f065c33c0754ff6983cfee8c7f2b4b9b

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2008-Nov-26 04:48:26
Detected languages Chinese - Taiwan
CompanyName
FileDescription
FileVersion 1.0.1.0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion 1.0.0.0
Comments

Plugin Output

Info Matching compiler(s): Borland C++ DLL
MASM/TASM - sig1(h)
Borland C++ for Win32 1999
Suspicious The PE is possibly packed. Section .text is both writable and executable.
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
  • LoadLibraryExA
Functions which can be used for anti-debugging purposes:
  • FindWindowA
Code injection capabilities (PowerLoader):
  • FindWindowA
  • GetWindowLongA
Can access the registry:
  • RegCloseKey
  • RegOpenKeyExA
  • RegQueryValueExA
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetForegroundWindow
  • MapVirtualKeyA
Can take screenshots:
  • BitBlt
  • CreateCompatibleDC
  • FindWindowA
  • GetDC
  • GetDCEx
Reads the contents of the clipboard:
  • GetClipboardData
Info The PE's resources present abnormal characteristics. The binary may have been compiled on a machine in the UTC+8 timezone.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 f065c33c0754ff6983cfee8c7f2b4b9b
SHA1 e9a58357d3804b42cdcaa66af1d6ab75ce6b7ec5
SHA256 8ecc2eee4c6f21ec624962acc8491fffc572c107c3772407bdb2d111415ac448
SHA3 8e0e51c1858a5a1021c4298962587123d9e0c38e1e7a36b2d0ea5d10b115b90f
SSDeep 12288:LpVMAcmK9DB9gHNkDsia2v2IIIzpwqULQ9kf/z7LOcAjx9oBtJ6:9Pq9d9gtkoi39+qUQr5m
Imports Hash 757ff57772b9c9dc4a65065d10065545

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x200

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 8
TimeDateStamp 2008-Nov-26 04:48:26
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 5.0
SizeOfCode 0x9a000
SizeOfInitializedData 0xb000
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000013B4 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x9b000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 0.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0xcc000
SizeOfHeaders 0x600
Checksum 0xbcea1
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
SizeofStackReserve 0x100000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 90e1da7c0ed31b17e604febc3f117949
SHA1 4b2769a73977d8938e7496c0cdd05eab81c493e6
SHA256 2da078fef95286e76394e99d8a723dcfe02aa7e10d924da9d60ab767e265ea95
SHA3 fed180495dc7c3924923d598baeb8a918f5ddf18360118cbde9220c76896b67a
VirtualSize 0x9a000
VirtualAddress 0x1000
SizeOfRawData 0x99c00
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.53497

.data

MD5 939525b89c505b009ed1d45a27e13949
SHA1 f02e9298f7f76dfda3f709ea0b3fc25cc77e3580
SHA256 e6d15b8a3d8941121914361dac126596d98486980f72ccde67cbea4e271e8856
SHA3 54810234e18bd0524a5751bb6204d04a7c11380362329521eb292b52cdea221c
VirtualSize 0xb000
VirtualAddress 0x9b000
SizeOfRawData 0x6400
PointerToRawData 0x9a200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.85742

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x1000
VirtualAddress 0xa6000
SizeOfRawData 0x200
PointerToRawData 0xa0600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rdata

MD5 2186d9648a4b3654876554cf380db94c
SHA1 f10d12f9483bd90f3b677d4a9806d2420a8651be
SHA256 489a7117a3cae0062a5501c0329bfc767fc731dbb842a2e51350f09fcb3f26cf
SHA3 10a3a276b434f56da3863575211e9a771bdb5b0e4c6006d3516c683100232c30
VirtualSize 0x1000
VirtualAddress 0xa7000
SizeOfRawData 0x200
PointerToRawData 0xa0800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 0.204488

.idata

MD5 aa297c2eefe660a03e7ca443d4209eeb
SHA1 18a73ae661fd48ae73e69e2f3c0c2e641a0adf5e
SHA256 c8999a52799816946cd5401c824a3d81a874b0891ffe926fa3f7b0ed5c787714
SHA3 a79ddabcfc1432a85ec4b3006ea8b0dcb770359bdc92194e2812f783d1f06954
VirtualSize 0x3000
VirtualAddress 0xa8000
SizeOfRawData 0x2400
PointerToRawData 0xa0a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.21878

.edata

MD5 7eba90f0e83e180cae43ee7077da496f
SHA1 90031ea77a64b71fc3a9d1369a30e7c4e7bb8512
SHA256 e2a31d573b13148bca14c0ba042b5c2626a6c40b3904ca0da907c8327830781f
SHA3 da0bfe3b4027ebabc8ab29d641133140bb5d9e2829717a434e7667e257936bf3
VirtualSize 0x1000
VirtualAddress 0xab000
SizeOfRawData 0x200
PointerToRawData 0xa2e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.10219

.rsrc

MD5 c646a3071ec4890bb3d5fec465699ee3
SHA1 d3d82bfe4f99617fed5c006521f76cb0b9865359
SHA256 b2e8b1d1662381bbfe5548d5f19571adf93f174147d219a8e0b80ad2a3be474a
SHA3 6f0838f6b2de2618173ff6e26f81408c879244ccb230a56a8069be331c5b0525
VirtualSize 0xb000
VirtualAddress 0xac000
SizeOfRawData 0xa400
PointerToRawData 0xa3000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.09729

.reloc

MD5 69d7a0c3f4f42c6d610e3f1e8e10b389
SHA1 7226ffe658c3f998cee58600f2b0d0851b414173
SHA256 0e6ef79b188ba750daf30ea78e40a2110d7ef2aba1924c8cd85d03184e625558
SHA3 7349d58f0bb193208d51518608a90b556301b0fdf3908a7fde9eb6b99fc82d72
VirtualSize 0x14871
VirtualAddress 0xb7000
SizeOfRawData 0xb200
PointerToRawData 0xad400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_SHARED
Entropy 6.63753

Imports

ADVAPI32.DLL RegCloseKey
RegOpenKeyExA
RegQueryValueExA
KERNEL32.DLL CloseHandle
CompareStringA
CreateEventA
CreateFileA
CreateThread
DeleteCriticalSection
EnterCriticalSection
EnumCalendarInfoA
ExitProcess
FindClose
FindFirstFileA
FindResourceA
FormatMessageA
FreeLibrary
FreeResource
GetACP
GetCPInfo
GetCommandLineA
GetCurrentProcessId
GetCurrentThreadId
GetDateFormatA
GetDiskFreeSpaceA
GetEnvironmentStrings
GetFileSize
GetFileType
GetLastError
GetLocalTime
GetLocaleInfoA
GetModuleFileNameA
GetModuleHandleA
GetOEMCP
GetPrivateProfileStringA
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetStdHandle
GetStringTypeExA
GetStringTypeW
GetSystemInfo
GetThreadLocale
GetTickCount
GetVersion
GetVersionExA
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFree
GlobalHandle
GlobalLock
GlobalReAlloc
GlobalUnlock
HeapAlloc
HeapFree
InitializeCriticalSection
InterlockedDecrement
InterlockedIncrement
LeaveCriticalSection
LoadLibraryA
LoadLibraryExA
LoadResource
LocalAlloc
LocalFree
LockResource
MulDiv
MultiByteToWideChar
RaiseException
ReadFile
ResetEvent
RtlUnwind
SetConsoleCtrlHandler
SetEndOfFile
SetErrorMode
SetEvent
SetFilePointer
SetHandleCount
SetLastError
SetThreadLocale
SizeofResource
Sleep
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
VirtualQuery
WaitForSingleObject
WideCharToMultiByte
WriteFile
WritePrivateProfileStringA
lstrcpyA
lstrcpynA
lstrlenA
COMCTL32.DLL ImageList_Add
ImageList_BeginDrag
ImageList_Create
ImageList_Destroy
ImageList_DragEnter
ImageList_DragLeave
ImageList_DragMove
ImageList_DragShowNolock
ImageList_Draw
ImageList_DrawEx
ImageList_EndDrag
ImageList_GetBkColor
ImageList_GetDragImage
ImageList_GetIconSize
ImageList_GetImageCount
ImageList_Read
ImageList_Remove
ImageList_ReplaceIcon
ImageList_SetBkColor
ImageList_SetDragCursorImage
ImageList_SetIconSize
ImageList_Write
COMDLG32.DLL GetOpenFileNameA
GDI32.DLL BitBlt
CopyEnhMetaFileA
CreateBitmap
CreateBrushIndirect
CreateCompatibleBitmap
CreateCompatibleDC
CreateDIBSection
CreateDIBitmap
CreateFontIndirectA
CreateHalftonePalette
CreatePalette
CreatePenIndirect
CreateSolidBrush
DeleteDC
DeleteEnhMetaFile
DeleteObject
ExcludeClipRect
GetBitmapBits
GetBrushOrgEx
GetClipBox
GetCurrentPositionEx
GetDCOrgEx
GetDIBColorTable
GetDIBits
GetDeviceCaps
GetEnhMetaFileBits
GetEnhMetaFileHeader
GetEnhMetaFilePaletteEntries
GetObjectA
GetPaletteEntries
GetPixel
GetStockObject
GetSystemPaletteEntries
GetTextExtentPoint32A
GetTextMetricsA
GetWinMetaFileBits
GetWindowOrgEx
IntersectClipRect
LineTo
MaskBlt
MoveToEx
PatBlt
PlayEnhMetaFile
RealizePalette
RectVisible
Rectangle
RestoreDC
SaveDC
SelectObject
SelectPalette
SetBkColor
SetBkMode
SetBrushOrgEx
SetDIBColorTable
SetEnhMetaFileBits
SetPixel
SetROP2
SetStretchBltMode
SetTextColor
SetViewportOrgEx
SetWinMetaFileBits
SetWindowOrgEx
StretchBlt
UnrealizeObject
USER32.DLL ActivateKeyboardLayout
AdjustWindowRectEx
BeginPaint
CallNextHookEx
CallWindowProcA
CharLowerA
CharLowerBuffA
CharNextA
CharUpperBuffA
CheckMenuItem
ClientToScreen
CreateIcon
CreateMenu
CreatePopupMenu
CreateWindowExA
DefFrameProcA
DefMDIChildProcA
DefWindowProcA
DeleteMenu
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
DispatchMessageA
DrawEdge
DrawFrameControl
DrawIcon
DrawIconEx
DrawMenuBar
DrawTextA
EnableMenuItem
EnableScrollBar
EnableWindow
EndPaint
EnumThreadWindows
EnumWindows
EqualRect
FillRect
FindWindowA
FrameRect
GetActiveWindow
GetCapture
GetClassInfoA
GetClassNameA
GetClientRect
GetClipboardData
GetCursor
GetCursorPos
GetDC
GetDCEx
GetDesktopWindow
GetDlgItem
GetFocus
GetForegroundWindow
GetIconInfo
GetKeyNameTextA
GetKeyState
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardState
GetKeyboardType
GetLastActivePopup
GetMenu
GetMenuItemCount
GetMenuItemID
GetMenuItemInfoA
GetMenuState
GetMenuStringA
GetParent
GetPropA
GetScrollInfo
GetScrollPos
GetScrollRange
GetSubMenu
GetSystemMenu
GetSystemMetrics
GetTopWindow
GetWindow
GetWindowDC
GetWindowLongA
GetWindowPlacement
GetWindowRect
GetWindowTextA
GetWindowThreadProcessId
InflateRect
InsertMenuA
InsertMenuItemA
IntersectRect
InvalidateRect
IsChild
IsDialogMessageA
IsIconic
IsRectEmpty
IsWindow
IsWindowEnabled
IsWindowVisible
IsZoomed
KillTimer
LoadBitmapA
LoadCursorA
LoadIconA
LoadKeyboardLayoutA
LoadStringA
MapVirtualKeyA
MapWindowPoints
MessageBoxA
OemToCharA
OffsetRect
PeekMessageA
PostMessageA
PostQuitMessage
PtInRect
RedrawWindow
RegisterClassA
RegisterClipboardFormatA
RegisterWindowMessageA
ReleaseCapture
ReleaseDC
RemoveMenu
RemovePropA
ScreenToClient
ScrollWindow
SendMessageA
SetActiveWindow
SetCapture
SetClassLongA
SetCursor
SetFocus
SetForegroundWindow
SetMenu
SetMenuItemInfoA
SetPropA
SetRect
SetScrollInfo
SetScrollPos
SetScrollRange
SetTimer
SetWindowLongA
SetWindowPlacement
SetWindowPos
SetWindowTextA
SetWindowsHookExA
ShowCursor
ShowOwnedPopups
ShowScrollBar
ShowWindow
SystemParametersInfoA
TrackPopupMenu
TranslateMDISysAccel
TranslateMessage
UnhookWindowsHookEx
UnregisterClassA
UpdateWindow
WaitMessage
WinHelpA
WindowFromPoint
wsprintfA
GetSysColor
OLE32.DLL CoCreateInstance
CoGetMalloc
CoInitialize
CoUninitialize
OLEAUT32.DLL GetErrorInfo
SafeArrayAccessData
SafeArrayCreate
SafeArrayGetElement
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayPtrOfIndex
SafeArrayPutElement
SafeArrayRedim
SafeArrayUnaccessData
SysAllocStringLen
SysFreeString
SysReAllocStringLen
SysStringLen
VariantChangeType
VariantClear
VariantCopy
VariantCopyInd
VariantInit

Delayed Imports

__GetExceptDLLinfo

Ordinal 1
Address 0x140d

@@Main@Initialize

Ordinal 2
Address 0x3688

@@Main@Finalize

Ordinal 3
Address 0x3698

___CPPdebugHook

Ordinal 4
Address 0x9b098

_fmMain

Ordinal 5
Address 0xa12ac

1

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.6633
MD5 ff4e5862f26ea666373e5fab2bddfb11
SHA1 cfa13c0ab30f1bbd566900dee3631902f9b6451c
SHA256 b8e6fc93d423931acbddae3c27dd3c4eb2a394005d746951a971cb700e0ee510
SHA3 91dae12a9f43c5443e0661091a336f882fa1482f75fa9a57c9298d1d70c8ae69

2

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.80231
MD5 2e87b3c111e3073a841775c1f8ec5a90
SHA1 20292304fa2ef1bfdc4a1000e90a1c16d4765a96
SHA256 ce19ace18e87b572e6912306776226af5b8e63959c61cde70a8ff05b3bbdcc41
SHA3 9527f09e739c2064835800a7e5c317cb422bdd7237f00fca079a1c62f58a2612

3

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.00046
MD5 a04c3c368cb37c07bd5f63e7e6841ebd
SHA1 699300bceaa1256818c43fecfc8cad93a59156b2
SHA256 ee1c9c194199c320c893b367602ccc7ee7270bd4395d029f727e097634f47f8c
SHA3 58722e3138aad1382e284c1605ecd665ced536de4906749ac8d6e11252cc9558

4

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.56318
MD5 9929115b21c2c59348058d4190392e75
SHA1 626fba1825d572ea441d36363307c9935de3c565
SHA256 9d9edf87ca203ecc60b246cc783d54218dd0ce77d3a025d0bafc580995a4abd8
SHA3 fea156e872544252c625076a6bf3baa733ee5b3d5399716e156734af7a841369

5

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.6949
MD5 f321ad13d1c3f35a05d67773b4bc27d6
SHA1 30aded8525417e2531d5eb88bf2f868172945baa
SHA256 99676c52310db365580965ea646ece86c62951bfd97ec0aae9f738a202a90593
SHA3 04c839da98a8c50a36697076af5bc6d527560a69153b2f718f065908fd4fe3ad

6

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.62527
MD5 5ca217e52bdc6f23b43c7b6a23171e6e
SHA1 d99dc22ec1b655a42c475431cc3259742d0957a4
SHA256 11726dcf1eebe23a1df5eb0ee2af39196b702eddd69083d646e4475335130b28
SHA3 b358d8a5b0f400dd2671956ec45486ae1035556837b5289df5f418fe69348b3f

7

Type RT_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x134
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.91604
MD5 6be7031995bb891cb8a787b9052f6069
SHA1 487eb59fd083cf4df02ce59d9b079755077ba1b5
SHA256 6f938aab0a03120de4ef8b27aff6ba5146226c92a056a6f04e5ec8d513ce5f9d
SHA3 0f1c6c0378a3646c9fbf3678bbeeccf929d32192f02d1ea9d6ba0be5c769e6ab

1 (#2)

Type RT_ICON
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.94548
MD5 9ee3922f8b47b47b1cd9f252b287b900
SHA1 f1252c19e03b10b23405e1b83720855317dd13b8
SHA256 88dc7df3afd22c762f6a672a00eb5a0ebe75e402e8fa1ed85740553abdd17bd6
SHA3 3349d21449b58de5d7fe29df243abdebfbd3b6e12b350b9b35424f155b25761e

2 (#2)

Type RT_ICON
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x128
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.34882
MD5 f3090432686ab669c5dae361870dda79
SHA1 e409e8ad3004adc78a37abcd68268c7a9c18029e
SHA256 f350433ed4bb69d248dfeb0db6a724e13f4b5f9dc21025398062b09b39e0f18e
SHA3 f8695f311c2ad313318c444562e29f6ea28e532342730d1e120e6cb8b4b99617

4079

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x174
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.96008
MD5 9e8ce82d48c7bd4ee69027a516821995
SHA1 4751f247bfb107f6e8163af12875bfa699f9e986
SHA256 42ef72b31167035fdd74b12587a46f4f66cc5c3f60a5f7d80e6b20676b3fb4ff
SHA3 e9377552adc8640bd7a2249ea8c671b97ded2ce01b4bb6214eb28fd3cab31d78

4080

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xfc
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.11286
MD5 eb880aefa0cb1cf021d4973eee8e1953
SHA1 decc7e4764d6a7a2ee8b2359ca828fd0043e5929
SHA256 948b6bcd1646bc3daa02b8c1bba4d7c5957a02637ef3280559c5cdacd2b5f825
SHA3 3e6d8f89d8c4306b8efbf91f5e6ebff711be1e908ce435a42eafd7c5e9456c5a

4081

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.14262
MD5 888a95a2b11317243e7230f7adc77df5
SHA1 0ced44944fcf5aab03d1ba4584b6be5be41d21c4
SHA256 ab72db01bda34e128d7d87013aefc5e0243ebb77f4c6027fe76de5f10823efee
SHA3 5d400d92b92ddea97d18d7149c4516e6fe18806d47cf748d5e7c22a1942053e8

4082

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x358
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.23446
MD5 632ba3db19095c68958d9abcb468fafd
SHA1 341a718e2c97590096e4592409d892002a604230
SHA256 2cff0fbb9819c6fab29adb1d821d10a80ee1caa660fca9b0d5cbbd68230566ce
SHA3 2418bc6c9138d1dca306c800fb3ebb25d7b281641415b1636ed492f84163b13c

4083

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3e0
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.19787
MD5 6face4eaa3c582c6151bd62b47dae721
SHA1 852605febb873ebf698ddc9f4261a4b273155a71
SHA256 315219efb389d3c799a366c2237c23226609fa152403c858df7ae1219b73dc51
SHA3 25e2767f7f32947c5123924cdc516501b1ccb4cf1fea8b0e1a7b3748e9ba111f

4084

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x110
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.03211
MD5 45d1492c862770a34630d5a18517b0b8
SHA1 813ff22e48365341f2d27bd3dc98a9658f7b744b
SHA256 5a6d7958afef4479418df82ffdc4bccd49288eeb0048d99a9a254818bc559518
SHA3 bbbc70b5b856084c76ff02f7555795e09f4a96f188007c2e9317739b7f3a142e

4085

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0xe4
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.99785
MD5 65b3a9f9ed7e68e403d141705bdd55e0
SHA1 502261a54bdcbc522e55d57040fdc35884861db1
SHA256 d1e4f67dfdac88a2667aef19c9e56fc6d0deaca637f10b941f1724a4466f9225
SHA3 eb75571e9fcd0bca2e4b6e55ec828d3db73d3da5d8118420670601e1acde9ba5

4086

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x280
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.22658
MD5 8a2e5df80087eeba1803515005933568
SHA1 9885a45a7cba0bafd5a6de364dec48cae5a9c7cd
SHA256 f2d7c4b1af3cbb835a6b6f2614f3b5893cce2c494df493181fc03e163e508887
SHA3 0ecf13ee4753e51ba76150e1685fac0131f37c692ab9fb6464df029890af3e05

4087

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x454
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.24481
MD5 9d0399cf9748b2f536979c529e4fa810
SHA1 63a82de0f9a4a3a2178cba73c7f44377cf9d1e06
SHA256 2cb02af456213bafcb49b0b5fdb731767dfb8725ab2287f190f8cbc610f09a60
SHA3 d8db31c72028b773ecf206b455b53b01514221bdb07e54db348f915c14bd6d79

4088

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x338
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.25645
MD5 d5062e8fadf5ed87a13b390df0f44786
SHA1 f3b84e1fed2de2ea1ee227b7b841f8321c47638c
SHA256 7e6caf1be15a2b5ecfb1432c95c16ac53d1416b923252730b774c9765167311b
SHA3 ca40b904469d0989b653c6f6567248c9074026bae9f2766b2115496f433f22fb

4089

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x310
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.18123
MD5 a84e3e9621d3c82f788db09a1d24c9f5
SHA1 62ea1281da14e4fb6738d8c47fad2e221ec3b0c3
SHA256 c15962d437daa555187d94d59118522d721366c2a4d72192a537d188b87f8b9b
SHA3 5f56e0a68c16ec3fe3f8c25596c78a9eae8b30f2c2a5f28b4e3ecc0567cd3f83

4090

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3e8
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.1645
MD5 fd01c686e968f36c88ee54d7789aea34
SHA1 10b4801b45cefa4a0aaf8b2654d046d38a9b8771
SHA256 00aeef5adc32196de01f1a46ec1d956d88aac0ea9df5dc1de23dfe96c76012f0
SHA3 7e5964ba5a980336a3331df407d1377253009cb659d7cb02db1c343bc3ae953f

4091

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3a4
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.214
MD5 d1eba00430f80b948d349acd3bcd2987
SHA1 c7dd4e87ded62beb6f3e85d5cee7c24b85fdfe10
SHA256 7b503079c46deaef667ba9634fb139347cf0344993dfe9edd52e1bcde756bf9f
SHA3 7115f98e5a15b7de19ea25507b9ef20ad6bac012b48d7f36e0559443b1b5b4f5

4092

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x40c
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.21869
MD5 c0fc3d5b8e893ac81e620e8be906448e
SHA1 799912356bf24b3140b6b9d29249ca6a4632be5a
SHA256 f1cbfb620a3c3fad939b3825c04037a3b0e643dbc578f8bbe200d311aacb9f57
SHA3 6d621c47762aff42ddeffd579a3834b14750c496e2976fcb3003885d87a9cc3a

4093

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x3d0
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.26769
MD5 ca46e0f0f20ae864895c6d36b5bf8ddd
SHA1 5ef7c58d17d2964e60559013f6c0b9b15dc2de7d
SHA256 62ae424ff48c46a18ea0215b6447c872bae976fd174f4d1a10b128a1855fe035
SHA3 d98d1d6a0ee41804853f4bb2e2c81f40752ae3c14ba0e6b38b87d6f46c947526

4094

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x408
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.15329
MD5 7ac8083d103547c68c86b9ba7ad00d11
SHA1 f5be13918415b24dcd77b2b0e692b117d309c19e
SHA256 b72f6b6caadb92aad6f1c0503ed2b3a9ac8e104dee0a5c76841ed6cff18b4f0f
SHA3 4664af362018fc942eb0dcbd7f650af7b9321fbf072e91ef5bf835c078da6aeb

4095

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x554
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.17535
MD5 f0becf953f218eab20501c86c40ea12d
SHA1 d1b83bd1aa104d43848d5adb9dadf578ac7b01a6
SHA256 a8fe58f224ba175dbb09fb2a5e43f6e1c171ae0bed350337759d69fa0c9cdcc3
SHA3 34969ade92080ec1d841480e3220065deca2bdc650173831afaffddf94ee6617

4096

Type RT_STRING
Language UNKNOWN
Codepage UNKNOWN
Size 0x56c
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.24793
MD5 2f62c17a780ad569234bed3bc889360f
SHA1 a40a13c089f74fe512dc23ed25ecc1f96f0483ea
SHA256 89395ae2e280c5d24fd826cae075817713b2b82fa0c9162069bbf53e1b2e633d
SHA3 7354abd62ee8ede64931090503728177e73ba0d2c6df7a4f3d7e2f904e0fb3db

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x10
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 4
MD5 d8090aba7197fbf9c7e2631c750965a8
SHA1 04f73efb0801b18f6984b14cd057fb56519cd31b
SHA256 88d14cc6638af8a0836f6d868dfab60df92907a2d7becaefbbd7e007acb75610
SHA3 a5a67ad8166061d38fc75cfb2c227911de631166c6531a6664cd49cfb207e8bb

TFMMAIN

Type RT_RCDATA
Language UNKNOWN
Codepage UNKNOWN
Size 0x52c2
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 5.79298
MD5 d46352fefe916499939d51de4983bc89
SHA1 a1a949e5e89184dbf09dea8f840e3ac02beb4471
SHA256 2ce12799dabfc5c70500cdf0127543ff7579c8c4815bbb8620181bb9e90fbeb4
SHA3 935df1a0b54f1af1fa4a0d5e2ce9e01819772baa6764c78c887cec9e79340ef1

32761

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 1.83876
Detected Filetype Cursor file
MD5 a2baa01ccdea3190e4998a54dbc202a4
SHA1 e8217df98038141ab4e449cb979b1c3bbea12da3
SHA256 c53efa8085835ba129c1909beaff8a67b45f50837707f22dfff0f24d8cd26710
SHA3 8874564c406835306368adf5e869422e1bb97109b97c1499caa8af219990e8dc
Preview

32762

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 1.91924
Detected Filetype Cursor file
MD5 aff0f5e372bd49ceb9f615b9a04c97df
SHA1 e3205724d7ee695f027ab5ea8d8e1a453aaad0dd
SHA256 b07e022f8ef0a8e5fd3f56986b2e5bf06df07054e9ea9177996b0a6c27d74d7c
SHA3 9cb042121a5269b80d18c3c5a94c0e453890686aedade960097752377dfa9712
Preview

32763

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.01924
Detected Filetype Cursor file
MD5 48e064acaba0088aa097b52394887587
SHA1 310b283d52aa218e77c0c08db694c970378b481d
SHA256 43f40dd5140804309a4c901ec3c85b54481316e67a6fe18beb9d5c0ce3a42c3a
SHA3 38753084b0ada40269914e80dbacf7656dc94764048bd5dff649b08b700f3ed5
Preview

32764

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.01924
Detected Filetype Cursor file
MD5 1ae28d964ba1a2b1b73cd813a32d4b40
SHA1 8883cd93b8ef7c15928177de37711f95f9e4cd22
SHA256 ff47a48c11c234903a7d625cb8b62101909f735ad84266c98dd4834549452c39
SHA3 a85dadd416ce2d22aa291c0794c45766a0613b853c6e3b884a2b05fc791427b8
Preview

32765

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.01924
Detected Filetype Cursor file
MD5 0893f6ba80d82936ebe7a8216546cd9a
SHA1 0754cbdf56c53de9ed7fbd47859d20b788c6f056
SHA256 a0adcedb82b57089f64e2857f97cefd6cf25f4d27eefc6648bda83fd5fef66bb
SHA3 ce6148ade08ef9b829f83cb13b4c650d9d4a7012bfd1ab697a7870a05f4104f8
Preview

32766

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.01924
Detected Filetype Cursor file
MD5 dcaa3c032fe97281b125d0d8f677c219
SHA1 58fe36409f932549e2f101515abee7a40cf47b2c
SHA256 6e1e7738a1b6373d8829f817915822ef415a1727bb5bb7cfe809e31b3c143ac5
SHA3 02ef292e1b4a70e439e362af6b4fa213e3816ade45222b78dabab712b6afba54
Preview

32767

Type RT_GROUP_CURSOR
Language UNKNOWN
Codepage UNKNOWN
Size 0x14
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.01924
Detected Filetype Cursor file
MD5 a95c7c78d0a0b30b87e3c4976e473508
SHA1 b19f3999f1b302a2d28977cb18a3416c918d486c
SHA256 326c048595bbc72e3f989cb3b95fbf09dc83739ced3cb13eb6f03336f95d74f1
SHA3 8157b4e6afa7ed2e2ffc174d655bec9fb81db609e4c5864faa5ead931ff60689
Preview

MAINICON

Type RT_GROUP_ICON
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x22
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 2.37086
Detected Filetype Icon file
MD5 d59e0d372ea5fd8c1f4de744376a6af4
SHA1 6883ce60e71a83424db0b41d0ab6bf61080e3de2
SHA256 b10e28a32eddb2ab20a46ceae59d9c0786911eb20f0c8dd2a28421f226ea2b8b
SHA3 5e39df982879204dd9f129a37d1e1c2ff906e88de9ae01b4418db5e8455e7ae1

1 (#3)

Type RT_VERSION
Language Chinese - Taiwan
Codepage UNKNOWN
Size 0x274
TimeDateStamp 2008-Nov-26 12:48:28
Entropy 3.08127
MD5 59a8fdde52df1f1fa46cefd9a38f55f6
SHA1 90e23889863e735915d21e3acde8a0877c59ebee
SHA256 9083ae2bf17406d33f95cb067b38f56f5f3250168f658ea38dc4c0343cb0c59b
SHA3 004f60e775be7102fc8fc46c434fccdde41ed68dab1479b2777172e2f7487d7f

String Table contents

Menu '%s' is already being used by another form
Docked control must have a name
Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
Enter
Space
PgUp
PgDn
End
Home
Left
Up
Right
Down
Ins
Del
Shift+
Ctrl+
Alt+
Clipboard does not support Icons
Information
Confirm
&Yes
&No
OK
Cancel
&Help
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Tab
Esc
Cannot change Visible in OnShow or OnHide
Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available
GroupIndex cannot be less than a previous menu item's GroupIndex
Cannot create form. No MDI forms are currently active
A control cannot have itself as its parent
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Icon image is not valid
Metafile is not valid
Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index
Failed to read ImageList data from stream
Failed to write ImageList data to stream
Error creating window device context
Error creating window class
Cannot focus a disabled or invisible window
Control '%s' has no parent window
Cannot hide an MDI Child Form
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Bitmap image is not valid
Aug
Sep
Oct
Nov
Dec
January
February
March
April
May
June
July
August
September
October
November
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s
A call to an OS function failed
Application is not licensed to use this feature
Jan
Feb
Mar
Apr
May
Jun
Jul
Invalid variant operation
Invalid variant operation ($%.8x)
Variant is not an array
Custom variant type (%.4x) is out of range
Custom variant type (%.4x) already used by %s
Custom variant type (%.4x) is not usable
Too many custom variant types have been registered
Invalid NULL variant operation
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
Variant method calls not supported
Read
Write
Format string too long
Error creating variant array
Variant array index out of bounds
Variant array is locked
Invalid variant type conversion
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Stream write error
OLE error %.8x
Method '%s' not supported by automation object
Variant does not reference an automation object
Dispatch methods do not support more than 64 parameters
'%s' is not a valid integer value
'%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid time
'%s' is not a valid date and time
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid property element: %s
Invalid property path
Invalid property type: %s
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Resource %s not found
%s.Seek not implemented
Operation not allowed on sorted list
%s not in a class registration group
Property %s does not exist
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
Can't write to a read-only resource stream
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists
List does not allow duplicates ($0%x)
A component named %s already exists
String list does not allow duplicates
Cannot create file %s
Cannot open file %s
Unable to write to %s
Invalid stream format
''%s'' is not a valid component name
Invalid property value
Unable to load bind parameters
Field '%s' is of an unsupported type
SQL not supported: %s
Execute not supported: %s
Operation not allowed on a unidirectional dataset
Unassigned variant value
Record not found
BCD overflow
%s is not a valid BCD value
Invalid format type for BCD
Could not parse SQL TimeStamp string
Invalid SQL date/time values
Unable to find a Table of Contents
No help found for %s
No context-sensitive help installed
No topic-based help system installed
Field '%s' must have a value
Field '%s' has no dataset
Field '%s' cannot be a calculated or lookup field
Field '%s' cannot be modified
No index for fields '%s'
Index '%s' not found
Circular datalinks are not allowed
Lookup information for field '%s' is incomplete
DataSource cannot be changed
Cannot perform this operation on an open dataset
Dataset not in edit or insert mode
Cannot perform this operation on a closed dataset
Nested dataset must inherit from %s
False
True
Parameter '%s' not found
Invalid FieldKind
Field '%s' is of an unknown type
Field name missing
Duplicate field name '%s'
Field '%s' not found
Cannot access field '%s' as type %s
Invalid value for field '%s'
%g is not a valid value for field '%s'. The allowed range is %g to %g
%s is not a valid value for field '%s'. The allowed range is %s to %s
'%s' is not a valid integer value for field '%s'
'%s' is not a valid boolean value for field '%s'
'%s' is not a valid floating point value for field '%s'
Type mismatch for field '%s', expecting: %s actual: %s
Size mismatch for field '%s', expecting: %d actual: %d
Invalid variant type or size for field '%s'
Value of field '%s' is out of range
Name
Value
Invalid Enum Value
Missing Connection or ConnectionString
Filter property cannot be used for detail tables
Dataset does not support bookmarks, which are required for multi-record data controls
Missing %s property
CommandText does not return a result set
Error creating object. Please verify that the Microsoft Data Access Components 2.1 (or later) have been properly installed
Events are not supported with server side TableDirect cursors
Unsupported field type (%s) in field %s
A connection component is required for async ExecuteOptions
Cannot perform a requery after connection has changed
FilterOptions are not supported
Recordset is not open
Invalid field size

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.0.1.0
ProductVersion 1.0.1.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language Chinese - Taiwan
CompanyName
FileDescription
FileVersion (#2) 1.0.1.0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion (#2) 1.0.0.0
Comments
Resource LangID Chinese - Taiwan

TLS Callbacks

StartAddressOfRawData 0x4a6000
EndAddressOfRawData 0x4a60b4
AddressOfIndex 0x4a1294
AddressOfCallbacks 0x4a7010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

<-- -->