d7618d760486b4531598a017402318c0

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2019-Sep-01 15:33:12
Detected languages Chinese - PRC
English - United States
Debug artifacts c:\x64_dbg\bin\x32\x32dbg_exe.pdb
FileDescription x64dbg
FileVersion 0.0.2.5
LegalCopyright x64dbg.com
ProductName x64dbg
ProductVersion 0.0.2.5

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info The PE contains common functions which appear in legitimate applications. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Info The PE is digitally signed. Signer: Open Source Developer
Issuer: Certum Code Signing CA SHA2
Safe VirusTotal score: 0/70 (Scanned on 2019-09-27 16:40:37) All the AVs think this file is safe.

Hashes

MD5 d7618d760486b4531598a017402318c0
SHA1 39f691231286171fc3c81da885a3c8204c73ae7a
SHA256 e2cda5eb8799b9fa0f5386f5b601a75a1e1115416d48aeebc6a8851809b28202
SHA3 18036f75b3de0b4ab016e7bf94f2cb413e305f5f3f06725b6ec25caea6ccfb8a
SSDeep 768:qQcOkLzaaJntU1n2LBfk3EsQMmzD1lnmeR4fsb4F8lsKBSjlEhFFeN0rA3:Bc3xnUwBu4MY1lme4OtB6EpeN0rA3
Imports Hash 404d16eb1f602a7d7d5fee6a9214ef1d

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x108

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2019-Sep-01 15:33:12
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0x1c00
SizeOfInitializedData 0xa200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00002274 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x3000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x10000
SizeOfHeaders 0x400
Checksum 0x13af2
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 db2b01b91d9ceb836bed95dee7d7fdad
SHA1 4f7abe1b6fcd2370d5b0d64ddd3651878667523b
SHA256 b3f7ca8a07cdbc8d2ad4e404e26e30dedbd0a425c93fb065e77ac863ca57760d
SHA3 2bc129303df102cb3ea66791bad03a8e13c7f8e88c67a9fe3f309df73f0f69b0
VirtualSize 0x1a2b
VirtualAddress 0x1000
SizeOfRawData 0x1c00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.0546

.rdata

MD5 5149a1428ef3190c2403d0a438421424
SHA1 0cae53d08c7011b4137207654804d1442dccf7d7
SHA256 a67cbd92cabc7416a854558acfff0f9b2bd54c8bea36e0e133bf4d865421849e
SHA3 c8970e14414c1f955eb95b3f68e2e179ac09e26cc12c6ad1b2def96344cf618c
VirtualSize 0x104c
VirtualAddress 0x3000
SizeOfRawData 0x1200
PointerToRawData 0x2000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.6545

.data

MD5 9c61a23add082bb4ed143dfe0b028ffe
SHA1 ea05d58e9f5463a7e28ae55376af544940368c82
SHA256 9dd81bcac4996937142c4ab9f923f614001afc3d42ee0865dae8e730be254d92
SHA3 a8af7de8ece5dada5a05745c47464fea2a7fe7747803649e3c636f981920e4d1
VirtualSize 0x46c
VirtualAddress 0x5000
SizeOfRawData 0x200
PointerToRawData 0x3200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.5453

.rsrc

MD5 2d8a09077cc8ffdd9d3ce23200320bb4
SHA1 153cb28f99f7bf97fef46f7ff63ea8400b0e2d2d
SHA256 274385e87250e50c6d0c6c20f4fea091c2e5be01c260020cde7afd7aec5b9f22
SHA3 929ca4276fb31f1d48850a5c46a2914a443256e40f1e8db2af9ea8852e70bce8
VirtualSize 0x85d0
VirtualAddress 0x6000
SizeOfRawData 0x8600
PointerToRawData 0x3400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.9248

.reloc

MD5 27b871bd900224148597d452cd62686b
SHA1 83a78cfee0ce2d83eea6f047a91fb46f180baa6d
SHA256 af5acb3e70dc357eff5a5e6b27f9f94b1387d6261891e0694b65c2803fa56e37
SHA3 b289d006e2027ff998ebd9bc1726e907cb10b5e6b8be4aff50d4269e3ac51d69
VirtualSize 0x308
VirtualAddress 0xf000
SizeOfRawData 0x400
PointerToRawData 0xba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.43969

Imports

x32bridge.dll BridgeStart
BridgeInit
KERNEL32.dll GetSystemTimeAsFileTime
QueryPerformanceCounter
IsProcessorFeaturePresent
GetProcAddress
GetCurrentProcess
GetCurrentProcessId
RaiseException
SetUnhandledExceptionFilter
GetCurrentThreadId
GetLastError
IsDebuggerPresent
CloseHandle
GetLocalTime
LoadLibraryA
GetModuleHandleA
GetCurrentDirectoryW
CreateDirectoryW
CreateFileW
DecodePointer
EncodePointer
USER32.dll LoadStringW
MessageBoxW
MessageBoxA
MSVCP120.dll ?_Winerror_map@std@@YAPBDH@Z
?_Xbad_alloc@std@@YAXXZ
?_Xlength_error@std@@YAXPBD@Z
?_Xout_of_range@std@@YAXPBD@Z
?_Syserror_map@std@@YAPBDH@Z
MSVCR120.dll _invoke_watson
_controlfp_s
wcscat_s
_set_purecall_handler
_set_invalid_parameter_handler
vswprintf_s
?set_terminate@@YAP6AXXZP6AXXZ@Z
signal
_purecall
??2@YAPAXI@Z
??3@YAXPAX@Z
memmove
_CxxThrowException
__CxxFrameHandler3
memcpy
_vsnprintf_s
_lock
_unlock
_calloc_crt
__dllonexit
_onexit
??1type_info@@UAE@XZ
_XcptFilter
__crtGetShowWindowMode
_amsg_exit
__getmainargs
__set_app_type
exit
_exit
_cexit
_ismbblead
_configthreadlocale
__setusermatherr
_initterm_e
_initterm
_acmdln
_fmode
_commode
_crt_debugger_hook
__crtUnhandledException
__crtTerminateProcess
_except_handler4_common
?terminate@@YAXXZ
__crtSetUnhandledExceptionFilter

Delayed Imports

105

Type AFX_DIALOG_LAYOUT
Language UNKNOWN
Codepage UNKNOWN
Size 0x2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 c4103f122d27677c9db144cae1394a66
SHA1 1489f923c4dca729178b3e3233458550d8dddf29
SHA256 96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
SHA3 762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x7b8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87773
Detected Filetype PNG graphic file
MD5 ccc573a844a6e5c6cbc6f152688fbfb9
SHA1 a3c244b6d2f69a349d32f6a73eb64722b246d4d3
SHA256 f22624f5c6379592f8dc4f2c9d4946395eeff02fdd348a57b6a0fa2ff287e3c8
SHA3 41f83923cedb8bb6cf0bd76408f1d14d2c77fe143c9eda1c4fe2112333112ee9

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1020
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9118
Detected Filetype PNG graphic file
MD5 c2021afdf491caeff115f249fece7ea8
SHA1 9a49a26c852df4a26a9c310ea7e2e7f72cc8a2f9
SHA256 7d3f35c06116abb1c041e3576c7ae2f0d47da6b0ec68335e2c7c1eb84f3d2de0
SHA3 b296ab0abdb60d4be3df69d72651f089e738f32164429105a92a2fb29ae74f59

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x201c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92989
Detected Filetype PNG graphic file
MD5 7e8023c8f695f0cd5b513a3166135498
SHA1 8e80d2962d0f5e50c81281f32651276fda685f17
SHA256 16cbc328428dfcca992fca0a7c4859842bbf51a35f571fd29c1135d3ebf8a6ac
SHA3 83153b8bb13072de9021caa38c45f3ca11bb45dcc5b059596a75d07c338c20ed

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.90268
MD5 a9e393fe90f31f1efaa75cf93e0db0be
SHA1 94ca6417e6f43e39a5fd3e822addc58b5a6434bb
SHA256 9c207f3b0445cad18cbbf8fc59af1375be01e766f1510bb06a0184f581c7ad23
SHA3 f92e6d486eb116fb66ca1c30e4cd503c1b3d797d16dc4ec4ab2f1ddc35e7f101

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.66938
MD5 ca9f461c1039c38002125e6a2f2d59ce
SHA1 a91b8568bba75be145ef1e6f935ca5da90784fef
SHA256 4998432f82ef2385d2c10145b99cbaadf87515f4a810430baf09eaf9a2cc0715
SHA3 0ffe1ca6cf2469e469546f448c689900d6679de7775d546a1ad55d2ba766cb5b

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.3666
MD5 ae8c0dbc7decf6763fd8d347e0e74e79
SHA1 63b0f831bf49bd4225e80977b475616e894ed9f5
SHA256 d92d9e08278c26b259b7976a3082db7a65a3e3f8a6781ac51f68fe5fd04a777c
SHA3 1d76b278b1a4112596a42595b062cd0216ea82a0e8aad3ca65cedab8c976712a

105 (#2)

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0xd2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97172
MD5 092af784b79ede28ec517d032223dbe6
SHA1 ed48f128ed676e2716a70463f8a80702b0112c40
SHA256 5ad20688b035a2c92436bbf7b69e02532de6bdf2413e41593669023bd7070363
SHA3 10e061149cb1cde5526184750d1437e3f7194850c65e45d12c4a987b87641a3b

7

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x15a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11878
MD5 fd8107e7383ccd4edccc256285ce4819
SHA1 007e888133eb54cf00300fb69101cb3e95da3e36
SHA256 ebe72363c83dfc291f354a85eabceb75c0318e8cccdc8f460c1f2ca760063f63
SHA3 e095505391c820c9949261469fc01e1afdfec93017db05faa90cb74d2f7f3351

7 (#2)

Type RT_STRING
Language Chinese - PRC
Codepage UNKNOWN
Size 0x94
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.53266
MD5 c776fa51af46e1e9e451ebc88782b8dd
SHA1 8b32783bd0cca7ffc911d16138da68257601339f
SHA256 e8c99bf0ee2f90a4b44b5b81a5452b40e3651676704b719a64e6fb7ee42dcedb
SHA3 53ee361ce4c89ac58851760ec193446d3eb5826bf19bf225788bae389670be2a

8

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2de
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39734
MD5 2d8077979fa66ea3bc70a72271208ae2
SHA1 4fe718c08c14ba03a1bcd97fe05d63f9672835ae
SHA256 8c5d8e43a89e7c53be8ec8b68983446e9bd8ecd92c0c7d665bf48d571989458a
SHA3 17e2b16c67a135b9a7db79302bc0744bf9fa85758138011313873b7c2e023bba

8 (#2)

Type RT_STRING
Language Chinese - PRC
Codepage UNKNOWN
Size 0x1b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47046
MD5 95c94c250b76b7d6c10bf22a805b1552
SHA1 948f22dc4a4fd9cc82d2377b98156f4ad957d909
SHA256 00fdf1f6d3638f95260970e00a02d97a0111f8012c4cede5c0c91aa0c69a1541
SHA3 5d5f168068a58f374aa0888c1a1054a22399aff7929b0d1f86ce8f5f888e2bab

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.65521
Detected Filetype Icon file
MD5 7443ef500983aa3d4345025037ab05d0
SHA1 50a6fa807fcd4f0289e51189f734653a55b89d84
SHA256 5daa3bc5d3803254dc60e0e7582f7d4c3c50a4e54fea28e367c7d0423b895911
SHA3 79ab10f2fbb8303cb4c045dc833e7a85d0534452b014025540488f0083e31bf3

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26343
MD5 6938f27e6eb59c9fe557554de80a88a8
SHA1 f011b4a0881bf1f96ccdab5575cfae6e9a1ed67b
SHA256 9f065038a0c220add773b2803b4bdd57ba6c4f6ba53872b080955f854348ad3c
SHA3 3388ffa7e8a1404c66911f50f0b4926d8cec95754e5d98cd7087da8aa21e00ae

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x5e1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.14646
MD5 93ec22e91389442a4fd271901050ea03
SHA1 3a91e978223cd6373fd54fb938638fdd41bb6258
SHA256 e5bf19e4cb90f0e5ea96d8a53ef47c98610bf1f61756a7e1851dac9462fc8e6e
SHA3 d760cfbf75ad8c67fcef67e4b7597c314fb5863ee2426ed95a2ec1da13459797

String Table contents

Setup
Error
Error getting module path!
Question
Do you want to register a shell extension?
Do you want to create Desktop Shortcuts?
Done!
New configuration written!
安装
错误
获取模块路径时出错!
温馨提示
您想要为调试器注册右键菜单吗?
您想要创建桌面快捷方式吗?
完成!
新的配置已经写入!
Path to x32dbg not specified in launcher configuration...
Path to x64dbg not specified in launcher configuration...
Invalid PE File!
File not found or in use!
A Debugger for the future!
Running as Admin?
RegCreateKey failed!
RegSetValueEx failed!
RegOpenKeyEx Failed!
BridgeInit Error
Debug with x64dbg
Do you want to register the database icon?
BridgeStart Error
启动器的配置文件中没有指定x32dbg的路径...
启动器的配置文件中没有指定x64dbg的路径...
无效的PE文件!
文件没找到,或者已被占用!
一个面向未来的调试器!
您确定以管理员权限运行本程序了吗?
RegCreateKey 失败!
RegSetValueEx 失败!
RegOpenKeyEx 失败!
BridgeInit 发生错误
用x64dbg调试
您想为调试数据库设置图标吗?
BridgeStart 发生错误

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.2.5
ProductVersion 0.0.2.5
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileDescription x64dbg
FileVersion (#2) 0.0.2.5
LegalCopyright x64dbg.com
ProductName x64dbg
ProductVersion (#2) 0.0.2.5
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2019-Sep-01 15:33:12
Version 0.0
SizeofData 58
AddressOfRawData 0x3550
PointerToRawData 0x2550
Referenced File c:\x64_dbg\bin\x32\x32dbg_exe.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2019-Sep-01 15:33:12
Version 0.0
SizeofData 20
AddressOfRawData 0x358c
PointerToRawData 0x258c

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x40500c
SEHandlerTable 0x403720
SEHandlerCount 3

RICH Header

XOR Key 0x5b28d8c3
Unmarked objects 0
199 (41118) 1
ASM objects (VS2013 build 21005) 2
C objects (VS2013 build 21005) 19
C++ objects (VS2013 build 21005) 4
221 (VS2013 build 21005) 4
Imports (VS2008 SP1 build 30729) 4
221 (VS2013 UPD5 build 40629) 3
Total imports 75
C++ objects (VS2013 UPD5 build 40629) 2
Resource objects (VS2013 build 21005) 1
151 2
Linker (VS2013 UPD5 build 40629) 1

Errors

<-- -->