e7a70923212586b014e40d20d1b803a9

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2011-Jul-01 18:40:37
Detected languages English - United States

Plugin Output

Info Matching compiler(s): Borland Delphi 5 -> Portions Copyright (c) 1983,99 Borland (h)
Suspicious The PE is possibly packed. Unusual section name found: .itext
Unusual section name found: .didata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • SwitchToThread
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegOpenKeyExW
  • RegCloseKey
  • RegUnLoadKeyW
  • RegSetValueExW
  • RegSaveKeyW
  • RegRestoreKeyW
  • RegReplaceKeyW
  • RegQueryInfoKeyW
  • RegLoadKeyW
  • RegFlushKey
  • RegEnumValueW
  • RegEnumKeyExW
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegCreateKeyExW
Possibly launches other programs:
  • ShellExecuteA
Can create temporary files:
  • CreateFileW
  • GetTempPathA
Uses functions commonly found in keyloggers:
  • MapVirtualKeyW
  • GetForegroundWindow
  • CallNextHookEx
Enumerates local disk drives:
  • GetDriveTypeA
Can take screenshots:
  • GetDCEx
  • GetDC
  • FindWindowW
  • CreateCompatibleDC
  • BitBlt
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC-4 timezone.
Suspicious The file contains overlay data. 3183425 bytes of data starting at offset 0x124000.
The overlay data has an entropy of 7.99306 and is possibly compressed or encrypted.
Malicious VirusTotal score: 3/69 (Scanned on 2019-03-13 02:02:10) Kaspersky: not-a-virus:HEUR:AdWare.Win32.DealPly.gen
ZoneAlarm: not-a-virus:HEUR:AdWare.Win32.DealPly.gen
Panda: PUP/RnkBend

Hashes

MD5 e7a70923212586b014e40d20d1b803a9
SHA1 6928cc27eee473f53a4e25d9b0dc4ce8556c15ae
SHA256 accd61ba734a95ad5fb2ea08d54ef28dd136729e6308ba2736b0cbfbaf70d0b0
SHA3 756942a05b6c49e5b4b8e7f9c55067981eb210febc3755ecfbf6654202467b5b
SSDeep 98304:0wwCYHFrNwdx2xeJwxtc0bkybUQJjG3C3BiMot:QdweeJKpbLbzJjJkt
Imports Hash c3a8489a4e4b12d37297073105c52659

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 10
TimeDateStamp 2011-Jul-01 18:40:37
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xf0c00
SizeOfInitializedData 0x33000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000F1DFC (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xf2000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.0
ImageVersion 0.0
SubsystemVersion 5.0
Win32VersionValue 0
SizeOfImage 0x134000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 af66a8375f977493e4cf37d197bdf2c8
SHA1 9a87140d5af43936d95438617762493e1808a5d7
SHA256 bb636c5e87312cf18bd31d0fd550f2ccccfa78e6cd4ad864ab95b6ebce230cd8
SHA3 5cee1a940a3f98f52da1c74d5ca1de3d91b710e338ec99dced1eb04973e50126
VirtualSize 0xefbc0
VirtualAddress 0x1000
SizeOfRawData 0xefc00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.48782

.itext

MD5 cbb1db815a42e11199de933ab29a23d5
SHA1 1b3fbd8725f92aa91f6dd379a5c76a11fa5ee830
SHA256 e943e744926b23076782113a57ad03729ca6d5cb1e2a30f5e2ca4209bb6a1954
SHA3 1440183b1ed9a7693c7436b98f25baecad260b162c9a73c18c503277ad867d1f
VirtualSize 0xe7c
VirtualAddress 0xf1000
SizeOfRawData 0x1000
PointerToRawData 0xf0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.85383

.data

MD5 235cbdd890d27a16f58db2edf86d7de9
SHA1 f8831f9a8799f6e108cee639765b41488c4b8d19
SHA256 0a056fc8ed2ebb50b6ab04ed471a05f340def50137b33f521b549735e22ea865
SHA3 3709cb4831ea9c6fdebae6f22a16c4e7edadba41b4bc336378f8189b718b5e11
VirtualSize 0x33c8
VirtualAddress 0xf2000
SizeOfRawData 0x3400
PointerToRawData 0xf1000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.31344

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0xae74
VirtualAddress 0xf6000
SizeOfRawData 0
PointerToRawData 0xf4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 6e65c897fb6e00f56e9181223791f4ba
SHA1 c28cb58b18d3c88f568397dd2aea72ea822ba04b
SHA256 79f7c4f844444d0beaabb2dc975048aaf228bd4369b946b24901862636a5b330
SHA3 95929996da93005c04010e74db04e5c83771484b6d77f0445218b5c105d8fa32
VirtualSize 0x365a
VirtualAddress 0x101000
SizeOfRawData 0x3800
PointerToRawData 0xf4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.11872

.didata

MD5 476377be76cf8a1c4aadba317da23333
SHA1 20df7272c516a856cfb444ca4cdc24d7763d400a
SHA256 5dcdcabb8291ab8dca153ebfce3e1409498be9a835cb6389dfef419dbaa24506
SHA3 db3c8c922d36d28dd865ad362b754f2beef25e3a9f95bdb0fbdb27827e8cf1a4
VirtualSize 0x3a6
VirtualAddress 0x105000
SizeOfRawData 0x400
PointerToRawData 0xf7c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.60858

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x3c
VirtualAddress 0x106000
SizeOfRawData 0
PointerToRawData 0xf8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 0c92b028e8dd8041758edf934914e454
SHA1 593d4866b03ade5685c346609282472182b34c99
SHA256 9c5199f1533c013df8d704d48d19c444a6ceda98a9649a0addd6e3c2c367d261
SHA3 998b0c6e59efbe11e96f433cb51e2338bce2855d1bb446fec7cff2873d1b3642
VirtualSize 0x18
VirtualAddress 0x107000
SizeOfRawData 0x200
PointerToRawData 0xf8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.210826

.reloc

MD5 972e4fa2eb3b0448a426d8f13d253534
SHA1 de01d79b076d676c289ee4f401bbb5ace63ec24f
SHA256 5fe1c20b7ec70dcbbfc929f8de5c7b55934ecc2484416e428320b57f813b5a28
SHA3 bbdcdd7679b08d62a6fd93a83cdf32ca18c132fd042089c6f289a18b651d640e
VirtualSize 0x13c98
VirtualAddress 0x108000
SizeOfRawData 0x13e00
PointerToRawData 0xf8200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.69509

.rsrc

MD5 1442858d55fbd13758d975c27ac3e8de
SHA1 7c06c3eefa04c4d540fe473b5920aaef73c7023b
SHA256 2bb42076b5d2e79ff94312bf11739162b935add1e421dd00bbbd1b2702501710
SHA3 ab0516d7fc35a686906f06f3265d8aafacd9f1fbeb702513105bfb939705ad75
VirtualSize 0x18000
VirtualAddress 0x11c000
SizeOfRawData 0x18000
PointerToRawData 0x10c000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.80649

Imports

oleaut32.dll SysFreeString
SysReAllocStringLen
SysAllocStringLen
advapi32.dll RegQueryValueExW
RegOpenKeyExW
RegCloseKey
user32.dll LoadStringW
MessageBoxA
CharNextW
kernel32.dll lstrcmpiA
LoadLibraryA
LocalFree
LocalAlloc
GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
RemoveDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
IsValidLocale
GetSystemDefaultUILanguage
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetUserDefaultUILanguage
GetLocaleInfoW
GetLastError
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
CreateDirectoryW
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
DeleteFileW
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
CreateFileW
CloseHandle
kernel32.dll (#2) lstrcmpiA
LoadLibraryA
LocalFree
LocalAlloc
GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
RemoveDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
IsValidLocale
GetSystemDefaultUILanguage
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetUserDefaultUILanguage
GetLocaleInfoW
GetLastError
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
CreateDirectoryW
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
DeleteFileW
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
CreateFileW
CloseHandle
user32.dll (#2) LoadStringW
MessageBoxA
CharNextW
msimg32.dll AlphaBlend
gdi32.dll UnrealizeObject
StretchDIBits
StretchBlt
StartPage
StartDocW
SetWindowOrgEx
SetWinMetaFileBits
SetViewportOrgEx
SetTextColor
SetStretchBltMode
SetROP2
SetPixel
SetEnhMetaFileBits
SetDIBits
SetDIBColorTable
SetBrushOrgEx
SetBkMode
SetBkColor
SetAbortProc
SelectPalette
SelectObject
SelectClipRgn
SaveDC
RoundRect
RestoreDC
Rectangle
RectVisible
RealizePalette
Polyline
Polygon
PolyBezierTo
PolyBezier
PlayEnhMetaFile
Pie
PatBlt
MoveToEx
MaskBlt
LineTo
IntersectClipRect
GetWindowOrgEx
GetWinMetaFileBits
GetTextMetricsW
GetTextExtentPoint32W
GetSystemPaletteEntries
GetStockObject
GetRgnBox
GetPixel
GetPaletteEntries
GetObjectW
GetEnhMetaFilePaletteEntries
GetEnhMetaFileHeader
GetEnhMetaFileDescriptionW
GetEnhMetaFileBits
GetDeviceCaps
GetDIBits
GetDIBColorTable
GetDCOrgEx
GetCurrentPositionEx
GetClipBox
GetBrushOrgEx
GetBitmapBits
GdiFlush
FrameRgn
ExtTextOutW
ExtFloodFill
ExcludeClipRect
EnumFontsW
EnumFontFamiliesExW
EndPage
EndDoc
Ellipse
DeleteObject
DeleteEnhMetaFile
DeleteDC
CreateSolidBrush
CreateRectRgn
CreatePenIndirect
CreatePalette
CreateICW
CreateHalftonePalette
CreateFontIndirectW
CreateDIBitmap
CreateDIBSection
CreateDCW
CreateCompatibleDC
CreateCompatibleBitmap
CreateBrushIndirect
CreateBitmap
CopyEnhMetaFileW
Chord
BitBlt
Arc
AbortDoc
version.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
kernel32.dll (#3) lstrcmpiA
LoadLibraryA
LocalFree
LocalAlloc
GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
RemoveDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
IsValidLocale
GetSystemDefaultUILanguage
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetUserDefaultUILanguage
GetLocaleInfoW
GetLastError
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
CreateDirectoryW
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
DeleteFileW
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
CreateFileW
CloseHandle
advapi32.dll (#2) RegQueryValueExW
RegOpenKeyExW
RegCloseKey
oleaut32.dll (#2) SysFreeString
SysReAllocStringLen
SysAllocStringLen
ole32.dll OleUninitialize
OleInitialize
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CoUninitialize
CoInitialize
IsEqualGUID
comctl32.dll InitializeFlatSB
FlatSB_SetScrollProp
FlatSB_SetScrollPos
FlatSB_SetScrollInfo
FlatSB_GetScrollPos
FlatSB_GetScrollInfo
_TrackMouseEvent
ImageList_GetImageInfo
ImageList_SetIconSize
ImageList_GetIconSize
ImageList_Write
ImageList_Read
ImageList_GetDragImage
ImageList_DragShowNolock
ImageList_DragMove
ImageList_DragLeave
ImageList_DragEnter
ImageList_EndDrag
ImageList_BeginDrag
ImageList_Copy
ImageList_LoadImageW
ImageList_GetIcon
ImageList_Remove
ImageList_DrawEx
ImageList_Replace
ImageList_Draw
ImageList_SetOverlayImage
ImageList_GetBkColor
ImageList_SetBkColor
ImageList_ReplaceIcon
ImageList_Add
ImageList_SetImageCount
ImageList_GetImageCount
ImageList_Destroy
ImageList_Create
InitCommonControls
kernel32.dll (#4) lstrcmpiA
LoadLibraryA
LocalFree
LocalAlloc
GetACP
Sleep
VirtualFree
VirtualAlloc
GetSystemInfo
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
VirtualQuery
WideCharToMultiByte
RemoveDirectoryW
MultiByteToWideChar
lstrlenW
lstrcpynW
LoadLibraryExW
IsValidLocale
GetSystemDefaultUILanguage
GetStartupInfoA
GetProcAddress
GetModuleHandleW
GetModuleFileNameW
GetUserDefaultUILanguage
GetLocaleInfoW
GetLastError
GetCommandLineW
FreeLibrary
FindFirstFileW
FindClose
CreateDirectoryW
ExitProcess
ExitThread
CreateThread
CompareStringW
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
DeleteFileW
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
CreateFileW
CloseHandle
ole32.dll (#2) OleUninitialize
OleInitialize
CoTaskMemFree
CoTaskMemAlloc
CoCreateInstance
CoUninitialize
CoInitialize
IsEqualGUID
oleaut32.dll (#3) SysFreeString
SysReAllocStringLen
SysAllocStringLen
shell32.dll ShellExecuteA
shell32.dll (#2) ShellExecuteA
comdlg32.dll GetOpenFileNameW
winspool.drv OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
winspool.drv (#2) OpenPrinterW
EnumPrintersW
DocumentPropertiesW
ClosePrinter
winmm.dll timeGetTime

Delayed Imports

1

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

BBABORT

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBALL

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.16995
MD5 f8a9b4a8f4097cea6a482026484c4d12
SHA1 2057a63edce2cbb165512bfad326728cf1053d60
SHA256 46cfc44afa8ab31ae3da35fa8346e4c085c441659d9992b09fc8ad517f2b289a
SHA3 f3852a8bcb1b38f498231cca2b0427af6c4c52886f92f980968d40fd8e8c5337
Preview

BBCANCEL

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.92079
MD5 c987e709cafd3a191333610e4c44914d
SHA1 901e4db5d379a222dd416776633ca9738db32e14
SHA256 c0ede68a98bd2bc58c78564dfb42f1640dc29766d3ab2782ab8b5ed28c6fd414
SHA3 7b14efd89b642988834daf08c97db5bb847f941d75f44a3915e3e5dca2510c53
Preview

BBCLOSE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.68492
MD5 6c2fba077bd332b3a48d6b5e43fe4a22
SHA1 e7d12e9fd5659881742773884db8ca537765dc81
SHA256 f8e1696801fe89b88936ac4226cea03bfa5aa345aa33ca982822ae7fbc6557e2
SHA3 39193ea4b2ffb32f16c75ca88ca20465a374cd928aac9b4b3ba5739bbb6222de
Preview

BBHELP

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.88085
MD5 1021657335ba4838db07f5231723df3b
SHA1 68f04f6ecbf628029e4e0061392029edec2b0e43
SHA256 cb7421b5c6af74c3159c361f3bb78bba8a488d8979d1250e106fa96cbf928789
SHA3 888ed4f8473561552d848c3d6624e2331c4ec7795bc5001237cb752b96e4929c
Preview

BBIGNORE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.29718
MD5 098b5f6c87471f5a83a4e55a6a036d6c
SHA1 e16d9186ffa72cc3e373cdf8e40f9e570f0082e7
SHA256 41f05a4df5f42d92b879493d51941de342d36460fe15c0f3b63b2b706b928fef
SHA3 7939e94342a45e6742dbf7c93f5b42fb861ac81b1fe5e8e04e49c0421338b2cf
Preview

BBNO

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.58804
MD5 8832519641f28981f87e1b3006896eef
SHA1 916eaafcf9ffb12bfd6338419bdd22764778ebbd
SHA256 81265e63c89ee5c2e5126452e22f84e9be9452449f3e5959ab6d346cb58b2bde
SHA3 39743ce838b215420cbb732e107e4c45f63384dcdd5b830d15097fa06cf32cc2
Preview

BBOK

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

BBRETRY

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.53344
MD5 7daf7522622a4fe823701fd2ff6f4996
SHA1 89f40bad3052afafbd71e80c07b928ec1aa7f4e5
SHA256 c925e4a8cbf6d42dbb1220a510614df725558f8d843338982bab8c4e020f6429
SHA3 95aa592de7b91edb5889cf5f9a7b042d3b6f6910bbd657ba85632f0d0ed557fb
Preview

BBYES

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x1d0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.67459
MD5 4b349737af0b7e5a5308dff7b93b274b
SHA1 b3d36a94fa9a57ad7a68a3b30be92947e811e760
SHA256 6b97877cdd547e6ba6467f86055f1fc7b06660b034439f0da4c137538ef14a83
SHA3 b9e9646067eae58ad9aded92130651d090a92771bae94676003e9aba47f77cd6
Preview

CD1

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.99925
MD5 1224699897d1aeb6fc845290e04bb75b
SHA1 14099f9d1e51ec7fda3cecc58334c79fb3a148c0
SHA256 1c189e906cfb6063011290660c6b52bf65484e470f793098d0334c333c4cb838
SHA3 6b87db65cfb3c35c7b5d850980ac4c1acd0232779efe02396e809642c68a46cd
Preview

CD2

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.03365
MD5 483b074ca57d94d9733a3f07bf048e12
SHA1 1f0b7073b7bae57cc0fdc9797d17ff553b1ee8f6
SHA256 21a6d224fe446379def069c66e542c44fabec20decf2460d57e0fc4750efb93f
SHA3 60b380f0270495bbfa62e6e498d8a9a7f7183940646b902ea8f4aee1b9e9f28c
Preview

CD3

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.99925
MD5 57654aa2adef69a44657c31d12e4db7e
SHA1 c2b06b50c135b870c77af0de5be63f20de7d5d73
SHA256 9927b3e46806131e57821fab9e4d0e01a1a58c0e43752cfcbdf5efa3c7685810
SHA3 d20bcb023695b3c3840347d353906043eac7a58d5c36af5115fea092cf3fa0c9
Preview

CD4

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x4e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.02725
MD5 bb86b96eb8a15b4f2ecd32caabfcbcda
SHA1 017e329199fd5f0000b44109ab8121510c4dfe74
SHA256 b65a0bc16f6e7439c043aee29377816ddf1dc25606345481df2388647c826f76
SHA3 b8c2970a4344bfaa6ebc72373f9c38631e9f905905406746dee00e68f48179ee
Preview

CDROM

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.78825
MD5 6bb98462b4b00776fd17038cbf1fb4bd
SHA1 f40205d022d824e0b7d930151138991504af3dc6
SHA256 4f72c53f3bac49ce0b7c248152479a14e383a90c9fe95edbddec9f03784ca698
SHA3 2e951c0dc6c1e7540825793fbf48393c33a7156ba8a9ce6343a06323ef1716aa
Preview

CLOSEDFOLDER

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.01477
MD5 7a7f1740c64d8b5af56ef7611410255c
SHA1 df7641fd3a5588e182515b337dcbbd28f2de12ab
SHA256 d20c1e7cdff419e1efe08e1b91b4c0d772f7436de618045f7e0fdb3afb662849
SHA3 111928d2405474821d76f758f1ba2dfb15368f64bbfde0644c9ec7acc5f56c9f
Preview

CURRENTFOLDER

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.97986
MD5 53466cf475196c6a883514140b1253c1
SHA1 02f577f238ea87b3400ec0ced2315d53cddfc7d1
SHA256 0f5248f16fe2b1e73aa9be760a6f0bef933dc09e3cc6d8a8958eae1ce0bd0f97
SHA3 e38ae4779212d26cd9f3f9298910aa52dbbbce2527673aa9ada7de9deb1a817c
Preview

EXECUTABLE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.96393
MD5 d623fd4c67881a744b9783e77cdaa9a3
SHA1 07fd1454decb874d847cb6e3a847391e3b03865a
SHA256 4a217ca811d9c29363ead1d67b7ffa0f6e8b8e1d1a068730f4f7d557c3710b44
SHA3 2aa8c8713c75f32e131b449444a6b570ee7be8da50c2f7e8a499cef693339e85
Preview

FLOPPY

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.63812
MD5 c3a2737f14f437f54cbf251782ae0a45
SHA1 e0a402c41f62804664b9d9cb9bae9615bf60f5ed
SHA256 2cb60d7d674640457497f54b82b42afaa8a2cbd7c28a1aae35f128b4471cfaaa
SHA3 eb1bb0ae168e1645292c6759be7ba322451b7035d87f01f8bf0f548290bb1830
Preview

HARD

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.62043
MD5 47957e26414e5a0cf93c9049b1a7f2a2
SHA1 08a70125bb3cf069d224c94dd4f4632b8f671a61
SHA256 a36fee3ac0a24b86169997e112d55de38ae2080815d2104c73bc90ad4eff5cbe
SHA3 59409ff1a314a69758371a1dafa7f175812eb3821240ff5b25b7b881b9d58deb
Preview

KNOWNFILE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.83217
MD5 7a6c4028ea8bdbe916a592614cb67a33
SHA1 e84fa7f028b79b4c641a2d66ad1ad296b7e6a262
SHA256 d8444a0e4c91df51a151d4c64256e5d5f62a3e4a5b17ccb9778422f0e01223c3
SHA3 de4dcc10f2110aa3f30104c8ef6a447c8fb22789a236072e61e38d5e16d0e0c9
Preview

LINKCOLOR

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xf80
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.22639
MD5 dc04d392941a41d936c5030aae616686
SHA1 916337f3e0dba6782b9be1f53e63f3f905241123
SHA256 5343db2d1152548a85756eaf8b2f4a87417aa4ba321ffe40c45a380e38b70934
SHA3 17c1ec03b93c8cdbabb07a0293c146c1c1b3127afedc3cdbc22ab18bb918b003
Preview

LINKFILLED

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xf80
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 1.42366
MD5 a748a2ad2f1ae3a335bc8b5d49de91bf
SHA1 1bf6f9c6a340e96cdb6a28c216424cbee69a368c
SHA256 1a87c46577db0c7b072613ebe92cd299d62c45da48f685cbae24ba447b3a0904
SHA3 b23e0d62d68f7d9920a7af4f6d140745871449acf00df2f63bdfcffa2ed3b459
Preview

LINKOPEN

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xf80
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 1.19406
MD5 25d720adf2df07f95dd38f8b392c8c9a
SHA1 08cdbe75009133ec9cc738fb92d1d4c72c500115
SHA256 2206cef63526454d7525cf9d92a92172c2dfc637041234b7b592729dd5403c56
SHA3 43d001c52e1068caf8658f63be6eab0b97a46fc31d627fa8744a58a54c8603d8
Preview

LINKPROLINK

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xf80
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.23963
MD5 964f09641781780aeacfc1539838ac6c
SHA1 3d0018a7ca57b23249ca19133617961bb3c55dd2
SHA256 2240acccbfd906515f6746262798cca7feded004ea8ad51e1fa12d0184d16b58
SHA3 e231413507d404703f396448f9b817f556fc681c3aeb99f52da6228488bf1d10
Preview

NETWORK

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.73457
MD5 30e739f7ed3dd033117260d97bb67e99
SHA1 b97adf513dd432cf039cd9425caf9b3241d7d233
SHA256 caf10784d936136cddde6b4489d7ffdc6098f8050a81c7e02d1ebdd9878cff15
SHA3 1511f9fa160bee36e6099269dade08d1a5709a22360ccbd4060fa6b54b8fb7d4
Preview

OPENFOLDER

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.0519
MD5 9b7d7f0031cfa6a137ff6436e59986fb
SHA1 20eb56f55581540919b119113b567bec618c3f95
SHA256 e086586402b8c51192766a01a37dd2f2b4b657bbd4d5b721f1eed692678f6ef6
SHA3 86a19763883baaae65d79b7e3c64525f16b942bd1187792bab8f56f7efaa2c56
Preview

RAM

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xc0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.73213
MD5 0ad765e61ab984673ce3db3a91fc6182
SHA1 2b67d4f1eec717c3aa2472db56ab4472c96b742f
SHA256 5bea8ae9edb158f767d478703ce5153b8773e1e0390fa2c4af83f063c6c2f1fa
SHA3 deda4d692b33e267292ba10effd899736e090a1af7f55028cdaa0ef850a85945
Preview

UNKNOWNFILE

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0xe0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.50975
MD5 307c6180ecb5efadfc8d59bb7dc28a5c
SHA1 8cd2e11eefecccd0c1414ce2b548c4fa82621dd4
SHA256 6af26f85073e8fce3b9ab49acbde0b702f68ec078be72e8aeca66086947a885e
SHA3 3e2f18021c6974600d7e8fc8064bb225657e4aeb0e28b7fdae034c6e938e264f
Preview

1 (#2)

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.04644
MD5 7192ac4251f9d11d755fd1fc545936fb
SHA1 36e4dd39b929273bff771099e59cc4c726d99276
SHA256 983874a0b4ac29f9a7a3e2bb61e842d9dfab5e33d7fe864dc0b6e83edf6899bb
SHA3 ebee3ab23b6fbfa5a8962ec8305a86a52b113f0a8ac8c2a38122ca18867de88c

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x374
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.31077
MD5 d81a31eb655b599c4bfb5d7753bb62a0
SHA1 407a0918469dbdaa3324bfcc8bfaba504244bcce
SHA256 6587d405ef1a683a371f68762eb80179205b104be384673f498cd3a3f10678ca
SHA3 c4f3edf8315a3799acc0ebbb4f3ba010e251db374b3357f556753bfa322fe93d

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x258
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.32609
MD5 1553db0d052a63290f59f524147d3869
SHA1 536e2c67e1478b44a08983cc2f6906a76a63f107
SHA256 709bfdff74073a9ecd1eaa36255e9a64faeb1f792a910e3d24382e63d9960186
SHA3 0b7523c6c3102aee0508f30d61c1e02592e721c14426e14fb84bd334b1867b34

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xc8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.46609
MD5 9a37b48c778a55a024ad74d9275832c9
SHA1 e78b5df8f2df9792177269c32263953328231694
SHA256 711a01bd189bd0d99ecdf33355d34977ea722b4a96eca2789f8c82ff7c713900
SHA3 a3d4bcce5997aaae99d58266ed0f50c225178cb265702b7253187b26e4ef4d56

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x118
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.46883
MD5 8621a10f12d96e92d6aecffe73068d58
SHA1 729aa660a9696f0f102aace8f110bba44765be47
SHA256 f5e75d6c0af5d1bc90dca21def3918a23c285e3fa90a8144ae2685c0b23a17d0
SHA3 11d552fbe44d4c1926a8894db8b16d65bfb75bb9574605789f5c659e2e091df1

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x268
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.37149
MD5 bbb7ffdb5fa0eac1698f8babd5f30ac7
SHA1 7f437740f8810b1c5517b93134dcd230086832e3
SHA256 21a716b6a36a6acded684c74deb7a92596cc828c6a0b1046a31624dcdad20bc1
SHA3 25d567acb97ad21ec3cfb04094299fdc00b770a1e9af95b4ebd3130e4fc27e23

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3f4
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.26893
MD5 befc611b4e27ffa8ee607e064236341c
SHA1 def062e4b34507ec0caf4382115b299fa7fb59a4
SHA256 00024e9bd788a0b9b2d17725d049170a55c498b474f8651a0407c9973177927d
SHA3 b6bddde89bbed22c1d7347ec253e8b60c1636469faa6906c6ce334728c972f09

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x35c
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.29634
MD5 3c0945b8da25b0773b923324d4552de5
SHA1 19ced035eca200bbe78029c74c03080341266f34
SHA256 5dec87436b6902d3202f8acdca32e3e6721954090f89e72deacdea48ff747239
SHA3 4d36976bef36610d4d9b8976cd370aa06c6427834077495486c9037923060999

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x414
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.26871
MD5 f8e41a96da84e0e5c915325c7c49d05b
SHA1 b5e1a32d5666ec3758d510b2e1eeef5bb7bea4a9
SHA256 d1072d683a747b4f93d99620e5efd3ae41b739c13052347c8d06462d67199648
SHA3 823a1a00cd37126b983589518eba021c571fed2c00e70017e22ad325f98227a8

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x384
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.21482
MD5 a7404d420fb733bd95107998668f9f72
SHA1 a2269b28b47bdb590e178c10c5d30e938a490bc0
SHA256 4d2f7a5d8ca4dd3f88870db6fa997a713387a77781b5729047546ff1a6ec9f51
SHA3 9bb0e79315f657e792a7de70193b1245c7867205b88edb08b76fbe48fcb3b915

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3c8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.31387
MD5 29999c61ed6064b7be2b32697c8b986b
SHA1 926d0fc56a909f99bff251ab76a3d836a23596cc
SHA256 8af1e84b04df3ccd4681bcf1fefa0c44dc3f85ea996cfd4c5e37950e2be40280
SHA3 55fff6b5de687f21d21d71325b6a5cf21d46a668202894dfde7455cf7b9ac9be

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3b0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.33652
MD5 fe8a66511db8e16cb0b6fabeb37fb04b
SHA1 6a34a2e54e47c4f55ee456bc3c69d47f2b99672d
SHA256 c219274d018d6021e69ac3a9e7e948fa674b9d33e626d39105e5d2ace9e61dbd
SHA3 b06cbf9cb8535ab6dbe5e77b4cf464ee8092cb03dbe3d61b52c7ccf296ea691a

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xcc
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.27116
MD5 fbfc238a45378c31fbae9bf45ec7f746
SHA1 5ce4e6515469074eb3c19bec6ecc8ac8a3e8642a
SHA256 786bc22aaa9dcb464caebde8e8d8b06a54bdb4c7abd7b1c53d0928be3650b386
SHA3 51c31b1c773f38ad457f08d3f91512a7dc41ac104f11460e1ef1c1036278c58b

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xb0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.32381
MD5 dca3a6c0c0a3c64d21555423c09e6c7f
SHA1 20b22b413f0e6157971189cd3646dd6a6d950dee
SHA256 676b0f607a54bc7a1d9c6e5c81ee45f5fcc11836860c714ca8df8ba1c3c4af4c
SHA3 d0f4388748387b467b6f9d71a6ec2752a6c27e0aa54aaba0e865f61a4574b944

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x298
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.37816
MD5 4e2ef41ad2b2329af3669e8c30d2052a
SHA1 b767576af141c9a088ef7d1fd53a777a9bae28d0
SHA256 48e2bb16c2ea3b89024198cd1a312c7b260a70b238cfa22953930b9534ea5da1
SHA3 9b332b3c37790e1de316bb40d118f02f38d8ad6abe64cf300e2711240de4aa1c

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x46c
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.31163
MD5 512ba4d45387f12b230dc19abd9645ec
SHA1 4264e019e5578b1c5603b461556e36f51da0ea02
SHA256 575a38a40e51c0e3cb50523264f10b41050142418cf516aa5f9bb79f8fcf1a9f
SHA3 d4711f082b198137d259db99c2683ef5df3f0f20b48c9a3ce80d3cec5c1d92e8

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x35c
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.33933
MD5 3959de07687076819e595c726efe714f
SHA1 607464112d8c08052ce60fa48ab176430abede27
SHA256 5de3ab0e6ffdee43cf7921ca4d399bfe27e67fa00ab2d657012e9157fc5c3d3a
SHA3 74197beeec1e37d1a5d6929fc585c80da29c68310172de16533f3559a6af3227

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x2c0
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.31316
MD5 8504d2a06f81476c9232c86c83802d77
SHA1 7eda3738bb4e448af6c5db125edf1ce41eacf437
SHA256 637a8a9b688dd3c8b29c4b96e2c0d86d09ca8eff0be6fb1d0a360982d3296581
SHA3 1654fc8f1348f0659702c033dd7b559743aaefd7f06b78941ff52ab30258db12

CHARTABLE

Type RT_RCDATA
Language English - United States
Codepage UNKNOWN
Size 0x82e8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 3.5072
MD5 6e9c1c8c0a0ec8d73165779560cd7ba4
SHA1 d044c45e2ffd24e1abef00079577df385e325ab4
SHA256 677245e2a6b2eb5495b4965b8c26025a4b26e8b8c21a825f658cb390b493b9a0
SHA3 3ec7819e8561ecad66b1ef2652d4f3b275030f7cf402f276daa38f28d288e4e7

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 4
MD5 a40263c75fde7440b1086b7da9c51fc2
SHA1 139a84f87110fb5cb16a386adade21f30cae98b0
SHA256 e7dbe99baa5c1045cdf7004edb037018b2e0f639a5edcf800ec4514d5c8e35b5
SHA3 d3a734fa7d36868d301f9569de92e1bfc551e4b5cf6d7c59eace8d0a554093c0

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x4d8
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.37914
MD5 f59fa4a7ae509d286ab8eda86f990747
SHA1 cca5f052524b24fa1b61ab8325cfe4064f409358
SHA256 b5a448bc91f2a730e37fb136be0b7ee7b2e3cfff19d88bce28d0dc88a43bc39c
SHA3 31e0e97918eca607138b695782d3bb2d444563632be0d39d878a1f4dbbdef8ef

TFINDFORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x4ec
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.4715
MD5 4063fb70d6c55b00622d7862d06a51fb
SHA1 9172e1bf3ff79717c6eb6c1a045f178a0c68ebc3
SHA256 4fb81814b0f939ed944b0ebb9e4830c91621a3a60e6675d3a76419b8c23b43b9
SHA3 3d851c4cc7afc0aa904229593a67a5b284ba8e39a6b6b2bcae0f193d27416322

TFORMDEBUG

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a1
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.40289
MD5 120826b7014c67b667ba1eb8405f3210
SHA1 0b8cb50e94023bf6a21ae15542d7b1e4c64fbbc5
SHA256 c477281daf80de4c0a80bfda6760f21c6bbe9aa2666f7f91f0d586a77408ef6f
SHA3 1aea597ab97504e4c6f29c3d00be2cfaf82578f502a3612717f924bbe842a346

TGOTOLINE_FORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x27a
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.45466
MD5 a68c967b59a701fe05f051fda7c7619d
SHA1 b2ff6bee711c795ed698e8f47799518215d1f997
SHA256 4ce93d8b8a58dd466ebca978b837d5e65c2be3a223d4752469c0e6859db79438
SHA3 08708c2e8a58fb2145f02e6af280276b3cd3968c1345fe09df564f7f98741513

TINFOBOXFORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x193
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.3578
MD5 7c4e665e869253a5d1bc916fedd27c34
SHA1 e3827a50e1da6708b0b6c168cb398d4a52f0416f
SHA256 29cc8e4d4dd5cd66f7b0e4a213ae66e25bfa5f549f95ef9bdf9850a4943694ac
SHA3 b511cad4f992284f5b3f1be099298df67b4c562d739971cd74e5c4dc21309a01

TMAINFORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xdef
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.42282
MD5 df42817ce708c729ea13c99a4a2f7a41
SHA1 ede8f7b671ac96cf36f18c584731fb7263289e13
SHA256 a98d794a4ba7264646aab304b9ebd2c207de5849135f6a73a62b03c52783d162
SHA3 5948bb0c5f06de48ee9efb12ac920198bdf81356c4cdfd01ec6f18fb0f2c731e

TSPECIALCHAR_FORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x1bc
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.38791
MD5 de536749593c0a20e8686d115fc1a53b
SHA1 6f0218155ef9eb6fbac365aa815b36b48e8baefa
SHA256 9b35176ff95f3af091706ad1cdea978ecfff1c1a1582c028380d7973fb6683de
SHA3 f26867f4d3ec44159f69b7561973882829bb0da216d3a0c6f02324dba2f4ac7c

TXYGRAPHFORM

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x16d3
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.44435
MD5 b72818f269b256abdcd672eafb95e977
SHA1 b6e49755fa747e694046b7f7c959410950094b69
SHA256 82481c17511d9f050e0ed510ca0f71f91d499b826b05f66c1965176a1830b594
SHA3 5c0937a1f431bec62352247d3dc8a7b70653397ffcb8ba199392ffae1c346d99

TXY_ANNOTATE

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0xb39
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 5.43053
MD5 455956ce34c75e69089d5972c25507e4
SHA1 5245a8b0c86e019b771244e6a76fc78116a7d2e6
SHA256 e7eaf4958b0ab7b1317d3fe4c273094d6810aade5de264a859dd295b74a4c04f
SHA3 cd9dd5913626614c69572c0de6e21b8c531e4fed45a77594667d56d7afdf981f

32761

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2011-Jul-01 14:40:38
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

String Table contents

Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Error loading dock zone from the stream. Expecting version %d, but found %d.
%s requires Windows Vista or later
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
Cannot change the size of a JPEG image
JPEG error #%d
JPEG Image File
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
All
Unable to insert a line
Clipboard does not support Icons
Text exceeds memo capacity
Operation not supported on selected printer
There is no default printer currently selected
Menu '%s' is already being used by another form
Docked control must have a name
&Retry
&Ignore
&All
N&o to All
Yes to &All
&Close
BkSp
Tab
Esc
Enter
Space
PgUp
PgDn
End
Home
Left
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
TIFF Images
Warning
Error
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
Printer selected is not valid
%s on %s
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
Can only modify an image if it contains a bitmap
A control cannot have itself as its parent
OK
Cancel
&Yes
&No
&Help
&Close
&Ignore
&Retry
Abort
&All
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Parent given is not a parent of '%s'
Cannot hide an MDI Child Form
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
Printer is not currently printing
Printing in progress
Printer index out of range
Icon image is not valid
Metafile is not valid
Invalid pixel format
Invalid image
Scan line index out of range
Cannot change the size of an icon
Cannot change the size of a WIC Image
Unknown picture file extension (.%s)
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Unable to Replace Image
Invalid ImageList Index
Failed to read ImageList data from stream
Cannot call Start on a running or suspended thread
Parameter %s cannot be a negative value
Input buffer exceeded for %s = %d, %s = %d
The specified file was not found
No help viewer that supports filters
Invalid Timeout value: %s
''%s'' is not a valid integer value
Invalid argument to time encode
No context-sensitive help installed
No help found for context
Unable to open Index
Unable to open Search
Unable to find a Table of Contents
No topic-based help system installed
No help found for %s
Bitmap image is not valid
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
A component named %s already exists
String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid file name - %s
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
Invalid data type for '%s'
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
%s has not been registered as a COM class
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Jan
Feb
Mar
Apr
May
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Custom variant type (%s%.4x) is out of range
Custom variant type (%s%.4x) already used by %s
Custom variant type (%s%.4x) is not usable
Too many custom variant types have been registered
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Error creating variant or safe array
Variant or safe array index out of bounds
'%s' is not a valid GUID value
Invalid argument to date encode
Out of memory
I/O error %d
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow

Version Info

TLS Callbacks

StartAddressOfRawData 0x506000
EndAddressOfRawData 0x50603c
AddressOfIndex 0x4f2a44
AddressOfCallbacks 0x507010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Could not read the name of the DLL to be delay-loaded! [*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0! [!] Error: Yara error: ERROR_COULD_NOT_MAP_FILE