c523b0c5397dc833bba2afcd4ff4b6f4

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2016-Aug-20 18:35:44
Detected languages English - United States
Debug artifacts C:\CodeBases\isdev\redist\Language Independent\i386\setupPreReq.pdb
CompanyName CMS Online
FileDescription Setup Launcher Unicode
FileVersion 1.08.7000
InternalName Setup
LegalCopyright Copyright (c) 2016 Flexera Software LLC. All Rights Reserved.
OriginalFilename InstallShield Setup.exe
ProductName CMS Terminal Integration Service Installation
ProductVersion 1.08.7000
Internal Build Number 169350
ISInternalVersion 23.0.288
ISInternalDescription Setup Launcher Unicode

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • http://www.installshield.com
  • http://www.installshield.com/isetup/ProErrorCentral.asp?ErrorCode
  • installshield.com
  • www.installshield.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryExA
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowW
Code injection capabilities (process hollowing):
  • WriteProcessMemory
  • SetThreadContext
  • ResumeThread
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegOpenKeyW
  • RegEnumKeyW
  • RegCreateKeyW
  • RegOverridePredefKey
  • RegQueryInfoKeyW
  • RegEnumKeyExW
  • RegDeleteKeyW
  • RegEnumValueW
  • RegDeleteValueW
  • RegSetValueExW
  • RegCreateKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Microsoft's cryptographic API:
  • CryptVerifySignatureW
  • CryptSignHashW
  • CryptDestroyHash
  • CryptHashData
  • CryptCreateHash
  • CryptImportKey
  • CryptExportKey
  • CryptGetHashParam
  • CryptSetHashParam
  • CryptDestroyKey
  • CryptDeriveKey
  • CryptReleaseContext
  • CryptAcquireContextW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32NextW
  • Process32FirstW
  • OpenProcess
  • WriteProcessMemory
Can take screenshots:
  • FindWindowW
  • GetDC
  • CreateCompatibleDC
  • BitBlt
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE's resources present abnormal characteristics. Resource 103 is possibly compressed or encrypted.
Info The PE is digitally signed. Signer: Complete Merchant Solutions
Issuer: Go Daddy Secure Certificate Authority - G2
Safe VirusTotal score: 0/69 (Scanned on 2021-06-12 05:01:18) All the AVs think this file is safe.

Hashes

MD5 c523b0c5397dc833bba2afcd4ff4b6f4
SHA1 eccb9261a602f5e35ddb774459e179dce5516e39
SHA256 bcb9681c1d7e7f6ee5f705950bee9b75b29b942880b41a07fca23ebb642e9f33
SHA3 c28283a4205aecf682921e26f769614696ca5aef0c4caad21e1644829232ee38
SSDeep 196608:yA2vz3RVFQVyMbZsQGlKkminm12KJPmMkDOlo/1I:yZHQs8ZsQArnm12KNBodI
Imports Hash 88b8ae64d7e8d8cd1394e41a763a1ffc

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 4
TimeDateStamp 2016-Aug-20 18:35:44
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 11.0
SizeOfCode 0xec600
SizeOfInitializedData 0x90c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0006D1DC (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xee000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x187000
SizeOfHeaders 0x400
Checksum 0x9299de
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7aee437c6b1b9704de8ee4aee1b42b73
SHA1 afc03eee1c1380af450d0137a5d6143709da906c
SHA256 d60073d50ef6c7aee687437f81eeb90cfe4ab58af440e9e0b0e206c1269d3903
SHA3 c63db7ed635d98bffb82536b88610716217aefb84a7ff9ced2b59529dafc81e9
VirtualSize 0xec416
VirtualAddress 0x1000
SizeOfRawData 0xec600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55607

.rdata

MD5 cf3bae7d088afe5de936f363c4b6ab9a
SHA1 baed977c111cccc75e63c641ade1281e53a03eed
SHA256 c48be4c6db0b450022f8ea4361dd4649f03e61318921c74725912cf22dcb1baa
SHA3 5717f45ef32bec32cc5192e673c684d91e73a1fb20428b7431e95aa214d937b3
VirtualSize 0x4131a
VirtualAddress 0xee000
SizeOfRawData 0x41400
PointerToRawData 0xeca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.95131

.data

MD5 cb708ea7ae96307cf087169f972f88a9
SHA1 4cba47d0a3caa0751d8b0342bc2547ee5c78dbe4
SHA256 3d656403727892e96443f289d2a7cba493040e2cc93e30db457cda2f4b99f682
SHA3 940555263598c9bf4d80533b9467a52cb4c65376dbecd43f06e985a4a851a92e
VirtualSize 0x9058
VirtualAddress 0x130000
SizeOfRawData 0x2a00
PointerToRawData 0x12de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.49568

.rsrc

MD5 d33a0daca3e7f560e7ef987caa29f93c
SHA1 7ed3109139484600c712d0f6f063ddcdea24b30b
SHA256 9ee78ea5bd3812d0397853c81fec1c9eb7b091af0b82dcbf14a995be3fca2e29
SHA3 abdb4ad74bc6d9b464b61f135413c063bf570fb3c27b3171c31f37dbc5b11026
VirtualSize 0x4ccd8
VirtualAddress 0x13a000
SizeOfRawData 0x4ce00
PointerToRawData 0x130800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.56063

Imports

COMCTL32.dll #17
KERNEL32.dll MoveFileW
LocalFree
FormatMessageW
GetSystemInfo
MulDiv
RaiseException
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
LoadLibraryExW
GetVersion
GetLocalTime
GetFileAttributesW
GetCurrentDirectoryW
FileTimeToLocalFileTime
GetFileTime
GetSystemDefaultUILanguage
GlobalAlloc
GlobalFree
FlushFileBuffers
SetEndOfFile
VirtualQuery
IsBadReadPtr
GetDiskFreeSpaceExW
GetDriveTypeW
GetCurrentThread
InterlockedExchange
LoadLibraryExA
GetPrivateProfileSectionW
GetShortPathNameW
GetModuleHandleW
GetProcAddress
GetSystemDirectoryA
LoadLibraryA
GetLastError
SetLastError
GetPrivateProfileStringW
GetFileSize
CloseHandle
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
lstrlenA
MultiByteToWideChar
WideCharToMultiByte
ReadFile
SetFilePointer
WriteFile
HeapAlloc
GetSystemTimeAsFileTime
SetFileAttributesW
FindNextFileW
FindFirstFileW
FindClose
CreateDirectoryW
CompareFileTime
VerLanguageNameW
GetUserDefaultLangID
GetSystemDefaultLangID
lstrcmpiW
lstrcmpW
IsValidLocale
GetLocaleInfoW
lstrcpyA
ExitThread
GetExitCodeProcess
GetCommandLineW
LoadLibraryW
FreeLibrary
FreeResource
GetPrivateProfileSectionNamesA
GetPrivateProfileStringA
GetPrivateProfileIntA
lstrcatA
lstrcmpiA
lstrcpynA
LocalAlloc
lstrcmpA
SystemTimeToFileTime
ResetEvent
SetEvent
Process32NextW
Process32FirstW
CreateToolhelp32Snapshot
FindResourceExW
GetEnvironmentVariableW
SetFileTime
OpenProcess
GetProcessTimes
ReadConsoleW
WriteConsoleW
SetStdHandle
SetFilePointerEx
GetConsoleMode
GetConsoleCP
CompareStringA
CompareStringW
lstrcatW
GetVersionExW
InterlockedDecrement
InterlockedIncrement
CreateEventW
QueryPerformanceFrequency
GetTempFileNameW
CopyFileW
GetTickCount
GetExitCodeThread
CreateThread
FindResourceW
GlobalUnlock
GlobalLock
SizeofResource
LockResource
LoadResource
lstrcpyW
GetWindowsDirectoryW
SetErrorMode
GetTempPathW
CreateFileW
ExpandEnvironmentStringsW
MoveFileExW
WriteProcessMemory
VirtualProtectEx
GetSystemDirectoryW
FlushInstructionCache
SetThreadContext
GetThreadContext
CreateProcessW
ResumeThread
TerminateProcess
ExitProcess
GetCurrentProcess
Sleep
WaitForSingleObject
DuplicateHandle
RemoveDirectoryW
DeleteFileW
SetCurrentDirectoryW
lstrlenW
lstrcpynW
GetModuleFileNameW
GetProcessHeap
HeapFree
FatalAppExitA
WritePrivateProfileSectionW
EnumSystemLocalesW
GetUserDefaultLCID
GetTimeFormatW
GetDateFormatW
SetConsoleCtrlHandler
OutputDebugStringW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCurrentProcessId
QueryPerformanceCounter
GetFileType
HeapReAlloc
CreateSemaphoreW
GetStartupInfoW
TlsFree
TlsSetValue
TlsGetValue
TlsAlloc
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetStringTypeW
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
GetCurrentThreadId
HeapSize
AreFileApisANSI
GetModuleHandleExW
GetStdHandle
IsProcessorFeaturePresent
IsDebuggerPresent
RtlUnwind
LCMapStringW
DecodePointer
EncodePointer
USER32.dll MapWindowPoints
GetMessageW
TranslateMessage
DispatchMessageW
PostMessageW
DefWindowProcW
PostQuitMessage
RegisterClassW
CreateWindowExW
SetTimer
KillTimer
LoadCursorW
LoadIconW
wsprintfW
PeekMessageW
MsgWaitForMultipleObjects
GetDesktopWindow
ShowWindow
DialogBoxIndirectParamW
EndDialog
GetDlgItem
SetWindowTextW
CharPrevW
wvsprintfW
LoadImageW
CreateDialogParamW
MoveWindow
GetParent
GetWindowTextW
SetCursor
GetWindow
GetDlgItemTextW
SetFocus
SetForegroundWindow
SetActiveWindow
SetDlgItemTextW
FindWindowW
SubtractRect
IntersectRect
SetRect
FillRect
SetWindowPos
GetSysColor
GetDC
GetSystemMetrics
GetDlgCtrlID
CreateDialogIndirectParamW
ExitWindowsEx
CharUpperW
wsprintfA
CallWindowProcW
DrawIcon
DrawTextW
UpdateWindow
InvalidateRect
SetPropW
GetPropW
RemovePropW
GetSysColorBrush
DrawFocusRect
CopyRect
InflateRect
EnumChildWindows
GetClassNameW
MapDialogRect
RegisterClassExW
MonitorFromPoint
CharNextW
IsDialogMessageW
FindWindowExW
ScreenToClient
MessageBoxW
GetWindowRect
EnableWindow
SendDlgItemMessageW
DestroyWindow
IsWindow
SendMessageW
WaitForInputIdle
SetWindowLongW
GetWindowLongW
GetClientRect
EndPaint
BeginPaint
ReleaseDC
GetWindowDC
GDI32.dll CreateHalftonePalette
GetDIBColorTable
SelectPalette
RealizePalette
GetSystemPaletteEntries
CreatePalette
CreateFontW
SetTextColor
SetBkMode
GetDeviceCaps
CreateSolidBrush
GetObjectW
TranslateCharsetInfo
CreateFontIndirectW
SetStretchBltMode
StretchBlt
SelectObject
DeleteDC
CreateDIBitmap
CreateCompatibleDC
BitBlt
DeleteObject
GetStockObject
CreateCompatibleBitmap
CreateDCW
CreatePatternBrush
GetTextExtentPoint32W
RestoreDC
SaveDC
DeleteMetaFile
CreateBitmap
CreateRectRgn
PatBlt
PlayMetaFile
SelectClipRgn
SetBkColor
SetMapMode
SetMetaFileBitsEx
SetPixel
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowOrgEx
UnrealizeObject
ADVAPI32.dll RegQueryValueExW
RegOpenKeyExW
CryptVerifySignatureW
CryptSignHashW
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptImportKey
CryptExportKey
CryptGetHashParam
CryptSetHashParam
CryptDestroyKey
CryptDeriveKey
CryptReleaseContext
CryptAcquireContextW
RegOpenKeyW
RegEnumKeyW
RegCreateKeyW
RegOverridePredefKey
LookupPrivilegeValueW
AdjustTokenPrivileges
GetTokenInformation
FreeSid
EqualSid
AllocateAndInitializeSid
OpenThreadToken
OpenProcessToken
SetEntriesInAclW
SetSecurityDescriptorOwner
SetSecurityDescriptorGroup
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
CreateWellKnownSid
RegQueryInfoKeyW
RegEnumKeyExW
RegDeleteKeyW
RegEnumValueW
RegDeleteValueW
RegSetValueExW
RegCreateKeyExW
RegCloseKey
SHELL32.dll CommandLineToArgvW
ShellExecuteW
SHBrowseForFolderW
SHGetFolderPathW
SHGetPathFromIDListW
ShellExecuteExW
SHGetMalloc
SHGetSpecialFolderLocation
ole32.dll CoUninitialize
CoInitializeSecurity
CoInitialize
CoTaskMemRealloc
ProgIDFromCLSID
CreateStreamOnHGlobal
CoTaskMemAlloc
CLSIDFromProgID
GetRunningObjectTable
CreateItemMoniker
CoCreateGuid
StringFromGUID2
CoCreateInstance
CoTaskMemFree
OLEAUT32.dll SysReAllocStringLen
VarUI4FromStr
SystemTimeToVariantTime
VarBstrCmp
CreateErrorInfo
SetErrorInfo
UnRegisterTypeLib
RegisterTypeLib
LoadTypeLib
SysStringLen
SysAllocString
SysStringByteLen
SysAllocStringByteLen
VarBstrCat
VarBstrFromDate
VariantClear
VariantChangeType
SysAllocStringLen
SysFreeString
GetErrorInfo
RPCRT4.dll UuidToStringW
UuidFromStringW
RpcStringFreeW
UuidCreate
gdiplus.dll GdipCreateBitmapFromStream
GdipCreateBitmapFromFile
GdipCreateBitmapFromStreamICM
GdipCreateBitmapFromFileICM
GdipCreateBitmapFromResource
GdipCreateFromHDC
GdipDeleteGraphics
GdipSetInterpolationMode
GdipDrawImageRectI
GdipGetImageWidth
GdipGetImageHeight
GdipAlloc
GdipFree
GdiplusStartup
GdipCloneImage
GdipDisposeImage
VERSION.dll (delay-loaded) VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW

Delayed Imports

Attributes 0x1
Name VERSION.dll
ModuleHandle 0x136d74
DelayImportAddressTable 0x1327d0
DelayImportNameTable 0x12c6a4
BoundDelayImportTable 0x12cc7c
UnloadDelayImportTable 0x12ce44
TimeStamp 1970-Jan-01 00:00:00

IDR_GIF1

Type GIF
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x33a7
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89919
Detected Filetype GIF graphic file
MD5 169f57ba53c84508d5a6391badff4c46
SHA1 7bbfceb774e9362d306277a4f6ed56819b45b2c6
SHA256 aaf68988dc686486280d290acc650ac4a014fd5f8b20f659f2fda313860239af
SHA3 bb319460007fedcd80f6642279f01cf1f068f1995aa12cf2074daf4bebed2906

IDR_GIF1 (#2)

Type GIF
Language English - United States
Codepage Latin 1 / Western European
Size 0x339f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89636
Detected Filetype GIF graphic file
MD5 60385ca1cb3cfe6090bda0cfe53bfdd7
SHA1 4bbfedfbd4944efab7dc10ee16df0b6df4c2f11f
SHA256 eb1fcdbf7a38b7f9f8a433df490d3305b30d5fa4adf8b60a442d91a2a37c0577
SHA3 e94e64248f127ce86a9b9bd61fa2dabd66ade6f561d1e527cd1c0515ee8bd344

10554

Type PNG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x39ed
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.97785
Detected Filetype PNG graphic file
MD5 eb1cdd8fb9a4ad195ee193e50729f52e
SHA1 7621a9b14f0d56a6ba16f6235aeeed0f1aa0673a
SHA256 68153a950285a97dd9f6f3fe038a0115434ce9ffa4f5fbbf9bc2e674b28d1fb9
SHA3 b5359cbb06497ee1da1b18dcd8375220a89340f350d6e8878eebac136fc87492

10652

Type PNG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2fc9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9635
Detected Filetype PNG graphic file
MD5 114d7243ea9abae505c59d0d8e27fa28
SHA1 0767bb00785713a18863547fe7f8c75f305a48aa
SHA256 38367e502c5727ff76a0cbf418f34b7050eefd84afb11ecf825256a3bf59fa65
SHA3 0d17a3a67689f166563dee772b417c7bcbde3667ab7865d4a86b1a1b70858fb1

103

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14220
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.19301
MD5 11d8906bd5a3ac7cc14e2c0817e2e83c
SHA1 e87c34a9ea6d5860302847363f09628a7e26e4e4
SHA256 2c1d7e2094b50a5aa3b7808db1f732f9c8d26d55691f849e93240134e7c17030
SHA3 f89ba4dfaa74412224d6d054fdf2e2ef450869f827f200fd1e7b9407c9f3d9ab
Preview

10550

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1b5c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.54635
MD5 441aa5f867dfd2ad74c7da511dac8e96
SHA1 d22ab57c50902ade576f7e1ccd6cf88526b070f4
SHA256 c2f7f7e254d0053ca1f5615e8baad380ad4218ae44213cff6042875279167e6e
SHA3 67b6acb4beb4704a9037623310807c26701b51e6164dad1a6dc11c662344cebb
Preview

10551

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x38e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.06921
MD5 3bab088935c8c517cd73b271a1567e3c
SHA1 6efaededbc23a916a72ed97b8c729ecaeebaaf6c
SHA256 f10f65452c48575987303de35f20e1b30f9e8fba6348baf1d729e103afdb1653
SHA3 c88faab1dd6a7cc4afcde31cd889f43df57a181a4cd37e29bb0ccaeaabe18828
Preview

10553

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1238
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.94256
MD5 1fef42f21c7f38122e5031d8c0c2556d
SHA1 dbecbb2f06fcffbda66037f3856129ca8d9b9c4a
SHA256 ed0f9f1dad2e631e93a64b6958cf0f952f1b633b8b27ea9c5fecacef89648f32
SHA3 b3e7cca7cced51bbf57e176cf6bebd170a6295a22f7853d8b748fd43a64adf0c
Preview

10650

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6588
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.93286
MD5 6770f6ad64a4cae6e9d16b3821cf09c1
SHA1 1e30386eccd37848bd07591283b2336ec05b509c
SHA256 463c15976e2dd0f64d142cb634dd8a1bb3df39a9f33b3075177bc167f356a14b
SHA3 54bcfc5abccf6099cc173eda6a2068ccee6f9dec1167baf68cfc5ae728a667d6
Preview

10651

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x11f88
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15548
MD5 05afcce75570a86f6bb4583014c1440e
SHA1 ff24df68d0053367d25266eb5283739e8c47b3c7
SHA256 b09b6e5f42319f07470a444e785d01a0edfa6ffb02b7507cf6d5dc6d4b04ca33
SHA3 742222b976d75a92f0eb86c53325c36b3da0d156fcae66e94cc114e4a36420f0
Preview

1

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.67732
MD5 07dbf03fcd263378ff834b33a124713a
SHA1 35b63af4195ee25daf709d949b7a1a3aa5604f0f
SHA256 2c0dac40992d77fca9b9fada755b2a5de1afd689fcca63ce43563d7575ef7177
SHA3 575692dfb14708f926808ce904f3a8592e36cdae4d586e7b33fccf49561ac24d

2

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31163
MD5 2c4c2ace15b7bbede07ec64626ec9b5a
SHA1 ef68430a8d6ec04c23edea5b07bc591ed7653823
SHA256 3ff598246933facbf5c36c5ba94ee549d2572a919344e98fb7fe65699640effb
SHA3 2cfbef476caf56238808ac3bd3323e22b8b07861a34a0c825433611dd2a751d3

3

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94006
MD5 6fc66216b68b96ae8c964b7a9b6aae2d
SHA1 9d73658fae8afd0b67ad1d6e9a93b8f08d3a5472
SHA256 9a86ae28f0d2b3564c103e8655df2213e4762c0e89af9e62b4aff53a770df91c
SHA3 60b9789fdd486ed9281a2fbc1cce94534ee0aebe7223654576a266ebd1eeeef0

4

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22977
MD5 6d74deb9b1d1f2302f7b083a7b531a09
SHA1 efadbf6fca3fb542aeaad5746bb90c8fa0de0829
SHA256 bd49d60cd9ffe7b74c16ed681c4fa9bc477d518de5026e113cea2530546b6ae8
SHA3 7cca62606e4d8970e1ec72d78f55b55d3c10cf5c97d3a3df8c98fdb0dc226446

5

Type RT_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5927
MD5 8a119cd704088b68ddc2d019340c968c
SHA1 461a0ad3670d41fdfc74a2ba83d8a2e2d0f69c4f
SHA256 d2d28da689a68e476deca303b752b3e865217888db7c9acff7c581fc86148469
SHA3 ed665f6a95d6a1f2068096e42f986e47236a53fea995f36c9265ae6b1a7db73a

103 (#2)

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70176
MD5 187f962e9a89c301e289975dc538ef28
SHA1 bd33501ac23dfc2d6ebf5d2a63cb15b4608c1def
SHA256 ad0d27e728a76e8d33357f25279797ca9b2a4530c20e541d07a1315cd795c978
SHA3 959308103386dee381470d8889605cfe7678700001c0702ef2d7d8e2a4a4ef76

105

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x266
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.8751
MD5 d6a18ee779f7c4f0e68bfcd70aa7b9c7
SHA1 4f2ab96893dc26509c2eb7fd1fc6a548f87af5a3
SHA256 b50a3258f93cd93427237241773018d0d756c18bf7b90ba880470dff6754ff17
SHA3 4ec10a50a3601ba01c1bc0cdfe5aa473e897f5bcdfdb2595dcdcccbe69da591c

106

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86461
MD5 28c42527e8d04b00b14fc23db21375f9
SHA1 adf67ae6c888cee8092845a8ab73ebe471f9e114
SHA256 c281cdb430097587ac27cac63fced3a59735fd56623f61b129c7ba16f4f93916
SHA3 d38d95f7ef3691a05cdfcadb28a1d4d4a26b032355e9afe46a93099577f5a5cf

107

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x54
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.10943
MD5 f2d6ea4bdd4a26752809c1cca93adaa7
SHA1 f92d0775822b72584e2aa6bed8fbd75a84e5025c
SHA256 8fe68faa00dd75c43d2da33c69cc59cd8da11a4d6746e3c71e2c9d91d33b8507
SHA3 a4db3a78d0ac20e283c38aa30c031c524fd01cf0ea57856ec1ddcf6ba2d62943

108

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.00588
MD5 b660810e4574c6d1d1de9c229e0e8c3c
SHA1 8f93c294823de497d37e9fe465cb40b8f3245dba
SHA256 9034c453e2b9e089a0ce0b8cec9663cd76266ff9a554bfc079d4bf6d82c86b58
SHA3 7397db15d4974339d5e376718b52fb6fd34edbbf6e92f3bd6320f776fca662ad

109

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.83301
MD5 6511aa60e1aa254bfa6e886c27ebd386
SHA1 016d38e94c73cf73f37229234f1140ebff4d26ef
SHA256 a66570c941f3e2e0f4c3f3281a41030f263b10b71ca88ae7cd1842c01fae36b6
SHA3 a662fb6b92113b0bdc53b08506070f77bb24cc20becced1de82b5feee22dbe08

119

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x114
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73676
MD5 e0880d30d0e52ebeda59489b27616df2
SHA1 29ffec2f8b3614d63b80f82192fb933af0264a44
SHA256 ef992251df2b334d6c1792a6f5ae9f11f39f35f548342ebf80b267aac4069b4d
SHA3 7f069f176f129e60a98fe5a16b640b839621e337f87d662aff31f67e79c72d9f

121

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62201
MD5 c658d0e8146e2ac4ce079123cce09dcd
SHA1 2f43bb69c3d1413216d174ddfc5369305f8a5ac9
SHA256 5d4ad6a6901589f1d8035674db13c4f92afc3a82ba504a97e5e01543e044064d
SHA3 26f93285d0e2f879d0df3f3cac2f2cab94818779bb4955d77eff83e4d2377db4

125

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x246
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.87449
MD5 d39b4694fd1a215ed04476faa1c53088
SHA1 0d1672f749375bfa83ef2584cfbe9c6271e310cb
SHA256 5ce1ad2dd52c0fe63ce0890888576cb51a478db410b518e915beda30d9752268
SHA3 33853c1d7f23c19de6aee4df0cfcd82577180c411ca3305af56ef58e2854ae9c

126

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33725
MD5 2195ab6349ba6802e66a81f559b7e66e
SHA1 ed2f6e1afae7be300c58852a1bccb8790f5a0001
SHA256 2257df0e1616bf41995104c427dfb2a9a99109b1deef8d65c632dc2e86059ee5
SHA3 9ac036831a9cda5bd1ced4d561045ccbec99234741c864e005c8697f022ee003

127

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75093
MD5 429b45486d8a3980731e6e98be11ec3f
SHA1 8961ff4838e6348dc4dffb503efa28b8e0c1f9b9
SHA256 36abd47b7117d61d8a5edc598c58cb525ce15d6cedbe005f78e2dc3c7f00c98c
SHA3 1f6157b778a3113c40472bdaa4608062c31ed689fd298cb2ce3edbb20d397e73

128

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.95626
MD5 4432db101e90085948cdd54a04d37d12
SHA1 dc250affce8fb0f44eac4e0ce9d40b75b8395ef9
SHA256 d376769646aaae56e7c9a783896eadb1c01a206dd64419631e52c5a1f3751ede
SHA3 4f095236ae319cb7fd12dd14764b2ca79e39aa3f026438a884002929e5b48b70

129

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1c6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98464
MD5 0edd49dbe8521fa5926477b1b9a2a51f
SHA1 beda960e0a861d0d98032026f4cfd52e95959222
SHA256 ffa56d910d3715159918764b1756898b028c0ad162251de26e532d0130c6a24e
SHA3 a0a84e41ccec92ce4f05f5112b5bf95ad7898260417d7854bd400cdb1749df6b

130

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1ee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91064
MD5 487989402a6bf0a0a5b7b792374f8e1b
SHA1 ddb7434721fd0b480a926ac36da005c3ac1b8051
SHA256 fa2eea681542eec4f7f4892b1720a3857d4291d5c8aad81222c98b2538f748ba
SHA3 bb92e686f4d07b07b3da82ef1e55efa594db3092be34241ac12af1a6e046e49c

131

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x7c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82979
MD5 a41d5e49ca41e82fbb15a16d08238b38
SHA1 00237963ee41d3e62fbcee7ecbba261260595469
SHA256 e6ea3b4185803b335c5539f9496a1b1a7a17a3bcfd2750ca53f9a6614d3fef71
SHA3 164bcb2134726a1fb57d8012ecc8f85d1bee71085b699854e44f6b0217aa9178

132

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32207
MD5 fad9f319fc9ef26237e674bc04efe4ec
SHA1 265f62d0882800737085e9540cc94e118d55fd89
SHA256 81e3994b8f8a32ad972a44c062bdc3d3bea87e1b618d1dbcf207273d55786784
SHA3 e02a6858cb6ec46d1e248f6dcd87096af56a9c171bb55f79be854b4fbfafa545

1000

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00215
MD5 8175eb8be87fc5a492a5c80bbfc7d030
SHA1 ea389295ab762ada2e0b783d035ea4864a7c867e
SHA256 bab3e69fe014bdb1ac518d8abff373d8e53d4663dfc6c116ebda283dc9f99043
SHA3 4deba26d3928fe725b5a1a9c83ded78525f56befca9c8d19fd38173c89fc6438

1001

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1da
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.09837
MD5 006becec3b7242f25acd588bbbbac9fa
SHA1 c0d3ac3717926322100965859e6781835cfdff4f
SHA256 a48b2b8dac8908ec78dce3857fe3ee4beffd8430d8372bb501843de8394c72fc
SHA3 d4bb989004a36199780c88ff22be014c84bbf666232b0cf7f7936981c31c1c55

1008

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99873
MD5 e4118168d2081ac50210e22bab538633
SHA1 7430510a8fa464b255d5cdb73b7a20184d05b989
SHA256 212e1a4b4c8d073ce79e5ea5fa5d4bfa6f263ea4d9059ea1b1d4d39c36599d6a
SHA3 6f092bd772726a96cbb7896144863bc87ae63a2a75680d2b3538dd3b73b5a1cd

1026

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xde
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.86883
MD5 5810db0422ff245ce8ab197683b60968
SHA1 f6c9a2caaba54186ce9984560b57f4a6a0c28adf
SHA256 e0be07df1d505e6c99708c257d6c0eff5836f8c655d93d1a39db2c840e0ee5f4
SHA3 1b8ad2e3eb846f0868e39598736a5723700ab565b7825e2d55dcc8742b5e990c

1034

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00866
MD5 fc488b7a04b76880147d7437424cbf24
SHA1 b128184ebe96da42b576790efaebceb80b2e2380
SHA256 0dac1402763a4e7f74b0aae954f47733bf97deec23290c50e2fe1f51aaf63f7a
SHA3 b8caaf50aa7b94e56a22287110d64c8aebb6ebffd389ccf30d9a577f6d330b98

3003

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x1dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22424
MD5 e339d2ebd8e57cb1a517a7886a35c93a
SHA1 837153bbb991ed6a9a96671df11bef2ffada6641
SHA256 5a482498a1132d89c0584479c8c17e1a3dcaea269321cb542f7d8eb7c8d92a4a
SHA3 06f5dd0cf0d2b32a9c7743135737d48b58fbc5986c235306f420afabb2576b5e

3004

Type RT_DIALOG
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.18131
MD5 48ee958b670661681ad32a656cbf4e5d
SHA1 8c143f45ea7a06f2b34b9c1bd1174a13d98d8ec7
SHA256 8d93c3fae36cbf0faf81d77133f11ffbbcf28ed2f7e9bba78ea51e195a106475
SHA3 f69aafb824692b3399de197800bc59f8aa47bbb0810a5d365d244f83011baa68

69

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x160
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.10251
MD5 572b4652bcded9fe5b2ff879214a6c7b
SHA1 c8764bae203c6ec1699b5c6bf76b6baf0560148b
SHA256 ad49677ffa11550aac8e410eb9acbf9c53a2e9de7c369136c43067365b337d73
SHA3 f9646b00b6741ada9d415595cc0fbd1342997a00e27546c048f95311b7f63c7d

70

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x23e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.14661
MD5 6af163e393980ecaab0d6c9764ebe160
SHA1 b9122541b62d0449dc61bd68f935b8641af18c05
SHA256 0aefbf895f45f37d244e659ef158fa6a02cbd1d34d4ff36e8361abec7b22ec89
SHA3 9438b1c40ca71df492430e9b46feec543caa4c4bec0bf2f319cc59cbde23076c

71

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x378
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25053
MD5 f3da1e60a94c4c5cd6c078c8d1d431cb
SHA1 f5722c1183ab8e74e9b7d72d256aab50ba33cff0
SHA256 d9c3dda7a23302d3424196ce4303feb823cbcd3eda8ea535f1cb10a0eec3d899
SHA3 1cc6d2cf25174dff5027f4b082374d982bf936e7346e19f914591660f0ac98d2

72

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x252
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.13124
MD5 f16d0f304aa818c26003d5d6e5f4b075
SHA1 7ac4900f70a68676f191b48d4ebbdf379b82681b
SHA256 b554a8e8d6d90965dbd39188e62110145f5e6cb8e3c8a33e97e4a3261d47a41e
SHA3 bfddc57577fbbc3e8ef6d6c0ce08405b9c3ecd22db990181c4b8500c21030586

73

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x1f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06893
MD5 8d7522472a83bf52b945a457a2f12768
SHA1 c09a7c1278e5868ec9247743c87d6674240649ca
SHA256 0bd115db78665e117a63ff686070525f79c9e4b38118c4fd38050e7847fab9d8
SHA3 246332a637f1d8b80a6bcbc5b7b81d01ea6da3bbf1333f2d6d88befcdc986b8f

76

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x66a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26659
MD5 241e8f9cceb46fa3e444580576dcc17d
SHA1 f916816d40bbc93cdfdd8750f462259af63038a2
SHA256 03e066f0fb3b050fed53096e4c2dea35af0acc05a9cd8c1ded106954993a6404
SHA3 5adf9ef9f5247bbdb294b235104b406c781f32559e735cac05e0e3b8876518f4

101

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x366
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22664
MD5 3acceab0966ed5b7bed6963b206e41de
SHA1 503023e4f53cf8d9716662aae30119351f42438f
SHA256 58576e1679571a7a705320b512d626164fbbf72bf2130366f57298419ffdd02b
SHA3 2d53b58b5a26a4ecfab04270fce2bdafa4e25da72f0f5169f482982f38f79e45

102

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x27e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.42599
MD5 f31ada5bfb35ba230aeaa0dcda91139e
SHA1 e4ba1ceeefd6a8a9d07b3c64d1f706d1de581831
SHA256 0a131fcd2d6d8a13b7ae4a6c7710b4ce835c74f518c6cb815ad7ae6246a83500
SHA3 405197e494160d4b5a4dcd4c85f5c37aec35e6096e3881d76dd9de5caa7ed48b

103 (#3)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x518
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31512
MD5 996df2a003938c8856634d72462e49d2
SHA1 ae2125661991d40c591bccc18916552cd69df0ac
SHA256 dfeae7d440bc4592034bb9ecbf2650f5962baa8139fbb76d8dfc8145463d7c2d
SHA3 27582f16a9b9154e13c1cf269e60c5b2a6fb03d1cb9ad723aa81f686d326ca6b

104

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x882
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30076
MD5 8e106743bbef67b67524c55abc228502
SHA1 54d52eeb22a579715fdde964baac0d1afbf8fda0
SHA256 74d115ec86f79688b003cd6dae785c83f625d629fca53f01c4f62c66cd2b9259
SHA3 0a706cc0736c5f601422616f0acbe847c6f2da4c501730b7e309b66313816c46

105 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x23e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19238
MD5 06edef821c76d22d12e74ba1168288ca
SHA1 c0340707d2a433fe5653a02a47056768b70bbb56
SHA256 2f10839b8abc5bec394bc2389c837cada9f749f37709785f3c5c39c7ff4b79f1
SHA3 f9f2bb2a377e3b7328788c1dba336e8d7372eb41e8b113b801f6faef9ee63fda

107 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15299
MD5 9a30cc9184933a7dd33bd6c8fdd62186
SHA1 f91d2f6d8864056b39355e2738a99e5d8df4c36c
SHA256 0e579051f7b62089b2979d829899aeaa0832ae0958cc7e008cfaa97215fc6bbb
SHA3 ffd56301210819028aabf974d4b02243944c1c632fa07715e9417e74d47ebe9c

108 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x12c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.03478
MD5 cb162d691f497a1761ec48f0e6828b18
SHA1 c6d79b825b23ae71018ec6aa66482d69cc5e568a
SHA256 2850820eebabc52e8bca80a49c27705a4a1338ac59880768c3534bfeb4d64d70
SHA3 450bc81f18e39342f7fdb906df7dc932eb5b0adab53a5907291ae5c636242f7d

113

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.00435
MD5 2e380bcf668e5fa19b962bd6bc8539a3
SHA1 08b0fe9523d1bc1e003363e1f04ee6845ad473c4
SHA256 3886b598186390b5a956feaaef8a950ce45d4c72f70dc93e7680f6bc757cb153
SHA3 7bd4210336187618deb86270b0fdca1eea501a4d2eaeaf2497394f86ebb883f4

114

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xda
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.98194
MD5 e22ba1942e4dfc0da36561f522ca975b
SHA1 d6f09610bc0302abfd1a522c95e556fdf899dc0e
SHA256 e8e471c3d1a5a410287dd2929671d4cb869dba02f0a04e0edaedf6299135b74f
SHA3 94364ed2b35183141290fdaa0fc0c80640932834ebdc6517f2f491da8a5b2b76

115

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x110
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.12316
MD5 645c31bad035c67cd24e1248664e5c93
SHA1 786a29cd8f11ab877fb2e9cd94947df7d529d771
SHA256 da900c97e87ff670a75593ea6d41ea507be3ac9a2f5c945a90635cdccb78dbd1
SHA3 e041f3fe554c2877fe4223b31664f17ccb2b32b680ea61d497cdd33972a18d02

116

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x20a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1073
MD5 8f5780a9d2c854f81bc3680372d0dfc6
SHA1 94e272a1f90415a225ef646272aa65e9e0134802
SHA256 701b6195e8ddf73fa48a23d815b706245cdb60a420ed70c4fcfc540312efe385
SHA3 20d8fe627d8e8faef881d0d552f2d18afad992aeb2765e3c7557ef375e4673a6

117

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xba
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73605
MD5 35cf75ad805192501e0d43678aad915a
SHA1 ae711e014dc29280949148781fcd9fa8671a54ce
SHA256 767a61525a32aa6b2b0afc4fc57a95f0e7039ad9eec5e2d5c6a84559ef30132c
SHA3 fc46884c60369f9127f320c96642c2d823683e30c3a44d9db8c92c7836f52eb0

118

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xa8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.9224
MD5 303f1b34eae85370d33999f6a62c6415
SHA1 12d2571ce1eace6158ff7b2faea6b9db91beb4df
SHA256 747f577e722d2063f12aa050f4199b5ff0b89c1f9156cdad0e889f27bbdca399
SHA3 e40e0d332df5973d9f471ffe0bcb6e86c6d40655e21924d981fbc44b8623b655

119 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x12a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.99164
MD5 0ce4d40a9b9d5774c92f9fb6b64335c6
SHA1 7de32eb8e4725a71e32e53fe3ac2a10424d5203d
SHA256 cfd165dcb26e6c716665602801ca7effca26f782ce102c979534d48676173a67
SHA3 d456d57deae5a09df7adb69de776aa758d730d797731b752852c9a263c2736eb

120

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x422
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.06351
MD5 9681e0ecef2c0e5d3b2626f56bebbd1a
SHA1 4903b6b443457ca1d06806662846a7906b29ced4
SHA256 1408114c1891c6c912d0a8dfec43824c5906fdb96040b54e9451088a162e3e2d
SHA3 d7a0f27c74408177e08aca00c68cf007630eb10b8c5cc26717e33a078e7f2214

126 (#2)

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x5c2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.19674
MD5 97f1458b319d8d0bcdc24cdf41c881fd
SHA1 65bc091816477ce32269920cbdec0ffd926e7338
SHA256 2f52b9ca6f9067a7bfa332a7db0f83e91fbf35a69dad91c06db021d00e5fa427
SHA3 f7981ad5dcba3f60e06900e2f289b1a1c907829bd86a3e25c52d7f76cea12db4

134

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x40
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.8271
MD5 2a7cd4ea0f93e2fb6561cb5fb4aa7d69
SHA1 da779b312d158781d77fdbc60c005e31e8d9d9ea
SHA256 823ed0db3f36524b80b1c8b7e345ab6c26800146e46b8eb3e91c5d178f73036b
SHA3 d0b4765b01007a339ec7771bf1352befbc9bdacb41771a347d9c70a1354a304b

135

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xcaa
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26135
MD5 239bdcafc38882b5d957a14e67896c9f
SHA1 c6f52938f623e5b6bf290bba6c7e634197fd25a5
SHA256 171bdccdb353a57e344016889875fbb9e35a16556823612262e874299a7235bc
SHA3 877451b70fc403261b472b977b9bce17feb25c84078ba0a2a6f8d880d356c622

138

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x284
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.05682
MD5 af903ea988d9c258669f8065498f8443
SHA1 63568b38870319bb42f5cd340dfb60071c5c935a
SHA256 09415964952f4d877de78ef9761a9516d18967d4eda1a5e56e7714d5f64bea3c
SHA3 68c9cba0c1ec5b16a203345813a9d33de30ffdc11c1cde7df3b3ddc302112d46

100

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 409e1724611e0bc39356e2f58888db55
SHA1 c06c0e66cc2f7956256e2f018aa0294bfa914960
SHA256 6ab18c3b81a5d30c5a190a4504cae807d73b1a4d02d56ffddf641abbb62b7210
SHA3 315b2ad40793f4ef885ff4c878169b02c62f619b57780a98a76c8538cd0ee5c9

112

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.32322
Detected Filetype Icon file
MD5 fc5da5253f4b97b58536299cc2062134
SHA1 cb7570d0fa85ad41efde439dc5744f344f9726ae
SHA256 7a08031f75135d4fae812d5b19935e247b73f02af232e35930c4c0ea355f10d2
SHA3 edb4705e19676bd4a0ae922b1ae9d2bf51deb437ea4b6c79f1edbfce58e28ca9

217

Type RT_GROUP_ICON
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.22322
Detected Filetype Icon file
MD5 25b4317405477359610e9d0120dae543
SHA1 b13ca8799b90f0050503c70ad42b8de6241ab325
SHA256 437eefb07f479ab5d002a5515ae0c3217542f162eae067c3107abf7fca02ad36
SHA3 f025d5740690a7014b61270c97d1916aece9f3f3c6d6612980649078010eddbf

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x460
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46735
MD5 caba71f52c2f9fc9f8b262c06979a010
SHA1 d23398f52efd5bb96e3a23d9ed53a015a73f8ed6
SHA256 ac557da913c18e4b6ef39e93d206ef9642c4030e92e625315f1250dc67bb8982
SHA3 28fb2624d402ca1071a02ffb75c8dff36dbb0ac571286407e08fe21cb02980be

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x52a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.27162
MD5 0f041ca264480e046e8120faf08240b1
SHA1 972c3077e12dce138a91708d95501bada3c2c99c
SHA256 b770fed869fa80a22c93881d3f2f5c3011ad2e935f006610cfae636bf3957faa
SHA3 30563048a5e75f389b1f0b62f4026c1478e13c339ebef29178c1958b2843ae96

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x280
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.07176
MD5 0f3b71d0fa474d73aff7de9cdf842732
SHA1 7990f81c60b8ab722c5ad7367f69c85106be5ed5
SHA256 5055de34114f55b1bfafbbbda68ec60c4291109780b9c197557b7c222c9a4e09
SHA3 c819cff55bde393211a32de2e92c070f295200f1b580ba63c6d18be15e762375

String Table contents

Setup Initialization Error
%s
%1 Setup is preparing the %2, which will guide you through the program setup process. Please wait.
Checking Operating System Version
Checking Windows(R) Installer Version
Configuring Windows Installer
Configuring %s
Setup has completed configuring the Windows Installer on your system. The system needs to be restarted in order to continue with the installation. Please click Restart to reboot the system.
%s
Choose Setup Language
Select the language for this installation from the choices below.
The installer must restart your system to complete configuring the Windows Installer service. Click Yes to restart now or No if you plan to restart later.
This setup will perform an upgrade of '%s'. Do you want to continue?
A later version of '%s' is already installed on this machine. The setup cannot continue.
OK
Cancel
Password:
Install
&Next >
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 6 (or later version), before relaunching the installation
Error writing to the temporary location
Error extracting %s to the temporary location
Error reading setup initialization file
Installer not found in %s
File %s not found
Internal error in Windows Installer
Error populating strings. Verify that all strings in Setup.ini are valid.
Restart
Setup needs %lu KB free disk space in %s. Please free up some space and try again
You do not have sufficient privileges to complete this installation for all users of the machine. Log on as administrator and then retry this installation
Command line parameters:
/L language ID
/S Hide intialization dialog. For silent mode use: /S /v/qn
/V parameters to MsiExec.exe
Windows(R) Installer %s found. This is an older version of the Windows(R) Installer. Click OK to continue.
ANSI code page for %s is not installed on the system and therefore setup cannot run in the selected language. Run the setup and select another language.
Setup requires Windows Installer version %s or higher to install the Microsoft .NET Framework version 2.0. Please install the Windows Installer version %s or higher and try again.
This setup does not contain the Windows Installer engine (%s) required to run the installation on this operating system.
Unable to install %s Scripting Runtime.
Unable to create InstallDriver instance, Return code: %d
Please specify a location to save the installation package.
Unable to extract the file %s.
Extracting files.
Downloading file %s.
An error occurred while downloading the file %s. What would you like to do?
hr
min
sec
MB
KB
/sec
Failed to verify signature of file %s.
Estimated time remaining:
%d %s of %d %s downloaded at %01d.%01d %s%s
Preparing to Install...
Get help for this installation.
Help
Unable to save file: %s
Failed to complete installation.
Invalid command line.
/UA<url to InstMsiA.exe>
/UW<url to InstMsiW.exe>
/UM<url to msi package>
/US<url to IsScript.msi>
Setup Initialization Error, failed to clone the process.
The file %s already exists. Would you like to replace it?
Could not verify signature. You need Internet Explorer 3.02 or later with Authenticode update.
Setup requires a newer version of WinInet.dll. You may need to install Internet Explorer 3.02 or later.
You do not have sufficient privileges to complete this installation. Log on as administrator and then retry this installation
Error installing Microsoft(R) .NET Framework, Return Code: %d
%s optionally uses the Microsoft (R) .NET %s Framework. Would you like to install it now?
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 3 (or later version), before relaunching the installation
%s optionally uses the Visual J# Redistributable Package. Would you like to install it now?
(This will also install the .NET Framework.)
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running Windows 2000 Service Pack 3 (or later version), before relaunching the installation
%s requires the following items to be installed on your computer. Click Install to begin installing these requirements.
Installing %s
Would you like to cancel the setup after %s has finished installing?
The files for installation requirement %s could not be found. The installation will now stop. This is probably due to a failed, or canceled download.
The installation of %s appears to have failed. Do you want to continue the installation?
Succeeded
Installing
Pending
Installed
Status
Requirement
Failed
Extracting
Downloading
Skipped
The installation of %s has failed. Setup will now exit.
The installation of %s requires a reboot. Click Yes to restart now or No if you plan to restart later.
%1 optionally uses %2. Would you like to install it now?
Downloading file %2 of %3: %1
This installation lets you install multiple instances of the product. Select the instance you would like to install, and then click Next to continue:
&Install a new instance
&Maintain or upgrade an existing instance
Default
Instance ID
Product Name
Location
This installation lets you patch multiple instances of the product. Select an option below to specify how you would like to apply this patch, and then click Next to continue.
Patch &all of the existing instances
&Patch an existing instance
This installation requires Windows Installer version 4.5 or newer. Setup will now exit.
Decompressing
Version
Choose Setup Language
Select the language for the installation from the choices below.
&OK
InstallShield Wizard
Cancel
&Next >
< &Back
Do you wish to install %s?
Authenticity Verified
The identity of this software publisher was verified by %s.
Caution: %s affirms this software is safe. You should only continue if you trust %s to make this assertion.
&Always trust software published by %s.
This software has not been altered since publication by %s. To install %s, click OK.
InstallShield
Preparing Setup
Please wait while the InstallShield Wizard prepares the setup.
Finish
Transfer rate:
Estimated time left:
/s
%s - InstallShield Wizard
Exit Setup
Are you sure you want to cancel the setup?
&Install a new instance of this application.
Existing Installed Instances Detected
Select the appropriate application instance to maintain or update.
Setup has detected one or more instances of this application already installed on your system.
&Maintain or update the instance of this application selected below:
Setup has detected one or more instances of this application already installed on your system. You can maintain or update an existing instance or install a completely new instance.
Select the instance of the application you want to &maintain or update below:
Display Name
Install Location
%s Setup is preparing the InstallShield Wizard, which will guide you through the rest of the setup process. Please wait.
Error Code:
Error Information:
An error (%s) has occurred while running the setup.
Please make sure you have finished any previous setup and closed other applications. If the error still occurs, please contact your vendor: %s.
&Detail
&Report
There is not enough space to initialize the setup. Please free up at least %ld KB on your %s drive before you run the setup.
A user with administrator rights installed this application. You need to have similar privileges to modify or uninstall it.
Another instance of this setup is already running. Please wait for the other instance to finish and then try again.
Security Warning
Do you want to run this setup?
The origin and integrity of this application could not be verified. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
I &do not trust this setup
I &understand the security risk and wish to continue
The origin and integrity of this application could not be verified because it was not signed by the publisher. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The origin and integrity of this application could not be verified. The certificate used to sign the software has expired or is invalid or untrusted. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The software is corrupted or has been altered since it was published. You should not continue this setup.
This setup was created with a BETA VERSION of %s
This Setup was created with an EVALUATION VERSION of %s
Please enter the password
This setup was created with an EVALUATION VERSION of %s, which does not support extraction of the internal MSI file. The full version of InstallShield supports this functionality. For more information, see InstallShield KB article Q200900.
This setup was created with an EVALUATION VERSION of %s. Evaluation setups work for only %s days after they were built. Please rebuild the setup to run it again. The setup will now exit.
This setup works until %s. The setup will now exit.
InstallShield Setup Player V23
The path to the installation contains unsupported characters. Try moving the installation to a location that does not have special characters, and then try relaunching it.
This setup requires administrative privileges that appear to be unavailable. Would you like to try again?

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.8.7000.0
ProductVersion 1.8.7000.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_DLL
Language English - United States
CompanyName CMS Online
FileDescription Setup Launcher Unicode
FileVersion (#2) 1.08.7000
InternalName Setup
LegalCopyright Copyright (c) 2016 Flexera Software LLC. All Rights Reserved.
OriginalFilename InstallShield Setup.exe
ProductName CMS Terminal Integration Service Installation
ProductVersion (#2) 1.08.7000
Internal Build Number 169350
ISInternalVersion 23.0.288
ISInternalDescription Setup Launcher Unicode
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2016-Aug-20 18:35:44
Version 0.0
SizeofData 92
AddressOfRawData 0x10a328
PointerToRawData 0x108d28
Referenced File C:\CodeBases\isdev\redist\Language Independent\i386\setupPreReq.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2016-Aug-20 18:35:44
Version 0.0
SizeofData 16
AddressOfRawData 0x10a384
PointerToRawData 0x108d84

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x5309a0
SEHandlerTable 0x50c640
SEHandlerCount 1494

RICH Header

XOR Key 0x87563365
Unmarked objects 0
211 (VS2012 UPD1 build 51106) 11
C objects (VS2012 UPD1 build 51106) 1
ASM objects (50929) 23
C objects (50929) 141
188 (30716) 3
C++ objects (50929) 66
185 (30716) 21
Total imports 497
C++ objects (VS2012 UPD1 build 51106) 64
Resource objects (VS2012 UPD1 build 51106) 1
151 1
Linker (VS2012 UPD1 build 51106) 1

Errors

<-- -->