filename | Magic.exe | |
---|---|---|
size | 2086792 (0x1fd788) | |
md5 | 051168e4fbb0a27e90a5a550e4d9bb85 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xf8 |
Rich Header
lib id | version | times used |
---|---|---|
132 | 21022 | 4 |
149 | 30729 | 24 |
132 | 30729 | 74 |
131 | 30729 | 180 |
147 | 30729 | 23 |
1 | 0 | 284 |
131 | 21022 | 2 |
138 | 30729 | 26 |
146 | 30729 | 1 |
148 | 21022 | 1 |
145 | 30729 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
module_name | hint | ord | function_name |
---|---|---|---|
kernel32.dll | GetProcAddress | ||
kernel32.dll | GetModuleHandleA | ||
kernel32.dll | LoadLibraryA | ||
user32.dll | EnableWindow | ||
gdi32.dll | DeleteDC | ||
advapi32.dll | RegCloseKey | ||
shell32.dll | ShellExecuteW | ||
ole32.dll | CoTaskMemAlloc | ||
oleaut32.dll | 146 | ||
wrapper.dll | void __cdecl DllGetRegInfo(char *) ?DllGetRegInfo@@YAXPAD@Z | ||
oleaut32.dll | VariantChangeTypeEx | ||
kernel32.dll | RaiseException |
Signers (1)
issuer: /C=US/O=VeriSign, Inc./OU=VeriSign Trust Network/OU=Terms of use at https:\/\/www.verisign.com\/rpa (c)10/CN=VeriSign Class 3 Code Signing 2010 CA
serial: 650A27A04DBAA9DF0C06DEBBA3983054
Certificates (4)
Certificate: Data: Version: 3 (0x2) Serial Number: 7e:93:eb:fb:7c:c6:4e:59:ea:4b:9a:77:d4:06:fc:3b Signature Algorithm: sha1WithRSAEncryption Issuer: C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA Validity Not Before: Dec 21 00:00:00 2012 GMT Not After : Dec 30 23:59:59 2020 GMT Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:b1:ac:b3:49:54:4b:97:1c:12:0a:d8:25:79:91: 22:57:2a:6f:dc:b8:26:c4:43:73:6b:c2:bf:2e:50: 5a:fb:14:c2:76:8e:43:01:25:43:b4:a1:e2:45:f4: e8:b7:7b:c3:74:cc:22:d7:b4:94:00:02:f7:4d:ed: bf:b4:b7:44:24:6b:cd:5f:45:3b:d1:44:ce:43:12: 73:17:82:8b:69:b4:2b:cb:99:1e:ac:72:1b:26:4d: 71:1f:b1:31:dd:fb:51:61:02:53:a6:aa:f5:49:2c: 05:78:45:a5:2f:89:ce:e7:99:e7:fe:8c:e2:57:3f: 3d:c6:92:dc:4a:f8:7b:33:e4:79:0a:fb:f0:75:88: 41:9c:ff:c5:03:51:99:aa:d7:6c:9f:93:69:87:65: 29:83:85:c2:60:14:c4:c8:c9:3b:14:da:c0:81:f0: 1f:0d:74:de:92:22:ab:ca:f7:fb:74:7c:27:e6:f7: 4a:1b:7f:a7:c3:9e:2d:ae:8a:ea:a6:e6:aa:27:16: 7d:61:f7:98:71:11:bc:e2:50:a1:4b:e5:5d:fa:e5: 0e:a7:2c:9f:aa:65:20:d3:d8:96:e8:c8:7c:a5:4e: 48:44:ff:19:e2:44:07:92:0b:d7:68:84:80:5d:6a: 78:64:45:cd:60:46:7e:54:c1:13:7c:c5:79:f1:c9: c1:71 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Subject Key Identifier: 5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD Authority Information Access: OCSP - URI:http://ocsp.thawte.com X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 CRL Distribution Points: Full Name: URI:http://crl.thawte.com/ThawteTimestampingCA.crl X509v3 Extended Key Usage: Time Stamping X509v3 Key Usage: critical Certificate Sign, CRL Sign X509v3 Subject Alternative Name: DirName:/CN=TimeStamp-2048-1 Signature Algorithm: sha1WithRSAEncryption Signature Value: 03:09:9b:8f:79:ef:7f:59:30:aa:ef:68:b5:fa:e3:09:1d:bb: 4f:82:06:5d:37:5f:a6:52:9f:16:8d:ea:1c:92:09:44:6e:f5: 6d:eb:58:7c:30:e8:f9:69:8d:23:73:0b:12:6f:47:a9:ae:39: 11:f8:2a:b1:9b:b0:1a:c3:8e:eb:59:96:00:ad:ce:0c:4d:b2: d0:31:a6:08:5c:2a:7a:fc:e2:7a:1d:57:4c:a8:65:18:e9:79: 40:62:25:96:6e:c7:c7:37:6a:83:21:08:8e:41:ea:dd:d9:57: 3f:1d:77:49:87:2a:16:06:5e:a6:38:6a:22:12:a3:51:19:83: 7e:b6
Certificate: Data: Version: 3 (0x2) Serial Number: 0e:cf:f4:38:c8:fe:bf:35:6e:04:d8:6a:98:1b:1a:50 Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services CA - G2 Validity Not Before: Oct 18 00:00:00 2012 GMT Not After : Dec 29 23:59:59 2020 GMT Subject: C=US, O=Symantec Corporation, CN=Symantec Time Stamping Services Signer - G4 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:a2:63:0b:39:44:b8:bb:23:a7:44:49:bb:0e:ff: a1:f0:61:0a:53:93:b0:98:db:ad:2c:0f:4a:c5:6e: ff:86:3c:53:55:0f:15:ce:04:3f:2b:fd:a9:96:96: d9:be:61:79:0b:5b:c9:4c:86:76:e5:e0:43:4b:22: 95:ee:c2:2b:43:c1:9f:d8:68:b4:8e:40:4f:ee:85: 38:b9:11:c5:23:f2:64:58:f0:15:32:6f:4e:57:a1: ae:88:a4:02:d7:2a:1e:cd:4b:e1:dd:63:d5:17:89: 32:5b:b0:5e:99:5a:a8:9d:28:50:0e:17:ee:96:db: 61:3b:45:51:1d:cf:12:56:0b:92:47:fc:ab:ae:f6: 66:3d:47:ac:70:72:e7:92:e7:5f:cd:10:b9:c4:83: 64:94:19:bd:25:80:e1:e8:d2:22:a5:d0:ba:02:7a: a1:77:93:5b:65:c3:ee:17:74:bc:41:86:2a:dc:08: 4c:8c:92:8c:91:2d:9e:77:44:1f:68:d6:a8:74:77: db:0e:5b:32:8b:56:8b:33:bd:d9:63:c8:49:9d:3a: c5:c5:ea:33:0b:d2:f1:a3:1b:f4:8b:be:d9:b3:57: 8b:3b:de:04:a7:7a:22:b2:24:ae:2e:c7:70:c5:be: 4e:83:26:08:fb:0b:bd:a9:4f:99:08:e1:10:28:72: aa:cd Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:FALSE X509v3 Extended Key Usage: critical Time Stamping X509v3 Key Usage: critical Digital Signature Authority Information Access: OCSP - URI:http://ts-ocsp.ws.symantec.com CA Issuers - URI:http://ts-aia.ws.symantec.com/tss-ca-g2.cer X509v3 CRL Distribution Points: Full Name: URI:http://ts-crl.ws.symantec.com/tss-ca-g2.crl X509v3 Subject Alternative Name: DirName:/CN=TimeStamp-2048-2 X509v3 Subject Key Identifier: 46:C6:69:A3:0E:4A:14:1E:D5:4C:DA:52:63:17:3F:5E:36:BC:0D:E6 X509v3 Authority Key Identifier: 5F:9A:F5:6E:5C:CC:CC:74:9A:D4:DD:7D:EF:3F:DB:EC:4C:80:2E:DD Signature Algorithm: sha1WithRSAEncryption Signature Value: 78:3b:b4:91:2a:00:4c:f0:8f:62:30:37:78:a3:84:27:07:6f: 18:b2:de:25:dc:a0:d4:94:03:aa:86:4e:25:9f:9a:40:03:1c: dd:ce:e3:79:cb:21:68:06:da:b6:32:b4:6d:bf:f4:2c:26:63: 33:e4:49:64:6d:0d:e6:c3:67:0e:f7:05:a4:35:6c:7c:89:16: c6:e9:b2:df:b2:e9:dd:20:c6:71:0f:cd:95:74:dc:b6:5c:de: bd:37:1f:43:78:e6:78:b5:cd:28:04:20:a3:aa:f1:4b:c4:88: 29:91:0e:80:d1:11:fc:dd:5c:76:6e:4f:5e:0e:45:46:41:6e: 0d:b0:ea:38:9a:b1:3a:da:09:71:10:fc:1c:79:b4:80:7b:ac: 69:f4:fd:9c:b6:0c:16:2b:f1:7f:5b:09:3d:9b:5b:e2:16:ca: 13:81:6d:00:2e:38:0d:a8:29:8f:2c:e1:b2:f4:5a:a9:01:af: 15:9c:2c:2f:49:1b:db:22:bb:c3:fe:78:94:51:c3:86:b1:82: 88:5d:f0:3d:b4:51:a1:79:33:2b:2e:7b:b9:dc:20:09:13:71: eb:6a:19:5b:cf:e8:a5:30:57:2c:89:49:3f:b9:cf:7f:c9:bf: 3e:22:68:63:53:9a:bd:69:74:ac:c5:1d:3c:7f:92:e0:c3:bc: 1c:d8:04:75
Certificate: Data: Version: 3 (0x2) Serial Number: 65:0a:27:a0:4d:ba:a9:df:0c:06:de:bb:a3:98:30:54 Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https:\/\/www.verisign.com\/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA Validity Not Before: Dec 19 00:00:00 2011 GMT Not After : Dec 31 23:59:59 2014 GMT Subject: C=US, ST=Virginia, L=Alexandria, O=Alawar Entertainment Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=-, CN=Alawar Entertainment Inc Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:8e:9c:98:ca:d4:1b:c1:26:31:99:f8:36:82:21: d1:6c:7c:61:6a:4c:a4:99:75:d2:17:45:b6:96:37: e1:eb:ec:a0:b6:54:6f:f1:00:b8:c0:d1:a1:d1:ac: 98:47:2a:a6:ab:59:5b:c1:d4:84:1b:3c:a8:88:75: e3:68:dc:47:e9:1a:9f:6a:fa:f6:6b:d5:ed:c2:a9: e5:41:8b:86:4f:bd:13:73:1c:fc:e6:eb:0f:92:80: 1c:af:ec:6e:84:69:1c:c4:b2:59:76:52:b4:13:6f: 71:ad:a3:44:f1:86:4c:dc:fa:e6:08:8d:e9:f9:bc: cd:b6:34:b0:b5:8a:1d:4f:a4:73:a4:ec:cf:a8:70: 3c:92:04:ce:8a:db:7a:6a:8e:d8:15:ca:87:c2:dd: bf:11:d6:b2:9a:5c:32:a1:5d:c5:de:2e:25:d6:bb: eb:f2:1d:da:f6:6e:16:f2:32:6f:7c:34:de:fb:80: c9:c0:2f:86:26:0a:b4:db:7d:1d:26:f6:3b:0e:16: 55:45:3c:60:c4:98:ba:82:48:ac:ea:68:9d:7a:a8: 2b:df:ef:14:9b:6d:57:ed:c1:4c:fc:b4:0f:9e:1c: bb:55:3f:83:00:45:c0:11:c2:49:34:1b:ad:13:69: 2a:98:e1:e7:b7:74:5d:85:60:7c:a6:df:ae:45:19: 3c:4f Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: critical Digital Signature X509v3 CRL Distribution Points: Full Name: URI:http://csc3-2010-crl.verisign.com/CSC3-2010.crl X509v3 Certificate Policies: Policy: 2.16.840.1.113733.1.7.23.3 CPS: https://www.verisign.com/rpa X509v3 Extended Key Usage: Code Signing Authority Information Access: OCSP - URI:http://ocsp.verisign.com CA Issuers - URI:http://csc3-2010-aia.verisign.com/CSC3-2010.cer X509v3 Authority Key Identifier: CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D Netscape Cert Type: Object Signing 1.3.6.1.4.1.311.2.1.27: 0....... Signature Algorithm: sha1WithRSAEncryption Signature Value: 2e:ae:99:82:1d:05:7a:b8:d4:09:61:a4:12:4e:2d:42:b1:ab: 24:aa:67:36:b0:68:87:74:37:19:97:31:13:11:e4:69:ac:42: f8:b7:5b:95:ec:16:bf:fd:c6:37:5b:92:6f:6f:9e:f0:bb:a4: 89:b1:74:e3:81:71:c0:05:60:fe:0d:86:4a:6c:a2:03:86:f7: 71:24:82:91:6f:61:98:12:58:26:90:d4:58:cc:52:49:e8:37: d4:cb:46:11:40:52:44:7b:c4:f9:b0:d2:ae:a9:12:1b:3c:98: 80:92:a1:77:94:58:74:25:b9:5f:82:4b:0d:66:60:aa:bd:a6: 7f:f1:4a:7f:98:bf:e2:48:a2:8e:86:c2:44:9f:1b:b7:3d:af: dd:6f:60:0b:e9:bc:d2:e0:9a:72:9e:3b:59:b4:5c:30:91:ab: ec:be:45:08:71:06:71:fa:31:87:f6:cc:08:58:29:34:c5:85: 1c:17:64:60:64:1f:f8:90:b3:5e:3a:16:e2:89:c9:0e:fd:ba: e5:63:d5:b1:a8:a1:64:b0:47:62:ce:38:15:84:b5:eb:fb:b8: a3:cf:f7:2e:9d:99:6f:ef:f6:5c:dd:59:94:47:27:50:ae:19: 70:1c:01:65:32:a2:75:23:0a:2d:21:a0:5c:54:9a:32:d3:3f: ba:dc:e6:e1
Certificate: Data: Version: 3 (0x2) Serial Number: 52:00:e5:aa:25:56:fc:1a:86:ed:96:c9:d4:4b:33:c7 Signature Algorithm: sha1WithRSAEncryption Issuer: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5 Validity Not Before: Feb 8 00:00:00 2010 GMT Not After : Feb 7 23:59:59 2020 GMT Subject: C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=Terms of use at https:\/\/www.verisign.com\/rpa (c)10, CN=VeriSign Class 3 Code Signing 2010 CA Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:f5:23:4b:5e:a5:d7:8a:bb:32:e9:d4:57:f7:ef: e4:c7:26:7e:ad:19:98:fe:a8:9d:7d:94:f6:36:6b: 10:d7:75:81:30:7f:04:68:7f:cb:2b:75:1e:cd:1d: 08:8c:df:69:94:a7:37:a3:9c:7b:80:e0:99:e1:ee: 37:4d:5f:ce:3b:14:ee:86:d4:d0:f5:27:35:bc:25: 0b:38:a7:8c:63:9d:17:a3:08:a5:ab:b0:fb:cd:6a: 62:82:4c:d5:21:da:1b:d9:f1:e3:84:3b:8a:2a:4f: 85:5b:90:01:4f:c9:a7:76:10:7f:27:03:7c:be:ae: 7e:7d:c1:dd:f9:05:bc:1b:48:9c:69:e7:c0:a4:3c: 3c:41:00:3e:df:96:e5:c5:e4:94:71:d6:55:01:c7: 00:26:4a:40:3c:b5:a1:26:a9:0c:a7:6d:80:8e:90: 25:7b:cf:bf:3f:1c:eb:2f:96:fa:e5:87:77:c6:b5: 56:b2:7a:3b:54:30:53:1b:df:62:34:ff:1e:d1:f4: 5a:93:28:85:e5:4c:17:4e:7e:5b:fd:a4:93:99:7f: df:cd:ef:a4:75:ef:ef:15:f6:47:e7:f8:19:72:d8: 2e:34:1a:a6:b4:a7:4c:7e:bd:bb:4f:0c:3d:57:f1: 30:d6:a6:36:8e:d6:80:76:d7:19:2e:a5:cd:7e:34: 2d:89 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: critical CA:TRUE, pathlen:0 X509v3 Certificate Policies: Policy: 2.16.840.1.113733.1.7.23.3 CPS: https://www.verisign.com/cps User Notice: Explicit Text: https://www.verisign.com/rpa X509v3 Key Usage: critical Certificate Sign, CRL Sign 1.3.6.1.5.5.7.1.12: 0_.].[0Y0W0U..image/gif0!0.0...+..............k...j.H.,{..0%.#http://logo.verisign.com/vslogo.gif X509v3 CRL Distribution Points: Full Name: URI:http://crl.verisign.com/pca3-g5.crl Authority Information Access: OCSP - URI:http://ocsp.verisign.com X509v3 Extended Key Usage: TLS Web Client Authentication, Code Signing X509v3 Subject Alternative Name: DirName:/CN=VeriSignMPKI-2-8 X509v3 Subject Key Identifier: CF:99:A9:EA:7B:26:F4:4B:C9:8E:8F:D7:F0:05:26:EF:E3:D2:A7:9D X509v3 Authority Key Identifier: 7F:D3:65:A7:C2:DD:EC:BB:F0:30:09:F3:43:39:FA:02:AF:33:31:33 Signature Algorithm: sha1WithRSAEncryption Signature Value: 56:22:e6:34:a4:c4:61:cb:48:b9:01:ad:56:a8:64:0f:d9:8c: 91:c4:bb:cc:0c:e5:ad:7a:a0:22:7f:df:47:38:4a:2d:6c:d1: 7f:71:1a:7c:ec:70:a9:b1:f0:4f:e4:0f:0c:53:fa:15:5e:fe: 74:98:49:24:85:81:26:1c:91:14:47:b0:4c:63:8c:bb:a1:34: d4:c6:45:e8:0d:85:26:73:03:d0:a9:8c:64:6d:dc:71:92:e6: 45:05:60:15:59:51:39:fc:58:14:6b:fe:d4:a4:ed:79:6b:08: 0c:41:72:e7:37:22:06:09:be:23:e9:3f:44:9a:1e:e9:61:9d: cc:b1:90:5c:fc:3d:d2:8d:ac:42:3d:65:36:d4:b4:3d:40:28: 8f:9b:10:cf:23:26:cc:4b:20:cb:90:1f:5d:8c:4c:34:ca:3c: d8:e5:37:d6:6f:a5:20:bd:34:eb:26:d9:ae:0d:e7:c5:9a:f7: a1:b4:21:91:33:6f:86:e8:58:bb:25:7c:74:0e:58:fe:75:1b: 63:3f:ce:31:7c:9b:8f:1b:96:9e:c5:53:76:84:5b:9c:ad:91: fa:ac:ed:93:ba:5d:c8:21:53:c2:82:53:63:af:12:0d:50:87: 11:1b:3d:54:52:96:8a:2c:9c:3d:92:1a:08:9a:05:2e:c7:93: a5:48:91:d3
- 1
- SHA1: nil
- 1.3.6.1.4.1.311.2.1.4
- #0
- 1.3.6.1.4.1.311.2.1.15
- :
00 3c 00 3c 00 3c 00 4f 00 62 00 73 00 6f 00 6c |.<.<.<.O.b.s.o.l| 00 65 00 74 00 65 00 3e 00 3e 00 3e |.e.t.e.>.>.> |
- :
- SHA1
1e db bd 0b 31 a6 6b 4d 71 71 b9 52 f8 c1 e9 ab |....1.kMqq.R....| ca 18 50 30 |..P0 |
- 1.3.6.1.4.1.311.2.1.15
- #0
- Certificates
- Certificate #0
- 2
- 7E:93:EB:FB:7C:C6:4E:59:EA:4B:9A:77:D4:06:FC:3B
- RSA-SHA1: nil
- Issuer
- C: ZA
- ST: Western Cape
- L: Durbanville
- O: Thawte
- OU: Thawte Certification
- CN: Thawte Timestamping CA
- 2012-12-21 00:00:00 UTC: 2020-12-30 23:59:59 UTC
- Subject
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- #5
- rsaEncryption: nil
- B1:AC:B3:49:54:4B:97:1C:12:0A:D8:25:79:91:22:57:
2A:6F:DC:B8:26:C4:43:73:6B:C2:BF:2E:50:5A:FB:14:
C2:76:8E:43:01:25:43:B4:A1:E2:45:F4:E8:B7:7B:C3:
74:CC:22:D7:B4:94:00:02:F7:4D:ED:BF:B4:B7:44:24:
6B:CD:5F:45:3B:D1:44:CE:43:12:73:17:82:8B:69:B4:
2B:CB:99:1E:AC:72:1B:26:4D:71:1F:B1:31:DD:FB:51:
61:02:53:A6:AA:F5:49:2C:05:78:45:A5:2F:89:CE:E7:
99:E7:FE:8C:E2:57:3F:3D:C6:92:DC:4A:F8:7B:33:E4:
79:0A:FB:F0:75:88:41:9C:FF:C5:03:51:99:AA:D7:6C:
9F:93:69:87:65:29:83:85:C2:60:14:C4:C8:C9:3B:14:
DA:C0:81:F0:1F:0D:74:DE:92:22:AB:CA:F7:FB:74:7C:
27:E6:F7:4A:1B:7F:A7:C3:9E:2D:AE:8A:EA:A6:E6:AA:
27:16:7D:61:F7:98:71:11:BC:E2:50:A1:4B:E5:5D:FA:
E5:0E:A7:2C:9F:AA:65:20:D3:D8:96:E8:C8:7C:A5:4E:
48:44:FF:19:E2:44:07:92:0B:D7:68:84:80:5D:6A:78:
64:45:CD:60:46:7E:54:C1:13:7C:C5:79:F1:C9:C1:71: 0x010001
- #6
- subjectKeyIdentifier:
5f 9a f5 6e 5c cc cc 74 9a d4 dd 7d ef 3f db ec |_..n\..t...}.?..| 4c 80 2e dd |L... |
- authorityInfoAccess
- OCSP: http://ocsp.thawte.com
- basicConstraints
- true
- true: 0
- crlDistributionPoints: http://crl.thawte.com/ThawteTimestampingCA.crl
- extendedKeyUsage: timeStamping
- keyUsage: true, 6
- subjectAltName
- CN: TimeStamp-2048-1
- subjectKeyIdentifier:
- RSA-SHA1:
03 09 9b 8f 79 ef 7f 59 30 aa ef 68 b5 fa e3 09 |....y..Y0..h....| 1d bb 4f 82 06 5d 37 5f a6 52 9f 16 8d ea 1c 92 |..O..]7_.R......| 09 44 6e f5 6d eb 58 7c 30 e8 f9 69 8d 23 73 0b |.Dn.m.X|0..i.#s.| 12 6f 47 a9 ae 39 11 f8 2a b1 9b b0 1a c3 8e eb |.oG..9..*.......| 59 96 00 ad ce 0c 4d b2 d0 31 a6 08 5c 2a 7a fc |Y.....M..1..\*z.| e2 7a 1d 57 4c a8 65 18 e9 79 40 62 25 96 6e c7 |.z.WL.e..y@b%.n.| c7 37 6a 83 21 08 8e 41 ea dd d9 57 3f 1d 77 49 |.7j.!..A...W?.wI| 87 2a 16 06 5e a6 38 6a 22 12 a3 51 19 83 7e b6 |.*..^.8j"..Q..~.|
- 2
- Certificate #1
- 2
- 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
- RSA-SHA1: nil
- Issuer
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- 2012-10-18 00:00:00 UTC: 2020-12-29 23:59:59 UTC
- Subject
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services Signer - G4
- #5
- rsaEncryption: nil
- A2:63:0B:39:44:B8:BB:23:A7:44:49:BB:0E:FF:A1:F0:
61:0A:53:93:B0:98:DB:AD:2C:0F:4A:C5:6E:FF:86:3C:
53:55:0F:15:CE:04:3F:2B:FD:A9:96:96:D9:BE:61:79:
0B:5B:C9:4C:86:76:E5:E0:43:4B:22:95:EE:C2:2B:43:
C1:9F:D8:68:B4:8E:40:4F:EE:85:38:B9:11:C5:23:F2:
64:58:F0:15:32:6F:4E:57:A1:AE:88:A4:02:D7:2A:1E:
CD:4B:E1:DD:63:D5:17:89:32:5B:B0:5E:99:5A:A8:9D:
28:50:0E:17:EE:96:DB:61:3B:45:51:1D:CF:12:56:0B:
92:47:FC:AB:AE:F6:66:3D:47:AC:70:72:E7:92:E7:5F:
CD:10:B9:C4:83:64:94:19:BD:25:80:E1:E8:D2:22:A5:
D0:BA:02:7A:A1:77:93:5B:65:C3:EE:17:74:BC:41:86:
2A:DC:08:4C:8C:92:8C:91:2D:9E:77:44:1F:68:D6:A8:
74:77:DB:0E:5B:32:8B:56:8B:33:BD:D9:63:C8:49:9D:
3A:C5:C5:EA:33:0B:D2:F1:A3:1B:F4:8B:BE:D9:B3:57:
8B:3B:DE:04:A7:7A:22:B2:24:AE:2E:C7:70:C5:BE:4E:
83:26:08:FB:0B:BD:A9:4F:99:08:E1:10:28:72:AA:CD: 0x010001
- X509v3 extensions
- basicConstraints
- true
- nil
- extendedKeyUsage: true, timeStamping
- keyUsage: true, 0x80
- authorityInfoAccess
- #0
- OCSP: http://ts-ocsp.ws.symantec.com
- caIssuers: http://ts-aia.ws.symantec.com/tss-ca-g2.cer
- #0
- crlDistributionPoints: http://ts-crl.ws.symantec.com/tss-ca-g2.crl
- subjectAltName
- CN: TimeStamp-2048-2
- subjectKeyIdentifier:
46 c6 69 a3 0e 4a 14 1e d5 4c da 52 63 17 3f 5e |F.i..J...L.Rc.?^| 36 bc 0d e6 |6... |
- authorityKeyIdentifier:
5f 9a f5 6e 5c cc cc 74 9a d4 dd 7d ef 3f db ec |_..n\..t...}.?..| 4c 80 2e dd |L... |
- basicConstraints
- RSA-SHA1:
78 3b b4 91 2a 00 4c f0 8f 62 30 37 78 a3 84 27 |x;..*.L..b07x..'| 07 6f 18 b2 de 25 dc a0 d4 94 03 aa 86 4e 25 9f |.o...%.......N%.| 9a 40 03 1c dd ce e3 79 cb 21 68 06 da b6 32 b4 |.@.....y.!h...2.| 6d bf f4 2c 26 63 33 e4 49 64 6d 0d e6 c3 67 0e |m..,&c3.Idm...g.| f7 05 a4 35 6c 7c 89 16 c6 e9 b2 df b2 e9 dd 20 |...5l|......... | c6 71 0f cd 95 74 dc b6 5c de bd 37 1f 43 78 e6 |.q...t..\..7.Cx.| 78 b5 cd 28 04 20 a3 aa f1 4b c4 88 29 91 0e 80 |x..(. ...K..)...| d1 11 fc dd 5c 76 6e 4f 5e 0e 45 46 41 6e 0d b0 |....\vnO^.EFAn..| ea 38 9a b1 3a da 09 71 10 fc 1c 79 b4 80 7b ac |.8..:..q...y..{.| 69 f4 fd 9c b6 0c 16 2b f1 7f 5b 09 3d 9b 5b e2 |i......+..[.=.[.| 16 ca 13 81 6d 00 2e 38 0d a8 29 8f 2c e1 b2 f4 |....m..8..).,...| 5a a9 01 af 15 9c 2c 2f 49 1b db 22 bb c3 fe 78 |Z.....,/I.."...x| 94 51 c3 86 b1 82 88 5d f0 3d b4 51 a1 79 33 2b |.Q.....].=.Q.y3+| 2e 7b b9 dc 20 09 13 71 eb 6a 19 5b cf e8 a5 30 |.{.. ..q.j.[...0| 57 2c 89 49 3f b9 cf 7f c9 bf 3e 22 68 63 53 9a |W,.I?.....>"hcS.| bd 69 74 ac c5 1d 3c 7f 92 e0 c3 bc 1c d8 04 75 |.it...<........u|
- 2
- Certificate #2
- 2
- 65:0A:27:A0:4D:BA:A9:DF:0C:06:DE:BB:A3:98:30:54
- RSA-SHA1: nil
- Issuer
- C: US
- O: VeriSign, Inc.
- OU: VeriSign Trust Network
- OU: Terms of use at https://www.verisign.com/rpa (c)10
- CN: VeriSign Class 3 Code Signing 2010 CA
- 2011-12-19 00:00:00 UTC: 2014-12-31 23:59:59 UTC
- Subject
- C: US
- ST: Virginia
- L: Alexandria
- O: Alawar Entertainment Inc
- OU: Digital ID Class 3 - Microsoft Software Validation v2
- OU: -
- CN: Alawar Entertainment Inc
- #5
- rsaEncryption: nil
- 8E:9C:98:CA:D4:1B:C1:26:31:99:F8:36:82:21:D1:6C:
7C:61:6A:4C:A4:99:75:D2:17:45:B6:96:37:E1:EB:EC:
A0:B6:54:6F:F1:00:B8:C0:D1:A1:D1:AC:98:47:2A:A6:
AB:59:5B:C1:D4:84:1B:3C:A8:88:75:E3:68:DC:47:E9:
1A:9F:6A:FA:F6:6B:D5:ED:C2:A9:E5:41:8B:86:4F:BD:
13:73:1C:FC:E6:EB:0F:92:80:1C:AF:EC:6E:84:69:1C:
C4:B2:59:76:52:B4:13:6F:71:AD:A3:44:F1:86:4C:DC:
FA:E6:08:8D:E9:F9:BC:CD:B6:34:B0:B5:8A:1D:4F:A4:
73:A4:EC:CF:A8:70:3C:92:04:CE:8A:DB:7A:6A:8E:D8:
15:CA:87:C2:DD:BF:11:D6:B2:9A:5C:32:A1:5D:C5:DE:
2E:25:D6:BB:EB:F2:1D:DA:F6:6E:16:F2:32:6F:7C:34:
DE:FB:80:C9:C0:2F:86:26:0A:B4:DB:7D:1D:26:F6:3B:
0E:16:55:45:3C:60:C4:98:BA:82:48:AC:EA:68:9D:7A:
A8:2B:DF:EF:14:9B:6D:57:ED:C1:4C:FC:B4:0F:9E:1C:
BB:55:3F:83:00:45:C0:11:C2:49:34:1B:AD:13:69:2A:
98:E1:E7:B7:74:5D:85:60:7C:A6:DF:AE:45:19:3C:4F: 0x010001
- X509v3 extensions
- basicConstraints
- nil
- keyUsage: true, 0x80
- crlDistributionPoints: http://csc3-2010-crl.verisign.com/CSC3-2010.crl
- certificatePolicies
- 2.16.840.1.113733.1.7.23.3
- id-qt-cps: https://www.verisign.com/rpa
- 2.16.840.1.113733.1.7.23.3
- extendedKeyUsage: codeSigning
- authorityInfoAccess
- #0
- OCSP: http://ocsp.verisign.com
- caIssuers: http://csc3-2010-aia.verisign.com/CSC3-2010.cer
- #0
- authorityKeyIdentifier:
cf 99 a9 ea 7b 26 f4 4b c9 8e 8f d7 f0 05 26 ef |....{&.K......&.| e3 d2 a7 9d |.... |
- nsCertType: 0x10
- 1.3.6.1.4.1.311.2.1.27
- false: true
- basicConstraints
- RSA-SHA1:
2e ae 99 82 1d 05 7a b8 d4 09 61 a4 12 4e 2d 42 |......z...a..N-B| b1 ab 24 aa 67 36 b0 68 87 74 37 19 97 31 13 11 |..$.g6.h.t7..1..| e4 69 ac 42 f8 b7 5b 95 ec 16 bf fd c6 37 5b 92 |.i.B..[......7[.| 6f 6f 9e f0 bb a4 89 b1 74 e3 81 71 c0 05 60 fe |oo......t..q..`.| 0d 86 4a 6c a2 03 86 f7 71 24 82 91 6f 61 98 12 |..Jl....q$..oa..| 58 26 90 d4 58 cc 52 49 e8 37 d4 cb 46 11 40 52 |X&..X.RI.7..F.@R| 44 7b c4 f9 b0 d2 ae a9 12 1b 3c 98 80 92 a1 77 |D{........<....w| 94 58 74 25 b9 5f 82 4b 0d 66 60 aa bd a6 7f f1 |.Xt%._.K.f`.....| 4a 7f 98 bf e2 48 a2 8e 86 c2 44 9f 1b b7 3d af |J....H....D...=.| dd 6f 60 0b e9 bc d2 e0 9a 72 9e 3b 59 b4 5c 30 |.o`......r.;Y.\0| 91 ab ec be 45 08 71 06 71 fa 31 87 f6 cc 08 58 |....E.q.q.1....X| 29 34 c5 85 1c 17 64 60 64 1f f8 90 b3 5e 3a 16 |)4....d`d....^:.| e2 89 c9 0e fd ba e5 63 d5 b1 a8 a1 64 b0 47 62 |.......c....d.Gb| ce 38 15 84 b5 eb fb b8 a3 cf f7 2e 9d 99 6f ef |.8............o.| f6 5c dd 59 94 47 27 50 ae 19 70 1c 01 65 32 a2 |.\.Y.G'P..p..e2.| 75 23 0a 2d 21 a0 5c 54 9a 32 d3 3f ba dc e6 e1 |u#.-!.\T.2.?....|
- 2
- Certificate #3
- 2
- 52:00:E5:AA:25:56:FC:1A:86:ED:96:C9:D4:4B:33:C7
- RSA-SHA1: nil
- Issuer
- C: US
- O: VeriSign, Inc.
- OU: VeriSign Trust Network
- OU: (c) 2006 VeriSign, Inc. - For authorized use only
- CN: VeriSign Class 3 Public Primary Certification Authority - G5
- 2010-02-08 00:00:00 UTC: 2020-02-07 23:59:59 UTC
- Subject
- C: US
- O: VeriSign, Inc.
- OU: VeriSign Trust Network
- OU: Terms of use at https://www.verisign.com/rpa (c)10
- CN: VeriSign Class 3 Code Signing 2010 CA
- #5
- rsaEncryption: nil
- F5:23:4B:5E:A5:D7:8A:BB:32:E9:D4:57:F7:EF:E4:C7:
26:7E:AD:19:98:FE:A8:9D:7D:94:F6:36:6B:10:D7:75:
81:30:7F:04:68:7F:CB:2B:75:1E:CD:1D:08:8C:DF:69:
94:A7:37:A3:9C:7B:80:E0:99:E1:EE:37:4D:5F:CE:3B:
14:EE:86:D4:D0:F5:27:35:BC:25:0B:38:A7:8C:63:9D:
17:A3:08:A5:AB:B0:FB:CD:6A:62:82:4C:D5:21:DA:1B:
D9:F1:E3:84:3B:8A:2A:4F:85:5B:90:01:4F:C9:A7:76:
10:7F:27:03:7C:BE:AE:7E:7D:C1:DD:F9:05:BC:1B:48:
9C:69:E7:C0:A4:3C:3C:41:00:3E:DF:96:E5:C5:E4:94:
71:D6:55:01:C7:00:26:4A:40:3C:B5:A1:26:A9:0C:A7:
6D:80:8E:90:25:7B:CF:BF:3F:1C:EB:2F:96:FA:E5:87:
77:C6:B5:56:B2:7A:3B:54:30:53:1B:DF:62:34:FF:1E:
D1:F4:5A:93:28:85:E5:4C:17:4E:7E:5B:FD:A4:93:99:
7F:DF:CD:EF:A4:75:EF:EF:15:F6:47:E7:F8:19:72:D8:
2E:34:1A:A6:B4:A7:4C:7E:BD:BB:4F:0C:3D:57:F1:30:
D6:A6:36:8E:D6:80:76:D7:19:2E:A5:CD:7E:34:2D:89: 0x010001
- X509v3 extensions
- basicConstraints
- true
- true: 0
- certificatePolicies
- 2.16.840.1.113733.1.7.23.3
- #0
- id-qt-cps: https://www.verisign.com/cps
- id-qt-unotice: https://www.verisign.com/rpa
- #0
- 2.16.840.1.113733.1.7.23.3
- keyUsage: true, 6
- 1.3.6.1.5.5.7.1.12
- image/gif
- SHA1:
8f e5 d3 1a 86 ac 8d 8e 6b c3 cf 80 6a d4 48 18 |........k...j.H.| 2c 7b 19 2e |,{.. |
- http://logo.verisign.com/vslogo.gif
- SHA1:
- image/gif
- crlDistributionPoints: http://crl.verisign.com/pca3-g5.crl
- authorityInfoAccess
- OCSP: http://ocsp.verisign.com
- extendedKeyUsage
- clientAuth: codeSigning
- subjectAltName
- CN: VeriSignMPKI-2-8
- subjectKeyIdentifier:
cf 99 a9 ea 7b 26 f4 4b c9 8e 8f d7 f0 05 26 ef |....{&.K......&.| e3 d2 a7 9d |.... |
- authorityKeyIdentifier:
7f d3 65 a7 c2 dd ec bb f0 30 09 f3 43 39 fa 02 |..e......0..C9..| af 33 31 33 |.313 |
- basicConstraints
- RSA-SHA1:
56 22 e6 34 a4 c4 61 cb 48 b9 01 ad 56 a8 64 0f |V".4..a.H...V.d.| d9 8c 91 c4 bb cc 0c e5 ad 7a a0 22 7f df 47 38 |.........z."..G8| 4a 2d 6c d1 7f 71 1a 7c ec 70 a9 b1 f0 4f e4 0f |J-l..q.|.p...O..| 0c 53 fa 15 5e fe 74 98 49 24 85 81 26 1c 91 14 |.S..^.t.I$..&...| 47 b0 4c 63 8c bb a1 34 d4 c6 45 e8 0d 85 26 73 |G.Lc...4..E...&s| 03 d0 a9 8c 64 6d dc 71 92 e6 45 05 60 15 59 51 |....dm.q..E.`.YQ| 39 fc 58 14 6b fe d4 a4 ed 79 6b 08 0c 41 72 e7 |9.X.k....yk..Ar.| 37 22 06 09 be 23 e9 3f 44 9a 1e e9 61 9d cc b1 |7"...#.?D...a...| 90 5c fc 3d d2 8d ac 42 3d 65 36 d4 b4 3d 40 28 |.\.=...B=e6..=@(| 8f 9b 10 cf 23 26 cc 4b 20 cb 90 1f 5d 8c 4c 34 |....#&.K ...].L4| ca 3c d8 e5 37 d6 6f a5 20 bd 34 eb 26 d9 ae 0d |.<..7.o. .4.&...| e7 c5 9a f7 a1 b4 21 91 33 6f 86 e8 58 bb 25 7c |......!.3o..X.%|| 74 0e 58 fe 75 1b 63 3f ce 31 7c 9b 8f 1b 96 9e |t.X.u.c?.1|.....| c5 53 76 84 5b 9c ad 91 fa ac ed 93 ba 5d c8 21 |.Sv.[........].!| 53 c2 82 53 63 af 12 0d 50 87 11 1b 3d 54 52 96 |S..Sc...P...=TR.| 8a 2c 9c 3d 92 1a 08 9a 05 2e c7 93 a5 48 91 d3 |.,.=.........H..|
- 2
- Certificate #0
- Signer
- 1
- unnamed
- #0
- C: US
- O: VeriSign, Inc.
- OU: VeriSign Trust Network
- OU: Terms of use at https://www.verisign.com/rpa (c)10
- CN: VeriSign Class 3 Code Signing 2010 CA
- 65:0A:27:A0:4D:BA:A9:DF:0C:06:DE:BB:A3:98:30:54
- #0
- SHA1: nil
- #3
- contentType: 1.3.6.1.4.1.311.2.1.4
- 1.3.6.1.4.1.311.2.1.11: msCodeInd
- messageDigest:
e5 06 85 25 53 b3 61 cf fe f0 69 1e 56 55 92 56 |...%S.a...i.VU.V| ba e2 e6 8e |.... |
- 1.3.6.1.4.1.311.2.1.12:
04 1c 04 30 04 33 04 38 04 47 04 35 04 41 04 3a |...0.3.8.G.5.A.:| 04 30 04 4f 00 20 04 4d 04 3d 04 46 04 38 04 3a |.0.O. .M.=.F.8.:| 04 3b 04 3e 04 3f 04 35 04 34 04 38 04 4f 00 2e |.;.>.?.5.4.8.O..| 00 20 04 18 04 3b 04 3b 04 4e 04 37 04 38 04 38 |. ...;.;.N.7.8.8|
- rsaEncryption:
52 7b 43 08 14 83 12 d4 4c bc 65 47 a8 76 17 e7 |R{C.....L.eG.v..| 4e 79 57 e3 50 e4 50 6d bf b7 a5 5f 45 5f 36 6e |NyW.P.Pm..._E_6n| 24 0e 91 d3 a2 d3 6b b1 32 07 c2 db bb e7 0b 79 |$.....k.2......y| 55 1f 17 9b 1b ea bc 31 76 4e fc 74 9d d5 6a 58 |U......1vN.t..jX| a0 ba 09 c6 6d 63 23 14 54 0b 74 24 ad d4 23 19 |....mc#.T.t$..#.| d2 5f a6 23 6c e7 a6 e0 a5 da ff 36 d0 24 07 54 |._.#l......6.$.T| 22 b9 68 76 9a d4 6a e0 ba de 4b 7d 1e 8d 0a 1e |".hv..j...K}....| a9 81 0a d4 87 63 5d c3 7a 09 27 64 f2 bc 74 1e |.....c].z.'d..t.| 76 3d 08 ba e6 33 96 39 7b ac bd 75 e0 18 89 fc |v=...3.9{..u....| 07 d9 44 ee 92 c5 9e d8 08 ec 3f 30 9f 5d 03 8c |..D.......?0.]..| 33 91 07 f0 53 e5 72 eb 35 d7 89 f0 25 3c 37 8f |3...S.r.5...%<7.| 76 be c2 48 69 2c 00 60 41 46 98 67 53 47 ef 2f |v..Hi,.`AF.gSG./| 0e b1 fd 6c bc e4 47 2e 89 79 89 a7 df 7a f0 89 |...l..G..y...z..| 27 2e 99 93 07 6e 88 ab 64 eb 7c 01 dc 68 94 f8 |'....n..d.|..h..| 0f 66 7c 6f d6 58 f1 5e 03 54 4e 0d 67 b9 57 a9 |.f|o.X.^.TN.g.W.| 18 43 51 55 08 49 b0 bc 7f 96 04 2a 52 f1 05 68 |.CQU.I.....*R..h|
- countersignature
- 1
- unnamed
- #0
- C: US
- O: Symantec Corporation
- CN: Symantec Time Stamping Services CA - G2
- 0E:CF:F4:38:C8:FE:BF:35:6E:04:D8:6A:98:1B:1A:50
- #0
- SHA1: nil
- #2
- contentType: pkcs7-data
- signingTime: 2013-01-11 10:35:27 UTC
- messageDigest:
4d 05 a9 96 02 16 02 73 58 ee 32 0b 42 19 60 ff |M......sX.2.B.`.| 12 95 84 fe |.... |
- rsaEncryption:
77 19 dd d3 55 fd c1 9b 02 0d 72 0a 03 76 fd 52 |w...U.....r..v.R| 3c 71 6a b9 92 31 a4 e4 69 7a 45 85 57 9a 3b d8 |
- unnamed
- 1
offset | size | type | comment | |
---|---|---|---|---|
0 | 2080256 | EXE | 10/05/2012 07:17:24 | # |
15c1 | 15 | HTM | # | |
1fbe00 | 6536 | PKCS7 | Authenticode Signature | # |
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x1afa64
[?] can't find file_offset of VA 0x1afd98
[?] can't find file_offset of VA 0x1afed8
[?] can't find file_offset of VA 0x1aff4c
[?] can't find file_offset of VA 0x1b008c
[?] can't find file_offset of VA 0x1b0440
[?] can't find file_offset of VA 0x1b1c10
[?] can't find file_offset of VA 0x1b4124
[?] can't find file_offset of VA 0x1bab60
[?] can't find file_offset of VA 0x1baff4
[?] can't find file_offset of VA 0x1bbd58
[?] can't find file_offset of VA 0x1bbe3c
[?] can't find file_offset of VA 0x1bc1b4
[?] can't find file_offset of VA 0x1bc77c
[?] can't find file_offset of VA 0x1be1ec
[?] can't find file_offset of VA 0x1be33c
[?] can't find file_offset of VA 0x1be9c0
[?] can't find file_offset of VA 0x1d205c
[?] can't find file_offset of VA 0x1e56f8
[?] can't find file_offset of VA 0x1f8d94
[?] can't find file_offset of VA 0x1f9468
[?] can't find file_offset of VA 0x20cb0c
[?] can't find file_offset of VA 0x2201b0
[?] can't find file_offset of VA 0x233854
[?] can't find file_offset of VA 0x235298
[?] can't find file_offset of VA 0x237078
[?] can't find file_offset of VA 0x24a714
[?] can't find file_offset of VA 0x25ddb0
[?] can't find file_offset of VA 0x25ff4c
[?] can't find file_offset of VA 0x2735e8
[?] can't find file_offset of VA 0x286c84
[?] can't find file_offset of VA 0x29a320
[?] can't find file_offset of VA 0x2ad9bc
[?] can't find file_offset of VA 0x2c1058
[?] can't find file_offset of VA 0x2c1c7c
[?] can't find file_offset of VA 0x2c237c
[?] can't find file_offset of VA 0x2c33e8
[?] can't find file_offset of VA 0x2c3d48
[?] can't find file_offset of VA 0x2c4a48
[?] can't find file_offset of VA 0x2c5634
[?] can't find file_offset of VA 0x2c6c78
[?] can't find file_offset of VA 0x2c7e98
[?] can't find file_offset of VA 0x2c9018
[?] can't find file_offset of VA 0x2c9ad8
[?] can't find file_offset of VA 0x2cb080
[?] can't find file_offset of VA 0x2cc010
[?] can't find file_offset of VA 0x2ccc4c
[?] can't find file_offset of VA 0x2cd354
[?] can't find file_offset of VA 0x2ce214
[?] can't find file_offset of VA 0x2ce7e4
[?] can't find file_offset of VA 0x2cfa3c
[?] can't find file_offset of VA 0x2d108c
[?] can't find file_offset of VA 0x2d2134
[?] can't find file_offset of VA 0x2d28d8
[?] can't find file_offset of VA 0x2d34fc
[?] can't find file_offset of VA 0x2d3b24
[?] can't find file_offset of VA 0x2d48d0
[?] can't find file_offset of VA 0x2d512c
[?] can't find file_offset of VA 0x2d6004
[?] can't find file_offset of VA 0x2d677c
[?] can't find file_offset of VA 0x2d7820
[?] can't find file_offset of VA 0x2d82b0
[?] can't find file_offset of VA 0x2d8fb0
[?] can't find file_offset of VA 0x2da084
[?] can't find file_offset of VA 0x2daf1c
[?] can't find file_offset of VA 0x2db49c
[?] can't find file_offset of VA 0x2dbe38
[?] can't find file_offset of VA 0x2dd100
[?] can't find file_offset of VA 0x2ddf3c
[?] can't find file_offset of VA 0x2ded78
[?] can't find file_offset of VA 0x2df74c
[?] can't find file_offset of VA 0x2e0340
[?] can't find file_offset of VA 0x2e132c
[?] can't find file_offset of VA 0x2e1d9c
[?] can't find file_offset of VA 0x2e2c10
[?] can't find file_offset of VA 0x2e4020
[?] can't find file_offset of VA 0x2e5078
[?] can't find file_offset of VA 0x2e5ac4
[?] can't find file_offset of VA 0x2e694c
[?] can't find file_offset of VA 0x2e7694
[?] can't find file_offset of VA 0x2e8918
[?] can't find file_offset of VA 0x2e9604
[?] can't find file_offset of VA 0x2ea598
[?] can't find file_offset of VA 0x2eaf88
[?] can't find file_offset of VA 0x2ec028
[?] can't find file_offset of VA 0x2ecbc4
[?] can't find file_offset of VA 0x2edad4
[?] can't find file_offset of VA 0x2ee560
[?] can't find file_offset of VA 0x2ef518
[?] can't find file_offset of VA 0x2f024c
[?] can't find file_offset of VA 0x2f1b78
[?] can't find file_offset of VA 0x2f25e4
[?] can't find file_offset of VA 0x305c80
[?] can't find file_offset of VA 0x319324
[?] can't find file_offset of VA 0x32c9c0
[?] can't find file_offset of VA 0x34005c
[?] can't find file_offset of VA 0x3536f8
[?] can't find file_offset of VA 0x366d94
[?] can't find file_offset of VA 0x37a430
[?] can't find file_offset of VA 0x37af24
[?] can't find file_offset of VA 0x38e5c8
[?] too many errors getting resource data, stopped on 0 of 1
[?] can't find file_offset of VA 0x0