| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2012-Oct-02 05:03:49 |
| Detected languages |
English - United States
|
| FileDescription | Setup/Uninstall |
| FileVersion | 51.1052.0.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 |
| Suspicious | The PE is possibly packed. | Unusual section name found: .itext |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Malicious | The PE is possibly a dropper. |
Resource HELPER_EXE_AMD64 detected as a PE Executable.
Resource SHFOLDERDLL detected as a PE Executable. |
| Suspicious | The file contains overlay data. | 22403 bytes of data starting at offset 0x16be00. |
| Safe | VirusTotal score: 0/71 (Scanned on 2023-06-28 10:36:57) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 8 |
| TimeDateStamp | 2012-Oct-02 05:03:49 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x14b000 |
| SizeOfInitializedData | 0x20a00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0014C094 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x14d000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 6.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x178000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
| kernel32.dll |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte SetCurrentDirectoryW MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCurrentDirectoryW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| kernel32.dll (#2) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte SetCurrentDirectoryW MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCurrentDirectoryW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| user32.dll (#2) |
GetKeyboardType
LoadStringW MessageBoxA CharNextW |
| msimg32.dll |
AlphaBlend
|
| gdi32.dll |
UnrealizeObject
StretchDIBits StretchBlt StartPage StartDocW SetWindowOrgEx SetViewportOrgEx SetTextColor SetTextAlign SetStretchBltMode SetROP2 SetPixel SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SetAbortProc SelectPalette SelectObject SelectClipRgn SaveDC RoundRect RestoreDC RemoveFontResourceW Rectangle RectVisible RealizePalette Polyline Pie PatBlt MoveToEx MaskBlt LineTo LineDDA IntersectClipRect GetWindowOrgEx GetTextMetricsW GetTextExtentPointW GetTextExtentPoint32W GetSystemPaletteEntries GetStockObject GetRgnBox GetPixel GetPaletteEntries GetObjectW GetDeviceCaps GetDIBits GetDIBColorTable GetDCOrgEx GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits FrameRgn ExtTextOutW ExtFloodFill ExcludeClipRect EnumFontsW EnumFontFamiliesExW EndPage EndDoc Ellipse DeleteObject DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateICW CreateHalftonePalette CreateFontIndirectW CreateDIBitmap CreateDIBSection CreateDCW CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap Chord BitBlt Arc AddFontResourceW |
| version.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
| mpr.dll |
WNetOpenEnumW
WNetGetUniversalNameW WNetGetConnectionW WNetEnumResourceW WNetCloseEnum |
| kernel32.dll (#3) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte SetCurrentDirectoryW MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCurrentDirectoryW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| ole32.dll |
OleUninitialize
OleInitialize CoTaskMemFree CoTaskMemAlloc CLSIDFromProgID CLSIDFromString StringFromCLSID CoCreateInstance CoFreeUnusedLibraries CoUninitialize CoInitialize IsEqualGUID |
| comctl32.dll |
InitializeFlatSB
FlatSB_SetScrollProp FlatSB_SetScrollPos FlatSB_SetScrollInfo FlatSB_GetScrollPos FlatSB_GetScrollInfo _TrackMouseEvent ImageList_GetImageInfo ImageList_SetIconSize ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Copy ImageList_LoadImageW ImageList_GetIcon ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_SetOverlayImage ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_SetImageCount ImageList_GetImageCount ImageList_Destroy ImageList_Create InitCommonControls |
| kernel32.dll (#4) |
GetACP
Sleep VirtualFree VirtualAlloc GetSystemInfo GetTickCount QueryPerformanceCounter GetVersion GetCurrentThreadId VirtualQuery WideCharToMultiByte SetCurrentDirectoryW MultiByteToWideChar lstrlenW lstrcpynW LoadLibraryExW GetThreadLocale GetStartupInfoA GetProcAddress GetModuleHandleW GetModuleFileNameW GetLocaleInfoW GetCurrentDirectoryW GetCommandLineW FreeLibrary FindFirstFileW FindClose ExitProcess ExitThread CreateThread CompareStringW WriteFile UnhandledExceptionFilter RtlUnwind RaiseException GetStdHandle CloseHandle |
| oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| winspool.drv |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| winspool.drv (#2) |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| shell32.dll |
ShellExecuteExW
ShellExecuteW SHGetFileInfoW ExtractIconW |
| shell32.dll (#2) |
ShellExecuteExW
ShellExecuteW SHGetFileInfoW ExtractIconW |
| comdlg32.dll |
GetSaveFileNameW
GetOpenFileNameW |
| ole32.dll (#2) |
OleUninitialize
OleInitialize CoTaskMemFree CoTaskMemAlloc CLSIDFromProgID CLSIDFromString StringFromCLSID CoCreateInstance CoFreeUnusedLibraries CoUninitialize CoInitialize IsEqualGUID |
| advapi32.dll (#3) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| oleaut32.dll (#4) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| Capacity < Length |
| Nil interface |
| Unknown method |
| Expected return address at stack base |
| Type Mismatch |
| Unexpected End Of File |
| Version error |
| divide by Zero |
| Math error |
| Could not call proc |
| Out of Record Fields Range |
| Null Pointer Exception |
| Null variant error |
| Out Of Memory |
| Interface not supported |
| Unknown error |
| Invalid array |
| Out of string range |
| Cannot cast an interface |
| Cannot cast an object |
| Dispatch methods do not support more than 64 parameters |
| Unknown Identifier |
| Exception: %s |
| [Invalid] |
| No Error |
| Cannot Import %s |
| Invalid Type |
| Internal error |
| Invalid Header |
| Invalid Opcode |
| Invalid Opcode Parameter |
| no Main Proc |
| Out of Global Vars range |
| Out of Proc Range |
| Out Of Range |
| Out Of Stack Range |
| Failed to get object at index %d |
| Failed to set tab "%s" at index %d |
| Failed to set object at index %d |
| MultiLine must be True when TabPosition is tpLeft or tpRight |
| Invalid item level assignment |
| Invalid level (%d) for item "%s" |
| Invalid index |
| Unable to insert an item |
| Invalid owner |
| %s is already associated with %s |
| %d is an invalid PageIndex value. PageIndex must be between 0 and %d |
| This control requires version 4.70 or greater of COMCTL32.DLL |
| Invalid float |
| OLE error %.8x |
| Method '%s' not supported by automation object |
| Variant does not reference an automation object |
| Error loading dock zone from the stream. Expecting version %d, but found %d. |
| Multiselect mode must be on for this feature |
| Error setting %s.Count |
| Listbox (%s) style must be virtual in order to set Count |
| No OnGetItem event handler assigned |
| PageControl must first be assigned |
| No context-sensitive help installed |
| No help found for context |
| Unable to open Index |
| Unable to open Search |
| Unable to find a Table of Contents |
| No topic-based help system installed |
| No help found for %s |
| Failed to clear tab control |
| Failed to delete tab at index %d |
| Failed to retrieve tab at index %d |
| Right |
| Down |
| Ins |
| Del |
| Shift+ |
| Ctrl+ |
| Alt+ |
| Unable to insert a line |
| Clipboard does not support Icons |
| Text exceeds memo capacity |
| There is no default printer currently selected |
| Menu '%s' is already being used by another form |
| Docked control must have a name |
| Error removing control from dock tree |
| - Dock zone not found |
| - Dock zone has no control |
| &Ignore |
| &All |
| N&o to All |
| Yes to &All |
| &Close |
| BkSp |
| Tab |
| Esc |
| Enter |
| Space |
| PgUp |
| PgDn |
| End |
| Home |
| Left |
| Up |
| %s on %s |
| GroupIndex cannot be less than a previous menu item's GroupIndex |
| Cannot create form. No MDI forms are currently active |
| A control cannot have itself as its parent |
| Cannot drag a form |
| Warning |
| Error |
| Information |
| Confirm |
| &Yes |
| &No |
| OK |
| Cancel |
| &Help |
| &Abort |
| &Retry |
| Error creating window class |
| Cannot focus a disabled or invisible window |
| Control '%s' has no parent window |
| Parent given is not a parent of '%s' |
| Cannot hide an MDI Child Form |
| Cannot change Visible in OnShow or OnHide |
| Cannot make a visible window modal |
| Scrollbar property out of range |
| %s property out of range |
| Menu index out of range |
| Menu inserted twice |
| Sub-menu is not in menu |
| Not enough timers available |
| Printer is not currently printing |
| Printing in progress |
| Printer selected is not valid |
| Tab position incompatible with current tab style |
| Tab style incompatible with current tab position |
| Bitmap image is not valid |
| Icon image is not valid |
| Invalid pixel format |
| Cannot change the size of an icon |
| Unsupported clipboard format |
| Out of system resources |
| Canvas does not allow drawing |
| Invalid image size |
| Invalid ImageList |
| Unable to Replace Image |
| Invalid ImageList Index |
| Failed to read ImageList data from stream |
| Failed to write ImageList data to stream |
| Error creating window device context |
| Property %s does not exist |
| Stream write error |
| Thread creation error: %s |
| Thread Error: %s (%d) |
| Cannot terminate an externally created thread |
| Cannot wait for an externally created thread |
| No help viewer that supports filters |
| String index out of range (%d). Must be >= 1 and <= %d |
| Invalid UTF32 character value. Must be >= 0 and <= $10FFF, excluding surrogate pair ranges |
| High surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properly |
| Low surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly |
| ''%s'' is not a valid date |
| ''%s'' is not a valid date and time |
| ''%s'' is not a valid integer value |
| ''%s'' is not a valid time |
| Invalid argument to time encode |
| List count out of bounds (%d) |
| List index out of bounds (%d) |
| Out of memory while expanding memory stream |
| Number expected |
| ANSI or UTF8 encoding expected |
| %s on line %d |
| Error reading %s%s%s: %s |
| Stream read error |
| Property is read-only |
| Failed to get data for '%s' |
| Resource %s not found |
| %s.Seek not implemented |
| Operation not allowed on sorted list |
| String expected |
| %s expected |
| %s not in a class registration group |
| A component named %s already exists |
| String list does not allow duplicates |
| Cannot create file "%s". %s |
| Cannot open file "%s". %s |
| Identifier expected |
| Invalid binary value |
| Invalid file name - %s |
| Invalid stream format |
| ''%s'' is not a valid component name |
| Invalid property value |
| Invalid property path |
| Invalid property value |
| Invalid data type for '%s' |
| Invalid string constant |
| Line too long |
| List capacity out of bounds (%d) |
| Invalid source array |
| Invalid destination array |
| Character index out of bounds (%d) |
| Start index out of bounds (%d) |
| Invalid count (%d) |
| Invalid destination index (%d) |
| Invalid code page |
| Ancestor for '%s' not found |
| Cannot assign a %s to a %s |
| Bits index out of range |
| Can't write to a read-only resource stream |
| ''%s'' expected |
| CheckSynchronize called from thread $%x, which is NOT the main thread |
| Class %s not found |
| A class named %s already exists |
| List does not allow duplicates ($0%x) |
| November |
| December |
| Sun |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Jul |
| Aug |
| Sep |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Monitor support function not initialized |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Format string too long |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid NULL variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Operation aborted |
| Exception %s in module %s at %p. |
| %s%s |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| '%s' is not a valid floating point value |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| File not found |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 51.1052.0.0 |
| ProductVersion | 0.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | UNKNOWN |
| FileDescription | Setup/Uninstall |
| FileVersion (#2) | 51.1052.0.0 |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x55c000 |
|---|---|
| EndAddressOfRawData | 0x55c03c |
| AddressOfIndex | 0x54d7e8 |
| AddressOfCallbacks | 0x55d010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.