f0a97fe42f7003dc6dcf4251c12223dd

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2018-Sep-01 22:59:28
Detected languages Chinese - PRC
English - United States
Debug artifacts c:\x64_dbg\bin\x96dbg.pdb
FileDescription x64dbg
FileVersion 0.0.2.5
LegalCopyright x64dbg.com
ProductName x64dbg
ProductVersion 0.0.2.5

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to debugging or reversing tools:
  • x32dbg.exe
  • x64dbg.exe
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
Can access the registry:
  • RegSetValueExW
  • RegOpenKeyExW
  • RegCreateKeyW
  • RegCloseKey
Possibly launches other programs:
  • ShellExecuteW
Manipulates other processes:
  • OpenProcess
Info The PE is digitally signed. Signer: Open Source Developer
Issuer: Certum Code Signing CA SHA2
Safe VirusTotal score: 0/67 (Scanned on 2018-09-08 13:33:19) All the AVs think this file is safe.

Hashes

MD5 f0a97fe42f7003dc6dcf4251c12223dd
SHA1 bd7525f3a09a281a63c014655f2f62d7d8348d6e
SHA256 7b49101953d1b723c416db5b8ffd9c77163320fda71c1a57215d6be80bcb3f7e
SHA3 54a6724aa6c2fe65188ae197309daf93391cb314e2de2548741a6cd58cdb2af5
SSDeep 3072:3RY3xBpc7dWIZ+2CkDXk7vNsIo4iFkiZgumU:BYrpUdWQB0zN1ixp
Imports Hash e465ad751fee704da50463c021a1db8d

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2018-Sep-01 22:59:28
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 12.0
SizeOfCode 0x11600
SizeOfInitializedData 0x15200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000061E2 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x13000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.1
ImageVersion 0.0
SubsystemVersion 5.1
Win32VersionValue 0
SizeOfImage 0x2b000
SizeOfHeaders 0x400
Checksum 0x31f9a
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 9b0f5e2fa5acea52cde99e53151c7471
SHA1 94e3f8db41f62aacd4dff348e6288a9b5eb1b293
SHA256 3ca1ced51bde729eb3cbf56d1868d52bc3b623d2e786933799f4b831f060c54d
SHA3 8adec75b7f96ba99ee17b08b1b3c4e215f1892b11d768a020895109a14588913
VirtualSize 0x1152b
VirtualAddress 0x1000
SizeOfRawData 0x11600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.66314

.rdata

MD5 f5008db4bfc9b772bef41c2a5322653e
SHA1 d34af460052886e45ed21d3fa2a1d93d90cc3ead
SHA256 1668e5c3e9748324f38b22d9f7e3c292a0f5acec24f18158a9b740c65130f692
SHA3 9587c18a3b95c3a250d33488e20d03d9c0faf7b7285e74b76ae1ba2ede091c7e
VirtualSize 0x7062
VirtualAddress 0x13000
SizeOfRawData 0x7200
PointerToRawData 0x11a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.6912

.data

MD5 c317e6f07035d4611d5ca59b1c7796c6
SHA1 9b4fd3f9f731c84af23dbf22f67d937d0b2f867f
SHA256 63e244b832e7fc1ebd1515dc58625353a77811805d241e07136fb36fcdf07fd9
SHA3 8d9059986905c75b0938ad2d2dcc25f32ef1c510cc396eaa5c3ec710cb8c8c62
VirtualSize 0x40a0
VirtualAddress 0x1b000
SizeOfRawData 0x1400
PointerToRawData 0x18c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.69925

.rsrc

MD5 f5be376837746275b0ee3f00d4b492cf
SHA1 d27d984b2dc0c65ff09f47c3cc7fbcdbf8d73ade
SHA256 d04f56b6ae335811f4bafa7a03fd6aa5a813bcb78e857e2870c72ff8f808de0c
SHA3 4e5d99f6c188cc2759b43322c0ed7cdb4fb920319b38d599b40e7166fa12c8ef
VirtualSize 0x86a0
VirtualAddress 0x20000
SizeOfRawData 0x8800
PointerToRawData 0x1a000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.92084

.reloc

MD5 33636775cdd00d1eea2b8f3ebb5a3a09
SHA1 665a682ffbd8f4f0ec7d3455fa2912805eec5c38
SHA256 9a562c5c42eb49cb26cd3ab6f276516cbd7009b4a598c57e7ab87966f0560556
SHA3 43e938cec0623d9d05d121fe581dacfd8e841b6ff99910aa9ed61100a27c3d2f
VirtualSize 0x14c4
VirtualAddress 0x29000
SizeOfRawData 0x1600
PointerToRawData 0x22800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.41651

Imports

SHLWAPI.dll PathIsRelativeW
PathRemoveFileSpecW
PathAppendW
KERNEL32.dll WriteFile
CloseHandle
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
GetModuleFileNameW
GetModuleHandleW
GetCommandLineW
OutputDebugStringW
GetPrivateProfileStringW
WritePrivateProfileStringW
GetCurrentDirectoryW
CreateFileW
InitializeCriticalSectionAndSpinCount
GetVersionExW
IsWow64Process
GetConsoleMode
GetConsoleCP
OpenProcess
GetCPInfo
GetOEMCP
GetACP
IsValidCodePage
LoadLibraryExW
LeaveCriticalSection
GetFileAttributesW
GetCurrentProcess
LocalFree
GetProcAddress
SetFilePointerEx
SetStdHandle
WriteConsoleW
EnterCriticalSection
LCMapStringW
FreeEnvironmentStringsW
HeapReAlloc
RtlUnwind
EncodePointer
DecodePointer
IsDebuggerPresent
IsProcessorFeaturePresent
RaiseException
FlushFileBuffers
GetCommandLineA
GetLastError
HeapFree
HeapAlloc
ExitProcess
GetModuleHandleExW
MultiByteToWideChar
WideCharToMultiByte
HeapSize
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
Sleep
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetCurrentThreadId
GetStringTypeW
GetProcessHeap
GetStdHandle
GetFileType
DeleteCriticalSection
GetModuleFileNameA
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
USER32.dll LoadStringW
MessageBoxW
EnableWindow
SetDlgItemTextW
GetDlgItem
EndDialog
DialogBoxParamW
SendMessageW
wsprintfW
LoadIconW
COMDLG32.dll GetOpenFileNameW
ADVAPI32.dll RegSetValueExW
RegOpenKeyExW
RegCreateKeyW
RegCloseKey
SHELL32.dll CommandLineToArgvW
SHGetSpecialFolderPathW
ShellExecuteW
SHChangeNotify
ole32.dll CoCreateInstance
CoInitialize
OLEAUT32.dll #6
#2
COMCTL32.dll #17

Delayed Imports

105

Type AFX_DIALOG_LAYOUT
Language UNKNOWN
Codepage UNKNOWN
Size 0x2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 c4103f122d27677c9db144cae1394a66
SHA1 1489f923c4dca729178b3e3233458550d8dddf29
SHA256 96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
SHA3 762ba6a3d9312bf3e6dc71e74f34208e889fc44e6ff400724deecfeda7d5b3ce

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x7a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.8611
Detected Filetype PNG graphic file
MD5 c0562ff6b55e75ed332044ed4b2dd52f
SHA1 c87a5f9fdf08e672701e5be9af60b878d424e117
SHA256 7fca88d8d57369f872794f2fd38f7124006040b4f360e590a85ea7204822bd16
SHA3 b093d896de0a946570948954b6a61314cc65c1838bbdf7afec343100ceb026dc

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x1014
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.91751
Detected Filetype PNG graphic file
MD5 b7a407b4b465b48049a4e3a94e8f5d8e
SHA1 84541115e8ab4fe358fd73c38b598b020fd85028
SHA256 9a143ce50aa6804fdcbdc459cb851394d29d790ea7d6fbc41d92657a5d1f3e76
SHA3 f54f24420d45c4c60e0272443e51a4cfac0d6999abb2513b75120044d2e8e349

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2108
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.92777
Detected Filetype PNG graphic file
MD5 2569dee72c4f22864a57c947e674fb91
SHA1 a323b4255c2bd997deadcb08f077b78de29c7a4f
SHA256 2620e7b24f63f53e56a163c7a6a757269d51c228e57f8243f965c9aaa994214e
SHA3 19ee3e3d3ad2d6a697211f6fe23d4a5cdb5c1418aaf1acf454448b68a5dc14f4

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38484
MD5 74e6d0432464d8c7059d98097fad4482
SHA1 c7ee2526b3be1f6705aee814b3657b83e64a4fbf
SHA256 a532201b3469e8f6d1dc8e440f353f4177f4046489560e38ad4a36339662a778
SHA3 d674b2829efe463c4f59b396e00e97567c112f0e81a5944e4dc9f72867a9d77c

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.24325
MD5 17cbeea315688bd09bc4c731b42e4bab
SHA1 b0b7a99b45e1f5325f513f39723b2e9c7f01779d
SHA256 06153d5e78263336d76c5bd53909fd55e192b63c26c36638bc28bf5776f6851c
SHA3 9dedc980eeb70e00ac4f915cda3fe97e413869f4293cb4821f023c64ba8dacb5

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45799
MD5 8736ed755dba51e0f71bf411619f8351
SHA1 f12fcdf88b276f8a3a02875899f42d2842c93329
SHA256 39637fb30a3315c10729511332070287c0e231e4b3fb16ec95166ad975e38cb4
SHA3 4e7ff4f86824ad0709295e643935692631f7e8a01e4586bceec486e67f66921c

105 (#2)

Type RT_DIALOG
Language UNKNOWN
Codepage UNKNOWN
Size 0xd2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.97172
MD5 092af784b79ede28ec517d032223dbe6
SHA1 ed48f128ed676e2716a70463f8a80702b0112c40
SHA256 5ad20688b035a2c92436bbf7b69e02532de6bdf2413e41593669023bd7070363
SHA3 10e061149cb1cde5526184750d1437e3f7194850c65e45d12c4a987b87641a3b

7

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x15a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11878
MD5 fd8107e7383ccd4edccc256285ce4819
SHA1 007e888133eb54cf00300fb69101cb3e95da3e36
SHA256 ebe72363c83dfc291f354a85eabceb75c0318e8cccdc8f460c1f2ca760063f63
SHA3 e095505391c820c9949261469fc01e1afdfec93017db05faa90cb74d2f7f3351

7 (#2)

Type RT_STRING
Language Chinese - PRC
Codepage UNKNOWN
Size 0x94
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.53266
MD5 c776fa51af46e1e9e451ebc88782b8dd
SHA1 8b32783bd0cca7ffc911d16138da68257601339f
SHA256 e8c99bf0ee2f90a4b44b5b81a5452b40e3651676704b719a64e6fb7ee42dcedb
SHA3 53ee361ce4c89ac58851760ec193446d3eb5826bf19bf225788bae389670be2a

8

Type RT_STRING
Language English - United States
Codepage UNKNOWN
Size 0x2de
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.39734
MD5 2d8077979fa66ea3bc70a72271208ae2
SHA1 4fe718c08c14ba03a1bcd97fe05d63f9672835ae
SHA256 8c5d8e43a89e7c53be8ec8b68983446e9bd8ecd92c0c7d665bf48d571989458a
SHA3 17e2b16c67a135b9a7db79302bc0744bf9fa85758138011313873b7c2e023bba

8 (#2)

Type RT_STRING
Language Chinese - PRC
Codepage UNKNOWN
Size 0x1b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.47046
MD5 95c94c250b76b7d6c10bf22a805b1552
SHA1 948f22dc4a4fd9cc82d2377b98156f4ad957d909
SHA256 00fdf1f6d3638f95260970e00a02d97a0111f8012c4cede5c0c91aa0c69a1541
SHA3 5d5f168068a58f374aa0888c1a1054a22399aff7929b0d1f86ce8f5f888e2bab

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.75765
Detected Filetype Icon file
MD5 66db78db1c920cd3c3eec8f10d7fd806
SHA1 00db958068360a5510a3cad21d4965445ac61f09
SHA256 539a0bd51e49032f04a57d1db4db480909745913be546f9d0cf822e72e68c6d3
SHA3 704e02b5666644022b89f8270859693ec199e05780eb664ffb3ada44defc4be2

1 (#2)

Type RT_VERSION
Language UNKNOWN
Codepage UNKNOWN
Size 0x1e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.26343
MD5 6938f27e6eb59c9fe557554de80a88a8
SHA1 f011b4a0881bf1f96ccdab5575cfae6e9a1ed67b
SHA256 9f065038a0c220add773b2803b4bdd57ba6c4f6ba53872b080955f854348ad3c
SHA3 3388ffa7e8a1404c66911f50f0b4926d8cec95754e5d98cd7087da8aa21e00ae

1 (#3)

Type RT_MANIFEST
Language UNKNOWN
Codepage UNKNOWN
Size 0x5e1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.14646
MD5 93ec22e91389442a4fd271901050ea03
SHA1 3a91e978223cd6373fd54fb938638fdd41bb6258
SHA256 e5bf19e4cb90f0e5ea96d8a53ef47c98610bf1f61756a7e1851dac9462fc8e6e
SHA3 d760cfbf75ad8c67fcef67e4b7597c314fb5863ee2426ed95a2ec1da13459797

String Table contents

Setup
Error
Error getting module path!
Question
Do you want to register a shell extension?
Do you want to create Desktop Shortcuts?
Done!
New configuration written!
安装
错误
获取模块路径时出错!
温馨提示
您想要为调试器注册右键菜单吗?
您想要创建桌面快捷方式吗?
完成!
新的配置已经写入!
Path to x32dbg not specified in launcher configuration...
Path to x64dbg not specified in launcher configuration...
Invalid PE File!
File not found or in use!
A Debugger for the future!
Running as Admin?
RegCreateKey failed!
RegSetValueEx failed!
RegOpenKeyEx Failed!
BridgeInit Error
Debug with x64dbg
Do you want to register the database icon?
BridgeStart Error
启动器的配置文件中没有指定x32dbg的路径...
启动器的配置文件中没有指定x64dbg的路径...
无效的PE文件!
文件没找到,或者已被占用!
一个面向未来的调试器!
您确定以管理员权限运行本程序了吗?
RegCreateKey 失败!
RegSetValueEx 失败!
RegOpenKeyEx 失败!
BridgeInit 发生错误
用x64dbg调试
您想为调试数据库设置图标吗?
BridgeStart 发生错误

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.2.5
ProductVersion 0.0.2.5
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_UNKNOWN
Language English - United States
FileDescription x64dbg
FileVersion (#2) 0.0.2.5
LegalCopyright x64dbg.com
ProductName x64dbg
ProductVersion (#2) 0.0.2.5
Resource LangID UNKNOWN

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2018-Sep-01 22:59:28
Version 0.0
SizeofData 50
AddressOfRawData 0x18a70
PointerToRawData 0x17470
Referenced File c:\x64_dbg\bin\x96dbg.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2018-Sep-01 22:59:28
Version 0.0
SizeofData 20
AddressOfRawData 0x18aa4
PointerToRawData 0x174a4

TLS Callbacks

Load Configuration

Size 0x48
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x41b190
SEHandlerTable 0x418e00
SEHandlerCount 14

RICH Header

XOR Key 0x1bf6b60d
Unmarked objects 0
ASM objects (VS2013 build 21005) 21
C objects (VS2013 build 21005) 122
C++ objects (VS2013 build 21005) 48
C objects (VS2008 SP1 build 30729) 3
Imports (VS2008 SP1 build 30729) 19
Total imports 115
C++ objects (VS2013 UPD5 build 40629) 1
Resource objects (VS2013 build 21005) 1
151 2
Linker (VS2013 UPD5 build 40629) 1

Errors

<-- -->