b7897fe6808eaa2
SHA1 1be0b10b780e1d7f74c67d247480496fc4337085
SHA256 bfd5b30156dc0b76524d5d59d457ca75f4d3366bbd5a27a6b98c26ca530ec2ae
SHA3 907e7ad6c1271e33b10b78abb453f18e363c2ce1e2df34175b8a4e31c6b91f2f

4 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.74603
MD5 4a5a8353cd47ef63f9c0c2b4360a1ce8
SHA1 30edf035da74cd729fcdc16aaa5d118ef7d707db
SHA256 0c133d74cd565e00627b99c2def965c8176e73e50e3c9355bbc65f98806adeb9
SHA3 10df87f57734aaf5bcbef5cbc9f03c90799699c13ad1df3273e4fbe30ca75422

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02517
MD5 4c097d1e95ee9ab9c5030867ae9a2c11
SHA1 69513a054011861c3a73702553c9f4dd37e3043e
SHA256 5ce7cb96a60dda4a4b33d325b7d6437ac85c3e30a28d50a94adfb87ca8407e1b
SHA3 813b32cd03a5a425aea152fb4a4288efa5f51d9a6cf7134916c5e73d376c6d13

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.35707
MD5 3f2ff95405f29fbf22e171ed4ff2745b
SHA1 32d245c43cb7091e768993d1c7704f9f9ab5b04c
SHA256 5c00dbb8016b1d0f0d106f13ceb78d17b18e3150d3ce4b17ebf1ed903530e2f6
SHA3 b5ec6f6bffd7227dd232bf40ea252f7247120dd07c8100031dff37f128e80d6c

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x28c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38129
MD5 ab703d2ced480a6ee35167ed3a118eb5
SHA1 93927997d73c1b7dcab90666c430ef1e78df72ba
SHA256 8b7e2f6191b2e6505247e4e2eccbaedfcb62d6ad0cf780202548118cc4a76afe
SHA3 a00159b354867518b6e55a65d90883ccfb47ab941d28888c72076905035196b1

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33195
MD5 0a0b5a9db659e4beb70d1a1dea335fd7
SHA1 711eefe35cc9e52ea7b3f0e943d748be9789b330
SHA256 04378d8b776486a246d3a49d3762a72703d56729fa809de401408943ced80d7a
SHA3 4705e37310c7cb9071b26b16b6b5d61079f00e7c2890695826f9af4efa44b8f6

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.44967
MD5 210964f4e28003a874454a06a5c2fca1
SHA1 715336d8fe6c741ec768b35c455ef99362ea658e
SHA256 3c8133ad5dc190728cd90e6bfccd9132046b36df960d4d900b1ac3ddcf37e078
SHA3 4b00d35e2af286b15e1965f9b132081dc597e596a8edbe19e66f654a03c5da04

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.37288
MD5 960f16982a86df542514b2269203a926
SHA1 2ac7e72fb923106362d6f42d213abf8304923027
SHA256 e557ee0e0b7d5aa10ba51091bd132ea08cd0041beff784069e22028c947f03b5
SHA3 d724692a5757379627e8e5c24e7ba17389eba7ee13340f8ba8fba405147f75fd

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29236
MD5 759d213331f1165836a6da4c89fdc0b1
SHA1 aef278d7277f0efc27c085a6530261aaf994be52
SHA256 db86cdd93bea1ba8e9374ba6d1884ecb82a4740ba5c49110f582e4348a746f5a
SHA3 056d8ce6ca5394e9000fe07e45f79b4d5852a44fcf656c29265b37f78cc13a17

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27854
MD5 08f1b7fd9e9450a10ecab50116bbdfd7
SHA1 8a215fbeecc019d68c6cd70d58c1d688f2dddab3
SHA256 d82878938552f43e0169b01ec23437fe40b4ab12cf7a16584af10fa4440a5989
SHA3 4c6b931443eb76cbc9fc6049394f3d5aa70f591eae216f1b572861950294f4f5

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24601
MD5 f91e8c6efab99bf8156240decbf039f9
SHA1 c077346b6f6dbbc2d730b71d65fec0053c98a9da
SHA256 328e787aafbb684152b4a1afe07401bc4378f53db1b152b07cd94aba5a7da87b
SHA3 28f44f67a7e82a7ecaf72dc95c7b951f10ee479478323b77f7c28afabe4d2012

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33599
MD5 7df73d476f9dd7c0b5e5be9f5d883e5c
SHA1 5ca0f785ca943d5ef8809335edf4cf2f0f5bf74b
SHA256 a5ec0e9221c27f6824cfb7a0058763cfd7705fd5e8064fbe41e9cbd6b212f9f3
SHA3 4c163753357d9785ed6a5aff9e78ef5a8b7c7aaeb52cca4ad2b2c26673fbbb2a

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32038
MD5 4f15a61a838d6ca3181851cfe45f268d
SHA1 565fc72cec6798d69412ffaee00e0eb880818c79
SHA256 b7ceb7289c2b1ad3a53b31c70650a08842fbe46f2b487edbf1a6c47bd7dcf628
SHA3 fbe0283bf26f7778b93eb44733393d8c566c940f9c3a2df1c49f2a88bce633af

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x108
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21998
MD5 9933ed9224c4c2e91380fef66a0e1beb
SHA1 26461c98544d572657722892b0f079fa93d444cb
SHA256 1da5614fbdcded0b9a021776217b90bc6ef0e83e962fef10f2bc60486937b438
SHA3 151865d066075f5a9be27c72388efe077be1cd3398bf13bde032f04efc23497e

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34426
MD5 6884c8135d8822921b30f5ada0bd1a09
SHA1 8ba1ace07e09fcba5bc138e02a611b83609923f7
SHA256 c6ec1e31e5a3b39db364ef98b5f44727eb821481518601e0d62a61a597231363
SHA3 f9e3f673b25f489b83723c8d7f067c5c05f8cb8d1baa72e14cedc27cac20bce0

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x234
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40141
MD5 f9330ca710193279e60c976c0acf3535
SHA1 5c70157687851563d696ba88f0369feff4c1fe74
SHA256 14ac140c5a26aa8d9ff9fd642e02ad8b375653fac27485140817acb14ecf4427
SHA3 90e87099f7fd825d35de16323624070efba0b88a2c438ca8b85ecc2e79c98708

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27126
MD5 f34f4b2fbffb2b2dc74250b07c7dbc42
SHA1 4ca332f32fa8678103b78406f05e3e3e8b31993b
SHA256 78160f5ba775c340c1c5dcdfe1cf96d0190a2d49090d4acba36acb041e2b825f
SHA3 640df8a9b7437cb1c4926e5c37d7ba48534c9a48e3104dc14e1b9610afda14f1

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x32c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34727
MD5 48281f50b36a965a0a719bc3c96e7ef5
SHA1 66a2366acc1388aa1d13a7694634768193e98a3f
SHA256 97814a867e3c980ede78426fb8a51dc24d915aa7a2386a5c926850c4d445e9e1
SHA3 d87a16f699dc7e42e85461e30610f2a3ac3c7a24929a3bf832a4af9d5a9b4534

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28088
MD5 92de8d2c3cb2848fa0d540dacc5a3cd8
SHA1 2774d0de3d04d035a9dd951745ce6c8f3311edea
SHA256 8f866a52b9bae84b8b558de9f94dc322baeaeb0eeb972b3a1c2b187fb1346b68
SHA3 d68ab47956bd7150c9e295085e65f1c93e14ca3414ff666e57bedd0f442f8d52

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

HELPER_EXE_AMD64

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.72037
Detected Filetype PE Executable
MD5 e4211d6d009757c078a9fac7ff4f03d4
SHA1 019cd56ba687d39d12d4b13991c9a42ea6ba03da
SHA256 388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
SHA3 711ebd07a2e4a2820eb2cbc94d8e731ecf51b395755a3b3747b2a932581b9df9

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44667
MD5 e65458a56bcee9480025036ce4b48b6b
SHA1 9fd3bdb3ab412d15c49576381a8471628b920f7c
SHA256 e83493af1aa90a6377b9240bd2912b60e168bc03bdf1f06f729cb54f76b29a23
SHA3 fa31d19aac49c2f45f686618a6272089c9ce5e99660f723cefeeabff60db0692

SHFOLDERDLL

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x5b10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.59624
Detected Filetype PE Executable
MD5 92dc6ef532fbb4a5c3201469a5b5eb63
SHA1 3e89ff837147c16b4e41c30d6c796374e0b8e62c
SHA256 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
SHA3 6c04a9206995500a984744fd15fcea5542f6f577f21c63ed00621a1acde31fe2

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x125
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33322
MD5 2e91d62c202ac5a0169929c30fcba160
SHA1 fd965f85fe5e741a590efb348e78e005c26ded8c
SHA256 2076fb3dc69ae89eea6b3c714a60bee0c9ba05e5aeef275bd8aafcb7e46aa5b6
SHA3 530ab1febf6e05c011bee807b3a2c2659edfa970e14b1dc618d5936dc8f8434d

TNEWDISKFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.50778
MD5 5ce723642022c039f178c2aed86f52ac
SHA1 f60b54ad66ed10214ce479c7082ecc31099016a8
SHA256 0b40409be6235e4055c04cd92c0044e63375b0123f8dfcb6f9038b95cdbf3897
SHA3 772be5373fa748c11cf901059b0dc9c1957f7c40a01633071eb0f94fbb195425

TSELECTFOLDERFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x320
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45298
MD5 d2c6d81c9631e66915e8784d6a4cfd41
SHA1 a02fb6ccb639b1c2af3c83e8f7387a5afeae07e0
SHA256 24a91a7b458e7ffc84e316587ca0b8c9bb92b89eac88271a892c5ba18b40aced
SHA3 fd3cfc2bbb5e2613612e0c1bba8a061576b9adc68d87d149f8f695226889e34d

TSELECTLANGUAGEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46511
MD5 98575f21ab9491e1b6ae5e852d4c4305
SHA1 9b642977985c5f8165ab104caa93481263367820
SHA256 c8cfb5e468a4a2376141c84f64d8431888dad485bfce8a6304a3d1e509fd2e28
SHA3 fe5f4907a9ab7f6cd607af666970009f4a927024a6b98d3ad6790a2546bfd29a

TUNINSTALLPROGRESSFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5d9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49396
MD5 52b0761ca7d2972fcfcbadcb577d444c
SHA1 ccc039edba58585a888ae6f856d8dd28868525f1
SHA256 0247d57b98275241c0999e00c11e1e8e7368121aa097856a980e0738d2e07360
SHA3 9c81a1fd9435070b1bd70c78436e17ebd439d9a4b8a929f15a0f0e7b9fecca64

TUNINSTSHAREDFILEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x461
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44622
MD5 4a32802bb5f3529cd029d0c2a8a5cec6
SHA1 2c4cb7d3e36c44852c227245a584657c868e526b
SHA256 683939c9900b86a18d49e77f21e39a6c15d4e7bb26bf7a59981c854c7ef5bb74
SHA3 52eb035d79cc6b2debf7730769cfc247df488983d02cf3b50ee85cecb0ac7687

TWIZARDFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2092
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49772
MD5 f8dc757da06401586dac3bdcc7bb6dd2
SHA1 086f4218a76be7a90a0524a42ae771b99a9a959f
SHA256 2c2da2607e131fb45ab58eac86a81e2d5b12112e16640ef687da5d855c2b8429
SHA3 73fad2605e2524fd261f377b47e8ca65a56a7b72026ecf3f32dbcfd64ebb65e1

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.43192
Detected Filetype Icon file
MD5 8bab646c9f904566ed64f40c8eb55a12
SHA1 50a2e44af80ac6ef203db3ecd0b434156e478a40
SHA256 7a8c3cc464084801dd02d698431889c226289831e19182fe37be988976f72ca4
SHA3 af8930858ab2be4ae8a8addc328087f55c9b04c29b751ec7790a7fbe8da821bc

1 (#3)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x15c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07819
MD5 9d4f340b6295c457d23b240e8782d433
SHA1 a8ba1e73322c6d2ee8273093cecaed51de25a7dc
SHA256 5ce534f7c44cb2b71b44102f11ec16bb8fbf4dcee652e1b24602c3020eb818bf
SHA3 7e236b482bf7e435cadaaabaff91f126e172c31a337ca9831212b6a8f27f6e07

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x62c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13965
MD5 f78a870573f5bf2f15570e286257fae7
SHA1 eaccbf47cd42836b0e21ab2196b86d98a28733ca
SHA256 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
SHA3 f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca

String Table contents

Cannot cast an object
Capacity < Length
Nil interface
Unknown method
Expected return address at stack base
Out Of Stack Range
Type Mismatch
Unexpected End Of File
Version error
divide by Zero
Math error
Could not call proc
Out of Record Fields Range
Null Pointer Exception
Null variant error
Out Of Memory
Interface not supported
Unknown error
Invalid array
Out of string range
Cannot cast an interface
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Unknown Identifier
Exception: %s
[Invalid]
No Error
Cannot Import %s
Invalid Type
Internal error
Invalid Header
Invalid Opcode
Invalid Opcode Parameter
no Main Proc
Out of Global Vars range
Out of Proc Range
Out Of Range
Ctrl+
Alt+
Unable to insert a line
Clipboard does not support Icons
Text exceeds memo capacity
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
Invalid float
OLE error %.8x
Method '%s' not supported by automation object
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
&Close
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Bitmap image is not valid
Icon image is not valid
Invalid pixel format
Scan line index out of range
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
No help viewer that supports filters
''%s'' is not a valid integer value
Invalid argument to time encode
No context-sensitive help installed
No help found for context
Unable to open Index
Unable to open Search
Cannot open file "%s". %s
Invalid file name - %s
Invalid stream format
''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to get data for '%s'
Resource %s not found
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 51.1052.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription Setup/Uninstall
FileVersion (#2) 51.1052.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x512000
EndAddressOfRawData 0x51203c
AddressOfIndex 0x5037e8
AddressOfCallbacks 0x513010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->