Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2062-Jul-25 12:18:00 |
Detected languages |
Chinese - PRC
English - United States |
Debug artifacts |
wextract.pdb
|
CompanyName | Microsoft Corporation |
FileDescription | Win32 CAB 自动解压缩程序 |
FileVersion | 11.00.19041.1706 (WinBuild.160101.0800) |
InternalName | Wextract |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | WEXTRACT.EXE .MUI |
ProductName | Internet Explorer |
ProductVersion | 11.00.19041.1706 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | The PE header may have been manually modified. |
Resource CABINET detected as a CAB Installer file.
The resource timestamps differ from the PE header:
|
Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xe8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2062-Jul-25 12:18:00 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x7c00 |
SizeOfInitializedData | 0x30600 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000008200 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | A.0 |
ImageVersion | A.0 |
SubsystemVersion | 6.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x3e000 |
SizeOfHeaders | 0x400 |
Checksum | 0x422b4 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x80000 |
SizeofStackCommit | 0x2000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.dll |
GetTokenInformation
RegDeleteValueA RegOpenKeyExA RegQueryInfoKeyA FreeSid OpenProcessToken RegSetValueExA RegCreateKeyExA LookupPrivilegeValueA AllocateAndInitializeSid RegQueryValueExA EqualSid RegCloseKey AdjustTokenPrivileges |
---|---|
KERNEL32.dll |
_lopen
_llseek CompareStringA GetLastError GetFileAttributesA GetSystemDirectoryA LoadLibraryA DeleteFileA GlobalAlloc GlobalFree CloseHandle WritePrivateProfileStringA IsDBCSLeadByte GetWindowsDirectoryA SetFileAttributesA GetProcAddress GlobalLock LocalFree RemoveDirectoryA FreeLibrary _lclose CreateDirectoryA GetPrivateProfileIntA GetPrivateProfileStringA GlobalUnlock ReadFile SizeofResource WriteFile GetDriveTypeA LoadLibraryExA SetFileTime SetFilePointer FindResourceA CreateMutexA GetVolumeInformationA WaitForSingleObject GetCurrentDirectoryA FreeResource GetVersion SetCurrentDirectoryA GetTempPathA LocalFileTimeToFileTime CreateFileA SetEvent TerminateThread GetVersionExA LockResource GetSystemInfo CreateThread ResetEvent LoadResource ExitProcess GetModuleHandleW CreateProcessA FormatMessageA GetTempFileNameA DosDateTimeToFileTime CreateEventA GetExitCodeProcess ExpandEnvironmentStringsA LocalAlloc lstrcmpA FindNextFileA GetCurrentProcess FindFirstFileA GetModuleFileNameA GetShortPathNameA Sleep GetStartupInfoW RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter SetUnhandledExceptionFilter TerminateProcess QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime GetTickCount EnumResourceLanguagesA GetDiskFreeSpaceA MulDiv FindClose |
GDI32.dll |
GetDeviceCaps
|
USER32.dll |
ShowWindow
MsgWaitForMultipleObjects SetWindowPos GetDC GetWindowRect DispatchMessageA GetSystemMetrics CallWindowProcA SetWindowTextA MessageBoxA SendDlgItemMessageA SendMessageA GetDlgItem DialogBoxIndirectParamA GetWindowLongPtrA SetWindowLongPtrA SetForegroundWindow ReleaseDC EnableWindow CharNextA LoadStringA CharPrevA EndDialog MessageBeep ExitWindowsEx SetDlgItemTextA CharUpperA GetDesktopWindow PeekMessageA GetDlgItemTextA |
msvcrt.dll |
?terminate@@YAXXZ
_commode _fmode _acmdln __C_specific_handler memset __setusermatherr _ismbblead _cexit _exit exit __set_app_type __getmainargs _amsg_exit _XcptFilter memcpy_s _vsnprintf _initterm memcpy |
COMCTL32.dll |
#17
|
Cabinet.dll |
#20
#21 #23 #22 |
VERSION.dll |
VerQueryValueA
GetFileVersionInfoSizeA GetFileVersionInfoA |
Please select a folder to store the extracted files. |
%s |
请选择用于存储提取文件的文件夹。 |
%s |
Failed to get disk space information from: %s. |
System Message: %s. |
A required resource cannot be located. |
Are you sure you want to cancel? |
Unable to retrieve operating system version information. |
Memory allocation request failed. |
Unable to create extraction thread. |
Cabinet is not valid. |
Filetable full. |
Can not change to destination folder. |
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup. |
That folder is invalid. Please make sure the folder exists and is writable. |
You must specify a folder with fully qualified pathname or choose Cancel. |
从 %s 获取磁盘空间信息失败。 |
系统消息: %s。 |
未找到所需的资源。 |
你确定要取消操作吗? |
无法检索到操作系统的版本信息。 |
内存分配请求失败。 |
无法创建解压缩线程。 |
CAB 文件无效。 |
文件表已满。 |
无法更改目标文件夹。 |
安装程序没有找到含 %s KB 可用磁盘空间的驱动器,安装过程无法进行。请释放部分空间,然后单击“重试”,或者单击“取消”退出安装程序。 |
文件夹无效。请确认文件夹是否存在而且可写。 |
必须指定文件夹路径或选择“取消”。 |
Could not update folder edit box. |
Could not load functions required for browser dialog. |
Could not load Shell32.dll required for browser dialog. |
Error creating process <%s>. Reason: %s |
The cluster size in this system is not supported. |
A required resource appears to be corrupted. |
Windows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation. |
Error loading %s |
GetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used. |
Windows 95 or Windows NT is required to install |
Could not create folder '%s' |
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue. |
Do you still want to continue? |
无法更新文件夹编辑框。 |
无法加载浏览器对话框所需的函数。 |
无法加载浏览器对话框所需的 Shell32.dll。 |
创建进程 <%s> 时出错。原因: %s |
不支持此系统的簇大小。 |
所需的资源可能已被破坏。 |
此安装程序要求 Windows 95、Windows NT 4.0 Beta 2 或更高版本的操作系统。 |
加载 %s 时出错 |
GetProcAddress() 在执行函数 %s 时失败。可能的原因: 所用的 advpack.dll 版本不对。 |
需要安装 Windows 95 或 Windows NT |
无法创建“%s”文件夹 |
要安装该程序,需要有 %s KB 的磁盘空间保留在驱动器 %s 上。建议在继续安装之前释放出所需的磁盘空间。 |
是否继续? |
Error retrieving Windows folder |
NT Shutdown: OpenProcessToken error. |
NT Shutdown: AdjustTokenPrivileges error. |
NT Shutdown: ExitWindowsEx error. |
Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file. |
The setup program could not retrieve the volume information for drive (%s) . |
System message: %s. |
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again. |
The installation program appears to be damaged or corrupted. Contact the vendor of this application. |
检索 Windows 文件夹时出错 |
NT 系统关闭: OpenProcessToken 出错。 |
NT 系统关闭: AdjustTokenPrivileges 出错。 |
NT 系统关闭: ExitWindowsEx 出错。 |
无法提取文件。很可能是由于内存不足(用于交换文件的磁盘空间不足)或 CAB 文件已损坏。 |
安装程序无法获取驱动器(%s)的卷标信息。 |
系统消息: %s。 |
安装程序无法找到含 %s KB 可用磁盘空间的驱动器,安装过程无法进行。请释放部分空间,然后再试。 |
安装程序可能已损坏。请与该应用程序的供应商联系。 |
Command line option syntax error. Type Command /? for Help. |
Command line options: |
/Q -- Quiet modes for package, |
/T:<full path> -- Specifies temporary working folder, |
/C -- Extract files only to the folder when used also with /T. |
/C:<Cmd> -- Override Install Command defined by author. |
You must restart your computer before the new settings will take effect. |
Do you want to restart your computer now? |
Another copy of the '%s' package is already running on your system. Do you want to run another copy? |
Could not find the file: %s. |
命令行选项语法错误。键入“命令 /?”可获得帮助信息。 |
命令行选项: |
/Q -- 无提示安装方式, |
/T:<full path> -- 指定临时工作文件夹, |
/C -- (与 /T 并用)仅将文件提取到指定文件夹。 |
/C:<Cmd> -- 替代作者定义的安装命令。 |
必须重新启动计算机才能使新的设置生效。 |
是否现在重新启动计算机? |
正在运行“%s”软件包的另一副本。是否运行新的副本? |
无法找到文件 %s。 |
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator. |
The folder '%s' does not exist. Do you want to create it? |
Another copy of the '%s' package is already running on your system. You can only run one copy at a time. |
The '%s' package is not compatible with the version of Windows you are running. |
The '%s' package is not compatible with the version of the file: %s on your system. |
你没有该计算机的管理员权限。如果不是由管理员运行,部分程序无法正确安装。 |
文件夹“%s”不存在,是否创建该文件夹? |
正在运行“%s”软件包的另一副本。是否要运行新的副本? |
“%s”软件包与你的 Windows 版本不兼容。 |
“%s”软件包与你计算机系统中的文件 %s 的版本不兼容。 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2062-Jul-25 12:18:00 |
Version | 0.0 |
SizeofData | 37 |
AddressOfRawData | 0x9a64 |
PointerToRawData | 0x8a64 |
Referenced File | wextract.pdb |
Characteristics |
0
|
---|---|
TimeDateStamp | 2062-Jul-25 12:18:00 |
Version | 0.0 |
SizeofData | 496 |
AddressOfRawData | 0x9a8c |
PointerToRawData | 0x8a8c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2062-Jul-25 12:18:00 |
Version | 0.0 |
SizeofData | 36 |
AddressOfRawData | 0x9c7c |
PointerToRawData | 0x8c7c |
Size | 0x118 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x14000c008 |
GuardCFCheckFunctionPointer | 5368747592 |
GuardCFDispatchFunctionPointer | 0 |
GuardCFFunctionTable | 0 |
GuardCFFunctionCount | 0 |
GuardFlags | (EMPTY) |
CodeIntegrity.Flags | 0 |
CodeIntegrity.Catalog | 0 |
CodeIntegrity.CatalogOffset | 0 |
CodeIntegrity.Reserved | 0 |
GuardAddressTakenIatEntryTable | 0 |
GuardAddressTakenIatEntryCount | 0 |
GuardLongJumpTargetTable | 0 |
GuardLongJumpTargetCount | 0 |
XOR Key | 0x3690b900 |
---|---|
Unmarked objects | 0 |
C++ objects (27412) | 1 |
ASM objects (27412) | 2 |
C objects (27412) | 18 |
Imports (27412) | 17 |
Total imports | 160 |
C objects (LTCG) (27412) | 10 |
Resource objects (27412) | 1 |
Linker (27412) | 1 |