Warning! We are currently in recovery mode. The complete archive is not available.

Sample details: e21b450726fbe4dada98dfd20581dee6 --

Hashes
MD5: e21b450726fbe4dada98dfd20581dee6
SHA1: 729f68dfa70f3d1e701a2c5f70c77b6f510c49e6
SHA256: 35fa24be83dcd8e8bfcce6e38a7cd4c08b78a324c0b1d310b9207a04734ed174
SSDEEP: 1536:AnlFOmzr/SrIS4AiE5Hk3CwIRzhTdcWMextlkNerJumPvDGkGdM72y+g:mASrlSViEx8BIRthxDVumHUGu
Details
File Type: PE32
Yara Hits
YRP/Borland_Cpp_DLL | YRP/Borland_Cpp_for_Win32_1999 | YRP/Borland | YRP/IsPE32 | YRP/IsDLL | YRP/IsWindowsGUI | YRP/IsBeyondImageSize | YRP/domain | YRP/contentis_base64 | YRP/DebuggerException__SetConsoleCtrl | YRP/win_registry | YRP/win_files_operation |
Parent Files
07366aeaaf4cc541451e35c636f53fa4
Strings
		This program must be run under Win32
`.data
.idata
@.edata
@.rsrc
@.reloc
fb:C++HOOK
char *
NExitCode::CMultipleErrors
NExitCode::CSystemError
CRecordVector<unsigned int>
CMyComPtr<IArchiveExtractCallback>
CObjectVector<CStringBase<wchar_t> >
NWindows::NCOM::CPropVariant
CStringBase<wchar_t>
CStringBase<char>
CExtractCallbackImp *
CExtractCallbackImp
tagPROPVARIANT
CRecordVector<void *>
CBaseRecordVector
ICryptoGetTextPassword
FIUnknown
IArchiveExtractCallback
UStringVector *
IProgress
CMyUnknownImp
CMyComPtr<IInArchive>
CMyComPtr<ISequentialOutStream>
_^[YY]
UString *
NWindows::NFile::NFind::CFileInfoW
COutFileStream *
CMyComBSTR
COutFileStream
NWindows::NFile::NFind::CFileInfoBase
NWindows::NFile::NIO::CFileBase
NWindows::NFile::NIO::COutFile
ISequentialOutStream
IOutStream
CMyComPtr<IInStream>
CInFileStream *
CInFileStream
NWindows::NFile::NIO::CInFile
IStreamGetSize
ISequentialInStream
IInStream
<X ucC;_
:f;4_u
AString *
F$_^[YY]
F$_^[YY]
NWindows::NFile::NFind::CFindFile
NWindows::NDLL::CLibrary
CHandlerLoader
ArcData *
CMyComPtr<IArchiveOpenCallback>
COpenCallbackImp *
CExtractOptions
COpenCallbackImp
ArcData
IArchiveOpenVolumeCallback
IArchiveOpenCallback
std::bad_alloc
bad_alloc *
std::exception
_^[YY]
std::bad_cast
std::bad_typeid
_RWSTDMutex
**BCCxh1
_^[YY]
std::type_info
type_info_hash
_^[YY]
_^[YY]
PSh]Pa
QUVWRSPT
0_^[Y]
]Borland C++ - Copyright 1999 Inprise Corporation
SIMULATE_TLS: A second thread was about to be created and the c0s32 startup code is in use
Nonshared DATA segment required
Cannot run multiple instances of a DLL under WIN32s
Everything is Ok
Can not create output directory
Testing     
Extracting  
Skipping    
can not create file with auto name
can not rename existing file
can not delete output file 
incorrect item
Software\Microsoft\Windows\CurrentVersion\App Paths\winrar.exe
Formats\7zxa.dll
GetHandlerProperty
CreateObject
GetPropertyValue error
borlndmm
hrdir_b.c: LoadLibrary != mmdll borlndmm failed
borlndmm
@Borlndmm@SysGetMem$qqri
@Borlndmm@SysFreeMem$qqrpv
@Borlndmm@SysReallocMem$qqrpvi
creating heap lock
no named exception thrown
bad exception thrown
bad alloc exception thrown
rwstderr
<notype>
<notype>
___CPPdebugHook
Stack Overflow!
allocating handle lock table
creating handle lock
creating global handle lock
),(((((),(((
Error 0
Invalid function number
No such file or directory
Path not found
Too many open files
Permission denied
Bad file number
Memory arena trashed
Not enough memory
Invalid memory block address
Invalid environment
Invalid format
Invalid access code
Invalid data
Bad address
No such device
Attempted to remove current directory
Not same device
No more files
Invalid argument
Arg list too big
Exec format error
Cross-device link
Too many open files
No child processes
Inappropriate I/O control operation
Executable file in use
File too large
No space left on device
Illegal seek
Read-only file system
Too many links
Broken pipe
Math argument
Result too large
File already exists
Possible deadlock
Operation not permitted
No such process
Interrupted function call
Input/output error
No such device or address
Resource temporarily unavailable
Block device required
Resource busy
Not a directory
Is a directory
Directory not empty
Unknown error
creating global stream lock
allocating stream lock table
creating stream lock
%H:%M:%S
%m/%d/%y
%A, %B %d, %Y
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday
January
February
August
September
October
November
December
printf : floating point formats not linked
scanf : floating point formats not linked
printf : floating point formats not linked
scanf : floating point formats not linked
Error: system code page access failure; MBCS table not initialized
%02d/%02d/%04d %02d:%02d:%02d.%03d 
kernel32.dll
GetProcAddress
Borland32
Pure virtual function called
Abnormal program termination
No space for copy of command line
No space for copy of command line
creating atexit lock
An exception (%08X) occurred during DllEntryPoint or DllMain in module:
creating thread data lock
Semaphore error 
___CPPdebugHook
**BCCxh1
EDSETUPD
ADVAPI32.DLL
KERNEL32.DLL
USER32.DLL
OLEAUT32.DLL
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
AreFileApisANSI
CloseHandle
CompareStringA
CompareStringW
CreateDirectoryA
CreateDirectoryW
CreateFileA
CreateFileW
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FileTimeToDosDateTime
FileTimeToLocalFileTime
FindClose
FindFirstFileA
FindFirstFileW
FreeEnvironmentStringsA
FreeLibrary
GetACP
GetCPInfo
GetCurrentThreadId
GetEnvironmentStrings
GetFileSize
GetFileType
GetLastError
GetLocalTime
GetModuleFileNameA
GetModuleHandleA
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetStdHandle
GetStringTypeW
GetVersion
GetVersionExA
GlobalMemoryStatus
HeapAlloc
HeapFree
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
LoadLibraryW
MultiByteToWideChar
RaiseException
ReadFile
RemoveDirectoryA
RemoveDirectoryW
RtlUnwind
SetConsoleCtrlHandler
SetEndOfFile
SetFileAttributesA
SetFileAttributesW
SetFilePointer
SetFileTime
SetHandleCount
SetLastError
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
VirtualQuery
WideCharToMultiByte
WriteFile
EnumThreadWindows
MessageBoxA
wsprintfA
SysAllocString
SysFreeString
VariantClear
7z.dll
Extract
GetListItem
Prepare
___CPPdebugHook
{<:y&q?	
>0>P>X>8>@>H>`>h>
0$0+010:0G0S0g0m0
1%1B1U1^1
2(252;2O2
;!;+;R;
;G2s2u374n6
> >4>]>
7#7'7+7/737
?'?3?@?
:0:<:H:D<t<|<
0D1[1g1
2#253[3
5H5l5}5
;D;\;d;
=(>0>=>Z>b>
?-?8?a?
596K6R6\6
617=7H7
8 8b8w8
9#9.9:9^9
:(:/:r:
:1;7;?;G;d;
1&141=1F1
2H2p2|2
3K3z3q3
4%555N5X5b5l5J5T5^5h5r5~5
3E3O3U3
3'4c474B4q4{4
<?<=M>]>
?$?J?7=
>*?Z?r?
9%9:9R9j9x9
9D;m;q;C9
:Q;_;g;
:z:";$<?<K<W<
:):V:a:p:
<^<o<~<
0)1/171E1W1]1f1j1w1
2%2S2n2
3+3@3U3j3
364Y4e4q4}4
7^9h9b9l9V:]:
1%140=0G0V0_0i0
6)525<5K5T5^5
<)=>=I=^=
=/=O=h=q=
=@>E>R>
?f?G?Y?
<S<]<m<
0!0+010;0
1V1_1s1j1
;*;t;k;
)040f0
;b0S0Y0
=A073I6
5$5*52585>5D5J5P5V5\5b5h5n5t5z5
6"6(6.646:6@6F6L6R6X6^6d6j6p6v6|6
8$848\8h8
8,9L9<9\9|9
?(?4?@?L?\?|?
4(4,404<4@4D4H4L4X4\4`4d4p4t4x4|4
5 585d5T6d6t6
686<6@6D6H6L6P6
0 0&0,02080>0D0J0P0V0\0b0h0n0t0z0
1 1$1(1
3$303<3T3x3
7 7,7<7H7h7
8 8@8\8h8x8
:$:0: :P:p:|:
;0;L;<<
4(4,4044484<4@4L4P4T4X4d4
405@5P5\5l5x5
6$646D6T6d6
000T0`0
1H1T1d1
282D2x2
283X3p3
6,6<6`6\6
80888P8|8
8h8l8p8t8
909T9`9d9p9
0(040X0d0p0
1(1D141T1d1
2$202\2L2l2
3P3p3|3
3`4l4p4t4x4|4
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
<t>x>|>
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2