d7a14f6e85f5d13b8db8d75284cb5a37

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Jun-14 13:27:46
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Crystal Rich Ltd
FileDescription LockHunter Setup
FileVersion 3.4.3.146
LegalCopyright
ProductName LockHunter
ProductVersion 3.4.3.146

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://www.jrsoftware.org
  • http://www.jrsoftware.org/ishelp/index.php?topic
  • jrsoftware.org
  • www.jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • AdjustTokenPrivileges
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Crystal Rich Ltd
Issuer: GlobalSign GCC R45 CodeSigning CA 2020
Safe VirusTotal score: 0/72 (Scanned on 2024-11-28 15:48:00) All the AVs think this file is safe.

Hashes

MD5 d7a14f6e85f5d13b8db8d75284cb5a37
SHA1 3a2773d1fd1fc488223d929f3ac77aac2fcc38f7
SHA256 02f738111a7ef929b8017277109ff3cb188ed0896fa385b79205da888afa266d
SHA3 c68076d08f9e475ab3dfda7abe4fed95e20d50316959bab1a70f68cf922ace05
SSDeep 49152:h8lKHdlR013v+ykqhNyYVuUpmO7NdBxV+k1ic6ROEpANEZ57vqmGAg:FdlC1XzhNnE/qx88CANE3ir
Imports Hash c60f9a83fcd28ab2eb686b76b194eb79

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2018-Jun-14 13:27:46
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0x10400
SizeOfInitializedData 0x24e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0001181C (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0x12000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 6.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x3f000
SizeOfHeaders 0x400
Checksum 0x33dd74
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 0da5d73ffbc41792fa65a09058a91476
SHA1 1398791fc2e15be62c9d251bc6b2f5256af1e5f9
SHA256 869e41576cc4d9d095cf7061aa84a29c4c0e5f25b3fe67afc3203e016df397ef
SHA3 0e9231aa206948d9a5df7caac7f703165e94451fdaf9c13e0199db2ddb0f95ae
VirtualSize 0xf25c
VirtualAddress 0x1000
SizeOfRawData 0xf400
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.37588

.itext

MD5 2eb275566563c3f1d0099a0da7345b74
SHA1 7e44497b20e01a93ca6cf7b5c2c2ea1a01732fcc
SHA256 10547a7743fcc09490636c8cf3d7704c8d4a99356bf9ea3b3dc998e851fed777
SHA3 126f2ecc56537f1bed14d015a68adb49e5b46a80dcb407a53fc3a84e9cc4e6a1
VirtualSize 0xfa4
VirtualAddress 0x11000
SizeOfRawData 0x1000
PointerToRawData 0xf800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.77877

.data

MD5 73b859e23f5fd17e00c08db2e0e73dfe
SHA1 c8610dc108300c199c915d1a355f792b45afc912
SHA256 01e152d7661f7b4da228ca9bbdb1428d058dc976ae49b38c11a53285a2cc5076
SHA3 0556612fbc844b43a14cfa171cc07f2f82077e32cef297cae93fe84f83a03e29
VirtualSize 0xc8c
VirtualAddress 0x12000
SizeOfRawData 0xe00
PointerToRawData 0x10800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.30283

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x56bc
VirtualAddress 0x13000
SizeOfRawData 0
PointerToRawData 0x11600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 e9b9c0328fd9628ad4d6ab8283dcb20e
SHA1 fd2927174e310130a51bdd648aefde6f89fe0007
SHA256 68a126ba6dddfa52cdc395cca81ae415921071acf02f75b7c00faf9d90353760
SHA3 8d72ac9fda0d2c851f62aab12f92db53db9fb187e522555aa7e82502850ce7a2
VirtualSize 0xe04
VirtualAddress 0x19000
SizeOfRawData 0x1000
PointerToRawData 0x11600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.59781

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x8
VirtualAddress 0x1a000
SizeOfRawData 0
PointerToRawData 0x12600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 3dffc444ccc131c9dcee18db49ee6403
SHA1 45d8f890e32cc1adf7ded113fd19004c8869f419
SHA256 821b0bda5922cc6f5fb74fb3a160e39c97727c21beb1ecf4f96e3bcfad9edbe3
SHA3 426ea652dcd361ec016030230ec1c87a2bc522f69cfb4c2af6313465cb2c516f
VirtualSize 0x18
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x12600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.204488

.rsrc

MD5 de4e3578b4e8cf7ab8f618a35a2560f6
SHA1 b043a3fb644612164a0ec682effdd29af606a477
SHA256 df015bfb0d4d9bb95ffc2246fc2d1fd014069415cdfc26713d2a006a4baaddfa
SHA3 1bfa0e80ade84e126e95c9f7777d6cb3f3bd36a790f177f4d6d8a0cbf7c8bebd
VirtualSize 0x22c70
VirtualAddress 0x1c000
SizeOfRawData 0x22e00
PointerToRawData 0x12800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.7642

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
kernel32.dll (#2) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
user32.dll (#2) GetKeyboardType
LoadStringW
MessageBoxA
CharNextW
kernel32.dll (#3) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
comctl32.dll InitCommonControls
kernel32.dll (#4) GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetLocaleInfoW
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
RtlUnwind
RaiseException
GetStdHandle
CloseHandle
advapi32.dll (#3) RegQueryValueExW
RegOpenKeyExW
RegCloseKey

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2f39
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.9248
Detected Filetype PNG graphic file
MD5 e193ecf62c9fb50818cf7d5275ff8d76
SHA1 47fca654271a2e9e90e13a725659038fa911d72c
SHA256 6b82ad2b2d348ae6380b05fc4b83db33c7d02611503897cce9059314ed36937f
SHA3 218043736831e0f567b23868ad6caafa0f76b203e38a488d8837b81ccd04e4e8

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x668
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.43851
MD5 f019f1b7b2a50ce23e75cfddbe8e98a8
SHA1 2a435dd3e9b4af04af9c7cee80952aa634b042d2
SHA256 f589e6666d69f38374e0c28c9caed761e1d11bd58246942ccb5db3f250e548ad
SHA3 1f5af97b583f1ddb85673e42e67a18b6a129312c24b824f59abfe4fa31b09ca6

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.76159
MD5 c69ea6a82b26a8b1e787029cae9a5b54
SHA1 0f87d24e30d6e88b83a14c4755ac7251c1ab3e4a
SHA256 e7ca64777f7d94beffa62039a90a46ce3d4fc7add2e4b6beef23c0cec87565f9
SHA3 4678a69329bb700194980af8c8289f3b12dc16cdd15da2fdaabbf7ef95617090

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x1e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.7613
MD5 b7e3761c37a8f91cb240d177d54d90c0
SHA1 2dd57dd88265c2424d28d48ff889921f6bf5daa7
SHA256 79ae2ef1dbf1f681034d146c593b189e426d72de74e7d21ddcdb0d0f436c326e
SHA3 b63e6af2cc3a4dff43885504bdb5b4a9f34b1cb92d3ce1587f026f1307f991df

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33777
MD5 72d421d69d7b30fb8597aaf4d76f28d2
SHA1 a395b4650c567ada8580b72e013c35490d9bb597
SHA256 c995f2915bb3615b814b0f751b1be0901e0daa1d27976bba4aa6396a4331fa87
SHA3 f90b8c0f37f137ed78da1227286debe9e10a4dc84b78834efa0d14c5d5f117c9

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x3357
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74877
Detected Filetype PNG graphic file
MD5 ae13655190ee0e8fd97591a10d5c1c32
SHA1 fc7fd1428c203b1c3867d93a11bd9c12c086ca32
SHA256 f2c872cc1d89f385f770c62c90c10b897353cda64f7385c0d30c1d28c2c7f6e4
SHA3 a821859af63504ce80c6cb0cb91452bad258b531acbad023178b8e1d89b3de64

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.2097
MD5 ca55db2dac524ebfea792d36e8a363fc
SHA1 0ce30074fca2bd6a60db083dd807a0e20843a233
SHA256 70f590067eabc21fb28e645cb58371c8b89233143c29ea09b20dbe277a874f72
SHA3 bc5ad0c5d7d0736cdf335ab310aafc1a9d82f177d24b1501b5b69066192306c8

8

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.98743
MD5 1760c7ef5a1fdd14ddea814dd5c86ebe
SHA1 3db86fca0dfae6e6015009c65d5c660d8dbf07f7
SHA256 d82e5b325a8a5c4d15cfae6bc37b573515ef092c32c046494cb02ea4cd559387
SHA3 a91e3abf1c16285a520beda3ccddfc212bdbe350279fc447e886986728a4dc64

9

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6c8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.18146
MD5 f4f95291e0f713d8c19a615d87d060ce
SHA1 7ed7177aef6fa4c3af87f1d76b23ad5bcfcc808d
SHA256 4698461f6a77b9d32d723bd2cd5d1a06997812a61338e0fb3dc9b2575215e320
SHA3 9501c0ee47082f17497c87ae178103afd382d0424e5154965f5b573c0befb7cb

10

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8259
MD5 d5267e8f5fe45b536b6151216472a9a2
SHA1 d0f50a7aa14c789109f6bae79d022bb7715b0d27
SHA256 3415ce290456c55add83ca21af82f9d66d2f00a5c211bd6f3496a0e84cf24a3c
SHA3 6d358101ccf595a54d5662d7811e207cbb477d7f14d4d0f21a0df6a66d500e61

11

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xb4b6
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92204
Detected Filetype PNG graphic file
MD5 9127665407f691ebb42c1d8b67587a32
SHA1 cac04134c81caa7960072cd9f52e8164b5bf860d
SHA256 0704cf9f993622e930b61d70c935158bfcfd84502e4b3ffb3b784bfe4cf68b1e
SHA3 6099d08e9a3c0333a099c264a1da22b9212c0597e43010fdcb65a9242a3bb16e

12

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.8841
MD5 8065cb1b588c831becdaf4fe4eaaffb4
SHA1 9b93cd57fcdd1299a1b59b6503e778b8a8824098
SHA256 146e44a014515db6445c443cd7144dcaee0e04c1f1882128ca41398cda32b0b0
SHA3 05e9f5cfa4db5860a7efcee5e942b67c67c6239f218ae5fb44c4502af7dce9c7

13

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.20679
MD5 7837443e7bff7c31365d2094006a1c78
SHA1 e8d5bd20ec3afb1e9dbc71c4637b5094e274f8e4
SHA256 e4aff023402806ee0f4ebe7e717c6d7321eb2323b60464c29fe1c457914e2ec2
SHA3 b66686907c93b21e65a2df06b836a53312d06f31d00e629fff6039290a458f9f

14

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x988
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.44737
MD5 7ffb16276209dd285426a7e8b347b1c9
SHA1 97e00bfac0ae38f0b5ce986f513f560ca0f817e5
SHA256 3b167e9f3724c76f029801150a3db166948a87db3133b72eb25b51f9dccb5f19
SHA3 890971a1d3e63bd1d8bbc29babfdf3bc62cdfc9fe2508a2f50c5949062012287

15

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28807
MD5 719569ae31127c0c3d1b39f1f16fc54c
SHA1 19cb461ebff75c5284443196c8575654040ce6c1
SHA256 af1118213ae1bf82d2060ae486403f73b84aecb0f1bef83320285ea576f2a2fd
SHA3 96bfe37b443e9d51207e8236651f71c51102e4f2080aa8de2839b5760290d60c

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56031
MD5 e518b8ae009986dd90363fcc61d7fff7
SHA1 24ed3f9f44fce167e79b53ea5f9b0505c4d567e1
SHA256 34ea1c2173226ecc593f8a2b0224c51ebbee1928715bda9339eec7717a822b89
SHA3 519dec097566117a56d9c49b0a711e82451c0f81fbb53f042549a61cd51122e6

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xd4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25287
MD5 ac85ded4e576ce909f5460536b63a4f1
SHA1 07e0380006e58eec02eaaa047a58aceeef1552d3
SHA256 e1d818d622875ce2cf81883816ef982aa05a724c46f82b3e67875e0bc24228b1
SHA3 d70f10064348a4608f8b92740e05f739736144b222db3aa5c51187c75c5cc4eb

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xa4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26919
MD5 519a33f5d2b4442ef3caf6d4501995fb
SHA1 e54df9d112555eb11a132bfee15b69ac186b422e
SHA256 80bc91470ef70d527d0c4e0824945bc3b17ff84f464bca425661c3e7e1972ce7
SHA3 88c911ed5f1b1354c3379baaaef2540d70c370fd877f536d069dc0ea55cd0b13

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33268
MD5 234c2763997eec9c8a72ef190b928d68
SHA1 089fcaabba97f63455ce8a47e2d5d07fa56ba55b
SHA256 33ef72f38fc1fe2842c44e11bb351f94385bb186fee0fadbefc9364ed52aeb93
SHA3 10cbb07d784f332702d9d3451649950c1af6fb999ac1c2dac82df168cba5f302

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x34c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34579
MD5 2596d19a6b88cbba9c9c9cb003affbc6
SHA1 37091a716fd1eed000e0c3bb195fbd589a750608
SHA256 7f63f3f944a0b62f8f3b35a60141081599f7f175605ced7e1b4dcb80fda58c8a
SHA3 0b2581dd0c1b08d882b1f4c4014652d2e7d046d95aa3df236690e9d22572b27c

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x294
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28057
MD5 1f9009e4d5b61392e05aa8ac6eceb6aa
SHA1 4af6f3144fff0951da37370a3d200e8d74fc4862
SHA256 cb21f2b28bfc6b8046348c7a96bf97149dc5f91e1cc1a4f2904a1044a008425a
SHA3 c1aebde06ed543947facd67a9541283cbec74e559e267c1b84c168a2bf839812

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x82e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x150
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.17906
MD5 9247d9dfc002426bf15a38569e1117d6
SHA1 724fbe0b18bf415f1871fbc45570b1ba809b1acd
SHA256 05efbff33471fec1389d42d84ee0572448b1dabb86c18ee38dd6463ff7f927af
SHA3 908ebb293645b24313fed4562495cebabd348ab84dceaded2145fa135e0ee180

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.56808
MD5 11f6af66bbb71e25ecc67a2a535df300
SHA1 3c5f244e0e4a79e9bcdb0523fa5acef4a8002d7c
SHA256 a3802449e0a9fa7638b92985953643074dc0bb6fe38be293658d449d3656619c
SHA3 f5362a4edfeeb642c8d545dc29ee815b3f941ec7dc0c123e4058ae3680c180b6

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0xd8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.0073
Detected Filetype Icon file
MD5 10cffdff5d7b87fac45062575c6d4043
SHA1 ac22e003fa460ece94ae8dee99c8e66c349b9358
SHA256 893cd0774117dec079e6e373a7798f0838c140ffdeb68afa18b5cc3ea714dbe0
SHA3 891a7ca3887db271365ab6df3bb13e615f250949ca17ad434211c76fe2482e31

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x4f4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.69417
MD5 bf17aa74c7688ae9f3f2dde2d5c73a30
SHA1 bb1dee9a2246b40b33494330f3dbbaaf1c061967
SHA256 f7f11480661f6dbec2cd6d4561a7ec4a202b4a56b8aaf10ffc4a049dcab65a3c
SHA3 5ac1275900d6eeac6f427a40ca605070572f5ae1c1b22ae21c37d438e50e2c67

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x62c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.13965
MD5 f78a870573f5bf2f15570e286257fae7
SHA1 eaccbf47cd42836b0e21ab2196b86d98a28733ca
SHA256 356ca8abf11d97bf9dcbff47c04bf1ddcb8685ef84d38e6850ec6c28a37655b9
SHA3 f19c38bb277b8098eb08d8b9a12df0b660a7c01098e20adda4c4fc5765d937ca

String Table contents

Friday
Saturday
Invalid file name - %s
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
Invalid variant type conversion
Invalid variant operation
Invalid argument
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
Jan
Feb
Mar
Apr
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 3.4.3.146
ProductVersion 3.4.3.146
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Crystal Rich Ltd
FileDescription LockHunter Setup
FileVersion (#2) 3.4.3.146
LegalCopyright
ProductName LockHunter
ProductVersion (#2) 3.4.3.146
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x41a000
EndAddressOfRawData 0x41a008
AddressOfIndex 0x4127ac
AddressOfCallbacks 0x41b010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->