Static | ZeroBOX

PE Compile Time

2015-08-01 06:07:17

PE Imphash

2cbe6db2ec1d8a931b50336af1a7dc15

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008104c 0x00081200 6.66075083511
.rdata 0x00083000 0x0001571e 0x00015800 5.44783642488
.data 0x00099000 0x00022d88 0x0001b400 5.78473083822
.rsrc 0x000bc000 0x000002e0 0x00000400 4.26192292884
.reloc 0x000bd000 0x00004c5c 0x00004e00 6.64213840165

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x000bc060 0x0000027e LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x48307c IsWow64Process
0x483080 GetLocaleInfoW
0x483084 CreateProcessW
0x483088 GetFileSize
0x48308c WriteFile
0x483090 ReadFile
0x483094 GetSystemDirectoryA
0x483098 CreateFileA
0x48309c SetFileAttributesA
0x4830a0 lstrcmpW
0x4830a4 lstrlenW
0x4830a8 GetModuleFileNameW
0x4830ac GetTempFileNameW
0x4830b0 RemoveDirectoryW
0x4830b4 SetFileAttributesW
0x4830b8 GetFileAttributesW
0x4830bc DeleteFileW
0x4830c0 CopyFileW
0x4830c4 MoveFileW
0x4830c8 MoveFileExW
0x4830cc GetCurrentProcessId
0x4830d0 GetVersionExW
0x4830d4 GetExitCodeProcess
0x4830d8 CreatePipe
0x4830dc PeekNamedPipe
0x4830e0 GetStartupInfoW
0x4830e4 DeleteFileA
0x4830e8 AreFileApisANSI
0x4830ec GetSystemTime
0x4830f0 LocalFree
0x4830f4 GetTempPathA
0x4830f8 GetVersionExA
0x4830fc OutputDebugStringA
0x483104 GetDiskFreeSpaceA
0x483108 CreateFileMappingW
0x48310c CreateFileMappingA
0x483110 GetDiskFreeSpaceW
0x483114 LockFileEx
0x483118 HeapSize
0x48311c GetLastError
0x483120 FlushFileBuffers
0x483124 CreateFileW
0x483128 HeapValidate
0x48312c HeapCreate
0x483130 HeapDestroy
0x483134 FormatMessageW
0x483138 FormatMessageA
0x483140 GetProcessHeap
0x483144 UnlockFileEx
0x483148 GetTickCount
0x48314c OutputDebugStringW
0x483154 LockFile
0x483158 FlushViewOfFile
0x48315c UnlockFile
0x483164 WaitForSingleObject
0x483168 HeapFree
0x483174 HeapAlloc
0x483178 FreeLibrary
0x48317c SetEndOfFile
0x483180 UnmapViewOfFile
0x483184 MapViewOfFile
0x483188 ResetEvent
0x48318c HeapCompact
0x483190 GetTempPathW
0x483194 HeapReAlloc
0x483198 GetFullPathNameA
0x48319c GetFullPathNameW
0x4831a0 GetCurrentThreadId
0x4831a8 GetCurrentProcess
0x4831ac SetErrorMode
0x4831b0 GetCommandLineW
0x4831b8 SetSystemPowerState
0x4831bc OpenMutexW
0x4831c0 GlobalAlloc
0x4831c4 GlobalFree
0x4831cc lstrcpyW
0x4831d0 GetComputerNameW
0x4831d4 GetLogicalDrives
0x4831d8 GetFileSizeEx
0x4831dc FindClose
0x4831e8 GetDriveTypeW
0x4831ec GetDiskFreeSpaceExW
0x4831f0 FindFirstFileW
0x4831f4 FindNextFileW
0x4831f8 SetEvent
0x483204 WriteConsoleW
0x483208 SetStdHandle
0x483214 GetModuleFileNameA
0x48321c GetConsoleCP
0x483220 GetFileType
0x483224 SetFilePointerEx
0x483228 ReadConsoleW
0x48322c GetConsoleMode
0x483238 GetStdHandle
0x48323c GetOEMCP
0x483240 GetACP
0x483244 IsValidCodePage
0x483248 GetModuleHandleExW
0x48324c ExitProcess
0x483250 EnumSystemLocalesW
0x483254 GetUserDefaultLCID
0x483258 IsValidLocale
0x48325c LCMapStringW
0x483260 CompareStringW
0x483264 GetTimeFormatW
0x483268 GetDateFormatW
0x48326c TlsFree
0x483274 TlsSetValue
0x483278 TlsGetValue
0x48327c TlsAlloc
0x483284 SetLastError
0x483290 GetCPInfo
0x483294 LoadLibraryW
0x483298 GetNativeSystemInfo
0x48329c GetSystemInfo
0x4832a4 Process32NextW
0x4832a8 Process32FirstW
0x4832ac CreateDirectoryW
0x4832b0 GetLocalTime
0x4832b4 GlobalUnlock
0x4832b8 GlobalLock
0x4832bc CreateEventW
0x4832c0 CreateMutexW
0x4832c4 Sleep
0x4832cc GetModuleHandleW
0x4832d0 ResumeThread
0x4832d4 TerminateThread
0x4832d8 CreateThread
0x4832dc Process32Next
0x4832e0 Process32First
0x4832e8 WideCharToMultiByte
0x4832ec MultiByteToWideChar
0x4832f8 LoadLibraryA
0x4832fc CloseHandle
0x483300 TerminateProcess
0x483304 OpenProcess
0x483308 GetProcAddress
0x48330c GetFileAttributesA
0x483310 lstrlenA
0x483314 lstrcatA
0x483318 SetFilePointer
0x48331c GetCommandLineA
0x483320 LoadLibraryExW
0x483324 ExitThread
0x48332c IsDebuggerPresent
0x483330 RtlUnwind
0x483334 RaiseException
0x483338 GetStringTypeW
0x48333c DecodePointer
0x483340 EncodePointer
Library USER32.dll:
0x4833a8 LoadIconW
0x4833ac wsprintfW
0x4833b0 OpenClipboard
0x4833b4 CloseClipboard
0x4833b8 GetClipboardData
0x4833bc GetForegroundWindow
0x4833c4 ToUnicodeEx
0x4833c8 GetKeyboardLayout
0x4833cc GetKeyboardState
0x4833d0 CharUpperW
0x4833d4 GetKeyState
0x4833d8 LoadCursorW
0x4833dc UnhookWindowsHookEx
0x4833e0 CallNextHookEx
0x4833e4 ExitWindowsEx
0x4833e8 GetLastInputInfo
0x4833ec GetWindowRect
0x4833f0 SendInput
0x4833f4 GetSystemMetrics
0x4833f8 GetDC
0x4833fc ReleaseDC
0x483400 GetClientRect
0x483404 SetCursorPos
0x48340c GetWindowTextW
0x483410 SetWindowTextW
0x483414 UpdateWindow
0x483418 FlashWindowEx
0x48341c ShowWindow
0x483420 CreateWindowExW
0x483428 EnumDisplayDevicesW
0x48342c GetDesktopWindow
0x483430 RegisterClassExW
0x483434 PostQuitMessage
0x483438 DefWindowProcW
0x48343c SendMessageW
0x483440 DispatchMessageW
0x483444 TranslateMessage
0x483448 GetMessageW
0x48344c SetWindowsHookExW
Library GDI32.dll:
0x483048 SetStretchBltMode
0x48304c StretchBlt
0x483050 SelectObject
0x483054 GetDIBits
0x483058 DeleteObject
0x48305c CreateCompatibleDC
0x483064 SetTextColor
0x483068 SetBkColor
0x48306c GetStockObject
0x483070 CreateFontW
0x483074 GetObjectW
Library ADVAPI32.dll:
0x483008 OpenProcessToken
0x48300c RegSetValueExW
0x483010 RegDeleteValueW
0x483014 RegCreateKeyW
0x483018 RegQueryValueExW
0x48301c RegOpenKeyExW
0x483020 GetUserNameW
0x483024 RegOpenKeyExA
0x483028 RegQueryValueExA
0x48302c RegCloseKey
Library SHELL32.dll:
0x48337c SHGetFileInfoW
0x483380 SHGetFolderPathW
0x483384 ShellExecuteW
0x48338c SHFileOperationW
0x483390 CommandLineToArgvW
0x483394 SHGetFolderPathA
Library ole32.dll:
0x4834d8 CoSetProxyBlanket
0x4834dc CoInitializeEx
0x4834e0 CoTaskMemFree
0x4834e4 CoCreateInstance
0x4834e8 CoInitialize
0x4834ec CoUninitialize
Library OLEAUT32.dll:
0x483354 SysAllocString
0x483358 SysFreeString
0x48335c VariantClear
0x483360 VariantInit
Library SHLWAPI.dll:
0x48339c None
0x4833a0 SHGetValueA
Library CRYPT32.dll:
0x483040 CryptUnprotectData
Library NETAPI32.dll:
0x483348 NetApiBufferFree
0x48334c NetUserEnum
Library urlmon.dll:
0x4834f4 URLDownloadToFileW
Library gdiplus.dll:
0x483490 GdipFree
0x483494 GdiplusShutdown
0x483498 GdipCloneImage
0x4834a4 GdipDisposeImage
0x4834a8 GdiplusStartup
0x4834b8 GdipBitmapLockBits
0x4834c4 GdipGetImageHeight
0x4834c8 GdipGetImageWidth
0x4834cc GdipAlloc
Library WS2_32.dll:
0x483454 WSAStartup
0x483458 connect
0x48345c ioctlsocket
0x483460 inet_ntop
0x483464 inet_pton
0x483468 FreeAddrInfoW
0x48346c GetAddrInfoW
0x483470 WSACleanup
0x483474 closesocket
0x483478 htons
0x48347c sendto
0x483480 socket
0x483484 send
0x483488 recv
Library PSAPI.DLL:
0x483374 GetModuleBaseNameW
Library POWRPROF.dll:
0x483368 SetSuspendState
Library COMCTL32.dll:

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
PSSSSS
t+9=LBK
t#9=8BK
PSShT6H
t&PPWVj
HtmHt[
VVVVVVVVj
LSVWj,3
G4PSWh17@
PPWhx7@
VjYXPh
VjZXPh
jSXjYYjTf
Yj\XjCZjuf
YjeXjnf
Xjt[jo^jlf
^jeXjZf
YjnXjAf
[jcXjtf
[jBXjsf
XjeYjZf
^jaXjmf
jSXjOf
XjWYjA[jRf
ji[jcXjrf
XjsZjff
j\XjTf
Xj ZjZf
ZjDXjpf
VWj@^V
SVWjSYjOf
YjWZjAf
Yj\^jMf
Yji_jcf
Yjs[jff
_jdYjof
jCYjuZjrf
^jtYjVf
SVWjHXjAYjR^jDZjWf
Xj\[jSf
YjPXjTf
jr[ja^jlXjPf
XjoZjcYjef
YjsXjNf
SVjNZjeXjt[jAf
XjIYj3f
TVWj@3
PVVVVVV
~!WWPVWW
s#9>w+>
(tvHHte
tSHtC-
VWPhH=H
tdHtO-
t6HHt j
_^[h(iK
~,9~$t
tC97u?j
tG9uCj
tZ9uVj
PWhd>H
PWhl>H
WSSSh4?H
ADf;BDt
HtQHt>
r6;V@u
;~Dt,9N$u'
~D9N4|
YY_^[]
QQSVWj
FT9^T~
9F@v79F,u
@M:C>t
</t5<\t1V
HtdHtDHt
Yf;FD}-
CX3FX%
YY;C,uT
@ f;F t
_f9<Vs
DFNf;B
DFNf;B
Bf9^LtFV
FLYf9\FNt
CYY;_@|
jAXj>Y
~#VSj0P
YY_^[]
FH@WPWj
jlXjiZ
jP^jRX
jSXjQZ
wHVPjg
YY<At{
f;P.s@
OHPQPj
N.QPj9
PQPjHW
@* u/V
B,#KH#CL
F,#KH#CL
u8GAu
HtsHt<j
j?Yf;J"}
QQWPQQQV
Bf9{ |wWWV
C+PRWWWV
f;V.sH
u?f;C"}9
f;H"}q
GL#J(#B,
:BINAu
7,...f
f;A t6
PPPjeS
QQQQQQ
G* u3j
f;H.s]
PPPPVWS
9>~.S3
twWj.S
HtdHtHt^
HtpHtAHHt=
PPPj!S
f;F.sU
uH9;~8
Yf9^Lu
89^<t&
SSPj=V
SSWj=V
G @PRQj
PPPj)V
C(;Aht
u`SSVW
YY^_[]
FLt'SSQ
;GPw~3
jeX_^[
9^(t'V
K<99u"
_WPj:j
FPSj;SWV
u78G*t2
FPRj;Rj
9J4t@V
tQ9~(v:
9{(vOV
;^Tt9SWj
F9r ~FVR
[0Y;~`|
GA_^[]
YYPj~V
F,twSW
_0^_[]
u$QjOW
u FPVjEW
u VjnW
F"@;G`~
YY_^[]
f;B"}G3
PPPPPQ
t+h(hH
0QVQja
79](t$
YYj}XF;
Y9F,t&
Vf9FLt~
DFNf;A
DSNf;A
u+8FIu
DANf;F
t#QQjd
G0Y_^]
6PPSj|
f!HN_^[
VPRj,P
O"PQRj1V
C* t(S
G* u%3
CHQPQj
YY9^4t)9^0~
YYC;^0|
PPPj=S
0QQVj~S
QQQj=P
F,YY^_[
YY_^[]
u"VPPjH
B&<at4<
PSSjUW
j WPSjQV
G QPjR
PPPj$V
F f;C
YY_^[]
4tZHt(H
4tmNt*N
#t/Ht Ht
f9B }%
Af9H.uw
f9H }
t);F u
HtgHtSHtaHt6
QQjmVW
f;N0s^
@* u=Q
f;B.s9
t-9w$t&Q
f;G"}=
$;p }!f
<tQHt6H
f;F0s,
PWjlVS
Q4CYY;
PPPPPP
_D_^[]
t"8H+u
Y;^ v%
8t,WS
YY_[^]
;^`}k
0Y;^`|
F@98uaS
:modeu
SVSjaW
@PVj#W
@PVj#W
@PSjaW
@PPj#W
@PPj#W
SS@Pj#W
^VSjaYQW
0SWSja
^VSjaW
V@Pj#W
^VSjaW
V@Pj#W
FHj6QWSV
NDSSSjl
tEPRSj/W
SPSjgW
SSVjLW
SSVjMW
Yf;F.s9
^VSjaW
@PSjaW
FAQSPW
@PPj#W
;_\~;h$
^<_^[]
t#9;~
YY[_^]
VPRj<W
P,f;W(}
@PVj3S
VWVjJS
f;HD})S
f;F.sc
FHQPQj
f;C"}j
f;C"}4
SSPj=W
t3Ht*HHt
SRQVPO
;C }4Vk
C H_^9E
HtzHtgH
$G<C|>j
Nt/It%It
s:!FL!FD
uS8NFtN3
GhHPQV
@L:GWs
u!9FPt
AtJHHt=Ht2Ht'
}|j Y;
f;FF}/
Y9^L|$V
49^Pt/
&#G8_^[]
8^;viW
uj9~Dt&
ub8^+u
YY8_Au
YY8_At%
utj6Y8V&t
uSj@Xf9G"}J
f;C"}A
YY_^[]
f;G"}`3
PPPPPP
Hf;G"}3
OF(QPV
C _^[]
B;SVW3
Y9;~93
F@_^[]
~8f;F"}
t@< t<3
Q@YY_^]
f9~(um
P<YY9]
;FDuGj
ub;NDr
#O #G$
j+XPRf
#H@#PD
G,f;A(
F89F0t
^49;t<
~,[_^]
f9F |M
}(f9B*u"
#A@#QD
9H@tWVPS
VVPVWVh
VVPVWVh
t PPSWj
t$SSWVj
~<9~(t%
9s`~&3
N.f9O.t
G2:F2u
K"f;N"
C f;F
f9C |L
PPSj=W
t`9N4t6VR
WWWWWWWPWV
PQQjtR
QQQjwR
PPPPPPP
QQQj9R
PQQj9R
!"#$%&
.6.78.9:;
<=>?.@
B.CDEFFG
.(YZ[\
.]^_`a8b
Gcdefghhijggklmnopqqqqqqqqrstuvwxyzz{|
PWWWWWWV
tG9uCj
SSSh<t@
;0u,9E
PVWj0h
PWWWWWW
PWWWWWWW
SSSSRP
QQQQQQPQ
WVhp<H
t*Ht#Ht
t<Ht9Ht/Ht%Ht
VWPhX9I
s Vhh9I
HtMHu)
YYh|;H
QQSVWd
HHtPHHt-H
HthHt3
PPPPPPPP
HtHu4j
PP9E u
jA[jZZ+
YYhl5H
Y;=|4K
~pjCXf
URPQQh0
,SVWj0X
Wj0XPV
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
vlh|4K
bWWWWj
<at-<rt"<wt
jdh`iI
j@j _W
HHtVHHt
htHjlZ;
HHtXHHt
nt'joZ;
YYjgXf9
>0t<NAj0X
SVWjA_jZ+
uBjAYjZ+
SSPQSW
tx8tt
?:uBGW
} kE$<
uHjAXf;
RVSQSWV
j$h`jI
t WW9}
;t$,v-
UQPXY]Y[
PWWWWV
PSSSSV
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
Yu2Vj@h
kSjA[jZ^+
8jZZf;
~';_t|%3
tHHt*Ht#
SVjA[jZ^+
jAZjZ^
htHjlZ;
HHtXHHt
nt'joZ;
YYjgXf9
>0t<NAj0X
HHtVHHt
Ht+Ht$Ht
HtHHt
+tHHt
+t"HHt
HAO8t
generic
unknown error
iostream
iostream stream error
system
string too long
invalid string position
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
firefox.exe
chrome.exe
plugin-container.exe
\AppData\Local\Google\Chrome\User Data\Default\Login Data
SELECT origin_url, username_value, password_value FROM logins
SOFTWARE\Mozilla\Mozilla Firefox
CurrentVersion
Install Directory
\nss3.dll
NSS_Init
NSS_Shutdown
PK11_GetInternalKeySlot
PK11_FreeSlot
PK11_Authenticate
PK11SDR_Decrypt
sqlite3_open
sqlite3_prepare_v2
sqlite3_step
sqlite3_column_text
Decryption error
Authenticate error
Internal Slot error
%s\Mozilla\Firefox\profiles.ini
Profile
%s\Mozilla\Firefox\Profiles\%s
\signons.sqlite
SELECT encryptedUsername, encryptedPassword, formSubmitURL FROM moz_logins
\logins.json
formSubmitURL
usernameField
encryptedUsername
encryptedPassword
invalid vector<T> subscript
vector<T> too long
\drivers\etc\HOSTS
invalid map<K, T> key
map/set<T> too long
NtQueryInformationProcess
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
_bufferLength:
bad cast
*T,h5#q./2
4e2%!m
D;Hdj
yIr-{b2$
=s}?@0t0123456789ABCDEF
liA>@?
naturaleftouterightfullinnercross
thstndrd
3.8.10.2
PQRSTUVWXYZ[\]^_lmn
23PQRSzUVWXYZ[\]^_
GHIJKLMNOPQRSzUVWXYZ[\]^_
a[\]^_
UVWXYZ[\]^_
YZ[\]^_
GHIJKLMNOPQRS3UVWXYZ[\]^_
23cdefghi
pAEGHIJKLMNOPQRS
UVWXYZ[\]^_
cgpfgh
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_B
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
GHIJKLMNOPQRS
UVWXYZ[\]^_
HIJKLMNOPQRS
UVWXYZ[\]^_
IJKLMNOPQRS
UVWXYZ[\]^_
SQLite format 3
CREATE TABLE sqlite_master(
type text,
name text,
tbl_name text,
rootpage integer,
sql text
CREATE TEMP TABLE sqlite_temp_master(
type text,
name text,
tbl_name text,
rootpage integer,
sql text
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
******""""""""""""""""""""
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
&&&&&&&&&&
onoffalseyestruefull
0123456789ABCDEF0123456789abcdef
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYWITHOUTERELEASEATTACHAVINGROUPDATEBEGINNERECURSIVEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTRIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
xPq>.T
memory
Function
Savepoint
AutoCommit
Transaction
SorterNext
PrevIfOpen
NextIfOpen
AggStep
Checkpoint
JournalMode
Vacuum
VFilter
VUpdate
Return
InitCoroutine
EndCoroutine
HaltIfNull
Integer
String
SoftNull
Variable
ResultRow
CollSeq
AddImm
MustBeInt
RealAffinity
Permutation
Compare
Column
Affinity
MakeRecord
sqlite_rename_table
ReadCookie
sqlite_rename_trigger
SetCookie
sqlite_rename_parent
ReopenIdx
win32-longpath
OpenRead
OpenWrite
delete
OpenAutoindex
persist
OpenEphemeral
SorterOpen
truncate
SequenceTest
OpenPseudo
SeekLT
SeekLE
SeekGE
SeekGT
NoConflict
NotFound
NotExists
Sequence
NewRowid
Insert
IsNull
NotNull
database schema has changed
InsertInt
BitAnd
ShiftLeft
ShiftRight
Subtract
Multiply
Divide
Remainder
Concat
Delete
BitNot
String8
ResetCount
SorterCompare
SorterData
RowKey
RowData
NullRow
SorterSort
Rewind
SorterInsert
IdxInsert
IdxDelete
IdxRowid
Destroy
ResetSorter
CreateIndex
CreateTable
ParseSchema
LoadAnalysis
DropTable
DropIndex
DropTrigger
IntegrityCk
RowSetAdd
RowSetRead
RowSetTest
Program
FkCounter
FkIfZero
MemMax
IfNotZero
DecrJumpZero
JumpZeroIncr
AggFinal
IncrVacuum
Expire
TableLock
VBegin
VCreate
VDestroy
VColumn
VRename
Pagecount
MaxPgcnt
Explain
julianday
datetime
strftime
current_time
current_timestamp
current_date
AreFileApisANSI
CharLowerW
CharUpperW
CloseHandle
CreateFileA
CreateFileW
CreateFileMappingA
CreateFileMappingW
CreateMutexW
DeleteFileA
DeleteFileW
FileTimeToLocalFileTime
FileTimeToSystemTime
FlushFileBuffers
FormatMessageA
FormatMessageW
FreeLibrary
GetCurrentProcessId
GetDiskFreeSpaceA
GetDiskFreeSpaceW
GetFileAttributesA
GetFileAttributesW
GetFileAttributesExW
GetFileSize
GetFullPathNameA
GetFullPathNameW
GetLastError
GetProcAddressA
GetSystemInfo
GetSystemTime
GetSystemTimeAsFileTime
GetTempPathA
GetTempPathW
GetTickCount
GetVersionExA
GetVersionExW
HeapAlloc
HeapCreate
HeapDestroy
sqlite_stat1
HeapFree
tbl,idx,stat
HeapReAlloc
sqlite_stat3
HeapSize
sqlite_stat4
HeapValidate
HeapCompact
LoadLibraryA
LoadLibraryW
LocalFree
LockFile
LockFileEx
MapViewOfFile
MultiByteToWideChar
QueryPerformanceCounter
ReadFile
SetEndOfFile
SetFilePointer
SystemTimeToFileTime
UnlockFile
UnlockFileEx
UnmapViewOfFile
WideCharToMultiByte
WriteFile
CreateEventExW
WaitForSingleObject
WaitForSingleObjectEx
SetFilePointerEx
GetFileInformationByHandleEx
MapViewOfFileFromApp
CreateFile2
LoadPackagedLibrary
GetTickCount64
GetNativeSystemInfo
OutputDebugStringA
OutputDebugStringW
GetProcessHeap
CreateFileMappingFromApp
InterlockedCompareExchange
UuidCreate
UuidCreateSequential
FlushViewOfFile
stat_init
shared
private
stat_push
stat_get
NOT NULL
UNIQUE
FOREIGN KEY
typeof
length
substr
printf
unicode
coalesce
ifnull
unlikely
likelihood
likely
random
randomblob
nullif
sqlite_version
sqlite_source_id
sqlite_log
sqlite_compileoption_used
sqlite_compileoption_get
UTF-16le
last_insert_rowid
UTF-16be
changes
UTF16le
total_changes
UTF16be
replace
UTF-16
zeroblob
load_extension
group_concat
string or blob too big
ROLLBACK
RELEASE
not an error
SQL logic error or missing database
access permission denied
callback requested query abort
database is locked
database table is locked
attempt to write a readonly database
interrupted
disk I/O error
database disk image is malformed
unknown operation
database or disk is full
unable to open database file
locking protocol
table contains no data
constraint failed
datatype mismatch
library routine called out of sequence
large file support is disabled
authorization denied
auxiliary database format error
bind or column index out of range
file is encrypted or is not a database
sqlite_detach
application_id
auto_vacuum
automatic_index
busy_timeout
cache_size
cache_spill
case_sensitive_like
checkpoint_fullfsync
sqlite_attach
collation_list
compile_options
count_changes
data_store_directory
data_version
database_list
SYSTEM_MALLOC
default_cache_size
THREADSAFE=1
defer_foreign_keys
empty_result_callbacks
encoding
foreign_key_check
foreign_key_list
foreign_keys
freelist_count
full_column_names
fullfsync
ignore_check_constraints
incremental_vacuum
index_info
index_list
index_xinfo
integrity_check
journal_mode
journal_size_limit
legacy_file_format
locking_mode
max_page_count
mmap_size
page_count
page_size
query_only
quick_check
read_uncommitted
recursive_triggers
reverse_unordered_selects
schema_version
secure_delete
short_column_names
shrink_memory
opcode
soft_heap_limit
synchronous
table_info
temp_store
temp_store_directory
comment
threads
selectid
user_version
wal_autocheckpoint
detail
wal_checkpoint
writable_schema
out of memory
SQLITE_
local time unavailable
localtime
unixepoch
weekday
start of
minute
second
%04d-%02d-%02d %02d:%02d:%02d
%02d:%02d:%02d
%04d-%02d-%02d
%06.3f
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
(NULL)
922337203685477580
API call with %s database connection pointer
unopened
invalid
OsError 0x%lx (%lu)
os_win.c:%d: (%lu) %s(%s) - %s
delayed %dms for lock/sharing conflict at line %d
winSeekFile
winClose
winRead
winWrite1
winWrite2
winTruncate1
winTruncate2
winSync1
winSync2
winFileSize
winUnlockReadLock
winUnlock
%s-shm
winOpenShm
winShmMap1
winShmMap2
winShmMap3
winUnmapfile1
winUnmapfile2
winMapfile1
winMapfile2
etilqs_
winGetTempname1
winGetTempname2
winGetTempname3
winGetTempname4
winGetTempname5
winOpen
winDelete
winAccess
%s%c%s
winFullPathname1
winFullPathname2
winFullPathname3
winFullPathname4
recovered %d pages from %s
-journal
nolock
immutable
recovered %d frames from WAL file %s
cannot limit WAL size: %s
:memory:
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
Rowid %lld out of order (previous was %lld)
Child page depth differs
On page %d at right child:
Rowid %lld out of order (max larger than parent min of %lld)
Rowid %lld out of order (min less than parent min of %lld)
Rowid %lld out of order (max larger than parent max of %lld)
Rowid %lld out of order (min less than parent max of %lld)
Corruption detected in cell %d on page %d
Multiple uses for byte %u of page %d
Fragmentation of %d bytes reported as %d on page %d
Main freelist:
List of tree roots:
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
destination database is in use
source and destination must be distinct
%!.15g
BINARY
(%.20s)
%s(%d)
(blob)
vtab:%p
intarray
program
%s-mjXXXXXX9XXz
MJ delete: %s
MJ collide: %s
-mj%06X9%02X
FOREIGN KEY constraint failed
API called with finalized prepared statement
API called with NULL prepared statement
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
'%.*q'
zeroblob(%d)
abort at %d in [%s]: %s
%s constraint failed: %s
%s constraint failed
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot release savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
cannot start a transaction within a transaction
cannot rollback - no transaction is active
cannot commit - no transaction is active
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
too many levels of trigger recursion
out of
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
integer
cannot open value of type %s
no such rowid: %lld
cannot open virtual table: %s
cannot open table without rowid: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
no such column
ambiguous column name
%s: %s.%s.%s
%s: %s.%s
%s: %s
%s prohibited in partial index WHERE clauses
%s prohibited in CHECK constraints
functions
second argument to likelihood() must be a constant between 0.0 and 1.0
not authorized to use function: %s
misuse of aggregate function %.*s()
no such function: %.*s
wrong number of arguments to function %.*s()
subqueries
parameters
%r %s BY term out of range - should be between 1 and %d
too many terms in ORDER BY clause
%r ORDER BY term does not match any column in the result set
too many terms in %s BY clause
a GROUP BY clause is required before HAVING
aggregate functions are not allowed in the GROUP BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
_ROWID_
SCALAR
CORRELATED
EXECUTE %s%s SUBQUERY %d
hex literal too big: %s
misuse of aggregate: %s()
unknown function: %.*s()
RAISE() may only be used within a trigger-program
%.*s"%w"%s
%s%.*s"%w"
name=%Q
%s OR name=%Q
type='trigger' AND (%s)
tbl_name=%Q
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
Cannot add a UNIQUE column
Cannot add a REFERENCES column with non-NULL default value
Cannot add a NOT NULL column with default value NULL
Cannot add a column with non-constant default
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
virtual tables may not be altered
Cannot add a column to a view
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
unordered*
sz=[0-9]*
noskipscan*
SELECT tbl,idx,stat FROM %Q.sqlite_stat1
too many attached databases - max %d
cannot ATTACH database within transaction
database %s is already in use
database is already attached
attached databases must use the same text encoding as main database
unable to open database: %s
no such database: %s
cannot detach database %s
cannot DETACH database within transaction
database %s is locked
%s %T cannot reference objects in database %s
%s cannot use variables
authorizer malfunction
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
not authorized
no such view
no such table
corrupt database
unknown database %T
object name reserved for internal use: %s
temporary table name must be unqualified
table %T already exists
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
INTEGER
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
CREATE TABLE
AUTOINCREMENT not allowed on WITHOUT ROWID tables
PRIMARY KEY missing on table %s
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
tbl_name='%q' AND type!='trigger'
parameters are not allowed in views
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
sqlite_stat%d
DELETE FROM %Q.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
sqlite_stat
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
cannot create a TEMP index on non-TEMP table "%s"
altertab_
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
conflicting ON CONFLICT clauses specified
UNIQUE
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
name='%q' AND type='index'
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
a JOIN clause is required before %s
COMMIT
unable to open a temporary database file for storing temporary tables
%s.rowid
unable to identify the object to be reindexed
duplicate WITH table name: %s
no such collation sequence: %s
table %s may not be modified
cannot modify %s because it is a view
rows deleted
integer overflow
LIKE or GLOB pattern too complex
ESCAPE expression must be a single character
%!.20e
foreign key mismatch - "%w" referencing "%w"
table %S has no column named %s
table %S has %d columns but %d values were supplied
%d values for %d columns
rows inserted
sqlite3_extension_init
unable to open shared library [%s]
sqlite3_
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
exclusive
normal
incremental
temporary storage cannot be changed from within a transaction
SET NULL
SET DEFAULT
CASCADE
RESTRICT
NO ACTION
result
not a writable directory
Safety level may not be changed inside a transaction
notnull
dflt_value
height
unique
origin
partial
on_update
on_delete
parent
*** in database %s ***
NULL value in %s.%s
missing from index
non-unique entry in index
wrong # of entries in index
unsupported encoding: %s
compile_option
restart
checkpointed
timeout
malformed database schema (%s)
%s - %s
create
invalid rootpage
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
statement too long
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
only a single result allowed for a SELECT that is part of an expression
UNION ALL
INTERSECT
EXCEPT
USE TEMP B-TREE FOR %s
USING TEMP B-TREE
COMPOUND SUBQUERIES %d AND %d %s(%s)
column%d
all VALUES must have the same number of terms
SELECTs to the left and right of %s do not have the same number of result columns
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
no such index: %s
multiple references to recursive table: %s
circular reference: %s
table %s has %d values for %d columns
multiple recursive references: %s
recursive reference in a subquery: %s
sqlite_sq_%p
too many references to "%s": max 65535
%s.%s.%s
no such table: %s
no tables specified
too many columns in result set
DISTINCT aggregates must have exactly one argument
USING COVERING INDEX
SCAN TABLE %s%s%s
DISTINCT
GROUP BY
RIGHT PART OF ORDER BY
ORDER BY
sqlite3_get_table() called with two or more incompatible queries
temporary trigger may not have qualified name
trigger
cannot create triggers on virtual tables
trigger %T already exists
cannot create trigger on system table
BEFORE
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
type='trigger' AND name='%q'
no such trigger: %S
-- TRIGGER %s
no such column: %s
rows updated
_rowid_
cannot VACUUM from within a transaction
cannot VACUUM - SQL statements in progress
ATTACH ':memory:' AS vacuum_db;
ATTACH '' AS vacuum_db;
PRAGMA vacuum_db.synchronous=OFF
BEGIN;
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
CREATE VIRTUAL TABLE %T
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
name='%q' AND type='table'
vtable constructor called recursively: %s
vtable constructor failed: %s
vtable constructor did not declare schema: %s
hidden
hidden
no such module: %s
NOCASE
automatic index on %s(%s)
auto-index
table %s: xBestIndex returned an invalid plan
ANY(%s)
SEARCH
SUBQUERY %d
TABLE %s
AS %s
PRIMARY KEY
AUTOMATIC PARTIAL COVERING INDEX
AUTOMATIC COVERING INDEX
COVERING INDEX %s
INDEX %s
USING
(rowid=?)
(rowid>? AND rowid<?)
(rowid>?)
(rowid<?)
USING INTEGER PRIMARY KEY
VIRTUAL TABLE INDEX %d:%s
%s.xBestIndex() malfunction
no query solution
at most %d tables in a join
too many terms in compound SELECT
parser stack overflow
unknown table option: %.*s
set list
near "%T": syntax error
too many arguments on function %T
qualified table names are not allowed on INSERT, UPDATE, and DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
interrupt
unrecognized token: "%T"
create
temporary
explain
2015-05-20 18:17:19 2ef4f3a5b1d1d0c4338f8243d40a2452cc1f7fe4
unable to close due to unfinalized statements or unfinished backups
abort due to ROLLBACK
unable to delete/modify user-function due to active statements
unknown database: %s
unable to delete/modify collation sequence due to active statements
localhost
invalid uri authority: %.*s
access
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
no such table column: %s.%s
>@aTR'
M@fffff
SELECT * FROM Win32_OperatingSystem
bad allocation
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefABCDEF
Access violation - no RTTI data!
Bad dynamic_cast!
Unknown exception
RoInitialize
RoUninitialize
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetFileInformationByHandleExW
SetFileInformationByHandleW
CorExitProcess
_hypot
_nextafter
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LE
UNICODE
(null)
`h````
xpxxxx
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
`h`hhh
xppwpp
1#SNAN
1#QNAN
lstrcatA
lstrlenA
GetFileAttributesA
GetProcAddress
OpenProcess
TerminateProcess
CloseHandle
LoadLibraryA
GetPrivateProfileStringA
GetPrivateProfileSectionNamesA
MultiByteToWideChar
WideCharToMultiByte
CreateToolhelp32Snapshot
Process32First
Process32Next
CreateThread
TerminateThread
ResumeThread
GetModuleHandleW
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
CreateEventW
GlobalLock
GlobalUnlock
GetLocalTime
CreateDirectoryW
Process32FirstW
Process32NextW
GlobalMemoryStatusEx
GetSystemInfo
GetNativeSystemInfo
LoadLibraryW
GetTempPathW
IsWow64Process
GetLocaleInfoW
CreateProcessW
GetFileSize
WriteFile
ReadFile
GetSystemDirectoryA
CreateFileA
SetFileAttributesA
lstrcmpW
lstrlenW
GetModuleFileNameW
GetTempFileNameW
RemoveDirectoryW
SetFileAttributesW
GetFileAttributesW
DeleteFileW
CopyFileW
MoveFileW
MoveFileExW
GetCurrentProcessId
GetVersionExW
GetExitCodeProcess
CreatePipe
PeekNamedPipe
GetStartupInfoW
DeleteFileA
AreFileApisANSI
GetSystemTime
LocalFree
GetTempPathA
GetVersionExA
OutputDebugStringA
GetFileAttributesExW
GetDiskFreeSpaceA
CreateFileMappingW
CreateFileMappingA
GetDiskFreeSpaceW
LockFileEx
HeapSize
GetLastError
FlushFileBuffers
CreateFileW
HeapValidate
HeapCreate
HeapDestroy
FormatMessageW
FormatMessageA
GetSystemTimeAsFileTime
GetProcessHeap
UnlockFileEx
GetTickCount
OutputDebugStringW
WaitForSingleObjectEx
LockFile
FlushViewOfFile
UnlockFile
InterlockedCompareExchange
WaitForSingleObject
HeapFree
QueryPerformanceCounter
SystemTimeToFileTime
HeapAlloc
FreeLibrary
SetEndOfFile
UnmapViewOfFile
MapViewOfFile
SetFilePointer
HeapCompact
CreateMutexW
HeapReAlloc
GetFullPathNameA
GetFullPathNameW
GetCurrentThreadId
TryEnterCriticalSection
GetCurrentProcess
SetErrorMode
GetCommandLineW
GetCurrentDirectoryW
SetSystemPowerState
OpenMutexW
GlobalAlloc
GlobalFree
InterlockedDecrement
lstrcpyW
GetComputerNameW
GetLogicalDrives
GetFileSizeEx
FindClose
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetDriveTypeW
GetDiskFreeSpaceExW
FindFirstFileW
FindNextFileW
KERNEL32.dll
GetMessageW
TranslateMessage
DispatchMessageW
SendMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
ShowWindow
FlashWindowEx
UpdateWindow
SetWindowTextW
GetWindowTextW
GetWindowTextLengthW
LoadCursorW
LoadIconW
wsprintfW
OpenClipboard
CloseClipboard
GetClipboardData
GetForegroundWindow
GetWindowThreadProcessId
ToUnicodeEx
GetKeyboardLayout
GetKeyboardState
CharUpperW
GetKeyState
SetWindowsHookExW
UnhookWindowsHookEx
CallNextHookEx
ExitWindowsEx
GetLastInputInfo
GetWindowRect
GetDesktopWindow
SendInput
GetSystemMetrics
ReleaseDC
GetClientRect
SetCursorPos
EnumDisplaySettingsW
EnumDisplayDevicesW
USER32.dll
CreateFontW
GetStockObject
SetBkColor
SetTextColor
CreateCompatibleBitmap
CreateCompatibleDC
DeleteObject
GetDIBits
SelectObject
StretchBlt
SetStretchBltMode
GetObjectW
GDI32.dll
RegCloseKey
RegQueryValueExA
RegOpenKeyExA
GetUserNameW
RegOpenKeyExW
RegQueryValueExW
RegCreateKeyW
RegDeleteValueW
RegSetValueExW
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueW
ADVAPI32.dll
SHGetFolderPathA
SHGetKnownFolderPath
ShellExecuteW
SHGetFolderPathW
CommandLineToArgvW
SHFileOperationW
SHGetFileInfoW
SHELL32.dll
CoUninitialize
CoInitializeEx
CoInitializeSecurity
CoSetProxyBlanket
CoCreateInstance
CoInitialize
CoTaskMemFree
ole32.dll
OLEAUT32.dll
SHGetValueA
SHLWAPI.dll
CryptUnprotectData
CryptStringToBinaryA
CRYPT32.dll
NetUserEnum
NetApiBufferFree
NETAPI32.dll
URLDownloadToFileW
urlmon.dll
GdipAlloc
GdipFree
GdipCloneImage
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipGetImagePixelFormat
GdipCreateBitmapFromStream
GdipBitmapLockBits
GdipBitmapUnlockBits
GdipGetImageEncodersSize
GdipGetImageEncoders
GdiplusStartup
GdiplusShutdown
GdipSaveImageToStream
GdipCreateBitmapFromGdiDib
gdiplus.dll
GetAddrInfoW
FreeAddrInfoW
inet_pton
inet_ntop
WS2_32.dll
GetModuleFileNameExW
GetModuleBaseNameW
PSAPI.DLL
SetSuspendState
POWRPROF.dll
InitCommonControlsEx
COMCTL32.dll
EncodePointer
DecodePointer
GetStringTypeW
RaiseException
RtlUnwind
IsDebuggerPresent
IsProcessorFeaturePresent
ExitThread
LoadLibraryExW
GetCommandLineA
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
ExitProcess
GetModuleHandleExW
IsValidCodePage
GetACP
GetOEMCP
GetStdHandle
SetEnvironmentVariableA
SetEnvironmentVariableW
GetConsoleMode
ReadConsoleW
SetFilePointerEx
GetFileType
GetConsoleCP
GetTimeZoneInformation
GetModuleFileNameA
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
WriteConsoleW
GetDiskFreeSpaceExW
Offline
Online
sckRelay
bss_server.usrRelay
Configuracoes
SETTINGS
MyApplication
ParadoxRAT_Client
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
!This program cannot be run in DOS mode.
Richq
`.rdata
@.data
@.reloc
QQSVWd
~pjCXf
jdhH;A
j@j _W
<v5hbiA
HtHu4j
,SVWj0X
Wj0XPV
PWWWWV
PSSSSV
URPQQh`
jA[jZZ+
r=H^A
VVhd+A
tO9=PqA
;t$,v-
UQPXY]Y[
PP9E u
+tHHt
+t"HHt
HAO8t
Ht+Ht$Ht
HtHHt
~';_t|%3
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.361706
FireEye Generic.mg.1f67cc3aee307cde
CAT-QuickHeal Backdoor.Dodiw.A5
McAfee BackDoor-FCXS!1F67CC3AEE30
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Gen:Variant.Zusy.361706
K7GW Riskware ( 0040eff71 )
CrowdStrike win/malicious_confidence_80% (D)
BitDefenderTheta Gen:NN.ZexaF.34218.TuW@aifT5qbi
Cyren W32/S-ad8de17d!Eldorado
ESET-NOD32 Win32/Spy.Agent.OSD
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Trojan.Agent-1323921
Kaspersky Trojan.Win32.Fsysna.cewh
Alibaba Clean
NANO-Antivirus Trojan.Win32.Dodiw.duviir
ViRobot Trojan.Win32.Agent.794624.L
Rising Spyware.Agent!1.AD22 (CLASSIC)
Ad-Aware Gen:Variant.Zusy.361706
Sophos Troj/Agent-BAGZ
Comodo Clean
F-Secure Clean
DrWeb Trojan.WebPick.8684
Zillya Trojan.Agent.Win32.560290
TrendMicro BKDR_DODIW.SM
McAfee-GW-Edition BehavesLike.Win32.BrowseFox.bh
CMC Clean
Emsisoft Gen:Variant.Zusy.361706 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Zusy.361706
Jiangmin Trojan/Generic.bhnec
Webroot W32.Trojan.Gen
Avira TR/AD.BabylonRAT.uqiib
MAX malware (ai score=85)
Antiy-AVL Trojan/Generic.ASMalwS.131BB0E
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Ransom.Cradle/Variant
ZoneAlarm Trojan.Win32.Fsysna.cewh
Microsoft Backdoor:Win32/Dodiw.A
Cynet Malicious (score: 99)
AhnLab-V3 Backdoor/Win32.Dodiw.R197218
Acronis Clean
VBA32 Trojan.Fsysna
ALYac Gen:Variant.Zusy.361706
TACHYON Trojan/W32.Fsysna.750592
Malwarebytes Spyware.PasswordStealer
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall BKDR_DODIW.SM
Tencent Malware.Win32.Gencirc.10b147b4
Yandex Trojan.GenAsa!qQ7637zty1s
Ikarus Backdoor.Win32.Dodiw
eGambit Unsafe.AI_Score_100%
Fortinet W32/Agent.OSD!tr
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.