c770875f920d8f302d48095719bfbc9a69e045c19c62c7cbab3802d9391ae64e

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2022-Apr-14 16:10:23
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName TrainingCircle
FileDescription MC_TC_Medicine Setup
FileVersion
LegalCopyright
OriginalFileName
ProductName MC_TC_Medicine
ProductVersion 22.10

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Looks for VirtualPC presence:
  • 0f 3f 07 0b
Contains domain names:
  • https://jrsoftware.org
  • jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegQueryValueExW
  • RegCloseKey
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Queries user information on remote machines:
  • NetWkstaGetInfo
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 17649363 bytes of data starting at offset 0xf2200.
The overlay data has an entropy of 7.99999 and is possibly compressed or encrypted.
Overlay data amounts for 94.6798% of the executable.
Malicious VirusTotal score: 31/72 (Scanned on 2025-12-17 03:20:04) ALYac: QD:Trojan.GenericKDQ.E7D59AADEC
Antiy-AVL: HackTool/Win64.Crack
Arcabit: QD:Trojan.GenericQ.E7D59AADEC
BitDefender: QD:Trojan.GenericKDQ.E7D59AADEC
CAT-QuickHeal: Trojan.Ghanarava.175930402600f1f7
CTX: exe.hacktool.crack
Cylance: Unsafe
DeepInstinct: MALICIOUS
ESET-NOD32: Win64/HackTool.Crack.CC potentially unsafe application
Emsisoft: QD:Trojan.GenericKDQ.E7D59AADEC (B)
Fortinet: Riskware/Crack
GData: QD:Trojan.GenericKDQ.E7D59AADEC
Ikarus: PUA.Toolbar.Widgi
K7AntiVirus: Unwanted-Program ( 0059286b1 )
K7GW: Unwanted-Program ( 0059286b1 )
Lionic: Trojan.Win32.Crack.4!c
McAfeeD: ti!C770875F920D
MicroWorld-eScan: QD:Trojan.GenericKDQ.E7D59AADEC
Microsoft: HackTool:Win32/Crack!MSR
Paloalto: generic.ml
Rising: Hacktool.Crack!8.38F (CLOUD)
Sangfor: Hacktool.Win32.Crack.Vc5b
Skyhigh: Artemis
Sophos: Generic Reputation PUA (PUA)
Symantec: Trojan.Gen.MBT
Trapmine: suspicious.low.ml.score
TrellixENS: Artemis!566822FF245D
TrendMicro-HouseCall: TROJ_GEN.R002H09IM25
VIPRE: QD:Trojan.GenericKDQ.E7D59AADEC
Yandex: Trojan.Igent.b0WE64.1
alibabacloud: HackTool:Win/Crack.CW

Hashes

MD5 566822ff245dadeeb71fc44eaa00f1f7
SHA1 0dc9e8564c069c467b37da39cdedeaf135a14547
SHA256 c770875f920d8f302d48095719bfbc9a69e045c19c62c7cbab3802d9391ae64e
SHA3 b1a13f83385c20518a1c1d0369902cc6844f6610aea459742bf62ed4883222e7
SSDeep 393216:O/50VbRdFcuCAxwgHjrMfBpNr9319w9sEg16Y7vntcGk:H3FlCwdHjs/l0PY5Y
Imports Hash fdee3b3ee79abb17ecbd4ec56b850c57

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 10
TimeDateStamp 2022-Apr-14 16:10:23
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xb5200
SizeOfInitializedData 0x3cc00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000B5EEC (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xb7000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 6.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xff000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 43af0a9476ca224d8e8461f1e22c94da
SHA1 343a0e7ec6c87dae257270b90b9988a3ff95a078
SHA256 a933eb68996d3f040a1fd1b96644bc5ecb4cf24db4dbf6a183c3bdf58cb970da
SHA3 4956636187217f5ab0bfacdc669a09eb1b32ca43e880e21a9a8b4485c76f638b
VirtualSize 0xb39e4
VirtualAddress 0x1000
SizeOfRawData 0xb3a00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.35764

.itext

MD5 185e04b9a1f554e31f7f848515dc890c
SHA1 171aebbe52333ffd36593522a712b96644b565e5
SHA256 f2300e07e9ec20796b49419889cf04e55373c6ea8882ebfc9e5b98293abf1f39
SHA3 a06644cc8a8b31ea9e64a6b397b580b922b0164df58ac18c0d844f1cb3f3a138
VirtualSize 0x1688
VirtualAddress 0xb5000
SizeOfRawData 0x1800
PointerToRawData 0xb3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.97143

.data

MD5 cab2107c933b696aa5cf0cc6c3fd3980
SHA1 7a25edc4b9ed265b2ce19bbb507bad1985c6793e
SHA256 6989cae1abfc0b88395ba1b4bcba6666e761ebf84f60e307398aa3b1167f4391
SHA3 97e513aa29faa87a694f0eaed6c3eb70745d959d80266aa9dfb257240fea1c0e
VirtualSize 0x37a4
VirtualAddress 0xb7000
SizeOfRawData 0x3800
PointerToRawData 0xb5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.04865

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x6de8
VirtualAddress 0xbb000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e7d1635e2624b124cfdce6c360ac21cd
SHA1 b7d043cca31864ef4b86887de77ebb3db089c2bd
SHA256 0fb442dbff26887e09155bb592264ecd1c79eb990c6f5f9fb19dfb5c06d013af
SHA3 febefe199e39e017a02fcaf2f07cbba1193d24bcd6a7ee89fc3043d716a527f4
VirtualSize 0xfdc
VirtualAddress 0xc2000
SizeOfRawData 0x1000
PointerToRawData 0xb8e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.02909

.didata

MD5 8ced971d8a7705c98b173e255d8c9aa7
SHA1 fc7a6c0a1f7068ea13be23c825b3ea7a9f3ea676
SHA256 69e13a7ca25a6aa8673b450efedcd45cd767524b6a7b0e73b41ce4ca0b60dab1
SHA3 a5bb9c6245d3a3b721b06f8e557e005524671c891c2546b064ca54f28b919565
VirtualSize 0x1a4
VirtualAddress 0xc3000
SizeOfRawData 0x200
PointerToRawData 0xb9e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.75098

.edata

MD5 8d4e1e508031afe235bf121c80fd7d5f
SHA1 f602c8394c4325ebe7c172a76ee1b74fa463888b
SHA256 1cf7e5628c2f379389b92c6d152f31340f59f5a7fa1962a4e21f463a9a43c4cd
SHA3 ea4abc307e8c9faf299edd25c2a6a3ab7a52e483834ccee85205392cf0728ef0
VirtualSize 0x9a
VirtualAddress 0xc4000
SizeOfRawData 0x200
PointerToRawData 0xba000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.87716

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x18
VirtualAddress 0xc5000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 8f2f090acd9622c88a6a852e72f94e96
SHA1 735078338d2c5f1b3f162ce296611076a9ddcf02
SHA256 61da25d2beb88b55ef629fab530d506a37b56cfabfa95916c6c5091595d936e4
SHA3 4262d6da74e50fbc7d6e60433db7c15d7d5e5687da986212f46c20e57086ed57
VirtualSize 0x5d
VirtualAddress 0xc6000
SizeOfRawData 0x200
PointerToRawData 0xba200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.38389

.rsrc

MD5 be155a16e0d3368a803c33e062693cab
SHA1 17ed0295ff2938d42fcdef5c549de5aeb92a9c20
SHA256 3ff4030fdaaf114437592bc26c80bdab79c24bf2a1d1ab95cca510f9bda105fb
SHA3 6f9d48a60814c009bf1374d71bad92a7b77a15f32780a6f46a565b463f402dc6
VirtualSize 0x37dac
VirtualAddress 0xc7000
SizeOfRawData 0x37e00
PointerToRawData 0xba400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.44125

Imports

kernel32.dll GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxW
DestroyWindow
CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SysAllocStringLen
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetLBound
SafeArrayGetUBound
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
VariantChangeType
SafeArrayCreate
netapi32.dll NetWkstaGetInfo
NetApiBufferFree
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
RegQueryValueExW
AdjustTokenPrivileges
GetTokenInformation
ConvertSidToStringSidW
LookupPrivilegeValueW
RegCloseKey
OpenProcessToken
RegOpenKeyExW
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVersion
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xc3080
DelayImportAddressTable 0xc3090
DelayImportNameTable 0xc30b4
BoundDelayImportTable 0xc30d8
UnloadDelayImportTable 0xc30f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xbe63c

__dbk_fcall_wrapper

Ordinal 2
Address 0xd0a0

TMethodImplementationIntercept

Ordinal 3
Address 0x541a8

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x330
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.42079
MD5 6e1fbb1d4192b37d28d4e08f934ff264
SHA1 2d7856aeba20e36feded4017dd2e4d44f2fa7c1f
SHA256 b26ef611babc024508f4359771b86aff65f1c87311eaab0f2aa463e6c44a1f6d
SHA3 544ec6662b3d5f1fe9f353ad00ac7d57b02df58edd879037008c55076918c781

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x130
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70087
MD5 061e083fef7b3f095a14df2bfb207638
SHA1 c2fb85ffe3f05bb5629993fbb53ba6b67d97f4dc
SHA256 b88c2e25ead81d931c1fe9e1e33fe0068790ce45fd4114aa4aaffd3dfc7416ce
SHA3 b944c94fdd93e9d768c79dd8720e748c517e9d22bd231ecb136a479eff22118b

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xb0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.73724
MD5 3b13db7125298073fb16f7998e8af9e6
SHA1 401dcc8ff50b7784da9aba432a730af3165b6f05
SHA256 59f04ef45aeb22c7e34cb8d9f64c7990f7038a2a19ce4478b80005d1f4e86a45
SHA3 9b7437f07662f56b3b4b4166ed49697748c08b6d2f628866d3ac0ea993eb73e7

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1bc5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89044
Detected Filetype PNG graphic file
MD5 a87a2cba8b5938eed797d19c893b6fa0
SHA1 627a7e1ced37214df6f29f7ed6ad598b08e333e8
SHA256 3d080b4c10404f3e2de074089c947501a0a2258fc94ad021e89221bb15f0edf1
SHA3 78150c98dcd3a20568696b72634b212397f29587b4992af498ca6924271d33d7

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.99643
MD5 52d29e8953ba571b1f0fe5e11507c1e5
SHA1 a756fbc8b3f43ea98a06c83221d6ced30b45c5bf
SHA256 af5975cd21da86a4b98248d44a0b469bcf30ddd3ad52cc9682a76ef5bf3d0c09
SHA3 7891ba1ed9d13a16187e550e00323ca911614a1e9c438b5f95666ce1bd12fd92

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.13038
MD5 227b881021ca1bd1298fcda868e7e5fc
SHA1 b567664a2e05c50a09ea357a5aab6db8f126d118
SHA256 30f880691c37dc04ecfb8dcdd2367b9cb59b8747c290648c1ba39e0f77e79442
SHA3 0812f041242154f87371fc1d4038f2617cd0a443f500ef189ee1b958995f3137

106

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.09924
MD5 63b644bbe011923b9f4008a2ce0c83f8
SHA1 6be32651e4d55462c96a8cc08b98ec809cbedddb
SHA256 0311352b4d7716f093c6d81895ad1ab17338a335f17b8742ca54626c5422049e
SHA3 9569cc6ff9cee28d95998b2cd8fa1c2742d9e6c678822d01131079c1e7863e98

107

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.97515
MD5 c576a079023cc4a97f87407a4b23b640
SHA1 9a8dbe6cb5528831fd7d6a36ebe83a076bee0274
SHA256 52d00db5a42d722e47e5536767c2aa17d6b90ec80fbd6b6fdfe8f67327a3339b
SHA3 ddeac6bd3d2b8e0571da8e3f2b7ffad11939d50c4833d89f2e61751f6995a14c

108

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1129
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.62852
Detected Filetype PNG graphic file
MD5 b681d569d3064e5a2cd0a88c010e9968
SHA1 faaae9fc46904bbfcb7aa61609f51f7e23bbcc56
SHA256 809de0475970008f0c933d32ab74c835c4299cdef0474c64160d7c7012f468fd
SHA3 da1e056436a50c5755f36a363bd1357537fa9219477268be46e2581ff9caa29b

109

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.54497
MD5 d364cc97474005cc37906238e4863a76
SHA1 7deacdd8339addebc1cee3567a6c21fca21f5ab6
SHA256 04dd2683e2958eed4e3259d88c455b9a6ab62e1fe329fd9247f980663b8eb79a
SHA3 2afa2538a90737484a75756bb1cfd76a36f1dbb4d8909c2274473baa3dad1e65

110

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.43251
MD5 64a3791e64266da60e867081c4383ced
SHA1 d2944d7cda049fe35ae2f53bbc66f47b85593e7c
SHA256 5ba20b32e640c34d5149b1f2189aa2d03b07d4dc0869c8a8ccf857788dd88a08
SHA3 d597a85dca9bf97748b205fbe8d9c6f4152a5af5bf9370abd9263f6a2435e483

111

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.26905
MD5 27bdb20ba11eb0d726ee6a62e51ae1f8
SHA1 e06b4812ce147d34e86908fd3f03fd0e2c7dad60
SHA256 4cde4eb5d40c87f16a66079c140c9d656ba7a4e13e30dd981c756ffe29432501
SHA3 05e4db65909e740d2d5e4f235f5748eb07dbffb2f6e4d90a78e4e55e1e93e874

112

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.866215
MD5 bcf0851eafd4f1b770ab6e4c2d77f5bc
SHA1 90cda4327edb9bbae1ff06a6e78fbef7f28c8bdc
SHA256 d3dd4e097a8288fdd373ea646f175531fc68f83813f5b5fa63a32dfe93620465
SHA3 cb28796cb633eadce634750ec558e23e8f9a4d0e839eb50f6026af78205cc269

113

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xcf0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.59344
Detected Filetype PNG graphic file
MD5 8df8b8ac1133d411bab542642851ac13
SHA1 3ea6289e5535b627bda70ee7314ff51d1901e86e
SHA256 027c1b68a0821c4149a17caa60c7576f5617f431eb3905ecb46b245fa56eb6b1
SHA3 19daa6aec79af280e7b73c97e7b264c41c821ca51d35382e8021c4b5fcb3f1b5

114

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.18548
MD5 aaf93f6d03408b0e1957f4e72e994701
SHA1 c860ec657e1fd5e6f32b9d48eafa9ba7203677d5
SHA256 d6a42153d06e19cfac51bde04fafdf8fd726fa401f13c150fc0bf50d4c079d93
SHA3 b91fcd31bd52efca765ef8b8021402a407b6550fad03d8d86df788eb18a61cd9

115

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.41886
MD5 a479af1896ca96ef0c75b87aa6b87130
SHA1 6ef5d8f86a716efe17ba4d7593561b4dfee2a0ad
SHA256 28841f732d4de21e3c5c91da14f068c38ac6e4aef31b3a74942a7c5a32884578
SHA3 288b5a49e394c023490ddb70486a3995ed6577bc3aecc5f5c07f331fa7460312

116

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x67e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.40188
MD5 5743a577ec2f530ace81062c50d50b22
SHA1 d9aced5d2e35cd201ecaa6c4a0e8fc53252ec30d
SHA256 07e253c4c0dd43cdf030e0bfb39762bd8e241ea8f183c47317b61900c7a64ee6
SHA3 319f3b777b7e3b3a475d781b4c8b2767e429402363f9aed28a5cee7ef9174ba1

117

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5488
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.50272
MD5 dda08ae38740daa02c479bb09f16e713
SHA1 214d16dfd16ad86e63f8e466fea8b6a8104baa9c
SHA256 ff90f749edb68c04eb90b0b85f35a57bdb50bced66fdc736c94016b4eca95d10
SHA3 ff8bd99b49875598cedfbcc2c188b0ece58552f1f7729a5cc610aa6c165ab4c5

118

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.31126
MD5 1410edd3da2b9fea3aa07022f1d6b8db
SHA1 b7515bc44033b6bd92778578df379c8d42708903
SHA256 db5005fccb2b1c09b255e664080776fb691f902dd75403b10900da9d66ea510f
SHA3 7f7166058f858650604b53646d99b4adde1a84f80a08a55945edd4dd195a7140

119

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.6995
MD5 b22740d3cee598e10c96b320f7b6a652
SHA1 3d1a16724374a8abdc32c851d21ec6a35cc8e087
SHA256 c7f1012e7774a53bd979ed7b66aee54b70cbfefc7c183e88ecb5a35a1fac9e59
SHA3 66ee267188f92a8ba24defee5b5f96aab4bb273b02846442cfad00657e220b51

120

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.87459
MD5 7c339cf1a16fbe8227b005da720db9f1
SHA1 70566c00749686f2e5e9c6fbbc203eec2ce5022e
SHA256 f0c9a1880afb04ee21edbeaf1ed0f6bcec249e35e77750b725fd79a50e9891cf
SHA3 d636927374a182f3be3478c1f40d27ed166bfe2266abddc06fdc9036439cebb2

121

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.79934
MD5 c22d5d1222bec87c16154c0f73c21780
SHA1 e5f30d7dbaf9a57d4ee01ca9dbb110a32ab578c8
SHA256 7f39c732fdc9a69ebcceb0e1f3acf92eb161dda31b1d24d7413230987ba54620
SHA3 5d34560627eedca82cca60c199b7347938f315f88ab3e545ed4f8caf232cf5b8

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.16547
MD5 98da6167be9a4eb3be8bab5877938ff2
SHA1 95641a365d88f070bcbd921d99bc1c034e92340e
SHA256 bb650ee3d30d21f22fc7853936b06be7cbfd05b4d88ed105d3e53774dae7f21f
SHA3 a9d9128c3f3c8d4c2c598c48390a012af7847fd0aadc64df63e86a25983aa7ad

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x260
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40938
MD5 21cba6c9d478ce13ad53587cdd7f21f8
SHA1 ed16991f4f735f8258ff195bed5f1641d1405cc9
SHA256 0852b5fce0c5b7ff53fe4c4163983daf8a2057d5481911c24253f330bfd65d9a
SHA3 434f4417d656f3e62678eccd5c3445487e21059d8fc5084f62fc19899ef6d1dd

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x45c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31153
MD5 09208f24be8c3f3b08c323e9836db5e6
SHA1 054aa93663138220373081b25672499d38cb2eaf
SHA256 4be11ded6c924c3181c0b2a17cbf6f017fbf2b074adadaae213a330711e22cd1
SHA3 9e72f2e022b1768e8723c2c93ceb39a4909564dee4d43bb3537ddd9ae9e381f3

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33977
MD5 aeb11111a0334d20d978e15c3eb3ebab
SHA1 19969a1f68d497f0114538352da478b41c3d2060
SHA256 99b7194bf59ac43cbbdc441ab7ca14ab0330449accd33730281da09bb96bcbe3
SHA3 b734c35baae6e8fb009f07d3a20892bde53b7db5335b1327e1118e89d657251b

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31895
MD5 4ac29bb5f7361e85771807112cd4ec93
SHA1 b164bf0882b60c0d7d4643495a2c1db5a20a1343
SHA256 2e6d8102640132ccabd2fa3c3a61c77c2b41a80d7f60013cf7149819c2b5c9d2
SHA3 ee5ab8846732cb786d250fc1780293072aff157ae61cf7f671eb4e6e29018bf7

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45
SHA1 30704560832bafa440df1fd20693653c2a30f815
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20462
MD5 def52a5b1e8bba58fe020b2c959f5c4f
SHA1 f9e4dd288cf9c760941cadb475675c52e660a4e3
SHA256 19151c084fcd30aed2f27deed3ec77351f27a94fd9618da56258ea03bbcbc7f3
SHA3 b618636930a1e8d8e18593541407308cd9e02d95555415c499c3a292b4693cc4

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.69463
MD5 e4642e6c203852b2a2ceb607d0fac2b5
SHA1 f41d59529b76372664b7e7753c49a36a886f6daf
SHA256 fa81ab29bb0bde66a8a315e169daeb81360329ad4eb9463fd4fda5d412aff476
SHA3 55328d099982e32cfee90536a812615ba5ea6a8343d894f671c2905e708eb786

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x13a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5166
Detected Filetype Icon file
MD5 c11845b2d02ad8ab9cbf463aa091081e
SHA1 5fef8cd695142e1e29d6e99c08d84ae41e06de9b
SHA256 296c24c74a40221669c98aff3308fac85f3a9a1af75bd9d79849179b8d99a3fa
SHA3 9d3c8c058a1b7dc2d91081118f1a1cc5501a487c9a2ef7daecebbce6a650da84

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.55864
MD5 890e933d0e7abba7d7715e40fad99bdf
SHA1 73f346ee91dc93255ed37598a762a456db3bf641
SHA256 693a627b80c9e114accb918bf296c93c362cd3f15dc58863bf13b10f6e170790
SHA3 6c167045ba6630aea2a0acb299f3c3e557bfdb7e067a395781faadd35febacb7

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x765
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.1883
MD5 b600174b76059d432a205957f9e6dd87
SHA1 0ab8d8ece213974bc7ad3036b42c3ac416ffd111
SHA256 70f1422a4c288192971ccca7861b8a2045a7a5e5eaf7dda57c243e844c939258
SHA3 adb6d450ea12501fc9e910a7810465df13de5a7094653e34fb18e6578fb089b5

String Table contents

Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows 8
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Argument out of range
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName TrainingCircle
FileDescription MC_TC_Medicine Setup
FileVersion (#2)
LegalCopyright
OriginalFileName
ProductName MC_TC_Medicine
ProductVersion (#2) 22.10
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4c5000
EndAddressOfRawData 0x4c5018
AddressOfIndex 0x4b7c14
AddressOfCallbacks 0x4c6010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.