filename | NimBUS Robot.exe | |
---|---|---|
size | 41948280 (0x2801478) | |
md5 | 6fd0aa72d38bf0332aa8d9fba1b21b28 | |
type | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0xf0 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x1067a | 0x11000 | R-X CODE | |
.rdata | 0x12000 | 0x17e8 | 0x2000 | R-- IDATA | |
.data | 0x14000 | 0x3cfc | 0x2000 | RW- IDATA | |
.rsrc | 0x18000 | 0x11208 | 0x12000 | R-- IDATA |
Data Directory
id | lang | string |
---|---|---|
1 | 1033 | PackageForTheWeb Error |
2 | 1033 | This self extracting executable file appears to have been corrupted and cannot be executed. You should obtain a new copy of this file to insure that it will execute correctly. |
3 | 1033 | Unable to open the self-extracting executable file. The file is locked or in use by another process. The installation will terminate. |
4 | 1033 | PackageForTheWeb |
5 | 1033 | Unable to access the source file! |
6 | 1033 | Unable to create the cabinet file! |
7 | 1033 | Unable to access the specified path. |
8 | 1033 | Unable to create the specified output folder. Bad path name. |
9 | 1033 | Unable to start the decompression process! |
10 | 1033 | The EXE file has been corrupted. Unable to continue. |
12 | 1033 | Unable to execute the specified command line! |
13 | 1033 | This program is used internally by PackageFromTheWeb. It should not be executed directly. |
14 | 1033 | Bad or missing header information! |
32 | 1033 | Do you wish to cancel the installation? |
34 | 1033 | Insufficient disk space to open the package! |
35 | 1033 | Security error! Invalid password. |
37 | 1033 | Unpacking '%s'... |
38 | 1033 | Memory allocation failure! |
44 | 1033 | General failure reading this package. |
48 | 1033 | Unable to initialize the extension DLL. |
49 | 1033 | Error Executing the Specified Program |
50 | 1033 | Unpacking %s... |
52 | 1033 | The specified drive does not exist |
300 | 1033 | No error |
301 | 1033 | Missing cabinet file! |
302 | 1033 | Input file is not a cabinet. |
303 | 1033 | Bad cabinet version. |
304 | 1033 | Corrupt cabinet file! |
305 | 1033 | Memory allocation failure! |
306 | 1033 | Invalid file compression type! |
307 | 1033 | CRC failure. |
308 | 1033 | System error during decompression |
310 | 1033 | Incorrect cabinet file selected |
311 | 1033 | The package decompression has been cancelled. |
312 | 1033 | Unable to create the specified output folder! |
313 | 1033 | Unable to compute required disk space |
314 | 1033 | There is not enough space on drive %s to extract this package. |
315 | 1033 | MB |
316 | 1033 | KB |
317 | 1033 | bytes |
318 | 1033 | There is not enough space on drive %s to extract this package |
319 | 1033 | version |
324 | 1033 | Please free up %.2f %s and click Retry |
328 | 1033 | 12,MS Shell Dlg |
329 | 1033 | &Finish |
6001 | 1033 | 8,MS Shell Dlg |
6002 | 1033 | 8,MS Shell Dlg |
module_name | hint | ord | function_name |
---|---|---|---|
KERNEL32.dll | 190 | FormatMessageA | |
KERNEL32.dll | 365 | GetSystemDefaultLCID | |
KERNEL32.dll | 339 | GetProcAddress | |
KERNEL32.dll | 380 | GetTempFileNameA | |
KERNEL32.dll | 514 | MulDiv | |
KERNEL32.dll | 71 | CreateProcessA | |
KERNEL32.dll | 772 | WaitForSingleObject | |
KERNEL32.dll | 358 | GetStartupInfoA | |
KERNEL32.dll | 468 | IsDBCSLeadByte | |
KERNEL32.dll | 709 | Sleep | |
KERNEL32.dll | 36 | CompareStringA | |
KERNEL32.dll | 665 | SetFileTime | |
KERNEL32.dll | 487 | LocalFileTimeToFileTime | |
KERNEL32.dll | 104 | DosDateTimeToFileTime | |
KERNEL32.dll | 195 | FreeLibrary | |
KERNEL32.dll | 589 | RemoveDirectoryA | |
KERNEL32.dll | 172 | FindNextFileA | |
KERNEL32.dll | 793 | WritePrivateProfileSectionA | |
KERNEL32.dll | 795 | WritePrivateProfileStringA | |
KERNEL32.dll | 827 | lstrcpynA | |
KERNEL32.dll | 331 | GetPrivateProfileSectionA | |
KERNEL32.dll | 789 | WriteFile | |
KERNEL32.dll | 92 | DeleteFileA | |
KERNEL32.dll | 485 | LocalAlloc | |
KERNEL32.dll | 498 | LockResource | |
KERNEL32.dll | 484 | LoadResource | |
KERNEL32.dll | 178 | FindResourceA | |
KERNEL32.dll | 708 | SizeofResource | |
KERNEL32.dll | 314 | GetModuleHandleA | |
KERNEL32.dll | 419 | GlobalFree | |
KERNEL32.dll | 430 | GlobalUnlock | |
KERNEL32.dll | 423 | GlobalLock | |
KERNEL32.dll | 412 | GlobalAlloc | |
KERNEL32.dll | 515 | MultiByteToWideChar | |
KERNEL32.dll | 821 | lstrcmpiA | |
KERNEL32.dll | 275 | GetDiskFreeSpaceA | |
KERNEL32.dll | 436 | HeapAlloc | |
KERNEL32.dll | 341 | GetProcessHeap | |
KERNEL32.dll | 442 | HeapFree | |
KERNEL32.dll | 312 | GetModuleFileNameA | |
KERNEL32.dll | 140 | ExitProcess | |
KERNEL32.dll | 55 | CreateFileA | |
KERNEL32.dll | 56 | CreateFileMappingA | |
KERNEL32.dll | 501 | MapViewOfFile | |
KERNEL32.dll | 736 | UnmapViewOfFile | |
KERNEL32.dll | 661 | SetFileAttributesA | |
KERNEL32.dll | 293 | GetFileSize | |
KERNEL32.dll | 573 | ReadFile | |
KERNEL32.dll | 663 | SetFilePointer | |
KERNEL32.dll | 163 | FindFirstFileA | |
KERNEL32.dll | 48 | CreateDirectoryA | |
KERNEL32.dll | 301 | GetLastError | |
KERNEL32.dll | 335 | GetPrivateProfileStringA | |
KERNEL32.dll | 159 | FindClose | |
KERNEL32.dll | 288 | GetFileAttributesA | |
KERNEL32.dll | 815 | lstrcatA | |
KERNEL32.dll | 830 | lstrlenA | |
KERNEL32.dll | 407 | GetWindowsDirectoryA | |
KERNEL32.dll | 824 | lstrcpyA | |
KERNEL32.dll | 368 | GetSystemDirectoryA | |
KERNEL32.dll | 382 | GetTempPathA | |
KERNEL32.dll | 509 | MoveFileExA | |
KERNEL32.dll | 479 | LoadLibraryA | |
KERNEL32.dll | 489 | LocalFree | |
KERNEL32.dll | 356 | GetShortPathNameA | |
KERNEL32.dll | 185 | FlushFileBuffers | |
KERNEL32.dll | 30 | CloseHandle | |
KERNEL32.dll | 682 | SetStdHandle | |
KERNEL32.dll | 461 | IsBadCodePtr | |
KERNEL32.dll | 464 | IsBadReadPtr | |
KERNEL32.dll | 698 | SetUnhandledExceptionFilter | |
KERNEL32.dll | 477 | LCMapStringW | |
KERNEL32.dll | 476 | LCMapStringA | |
KERNEL32.dll | 296 | GetFileType | |
KERNEL32.dll | 360 | GetStdHandle | |
KERNEL32.dll | 666 | SetHandleCount | |
KERNEL32.dll | 283 | GetEnvironmentStringsW | |
KERNEL32.dll | 281 | GetEnvironmentStrings | |
KERNEL32.dll | 776 | WideCharToMultiByte | |
KERNEL32.dll | 194 | FreeEnvironmentStringsW | |
KERNEL32.dll | 193 | FreeEnvironmentStringsA | |
KERNEL32.dll | 733 | UnhandledExceptionFilter | |
KERNEL32.dll | 265 | GetCurrentProcess | |
KERNEL32.dll | 717 | TerminateProcess | |
KERNEL32.dll | 364 | GetStringTypeW | |
KERNEL32.dll | 361 | GetStringTypeA | |
KERNEL32.dll | 326 | GetOEMCP | |
KERNEL32.dll | 201 | GetACP | |
KERNEL32.dll | 207 | GetCPInfo | |
KERNEL32.dll | 467 | IsBadWritePtr | |
KERNEL32.dll | 445 | HeapReAlloc | |
KERNEL32.dll | 753 | VirtualAlloc | |
KERNEL32.dll | 757 | VirtualFree | |
KERNEL32.dll | 438 | HeapCreate | |
KERNEL32.dll | 440 | HeapDestroy | |
KERNEL32.dll | 398 | GetVersion | |
KERNEL32.dll | 218 | GetCommandLineA | |
KERNEL32.dll | 601 | RtlUnwind | |
USER32.dll | 312 | GetParent | |
USER32.dll | 261 | GetDlgItem | |
USER32.dll | 531 | SendDlgItemMessageA | |
USER32.dll | 185 | EnableWindow | |
USER32.dll | 54 | CheckRadioButton | |
USER32.dll | 611 | SetWindowTextA | |
USER32.dll | 354 | GetWindowTextA | |
USER32.dll | 431 | LoadStringA | |
USER32.dll | 420 | LoadImageA | |
USER32.dll | 451 | MessageBoxA | |
USER32.dll | 398 | IsDlgButtonChecked | |
USER32.dll | 263 | GetDlgItemTextA | |
USER32.dll | 560 | SetDlgItemTextA | |
USER32.dll | 519 | ReleaseDC | |
USER32.dll | 256 | GetDC | |
USER32.dll | 346 | GetWindowLongA | |
USER32.dll | 563 | SetFocus | |
USER32.dll | 483 | PostMessageA | |
USER32.dll | 342 | GetWindow | |
USER32.dll | 691 | wsprintfA | |
USER32.dll | 258 | GetDesktopWindow | |
USER32.dll | 144 | DestroyWindow | |
USER32.dll | 80 | CreateDialogParamA | |
USER32.dll | 151 | DispatchMessageA | |
USER32.dll | 647 | TranslateMessage | |
USER32.dll | 326 | GetSysColor | |
USER32.dll | 327 | GetSysColorBrush | |
USER32.dll | 214 | FillRect | |
USER32.dll | 12 | BeginPaint | |
USER32.dll | 177 | DrawTextA | |
USER32.dll | 189 | EndPaint | |
USER32.dll | 243 | GetClientRect | |
USER32.dll | 526 | ScreenToClient | |
USER32.dll | 462 | MoveWindow | |
USER32.dll | 579 | SetParent | |
USER32.dll | 441 | MapDialogRect | |
USER32.dll | 310 | GetNextDlgTabItem | |
USER32.dll | 352 | GetWindowRect | |
USER32.dll | 77 | CreateDialogIndirectParamA | |
USER32.dll | 403 | IsWindow | |
USER32.dll | 382 | InvalidateRect | |
USER32.dll | 404 | IsWindowEnabled | |
USER32.dll | 623 | ShowWindow | |
USER32.dll | 662 | UpdateWindow | |
USER32.dll | 396 | IsDialogMessageA | |
USER32.dll | 608 | SetWindowPos | |
USER32.dll | 223 | GetActiveWindow | |
USER32.dll | 544 | SetActiveWindow | |
USER32.dll | 37 | CharNextA | |
USER32.dll | 418 | LoadIconA | |
USER32.dll | 536 | SendMessageA | |
USER32.dll | 481 | PeekMessageA | |
USER32.dll | 605 | SetWindowLongA | |
GDI32.dll | 84 | DeleteObject | |
GDI32.dll | 67 | CreatePalette | |
GDI32.dll | 435 | RealizePalette | |
GDI32.dll | 301 | GetDeviceCaps | |
GDI32.dll | 49 | CreateDIBitmap | |
GDI32.dll | 343 | GetObjectA | |
GDI32.dll | 463 | SelectPalette | |
GDI32.dll | 143 | EnumFontFamiliesExA | |
GDI32.dll | 376 | GetTextExtentPointA | |
GDI32.dll | 359 | GetStockObject | |
GDI32.dll | 524 | TextOutA | |
GDI32.dll | 81 | DeleteDC | |
GDI32.dll | 462 | SelectObject | |
GDI32.dll | 43 | CreateCompatibleDC | |
GDI32.dll | 469 | SetBkMode | |
GDI32.dll | 18 | BitBlt | |
GDI32.dll | 506 | SetTextColor | |
GDI32.dll | 78 | CreateSolidBrush | |
GDI32.dll | 468 | SetBkColor | |
GDI32.dll | 56 | CreateFontIndirectA | |
ADVAPI32.dll | 388 | RegCloseKey | |
ADVAPI32.dll | 423 | RegQueryValueExA | |
ADVAPI32.dll | 413 | RegOpenKeyExA | |
SHELL32.dll | 134 | ShellExecuteA | |
SHELL32.dll | 59 | SHBrowseForFolderA | |
SHELL32.dll | 94 | SHGetPathFromIDListA | |
SHELL32.dll | 89 | SHGetMalloc | |
LZ32.dll | 9 | LZOpenFileA | |
LZ32.dll | 5 | LZCopy | |
LZ32.dll | 3 | LZClose | |
COMCTL32.dll | 17 |
StringTable 040904b0
Comments |