Static | ZeroBOX

PE Compile Time

2020-06-07 16:33:06

PDB Path

c:\Projects\VS2005\ChromePass\Command-Line\ChromePass.pdb

PE Imphash

aff246af2667d7ec446697339be86337

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002ea9e 0x0002ec00 6.63368225954
.rdata 0x00030000 0x00007770 0x00007800 5.80688007849
.data 0x00038000 0x00004dbc 0x00000e00 3.18009670133
.rsrc 0x0003d000 0x000037ac 0x00003800 4.56657023212

Resources

Name Offset Size Language Sub-language File type
BIN 0x0003d5e8 0x00000318 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x0003d900 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0003def4 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0003def4 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x0003def4 0x000000d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x0003e874 0x00000128 LANG_HEBREW SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0003e874 0x00000128 LANG_HEBREW SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_MENU 0x0003ed14 0x000001c4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0003ed14 0x000001c4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0003fa7c 0x00000336 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0003fa7c 0x00000336 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0003fa7c 0x00000336 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0003fa7c 0x00000336 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0003fa7c 0x00000336 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00040270 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00040270 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00040270 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00040270 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00040270 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000402d8 0x00000050 LANG_HEBREW SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00040328 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00040350 0x00000014 LANG_HEBREW SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00040350 0x00000014 LANG_HEBREW SUBLANG_DEFAULT data
RT_VERSION 0x00040364 0x000002dc LANG_HEBREW SUBLANG_DEFAULT data
RT_MANIFEST 0x00040640 0x0000016a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x4302ec _purecall
0x4302f0 atoi
0x4302f4 toupper
0x4302f8 realloc
0x4302fc isalnum
0x430300 _gmtime64
0x430304 isxdigit
0x430308 tolower
0x43030c isspace
0x430310 isdigit
0x430314 strftime
0x430318 __dllonexit
0x43031c _onexit
0x430320 _c_exit
0x430324 _exit
0x430328 _XcptFilter
0x43032c _cexit
0x430330 _wcslwr
0x430334 _wcmdln
0x430338 __wgetmainargs
0x43033c free
0x430340 modf
0x430344 _wtoi
0x430348 wcstoul
0x43034c _itow
0x430350 strcmp
0x430354 memcmp
0x430358 memmove
0x43035c _memicmp
0x430360 ??2@YAPAXI@Z
0x430364 ??3@YAXPAX@Z
0x430368 memcpy
0x43036c wcscpy
0x430370 wcsrchr
0x430374 malloc
0x430378 exit
0x43037c log
0x430380 abs
0x430384 _wcsicmp
0x430388 wcscmp
0x43038c wcschr
0x430390 wcslen
0x430394 strlen
0x430398 memset
0x43039c wcsncat
0x4303a0 _snwprintf
0x4303a4 wcscat
0x4303a8 _initterm
0x4303ac __setusermatherr
0x4303b0 _adjust_fdiv
0x4303b4 __p__commode
0x4303b8 __p__fmode
0x4303bc __set_app_type
0x4303c0 _controlfp
0x4303c4 _except_handler3
Library COMCTL32.dll:
0x430010 CreateToolbarEx
0x430014 ImageList_AddMasked
0x43001c ImageList_Create
0x430020 None
0x430028 CreateStatusWindowW
Library KERNEL32.dll:
0x430058 AreFileApisANSI
0x430060 GetSystemTime
0x430064 GetTempPathA
0x43006c SetEndOfFile
0x430070 GetFileAttributesA
0x430078 UnlockFile
0x43007c CreateFileA
0x430084 Sleep
0x430088 GetFullPathNameA
0x43008c GetFullPathNameW
0x43009c LockFileEx
0x4300a0 GetTickCount
0x4300a4 LocalAlloc
0x4300a8 EnumResourceTypesW
0x4300ac OpenProcess
0x4300b0 DeleteFileW
0x4300b4 LockFile
0x4300b8 CopyFileW
0x4300bc GetModuleHandleA
0x4300c0 GetStartupInfoW
0x4300c4 GetCurrentThreadId
0x4300c8 DeleteFileA
0x4300cc FlushFileBuffers
0x4300d0 CompareFileTime
0x4300d4 WriteFile
0x4300dc WideCharToMultiByte
0x4300e4 GetModuleHandleW
0x4300e8 LoadLibraryW
0x4300f0 GetProcAddress
0x4300f4 FindClose
0x4300f8 FindNextFileW
0x4300fc CloseHandle
0x430100 GetFileSize
0x430104 FindFirstFileW
0x430108 MultiByteToWideChar
0x43010c GetLastError
0x43011c EnumResourceNamesW
0x430120 FreeLibrary
0x430124 SetFilePointer
0x430128 CreateFileW
0x43012c GlobalAlloc
0x430130 GlobalUnlock
0x430134 FindResourceW
0x430138 GetSystemDirectoryW
0x43013c GetTempPathW
0x430140 LoadResource
0x430144 LoadLibraryExW
0x430148 SizeofResource
0x43014c FormatMessageW
0x430150 GlobalLock
0x430154 GetVersionExW
0x43015c GetTimeFormatW
0x430160 GetDateFormatW
0x430164 GetFileAttributesW
0x430168 LocalFree
0x43016c GetTempFileNameW
0x430170 ReadFile
0x430174 LockResource
0x430178 GetModuleFileNameW
0x43017c GetCurrentProcess
0x430180 ReadProcessMemory
0x430184 GetCurrentProcessId
0x430188 ExitProcess
0x43018c SetErrorMode
Library USER32.dll:
0x4301b0 GetMessageW
0x4301b4 PostQuitMessage
0x4301b8 TrackPopupMenu
0x4301bc BeginDeferWindowPos
0x4301c4 EndDeferWindowPos
0x4301c8 DispatchMessageW
0x4301cc DrawTextExW
0x4301d0 TranslateMessage
0x4301d4 IsDialogMessageW
0x4301d8 GetCursorPos
0x4301dc CheckMenuItem
0x4301e0 MoveWindow
0x4301e4 CloseClipboard
0x4301e8 GetMenuStringW
0x4301ec OpenClipboard
0x4301f0 LoadCursorW
0x4301f4 GetSysColorBrush
0x4301f8 ShowWindow
0x4301fc SetCursor
0x430204 SetWindowTextW
0x430208 GetClientRect
0x43020c UpdateWindow
0x430210 SetDlgItemTextW
0x430214 GetDlgItemTextW
0x430218 GetSystemMetrics
0x43021c DeferWindowPos
0x430220 CreateWindowExW
0x430224 GetWindowRect
0x430228 GetDlgItemInt
0x43022c SendDlgItemMessageW
0x430230 EndDialog
0x430234 GetDlgItem
0x430238 InvalidateRect
0x43023c SetDlgItemInt
0x430240 LoadIconW
0x430244 SendMessageW
0x430248 MessageBoxW
0x43024c LoadImageW
0x430250 SetWindowPos
0x430254 GetWindowPlacement
0x430258 LoadAcceleratorsW
0x43025c PostMessageW
0x430260 DefWindowProcW
0x430268 RegisterClassW
0x43026c SetMenu
0x430270 SetWindowLongW
0x430274 GetWindowLongW
0x430278 SetFocus
0x43027c GetMenuItemCount
0x430280 CreateDialogParamW
0x430284 EnumChildWindows
0x430288 LoadStringW
0x43028c DestroyWindow
0x430290 GetClassNameW
0x430294 GetWindowTextW
0x430298 LoadMenuW
0x43029c ModifyMenuW
0x4302a0 GetMenuItemInfoW
0x4302a4 GetDlgCtrlID
0x4302a8 DestroyMenu
0x4302ac GetParent
0x4302b0 DialogBoxParamW
0x4302b4 GetSysColor
0x4302b8 GetMenu
0x4302bc GetSubMenu
0x4302c0 SetClipboardData
0x4302c4 EnableWindow
0x4302c8 MapWindowPoints
0x4302cc GetDC
0x4302d0 EmptyClipboard
0x4302d4 EnableMenuItem
0x4302d8 ReleaseDC
Library GDI32.dll:
0x430030 SetBkColor
0x430034 GetDeviceCaps
0x430038 SelectObject
0x43003c SetTextColor
0x430040 CreateFontIndirectW
0x430044 SetBkMode
0x430048 DeleteObject
0x43004c GetStockObject
Library comdlg32.dll:
0x4302e0 GetSaveFileNameW
0x4302e4 FindTextW
Library ADVAPI32.dll:
0x430000 RegCloseKey
0x430004 RegOpenKeyExW
0x430008 RegQueryValueExW
Library SHELL32.dll:
0x430198 SHGetMalloc
0x43019c ShellExecuteExW
0x4301a0 SHBrowseForFolderW
0x4301a4 SHGetFileInfoW
0x4301a8 ShellExecuteW
Library ole32.dll:
0x4303cc CoUninitialize
0x4303d0 CoInitialize

!This program cannot be run in DOS mode.
`.rdata
@.data
A;L$D|
P j YP
YYt49\$
tff9t$@tI
YY9t$$t
tdSVW3
9_DV~B
tqSVWj
GWCSPQ
0vpSW3
9^,W~.S
9^,~aS
9^,W~$S
u/C;^,|
9~$~ZS
9_$YY~{Vf
C;_$|
t?9s$~-
9^,~=S
D$ PUhp
SVWt|H
WWWjhP
D$P+D$H
D$X+D$P
D$l+D$d@P3
+D$dAQ
L$H+L$@AQ
Bt9HHt.
Ht'HuE
YY~'Ph,
Et;Chr
u|j@[SVW
333310
YY_^[Y
t-It.IIt
9n u\W
_T9_ tB;
Fl98t7
jeX_^[
Cl90t[
u#;^$s
lSVWjd
u;9_|t6
t 9_Hu
|A9w|t<9
X_^][Y
YYu]9\$
t08^u+8_
QQSVWj
8^,u-SV
u&8FCu
_^[Y]
SVWjTYjT
9_0UVt/3
A9NH|"j(Z
9^lt'9^d~
u<9Ktt(
t*9Kp|%9M
9^pY|E
#Ft_^[
8F StS
O4;K4t
tvKtjKtYK
NtgHt]HtEHt"
Jt.Ht!
CtkIt_ItSItGIt;3
Fh;GTu
QPWVPP
Q!"#$Q
%Q&'()*+
/0111111
222233333456789:;<Q=>
?@QAQQB$CDEFGQQHIQJK
MNOQQQQQQQQQQQQQQQP
8?uA@P
pthpMC
<@t<pt
u693~2
OtIOt>O
D$ tCj
D$$_^[
W$;Q$u
W(;Q(t
@Y:AYt
YYu59E
@YWPj/
7 PGh|KC
9{@YYu.
Q@PRh\RC
tff9+W
t\9_@uW8^
t!9_@u
YYud9E
$SSSSSSVPW3
jc_j[V
YYt=CS
YYt=CS
|$(_WX
QSUVW3
QSUVWj
9_(Vu:
9|$@Yt
D$HWj[
|$$9|$$
9D$DWt
9D$DWtR
9L$$tA;
}89L$D
9|$Dt3
9|$TuGj
9\$ uQ9\$
t<h(%C
AYhLUC
tV;wT~
PShdKC
@Ph WC
D$4Vh0WC
;QX~$9}
_ ^[Y]
@WWWj[
YYuiCC
u09H$u+
uTWj?WWj
j@ht]C
Q@PRh\RC
PPPPPPP
t%WWWWWWW
%(%(%%)*
%EFGHIJ%*KL
/MN%OPQQRSPPTUVWXYZ[[[[[[[[\]\]%
^_`abccde
ghijklmn%
tuvtwwx
HtiHt^HtSHtHHt=H
<tHHt0H
QSUVWhH
EPh(KC
D$nSPf
</entries>
</xml>
"Account","Login Name","Password","Web Site","Comments"
<entries ext="Password Exporter" extxmlversion="1.1" type="saved" encrypt="false">
name,url,username,password
InitCommonControlsEx
CreateToolhelp32Snapshot
Module32First
Module32Next
Process32First
Process32Next
GetModuleBaseNameW
EnumProcessModules
GetModuleFileNameExW
EnumProcesses
GetModuleInformation
SHGetSpecialFolderPathW
SHAutoComplete
CryptAcquireContextW
CryptReleaseContext
CryptCreateHash
CryptGetHashParam
CryptHashData
CryptDestroyHash
CryptDecrypt
CryptDeriveKey
CryptImportKey
CryptDestroyKey
CryptUnprotectData
persist
delete
read_uncommitted
omit_readlock
writable_schema
fullfsync
legacy_file_format
empty_result_callbacks
count_changes
short_column_names
full_column_names
group_concat
zeroblob
replace
total_changes
changes
last_insert_rowid
sqlite_version
nullif
randomblob
random
ifnull
coalesce
substr
length
typeof
%Y-%m-%d %H:%M:%S
current_timestamp
%Y-%m-%d
current_date
%H:%M:%S
current_time
0123456789ABCDEF0123456789abcdef
thstndrd
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
SQLite format 3
0123456789ABCDEFk
onoffalseyestruefull
CREATE TABLE sqlite_master(
type text,
name text,
tbl_name text,
rootpage integer,
sql text
natural
(right
8outer
inner
JKLMNOPQRSTNO*+IJKLMNOPQRST
:<=>?@ABCDEFGH
JKLMNOPQRST
JKLMNOPQRST
.NOPQRSTXY|}~
<=>?@ABCDEFGH
JKLMNOPQRST*+,PQRST
<=>?@ABCDEFGHnJKLMNOPQRST
*+NOXY
<=>?@ABCDEFGH
JKLMNOPQRST*+N
<=>?@ABCDEFGH
JKLMNOPQRST*+
<=>?@ABCDEFGH
JKLMNOPQRST
Z[\]^_`
g<=>?@ABCDEFGH
JKLMNOPQRST
[\]^_`Z
<=>?@ABCDEFGH
JKLMNOPQRST
1<=>?@ABCDEFGH
JKLMNOPQRST
<=>?@ABCDEFGH
JKLMNOPQRST
XYj\lm
<=>?@ABCDEFGH
JKLMNOPQRST*+P
<=>?@ABCDEFGHrJKLMNOPQRST*+
<=>?@ABCDEFGH
JKLMNOPQRST*+
=>?@ABCDEFGH
JKLMNOPQRST*+
>?@ABCDEFGH
JKLMNOPQRST
BEFOREIGNOREGEXPLAINSTEADDESCAPEACHECKEYCONSTRAINTERSECTABLEFTHENDATABASELECTRANSACTIONATURALTERAISELSEXCEPTRIGGEREFERENCESUNIQUERYATTACHAVINGROUPDATEMPORARYBEGINNEREINDEXCLUSIVEXISTSBETWEENOTNULLIKECASCADEFERRABLECASECOLLATECREATECURRENT_DATEDELETEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFINTOFFSETISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
pCh1(G
"I$_,Zm
o>i%qY*u
z.-fAt2YY
3js56(k
(NULL)
922337203685477580
%s\etilqs_
-journal
%!.15g
%s-mj%08X
string or blob too big
unable to use function %s in the requested context
transaction - SQL statements in progress
rollback
commit
cannot
cannot start a transaction within a transaction
cannot rollback - no transaction is active
cannot commit - no transaction is active
database schema has changed
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s
out of memory
integer
near "%T": syntax error
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
_ROWID_
misuse of aliased aggregate %s
no such column
ambiguous column name
%s: %s.%s.%s
%s: %s.%s
%s: %s
misuse of aggregate function %.*s()
no such function: %.*s
wrong number of arguments to function %.*s()
Expression tree is too large (maximum depth %d)
misuse of aggregate: %T
RAISE() may only be used within a trigger-program
invalid name: "%T"
too many attached databases - max %d
cannot ATTACH database within transaction
database %s is already in use
attached databases must use the same text encoding as main database
unable to open database: %s
no such database: %s
cannot detach database %s
cannot DETACH database within transaction
database %s is locked
sqlite_detach
sqlite_attach
%s %T cannot reference objects in database %s
no such table
unknown database %T
sqlite_
object name reserved for internal use: %s
table %T already exists
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
INTEGER
no such collation sequence: %.*s
CREATE TABLE
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
tbl_name='%q'
view %s is circularly defined
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
rows deleted
integer overflow
LIKE or GLOB pattern too complex
ESCAPE expression must be a single character
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
rows inserted
may not be NULL
PRIMARY KEY must be unique
columns
column
are not unique
is not unique
automatic extension loading failed: %s
malformed database schema (
BINARY
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s
statement too long
unknown or unsupported join type: %T%s%T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
only a single result allowed for a SELECT that is part of an expression
column%d
no such table: %s
no tables specified
too many columns in result set
too many terms in %s BY clause
%r %s BY term out of range - should be between 1 and %d
a GROUP BY clause is required before HAVING
aggregate functions are not allowed in the GROUP BY clause
DISTINCT in aggregate must be followed by an expression
trigger
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
type='trigger' AND name='%q'
no such column: %s
rows updated
cannot VACUUM from within a transaction
ATTACH '' AS vacuum_db;
PRAGMA vacuum_db.synchronous=OFF
BEGIN EXCLUSIVE;
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';'FROM sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM ' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
at most %d tables in a join
parser stack overflow
set list
too many arguments on function %T
interrupt
unrecognized token: "%T"
Unable to close due to unfinalised statements
not an error
SQL logic error or missing database
access permission denied
callback requested query abort
database is locked
database table is locked
attempt to write a readonly database
interrupted
disk I/O error
database disk image is malformed
database or disk is full
unable to open database file
table contains no data
String or BLOB exceeded size limit
constraint failed
datatype mismatch
library routine called out of sequence
large file support is disabled
authorization denied
auxiliary database format error
bind or column index out of range
file is encrypted or is not a database
unknown error
bad parameters
Unable to delete/modify user-function due to active statements
unknown encoding
Unable to delete/modify collation sequence due to active statements
no such vfs: %s
NOCASE
AES-256-GCM
AES-192-GCM
AES-128-GCM
AES-256-ECB
AES-192-ECB
AES-128-ECB
c:\Projects\VS2005\ChromePass\Command-Line\ChromePass.pdb
wcscat
_snwprintf
wcsncat
memset
strlen
wcslen
wcschr
wcscmp
_wcsicmp
wcscpy
memcpy
??3@YAXPAX@Z
??2@YAPAXI@Z
_memicmp
memmove
memcmp
strcmp
wcstoul
malloc
wcsrchr
_wcslwr
_purecall
toupper
realloc
isalnum
_gmtime64
isxdigit
tolower
isspace
isdigit
strftime
msvcrt.dll
__dllonexit
_onexit
_c_exit
_XcptFilter
_cexit
_wcmdln
__wgetmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
_except_handler3
ImageList_ReplaceIcon
ImageList_Create
ImageList_SetImageCount
ImageList_AddMasked
CreateToolbarEx
CreateStatusWindowW
COMCTL32.dll
CompareFileTime
WriteFile
FileTimeToLocalFileTime
WideCharToMultiByte
SystemTimeToFileTime
GetModuleHandleW
LoadLibraryW
FileTimeToSystemTime
GetProcAddress
FindClose
FindNextFileW
CloseHandle
GetFileSize
FindFirstFileW
MultiByteToWideChar
GetLastError
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileIntW
EnumResourceNamesW
FreeLibrary
SetFilePointer
CreateFileW
GlobalAlloc
GlobalUnlock
FindResourceW
GetSystemDirectoryW
GetTempPathW
LoadResource
LoadLibraryExW
SizeofResource
FormatMessageW
GlobalLock
GetVersionExW
GetWindowsDirectoryW
GetTimeFormatW
GetDateFormatW
GetFileAttributesW
LocalFree
GetTempFileNameW
ReadFile
LockResource
GetModuleFileNameW
GetCurrentProcess
ReadProcessMemory
GetCurrentProcessId
ExitProcess
SetErrorMode
DeleteFileW
OpenProcess
EnumResourceTypesW
LocalAlloc
GetTickCount
LockFileEx
EnterCriticalSection
GetSystemTimeAsFileTime
InitializeCriticalSection
GetFullPathNameW
GetFullPathNameA
DeleteCriticalSection
CreateFileA
GetCurrentThreadId
LeaveCriticalSection
GetFileAttributesA
SetEndOfFile
InterlockedIncrement
GetTempPathA
FlushFileBuffers
GetSystemTime
QueryPerformanceCounter
AreFileApisANSI
DeleteFileA
UnlockFile
LockFile
CopyFileW
GetModuleHandleA
GetStartupInfoW
KERNEL32.dll
LoadCursorW
GetSysColorBrush
ShowWindow
SetCursor
ChildWindowFromPoint
SetWindowTextW
GetClientRect
UpdateWindow
SetDlgItemTextW
GetDlgItemTextW
GetSystemMetrics
DeferWindowPos
CreateWindowExW
GetWindowRect
GetDlgItemInt
SendDlgItemMessageW
EndDialog
GetDlgItem
InvalidateRect
SetDlgItemInt
LoadIconW
SendMessageW
MessageBoxW
LoadImageW
SetWindowPos
GetWindowPlacement
LoadAcceleratorsW
PostMessageW
DefWindowProcW
TranslateAcceleratorW
RegisterClassW
SetMenu
SetWindowLongW
GetWindowLongW
SetFocus
GetMenuItemCount
CreateDialogParamW
EnumChildWindows
LoadStringW
DestroyWindow
GetClassNameW
GetWindowTextW
LoadMenuW
ModifyMenuW
GetMenuItemInfoW
GetDlgCtrlID
DestroyMenu
GetParent
DialogBoxParamW
GetSysColor
GetMenu
GetSubMenu
SetClipboardData
EnableWindow
MapWindowPoints
EmptyClipboard
EnableMenuItem
ReleaseDC
OpenClipboard
GetMenuStringW
CloseClipboard
MoveWindow
CheckMenuItem
GetCursorPos
IsDialogMessageW
TranslateMessage
DrawTextExW
DispatchMessageW
EndDeferWindowPos
RegisterWindowMessageW
BeginDeferWindowPos
TrackPopupMenu
PostQuitMessage
GetMessageW
USER32.dll
DeleteObject
SetBkMode
CreateFontIndirectW
SetTextColor
SelectObject
GetDeviceCaps
SetBkColor
GetTextExtentPoint32W
GetStockObject
GDI32.dll
GetSaveFileNameW
FindTextW
comdlg32.dll
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
ADVAPI32.dll
ShellExecuteW
SHGetFileInfoW
SHBrowseForFolderW
ShellExecuteExW
SHGetMalloc
SHGetPathFromIDListW
SHELL32.dll
CoInitialize
CoUninitialize
ole32.dll
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
,,,,,,,,,,
wwwwwp
wwwwwwwwwwwwwwwwwwww~gww
wwwwwwwwwwwwwwN
wwwwww~fww
wwwwwwwwwwp
wwwwwwwwwwxwwN
wwwwpw~fhw
wwwwwwwwwwx
wwwwwwwwwwx
wwwwwwwwww
wwwwww
wwwwwwwwwx
wwwwwwwwwx
wwwwwwwwwx
wwwwwwwwww
wwwwwwwwwwx
wwwwwwwwwwx
wwwwwwp
wwwwwwwwwwx
wwwwwwww
xpwwwwwwwwwwwx
wwwwwwwwwwwp
wwwwwwwwwwwx
wwwwwwwwwwwwwwwwwwwwwwww
wwwwwwwwwww(
NXXmummmhh
NNHR{ppppmmhhb
NHH.m{ppppppmmmh]
N3H3]{uuupppppmmbhb
{{uuuuppppmmbbb
HN)))]
{{{uuuppppmmb]]
N)).33)){{{{uuuppppmmb]
HH).3HNR3#p
{{{uuppppmmbb
N).3NRXZ
pppmmh]
RN.3NRXZ
pppmmb]
RH3HRXZ]
ppppmh]
R3HNXZ]h
{pppmmbb
X3NRZ]bum
uppmmbb
RHRX]bh{.
:;<=>?
p{pppmhh
RNRZ]hm{
pppmmh
NX]bhub
9:;<=>?@
pppp].
bRZ]hh
789:;<=>?@AB
bZZbhm
6789:;<=>?@ABC
m]hhpX
hu{{X]Rb
uu{X]3
HH33..33HH
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
B%2.2X
MS Sans Serif
@ShowGridLines
SaveFilterIndex
ShowInfoTip
UseProfileFolder
ProfileFolder
MarkOddEvenRows
UseLocalStateFile
LocalStateFilename
ChromeUserDataFolder
AdvancedExternal
ProtectFolder
%s\User Data
Google\Chrome
google\Chrome SxS
Chromium
<entry host="%s" user="%s" password="%s" formSubmitURL="%s" httpRealm="%s" userFieldName="%s" passFieldName="%s"/>
AppData\Local
Local Settings\Application Data
AppData\Roaming
Application Data
<meta http-equiv='content-type' content='text/html;charset=%s'>
<table dir="rtl"><tr><td>
<br><h4>%s <a href="http://www.nirsoft.net/" target="newwin">%s</a></h4><p>
</table>
@comctl32.dll
Error: Cannot load the common control classes.
@caption
menu_%d
dialog_%d
strings
general
sysdatetimepick32
charset
TranslatorName
TranslatorURL
Version
_lng.ini
netmsg.dll
Unknown Error
Error %d: %s
kernel32.dll
%2.2X
%s (%s)
%-18s: %s
%%-%d.%ds
<td bgcolor=#%s nowrap>%s
<td bgcolor=#%s>%s
&nbsp;
<tr><td%s nowrap><b>%s</b><td bgcolor=#%s%s>%s
bgcolor="%s"
<table border="1" cellpadding="5">
nowrap
<font color="%s">%s</font>
</table><p>
<item>
<%s>%s</%s>
</item>
<?xml version="1.0" ?>
@{Unknown}
Exception %8.8X at address %8.8X in module %s
Registers:
EAX=%8.8X EBX=%8.8X ECX=%8.8X EDX=%8.8X
ESI=%8.8X EDI=%8.8X EBP=%8.8X ESP=%8.8X
EIP=%8.8X
Stack Data: %s
Code Data: %s
%s: %s
SysListView32
/nosaveload
report.html
commdlg_FindReplace
*.htm;*.html
General
WinPos
Columns
/external
/stext
/shtml
/sverhtml
/stabular
/scomma
/skeepass
/spassexp
/savelangfile
/deleteregkey
@advapi32.dll
psapi.dll
\systemroot
STATIC
@shell32.dll
WAppData
Favorites
Desktop
Start Menu
Programs
Startup
Common Start Menu
Common Programs
Common Desktop
Common Startup
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shlwapi.dll
%2.2X%2.2X%2.2X
&quot;
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html><head>%s<title>%s</title></head>
<body>
%s <h3>%s</h3>
</body></html>
size="%d"
color="#%s"
</font>
<font color="%s">
<table border="1" cellpadding="5"><tr%s>
width="%s"
<th%s>%s%s%s
</table>
%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X
crypt32.dll
????@@AAAB
D????@@AAAB
>>====
????@@AAAB
????@@AAAB
:@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
>>====
????@@AAAB
!%(/7:=?AFGLUV[_cfkq{~
Local State
AppData\Roaming\Microsoft\Protect
Application Data\Microsoft\Protect
&Advanced Options
&Save Selected Items
Ctrl+S
&Properties
Alt+Enter
Ctrl+F
&Copy Selected Items
Ctrl+C
Select &All
Ctrl+A
Deselect All
Ctrl+D
Show &Grid Lines
Show &Tooltips
Mark &Odd/Even Rows
&HTML Report - All Items
HTML R&eport - Selected Items
Choose Colum&ns
&Auto Size Columns
Ctrl+Plus
&Refresh
&Run As Administrator
Ctrl+F11
&About
Popup1
&Save Selected Items
Ctrl+S
&Copy Selected Items
Ctrl+C
HTML Report - All Items
HTML Report - Selected Items
Choose Colum&ns
&Auto Size Columns
Ctrl+Plus
&Properties
Alt+Enter
&Refresh
Properties
MS Sans Serif
Exception !
MS Sans Serif
Copy Exception
Continue
Terminate Application
The following application error has occurred:
If this problem persists, copy the above exception information to the clipboard, and send it to the author of this software.
Advanced Options
MS Shell Dlg
Load the passwords of the current logged-on user
Use the following profile folder:
Load the passwords from another Windows user or external drive:
Windows User Profile Path, For example: K:\Users\Admin
Windows Login Password:
Advanced external drive settings:
Windows Protect folder for getting the encryption keys, For example: F:\Users\Nir\AppData\Roaming\Microsoft\Protect
Chrome User Data folder where the password file is stored , for example: G:\Users\Nir\AppData\Local\Google\Chrome\User Data\Default
Extract the encryption key from the following 'Local State' File: (For Chrome 80.0 or greater)
Cancel
MS Sans Serif
Translation:
Column Settings
MS Shell Dlg
SysListView32
Move &Up
Move &Down
Default
Cancel
Check the columns that you would like to make visible. Use the Move Up and Move Down buttons to reorder the columns
Width of selected column (in pixels):
%d item(s)
, %d Selected
Created by using
Select a filename to save
Chrome Passwords List!Select the windows profile folderfCannot find the files of Chrome on the external profile folder. Try to run this tool as Administrator.
Loading... %d
Text File
Tab Delimited Text File
Tabular Text File
HTML File - Horizontal
HTML File - Vertical
XML File
Comma Delimited Text File
KeePass csv file,Password Exporter Firefox Extension XML File
Chrome CSV File
Origin URL
Action URL
User Name Field
Password Field
User Name
Password
Created Time
Password Strength
Password File
Very Weak
Medium
Strong
Very Strong
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
NirSoft
FileDescription
Chrome Password Recovery
FileVersion
InternalName
ChromePass
LegalCopyright
Copyright
2008 - 2020 Nir Sofer
OriginalFilename
ChromePass
ProductName
ChromePass
ProductVersion
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Riskware.Win32.Chromepass.1!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Application.Heur.oq0@kK9ERXlO
CMC Clean
CAT-QuickHeal Hacktool.Chromepass
Qihoo-360 Win32/HackTool.Generic.HgIASQ8A
ALYac Gen:Application.Heur.oq0@kK9ERXlO
Cylance Unsafe
VIPRE Nirsoft Password Recovery (not malicious)
Sangfor Hacktool.Win32.ChromePass.mt
CrowdStrike win/malicious_confidence_60% (D)
BitDefender Gen:Application.Heur.oq0@kK9ERXlO
K7GW Unwanted-Program ( 0056d3a51 )
K7AntiVirus Unwanted-Program ( 0056d3a51 )
BitDefenderTheta Clean
Cyren W32/Application.ZBFX-9294
Symantec PasswordRevealer
ESET-NOD32 a variant of Win32/PSWTool.ChromePass.D potentially unsafe
Baidu Clean
APEX Clean
Paloalto generic.ml
ClamAV Win.Tool.ChromePassVariant-6615990-0
Kaspersky Clean
Alibaba HackTool:Win32/ChromePass.10dd59db
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.100 (RDML:7NWhW+/C1ctzTDMUznAzEQ)
Ad-Aware Gen:Application.Heur.oq0@kK9ERXlO
TACHYON Clean
Emsisoft Gen:Application.Heur.oq0@kK9ERXlO (B)
Comodo Malware@#m51cuhbd5d44
F-Secure Clean
DrWeb Clean
Zillya Trojan.PSWTool.Win32.106
TrendMicro HackTool.Win32.NirsoftPT.SM
McAfee-GW-Edition Tool-PassView.b
FireEye Generic.mg.cf53febec7e1376c
Sophos NirPassView (PUA)
Ikarus Clean
GData Gen:Application.Heur.oq0@kK9ERXlO
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
Antiy-AVL Trojan/Generic.ASMalwS.30D291E
Kingsoft Clean
Gridinsoft Risk.Win32.ChromePass.ad!i
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft HackTool:Win32/ChromePass
Cynet Clean
AhnLab-V3 Trojan/Win32.Wacatac.R346831
Acronis Clean
McAfee Tool-PassView.b
MAX malware (ai score=77)
VBA32 Clean
Malwarebytes RiskWare.ChromePasswordTool
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall HackTool.Win32.NirsoftPT.SM
Tencent Clean
Yandex Trojan.Igent.bUkQId.2
SentinelOne Clean
eGambit Trojan.Generic
Fortinet Riskware/PassView
AVG FileRepMetagen [PUP]
Cybereason malicious.ec7e13
Avast FileRepMetagen [PUP]
MaxSecure Trojan.Malware.102171505.susgen
No IRMA results available.