dacdabddebcc35c629c46bfdefbad010

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2024-Jun-10 21:24:32
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName MeldaProduction
FileDescription MeldaProduction MCompleteBundle
FileVersion 17.0.0
LegalCopyright © MeldaProduction
OriginalFileName
ProductName MeldaProduction MCompleteBundle
ProductVersion 17.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • https://jrsoftware.org
  • jrsoftware.org
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Queries user information on remote machines:
  • NetWkstaGetInfo
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 2525487 bytes of data starting at offset 0xd0c00.
Malicious VirusTotal score: 3/73 (Scanned on 2024-10-21 20:21:41) Bkav: W32.AIDetectMalware
Trapmine: suspicious.low.ml.score
Webroot: W32.Adware.Gen

Hashes

MD5 dacdabddebcc35c629c46bfdefbad010
SHA1 ea684a794da9715e5b8deeb47780e3349f65950b
SHA256 5c67212c03d20ea0fdb2eb8f61537cbbdaa2fb173dc0a2fceda2811040ace79d
SHA3 c8b39dc8190b78b6ca2547b928300a456ec16e124409af948969787ad3371013
SSDeep 98304:B5UyiNPb7v1uSBRHmrbE8YQ7Qle1p87/f8:MyGbLB8x7Qleve/U
Imports Hash b49b3861c48a6f37f9640009294a0426

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 10
TimeDateStamp 2024-Jun-10 21:24:32
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xbf200
SizeOfInitializedData 0x11600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000C0004 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xc1000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0xe1000
SizeOfHeaders 0x400
Checksum 0xdbf18
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9780468e467fe6aa0eafdeaf86c70e43
SHA1 bc9c0f4cf7da83957ced0df27d7e1ff27474ef10
SHA256 b3e24e182128b5710348a4c9c90560f5dd6fa3f3a2e5b5367f41d34e5060f42c
SHA3 2256b75b8a70756371f508494a88146ce85d34b1337d507d466cb8a36422d091
VirtualSize 0xbd8b4
VirtualAddress 0x1000
SizeOfRawData 0xbda00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.36676

.itext

MD5 413912c7da5cb2c25e79e310ea5affe8
SHA1 06871074a5a724bcff425e0bd10b57f307297b53
SHA256 d7fad1a474d4a876f73d0acc7f254804aaf3b31e943563f3f1ecd8302b0ea7b6
SHA3 6eb4b3dc4aceb9e4e88116f9e23fd26fb8c19abcc2c8d8b13ef823702a40cf78
VirtualSize 0x17ac
VirtualAddress 0xbf000
SizeOfRawData 0x1800
PointerToRawData 0xbde00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.13306

.data

MD5 51755f0b2df136b19467c4e7754a31a5
SHA1 4e55e5bc9bd12f7e870ffcc5391a04a524453dcd
SHA256 c7d2534ae160613381cf88194db011f96dac50dbdd21d780b2491f178cfc66a9
SHA3 4f0050197a77cfc56f1ef9d22e5bd3498fe446bec04779fb978bb15110fffea5
VirtualSize 0x3f4c
VirtualAddress 0xc1000
SizeOfRawData 0x4000
PointerToRawData 0xbf600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.60802

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x94a8
VirtualAddress 0xc5000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 7582ef3f15a5d322a99cb03d6b10a09a
SHA1 4deb7b2644b664298ddc15918cc32da500acfab7
SHA256 c02af166f45feda6d38ccd280e8649094993aae4aba826d9f043c68d08fe7b1e
SHA3 511418036c98f4eaf514726460a9a5b184c037a313ac472374a195af668a6731
VirtualSize 0x10d0
VirtualAddress 0xcf000
SizeOfRawData 0x1200
PointerToRawData 0xc3600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.87912

.didata

MD5 07d26ec7111ace9f0cde68f7e279534b
SHA1 cc044c1c1a885f72d19f1f0ec737504b2921761e
SHA256 4a116e4805db1fc58b37622b8ca2fc764920ee50e735fb6c4ba216a027aafc38
SHA3 f580213cbfa3f04724b79adbef0826553232aab0fc97bc2a2b93907f71284991
VirtualSize 0x1a4
VirtualAddress 0xd1000
SizeOfRawData 0x200
PointerToRawData 0xc4800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.76418

.edata

MD5 fa1e6fba1b2d9c1a9282338f3644d0b9
SHA1 f2fe896b0c80cfd5395262cc845813aaedd0e597
SHA256 e46de3751f6b30c58d8f0105881849a9be39ed703075cd33552d4d10d19ed0ea
SHA3 e2d7bd33f12a2518b35f1ebf78ae7d70a5e2494921fc849d4c056d62f418261a
VirtualSize 0x9a
VirtualAddress 0xd2000
SizeOfRawData 0x200
PointerToRawData 0xc4a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.87366

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x18
VirtualAddress 0xd3000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 5b75a462f7f0f49c8a970097caddd6d6
SHA1 2bd9716c6178d18accb39240ac7e2ca0e3e55372
SHA256 f6e0e43ca97731d712cd7355d41284035e508ad6d8f3332ce9a1fb2f4bba9196
SHA3 e8c4912fcf0fa65d85138ebcf369a360785cd46d31ede84ad3a78fef2029a65b
VirtualSize 0x5d
VirtualAddress 0xd4000
SizeOfRawData 0x200
PointerToRawData 0xc4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.36671

.rsrc

MD5 f190623c2f4996192a13e0bbb6e3e47c
SHA1 51fd5b0ff54b4469e3765856ba5b29a253a62c74
SHA256 c9225a3a8dc045ac4dfcebcabffd84b3a304d2c07e92c0ef943b742138b1188e
SHA3 d46456bec29c9d3e2326d2735a16eb92d1f3dd53588855be1867f386bf3db39b
VirtualSize 0xbd5c
VirtualAddress 0xd5000
SizeOfRawData 0xbe00
PointerToRawData 0xc4e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 3.2492

Imports

kernel32.dll GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
GetModuleFileNameA
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
version.dll GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxA
MessageBoxW
DestroyWindow
CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SysAllocStringLen
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetLBound
SafeArrayGetUBound
VariantInit
VariantClear
SysFreeString
SysReAllocStringLen
VariantChangeType
SafeArrayCreate
netapi32.dll NetWkstaGetInfo
NetApiBufferFree
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenThreadToken
AdjustTokenPrivileges
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
FreeSid
AllocateAndInitializeSid
EqualSid
RegQueryValueExW
GetTokenInformation
ConvertSidToStringSidW
RegCloseKey
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
LocalFree
CloseHandle
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetSystemInfo
GetCommandLineW
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
GetModuleFileNameA
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xd1080
DelayImportAddressTable 0xd1090
DelayImportNameTable 0xd10b4
BoundDelayImportTable 0xd10d8
UnloadDelayImportTable 0xd10f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xc863c

__dbk_fcall_wrapper

Ordinal 2
Address 0xf628

TMethodImplementationIntercept

Ordinal 3
Address 0x5747c

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.89222
MD5 a2a554e34238d88a3ef4f73acbe0a261
SHA1 a235df9a3a29752c366c4bb3c3daa1f21c421f35
SHA256 c3ee4c1806f6aab43352b88b9540ce4f35a010c3afe051ef86ac41c38b19c4f2
SHA3 6c27dea92a4c592c0622059233501fe1cbda584bfca7f8c437f0227e039f34ec

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.32532
MD5 9839babfb0dbaf833193544fbc4d6e5e
SHA1 f6676b511721f58b3fa6d8e70fd1ce781857835c
SHA256 b4e7c4d675c4ed81bc80682fdfec7b79784d9197e92fcd25f6809a87c877157b
SHA3 20c1736abfb842af709da600eb075cdb2140b85b81b14a8a957071a1e674d1c5

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.05828
MD5 b40a9468a348b818b0133533efa0b0d4
SHA1 b50a1f413a33901ee320a5e56e70f9ce42f431c5
SHA256 f0212c25d79e4b6f2d25e5d8eb740b36c11d388764cde8b90c8029cb359e146a
SHA3 d550f0591a0b919557597b0c230e29305af2acb10ed5c318efd6bf5656dbb410

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.17204
MD5 1b9b0fc55fdf5e9d07b52f690788fba5
SHA1 d1196b7c04da954c1c57f6131b5c939d0b3d3c55
SHA256 9adbc45bef72d9e43b841277b5c4a0fc7d1208822a72f090a264a4a565c4e16f
SHA3 5f2548b0cefdaf3a9ef8cd2f0295b9935ac05f4ef1d29b8a7d6ac74ea9607200

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.40963
MD5 762548d428ed6523fcf3ce21cfb881d5
SHA1 3469cd6490173277f63fdeed21372d35e4c9b49b
SHA256 0a4c0c1968008d1a8eeb72d01af7afa22ec16f995954a7635ad20dcf16c4c79c
SHA3 be32091a665a132317e40d4c63f95a0aeabc19f72fd45612192804394a821f4b

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04133
MD5 ce4b13d982d553346783a4c774eea97e
SHA1 f9a8b1db2215dcc1065def78a1baf93dc1137ff4
SHA256 6d8160605534540693c102f7ad8da879732783cbed4da15b52a0e7d0a69b922a
SHA3 333360f76e3e5e77f85f06c773b1a61425700540441e2ffa9ea018413c3e7422

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3bc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.25034
MD5 00e9e39479d434ac3a71dce7cb6ed4c7
SHA1 e8d56b421291d4544e555f07da75e354d20b545f
SHA256 0e57c6795194868ec9a26e350e4a0602635499b05d633112334111f32e917b04
SHA3 0d3634bfbca0ecf5d5d99a5e0644bacb7b4d6227a0e7d30d7134042216a9aace

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2dc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.52568
MD5 6389af7862593e7ce4db180f39e50140
SHA1 88b9651a981bf3348a74e5ab7d73a68c00eacb34
SHA256 91a2703df665f2d3201c6a5071fafb0b9aef1f7cf2ee36c53ba1d463251b1d90
SHA3 b14fffd73c83498cf4e53e90f20804af158c45088ae7f345668efc50088a4508

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x430
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24973
MD5 c585062fd9508d9ef6eed11299d5cdb9
SHA1 a86d3099f1ff650e0fbbcfa50dcc7069eb12a9bd
SHA256 a33f03dda00385bdf0b927b77ab2d02256f5dbb3d1e973a4bacd49a8e835d497
SHA3 dbce279b2b5fa3baae5d5fc5c390abd14c3467917892d72491220e955459fe7b

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x40c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33977
MD5 aeb11111a0334d20d978e15c3eb3ebab
SHA1 19969a1f68d497f0114538352da478b41c3d2060
SHA256 99b7194bf59ac43cbbdc441ab7ca14ab0330449accd33730281da09bb96bcbe3
SHA3 b734c35baae6e8fb009f07d3a20892bde53b7db5335b1327e1118e89d657251b

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31895
MD5 4ac29bb5f7361e85771807112cd4ec93
SHA1 b164bf0882b60c0d7d4643495a2c1db5a20a1343
SHA256 2e6d8102640132ccabd2fa3c3a61c77c2b41a80d7f60013cf7149819c2b5c9d2
SHA3 ee5ab8846732cb786d250fc1780293072aff157ae61cf7f671eb4e6e29018bf7

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45
SHA1 30704560832bafa440df1fd20693653c2a30f815
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.65899
MD5 69a9e884da4b0767c4bbd049ade35c95
SHA1 24a135dbe7577dcb1bd51dbe1919268f847f41b9
SHA256 9968189acc4274e4d27f063cb12e0c57bd58c86543962c3f9b158c6160dedac7
SHA3 20d3c07b2d932b9b337fca49e16b8a77bcbe892a25f125ba8c688ec433b8a2ae

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.85175
Detected Filetype Icon file
MD5 969e1847c12c106dfc006c928a9b87d8
SHA1 d6f338a6487a14b09218560b9f573d91ee271083
SHA256 b09e53e09fc8c7c8d7bd1c70ee755ec5bb3b5c29f95d34611d05c56ea6542fa8
SHA3 bd8f7448787405900e054836453bc88ade8a93ae7a98900e9dae8fe405306643

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75486
MD5 dcfb6a2c80bb07e3ae6ffae1f512d831
SHA1 68973c0cff75bc1a5c82abae687bf687c8d67fc0
SHA256 450a5e7863eeea5da1414b1fbf8432f6bedd059f935e377051b319c97b57d251
SHA3 2b26182f4193f73de0feccaa814c2fa3ea7204d0a7fa91d4e693ea4c248e78dc

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89085
MD5 e07ab8c9030f776ce0f6d9040d41c616
SHA1 593953973c74066bcd09b22402948425dab9b12f
SHA256 75bb01fe4bafdef22d879aaea5b85d1165a30ec0e558536e1b4c6002c4730d5d
SHA3 51b78d43db0954fcaa7c6fd2558eece5eb98a1c5f6e95a3033891777bfd00a7c

String Table contents

Windows Server 2016
Windows Server 2019
Windows 8
Windows 8.1
Windows 10
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
VAR and OUT arguments must match parameter type exactly
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Invalid argument
Source and Destination arrays must not be the same
Argument out of range
Duplicates not allowed
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Error reading %s%s%s: %s
Stream read error
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 17.0.0.0
ProductVersion 17.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName MeldaProduction
FileDescription MeldaProduction MCompleteBundle
FileVersion (#2) 17.0.0
LegalCopyright © MeldaProduction
OriginalFileName
ProductName MeldaProduction MCompleteBundle
ProductVersion (#2) 17.0.0
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4d3000
EndAddressOfRawData 0x4d3018
AddressOfIndex 0x4c1c1c
AddressOfCallbacks 0x4d4010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
<-- -->