Static | ZeroBOX

PE Compile Time

2021-04-01 10:09:48

PDB Path

D:\workspace\workspace_c\GjOGoOIgHJEwh52iJ_20\Release\GjOGoOIgHJEwh52iJ_20.pdb

PE Imphash

af32313fc3f12018e1ca631ff1044218

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000627d2 0x00062800 6.60240046932
.rdata 0x00064000 0x00017f44 0x00018000 5.27215343068
.data 0x0007c000 0x00003540 0x00002600 4.52215470726
.rsrc 0x00080000 0x00071690 0x00071800 7.89136660256
.reloc 0x000f2000 0x00004d34 0x00004e00 6.55313241608

Resources

Name Offset Size Language Sub-language File type
HHGE 0x000bd710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
HHGE 0x000bd710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
HHGE 0x000bd710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
RT_MANIFEST 0x000f1510 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x464028 SizeofResource
0x46402c GetTempPathA
0x464030 LockResource
0x464034 GetModuleHandleW
0x464038 FindResourceW
0x46403c WinExec
0x464040 WriteConsoleW
0x464044 CreateThread
0x464048 CopyFileA
0x46404c GetModuleFileNameA
0x464050 LocalFree
0x464054 GetLastError
0x464058 FormatMessageW
0x46405c Sleep
0x464060 LoadResource
0x464064 lstrlenW
0x464068 HeapSize
0x46406c CreateFileW
0x464070 SetStdHandle
0x464074 GetProcessHeap
0x464084 GetCommandLineW
0x464088 GetCommandLineA
0x46408c GetOEMCP
0x464090 GetACP
0x464094 IsValidCodePage
0x464098 FindNextFileW
0x46409c FindFirstFileExW
0x4640a0 FindClose
0x4640a8 MultiByteToWideChar
0x4640ac GetStringTypeW
0x4640b0 WideCharToMultiByte
0x4640c0 EncodePointer
0x4640c4 DecodePointer
0x4640c8 GetCPInfo
0x4640cc CompareStringW
0x4640d0 LCMapStringW
0x4640d4 GetLocaleInfoW
0x4640d8 SetLastError
0x4640e0 CreateEventW
0x4640e4 TlsAlloc
0x4640e8 TlsGetValue
0x4640ec TlsSetValue
0x4640f0 TlsFree
0x4640f8 GetProcAddress
0x4640fc CloseHandle
0x464100 SetEvent
0x464104 ResetEvent
0x464114 GetCurrentProcess
0x464118 TerminateProcess
0x464120 IsDebuggerPresent
0x464124 GetStartupInfoW
0x46412c GetCurrentProcessId
0x464130 GetCurrentThreadId
0x464134 InitializeSListHead
0x464138 RtlUnwind
0x46413c RaiseException
0x464140 FreeLibrary
0x464144 LoadLibraryExW
0x464148 ExitProcess
0x46414c GetModuleHandleExW
0x464150 GetModuleFileNameW
0x464154 GetStdHandle
0x464158 WriteFile
0x46415c HeapReAlloc
0x464160 HeapFree
0x464164 HeapAlloc
0x464168 GetFileType
0x46416c GetFileSizeEx
0x464170 SetFilePointerEx
0x464174 FlushFileBuffers
0x464178 GetConsoleCP
0x46417c GetConsoleMode
0x464180 GetDateFormatW
0x464184 GetTimeFormatW
0x464188 IsValidLocale
0x46418c GetUserDefaultLCID
0x464190 EnumSystemLocalesW
0x464194 DeleteFileW
0x464198 ReadFile
0x46419c ReadConsoleW
0x4641a0 SetEndOfFile
Library ADVAPI32.dll:
0x464000 RegSetValueExW
0x464004 RegOpenKeyExW
0x464008 RegCreateKeyW
0x46400c RegCloseKey
0x464014 RegSetValueExA
0x464018 FreeSid
0x464020 RegOpenKeyExA
Library SHELL32.dll:
0x4641a8 ShellExecuteExA
Library WINHTTP.dll:
0x4641b0 WinHttpQueryHeaders
0x4641b4 WinHttpReadData
0x4641b8 WinHttpOpenRequest
0x4641bc WinHttpSetOption
0x4641c0 WinHttpCloseHandle
0x4641d0 WinHttpSendRequest
0x4641d8 WinHttpConnect
0x4641e4 WinHttpOpen

!This program cannot be run in DOS mode.
Rich:R
`.rdata
@.data
@.reloc
j-h0"G
9Vhvr3
+YL+QL
;QLu&;QPu
j9hl7G
j!h,;G
j!h,;G
L$<_^3
tG9uCj
tG9uCj
tZ9uVj
tC97u?j4
t{9uwj
tO9uKjD
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tc9u_jX
td9u`jX
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tZ9uVj
tZ9uVj
tI97uEjD
tI97uEjD
tS9uOj
tS9uOj
YPhG_F
PVh$:G
PVh,:G
PWh$:G
PWh,:G
M$+E4@Pj
M$+E4@Pj
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
t{9uwj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tI97uEjD
tS9uOj
M$+E4@Pj
<xt><Xu=
<xt <Xt
<xt"<Xu!
QQSVWd
URPQQh-
;t$,v-
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
ARPRQh
PPPPPPPP
zSSSSj
YYhlBF
SWt@jU
_tqPVj@
Wj0XPV
SPjdVQ
<at.<rt!<wt
<=upG8
D8(Ht'
PPPPPWS
PP9E u:PPVWP
tlj*Yf
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
bad allocation
regex_error(error_collate): The expression contained an invalid collating element name.
regex_error(error_ctype): The expression contained an invalid character class name.
regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.
regex_error(error_backref): The expression contained an invalid back reference.
regex_error(error_brack): The expression contained mismatched [ and ].
regex_error(error_paren): The expression contained mismatched ( and ).
regex_error(error_brace): The expression contained mismatched { and }.
regex_error(error_badbrace): The expression contained an invalid range in a { expression }.
regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.
regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.
regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.
regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.
regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.
regex_error(error_parse)
regex_error(error_syntax)
regex_error
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
%b %d %H : %M : %S %Y
%m / %d / %y
:AM:am:PM:pm
%I : %M : %S %p
%H : %M
%H : %M : %S
%d / %m / %y
0123456789-
0123456789-
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
0123456789ABCDEFabcdef-+XxPp
+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
0123456789-
0123456789-
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UTF-16LEUNICODE
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid stoi argument
stoi argument out of range
UseJu47egg whatppphatOjk4ehg riwjgHgeg
Use whatppphatYk43h7gr riwjg
error_self
vector too long
invalid string position
vector<bool> too long
xdigit
iostream stream error
()$^.*+?[]|\-{},:=!
invalid stof argument
stof argument out of range
map/set too long
haleng
Software\Microsoft\Windows\CurrentVersion\Run
countryCode
country_code
isinstall
isLogined
version
c_user
jazoest=
/login/device-based/login/
"jazoest"
"source"
&source=
&next=
cookieJson
access_token:
{accountID:
/v9.0/act
payInfo
accountId
https://graph.facebook.com/v9.0/act_fb_uid?access_token=fb_access_token&_index=5&_reqName=adaccount&_reqSrc=AdsCMPaymentsAccountDataDispatcher&fields=%5B%22active_billing_date_preference%7Bday_of_month%2Cid%2Cnext_bill_date%2Ctime_created%2Ctime_effective%7D%22%2C%22can_pay_now%22%2C%22can_repay_now%22%2C%22current_unbilled_spend%22%2C%22extended_credit_info%22%2C%22is_br_entity_account%22%2C%22has_extended_credit%22%2C%22max_billing_threshold%22%2C%22min_billing_threshold%22%2C%22min_payment%22%2C%22next_bill_date%22%2C%22pending_billing_date_preference%7Bday_of_month%2Cid%2Cnext_bill_date%2Ctime_created%2Ctime_effective%7D%22%2C%22promotion_progress_bar_info%22%2C%22show_improved_boleto%22%2C%22business%7Bid%2Cname%2Cpayment_account_id%7D%22%2C%22total_prepay_balance%22%2C%22is_in_middle_of_local_entity_migration%22%2C%22is_in_3ds_authorization_enabled_market%22%2C%22current_unpaid_unrepaid_invoice%22%2C%22has_repay_processing_invoices%22%5D&include_headers=false&method=get&pretty=0&suppress_http_code=1
un_pwd
fb_uid
fb_access_token
can_pay_now
https://graph.facebook.com/v9.0/me/adaccounts?access_token=fb_access_token&_reqName=me%2Fadaccounts&_reqSrc=AdsTypeaheadDataManager&fields=%5B%22account_id%22%2C%22account_status%22%2C%22is_direct_deals_enabled%22%2C%22business%7Bid%2Cname%7D%22%2C%22viewable_business%7Bid%2Cname%7D%22%2C%22name%22%5D&filtering=%5B%5D&include_headers=false&limit=100&method=get&pretty=0&sort=name_ascending&suppress_http_code=1
"business"
business
account_id
https://business.facebook.com/ads/manager/account_settings/account_billing/?act=fb_account_id&pid=p1&business_id=fb_business_id&page=account_settings&tab=account_billing_settings
fb_account_id
fb_business_id
https://graph.facebook.com/v9.0/act_fb_uid?access_token=fb_access_token&_priority=HIGH&_reqName=adaccount&_reqSrc=AdsCMAccountSpendLimitDataLoader&fields=%5B%22spend_cap%22%2C%22amount_spent%22%5D&include_headers=false&method=get&pretty=0&suppress_http_code=1
amount_spent
adtrust
https://www.facebook.com/adsmanager/creation?act=fb_id
"account_currency_ratio_to_usd":
"adtrust_dsl":
category=your_pages
hasHomePage
ofen_place
timeline_chrome
https://www.facebook.com/profile.php?id=c_user&sk=friends
href="
"_gs6"
"items":{"count"
friendsNum
api/fbtime
{"sid":0,"time":0,"rand_str":""}
api/?sid=
#IO$J2&89DFJ2^984%7FJfj<>asi?h3.728*fhas
rand_str
89%3gj,IH@<F7>84|j5kl3;4y:jdFJOhf01(92)3
status
https://script.google.com/macros/s/AKfycbyeDUociDSMjODhy_ZapM5zzyoJ3zrch9n5IUJeKIM3UQOEtZs/exec?loc=location&app=Staoism&payoutcents=0.08&ver=3.5&ip=
location
0123456789abcdef
\u%04x
\u2028
\u2029
'%c' (%d)
unexpected end of input after start of comment
unexpected end of input inside multi-line comment
malformed comment
unexpected end of input
unexpected end of input in string
in string
unescaped
bad \u escape:
invalid escape character
, got
parseNhOIg354SHE errorFaegJ64U3: expected
exceeded maximum nesting depth
expected '"' in object, got
expected ':' in object, got
expected ',' in object, got
expected ',' in list, got
expected valueGbJ4ogHi4E4, got
leading 0s not permitted in numbers
in number
invalid
at least one digit required in fractional part
at least one digit required in exponent
unexpected trailing
jfiag3g_gg.exe
http://uyyge5w3ye.2ihsfa.com/
fj4ghga23_fsa.txt
C:\Windows\
Cookie:
facebook.com
domain
secure
httpOnly
sameSite
expirationDate
/stab
/scookiestxt
invalid vector subscript
D:\workspace\workspace_c\GjOGoOIgHJEwh52iJ_20\Release\GjOGoOIgHJEwh52iJ_20.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
lstrlenW
FormatMessageW
GetLastError
LocalFree
GetModuleFileNameA
CopyFileA
CreateThread
GetModuleHandleW
SizeofResource
GetTempPathA
LockResource
LoadResource
FindResourceW
WinExec
KERNEL32.dll
RegOpenKeyExA
CheckTokenMembership
FreeSid
RegSetValueExA
AllocateAndInitializeSid
RegCloseKey
RegCreateKeyW
RegOpenKeyExW
RegSetValueExW
ADVAPI32.dll
ShellExecuteExA
SHELL32.dll
WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSetCredentials
WinHttpSendRequest
WinHttpGetProxyForUrl
WinHttpQueryAuthSchemes
WinHttpGetIEProxyConfigForCurrentUser
WinHttpCloseHandle
WinHttpSetOption
WinHttpOpenRequest
WinHttpReadData
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpOpen
WinHttpReceiveResponse
WINHTTP.dll
MultiByteToWideChar
GetStringTypeW
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
GetCPInfo
CompareStringW
LCMapStringW
GetLocaleInfoW
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetProcAddress
CloseHandle
SetEvent
ResetEvent
WaitForSingleObjectEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
RtlUnwind
RaiseException
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapReAlloc
HeapFree
HeapAlloc
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleCP
GetConsoleMode
GetDateFormatW
GetTimeFormatW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
DeleteFileW
ReadFile
ReadConsoleW
GetTimeZoneInformation
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVregex_error@std@@
.?AV_Locimp@locale@std@@
.?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$codecvt@GDU_Mbstatet@@@std@@
.?AV?$ctype@G@std@@
.?AUmessages_base@std@@
.?AUmoney_base@std@@
.?AUtime_base@std@@
.?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AV?$messages@_W@std@@
.?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$moneypunct@_W$0A@@std@@
.?AV?$_Mpunct@_W@std@@
.?AV?$moneypunct@_W$00@std@@
.?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$numpunct@G@std@@
.?AV?$collate@G@std@@
.?AV?$messages@G@std@@
.?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$moneypunct@G$0A@@std@@
.?AV?$_Mpunct@G@std@@
.?AV?$moneypunct@G$00@std@@
.?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$collate@D@std@@
.?AV?$messages@D@std@@
.?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$moneypunct@D$0A@@std@@
.?AV?$_Mpunct@D@std@@
.?AV?$moneypunct@D$00@std@@
.?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AVbad_alloc@std@@
.?AV_Node_if@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV_Node_end_rep@std@@
.?AVsystem_error@std@@
.?AV_Node_end_group@std@@
.?AV_Node_back@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Node_base@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AVbad_cast@std@@
.?AUctype_base@std@@
.?AV?$_Node_class@_WV?$regex_traits@_W@std@@@std@@
.?AV_Root_node@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$_Node_str@_W@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AVfacet@locale@std@@
.?AV_Node_assert@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV_Node_rep@std@@
.?AV?$collate@_W@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV_System_error@std@@
.?AV?$ctype@_W@std@@
.?AVerrorFaegJ64U3@BTX6dfR9U7EG6V4B8eA@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV_Node_capture@std@@
.?AVexception@std@@
.?AV_Node_endif@std@@
.?AVbad_array_new_length@std@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@std@@
.?AVJsonValueBh7yhue@QIaUEgeH5jG6H4WgG3H@@
.?AV?$_Ref_count_obj2@VJsonObject@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$_Ref_count_obj2@VJsonIntXk7le4g@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$ValueXgYU4gDhK3@$04V?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VJsonNhHu7kg4he@QIaUEgeH5jG6H4WgG3H@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VJsonNhHu7kg4he@QIaUEgeH5jG6H4WgG3H@@@std@@@2@@std@@@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonObject@QIaUEgeH5jG6H4WgG3H@@
.?AV?$_Ref_count_obj2@VJsonNullWjse7h4g@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$_Ref_count_obj2@VJsonStringVh7r44hg@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AVJsonNullWjse7h4g@QIaUEgeH5jG6H4WgG3H@@
.?AV?$ValueXgYU4gDhK3@$00H@QIaUEgeH5jG6H4WgG3H@@
.?AV?$_Ref_count_obj2@VJsonDoubleZeahfagg5ru@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$ValueXgYU4gDhK3@$0A@UNullStructVjG7J6KeHrh4g@QIaUEgeH5jG6H4WgG3H@@@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonIntXk7le4g@QIaUEgeH5jG6H4WgG3H@@
.?AV?$ValueXgYU4gDhK3@$02V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@QIaUEgeH5jG6H4WgG3H@@
.?AV?$ValueXgYU4gDhK3@$00N@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonDoubleZeahfagg5ru@QIaUEgeH5jG6H4WgG3H@@
.?AV?$_Ref_count_obj2@VJsonBooleanUdje7h4g@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$_Ref_count_obj2@VJsonArray@QIaUEgeH5jG6H4WgG3H@@@std@@
.?AV?$ValueXgYU4gDhK3@$01_N@QIaUEgeH5jG6H4WgG3H@@
.?AV?$ValueXgYU4gDhK3@$03V?$vector@VJsonNhHu7kg4he@QIaUEgeH5jG6H4WgG3H@@V?$allocator@VJsonNhHu7kg4he@QIaUEgeH5jG6H4WgG3H@@@std@@@std@@@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonStringVh7r44hg@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonBooleanUdje7h4g@QIaUEgeH5jG6H4WgG3H@@
.?AVJsonArray@QIaUEgeH5jG6H4WgG3H@@
.?AV?$_Ref_count_obj2@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@std@@
.?AV?$_Ref_count_obj2@H@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AVcodecvt_base@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AV?$codecvt_utf16@_W$0BAPPPP@$03@std@@
.?AV?$basic_ifstream@_WU?$char_traits@_W@std@@@std@@
!This program cannot be run in DOS mode.
<+uF+2
)_^X+@,#8
?Psf_
nDBhs
/p1.(Vj
=+KdzRvG^l
vi8\Pa((*\FN*t
D@'CX}
CXuOrp
L>HPTQ
T:5"NM
vtl9SWE|
(aj?.E
,`j XPn
LM#y~GF
Y|hT4
(F$jHP
~@Fth
g3XS0"
uP^AQ[
d4mj;SgO
}Q!0|B
30S{Y\
[P-umV
U@UY(Y
m(]}hj
v/#tD<
HP']e`Kh4
1"t#9]
M@8nTx
Mp/:Va
^(){A5Y
~`etW
PR'x_I
/ftU[B
{-WQ'!
^0W~.S
4Rn1A.)
ZV.`_P
TWn5E*
m. Puh
@Ph:TJ
SF;p0|
(I,-V`*M./0t8~
<N@ABC<
PBCTU_i
rGZX8m
h$lDD!
,!dZ.
KEG;x0|
0[;t!KZ
NUW3h3
ne&]q"
:t-d$}
Aa $L:
`f9(t^
68ql#&;
#_wB+WC
H 8+MB
A[ I4Q:
~<<Avbm
4Pt,TkT4h
oAQ(H+
(uLm^k
Bt9HHt
"N69%r
@w`]QZ
yUKhH@
<(9gu V
#@8#!6#
=)9Xi`vR;
lrBL0$
61It3I
d-$`BK
t0d uH
Tp?~!kC^j
MD-*zp
=Wu 1+
wKt&=M=x
,8#jBO,
/(Vj(^w+:
^FdC=J?S
t)WPSQ
048<N.
5B4Mkms
tmSK)<@y
"62`K]
`{O;>r
qj}YvG
w4[F26I[
{P>)
TuH%wH
^t6qYS
M0:"[F~<
g*0dj?
(r82i#
4QGW.3@
b$.h(1!
&HrCRB
"~;F`|
?LFTu%&
0PEmD$
U6B<.
]vw`Y|
2Et_P8
t.@2\QX
hp"nVY
:D8uyW
MlR,hW+t
IUJ&[:
@amv[sD7
+QAfaxp
-nh@4SQ
P[$y{AU
@*NU%jc
ge=Q-4
<XO==t8
iy=jRQ/\n
EOvR}x1,s
YN8h-
8}Oe|L
$;|Hs*Ll
j`syZH
j5u41WdP4*@
89Bw^i
u#j\r~fV
(,7XtP>R
pMevpz"
w;~,vh
C *IhW
n9^,l^
Al`(AV
NXUd$P
I<rR +
HDb``#
RxTrhZ
x1>|X6
Z|xU*mA
;9wy+,(
pvs8a]
I<Enh&
_wScgh
X}72rZ
}dR2AP/
@bmf;dYA
MX'|!E
_Nr@Hhp
C@ RS4
A%@$P1 i
\v P(p8
Eh.a)9
8Vyqe&F
nfcQfH
2F+06a
|yU@Cp
>8X3HX_
BAgX3W
u;ZW}1
(z~ 4(
5,N*D~
A;/u%n
;&?HP
Q8XA9j
jq3WSyc
7,{,t;
Ip%6>O
9p}*ka
!2GE=}
T5rFc`
<hH^EW!
FL@p3SPK
N8hpoY
uJp]jXj
oJRW R
B{`T)\M
(G;^Qz&
wSPilA
&t8sUD&
9RRhd`
Iu0:=t
@L:FW++P
;Du"f9P
G;@JQb
$zQ;a*Mj
j`>Z$Y
d !"##$%&d'()**++,-./d012
o33456789:;<
=:>?@ABCDDEFGHHIJJKLMNOg
XYdZ[\]^_`adbd
xo1+0u+
!b#04#
HSyHX-
g9~|)BQ
O<wM4EH
r1_ltW
-=^$^-
0K4z@]~
Fh/LPQ
S_;X'uj
G18S;v
z8^8DN$
|B7cN69Y
74&F&f
:Wkppv"t
%=uZ;@
}3hpa>(
}B@')LWS
3D|@8p
e4Xh9 :
t@)HNa#.LX
IdDF~1c#-
p(Ly?e
FvukL2
tTOP xXC
,qYpZ(
|PzTmLHP
_`tS-
puvY|
?HpDq
HdVTLL
' .I~"$)F
dw:I$4.
4yoUW
*8x:25y'*
"<%beAWf
&a,::]3
X.VXS;
F&Q?''
,;E0.;0
4tnHt&H
.ySuf<
|1piG:V
96C=I-
XF$3*~
O,lat(
a)7>%/
Ph`gx`
:-h*&T
@M:F>H
Vq>_Yo
T7;r#\B|
8Nf;1f@
i_c`+%
V@P5zY4
(uFtnij
V HPlxu
,h&v$e
HsK19]
KBB2/:
#,?gkl
P@G'Sr
vITC(+
`%\<Mkfs
= 0hPk
"=f5XZ
.PVQj:7
;,zj6924
S8uU
38X2tLb
{ErE*?Q
~ 0qWt
f9p.`C
G]|fh]f
0xRF 0
zhDnaMr
m*hXO|/
F`C;XF
0,(4@l
EQPQf#T
nFV8Q#
v(7PIb
3$b;hA
/gb%ok
6+R^VL0X
t<fy0Z
58Efiz
[BemM`Q\
;Oq@Z+(
K`<@ 0
PaS/ 6e
IBa{DL
cK$&T8
{1Fdg&
@BwtHP
ZL/8nt*
uyHM\2
H{0N6
A@Xu
[6zLcm
ZrF804
^/@#zk
B0;r Q
;s\~-hl
Y@xuW%
bwDRKFP
,#0<J!Xn
Hy[D;6
A L5Xk
d*Ff|J
[bcQcv
dK$W~6
RKEkZZ
jKkWV!j
./"]j!
8I-FKll
89]Qo;
H)avnx
8:ggbH
#G$XBF)
2B@}]asx*
uU>"AH
Vc1V2{
NN&BfI
H4_(4I0
$W.1|:D;
DPI0Mp
P:v|,Px[
(S>x&#
|'+"V&
1XO61
4uKEA:
"`vxq7
|^6vBL
|+ZTp8
cVKEDTV
;*T0Sk
|*ZD<x)M
pe"mab
f9x@8`
Q>RJQI`
?rKHDT
#H(#p,
;AFNvC
$~+qra<
6J&'a-
6[|C4vYW
73F&f9J.v
(j,#CH#KL
vab6V'
/XnADO
/l0ADP
P #a4[J<bF
Ctpurl
-\TY~!
2Z,6U&Pi
mST)v/
Y[TFP4
Y(Vp(Wy*
;z,A(H`
NvZ@K%
x(BNf/
/XJ(Ix0
#F #N$
_nG$[B
RsZglE
zw%j+X
'T{$@W
8.Az"r
UJ)mx@
%2tp_K"2d
5GNikt
] hj1hX
$yPBf(
j{CK07
iJ12345
.6.78.9:;
cdefghhijggklmnopq
rstuvwxy
zz{|v}
F-"'ek
Ysufcu`
8%KTEj
ACSH?
3V|"CT*I
c{`Yymi
H^#S)%
Z6\N~-b
8hn(z0
tbw"]2
QR8S+Q8
wpJh$#n
Yj8XH(=Qn
;-<a (
se@nZc
>L2txN
Q4(.Dq
0<J\h<
<:LZdt
$2:L^jy
4>L^tQw
f\RH>4<
DELETE FROM cookie
HER$creation_utc = %I64d
AND name='%ws'
host_key%
expiZsS
ypted_
{:d>xw'f
[{Np/
{c>Go3#
RdAkpO
wR>m\[
:t+e2 7Z
m.;Jhk
/^ {g#
ConteY
xtW/Releas'
H,hGet
Paramo!DJaDe
stroyi'
_riveKeyImportupq[
cKcnxh8
IniDomm
dj`lsEl8
Rugw~J
1pO\W
n~l;N&\
;7_^_.o_
ejS""?+
p'sfvxp!
vdL8Tj
Toolhelp32Snapsho
Module\s
numw7sOFil
ExRWLOIn
?:SpecialF
#\kdg\#7
bVAuto"p
G_JLc *-`
og/memo
o&|S@)z
zhared@
;;.s dnot a d
8bPNbin5c
f rang~aux
typmisc
ock g ii
ksfulwk
nAgx3_s
t_"ap_
ct46cu
~^dszf
kr_4@R
PTwR}h
NUMTEXT
IGN KEY
NIQUHNOT
=/NIa8"
p4FrDA
De~gS$
VW'AoNa
9'Wai(\S
LowArY
%H:%MS&O
*l?nr%
3.8.1q"
bGU?{|}
Vj/3G>z
onoffalsey
tbl_!rootpN
mjB?A@u
2w2N(=
B`VWXY
z;7q$
_l,i.bNDEXE
SCAPEAoEYBE
G<PLAINST
o2XCEPT
TION^U
I7LUSIV
JGROUPN
6G"B4A
TUM OMz
<<OSS-
OkIL2F
GLOBYIF
*T,h5#q./2
4e2%!m
D;Hdj
yIr-{b2$
%u bjh!u
68547758
w with
0x%lx (
vs_t.c:%d:-/
|Y/m1'
'`%Wr23
-jZngp<C_
mZ!Z%06V
@\*he'yQK)h
d(-\Jd[
m-7/vn
P' Dnt
<uof#c
la #s!z
05s=B]()Hh(b
we|0.0,v1
+@5lA=
[@'Y=2,
Yj"i?_
T2x20
65535T
+<}q,91
015-07-27
M4"a469X67
e4361f099c0b720u
AESn56-GCM
19228GECBa
&005\Ch @C2
3.pdb]
tgANtbE
RV>T-g
n^+7{p~tg9
{pTCmWa
Gd*E
+i'+1^
b[,3.w
[V{.vt
RG[4x[
!#<(I]
TzS1cS
Dir~oE
L7D{-W
#Typ9:
88aeviF
[f8)5wcm
??2@YAP
AXI@ZA*i)3X*
n'n)kfg!
TblRl0a
pborpJ
.P4(v_
Cy!m ,
O;_ Hqs}
f";WQ&
XPTPSW
1111110
111111
nDDKDKnKn
KKKEKKKKEEn
nKnoKKnnKKKE
KDDKoooonKnK
noDDKooKKn=Kot
KKKKooK
KKDLoL
KoooooKKoKoooo
oonKttoottoKot
KotttooDt
oonotttttoot
ttottttttttt
tttontuttt
utntttt
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PA
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
CRYPT32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
USER32.dll
VERSION.dll
RegCloseKey
FindTextW
CryptUnprotectData
SetBkMode
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellExecuteW
VerQueryValueW
!This program cannot be run in DOS mode.
(t\_Ub
$)'G'(
oOQUWI
P^YYdF
3 e2#m
FkPM"kTJ
L]3\R2
0!4EQ'9
&20*wt
_:MRrz&
\$#4H[
j>2^k6
Bv.o])U*]
`hiLhu^
/S@pf?W
E@<~Wp
#bT2.9
j 9VOb+
".z Wj
R=!^Zt?
a/,tlk
uHf#PE
{MQ3K.:
D!zMK$
@)Fh;q
jK57Afm_
iQ6%r
:[td0 1
mV5D#Y
x?uz)Y
Rv0wpD
L_o.(":
jU hCD
~AR2kU
RUgN= F
fOSC~
&z nqw
XO*#Ut
4oOLX<
;.6mcwrQ
rbIklF=!}
`Sc&C,
zT=9dv
MAXy.R
!\r3u0
.y@'PC
=0 @LJn
%2W1'7
[>(A9TI
|{Co8`
&(O5.8
E!trxR
5jL"0/G
.ewiz.
vID\35q
Bq9{tWD
70x)]JL
\u6gSI\
"#8RA-t
otmIi$
O;UV2/
Q'v(?H
~8qERL
PR*)%}?
Y?ZeMM
2W@Jm+
+z<b}
Jv "vx
g|" zCV
IOKMl{
a6ONO2
{S*/cv
GqrD_Y
BO{,I.
Q=}Bk")
!mtT]{E83
QS)q_iC
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
</application>
</compatibility></assembly>PAD
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
USER32.dll
VERSION.dll
RegCloseKey
FindTextW
DeleteDC
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellExecuteW
VerQueryValueW
AddTrust AB1&0$
AddTrust External TTP Network1"0
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
AddTrust AB1&0$
AddTrust External TTP Network1"0
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110427000000Z
200530104838Z0z1
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110824000000Z
200530104838Z0{1
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
190502000000Z
200530104838Z0
Greater Manchester1
Salford1
Sectigo Limited1+0)
"Sectigo SHA-1 Time Stamping Signer0
https://sectigo.com/CPS0B
1http://crl.sectigo.com/COMODOTimeStampingCA_2.crl0r
1http://crt.sectigo.com/COMODOTimeStampingCA_2.crt0#
http://ocsp.sectigo.com0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
140912000000Z
190912235959Z0
525831
Gush Dan1
Ramat Gan1
5 Hashoshanim st.1
Nir Sofer1
Nir Sofer0
z<%()S
https://secure.comodo.net/CPS0A
0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
http://ocsp.comodoca.com0
support@nirsoft.net0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 2
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA
190817115657Z0#
Z7IcXBE4E
!This program cannot be run in DOS mode.
&g$4=H
YnfAyI
R3>h4q
{x{ny%43g^4
7k\`0_
S~/YQ-
q1/!E9
ly7nM
K(x%S83$
K#L;)M
=\{V[a
x]ZzY<
KzLR$z/
8m5;\b
^w{TJ5
7g-l4Xy
0%b~w6
xL0qI29
1%lM]^
7zw,f7D
vOptq`
e?T@AI
X4g)4&
;=TR\:3
dG>GgYY/*p
uNJr<6
OSA,B~u}
YLAI&?/
x8!'*l
Y:V]%
w{oJE)
3E74Ox
}q$*bV
c{J0^C
#idBi9
)#;H,DZ$3
2 X&]z
G<tK<@
o3>}ho
A)x/.T
?AUN1C
NR> 8r
wh 7\s
G/jc'o
Y@~fH_=
ZT/WF(
aZrqYM3
CW3#}d
lA>ixa
oyL/P]*~c
$R@`cx
lIZAe(
j"Up9T
>Xu8`+N
"q95=;
`p$hj.#
<;!XJ/z
%fJI~lC
KkcgKj
GoVGIh
J4amb4"
TZV$GV
N*{-{|
J,pStpe
0[$!"E
n<9a?Q/
tK{mw$3
S}qVYT)w|
uYKwM@
,A*SDcE
0dzi!k
K_X5lra
@mD%[L
_@iZY
C4dFk~
MUh\N"
EcU5Zs@03[
d/ps|#
e${EZ7bG
"VVWh8
3yYKmj
Qk?{&M
l&e/"C{
'C&If)R
Djz3R/
nL+s^
gIuoJ`Y
/-NV/\
E-fW,O
$W^\@q
tDhA2:
q^X*-j
9nPoJ7-/C
k%cclTFa4
z#_?"
@bLU~-i
TBRhA}
AZldvX
5l*0Ds
wjwdgN
J!H/@G
,Q1uDr
*,'k>g
72(~qi&
no~smKI
zZ9DJ
Y0FqC8
mIs]hp
7S{g4=
4.UncEc
KiQKG'
mBS*Up
2QhG};Z
i30%dm
*UjB*+
t+"gqI
F@9-U h
iU|cF*f
;0u#Z3
y^q:Sn
;EtG^"
vUEQLZ
p[3H#"n
`J][\r
MKkvI9
*@]!,|
@rD#Ie
_<XrDu
9"9X?J
x#T4T8X
[ymy~
ay7oKL
.1E\Z
EED6I
(aF(n.
)eX6=<
1M8UAE
;BR~kkz
t{]$JkTY
^e><~-h
gPZ-[B
yvwdh"
we~o8P
lY4vvV
yXUf7J7
?1Sumc
]X5U7b
VWJdhY
jK+BD!u_
0_ei7Q
,3H[/\
@45TUhY(
#M;Oi\
2[MyM=M
7_s1ttO|
`&Iia:
3d8<4v
<0*WB2
rhl*W-)6
+Uv5'm
aV"o_&o
,u({+j
fJdw;Z'*
aI$6oJ
#OdT6A
Z5d&?l
[@nW;z
o>J4=B>
{",|F+
ZND_iMs
y7sB&AxM&
L8Ar0b
<uPzL/
`lLAHn
LNN@Sj
{p _'_&
%VaQ|3w
9Rm0QY
\2*M/_
Gc~`?b
AHY@9W:i
"57w'
B&j}!3
AxW U3p&
Sfn/9S~
-m?QJ;
-!KLV'H
nY^eg!
2ZdhBn
?9i>uk
7~)$h)
\PSjMW
2S'x1z
Km^FsBE<
WEbN"?
?QL)erL
[$a$}bD
1zD6L[2B
k}m:W$ 4
xyd5K:7
t#CIil>
.Y>*^v
GXJMUf
?`CZ>Xe=X
U2$=&{9
LF*6XH
?Zg,$<
L>]L&I
X#,Q8iR
(PD_[}|
L4>P<?X
LNCx"G8
(Q^!J1
5=4:5m\
YW[p&,Xe
Qd(xI]j
7W^(cm
JV$<1y
I|0(op
ZQ+=D
luL[KfY
-6;c1BF
0JaS`0
c-FqXu
T5WTEL
:r&]_)
G3]`[Dy
X9OvN!,
tNE<%=
[)lkdC
,`44Xa
#I8A"#
@z68k>
g:e|<#
l4G"hz^
-f~84W
Yh.z'J<dpD
h7Zx-I
Fx1L6N
mygy^;.
wv9y{e
Z3h2e@
WG`] +
5I.FB:
0<N-]Z
B-1(B2^,?
3kOiiC
x;+C.t
ghZWSLRhIL
*US|>e
-9SRPw
o*+c6Es)
)_$I?S^
=g_nQ;B
sY02uT
\=)6D@
"N@U#6
EagWj0
LB^/BWY
cZ(yI6
v9@&Hj
L@u-63
IH3w\lL
8=kD!'*
4FwD;
FP}/U+
8[v]1H
yx.P-+F
H^a84a
OJX[F2aw
h&imjX{q
@/#V(z
&L[g'Zq
G3"]{N
%oL>dP
peUK=OpW
XV?r=B
9"k9";zd
;>@zN7
dvFmME
F9_asZA
hEAprx{
}:^2.!
Cy`Xr}
"#-SAk
d)@@p
.<YiI
#N3{%_b.
ua~n,(
_<z#AA)Z
h(MxFc
OuNnem
DAmXi#F
26g36B
!5b'Y[
75`95b
myR&yb
P~6+@G
I4Ncyve0O#c
=)d.|r
elWw'!
H?)!pxJ
`JF&eU
SEP~s<
AwxLm0*
ix;PL?b
>JPAYf
N[[$T+
h3hBV\ n
9QnZ9T
U3/4xI
?a91M*
e4gSmA5
4&)gRq
tR"k
Zbjj{Y
nR]tU+
DvDct+
^_%5"Na;
cacHq5
YQ]7TEIxl
Vc\q-X
_c{&1w,
F}7B sLu
F!Y:!Uu
F*mHzD+
g3xcLd85S
!?Cgy:
B<1,DA
> 8Zl2
Jg\qaY
zr!!P:
7zq`aH
6z LcB
u/0"[!
GAyx`S*
7aAm'B
!t7L>=
f!$35SB
dI&AR0
P\jWN
JUO/FJ
PVG n]
(HGW9$
u_S6mdn?n=>
Q>s(ln4
EW-;Vr>V
,}"D>|
)Y\5}f
xk30}q
%F2[&~
/H.jhb
ZAXn):
j#HAG-
'G{nn#>
M7}VD
9{v+-0oT
(=[|m1
++ILPD
abB`C/
g)T[g2iq
&6KX>Y
tN~EEU
fW(S*T
{B6uAc-~E
s}L[1Y
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
</application>
</compatibility></assembly>PAD
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
ole32.dll
SHELL32.dll
USER32.dll
VERSION.dll
WININET.dll
RegCloseKey
FindTextW
SetBkMode
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoInitialize
SHGetMalloc
VerQueryValueW
FindCloseUrlCache
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0/090C0S0X0b0x0
2-232O2o2
6+7c7v7
9,9V9d9
1(22272Y2v2
2C3V3m3
5<6@6D6H6L6
7'7.7q7
:F:U:}:
=6>H>T?
3$3(3,3034383<3@3D3H3
;);A;Y;j;
>)>8>V>h>
1q2F3O3
6!7+737<7N7V7_7q7y7
8 8(818C8K8T8
9%9-969H9P9Y9k9s9|9
:*:2:;:M:U:^:p:x:
<%<-<6<H<P<Y<k<s<|<
?#?)?@?H?_?g?~?
>0D1L1R1i1q1
132a2u2
2V3=4D4Y4
909E9V9k9
::4:L:]:r:
;,;D;U;j;
<$<<<R<g<
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.36688088
FireEye Generic.mg.9786f11c6015566b
CAT-QuickHeal Trojan.Cookiesstealer
ALYac Trojan.GenericKD.36688088
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Stealer.KA
K7AntiVirus Trojan ( 005723511 )
BitDefender Trojan.GenericKD.36688088
K7GW Trojan ( 005723511 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/CookieStealer.A.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Agent.ACLN
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Malware.Spyagent-9830839-0
Kaspersky Trojan.Win32.CookiesStealer.b
Alibaba Trojan:Win32/CookiesStealer.b842e0e9
NANO-Antivirus Riskware.Win32.PSWTool.hqsnsl
ViRobot Clean
AegisLab Clean
Tencent Win32.Trojan.Cookiesstealer.Hufm
Ad-Aware Trojan.GenericKD.36688088
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader38.9705
Zillya Trojan.CookiesStealer.Win32.62
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PUP.dc
MaxSecure Trojan.Malware.7164915.susgen
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Trojan.Malagent
GData Trojan.GenericKD.36688088
Jiangmin Trojan.CookiesStealer.n
Webroot W32.Malware.Gen
Avira TR/AD.JazoStealer.wcoir
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.Heur.KVM003.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.ns
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Stealer.KA!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.RL_Infostealer.R356907
Acronis Clean
McAfee GenericRXAA-AA!9786F11C6015
TACHYON Clean
VBA32 BScope.Trojan.Infospy
Malwarebytes Generic.Trojan.Malicious.DDS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DD321
Rising Stealer.Facebook!1.CC5B (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Agent.UAW!tr
BitDefenderTheta Gen:NN.ZexaF.34670.8uW@aKzHNfnj
AVG Win32:Malware-gen
Cybereason malicious.c60155
Paloalto generic.ml
Qihoo-360 Win32/Backdoor.SpyAgent.HgIASSAA
No IRMA results available.