Static | ZeroBOX

PE Compile Time

2021-03-28 03:11:19

PE Imphash

afcdf79be1557326c854b6e20cb900a7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008dfdd 0x0008e000 6.67524835171
.rdata 0x0008f000 0x0002fd8e 0x0002fe00 5.76324400576
.data 0x000bf000 0x00008f74 0x00005200 1.19638192355
.rsrc 0x000c8000 0x00f27c68 0x00f27e00 7.99983884848
.reloc 0x00ff0000 0x00007134 0x00007200 6.78395555713

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000ce038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000ce4a0 0x00000050 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d0660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_RCDATA 0x000d07b8 0x00f1ef2e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00fef788 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x00fef788 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x00fef788 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x00fef788 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x00fef79c 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x00fef878 0x000003ef LANG_ENGLISH SUBLANG_ENGLISH_UK ASCII text, with CRLF line terminators

Imports

Library WSOCK32.dll:
0x48f7c8 WSACleanup
0x48f7cc socket
0x48f7d0 inet_ntoa
0x48f7d4 setsockopt
0x48f7d8 ntohs
0x48f7dc recvfrom
0x48f7e0 ioctlsocket
0x48f7e4 htons
0x48f7e8 WSAStartup
0x48f7ec __WSAFDIsSet
0x48f7f0 select
0x48f7f4 accept
0x48f7f8 listen
0x48f7fc bind
0x48f800 closesocket
0x48f804 WSAGetLastError
0x48f808 recv
0x48f80c sendto
0x48f810 send
0x48f814 inet_addr
0x48f818 gethostbyname
0x48f81c gethostname
0x48f820 connect
Library VERSION.dll:
0x48f76c GetFileVersionInfoW
0x48f774 VerQueryValueW
Library WINMM.dll:
0x48f7b8 timeGetTime
0x48f7bc waveOutSetVolume
0x48f7c0 mciSendStringW
Library COMCTL32.dll:
0x48f08c ImageList_Destroy
0x48f090 ImageList_Remove
0x48f098 ImageList_BeginDrag
0x48f09c ImageList_DragEnter
0x48f0a0 ImageList_DragLeave
0x48f0a4 ImageList_EndDrag
0x48f0a8 ImageList_DragMove
0x48f0b0 ImageList_Create
Library MPR.dll:
0x48f3f8 WNetUseConnectionW
0x48f400 WNetGetConnectionW
0x48f404 WNetAddConnection2W
Library WININET.dll:
0x48f780 InternetCloseHandle
0x48f784 InternetOpenW
0x48f788 InternetSetOptionW
0x48f78c InternetCrackUrlW
0x48f790 HttpQueryInfoW
0x48f798 HttpOpenRequestW
0x48f79c HttpSendRequestW
0x48f7a0 FtpOpenFileW
0x48f7a4 FtpGetFileSize
0x48f7a8 InternetOpenUrlW
0x48f7ac InternetReadFile
0x48f7b0 InternetConnectW
Library PSAPI.DLL:
Library IPHLPAPI.DLL:
0x48f154 IcmpCreateFile
0x48f158 IcmpCloseHandle
0x48f15c IcmpSendEcho
Library USERENV.dll:
0x48f754 UnloadUserProfile
0x48f75c LoadUserProfileW
Library UxTheme.dll:
0x48f764 IsThemeActive
Library KERNEL32.dll:
0x48f164 DuplicateHandle
0x48f168 CreateThread
0x48f16c WaitForSingleObject
0x48f170 HeapAlloc
0x48f174 GetProcessHeap
0x48f178 HeapFree
0x48f17c Sleep
0x48f180 GetCurrentThreadId
0x48f184 MultiByteToWideChar
0x48f188 MulDiv
0x48f18c GetVersionExW
0x48f190 IsWow64Process
0x48f194 GetSystemInfo
0x48f198 FreeLibrary
0x48f19c LoadLibraryA
0x48f1a0 GetProcAddress
0x48f1a4 SetErrorMode
0x48f1a8 GetModuleFileNameW
0x48f1ac WideCharToMultiByte
0x48f1b0 lstrcpyW
0x48f1b4 lstrlenW
0x48f1b8 GetModuleHandleW
0x48f1c0 VirtualFreeEx
0x48f1c4 OpenProcess
0x48f1c8 VirtualAllocEx
0x48f1cc WriteProcessMemory
0x48f1d0 ReadProcessMemory
0x48f1d4 CreateFileW
0x48f1d8 SetFilePointerEx
0x48f1dc SetEndOfFile
0x48f1e0 ReadFile
0x48f1e4 WriteFile
0x48f1e8 FlushFileBuffers
0x48f1ec TerminateProcess
0x48f1f4 Process32FirstW
0x48f1f8 Process32NextW
0x48f1fc SetFileTime
0x48f200 GetFileAttributesW
0x48f204 FindFirstFileW
0x48f20c GetLongPathNameW
0x48f210 GetShortPathNameW
0x48f214 DeleteFileW
0x48f218 FindNextFileW
0x48f21c CopyFileExW
0x48f220 MoveFileW
0x48f224 CreateDirectoryW
0x48f228 RemoveDirectoryW
0x48f22c SetSystemPowerState
0x48f234 FindResourceW
0x48f238 LoadResource
0x48f23c LockResource
0x48f240 SizeofResource
0x48f244 EnumResourceNamesW
0x48f248 OutputDebugStringW
0x48f24c GetTempPathW
0x48f250 GetTempFileNameW
0x48f254 DeviceIoControl
0x48f258 GetLocalTime
0x48f25c CompareStringW
0x48f260 GetCurrentProcess
0x48f26c GetStdHandle
0x48f270 CreatePipe
0x48f274 InterlockedExchange
0x48f278 TerminateThread
0x48f27c LoadLibraryExW
0x48f280 FindResourceExW
0x48f284 CopyFileW
0x48f288 VirtualFree
0x48f28c FormatMessageW
0x48f290 GetExitCodeProcess
0x48f2b8 GetDriveTypeW
0x48f2bc GetDiskFreeSpaceExW
0x48f2c0 GetDiskFreeSpaceW
0x48f2c8 SetVolumeLabelW
0x48f2cc CreateHardLinkW
0x48f2d0 SetFileAttributesW
0x48f2d4 CreateEventW
0x48f2d8 SetEvent
0x48f2e4 GlobalLock
0x48f2e8 GlobalUnlock
0x48f2ec GlobalAlloc
0x48f2f0 GetFileSize
0x48f2f4 GlobalFree
0x48f2fc Beep
0x48f300 GetSystemDirectoryW
0x48f304 HeapReAlloc
0x48f308 HeapSize
0x48f30c GetComputerNameW
0x48f314 GetCurrentProcessId
0x48f31c CreateProcessW
0x48f320 GetProcessId
0x48f324 SetPriorityClass
0x48f328 LoadLibraryW
0x48f32c VirtualAlloc
0x48f330 IsDebuggerPresent
0x48f338 lstrcmpiW
0x48f33c DecodePointer
0x48f340 GetLastError
0x48f344 RaiseException
0x48f358 GetCurrentThread
0x48f35c CloseHandle
0x48f360 GetFullPathNameW
0x48f364 EncodePointer
0x48f368 ExitProcess
0x48f36c GetModuleHandleExW
0x48f370 ExitThread
0x48f378 ResumeThread
0x48f37c GetCommandLineW
0x48f384 IsValidCodePage
0x48f388 GetACP
0x48f38c GetOEMCP
0x48f390 GetCPInfo
0x48f394 SetLastError
0x48f3a0 TlsAlloc
0x48f3a4 TlsGetValue
0x48f3a8 TlsSetValue
0x48f3ac TlsFree
0x48f3b0 GetStartupInfoW
0x48f3b4 GetStringTypeW
0x48f3b8 SetStdHandle
0x48f3bc GetFileType
0x48f3c0 GetConsoleCP
0x48f3c4 GetConsoleMode
0x48f3c8 RtlUnwind
0x48f3cc ReadConsoleW
0x48f3d4 GetDateFormatW
0x48f3d8 GetTimeFormatW
0x48f3dc LCMapStringW
0x48f3e8 WriteConsoleW
0x48f3ec FindClose
Library USER32.dll:
0x48f4cc AdjustWindowRectEx
0x48f4d0 CopyImage
0x48f4d4 SetWindowPos
0x48f4d8 GetCursorInfo
0x48f4dc RegisterHotKey
0x48f4e0 ClientToScreen
0x48f4e8 IsCharAlphaW
0x48f4ec IsCharAlphaNumericW
0x48f4f0 IsCharLowerW
0x48f4f4 IsCharUpperW
0x48f4f8 GetMenuStringW
0x48f4fc GetSubMenu
0x48f500 GetCaretPos
0x48f504 IsZoomed
0x48f508 MonitorFromPoint
0x48f50c GetMonitorInfoW
0x48f510 SetWindowLongW
0x48f518 FlashWindow
0x48f51c GetClassLongW
0x48f524 IsDialogMessageW
0x48f528 GetSysColor
0x48f52c InflateRect
0x48f530 DrawFocusRect
0x48f534 DrawTextW
0x48f538 FrameRect
0x48f53c DrawFrameControl
0x48f540 FillRect
0x48f544 PtInRect
0x48f550 SetCursor
0x48f554 GetWindowDC
0x48f558 GetSystemMetrics
0x48f55c GetActiveWindow
0x48f560 CharNextW
0x48f564 wsprintfW
0x48f568 RedrawWindow
0x48f56c DrawMenuBar
0x48f570 DestroyMenu
0x48f574 SetMenu
0x48f57c CreateMenu
0x48f580 IsDlgButtonChecked
0x48f584 DefDlgProcW
0x48f588 CallWindowProcW
0x48f58c ReleaseCapture
0x48f590 SetCapture
0x48f598 mouse_event
0x48f59c ExitWindowsEx
0x48f5a0 SetActiveWindow
0x48f5a4 FindWindowExW
0x48f5a8 EnumThreadWindows
0x48f5ac SetMenuDefaultItem
0x48f5b0 InsertMenuItemW
0x48f5b4 IsMenu
0x48f5b8 TrackPopupMenuEx
0x48f5bc GetCursorPos
0x48f5c0 DeleteMenu
0x48f5c4 SetRect
0x48f5c8 GetMenuItemID
0x48f5cc GetMenuItemCount
0x48f5d0 SetMenuItemInfoW
0x48f5d4 GetMenuItemInfoW
0x48f5d8 SetForegroundWindow
0x48f5dc IsIconic
0x48f5e0 FindWindowW
0x48f5e4 MonitorFromRect
0x48f5e8 keybd_event
0x48f5ec SendInput
0x48f5f0 GetAsyncKeyState
0x48f5f4 SetKeyboardState
0x48f5f8 GetKeyboardState
0x48f5fc GetKeyState
0x48f600 VkKeyScanW
0x48f604 LoadStringW
0x48f608 DialogBoxParamW
0x48f60c MessageBeep
0x48f610 EndDialog
0x48f614 SendDlgItemMessageW
0x48f618 GetDlgItem
0x48f61c SetWindowTextW
0x48f620 CopyRect
0x48f624 ReleaseDC
0x48f628 GetDC
0x48f62c EndPaint
0x48f630 BeginPaint
0x48f634 GetClientRect
0x48f638 GetMenu
0x48f63c DestroyWindow
0x48f640 EnumWindows
0x48f644 GetDesktopWindow
0x48f648 IsWindow
0x48f64c IsWindowEnabled
0x48f650 IsWindowVisible
0x48f654 EnableWindow
0x48f658 InvalidateRect
0x48f65c GetWindowLongW
0x48f664 AttachThreadInput
0x48f668 GetFocus
0x48f66c GetWindowTextW
0x48f670 ScreenToClient
0x48f674 SendMessageTimeoutW
0x48f678 EnumChildWindows
0x48f67c CharUpperBuffW
0x48f680 GetParent
0x48f684 GetDlgCtrlID
0x48f688 SendMessageW
0x48f68c MapVirtualKeyW
0x48f690 PostMessageW
0x48f694 GetWindowRect
0x48f69c CloseDesktop
0x48f6a0 CloseWindowStation
0x48f6a4 OpenDesktopW
0x48f6b0 OpenWindowStationW
0x48f6b8 MessageBoxW
0x48f6bc DefWindowProcW
0x48f6c0 SetClipboardData
0x48f6c4 EmptyClipboard
0x48f6cc CloseClipboard
0x48f6d0 GetClipboardData
0x48f6d8 OpenClipboard
0x48f6dc BlockInput
0x48f6e0 GetMessageW
0x48f6e4 LockWindowUpdate
0x48f6e8 DispatchMessageW
0x48f6ec TranslateMessage
0x48f6f0 PeekMessageW
0x48f6f4 UnregisterHotKey
0x48f6f8 CheckMenuRadioItem
0x48f6fc CharLowerBuffW
0x48f700 MoveWindow
0x48f704 SetFocus
0x48f708 PostQuitMessage
0x48f70c KillTimer
0x48f710 CreatePopupMenu
0x48f718 SetTimer
0x48f71c ShowWindow
0x48f720 CreateWindowExW
0x48f724 RegisterClassExW
0x48f728 LoadIconW
0x48f72c LoadCursorW
0x48f730 GetSysColorBrush
0x48f734 GetForegroundWindow
0x48f738 MessageBoxA
0x48f73c DestroyIcon
0x48f744 LoadImageW
0x48f748 GetClassNameW
Library GDI32.dll:
0x48f0c4 StrokePath
0x48f0c8 DeleteObject
0x48f0d0 ExtCreatePen
0x48f0d4 GetDeviceCaps
0x48f0d8 EndPath
0x48f0dc SetPixel
0x48f0e0 CloseFigure
0x48f0e8 CreateCompatibleDC
0x48f0ec SelectObject
0x48f0f0 StretchBlt
0x48f0f4 GetDIBits
0x48f0f8 LineTo
0x48f0fc AngleArc
0x48f100 MoveToEx
0x48f104 Ellipse
0x48f108 DeleteDC
0x48f10c GetPixel
0x48f110 CreateDCW
0x48f114 GetStockObject
0x48f118 GetTextFaceW
0x48f11c CreateFontW
0x48f120 SetTextColor
0x48f124 PolyDraw
0x48f128 BeginPath
0x48f12c Rectangle
0x48f130 SetViewportOrgEx
0x48f134 GetObjectW
0x48f138 SetBkMode
0x48f13c RoundRect
0x48f140 SetBkColor
0x48f144 CreatePen
0x48f148 CreateSolidBrush
0x48f14c StrokeAndFillPath
Library COMDLG32.dll:
0x48f0b8 GetOpenFileNameW
0x48f0bc GetSaveFileNameW
Library ADVAPI32.dll:
0x48f000 GetAce
0x48f004 RegEnumValueW
0x48f008 RegDeleteValueW
0x48f00c RegDeleteKeyW
0x48f010 RegEnumKeyExW
0x48f014 RegSetValueExW
0x48f018 RegOpenKeyExW
0x48f01c RegCloseKey
0x48f020 RegQueryValueExW
0x48f024 RegConnectRegistryW
0x48f02c InitializeAcl
0x48f034 OpenThreadToken
0x48f038 OpenProcessToken
0x48f040 DuplicateTokenEx
0x48f04c GetLengthSid
0x48f050 CopySid
0x48f054 LogonUserW
0x48f060 RegCreateKeyExW
0x48f064 FreeSid
0x48f068 GetTokenInformation
0x48f070 GetAclInformation
0x48f074 AddAce
0x48f07c GetUserNameW
Library SHELL32.dll:
0x48f48c DragQueryPoint
0x48f490 ShellExecuteExW
0x48f494 DragQueryFileW
0x48f498 SHEmptyRecycleBinW
0x48f4a0 SHBrowseForFolderW
0x48f4a4 SHCreateShellItem
0x48f4a8 SHGetDesktopFolder
0x48f4b0 SHGetFolderPathW
0x48f4b4 SHFileOperationW
0x48f4b8 ExtractIconExW
0x48f4bc Shell_NotifyIconW
0x48f4c0 ShellExecuteW
0x48f4c4 DragFinish
Library ole32.dll:
0x48f828 CoTaskMemAlloc
0x48f82c CoTaskMemFree
0x48f830 CLSIDFromString
0x48f834 ProgIDFromCLSID
0x48f838 CLSIDFromProgID
0x48f840 MkParseDisplayName
0x48f848 CoCreateInstance
0x48f84c IIDFromString
0x48f850 StringFromGUID2
0x48f858 OleInitialize
0x48f85c OleUninitialize
0x48f860 CoInitialize
0x48f864 CoUninitialize
0x48f870 CoGetObject
0x48f874 CoSetProxyBlanket
0x48f878 CoCreateInstanceEx
Library OLEAUT32.dll:
0x48f40c LoadTypeLibEx
0x48f410 VariantCopyInd
0x48f414 SysReAllocString
0x48f418 SysFreeString
0x48f428 SafeArrayAccessData
0x48f42c SafeArrayAllocData
0x48f438 RegisterTypeLib
0x48f43c CreateStdDispatch
0x48f440 DispCallFunc
0x48f444 VariantChangeType
0x48f448 SysStringLen
0x48f450 VarR8FromDec
0x48f454 SafeArrayGetVartype
0x48f458 VariantCopy
0x48f45c VariantClear
0x48f460 OleLoadPicture
0x48f470 UnRegisterTypeLib
0x48f474 CreateDispTypeInfo
0x48f478 SysAllocString
0x48f47c VariantInit

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
t$8]4t
9^Xt=9^\tE
WWjdh,
PWWWWh
t4j"Yf;
L$$9N@
<SVWj,
j\_f98
8F4ti!E
rCSVWj
Yj?Yj0Z
j9Zj._f9<A
r%j9Yf;
<{=tfjB
|$pAU3!
?#tRf9t
f98t?j
t+HuA9
Ht;Ht.H
Ht7HtPHt
D$<DtL
D$`DtL
D$8DtL
D$`DtL
D$<;D$Hr
9D$lu;
9t$lv6
F;t$lr
jNYf9H
9t$(v-
F;t$(r
D$$PVj
D$(PVj
D$d|)I
D$p$*I
09L$ v"
Ht)Ht&H
L$L;|$D
D$0FVP
D$(;D$8
 !"#$
 !"#$%%%%%%&&'()*+%%%%%%&&'()*+,,,,,,--./012RRRRRRRRRRRR3345566789::::;<=<=>?>@ABC>@ABCRRRRRDEFGHIJKLMNO
~:9~(~)
D$@9G@
\$(j|Zf9
L$<jxXf
_j\YjEZ
j\_f9~
j-Xf9F
j]Xf9F
j#Xf9F
Zj:Xf;
>j)Xf;
YYj!Yf;
+t\HHtT
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
9E v\PWj
9u(v?VSj
YYHtIHt8
HHtPHHt-H
HthHt3
th$RL
~pjCXf
VWhp3I
uHjAXf;
uWjAXf;
htHjlZ;
HHtXHHt
nt'joZ;
YYjgXf9
>0t<NAj0X
PVVVVQ
+tIIt
-t*j0X;
+t"HHt
j@j _W
HHtVHHt
PP9E u
URPQQh
f- 8f=
f-00f=
f-00f=
tfHtWHtHHt/
SSPQSW
tx8tt
?:uBGW
} kE$<
jA[jZZ+
QQSVWh
j"_f9y
PWWWWV
PSSSSV
~';_t|%3
,SVWj0X
Wj0XPV
Ht+Ht$Ht
HtHHt
tHHt*Ht#
;t$,v-
UQPXY]Y[
+tHHt
+t"HHt
HAO8t
bWWWWj
7t;Ht5Ht"H
QPQWVS
QPQWVS
QPQWVS
QPQWVS
t4HHt
t5j'Zf;
|$tEA06
D$L;D$8
f98t#V
t2Ht%H
HHt?HHu7
~Ej Yj.Z
Yj Yj.Z;
Hu@IyG
t$L9D$
D$8QVP
L$0FVQ
\$d@SP
SSSSS3
t$;F|r
}G;F|s
}H;F|s
t.;V|r)
;~|s!f
t.;V|r)
;~|s!f
}P;~|s&
jEYf9N
tej+Zf;
t]j?Zf;
tUj{Zf;
u=jCYf9N
t!j!Yf;
j&[f9^
BL;z0}`
U(CG;z0|
jR_f98uX
](j)Xf9
9A0~];W
C89C0|?
m~XjoX;
j\Xf9F
jEYf9N
t#j-Y;
Zj9[f;
mt"js_;
GP;WL~
FP;~L~
jEYf9N
j\Xf9F
jEYf9N
NtvNtPNt)N
j\ZjE_f9~
Xu!jEXf9F
j0Yj7+
'tWj9Xj}Zj
tEj9[j-^f;
j-Zf9V
[j}Zr1f9E
j}Xf9F
r?j7Zf;
t4;H s#
P;V s/
4Ff9>t
4Ff9>t
4Ff9>t
4Ff9>t
t#Ht3Ht
HHt#HH
j$Xj(f
Mj$Xj(f
&j$Xj(f
Cj$Xj(f
f;H,sB
t$j\Xf9
\SVWQQ
QQSVWh
u5SVh+
j#_f98u
t1j;Yf;
t)j]Yf;
D$ +D$
D$$+D$
Q,8^=u
^<9^4t
^,9^0t
^09^(t
f;D$tu
f;D$@u
f;D$Hu
|$\9T$D}
f;D$tu
~f;D$@ulIyt
|$`[9D$
8f;D$Hu
#D$,SP
f91t,SWj,[j.
T$8Y9D$(
t$8f9D$$ue
t$4QVPR
D$<;D$(
|$jZ;
8jXf;
j|Zj f
j;Zj f
j XAf9
Oj;_f;
~%j;[f9
j;_f9;j
t$j'Zf;
SVWj ^j
4Bj"Yf;
<"t|<%tx<'tt<$tp<&tl<!th<otd<]t`<[t\<\tX<
tP<_tL<
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
DSVWj,3
j.^f90u
PSSSSSSh
f9t$Ht
YSPVWj
j0Xjxf
PPPPVWPP
QQSPVWQQ
D$,Yu)
JtsJJt8
HHt%Ht
Ht]Ht#j
u+Sj)^j
FLjDWP
;GLujDj$X+
PWWWWW
WWWWWh
WWWWPh
HHt@Ht3Ht&Ht
D$ SSP
T$$Rh<,I
T$PSRP
T$PSRP
T$PSRP
D$0SSP
|$ f94_uA@
t@Ht'Ht
t7Ht"Ht
Nt,NNt
tfHtYHt8Ht,Ht
HtQHtL
QQSVW3
BtFHHt>
t8HHt0
HtIHtAHuFj
D$<PSW
u&VVWSh
t4PhL'
@9D$ v=
t$0;t$$t"F
PVh,,I
Gt.Ht$
j3Zf9P
jNZf9P
tKHt:HuQ
@uIBj3
jNYf9J
j3Zf9P
jGXf9A
D$,PSR
RtUHt5Ht"Ht
YjNf9H
jNXf9A
jGXf9A
RtKHt/Ht
+jHXf;
j%YFf;
j$Yj@FZf;
X+D$8P
9u 8]
j;YFf9
D$ ;D$
t/Ht%Ht
SVWjD^V3
D$tPVj
L$(VQV
9t$<t0
L$ VQV
t$ PV3
t$ PV3
j\^f90uJj
f90u;j
HthHtSHt?H
HtEHt#Ht
L$,SWPV
D$$WPV
D$$WPV
D$$WPV
QQQQPVh
L$PQVh2
L$PQVh9
t$H+t$@
D$LF+D$Dj
L$<+L$
D$,+D$$
\$,WSPV
D$$SPV
D$$SPV
D$$SPV
\$(+\$
|$,+|$$
QQSVWj$
F;54hL
f9t^SQ
#M,@PQ
f91t%QV
4SVWj,
8SVWj,3
QQQQQP
SSSSPSh(
tCHt8HuO
tDf91t?
@PPj!j
u<@PPj!j
uS9q4uN
Wj!j j
Ht^HtIHt6
D$TPVhL
HHtLHt*H
HHt,Ht,
D$0VPS
D$0VPS
*;5PhL
_9=4hL
G;=4hL
)GHjG3
PPj PPP
T$L;t$
D$\PWV
;|$<}+
+G<+W@
D$TPVh>
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$0Ft>
uLPPRj
w,9G0~X
tXj]Zf
jHX_^[
SVWj0Zf;
rEj9_f;
$j9Yf;
GetNativeSystemInfo
kernel32.dll
[:>:]]
[:<:]]
bad allocation
CorExitProcess
RoInitialize
RoUninitialize
Unknown exception
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
_hypot
_nextafter
(null)
`h````
xpxxxx
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
<8bunz8
l,kg<i
<@En[vP
?Dj0Q:W$=
5s3R6=
RUUUUU
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
?UUUUUU
|u?!u$
Nu?-HF
d? cf>
&2@UUUUUU
UUUUUU
#wi#:=
&2@UUUUUU
Nu?-HF
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
`h`hhh
xppwpp
CreateFile2
i^^?(>
Y:/(A6>
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
1#SNAN
1#QNAN
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
pqrstuvwxyz{$--%"!'
`abcdefghijkmno]
 !"#$%&'()))*+,-./0123456789:;<=>?@ABBCDEFGHIGJKLLBMBBNOPQRSTUVWXYZ[\]^G___________________________________________________`___________________________________________________________________________________________________________________________________________________________________abccccccccdeefghijklmnopqrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstyzzzzzzzzzzzzzzzz{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{__|}~
_____________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
________________________________
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
Qkkbal
xdigit
ACCEPT
COMMIT
no error
\ at end of pattern
\c at end of pattern
unrecognized character follows \
numbers out of order in {} quantifier
number too big in {} quantifier
missing terminating ] for character class
invalid escape sequence in character class
range out of order in character class
nothing to repeat
operand of unlimited repeat could match the empty string
internal error: unexpected repeat
unrecognized character after (? or (?-
POSIX named classes are supported only within a class
missing )
reference to non-existent subpattern
erroffset passed as NULL
unknown option bit(s) set
missing ) after comment
parentheses nested too deeply
regular expression is too large
failed to get memory
unmatched parentheses
internal error: code overflow
unrecognized character after (?<
lookbehind assertion is not fixed length
malformed number or name after (?(
conditional group contains more than two branches
assertion expected after (?(
(?R or (?[+-]digits must be followed by )
unknown POSIX class name
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
spare error
character value in \x{} or \o{} is too large
invalid condition (?(0)
\C not allowed in lookbehind assertion
PCRE does not support \L, \l, \N{name}, \U, or \u
number after (?C is > 255
closing ) for (?C expected
recursive call could loop indefinitely
unrecognized character after (?P
syntax error in subpattern name (missing terminator)
two named subpatterns have the same name
invalid UTF-8 string
support for \P, \p, and \X has not been compiled
malformed \P or \p sequence
unknown property name after \P or \p
subpattern name is too long (maximum 32 characters)
too many named subpatterns (maximum 10000)
repeated subpattern is too long
octal value is greater than \377 in 8-bit non-UTF-8 mode
internal error: overran compiling workspace
internal error: previously-checked referenced subpattern not found
DEFINE group contains more than one branch
repeating a DEFINE group is not allowed
inconsistent NEWLINE options
\g is not followed by a braced, angle-bracketed, or quoted name/number or by a plain number
a numbered reference must not be zero
an argument is not allowed for (*ACCEPT), (*FAIL), or (*COMMIT)
(*VERB) not recognized or malformed
number is too big
subpattern name expected
digit expected after (?+
] is an invalid data character in JavaScript compatibility mode
different names for subpatterns of the same number are not allowed
(*MARK) must have an argument
this version of PCRE is not compiled with Unicode property support
\c must be followed by an ASCII character
\k is not followed by a braced, angle-bracketed, or quoted name
internal error: unknown opcode in find_fixedlength()
\N is not supported in a class
too many forward references
disallowed Unicode code point (>= 0xd800 && <= 0xdfff)
invalid UTF-16 string
name is too long in (*MARK), (*PRUNE), (*SKIP), or (*THEN)
character value in \u.... sequence is too large
invalid UTF-32 string
setting UTF is disabled by the application
non-hex character in \x{} (closing brace missing?)
non-octal character in \o{} (closing brace missing?)
missing opening brace after \o
parentheses are too deeply nested
invalid range in character class
group name must start with a non-digit
parentheses are too deeply nested (stack check)
digits missing in \x{} or \o{}
Arabic
Armenian
Avestan
Balinese
Bassa_Vah
Bengali
Bopomofo
Brahmi
Braille
Buginese
Canadian_Aboriginal
Carian
Caucasian_Albanian
Chakma
Cherokee
Common
Coptic
Cuneiform
Cypriot
Cyrillic
Deseret
Devanagari
Duployan
Egyptian_Hieroglyphs
Elbasan
Ethiopic
Georgian
Glagolitic
Gothic
Grantha
Gujarati
Gurmukhi
Hangul
Hanunoo
Hebrew
Hiragana
Imperial_Aramaic
Inherited
Inscriptional_Pahlavi
Inscriptional_Parthian
Javanese
Kaithi
Kannada
Katakana
Kayah_Li
Kharoshthi
Khojki
Khudawadi
Lepcha
Linear_A
Linear_B
Lycian
Lydian
Mahajani
Malayalam
Mandaic
Manichaean
Meetei_Mayek
Mende_Kikakui
Meroitic_Cursive
Meroitic_Hieroglyphs
Mongolian
Myanmar
Nabataean
New_Tai_Lue
Ol_Chiki
Old_Italic
Old_North_Arabian
Old_Permic
Old_Persian
Old_South_Arabian
Old_Turkic
Osmanya
Pahawh_Hmong
Palmyrene
Pau_Cin_Hau
Phags_Pa
Phoenician
Psalter_Pahlavi
Rejang
Samaritan
Saurashtra
Sharada
Shavian
Siddham
Sinhala
Sora_Sompeng
Sundanese
Syloti_Nagri
Syriac
Tagalog
Tagbanwa
Tai_Le
Tai_Tham
Tai_Viet
Telugu
Thaana
Tibetan
Tifinagh
Tirhuta
Ugaritic
Warang_Citi
This is a third-party compiled AutoIt script.
DllGetClassObject
GetModuleHandleExW
GetSystemWow64DirectoryW
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
DEFINE
UTF16)
NO_AUTO_POSSESS)
NO_START_OPT)
LIMIT_MATCH=
LIMIT_RECURSION=
ANYCRLF)
BSR_ANYCRLF)
BSR_UNICODE)
argument is not a compiled regular expression
argument not compiled in 16 bit mode
internal error: opcode not recognized
internal error: missing capturing bracket
failed to get memory
WSOCK32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
timeGetTime
mciSendStringW
waveOutSetVolume
WINMM.dll
InitCommonControlsEx
ImageList_Create
ImageList_ReplaceIcon
ImageList_Destroy
ImageList_Remove
ImageList_SetDragCursorImage
ImageList_BeginDrag
ImageList_DragEnter
ImageList_DragLeave
ImageList_EndDrag
ImageList_DragMove
COMCTL32.dll
WNetAddConnection2W
WNetUseConnectionW
WNetCancelConnection2W
WNetGetConnectionW
MPR.dll
InternetCloseHandle
InternetOpenW
InternetSetOptionW
InternetCrackUrlW
HttpQueryInfoW
InternetQueryOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
InternetReadFile
InternetQueryDataAvailable
WININET.dll
GetProcessMemoryInfo
PSAPI.DLL
IcmpCreateFile
IcmpSendEcho
IcmpCloseHandle
IPHLPAPI.DLL
LoadUserProfileW
CreateEnvironmentBlock
UnloadUserProfile
DestroyEnvironmentBlock
USERENV.dll
IsThemeActive
UxTheme.dll
InterlockedIncrement
InterlockedDecrement
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
RaiseException
GetLastError
DecodePointer
lstrcmpiW
GetCurrentDirectoryW
IsDebuggerPresent
SetCurrentDirectoryW
GetFullPathNameW
CloseHandle
GetCurrentThread
GetCurrentProcess
DuplicateHandle
CreateThread
WaitForSingleObject
HeapAlloc
GetProcessHeap
HeapFree
GetCurrentThreadId
MultiByteToWideChar
MulDiv
GetVersionExW
IsWow64Process
GetSystemInfo
FreeLibrary
LoadLibraryA
GetProcAddress
SetErrorMode
GetModuleFileNameW
WideCharToMultiByte
lstrcpyW
lstrlenW
GetModuleHandleW
QueryPerformanceCounter
VirtualFreeEx
OpenProcess
VirtualAllocEx
WriteProcessMemory
ReadProcessMemory
CreateFileW
SetFilePointerEx
SetEndOfFile
ReadFile
WriteFile
FlushFileBuffers
TerminateProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
SetFileTime
GetFileAttributesW
FindFirstFileW
FindClose
GetLongPathNameW
GetShortPathNameW
DeleteFileW
FindNextFileW
CopyFileExW
MoveFileW
CreateDirectoryW
RemoveDirectoryW
SetSystemPowerState
QueryPerformanceFrequency
FindResourceW
LoadResource
LockResource
SizeofResource
EnumResourceNamesW
OutputDebugStringW
GetTempPathW
GetTempFileNameW
DeviceIoControl
GetLocalTime
CompareStringW
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
CreatePipe
InterlockedExchange
TerminateThread
LoadLibraryExW
FindResourceExW
CopyFileW
VirtualFree
FormatMessageW
GetExitCodeProcess
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileSectionW
WritePrivateProfileSectionW
GetPrivateProfileSectionNamesW
FileTimeToLocalFileTime
FileTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
GetDriveTypeW
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetVolumeInformationW
SetVolumeLabelW
CreateHardLinkW
SetFileAttributesW
CreateEventW
SetEvent
GetEnvironmentVariableW
SetEnvironmentVariableW
GlobalLock
GlobalUnlock
GlobalAlloc
GetFileSize
GlobalFree
GlobalMemoryStatusEx
GetSystemDirectoryW
HeapReAlloc
HeapSize
GetComputerNameW
GetWindowsDirectoryW
GetCurrentProcessId
GetProcessIoCounters
CreateProcessW
GetProcessId
SetPriorityClass
LoadLibraryW
VirtualAlloc
KERNEL32.dll
DestroyIcon
MessageBoxA
GetForegroundWindow
GetSysColorBrush
LoadCursorW
LoadIconW
RegisterClassExW
CreateWindowExW
ShowWindow
SetTimer
RegisterWindowMessageW
CreatePopupMenu
KillTimer
PostQuitMessage
SetFocus
MoveWindow
DefWindowProcW
MessageBoxW
GetUserObjectSecurity
OpenWindowStationW
GetProcessWindowStation
SetProcessWindowStation
OpenDesktopW
CloseWindowStation
CloseDesktop
SetUserObjectSecurity
GetWindowRect
PostMessageW
MapVirtualKeyW
SendMessageW
GetDlgCtrlID
GetParent
GetClassNameW
CharUpperBuffW
EnumChildWindows
SendMessageTimeoutW
ScreenToClient
GetWindowTextW
GetFocus
AttachThreadInput
GetWindowThreadProcessId
GetWindowLongW
InvalidateRect
EnableWindow
IsWindowVisible
IsWindowEnabled
IsWindow
GetDesktopWindow
EnumWindows
DestroyWindow
GetMenu
GetClientRect
BeginPaint
EndPaint
ReleaseDC
CopyRect
SetWindowTextW
GetDlgItem
SendDlgItemMessageW
EndDialog
MessageBeep
DialogBoxParamW
LoadStringW
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
SendInput
keybd_event
SystemParametersInfoW
FindWindowW
IsIconic
SetForegroundWindow
GetMenuItemInfoW
SetMenuItemInfoW
GetMenuItemCount
GetMenuItemID
CheckMenuRadioItem
DeleteMenu
GetCursorPos
TrackPopupMenuEx
IsMenu
InsertMenuItemW
SetMenuDefaultItem
EnumThreadWindows
FindWindowExW
SetActiveWindow
ExitWindowsEx
mouse_event
CreateIconFromResourceEx
LoadImageW
MonitorFromRect
CharLowerBuffW
UnregisterHotKey
PeekMessageW
TranslateMessage
DispatchMessageW
LockWindowUpdate
GetMessageW
BlockInput
OpenClipboard
IsClipboardFormatAvailable
GetClipboardData
CloseClipboard
CountClipboardFormats
EmptyClipboard
SetClipboardData
SetRect
AdjustWindowRectEx
CopyImage
SetWindowPos
GetCursorInfo
RegisterHotKey
ClientToScreen
GetKeyboardLayoutNameW
IsCharAlphaW
IsCharAlphaNumericW
IsCharLowerW
IsCharUpperW
GetMenuStringW
GetSubMenu
GetCaretPos
IsZoomed
MonitorFromPoint
GetMonitorInfoW
SetWindowLongW
SetLayeredWindowAttributes
FlashWindow
GetClassLongW
TranslateAcceleratorW
IsDialogMessageW
GetSysColor
InflateRect
DrawFocusRect
DrawTextW
FrameRect
DrawFrameControl
FillRect
PtInRect
DestroyAcceleratorTable
CreateAcceleratorTableW
SetCursor
GetWindowDC
GetSystemMetrics
GetActiveWindow
CharNextW
wsprintfW
RedrawWindow
DrawMenuBar
DestroyMenu
SetMenu
GetWindowTextLengthW
CreateMenu
IsDlgButtonChecked
DefDlgProcW
CallWindowProcW
ReleaseCapture
SetCapture
USER32.dll
GetDeviceCaps
DeleteObject
GetTextExtentPoint32W
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
StretchBlt
GetDIBits
DeleteDC
GetPixel
CreateDCW
GetStockObject
GetTextFaceW
CreateFontW
SetTextColor
CreateSolidBrush
CreatePen
SetBkColor
RoundRect
SetBkMode
GetObjectW
SetViewportOrgEx
Rectangle
BeginPath
PolyDraw
Ellipse
MoveToEx
AngleArc
LineTo
CloseFigure
SetPixel
EndPath
StrokePath
StrokeAndFillPath
ExtCreatePen
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
RegConnectRegistryW
InitializeSecurityDescriptor
InitializeAcl
AdjustTokenPrivileges
OpenThreadToken
OpenProcessToken
LookupPrivilegeValueW
DuplicateTokenEx
CreateProcessAsUserW
CreateProcessWithLogonW
GetLengthSid
CopySid
LogonUserW
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
GetTokenInformation
GetSecurityDescriptorDacl
GetAclInformation
GetAce
AddAce
SetSecurityDescriptorDacl
InitiateSystemShutdownExW
GetUserNameW
RegCreateKeyExW
RegSetValueExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumValueW
ADVAPI32.dll
ShellExecuteW
Shell_NotifyIconW
ExtractIconExW
SHFileOperationW
SHGetFolderPathW
SHGetSpecialFolderLocation
SHGetDesktopFolder
SHCreateShellItem
SHBrowseForFolderW
SHGetPathFromIDListW
SHEmptyRecycleBinW
DragQueryFileW
ShellExecuteExW
DragQueryPoint
DragFinish
SHELL32.dll
CoTaskMemAlloc
CoTaskMemFree
CLSIDFromString
ProgIDFromCLSID
CLSIDFromProgID
OleSetMenuDescriptor
MkParseDisplayName
OleSetContainedObject
CoCreateInstance
IIDFromString
StringFromGUID2
CreateStreamOnHGlobal
OleInitialize
OleUninitialize
CoInitialize
CoUninitialize
GetRunningObjectTable
CoGetInstanceFromFile
CoGetObject
CoInitializeSecurity
CoCreateInstanceEx
CoSetProxyBlanket
ole32.dll
OLEAUT32.dll
EncodePointer
ExitProcess
GetModuleHandleExW
ExitThread
GetSystemTimeAsFileTime
ResumeThread
GetCommandLineW
IsProcessorFeaturePresent
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetStringTypeW
SetStdHandle
GetFileType
GetConsoleCP
GetConsoleMode
RtlUnwind
ReadConsoleW
GetTimeZoneInformation
GetDateFormatW
GetTimeFormatW
LCMapStringW
GetEnvironmentStringsW
FreeEnvironmentStringsW
WriteConsoleW
SetEnvironmentVariableA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AU3!P/I
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
wwwwwwwwwwwwwx
wwwwwwwwwwwwwx
xwxwxx
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
jqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqj
~~~~~z~zzzzzzzzzzzzzzz
vvvvvvvvvvvvvvzvvvv~zz~zzzzzwzwzvzvz
knnnnnnnnnnnnnnnnnkv~z~zzzzzzzzxzxxxx
nGGHHH
nv~zsssssssszxzzzzx
nGGGHH
nv~~~~~~~z~zzzzxzxy
n..GGHHH
nv~~ssssssss{zzzyyy
n...GGHHH
nv~~~~~~~~~{{zzzzyz
n+....HGHHHH
ssssssst~{{zzyy
n++....G.HHH
~~~~{~{{{{
n!!+....HGHHHH
ssssstts~{~{{{{
n!!++.....HHHHHH
~~~~~~{~{{
n!!!++....GGHHH
n!!""....-HHHH
!!"".....HHHHnv
ssssssss
"""+....G-Hnv
""""..-.-Gnv
ssssssss
"""...-.nv
""""..-nv
ssssssss
nU_[_[D
!""".+nv
nOTUTU[[ED'"""+nv
ssssssss
nCODOSSSWWWWXWLWaanv
n;;>D;DDDEESLWLLLLnv
ssssssss
;;:::3***3444nv
'''*"31nv
ssssssss
'*nv
mnnnnnnnnnnnnnnnnnm
ssssssss
jurrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrruj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
J>>>>>>>>>>>>>>>>ACA>>>>>>>>>G
>S]]]]]]]]]]]]]]]]]]]]]]]]]]]>
>S]]a]aaa]]]]]]a```____R_R_U]>
>_]]QQQQQQRQRQQQ_``__STTRRRR]>
>\]FIIIIIIIIIIFQ`LLLLLL_TRRR]>
>_]I$$$
IQ```a\a_`_URR]>
IQ^LLLLLL___RR]>
IQ`_``a\a\_SRU]>
IQ````ca\a__a]]>
IQ`LLLLLL\]a_a]>
$$$IQ````aca_a\]_]>
$$IQ`LLLLLL]`
IQ``_`a\a`a
IQ`LLLLLLa\$
>_]IE=,
IQ``````a\a
>_]I66;;80-&&7IQ`LLLLLL`\
>]]I11255880::IQ`````a\ac
C]]I****,+...-IQ`LLLLLLca
 ""IQ````aca\c
C]]HIIIIIIIIIIH]aLLLLLLa\
C]]]]]]]]]]]]]]]]]]]]]]]]]]]]>
C_]a`a]]ac]a]a]a]a`a\a\a\ac]]>
DKLKKKLKKLKKKKLKLKLKLMKKKKLKL>
APOOOOOOOOOOOOOOOOOOOOO
>>>>>>>>>>>>>>>>>>>>>>>>>>>>J
H}AU3!EA06M
8v~d:^
pZhH'e
|-:|sd
b.qni1$
^8qq\!
8!u~%q
D1WfQi
.LMc1
H<HqJ@<
K6"@Aa
vby:@/
4NVO>]
d5wOuA
eAx+{D
]F00[<
,=vLPV
CCKWsf
O22\=@
[?b.;kr
/bkss7
\\`s)@
$ \'TQ
J;mnG`
7j]-_wPv
TEr%}7i$p
hU_u|&v
\Rjx+5
@^Os;L
/'G.L~Q-
v}K9Ur
?d}4I6
6;ps'e
;~Pm{f
gIiw+,
|<'&BF
j2U.4%
XG6Adk
?Zz4WN
QfyTPQ
RL{qhb
[YZk<9
%Xc<k~
YK}-zw2
T~6|7DF
DE"*I
x%=-ZV
W:BHrl
22 BpIe+
{`?D|}
f1(e0&
]i=[-
@_)ury
-7&GPq
Wi((_Lv
hf.7<
tJo[{Dg
v|SIC}
NgX3"j
K=$74;
OKX<"d
60cA7&D
@HrjTq
4=}P.%kN
KsSw4
<i}8)J
elzW6D
}<Sua7
|g+3SAoU!R{l/&
j4%$%a
jh-IhL
JXC#lr!^
%/}A-q$
}D %86S
:r,`&7![
\C$drb
6A pES
1eRm,9
T{A[b8d
crfJMAfl
,/dUW*
U>pex[
saoO(
XT$,Dq
TI4xT8n(
H{0pH'Uf
1Gkv6
?:[V g+
)n?({{
(6PG$pA
`,$8x\
/fOxb#
e2 /)W
,Wy`1c
dZ]rz{
V-x`0CO
w\dKjQ
&eO,/`
\DfzPflI
RgLju_7
<.aC|[,Va
d52Y s
)uxdrwh=
1EIn(K
F9@UgH
DFb_%Z
!20TOP
TeCNjV
J&qt04}
Ub1)gK
.'#/<,+#
P8*=L
Ui~k!U,
\[LVV.
&hW/^WF
}hqaqW
0XYZY_
u.h^s;u
z,;ec/
^^w4K
:2.=MG
p;}GON
4-?d>{
KvNm}0
kcTznK
33?ovr
%n2vB\
+a;\3p
^O)b##
med:O)E
s~v(ZQG
[H#EOsj
X 1aEu4
Z|6@z8
p6;8r{-y
!MtD|a*
|G?5nr
;FAuA~y
,3dm/S
;Xb6CPjK
RpqfuP
jjgG_^
tQJTPq
C{{8-k
H,'mmG
6@$WKd
Hor enr
>PkOE/
QMJ7SE)z
{HPbc@
)J2AIM
FT-`<X
UR.}u~
[%E`$/
Zz!r3,X
YuZ>7~
K6T-|}
/tQ[!6
>MzQS{1j
E~f[VY
%JZ%VQq
U2JeR)
kQ$ocx9
eKU!)f
o dxE4T/
n!'(cUd
Zn`II~@
SvM0qv
!1G~Wb?
ewS!PN
MZo|hE&
%)-SBJ
nXqZE&
>1od'x
JXXv.w
cB;Hm8
M;< P[
"+[L|?S
UEfoLcq
H\?z=e
C!56c*
XtOT:ZC"i
+8]("
fmS#lc
3W<FA\f
S,91
=SCrZJ$
LIyTny
FPBAs`Y
#U!nc~}
#^&%="
I|aA-$jtS
|$=RGSS
eY'4G9
l5%xO;x
Lw;xhE
;(P[n=
l(wZ|2
<RJ<,~(D
$wK\r<
Cya_qW
\IGjytY9
s&[cnw$
|+6pt*
Bbg|rmm
2~9L[
9y:|7vR
uC76Uv
iG>0Ip
:R::|
Hz'xM;
v_.t%ZL
Y-o[#G@r
ccXzVR
YD0$[K
=fLrHK5
1[EX|M
%_R@yc}wI
ud7pp&
p6V;[>
+)ay@~
'f#KH<o|8
=^%`D5
wm"^$Iu
+h[H#s
l-]otq
IOA,[>
N"qLmr4
^zU4-2b
TO f~_%
+OJ;}e
t&gd{9+Y
RD9yD-:
?ix ]L
G{'\0L
r$UngT;
kX3t(:dVlV
;Kfl9V9
vC&.yM
S4R]aN^
x9,,$`
f76<i6
x}Vcx[
uI['BlCx
0jRldIr
DsBt {}
9bt%=o=
#p (_V
,qd{.+V
"*>x^.=0
,=Goth
r)y,_%
KWaLK)
C>78n#
4uLR[
au>PDa
V3Z;;R
_)ZT.
{s~m,,11
E)XqGY
BAYC6Z
x"1~|h!
e@ac9;
9$}%u#
-$gErQl,
rIuiJ/
q3Am9-Q
ngl7`=
+O=x,-
qeR>d@
wYC_:6u
9zcQ}0
_]CBE?
><I8Xn\
"%^W{b
`i*b d
$G;(CQ
*~JE-R,
<`72%\[q
N+bbCT
ajNDL#(
Gjj5l5
kgu>n:
5qe.`G
Di[vUbw
nGrxaK
ZKVe=m
@Nl\"^
JGv]dQsh
}H"%0X@
#,ZH<j
|%LDtee9Vr
Yt`-Nn
GHohKpL"
]qk-0)
Hm$Mbw
7%Zzx<
e#-}_9p.
fhmX!YE>
vg4ONP
h"`|oX01
Jh.<\P2
yh!u4O
xS.5z<
~kE]r&
<S=3~b
6dk{y'
n4kTK\
>;nUn3,
Zk&_,2-
C}j\d[?
crY[Eaoy
(S3<Md
$Id h{
Jo6,Z`
Mzmh;o
K#UDma=3
QRA(<A`
S{K081y
5~Ir']
_;L\Ojh
0!_Y26
oj[e-gf
B(LXp
3kaq&Y
P'-4nE
vR4\3|aI[2
OUO= f
c'vF*#iX
H+z:DC
AbliRk
-a98=7e
omi!R:Y
]"k{cCR
xkT9+r
}-wsh`
WS=onw
X-0-oDf
x|)5t.
UlBK_E
v,)x<`
jHmc&/
TPZc@,
{IuV5p
kvJ%>=z
Z2+Vz5
~=s'2o_
t1k{qE
(>o A
5'A{w5
ITj h(
%\FWJ
%SlF;?L
u\K%dV[(
'@th;[
!hOq#^Ox
]ER ;F
~?@Y--i
.jO'B[
@z%:Ons3
faLa>%
=2.Uy]
fa+d2Q
CV^~0V
&snxD19:X
#EHQ!(n
XJ3x<O
p0/0P6
Q0JJvi
Nc2Ief
9JK'O0
nuY=VVr4
JtPzij
'('=>9
ko*SJWl
L9D|M)zy
TBYVUI
Z^GApB
<V@Db
<8A:HcM
)SxD<
~U/pe$o
y\#l+RaS
ljA}W84
ZGouai
VV@o0f&u
4c`V\#
y"[GEH
%{ 7%H
]&`m(wP
9d{6Tqx
QMiQgL
e0dA\j
%Ym;Q\A
mDF{uy
&K3g {
'RpeIF2
;#@fH{EJ4h
d/qckI
2*eel68
z`L4K}
YC-fr.
3$--qkL
&C%X+S5
>P0POI
4o}Csg
*B1$ %
<_lfX.3
5TF|(q
jp1lFX{H
SHP3-%eo
cNXJh
_R]`-c
/e-Z.`
J,UsDH[
7-R1"O
vv962/
/%1f&
FD!6DY
H>YY/5
:'8$VK
BePQ^^
vJW+:l
ux2bag
wfCqN3
\4aT6+
1u{uN
iR5w~2-
$~U=s(3
^ID 4N
(Y3FZF
FmBE8f
r"E~!#2
RJ`S,~
-n&cR[
y|-D A
a2[d~y<
nc>g;o
--8<1n
jR00KC
_9qu'k;
5KK[)H"
qj36Sz
Or$k!x
&Zfj E
6%W<+
M/),s?z
Qa!m(7
FgQ7tH
&&y5_0
r_% AbN
|qjp26
b*?$W3J
#K:tZW
k`R@!U
QuKT+z~
1!ejdx
C){k1@
^f?'+<
&5 zlY^g
4q {C`$,i
q!1?S0
GIN5TRzs(?
cz/4p\
rd(n)q
oi-Rlq8
GF:c#G
'/2=q<
,2o*{"
J0:=Xy
R+%)t_
dVM~"Pj
ut{]hU
Y=AEF}
k~L`q%W
J>Qc(bP
rO}6d#
,4wIh%
A K0tb_M
q5_G{+
fWzIU{
r^egnS
BJc/@-
~]G#MpP
a%d(k
?1;`*k
ZV'dBB
bIE$#Z
.I$DxG
foo!(c
c~YdKD>
;2P2q"
}af5$#
ljfslb
.66[Ej
'K*k[0tG
"OVct'F
XZnp4>!O
{o:NN0}X
lT|:&k
nX&)@d/q
do1>R0
|~NYjs[
Ude|iaOu
WKkGPy/^&
(lH2JI%
6~Z|[,
O`%[h7
u%-On
pq<Ms;[p
:))<el=
+]oG&xb
@Gn)w
:6qGA9b
\1Il=6
_xc}zG
=T!0F4
RP:oI>
9d8f8F
rj=!%y_e/
|";69GM
VkuU}e
nv"94!
d1~ON8
Vg82"P
a}m.*TV
"v*Ns~
U\CLSv
,9.7A]
vklM5D-&
9,,v,kn?
4#Zs8U
Sp|kc)r
`&jN'Md
AHGB$My]
H|zq[J
vg01%4
e=@2lW
(_T9B"w
pf}(6f
R~l(4MU
2d>R|[4p
GkAEd[t
9l%TEP
ii7@W%WK
B1F4Pnt
D"4:7\
P:dV1++
1!M+;b
#$uOH]
(K?3p"
NqZGrM
<m1ph\
"\NB`i
K1Z6T{eA(Y
J8rv<B
,D;<:X`
9\tHAB
q4Vr2b
Lg`@T]-hu
Fy\U{=
tF*:PO
[%#},k
7G3,^7@
>ce=S+
L i?K
*o;y\q
ORen$Zo+h
Q<NLo
uZ_OIS
$*6+lbu
hdj\-O
B1eDF?
Bj8^.+o
%+1Fdh
dKdDg -
fKB5-0
(CLeUJ
h?\3zSW
Hl~ZR'
W!9+:J
v0CW Z
&Haqhr
cx=0_m
&+G#%}
s'2.3q
c&v0fd
qACILfC
,bO.n~
GLKqrQhz
i$KnPb
|BjG@)
J"0K^d
hWY0/8
8hS%'4?
bK>eE|
{k#Byn1
|lK=FO
w$)~;RM
FSu:4
u=oB)}
w?O)Bt7
zw5vc'D9
$^frn\
6/v'S,7
7)0,5a
`}\BG[
GX^E*\
"[|%)n
-"KWPeBP
}<hnB?
#!isL}
De=pUy
>5l$w/
W==k6N
VE!J^G
1;EeK|/
=$zyIB
t3b+Uh-
"K~~uL~q
X4?}Xg
#QW*!\
~m)GT2
D[5_I
Cz:fg=
$:@;;J
q~UTq<
1j}8h\
^J:5uOx
4E#6R4S
e#mHLSfz
xjI3<3B
I(DS(;W
.|\a?~<
z a<(T
)hI}g|U
71HL60V
<7|Nj@
@cbNS_+
|@pXj#?
&J/)WQ
"J,WU^
DTxd2-
Um)Qw?
l#s9|e
);|%%vA
sg#q]Q*
VL(qwr
rt~nJ>:(
J`+y(+
31`Hn4(
eg8a\a
[Fc{UBX
Iu#[iL
Hl=<,>
9u3$B"
K@jVw
g|C3@6q
/tFgcW
0=l)jO
=^|kHz
nY]/QN,Q
VAo(C(
FPM519
~HI'~-nT-
amkQs
#r/[Ut
UhwW2eZ
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan AIT:Trojan.Nymeria.1546
CMC Clean
CAT-QuickHeal Trojan.AutoIt.MineDropper.C
McAfee Artemis!35AB7B989418
Malwarebytes Clean
Zillya Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike Clean
BitDefender AIT:Trojan.Nymeria.1546
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
ESET-NOD32 a variant of Win32/TrojanDropper.Autoit.TL
APEX Malicious
Avast AutoIt:Injector-JY [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.Script.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware AIT:Trojan.Nymeria.1546
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.wc
FireEye Generic.mg.35ab7b989418f63d
Emsisoft AIT:Trojan.Nymeria.1546 (B)
SentinelOne Clean
GData AIT:Trojan.Nymeria.1546 (2x)
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira DR/AutoIt.Gen
Kingsoft Clean
Gridinsoft Clean
Arcabit AIT:Trojan.Nymeria.D60A
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDropper:AutoIt/Nymeria.AR!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Dropper/AU3.Miner.S1098
Acronis Clean
BitDefenderTheta AI:Packer.BC75735117
ALYac AIT:Trojan.Nymeria.1546
MAX malware (ai score=100)
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.CoinMiner/Autoit!1.C937 (CLASSIC)
Yandex Clean
Ikarus Trojan-Dropper.Win32.Autoit
MaxSecure Clean
Fortinet AutoIt/CoinMiner.TL!tr
Webroot Clean
AVG AutoIt:Injector-JY [Trj]
Paloalto Clean
Qihoo-360 HEUR/QVM10.1.9EDA.Malware.Gen
No IRMA results available.