c99028b44b790598c92b8994d63c2dc3

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2001-Aug-18 01:42:57
Detected languages English - United States
Debug artifacts .pdb
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion 6.00.2600.0000
InternalName Wextract
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WEXTRACT.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion 6.00.2600.0000

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains domain names:
  • Command.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryA
Can access the registry:
  • RegCloseKey
  • RegDeleteValueA
  • RegOpenKeyExA
  • RegSetValueExA
  • RegQueryValueExA
  • RegCreateKeyExA
  • RegQueryInfoKeyA
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • CreateFileA
  • GetTempPathA
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetVolumeInformationA
  • GetDriveTypeA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE header may have been manually modified. Resource CABINET detected as a CAB Installer file.
The resource timestamps differ from the PE header:
  • 1980-Jan-21 20:26:08
Resources amount for 98.7769% of the executable.
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA
Safe VirusTotal score: 0/56 (Scanned on 2024-09-02 10:02:58) All the AVs think this file is safe.

Hashes

MD5 c99028b44b790598c92b8994d63c2dc3
SHA1 953184334defcae97cbd0c5380d915362dc284ca
SHA256 d072ec89ed39f294b0b9ba2a04db4a93d5784b80ed694888b482c9c878f149ea
SHA3 0a87007d2998536f3dff9f07c802f745ce4a88fa09bcedb6beb016ababde09dc
SSDeep 98304:G4iFvclHzqGBl3SdGXBsg33e9/kKBl1TVYonM+Un:GwHZ3SsXl3ehHvTVYon50
Imports Hash 1494de9b53e05fc1f40cb92afbdd6ce4

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xc8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 2001-Aug-18 01:42:57
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 7.1
SizeOfCode 0x8800
SizeOfInitializedData 0x38d800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00005A5E (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa000
ImageBase 0x1000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 5.1
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x39a000
SizeOfHeaders 0x400
Checksum 0x3a713b
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 43984be5cb414e4634db17caa4d1c30b
SHA1 03418ebc42b91a08a6b42629c02703d9d905e7a2
SHA256 73ce1945c52b1bf9a61f890d7650e8993de5d2f50f719d121e5401a060bd8f79
SHA3 3a4b9b8f9dff88fa6c19fcab446a368753a0110bd976c1b98ef49874bb505714
VirtualSize 0x861a
VirtualAddress 0x1000
SizeOfRawData 0x8800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.55102

.data

MD5 730893b14fc930a187215e7fb53bc0a5
SHA1 8d38660485ad9cbae834e4aa747167ff99f25bae
SHA256 58306fafd95a42b7b6e512d2f8cfe4726e7470978ccae8e4e24f8ed2ee9c26a3
SHA3 29ed3ce0a2433a4df2348ae38ea8baa22f7970b548b956ebef85e8a9d2801e6d
VirtualSize 0x1be4
VirtualAddress 0xa000
SizeOfRawData 0x400
PointerToRawData 0x8c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.18428

.rsrc

MD5 c11dec2afe9ca6bf2b2d07577d8d1c4d
SHA1 5f84be2b2e8c53be64870f5a78885d8e608e9130
SHA256 73cb884732de805c6680a5b3fffd9afdd676d135e92ffe27cfe8ec2b1028959c
SHA3 df0de8a99583bd22e9ced7336983d65d8be3e3343d674fa36f1a9d0b67daec83
VirtualSize 0x38e000
VirtualAddress 0xc000
SizeOfRawData 0x38d400
PointerToRawData 0x9000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.99791

Imports

ADVAPI32.dll FreeSid
AllocateAndInitializeSid
EqualSid
GetTokenInformation
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueA
RegCloseKey
RegDeleteValueA
RegOpenKeyExA
RegSetValueExA
RegQueryValueExA
RegCreateKeyExA
RegQueryInfoKeyA
KERNEL32.dll LocalFree
LocalAlloc
GetLastError
GetCurrentProcess
GetModuleFileNameA
lstrlenA
GetSystemDirectoryA
RemoveDirectoryA
FindClose
FindNextFileA
DeleteFileA
SetFileAttributesA
lstrcmpA
FindFirstFileA
lstrcatA
lstrcpyA
_lclose
_llseek
_lopen
WritePrivateProfileStringA
GetWindowsDirectoryA
CreateDirectoryA
GetFileAttributesA
ExpandEnvironmentStringsA
IsDBCSLeadByte
GetShortPathNameA
GetPrivateProfileStringA
GetPrivateProfileIntA
lstrcmpiA
GetProcAddress
GlobalUnlock
GlobalLock
GlobalAlloc
FreeResource
CloseHandle
LoadResource
SizeofResource
FindResourceA
ReadFile
WriteFile
SetFilePointer
SetFileTime
LocalFileTimeToFileTime
DosDateTimeToFileTime
SetCurrentDirectoryA
GetTempFileNameA
ExitProcess
CreateFileA
LoadLibraryExA
lstrcpynA
GetVolumeInformationA
FormatMessageA
GetCurrentDirectoryA
GetVersionExA
GetExitCodeProcess
WaitForSingleObject
CreateProcessA
GetTempPathA
GetSystemInfo
CreateMutexA
SetEvent
CreateEventA
CreateThread
ResetEvent
TerminateThread
GetDriveTypeA
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
LockResource
LoadLibraryA
GetDiskFreeSpaceA
MulDiv
EnumResourceLanguagesA
FreeLibrary
GlobalFree
GDI32.dll GetDeviceCaps
USER32.dll ExitWindowsEx
wsprintfA
CharNextA
CharUpperA
CharPrevA
SetWindowLongA
GetWindowLongA
CallWindowProcA
DispatchMessageA
MsgWaitForMultipleObjects
PeekMessageA
SendMessageA
SetWindowPos
ReleaseDC
GetDC
GetWindowRect
SendDlgItemMessageA
GetDlgItem
SetForegroundWindow
SetWindowTextA
MessageBoxA
DialogBoxIndirectParamA
ShowWindow
EnableWindow
GetDlgItemTextA
EndDialog
GetDesktopWindow
MessageBeep
SetDlgItemTextA
LoadStringA
GetSystemMetrics
COMCTL32.dll #17
VERSION.dll GetFileVersionInfoA
VerQueryValueA
GetFileVersionInfoSizeA

Delayed Imports

3001

Type AVI
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e1a
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.52241
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 f9035cf32b756fd6a452e9fdfd4a5dd9
SHA1 6912e88a3ee4d2c98ca69772cec564c6334fd9c4
SHA256 3bd1d253c90f7e82dc70dc1e4b869cc2e5e154e6b4079be93837e4a6c68044c0
SHA3 8cd00290363b6d3e609845f2e5828f3e2adaf35c4a97561bcf427bbd054401a6

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.75013
MD5 760b19b7b9c731af7673221f7781b99f
SHA1 a3b139e52af4b2004a0c7ceca80ff4101ba9b2c4
SHA256 ea5e771d2e590691c5c624a1204015a71d390ccb57781860f9cbc2fed1425f02
SHA3 41108697ba7383a73072bdcefd21fc18a240f55b1b1a2490c3cb172be29c6b19

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.53793
MD5 601aa6e69d0cd049a2c9b8177188a07f
SHA1 aa2266a300eb43df1c02acade8868980e3e80b41
SHA256 155ac1573c5f09ad098c18d0fa1cb6dc21081f0d969d743869938146abd9aa5e
SHA3 03a587ecb31a94af9cbfdc4c8c83585aca2a052ab723249ace5a4852f70f5576

2001

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2cc
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.35785
MD5 769011a5df32441735f096ddea7b0e07
SHA1 0319fb5891d937a6cfc63e0e63514430b843d36a
SHA256 a0ccefebb8b748d0468481e5a82890f499007fa81fda74b3273aa9b4c6461e67
SHA3 a54874a490e965d2675c90924abea2096afa187a3f8fd0aa4d4069b0bb126b7b

2002

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.34986
MD5 e97568f80f472e46e3195da9a1cf81c7
SHA1 cd79da76f373e2925ba469bb292e5647c9334b5b
SHA256 5723d7bfd7c984e35d5704cdbd8e35361e0d2d63af73397c820fdacc7a1764de
SHA3 6e9947644a684eb6ab4dff80fbb61cd0604a30365b831cacea04cbec1ec901f7

2003

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x140
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.21922
MD5 f57626df11e6296d34aba2b1cce53e2a
SHA1 7ab77fc005afc1a2d24397d9872b2c94f7aa9fdb
SHA256 856fbd66e2ad2243f9d6f077c1107b52a5828e3d596d202baa66b48e4189cf6d
SHA3 14420d3700506c88adcba3e925fa8a9ec3042b10c475a88ad5b021a226a1caf4

2004

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x196
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.32349
MD5 b4b7a4a6f9a6a2651aca59ad9ba0529b
SHA1 662f28d6eefc50bd9b015c7f83e4e4e192802f9d
SHA256 765756ad9676261a31eaebdc08d1c754401482163e3aa1d47450ab7eedc030ba
SHA3 3cd03ae9ce08ecff683c855a1bb12ff5d22cb0847da006ce934736877d2c93aa

2005

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x10e
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.19511
MD5 87d9cbe81b5fd7ae1d0d55cc0992f11c
SHA1 af223ec77472d77f22bab1463bed6b0198620a64
SHA256 253aea2de827095918561dbd9159889184401da67f3a72d0f1a6f94e6305e690
SHA3 8f795cdcdfae062f40095874a6db6d3e8f5dc055406b33f6991ff33c9b6c6354

2006

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xfa
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.26012
MD5 90fcaceed70158515129d540e28a9755
SHA1 c720320f9c6b6275160cda38baa59fe656efb0d6
SHA256 0a0e83c7a9c1aeede6b859461de64a0ca90fdb6a82912c19e30ec1dbec16fe33
SHA3 d26b66bd995a095e6b131cf54eef93bce005f8a3b65d37e2becf3122b608b21d

63

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x8c
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.48958
MD5 ad0fe039aecc9c8af6f573923f182a0a
SHA1 b4fd492a37127d31fc36b7bd07084cc2f1ae18a1
SHA256 29b228ae95784d37b8729fe88e3bf1346c4b1339231dd1e9f702fab0654c5b1f
SHA3 7a67b4664ab18841c125d33dbe110fe774b16f91d1471094307c0ac35be5d8a8

76

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x520
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.2674
MD5 0f3f664bff00f8c4a1b42349d2956963
SHA1 d0ec056db75705bd79b7ebf1767c91dce955d79a
SHA256 7cc882dbb9f1315968f31bf40b57a535ff468271e253575752e03cb4aaa25f0c
SHA3 a81b1ab97bb98d4fb6d1619bf8bdee495b3176693e77305e438805563e952b91

77

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x5cc
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.29977
MD5 5f3ef55a113dc5f00ffc647e8be50df1
SHA1 cf04ac59ce78d6b2ffde0990ef76cf40ee1c439b
SHA256 3f715c8970d240cb57ba8ae8914ea8385b42728ffd48a3916493422a80cc3ed4
SHA3 fdabc44cd05ee45599b1e28ee3ca323cd6768db6606bffe95ceb6025b31b4d2f

80

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b0
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.27174
MD5 1f268a77ca8f853ff0c410e622706bef
SHA1 75afb11daf446704dddb5ef5fe39b2009aecf01d
SHA256 39023f15fbabf4be02e0d84a76c363003374b11076406f84cd8f92e49aecd3ba
SHA3 5e684d700849b8552f5449c5869807ce32caa8ae657695824e4a41be4a2ee55d

83

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x44a
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.2912
MD5 586fc633195baca29ef84b9271b42689
SHA1 69d5712401f0ca87f897c68f3a07ee9e01de8a25
SHA256 c1a5490b8a26165048de894aacdcd25e09cec0c4aebc5ff1d435f2cc4757118b
SHA3 04492be8d1f2fd83ad6633ec69825c302118f6039586e9f2bd804e00fdcc0913

85

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x3ce
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.13591
MD5 949714f4f3946ad108bb0817d170c459
SHA1 01b3524390968f27c27943e9f06f145b8527f8de
SHA256 59d8ad57a3629edd20c7b298a6e3604eeb95dfc7c507ad7e329ea0bff7a571ff
SHA3 6447983c227f98b8cd5f4045d58626cd5f965fa8e9cb99c33a68a58136ceb655

ADMQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

CABINET

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x3871ee
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 7.99953
Detected Filetype CAB Installer file
MD5 64f53e2e48cd1635059956004cd5730b
SHA1 e023f20865087c1c2ddb0339790b31e049cac575
SHA256 e0cbc197ac6649e447f79801e17e3adc47189629ad61258d9c42b5041c7ac011
SHA3 1c5538956f1916445262b73e81f9bb2404eddb94552a04060f33c1cec80e8c4b

EXTRACTOPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

FILESIZES

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.04025
MD5 70e0a38873de5b518a56b3546fc12325
SHA1 db1725c67dba4369f9d3dc931946ccfd4baf65dd
SHA256 ea9603dfe15515de62556c20a4ef1289438eb6a6ef1ca089505253d58409473f
SHA3 33771f07463356952fa0094bc935a1bdb4e89802aab3d7cef15de17afe7b932a

FINISHMSG

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

LICENSE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

PACKINSTSPACE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

POSTRUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

REBOOT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

RUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1b
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.79192
MD5 e893905ccf0d40a1aa1815dc1d43ddbe
SHA1 feaa294cdedd5570ee1f2c6d1114878157798c3d
SHA256 b326545c1346783650415ab6f33d386a508959a3ac09e492c0ba84f1c0d3e4b8
SHA3 57d803d43edf47ef87f2241ee77f7ac2d8ad50c19c76800f8f7c13be791d138b

SHOWWINDOW

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

TITLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x11
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.69012
MD5 0d1c9e1c2dd32657bf0f6cf79aa00cd8
SHA1 27e23cbc28ae21ddc4aa557bce61bcf57a956303
SHA256 ca37fe88f5dc6de8c6039cec62e0b481200ab2b335570abea327ce6d7f5dc875
SHA3 1c52e654cf240e9faefdbb64784b07b1d29a6dd3cdd594b4dc6023a2c8943c1f

UPROMPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1a
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.99795
MD5 f6f7377b8bcb89c06b28efe9ae862c6b
SHA1 a17d5c2545a80bb211ee0a09f4df18e6d990ee80
SHA256 8ccde961ebf5e708eb9397d6331a1dc04d0f324b99bd602cf17aa43777d9cdca
SHA3 205eb6ffd4d78fe1a3913b90106d8d837191eff334e78668605d1a91b7037226

USRQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

3000

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 2.37086
Detected Filetype Icon file
MD5 d59e0d372ea5fd8c1f4de744376a6af4
SHA1 6883ce60e71a83424db0b41d0ab6bf61080e3de2
SHA256 b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b
SHA3 5e39df982879204dd9f129a37d1e1c2ff906e88de9ae01b4418db5e8455e7ae1

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-21 20:26:08
Entropy 3.34858
MD5 887ebfd7202ee50f41e9e689f9d8c2de
SHA1 292aae4935316ab55b5c8e0cf3b4e510e6036a24
SHA256 d9431cd542b8cf07aa1aac1bd71720e685524b676f2280d61ad5d5605074974d
SHA3 0c63aa5923e72a2375aaab4a6f7fed4f2502d4a98fb12398db149552d64cb90f

String Table contents

Please select a folder to store the extracted files.
%s
Failed to get disk space information from: %s.
System Message: %s.
A required resource cannot be located.
Are you sure you want to cancel?
Unable to retrieve operating system version information.
Memory allocation request failed.
Unable to create extraction thread.
Cabinet is not valid.
Filetable full.
Can not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.
That folder is invalid. Please make sure the folder exists and is writable.
You must specify a folder with fully qualified pathname or choose Cancel.
Could not update folder edit box.
Could not load functions required for browser dialog.
Could not load Shell32.dll required for browser dialog.
Error creating process <%s>. Reason: %s
The cluster size in this system is not supported.
A required resource appears to be corrupted.
Windows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %s
GetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used.
Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Do you still want to continue?
Error retrieving Windows folder
NT Shutdown: OpenProcessToken error.
NT Shutdown: AdjustTokenPrivileges error.
NT Shutdown: ExitWindowsEx error.
Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.
The setup program could not retrieve the volume information for drive (%s) .
System message: %s.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.
The installation program appears to be damaged or corrupted. Contact the vendor of this application.
Command line option syntax error. Type Command /? for Help.
Command line options:
/Q -- Quiet modes for package,
/T:<full path> -- Specifies temporary working folder,
/C -- Extract files only to the folder when used also with /T.
/C:<Cmd> -- Override Install Command defined by author.
You must restart your computer before the new settings will take effect.
Do you want to restart your computer now?
Another copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator.
The folder '%s' does not exist. Do you want to create it?
Another copy of the '%s' package is already running on your system. You can only run one copy at a time.
The '%s' package is not compatible with the version of Windows you are running.
The '%s' package is not compatible with the version of the file: %s on your system.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 6.0.2600.0
ProductVersion 6.0.2600.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion (#2) 6.00.2600.0000
InternalName Wextract
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename WEXTRACT.EXE
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 6.00.2600.0000
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2001-Aug-18 01:42:57
Version 0.0
SizeofData 29
AddressOfRawData 0x15d8
PointerToRawData 0x9d8
Referenced File .pdb

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x87d35f69
Unmarked objects 0
Imports (9210) 13
Total imports 126
Resource objects (9111) 1
C objects (9178) 24
Linker (9210) 1

Errors

[*] Warning: [plugin_authenticode] Hashing algorithm 1.2.840.1015.13.2.5 is not supported.
<-- -->