d5f4ab6063b3b3795b1c0f0cf30c7dfb

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1997-Jul-15 11:48:12
Detected languages English - United States
Debug artifacts exe\wextract.dbg
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion 4.71.1015.0
InternalName Wextract
LegalCopyright Copyright (C) Microsoft Corp. 1995
OriginalFilename WEXTRACT.EXE
ProductName Microsoft(R) Windows NT(R) Operating System
ProductVersion 4.71.1015.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ v6.0 SPx
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • rundll32.exe
May have dropper capabilities:
  • CurrentVersion\Run
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExA
Possibly launches other programs:
  • CreateProcessA
Can create temporary files:
  • GetTempPathA
  • CreateFileA
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetDriveTypeA
  • GetVolumeInformationA
Can shut the system down or lock the screen:
  • ExitWindowsEx
Malicious The PE header may have been manually modified. Resource CABINET detected as a CAB Installer file.
The resource timestamps differ from the PE header:
  • 1995-Jul-13 05:55:56
Resources amount for 84.3848% of the executable.
Info The PE is digitally signed. Signer: Microsoft Corporation
Issuer: Microsoft Code Signing PCA
Safe VirusTotal score: 0/66 (Scanned on 2018-08-06 18:27:12) All the AVs think this file is safe.

Hashes

MD5 d5f4ab6063b3b3795b1c0f0cf30c7dfb
SHA1 23d3c4d0869769f424b1c0c54f18c50761ca2c14
SHA256 08565fe3a18e051f9f557c219a51844dbac4a6dee9076eb8ecfed2a3137a3fe8
SHA3 dbbc94bd537ca3b46293a6f8a13dbab66a21f3936eba633bb0d7a906731166d5
SSDeep 6144:dFfDAEl3nOvkGe/DDWGszKjV1eNHkG+ovUM3ep3Dx1RzSG:XwGDWGszKjV1eWGL5epTXRzSG
Imports Hash cc9802db025851425e8413af448880e3

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x80

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 3
TimeDateStamp 1997-Jul-15 11:48:12
PointerToSymbolTable 0
NumberOfSymbols 739
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x9000
SizeOfInitializedData 0x4ae00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00002723 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0xa000
ImageBase 0x1000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 5.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x57000
SizeOfHeaders 0x200
Checksum 0x5d1f8
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x40000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b05ce693566c55c2601c98219c04e5e5
SHA1 230d112294d58430d501e75d60bfcbb0a5827cf5
SHA256 248d56b7bf0bce8bde4eb59d0c3140c605d12e8eeef696487a8e98c336310b38
SHA3 2ddd6b46a6b589ef150c89385406cd480c7482cfc856fe22de1e73bf1b938f84
VirtualSize 0x8e48
VirtualAddress 0x1000
SizeOfRawData 0x9000
PointerToRawData 0x1000
PointerToRelocations 0
PointerToLineNumbers 0x10820
NumberOfLineNumbers 2142
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48415

.data

MD5 a8800423228f9a86657c80297a8ce5f0
SHA1 381275a0daec1c6635ddaecc940e9e1708eb3cdf
SHA256 74de0ba725ff4623c23794becb5af49efce43c30d104d9ddacb489a4c36e9084
SHA3 1c5c274db52e961514b3fe74d3cee39da4f96aa2af7a41a5bef72e4b91818a7a
VirtualSize 0x1c0c
VirtualAddress 0xa000
SizeOfRawData 0x400
PointerToRawData 0xa000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.0991

.rsrc

MD5 7f803fddb2adeabdd2d5cc332a567577
SHA1 c8bb699496ead465ea23975068386e884a5a0bc0
SHA256 118ef3a5e93bcb37070494b5a6ef34965a6ec1c83eb942051441ad5ff23cc9dd
SHA3 d98bd4ee20594d77967c47ad202fcc93dd9d4beb60f586d9c6262a5f81e69e6b
VirtualSize 0x4b000
VirtualAddress 0xc000
SizeOfRawData 0x4aa00
PointerToRawData 0xa400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.88927

Imports

ADVAPI32.dll RegCloseKey
EqualSid
AllocateAndInitializeSid
GetTokenInformation
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueA
FreeSid
RegDeleteValueA
RegOpenKeyExA
RegSetValueExA
RegQueryValueExA
RegCreateKeyExA
RegQueryInfoKeyA
KERNEL32.dll lstrcatA
GetFileAttributesA
GetShortPathNameA
GetPrivateProfileStringA
GetPrivateProfileIntA
GetCurrentProcess
lstrlenA
lstrcmpiA
lstrcpyA
GetModuleFileNameA
FreeLibrary
LocalAlloc
GetLastError
GetSystemDirectoryA
LoadLibraryA
FindClose
FindNextFileA
DeleteFileA
SetFileAttributesA
lstrcmpA
FindFirstFileA
_lclose
_llseek
_lopen
GetWindowsDirectoryA
GetProcAddress
RemoveDirectoryA
GlobalUnlock
GlobalLock
GlobalAlloc
ExitProcess
GetModuleHandleA
GetStartupInfoA
CloseHandle
LoadResource
FindResourceA
CreateMutexA
SetEvent
CreateEventA
SetCurrentDirectoryA
CreateThread
ResetEvent
TerminateThread
GetVersionExA
LocalFree
GetExitCodeProcess
WaitForSingleObject
CreateProcessA
GetTempPathA
FreeResource
LockResource
SizeofResource
CreateFileA
ReadFile
WriteFile
SetFilePointer
SetFileTime
LocalFileTimeToFileTime
DosDateTimeToFileTime
GetTempFileNameA
GetSystemInfo
GetDiskFreeSpaceA
GetDriveTypeA
lstrcpynA
GetVolumeInformationA
GetCurrentDirectoryA
LoadLibraryExA
GetCommandLineA
CreateDirectoryA
GlobalFree
FormatMessageA
IsDBCSLeadByte
GDI32.dll GetDeviceCaps
USER32.dll EndDialog
wsprintfA
ExitWindowsEx
CharNextA
CharUpperA
GetDesktopWindow
SetWindowLongA
GetWindowLongA
CallWindowProcA
GetDlgItem
SetForegroundWindow
SetWindowTextA
SendDlgItemMessageA
EnableWindow
GetDlgItemTextA
SendMessageA
DispatchMessageA
LoadStringA
PeekMessageA
MessageBoxA
CharPrevA
SetWindowPos
ReleaseDC
GetDC
GetWindowRect
ShowWindow
DialogBoxIndirectParamA
SetDlgItemTextA
MessageBeep
MsgWaitForMultipleObjects
COMCTL32.dll #17
VERSION.dll GetFileVersionInfoSizeA
VerQueryValueA
GetFileVersionInfoA

Delayed Imports

3001

Type AVI
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e1a
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.52241
Detected Filetype AVI Resource Interchange File Format
Detected Filetype (#2) Windows animated cursor
MD5 f9035cf32b756fd6a452e9fdfd4a5dd9
SHA1 6912e88a3ee4d2c98ca69772cec564c6334fd9c4
SHA256 3bd1d253c90f7e82dc70dc1e4b869cc2e5e154e6b4079be93837e4a6c68044c0
SHA3 8cd00290363b6d3e609845f2e5828f3e2adaf35c4a97561bcf427bbd054401a6

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.75013
MD5 760b19b7b9c731af7673221f7781b99f
SHA1 a3b139e52af4b2004a0c7ceca80ff4101ba9b2c4
SHA256 ea5e771d2e590691c5c624a1204015a71d390ccb57781860f9cbc2fed1425f02
SHA3 41108697ba7383a73072bdcefd21fc18a240f55b1b1a2490c3cb172be29c6b19

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.53793
MD5 601aa6e69d0cd049a2c9b8177188a07f
SHA1 aa2266a300eb43df1c02acade8868980e3e80b41
SHA256 155ac1573c5f09ad098c18d0fa1cb6dc21081f0d969d743869938146abd9aa5e
SHA3 03a587ecb31a94af9cbfdc4c8c83585aca2a052ab723249ace5a4852f70f5576

2001

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x2cc
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.35785
MD5 769011a5df32441735f096ddea7b0e07
SHA1 0319fb5891d937a6cfc63e0e63514430b843d36a
SHA256 a0ccefebb8b748d0468481e5a82890f499007fa81fda74b3273aa9b4c6461e67
SHA3 a54874a490e965d2675c90924abea2096afa187a3f8fd0aa4d4069b0bb126b7b

2002

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x18a
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.34986
MD5 e97568f80f472e46e3195da9a1cf81c7
SHA1 cd79da76f373e2925ba469bb292e5647c9334b5b
SHA256 5723d7bfd7c984e35d5704cdbd8e35361e0d2d63af73397c820fdacc7a1764de
SHA3 6e9947644a684eb6ab4dff80fbb61cd0604a30365b831cacea04cbec1ec901f7

2003

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x140
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.21922
MD5 f57626df11e6296d34aba2b1cce53e2a
SHA1 7ab77fc005afc1a2d24397d9872b2c94f7aa9fdb
SHA256 856fbd66e2ad2243f9d6f077c1107b52a5828e3d596d202baa66b48e4189cf6d
SHA3 14420d3700506c88adcba3e925fa8a9ec3042b10c475a88ad5b021a226a1caf4

2004

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x196
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.32349
MD5 b4b7a4a6f9a6a2651aca59ad9ba0529b
SHA1 662f28d6eefc50bd9b015c7f83e4e4e192802f9d
SHA256 765756ad9676261a31eaebdc08d1c754401482163e3aa1d47450ab7eedc030ba
SHA3 3cd03ae9ce08ecff683c855a1bb12ff5d22cb0847da006ce934736877d2c93aa

2005

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0x10e
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.19511
MD5 87d9cbe81b5fd7ae1d0d55cc0992f11c
SHA1 af223ec77472d77f22bab1463bed6b0198620a64
SHA256 253aea2de827095918561dbd9159889184401da67f3a72d0f1a6f94e6305e690
SHA3 8f795cdcdfae062f40095874a6db6d3e8f5dc055406b33f6991ff33c9b6c6354

2006

Type RT_DIALOG
Language English - United States
Codepage Latin 1 / Western European
Size 0xfa
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.26012
MD5 90fcaceed70158515129d540e28a9755
SHA1 c720320f9c6b6275160cda38baa59fe656efb0d6
SHA256 0a0e83c7a9c1aeede6b859461de64a0ca90fdb6a82912c19e30ec1dbec16fe33
SHA3 d26b66bd995a095e6b131cf54eef93bce005f8a3b65d37e2becf3122b608b21d

63

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x8c
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.48958
MD5 ad0fe039aecc9c8af6f573923f182a0a
SHA1 b4fd492a37127d31fc36b7bd07084cc2f1ae18a1
SHA256 29b228ae95784d37b8729fe88e3bf1346c4b1339231dd1e9f702fab0654c5b1f
SHA3 7a67b4664ab18841c125d33dbe110fe774b16f91d1471094307c0ac35be5d8a8

66

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x40
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 1.7646
MD5 f6d6f245c7ebdeb2153703d0f556a837
SHA1 03b2f04247aaba75cda768d6e07a6fbead89a28d
SHA256 cfcaed567b5f7530d255051fd09198e4fc816ad023203f8dcc2f3db7f3c95c73
SHA3 f41babb81e7b4bc06eea2735d8d78877cc971391ced0e008ffd45b972ac8e079

76

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x60a
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.27164
MD5 3c9a5541ede1917a3e3b7718465614d1
SHA1 2fa74817b4b05b339ac80854664db5f808be0c05
SHA256 acc00b47379735eeb5d6844b5c5b289b54d0a7185eb5079e4939a9914df281f4
SHA3 9c1897255e4ddb73c9a1f9aa62fd33b9e9005ea76e44665d17670f79b585731f

77

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x5f4
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.30764
MD5 80451b4e2d05aef21552b24ac9589edd
SHA1 30b5bcbc8e4f0519a9b9982863d3dcd28ab41f67
SHA256 1946fff374a577fcfe600c6169548bca839aad5e09c6253902a1eacd0d7870f7
SHA3 d70258b54bf239c6f780496176482dfbb7c23358c4cf8367590d83b6a944f77f

80

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b0
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.27174
MD5 1f268a77ca8f853ff0c410e622706bef
SHA1 75afb11daf446704dddb5ef5fe39b2009aecf01d
SHA256 39023f15fbabf4be02e0d84a76c363003374b11076406f84cd8f92e49aecd3ba
SHA3 5e684d700849b8552f5449c5869807ce32caa8ae657695824e4a41be4a2ee55d

82

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x318
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.24912
MD5 0717e553456f3c9cc1c5eb82c84645ad
SHA1 ef14cb6e0b73501ef37168126d7119478b890ada
SHA256 1bab3cdd9f7052791a0b9ea759804dcab85c063c4498d07707d7998abc74d89e
SHA3 1082ccf1b873756d857b1f57712df28b550c78da315eec2d6870b30a4bc81d37

83

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4f8
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.26481
MD5 7c965a379de34e34aff6ad4675cc0181
SHA1 0ed8339f94f1a14ad6c3435546ade66bd84c46a1
SHA256 1773587067d205db87038812de66ebb2332aa5fed16bb9d3bb93ce9b5827d571
SHA3 ec791c0af12f9db91ee1f30344c926065fc950a70647f8b0d345e0223a8ff596

85

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x524
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.1621
MD5 cc9abb31ab23123a7535bcae6d13dabd
SHA1 259367e2f15c635c6c5b462e03a750291d3cf0df
SHA256 e9fd5822f99c47f60afee06f2d0c66e79e45d841a62a0c3dee516d6e951cf3ee
SHA3 664a677ad277fc2b15f82e7287d6c39f92c0395e15af4253dfb95733f258ac55

ADMQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

CABINET

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x442d6
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 7.9985
Detected Filetype CAB Installer file
MD5 de78214408001d7ded1addcf332de3cc
SHA1 7d41496e38f721936ec3d49deb748452162875f4
SHA256 e698f05994481766e615367449f3a3e085b207374371395444b2ee091a48286c
SHA3 cb3f2332f34894b287ffb70965204b487ff10a509ae4e402eb91f9f7398f1aaf

EXTRACTOPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 0.811278
MD5 4352d88a78aa39750bf70cd6f27bcaa5
SHA1 3c585604e87f855973731fea83e21fab9392d2fc
SHA256 67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450
SHA3 295cd1698c6ac5bd804a09e50f19f8549475e52db1c6ebd441ed0c7b256e1ddf

FILESIZES

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.65414
MD5 cec4994e3a87e63bb5b7b5d20be0f915
SHA1 5e314b882e1c1f23b50915fd5717686ffbe63e98
SHA256 86aa1ce17f641af82b4254b58d5e7429c3b9fe60b47a1c23938ca433e85204b0
SHA3 58ac8c829cd63e1452b704b230dacf1de30b6b1bc35220e4aac786ba55f5a621

FINISHMSG

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

LICENSE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

PACKINSTSPACE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

POSTRUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

REBOOT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

RUNPROGRAM

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x15
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.74899
MD5 28ffc4cccb76afc7a5f4e4b1489240d7
SHA1 157cbfeb953ce12f9be3aff892832014d11740e4
SHA256 0cfd0e715c7ea94fb0e8dc493795933a4986009cc48da31ac3dc03831a027631
SHA3 2509f242aa73aa6c1c4c79a9ec0a7fa2c6d7c3b6f1bdbc7bf5b3dab453ebb16c

SHOWWINDOW

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x4
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 0
MD5 f1d3ff8443297732862df21dc4e57262
SHA1 9069ca78e7450a285173431b3e52c5c25299e473
SHA256 df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
SHA3 8b0a2385d83c8bf7be27e59996f7d881d3bf1fc6606f81ce600b753ad94192a2

TITLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x28
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.88483
MD5 80ed5aae3dd330ecf6f18ca63d55a1d4
SHA1 a7fb179c8c64eb4bc4bc1fa9e419bdb3be3cb0fd
SHA256 625ec908925ba737e104ffbe9e8e6900967e5542e97466cb506a26bbb2b9b47c
SHA3 d4f9f7db76810c0ab1d7546c0397453bb820541f053352144df3a72f41896bdf

UPROMPT

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

USRQCMD

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x7
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.80735
MD5 527eeaa35a23dd5cac9bddcc2561a457
SHA1 0445b1735fd9797d537d360695940c7e68d25ace
SHA256 eaadcdd05a9a7c7f80d53d758f39e4399749d774b09a8a0165fe7c69ad6d8c3c
SHA3 28c8e1f57de512535bfd686562ef240323f7331b18e71f0506079f0e67e8f89e

3000

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x22
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 2.37086
Detected Filetype Icon file
MD5 d59e0d372ea5fd8c1f4de744376a6af4
SHA1 6883ce60e71a83424db0b41d0ab6bf61080e3de2
SHA256 b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b
SHA3 5e39df982879204dd9f129a37d1e1c2ff906e88de9ae01b4418db5e8455e7ae1

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x3e8
TimeDateStamp 1995-Jul-13 05:55:56
Entropy 3.41506
MD5 d4f94c785ee00acc241cb7dcda43e35c
SHA1 fedad31b68a0b431d5ea10ff075e3eaf7a6942de
SHA256 69d0a43191221e8ec4758a80336bb1010f6e55f312712bc8d21b76a7142a3581
SHA3 54cb34fe5a49b784e989f0d0e2dba0bf1d7cad8d6031bfcfff1acc0627707398

String Table contents

Please select a folder to store the extracted files.
%s
DEBUG: <%s> <%s>
Failed to get disk space information from: %s.
System Message: %s.
A required resource cannot be located.
Are you sure you want to cancel?
Unable to retrieve operating system version information.
Memory allocation request failed.
Unable to register window class.
Failed to create requested window.
Unable to create extraction thread.
No valid folder can be located for extracted files.
Cabinet is not valid.
Filetable full.
Can not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.
That folder is invalid. Please make sure the folder exists and is writable.
You must specify a folder with fully qualified pathname or choose Cancel.
Could not update folder edit box.
Could not load functions required for browser dialog.
Could not load Shell32.dll required for browser dialog.
Installation failed.
Error creating process <%s>. Reason: %s
The cluster size in this system is not supported.
A required resource appears to be corrupted.
Windows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %s
GetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used.
Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Do you still want to continue?
Error retrieving Windows folder
NT Shutdown: OpenProcessToken error.
NT Shutdown: AdjustTokenPrivileges error.
NT Shutdown: ExitWindowsEx error.
Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.
The setup program could not retrieve the volume information for drive (%s) .
System message: %s.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.
The installation program appears to be damaged or corrupted. Contact the vendor of this application.
FDI Extraction completed successfully.
Cabinet file not found.
Cabinet is not formed properly.
Cabinet data is corrupt. This executable is damaged and installation is not possible.
FDI memory allocation failure.
FDI compression type not supported.
FDI decompression failure.
Unable to create a requested file.
Cabinet reserve size mismatch.
Wrong cabinet file.
FDI user canceled or halted.
Command line option syntax error. Type Command /? for Help.
Command line options:
/Q -- Quiet modes for package,
/T:<full path> -- Specifies temporary working folder,
/C -- Extract files only to the folder when used also with /T.
/C:<Cmd> -- Override Install Command defined by author.
You must restart your computer before the new settings will take effect.
Do you want to restart your computer now?
You must restart your computer before the new settings will take effect.
Do you want to restart your computer now?
Another copy of the '%s' package is already running on your system. Do you want to run another copy?
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator.
There is not enough free space in the Windows temp folder or in the current folder. Please enter a new folder below.
The setup program is preparing to run.
Please wait...
The folder '%s' does not exist. Do you want to create it?
Another copy of the '%s' package is already running on your system. You can only run one copy at a time.
The '%s' package is not compatible with the version of Windows you are running.
The '%s' package is not compatible with the version of the file: %s on your system.

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 4.71.1015.0
ProductVersion 4.71.1015.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Win32 Cabinet Self-Extractor
FileVersion (#2) 4.71.1015.0
InternalName Wextract
LegalCopyright Copyright (C) Microsoft Corp. 1995
OriginalFilename WEXTRACT.EXE
ProductName Microsoft(R) Windows NT(R) Operating System
ProductVersion (#2) 4.71.1015.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_MISC

Characteristics 0
TimeDateStamp 1997-Jul-15 11:48:12
Version 0.0
SizeofData 272
AddressOfRawData 0
PointerToRawData 0x54e00
Referenced File exe\wextract.dbg

IMAGE_DEBUG_TYPE_FPO

Characteristics 0
TimeDateStamp 1997-Jul-15 11:48:12
Version 0.0
SizeofData 2512
AddressOfRawData 0
PointerToRawData 0x54f10

TLS Callbacks

Load Configuration

RICH Header

Errors