Static | ZeroBOX

PE Compile Time

2013-10-14 14:50:27

PDB Path

wextract.pdb

PE Imphash

bc70c4fa605f17c85050b7c7b6d42e44

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000065cc 0x00006600 6.38489758163
.data 0x00008000 0x00001a8c 0x00000400 3.17592784688
.idata 0x0000a000 0x00001078 0x00001200 5.04857670572
.rsrc 0x0000c000 0x00020000 0x0001f400 6.87527934946
.reloc 0x0002c000 0x000013ae 0x00001400 3.72277223578

Resources

Name Offset Size Language Sub-language File type
AVI 0x0000cb30 0x00002e1a LANG_ENGLISH SUBLANG_ENGLISH_US RIFF (little-endian) data, AVI, 272 x 60, 10.00 fps, video: RLE 8bpp
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000242d8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_DIALOG 0x00025a60 0x0000011c LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_STRING 0x0002889c 0x00000332 LANG_TURKISH SUBLANG_DEFAULT data
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_RCDATA 0x0002a360 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_GROUP_ICON 0x0002a374 0x000000bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0002a84c 0x00000418 LANG_TURKISH SUBLANG_DEFAULT data
RT_VERSION 0x0002a84c 0x00000418 LANG_TURKISH SUBLANG_DEFAULT data
RT_MANIFEST 0x0002ac64 0x000005e7 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x40a000 OpenProcessToken
0x40a004 GetTokenInformation
0x40a008 RegSetValueExA
0x40a00c EqualSid
0x40a010 RegQueryValueExA
0x40a018 RegCreateKeyExA
0x40a01c RegOpenKeyExA
0x40a020 RegQueryInfoKeyA
0x40a024 RegDeleteValueA
0x40a02c FreeSid
0x40a034 RegCloseKey
Library KERNEL32.dll:
0x40a064 GetFileAttributesA
0x40a068 IsDBCSLeadByte
0x40a06c GetSystemDirectoryA
0x40a070 GlobalUnlock
0x40a074 GetShortPathNameA
0x40a078 CreateDirectoryA
0x40a07c FindFirstFileA
0x40a080 GetLastError
0x40a084 GetProcAddress
0x40a088 RemoveDirectoryA
0x40a08c SetFileAttributesA
0x40a090 GlobalFree
0x40a094 FindClose
0x40a09c LoadLibraryA
0x40a0a0 LocalAlloc
0x40a0a8 GetModuleFileNameA
0x40a0ac FindNextFileA
0x40a0b0 CompareStringA
0x40a0b4 _lopen
0x40a0b8 CloseHandle
0x40a0bc LocalFree
0x40a0c0 DeleteFileA
0x40a0c4 ExitProcess
0x40a0cc CreateFileA
0x40a0d0 FindResourceA
0x40a0d4 GlobalAlloc
0x40a0dc LoadResource
0x40a0e0 WaitForSingleObject
0x40a0e4 SetEvent
0x40a0e8 GetModuleHandleW
0x40a0ec FormatMessageA
0x40a0f0 SetFileTime
0x40a0f4 WriteFile
0x40a0f8 GetDriveTypeA
0x40a100 TerminateThread
0x40a104 SizeofResource
0x40a108 CreateEventA
0x40a10c GetExitCodeProcess
0x40a110 CreateProcessA
0x40a114 _llseek
0x40a11c GetTempFileNameA
0x40a120 ResetEvent
0x40a124 LockResource
0x40a128 GetSystemInfo
0x40a12c LoadLibraryExA
0x40a130 CreateMutexA
0x40a138 GetVersionExA
0x40a13c GetVersion
0x40a140 GetTempPathA
0x40a144 CreateThread
0x40a14c SetFilePointer
0x40a154 lstrcmpA
0x40a158 _lclose
0x40a15c GlobalLock
0x40a160 GetCurrentProcess
0x40a164 FreeResource
0x40a168 FreeLibrary
0x40a16c Sleep
0x40a170 GetStartupInfoA
0x40a17c TerminateProcess
0x40a180 OutputDebugStringA
0x40a184 RtlUnwind
0x40a188 GetModuleHandleA
0x40a190 GetCurrentProcessId
0x40a194 GetCurrentThreadId
0x40a19c GetTickCount
0x40a1a4 MulDiv
0x40a1a8 GetDiskFreeSpaceA
0x40a1ac ReadFile
Library GDI32.dll:
0x40a058 GetDeviceCaps
Library USER32.dll:
0x40a1b4 GetDC
0x40a1b8 SendMessageA
0x40a1bc SetForegroundWindow
0x40a1c4 SendDlgItemMessageA
0x40a1c8 GetWindowRect
0x40a1cc MessageBoxA
0x40a1d0 GetWindowLongA
0x40a1d4 PeekMessageA
0x40a1d8 ReleaseDC
0x40a1dc GetDlgItem
0x40a1e0 SetWindowPos
0x40a1e4 ShowWindow
0x40a1e8 DispatchMessageA
0x40a1ec SetWindowTextA
0x40a1f0 EnableWindow
0x40a1f4 CallWindowProcA
0x40a1fc GetDlgItemTextA
0x40a200 LoadStringA
0x40a204 MessageBeep
0x40a208 CharUpperA
0x40a20c CharNextA
0x40a210 ExitWindowsEx
0x40a214 CharPrevA
0x40a218 EndDialog
0x40a21c GetDesktopWindow
0x40a220 SetDlgItemTextA
0x40a224 SetWindowLongA
0x40a228 GetSystemMetrics
Library msvcrt.dll:
0x40a240 memset
0x40a244 ?terminate@@YAXXZ
0x40a248 _controlfp
0x40a24c memcpy
0x40a250 _ismbblead
0x40a254 __p__fmode
0x40a258 _cexit
0x40a25c _exit
0x40a260 exit
0x40a264 __set_app_type
0x40a268 __getmainargs
0x40a26c _acmdln
0x40a270 _initterm
0x40a274 _amsg_exit
0x40a278 __p__commode
0x40a27c _XcptFilter
0x40a280 _errno
0x40a284 _vsnprintf
0x40a288 __setusermatherr
Library COMCTL32.dll:
0x40a03c None
Library Cabinet.dll:
0x40a044 None
0x40a048 None
0x40a04c None
0x40a050 None
Library VERSION.dll:
0x40a230 GetFileVersionInfoA
0x40a238 VerQueryValueA

!This program cannot be run in DOS mode.
`.data
.idata
@.rsrc
@.reloc
Invalid parameter passed to C runtime function.
advapi32.dll
CheckTokenMembership
Reboot
AdvancedINF
Version
setupx.dll
setupapi.dll
SeShutdownPrivilege
advpack.dll
DelNodeRunDLL32
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
HeapSetInformation
EXTRACTOPT
INSTANCECHECK
VERCHECK
DecryptFileA
LICENSE
<None>
REBOOT
SHOWWINDOW
ADMQCMD
USRQCMD
RUNPROGRAM
POSTRUNPROGRAM
FINISHMSG
LoadString() Error. Could not load string resource.
CABINET
FILESIZES
PACKINSTSPACE
UPROMPT
IXP%03d.TMP
msdownld.tmp
TMP4351$.TMP
RegServer
UPDFILE%lu
Control Panel\Desktop\ResourceLocale
wextract.pdb
PQQQQQQh
PSSSSSSh
PSSShp
D$<tVhH
PVVVVVV
D$HjDj
t$ u"3
WWj WWWVW
:<\u6:
<At <Bt
jXhhu@
j"_VVVVV
URPQQh
UQPXY]Y[
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
System\CurrentControlSet\Control\Session Manager
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
Command.com /c %s
rundll32.exe %s,InstallHinfSection %s 128 %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
DefaultInstall
%s /D:%s
PendingFileRenameOperations
*MEMCAB
SHBrowseForFolder
SHELL32.DLL
DoInfInstall
SHGetPathFromIDList
OpenProcessToken
GetTokenInformation
RegSetValueExA
EqualSid
RegQueryValueExA
LookupPrivilegeValueA
RegCreateKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegDeleteValueA
AllocateAndInitializeSid
FreeSid
AdjustTokenPrivileges
RegCloseKey
ADVAPI32.dll
lstrcmpA
_llseek
FreeLibrary
GetCurrentProcess
GlobalLock
_lclose
ExpandEnvironmentStringsA
GetWindowsDirectoryA
GlobalAlloc
GetPrivateProfileIntA
GetFileAttributesA
IsDBCSLeadByte
GetSystemDirectoryA
GlobalUnlock
GetShortPathNameA
CreateDirectoryA
FindFirstFileA
GetLastError
GetProcAddress
RemoveDirectoryA
SetFileAttributesA
GlobalFree
FindClose
GetPrivateProfileStringA
LoadLibraryA
LocalAlloc
WritePrivateProfileStringA
GetModuleFileNameA
FindNextFileA
CompareStringA
_lopen
CloseHandle
LocalFree
DeleteFileA
ExitProcess
DosDateTimeToFileTime
CreateFileA
FindResourceA
SetFilePointer
FreeResource
LoadResource
WaitForSingleObject
SetEvent
GetModuleHandleW
FormatMessageA
SetFileTime
WriteFile
GetDriveTypeA
GetVolumeInformationA
TerminateThread
SizeofResource
CreateEventA
GetExitCodeProcess
CreateProcessA
ReadFile
SetCurrentDirectoryA
GetTempFileNameA
ResetEvent
LockResource
GetSystemInfo
LoadLibraryExA
CreateMutexA
GetCurrentDirectoryA
GetVersionExA
GetVersion
GetTempPathA
CreateThread
LocalFileTimeToFileTime
KERNEL32.dll
GetDeviceCaps
GDI32.dll
SetDlgItemTextA
GetDesktopWindow
EndDialog
CharPrevA
ExitWindowsEx
CharNextA
CharUpperA
MessageBeep
LoadStringA
GetDlgItemTextA
DialogBoxIndirectParamA
CallWindowProcA
EnableWindow
SetWindowTextA
DispatchMessageA
ShowWindow
SetWindowPos
GetDlgItem
ReleaseDC
PeekMessageA
GetWindowLongA
MessageBoxA
SetWindowLongA
SendMessageA
SetForegroundWindow
MsgWaitForMultipleObjects
SendDlgItemMessageA
GetWindowRect
USER32.dll
_vsnprintf
_errno
_XcptFilter
__p__commode
_amsg_exit
__getmainargs
__set_app_type
_cexit
__p__fmode
_ismbblead
__setusermatherr
_initterm
_acmdln
msvcrt.dll
memcpy
memset
?terminate@@YAXXZ
_controlfp
COMCTL32.dll
Cabinet.dll
VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
VERSION.dll
GetStartupInfoA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
OutputDebugStringA
RtlUnwind
GetModuleHandleA
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
GetTickCount
EnumResourceLanguagesA
MulDiv
GetDiskFreeSpaceA
GetSystemMetrics
AVI LIST
hdrlavih8
strlstrh8
vidsRLE
LISTv$
movi00dc(
wgwwxx
wwwwwwp
wwwwwwp
\)((Bc
tZXXXj!
kXZt&'pp
\Xt'Qp
IhhI>In
IG>G>h
:>G>G>h
ICGIGn
:>>>H>r
eeRC>:y
RCIeeee
kII=GCR
>~32"*_h
nhII:h
h40.+Il
{{aFIdqx
WPMMMPPUW
WWWUWW
W***lf
****kf
PM/1NJ\
~dD>>CEwC9
8w>68~
~xxwwEwu~
ExxwwEEx
X)$DJF
}:75235:p~
"&&4(A?=
(@KM<"
Q999999999Q
GGGGGGGGGGG
wh:Mzn
{BPMS}
h0`0p@o6kll4
,m$I"=
[H)Yk6x
gF@m1%
(C!xg0
?Ed`n0
6_z0#;
Gx:=,F1
]h]e()I
ij8::f{{
iw;t:=
B/#5/s
xl}QO.
Gg}W_n
(Nhsp
$&Bu^C
VaL_d1PY
n`nT";
78><bp
RCYH($
Bj,*3E
t\gWh$
F'u@&:
GdYNRV
<g0>&o
ZpNbx!
nE&Lh/
PH7TJ)
Mx!]x1
9NZ|QA9
!#hG*I
VLon8:
4mp-LeQ
[|Y2
|Zg}UUK
Z-Y,fX
b3eSAy
R!Spss
dCJ5@K
GGGXky
aaV<^-
|bdA*0jq
@^@i-"
D,evd2
6X'e7U
@75MU:
cVUI)#j]
M{Zk}Hr-@
f?:88x#
W%y%)JMU
pINJJ<KP[Efk
Y%HRIZH
x4z]*EU
G`Zw-B)p
4K9=9e
T1R;D2]
j[3PC"$
2yT(t
A6@XAY
mma[W[
uUQ45MS#
L&V)eNNN
Y.s0)Q4a
'FtHc1
n@WXl3
TX@'IR
_>99y5I
)%u]Q
8I&DQF
QIDAT{
UUqttt
I\D <,
#)QQD"#
W6Z]#P\
LaFN"M
la:EOu#
c:gazz
?<tyt
gA`0)%UJ
9=D2'O
yyHaOO
P@@sRCCRCC
O??qYIIYVEECRBB
L==^\KKpYHHeUDD2SDD
J<<Q[IIaZIIfXGGKVFF1WII
J<<BYHHSYHHVXHHCXHH8SDD#RCC
H::2UEE:UDD9TEE)SCC"SED
SCC%RBB"QBB
]LLNQBB
aOOx[JJgSCC%QBB
\JJX[IIdZJJQUEE&QBB
ZII?XGGKXGG?TDD0SDD
SCC%QBB
ab`L4K*
ZZ[:443
WFFYO??
eee8AB@
[IIZYHHRVFF;RCC
jjj;FFD
[HH/RBBRBB
ggg=EED
FFF?@>?
[\\?>>=
]^^@JAC
^__AQFJ
cccCIHH
YYYEHGG
TTTI444
WWWILLL
PA<None>
Tumeg.bat
3:;[Sf
V'CAh
0mf,IL
\E+Xg`F
QbU'Q+
{xjB47
p6Ej=+
sdc_~}
<None>
P<None>
<None>
cmd /c "Tumeg.bat"
PA<None>
P%UserQuietInstCmd%
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="5.1.0.0"
processorArchitecture="x86"
name="wextract"
type="win32"/>
<description>IExpress extraction tool</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
</application>
</compatibility>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
6(626f6m6|6
7 7*7=7e7
8'9S9b9
:8:=:B:H:R:
;7<@<N<t<
<>=V=c=|=
=%>0>A>H>_>k>
?(?.?I?c?
0%0A0L0u0
1!1-1U1
2W2e2q2
4%5P5{5
6#6A6q6{6
7-7>7Y7n7w7
::&:>:]:f:u:
:;%;+;2;7;Y;h;
<%<-<><E<Q<Y<b<h<
=!=*=D=x=}=
>!>+>3>8>B>V>]>
??,?1?8???G?R?W?_?e?r?
)040:0m0y0
1J1S1^1o1
1)232=2N2U2[2g2n2{2
3#3.343:3@3T3Z3k3
4E4X4q4
5"575=5T5Z5`5f5
7:7C7j7
8!8'828C8K8U8d8j8r8
9.949=9B9g9x9
:+:G:[:
:6;>;\;q;
<6<F<Q<
>$>[>j>
?,?R?o?x?
0"0-080F0]0k0{0
5'535J5`5
7 7)7A7J7O7U7[7e7k7
858@8_8e8{8
9+9>9L9W9]9}9
<#<(<-<3<L<g<w<
='=A=H=M=R=W=\=a=f=l=z=
>/>4>W>c>h>z>
>?%?0?7?B?b?m?u?
0/050E0L0a0
1*1V1m1
232=2V2_2e2s2{2
3!3,333@3G3L3Z3h3
6 6A6K6Z6a6r6
7"878D8L8T8^8
<<(<4<:<V<`<
?(?G?s?
0%030;0
151G1T1~1
5!5@5M5t5
6"6P6X6
7'717=7C7J7S7Y7a7g7t7|7
8,8D8L8T8]8b8x8
9"9,9G9u9{9
::&:=:C:I:O:U:[:b:i:p:w:~:
;+;4;L;R;X;^;d;j;q;x;
33(313F3[3h3p3
Kernel32.dll
ADMQCMD
CABINET
EXTRACTOPT
FILESIZES
FINISHMSG
LICENSE
PACKINSTSPACE
POSTRUNPROGRAM
REBOOT
RUNPROGRAM
SHOWWINDOW
UPROMPT
USRQCMD
License
MS Shell Dlg
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
Do you accept all of the terms of the preceding License Agreement? If you choose No, Install will close. To install you must accept this agreement.
Lisans
MS Shell Dlg
daki lisans s
mesini okuyun. S
menin devam
rmek i
in PAGE DOWN tu
una bas
daki Lisans S
mesi'nin t
mlerini kabul ediyor musunuz? Hay
erseniz, y
kleme sona erecektir. Y
klemeye devam etmek i
in bu s
meyi kabul etmelisiniz.
Temporary folder
MS Shell Dlg
Please type the location where you want to place the extracted files.
&Browse...
Cancel
ici klas
MS Shell Dlg
klanan dosyalar
n yerle
tirilece
i konumu yaz
zat...
Overwrite file
MS Shell Dlg
Do you want to overwrite the file:
Yes To &All
Dosyan
zerine yaz
MS Shell Dlg
Bu dosyan
zerine yaz
ne Evet
Extract
MS Shell Dlg
&Cancel
Extracting
Initializing... Please wait...
msctls_progress32
Generic1
SysAnimate32
MS Shell Dlg
yor... Bekleyin...
msctls_progress32
Generic1
SysAnimate32
Extract
MS Shell Dlg
&Cancel
Extracting
Initializing... Please wait...
MS Shell Dlg
yor... Bekleyin...
Warning
MS Shell Dlg
&Continue
Do you want to continue?
MS Shell Dlg
&Devam
Devam etmek istiyor musunuz?
4Please select a folder to store the extracted files.
tfen ay
klanan dosyalar
n saklanaca
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
#Unable to create extraction thread.
Cabinet is not valid.
Filetable full.%Can not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.@Disk alan
bilgileri al
namayan s
Sistem
letisi: %s.Gereken bir kaynak bulunam
ptal etmek istedi
inizden emin misiniz?
letim sistemi s
m bilgileri al
yor.$Bellek ay
rma iste
z oldu.
klama dosyas
turulam
Kabin ge
ersiz.
Dosya tablosu dolu.
Hedef klas
tirilemiyor.
Kur, program
klemek i
in %s KB bo
disk alan
olan bir s
bulamad
nce biraz alan bo
n ve YEN
DEN DENE'ye veya kurdan
kmak i
PTAL'e bas
n.ZBu klas
ersiz. L
tfen bu klas
n var oldu
undan ve yaz
labilir oldu
undan emin olun.@Bir klas
in tam yolunu belirtmeli veya
ptal'i se
melisiniz.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process <%s>. Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Do you still want to continue?
zenleme kutusu g
ncelle
tirilemedi.;Taray
ileti
im kutusu i
in gereken i
levler y
klenemedi.>Taray
ileti
im kutusu i
in gereken Shell32.dll y
klenemedi.
*<%s> i
lemini olu
turma hatas
. Neden: %s)Bu sistemdeki k
me boyutu desteklenmiyor."Gereken bir kaynak bozuk olabilir.XBu y
kleme i
in Windows 95 ya da Windows NT 4.0 Beta 2 veya daha sonraki s
gerekir.
kleme hatas
`'%s' i
levinde GetProcAddress() ba
z. Olas
neden: yanl
advpack.dll s
kullan
yor.0Y
klemek i
in Windows 95 veya Windows NT gerekli
'%s' klas
turulamad
Bu program
klemek i
in %s KB bo
disk alan
nde gerekiyor. Devam etmeden
nce gereken alan
altman
nerilir.
Yine de devam etmek istiyor musunuz?
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
Windows klas
alma hatas
,NT Oturumunu Kapat: OpenProcessToken hatas
.1NT Oturumunu Kapat: AdjustTokenPrivileges hatas
.)NT Oturumunu Kapat: ExitWindowsEx hatas
Dosya ay
klamas
z. Yetersiz bellek (takas dosyas
in yetersiz bo
disk alan
) veya bozuk Kabin dosyas
en olas
nedendir.PKurma program
(%s) i
in birim bilgilerini alamad
Sistem iletisi: %s.yKur, program
klemek i
in %s KB bo
disk alan
olan bir s
bulamad
tfen biraz alan bo
n ve yeniden deneyin.ZY
kleme program
zarar g
veya bozulmu
olabilir. Bu uygulaman
vurun.
;Command line option syntax error. Type Command /? for Help.
Command line options:
/Q -- Quiet modes for package,
/T:<full path> -- Specifies temporary working folder,
/C -- Extract files only to the folder when used also with /T.
/C:<Cmd> -- Override Install Command defined by author.
sYou must restart your computer before the new settings will take effect.
Do you want to restart your computer now?
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
CKomut sat
zdizimi hatas
. Yard
in Komut /? yaz
Komut sat
enekleri:
/Q -- Paket i
in sessiz modlar,
/T:<tam yol> -- Ge
ma dosyas
belirtir,
/C -- /T ile birlikte kullan
nda dosyalar
zca bu klas
/C:<Kmt> -- Yazan taraf
ndan tan
mlanan Y
kleme Komutunu Ge
ersiz K
ikliklerin etkili olabilmesi i
in bilgisayar
yeniden ba
latmal
Bilgisayar
imdi yeniden ba
latmak istiyor musunuz?
fSisteminizde '%s' paketinin bir kopyas
zaten
yor. Ba
ka bir kopya
rmak istiyor musunuz?
Bu dosya bulunam
yor: %s.
You do not have administrator privileges on this machine. Some installations cannot be completed correctly unless they are run by an administrator.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
vBu makinede y
netici ayr
z yok. Baz
klemeler y
netici taraf
ndan yap
lmazsa d
imde tamamlanamaz.
-'%s' klas
yok. Olu
turmak istiyor musunuz?jSisteminizde '%s' paketinin bir kopyas
zaten
yor. Ayn
anda yaln
zca bir kopya
rabilirsiniz.<'%s' paketi
z Windows s
ile uyumlu de
il.@'%s' paketi sisteminizdeki %s dosyas
yle uyumlu de
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Win32 Cabinet Self-Extractor
FileVersion
11.00.9600.16428 (winblue_gdr.131013-1700)
InternalName
Wextract
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
WEXTRACT.EXE .MUI
ProductName
Internet Explorer
ProductVersion
11.00.9600.16428
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
041F04B0
CompanyName
Microsoft Corporation
FileDescription
Win32 Kabin Ay
FileVersion
11.00.9600.16428 (winblue_gdr.131013-1700)
InternalName
Wextract
LegalCopyright
Microsoft Corporation. T
m haklar
OriginalFilename
WEXTRACT.EXE .MUI
ProductName
Internet Explorer
ProductVersion
11.00.9600.16428
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Zefaao.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Trojan.Heur.ku0@j3zEfaaO
ClamAV Clean
FireEye Gen:Trojan.Heur.ku0@j3zEfaaO
CAT-QuickHeal Clean
ALYac Gen:Trojan.Heur.ku0@j3zEfaaO
Malwarebytes Clean
VIPRE Gen:Trojan.Heur.ku0@j3zEfaaO
Sangfor Trojan.Win32.Agent.Vm25
K7AntiVirus Clean
BitDefender Gen:Trojan.Heur.ku0@j3zEfaaO
K7GW Clean
Cybereason malicious.6c86f7
BitDefenderTheta AI:Packer.A40A59791C
VirIT Clean
Cyren Clean
Symantec Trojan.Gen.MBT
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Malicious (score: 99)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Generic Reputation PUA (PUA)
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
Trapmine Clean
CMC Clean
Emsisoft Gen:Trojan.Heur.ku0@j3zEfaaO (B)
Ikarus Clean
GData Gen:Trojan.Heur.ku0@j3zEfaaO
Jiangmin Clean
Webroot Clean
Avira TR/AD.BatBadJoke.wlsah
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Heur.E0C5D6
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Clean
AhnLab-V3 Trojan/Win.Generic.C5462398
Acronis Clean
McAfee Artemis!E5655066C86F
MAX malware (ai score=87)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Clean
Paloalto Clean
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.