parent | worksxc_220.exe | |
---|---|---|
filename | worksxc_220.unpacked.exe | |
size | 477259 (0x7484b) | |
md5 | e26205c83d77d1c5e938e16dfb5fec0b | |
type | PE32 executable (GUI) Intel 80386, for MS Windows | |
mimetype | application/x-dosexec | |
clamav | OK | |
virustotal | → scan with virustotal.com | |
histogram |
MZ Header
signature | MZ |
bytes_in_last_block | 0x90 |
blocks_in_file | 3 |
num_relocs | 0 |
header_paragraphs | 4 |
min_extra_paragraphs | 0 |
max_extra_paragraphs | 0xffff |
ss | 0 |
sp | 0xb8 |
checksum | 0 |
ip | 0 |
cs | 0 |
reloc_table_offset | 0x40 |
overlay_number | 0 |
reserved0 | 0 |
oem_id | 0 |
oem_info | 0 |
reserved2 | 0 |
reserved3 | 0 |
reserved4 | 0 |
reserved5 | 0 |
reserved6 | 0 |
lfanew | 0x80 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
name | va | vsize | raw size | flags | |
---|---|---|---|---|---|
.text | 0x1000 | 0x365a | 0x3800 | R-X CODE | |
.rdata | 0x5000 | 0xd83 | 0xe00 | R-- IDATA | |
.data | 0x6000 | 0x16a7c | 0x600 | RW- IDATA | |
.idata | 0x1d000 | 0x68c | 0x800 | RW- IDATA | |
.rsrc | 0x1e000 | 0xa90 | 0xc00 | R-- IDATA |
Data Directory
type | va | size | |
---|---|---|---|
EXPORT | 0 | 0 | |
IMPORT | 0x1d000 | 0x8c | |
RESOURCE | 0x1e000 | 0xa90 | |
EXCEPTION | 0 | 0 | |
SECURITY | 0 | 0 | |
BASERELOC | 0 | 0 | |
DEBUG | 0 | 0 | |
ARCHITECTURE | 0 | 0 | |
GLOBALPTR | 0 | 0 | |
TLS | 0 | 0 | |
LOAD_CONFIG | 0 | 0 | |
Bound_IAT | 0 | 0 | |
IAT | 0 | 0 | |
Delay_IAT | 0 | 0 | |
CLR_Header | 0 | 0 |
id | lang | string |
---|---|---|
1 | 1033 | No package found |
2 | 1033 | Couldn't execute command |
3 | 1033 | Unexpected end of package |
4 | 1033 | Unknown header |
5 | 1033 | Unsupported zip method |
6 | 1033 | Can't write file |
7 | 1033 | Out of memeory |
8 | 1033 | Corrupted package |
9 | 1033 | RL SOFTWARE SELF EXTRACTOR (www.rl-software.com) |
10 | 1033 | &Install |
11 | 1033 | &Exit |
12 | 1033 | Loading.. |
13 | 1033 | Uncompressing |
14 | 1033 | Starting |
15 | 1033 | B&rowse |
16 | 1033 | Create |
17 | 1033 | Select the destination folder |
18 | 1033 | Destination path |
19 | 1033 | You have entered an unvalid path. Please browse again. |
20 | 1033 | Configuration file |
21 | 1033 | Uninstalling "%s" |
22 | 1033 | Finished. |
Scanning the drive for archives: 1 file, 477259 bytes (467 KiB) -- Type = zip Offset = 25604 Physical Size = 451655 Date Time Attr Size Compressed Name ------------------- ----- ------------ ------------ ------------------------ 2004-11-27 13:40:15 ....A 92 88 __config.sfx 2008-08-28 07:46:51 ....A 205312 199212 setup.exe 2008-08-08 09:05:23 ....A 526 330 __config.rtf 2005-12-07 09:13:09 ....A 6656 4934 Uninstall.exe 2008-08-28 10:44:32 ....A 50688 18595 wksxcnv.xla 2008-08-20 09:40:35 ....A 8840 3525 wksxinfo.rtf 2001-04-03 09:40:22 ....A 19456 6419 RemoveWksBars.xla 2001-06-21 20:52:46 ....A 50 50 RL-Software Website.url 2008-08-18 07:56:26 ....A 135680 123851 WKSXCNV.dll 2008-08-28 11:17:51 ....A 63851 56490 info.chm 2008-08-28 11:16:23 ....A 44164 36629 rlorder.chm ------------------- ----- ------------ ------------ ------------------------ 2008-08-28 11:17:51 535315 450123 11 files
Please donate some bucks to keep this site up and running: | |
Ko-fi | |
---|---|
Yandex.Money | |
Thank you! |
everything is OK