| filename | server_protected.exe | |
|---|---|---|
| size | 1542656 (0x178a00) | |
| md5 | 2d1e75644a400651df2a737a006f7488 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x50 |
| blocks_in_file | 2 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0xf |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0x1a |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x100 |
DOS stub
00000000: ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 |........!..L.!..| 00000010: 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 |This program mus| 00000020: 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 |t be run under W| 00000030: 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |in32..$7........| 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 000000c0:
PE Header
Packer / Compiler
Enigma Protector 1.1X-1.3X (Sukhov Vladimir & Serge N. Markin) |
Sections
Data Directory
TLS
| raw start | raw end | index | callbks | zero fill | flags | |
|---|---|---|---|---|---|---|
| 0x4a5000 | 0x4a5038 | 0x770018 | 0x770020 | 0 | 0 |
| id | lang | string |
|---|---|---|
| 65312 | 0 | DCOM not installed |
| 65313 | 0 | Unable to find a Table of Contents |
| 65314 | 0 | No help found for %s |
| 65315 | 0 | No context-sensitive help installed |
| 65316 | 0 | No help found for context |
| 65317 | 0 | No topic-based help system installed |
| 65318 | 0 | Unable to retrieve a pointer to a running object registered with OLE for %s/%s |
| 65328 | 0 | Shift+ |
| 65329 | 0 | Ctrl+ |
| 65330 | 0 | Alt+ |
| 65331 | 0 | Invalid clipboard format |
| 65332 | 0 | Clipboard does not support Icons |
| 65333 | 0 | Cannot open clipboard |
| 65334 | 0 | Menu '%s' is already being used by another form |
| 65335 | 0 | Docked control must have a name |
| 65336 | 0 | Error removing control from dock tree |
| 65337 | 0 | - Dock zone not found |
| 65338 | 0 | - Dock zone has no control |
| 65339 | 0 | Error loading dock zone from the stream. Expecting version %d, but found %d. |
| 65340 | 0 | OLE error %.8x |
| 65341 | 0 | Method '%s' not supported by automation object |
| 65342 | 0 | Variant does not reference an automation object |
| 65343 | 0 | Dispatch methods do not support more than 64 parameters |
| 65344 | 0 | Yes to &All |
| 65345 | 0 | BkSp |
| 65346 | 0 | Tab |
| 65347 | 0 | Esc |
| 65348 | 0 | Enter |
| 65349 | 0 | Space |
| 65350 | 0 | PgUp |
| 65351 | 0 | PgDn |
| 65352 | 0 | End |
| 65353 | 0 | Home |
| 65354 | 0 | Left |
| 65355 | 0 | Up |
| 65356 | 0 | Right |
| 65357 | 0 | Down |
| 65358 | 0 | Ins |
| 65359 | 0 | Del |
| 65360 | 0 | A control cannot have itself as its parent |
| 65361 | 0 | Cannot drag a form |
| 65362 | 0 | Warning |
| 65363 | 0 | Error |
| 65364 | 0 | Information |
| 65365 | 0 | Confirm |
| 65366 | 0 | &Yes |
| 65367 | 0 | &No |
| 65368 | 0 | OK |
| 65369 | 0 | Cancel |
| 65370 | 0 | &Help |
| 65371 | 0 | &Abort |
| 65372 | 0 | &Retry |
| 65373 | 0 | &Ignore |
| 65374 | 0 | &All |
| 65375 | 0 | N&o to All |
| 65376 | 0 | Invalid ImageList Index |
| 65377 | 0 | Failed to read ImageList data from stream |
| 65378 | 0 | Failed to write ImageList data to stream |
| 65379 | 0 | Error creating window device context |
| 65380 | 0 | Error creating window class |
| 65381 | 0 | Cannot focus a disabled or invisible window |
| 65382 | 0 | Control '%s' has no parent window |
| 65383 | 0 | Cannot hide an MDI Child Form |
| 65384 | 0 | Cannot change Visible in OnShow or OnHide |
| 65385 | 0 | Cannot make a visible window modal |
| 65386 | 0 | Menu index out of range |
| 65387 | 0 | Menu inserted twice |
| 65388 | 0 | Sub-menu is not in menu |
| 65389 | 0 | Not enough timers available |
| 65390 | 0 | GroupIndex cannot be less than a previous menu item's GroupIndex |
| 65391 | 0 | Cannot create form. No MDI forms are currently active |
| 65392 | 0 | %s not in a class registration group |
| 65393 | 0 | Property %s does not exist |
| 65394 | 0 | Stream write error |
| 65395 | 0 | Thread creation error: %s |
| 65396 | 0 | Thread Error: %s (%d) |
| 65397 | 0 | Bitmap image is not valid |
| 65398 | 0 | Icon image is not valid |
| 65399 | 0 | Metafile is not valid |
| 65400 | 0 | Invalid pixel format |
| 65401 | 0 | Scan line index out of range |
| 65402 | 0 | Cannot change the size of an icon |
| 65403 | 0 | Unsupported clipboard format |
| 65404 | 0 | Out of system resources |
| 65405 | 0 | Canvas does not allow drawing |
| 65406 | 0 | Invalid image size |
| 65407 | 0 | Invalid ImageList |
| 65408 | 0 | Invalid property path |
| 65409 | 0 | Invalid property value |
| 65410 | 0 | Invalid data type for '%s' |
| 65411 | 0 | List capacity out of bounds (%d) |
| 65412 | 0 | List count out of bounds (%d) |
| 65413 | 0 | List index out of bounds (%d) |
| 65414 | 0 | Out of memory while expanding memory stream |
| 65415 | 0 | Error reading %s%s%s: %s |
| 65416 | 0 | Stream read error |
| 65417 | 0 | Property is read-only |
| 65418 | 0 | Failed to create key %s |
| 65419 | 0 | Failed to get data for '%s' |
| 65420 | 0 | Failed to set data for '%s' |
| 65421 | 0 | Resource %s not found |
| 65422 | 0 | %s.Seek not implemented |
| 65423 | 0 | Operation not allowed on sorted list |
| 65424 | 0 | Saturday |
| 65425 | 0 | Unable to create directory |
| 65426 | 0 | Ancestor for '%s' not found |
| 65427 | 0 | Cannot assign a %s to a %s |
| 65428 | 0 | Bits index out of range |
| 65429 | 0 | Can't write to a read-only resource stream |
| 65430 | 0 | CheckSynchronize called from thread $%x, which is NOT the main thread |
| 65431 | 0 | Class %s not found |
| 65432 | 0 | A class named %s already exists |
| 65433 | 0 | List does not allow duplicates ($0%x) |
| 65434 | 0 | A component named %s already exists |
| 65435 | 0 | String list does not allow duplicates |
| 65436 | 0 | Cannot create file "%s". %s |
| 65437 | 0 | Cannot open file "%s". %s |
| 65438 | 0 | Invalid stream format |
| 65439 | 0 | ''%s'' is not a valid component name |
| 65440 | 0 | October |
| 65441 | 0 | November |
| 65442 | 0 | December |
| 65443 | 0 | Sun |
| 65444 | 0 | Mon |
| 65445 | 0 | Tue |
| 65446 | 0 | Wed |
| 65447 | 0 | Thu |
| 65448 | 0 | Fri |
| 65449 | 0 | Sat |
| 65450 | 0 | Sunday |
| 65451 | 0 | Monday |
| 65452 | 0 | Tuesday |
| 65453 | 0 | Wednesday |
| 65454 | 0 | Thursday |
| 65455 | 0 | Friday |
| 65456 | 0 | Jun |
| 65457 | 0 | Jul |
| 65458 | 0 | Aug |
| 65459 | 0 | Sep |
| 65460 | 0 | Oct |
| 65461 | 0 | Nov |
| 65462 | 0 | Dec |
| 65463 | 0 | January |
| 65464 | 0 | February |
| 65465 | 0 | March |
| 65466 | 0 | April |
| 65467 | 0 | May |
| 65468 | 0 | June |
| 65469 | 0 | July |
| 65470 | 0 | August |
| 65471 | 0 | September |
| 65472 | 0 | Unexpected variant error |
| 65473 | 0 | External exception %x |
| 65474 | 0 | Assertion failed |
| 65475 | 0 | Interface not supported |
| 65476 | 0 | Exception in safecall method |
| 65477 | 0 | %s (%s, line %d) |
| 65478 | 0 | Abstract Error |
| 65479 | 0 | Access violation at address %p in module '%s'. %s of address %p |
| 65480 | 0 | System Error. Code: %d. %s |
| 65481 | 0 | A call to an OS function failed |
| 65482 | 0 | Application is not licensed to use this feature |
| 65483 | 0 | Jan |
| 65484 | 0 | Feb |
| 65485 | 0 | Mar |
| 65486 | 0 | Apr |
| 65487 | 0 | May |
| 65488 | 0 | No argument for format '%s' |
| 65489 | 0 | Variant method calls not supported |
| 65490 | 0 | Read |
| 65491 | 0 | Write |
| 65492 | 0 | Error creating variant or safe array |
| 65493 | 0 | Variant or safe array index out of bounds |
| 65494 | 0 | Variant or safe array is locked |
| 65495 | 0 | Invalid variant type conversion |
| 65496 | 0 | Invalid variant operation |
| 65497 | 0 | Invalid variant operation (%s%.8x) %s |
| 65498 | 0 | Could not convert variant of type (%s) into type (%s) |
| 65499 | 0 | Overflow while converting variant of type (%s) into type (%s) |
| 65500 | 0 | Variant overflow |
| 65501 | 0 | Invalid argument |
| 65502 | 0 | Invalid variant type |
| 65503 | 0 | Operation not supported |
| 65504 | 0 | Range check error |
| 65505 | 0 | Integer overflow |
| 65506 | 0 | Invalid floating point operation |
| 65507 | 0 | Floating point division by zero |
| 65508 | 0 | Floating point overflow |
| 65509 | 0 | Floating point underflow |
| 65510 | 0 | Invalid pointer operation |
| 65511 | 0 | Invalid class typecast |
| 65512 | 0 | Access violation at address %p. %s of address %p |
| 65513 | 0 | Access violation |
| 65514 | 0 | Stack overflow |
| 65515 | 0 | Control-C hit |
| 65516 | 0 | Privileged instruction |
| 65517 | 0 | Exception %s in module %s at %p. %s%s |
| 65518 | 0 | Application Error |
| 65519 | 0 | Format '%s' invalid or incompatible with argument |
| 65520 | 0 | '%s' is not a valid integer value |
| 65521 | 0 | '%s' is not a valid floating point value |
| 65522 | 0 | '%s' is not a valid date and time |
| 65523 | 0 | '%s' is not a valid GUID value |
| 65524 | 0 | Invalid argument to time encode |
| 65525 | 0 | Invalid argument to date encode |
| 65526 | 0 | Out of memory |
| 65527 | 0 | I/O error %d |
| 65528 | 0 | File not found |
| 65529 | 0 | Invalid filename |
| 65530 | 0 | Too many open files |
| 65531 | 0 | File access denied |
| 65532 | 0 | Read beyond end of file |
| 65533 | 0 | Disk full |
| 65534 | 0 | Invalid numeric input |
| 65535 | 0 | Division by zero |
| module_name | hint | ord | function_name |
|---|---|---|---|
| kernel32.dll | GetModuleHandleA | ||
| kernel32.dll | GetProcAddress | ||
| kernel32.dll | ExitProcess | ||
| kernel32.dll | LoadLibraryA | ||
| user32.dll | MessageBoxA | ||
| advapi32.dll | RegCloseKey | ||
| oleaut32.dll | SysFreeString | ||
| gdi32.dll | CreateFontA | ||
| shell32.dll | ShellExecuteA | ||
| version.dll | GetFileVersionInfoA | ||
| wsock32.dll | __WSAFDIsSet | ||
| ole32.dll | CoTaskMemFree | ||
| urlmon.dll | URLDownloadToFileA | ||
| comctl32.dll | _TrackMouseEvent | ||
| wininet.dll | InternetReadFile | ||
| winmm.dll | waveInUnprepareHeader | ||
| netapi32.dll | Netbios | ||
| gdiplus.dll | GdipGetImageEncoders | ||
| msacm32.dll | acmStreamUnprepareHeader | ||
| ntdll.dll | NtQuerySystemInformation | ||
| ws2_32.dll | WSAIoctl | ||
| shfolder.dll | SHGetFolderPathA | ||
| ntdll | NtUnmapViewOfSection | ||
| avicap32.dll | capGetDriverDescriptionA |
StringTable 040904b0
| Comments | Remote Service Application |
| CompanyName | Microsoft Corp. |
| FileDescription | Remote Service Application |
| FileVersion | 1, 0, 0, 1 |
| InternalName | MSRSAAPP |
| LegalCopyright | Copyright (C) 1999 |
| OriginalFilename | MSRSAAP.EXE |
| ProductName | Remote Service Application |
| ProductVersion | 4, 0, 0, 0 |
VS_FIXEDFILEINFO
| FileVersion | 4.0.0.0 |
| ProductVersion | 4.0.0.0 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] can't find file_offset of VA 0xb0a58
[?] can't find file_offset of VA 0xb0b8c
[?] can't find file_offset of VA 0xb0cc0
[?] can't find file_offset of VA 0xb0df4
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0xb3440
[?] can't find file_offset of VA 0xb362c
[?] can't find file_offset of VA 0xb363c
[?] can't find file_offset of VA 0xb3e30
[?] can't find file_offset of VA 0xb3e44
[?] can't find file_offset of VA 0xb3e58
[?] can't find file_offset of VA 0xb3e6c
[?] can't find file_offset of VA 0xb3e80
[?] can't find file_offset of VA 0xb3e94
[?] can't find file_offset of VA 0xb3ea8
offset:( 0x )