Static | ZeroBOX

PE Compile Time

2023-10-03 16:51:19

PDB Path

D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

PE Imphash

75e9596d74d063246ba6f3ac7c5369a0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000345cc 0x00034600 6.70839081779
.rdata 0x00036000 0x0000b410 0x0000b600 5.21594545639
.data 0x00042000 0x00024758 0x00001200 4.07891979604
.didat 0x00067000 0x000001a4 0x00000200 3.5194570554
.rsrc 0x00068000 0x000060c8 0x00006200 6.86523287112
.reloc 0x0006f000 0x0000255c 0x00002600 6.66608362789

Resources

Name Offset Size Language Sub-language File type
PNG 0x0006906c 0x000015a9 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
PNG 0x0006906c 0x000015a9 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
RT_ICON 0x0006a618 0x00001763 LANG_NEUTRAL SUBLANG_DEFAULT PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006c694 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0006d888 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0006d960 0x00000014 LANG_NEUTRAL SUBLANG_DEFAULT data
RT_MANIFEST 0x0006d974 0x00000753 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x436000 GetLastError
0x436004 SetLastError
0x436008 FormatMessageW
0x43600c GetCurrentProcess
0x436010 DeviceIoControl
0x436014 SetFileTime
0x436018 CloseHandle
0x43601c CreateDirectoryW
0x436020 RemoveDirectoryW
0x436024 CreateFileW
0x436028 DeleteFileW
0x43602c CreateHardLinkW
0x436030 GetShortPathNameW
0x436034 GetLongPathNameW
0x436038 MoveFileW
0x43603c GetFileType
0x436040 GetStdHandle
0x436044 WriteFile
0x436048 ReadFile
0x43604c FlushFileBuffers
0x436050 SetEndOfFile
0x436054 SetFilePointer
0x436058 GetCurrentProcessId
0x43605c SetFileAttributesW
0x436060 GetFileAttributesW
0x436064 FindClose
0x436068 FindFirstFileW
0x43606c FindNextFileW
0x436074 GetVersionExW
0x43607c GetFullPathNameW
0x436080 FoldStringW
0x436084 GetModuleFileNameW
0x436088 GetModuleHandleW
0x43608c FindResourceW
0x436090 FreeLibrary
0x436094 GetProcAddress
0x436098 ExitProcess
0x4360a0 Sleep
0x4360a4 LoadLibraryW
0x4360a8 GetSystemDirectoryW
0x4360ac CompareStringW
0x4360b0 AllocConsole
0x4360b4 FreeConsole
0x4360b8 AttachConsole
0x4360bc WriteConsoleW
0x4360c4 CreateThread
0x4360c8 SetThreadPriority
0x4360dc SetEvent
0x4360e0 ResetEvent
0x4360e4 ReleaseSemaphore
0x4360e8 WaitForSingleObject
0x4360ec CreateEventW
0x4360f0 CreateSemaphoreW
0x4360f4 GetSystemTime
0x436110 GetCPInfo
0x436114 IsDBCSLeadByte
0x436118 MultiByteToWideChar
0x43611c WideCharToMultiByte
0x436120 GlobalAlloc
0x436124 LockResource
0x436128 GlobalLock
0x43612c GlobalUnlock
0x436130 GlobalFree
0x436134 LoadResource
0x436138 SizeofResource
0x436140 GetTimeFormatW
0x436144 GetDateFormatW
0x436148 LocalFree
0x43614c GetExitCodeProcess
0x436150 GetLocalTime
0x436154 GetTickCount
0x436158 MapViewOfFile
0x43615c UnmapViewOfFile
0x436160 CreateFileMappingW
0x436164 OpenFileMappingW
0x436168 GetCommandLineW
0x436174 GetTempPathW
0x436178 MoveFileExW
0x43617c GetLocaleInfoW
0x436180 GetNumberFormatW
0x436184 DecodePointer
0x436188 SetFilePointerEx
0x43618c GetConsoleMode
0x436190 GetConsoleCP
0x436194 HeapSize
0x436198 SetStdHandle
0x43619c GetProcessHeap
0x4361a8 GetCommandLineA
0x4361ac GetOEMCP
0x4361b0 RaiseException
0x4361b4 GetSystemInfo
0x4361b8 VirtualProtect
0x4361bc VirtualQuery
0x4361c0 LoadLibraryExA
0x4361cc TerminateProcess
0x4361d4 IsDebuggerPresent
0x4361d8 GetStartupInfoW
0x4361e0 GetCurrentThreadId
0x4361e8 InitializeSListHead
0x4361ec RtlUnwind
0x4361f0 EncodePointer
0x4361f8 TlsAlloc
0x4361fc TlsGetValue
0x436200 TlsSetValue
0x436204 TlsFree
0x436208 LoadLibraryExW
0x436210 GetModuleHandleExW
0x436214 GetModuleFileNameA
0x436218 GetACP
0x43621c HeapFree
0x436220 HeapReAlloc
0x436224 HeapAlloc
0x436228 GetStringTypeW
0x43622c LCMapStringW
0x436230 FindFirstFileExA
0x436234 FindNextFileA
0x436238 IsValidCodePage
Library OLEAUT32.dll:
0x436240 SysAllocString
0x436244 SysFreeString
0x436248 VariantClear
Library gdiplus.dll:
0x436250 GdipAlloc
0x436254 GdipDisposeImage
0x436258 GdipCloneImage
0x436268 GdiplusStartup
0x43626c GdiplusShutdown
0x436270 GdipFree

!This program cannot be run in DOS mode.
`.rdata
@.data
.didat
@.reloc
D$ ^VQP
thU@WP
t0j.Xj\f
_^][YY
\$4UVW
D$(Pj S
u$UUUU
D$$Pj Vj S
L$4_^][3
t$$UPW
D$,SSUP
l$$VW3
tmSUVj
QQSUVW
_^][YY
t:j_[f9^
G jEYjX
jPXt;f9E
O(PPPPPPPP
t~jIYf;
tvjEYf;
jPXf9E
_^][YY
PQh$kC
D$,j2P
PVh$kC
D$,j2P
0SSSSQ
0Wh|kC
j*_f9y
_^][YY
j\Zf9TN
j.]f9.u
WVj\^f;
v3Uj.]
0j\Yf9
f9.t[S
D$XSUV
L$`_^][3
SVj Y+M
_^][YY
o 9w$v'S
YY;w$r
M|VWk8
G;= 'D
j Yf9LC
u'jdhxlC
Aj Xf9
j"Xf9Dw
wj"Xf9
j"Xf9Dw
wj"Xf9
~0YY9^$v
D$djPP
L$<+L$4
t$@A+t$8
jd^+L$<
L$0_^[3
D$ 3L$
K$3D$(3L$,3T$ 3t$$
3D$d3T$\3t$`3L$h
L$l_^][3
L$(][3
D$4SUV
L$<_^][3
u3h mC
th8mC
ulhdmC
D$$3L$0
L$ 3L$
W83W$3W
3w 373w
T$(3t$
t$\Wj8]
tFv-j@Y;
L$X_^][3
?vVUj@^+
L$P_^[3
t$dWj?_
v{j@[+
L$`_^][3
t7v"j@Z;
t9Vj@^+
L$x][3
PSSSSSSh
D$ XoC
D$$poC
D$D(pC
D$H@pC
D$LXpC
D$PppC
D$p,qC
D$tDqC
D$x\qC
D$|tqC
t Uh<oC
L$$+D$
\$TUVWf
D$$+L$
L$T^][3
t/h`DA
Ft;Fpt
9t$ vL
_^][YY
_^][YY
D$$SUV
th9.ud
ot_^][
T$$t&W
w?9Ntt:
T$ ;l$(r
D$ ;t$$r
\$8UVW
;L$$|9;L$(
j Y+L$
9t$,sD
9t$,sD
tdf9+tR
D$0PjE
tJ9o$uE9o t@
V,]^[Y
SVhXyC
,__f9~
uh$yC
[_^]YY
D$0+D$(PV
tJ9s$uE9s t@
L$$_^][3
W;l$4u
D$hXWWf
$SUVWj
tGSVWj\
EZ;l$(
Yj"8D$
t$,SVW
f98tNV
.u'f9O
Yj\Yf9
tfj"]f9+u
f9(tSVWS
D$\SUVW
L$l_^][3
t\USSVW
u"h``F
QQSVWd
URPQQh``B
UQPXY]Y[
Tt1jhZ;
^$+^8+
t0jXXf
~$+~8+
F2jgYf;
u0jAXf;
u0jAXf;
35XaF
Wj0XPV
PPPPPWS
PP9E u:PPVWP
WWWPWS
u-PWWS
PQhh*D
PQhp+D
SSVWh
f9:t!V
35(gF
QQSWj0j@
PPPPPPPP
Unknown exception
bad array new length
string too long
vector too long
SELECT * FROM Win32_OperatingSystem
*messages***
CryptProtectMemory
CryptUnprotectMemory
xlistpos
SetDllDirectoryW
SetDefaultDllDirectories
bad allocation
s:IDS_BROWSETITLE
s:IDS_CMDEXTRACTING
s:IDS_SKIPPING
s:IDS_UNEXPEOF
s:IDS_FILEHEADERBROKEN
s:IDS_HEADERBROKEN
s:IDS_MAINHEADERBROKEN
s:IDS_CMTHEADERBROKEN
s:IDS_CMTBROKEN
s:IDS_OUTOFMEMORYERROR
s:IDS_UNKNOWNMETHOD
s:IDS_CANNOTOPEN
s:IDS_CANNOTCREATE
s:IDS_CANNOTMKDIR
s:IDS_ENCRCRCFAILED
s:IDS_EXTRCRCFAILED
s:IDS_PACKEDDATACRCFAILED
s:IDS_WRITEERROR
s:IDS_READERROR
s:IDS_CLOSEERROR
s:IDS_CANNOTFINDVOL
s:IDS_BADARCHIVE
s:IDS_EXTRACTING
s:IDS_ASKNEXTVOLTITLE
s:IDS_ARCHEADERBROKEN
s:IDS_DONE
s:IDS_ERROR
s:IDS_ERRORS
s:IDS_BYTES
s:IDS_MODIFIEDON
s:IDS_BADFOLDER
s:IDS_CREATEERRORS
s:IDS_RESTARTHINT
s:IDS_CRCERRORS
s:IDS_ALLFILES
s:IDS_TITLE1
s:IDS_TITLE1A
s:IDS_TITLE2
s:IDS_TITLE3
s:IDS_TITLE4
s:IDS_TITLE5
s:IDS_TITLE6
s:IDS_ARCBROKEN
s:IDS_EXTRFILESTO
s:IDS_EXTRFILESTOTEMP
s:IDS_EXTRACTBUTTON
s:IDS_EXTRACTPROGRESS
s:IDS_MAXPATHLIMIT
s:IDS_UNKENCMETHOD
s:IDS_WRONGPASSWORD
s:IDS_WRONGFILEPASSWORD
s:IDS_COPYERROR
s:IDS_CANNOTCREATELNKS
s:IDS_CANNOTCREATELNKH
s:IDS_ERRLNKTARGET
s:IDS_NEEDADMIN
s:IDS_PAUSE
s:IDS_CONTINUE
s:IDS_SECWARNING
s:IDS_SECDELDLL
$STARTDLG:SIZE
$STARTDLG:CAPTION
$STARTDLG:IDC_DESTEDITTITLE
$STARTDLG:IDC_CHANGEDIR
$STARTDLG:IDC_PROGRESSBARTITLE
$STARTDLG:IDOK
$STARTDLG:IDCANCEL
$REPLACEFILEDLG:SIZE
$REPLACEFILEDLG:CAPTION
$REPLACEFILEDLG:IDC_OWRFILEEXISTS
$REPLACEFILEDLG:IDC_OWRASKREPLACE
$REPLACEFILEDLG:IDC_OWRQUESTION
$REPLACEFILEDLG:IDC_OWRYES
$REPLACEFILEDLG:IDC_OWRALL
$REPLACEFILEDLG:IDC_OWRRENAME
$REPLACEFILEDLG:IDC_OWRNO
$REPLACEFILEDLG:IDC_OWRNOALL
$REPLACEFILEDLG:IDC_OWRCANCEL
$RENAMEDLG:SIZE
$RENAMEDLG:CAPTION
$RENAMEDLG:IDOK
$RENAMEDLG:IDCANCEL
$RENAMEDLG:IDC_RENAMEFROM
$RENAMEDLG:IDC_RENAMETO
$GETPASSWORD1:SIZE
$GETPASSWORD1:CAPTION
$GETPASSWORD1:IDC_PASSWORDENTER
$GETPASSWORD1:IDOK
$GETPASSWORD1:IDCANCEL
$LICENSEDLG:SIZE
$LICENSEDLG:CAPTION
$LICENSEDLG:IDOK
$LICENSEDLG:IDCANCEL
$ASKNEXTVOL:SIZE
$ASKNEXTVOL:CAPTION
$ASKNEXTVOL:IDC_NEXTVOLINFO1
$ASKNEXTVOL:IDC_NEXTVOLFIND
$ASKNEXTVOL:IDC_NEXTVOLINFO2
$ASKNEXTVOL:IDOK
$ASKNEXTVOL:IDCANCEL
USER32.dll
GDI32.dll
COMDLG32.dll
ADVAPI32.dll
SHELL32.dll
ole32.dll
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
SHLWAPI.dll
COMCTL32.dll
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
`h````
xpxxxx
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.didat$5
.rsrc$01
.rsrc$02
ShowWindow
GetDlgItem
EnableWindow
SetWindowTextW
GetParent
SetWindowPos
SetDlgItemTextW
GetSystemMetrics
GetClientRect
GetWindowRect
GetWindowLongW
SetWindowLongW
SetProcessDefaultLayout
GetWindow
LoadStringW
OemToCharBuffA
CharUpperW
DefWindowProcW
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
UpdateWindow
MapWindowPoints
CopyRect
LoadCursorW
SendMessageW
ReleaseDC
MessageBoxW
FindWindowExW
GetClassNameW
CopyImage
wvsprintfW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
PostMessageW
WaitForInputIdle
IsWindowVisible
DialogBoxParamW
EndDialog
GetDlgItemTextW
SendDlgItemMessageW
SetFocus
SetForegroundWindow
GetSysColor
LoadBitmapW
LoadIconW
DestroyIcon
IsDialogMessageW
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
GetDeviceCaps
SelectObject
StretchBlt
CreateDIBSection
GetObjectW
GetOpenFileNameW
GetSaveFileNameW
CommDlgExtendedError
OpenProcessToken
AdjustTokenPrivileges
SetFileSecurityW
LookupPrivilegeValueW
AllocateAndInitializeSid
FreeSid
CheckTokenMembership
GetTokenInformation
CopySid
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SetEntriesInAclW
SHGetMalloc
SHGetPathFromIDListW
SHBrowseForFolderW
SHFileOperationW
ShellExecuteExW
SHGetFileInfoW
SHGetFolderLocation
SHChangeNotify
CoSetProxyBlanket
CoCreateInstance
CreateStreamOnHGlobal
CLSIDFromString
OleInitialize
OleUninitialize
SHAutoComplete
InitCommonControlsEx
sfxrar.exe
GetLastError
SetLastError
FormatMessageW
GetCurrentProcess
DeviceIoControl
SetFileTime
CloseHandle
CreateDirectoryW
RemoveDirectoryW
CreateFileW
DeleteFileW
CreateHardLinkW
GetShortPathNameW
GetLongPathNameW
MoveFileW
GetFileType
GetStdHandle
WriteFile
ReadFile
FlushFileBuffers
SetEndOfFile
SetFilePointer
GetCurrentProcessId
SetFileAttributesW
GetFileAttributesW
FindClose
FindFirstFileW
FindNextFileW
InterlockedDecrement
GetVersionExW
GetCurrentDirectoryW
GetFullPathNameW
FoldStringW
GetModuleFileNameW
GetModuleHandleW
FindResourceW
FreeLibrary
GetProcAddress
ExitProcess
SetThreadExecutionState
LoadLibraryW
GetSystemDirectoryW
CompareStringW
AllocConsole
FreeConsole
AttachConsole
WriteConsoleW
GetProcessAffinityMask
CreateThread
SetThreadPriority
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
ReleaseSemaphore
WaitForSingleObject
CreateEventW
CreateSemaphoreW
GetSystemTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
LocalFileTimeToFileTime
FileTimeToSystemTime
GetCPInfo
IsDBCSLeadByte
MultiByteToWideChar
WideCharToMultiByte
GlobalAlloc
LockResource
GlobalLock
GlobalUnlock
GlobalFree
LoadResource
SizeofResource
SetCurrentDirectoryW
GetTimeFormatW
GetDateFormatW
LocalFree
GetExitCodeProcess
GetLocalTime
GetTickCount
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
OpenFileMappingW
GetCommandLineW
SetEnvironmentVariableW
ExpandEnvironmentStringsW
GetTempPathW
MoveFileExW
GetLocaleInfoW
GetNumberFormatW
KERNEL32.dll
OLEAUT32.dll
GdipAlloc
GdipFree
GdipCloneImage
GdipDisposeImage
GdipCreateBitmapFromStream
GdipCreateBitmapFromStreamICM
GdipCreateHBITMAPFromBitmap
GdiplusStartup
GdiplusShutdown
gdiplus.dll
RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
QueryPerformanceFrequency
GetModuleHandleExW
GetModuleFileNameA
GetACP
HeapFree
HeapReAlloc
HeapAlloc
GetStringTypeW
LCMapStringW
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
GetConsoleCP
GetConsoleMode
SetFilePointerEx
DecodePointer
(08@P`p
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AW4RAR_EXIT@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AV_com_error@@
.?AVbad_exception@std@@
.?AVtype_info@@
vuOuefweV$y
d{a?b\l
c_qQ_}
'_c?!k
-[jE>y,
xT28FX
401pQm
o1CpQm0
3z.g-]`
,\`2E&X
om\^\p
SYc61r
u_Agr,
6y3&T.
Gv&F~2
QM~2^~
)'/<4t
pM%>V^
4'M]?<
E})Vow
L^K0{{a
k~v0y
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="*"
name="WinRAR SFX"
type="win32"/>
<description>WinRAR SFX module</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"/>
</dependentAssembly>
</dependency>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!--The ID below indicates application support for Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!--The ID below indicates application support for Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
0!0+0A0V0a0q0{0
2)2E2M2
233:3X3_3|3
:+;R;f;
5%5+585i5
;A<u<1=\=
050?0J0
2+373k3v3
5,525=5D5Y5|5
5 6M6g6
:[;)<J<
1(131`1
?5?A?W?
031c1{1
2)2I2y2
9%9N9t9
9':S:v:
5$5K5W5
>@>g>w>
?$?-???~?
0(0B0U0h0
5)6F6v6
8#8:8H8l8
9':A:J:[:
`1j1v1
2+2=2K2n2
434L4T4_4
6A6G6V6g6n6u6|6
7!7(7/767H7O7V7]7d7k7r7y7
:5:<:H:T:k:v:
:7;>;J;X;q;|;
=!=3=@=M=^=h=
>0?;?B?P?
B0Q0`0o0~0
3'3q3z3
,102H3
9.999D9K9^9g9n9u9
:%:-:5:=:E:M:U:]:e:m:u:
;%;0;;;F;Q;\;g;r;};
;<9<M<k<
<'=<=f=
=M>h>r>y>
?c?m?}?
0#0<0H0T0
1+161;1G1S1e1r1
122r2|2
2B3T3e3u3
6&696I6Y6V7
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
: ;<;N;o;
<.=P=f=z=f?
4^5m5'6
0L447H8
G0N0l1s1
0D0R0i0p0w0~0
1+2I2Y2
4:4e405T5]5w5
7(7O7t7
8P8W8z8
:&:A:\:w:
:3;J;x;
?2?9?n?v?
050E0\0e0s0
2#262`2i2
3+3@3h3
4'4/454J4U4z4
555H5u5
6#6/6:6E6W6a6g6x6~6
7M7X7_7y7
7!8+818R8t8
:":6:K:r:
;;&;-;9;S;l;v;
<,<D<h<}<
=/=5=E=S=f=t=
>*>1>?>K>T>
>"?1?D?c?q?
1,1X2g2b3
4/4=4g4r4
7#797V7y7
9&999>9R9W9c9l9
:F:i:x:
<&<9<G<Q<W<t<z<
??.?5?D?P?\?h?y?
0%0.0O0h0
11&13191F1O1X1c1w1}1
2W2]2c2u2z2
3'333J3]3c3r3}3
4(454U4f4v4
636:6n6
8Q8}89'939=9I9o9}9
< <7<T<m<
=%=d=x=
>7>@>I>
?<?L?Z?
060;0F0R0`0
3%3-373]3k3q3
6C7G7K7O7S7W7[7_7c7g7k7o7s7w7
8!80888F8U8Z8c8i8}8
8 9%9/9i9
9":N:S:j:
<5<G<z<
=-=A=I=z=
>4>9>K>P>[>h>
??7?E?V?h?
040:0[0u0
1*1/191?1D1J1P1^1e1k1
272=2C2I2U2a2l2z2
3T3Z3e3
4#454B4W4^4p4x4~4
5&5+5H5R5[5a5g5q5w5
6!6'6.666<6D6}6
7$7.787B7L7V7`7j7t7~7
8(828<8F8P8Z8d8n8x8
9&939A9K9U9_9i9s9}9
:$:.:8:B:L:Y:g:q:{:
;;M;T;Z;c;l;
<<(<d<
=!='=1=N=x=
>7>L>X>^>s>
?&?,?A?f?y?
3 3&3,32383?3F3M3T3[3b3i3q3y3
4 4&4,42484>4E4L4S4Z4a4h4o4w4
8/8D8K8Q8c8m8
<<@<E<R<
?%?.?]?f?o?}?
11^1d1
2W2`2m2s2
3+3F3S3f3k3z3
4!5>5d5
2"2&2*2.22262:2>2B2F2J2
5[5`5d5h5l5
0!0.0P0
1*101K1s1
1L2[2;3h5
1*1F1f1t1{1
2!2A2K2W2s2
3'33383=3[3e3q3v3{3
0d1h1l1p1t1x1|1
2p9+<G<K<O<S<W<[<_<c<g<k<o<s<
333N3Y3
5*5Z5i5
5c6j6|6
1$1a1p1u1
222G2S2[2s2
2-3T3n3
6+7'8;8
::0:9:n:
818!:;:J:X:d:p:~:
;);4;J;^;f;q;
2:3J3a3i3
464@4\4g4l4q4
5;5E5a5l5q5v5
6/6K6V6[6`6~6
7'767]7o7{7
=*=<=N=j=
>>.>8>E>O>_>
1I1j1o1
42575=5B5
747V7}7
7#8*81888E8
:):;:h:
;&<-<I<P<g<}<
=#=g=y=
>->?>`>r>
3q4@5t7J?
;-<4<9?
313>3C3Q334R4W4f5z5
8Y9k9}9r:
;7;D;t;
=5>\>g>w>
>%?D?Z?d?
0'1P1l1
1#2T2p2
6)7>7O7
>9?A?I?Q?Y?w?
4I5f5v5
838?8K8^8}8
9)9<9`9
9K:Z:y:
7/757a9~9
5@5]5q5
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
P8T8X8\8`8d8h8l8p8t8x8|8
9P9h9p9t9x9|9p;t;x;|;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
D5H5L5
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
3$3,343<3D3L3T3\3L4P4`4d4l4
5,505@5D5H5L5T5l5|5
6(6,60686P6h<t<
=(=H=T=t=
><>D>L>P>T>\>p>x>
?8?@?L?t?|?
0<0H0h0p0|0
1(1H1T1t1
2 2(242T2`2
343T3\3d3l3t3|3
4$4,444D4T4\4p4x4
5$585X5t5x5
6,6D6H6h6p6t6
7,70787@7H7L7T7h7
808P8p8
909P9p9
:8:X:x:
$0(0,0004080
3 3,383D3P3\3h3t3
4(444@4L4X4d4p4|4
5$505<5H5T5`5l5x5
6 6,686D6P6\6h6t6
7$787D7H7L7P7T7X7\7`7d7h7l7p7t7x7
909<9@9D9`9d9l9
> ?H?d?
0 0$0(0,0004080<0@0H0P0T0X0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
CMT;The comment below contains SFX script commands
Setup=upsync.exe
Setup=sample.pdf
Silent=1
Update=U
sample.pdf
upsync.exe
}Wr;W.
J?NOPp
7W2?r=?I
rB%]t]
L1+z$b/
u$_YkN
>cZP%R
>:)Zu!
>;%@k{
2E3bUC
%W#n 3
Z@0l=X
8W8^g$
'W^2n"h
gNtZ.c
Vl]xSX
Oj~MP
xi(GgU9
_f3Zx/72
8GwDn8I>f7
-z$5v[
-Zg5Q\
wd;+[o
n(X3kab
|6}$l6ZZ
3,w`r
rH9bJ
7j4`qBF~LLoS
v1{F<~
qS0S;W
%~#~WXS
\5W'\Y
'DW?Id
~2!G.#
Wi3?S#Z&n$
3s[/q
(Pk1$I
8_"[L~3
|"|?i6
OYf1p2g
P4}/
6sO'>~
.{x8HWS
:drA%>&A
$9'Fwg`Lh9
y^y^Un
IP"#94
(A~hla
s/"y |
N2Loo?
mmr*.t3
BIDF{t
J_tt.Zs
;TfkI'
!]){t^
ILAB\2Du
Ol:^rcg
v~(6;w
1Rdk>B
N.Ufa
${dzar)
/,3Z&^
8*m=2?G-
dMtc(#
K~q<K?Q~
>b+<'i
'Jg4l
3Y3q~&Q
Q$VQ-V
W`uzF7
a{)T:f^H
>t'9'vdb
wh24_]
YOQOSOYO]O
upsync.exe
Maximum allowed array size (%u) is exceeded
::$ATTRIBUTE_LIST
::$BITMAP
::$DATA
::$EA_INFORMATION
::$FILE_NAME
::$INDEX_ALLOCATION
:$I30:$INDEX_ALLOCATION
::$INDEX_ROOT
::$LOGGED_UTILITY_STREAM
:$EFS:$LOGGED_UTILITY_STREAM
:$TXF_DATA:$LOGGED_UTILITY_STREAM
::$OBJECT_ID
::$REPARSE_POINT
SeSecurityPrivilege
SeRestorePrivilege
SeCreateSymbolicLinkPrivilege
__tmp_reference_source_
rtmp%d
@%u.%03u
ROOT\CIMV2
Windows 10
?*<>|"
*messages***
STRINGS
DIALOG
DIRECTION
s$%s:%s
CAPTION
Crypt32.dll
CryptProtectMemory failed
CryptUnprotectMemory failed
kernel32
version.dll
DXGIDebug.dll
sfc_os.dll
SSPICLI.DLL
rsaenh.dll
UXTheme.dll
dwmapi.dll
cryptbase.dll
lpk.dll
usp10.dll
clbcatq.dll
comres.dll
ws2_32.dll
ws2help.dll
psapi.dll
ieframe.dll
ntshrui.dll
atl.dll
setupapi.dll
apphelp.dll
userenv.dll
netapi32.dll
shdocvw.dll
crypt32.dll
msasn1.dll
cryptui.dll
wintrust.dll
shell32.dll
secur32.dll
cabinet.dll
oleaccrc.dll
ntmarta.dll
profapi.dll
WindowsCodecs.dll
srvcli.dll
cscapi.dll
slc.dll
imageres.dll
dnsapi.DLL
iphlpapi.DLL
WINNSI.DLL
netutils.dll
mpr.dll
devrtl.dll
propsys.dll
mlang.dll
samcli.dll
samlib.dll
wkscli.dll
dfscli.dll
browcli.dll
rasadhlp.dll
dhcpcsvc6.dll
dhcpcsvc.dll
XmlLite.dll
linkinfo.dll
cryptsp.dll
RpcRtRemote.dll
aclui.dll
dsrole.dll
peerdist.dll
uxtheme.dll
Please remove %s from %s folder. It is unsecure to run %s until it is done.
CreateThread failed
WaitForMultipleObjects error %d, GetLastError %d
Thread pool initialization failed.
%s: %s
ARarHtmlClassName
Shell.Explorer
about:blank
<html>
<head><meta http-equiv="content-type" content="text/html; charset=
utf-8"></head>
</html>
<style>
</style>
<style>body{font-family:"Arial";font-size:12;}</style>
&nbsp;
riched20.dll
RarSFX
STATIC
REPLACEFILEDLG
RENAMEDLG
GETPASSWORD1
ASKNEXTVOL
winrarsfxmappingfile.tmp
sfxname
%4d-%02d-%02d-%02d-%02d-%02d-%03d
sfxstime
STARTDLG
sfxcmd
sfxpar
LICENSEDLG
__tmp_rar_sfx_access_check_%u
-el -s2 "-d%s" "-sp%s"
Delete
Silent
Overwrite
TempMode
License
Presetup
Shortcut
SavePath
Update
SetupCode
%s.%d.tmp
Software\Microsoft\Windows\CurrentVersion
ProgramFilesDir
%s%s%u
Install
Software\WinRAR SFX
KERNEL32.DLL
C<pi-ms-win-core-fibers-l1-1-1
<pi-ms-win-core-synch-l1-2-0
api-ms-
(null)
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
(
((((( H
Capi-ms-win-appmodel-runtime-l1-1-1
<pi-ms-win-core-datetime-l1-1-1
<pi-ms-win-core-fibers-l1-1-1
<pi-ms-win-core-file-l2-1-1
<pi-ms-win-core-localization-l1-2-1
<pi-ms-win-core-localization-obsolete-l1-2-0
<pi-ms-win-core-processthreads-l1-1-2
<pi-ms-win-core-string-l1-1-0
<pi-ms-win-core-synch-l1-2-0
<pi-ms-win-core-sysinfo-l1-2-1
<pi-ms-win-core-winrt-l1-1-0
<pi-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Cja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ASKNEXTVOL
GETPASSWORD1
LICENSEDLG
RENAMEDLG
REPLACEFILEDLG
STARTDLG
Next volume is required
MS Shell Dlg 2
You need to have the following volume to continue extraction:
&Browse...
Insert a disk with this volume and press "OK" to try again or press "Cancel" to break extraction
Cancel
Enter password
MS Shell Dlg 2
&Enter password for the encrypted file:
Cancel
License
MS Shell Dlg 2
Accept
Decline
Rename
MS Shell Dlg 2
Cancel
Rename file
Confirm file replace
MS Shell Dlg 2
The following file already exists
Would you like to replace the existing file
with this one?
Yes to &All
&Rename
No to A&ll
&Cancel
WinRAR self-extracting archive
MS Shell Dlg 2
&Destination folder
Bro&wse...
hRichEdit20W
Installation progress
jmsctls_progress32
Install
Cancel
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
Corrupt header is found
Main archive header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
Not enough memory
Unknown method in %s
Cannot open %s
Cannot create %s
Cannot create folder %sHChecksum error in the encrypted file %s. Corrupt file or wrong password.
Checksum error in %s Packed data checksum error in %s
Write error in the file %s
Read error in the file %s
File close error
The required volume is absent
2The archive is either in unknown format or damaged
Extracting from %s
Next volume
The archive header is corrupt
ErroraErrors encountered while performing the operation
Look at the information window for more details
modified on
folder is not accessible
Some files could not be created._You can try to repeat the installation after closing other applications and restarting Windows.\Some installation files are corrupt.
Please download a fresh copy and retry the installation
All files
E<ul><li>Press <b>Install</b> button to start extraction.</li><br><br>E<ul><li>Press <b>Extract</b> button to start extraction.</li><br><br>6<li>Use <b>Browse</b> button to select the destination4folder from the folders tree. It can be also entered
manually.</li><br><br>8<li>If the destination folder does not exist, it will be2created automatically before extraction.</li></ul>
The archive is corrupt
Extracting files to %s folder$Extracting files to temporary folder
Extract
Extraction progress
=Total path and file name length must not exceed %d characters
Unknown encryption method in %s$The specified password is incorrect.
Incorrect password for %s
Cannot copy %s to %s.
Cannot create symbolic link %s
Cannot create hard link %s(You need to unpack the link target first
AYou may need to run this self-extracting archive as administrator
Continue
Security warningKPlease remove %s from folder %s. It is unsecure to run %s until it is done.
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Trojan.Nsisx-9979076-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fh
ALYac Generic.Trojan.Havokiz.Marte.D.28F89B35
Cylance unsafe
Zillya Trojan.Generic.Win32.1827528
Sangfor Backdoor.Win64.Havoc.Vq4k
K7AntiVirus Clean
Alibaba Backdoor:Win64/Havokiz.f443c9e5
K7GW Clean
Cybereason malicious.fae9b8
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Havoc_AGen.E
APEX Clean
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Generic.Trojan.Havokiz.Marte.D.28F89B35
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Generic.Trojan.Havokiz.Marte.D.28F89B35
Tencent Win64.Backdoor.C2.Kcnw
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1368308
DrWeb Clean
VIPRE Generic.Trojan.Havokiz.Marte.D.28F89B35
TrendMicro Clean
Trapmine Clean
FireEye Generic.mg.55461180284dcdf6
Emsisoft Generic.Trojan.Havokiz.Marte.D.28F89B35 (B)
SentinelOne Static AI - Malicious SFX
GData Generic.Trojan.Havokiz.Marte.D.28F89B35
Jiangmin Clean
Webroot Clean
Varist Clean
Avira HEUR/AGEN.1368308
Antiy-AVL Trojan/Win64.Havoc
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Clean
Xcitium Clean
Arcabit Generic.Trojan.Havokiz.Marte.D.28F89B35
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft VirTool:Win64/Havokiz.E!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Havoc!8.970A (TFE:4:Muj2LsPTQQM)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Win64:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.