Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2001-Aug-18 01:42:57 |
Detected languages |
English - United States
|
Debug artifacts |
.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion | 6.00.2600.0000 |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.00.2600.0000 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE header may have been manually modified. |
Resource CABINET detected as a CAB Installer file.
The resource timestamps differ from the PE header:
|
Info | The PE is digitally signed. |
Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA |
Safe | VirusTotal score: 0/56 (Scanned on 2024-09-02 10:02:58) | All the AVs think this file is safe. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xc8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 3 |
TimeDateStamp | 2001-Aug-18 01:42:57 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 7.1 |
SizeOfCode | 0x8800 |
SizeOfInitializedData | 0x38d800 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x00005A5E (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0xa000 |
ImageBase | 0x1000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.1 |
ImageVersion | 5.1 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x39a000 |
SizeOfHeaders | 0x400 |
Checksum | 0x3a713b |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x40000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
FreeSid
AllocateAndInitializeSid EqualSid GetTokenInformation OpenProcessToken AdjustTokenPrivileges LookupPrivilegeValueA RegCloseKey RegDeleteValueA RegOpenKeyExA RegSetValueExA RegQueryValueExA RegCreateKeyExA RegQueryInfoKeyA |
---|---|
KERNEL32.dll |
LocalFree
LocalAlloc GetLastError GetCurrentProcess GetModuleFileNameA lstrlenA GetSystemDirectoryA RemoveDirectoryA FindClose FindNextFileA DeleteFileA SetFileAttributesA lstrcmpA FindFirstFileA lstrcatA lstrcpyA _lclose _llseek _lopen WritePrivateProfileStringA GetWindowsDirectoryA CreateDirectoryA GetFileAttributesA ExpandEnvironmentStringsA IsDBCSLeadByte GetShortPathNameA GetPrivateProfileStringA GetPrivateProfileIntA lstrcmpiA GetProcAddress GlobalUnlock GlobalLock GlobalAlloc FreeResource CloseHandle LoadResource SizeofResource FindResourceA ReadFile WriteFile SetFilePointer SetFileTime LocalFileTimeToFileTime DosDateTimeToFileTime SetCurrentDirectoryA GetTempFileNameA ExitProcess CreateFileA LoadLibraryExA lstrcpynA GetVolumeInformationA FormatMessageA GetCurrentDirectoryA GetVersionExA GetExitCodeProcess WaitForSingleObject CreateProcessA GetTempPathA GetSystemInfo CreateMutexA SetEvent CreateEventA CreateThread ResetEvent TerminateThread GetDriveTypeA GetModuleHandleA GetStartupInfoA GetCommandLineA LockResource LoadLibraryA GetDiskFreeSpaceA MulDiv EnumResourceLanguagesA FreeLibrary GlobalFree |
GDI32.dll |
GetDeviceCaps
|
USER32.dll |
ExitWindowsEx
wsprintfA CharNextA CharUpperA CharPrevA SetWindowLongA GetWindowLongA CallWindowProcA DispatchMessageA MsgWaitForMultipleObjects PeekMessageA SendMessageA SetWindowPos ReleaseDC GetDC GetWindowRect SendDlgItemMessageA GetDlgItem SetForegroundWindow SetWindowTextA MessageBoxA DialogBoxIndirectParamA ShowWindow EnableWindow GetDlgItemTextA EndDialog GetDesktopWindow MessageBeep SetDlgItemTextA LoadStringA GetSystemMetrics |
COMCTL32.dll |
#17
|
VERSION.dll |
GetFileVersionInfoA
VerQueryValueA GetFileVersionInfoSizeA |
Please select a folder to store the extracted files. |
%s |
Failed to get disk space information from: %s. |
System Message: %s. |
A required resource cannot be located. |
Are you sure you want to cancel? |
Unable to retrieve operating system version information. |
Memory allocation request failed. |
Unable to create extraction thread. |
Cabinet is not valid. |
Filetable full. |
Can not change to destination folder. |
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup. |
That folder is invalid. Please make sure the folder exists and is writable. |
You must specify a folder with fully qualified pathname or choose Cancel. |
Could not update folder edit box. |
Could not load functions required for browser dialog. |
Could not load Shell32.dll required for browser dialog. |
Error creating process <%s>. Reason: %s |
The cluster size in this system is not supported. |
A required resource appears to be corrupted. |
Windows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation. |
Error loading %s |
GetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used. |
Windows 95 or Windows NT is required to install |
Could not create folder '%s' |
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue. |
Do you still want to continue? |
Error retrieving Windows folder |
NT Shutdown: OpenProcessToken error. |
NT Shutdown: AdjustTokenPrivileges error. |
NT Shutdown: ExitWindowsEx error. |
Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file. |
The setup program could not retrieve the volume information for drive (%s) . |
System message: %s. |
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again. |
The installation program appears to be damaged or corrupted. Contact the vendor of this application. |
Command line option syntax error. Type Command /? for Help. |
Command line options: |
/Q -- Quiet modes for package, |
/T:<full path> -- Specifies temporary working folder, |
/C -- Extract files only to the folder when used also with /T. |
/C:<Cmd> -- Override Install Command defined by author. |
You must restart your computer before the new settings will take effect. |
Do you want to restart your computer now? |
Another copy of the '%s' package is already running on your system. Do you want to run another copy? |
Could not find the file: %s. |
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator. |
The folder '%s' does not exist. Do you want to create it? |
Another copy of the '%s' package is already running on your system. You can only run one copy at a time. |
The '%s' package is not compatible with the version of Windows you are running. |
The '%s' package is not compatible with the version of the file: %s on your system. |
Signature | 0xfeef04bd |
---|---|
StructVersion | 0x10000 |
FileVersion | 6.0.2600.0 |
ProductVersion | 6.0.2600.0 |
FileFlags | (EMPTY) |
FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
FileType |
VFT_APP
|
Language | English - United States |
CompanyName | Microsoft Corporation |
FileDescription | Win32 Cabinet Self-Extractor |
FileVersion (#2) | 6.00.2600.0000 |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE |
ProductName | Microsoft® Windows® Operating System |
ProductVersion (#2) | 6.00.2600.0000 |
Resource LangID | English - United States |
---|
Characteristics |
0
|
---|---|
TimeDateStamp | 2001-Aug-18 01:42:57 |
Version | 0.0 |
SizeofData | 29 |
AddressOfRawData | 0x15d8 |
PointerToRawData | 0x9d8 |
Referenced File | .pdb |
XOR Key | 0x87d35f69 |
---|---|
Unmarked objects | 0 |
Imports (9210) | 13 |
Total imports | 126 |
Resource objects (9111) | 1 |
C objects (9178) | 24 |
Linker (9210) | 1 |