d5f4043f83f13763dfd2eec46f953c43a8af8e9590c8ea064368da16e1bb3ef4

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2014-Jul-09 07:58:14
Detected languages English - United States
FileDescription Setup/Uninstall
FileVersion 51.1052.0.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regsvr32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • http://www.innosetup.com
  • http://www.innosetup.com/
  • http://www.remobjects.com
  • http://www.remobjects.com/ps
  • innosetup.com
  • remobjects.com
  • www.innosetup.com
  • www.remobjects.com
Info Cryptographic algorithms detected in the binary: Uses constants related to MD5
Uses constants related to SHA1
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • SwitchToThread
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegSetValueExW
  • RegQueryInfoKeyW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • CallNextHookEx
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE is possibly a dropper. Resource HELPER_EXE_AMD64 detected as a PE Executable.
Resource SHFOLDERDLL detected as a PE Executable.
Safe VirusTotal score: 0/68 (Scanned on 2024-01-17 05:24:36) All the AVs think this file is safe.

Hashes

MD5 2fa595f58c3549bafa9deab66d35bf2c
SHA1 0a12c2dac8e1d27a77335519ffbd577df7f3b4f7
SHA256 d5f4043f83f13763dfd2eec46f953c43a8af8e9590c8ea064368da16e1bb3ef4
SHA3 201d99875b5bb61c8562468c428da725fdf025056e0618221e1f4130caccf8c0
SSDeep 24576:N1VqyG3T/+ofiDIZE2kChYYmpY9a2nWEdEC6GnJJ3Gm5zldCiqo9QBghvx93M:nQdhZgEN6GnJ95zDCNBg32
Imports Hash f2865f24295b7ad0db7648d00d4f377a

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2014-Jul-09 07:58:14
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xfe400
SizeOfInitializedData 0x66e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000FF004 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x100000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x172000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 f07528ad00ef563f25b078973ab74526
SHA1 7c881b5ff662b18f2e0993e1c15b213dcb02b183
SHA256 70a55a8282e34978f7330fc3daccbfd9191edf54983f911fae89047975ff03e0
SHA3 75651615bd958fd02abf99c2c3b6681b368aa0cd99cf968fc12af28ea74d61d9
VirtualSize 0xfcfd8
VirtualAddress 0x1000
SizeOfRawData 0xfd000
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48175

.itext

MD5 ee1623fb4bfbf53c6d7a796fee40c5b0
SHA1 339c83caf96ebda6fcb61aa18fe0b47b843a01a1
SHA256 12a7da153aa0120e49385cf2a55b5e5f2f54d4863d5c394de59a891c1a40e72a
SHA3 4f2efcb49f188d592128148ca06c071a341925bd08d9da2389ae703bcad37b67
VirtualSize 0x1220
VirtualAddress 0xfe000
SizeOfRawData 0x1400
PointerToRawData 0xfd400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.68971

.data

MD5 a563250498abf40b0297b5b019d7ed90
SHA1 30f03fd9d9c83cdf4c524f581f463a782ae36528
SHA256 f6e57769737ce84323d85bb348eb92ac4a9446d7efca99fb1b9af59d415aff44
SHA3 de90fc43dde70b503115e525630fa324fa47b37a81ec5bb867a0fdef7232d5b2
VirtualSize 0x3038
VirtualAddress 0x100000
SizeOfRawData 0x3200
PointerToRawData 0xfe800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.30712

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x618c
VirtualAddress 0x104000
SizeOfRawData 0
PointerToRawData 0x101a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 81c7429c9619a00840c630c4427dc350
SHA1 1d6b16c45694d7b5d99fa6d172a365f88c2b1ee6
SHA256 fab9a0550caa9a535cc23703d317d94a19a2f376c11bba7b5d13f64cb3324b60
SHA3 1b872b04d7b2e97a4f3ef7b374c2b224357b48bea077939bbc2fb595cab3452e
VirtualSize 0x37e0
VirtualAddress 0x10b000
SizeOfRawData 0x3800
PointerToRawData 0x101a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.25108

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3c
VirtualAddress 0x10f000
SizeOfRawData 0
PointerToRawData 0x105200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 543246b7273241d8e173a5d9dcb01e12
SHA1 08e4795542accb32fab8575088c8aa0aa48fc54f
SHA256 c1741bbc6976a4b366cde27903b58fe3ba20b7016415da2f710e05d8c0005ead
SHA3 2da238a9a667f36bd95317f5b247bdc071515439bd7c33e50ca2de45c39f5c12
VirtualSize 0x18
VirtualAddress 0x110000
SizeOfRawData 0x200
PointerToRawData 0x105200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.190489

.rsrc

MD5 ae2942c2eb97d0b58413e57c4a3dd3b9
SHA1 d2a90137e6af0545627473e7ca4482e9acd0bb60
SHA256 cc6182abda10065fa3fde8197e06f30132d5a601c134ae1b90450907832a3377
SHA3 ee583dd9d869f92c385a14baabab84d86a3d800f7a8c8293537e255d94a1a0bc
VirtualSize 0x6010c
VirtualAddress 0x111000
SizeOfRawData 0x60200
PointerToRawData 0x105400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.23059

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
msimg32.dll AlphaBlend
gdi32.dll UnrealizeObject
StretchBlt
SetWindowOrgEx
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SelectPalette
SelectObject
SaveDC
RoundRect
RestoreDC
RemoveFontResourceW
Rectangle
RectVisible
RealizePalette
Polyline
Pie
PatBlt
MoveToEx
MaskBlt
LineTo
LineDDA
IntersectClipRect
GetWindowOrgEx
GetTextMetricsW
GetTextExtentPointW
GetTextExtentPoint32W
GetSystemPaletteEntries
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectW
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
FrameRgn
ExtTextOutW
ExtFloodFill
ExcludeClipRect
EnumFontsW
Ellipse
DeleteObject
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateHalftonePalette
CreateFontIndirectW
CreateDIBitmap
CreateDIBSection
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
Chord
BitBlt
Arc
AddFontResourceW
version.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
mpr.dll WNetOpenEnumW
WNetGetUniversalNameW
WNetGetConnectionW
WNetEnumResourceW
WNetCloseEnum
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
SetCurrentDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCurrentDirectoryW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CLSIDFromProgID
CLSIDFromString
StringFromCLSID
CoCreateInstance
CoFreeUnusedLibraries
CoUninitialize
CoInitialize
IsEqualGUID
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
comctl32.dll (#2) InitCommonControls
shell32.dll ShellExecuteExW
ShellExecuteW
SHGetFileInfoW
ExtractIconW
shell32.dll (#2) ShellExecuteExW
ShellExecuteW
SHGetFileInfoW
ExtractIconW
comdlg32.dll GetSaveFileNameW
GetOpenFileNameW
ole32.dll (#2) OleUninitialize
OleInitialize
CoTaskMemFree
CLSIDFromProgID
CLSIDFromString
StringFromCLSID
CoCreateInstance
CoFreeUnusedLibraries
CoUninitialize
CoInitialize
IsEqualGUID
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
oleaut32.dll (#4) SysFreeString
SysReAllocStringLen
SysAllocStringLen

Delayed Imports

1

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x134
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

DISKIMAGE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x4e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27885
MD5 9f36c65260f5b9b63749b80e87baa108
SHA1 606acb721dc20da5f8e1feb0a3d174cefbee4eda
SHA256 5ef379b2771118b2ce2d78c915d48230d8f9d4e4905e62a9b7f150c009c7bc67
SHA3 eab22bc47d1eacf9a480dc79e6e8f754469badd850d0a591a4324406100b190c
Preview

STOPIMAGE

Type RT_BITMAP
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34815
MD5 f21ffbe1149520d40d1a034da636c6fd
SHA1 db7c7bc0cd61d73be92b71bbb535a172f77ef2b5
SHA256 ea9b569ac7e3d063e22795d5f428289938caa4b74272a8870ebbca46f21b929b
SHA3 f56506ed838ee62feb25b27b2446acb95fc801a8430101566713d7e1f3262c30
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.59986
MD5 f488f7974093826736928e6348c440de
SHA1 deec1638902ae3f72487ce18e4837ebf97cf43a8
SHA256 7f73c66a12d6315a5b642dde202df0d463d2b52c7c1c66acdf5bf185b47dbaca
SHA3 ac6859750ff2de2836fa29da52cd05326e3b52277b62cd0cec3bdc7c926030a3

2 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.72414
MD5 73fb8fec2756acc269ca9a3ad5de3f9b
SHA1 ca178a1bff74f553e67b89edc6aa7bdac389dd8f
SHA256 6cbc36d55d2bd0e3223564c91365f19ead63da8f93c1ea8e3219746574d326b6
SHA3 ff3b768a160936d53d7b090972f92aff0c447a41f8deccd6e9d8ce0177565d9a

3 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.74243
MD5 b0d257dd69c6959aecb3ac562af2906f
SHA1 b0a5f859a32838e74f9b6432e498ba7669e90987
SHA256 b26d9246a7a8a5adf065963511c12813d2a566c86324eaa5d142ac1e9fc16fc8
SHA3 bfdd88df27fee9b799b9587de69be8b3a0abdb422eec697cfc4b9162cd2493df

4 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.70487
MD5 1dd06f8ca4a13f5bb8bda59c12936bc5
SHA1 6bac0f260ff1daa7c1d4207d7d7da19e080adfad
SHA256 6f77eeb5e0c8dd9a7bff33c015885e1fd64daeaf61706320986791a20e865aaf
SHA3 65c16b77142c5f89a38014e173b56c29045c8e3f04362dbe3d1e6e37dc61ba75

5 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.71429
MD5 c2033e3da6269aec383ff94b7f779b97
SHA1 0166c338b1cff7e56094d1e3b83e7b774023e9d2
SHA256 59dbfae6e685ac035b41f1ac1f8461d4a659a822c02f678374e71baa07a53f09
SHA3 adbae9b208e448688c21aa4c2db01e713201f0cf41db16afc5aca6830471d6ca

6 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x94a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.70516
MD5 b024ad653222236dd98c6dfae90ef2ef
SHA1 00fe8f4e246ec866ed18f159b86c1a3b4e81a611
SHA256 4850f4134914babef9880cfd4234d98c376ffe97777cffb814e58392bb4cdcae
SHA3 ceb426f9441017e0cf63a1d6ec0bd905c5a936ee7b8f6caa40649841450c7391

7 (#2)

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.70158
MD5 c4ce70827f52ad06f1246bad6def8440
SHA1 4289c3311a973020b0674202ccbc34de71bf0bb2
SHA256 f773536950dc9e5b72497873688a545342226a243bd8dcaaab2199ac7ee0453f
SHA3 b90e3db68d80ae24780431e56356e782989d7e9e1433020e57ae0587040cad8c

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25c37
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.99668
Detected Filetype PNG graphic file
MD5 34aeee9b6592180431d18ffab05ebf3e
SHA1 17c8dd1b830a152ddc6eddaab673966a893a84d9
SHA256 c23b65ebaa84acf6fc964108f64677eeccdbac8a7239f97c1d7f4aa95ffedbd4
SHA3 4e35bc472212c2fb29da8bf4094de02c6a768ed4172f2e83eefda662f0abedab

4080

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xc4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.94555
MD5 f6db83c51a6b7301d394bcd88eca894d
SHA1 3733d8c9bedcb3d9e4f14606b28b8d47547ad1c2
SHA256 d5e37b212281164ab1c665561fe8eda02969d73c0b6bfcd4e971cd6da1d4493f
SHA3 d67d42e348cb346cec5ccb57664f67794b71df372675dae857fc63d88c37fa12

4081

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x258
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33755
MD5 90a7ff1509707fa98ff835b06de1c901
SHA1 974f6417457413df2ccc40993cbfdb6c68a182b7
SHA256 53b8c089a394550f7796a02a91cfeef45d29084c7020c9ee8f01161d755b4902
SHA3 75efc29e291581df20879cf30ec194f495a69cd6785cae386bf7d57905efaa75

4082

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x250
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43108
MD5 4d55b90daf5759ae92af09f35695bca5
SHA1 4e3ed1984036d825b65320a71885647c722bc0da
SHA256 45b8e3bf54baa870d201058a7eaffca9afc049273cf2110d26ea7cd6010744fa
SHA3 37254a6dd257d91eb7fca5dadbb92c654a4b22e0b78614a8f79362422bfde43f

4083

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x438
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.30802
MD5 a02a7ac0a182aae81d1908a26d07031c
SHA1 dfa1217ed4c5d6a076819eb26877586b158ae6e0
SHA256 6d47f4fe2243cb0ba63c345a30420e75175670f05ac6accaf9b52ded4b30940c
SHA3 5d1da8c1cff97099d23fdab467389f04b0659a117c57ac2abbf7f6761cdde6fd

4084

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.41821
MD5 c4a8472f3364192e4e44e8a5b623cda4
SHA1 8fabe424e1b26d8d485343be04a13f6cb140e0b8
SHA256 8fffe95c77e77ceee1741df87dc4fed649ba248155542a265363ca8ee65b7371
SHA3 6b92047129db3e56a1c67a88a609ddaf9b1475d1bba13d876b9c86618dfa1ea3

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xe4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38478
MD5 de42183be62c18222ddc6514014d3258
SHA1 9cdadf21b7e4e8174061fb805edcf1b27b63e07d
SHA256 bb7314c5862c6f58c99fe3fdf288b778ba3c21f0591a6829168473e67919dab4
SHA3 492d087ea43e592cc39881a9df5876b478c01c8c36e76db5191252e1c62ec02f

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29881
MD5 937b193d2945e0062561309aadde77aa
SHA1 361228030ab4a1c15ad6d2eca762e300707a747f
SHA256 1d554d85ab1336ac2281f650a8cf1e5d56ecf56021f676a3a1a0ad35d8cb839b
SHA3 d7ce561e996b7cb8716d084f236099d8a02dc20bcc70bf3151e87756fd3cd778

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x39c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28483
MD5 827dbd62155d5015f85a34b8e84b5a34
SHA1 088c8f7002e08ce1fd46308a99550264cce1b461
SHA256 a7a496ac0c6167d1210071b4cb6446cd173c9ae40fac999917aa2362f761e11e
SHA3 d8b50b58e9e3c7da1d074c016dc6163ab6a084bbfc5bc76a962e1d049a53f547

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24601
MD5 f91e8c6efab99bf8156240decbf039f9
SHA1 c077346b6f6dbbc2d730b71d65fec0053c98a9da
SHA256 328e787aafbb684152b4a1afe07401bc4378f53db1b152b07cd94aba5a7da87b
SHA3 28f44f67a7e82a7ecaf72dc95c7b951f10ee479478323b77f7c28afabe4d2012

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x360
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33599
MD5 7df73d476f9dd7c0b5e5be9f5d883e5c
SHA1 5ca0f785ca943d5ef8809335edf4cf2f0f5bf74b
SHA256 a5ec0e9221c27f6824cfb7a0058763cfd7705fd5e8064fbe41e9cbd6b212f9f3
SHA3 4c163753357d9785ed6a5aff9e78ef5a8b7c7aaeb52cca4ad2b2c26673fbbb2a

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32038
MD5 4f15a61a838d6ca3181851cfe45f268d
SHA1 565fc72cec6798d69412ffaee00e0eb880818c79
SHA256 b7ceb7289c2b1ad3a53b31c70650a08842fbe46f2b487edbf1a6c47bd7dcf628
SHA3 fbe0283bf26f7778b93eb44733393d8c566c940f9c3a2df1c49f2a88bce633af

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x108
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.21998
MD5 9933ed9224c4c2e91380fef66a0e1beb
SHA1 26461c98544d572657722892b0f079fa93d444cb
SHA256 1da5614fbdcded0b9a021776217b90bc6ef0e83e962fef10f2bc60486937b438
SHA3 151865d066075f5a9be27c72388efe077be1cd3398bf13bde032f04efc23497e

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xcc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34426
MD5 6884c8135d8822921b30f5ada0bd1a09
SHA1 8ba1ace07e09fcba5bc138e02a611b83609923f7
SHA256 c6ec1e31e5a3b39db364ef98b5f44727eb821481518601e0d62a61a597231363
SHA3 f9e3f673b25f489b83723c8d7f067c5c05f8cb8d1baa72e14cedc27cac20bce0

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x234
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.40141
MD5 f9330ca710193279e60c976c0acf3535
SHA1 5c70157687851563d696ba88f0369feff4c1fe74
SHA256 14ac140c5a26aa8d9ff9fd642e02ad8b375653fac27485140817acb14ecf4427
SHA3 90e87099f7fd825d35de16323624070efba0b88a2c438ca8b85ecc2e79c98708

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.27126
MD5 f34f4b2fbffb2b2dc74250b07c7dbc42
SHA1 4ca332f32fa8678103b78406f05e3e3e8b31993b
SHA256 78160f5ba775c340c1c5dcdfe1cf96d0190a2d49090d4acba36acb041e2b825f
SHA3 640df8a9b7437cb1c4926e5c37d7ba48534c9a48e3104dc14e1b9610afda14f1

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x32c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34727
MD5 48281f50b36a965a0a719bc3c96e7ef5
SHA1 66a2366acc1388aa1d13a7694634768193e98a3f
SHA256 97814a867e3c980ede78426fb8a51dc24d915aa7a2386a5c926850c4d445e9e1
SHA3 d87a16f699dc7e42e85461e30610f2a3ac3c7a24929a3bf832a4af9d5a9b4534

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28088
MD5 92de8d2c3cb2848fa0d540dacc5a3cd8
SHA1 2774d0de3d04d035a9dd951745ce6c8f3311edea
SHA256 8f866a52b9bae84b8b558de9f94dc322baeaeb0eeb972b3a1c2b187fb1346b68
SHA3 d68ab47956bd7150c9e295085e65f1c93e14ca3414ff666e57bedd0f442f8d52

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

HELPER_EXE_AMD64

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x1800
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.36336
Detected Filetype PE Executable
MD5 526426126ae5d326d0a24706c77d8c5c
SHA1 68baec323767c122f74a269d3aa6d49eb26903db
SHA256 b20a8d88c550981137ed831f2015f5f11517aeb649c29642d9d61dea5ebc37d1
SHA3 a4e1cccee20980eb69d054dd0a9ba02861f0572bc4d06c08ee592073013e124c

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x6b0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44862
MD5 0414397738a888384847bcdaf8e6b78c
SHA1 a005d0b12988e743b29763563b39e31775f33754
SHA256 286319c1f6e8ba9546c22fa7882a80f959d59f495339b8e0b5f111c6743bc81d
SHA3 7f2994fd3db0870021ec243ecc1affe1a187719c54574dafc2ba2dbdd8a6942a

SHFOLDERDLL

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x5b10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.59624
Detected Filetype PE Executable
MD5 92dc6ef532fbb4a5c3201469a5b5eb63
SHA1 3e89ff837147c16b4e41c30d6c796374e0b8e62c
SHA256 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
SHA3 6c04a9206995500a984744fd15fcea5542f6f577f21c63ed00621a1acde31fe2

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x125
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33322
MD5 2e91d62c202ac5a0169929c30fcba160
SHA1 fd965f85fe5e741a590efb348e78e005c26ded8c
SHA256 2076fb3dc69ae89eea6b3c714a60bee0c9ba05e5aeef275bd8aafcb7e46aa5b6
SHA3 530ab1febf6e05c011bee807b3a2c2659edfa970e14b1dc618d5936dc8f8434d

TNEWDISKFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3a2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.50778
MD5 5ce723642022c039f178c2aed86f52ac
SHA1 f60b54ad66ed10214ce479c7082ecc31099016a8
SHA256 0b40409be6235e4055c04cd92c0044e63375b0123f8dfcb6f9038b95cdbf3897
SHA3 772be5373fa748c11cf901059b0dc9c1957f7c40a01633071eb0f94fbb195425

TSELECTFOLDERFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x320
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.45298
MD5 d2c6d81c9631e66915e8784d6a4cfd41
SHA1 a02fb6ccb639b1c2af3c83e8f7387a5afeae07e0
SHA256 24a91a7b458e7ffc84e316587ca0b8c9bb92b89eac88271a892c5ba18b40aced
SHA3 fd3cfc2bbb5e2613612e0c1bba8a061576b9adc68d87d149f8f695226889e34d

TSELECTLANGUAGEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x300
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.46511
MD5 98575f21ab9491e1b6ae5e852d4c4305
SHA1 9b642977985c5f8165ab104caa93481263367820
SHA256 c8cfb5e468a4a2376141c84f64d8431888dad485bfce8a6304a3d1e509fd2e28
SHA3 fe5f4907a9ab7f6cd607af666970009f4a927024a6b98d3ad6790a2546bfd29a

TUNINSTALLPROGRESSFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x5d9
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49396
MD5 52b0761ca7d2972fcfcbadcb577d444c
SHA1 ccc039edba58585a888ae6f856d8dd28868525f1
SHA256 0247d57b98275241c0999e00c11e1e8e7368121aa097856a980e0738d2e07360
SHA3 9c81a1fd9435070b1bd70c78436e17ebd439d9a4b8a929f15a0f0e7b9fecca64

TUNINSTSHAREDFILEFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x461
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44622
MD5 4a32802bb5f3529cd029d0c2a8a5cec6
SHA1 2c4cb7d3e36c44852c227245a584657c868e526b
SHA256 683939c9900b86a18d49e77f21e39a6c15d4e7bb26bf7a59981c854c7ef5bb74
SHA3 52eb035d79cc6b2debf7730769cfc247df488983d02cf3b50ee85cecb0ac7687

TWIZARDFORM

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2057
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.49735
MD5 70f1e731c6ea743ce6dcdfafb5675034
SHA1 52624147daebc10579a223cacd5d5e17a66f8718
SHA256 4ddb37d4e5ab53c7c236ca3d12926cd2158815dd3e5646b30527d38d3a5206dd
SHA3 4b26c866bef8f4cfeab93d777caccc16a4bec78fe014d74b6edde78fd41949c4

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage Latin 1 / Western European
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x76
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.01865
Detected Filetype Icon file
MD5 8ad7734d6789415c145980af974f911c
SHA1 3782dfe4459f58c331647156352bc6e1df5a8059
SHA256 d33680740de2242f194d94d2f4bd7376c342e82eea06f52c5b5982a095896d48
SHA3 32364ed5f21f24a90d4458bca6baeba51da5fc8e4f61477fc8cd973a659a52b4

1 (#3)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x15c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.07819
MD5 9d4f340b6295c457d23b240e8782d433
SHA1 a8ba1e73322c6d2ee8273093cecaed51de25a7dc
SHA256 5ce534f7c44cb2b71b44102f11ec16bb8fbf4dcee652e1b24602c3020eb818bf
SHA3 7e236b482bf7e435cadaaabaff91f126e172c31a337ca9831212b6a8f27f6e07

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x5e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11919
MD5 a561f3d4bfa3931040422a49ec17c06e
SHA1 9a27136c8b8073f832d2f3a9239a49f0c14cfaf6
SHA256 8d51d4405593fb12ba0d4a2708507e2300b363f7ce3cf538cb65c25cc1d3044f
SHA3 5ef4d8131a8cc50f1295dc3ebde9c211384f3ca41c657f5c8b18fd6b3a5c7c75

String Table contents

Capacity < Length
Nil interface
Unknown method
Expected return address at stack base
Type Mismatch
Unexpected End Of File
Version error
divide by Zero
Math error
Could not call proc
Out of Record Fields Range
Null Pointer Exception
Null variant error
Out Of Memory
Interface not supported
Unknown error
Invalid array
Out of string range
Cannot cast an interface
Cannot cast an object
Dispatch methods do not support more than 64 parameters
Unknown Identifier
Exception: %s
[Invalid]
No Error
Cannot Import %s
Invalid Type
Internal error
Invalid Header
Invalid Opcode
Invalid Opcode Parameter
no Main Proc
Out of Global Vars range
Out of Proc Range
Out Of Range
Out Of Stack Range
Alt+
Unable to insert a line
Clipboard does not support Icons
Text exceeds memo capacity
Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
Error setting %s.Count
Listbox (%s) style must be virtual in order to set Count
Invalid float
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
&Close
BkSp
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Warning
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Bitmap image is not valid
Icon image is not valid
Invalid pixel format
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
No help viewer that supports filters
''%s'' is not a valid integer value
Invalid argument to time encode
No context-sensitive help installed
No help found for context
Unable to open Index
Unable to open Search
Cannot open file "%s". %s
Invalid file name - %s
Invalid stream format
''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to get data for '%s'
Resource %s not found
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
December
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 51.1052.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription Setup/Uninstall
FileVersion (#2) 51.1052.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x50f000
EndAddressOfRawData 0x50f03c
AddressOfIndex 0x5007e8
AddressOfCallbacks 0x510010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.