| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2018-Nov-12 16:50:07 |
| Detected languages |
English - United States
|
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .itext
Unusual section name found: .didata Unusual section name found: .debug |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | The binary may have been compiled on a machine in the UTC-3 timezone. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x50 |
| e_cp | 0x2 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0xf |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0x1a |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x100 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 12 |
| TimeDateStamp | 2018-Nov-12 16:50:07 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 2.0 |
| SizeOfCode | 0x213a00 |
| SizeOfInitializedData | 0x980a27 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00215680 (Section: .itext) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x216000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xba2000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x4000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| oleaut32.dll |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
|---|---|
| advapi32.dll |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| user32.dll |
CharNextW
LoadStringW |
| kernel32.dll |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| kernel32.dll (#2) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| kernel32.dll (#3) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| borlndmm.dll |
@Borlndmm@SysGetMem$qqri
|
| user32.dll (#2) |
CharNextW
LoadStringW |
| gdi32.dll |
UnrealizeObject
StretchDIBits StretchBlt StartPage StartDocW SetWindowOrgEx SetWinMetaFileBits SetViewportOrgEx SetTextColor SetStretchBltMode SetRectRgn SetROP2 SetPixel SetEnhMetaFileBits SetDIBits SetDIBColorTable SetBrushOrgEx SetBkMode SetBkColor SetAbortProc SelectPalette SelectObject SaveDC RoundRect RestoreDC Rectangle RectVisible RealizePalette Polyline Polygon PolyBezierTo PolyBezier PlayEnhMetaFile Pie PatBlt MoveToEx MaskBlt LineTo IntersectClipRect GetWindowOrgEx GetWinMetaFileBits GetTextMetricsW GetTextExtentPointW GetTextExtentPoint32W GetSystemPaletteEntries GetStockObject GetRgnBox GetPixel GetPaletteEntries GetObjectW GetEnhMetaFilePaletteEntries GetEnhMetaFileHeader GetEnhMetaFileDescriptionW GetEnhMetaFileBits GetDeviceCaps GetDIBits GetDIBColorTable GetCurrentPositionEx GetClipBox GetBrushOrgEx GetBitmapBits GdiFlush FrameRgn ExtTextOutW ExtFloodFill ExcludeClipRect EnumFontsW EnumFontFamiliesExW EndPage EndDoc Ellipse DeleteObject DeleteEnhMetaFile DeleteDC CreateSolidBrush CreateRectRgn CreatePenIndirect CreatePalette CreateICW CreateHalftonePalette CreateFontIndirectW CreateDIBitmap CreateDIBSection CreateDCW CreateCompatibleDC CreateCompatibleBitmap CreateBrushIndirect CreateBitmap CopyEnhMetaFileW Chord BitBlt ArcTo Arc AngleArc AbortDoc |
| version.dll |
VerQueryValueW
GetFileVersionInfoSizeW GetFileVersionInfoW |
| kernel32.dll (#4) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| advapi32.dll (#2) |
RegQueryValueExW
RegOpenKeyExW RegCloseKey |
| kernel32.dll (#5) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| netapi32.dll |
NetWkstaGetInfo
|
| oleaut32.dll (#2) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| oleaut32.dll (#3) |
SysFreeString
SysReAllocStringLen SysAllocStringLen |
| ole32.dll |
OleUninitialize
OleInitialize CoTaskMemFree CoTaskMemAlloc CoCreateInstance CoUninitialize CoInitialize IsEqualGUID |
| comctl32.dll |
InitializeFlatSB
FlatSB_SetScrollProp FlatSB_SetScrollPos FlatSB_SetScrollInfo FlatSB_GetScrollPos FlatSB_GetScrollInfo _TrackMouseEvent ImageList_GetImageInfo ImageList_SetIconSize ImageList_GetIconSize ImageList_Write ImageList_Read ImageList_GetDragImage ImageList_DragShowNolock ImageList_DragMove ImageList_DragLeave ImageList_DragEnter ImageList_EndDrag ImageList_BeginDrag ImageList_Copy ImageList_LoadImageW ImageList_GetIcon ImageList_Remove ImageList_DrawEx ImageList_Replace ImageList_Draw ImageList_SetOverlayImage ImageList_GetBkColor ImageList_SetBkColor ImageList_ReplaceIcon ImageList_Add ImageList_SetImageCount ImageList_GetImageCount ImageList_Destroy ImageList_Create |
| user32.dll (#3) |
CharNextW
LoadStringW |
| msvcrt.dll |
memset
memcpy |
| shell32.dll |
ShellExecuteW
Shell_NotifyIconW |
| winspool.drv |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| winspool.drv (#2) |
OpenPrinterW
EnumPrintersW DocumentPropertiesW ClosePrinter |
| kernel32.dll (delay-loaded) |
Sleep
VirtualFree VirtualAlloc lstrlenW VirtualQuery QueryPerformanceCounter GetTickCount GetSystemInfo GetVersion CompareStringW IsValidLocale SetThreadLocale GetSystemDefaultUILanguage GetUserDefaultUILanguage GetLocaleInfoW WideCharToMultiByte MultiByteToWideChar GetACP LoadLibraryExW GetStartupInfoW GetProcAddress GetModuleHandleW GetModuleFileNameW GetCommandLineW FreeLibrary GetLastError UnhandledExceptionFilter RtlUnwind RaiseException ExitProcess ExitThread SwitchToThread GetCurrentThreadId CreateThread DeleteCriticalSection LeaveCriticalSection EnterCriticalSection InitializeCriticalSection FindFirstFileW FindClose WriteFile GetStdHandle CloseHandle |
| Attributes | 0x1 |
|---|---|
| Name | kernel32.dll |
| ModuleHandle | 0x22a1c0 |
| DelayImportAddressTable | 0x22a1f8 |
| DelayImportNameTable | 0x22a2fc |
| BoundDelayImportTable | 0x22a400 |
| UnloadDelayImportTable | 0x22a4d0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1 |
|---|---|
| Address | 0x222c5c |
| Ordinal | 2 |
|---|---|
| Address | 0x62e00 |
| Dispatch methods do not support more than 64 parameters |
| Cannot change the size of a JPEG image |
| JPEG error #%d |
| JPEG Image File |
| Style class '%s' already registered |
| Style '%s' not found |
| Style class '%s' not found |
| Invalid style handle |
| Invalid style format |
| Class '%s' is already registered for '%s' |
| Class '%s' is not registered for '%s' |
| %s parameter cannot be nil |
| Feature not supported by this style |
| Style '%s' is not registered |
| Cannot unregister the system style |
| Style not registered |
| Cannot call BeginInvoke on a control with no parent or window handle |
| OLE error %.8x |
| Method '%s' not supported by automation object |
| Variant does not reference an automation object |
| - Dock zone has no control |
| Error loading dock zone from the stream. Expecting version %d, but found %d. |
| Length of value array must be >= length of prompt array |
| Prompt array must not be empty |
| &Username |
| &Password |
| &Domain |
| Login |
| Cannot remove shell notification icon |
| %s requires Windows Vista or later |
| Button%d |
| RadioButton%d |
| Caption cannot be empty |
| Unable to load style '%s' |
| Unable to load styles: %s |
| Style '%s' already registered |
| Down |
| Ins |
| Del |
| Shift+ |
| Ctrl+ |
| Alt+ |
| Value must be between %d and %d |
| All |
| Clipboard does not support Icons |
| Cannot open clipboard: %s |
| Operation not supported on selected printer |
| There is no default printer currently selected |
| Menu '%s' is already being used by another form |
| Docked control must have a name |
| Error removing control from dock tree |
| - Dock zone not found |
| &All |
| N&o to All |
| Yes to &All |
| &Close |
| BkSp |
| Tab |
| Esc |
| Enter |
| Space |
| PgUp |
| PgDn |
| End |
| Home |
| Left |
| Up |
| Right |
| Enhanced Metafiles |
| Icons |
| Bitmaps |
| TIFF Images |
| Warning |
| Error |
| Information |
| Confirm |
| &Yes |
| &No |
| OK |
| Cancel |
| &Help |
| &Abort |
| &Retry |
| &Ignore |
| %s property out of range |
| Menu index out of range |
| Menu inserted twice |
| Sub-menu is not in menu |
| Not enough timers available |
| Printer is not currently printing |
| Printing in progress |
| Printer index out of range |
| Printer selected is not valid |
| %s on %s |
| GroupIndex cannot be less than a previous menu item's GroupIndex |
| Cannot create form. No MDI forms are currently active |
| Can only modify an image if it contains a bitmap |
| A control cannot have itself as its parent |
| Cannot drag a form |
| Metafiles |
| Text format flag '%s' not supported |
| Invalid image size |
| Invalid ImageList |
| Unable to Replace Image |
| Invalid ImageList Index |
| Failed to read ImageList data from stream |
| Failed to write ImageList data to stream |
| Error creating window device context |
| Error creating window class |
| Cannot focus a disabled or invisible window |
| Control '%s' has no parent window |
| Parent given is not a parent of '%s' |
| Cannot hide an MDI Child Form |
| Cannot change Visible in OnShow or OnHide |
| Cannot make a visible window modal |
| Scrollbar property out of range |
| Invalid time string: %s |
| Invalid time Offset string: %s |
| Must wait on at least one event |
| Cannot call BeginInvoke on a TComponent in the process of destruction |
| Bitmap image is not valid |
| Icon image is not valid |
| Metafile is not valid |
| Invalid pixel format |
| Invalid image |
| Scan line index out of range |
| Cannot change the size of an icon |
| Cannot change the size of a WIC Image |
| Unknown picture file extension (.%s) |
| Unsupported clipboard format |
| Out of system resources |
| Canvas does not allow drawing |
| Error writing zip file |
| Invalid Zip Local Header signature |
| Invalid Zip Central Header signature |
| Support for compression method not registered: %s |
| File must be open |
| File must be open for writing |
| File must be open for reading |
| Zip file must be empty |
| File name must not be empty |
| Observer is not supported |
| Cannot have multiple single cast observers added to the observers collection |
| The object does not implement the observer interface |
| No single cast observer with ID %d was added to the observer collection |
| No multi cast observer with ID %d was added to the observer collection |
| Observer is not available |
| Invalid date string: %s |
| 64-bit Edition |
| Windows |
| Windows Vista |
| Windows Server 2008 |
| Windows 7 |
| Windows Server 2008 R2 |
| Windows 2000 |
| Windows XP |
| Windows Server 2003 |
| Windows Server 2003 R2 |
| Windows Server 2012 |
| Windows Server 2012 R2 |
| Windows 8 |
| Windows 8.1 |
| Windows 10 |
| Error reading zip file |
| Unable to open Search |
| Unable to find a Table of Contents |
| No topic-based help system installed |
| No help found for %s |
| Argument out of range |
| Argument must not be nil |
| Item not found |
| Duplicates not allowed |
| Insufficient RTTI available to support this operation |
| Parameter count mismatch |
| Type '%s' is not declared in the interface section of a unit |
| VAR and OUT arguments must match parameter type exactly |
| Specified Login Credential Service not found |
| %s (Version %d.%d, Build %d, %5:s) |
| %s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
| 32-bit Edition |
| No help viewer that supports filters |
| Invalid argument |
| Index out of range (%d). Must be >= 0 and < %d |
| Length of Strings and Objects arrays must be equal |
| Class %s is not intended to be constructed |
| Invalid Timeout value: %s |
| SpinCount out of range. Must be between 0 and %d |
| Timespan too long |
| The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue |
| Value cannot be NaN |
| Negating the minimum value of a Timespan is invalid |
| Invalid Timespan format |
| Timespan element too long |
| No context-sensitive help installed |
| No help found for context %d |
| Unable to open Index |
| Cannot wait for an externally created thread |
| Cannot call Start on a running or suspended thread |
| Cannot call CheckTerminated on an externally created thread |
| Cannot call SetReturnValue on an externally create thread |
| Parameter %s cannot be nil |
| Parameter %s cannot be a negative value |
| Input buffer exceeded for %s = %d, %s = %d |
| Invalid characters in path |
| Invalid characters in search pattern |
| The specified path is too long |
| The specified path was not found |
| The path format is not supported |
| The drive cannot be found |
| The specified file was not found |
| The specified file already exists |
| The given "%s" local time is invalid (situated within the missing period prior to DST). |
| %s has not been registered as a COM class |
| Error reading %s%s%s: %s |
| Stream read error |
| Property is read-only |
| Failed to create key %s |
| Failed to get data for '%s' |
| Failed to set data for '%s' |
| Resource %s not found |
| %s.Seek not implemented |
| Operation not allowed on sorted list |
| %s not in a class registration group |
| Property %s does not exist |
| Stream write error |
| Thread creation error: %s |
| Thread Error: %s (%d) |
| Cannot terminate an externally created thread |
| String list does not allow duplicates |
| Cannot create file "%s". %s |
| Cannot open file "%s". %s |
| Unable to write to %s |
| Invalid file name - %s |
| Invalid stream format |
| '%s' is an invalid mask at (%d) |
| ''%s'' is not a valid component name |
| Invalid property value |
| Invalid property path |
| Invalid property value |
| Invalid data type for '%s' |
| List capacity out of bounds (%d) |
| List count out of bounds (%d) |
| List index out of bounds (%d) |
| Out of memory while expanding memory stream |
| Character index out of bounds (%d) |
| Start index out of bounds (%d) |
| Invalid count (%d) |
| Invalid destination index (%d) |
| Invalid code page |
| Invalid encoding name |
| No mapping for the Unicode character exists in the target multi-byte code page |
| Ancestor for '%s' not found |
| Cannot assign a %s to a %s |
| Bits index out of range |
| Can't write to a read-only resource stream |
| CheckSynchronize called from thread $%x, which is NOT the main thread |
| Class %s not found |
| A class named %s already exists |
| List does not allow duplicates ($0%x) |
| A component named %s already exists |
| Mon |
| Tue |
| Wed |
| Thu |
| Fri |
| Sat |
| Sunday |
| Monday |
| Tuesday |
| Wednesday |
| Thursday |
| Friday |
| Saturday |
| Unable to create directory |
| Invalid source array |
| Invalid destination array |
| Oct |
| Nov |
| Dec |
| January |
| February |
| March |
| April |
| May |
| June |
| July |
| August |
| September |
| October |
| November |
| December |
| Sun |
| Feature not implemented |
| Method called on disposed object |
| %s (%s, line %d) |
| Abstract Error |
| Access violation at address %p in module '%s'. %s of address %p |
| System Error. Code: %d. |
| %s%s |
| A call to an OS function failed |
| Jan |
| Feb |
| Mar |
| Apr |
| May |
| Jun |
| Jul |
| Aug |
| Sep |
| Custom variant type (%s%.4x) already used by %s |
| Custom variant type (%s%.4x) is not usable |
| Too many custom variant types have been registered |
| Could not convert variant of type (%s) into type (%s) |
| Overflow while converting variant of type (%s) into type (%s) |
| Variant overflow |
| Invalid argument |
| Invalid variant type |
| Operation not supported |
| Unexpected variant error |
| External exception %x |
| Assertion failed |
| Interface not supported |
| Exception in safecall method |
| Object lock not owned |
| Monitor support function not initialized |
| Application Error |
| Format '%s' invalid or incompatible with argument |
| No argument for format '%s' |
| Variant method calls not supported |
| Read |
| Write |
| Execution |
| Invalid access |
| Error creating variant or safe array |
| Variant or safe array index out of bounds |
| Variant or safe array is locked |
| Invalid variant type conversion |
| Invalid variant operation |
| Invalid NULL variant operation |
| Invalid variant operation (%s%.8x) |
| %s |
| Custom variant type (%s%.4x) is out of range |
| Invalid numeric input |
| Division by zero |
| Range check error |
| Integer overflow |
| Invalid floating point operation |
| Floating point division by zero |
| Floating point overflow |
| Floating point underflow |
| Invalid pointer operation |
| Invalid class typecast |
| Access violation at address %p. %s of address %p |
| Access violation |
| Stack overflow |
| Control-C hit |
| Privileged instruction |
| Exception %s in module %s at %p. |
| %s%s |
| <unknown> |
| '%s' is not a valid integer value |
| '%s' is not a valid floating point value |
| '%s' is not a valid date |
| '%s' is not a valid time |
| '%s' is not a valid date and time |
| '%d.%d' is not a valid timestamp |
| '%s' is not a valid GUID value |
| Invalid argument to time encode |
| Invalid argument to date encode |
| Out of memory |
| I/O error %d |
| Too many open files |
| File access denied |
| Read beyond end of file |
| Disk full |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileVersion (#2) | 1.0.0.0 |
| ProductVersion (#2) | 1.0.0.0 |
| Resource LangID | English - United States |
|---|
| StartAddressOfRawData | 0x62c000 |
|---|---|
| EndAddressOfRawData | 0x62c040 |
| AddressOfIndex | 0x616c10 |
| AddressOfCallbacks | 0x62d010 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_TYPE_REG
|
| Callbacks | (EMPTY) |
No comments yet.