| filename | WDExpress.exe | |
|---|---|---|
| size | 439264 (0x6b3e0) | |
| md5 | a307a88ef4da04f7ca901b803217aef8 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0x108 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 188 | 30716 | 5 |
| 190 | 30716 | 1 |
| 203 | 50628 | 4 |
| 205 | 50628 | 9 |
| 206 | 50628 | 30 |
| 1 | 0 | 468 |
| 185 | 30716 | 23 |
| 207 | 50628 | 64 |
| 207 | 40602 | 1 |
| 211 | 50628 | 59 |
| 201 | 50628 | 1 |
| 204 | 50628 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
TLS
| raw start | raw end | index | callbks | zero fill | flags | |
|---|---|---|---|---|---|---|
| 0x44d000 | 0x44d008 | 0x448194 | 0x4010b4 | 0 | 0 |
| id | lang | string |
|---|---|---|
| 6630 | 1033 | Microsoft Visual Studio Express 2012 for Windows Desktop |
| 6631 | 1033 | Cannot find one or more components. Please reinstall the application. |
| 6633 | 1033 | WDExpress |
| 6634 | 1033 | M 191.99,0 C191.99,0 90.39,101.60 90.39,101.60 90.39,101.60 25.59,51.20 25.59,51.20 25.59,51.20 0,63.99 0,63.99 0,63.99 0,191.99 0,191.99 0,191.99 25.59,204.79 25.59,204.79 25.59,204.79 90.39,154.39 90.39,154.39 90.39,154.39 191.99,256 191.99,256 191.99,256 256,230.39 256,230.39 256,230.39 256,25.59 256,25.59 256,25.59 191.99,0 191.99,0 zM 25.59,166.39 C25.59,166.39 25.59,89.59 25.59,89.59 25.59,89.59 64.00,127.99 64.00,127.99 64.00,127.99 25.59,166.39 25.59,166.39 zM 124.34,127.99 C124.34,127.99 191.99,75.37 191.99,75.37 191.99,75.37 191.99,180.62 191.99,180.62 191.99,180.62 124.34,127.99 124.34,127.99 z |
| module_name | hint | ord | function_name |
|---|---|---|---|
| ADVAPI32.dll | 600 | RegCloseKey | |
| ADVAPI32.dll | 649 | RegOpenKeyExW | |
| ADVAPI32.dll | 662 | RegQueryValueExW | |
| ADVAPI32.dll | 678 | RegSetValueExW | |
| ADVAPI32.dll | 620 | RegDeleteKeyW | |
| ADVAPI32.dll | 624 | RegDeleteValueW | |
| ADVAPI32.dll | 609 | RegCreateKeyExW | |
| ADVAPI32.dll | 656 | RegQueryInfoKeyW | |
| ADVAPI32.dll | 631 | RegEnumKeyExW | |
| ADVAPI32.dll | 123 | ConvertSidToStringSidW | |
| ADVAPI32.dll | 412 | IsValidSid | |
| ADVAPI32.dll | 367 | GetTokenInformation | |
| ADVAPI32.dll | 530 | OpenProcessToken | |
| ADVAPI32.dll | 632 | RegEnumKeyW | |
| ADVAPI32.dll | 307 | FreeSid | |
| ADVAPI32.dll | 95 | CheckTokenMembership | |
| ADVAPI32.dll | 32 | AllocateAndInitializeSid | |
| ADVAPI32.dll | 655 | RegQueryInfoKeyA | |
| ADVAPI32.dll | 634 | RegEnumValueW | |
| ADVAPI32.dll | 633 | RegEnumValueA | |
| ADVAPI32.dll | 630 | RegEnumKeyExA | |
| ADVAPI32.dll | 623 | RegDeleteValueA | |
| ADVAPI32.dll | 661 | RegQueryValueExA | |
| ADVAPI32.dll | 648 | RegOpenKeyExA | |
| ADVAPI32.dll | 608 | RegCreateKeyExA | |
| ADVAPI32.dll | 230 | CryptVerifySignatureW | |
| ADVAPI32.dll | 216 | CryptHashData | |
| ADVAPI32.dll | 195 | CryptCreateHash | |
| ADVAPI32.dll | 218 | CryptImportKey | |
| ADVAPI32.dll | 193 | CryptAcquireContextW | |
| ADVAPI32.dll | 219 | CryptReleaseContext | |
| ADVAPI32.dll | 199 | CryptDestroyKey | |
| ADVAPI32.dll | 198 | CryptDestroyHash | |
| ADVAPI32.dll | 129 | ConvertStringSecurityDescriptorToSecurityDescriptorW | |
| KERNEL32.dll | 206 | CreateFileA | |
| KERNEL32.dll | 446 | GetACP | |
| KERNEL32.dll | 909 | IsValidCodePage | |
| KERNEL32.dll | 1427 | UnmapViewOfFile | |
| KERNEL32.dll | 987 | MapViewOfFile | |
| KERNEL32.dll | 211 | CreateFileMappingW | |
| KERNEL32.dll | 429 | FlushFileBuffers | |
| KERNEL32.dll | 752 | GetSystemPreferredUILanguages | |
| KERNEL32.dll | 797 | GetUserDefaultUILanguage | |
| KERNEL32.dll | 745 | GetSystemDefaultUILanguage | |
| KERNEL32.dll | 1000 | MoveFileW | |
| KERNEL32.dll | 198 | CreateDirectoryW | |
| KERNEL32.dll | 802 | GetVersionExA | |
| KERNEL32.dll | 961 | LoadLibraryExA | |
| KERNEL32.dll | 596 | GetFileSize | |
| KERNEL32.dll | 1288 | SetFilePointer | |
| KERNEL32.dll | 638 | GetModuleHandleA | |
| KERNEL32.dll | 625 | GetLogicalDrives | |
| KERNEL32.dll | 569 | GetDriveTypeW | |
| KERNEL32.dll | 564 | GetDiskFreeSpaceExW | |
| KERNEL32.dll | 1179 | ReleaseSemaphore | |
| KERNEL32.dll | 245 | CreateSemaphoreW | |
| KERNEL32.dll | 767 | GetTempFileNameW | |
| KERNEL32.dll | 769 | GetTempPathW | |
| KERNEL32.dll | 388 | FindClose | |
| KERNEL32.dll | 411 | FindNextFileW | |
| KERNEL32.dll | 399 | FindFirstFileW | |
| KERNEL32.dll | 631 | GetLongPathNameW | |
| KERNEL32.dll | 610 | GetFullPathNameW | |
| KERNEL32.dll | 369 | ExpandEnvironmentStringsW | |
| KERNEL32.dll | 1274 | SetEnvironmentVariableW | |
| KERNEL32.dll | 377 | FileTimeToSystemTime | |
| KERNEL32.dll | 1020 | OpenEventW | |
| KERNEL32.dll | 185 | CopyFileW | |
| KERNEL32.dll | 587 | GetFileAttributesExW | |
| KERNEL32.dll | 973 | LocalFree | |
| KERNEL32.dll | 1303 | SetLastError | |
| KERNEL32.dll | 801 | GetVersion | |
| KERNEL32.dll | 1268 | SetDllDirectoryW | |
| KERNEL32.dll | 853 | HeapSetInformation | |
| KERNEL32.dll | 881 | InterlockedIncrement | |
| KERNEL32.dll | 877 | InterlockedDecrement | |
| KERNEL32.dll | 637 | GetModuleFileNameW | |
| KERNEL32.dll | 962 | LoadLibraryExW | |
| KERNEL32.dll | 1556 | lstrcmpiW | |
| KERNEL32.dll | 440 | FreeLibrary | |
| KERNEL32.dll | 957 | LeaveCriticalSection | |
| KERNEL32.dll | 320 | EnterCriticalSection | |
| KERNEL32.dll | 286 | DeleteCriticalSection | |
| KERNEL32.dll | 870 | InitializeCriticalSectionAndSpinCount | |
| KERNEL32.dll | 618 | GetLastError | |
| KERNEL32.dll | 1004 | MultiByteToWideChar | |
| KERNEL32.dll | 641 | GetModuleHandleW | |
| KERNEL32.dll | 693 | GetProcAddress | |
| KERNEL32.dll | 1360 | SetUnhandledExceptionFilter | |
| KERNEL32.dll | 878 | InterlockedExchange | |
| KERNEL32.dll | 984 | LockResource | |
| KERNEL32.dll | 1374 | SizeofResource | |
| KERNEL32.dll | 966 | LoadResource | |
| KERNEL32.dll | 420 | FindResourceW | |
| KERNEL32.dll | 1096 | RaiseException | |
| KERNEL32.dll | 1386 | SwitchToThread | |
| KERNEL32.dll | 316 | EncodePointer | |
| KERNEL32.dll | 279 | DecodePointer | |
| KERNEL32.dll | 899 | IsDebuggerPresent | |
| KERNEL32.dll | 904 | IsProcessorFeaturePresent | |
| KERNEL32.dll | 1084 | QueryPerformanceCounter | |
| KERNEL32.dll | 552 | GetCurrentThreadId | |
| KERNEL32.dll | 756 | GetSystemTimeAsFileTime | |
| KERNEL32.dll | 785 | GetTickCount64 | |
| KERNEL32.dll | 848 | HeapDestroy | |
| KERNEL32.dll | 845 | HeapAlloc | |
| KERNEL32.dll | 852 | HeapReAlloc | |
| KERNEL32.dll | 849 | HeapFree | |
| KERNEL32.dll | 854 | HeapSize | |
| KERNEL32.dll | 698 | GetProcessHeap | |
| KERNEL32.dll | 142 | CloseHandle | |
| KERNEL32.dll | 202 | CreateEventW | |
| KERNEL32.dll | 1198 | ResetEvent | |
| KERNEL32.dll | 1276 | SetEvent | |
| KERNEL32.dll | 313 | DuplicateHandle | |
| KERNEL32.dll | 547 | GetCurrentProcess | |
| KERNEL32.dll | 750 | GetSystemInfo | |
| KERNEL32.dll | 590 | GetFileAttributesW | |
| KERNEL32.dll | 1346 | SetThreadPriority | |
| KERNEL32.dll | 1205 | ResumeThread | |
| KERNEL32.dll | 257 | CreateThread | |
| KERNEL32.dll | 1467 | WaitForSingleObject | |
| KERNEL32.dll | 419 | FindResourceExW | |
| KERNEL32.dll | 1565 | lstrlenW | |
| KERNEL32.dll | 291 | DeleteFileW | |
| KERNEL32.dll | 1564 | lstrlenA | |
| KERNEL32.dll | 1501 | WideCharToMultiByte | |
| KERNEL32.dll | 548 | GetCurrentProcessId | |
| KERNEL32.dll | 1032 | OpenProcess | |
| KERNEL32.dll | 963 | LoadLibraryW | |
| KERNEL32.dll | 214 | CreateFileW | |
| KERNEL32.dll | 754 | GetSystemTime | |
| KERNEL32.dll | 1387 | SystemTimeToFileTime | |
| KERNEL32.dll | 1478 | WerRegisterFile | |
| KERNEL32.dll | 1460 | VirtualQueryEx | |
| KERNEL32.dll | 1348 | SetThreadStackGuarantee | |
| KERNEL32.dll | 1424 | UnhandledExceptionFilter | |
| KERNEL32.dll | 1045 | OutputDebugStringW | |
| KERNEL32.dll | 784 | GetTickCount | |
| KERNEL32.dll | 164 | CompareStringA | |
| KERNEL32.dll | 167 | CompareStringW | |
| KERNEL32.dll | 551 | GetCurrentThread | |
| KERNEL32.dll | 1112 | ReadFile | |
| KERNEL32.dll | 578 | GetEnvironmentVariableW | |
| KERNEL32.dll | 733 | GetStdHandle | |
| KERNEL32.dll | 1521 | WriteFile | |
| KERNEL32.dll | 1375 | Sleep | |
| KERNEL32.dll | 483 | GetCommandLineW | |
| KERNEL32.dll | 239 | CreateProcessW | |
| KERNEL32.dll | 163 | CompareFileTime | |
| KERNEL32.dll | 803 | GetVersionExW | |
| KERNEL32.dll | 284 | DeleteAtom | |
| KERNEL32.dll | 6 | AddAtomW | |
| KERNEL32.dll | 387 | FindAtomW | |
| KERNEL32.dll | 875 | InterlockedCompareExchange | |
| KERNEL32.dll | 1384 | SuspendThread | |
| KERNEL32.dll | 770 | GetThreadContext | |
| KERNEL32.dll | 1337 | SetThreadContext | |
| KERNEL32.dll | 430 | FlushInstructionCache | |
| KERNEL32.dll | 1451 | VirtualAlloc | |
| KERNEL32.dll | 1457 | VirtualProtect | |
| KERNEL32.dll | 1459 | VirtualQuery | |
| MSVCR110.dll | 608 | _except_handler4_common | |
| MSVCR110.dll | 559 | _controlfp_s | |
| MSVCR110.dll | 758 | _invoke_watson | |
| MSVCR110.dll | 408 | __crtSetUnhandledExceptionFilter | |
| MSVCR110.dll | 315 | void __cdecl terminate(void) ?terminate@@YAXXZ | |
| MSVCR110.dll | 409 | __crtTerminateProcess | |
| MSVCR110.dll | 410 | __crtUnhandledException | |
| MSVCR110.dll | 571 | _crt_debugger_hook | |
| MSVCR110.dll | 376 | __CxxFrameHandler3 | |
| MSVCR110.dll | 112 | public: virtual __thiscall type_info::~type_info(void) ??1type_info@@UAE@XZ | |
| MSVCR110.dll | 1564 | memset | |
| MSVCR110.dll | 1563 | memmove_s | |
| MSVCR110.dll | 1688 | wmemcpy_s | |
| MSVCR110.dll | 1324 | _wcsnicmp | |
| MSVCR110.dll | 1670 | wcsnlen | |
| MSVCR110.dll | 107 | public: virtual __thiscall std::exception::~exception(void) ??1exception@std@@UAE@XZ | |
| MSVCR110.dll | 44 | public: __thiscall std::exception::exception(char const * const &, int) ??0exception@std@@QAE@ABQBDH@Z | |
| MSVCR110.dll | 45 | public: __thiscall std::exception::exception(class std::exception const &) ??0exception@std@@QAE@ABV01@@Z | |
| MSVCR110.dll | 329 | public: virtual char const * __thiscall std::exception::what(void)const ?what@exception@std@@UBEPBDXZ | |
| MSVCR110.dll | 1071 | _resetstkoflw | |
| MSVCR110.dll | 1418 | _wsplitpath_s | |
| MSVCR110.dll | 1384 | _wmakepath_s | |
| MSVCR110.dll | 1270 | _vscwprintf | |
| MSVCR110.dll | 1042 | _onexit | |
| MSVCR110.dll | 1168 | _strlwr_s | |
| MSVCR110.dll | 1227 | _ultow_s | |
| MSVCR110.dll | 1672 | wcsrchr | |
| MSVCR110.dll | 1460 | calloc | |
| MSVCR110.dll | 1280 | _vsnwprintf | |
| MSVCR110.dll | 1626 | swprintf_s | |
| MSVCR110.dll | 1104 | _set_purecall_handler | |
| MSVCR110.dll | 1522 | isprint | |
| MSVCR110.dll | 1604 | strcpy_s | |
| MSVCR110.dll | 1628 | swscanf_s | |
| MSVCR110.dll | 1433 | _wtoi | |
| MSVCR110.dll | 1562 | memmove | |
| MSVCR110.dll | 1378 | _wfullpath | |
| MSVCR110.dll | 1671 | wcspbrk | |
| MSVCR110.dll | 1320 | _wcslwr_s | |
| MSVCR110.dll | 1374 | _wfopen_s | |
| MSVCR110.dll | 1479 | fgetws | |
| MSVCR110.dll | 1675 | wcsspn | |
| MSVCR110.dll | 1662 | wcscspn | |
| MSVCR110.dll | 1560 | memcpy | |
| MSVCR110.dll | 349 | _CxxThrowException | |
| MSVCR110.dll | 1461 | ceil | |
| MSVCR110.dll | 1344 | _wcsupr_s | |
| MSVCR110.dll | 1536 | iswspace | |
| MSVCR110.dll | 1636 | tolower | |
| MSVCR110.dll | 1223 | _ui64tow_s | |
| MSVCR110.dll | 1667 | wcsncmp | |
| MSVCR110.dll | 1377 | _wfsopen | |
| MSVCR110.dll | 1473 | ferror | |
| MSVCR110.dll | 1489 | fputws | |
| MSVCR110.dll | 1656 | wcscat_s | |
| MSVCR110.dll | 1437 | _wtol | |
| MSVCR110.dll | 1559 | memcmp | |
| MSVCR110.dll | 1195 | _swab | |
| MSVCR110.dll | 851 | _itow_s | |
| MSVCR110.dll | 1549 | malloc | |
| MSVCR110.dll | 538 | _callnewh | |
| MSVCR110.dll | 115 | void __cdecl operator delete(void *) ??3@YAXPAX@Z | |
| MSVCR110.dll | 1057 | _purecall | |
| MSVCR110.dll | 1492 | free | |
| MSVCR110.dll | 1669 | wcsncpy_s | |
| MSVCR110.dll | 1661 | wcscpy_s | |
| MSVCR110.dll | 1483 | fopen_s | |
| MSVCR110.dll | 1484 | fprintf | |
| MSVCR110.dll | 1471 | fclose | |
| MSVCR110.dll | 1314 | _wcsicmp | |
| MSVCR110.dll | 138 | void __cdecl operator delete[](void *) ??_V@YAXPAX@Z | |
| MSVCR110.dll | 1561 | memcpy_s | |
| MSVCR110.dll | 1676 | wcsstr | |
| MSVCR110.dll | 1069 | _recalloc | |
| MSVCR110.dll | 367 | _XcptFilter | |
| MSVCR110.dll | 404 | __crtGetShowWindowMode | |
| MSVCR110.dll | 517 | _amsg_exit | |
| MSVCR110.dll | 420 | __getmainargs | |
| MSVCR110.dll | 480 | __set_app_type | |
| MSVCR110.dll | 1468 | exit | |
| MSVCR110.dll | 617 | _exit | |
| MSVCR110.dll | 540 | _cexit | |
| MSVCR110.dll | 784 | _ismbblead | |
| MSVCR110.dll | 556 | _configthreadlocale | |
| MSVCR110.dll | 482 | __setusermatherr | |
| MSVCR110.dll | 751 | _initterm_e | |
| MSVCR110.dll | 750 | _initterm | |
| MSVCR110.dll | 508 | _acmdln | |
| MSVCR110.dll | 644 | _fmode | |
| MSVCR110.dll | 555 | _commode | |
| MSVCR110.dll | 876 | _lock | |
| MSVCR110.dll | 1657 | wcschr | |
| MSVCR110.dll | 1238 | _unlock | |
| MSVCR110.dll | 539 | _calloc_crt | |
| MSVCR110.dll | 412 | __dllonexit | |
| MSVCR110.dll | 1650 | vswprintf_s | |
| USER32.dll | 49 | CharNextW | |
| USER32.dll | 558 | LoadStringW | |
| USER32.dll | 586 | MessageBoxW | |
| USER32.dll | 594 | MsgWaitForMultipleObjectsEx | |
| USER32.dll | 617 | PeekMessageW | |
| USER32.dll | 826 | TranslateMessage | |
| USER32.dll | 545 | LoadIconW | |
| USER32.dll | 547 | LoadImageW | |
| USER32.dll | 173 | DestroyWindow | |
| USER32.dll | 836 | UnregisterClassW | |
| USER32.dll | 646 | RegisterClassW | |
| USER32.dll | 113 | CreateWindowExW | |
| USER32.dll | 795 | ShowWindow | |
| USER32.dll | 532 | IsWindowVisible | |
| USER32.dll | 535 | KillTimer | |
| USER32.dll | 764 | SetTimer | |
| USER32.dll | 369 | GetMessageTime | |
| USER32.dll | 847 | UpdateLayeredWindow | |
| USER32.dll | 161 | DefWindowProcW | |
| USER32.dll | 424 | GetSystemMetrics | |
| USER32.dll | 809 | SystemParametersInfoA | |
| USER32.dll | 182 | DispatchMessageW | |
| ole32.dll | 25 | CoCreateInstance | |
| ole32.dll | 120 | CoTaskMemAlloc | |
| ole32.dll | 122 | CoTaskMemRealloc | |
| ole32.dll | 121 | CoTaskMemFree | |
| ole32.dll | 242 | IIDFromString | |
| ole32.dll | 152 | CreateStreamOnHGlobal | |
| ole32.dll | 437 | StringFromGUID2 | |
| ole32.dll | 349 | OleInitialize | |
| ole32.dll | 80 | CoInitializeSecurity | |
| ole32.dll | 378 | OleUninitialize | |
| ole32.dll | 78 | CoInitialize | |
| ole32.dll | 436 | StringFromCLSID | |
| ole32.dll | 24 | CoCreateGuid | |
| ole32.dll | 12 | CLSIDFromString | |
| ole32.dll | 125 | CoUninitialize | |
| OLEAUT32.dll | 184 | ||
| OLEAUT32.dll | 4 | ||
| OLEAUT32.dll | 6 | ||
| OLEAUT32.dll | 7 | ||
| OLEAUT32.dll | 277 | ||
| OLEAUT32.dll | 2 | ||
| OLEAUT32.dll | 201 | ||
| OLEAUT32.dll | 185 | ||
| OLEAUT32.dll | 8 | ||
| OLEAUT32.dll | 9 | ||
| OLEAUT32.dll | 200 | ||
| OLEAUT32.dll | 313 | ||
| OLEAUT32.dll | 19 | ||
| OLEAUT32.dll | 20 | ||
| OLEAUT32.dll | 21 | ||
| OLEAUT32.dll | 150 | ||
| OLEAUT32.dll | 149 | ||
| OLEAUT32.dll | 15 | ||
| OLEAUT32.dll | 16 | ||
| OLEAUT32.dll | 22 | ||
| gdiplus.dll | 628 | GdiplusShutdown | |
| gdiplus.dll | 286 | GdipGetImageEncoders | |
| gdiplus.dll | 287 | GdipGetImageEncodersSize | |
| gdiplus.dll | 77 | GdipCreateBitmapFromHBITMAP | |
| gdiplus.dll | 80 | GdipCreateBitmapFromScan0 | |
| gdiplus.dll | 497 | GdipSaveImageToStream | |
| gdiplus.dll | 142 | GdipDeleteFont | |
| gdiplus.dll | 86 | GdipCreateFont | |
| gdiplus.dll | 143 | GdipDeleteFontFamily | |
| gdiplus.dll | 87 | GdipCreateFontFamilyFromName | |
| gdiplus.dll | 200 | GdipDrawString | |
| gdiplus.dll | 596 | GdipSetTextRenderingHint | |
| gdiplus.dll | 602 | GdipStringFormatGetGenericDefault | |
| gdiplus.dll | 591 | GdipSetStringFormatLineAlign | |
| gdiplus.dll | 587 | GdipSetStringFormatAlign | |
| gdiplus.dll | 132 | GdipCreateStringFormat | |
| gdiplus.dll | 130 | GdipCreateSolidFill | |
| gdiplus.dll | 50 | GdipCloneBrush | |
| gdiplus.dll | 138 | GdipDeleteBrush | |
| gdiplus.dll | 629 | GdiplusStartup | |
| gdiplus.dll | 95 | GdipCreateHBITMAPFromBitmap | |
| gdiplus.dll | 79 | GdipCreateBitmapFromResource | |
| gdiplus.dll | 81 | GdipCreateBitmapFromStream | |
| gdiplus.dll | 73 | GdipCreateBitmapFromFile | |
| gdiplus.dll | 290 | GdipGetImageHeight | |
| gdiplus.dll | 300 | GdipGetImageWidth | |
| gdiplus.dll | 54 | GdipCloneImage | |
| gdiplus.dll | 474 | GdipReleaseDC | |
| gdiplus.dll | 257 | GdipGetDC | |
| gdiplus.dll | 144 | GdipDeleteGraphics | |
| gdiplus.dll | 289 | GdipGetImageGraphicsContext | |
| gdiplus.dll | 152 | GdipDisposeImage | |
| gdiplus.dll | 33 | GdipAlloc | |
| gdiplus.dll | 237 | GdipFree | |
| gdiplus.dll | 269 | GdipGetFontHeight | |
| gdiplus.dll | 151 | GdipDeleteStringFormat | |
| MSVCP110.dll | 727 | void __cdecl std::_Xbad_alloc(void) ?_Xbad_alloc@std@@YAXXZ | |
| MSVCP110.dll | 728 | void __cdecl std::_Xbad_function_call(void) ?_Xbad_function_call@std@@YAXXZ | |
| GDI32.dll | 261 | DeleteObject | |
| GDI32.dll | 49 | CreateCompatibleDC | |
| GDI32.dll | 713 | SelectObject | |
| GDI32.dll | 258 | DeleteDC | |
| GDI32.dll | 541 | GetObjectW | |
| SHELL32.dll | 195 | SHGetFileInfoW | |
| SHELL32.dll | 145 | SHCreateDirectoryExW | |
| SHELL32.dll | 205 | SHGetFolderPathW | |
| SHELL32.dll | 177 | SHFileOperationW | |
| SHLWAPI.dll | 56 | PathAppendW | |
| SHLWAPI.dll | 62 | PathCombineW | |
| SHLWAPI.dll | 144 | PathRemoveFileSpecW | |
| SHLWAPI.dll | 175 | SHCreateStreamOnFileEx | |
| SHLWAPI.dll | 343 | StrToIntW | |
| SHLWAPI.dll | 52 | PathAddBackslashW | |
| SHLWAPI.dll | 142 | PathRemoveExtensionW | |
| SHLWAPI.dll | 78 | PathFindFileNameW | |
| SHLWAPI.dll | 146 | PathRenameExtensionW | |
| SHLWAPI.dll | 76 | PathFindExtensionW | |
| SHLWAPI.dll | 128 | PathMatchSpecW | |
| SHLWAPI.dll | 154 | PathStripPathW | |
| SHLWAPI.dll | 98 | PathIsFileSpecW | |
| SHLWAPI.dll | 138 | PathRemoveBackslashW | |
| SHLWAPI.dll | 140 | PathRemoveBlanksW | |
| SHLWAPI.dll | 106 | PathIsRelativeW | |
| SHLWAPI.dll | 8 | AssocQueryStringW | |
| SHLWAPI.dll | 342 | StrToIntExW | |
| SHLWAPI.dll | 74 | PathFileExistsW | |
| SHLWAPI.dll | 96 | PathIsDirectoryW | |
| SHLWAPI.dll | 339 | StrToInt64ExW | |
| VERSION.dll | 8 | GetFileVersionInfoW | |
| VERSION.dll | 16 | VerQueryValueW | |
| VERSION.dll | 7 | GetFileVersionInfoSizeW | |
| CRYPT32.dll | 228 | CryptUnprotectData |
StringTable 040904b0
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft Visual Studio Express 2012 for Windows Desktop |
| FileVersion | 11.0.50727.42 built by: VSLRSTAGE |
| InternalName | WDExpress.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | WDExpress.exe |
| ProductName | Microsoft® Visual Studio® 2012 |
| ProductVersion | 11.0.50727.42 |
VS_FIXEDFILEINFO
| FileVersion | 11.0.50727.42 |
| ProductVersion | 11.0.50727.42 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 4 |
| FileType | 1 |
| FileSubtype | 0 |
Signers (1)
issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Code Signing PCA
serial: 3300000088590E3C511FE26A67000100000088
Certificates (4)
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
33:00:00:00:88:59:0e:3c:51:1f:e2:6a:67:00:01:00:00:00:88
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA
Validity
Not Before: Jul 26 20:50:41 2012 GMT
Not After : Oct 26 20:50:41 2013 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, OU=MOPR, CN=Microsoft Corporation
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b3:74:74:d0:82:3c:87:a7:9a:d4:8e:b2:04:42:
80:97:25:2e:e4:41:ce:93:63:36:5f:13:f2:b4:78:
98:80:c6:28:7e:cc:8a:13:ef:3d:37:8c:3b:09:a0:
d8:14:c5:5c:5e:d8:a9:1d:7f:01:c1:b3:98:1b:50:
77:ec:fe:ea:7c:45:cf:7f:e1:21:0e:c5:84:ca:9f:
0f:6b:b3:09:38:b7:74:c4:57:1e:be:f0:48:a8:79:
5a:df:0e:9b:1c:9a:a8:bc:c8:52:b5:0c:69:8f:84:
ce:71:55:7b:ff:09:20:bf:40:77:37:21:30:74:5b:
95:df:77:cb:a0:e5:c1:72:12:06:3d:f2:c8:55:6c:
af:c1:fb:6a:16:27:c8:f5:b3:61:e3:d9:ce:1b:0f:
1e:f4:e4:cd:4c:34:6c:3e:47:11:e7:02:2b:5f:14:
7a:04:07:f5:d7:3d:8b:db:67:7d:57:3e:35:eb:6d:
8d:01:40:8d:1a:87:96:e2:0f:77:4c:89:ba:38:9c:
fb:8e:02:91:db:22:0f:e5:d0:36:a9:b8:37:45:d0:
2a:fc:96:8d:c1:60:71:33:a5:88:b1:f6:c2:04:30:
87:5b:c3:d7:2f:b2:79:11:d8:8b:65:62:a2:8a:11:
66:5d:7e:7f:05:7a:73:8a:1f:7a:85:e5:cd:28:10:
d1:3d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
26:5B:3E:5B:5D:96:5F:E2:F7:77:88:7F:5E:45:53:58:A8:2E:5B:B8
X509v3 Key Usage: critical
Digital Signature
X509v3 Authority Key Identifier:
CB:11:E8:CA:D2:B4:16:58:01:C9:37:2E:33:16:16:B9:4C:9A:0A:1F
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
0f:de:40:49:88:91:d1:31:37:a3:44:38:69:b2:6a:2b:d4:91:
fb:68:85:ae:58:bb:1e:0c:8f:56:fa:99:d7:ca:97:27:4c:e8:
85:8e:79:69:2c:e4:bd:96:3f:e5:70:66:97:95:30:65:29:ad:
c6:ca:ac:f5:0f:79:a8:67:bf:69:f4:0f:97:e3:0a:0f:bf:ee:
96:76:29:b2:22:d0:33:c6:ff:8b:49:ad:ae:b2:fd:bf:25:ea:
ef:27:50:c0:eb:19:f8:1a:64:6a:a0:e1:17:59:af:f1:cf:ec:
81:a8:89:e8:b1:d2:14:06:e3:6a:6d:74:52:64:da:96:94:2a:
5c:69:6b:1f:ed:05:99:1a:dc:e8:65:aa:88:1b:15:95:1a:d3:
a4:51:96:fd:55:95:f8:63:8d:9f:14:0c:b1:9e:7f:4a:04:ff:
c3:66:ad:0a:af:ae:a4:de:63:fa:f0:ea:c3:b3:b2:eb:87:db:
c5:38:ad:b6:73:d2:78:64:ea:ec:21:5b:6b:3b:d6:44:22:f4:
81:52:a5:2b:43:29:8b:0c:a1:2a:71:82:42:cb:ab:1b:7e:d4:
a5:a7:ad:f7:de:f7:46:9a:ce:43:39:e8:2a:53:ed:cf:40:e4:
77:88:42:bf:47:16:e0:a5:36:6a:ef:a7:1a:8d:3a:3d:33:04:
f6:25:20:23
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:02:8e:42:00:00:00:00:00:1f
Signature Algorithm: sha1WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time-Stamp PCA
Validity
Not Before: Jan 9 22:25:58 2012 GMT
Not After : Apr 9 22:25:58 2013 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, OU=MOPR, OU=nCipher DSE ESN:F528-3777-8A76, CN=Microsoft Time-Stamp Service
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:96:ec:8e:47:4d:54:c2:5c:95:80:d7:4e:0b:3d:
bf:97:43:c3:4b:e3:60:67:11:2f:01:4d:0c:d8:d1:
46:2f:10:40:de:0b:a4:50:52:12:88:0b:43:7a:2d:
3f:ee:48:6e:66:c7:91:e6:03:ca:6e:ec:79:a9:6a:
23:9b:cd:62:9e:cd:6a:a4:3f:e7:a3:43:ff:62:47:
a1:b4:ba:44:fa:df:40:c1:85:54:7e:e8:a0:a7:2c:
43:23:9b:52:1f:32:35:f4:fe:9a:56:9f:8d:63:77:
7b:30:9e:0a:33:85:72:1b:ca:4a:c8:cc:25:cd:db:
5d:11:2e:c7:b0:8c:f1:8f:43:48:47:05:b5:7a:20:
0b:e5:f3:ef:c1:ba:f4:b3:d8:cd:38:8f:fb:21:aa:
3d:0a:6d:85:17:d0:ca:e7:86:03:c0:33:83:b5:25:
c4:cc:5a:9c:c4:c3:da:62:25:4d:53:25:14:61:8f:
fb:1b:e0:ec:f7:47:c6:80:45:e6:35:53:23:36:77:
ca:b0:dd:98:2b:39:c0:75:35:0f:dd:81:4c:21:3d:
76:30:c5:b2:b0:65:73:29:48:27:d8:c2:d2:b0:84:
47:bb:78:ba:d5:74:03:de:d7:4b:19:f7:53:de:78:
da:86:f7:61:88:26:33:b4:47:c6:a0:54:88:15:2b:
2c:75
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Subject Key Identifier:
2F:E8:46:C8:68:D3:6E:4F:B2:20:D0:DE:89:4E:F1:47:EE:48:C1:F2
X509v3 Authority Key Identifier:
23:34:F8:D9:52:46:70:0A:ED:40:FB:76:FB:B3:2B:B0:C3:35:B3:0F
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt
X509v3 Extended Key Usage:
Time Stamping
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
73:ff:7d:2e:9d:cd:8d:88:2b:7c:7d:e3:5e:15:71:e9:68:62:
f0:08:b6:43:56:c4:5c:4a:2d:68:d8:f9:48:11:91:f3:11:9c:
85:ec:12:d4:54:a0:75:a9:38:a1:59:7f:75:ee:c6:f5:34:d8:
54:a4:e2:d0:cc:7c:97:ab:93:75:30:97:07:1d:04:53:2c:36:
7f:7f:f1:40:1e:0c:9b:80:e2:12:0a:20:3a:31:c0:07:75:67:
e0:fa:34:9c:ec:88:fb:57:1c:e5:58:62:20:90:45:2f:5d:45:
a9:c8:8e:b3:7c:72:6d:10:27:c5:4b:d8:6f:a2:a8:12:b3:6d:
35:23:67:fa:2c:db:25:2d:b9:5d:b1:1e:05:e7:43:28:3e:9c:
05:76:77:f1:25:de:05:47:19:6d:de:49:85:a1:da:4a:4b:08:
46:21:35:a8:75:36:4c:b7:b3:08:aa:df:b7:2b:d9:be:2a:6a:
fd:df:35:17:cc:3f:0c:c7:dd:06:cf:4e:94:24:63:20:0b:2e:
24:ae:5f:43:44:12:7a:5c:dd:37:db:a4:45:b3:91:3a:12:57:
7d:e3:47:c6:66:d3:cf:9c:46:56:f4:4c:07:b1:e0:0c:aa:d5:
f6:d5:3c:a2:e0:b5:d4:f8:1c:7e:04:55:10:6b:18:f4:91:cd:
51:a7:95:65
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:33:26:1a:00:00:00:00:00:31
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
Validity
Not Before: Aug 31 22:19:32 2010 GMT
Not After : Aug 31 22:29:32 2020 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Code Signing PCA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:b2:72:59:5c:19:30:64:bf:1d:9a:60:20:20:42:
99:76:53:6c:3e:1b:d6:6f:cc:cb:f1:ea:6b:fe:97:
16:10:e0:df:3a:74:83:1a:b7:2f:a0:32:ec:ff:de:
c2:42:4e:23:d5:72:00:db:35:57:0a:89:ca:ae:20:
49:f4:f0:68:ac:4d:4b:8d:a5:bd:79:4b:71:9b:47:
07:da:fd:25:df:9d:75:88:cf:aa:73:44:7f:d7:81:
db:f3:bd:f2:36:a4:c9:5c:45:dc:af:ad:3d:e0:28:
68:97:1a:a7:a5:72:73:56:f1:17:94:e4:fd:35:94:
72:a0:d6:76:5f:1e:77:45:83:85:38:16:d0:73:5b:
05:ba:67:52:8d:a5:b2:69:2f:da:19:0b:fe:92:74:
29:e2:76:2f:54:dd:14:30:59:f8:d2:8d:62:fd:cb:
c9:5f:46:31:50:b9:27:13:e4:40:30:cf:72:29:10:
28:22:c7:37:4e:3d:a0:32:3d:90:cd:a1:38:06:85:
5c:4e:56:82:28:2a:05:32:b7:4b:d7:4f:63:e7:d2:
2d:62:f1:45:3d:e7:ac:08:00:f6:46:a1:9e:d1:5b:
8c:26:53:e8:7a:aa:4a:f2:46:cf:37:3c:38:9e:b4:
77:5c:a5:17:9e:8d:cb:11:8f:56:3c:c1:ac:09:5f:
03:d3
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Subject Key Identifier:
CB:11:E8:CA:D2:B4:16:58:01:C9:37:2E:33:16:16:B9:4C:9A:0A:1F
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
1.3.6.1.4.1.311.21.1:
.....
1.3.6.1.4.1.311.21.2:
....1N.&....`;.1o.<..-
1.3.6.1.4.1.311.20.2:
.
.S.u.b.C.A
X509v3 Authority Key Identifier:
0E:AC:82:60:40:56:27:97:E5:25:13:FC:2A:E1:0A:53:95:59:E4:A4
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
59:39:3e:7f:26:46:af:eb:6f:40:b1:32:b5:6a:eb:0e:2f:6e:
a8:49:f7:eb:5f:75:ed:4c:3b:2d:d7:43:ad:0b:fe:cb:e9:2d:
31:a3:23:cc:7c:50:98:80:21:5d:ac:3d:2f:4c:ba:a2:a8:56:
9c:e3:70:bb:b8:b4:f8:79:b5:49:72:f7:3e:ea:41:7f:ca:e1:
0c:17:69:cb:a5:9c:20:2d:fa:0b:50:c4:56:cd:2d:e3:4a:d2:
bc:70:e7:a8:0d:a2:03:a5:56:e0:b8:8a:4b:57:f2:95:42:9c:
f1:f3:ef:ee:e3:86:1f:34:3c:b8:56:9a:f0:53:23:85:2a:a4:
82:1c:93:e2:94:07:1d:f2:e2:4e:f8:8c:a1:ca:e8:13:a5:91:
4e:c8:1b:d2:8f:72:95:2a:71:6d:9b:1a:f8:1c:f0:53:d6:67:
cc:22:ff:5c:1d:cd:a2:8c:bd:27:b2:79:63:56:44:a2:51:cd:
f9:e9:a3:58:56:dd:9b:02:45:44:2f:5f:f4:da:ae:d4:82:32:
6e:fc:a4:95:13:e4:eb:69:e7:a9:a2:2c:be:c8:2b:10:0e:65:
8e:99:db:f5:a2:fa:12:26:09:65:38:94:f1:7a:1f:4a:bb:d1:
e1:56:e8:d0:78:96:18:5c:c9:35:16:5f:dd:93:1d:49:8e:2d:
be:ad:34:44:1c:ee:10:15:1a:00:5d:dd:35:5b:21:ce:98:c7:
09:ee:85:0e:8c:4f:6d:0e:13:4e:3d:7c:29:48:9c:72:d1:f3:
6c:ca:c1:ec:70:a3:57:92:57:7d:94:8d:a0:1b:48:03:5a:f7:
cf:a3:67:0a:74:a5:36:ed:2d:2f:17:c8:e6:72:37:12:f4:6f:
b1:3c:67:82:f9:52:b2:8d:33:16:65:1e:0e:8a:dd:10:de:64:
f4:6f:ce:46:d4:d3:17:e9:79:c4:04:b4:d3:fb:2c:df:1f:8a:
9e:ac:0a:fb:13:27:40:ad:e4:f9:e1:a9:7f:46:bb:07:60:47:
65:60:40:4e:b0:42:ec:4e:ed:b3:76:79:d8:0a:34:09:6d:1c:
80:31:1f:e2:0e:54:dd:e5:a1:fb:e5:47:10:ad:64:98:ff:50:
16:2e:7c:bf:05:21:7a:e2:95:41:27:69:c3:93:8f:95:c9:8d:
d8:9b:21:ae:0d:5c:9c:f0:a2:ae:86:68:83:0c:6a:2d:bb:76:
6b:00:1d:96:ad:f2:16:7b:f6:16:83:24:b9:88:cf:6a:a8:47:
31:2f:9a:dc:e3:71:3d:d7:00:7e:62:47:d1:ce:88:c9:b8:18:
fa:0e:72:8d:c1:a3:3d:af:02:40:6a:ff:69:9b:96:e2:10:a8:
10:b4:37:50:08:d6:c3:3d
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:16:68:34:00:00:00:00:00:1c
Signature Algorithm: sha1WithRSAEncryption
Issuer: DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
Validity
Not Before: Apr 3 12:53:09 2007 GMT
Not After : Apr 3 13:03:09 2021 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time-Stamp PCA
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:9f:a1:6c:b1:df:db:48:92:2a:7c:6b:2e:19:e1:
bd:e2:e3:c5:99:51:23:50:ad:ce:dd:18:4e:24:0f:
ee:d1:a7:d1:4c:ad:74:30:20:11:eb:07:d5:54:95:
15:49:94:1b:42:92:ae:98:5c:30:26:da:00:6b:e8:
7b:bd:ec:89:07:0f:f7:0e:04:98:f0:89:cc:1f:cb:
33:24:87:9d:f2:f4:67:1c:2c:fc:7b:e7:88:1d:ea:
e7:4e:a3:a1:c1:23:53:ca:8d:fa:45:cf:09:d0:5e:
af:d0:b0:42:04:a2:f9:a6:6c:93:67:d7:28:dc:46:
53:b0:86:d0:e5:28:46:2e:27:ac:86:4f:55:52:0c:
e4:03:2c:fb:6a:90:90:30:6e:87:f3:59:30:9d:fa:
7e:d6:97:b3:e8:21:97:7e:f8:d2:13:f3:08:b7:53:
6d:52:b4:45:90:9f:48:00:4a:47:66:11:27:29:66:
a8:97:e4:d3:06:81:4a:a2:f9:84:a7:11:47:14:09:
82:9f:84:ed:55:78:fe:01:9a:1d:50:08:85:00:10:
30:46:ed:b7:de:23:46:bb:c4:2d:54:9f:af:1e:78:
41:31:77:cc:9b:df:3b:83:93:a1:61:02:b5:1d:0d:
b1:fc:f7:9b:b2:01:ce:22:4b:54:ff:f9:05:c3:c2:
20:0b
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Subject Key Identifier:
23:34:F8:D9:52:46:70:0A:ED:40:FB:76:FB:B3:2B:B0:C3:35:B3:0F
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
1.3.6.1.4.1.311.21.1:
...
X509v3 Authority Key Identifier:
keyid:0E:AC:82:60:40:56:27:97:E5:25:13:FC:2A:E1:0A:53:95:59:E4:A4
DirName:/DC=com/DC=microsoft/CN=Microsoft Root Certificate Authority
serial:79:AD:16:A1:4A:A0:A5:AD:4C:73:58:F4:07:13:2E:65
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt
X509v3 Extended Key Usage:
Time Stamping
Signature Algorithm: sha1WithRSAEncryption
Signature Value:
10:97:8a:c3:5c:03:44:36:dd:e9:b4:ad:77:db:ce:79:51:4d:
01:b1:2e:74:71:5b:6d:0c:13:ab:ce:be:7b:8f:b8:2e:d4:12:
a2:8c:6d:62:b8:57:02:cb:4e:20:13:50:99:dd:7a:40:e2:57:
bb:af:58:9a:1c:e1:1d:01:86:ac:bb:78:f2:8b:d0:ec:3b:01:
ee:e2:be:8f:0a:05:c8:8d:48:e2:f0:53:15:dd:4f:ab:92:e4:
e7:8d:6a:d5:80:c1:e6:94:f2:06:2f:85:03:e9:91:2a:24:22:
70:fb:f6:fc:e4:78:99:2e:0d:f7:07:e2:70:bc:18:4e:9d:8e:
6b:0a:72:95:b8:a1:39:9c:67:2d:c5:51:0e:ea:62:5c:3f:16:
98:8b:20:3f:e2:07:1a:32:f9:cc:31:4a:76:31:3d:2b:72:0b:
c8:ea:70:3d:ff:85:0a:13:df:c2:0a:61:8e:f0:d7:b8:17:eb:
4e:8b:7f:c5:35:2b:5e:a3:bf:eb:bc:7d:0b:42:7b:d4:53:72:
21:ee:30:ca:bb:78:65:5c:5b:01:17:0a:14:0e:d2:da:14:98:
f5:3c:b9:66:58:b3:2d:2f:e7:f9:85:86:cc:51:56:e8:9d:70:
94:6c:ac:39:4c:d4:f6:79:bf:aa:18:7a:62:29:ef:a2:9b:29:
34:06:77:1a:62:c9:3d:1e:6d:1f:82:f0:0b:c7:2c:bb:cf:43:
b3:e5:f9:ec:7d:b5:e3:a4:a8:74:35:b8:4e:c5:71:23:12:26:
76:0b:3c:52:8c:71:5a:46:43:14:bc:b3:b3:b0:4d:67:c8:9f:
42:ff:80:79:21:80:9e:15:30:66:e8:42:12:5e:1a:c8:9e:22:
21:d0:43:e9:2b:e9:bb:f4:48:cc:2c:d4:d8:32:80:4c:26:2a:
48:24:5f:5a:ea:56:ef:a6:de:99:9d:ca:3a:6f:bd:81:27:74:
06:11:ee:76:21:bf:9b:82:c1:27:54:b6:b1:6a:3d:89:a1:76:
61:b4:6e:a1:13:a6:bf:aa:47:f0:12:6f:fd:8a:32:6c:b2:fe:
df:51:c8:8c:23:c9:66:bd:9d:1d:87:12:64:02:3d:2d:af:59:
8f:b8:e4:21:e5:b5:b0:ca:63:b4:78:54:05:d4:41:2e:50:ac:
94:b0:a5:78:ab:b3:a0:96:75:1a:d9:92:87:13:75:22:2f:32:
a8:08:6e:a0:5b:8c:25:bf:a0:ef:84:ca:21:d6:eb:1e:4f:c9:
9a:ee:49:e0:f7:01:65:6f:89:0b:7d:c8:69:c8:e6:6e:ea:a7:
97:ce:31:29:ff:0e:c5:5b:5c:d8:4d:1b:a1:d8:fa:2f:9e:3f:
2e:55:16:6b:c9:13:a3:fd
undefined method `first' for #
| offset | size | type | comment | |
|---|---|---|---|---|
| 0 | 423424 | EXE | 08/30/2012 01:15:11 | # |
| 15c1 | 15 | HTM | # | |
| 4bef0 | 3301 | PNG | (256 x 256) | # |
| 518b0 | 4465 | PNG | (256 x 256) | # |
| 576fc | 4898 | PNG | (256 x 256) | # |
| 67600 | 15840 | PKCS7 | Authenticode Signature | # |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[?] can't find file_offset of VA 0x48194
offset:( 0x )