| filename | WinCon.SFX | |
|---|---|---|
| size | 75264 (0x12600) | |
| md5 | 93471c3d5990a0677499ef6fbdacd0e6 | |
| type | PE32 executable (console) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xe0 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 147 | 30729 | 9 |
| 1 | 0 | 81 |
| 149 | 21022 | 5 |
| 131 | 30729 | 1 |
| 132 | 30729 | 42 |
| 146 | 30729 | 1 |
| 148 | 30729 | 1 |
| 145 | 30729 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| .text | 0x1000 | 0xf1b5 | 0xf200 | R-X CODE | |
| .rdata | 0x11000 | 0xd05 | 0xe00 | R-- IDATA | |
| .data | 0x12000 | 0xa568 | 0x200 | RW- IDATA | |
| .CRT | 0x1d000 | 0x14 | 0x200 | R-- IDATA | |
| .rsrc | 0x1e000 | 0x1da8 | 0x1e00 | R-- IDATA |
Data Directory
| id | lang | string |
|---|---|---|
| 3002 | 1033 | _Yes_No |
| 3004 | 1033 | _Yes_No_All |
| 3008 | 1033 | _Yes_No_All_nEver_Rename_Quit |
| 3010 | 1033 | _Continue_Quit |
| 3014 | 1033 | RAR SFX archive |
| 3286 | 1033 | ERROR: Bad archive %s |
| 3288 | 1033 | Enter password (will not be echoed) |
| 3290 | 1033 | Enter password |
| 3294 | 1033 | for |
| 3298 | 1033 | Write error in the file %s |
| 3300 | 1033 | Read error in the file %s |
| 3302 | 1033 | Seek error in the file %s |
| 3304 | 1033 | Cannot close the file %s |
| 3306 | 1033 | Not enough memory |
| 3308 | 1033 | Corrupt archive - use 'Repair' command |
| 3310 | 1033 | Program aborted |
| 3312 | 1033 | Cannot rename %s to %s |
| 3314 | 1033 | Cannot find volume %s |
| 3316 | 1033 | User break |
| 3324 | 1033 | Insert disk with %s |
| 3326 | 1033 | Testing archive %s |
| 3328 | 1033 | Extracting from %s |
| 3338 | 1033 | %s is not RAR archive |
| 3340 | 1033 | %s is not first volume |
| 3344 | 1033 | Cannot create %s |
| 3346 | 1033 | Cannot open %s |
| 3348 | 1033 | Unknown method in %s |
| 3354 | 1033 | OK |
| 3356 | 1033 | Done |
| 3420 | 1033 | %s: encrypted |
| 3428 | 1033 | %-20s - CRC failed |
| 3430 | 1033 | Testing archive %s |
| 3432 | 1033 | Extracting from %s |
| 3434 | 1033 | %s - use current password ? |
| 3436 | 1033 | Creating %-56s |
| 3438 | 1033 | Skipping %-56s |
| 3440 | 1033 | Testing %-56s |
| 3442 | 1033 | Extracting %-56s |
| 3444 | 1033 | ... %-56s |
| 3446 | 1033 | Cannot create directory %s |
| 3448 | 1033 | ------ Printing %s |
| 3450 | 1033 | Encrypted file: CRC failed in %s (password incorrect ?) |
| 3452 | 1033 | No files to extract |
| 3454 | 1033 | All OK |
| 3456 | 1033 | Total errors: %ld |
| 3458 | 1033 | %s already exists. Overwrite it ? |
| 3460 | 1033 | Overwrite %s ? |
| 3462 | 1033 | Enter new name: |
| 3464 | 1033 | The archive header is corrupt |
| 3466 | 1033 | %s - the file header is corrupt |
| 3468 | 1033 | The comment header is corrupt |
| 3484 | 1033 | The archive comment is corrupt |
| 3486 | 1033 | Press 'Enter' to continue or 'Q' to quit: |
| 3488 | 1033 | The file comment is corrupt |
| 3502 | 1033 | -------- %2d %s %d, archive %s |
| 3506 | 1033 | Solid |
| 3508 | 1033 | SFX |
| 3510 | 1033 | volume |
| 3512 | 1033 | Volume |
| 3514 | 1033 | archive |
| 3516 | 1033 | Archive |
| 3518 | 1033 | Recovery record is present |
| 3520 | 1033 | Lock is present |
| 3522 | 1033 | Pathname/Comment |
| 3524 | 1033 | Name |
| 3526 | 1033 | Size Packed Ratio Date Time Attr CRC Meth Ver |
| 3528 | 1033 | Host OS Solid |
| 3542 | 1033 | Comment: |
| 3544 | 1033 | Yes |
| 3546 | 1033 | No |
| 3548 | 1033 | 0 files |
| 3570 | 1033 | Unexpected end of archive |
| 3596 | 1033 | ERROR: %s group and owner data are corrupt |
| 3598 | 1033 | WARNING: Cannot set %s owner and group |
| 3602 | 1033 | WARNING: Cannot create link %s |
| 3604 | 1033 | WARNING: Symbolic link %s already exists |
| 3606 | 1033 | Cannot create %s. Retry ? |
| 3612 | 1033 | %-20s : packed data CRC failed in volume %s |
| 3614 | 1033 | %s is read-only |
| 3618 | 1033 | WARNING: Cannot set %s security data |
| 3620 | 1033 | ERROR: %s security data are corrupt |
| 3624 | 1033 | ERROR: %s stream data are corrupt |
| 3628 | 1033 | ERROR: Invalid file name %s |
| 3646 | 1033 | WARNING: Attempting to correct the invalid file name |
| 3648 | 1033 | WARNING: You need to start extraction from a previous volume to unpack %s |
| 3650 | 1033 | ERROR: Unknown option: %s |
| 3692 | 1033 | <Commands> |
| 3694 | 1033 | -x Extract from archive (default) |
| 3696 | 1033 | -t Test archive files |
| 3698 | 1033 | -v Verbosely list contents of archive |
| module_name | hint | ord | function_name |
|---|---|---|---|
| SHLWAPI.dll | 367 | wvnsprintfA | |
| KERNEL32.dll | 447 | GetCurrentDirectoryW | |
| KERNEL32.dll | 514 | GetLastError | |
| KERNEL32.dll | 1202 | Sleep | |
| KERNEL32.dll | 82 | CloseHandle | |
| KERNEL32.dll | 448 | GetCurrentProcess | |
| KERNEL32.dll | 1130 | SetFileTime | |
| KERNEL32.dll | 867 | MoveFileW | |
| KERNEL32.dll | 343 | FlushFileBuffers | |
| KERNEL32.dll | 1126 | SetFilePointer | |
| KERNEL32.dll | 1107 | SetEndOfFile | |
| KERNEL32.dll | 499 | GetFileType | |
| KERNEL32.dll | 136 | CreateFileA | |
| KERNEL32.dll | 143 | CreateFileW | |
| KERNEL32.dll | 960 | ReadFile | |
| KERNEL32.dll | 1317 | WriteFile | |
| KERNEL32.dll | 466 | GetDriveTypeA | |
| KERNEL32.dll | 485 | GetFileAttributesA | |
| KERNEL32.dll | 490 | GetFileAttributesW | |
| KERNEL32.dll | 1118 | SetFileAttributesA | |
| KERNEL32.dll | 1121 | SetFileAttributesW | |
| KERNEL32.dll | 211 | DeleteFileA | |
| KERNEL32.dll | 214 | DeleteFileW | |
| KERNEL32.dll | 124 | CreateDirectoryA | |
| KERNEL32.dll | 129 | CreateDirectoryW | |
| KERNEL32.dll | 302 | FindClose | |
| KERNEL32.dll | 323 | FindNextFileA | |
| KERNEL32.dll | 306 | FindFirstFileA | |
| KERNEL32.dll | 612 | GetStdHandle | |
| KERNEL32.dll | 313 | FindFirstFileW | |
| KERNEL32.dll | 676 | GetVersionExW | |
| KERNEL32.dll | 871 | MultiByteToWideChar | |
| KERNEL32.dll | 390 | GetCommandLineA | |
| KERNEL32.dll | 1112 | SetErrorMode | |
| KERNEL32.dll | 532 | GetModuleFileNameW | |
| KERNEL32.dll | 715 | HeapAlloc | |
| KERNEL32.dll | 586 | GetProcessHeap | |
| KERNEL32.dll | 719 | HeapFree | |
| KERNEL32.dll | 722 | HeapReAlloc | |
| KERNEL32.dll | 97 | CompareStringA | |
| KERNEL32.dll | 281 | ExitProcess | |
| KERNEL32.dll | 354 | FreeLibrary | |
| KERNEL32.dll | 581 | GetProcAddress | |
| KERNEL32.dll | 831 | LoadLibraryW | |
| KERNEL32.dll | 449 | GetCurrentProcessId | |
| KERNEL32.dll | 536 | GetModuleHandleW | |
| KERNEL32.dll | 838 | LocalFileTimeToFileTime | |
| KERNEL32.dll | 1213 | SystemTimeToFileTime | |
| KERNEL32.dll | 293 | FileTimeToSystemTime | |
| KERNEL32.dll | 292 | FileTimeToLocalFileTime | |
| KERNEL32.dll | 631 | GetSystemTime | |
| KERNEL32.dll | 1297 | WideCharToMultiByte | |
| KERNEL32.dll | 100 | CompareStringW | |
| KERNEL32.dll | 766 | IsDBCSLeadByte | |
| KERNEL32.dll | 370 | GetCPInfo | |
| KERNEL32.dll | 428 | GetConsoleMode | |
| KERNEL32.dll | 1085 | SetConsoleMode | |
| KERNEL32.dll | 958 | ReadConsoleW | |
| KERNEL32.dll | 325 | FindNextFileW | |
| USER32.dll | 506 | LoadStringW | |
| USER32.dll | 54 | CharToOemBuffA | |
| USER32.dll | 57 | CharUpperA | |
| USER32.dll | 821 | wvsprintfW | |
| USER32.dll | 60 | CharUpperW | |
| USER32.dll | 55 | CharToOemBuffW | |
| USER32.dll | 820 | wvsprintfA | |
| USER32.dll | 53 | CharToOemA | |
| USER32.dll | 546 | OemToCharBuffA | |
| USER32.dll | 545 | OemToCharA | |
| ADVAPI32.dll | 682 | SetFileSecurityW | |
| ADVAPI32.dll | 407 | LookupPrivilegeValueW | |
| ADVAPI32.dll | 503 | OpenProcessToken | |
| ADVAPI32.dll | 681 | SetFileSecurityA | |
| ADVAPI32.dll | 31 | AdjustTokenPrivileges |
| ord | entry_va | function_name |
|---|
| module_name | WINRAR.SFX |
|---|---|
| flags | 0 |
| timestamp | 2012-06-09 13:19:29 |
| version | 0.0 |
| ordinal_base | 1 |
| nFunctions | 0 |
| nNames | 0 |
| Names(0) | 0 |
| Functions(0) | 0 |
| NameOrdinals(0) | 0 |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] can't find file_offset of VA 0x0
offset:( 0x )