Static | ZeroBOX

PE Compile Time

2012-01-30 06:32:28

PE Imphash

d3bf8a7746a8d1ee8f6e5960c3f69378

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008061c 0x00080800 6.68469014817
.rdata 0x00082000 0x0000dfc0 0x0000e000 4.79974113225
.data 0x00090000 0x0001a758 0x00006800 2.15007153917
.rsrc 0x000ab000 0x0000a200 0x0000a200 5.5885456562

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000afcc0 0x00002d74 LANG_ENGLISH SUBLANG_ENGLISH_UK PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_MENU 0x000b2a38 0x00000050 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_DIALOG 0x000b2a88 0x000000fc LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000b4c00 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b4dd8 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000b4dd8 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000b4dd8 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000b4dd8 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000b4df0 0x0000019c LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000b4f90 0x0000026c LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library WSOCK32.dll:
0x482794 __WSAFDIsSet
0x482798 setsockopt
0x48279c ntohs
0x4827a0 recvfrom
0x4827a4 sendto
0x4827a8 htons
0x4827ac select
0x4827b0 listen
0x4827b4 WSAStartup
0x4827b8 bind
0x4827bc closesocket
0x4827c0 connect
0x4827c4 socket
0x4827c8 send
0x4827cc WSACleanup
0x4827d0 ioctlsocket
0x4827d4 accept
0x4827d8 WSAGetLastError
0x4827dc inet_addr
0x4827e0 gethostbyname
0x4827e4 gethostname
0x4827e8 recv
Library VERSION.dll:
0x482738 VerQueryValueW
0x48273c GetFileVersionInfoW
Library WINMM.dll:
0x482784 timeGetTime
0x482788 waveOutSetVolume
0x48278c mciSendStringW
Library COMCTL32.dll:
0x48208c ImageList_Remove
0x482094 ImageList_BeginDrag
0x482098 ImageList_DragEnter
0x48209c ImageList_DragLeave
0x4820a0 ImageList_EndDrag
0x4820a4 ImageList_DragMove
0x4820ac ImageList_Create
0x4820b4 ImageList_Destroy
Library MPR.dll:
0x4823dc WNetGetConnectionW
0x4823e0 WNetAddConnection2W
0x4823e4 WNetUseConnectionW
Library WININET.dll:
0x482748 InternetReadFile
0x48274c InternetCloseHandle
0x482750 InternetOpenW
0x482754 InternetSetOptionW
0x482758 InternetCrackUrlW
0x48275c HttpQueryInfoW
0x482760 InternetConnectW
0x482764 HttpOpenRequestW
0x482768 HttpSendRequestW
0x48276c FtpOpenFileW
0x482770 FtpGetFileSize
0x482774 InternetOpenUrlW
Library PSAPI.DLL:
0x482450 EnumProcesses
0x482454 GetModuleBaseNameW
0x48245c EnumProcessModules
Library USERENV.dll:
0x48272c UnloadUserProfile
0x482730 LoadUserProfileW
Library KERNEL32.dll:
0x482158 HeapAlloc
0x48215c Sleep
0x482160 GetCurrentThreadId
0x482164 RaiseException
0x482168 MulDiv
0x48216c GetVersionExW
0x482170 GetSystemInfo
0x48217c WideCharToMultiByte
0x482180 lstrcpyW
0x482184 MultiByteToWideChar
0x482188 lstrlenW
0x48218c lstrcmpiW
0x482190 GetModuleHandleW
0x482198 VirtualFreeEx
0x48219c OpenProcess
0x4821a0 VirtualAllocEx
0x4821a4 WriteProcessMemory
0x4821a8 ReadProcessMemory
0x4821ac CreateFileW
0x4821b0 SetFilePointerEx
0x4821b4 ReadFile
0x4821b8 WriteFile
0x4821bc FlushFileBuffers
0x4821c0 TerminateProcess
0x4821c8 Process32FirstW
0x4821cc Process32NextW
0x4821d0 SetFileTime
0x4821d4 GetFileAttributesW
0x4821d8 FindFirstFileW
0x4821dc FindClose
0x4821e0 DeleteFileW
0x4821e4 FindNextFileW
0x4821e8 MoveFileW
0x4821ec CopyFileW
0x4821f0 CreateDirectoryW
0x4821f4 RemoveDirectoryW
0x4821f8 GetProcessHeap
0x482200 FindResourceW
0x482204 LoadResource
0x482208 LockResource
0x48220c SizeofResource
0x482210 EnumResourceNamesW
0x482214 OutputDebugStringW
0x482218 GetLocalTime
0x48221c CompareStringW
0x482230 GetStdHandle
0x482234 CreatePipe
0x482238 InterlockedExchange
0x48223c TerminateThread
0x482240 GetTempPathW
0x482244 GetTempFileNameW
0x482248 VirtualFree
0x48224c FormatMessageW
0x482250 GetExitCodeProcess
0x482254 SetErrorMode
0x48227c GetDriveTypeW
0x482280 GetDiskFreeSpaceExW
0x482284 GetDiskFreeSpaceW
0x48228c SetVolumeLabelW
0x482290 CreateHardLinkW
0x482294 DeviceIoControl
0x482298 SetFileAttributesW
0x48229c GetShortPathNameW
0x4822a0 CreateEventW
0x4822a4 SetEvent
0x4822b0 GlobalLock
0x4822b4 GlobalUnlock
0x4822b8 GlobalAlloc
0x4822bc GetFileSize
0x4822c0 GlobalFree
0x4822c8 Beep
0x4822cc GetSystemDirectoryW
0x4822d0 GetComputerNameW
0x4822d8 GetCurrentProcessId
0x4822dc GetCurrentThread
0x4822e4 CreateProcessW
0x4822e8 SetPriorityClass
0x4822ec LoadLibraryW
0x4822f0 VirtualAlloc
0x4822f4 LoadLibraryExW
0x4822f8 HeapFree
0x4822fc WaitForSingleObject
0x482300 CreateThread
0x482304 DuplicateHandle
0x482308 GetLastError
0x48230c CloseHandle
0x482310 GetCurrentProcess
0x482314 GetProcAddress
0x482318 LoadLibraryA
0x48231c FreeLibrary
0x482320 GetModuleFileNameW
0x482324 GetFullPathNameW
0x48232c IsDebuggerPresent
0x482334 ExitProcess
0x482338 ExitThread
0x482340 ResumeThread
0x482344 GetTimeFormatW
0x482348 GetDateFormatW
0x48234c GetCommandLineW
0x482350 GetStartupInfoW
0x482358 HeapSize
0x48235c GetCPInfo
0x482360 GetACP
0x482364 GetOEMCP
0x482368 IsValidCodePage
0x48236c TlsAlloc
0x482370 TlsGetValue
0x482374 TlsSetValue
0x482378 TlsFree
0x48237c SetLastError
0x482388 GetStringTypeW
0x48238c HeapCreate
0x482390 SetHandleCount
0x482394 GetFileType
0x482398 SetStdHandle
0x48239c GetConsoleCP
0x4823a0 GetConsoleMode
0x4823a4 LCMapStringW
0x4823a8 RtlUnwind
0x4823ac SetFilePointer
0x4823bc GetTickCount
0x4823c0 HeapReAlloc
0x4823c4 WriteConsoleW
0x4823c8 SetEndOfFile
0x4823cc SetSystemPowerState
Library USER32.dll:
0x4824a0 GetCursorInfo
0x4824a4 RegisterHotKey
0x4824a8 ClientToScreen
0x4824b0 IsCharAlphaW
0x4824b4 IsCharAlphaNumericW
0x4824b8 IsCharLowerW
0x4824bc IsCharUpperW
0x4824c0 GetMenuStringW
0x4824c4 GetSubMenu
0x4824c8 GetCaretPos
0x4824cc IsZoomed
0x4824d0 MonitorFromPoint
0x4824d4 GetMonitorInfoW
0x4824d8 SetWindowLongW
0x4824e0 FlashWindow
0x4824e4 GetClassLongW
0x4824ec IsDialogMessageW
0x4824f0 GetSysColor
0x4824f4 InflateRect
0x4824f8 DrawFocusRect
0x4824fc DrawTextW
0x482500 FrameRect
0x482504 DrawFrameControl
0x482508 FillRect
0x48250c PtInRect
0x482518 SetCursor
0x48251c GetWindowDC
0x482520 GetSystemMetrics
0x482524 GetActiveWindow
0x482528 CharNextW
0x48252c wsprintfW
0x482530 RedrawWindow
0x482534 DrawMenuBar
0x482538 DestroyMenu
0x48253c SetMenu
0x482544 CreateMenu
0x482548 IsDlgButtonChecked
0x48254c DefDlgProcW
0x482550 ReleaseCapture
0x482554 SetCapture
0x482558 WindowFromPoint
0x48255c LoadImageW
0x482564 mouse_event
0x482568 ExitWindowsEx
0x48256c SetActiveWindow
0x482570 FindWindowExW
0x482574 EnumThreadWindows
0x482578 SetMenuDefaultItem
0x48257c InsertMenuItemW
0x482580 IsMenu
0x482584 TrackPopupMenuEx
0x482588 GetCursorPos
0x48258c DeleteMenu
0x482590 CheckMenuRadioItem
0x482594 SetWindowPos
0x482598 GetMenuItemCount
0x48259c SetMenuItemInfoW
0x4825a0 GetMenuItemInfoW
0x4825a4 SetForegroundWindow
0x4825a8 IsIconic
0x4825ac FindWindowW
0x4825b4 TranslateMessage
0x4825b8 SendInput
0x4825bc GetAsyncKeyState
0x4825c0 SetKeyboardState
0x4825c4 GetKeyboardState
0x4825c8 GetKeyState
0x4825cc VkKeyScanW
0x4825d0 LoadStringW
0x4825d4 DialogBoxParamW
0x4825d8 MessageBeep
0x4825dc EndDialog
0x4825e0 SendDlgItemMessageW
0x4825e4 GetDlgItem
0x4825e8 SetWindowTextW
0x4825ec CopyRect
0x4825f0 ReleaseDC
0x4825f4 GetDC
0x4825f8 EndPaint
0x4825fc BeginPaint
0x482600 GetClientRect
0x482604 GetMenu
0x482608 DestroyWindow
0x48260c EnumWindows
0x482610 GetDesktopWindow
0x482614 IsWindow
0x482618 IsWindowEnabled
0x48261c IsWindowVisible
0x482620 EnableWindow
0x482624 InvalidateRect
0x482628 GetWindowLongW
0x48262c AttachThreadInput
0x482630 GetFocus
0x482634 GetWindowTextW
0x482638 ScreenToClient
0x48263c SendMessageTimeoutW
0x482640 EnumChildWindows
0x482644 CharUpperBuffW
0x482648 GetClassNameW
0x48264c GetParent
0x482650 GetDlgCtrlID
0x482654 SendMessageW
0x482658 MapVirtualKeyW
0x48265c PostMessageW
0x482660 GetWindowRect
0x48266c CloseDesktop
0x482670 CloseWindowStation
0x482674 OpenDesktopW
0x482680 OpenWindowStationW
0x482684 MessageBoxW
0x482688 DefWindowProcW
0x48268c CopyImage
0x482690 AdjustWindowRectEx
0x482694 SetRect
0x482698 SetClipboardData
0x48269c EmptyClipboard
0x4826a4 CloseClipboard
0x4826a8 GetClipboardData
0x4826b0 OpenClipboard
0x4826b4 BlockInput
0x4826b8 GetMessageW
0x4826bc LockWindowUpdate
0x4826c0 GetMenuItemID
0x4826c4 DispatchMessageW
0x4826c8 MoveWindow
0x4826cc SetFocus
0x4826d0 PostQuitMessage
0x4826d4 KillTimer
0x4826d8 CreatePopupMenu
0x4826e0 SetTimer
0x4826e4 ShowWindow
0x4826e8 CreateWindowExW
0x4826ec RegisterClassExW
0x4826f0 LoadIconW
0x4826f4 LoadCursorW
0x4826f8 GetSysColorBrush
0x4826fc GetForegroundWindow
0x482700 MessageBoxA
0x482704 DestroyIcon
0x482708 PeekMessageW
0x48270c UnregisterHotKey
0x482710 CharLowerBuffW
0x482714 keybd_event
0x482718 MonitorFromRect
Library GDI32.dll:
0x4820c8 DeleteObject
0x4820cc AngleArc
0x4820d4 ExtCreatePen
0x4820d8 StrokeAndFillPath
0x4820dc StrokePath
0x4820e0 EndPath
0x4820e4 SetPixel
0x4820e8 CloseFigure
0x4820f0 CreateCompatibleDC
0x4820f4 SelectObject
0x4820f8 StretchBlt
0x4820fc GetDIBits
0x482100 GetDeviceCaps
0x482104 MoveToEx
0x482108 DeleteDC
0x48210c GetPixel
0x482110 CreateDCW
0x482114 Ellipse
0x482118 PolyDraw
0x48211c BeginPath
0x482120 Rectangle
0x482124 SetViewportOrgEx
0x482128 GetObjectW
0x48212c SetBkMode
0x482130 RoundRect
0x482134 SetBkColor
0x482138 CreatePen
0x48213c CreateSolidBrush
0x482140 SetTextColor
0x482144 CreateFontW
0x482148 GetTextFaceW
0x48214c GetStockObject
0x482150 LineTo
Library COMDLG32.dll:
0x4820bc GetSaveFileNameW
0x4820c0 GetOpenFileNameW
Library ADVAPI32.dll:
0x482000 RegEnumValueW
0x482004 RegDeleteValueW
0x482008 RegDeleteKeyW
0x48200c RegEnumKeyExW
0x482010 RegSetValueExW
0x482014 RegCreateKeyExW
0x482018 GetUserNameW
0x48201c RegConnectRegistryW
0x482020 CloseServiceHandle
0x482028 OpenThreadToken
0x48202c OpenProcessToken
0x482034 DuplicateTokenEx
0x482044 InitializeAcl
0x482048 GetLengthSid
0x48204c CopySid
0x482050 LogonUserW
0x482054 LockServiceDatabase
0x482058 GetTokenInformation
0x482060 GetAclInformation
0x482064 GetAce
0x482068 AddAce
0x482070 RegOpenKeyExW
0x482074 RegQueryValueExW
0x482080 OpenSCManagerW
0x482084 RegCloseKey
Library SHELL32.dll:
0x482464 DragQueryPoint
0x482468 ShellExecuteExW
0x48246c SHGetFolderPathW
0x482470 DragQueryFileW
0x482474 SHEmptyRecycleBinW
0x482478 SHBrowseForFolderW
0x48247c SHFileOperationW
0x482484 SHGetDesktopFolder
0x482488 SHGetMalloc
0x48248c ExtractIconExW
0x482490 Shell_NotifyIconW
0x482494 ShellExecuteW
0x482498 DragFinish
Library ole32.dll:
0x4827f4 MkParseDisplayName
0x4827fc CLSIDFromString
0x482800 StringFromGUID2
0x482804 CoInitialize
0x482808 CoUninitialize
0x48280c CoCreateInstance
0x482814 CoTaskMemAlloc
0x482818 CoTaskMemFree
0x48281c ProgIDFromCLSID
0x482820 OleInitialize
0x482824 CreateBindCtx
0x482828 CLSIDFromProgID
0x482830 CoCreateInstanceEx
0x482834 CoSetProxyBlanket
0x482838 OleUninitialize
0x48283c IIDFromString
Library OLEAUT32.dll:
0x4823ec VariantChangeType
0x4823f0 VariantCopyInd
0x4823f4 DispCallFunc
0x4823f8 CreateStdDispatch
0x4823fc CreateDispTypeInfo
0x482400 SysFreeString
0x482410 SysStringLen
0x482414 SafeArrayAllocData
0x482418 GetActiveObject
0x482428 SysAllocString
0x48242c VariantCopy
0x482430 VariantClear
0x482438 VarR8FromDec
0x48243c SafeArrayGetVartype
0x482440 OleLoadPicture
0x482444 SafeArrayAccessData
0x482448 VariantInit

!This program cannot be run in DOS mode.
`.rdata
@.data
L$LQVW
L$p9L$\
D$x;D$\
D$p;D$D
T$x;T$p
D$x;D$\
C;\$8r
T$XR@Q
{D9{ v
u h4SH
u h4SH
9U tO9U$uE9U(uE3
9E vgPQj
9U$tE+
9u(vEVSj
9u v&VQj
HtcHt.
HYYtJHt9H
uhl8H
^SSSSS
u)jAXf;
u)jAXf;
t;f99t6C;]
sej\Yf
.t C;]
s%j.Zf
j@j ^V
HHt$HHt
?If90t
t"SS9] u
URPQQh
>:u8FV
VVVVVQRSSj
QQSVWh
PPPPPPPP
PPPPPPPP
tCHt(Ht
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
D$$PjeQ
L$ h\VH
T$p9T$\~
D$p9D$\
D$|Pjp
D$`PWQ
L$$PjnQ
L$$PjmQ
L$$PjkQ
L$$PjlQ
L$$PjnQ
T$pRQW
T$hRh0
KteKt)KuB
W\RPQV
<)t)<|u
<}t <-t
Xd_^[]
u h4SH
u h4SH
PVQSRj
Ht^HtTW
PjxPPh
SVWj*P3
tth\VH
A,Ht*Ht
upPPPj
8crtsu
=ERCPt
WRPQCSV
t%;wlsG
WRPQSV
WQRPSV
WRPQSV
WRPQSV
WQRPSV
}6;wls
WQRPSV
WRPQSV
WRPQSV
}9;wls
t%@F;E
WQRPSV
WPQRSV
}1;wls
WRPQSV
';wls,
WQRPSV
WQRPSV
WPQRSV
WPQRSV
WQRPSV
WQRPSV
WRPQSV
WQRPSV
WQRPSV
WQRPSV
}Q;wls+
WPQRSV
WRPQSV
WPQRSV
WRPQSV
WQRPSV
WRPQSV
WQRPSV
WRPQSV
WPQRSV
WPQRSV
WQRPSV
WQRPSV
WPQRSV
WPQRSV
WRPQSV
WPQRSV
WPQRSV
 !""""""##$%&'())))))**+,-./KKKKKKKK001234566678789:;<=;<=KKKKK>?@ABCDEFGH
8ERCPt!
S\RPQV
SVWPh0
+~<+^@
)CHjGj
T$<t<j
)D$0)D$4
u'SSWVh
Pj SWV
@PQj+S
BRPj,S
t=jch_0C
t29s u-P
<(t|<"tx<%tt<'tp<$tl<&th<!td<ot`<]t\<[tX<\tT<
tL<_tH<
f1<C@;
>ERCPt,
;D$$|};D$,
SVWPh0
L$(QRh0
T$(RWh+
tRJt6JuV
Ht:HtHt
Ht:HtHt
|M9tIV
t,9U(u$
V\RPQW
@FVh0
VPGWQR
VQGWRP
VRGWPQ
<=t4<>t<<
<)t^<:tW
9M(t`;
F@;N<~
M QRh0
j SWRQ
M 9E$u
E,Rh$MH
uEVWh$
PQRh`VH
FD9D$Dt
F4;D$0~
C9P<t>
D$ PQW
PVQRSh
RVPQSh
u2PPP8E
t#h,}H
\$$u#Sj
T$,RPj}
PVQRSh$WH
t$$t4Ht
L$,QVW
L$ +L$
T$$+T$
8|u&j|
T$ PQRVS
T$<Rj@Vj
L$<Qj@Vj
T$$9T$
D$$9D$
GtHt'Ht
t QWQV
8\ueFVS
L$,HPQ
T$(RSP
L$,RPQ
L$LQVS
F;t$$|
T$LRVS
T$0htQH
T$0h8PH
T$0hdPH
L$0hhPH
D$0hlPH
T$0hpPH
L$0htPH
D$0h\QH
T$ RPQ
L$$;B0u
L$09L$(
T$,RQP
D$0;D$(
D$0_^[
T$\RSP
D$@RPh
U 9M$u
j!j j
uM9p0uH
1E Rh0
M WRSPht
@SVWjX
RQPSWV
RQPSWV
PQRSWV
RQPSWV
QRPSWV
PQRSWV
RQPSWV
RPQSWV
T$,WRP
T$,PRV
L$,PVQ
D$49D$
t$h9t$l
t$lFVj
L$XQVS
L$HQPP
Ht2Hub
t$ ;\$$
L$Hh,aH
L$XQP3
T$ @RP
D$(+D$
\$,+\$$
D$4PQR
Ht4Ht*Ht
D$$PVh0
T$$RPh0
T$ QRj
D$0Ft5
L$$QRh0
T$ QRh
D$$PQh0
T$ RS@Phx
L$HQSP
t[8X@tV
va8] t
D$8PQhx
L$XQPhx
t`HtNHuf
bad allocation
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Unknown exception
(null)
`h````
xpxxxx
_nextafter
_hypot
UTF-16LE
UNICODE
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
1#QNAN
1#SNAN
This is a compiled AutoIt script. AV researchers please email avsupport@autoitscript.com for support.
uxtheme.dll
IsThemeActive
kernel32.dll
IsWow64Process
GetNativeSystemInfo
AU3_GetPluginDetails
AU3_FreeVar
ACCEPT
COMMIT
Arabic
Armenian
Avestan
Balinese
Bengali
Bopomofo
Braille
Buginese
Canadian_Aboriginal
Carian
Cherokee
Common
Coptic
Cuneiform
Cypriot
Cyrillic
Deseret
Devanagari
Egyptian_Hieroglyphs
Ethiopic
Georgian
Glagolitic
Gothic
Gujarati
Gurmukhi
Hangul
Hanunoo
Hebrew
Hiragana
Imperial_Aramaic
Inherited
Inscriptional_Pahlavi
Inscriptional_Parthian
Javanese
Kaithi
Kannada
Katakana
Kayah_Li
Kharoshthi
Lepcha
Linear_B
Lycian
Lydian
Malayalam
Meetei_Mayek
Mongolian
Myanmar
New_Tai_Lue
Ol_Chiki
Old_Italic
Old_Persian
Old_South_Arabian
Old_Turkic
Osmanya
Phags_Pa
Phoenician
Rejang
Samaritan
Saurashtra
Shavian
Sinhala
Sundanese
Syloti_Nagri
Syriac
Tagalog
Tagbanwa
Tai_Le
Tai_Tham
Tai_Viet
Telugu
Thaana
Tibetan
Tifinagh
Ugaritic
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
xdigit
no error
\ at end of pattern
\c at end of pattern
unrecognized character follows \
numbers out of order in {} quantifier
number too big in {} quantifier
missing terminating ] for character class
invalid escape sequence in character class
range out of order in character class
nothing to repeat
operand of unlimited repeat could match the empty string
internal error: unexpected repeat
unrecognized character after (? or (?-
POSIX named classes are supported only within a class
missing )
reference to non-existent subpattern
erroffset passed as NULL
unknown option bit(s) set
missing ) after comment
parentheses nested too deeply
regular expression is too large
failed to get memory
unmatched parentheses
internal error: code overflow
unrecognized character after (?<
lookbehind assertion is not fixed length
malformed number or name after (?(
conditional group contains more than two branches
assertion expected after (?(
(?R or (?[+-]digits must be followed by )
unknown POSIX class name
POSIX collating elements are not supported
this version of PCRE is not compiled with PCRE_UTF8 support
spare error
character value in \x{...} sequence is too large
invalid condition (?(0)
\C not allowed in lookbehind assertion
PCRE does not support \L, \l, \N{name}, \U, or \u
number after (?C is > 255
closing ) for (?C expected
recursive call could loop indefinitely
unrecognized character after (?P
syntax error in subpattern name (missing terminator)
two named subpatterns have the same name
invalid UTF-8 string
support for \P, \p, and \X has not been compiled
malformed \P or \p sequence
unknown property name after \P or \p
subpattern name is too long (maximum 32 characters)
too many named subpatterns (maximum 10000)
repeated subpattern is too long
octal value is greater than \377 (not in UTF-8 mode)
internal error: overran compiling workspace
internal error: previously-checked referenced subpattern not found
DEFINE group contains more than one branch
repeating a DEFINE group is not allowed
inconsistent NEWLINE options
\g is not followed by a braced, angle-bracketed, or quoted name/number or by a plain number
a numbered reference must not be zero
an argument is not allowed for (*ACCEPT), (*FAIL), or (*COMMIT)
(*VERB) not recognized
number is too big
subpattern name expected
digit expected after (?+
] is an invalid data character in JavaScript compatibility mode
different names for subpatterns of the same number are not allowed
(*MARK) must have an argument
this version of PCRE is not compiled with PCRE_UCP support
\c must be followed by an ASCII character
ICMP.DLL
IcmpCreateFile
IcmpCloseHandle
IcmpSendEcho
GetModuleHandleExW
GetSystemWow64DirectoryW
advapi32.dll
RegDeleteKeyExW
Error text not found (please report)
DEFINE
NO_START_OPT)
ANYCRLF)
BSR_ANYCRLF)
BSR_UNICODE)
WSOCK32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
timeGetTime
mciSendStringW
waveOutSetVolume
WINMM.dll
InitCommonControlsEx
ImageList_Create
ImageList_ReplaceIcon
ImageList_Destroy
ImageList_Remove
ImageList_SetDragCursorImage
ImageList_BeginDrag
ImageList_DragEnter
ImageList_DragLeave
ImageList_EndDrag
ImageList_DragMove
COMCTL32.dll
WNetUseConnectionW
WNetCancelConnection2W
WNetGetConnectionW
WNetAddConnection2W
MPR.dll
InternetCloseHandle
InternetOpenW
InternetSetOptionW
InternetCrackUrlW
HttpQueryInfoW
InternetQueryOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
InternetReadFile
InternetQueryDataAvailable
WININET.dll
EnumProcesses
EnumProcessModules
GetModuleBaseNameW
GetProcessMemoryInfo
PSAPI.DLL
LoadUserProfileW
CreateEnvironmentBlock
UnloadUserProfile
DestroyEnvironmentBlock
USERENV.dll
GetCurrentDirectoryW
IsDebuggerPresent
SetCurrentDirectoryW
GetFullPathNameW
GetModuleFileNameW
FreeLibrary
LoadLibraryA
GetProcAddress
GetCurrentProcess
CloseHandle
GetLastError
DuplicateHandle
CreateThread
WaitForSingleObject
HeapFree
GetProcessHeap
HeapAlloc
GetCurrentThreadId
RaiseException
MulDiv
GetVersionExW
GetSystemInfo
InterlockedIncrement
InterlockedDecrement
WideCharToMultiByte
lstrcpyW
MultiByteToWideChar
lstrlenW
lstrcmpiW
GetModuleHandleW
QueryPerformanceCounter
VirtualFreeEx
OpenProcess
VirtualAllocEx
WriteProcessMemory
ReadProcessMemory
CreateFileW
SetFilePointerEx
ReadFile
WriteFile
FlushFileBuffers
TerminateProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
SetFileTime
GetFileAttributesW
FindFirstFileW
FindClose
DeleteFileW
FindNextFileW
MoveFileW
CopyFileW
CreateDirectoryW
RemoveDirectoryW
SetSystemPowerState
QueryPerformanceFrequency
FindResourceW
LoadResource
LockResource
SizeofResource
EnumResourceNamesW
OutputDebugStringW
GetLocalTime
CompareStringW
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
GetStdHandle
CreatePipe
InterlockedExchange
TerminateThread
GetTempPathW
GetTempFileNameW
VirtualFree
FormatMessageW
GetExitCodeProcess
SetErrorMode
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileSectionW
WritePrivateProfileSectionW
GetPrivateProfileSectionNamesW
FileTimeToLocalFileTime
FileTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
GetDriveTypeW
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetVolumeInformationW
SetVolumeLabelW
CreateHardLinkW
DeviceIoControl
SetFileAttributesW
GetShortPathNameW
CreateEventW
SetEvent
GetEnvironmentVariableW
SetEnvironmentVariableW
GlobalLock
GlobalUnlock
GlobalAlloc
GetFileSize
GlobalFree
GlobalMemoryStatusEx
GetSystemDirectoryW
GetComputerNameW
GetWindowsDirectoryW
GetCurrentProcessId
GetCurrentThread
GetProcessIoCounters
CreateProcessW
SetPriorityClass
LoadLibraryW
VirtualAlloc
LoadLibraryExW
KERNEL32.dll
DestroyIcon
MessageBoxA
GetForegroundWindow
GetSysColorBrush
LoadCursorW
LoadIconW
RegisterClassExW
CreateWindowExW
ShowWindow
SetTimer
RegisterWindowMessageW
CreatePopupMenu
KillTimer
PostQuitMessage
SetFocus
MoveWindow
DefWindowProcW
MessageBoxW
OpenWindowStationW
GetProcessWindowStation
SetProcessWindowStation
OpenDesktopW
CloseWindowStation
CloseDesktop
GetUserObjectSecurity
SetUserObjectSecurity
GetWindowRect
PostMessageW
MapVirtualKeyW
SendMessageW
GetDlgCtrlID
GetParent
GetClassNameW
CharUpperBuffW
EnumChildWindows
SendMessageTimeoutW
ScreenToClient
GetWindowTextW
GetFocus
AttachThreadInput
GetWindowThreadProcessId
GetWindowLongW
InvalidateRect
EnableWindow
IsWindowVisible
IsWindowEnabled
IsWindow
GetDesktopWindow
EnumWindows
DestroyWindow
GetMenu
GetClientRect
BeginPaint
EndPaint
ReleaseDC
CopyRect
SetWindowTextW
GetDlgItem
SendDlgItemMessageW
EndDialog
MessageBeep
DialogBoxParamW
LoadStringW
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
SendInput
keybd_event
SystemParametersInfoW
FindWindowW
IsIconic
SetForegroundWindow
GetMenuItemInfoW
SetMenuItemInfoW
GetMenuItemCount
GetMenuItemID
CheckMenuRadioItem
DeleteMenu
GetCursorPos
TrackPopupMenuEx
IsMenu
InsertMenuItemW
SetMenuDefaultItem
EnumThreadWindows
FindWindowExW
SetActiveWindow
ExitWindowsEx
mouse_event
CreateIconFromResourceEx
LoadImageW
MonitorFromRect
CharLowerBuffW
UnregisterHotKey
PeekMessageW
TranslateMessage
DispatchMessageW
LockWindowUpdate
GetMessageW
BlockInput
OpenClipboard
IsClipboardFormatAvailable
GetClipboardData
CloseClipboard
CountClipboardFormats
EmptyClipboard
SetClipboardData
SetRect
AdjustWindowRectEx
CopyImage
SetWindowPos
GetCursorInfo
RegisterHotKey
ClientToScreen
GetKeyboardLayoutNameW
IsCharAlphaW
IsCharAlphaNumericW
IsCharLowerW
IsCharUpperW
GetMenuStringW
GetSubMenu
GetCaretPos
IsZoomed
MonitorFromPoint
GetMonitorInfoW
SetWindowLongW
SetLayeredWindowAttributes
FlashWindow
GetClassLongW
TranslateAcceleratorW
IsDialogMessageW
GetSysColor
InflateRect
DrawFocusRect
DrawTextW
FrameRect
DrawFrameControl
FillRect
PtInRect
DestroyAcceleratorTable
CreateAcceleratorTableW
SetCursor
GetWindowDC
GetSystemMetrics
GetActiveWindow
CharNextW
wsprintfW
RedrawWindow
DrawMenuBar
DestroyMenu
SetMenu
GetWindowTextLengthW
CreateMenu
IsDlgButtonChecked
DefDlgProcW
ReleaseCapture
SetCapture
WindowFromPoint
USER32.dll
GetDeviceCaps
DeleteObject
GetTextExtentPoint32W
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
StretchBlt
GetDIBits
DeleteDC
GetPixel
CreateDCW
GetStockObject
GetTextFaceW
CreateFontW
SetTextColor
CreateSolidBrush
CreatePen
SetBkColor
RoundRect
SetBkMode
GetObjectW
SetViewportOrgEx
Rectangle
BeginPath
PolyDraw
Ellipse
MoveToEx
AngleArc
LineTo
CloseFigure
SetPixel
EndPath
StrokePath
StrokeAndFillPath
ExtCreatePen
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
COMDLG32.dll
OpenThreadToken
OpenProcessToken
LookupPrivilegeValueW
DuplicateTokenEx
CreateProcessAsUserW
CreateProcessWithLogonW
InitializeSecurityDescriptor
InitializeAcl
GetLengthSid
CopySid
LogonUserW
GetTokenInformation
GetSecurityDescriptorDacl
GetAclInformation
GetAce
AddAce
SetSecurityDescriptorDacl
RegOpenKeyExW
RegQueryValueExW
RegCloseKey
AdjustTokenPrivileges
InitiateSystemShutdownExW
OpenSCManagerW
LockServiceDatabase
UnlockServiceDatabase
CloseServiceHandle
RegConnectRegistryW
GetUserNameW
RegCreateKeyExW
RegSetValueExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumValueW
ADVAPI32.dll
ShellExecuteW
Shell_NotifyIconW
ExtractIconExW
SHGetMalloc
SHGetDesktopFolder
SHGetPathFromIDListW
SHFileOperationW
SHBrowseForFolderW
SHEmptyRecycleBinW
DragQueryFileW
SHGetFolderPathW
ShellExecuteExW
DragQueryPoint
DragFinish
SHELL32.dll
OleSetMenuDescriptor
MkParseDisplayName
OleSetContainedObject
CLSIDFromString
StringFromGUID2
CoInitialize
CoUninitialize
CoCreateInstance
CreateStreamOnHGlobal
CoTaskMemAlloc
CoTaskMemFree
ProgIDFromCLSID
OleInitialize
CreateBindCtx
CLSIDFromProgID
CoInitializeSecurity
CoCreateInstanceEx
CoSetProxyBlanket
OleUninitialize
IIDFromString
ole32.dll
OLEAUT32.dll
ExitProcess
ExitThread
GetSystemTimeAsFileTime
ResumeThread
GetTimeFormatW
GetDateFormatW
GetCommandLineW
GetStartupInfoW
IsProcessorFeaturePresent
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStringTypeW
HeapCreate
SetHandleCount
GetFileType
SetStdHandle
GetConsoleCP
GetConsoleMode
LCMapStringW
RtlUnwind
SetFilePointer
GetTimeZoneInformation
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetTickCount
HeapReAlloc
WriteConsoleW
SetEndOfFile
SetEnvironmentVariableA
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
Qkkbal
$Id: qmath.h,v 1.1 2004/01/15 19:50:35 jonbennett Exp $
pqrstuvwxyz{$--%"!'
`abcdefghijkmno]
-;IDATx
&a+)QF
Yrdb8K!
.A>Km#
MG:pID`
h5;Z?=8h
`h-;c9
[}-MO>
|l!J?a
.8@W4[
.IsCp]
|1A[.4
~w-;6=
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>
H}AU3!EA06_
o 6x1
nSGII:
QYl9My\cj<
)9Wu=R
]J@f9vde
ov?RX9
6=w?{6I
GQD''Z|`
o{DAzz
`Z[5mf
S7Rs$su
Ml{_\%
hv*%xm
VJB$w@
6&Q.'P8H
^j6PCc
#dmBOh
'(`KV3
v^ae0e
TU;BG[
vC7Mtam4F
?[I(F.
1I<2A(0q
aSb}.
\}<t|( =1
;(SJ.d
$-o$sP
12X h<[l
|7[VZw;8
8 =GT3
#6PE1c
6v_.\Y
Pb-N76
<>3y'\Hc_
2LCo5@qnN
*&8m\&#z
S%k]>Bv
Z&jx*o
+rd<eP
iAJ.0^R[
dSCbRE
>>yEK/|
,[0jb-r
7Q4*Cj
JwQoHv-`s
o^[YD|FI
o1>Em)r3^
^,XLfG
'~{(2
z3/+Af9
Cz1Fih
4qyNoNx
sNj2Qn@
O9#|H.
umR,ox
yV7=8~,
:>Un|
LC?ph
D<thiS
}MW-/
E@,ugX
bzwIF0`
@R":\'-
d:WY#=
$XVaW=
qd%1;h
@`UY!^Z^
U&|#{d
o_=oF W
;"CFg55
Gh5T/W]
MsdhfY
qt)$m!,b
rZ~_C<*
vQ$^#h
ZxHU:
K*}&uW
g$@i4<
\z2:CB
9?bNWTTBD
XT?Hh'
l#@7\*
Joi^%q
00mr[=
Fi2+5z
_?h_06
;"XMyK
nv|(d*
^+_'.g
1'}mRy2v
;:jk+e
Ig<}\}
7}2&7f
)5TjG&@K
P1h>3v
7]17&:Iy
gB6D^)
"j<%`Wx{Z
rS*ZH
@Wl4uiQ
>QXTk
RoL%'Fc
(m=ps
@ZJ8z.\.
)LF-S$
Lt.Fp9
m3iHcK
43*F]ox
3*#*R2
<{nHK
KzSTOk6
anEiSk#
^$p]|P
;CyQCsY
>}P"-!
usu1K8
mDGfXG
ozr66g@
/P |=}
~3;5b)
l7j%T!
`YMQEd&
PY#hdy
\TJ=Bf
K6lp9{s~
#\~\|]
*|K*\-_
FX3F3
2R$i-v
$/s|A9
f8o{vLc
97fd;T
c?Y1rX
eV3/Ra
"C4HT1
GhHJSa
J;h=E/P
S?&`4Qs
v53S[k
Ue_LBUA
0os31q
Oy4i20
@V,PX-
yksiE{
n|4 #j
+~.LA"Q
+2&QL,
>u0D<U
Jdi!F%
vTMJMT3x
r~bHlE
[Cm"'^
@ayw2?^
\p@z#O
ee9sZm}
:Lap$
8Zk??:!
_\A^pM
k+Q$Vr
:M?rkq%
{2nXz4V
iS|n*;]Z
_=}ms[
E^lqbxQ
P^z11?@
A/];CXHX
e~^aQm
[?x6>@eR
zMQ\M;
TMmkYs?
ru\;(_
b1sNfn
6EKVv+
b8hLMsd
LVk>16
`b]K\i
e'c)$b
$($e]{
>c|e`8
^z<FDkN
34_'D`
wdO?n`
[3j3">'
^0N$yo
Tc$fX;
'2`Yf_
{|.=7:
'jpRwp
No0~.#
-VN&~F
Sy?2bfql
dv%n`Z`
$Q1B=g
:Ei0bl
Qm1BY|@ Q
/xu'Ssa%p
F.55^#"v
@ERl^h
I4]4hM
ILx+0E
FN,L#
?c2'KR
}-|&ye
I5"^R:
b.:1|\
9+>J12
xH+B=?
=U)3HM&
D+ae
D16'IM
-&#.)kS
Bq|07Z
BQr9378
Z/#$Cl
~B+Vnf
Pm+4B(wy
.U?u.3
a"U^L1E
:vQT:=
x'&^Y]
SIR]@z
:DEXI6c
Ny*L={
%(Oc.d_>
o|NYL1
h0?XtD
I\XP>n9h
M=AU3!EA06
mscoree.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
HMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
UTF-16LE
UNICODE
((((( H
h(((( H
H
WUSER32.DLL
HCONOUT$
RETCODE
SCRIPTLINE
LASTDLLERROR
HELPCONTEXT
HELPFILE
SOURCE
DESCRIPTION
WINDESCRIPTION
NUMBER
AutoIt v3
>>>AUTOIT NO CMDEXECUTE<<<
CMDLINERAW
CMDLINE
/ErrorStdOut
/AutoIt3OutputDebug
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
TaskbarCreated
AutoIt
Error allocating memory.
DSeAssignPrimaryTokenPrivilege
SeIncreaseQuotaPrivilege
winsta0
default
winsta0\default
ComboBox
ListBox
SHELLDLL_DefView
largeicons
details
smallicons
WM_GETCONTROLNAME
CLASSNN
REGEXPCLASS
INSTANCE
ACTIVE
[ACTIVE
HANDLE=
[HANDLE:
REGEXP=
[REGEXPTITLE:
CLASSNAME=
[CLASS:
HANDLE
REGEXPTITLE
ThumbnailClass
AutoIt3GUI
Container
oclsid
struct
object
idispatch
wparam
dword_ptr
ulong_ptr
uint_ptr
lparam
lresult
long_ptr
int_ptr
handle
hresult
double
uint64
variant
ushort
boolean
InterfaceDispatch
QueryInterface
AddRef
Release
rInclude
Software\AutoIt v3\AutoIt
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
Error:
^ ERROR
Error:
%s (%d) : ==> %s:
#include
Run Script:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
#include depth exceeded. Make sure there are no recursive includes
Error opening the file
Unterminated string
#notrayicon
#requireadmin
#NoAutoIt3Execute
#OnAutoItStartRegister
#include-once
Cannot parse #include
#comments-start
Unterminated group of comments
#comments-end
>>>AUTOIT SCRIPT<<<
RWINUP
RWINDOWN
LWINUP
LWINDOWN
SHIFTUP
SHIFTDOWN
ALTDOWN
CTRLUP
CTRLDOWN
MOUSE_XBUTTON2
MOUSE_XBUTTON1
MOUSE_MBUTTON
MOUSE_RBUTTON
MOUSE_LBUTTON
LAUNCH_APP2
LAUNCH_APP1
LAUNCH_MEDIA
LAUNCH_MAIL
MEDIA_PLAY_PAUSE
MEDIA_STOP
MEDIA_PREV
MEDIA_NEXT
VOLUME_UP
VOLUME_DOWN
VOLUME_MUTE
BROWSER_HOME
BROWSER_FAVORTIES
BROWSER_SEARCH
BROWSER_STOP
BROWSER_REFRESH
BROWSER_FORWARD
BROWSER_BACK
NUMPADENTER
RSHIFT
LSHIFT
APPSKEY
NUMPADDIV
NUMPADDOT
NUMPADSUB
NUMPADADD
NUMPADMULT
NUMPAD9
NUMPAD8
NUMPAD7
NUMPAD6
NUMPAD5
NUMPAD4
NUMPAD3
NUMPAD2
NUMPAD1
NUMPAD0
CAPSLOCK
NUMLOCK
SCROLLLOCK
PRINTSCREEN
INSERT
ESCAPE
DELETE
BACKSPACE
Shell_TrayWnd
Script Paused
question
warning
Line:
:;<=>?@
[\]^_`
BUTTON
#32770
StringFileInfo\
\VarFileInfo\Translation
04090000
DefaultLangCodepage
%u.%u.%u.%u
0.0.0.0
alias PlayMe
status PlayMe mode
close PlayMe
play PlayMe wait
play PlayMe
SeShutdownPrivilege
SwapMouseButtons
Control Panel\Mouse
MIDDLE
PRIMARY
SECONDARY
0123456789ABCDEF
DEFAULT
ENDWITH
RETURN
ENDFUNC
STATIC
GLOBAL
CONTINUECASE
ENDSWITCH
SWITCH
ENDSELECT
SELECT
CONTINUELOOP
EXITLOOP
ELSEIF
D%.15g
%4d%02d%02d%02d%02d%02d
close all
%s (%d) : ==> %s:
%s (%d) : ==> %s:
^ ERROR
@EXITCODE
@EXITMETHOD
@GUI_CTRLID
@GUI_WINHANDLE
@GUI_CTRLHANDLE
@TRAY_ID
@COM_EVENTOBJ
WINWAITNOTACTIVE
WINWAITCLOSE
WINWAITACTIVE
WINWAIT
WINSETTRANS
WINSETTITLE
WINSETSTATE
WINSETONTOP
WINMOVE
WINMINIMIZEALLUNDO
WINMINIMIZEALL
WINMENUSELECTITEM
WINLIST
WINKILL
WINGETTITLE
WINGETTEXT
WINGETSTATE
WINGETPROCESS
WINGETPOS
WINGETHANDLE
WINGETCLIENTSIZE
WINGETCLASSLIST
WINGETCARETPOS
WINFLASH
WINEXISTS
WINCLOSE
WINACTIVE
WINACTIVATE
VARGETTYPE
UDPSTARTUP
UDPSHUTDOWN
UDPSEND
UDPRECV
UDPOPEN
UDPCLOSESOCKET
UDPBIND
UBOUND
TRAYTIP
TRAYSETTOOLTIP
TRAYSETSTATE
TRAYSETPAUSEICON
TRAYSETONEVENT
TRAYSETICON
TRAYSETCLICK
TRAYITEMSETTEXT
TRAYITEMSETSTATE
TRAYITEMSETONEVENT
TRAYITEMGETTEXT
TRAYITEMGETSTATE
TRAYITEMGETHANDLE
TRAYITEMDELETE
TRAYGETMSG
TRAYCREATEMENU
TRAYCREATEITEM
TOOLTIP
TIMERINIT
TIMERDIFF
TCPSTARTUP
TCPSHUTDOWN
TCPSEND
TCPRECV
TCPNAMETOIP
TCPLISTEN
TCPCONNECT
TCPCLOSESOCKET
TCPACCEPT
STRINGUPPER
STRINGTRIMRIGHT
STRINGTRIMLEFT
STRINGTOBINARY
STRINGTOASCIIARRAY
STRINGSTRIPWS
STRINGSTRIPCR
STRINGSPLIT
STRINGRIGHT
STRINGREPLACE
STRINGREGEXPREPLACE
STRINGREGEXP
STRINGMID
STRINGLOWER
STRINGLEN
STRINGLEFT
STRINGISXDIGIT
STRINGISUPPER
STRINGISSPACE
STRINGISLOWER
STRINGISINT
STRINGISFLOAT
STRINGISDIGIT
STRINGISASCII
STRINGISALPHA
STRINGISALNUM
STRINGINSTR
STRINGFROMASCIIARRAY
STRINGFORMAT
STRINGCOMPARE
STRINGADDCR
STRING
STDOUTREAD
STDIOCLOSE
STDINWRITE
STDERRREAD
STATUSBARGETTEXT
SRANDOM
SPLASHTEXTON
SPLASHOFF
SPLASHIMAGEON
SOUNDSETWAVEVOLUME
SOUNDPLAY
SHUTDOWN
SHELLEXECUTEWAIT
SHELLEXECUTE
SETEXTENDED
SETERROR
SENDKEEPACTIVE
RUNWAIT
RUNASWAIT
REGWRITE
REGREAD
REGENUMVAL
REGENUMKEY
REGDELETE
RANDOM
PROGRESSSET
PROGRESSON
PROGRESSOFF
PROCESSWAITCLOSE
PROCESSWAIT
PROCESSSETPRIORITY
PROCESSLIST
PROCESSGETSTATS
PROCESSEXISTS
PROCESSCLOSE
PLUGINOPEN
PLUGINCLOSE
PIXELSEARCH
PIXELGETCOLOR
PIXELCHECKSUM
ONAUTOITEXITUNREGISTER
ONAUTOITEXITREGISTER
OBJNAME
OBJGET
OBJEVENT
OBJCREATEINTERFACE
OBJCREATE
MSGBOX
MOUSEWHEEL
MOUSEUP
MOUSEMOVE
MOUSEGETPOS
MOUSEGETCURSOR
MOUSEDOWN
MOUSECLICKDRAG
MOUSECLICK
MEMGETSTATS
ISSTRING
ISNUMBER
ISKEYWORD
ISHWND
ISFLOAT
ISDLLSTRUCT
ISDECLARED
ISBOOL
ISBINARY
ISARRAY
ISADMIN
INPUTBOX
INIWRITESECTION
INIWRITE
INIRENAMESECTION
INIREADSECTIONNAMES
INIREADSECTION
INIREAD
INIDELETE
INETREAD
INETGETSIZE
INETGETINFO
INETGET
INETCLOSE
HTTPSETUSERAGENT
HTTPSETPROXY
HOTKEYSET
GUISWITCH
GUISTARTGROUP
GUISETSTYLE
GUISETSTATE
GUISETONEVENT
GUISETICON
GUISETHELP
GUISETFONT
GUISETCURSOR
GUISETCOORD
GUISETBKCOLOR
GUISETACCELERATORS
GUIREGISTERMSG
GUIGETSTYLE
GUIGETMSG
GUIGETCURSORINFO
GUIDELETE
GUICTRLSETTIP
GUICTRLSETSTYLE
GUICTRLSETSTATE
GUICTRLSETRESIZING
GUICTRLSETPOS
GUICTRLSETONEVENT
GUICTRLSETLIMIT
GUICTRLSETIMAGE
GUICTRLSETGRAPHIC
GUICTRLSETFONT
GUICTRLSETDEFCOLOR
GUICTRLSETDEFBKCOLOR
GUICTRLSETDATA
GUICTRLSETCURSOR
GUICTRLSETCOLOR
GUICTRLSETBKCOLOR
GUICTRLSENDTODUMMY
GUICTRLSENDMSG
GUICTRLREGISTERLISTVIEWSORT
GUICTRLRECVMSG
GUICTRLREAD
GUICTRLGETSTATE
GUICTRLGETHANDLE
GUICTRLDELETE
GUICTRLCREATEUPDOWN
GUICTRLCREATETREEVIEWITEM
GUICTRLCREATETREEVIEW
GUICTRLCREATETABITEM
GUICTRLCREATETAB
GUICTRLCREATESLIDER
GUICTRLCREATERADIO
GUICTRLCREATEPROGRESS
GUICTRLCREATEPIC
GUICTRLCREATEOBJ
GUICTRLCREATEMONTHCAL
GUICTRLCREATEMENUITEM
GUICTRLCREATEMENU
GUICTRLCREATELISTVIEWITEM
GUICTRLCREATELISTVIEW
GUICTRLCREATELIST
GUICTRLCREATELABEL
GUICTRLCREATEINPUT
GUICTRLCREATEICON
GUICTRLCREATEGROUP
GUICTRLCREATEGRAPHIC
GUICTRLCREATEEDIT
GUICTRLCREATEDUMMY
GUICTRLCREATEDATE
GUICTRLCREATECONTEXTMENU
GUICTRLCREATECOMBO
GUICTRLCREATECHECKBOX
GUICTRLCREATEBUTTON
GUICTRLCREATEAVI
GUICREATE
FTPSETPROXY
FILEWRITELINE
FILEWRITE
FILESETTIME
FILESETPOS
FILESETATTRIB
FILESELECTFOLDER
FILESAVEDIALOG
FILERECYCLEEMPTY
FILERECYCLE
FILEREADLINE
FILEREAD
FILEOPENDIALOG
FILEOPEN
FILEMOVE
FILEINSTALL
FILEGETVERSION
FILEGETTIME
FILEGETSIZE
FILEGETSHORTNAME
FILEGETSHORTCUT
FILEGETPOS
FILEGETLONGNAME
FILEGETENCODING
FILEGETATTRIB
FILEFLUSH
FILEFINDNEXTFILE
FILEFINDFIRSTFILE
FILEEXISTS
FILEDELETE
FILECREATESHORTCUT
FILECREATENTFSLINK
FILECOPY
FILECLOSE
FILECHANGEDIR
EXECUTE
ENVUPDATE
ENVSET
ENVGET
DUMMYSPEEDTEST
DRIVESTATUS
DRIVESPACETOTAL
DRIVESPACEFREE
DRIVESETLABEL
DRIVEMAPGET
DRIVEMAPDEL
DRIVEMAPADD
DRIVEGETTYPE
DRIVEGETSERIAL
DRIVEGETLABEL
DRIVEGETFILESYSTEM
DRIVEGETDRIVE
DLLSTRUCTSETDATA
DLLSTRUCTGETSIZE
DLLSTRUCTGETPTR
DLLSTRUCTGETDATA
DLLSTRUCTCREATE
DLLOPEN
DLLCLOSE
DLLCALLBACKREGISTER
DLLCALLBACKGETPTR
DLLCALLBACKFREE
DLLCALLADDRESS
DLLCALL
DIRREMOVE
DIRMOVE
DIRGETSIZE
DIRCREATE
DIRCOPY
CONTROLTREEVIEW
CONTROLSHOW
CONTROLSETTEXT
CONTROLSEND
CONTROLMOVE
CONTROLLISTVIEW
CONTROLHIDE
CONTROLGETTEXT
CONTROLGETPOS
CONTROLGETHANDLE
CONTROLGETFOCUS
CONTROLFOCUS
CONTROLENABLE
CONTROLDISABLE
CONTROLCOMMAND
CONTROLCLICK
CONSOLEWRITEERROR
CONSOLEWRITE
CONSOLEREAD
CLIPPUT
CLIPGET
CEILING
CDTRAY
BLOCKINPUT
BITXOR
BITSHIFT
BITROTATE
BITNOT
BITAND
BINARYTOSTRING
BINARYMID
BINARYLEN
BINARY
AUTOITWINSETTITLE
AUTOITWINGETTITLE
AUTOITSETOPTION
ASSIGN
ADLIBUNREGISTER
ADLIBREGISTER
removable
network
ramdisk
unknown
closed
type cdaudio alias cd wait
set cd door
close cd wait
Removable
Network
RAMDisk
Unknown
INVALID
NOTREADY
READONLY
UNKNOWN
\??\%s
GUI_RUNDEFMSG
<local>
Environment
static
DISPLAY
msctls_progress32
CaretCoordMode
d1r0,2
ExpandEnvStrings
ExpandVarStrings
GUICloseOnESC
GUICoordMode
GUIDataSeparatorChar
GUIEventOptions
d0r0,3
GUIOnEventMode
GUIResizeMode
d0r0,1023
MouseClickDelay
MouseClickDownDelay
MouseClickDragDelay
d250m0
MouseCoordMode
MustDeclareVars
PixelCoordMode
SendAttachMode
SendCapsLockMode
SendKeyDelay
SendKeyDownDelay
SetExitCode
TCPTimeout
d100m0
TrayAutoPause
TrayIconDebug
TrayIconHide
TrayMenuMode
TrayOnEventMode
WinDetectHiddenText
WinSearchChildren
WinTextMatchMode
d1r1,2
WinTitleMatchMode
WinWaitDelay
CALLARGARRAY
AUTOITCALLVARIABLE%d
255.255.255.255
Double
String
DLLStruct
Reference
Object
Keyword
Binary
SOFTWARE\Classes\
\CLSID
NULL Pointer assignment
AutoIt.Error
Incorrect Parameter format
Can't install a new Errorhandler when one is still active.
Failed to create the Error Handler
First parameter must be of type 'Object'.
Failed to create the Event Object.
_NewEnum
get__NewEnum
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
Not an Object type
Failed to create object
Invalid parameter
Variable must be of type 'Object'.
Invalid characters behind Object assignment !
Variable is not of type 'Object'.
DMUILANG
UNICODE
AUTOITX64
AUTOITUNICODE
AUTOITPID
HOTKEYPRESSED
NUMPARAMS
INETGETACTIVE
INETGETBYTESREAD
LOGONDNSDOMAIN
LOGONDOMAIN
LOGONSERVER
HOMESHARE
HOMEPATH
HOMEDRIVE
USERPROFILEDIR
TEMPDIR
USERNAME
COMSPEC
COMPILED
DESKTOPREFRESH
DESKTOPDEPTH
DESKTOPHEIGHT
DESKTOPWIDTH
IPADDRESS4
IPADDRESS3
IPADDRESS2
IPADDRESS1
AUTOITEXE
AUTOITVERSION
KBLAYOUT
CPUARCH
OSARCH
PROCESSORARCH
OSLANG
OSSERVICEPACK
OSBUILD
OSVERSION
OSTYPE
WORKINGDIR
SCRIPTLINENUMBER
SCRIPTDIR
SCRIPTNAME
SCRIPTFULLPATH
TRAYICONFLASHING
TRAYICONVISIBLE
SW_UNLOCK
SW_LOCK
SW_SHOWNORMAL
SW_SHOWNOACTIVATE
SW_SHOWNA
SW_SHOWMINNOACTIVE
SW_SHOWMINIMIZED
SW_SHOWMAXIMIZED
SW_DISABLE
SW_ENABLE
SW_SHOWDEFAULT
SW_SHOW
SW_RESTORE
SW_MAXIMIZE
SW_MINIMIZE
SW_HIDE
SYSTEMDIR
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic Clean
MicroWorld-eScan Generic.Ransom.Locked.767B115C
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!688CBA9C88F9
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.Win32.Autoit.lzM7
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Generic.Ransom.Locked.767B115C
K7GW Clean
Cybereason malicious.c88f92
Baidu Clean
Cyren Clean
Symantec Ransom.Cryptolocker
ESET-NOD32 a variant of Win32/Filecoder.Crypt888.B
APEX Malicious
Paloalto generic.ml
ClamAV Win.Malware.Autoit-6992337-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Ransom:Win32/Pocrimcrypt.cfc916b8
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Ransom.Crypt888/Autoit!1.C27B (CLASSIC)
Ad-Aware Generic.Ransom.Locked.767B115C
Sophos Clean
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1110296
DrWeb Trojan.Encoder.24597
Zillya Clean
TrendMicro Ransom.AutoIt.CRYPTEIGHT.SMTH
McAfee-GW-Edition BehavesLike.Win32.Dropper.bh
FireEye Generic.mg.688cba9c88f928b0
Emsisoft Generic.Ransom.Locked.767B115C (B)
SentinelOne Clean
GData Generic.Ransom.Locked.767B115C (2x)
Jiangmin Trojan.Banker.Agent.cal
Webroot Clean
Avira HEUR/AGEN.1110296
eGambit Unsafe.AI_Score_62%
MAX malware (ai score=88)
Antiy-AVL Trojan/Generic.ASCommon.1A0
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Generic.Ransom.Locked.767B115C
ViRobot Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/Pocrimcrypt.A
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Generic.Ransom.Locked.767B115C
TACHYON Clean
Malwarebytes Malware.AI.3512376734
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Ransom.AutoIt.CRYPTEIGHT.SMTH
Tencent Win32.Trojan.Filecoder.Wpts
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Autoit.AZA
Fortinet W32/Filecoder.DYB!tr
BitDefenderTheta AI:Packer.E19D7A3317
AVG AutoIt:Ransom-L [Trj]
Avast AutoIt:Ransom-L [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.