filename | fundelete.exe | |
---|---|---|
size | 892690 (0xd9f12) | |
md5 | 478c61f24215c3528c6621df8d0f5011 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x9fc4 | 0xa000 | R-X CODE | |
.rdata | 0xb000 | 0x33f | 0x400 | R-- IDATA | |
.data | 0xc000 | 0x44d8 | 0x2a00 | RW- IDATA | |
.idata | 0x11000 | 0xd9a | 0xe00 | RW- IDATA | |
.rsrc | 0x12000 | 0xa0a4 | 0xa200 | R-- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x11000 | 0xa0 | |
RESOURCE | 0x12000 | 0xa0a4 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0x112c0 | 0x220 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
id | lang | string |
---|---|---|
1 | 1033 | PackageForTheWeb Error |
2 | 1033 | This self-extracting executable file has been corrupted. The installation will be terminated. |
3 | 1033 | Unable to open the self-extracting executable file. The file is locked or in use by another process. The installation will terminate. |
4 | 1033 | PackageForTheWeb |
5 | 1033 | Unable to access the source file! |
6 | 1033 | Unable to create the cabinet file! |
7 | 1033 | Unable to access the specified path. |
8 | 1033 | Unable to create the specified output directory. Bad path name. |
9 | 1033 | Unable to start the decompression process! |
10 | 1033 | The EXE file has been corrupted. Unable to continue. |
11 | 1033 | Unable to decompress the EXE file. |
12 | 1033 | Unable to execute the specified command line! |
13 | 1033 | This program is used internally by PackageFromTheWeb. It should not be executed directly. |
14 | 1033 | Bad or missing header information! |
15 | 1033 | The Software Licensing Agreement file is missing. The installation will stop. |
16 | 1033 | %s - Welcome |
17 | 1033 | %s - License Agreement |
18 | 1033 | %s - Installation Folder |
19 | 1033 | http://www.installshield.com/pftw/ |
20 | 1033 | %s - Password |
21 | 1033 | PROGRAMFILES |
22 | 1033 | COMMONFILES |
23 | 1033 | Software\Microsoft\Windows\CurrentVersion |
24 | 1033 | ProgramFilesDir |
25 | 1033 | CommonFilesDir |
26 | 1033 | WINDOWS |
27 | 1033 | SYSTEM |
28 | 1033 | TEMP |
29 | 1033 | The specified output directory does not exist. Create it? |
30 | 1033 | Error writing the cabinet file! |
31 | 1033 | This installation program was created using a trial version of PackageForTheWeb. The PackageForTheWeb Wizard must be running to execute this program. |
32 | 1033 | Do you wish to cancel the installation? |
33 | 1033 | The package has been delivered successfully. |
34 | 1033 | Insufficient disk space to open the package! |
35 | 1033 | Security error! Invalid password. |
36 | 1033 | Invalid command line option. |
37 | 1033 | Unpacking '%s'... |
38 | 1033 | Memory allocation failure! |
39 | 1033 | Unable to open the unpacking application |
40 | 1033 | Fatal error reading the package data. |
41 | 1033 | Fatal error writing the package data. |
42 | 1033 | Program format is invalid and cannot be updated. |
43 | 1033 | This package is missing its file container. |
44 | 1033 | General failure reading this package. |
45 | 1033 | This package already contains a file container. |
46 | 1033 | This package has been signed and cannot be updated. |
47 | 1033 | Fatal Microsoft Error |
48 | 1033 | Unable to initialize the extension DLL. |
49 | 1033 | Error Executing the Specified Program |
300 | 1033 | No error |
301 | 1033 | Missing cabinet file! |
302 | 1033 | Input file is not a cabinet. |
303 | 1033 | Bad cabinet version. |
304 | 1033 | Corrupt cabinet file! |
305 | 1033 | Memory allocation failure! |
306 | 1033 | Invalid file compression type! |
307 | 1033 | CRC failure. |
308 | 1033 | System error during decompression |
309 | 1033 | Internal data size error. |
310 | 1033 | Incorrect cabinet file selected |
311 | 1033 | The package decompression has been cancelled. |
312 | 1033 | Unable to create the specified output directory! |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.dll | 658 | lstrcatA | |
KERNEL32.dll | 535 | SetFileAttributesA | |
KERNEL32.dll | 538 | SetFileTime | |
KERNEL32.dll | 408 | LocalFileTimeToFileTime | |
KERNEL32.dll | 83 | DosDateTimeToFileTime | |
KERNEL32.dll | 42 | CreateDirectoryA | |
KERNEL32.dll | 274 | GetPrivateProfileStringA | |
KERNEL32.dll | 78 | DeleteFileA | |
KERNEL32.dll | 152 | FreeLibrary | |
KERNEL32.dll | 315 | GetTempFileNameA | |
KERNEL32.dll | 400 | LoadLibraryA | |
KERNEL32.dll | 317 | GetTempPathA | |
KERNEL32.dll | 305 | GetSystemDirectoryA | |
KERNEL32.dll | 232 | GetFileAttributesA | |
KERNEL32.dll | 278 | GetProcAddress | |
KERNEL32.dll | 670 | lstrcpynA | |
KERNEL32.dll | 537 | SetFilePointer | |
KERNEL32.dll | 667 | lstrcpyA | |
KERNEL32.dll | 405 | LoadResource | |
KERNEL32.dll | 137 | FindResourceA | |
KERNEL32.dll | 30 | CompareStringA | |
KERNEL32.dll | 61 | CreateProcessA | |
KERNEL32.dll | 618 | WaitForSingleObject | |
KERNEL32.dll | 296 | GetStartupInfoA | |
KERNEL32.dll | 479 | RemoveDirectoryA | |
KERNEL32.dll | 135 | FindNextFileA | |
KERNEL32.dll | 237 | GetFileSize | |
KERNEL32.dll | 107 | ExitProcess | |
KERNEL32.dll | 49 | CreateFileA | |
KERNEL32.dll | 244 | GetLastError | |
KERNEL32.dll | 147 | FormatMessageA | |
KERNEL32.dll | 575 | Sleep | |
KERNEL32.dll | 673 | lstrlenA | |
KERNEL32.dll | 219 | GetDiskFreeSpaceA | |
KERNEL32.dll | 130 | FindFirstFileA | |
KERNEL32.dll | 24 | CloseHandle | |
KERNEL32.dll | 635 | WriteFile | |
KERNEL32.dll | 470 | ReadFile | |
KERNEL32.dll | 252 | GetModuleFileNameA | |
KERNEL32.dll | 419 | LockResource | |
KERNEL32.dll | 337 | GetWindowsDirectoryA | |
KERNEL32.dll | 661 | lstrcmpA | |
KERNEL32.dll | 398 | LCMapStringW | |
KERNEL32.dll | 239 | GetFileType | |
KERNEL32.dll | 298 | GetStdHandle | |
KERNEL32.dll | 485 | RtlUnwind | |
KERNEL32.dll | 265 | GetOEMCP | |
KERNEL32.dll | 157 | GetACP | |
KERNEL32.dll | 539 | SetHandleCount | |
KERNEL32.dll | 227 | GetEnvironmentStringsW | |
KERNEL32.dll | 225 | GetEnvironmentStrings | |
KERNEL32.dll | 397 | LCMapStringA | |
KERNEL32.dll | 126 | FindClose | |
KERNEL32.dll | 163 | GetCPInfo | |
KERNEL32.dll | 151 | FreeEnvironmentStringsW | |
KERNEL32.dll | 150 | FreeEnvironmentStringsA | |
KERNEL32.dll | 592 | UnhandledExceptionFilter | |
KERNEL32.dll | 211 | GetCurrentProcess | |
KERNEL32.dll | 582 | TerminateProcess | |
KERNEL32.dll | 427 | MultiByteToWideChar | |
KERNEL32.dll | 302 | GetStringTypeW | |
KERNEL32.dll | 299 | GetStringTypeA | |
KERNEL32.dll | 622 | WideCharToMultiByte | |
KERNEL32.dll | 603 | VirtualAlloc | |
KERNEL32.dll | 606 | VirtualFree | |
KERNEL32.dll | 362 | HeapCreate | |
KERNEL32.dll | 364 | HeapDestroy | |
KERNEL32.dll | 332 | GetVersion | |
KERNEL32.dll | 170 | GetCommandLineA | |
KERNEL32.dll | 254 | GetModuleHandleA | |
KERNEL32.dll | 366 | HeapFree | |
KERNEL32.dll | 360 | HeapAlloc | |
USER32.dll | 474 | SendMessageA | |
USER32.dll | 581 | TranslateMessage | |
USER32.dll | 564 | SystemParametersInfoA | |
USER32.dll | 612 | wsprintfA | |
USER32.dll | 314 | GetWindowLongA | |
USER32.dll | 285 | GetParent | |
USER32.dll | 545 | SetWindowTextA | |
USER32.dll | 319 | GetWindowTextA | |
USER32.dll | 311 | GetWindow | |
USER32.dll | 498 | SetDlgItemTextA | |
USER32.dll | 180 | EndDialog | |
USER32.dll | 472 | SendDlgItemMessageA | |
USER32.dll | 142 | DialogBoxParamA | |
USER32.dll | 240 | GetDesktopWindow | |
USER32.dll | 245 | GetDlgItemTextA | |
USER32.dll | 365 | KillTimer | |
USER32.dll | 178 | EnableWindow | |
USER32.dll | 534 | SetTimer | |
USER32.dll | 433 | PostMessageA | |
USER32.dll | 501 | SetFocus | |
USER32.dll | 75 | CreateDialogParamA | |
USER32.dll | 138 | DestroyWindow | |
USER32.dll | 243 | GetDlgItem | |
USER32.dll | 238 | GetDC | |
USER32.dll | 461 | ReleaseDC | |
USER32.dll | 467 | ScreenToClient | |
USER32.dll | 539 | SetWindowLongA | |
USER32.dll | 431 | PeekMessageA | |
USER32.dll | 542 | SetWindowPos | |
USER32.dll | 228 | GetClientRect | |
USER32.dll | 400 | MapWindowPoints | |
USER32.dll | 297 | GetSysColor | |
USER32.dll | 387 | LoadStringA | |
USER32.dll | 404 | MessageBeep | |
USER32.dll | 405 | MessageBoxA | |
USER32.dll | 225 | GetClassNameA | |
USER32.dll | 144 | DispatchMessageA | |
USER32.dll | 317 | GetWindowRect | |
USER32.dll | 85 | CreateWindowExA | |
GDI32.dll | 70 | DeleteObject | |
GDI32.dll | 370 | SetTextColor | |
GDI32.dll | 330 | SelectObject | |
GDI32.dll | 337 | SetBkMode | |
GDI32.dll | 263 | GetTextExtentPointA | |
GDI32.dll | 44 | CreateFontIndirectA | |
GDI32.dll | 387 | TextOutA | |
COMCTL32.dll | 17 | ||
COMCTL32.dll | 59 | PropertySheetA | |
ADVAPI32.dll | 302 | RegOpenKeyExA | |
ADVAPI32.dll | 310 | RegQueryValueExA | |
ADVAPI32.dll | 279 | RegCloseKey | |
SHELL32.dll | 97 | ShellExecuteA | |
SHELL32.dll | 52 | SHBrowseForFolderA | |
SHELL32.dll | 70 | SHGetPathFromIDListA | |
LZ32.dll | 7 | LZOpenFileA | |
LZ32.dll | 4 | LZCopy | |
LZ32.dll | 3 | LZClose |
StringTable 040904b0
CompanyName | InstallShield Software Corporation |
FileDescription | PackageForTheWeb Stub |
FileVersion | 2.00.201 |
InternalName | STUB.EXE |
LegalCopyright | Copyright © 1996 InstallShield Software Corporation |
OriginalFilename | STUB32.EXE |
ProductName | PackageForTheWeb Stub |
ProductVersion | 2.00.201 |
VS_FIXEDFILEINFO
FileVersion | 2.0.201.0 |
ProductVersion | 2.0.201.0 |
StrucVersion | 0x10000 |
FileFlagsMask | 0x3f |
FileFlags | 0 |
FileOS | 0x10004 |
FileType | 1 |
FileSubtype | 0 |
offset | size | type | comment | |
---|---|---|---|---|
0 | 98816 | EXE | 11/25/1997 00:10:04 | # |
15c1 | 15 | HTM | # | |
14010 | 11432 | AVI | # | |
18200 | 793874 | BIN | overlay data past EOF | # |
Scanning the drive for archives: 1 file, 892690 bytes (872 KiB) -- Type = Cab Offset = 99073 Physical Size = 793617 Method = MSZip Blocks = 1 Volumes = 1 Volume Index = 0 ID = 12345 Date Time Attr Size Compressed Name ------------------- ----- ------------ ------------ ------------------------ 1997-05-06 14:15:20 ....A 417 /os.dat 1997-12-17 18:30:02 ....A 8192 /_ISDEL.EXE 1997-12-17 18:30:30 ....A 59904 /SETUP.EXE 1997-05-30 11:31:50 ....A 4557 /lang.dat 1997-12-17 18:47:44 ....A 290586 /_INST32I.EX_ 1997-12-17 18:29:50 ....A 11264 /_SETUP.DLL 2000-02-24 18:47:04 ....A 204982 /_sys1.cab 1999-11-20 12:28:40 ....A 58357 /setup.ins 1999-11-06 07:25:02 ....A 169190 /setup.bmp 1998-09-27 14:39:14 ....A 97168 /setup.psd 1999-11-06 07:23:40 ....A 9722 /setup.GIF 2000-02-24 18:47:04 ....A 47239 /_user1.cab 2000-02-24 18:47:04 ....A 128 /DATA.TAG 2000-02-24 18:47:04 ....A 80 /SETUP.INI 2000-02-24 18:47:06 ....A 210125 /data1.cab 2000-02-24 18:47:06 ....A 391 /layout.bin 2000-02-24 18:47:06 ....A 49 /setup.lid ------------------- ----- ------------ ------------ ------------------------ 2000-02-24 18:47:06 1172351 892690 17 files
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK