10b2ae7c96d0c0714d52ea6d0e203f269aae652b3109485e2b113a3eecdcbeec

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-May-03 14:45:36
Detected languages English - United States
Comments This installation was built with Inno Setup.
CompanyName Troplo
FileDescription NexusTools for WATCH_DOGS Setup
FileVersion
LegalCopyright
OriginalFileName
ProductName NexusTools for WATCH_DOGS
ProductVersion 1.1.12

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • https://jrsoftware.org
  • jrsoftware.org
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegCloseKey
Possibly launches other programs:
  • CreateProcessW
Memory manipulation functions often used by packers:
  • VirtualProtect
  • VirtualAlloc
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Enumerates local disk drives:
  • GetVolumeInformationW
  • GetDriveTypeW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 11610765 bytes of data starting at offset 0x120a00.
The overlay data has an entropy of 7.99997 and is possibly compressed or encrypted.
Overlay data amounts for 90.7589% of the executable.
Suspicious VirusTotal score: 1/69 (Scanned on 2026-09-22 21:48:04) APEX: Malicious

Hashes

MD5 dd89a8cb81cf5af6c7780800b2c5bb18 🔍
SHA1 33fb8758a977190070d1312808d2e25315ebbff6 🔍
SHA256 10b2ae7c96d0c0714d52ea6d0e203f269aae652b3109485e2b113a3eecdcbeec 🔍
SHA3 5cff8ffbe03d905460c8bf797ac2c114f0e98860958ea3dd43e668e02de73657 🔍
SSDeep 196608:GS98FVKkChDq1oSVCtYfM6sv6GmUUTYoa3a1URLaZbjufJBA/SfLs8utNYZ59/5s:GQ906SVCSfyfV3aSOqxsWEt6/9/Fz8P 🔍
Imports Hash 2d6e459250971c14c22e07972bba6599 🔍

DOS Header

e_magic MZ
e_cblp 0x50
e_cp 0x2
e_crlc 0
e_cparhdr 0x4
e_minalloc 0xf
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0x1a
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 11
TimeDateStamp 2025-May-03 14:45:36
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE

Image Optional Header

Magic PE32
LinkerVersion 2.0
SizeOfCode 0xac000
SizeOfInitializedData 0x74600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000ACFE0 (Section: .itext)
BaseOfCode 0x1000
BaseOfData 0xae000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x130000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x4000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b8445bdd9e5484c726072a6120dac5d3 🔍
SHA1 2877da17669e2e863272e5c50162156fc3aeff94 🔍
SHA256 dbfaca65e02e8d69892f5ef2a294b9bf9a0b7ae5cd202fd92c88dfffa168ce57 🔍
SHA3 d2371759a389b38b8243b5babd5da6457546cde0beaddc3d274c4c2cbff78b6c 🔍
VirtualSize 0xaa6e4
VirtualAddress 0x1000
SizeOfRawData 0xaa800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.39047

.itext

MD5 5f4b1e9e79c8b34d6a04f97d624934e2 🔍
SHA1 b44d09223bd386c39c44d1fe0b5213336e85621e 🔍
SHA256 fbf363832b0a3951f3edcaf3b73d1efb304ceeeb476a74beb3c58ead068cfb17 🔍
SHA3 469abeb751b5f8763ed30fe40fd20c9e08cd331378a6a93944793f3b07a4e914 🔍
VirtualSize 0x1788
VirtualAddress 0xac000
SizeOfRawData 0x1800
PointerToRawData 0xaac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.24871

.data

MD5 5c86c8844d87a63141d9256ab8648c6d 🔍
SHA1 21c9324b7dd71d81aeceba5aa2d227f72a6b5080 🔍
SHA256 c26117fc7d3529ab392b39cdccb02cf399894ba565aca8424a97906caaba1ea1 🔍
SHA3 5d26166d82bc3c9cdc29fd32d43309b9009f45bf91b733f94e2d94916926cad0 🔍
VirtualSize 0x3bfc
VirtualAddress 0xae000
SizeOfRawData 0x3c00
PointerToRawData 0xac400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.96078

.bss

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x72a4
VirtualAddress 0xb2000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.idata

MD5 cfabbe97f496978be1d9ed2b0e76508c 🔍
SHA1 e2eb539daf29399a326a1f3a2a1946805f73b707 🔍
SHA256 ae2ddc805a73a571dfd040a50bff39cbd3155ee3d8b58d7c7909cebf83dc847f 🔍
SHA3 5dd42959f1063854fe6361d9b544e7561365c5b5a4c3452eff81d5c000b55af7 🔍
VirtualSize 0x1066
VirtualAddress 0xba000
SizeOfRawData 0x1200
PointerToRawData 0xb0000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.81671

.didata

MD5 6b25d6a3ba6793df88ceec45d9ed59b3 🔍
SHA1 1364b2f455ee4cafcc3a6634c8d459be095c93eb 🔍
SHA256 58b230c875515ffb398ef8a79b40e0d5501224bb3cb27a24c7986034091cde10 🔍
SHA3 29a3c2ec08c2936f5aaeca3eeee98fcf9697e4cdc2b7e6f207d6999e76229d8b 🔍
VirtualSize 0x1a4
VirtualAddress 0xbc000
SizeOfRawData 0x200
PointerToRawData 0xb1200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.75879

.edata

MD5 1f044b007f9a7c5e77e0a9392c1c3bcb 🔍
SHA1 44d02348c84b3ffb310d7c0753682d51ee82ce62 🔍
SHA256 306530c7b8ebffcc47810688fe90875b0d718077317ced9337a45ed7573c17db 🔍
SHA3 27332e927a5e4855c0e22d5aaa00126770f83515798de353346d49700370a0da 🔍
VirtualSize 0x71
VirtualAddress 0xbd000
SizeOfRawData 0x200
PointerToRawData 0xb1400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.32693

.tls

MD5 d41d8cd98f00b204e9800998ecf8427e 🔍
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 🔍
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 🔍
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a 🔍
VirtualSize 0x18
VirtualAddress 0xbe000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 48bdf6e6093f9760e6f540d2b96a5683 🔍
SHA1 279f6169018518a5395cca1b17a40f102d2d519d 🔍
SHA256 e5deaa9340d94cffc875cfcc6462906702bc5393fa61c1a51f5be3561fec3550 🔍
SHA3 0d9b487a324f855235df8e07b750266cdfeee321a8c9f4074ca0770dde0b7e50 🔍
VirtualSize 0x5d
VirtualAddress 0xbf000
SizeOfRawData 0x200
PointerToRawData 0xb1600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 1.40023

.reloc

MD5 94b970c14a85684de6c6a4dfaa0a363b 🔍
SHA1 508631542e49af9faa98a478eb60604116a99416 🔍
SHA256 b1607b0d6a37307747511cf7715ff15b3f93ceb15cdbecafcd2bd66bd3f40853 🔍
SHA3 81ff0c1bf160d94c2c85e285fa2bc4da41f20766b2aa2709857033c77629a056 🔍
VirtualSize 0x11308
VirtualAddress 0xc0000
SizeOfRawData 0x11400
PointerToRawData 0xb1800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.71124

.rsrc

MD5 1845c7e07cb8edae09b1885a93cc98d2 🔍
SHA1 3e37c241c21023fabf0625eb2f22383b3d7113b1 🔍
SHA256 9c5e25a160c4e9508b1894a0f945a69669aa8dce0787030818074fcffa9dfaa3 🔍
SHA3 791b3570e189c2e04580214c23b535175abed4969b00367a8e912955912cc08c 🔍
VirtualSize 0x5ddc0
VirtualAddress 0xd2000
SizeOfRawData 0x5de00
PointerToRawData 0xc2c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.64369

Imports

kernel32.dll GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale
comctl32.dll InitCommonControls
user32.dll CreateWindowExW
TranslateMessage
CharLowerBuffW
CallWindowProcW
CharUpperW
PeekMessageW
GetSystemMetrics
SetWindowLongW
MessageBoxW
DestroyWindow
CharUpperBuffW
CharNextW
MsgWaitForMultipleObjects
LoadStringW
ExitWindowsEx
DispatchMessageW
oleaut32.dll SafeArrayPutElement
VariantInit
VariantClear
SysFreeString
SafeArrayAccessData
SysReAllocStringLen
SafeArrayCreate
SafeArrayGetElement
SysAllocStringLen
SafeArrayUnaccessData
SafeArrayPtrOfIndex
VariantCopy
SafeArrayGetUBound
SafeArrayGetLBound
VariantChangeType
advapi32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW
OpenThreadToken
AdjustTokenPrivileges
LookupPrivilegeValueW
RegOpenKeyExW
OpenProcessToken
FreeSid
AllocateAndInitializeSid
EqualSid
RegQueryValueExW
GetTokenInformation
ConvertSidToStringSidW
RegCloseKey
kernel32.dll (delay-loaded) GetACP
GetExitCodeProcess
CloseHandle
LocalFree
SizeofResource
VirtualProtect
QueryPerformanceFrequency
VirtualFree
GetFullPathNameW
GetProcessHeap
ExitProcess
HeapAlloc
GetCPInfoExW
RtlUnwind
GetCPInfo
GetStdHandle
GetModuleHandleW
FreeLibrary
HeapDestroy
ReadFile
CreateProcessW
GetLastError
GetModuleFileNameW
SetLastError
FindResourceW
CreateThread
CompareStringW
LoadLibraryA
ResetEvent
GetVolumeInformationW
GetVersion
GetDriveTypeW
RaiseException
FormatMessageW
SwitchToThread
GetExitCodeThread
GetCurrentThread
LoadLibraryExW
LockResource
GetCurrentThreadId
UnhandledExceptionFilter
VirtualQuery
VirtualQueryEx
Sleep
EnterCriticalSection
SetFilePointer
LoadResource
SuspendThread
GetTickCount
GetFileSize
GetStartupInfoW
GetFileAttributesW
InitializeCriticalSection
GetSystemWindowsDirectoryW
GetThreadPriority
SetThreadPriority
GetCurrentProcess
VirtualAlloc
GetCommandLineW
GetSystemInfo
LeaveCriticalSection
GetProcAddress
ResumeThread
GetVersionExW
VerifyVersionInfoW
HeapCreate
GetWindowsDirectoryW
LCMapStringW
VerSetConditionMask
GetDiskFreeSpaceW
FindFirstFileW
GetUserDefaultUILanguage
lstrlenW
QueryPerformanceCounter
SetEndOfFile
HeapFree
WideCharToMultiByte
FindClose
MultiByteToWideChar
LoadLibraryW
SetEvent
CreateFileW
GetLocaleInfoW
GetSystemDirectoryW
DeleteFileW
GetLocalTime
GetEnvironmentVariableW
WaitForSingleObject
WriteFile
ExitThread
DeleteCriticalSection
TlsGetValue
GetDateFormatW
SetErrorMode
IsValidLocale
TlsSetValue
CreateDirectoryW
GetSystemDefaultUILanguage
EnumCalendarInfoW
LocalAlloc
GetUserDefaultLangID
RemoveDirectoryW
CreateEventW
SetThreadLocale
GetThreadLocale

Delayed Imports

Attributes 0x1
Name kernel32.dll
ModuleHandle 0xbc080
DelayImportAddressTable 0xbc090
DelayImportNameTable 0xbc0b4
BoundDelayImportTable 0xbc0d8
UnloadDelayImportTable 0xbc0f0
TimeStamp 1970-Jan-01 00:00:00

dbkFCallWrapperAddr

Ordinal 1
Address 0xb563c

__dbk_fcall_wrapper

Ordinal 2
Address 0xe49c

100

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x42028
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.23878
MD5 12299f1ed319e2bce0404b04368869b0 🔍
SHA1 cc53292209184cbd1a8bfee62764db3cfc838b67 🔍
SHA256 ee7507105c4765fbd7a30324e349f1347c2fbaa5c6287b5a9f2bcd684b2e3528 🔍
SHA3 8bd62bb79ee89be9caf7273254f7279637505816a6e9eb97cd14e4ef43d60bf0 🔍

101

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10828
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.42786
MD5 77b170a072748cff62563567dd5c3849 🔍
SHA1 c52bd3f2e903981178542e4ee674aaf5fe07af7d 🔍
SHA256 d9d1a2f93d1162eef7eef37772731a8e28be62b586eef4c5a9563c92d8ebb8f0 🔍
SHA3 8736840a3a4d458455d1e4bce68168ddddce9047d26e481087460237788fca62 🔍

102

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15783
MD5 73ad1fe55db749bb5599f50685b4f9c5 🔍
SHA1 4e3df56214f97c072aa871b4642981b00bb0d476 🔍
SHA256 1b9346413266d2e4cd76a05e34a9aee346e2a6fa8c3820d681054333c183cc67 🔍
SHA3 9eb40414367b335787b387b12be7c284c526bf1afa1974f81de5d8f51ac73b66 🔍

103

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.5071
MD5 ecbe7c91d0ba2aa68d58e8db4420c6df 🔍
SHA1 a8ea7ccd808beb7d6187515ae8dc553cbdc0e4e2 🔍
SHA256 b9cee7c078f36933c7f03c4f9af7d93416d1640a8051a57ba61aeb857fd9c314 🔍
SHA3 3e76feae6b39479428c66c2a15a9f873be933f78503623e0f6c1b9584d0c5d35 🔍

104

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.12695
MD5 9cd6596b99011a4c3511252dda65918c 🔍
SHA1 68492eefde5ef31c27fb661911ad1570518471b8 🔍
SHA256 769d0d00bc5c641aee94e65445dc59a5e1bc8c409b6e60443ec290256caf4f65 🔍
SHA3 3182f63ca8ae7bbc909357d423be4647e3f003cb22947b86cddb12886f5cb194 🔍

105

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.62142
MD5 c587e765122bcf30c1220bacf761ef01 🔍
SHA1 974ec7658f4f3e01bc22fc30e87f5823d247bcd7 🔍
SHA256 9f724e862cabf250a995d2628ddf9698487d49913f053aeb705b1e7c53daca57 🔍
SHA3 978794b8b73d1eef3704b7d2e9f7beb379a8f24a87360ba249ed23ca2f95c11b 🔍

4085

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x204
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.02911
MD5 742ec64fae19c3079d9e0d9cb5269777 🔍
SHA1 b4000fec117ee423dfa39a0278bbc26d11edb9ba 🔍
SHA256 3b5144db1705312e8cb3c5e15131fc6ae695b6d5afee9bc0414c5cf1e1f3c1a9 🔍
SHA3 f923c31e0750840a9ea6aadde2997be0d8e81316d534a855352cc111f8607d7a 🔍

4086

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2e4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.32885
MD5 f96fdce1c116135874fb82281b493ac0 🔍
SHA1 562daa783cc168f8e46b1a798879583176af22cc 🔍
SHA256 3ab3b2c63dc1c1810fca5518c1bb174be9ebf36547ed1feae9e357ccf8bc3ef1 🔍
SHA3 05d0914dffa4501268059355b689944d50e9aa4a986777d770f0e713d1a8d59c 🔍

4087

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x400
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.51239
MD5 7ee56b85a64cd12875800e5eb0f8a8cc 🔍
SHA1 aedd1bec33089176851004b6593393629eb0fa6f 🔍
SHA256 dc6b3544e2299b1708bb325f9eecdb6d3a7c96755eab1d83ea51fc8b5102715c 🔍
SHA3 5b5c207556b66f9b50ed909ae8d9a80068adcd483f406df26c87f8151450bc20 🔍

4088

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3d0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.24302
MD5 44f76d42ead76c495e69824f453e64ec 🔍
SHA1 3fb0774ab962aa9cc511af9e8836164c477b9d9e 🔍
SHA256 98ffaee3d049334960e4f4bac5dd69ae5ea0e8a8f154a71ce30230508692db8d 🔍
SHA3 cbb48eb071e2f28c8b7c315c9192c0a8de0a4c75bcc188e12c72e8bad4b3230e 🔍

4089

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x3fc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34822
MD5 ba10a3e64b7ee79204e6728702cebcf5 🔍
SHA1 7c7298de979e3bb2f128be40f110a376be3350fc 🔍
SHA256 c0dce66eaf68d1a945a6c5ec96a54baeb9bf8ff533392a1c1d66cc0ac4f7e3fd 🔍
SHA3 3bce8f10959f4d33092d14e38f0d70b276193106f38f6066c66fdec4f62571ba 🔍

4090

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2d4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36723
MD5 d2467f70311fc072d9202909bdfa9fcb 🔍
SHA1 c8abb69fb38434daf6811309cc88e9d0df65e2cd 🔍
SHA256 51209c8034cd5c2127a7b877a3280699d6bad965bcc102e830420c836f535c97 🔍
SHA3 4386b5d28f8adc0eccd1a396c2d0689b85cd7cfcf727c8d08a87940c92bd64c7 🔍

4091

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0xb8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33978
MD5 e8e4995b464abd85d77008d3750ca7af 🔍
SHA1 2c39cf9c2c1cfab48077cda2d4d6312fdb53c54b 🔍
SHA256 22296669c2c50d3fdfee9de9f7730d0a5cc498b7cc54cd2aa8ded74d7e69f654 🔍
SHA3 5480674ca53405ca327424ca774da73700d535e5ca7d51363d86511e5268bb0c 🔍

4092

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x9c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.15425
MD5 d0969cc9a96275d54a109de740708a5a 🔍
SHA1 2c365c0341faf71f810a39c69859a7eb5bc0de8d 🔍
SHA256 3c45c82b39b3c90c9c22342a8f6be98073faf1dcd26dbc578b3a6fa9a499cb46 🔍
SHA3 99f949ba47f1c5cd7b313b0b89e2b14f238be4bd78199a590c1f257e4f562967 🔍

4093

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x374
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.31895
MD5 4ac29bb5f7361e85771807112cd4ec93 🔍
SHA1 b164bf0882b60c0d7d4643495a2c1db5a20a1343 🔍
SHA256 2e6d8102640132ccabd2fa3c3a61c77c2b41a80d7f60013cf7149819c2b5c9d2 🔍
SHA3 ee5ab8846732cb786d250fc1780293072aff157ae61cf7f671eb4e6e29018bf7 🔍

4094

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x398
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.28786
MD5 110abe16232608d8671eaca8ee324f45 🔍
SHA1 30704560832bafa440df1fd20693653c2a30f815 🔍
SHA256 b33f156b0a8ce96c7182dfb6afa9f6a7020433a6e16ca21f6092ba03695bdd12 🔍
SHA3 0179804f22369dabd55b8e4ca79a33645191c197c0474cabc4e13546c7e7fcd6 🔍

4095

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x368
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.33385
MD5 1c9252919f0a0d2072f3fe0565f0b443 🔍
SHA1 dc6002a243c7567105aef957d8b01142df42b3d2 🔍
SHA256 734b698aafc2cfabfd0750c88498022d650f6ee025250dc8795de56a6e122445 🔍
SHA3 4d0c5d27e1b222f09e17dc6fa9ec0bc174b3e58bba30ce90cb89b3594622e627 🔍

4096

Type RT_STRING
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2a4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.2935
MD5 d1efb0d972603f09c3a2a866a8b36d48 🔍
SHA1 64a194ea368bb16ffac3e7a4ca84b3c00bf15920 🔍
SHA256 351e7d3c756242cde2e4a2bef16d636d5e073e0cf3e9cfa2b1da1efccd7806ae 🔍
SHA3 545cc79af077359ed49f0ba5cdc74b58bef1f6fd71725c976ad9c892dc9a0b56 🔍

DVCLAL

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x10
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.75
MD5 fa1c96712ab8720f82ad4095daf7cee5 🔍
SHA1 abe71b9873e6e494a7d9de8f1f1985c550fc6b59 🔍
SHA256 10ca7c7ba673f29383bc50d1becb5fbeddddecaa6109de088da9a94c74d4f1c4 🔍
SHA3 c3be1ab5871e6568c50c4c2dd73e7c8c09d9e9451b256e9871c537b6da54a299 🔍

PACKAGEINFO

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x380
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.11694
MD5 50e02a5a9a00b97db2ea6a265858d96b 🔍
SHA1 da6db0e306416c11d04a4e47daf449e29f978103 🔍
SHA256 2ae1627b8c63488e87a0b1ef0016e50fcf7b2ae06944de6b2be4de5fa978fee8 🔍
SHA3 01ec54185ac8b02dcc5f32d6d4d22ccd4dee06a4a8640abf90c2b728f05e692e 🔍

11111

Type RT_RCDATA
Language UNKNOWN
Codepage Latin 1 / Western European
Size 0x2c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.65899
MD5 ca63fed5c59e3c79a738ea4e2e2502fe 🔍
SHA1 c16b2dda12b33eb23aa722065867ee1a0a8b3216 🔍
SHA256 7fac2b48c2c66d89226306f893264ded9ac0825adb997e6d669d9142e99072d1 🔍
SHA3 7eab4595c82d9eb3a4a0f958e864468bc023a2c479c0c4857661d702f5e05ca0 🔍

MAINICON

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.84604
Detected Filetype Icon file
MD5 d3f94076e2cecf1dc5ce6328898e0992 🔍
SHA1 bc573f7b356ed7a92df28ec4baab51537ecac9c3 🔍
SHA256 bb28105bff4bbf2adbcfc150a820ed0e9f67c29b3ac02aef2a0d9eed1b8128bc 🔍
SHA3 5599eae728e5774d126d3682d8ddadff1195fa9946dd76fe74c2b6c96f929ae7 🔍

1

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x584
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.62803
MD5 b99960dd9af5111f516e4b1b32b07e65 🔍
SHA1 1bbcba1463a8d2063dc783d3fe64d56a55bd7908 🔍
SHA256 552c0d8bb8de7c6c6d2b34aeccb09c70f6d8b985fe677afd058368255556dec5 🔍
SHA3 2f7a4d2c5aafac85b64ea199cc1ce088a1859ddb979f756846c42c37be14aada 🔍

1 (#2)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x7a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89085
MD5 e07ab8c9030f776ce0f6d9040d41c616 🔍
SHA1 593953973c74066bcd09b22402948425dab9b12f 🔍
SHA256 75bb01fe4bafdef22d879aaea5b85d1165a30ec0e558536e1b4c6002c4730d5d 🔍
SHA3 51b78d43db0954fcaa7c6fd2558eece5eb98a1c5f6e95a3033891777bfd00a7c 🔍

String Table contents

No single cast observer with ID %d was added to the observer collection
No multi cast observer with ID %d was added to the observer collection
Must wait on at least one event
Cannot call BeginInvoke on a TComponent in the process of destruction
Windows 2000
Windows XP
Windows Server 2003
Windows Server 2003 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server 2022
Windows 8
Windows 8.1
Windows 10
Windows 11
Observer is not supported
Cannot have multiple single cast observers added to the observers collection
The object does not implement the observer interface
Insufficient RTTI available to support this operation
Parameter count mismatch
Type '%s' is not declared in the interface section of a unit
VAR and OUT arguments must match parameter type exactly
Property '%s' is read-only
Property '%s' is write-only
RTTI objects cannot be manually destroyed by application code
%s (Version %d.%d, Build %d, %5:s)
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s)
32-bit Edition
64-bit Edition
Windows
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Error reading %s%s%s: %s
Stream read error
Property is read-only
%s.Seek not implemented
Property %s does not exist
Stream write error
Thread creation error: %s
Thread Error: %s (%d)
Cannot terminate an externally created thread
Cannot wait for an externally created thread
Cannot call Start on a running or suspended thread
Invalid argument
Source and Destination arrays must not be the same
SpinCount out of range. Must be between 0 and %d
Argument out of range
Duplicates not allowed
Cannot assign a %s to a %s
CheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
List does not allow duplicates ($0%x)
A component named %s already exists
''%s'' is not a valid component name
Invalid property value
Invalid property path
Invalid property value
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
. %s range is 0..%d
. %s is empty
Out of memory while expanding memory stream
%s has not been registered as a COM class
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Invalid source array
Invalid destination array
Character index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid code page
No mapping for the Unicode character exists in the target multi-byte code page
Invalid StringBaseIndex
Ancestor for '%s' not found
May
June
July
August
September
October
November
December
Sun
Mon
Tue
Wed
Thu
Fri
Sat
Sunday
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
Nov
Dec
January
February
March
April
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
Object lock not owned
Monitor support function not initialized
Feature not implemented
Method called on disposed object
%s (%s, line %d)
Abstract Error
Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%s%s
A call to an OS function failed
Variant method calls not supported
Read
Write
Execution
Invalid access
Error creating variant or safe array
Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation
Invalid NULL variant operation
Invalid variant operation (%s%.8x)
%s
Could not convert variant of type (%s) into type (%s)
Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid floating point operation
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast
Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction
Operation aborted
Exception %s in module %s at %p.
%s%s
Application Error
Format '%s' invalid or incompatible with argument
No argument for format '%s'
'%s' is not a valid integer value
'%d.%d' is not a valid timestamp
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.0.0.0
ProductVersion 0.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
Comments This installation was built with Inno Setup.
CompanyName Troplo
FileDescription NexusTools for WATCH_DOGS Setup
FileVersion (#2)
LegalCopyright
OriginalFileName
ProductName NexusTools for WATCH_DOGS
ProductVersion (#2) 1.1.12
Resource LangID English - United States

TLS Callbacks

StartAddressOfRawData 0x4be000
EndAddressOfRawData 0x4be018
AddressOfIndex 0x4aec24
AddressOfCallbacks 0x4bf010
SizeOfZeroFill 0
Characteristics IMAGE_SCN_TYPE_REG
Callbacks (EMPTY)

Load Configuration

RICH Header

Errors

[*] Warning: Section .bss has a size of 0! [*] Warning: Section .tls has a size of 0!
Leave a comment

No comments yet.