Static | ZeroBOX

PE Compile Time

2021-05-05 23:35:25

PDB Path

D:\workspace\workspace_c\GjOGoOIgHJEwh52iJ_20\Release\GjOGoOIgHJEwh52iJ_20.pdb

PE Imphash

2d61767a66f97802f04479dc222ea0b1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00061e42 0x00062000 6.60825866521
.rdata 0x00063000 0x00017da8 0x00017e00 5.25768594587
.data 0x0007b000 0x00003588 0x00002600 4.56811039361
.rsrc 0x0007f000 0x00071690 0x00071800 7.89136891791
.reloc 0x000f1000 0x00004cd4 0x00004e00 6.54404404928

Resources

Name Offset Size Language Sub-language File type
HHGE 0x000bc710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
HHGE 0x000bc710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
HHGE 0x000bc710 0x00033e00 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
RT_MANIFEST 0x000f0510 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x463014 LocalFree
0x463018 SizeofResource
0x46301c GetLastError
0x463020 LockResource
0x463024 LoadResource
0x463028 FindResourceW
0x46302c WinExec
0x463030 WriteConsoleW
0x463034 FormatMessageW
0x463038 Sleep
0x46303c GetTempPathA
0x463040 lstrlenW
0x463044 HeapSize
0x463048 CreateFileW
0x46304c SetStdHandle
0x463050 GetProcessHeap
0x463060 GetCommandLineW
0x463064 GetCommandLineA
0x463068 GetOEMCP
0x46306c GetACP
0x463070 IsValidCodePage
0x463074 FindNextFileW
0x463078 FindFirstFileExW
0x46307c FindClose
0x463084 MultiByteToWideChar
0x463088 GetStringTypeW
0x46308c WideCharToMultiByte
0x46309c EncodePointer
0x4630a0 DecodePointer
0x4630a4 GetCPInfo
0x4630a8 CompareStringW
0x4630ac LCMapStringW
0x4630b0 GetLocaleInfoW
0x4630b4 SetLastError
0x4630bc CreateEventW
0x4630c0 TlsAlloc
0x4630c4 TlsGetValue
0x4630c8 TlsSetValue
0x4630cc TlsFree
0x4630d4 GetModuleHandleW
0x4630d8 GetProcAddress
0x4630dc CloseHandle
0x4630e0 SetEvent
0x4630e4 ResetEvent
0x4630f4 GetCurrentProcess
0x4630f8 TerminateProcess
0x463100 IsDebuggerPresent
0x463104 GetStartupInfoW
0x46310c GetCurrentProcessId
0x463110 GetCurrentThreadId
0x463114 InitializeSListHead
0x463118 RtlUnwind
0x46311c RaiseException
0x463120 FreeLibrary
0x463124 LoadLibraryExW
0x463128 ExitProcess
0x46312c GetModuleHandleExW
0x463130 GetModuleFileNameW
0x463134 GetStdHandle
0x463138 WriteFile
0x46313c HeapReAlloc
0x463140 HeapFree
0x463144 HeapAlloc
0x463148 GetFileType
0x46314c GetFileSizeEx
0x463150 SetFilePointerEx
0x463154 FlushFileBuffers
0x463158 GetConsoleCP
0x46315c GetConsoleMode
0x463160 GetDateFormatW
0x463164 GetTimeFormatW
0x463168 IsValidLocale
0x46316c GetUserDefaultLCID
0x463170 EnumSystemLocalesW
0x463174 DeleteFileW
0x463178 ReadFile
0x46317c ReadConsoleW
0x463180 SetEndOfFile
Library ADVAPI32.dll:
0x463000 RegSetValueExW
0x463004 RegOpenKeyExW
0x463008 RegCreateKeyW
0x46300c RegCloseKey
Library WINHTTP.dll:
0x463188 WinHttpQueryHeaders
0x46318c WinHttpReadData
0x463190 WinHttpOpenRequest
0x463194 WinHttpSetOption
0x463198 WinHttpCloseHandle
0x4631a8 WinHttpSendRequest
0x4631b0 WinHttpConnect
0x4631bc WinHttpOpen

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
9Vhvr3
+YL+QL
;QLu&;QPu
uSh8$G
uLhp"G
PPh *G
j.hX,G
L$<_^3
YYh(0G
tG9uCj
tG9uCj
tZ9uVj
u.h(0G
tC97u?j4
t{9uwj
tO9uKjD
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tc9u_jX
td9u`jX
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tZ9uVj
tZ9uVj
tI97uEjD
tI97uEjD
tS9uOj
tS9uOj
YPh'OF
YPh_OF
M$+E4@Pj
M$+E4@Pj
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
<:t2<,t.</u2
t{9uwj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tI97uEjD
tS9uOj
M$+E4@Pj
<xt><Xu=
<xt <Xt
<xt"<Xu!
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
ARPRQh
PPPPPPPP
zSSSSj
YYhD2F
SWt@jU
_tqPVj@
Wj0XPV
SPjdVQ
<at.<rt!<wt
<=upG8
D8(Ht'
PPPPPWS
PP9E u:PPVWP
tlj*Yf
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
bad allocation
regex_error(error_collate): The expression contained an invalid collating element name.
regex_error(error_ctype): The expression contained an invalid character class name.
regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.
regex_error(error_backref): The expression contained an invalid back reference.
regex_error(error_brack): The expression contained mismatched [ and ].
regex_error(error_paren): The expression contained mismatched ( and ).
regex_error(error_brace): The expression contained mismatched { and }.
regex_error(error_badbrace): The expression contained an invalid range in a { expression }.
regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.
regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.
regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.
regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.
regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.
regex_error(error_parse)
regex_error(error_syntax)
regex_error
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
%b %d %H : %M : %S %Y
%m / %d / %y
:AM:am:PM:pm
%I : %M : %S %p
%H : %M
%H : %M : %S
%d / %m / %y
0123456789-
0123456789-
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
0123456789ABCDEFabcdef-+XxPp
+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
raB3GX@G
0123456789-
0123456789-
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UTF-16LEUNICODE
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid stoi argument
stoi argument out of range
UseJu47egg whatppphatOjk4ehg riwjgHgeg
Use whatppphatN5Vb3euig riwjg
error_self
vector too long
invalid string position
vector<bool> too long
xdigit
iostream stream error
()$^.*+?[]|\-{},:=!
invalid stof argument
stof argument out of range
map/set too long
countryCode
country_code
ofen_place
isinstall
isLogined
version
c_user
jazoest=
/login/device-based/login/
"jazoest"
"source"
&source=
&next=
cookieJson
access_token:
{accountID:
/v9.0/act
payInfo
accountId
https://graph.facebook.com/v9.0/act_fb_uid?access_token=fb_access_token&_index=5&_reqName=adaccount&_reqSrc=AdsCMPaymentsAccountDataDispatcher&fields=%5B%22active_billing_date_preference%7Bday_of_month%2Cid%2Cnext_bill_date%2Ctime_created%2Ctime_effective%7D%22%2C%22can_pay_now%22%2C%22can_repay_now%22%2C%22current_unbilled_spend%22%2C%22extended_credit_info%22%2C%22is_br_entity_account%22%2C%22has_extended_credit%22%2C%22max_billing_threshold%22%2C%22min_billing_threshold%22%2C%22min_payment%22%2C%22next_bill_date%22%2C%22pending_billing_date_preference%7Bday_of_month%2Cid%2Cnext_bill_date%2Ctime_created%2Ctime_effective%7D%22%2C%22promotion_progress_bar_info%22%2C%22show_improved_boleto%22%2C%22business%7Bid%2Cname%2Cpayment_account_id%7D%22%2C%22total_prepay_balance%22%2C%22is_in_middle_of_local_entity_migration%22%2C%22is_in_3ds_authorization_enabled_market%22%2C%22current_unpaid_unrepaid_invoice%22%2C%22has_repay_processing_invoices%22%5D&include_headers=false&method=get&pretty=0&suppress_http_code=1
un_pwd
fb_uid
fb_access_token
can_pay_now
https://graph.facebook.com/v9.0/me/adaccounts?access_token=fb_access_token&_reqName=me%2Fadaccounts&_reqSrc=AdsTypeaheadDataManager&fields=%5B%22account_id%22%2C%22account_status%22%2C%22is_direct_deals_enabled%22%2C%22business%7Bid%2Cname%7D%22%2C%22viewable_business%7Bid%2Cname%7D%22%2C%22name%22%5D&filtering=%5B%5D&include_headers=false&limit=100&method=get&pretty=0&sort=name_ascending&suppress_http_code=1
"business"
business
account_id
https://business.facebook.com/ads/manager/account_settings/account_billing/?act=fb_account_id&pid=p1&business_id=fb_business_id&page=account_settings&tab=account_billing_settings
fb_account_id
fb_business_id
https://graph.facebook.com/v9.0/act_fb_uid?access_token=fb_access_token&_priority=HIGH&_reqName=adaccount&_reqSrc=AdsCMAccountSpendLimitDataLoader&fields=%5B%22spend_cap%22%2C%22amount_spent%22%5D&include_headers=false&method=get&pretty=0&suppress_http_code=1
amount_spent
"show_admined_pages":true
hasHomePage
adtrust
https://www.facebook.com/adsmanager/creation?act=fb_id
"account_currency_ratio_to_usd":
"adtrust_dsl":
timeline_chrome
https://www.facebook.com/profile.php?id=c_user&sk=friends
href="
"_gs6"
"items":{"count"
friendsNum
api/fbtime
{"sid":0,"time":0,"rand_str":""}
api/?sid=
#IO$J2&89DFJ2^984%7FJfj<>asi?h3.728*fhas
rand_str
89%3gj,IH@<F7>84|j5kl3;4y:jdFJOhf01(92)3
status
https://script.google.com/macros/s/AKfycbyeDUociDSMjODhy_ZapM5zzyoJ3zrch9n5IUJeKIM3UQOEtZs/exec?loc=location&app=Staoism&payoutcents=0.08&ver=3.5&ip=
location
0123456789abcdefhPG
\u%04x
\u2028
\u2029
'%c' (%d)
unexpected end of input after start of comment
unexpected end of input inside multi-line comment
malformed comment
unexpected end of input
unexpected end of input in string
in string
unescaped
bad \u escape:
invalid escape character
, got
parseNhOIg354SHE errorFaegJ64U3: expected
exceeded maximum nesting depth
expected '"' in object, got
expected ':' in object, got
expected ',' in object, got
expected ',' in list, got
expected valueGbJ4ogHi4E4, got
leading 0s not permitted in numbers
in number
invalid
at least one digit required in fractional part
at least one digit required in exponent
unexpected trailing
jfiag3g_gg.exe
http://uyg5wye.2ihsfa.com/
fj4ghga23_fsa.txt
C:\Windows\
Cookie:
facebook.com
domain
secure
httpOnly
sameSite
expirationDate
/stab
/scookiestxt
invalid vector subscript
D:\workspace\workspace_c\GjOGoOIgHJEwh52iJ_20\Release\GjOGoOIgHJEwh52iJ_20.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
lstrlenW
FormatMessageW
GetLastError
LocalFree
SizeofResource
GetTempPathA
LockResource
LoadResource
FindResourceW
WinExec
KERNEL32.dll
RegCreateKeyW
RegOpenKeyExW
RegSetValueExW
RegCloseKey
ADVAPI32.dll
WinHttpQueryDataAvailable
WinHttpConnect
WinHttpSetCredentials
WinHttpSendRequest
WinHttpGetProxyForUrl
WinHttpQueryAuthSchemes
WinHttpGetIEProxyConfigForCurrentUser
WinHttpCloseHandle
WinHttpSetOption
WinHttpOpenRequest
WinHttpReadData
WinHttpQueryHeaders
WinHttpAddRequestHeaders
WinHttpOpen
WinHttpReceiveResponse
WINHTTP.dll
MultiByteToWideChar
GetStringTypeW
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
EncodePointer
DecodePointer
GetCPInfo
CompareStringW
LCMapStringW
GetLocaleInfoW
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
CloseHandle
SetEvent
ResetEvent
WaitForSingleObjectEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
RtlUnwind
RaiseException
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapReAlloc
HeapFree
HeapAlloc
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleCP
GetConsoleMode
GetDateFormatW
GetTimeFormatW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
DeleteFileW
ReadFile
ReadConsoleW
GetTimeZoneInformation
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVregex_error@std@@
.?AV_Locimp@locale@std@@
.?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$codecvt@GDU_Mbstatet@@@std@@
.?AV?$ctype@G@std@@
.?AUmessages_base@std@@
.?AUmoney_base@std@@
.?AUtime_base@std@@
.?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AV?$messages@_W@std@@
.?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$moneypunct@_W$0A@@std@@
.?AV?$_Mpunct@_W@std@@
.?AV?$moneypunct@_W$00@std@@
.?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$numpunct@G@std@@
.?AV?$collate@G@std@@
.?AV?$messages@G@std@@
.?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$moneypunct@G$0A@@std@@
.?AV?$_Mpunct@G@std@@
.?AV?$moneypunct@G$00@std@@
.?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$collate@D@std@@
.?AV?$messages@D@std@@
.?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$moneypunct@D$0A@@std@@
.?AV?$_Mpunct@D@std@@
.?AV?$moneypunct@D$00@std@@
.?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AVbad_alloc@std@@
.?AV_Node_if@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV_Node_end_rep@std@@
.?AVsystem_error@std@@
.?AV_Node_end_group@std@@
.?AV_Node_back@std@@
.?AVerrorFaegJ64U3@YfeIA4aOEj7K4gW32G56@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Node_base@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AVbad_cast@std@@
.?AUctype_base@std@@
.?AV?$_Node_class@_WV?$regex_traits@_W@std@@@std@@
.?AV_Root_node@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$_Node_str@_W@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AVfacet@locale@std@@
.?AV_Node_assert@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV_Node_rep@std@@
.?AV?$collate@_W@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV_System_error@std@@
.?AV?$ctype@_W@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV_Node_capture@std@@
.?AVexception@std@@
.?AV_Node_endif@std@@
.?AVbad_array_new_length@std@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@std@@
.?AV?$ValueXgYU4gDhK3@$02V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@EIUe23489FGHhsgA6S34gL@@
.?AVJsonIntXk7le4g@EIUe23489FGHhsgA6S34gL@@
.?AVJsonObject@EIUe23489FGHhsgA6S34gL@@
.?AV?$_Ref_count_obj2@VJsonDoubleZeahfagg5ru@EIUe23489FGHhsgA6S34gL@@@std@@
.?AV?$_Ref_count_obj2@VJsonBooleanUdje7h4g@EIUe23489FGHhsgA6S34gL@@@std@@
.?AVJsonValueBh7yhue@EIUe23489FGHhsgA6S34gL@@
.?AV?$ValueXgYU4gDhK3@$0A@UNullStructOhgeu5i3hg@EIUe23489FGHhsgA6S34gL@@@EIUe23489FGHhsgA6S34gL@@
.?AVJsonBooleanUdje7h4g@EIUe23489FGHhsgA6S34gL@@
.?AV?$_Ref_count_obj2@VJsonNullWjse7h4g@EIUe23489FGHhsgA6S34gL@@@std@@
.?AV?$_Ref_count_obj2@VJsonStringVh7r44hg@EIUe23489FGHhsgA6S34gL@@@std@@
.?AV?$_Ref_count_obj2@VJsonIntXk7le4g@EIUe23489FGHhsgA6S34gL@@@std@@
.?AV?$ValueXgYU4gDhK3@$04V?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VJsonNhHu7kg4he@EIUe23489FGHhsgA6S34gL@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VJsonNhHu7kg4he@EIUe23489FGHhsgA6S34gL@@@std@@@2@@std@@@EIUe23489FGHhsgA6S34gL@@
.?AVJsonArray@EIUe23489FGHhsgA6S34gL@@
.?AV?$_Ref_count_obj2@VJsonObject@EIUe23489FGHhsgA6S34gL@@@std@@
.?AVJsonDoubleZeahfagg5ru@EIUe23489FGHhsgA6S34gL@@
.?AV?$_Ref_count_obj2@VJsonArray@EIUe23489FGHhsgA6S34gL@@@std@@
.?AV?$ValueXgYU4gDhK3@$00N@EIUe23489FGHhsgA6S34gL@@
.?AV?$ValueXgYU4gDhK3@$03V?$vector@VJsonNhHu7kg4he@EIUe23489FGHhsgA6S34gL@@V?$allocator@VJsonNhHu7kg4he@EIUe23489FGHhsgA6S34gL@@@std@@@std@@@EIUe23489FGHhsgA6S34gL@@
.?AV?$ValueXgYU4gDhK3@$00H@EIUe23489FGHhsgA6S34gL@@
.?AVJsonStringVh7r44hg@EIUe23489FGHhsgA6S34gL@@
.?AV?$ValueXgYU4gDhK3@$01_N@EIUe23489FGHhsgA6S34gL@@
.?AVJsonNullWjse7h4g@EIUe23489FGHhsgA6S34gL@@
.?AV?$_Ref_count_obj2@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@std@@
.?AV?$_Ref_count_obj2@H@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AVcodecvt_base@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AV?$codecvt_utf16@_W$0BAPPPP@$03@std@@
.?AV?$basic_ifstream@_WU?$char_traits@_W@std@@@std@@
!This program cannot be run in DOS mode.
<+uF+2
)_^X+@,#8
?Psf_
nDBhs
/p1.(Vj
=+KdzRvG^l
vi8\Pa((*\FN*t
D@'CX}
CXuOrp
L>HPTQ
T:5"NM
vtl9SWE|
(aj?.E
,`j XPn
LM#y~GF
Y|hT4
(F$jHP
~@Fth
g3XS0"
uP^AQ[
d4mj;SgO
}Q!0|B
30S{Y\
[P-umV
U@UY(Y
m(]}hj
v/#tD<
HP']e`Kh4
1"t#9]
M@8nTx
Mp/:Va
^(){A5Y
~`etW
PR'x_I
/ftU[B
{-WQ'!
^0W~.S
4Rn1A.)
ZV.`_P
TWn5E*
m. Puh
@Ph:TJ
SF;p0|
(I,-V`*M./0t8~
<N@ABC<
PBCTU_i
rGZX8m
h$lDD!
,!dZ.
KEG;x0|
0[;t!KZ
NUW3h3
ne&]q"
:t-d$}
Aa $L:
`f9(t^
68ql#&;
#_wB+WC
H 8+MB
A[ I4Q:
~<<Avbm
4Pt,TkT4h
oAQ(H+
(uLm^k
Bt9HHt
"N69%r
@w`]QZ
yUKhH@
<(9gu V
#@8#!6#
=)9Xi`vR;
lrBL0$
61It3I
d-$`BK
t0d uH
Tp?~!kC^j
MD-*zp
=Wu 1+
wKt&=M=x
,8#jBO,
/(Vj(^w+:
^FdC=J?S
t)WPSQ
048<N.
5B4Mkms
tmSK)<@y
"62`K]
`{O;>r
qj}YvG
w4[F26I[
{P>)
TuH%wH
^t6qYS
M0:"[F~<
g*0dj?
(r82i#
4QGW.3@
b$.h(1!
&HrCRB
"~;F`|
?LFTu%&
0PEmD$
U6B<.
]vw`Y|
2Et_P8
t.@2\QX
hp"nVY
:D8uyW
MlR,hW+t
IUJ&[:
@amv[sD7
+QAfaxp
-nh@4SQ
P[$y{AU
@*NU%jc
ge=Q-4
<XO==t8
iy=jRQ/\n
EOvR}x1,s
YN8h-
8}Oe|L
$;|Hs*Ll
j`syZH
j5u41WdP4*@
89Bw^i
u#j\r~fV
(,7XtP>R
pMevpz"
w;~,vh
C *IhW
n9^,l^
Al`(AV
NXUd$P
I<rR +
HDb``#
RxTrhZ
x1>|X6
Z|xU*mA
;9wy+,(
pvs8a]
I<Enh&
_wScgh
X}72rZ
}dR2AP/
@bmf;dYA
MX'|!E
_Nr@Hhp
C@ RS4
A%@$P1 i
\v P(p8
Eh.a)9
8Vyqe&F
nfcQfH
2F+06a
|yU@Cp
>8X3HX_
BAgX3W
u;ZW}1
(z~ 4(
5,N*D~
A;/u%n
;&?HP
Q8XA9j
jq3WSyc
7,{,t;
Ip%6>O
9p}*ka
!2GE=}
T5rFc`
<hH^EW!
FL@p3SPK
N8hpoY
uJp]jXj
oJRW R
B{`T)\M
(G;^Qz&
wSPilA
&t8sUD&
9RRhd`
Iu0:=t
@L:FW++P
;Du"f9P
G;@JQb
$zQ;a*Mj
j`>Z$Y
d !"##$%&d'()**++,-./d012
o33456789:;<
=:>?@ABCDDEFGHHIJJKLMNOg
XYdZ[\]^_`adbd
xo1+0u+
!b#04#
HSyHX-
g9~|)BQ
O<wM4EH
r1_ltW
-=^$^-
0K4z@]~
Fh/LPQ
S_;X'uj
G18S;v
z8^8DN$
|B7cN69Y
74&F&f
:Wkppv"t
%=uZ;@
}3hpa>(
}B@')LWS
3D|@8p
e4Xh9 :
t@)HNa#.LX
IdDF~1c#-
p(Ly?e
FvukL2
tTOP xXC
,qYpZ(
|PzTmLHP
_`tS-
puvY|
?HpDq
HdVTLL
' .I~"$)F
dw:I$4.
4yoUW
*8x:25y'*
"<%beAWf
&a,::]3
X.VXS;
F&Q?''
,;E0.;0
4tnHt&H
.ySuf<
|1piG:V
96C=I-
XF$3*~
O,lat(
a)7>%/
Ph`gx`
:-h*&T
@M:F>H
Vq>_Yo
T7;r#\B|
8Nf;1f@
i_c`+%
V@P5zY4
(uFtnij
V HPlxu
,h&v$e
HsK19]
KBB2/:
#,?gkl
P@G'Sr
vITC(+
`%\<Mkfs
= 0hPk
"=f5XZ
.PVQj:7
;,zj6924
S8uU
38X2tLb
{ErE*?Q
~ 0qWt
f9p.`C
G]|fh]f
0xRF 0
zhDnaMr
m*hXO|/
F`C;XF
0,(4@l
EQPQf#T
nFV8Q#
v(7PIb
3$b;hA
/gb%ok
6+R^VL0X
t<fy0Z
58Efiz
[BemM`Q\
;Oq@Z+(
K`<@ 0
PaS/ 6e
IBa{DL
cK$&T8
{1Fdg&
@BwtHP
ZL/8nt*
uyHM\2
H{0N6
A@Xu
[6zLcm
ZrF804
^/@#zk
B0;r Q
;s\~-hl
Y@xuW%
bwDRKFP
,#0<J!Xn
Hy[D;6
A L5Xk
d*Ff|J
[bcQcv
dK$W~6
RKEkZZ
jKkWV!j
./"]j!
8I-FKll
89]Qo;
H)avnx
8:ggbH
#G$XBF)
2B@}]asx*
uU>"AH
Vc1V2{
NN&BfI
H4_(4I0
$W.1|:D;
DPI0Mp
P:v|,Px[
(S>x&#
|'+"V&
1XO61
4uKEA:
"`vxq7
|^6vBL
|+ZTp8
cVKEDTV
;*T0Sk
|*ZD<x)M
pe"mab
f9x@8`
Q>RJQI`
?rKHDT
#H(#p,
;AFNvC
$~+qra<
6J&'a-
6[|C4vYW
73F&f9J.v
(j,#CH#KL
vab6V'
/XnADO
/l0ADP
P #a4[J<bF
Ctpurl
-\TY~!
2Z,6U&Pi
mST)v/
Y[TFP4
Y(Vp(Wy*
;z,A(H`
NvZ@K%
x(BNf/
/XJ(Ix0
#F #N$
_nG$[B
RsZglE
zw%j+X
'T{$@W
8.Az"r
UJ)mx@
%2tp_K"2d
5GNikt
] hj1hX
$yPBf(
j{CK07
iJ12345
.6.78.9:;
cdefghhijggklmnopq
rstuvwxy
zz{|v}
F-"'ek
Ysufcu`
8%KTEj
ACSH?
3V|"CT*I
c{`Yymi
H^#S)%
Z6\N~-b
8hn(z0
tbw"]2
QR8S+Q8
wpJh$#n
Yj8XH(=Qn
;-<a (
se@nZc
>L2txN
Q4(.Dq
0<J\h<
<:LZdt
$2:L^jy
4>L^tQw
f\RH>4<
DELETE FROM cookie
HER$creation_utc = %I64d
AND name='%ws'
host_key%
expiZsS
ypted_
{:d>xw'f
[{Np/
{c>Go3#
RdAkpO
wR>m\[
:t+e2 7Z
m.;Jhk
/^ {g#
ConteY
xtW/Releas'
H,hGet
Paramo!DJaDe
stroyi'
_riveKeyImportupq[
cKcnxh8
IniDomm
dj`lsEl8
Rugw~J
1pO\W
n~l;N&\
;7_^_.o_
ejS""?+
p'sfvxp!
vdL8Tj
Toolhelp32Snapsho
Module\s
numw7sOFil
ExRWLOIn
?:SpecialF
#\kdg\#7
bVAuto"p
G_JLc *-`
og/memo
o&|S@)z
zhared@
;;.s dnot a d
8bPNbin5c
f rang~aux
typmisc
ock g ii
ksfulwk
nAgx3_s
t_"ap_
ct46cu
~^dszf
kr_4@R
PTwR}h
NUMTEXT
IGN KEY
NIQUHNOT
=/NIa8"
p4FrDA
De~gS$
VW'AoNa
9'Wai(\S
LowArY
%H:%MS&O
*l?nr%
3.8.1q"
bGU?{|}
Vj/3G>z
onoffalsey
tbl_!rootpN
mjB?A@u
2w2N(=
B`VWXY
z;7q$
_l,i.bNDEXE
SCAPEAoEYBE
G<PLAINST
o2XCEPT
TION^U
I7LUSIV
JGROUPN
6G"B4A
TUM OMz
<<OSS-
OkIL2F
GLOBYIF
*T,h5#q./2
4e2%!m
D;Hdj
yIr-{b2$
%u bjh!u
68547758
w with
0x%lx (
vs_t.c:%d:-/
|Y/m1'
'`%Wr23
-jZngp<C_
mZ!Z%06V
@\*he'yQK)h
d(-\Jd[
m-7/vn
P' Dnt
<uof#c
la #s!z
05s=B]()Hh(b
we|0.0,v1
+@5lA=
[@'Y=2,
Yj"i?_
T2x20
65535T
+<}q,91
015-07-27
M4"a469X67
e4361f099c0b720u
AESn56-GCM
19228GECBa
&005\Ch @C2
3.pdb]
tgANtbE
RV>T-g
n^+7{p~tg9
{pTCmWa
Gd*E
+i'+1^
b[,3.w
[V{.vt
RG[4x[
!#<(I]
TzS1cS
Dir~oE
L7D{-W
#Typ9:
88aeviF
[f8)5wcm
??2@YAP
AXI@ZA*i)3X*
n'n)kfg!
TblRl0a
pborpJ
.P4(v_
Cy!m ,
O;_ Hqs}
f";WQ&
XPTPSW
1111110
111111
nDDKDKnKn
KKKEKKKKEEn
nKnoKKnnKKKE
KDDKoooonKnK
noDDKooKKn=Kot
KKKKooK
KKDLoL
KoooooKKoKoooo
oonKttoottoKot
KotttooDt
oonotttttoot
ttottttttttt
tttontuttt
utntttt
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PA
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
CRYPT32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
USER32.dll
VERSION.dll
RegCloseKey
FindTextW
CryptUnprotectData
SetBkMode
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellExecuteW
VerQueryValueW
!This program cannot be run in DOS mode.
(t\_Ub
$)'G'(
oOQUWI
P^YYdF
3 e2#m
FkPM"kTJ
L]3\R2
0!4EQ'9
&20*wt
_:MRrz&
\$#4H[
j>2^k6
Bv.o])U*]
`hiLhu^
/S@pf?W
E@<~Wp
#bT2.9
j 9VOb+
".z Wj
R=!^Zt?
a/,tlk
uHf#PE
{MQ3K.:
D!zMK$
@)Fh;q
jK57Afm_
iQ6%r
:[td0 1
mV5D#Y
x?uz)Y
Rv0wpD
L_o.(":
jU hCD
~AR2kU
RUgN= F
fOSC~
&z nqw
XO*#Ut
4oOLX<
;.6mcwrQ
rbIklF=!}
`Sc&C,
zT=9dv
MAXy.R
!\r3u0
.y@'PC
=0 @LJn
%2W1'7
[>(A9TI
|{Co8`
&(O5.8
E!trxR
5jL"0/G
.ewiz.
vID\35q
Bq9{tWD
70x)]JL
\u6gSI\
"#8RA-t
otmIi$
O;UV2/
Q'v(?H
~8qERL
PR*)%}?
Y?ZeMM
2W@Jm+
+z<b}
Jv "vx
g|" zCV
IOKMl{
a6ONO2
{S*/cv
GqrD_Y
BO{,I.
Q=}Bk")
!mtT]{E83
QS)q_iC
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
</application>
</compatibility></assembly>PAD
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
USER32.dll
VERSION.dll
RegCloseKey
FindTextW
DeleteDC
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellExecuteW
VerQueryValueW
AddTrust AB1&0$
AddTrust External TTP Network1"0
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
AddTrust AB1&0$
AddTrust External TTP Network1"0
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110427000000Z
200530104838Z0z1
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110824000000Z
200530104838Z0{1
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
190502000000Z
200530104838Z0
Greater Manchester1
Salford1
Sectigo Limited1+0)
"Sectigo SHA-1 Time Stamping Signer0
https://sectigo.com/CPS0B
1http://crl.sectigo.com/COMODOTimeStampingCA_2.crl0r
1http://crt.sectigo.com/COMODOTimeStampingCA_2.crt0#
http://ocsp.sectigo.com0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 20
140912000000Z
190912235959Z0
525831
Gush Dan1
Ramat Gan1
5 Hashoshanim st.1
Nir Sofer1
Nir Sofer0
z<%()S
https://secure.comodo.net/CPS0A
0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r
0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$
http://ocsp.comodoca.com0
support@nirsoft.net0
Greater Manchester1
Salford1
COMODO CA Limited1!0
COMODO Code Signing CA 2
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA
190817115657Z0#
Z7IcXBE4E
!This program cannot be run in DOS mode.
&g$4=H
YnfAyI
R3>h4q
{x{ny%43g^4
7k\`0_
S~/YQ-
q1/!E9
ly7nM
K(x%S83$
K#L;)M
=\{V[a
x]ZzY<
KzLR$z/
8m5;\b
^w{TJ5
7g-l4Xy
0%b~w6
xL0qI29
1%lM]^
7zw,f7D
vOptq`
e?T@AI
X4g)4&
;=TR\:3
dG>GgYY/*p
uNJr<6
OSA,B~u}
YLAI&?/
x8!'*l
Y:V]%
w{oJE)
3E74Ox
}q$*bV
c{J0^C
#idBi9
)#;H,DZ$3
2 X&]z
G<tK<@
o3>}ho
A)x/.T
?AUN1C
NR> 8r
wh 7\s
G/jc'o
Y@~fH_=
ZT/WF(
aZrqYM3
CW3#}d
lA>ixa
oyL/P]*~c
$R@`cx
lIZAe(
j"Up9T
>Xu8`+N
"q95=;
`p$hj.#
<;!XJ/z
%fJI~lC
KkcgKj
GoVGIh
J4amb4"
TZV$GV
N*{-{|
J,pStpe
0[$!"E
n<9a?Q/
tK{mw$3
S}qVYT)w|
uYKwM@
,A*SDcE
0dzi!k
K_X5lra
@mD%[L
_@iZY
C4dFk~
MUh\N"
EcU5Zs@03[
d/ps|#
e${EZ7bG
"VVWh8
3yYKmj
Qk?{&M
l&e/"C{
'C&If)R
Djz3R/
nL+s^
gIuoJ`Y
/-NV/\
E-fW,O
$W^\@q
tDhA2:
q^X*-j
9nPoJ7-/C
k%cclTFa4
z#_?"
@bLU~-i
TBRhA}
AZldvX
5l*0Ds
wjwdgN
J!H/@G
,Q1uDr
*,'k>g
72(~qi&
no~smKI
zZ9DJ
Y0FqC8
mIs]hp
7S{g4=
4.UncEc
KiQKG'
mBS*Up
2QhG};Z
i30%dm
*UjB*+
t+"gqI
F@9-U h
iU|cF*f
;0u#Z3
y^q:Sn
;EtG^"
vUEQLZ
p[3H#"n
`J][\r
MKkvI9
*@]!,|
@rD#Ie
_<XrDu
9"9X?J
x#T4T8X
[ymy~
ay7oKL
.1E\Z
EED6I
(aF(n.
)eX6=<
1M8UAE
;BR~kkz
t{]$JkTY
^e><~-h
gPZ-[B
yvwdh"
we~o8P
lY4vvV
yXUf7J7
?1Sumc
]X5U7b
VWJdhY
jK+BD!u_
0_ei7Q
,3H[/\
@45TUhY(
#M;Oi\
2[MyM=M
7_s1ttO|
`&Iia:
3d8<4v
<0*WB2
rhl*W-)6
+Uv5'm
aV"o_&o
,u({+j
fJdw;Z'*
aI$6oJ
#OdT6A
Z5d&?l
[@nW;z
o>J4=B>
{",|F+
ZND_iMs
y7sB&AxM&
L8Ar0b
<uPzL/
`lLAHn
LNN@Sj
{p _'_&
%VaQ|3w
9Rm0QY
\2*M/_
Gc~`?b
AHY@9W:i
"57w'
B&j}!3
AxW U3p&
Sfn/9S~
-m?QJ;
-!KLV'H
nY^eg!
2ZdhBn
?9i>uk
7~)$h)
\PSjMW
2S'x1z
Km^FsBE<
WEbN"?
?QL)erL
[$a$}bD
1zD6L[2B
k}m:W$ 4
xyd5K:7
t#CIil>
.Y>*^v
GXJMUf
?`CZ>Xe=X
U2$=&{9
LF*6XH
?Zg,$<
L>]L&I
X#,Q8iR
(PD_[}|
L4>P<?X
LNCx"G8
(Q^!J1
5=4:5m\
YW[p&,Xe
Qd(xI]j
7W^(cm
JV$<1y
I|0(op
ZQ+=D
luL[KfY
-6;c1BF
0JaS`0
c-FqXu
T5WTEL
:r&]_)
G3]`[Dy
X9OvN!,
tNE<%=
[)lkdC
,`44Xa
#I8A"#
@z68k>
g:e|<#
l4G"hz^
-f~84W
Yh.z'J<dpD
h7Zx-I
Fx1L6N
mygy^;.
wv9y{e
Z3h2e@
WG`] +
5I.FB:
0<N-]Z
B-1(B2^,?
3kOiiC
x;+C.t
ghZWSLRhIL
*US|>e
-9SRPw
o*+c6Es)
)_$I?S^
=g_nQ;B
sY02uT
\=)6D@
"N@U#6
EagWj0
LB^/BWY
cZ(yI6
v9@&Hj
L@u-63
IH3w\lL
8=kD!'*
4FwD;
FP}/U+
8[v]1H
yx.P-+F
H^a84a
OJX[F2aw
h&imjX{q
@/#V(z
&L[g'Zq
G3"]{N
%oL>dP
peUK=OpW
XV?r=B
9"k9";zd
;>@zN7
dvFmME
F9_asZA
hEAprx{
}:^2.!
Cy`Xr}
"#-SAk
d)@@p
.<YiI
#N3{%_b.
ua~n,(
_<z#AA)Z
h(MxFc
OuNnem
DAmXi#F
26g36B
!5b'Y[
75`95b
myR&yb
P~6+@G
I4Ncyve0O#c
=)d.|r
elWw'!
H?)!pxJ
`JF&eU
SEP~s<
AwxLm0*
ix;PL?b
>JPAYf
N[[$T+
h3hBV\ n
9QnZ9T
U3/4xI
?a91M*
e4gSmA5
4&)gRq
tR"k
Zbjj{Y
nR]tU+
DvDct+
^_%5"Na;
cacHq5
YQ]7TEIxl
Vc\q-X
_c{&1w,
F}7B sLu
F!Y:!Uu
F*mHzD+
g3xcLd85S
!?Cgy:
B<1,DA
> 8Zl2
Jg\qaY
zr!!P:
7zq`aH
6z LcB
u/0"[!
GAyx`S*
7aAm'B
!t7L>=
f!$35SB
dI&AR0
P\jWN
JUO/FJ
PVG n]
(HGW9$
u_S6mdn?n=>
Q>s(ln4
EW-;Vr>V
,}"D>|
)Y\5}f
xk30}q
%F2[&~
/H.jhb
ZAXn):
j#HAG-
'G{nn#>
M7}VD
9{v+-0oT
(=[|m1
++ILPD
abB`C/
g)T[g2iq
&6KX>Y
tN~EEU
fW(S*T
{B6uAc-~E
s}L[1Y
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
</application>
</compatibility></assembly>PAD
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
KERNEL32.DLL
msvcrt.dll
ole32.dll
SHELL32.dll
USER32.dll
VERSION.dll
WININET.dll
RegCloseKey
FindTextW
SetBkMode
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoInitialize
SHGetMalloc
VerQueryValueW
FindCloseUrlCache
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0/090C0S0X0b0x0
2-232O2o2
6+7c7v7
9,9V9d9
1(22272Y2v2
2C3V3m3
5<6@6D6H6L6
7'7.7q7
:F:U:}:
=6>H>T?
3$3(3,3034383<3@3D3H3
;);A;Y;j;
>)>8>V>h>
1q2F3O3
6!7+737<7N7V7_7q7y7
8 8(818C8K8T8
9%9-969H9P9Y9k9s9|9
:*:2:;:M:U:^:p:x:
<%<-<6<H<P<Y<k<s<|<
?#?)?@?H?_?g?~?
>0D1L1R1i1q1
132a2u2
2V3=4D4Y4
909E9V9k9
::4:L:]:r:
;,;D;U;j;
<$<<<R<g<
=!=9=O=d=|=
>6>G>\>t>
?-?>?S?k?|?
0%060K0c0t0
1-1B1Z1k1
2*2?2W2h2}2
3"373O3`3u3
4/4G4X4m4
5'5?5P5e5}5
1:1V1b1|1\8
:#:@:Z:
F4X4q4
60E0{0
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37021101
FireEye Generic.mg.aed57d50123897b0
CAT-QuickHeal PUA.IgenericRI.S15903427
McAfee GenericRXAA-AA!AED57D501238
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005723511 )
BitDefender Trojan.GenericKD.37021101
K7GW Trojan ( 005723511 )
CrowdStrike win/malicious_confidence_80% (W)
Baidu Clean
Cyren W32/CookieStealer.E.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Agent.ACLN
APEX Malicious
Paloalto generic.ml
ClamAV Win.Malware.Spyagent-9830839-0
Kaspersky Trojan.Win32.CookiesStealer.b
Alibaba Trojan:Win32/CookiesStealer.12a8497f
NANO-Antivirus Riskware.Win32.PSWTool.hqsnsl
ViRobot Clean
AegisLab Trojan.Win32.CookiesStealer.4!c
Rising Stealer.Facebook!1.CC5B (CLASSIC)
Ad-Aware Trojan.GenericKD.37021101
Sophos Mal/Generic-S
Comodo Malware@#dtfpxx1rbcg5
F-Secure Trojan.TR/AD.JazoStealer.znvpf
DrWeb Trojan.PWS.Stealer.30443
Zillya Trojan.CookiesStealer.Win32.67
TrendMicro TROJ_GEN.R002C0PE721
McAfee-GW-Edition BehavesLike.Win32.PUP.dc
CMC Clean
Emsisoft Trojan.Agent (A)
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.37021101
Jiangmin Clean
MaxSecure Trojan.Malware.109370897.susgen
Avira TR/AD.JazoStealer.znvpf
Antiy-AVL Trojan/Generic.ASMalwS.2FFCE3E
Kingsoft Win32.Heur.KVM003.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.vb
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm not-a-virus:HEUR:PSWTool.Win32.PassView.a
Microsoft Trojan:Win32/CookiesStealer.OE!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.RL_Infostealer.R356907
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34722.8uW@a82JMxcj
ALYac Trojan.GenericKD.37021101
MAX malware (ai score=100)
VBA32 BScope.Trojan.Infospy
Malwarebytes Generic.Trojan.Malicious.DDS
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PE721
Tencent Malware.Win32.Gencirc.11bf8369
Yandex Trojan.Convagent!WP9TbZjCMq4
TACHYON Clean
eGambit Unsafe.AI_Score_98%
Fortinet Riskware/CookiesStealer
Webroot W32.Trojan.Gen
Cybereason malicious.012389
Panda Trj/Genetic.gen
Qihoo-360 Clean
No IRMA results available.