| parent | PHD_CrackMe.exe | |
|---|---|---|
| filename | PHD_CrackMe.unpacked.exe | |
| size | 6946304 (0x69fe00) | |
| md5 | e7c138bab354e1bc490a7a4e7f2fbe6c | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xf8 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 152 | 20115 | 1 |
| 158 | 40219 | 60 |
| 170 | 40219 | 192 |
| 170 | 30319 | 74 |
| 171 | 30319 | 461 |
| 131 | 30729 | 5 |
| 147 | 30729 | 19 |
| 1 | 0 | 384 |
| 171 | 40219 | 67 |
| 154 | 40219 | 1 |
| 157 | 40219 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
| type | va | size | |
|---|---|---|---|
| EXPORT | 0 | 0 | |
| IMPORT | 0x5de424 | 0xb4 | |
| RESOURCE | 0x5f0000 | 0x74b50 | |
| EXCEPTION | 0 | 0 | |
| SECURITY | 0 | 0 | |
| BASERELOC | 0 | 0 | |
| DEBUG | 0 | 0 | |
| ARCHITECTURE | 0 | 0 | |
| GLOBALPTR | 0 | 0 | |
| TLS | 0 | 0 | |
| LOAD_CONFIG | 0x590b78 | 0x40 | |
| Bound_IAT | 0 | 0 | |
| IAT | 0 | 0 | |
| Delay_IAT | 0 | 0 | |
| CLR_Header | 0 | 0 |
| id | lang | string |
|---|---|---|
| 61440 | 1033 | Open |
| 61441 | 1033 | Save As |
| 61442 | 1033 | All Files (*.*) |
| 61443 | 1033 | Untitled |
| 61446 | 1033 | an unnamed file |
| 61457 | 1033 | &Hide |
| 61472 | 1033 | No error message is available. |
| 61473 | 1033 | Attempted an unsupported operation. |
| 61474 | 1033 | A required resource was unavailable. |
| 61475 | 1033 | Out of memory. |
| 61476 | 1033 | An unknown error has occurred. |
| 61477 | 1033 | Encountered an improper argument. |
| 61696 | 1033 | Incorrect filename. |
| 61697 | 1033 | Failed to open document. |
| 61698 | 1033 | Failed to save document. |
| 61699 | 1033 | Save changes to %1? |
| 61700 | 1033 | Failed to create empty document. |
| 61701 | 1033 | The file is too large to open. |
| 61702 | 1033 | Could not start print job. |
| 61703 | 1033 | Failed to launch help. |
| 61704 | 1033 | Internal application error. |
| 61705 | 1033 | Command failed. |
| 61706 | 1033 | Insufficient memory to perform operation. |
| 61707 | 1033 | System registry entries have been removed and the INI file (if any) was deleted. |
| 61708 | 1033 | Not all of the system registry entries (or INI file) were removed. |
| 61709 | 1033 | This program requires the file %s, which was not found on this system. |
| 61710 | 1033 | This program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. |
| 61712 | 1033 | Enter an integer. |
| 61713 | 1033 | Enter a number. |
| 61714 | 1033 | Enter an integer between %1 and %2. |
| 61715 | 1033 | Enter a number between %1 and %2. |
| 61716 | 1033 | Enter no more than %1 characters. |
| 61717 | 1033 | Select a button. |
| 61718 | 1033 | Enter an integer between 0 and 255. |
| 61719 | 1033 | Enter a positive integer. |
| 61720 | 1033 | Enter a date and/or time. |
| 61721 | 1033 | Enter a currency. |
| 61722 | 1033 | Enter a GUID. |
| 61723 | 1033 | Enter a time. |
| 61724 | 1033 | Enter a date. |
| 61728 | 1033 | Unexpected file format. |
| 61729 | 1033 | %1 Cannot find this file. Verify that the correct path and file name are given. |
| 61730 | 1033 | Destination disk drive is full. |
| 61731 | 1033 | Unable to read from %1, it is opened by someone else. |
| 61732 | 1033 | Unable to write to %1, it is read-only or opened by someone else. |
| 61733 | 1033 | Encountered an unexpected error while reading %1. |
| 61734 | 1033 | Encountered an unexpected error while writing %1. |
| 61744 | 1033 | %1: %2 Continue running script? |
| 61745 | 1033 | Dispatch exception: %1 |
| 61836 | 1033 | Unable to read write-only property. |
| 61837 | 1033 | Unable to write read-only property. |
| 61840 | 1033 | Unable to load mail system support. |
| 61841 | 1033 | Mail system DLL is invalid. |
| 61842 | 1033 | Send Mail failed to send message. |
| 61856 | 1033 | No error occurred. |
| 61857 | 1033 | An unknown error occurred while accessing %1. |
| 61858 | 1033 | %1 was not found. |
| 61859 | 1033 | %1 contains an incorrect path. |
| 61860 | 1033 | Could not open %1 because there are too many open files. |
| 61861 | 1033 | Access to %1 was denied. |
| 61862 | 1033 | An incorrect file handle was associated with %1. |
| 61863 | 1033 | Could not remove %1 because it is the current directory. |
| 61864 | 1033 | Could not create %1 because the directory is full. |
| 61865 | 1033 | Seek failed on %1 |
| 61866 | 1033 | Encountered a hardware I/O error while accessing %1. |
| 61867 | 1033 | Encountered a sharing violation while accessing %1. |
| 61868 | 1033 | Encountered a locking violation while accessing %1. |
| 61869 | 1033 | Disk full while accessing %1. |
| 61870 | 1033 | Attempted to access %1 past its end. |
| 61872 | 1033 | No error occurred. |
| 61873 | 1033 | An unknown error occurred while accessing %1. |
| 61874 | 1033 | Attempted to write to the reading %1. |
| 61875 | 1033 | Attempted to access %1 past its end. |
| 61876 | 1033 | Attempted to read from the writing %1. |
| 61877 | 1033 | %1 has a bad format. |
| 61878 | 1033 | %1 contained an unexpected object. |
| 61879 | 1033 | %1 contains an incorrect schema. |
| 61888 | 1033 | pixels |
| 62177 | 1033 | Uncheck |
| 62178 | 1033 | Check |
| 62179 | 1033 | Mixed |
| 62180 | 1033 | One or more auto-saved documents were found. |
| 62181 | 1033 | These are more recently saved than the currently open documents and contain changes that were made before the application closed. |
| 62182 | 1033 | Do you want to recover these auto-saved documents? |
| 62183 | 1033 | Note that if you choose to recover the auto-saved documents, you must explicitly save them to overwrite the original documents. If you choose to not recover the auto-saved versions, they will be deleted. |
| 62184 | 1033 | Recover the auto-saved documents Open the auto-saved versions instead of the explicitly saved versions |
| 62185 | 1033 | Don't recover the auto-saved documents Use the last explicitly saved versions of the documents |
| 62186 | 1033 | %s [Recovered] |
StringTable 040904b0
| CompanyName | ESET spol. s r.o. |
| FileDescription | PHDays'2012 CrackMe |
| FileVersion | 1.0.0.1 |
| InternalName | PHD_CrackMe |
| LegalCopyright | Copyright (c) 1992-2012 ESET, spol. s r.o. All rights reserved. |
| OriginalFilename | PHD_CrackMe.exe |
| ProductName | PHDays'2012 CrackMe |
| ProductVersion | 1.0.0.1 |
VS_FIXEDFILEINFO
| FileVersion | 1.0.0.1 |
| ProductVersion | 1.0.0.1 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 0x40004 |
| FileType | 1 |
| FileSubtype | 0 |
| offset | size | type | comment | |
|---|---|---|---|---|
| 15c1 | 15 | HTM | # | |
| 456544 | 77343 | PNG | (146 x 220) | # |
| 469367 | 74437 | PNG | (146 x 220) | # |
| 47b630 | 10777 | PNG | (650 x 54) | # |
| 4fd8b4 | 700 | PNG | (24 x 24) | # |
| 4fdb74 | 792 | PNG | (24 x 24) | # |
| 4fde90 | 985 | PNG | (32 x 32) | # |
| 4fe26d | 782 | PNG | (24 x 24) | # |
| 4fe57f | 1749 | PNG | (32 x 32) | # |
| 4fec58 | 620 | PNG | (24 x 24) | # |
| 4feec8 | 1330 | PNG | (32 x 32) | # |
| 4ff3fe | 820 | PNG | (24 x 24) | # |
| 4ff736 | 908 | PNG | (32 x 32) | # |
| 4ffac6 | 796 | PNG | (24 x 24) | # |
| 4ffde6 | 556 | PNG | (32 x 32) | # |
| 500016 | 1353 | PNG | (32 x 32) | # |
| 500563 | 797 | PNG | (24 x 24) | # |
| 500884 | 817 | PNG | (24 x 24) | # |
| 500bb9 | 984 | PNG | (32 x 32) | # |
| 500f95 | 1202 | PNG | (32 x 32) | # |
| 50144b | 948 | PNG | (32 x 32) | # |
| 501803 | 810 | PNG | (32 x 32) | # |
| 501b31 | 1302 | PNG | (24 x 24) | # |
| 50204b | 1004 | PNG | (32 x 32) | # |
| 50243b | 1330 | PNG | (32 x 32) | # |
| 502971 | 945 | PNG | (32 x 32) | # |
| 502d26 | 390 | PNG | (24 x 24) | # |
| 502eb0 | 1247 | PNG | (24 x 24) | # |
| 503393 | 706 | PNG | (24 x 24) | # |
| 503659 | 985 | PNG | (24 x 24) | # |
| 503a36 | 914 | PNG | (24 x 24) | # |
| 503dcc | 662 | PNG | (24 x 24) | # |
| 504066 | 1154 | PNG | (32 x 32) | # |
| 5044ec | 1873 | PNG | (32 x 32) | # |
| 504c41 | 1475 | PNG | (32 x 32) | # |
| 505208 | 1254 | PNG | (32 x 32) | # |
| 505ebc | 2991 | PNG | (64 x 64) | # |
| 506b24 | 578 | PNG | (16 x 16) | # |
| 506d6a | 406 | PNG | (16 x 16) | # |
| 506f04 | 516 | PNG | (16 x 16) | # |
| 50710c | 438 | PNG | (16 x 16) | # |
| 5072c6 | 845 | PNG | (16 x 16) | # |
| 507617 | 5601 | PNG | (128 x 128) | # |
| 508bfc | 231 | PNG | (16 x 16) | # |
| 508ce7 | 4069 | PNG | (128 x 128) | # |
| 509cd0 | 1279 | PNG | (30 x 32) | # |
| 50a1d3 | 1751 | PNG | (32 x 32) | # |
| 50a8ae | 602 | PNG | (16 x 16) | # |
| 50ab0c | 1798 | PNG | (32 x 32) | # |
| 50b216 | 396 | PNG | (16 x 16) | # |
| 50b3a6 | 549 | PNG | (32 x 32) | # |
| 50b5cf | 5414 | PNG | (128 x 128) | # |
| 50caf9 | 870 | PNG | (16 x 16) | # |
| 50ce63 | 1445 | PNG | (32 x 29) | # |
| 50d40c | 799 | PNG | (16 x 14) | # |
| 50d72f | 817 | PNG | (16 x 16) | # |
| 50da64 | 1267 | PNG | (24 x 24) | # |
| 50df5b | 1807 | PNG | (32 x 32) | # |
| 50e66e | 583 | PNG | (16 x 16) | # |
| 50e8b9 | 1006 | PNG | (32 x 32) | # |
| 50ecab | 1046 | PNG | (32 x 32) | # |
| 50f0c5 | 499 | PNG | (16 x 16) | # |
| 50f2bc | 1878 | PNG | (32 x 32) | # |
| 50fa16 | 423 | PNG | (16 x 16) | # |
| 50fbc1 | 5074 | PNG | (128 x 128) | # |
| 510f97 | 570 | PNG | (16 x 16) | # |
| 5111d5 | 1590 | PNG | (32 x 32) | # |
| 51180f | 185 | PNG | (32 x 32) | # |
| 5118cc | 1386 | PNG | (128 x 128) | # |
| 511e3a | 849 | PNG | (16 x 16) | # |
| 51218f | 7503 | PNG | (128 x 128) | # |
| 513ee2 | 416 | PNG | (16 x 16) | # |
| 514086 | 3296 | PNG | (128 x 128) | # |
| 514d6a | 713 | PNG | (32 x 32) | # |
| 515037 | 537 | PNG | (16 x 16) | # |
| 515254 | 248 | PNG | (16 x 16) | # |
| 515350 | 4743 | PNG | (128 x 128) | # |
| 5165db | 456 | PNG | (16 x 16) | # |
| 5167a7 | 938 | PNG | (16 x 16) | # |
| 516b55 | 1019 | PNG | (32 x 32) | # |
| 516f54 | 766 | PNG | (16 x 16) | # |
| 517256 | 814 | PNG | (16 x 16) | # |
| 517588 | 780 | PNG | (32 x 32) | # |
| 517898 | 166 | PNG | (16 x 16) | # |
| 517942 | 570 | PNG | (32 x 32) | # |
| 517b80 | 3997 | PNG | (128 x 128) | # |
| 518b21 | 2066 | PNG | (32 x 32) | # |
| 519337 | 1799 | PNG | (32 x 32) | # |
| 519a42 | 1804 | PNG | (32 x 32) | # |
| 51a152 | 566 | PNG | (16 x 16) | # |
| 51a38c | 629 | PNG | (16 x 16) | # |
| 51a605 | 176 | PNG | (32 x 32) | # |
| 51a6b9 | 1712 | PNG | (32 x 32) | # |
| 51ad6d | 524 | PNG | (32 x 32) | # |
| 51af7d | 9363 | PNG | (128 x 128) | # |
| 51d414 | 8109 | PNG | (128 x 128) | # |
| 51f3c5 | 1504 | PNG | (32 x 29) | # |
| 51f9a9 | 1103 | PNG | (35 x 34) | # |
| 51fdfc | 826 | PNG | (16 x 16) | # |
| 52013a | 14941 | PNG | (128 x 128) | # |
| 523b9b | 7039 | PNG | (128 x 128) | # |
| 52571e | 811 | PNG | (16 x 16) | # |
| 525a4d | 1154 | PNG | (32 x 32) | # |
| 525ed3 | 413 | PNG | (32 x 32) | # |
| 526074 | 5395 | PNG | (121 x 128) | # |
| 52758b | 802 | PNG | (16 x 16) | # |
| 5278b1 | 16418 | PNG | (128 x 128) | # |
| 52b8d7 | 9367 | PNG | (128 x 128) | # |
| 52dd72 | 2075 | PNG | (128 x 128) | # |
| 52e591 | 687 | PNG | (16 x 14) | # |
| 52e844 | 633 | PNG | (32 x 32) | # |
| 52eac1 | 6520 | PNG | (128 x 117) | # |
| 53043d | 1820 | PNG | (32 x 32) | # |
| 530b5d | 5415 | PNG | (128 x 128) | # |
| 532088 | 782 | PNG | (16 x 16) | # |
| 53239a | 1541 | PNG | (32 x 32) | # |
| 5329a3 | 1092 | PNG | (32 x 32) | # |
| 532deb | 490 | PNG | (16 x 16) | # |
| 532fd9 | 442 | PNG | (16 x 16) | # |
| 533197 | 584 | PNG | (16 x 16) | # |
| 5333e3 | 4398 | PNG | (128 x 128) | # |
| 534515 | 4232 | PNG | (128 x 126) | # |
| 5355a1 | 2205 | PNG | (32 x 32) | # |
| 535e42 | 9550 | PNG | (128 x 128) | # |
| 538394 | 481 | PNG | (16 x 16) | # |
| 538579 | 1654 | PNG | (24 x 24) | # |
| 538bf3 | 11250 | PNG | (128 x 128) | # |
| 53b7e9 | 4512 | PNG | (128 x 128) | # |
| 53c98d | 5155 | PNG | (128 x 128) | # |
| 53ddb4 | 370 | PNG | (16 x 16) | # |
| 53df2a | 384 | PNG | (16 x 16) | # |
| 53e0ae | 8093 | PNG | (128 x 128) | # |
| 54004f | 2431 | PNG | (32 x 32) | # |
| 5409d2 | 701 | PNG | (16 x 15) | # |
| 540c93 | 892 | PNG | (16 x 16) | # |
| 541013 | 1573 | PNG | (32 x 32) | # |
| 54163c | 262 | PNG | (16 x 16) | # |
| 541746 | 406 | PNG | (16 x 16) | # |
| 5418e0 | 866 | PNG | (32 x 32) | # |
| 541c46 | 10765 | PNG | (128 x 128) | # |
| 544657 | 668 | PNG | (16 x 14) | # |
| 5448f7 | 1603 | PNG | (32 x 32) | # |
| 544f3e | 12002 | PNG | (128 x 128) | # |
| 547e24 | 419 | PNG | (16 x 16) | # |
| 547fcb | 366 | PNG | (16 x 16) | # |
| 54813d | 1092 | PNG | (32 x 32) | # |
| 548585 | 840 | PNG | (16 x 16) | # |
| 5488d1 | 2245 | PNG | (32 x 32) | # |
| 54919a | 384 | PNG | (16 x 16) | # |
| 54931e | 2016 | PNG | (32 x 32) | # |
| 549b02 | 1192 | PNG | (32 x 32) | # |
| 549fae | 229 | PNG | (16 x 16) | # |
| 54a097 | 18075 | PNG | (128 x 128) | # |
| 54e736 | 474 | PNG | (32 x 32) | # |
| 54e914 | 611 | PNG | (15 x 16) | # |
| 54eb7b | 689 | PNG | (16 x 16) | # |
| 54ee30 | 2010 | PNG | (32 x 32) | # |
| 54f60e | 722 | PNG | (16 x 16) | # |
| 54f8e4 | 9432 | PNG | (128 x 128) | # |
| 551dc0 | 883 | PNG | (32 x 32) | # |
| 552137 | 773 | PNG | (16 x 16) | # |
| 552440 | 3094 | PNG | (128 x 128) | # |
| 55305a | 1246 | PNG | (32 x 32) | # |
| 55353c | 6554 | PNG | (128 x 116) | # |
| 554eda | 548 | PNG | (32 x 32) | # |
| 555102 | 885 | PNG | (16 x 16) | # |
| 555477 | 1354121 | BIN | overlay data past EOF | # |
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )