Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

4afbc3ea79152c3f8469f1157ab7e53a

PEiD Signatures

BobSoft Mini Delphi -> BoB / BobSoft

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x00025958 0x00025a00 6.49425025835
DATA 0x00027000 0x00001f14 0x00002000 3.26566508162
BSS 0x00029000 0x00000911 0x00000000 0.0
.idata 0x0002a000 0x00001176 0x00001200 4.8147885162
.tls 0x0002c000 0x00000008 0x00000000 0.0
.rdata 0x0002d000 0x00000018 0x00000200 0.199107517787
.reloc 0x0002e000 0x000021d4 0x00002200 6.7435526146
.rsrc 0x00031000 0x00001ba8 0x00001c00 4.23305614485

Resources

Name Offset Size Language Sub-language File type
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00031aec 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031dbc 0x00000174 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031dbc 0x00000174 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00032398 0x00000334 LANG_HEBREW SUBLANG_DEFAULT data
RT_VERSION 0x00032398 0x00000334 LANG_HEBREW SUBLANG_DEFAULT data
RT_MANIFEST 0x000326cc 0x000004db LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library kernel32.dll:
0x42a114 VirtualFree
0x42a118 VirtualAlloc
0x42a11c LocalFree
0x42a120 LocalAlloc
0x42a124 GetTickCount
0x42a12c GetVersion
0x42a130 GetCurrentThreadId
0x42a134 WideCharToMultiByte
0x42a138 lstrlenA
0x42a13c lstrcpynA
0x42a140 LoadLibraryExA
0x42a144 GetThreadLocale
0x42a148 GetStartupInfoA
0x42a14c GetProcAddress
0x42a150 GetModuleHandleA
0x42a154 GetModuleFileNameA
0x42a158 GetLocaleInfoA
0x42a15c GetLastError
0x42a160 GetCommandLineA
0x42a164 FreeLibrary
0x42a168 FindFirstFileA
0x42a16c FindClose
0x42a170 ExitProcess
0x42a174 WriteFile
0x42a17c SetFilePointer
0x42a180 SetEndOfFile
0x42a184 RtlUnwind
0x42a188 ReadFile
0x42a18c RaiseException
0x42a190 GetStdHandle
0x42a194 GetFileSize
0x42a198 GetFileType
0x42a19c CreateFileA
0x42a1a0 CloseHandle
Library user32.dll:
0x42a1a8 GetKeyboardType
0x42a1ac LoadStringA
0x42a1b0 MessageBoxA
0x42a1b4 CharNextA
Library advapi32.dll:
0x42a1bc RegQueryValueExA
0x42a1c0 RegOpenKeyExA
0x42a1c4 RegCloseKey
Library oleaut32.dll:
0x42a1cc SysFreeString
0x42a1d0 SysAllocStringLen
Library kernel32.dll:
0x42a1d8 TlsSetValue
0x42a1dc TlsGetValue
0x42a1e0 LocalAlloc
0x42a1e4 GetModuleHandleA
Library advapi32.dll:
0x42a1ec RegQueryValueExA
0x42a1f0 RegOpenKeyExA
0x42a1f4 RegCloseKey
0x42a1f8 LookupAccountNameA
0x42a1fc GetUserNameA
Library kernel32.dll:
0x42a208 WriteFile
0x42a20c WinExec
0x42a210 VirtualQuery
0x42a214 TerminateProcess
0x42a218 SetFileTime
0x42a21c SetFilePointer
0x42a220 SetFileAttributesA
0x42a224 SetErrorMode
0x42a22c RemoveDirectoryA
0x42a230 ReadFile
0x42a234 OpenProcess
0x42a238 MulDiv
0x42a23c MoveFileA
0x42a244 LoadLibraryA
0x42a24c IsDBCSLeadByte
0x42a254 GlobalFindAtomA
0x42a258 GlobalDeleteAtom
0x42a25c GlobalAddAtomA
0x42a264 GetVersionExA
0x42a268 GetTickCount
0x42a26c GetThreadLocale
0x42a270 GetTempPathA
0x42a274 GetSystemDirectoryA
0x42a278 GetStringTypeExA
0x42a27c GetStdHandle
0x42a280 GetShortPathNameA
0x42a284 GetProcAddress
0x42a28c GetModuleHandleA
0x42a290 GetModuleFileNameA
0x42a294 GetLocaleInfoA
0x42a298 GetLocalTime
0x42a29c GetLastError
0x42a2a0 GetFullPathNameA
0x42a2a4 GetFileSize
0x42a2a8 GetFileAttributesA
0x42a2ac GetExitCodeProcess
0x42a2b4 GetDriveTypeA
0x42a2b8 GetDiskFreeSpaceA
0x42a2bc GetDateFormatA
0x42a2c0 GetCurrentThreadId
0x42a2c4 GetCurrentProcessId
0x42a2c8 GetComputerNameA
0x42a2cc GetCPInfo
0x42a2d0 GetACP
0x42a2d4 FreeLibrary
0x42a2d8 FormatMessageA
0x42a2dc FindNextFileA
0x42a2e0 FindFirstFileA
0x42a2e4 FindClose
0x42a2f0 EnumCalendarInfoA
0x42a2fc DeviceIoControl
0x42a300 DeleteFileA
0x42a304 CreateProcessA
0x42a308 CreateFileA
0x42a30c CreateDirectoryA
0x42a310 CopyFileA
0x42a314 CloseHandle
Library gdi32.dll:
0x42a31c SelectObject
0x42a320 MoveToEx
0x42a324 LineTo
0x42a328 GetTextMetricsA
0x42a330 GetDeviceCaps
0x42a334 DeleteObject
0x42a338 CreateSolidBrush
0x42a33c CreatePen
0x42a340 CreateFontA
Library user32.dll:
0x42a348 CreateWindowExA
0x42a34c UnregisterClassA
0x42a350 TranslateMessage
0x42a358 ShowWindow
0x42a35c SetWindowPos
0x42a360 SetWindowLongA
0x42a364 SetTimer
0x42a368 SetFocus
0x42a36c SetActiveWindow
0x42a370 SendMessageA
0x42a374 ReleaseDC
0x42a37c RegisterClassA
0x42a380 PostQuitMessage
0x42a384 PostMessageA
0x42a388 PeekMessageA
0x42a38c MessageBoxA
0x42a390 LoadStringA
0x42a394 LoadIconA
0x42a398 LoadCursorA
0x42a39c KillTimer
0x42a3a0 IsWindowVisible
0x42a3a8 GetWindowTextA
0x42a3ac GetWindowRect
0x42a3b0 GetWindowLongA
0x42a3b4 GetSystemMetrics
0x42a3b8 GetSystemMenu
0x42a3bc GetSysColor
0x42a3c0 GetWindow
0x42a3c4 GetMessageA
0x42a3c8 GetFocus
0x42a3cc GetDesktopWindow
0x42a3d0 GetDC
0x42a3d4 GetClientRect
0x42a3d8 GetActiveWindow
0x42a3dc FindWindowA
0x42a3e0 FillRect
0x42a3e4 EnumWindows
0x42a3e8 EndPaint
0x42a3ec EnableWindow
0x42a3f0 EnableMenuItem
0x42a3f4 DrawIcon
0x42a3f8 DispatchMessageA
0x42a3fc DefWindowProcA
0x42a400 BeginPaint
0x42a404 CharNextA
0x42a408 CharToOemA
Library kernel32.dll:
0x42a410 Sleep
Library shell32.dll:
0x42a418 ShellExecuteA
Library comctl32.dll:
0x42a420 InitCommonControls

This program must be run under Win32
TKRIOHZGXPTIMWNDDADPCTCFNFGLVJJQWYKQJINBMRWRVNRZLNRTJPMVMPEMFMWY
.idata
.rdata
P.reloc
P.rsrc
StringX
TObject
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
C<"u1S
Q<"u8S
Ht Ht.
~KxI[)
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
ZTUWVSPRTj
tVSVWU
t@h R@
kernel32.dll
GetLongPathNameA
Software\Borland\Locales
Software\Borland\Delphi\Locales
_^[YY]
TFileName
TSearchRecX
Exception
EHeapException
EOutOfMemory
EInOutError
EExternal
EExternalException
EIntError
EDivByZero
ERangeError
EIntOverflow
EMathError
EInvalidOp
EZeroDivide
EOverflow
EUnderflow
EInvalidPointer
EInvalidCast
EConvertError
EAccessViolation
EPrivilege
EStackOverflow
EControlC
EVariantError
EAssertionFailed
EAbstractError
EIntfCastError
ESafecallException
SysUtils
SysUtils
_^[YY]
<*t"<0r=<9w9i
INFNAN
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
_^[YY]
_^[YY]
$YZ_^[
t%HtIHtm
QQQQQQSVW3
QQQQQSVW
_^[YY]
TErrorRec
TExceptRec
m/d/yy
mmmm d, yyyy
:mm:ss
kernel32.dll
GetDiskFreeSpaceExA
_^[YY]
GetDiskFreeSpaceExA
kernel32.dll
_DEL_ME_.BAT
:START
IF exist
GOTO START
QQQQQQQSVW
EjectCD-2:
EjectCD-3:
kernel32.dll
CreateToolhelp32Snapshot
Heap32ListFirst
Heap32ListNext
Heap32First
Heap32Next
Toolhelp32ReadProcessMemory
Process32First
Process32Next
Process32FirstW
Process32NextW
Thread32First
Thread32Next
Module32First
Module32Next
Module32FirstW
Module32NextW
PSAPI.dll
EnumProcesses
EnumProcessModules
GetModuleBaseNameA
GetModuleFileNameExA
GetModuleBaseNameW
GetModuleFileNameExW
GetModuleInformation
EmptyWorkingSet
QueryWorkingSet
InitializeProcessForWsWatch
GetMappedFileNameA
GetDeviceDriverBaseNameA
GetDeviceDriverFileNameA
GetMappedFileNameW
GetDeviceDriverBaseNameW
GetDeviceDriverFileNameW
EnumDeviceDrivers
GetProcessMemoryInfo
_^[YY]
TAnalizer
_^[YY]
_^[YY]
shell32.dll
USP10.dll
MSLS31.dll
RICHED32.DLL
|^!~@#$&*
QQQQQQS
QQQQQS
QueryCancelAutoPlay
|Error|Attention|Confirm|
</b><P><P>
|&OK|&Cancel|&Yes|&No|&Abort|&Retry|&Ignore|
|Error|Attention|Confirm|
QQQQQQS
_^[YY]
QQQQQS
||JAN|FEB|MAR|APR|MAY|JUN|JUL|AUG|SEP|OCT|NOV|DEC|
HH:NN:SS
dd/mm/yy HH:NN:SS
Workstation
Server
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
EXCEPTION --- Utils.ReadIniString()
Scrambled=01
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Windows NT
Windows
RegisteredOwner
RegisteredOrganization
Error Reading "SysUtils.SysErrorMessage(GetLastError)"
QMsgBox
Tahoma
MainIcon
MS PGothic
RICHEDIT
Button
QQQQQSVW
RICHED32.DLL
Do you want to store the new Entry in
uhx,A
RICHED32.DLL
EZLibError
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
S0;S(t!
S0;S(t!
C0;C4t8
C4;C0s
L$ #T$
L$ +l$
L$ #T$
T$ +l$
S0;S(t
C(;C0s
C4;C0s
K0;K(t
C(;C0s
K0;K(t
C(;C0s
C4;C0s
K0;K(t
C(;C0s
C4;C0s
K0;K4t.
~0;~4w
.Q_DebugMsg.
.QDebug.
<TITLE
</TITLE>
<HTML>
<HEAD>
<TITLE>
<B>404 File Not Found...</B><P><P>URL:
<P><P>Please make sure the file is available and access is allowed to this file.
<P><P>If you are using an IIS webserver you must define appropriate MIME-Types.
QQQQSVW
|AFRIKAANS = 54|ALBANIAN = 28|ARABIC = 01|BASQUE = 45|BELARUSIAN = 35|BULGARIAN = 02|CATALAN = 03|CHINESE = 04|CROATIAN = 26|CZECH = 05|DANISH = 06|DUTCH = 19|ENGLISH = 09|ESTONIAN = 37|FAEROESE = 56|FARSI = 41|FINNISH = 11|FRENCH = 12|GERMAN = 07|GREEK = 08|HEBREW = 13|HUNGARIAN = 14|ICELANDIC = 15|INDONESIAN = 33|ITALIAN = 16|JAPANESE = 17|KOREAN = 18|LATVIAN = 38|LITHUANIAN = 39|NORWEGIAN = 20|POLISH = 21|PORTUGUESE = 22|ROMANIAN = 24|RUSSIAN = 25|SERBIAN = 26|SLOVAK = 27|SLOVENIAN = 36|SPANISH = 10|SWEDISH = 29|THAI = 30|TURKISH = 31|UKRAINIAN = 34|VIETNAMESE = 42|CHINESE(SIMPLIFIED) = 2052|CHINESE(TRADITIONAL) = 1028|DUTCH(FLEMISH) = 2067|DUTCH(STANDARD) = 1043|PORTUGUESE(PORTUGAL) = 2070|PORTUGUESE(BRAZIL) = 1046|SERBIAN(LATIN) = 2074|SERBIAN(CYRILIC) = 3098|
TGFileInfo
_^[YY]
.original
English
Charset
FontSize
Tahoma
FontName
English
QSetup.language.ini
STRINGS
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\
RunTimeDir (<?>)<P><P>Not Found!
RunTimeDir_01
SHGetSpecialFolderPathA
shell32.dll
SHGetFolderPathA
SHFolder.dll
Profiles\
QQQQQSV
Application Data
Application Data
Application Data
My Documents
Documents
Start Menu
Start Menu
Start Menu
\Programs
Start Menu
\Programs
Desktop
Desktop
System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
/OriginExe=
ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Start Menu
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
dd/mmmm/yyyy
dd-mm-yy
mm-dd-yy
yy-mm-dd
dd-mm-yyyy
mm-dd-yyyy
yyyy-mm-dd
yyyy-mm-dd hh:nn:ss
<Date=
QQQQQSVW
<ServiceDir>
<Date=
<LoggedUserName>
<UserName>
<CompanyName>
<ComputerName>
<CurrentDomainName>
<LastExecutableExitCode>
UserName
<EnteredUserName>
CompanyName
<EnteredCompanyName>
SerialNum
<EnteredSerialNum>
EnteredStartProgramMenu
<EnteredStartProgramMenu>
VendorCompanyName
<VendorCompanyName>
ProjectName
<ProjectName>
ProgramDescriptiveName
<ProgramDescriptiveName>
ProgramVersion
<ProgramVersion>
SelectedLanguage
<SelectedLanguage>
UnInstallExePath
<UnInstallExePath>
<RunTimeDir_
<RunTimeDir_%d>
<Application Folder>
<Common Folder>
<Auxiliary Folder>
<Windows Directory>
<System Directory>
<System16 Directory>
<InstallDir>
<InstallCommonDir>
<InstallAuxDir>
<AbsoluteDir>
<WinDir>
<WinSysDir>
<WinSys32Dir>
<WinSys16Dir>
<InstallDrive>
<WinDrive>
<WinSysDrive>
<OriginDrive>
<InstallDisk>
<WinDisk>
<WinSysDisk>
<OriginDisk>
<StartMenuDir>
<ProgramFilesDir>
<CommonFilesDir>
<FontDir>
<SrcDir>
<OriginDir>
<TempDir>
<UserDir>
<UserAppDataDir>
<UserLocalAppDataDir>
<MyDocumentsDir>
<UserStartMenuDir>
<UserStartProgramMenuDir>
<UserDesktopDir>
<DocumentsAndSettingsDir>
<AllUsersDir>
<AllUsersAppDataDir>
<AllUsersDocumentsDir>
<AllUsersStartMenuDir>
<AllUsersStartProgramMenuDir>
<AllUsersDesktopDir>
Data Size: <T>
Bytes<P>
File Size: <T>
Bytes Free: <T>
Bytes
FileInfo.FilesCount=
FileLen=
<P><P>Unable to create Directory!<P><P>
<P><P>Unable to save Extracted File!<P><P>
.exe.001
New AU-Agent:
<DISK_NUM>
UnCompressTime:
_^[YY]
SETUP_
\~aa.tmp
:\TEMP
ProbeSecondsInterval
OriginalSetup
ProbeSecondsLast
OriginalSetup
ReAskSecondsInterval
OriginalSetup
ReAskSecondsLast
OriginalSetup
VersionOriginal
OriginalSetup
OriginalSetup
TargetDir
Directories
SharedDir
Directories
AuxiliaryDir
Directories
StartUpLink
UnInstall
CheckforNewUpdateLink
UnInstall
ProgramName
OriginalSetup
|&OK|&Cancel|&Yes|&No|&Abort|&Retry|&Ignore|
BtnText
MsgBox
MsgBox
Confirm
MsgBox
Attention
MsgBox
CharSet
MsgBox
Tahoma
FontName
MsgBox
FontSize
MsgBox
AutoUpdate
ProbeSecondsInterval
OriginalSetup
ProbeSecondsLast
OriginalSetup
__ProbeSecondsLast
ReAskSecondsInterval
OriginalSetup
ReAskSecondsLast
OriginalSetup
__ReAskSecondsLast
VersionOriginal
OriginalSetup
OriginalSetup
QQQQQQQQS
DownloadURL_UPDATE
NewSetup
NameOfUpdateFile
NewSetup
SizeOfUpdateFile
NewSetup
RequestConfirmationBeforeDownload
NewSetup
RequestConfirmationBeforeDownloadForce
NewSetup
RequestConfirmationBeforeInstall
NewSetup
RequestConfirmationBeforeInstallForce
NewSetup
BackgroundUpdate
NewSetup
ShutDownMethod
NewSetup
RestartProcess
NewSetup
InformFinish
NewSetup
RunningProcess
NewSetup
ProgramName
NewSetup
VersionNew
NewSetup
NewSetup
ValidVersions
NewSetup
RemoveStartUpShortcut
NewSetup
RemoveCheckForNewUpdateShortcut
NewSetup
AutoInform
General
DownloadURL_INFORM
AutoInform
NameOfInformFile
AutoInform
SizeOfInformFile
AutoInform
AutoInformW
AutoInform
AutoInformH
AutoInform
PayingProCustomerOK=FALSE
InternetGetConnectedState
WinINet.dll
InternetCloseHandle
WinINet.dll
InternetOpenA
WinINet.dll
InternetOpenUrlA
WinINet.dll
HttpQueryInfoA
WinINet.dll
InternetReadFile
WinINet.dll
InternetSetFilePointer
WinINet.dll
HTTP_Connect_2
HTTP_Connect_2
HTTP_GetFileSize=
Bytes
KB/Sec
HTTP_Connect_3
Unable to initialize "WinINet.dll"
Unable to open Internet Connection <P>URL:
HTTP_DownloadFile_Incremental FileSize=
<P><P>File Not Found !
Download Aborted
HTTP_DownloadFile_Incremental:
ForcePrompt
HKEY_CURRENT_USER\Software\Pantaray\QSetup\SpanDisk
QSetup will extract files to your Temp Drive (<DRIVE>)<P>
Limited Free Space on your Temp Drive! (<DRIVE>)<P>
<P>Estimated space required on your Temp drive is: <T> <SPACE_REQ> MB<P>
Free space available on your Temp drive is: <T> <SPACE_AVAIL> MB<P>
<P>Continue with Setup?<P>
<DRIVE>
<SPACE_REQ>
<SPACE_AVAIL>
|&OK|&Cancel|&Yes|&No|&Abort|&Retry|&Ignore|
BtnText
Confirm
Extracting Files...
========= ForegroundOp=
==========
Please insert <B>DISK #<DISK_NUM></B> and press OK to continue
Attention
|&OK|&Cancel|&Yes|&No|&Abort|&Retry|&Ignore|
BtnText
/TH_ID=
/OriginExe=
/OriginExe="
/AutoUpdateProg
/SpanCdLvl=
/SpanDiskFName1=
==== WinExec(Engine.exe) >>
AutoUpdateAtomTokenByQSetup
.SDialog_Class_Name.
Bad CRC!<P>This indicates that your setup file might be corrupted...
Downloading File...
<b>INTERNET DOWNLOAD</b><p><p>QSetup will download the Setup File from the Internet...<p>Please make sure your Internet connection is properly set.<p><p>Continue with Setup?<p><P>Size: <SIZE> MB<P>
<SIZE>
|&OK|&Cancel|&Yes|&No|&Abort|&Retry|&Ignore|
BtnText
Confirm
No valid Internet Connection.<p>Can not Download File!
<P><P>
Bad Secret Token!
/SpanDiskFName1=
QRichEditBox
RICHEDIT
Button
RICHED32.DLL
Verdana
Tahoma
QQQQSV
TestMode
HKEY_CURRENT_USER\Software\Pantaray\QSetup\AutoUpdate
TestModeDate
TestModeURL
Downloading INFO File...
Downloading UPDATE File...
Downloading INFORM File...
DownloadFileAU:
TestMode=
Download START:
Download END:
Bad Secret Token!
ERROR:
File Download Aborted!
<P><P>
File not Found!
Unable to Download File!
ATTENTION:
PerformAutoInform() - START
==== PerformAutoInform-1 ====
==== PerformAutoInform-2 ====
==== PerformAutoInform-3 ====
New Version
Download
==== PerformAutoInform-4 ====
PerformAutoInform() - END
PerformAutoUpdate() - START
==== PerformAutoUpdate-4 ====
==== PerformAutoUpdate-5 ====
PROG_NAME
==== PerformAutoUpdate-6 ====
==== PerformAutoUpdate-7 ====
Shut Down Process() - START (
) Method:
Issue a Message Box
==== PerformAutoUpdate-8 ====
Using WM_CLOSE
Using WM_QUIT
Using Terminate Process
Don't Shut Down
==== PerformAutoUpdate-9 ====
Shut Down Process() - END
/OriginalInfoFile="
==== PerformAutoUpdate-10 ====
==== PerformAutoUpdate-11 ====
==== PerformAutoUpdate-12 ====
==== PerformAutoUpdate-13 ====
PerformAutoUpdate() - END Result=
InfoSize=
HttpSize=
URL=
QQQQQS3
QQQQQQQ3
.. ReStartAutoUpdateExe() - Start
/_ZZ=99 /WAIT=10 /TRANSIENT=
.. WinExec -
.. PostMessage(WM_DESTROY)
.. ReStartAutoUpdateExe() - End
|Error downloading .INFO file|Error reading .ORIGINAL file|Too early for retesting|New version is not higher then old version|"Valid for version" mismatch|Download file size error|OK|
GetOkToPerformAU=
GetOkToPerformAU =
Fire
==== PerformShot-1 ====
==== PerformShot-2 ====
TestMode=
InternetConnected=
<P><P>
<P><P>(
<P><P><T><B>PLEASE NOTE</B> - You are now running in <B>Test Mode</B>!
PROG_NAME
-------------- JustDownloadInfoFile ---------------
AutoUpdateTimerCount=
ShotTimeStatus=
QSetupStub
RAMAT*gan
KFAR*saba
MainIcon
Static
msctls_progress32
Tahoma
.. DestroyMainWindow() - Start
.. DestroyMainWindow() - End
.. CloseMainWindow() - Start
.. CloseMainWindow() - End
- wm_Destroy -
- wm_Quit -
/SleepX=
MainIcon
QSetup Installation Suite
.AutoUpdate.X_
QQQQS3
/SpanCdLvl=
/SpanCdLvl=
/SpanCdLvl=2 /SpanDiskFName1="
/OriginExe="
CreateAndRun_X_Exe() --- Start
CreateAndRun_X_Exe-1
CreateAndRun_X_Exe-2
/WAIT=
Wait %d SEC
Create X_ File
/TRANSIENT=
/TRANSIENTx=
/DELAY=
/SleepX=
WinExec:
CreateAndRun_X_Exe() --- End
HandleParamOK() --- Start
/STOP=
PostProcessMessage(wm_ShutDown) to:
/WM_MSG=
PostProcessMessage(wm_LocalMsg) to:
/TEST=
PostProcessMessage(wm_AgentMsg) to:
AU_PerformUpdateCycle (
/TRANSIENTx=
HandleParamOK() --- End
DoRunStubWin() --- Start
.AutoUpdate.
X_ExeIsRunning=
ThisIs_Plain_AutoUpdate_Exe=
ThisIs_X_AutoUpdate_Exe=
CheckTestMode
WinMain
DeleteMySelf
DoRunStubWin() --- End
==== STUB START ====>
=== START === %s
CommandLine=
==== ThisIs_AutoUpdateProg=
==== STUB END ====>
=== EXIT === %s
Runtime error at 00000000
0123456789ABCDEF
%.*d|_@
0123456789ABCDEF
unknown compression method
invalid window size
incorrect header check
need dictionary
incorrect data check
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid bit length repeat
inflate 1.1.4 Copyright 1995-2002 Mark Adler
oversubscribed dynamic bit lengths tree
incomplete dynamic bit lengths tree
oversubscribed literal/length tree
incomplete literal/length tree
oversubscribed distance tree
incomplete distance tree
empty distance tree with lengths
invalid literal/length code
invalid distance code
invalid distance code
invalid literal/length code
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
WideCharToMultiByte
lstrlenA
lstrcpynA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
FindFirstFileA
FindClose
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
LoadStringA
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
SysAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
LookupAccountNameA
GetUserNameA
kernel32.dll
WritePrivateProfileStringA
WriteFile
WinExec
VirtualQuery
TerminateProcess
SetFileTime
SetFilePointer
SetFileAttributesA
SetErrorMode
SetCurrentDirectoryA
RemoveDirectoryA
ReadFile
OpenProcess
MulDiv
MoveFileA
LocalFileTimeToFileTime
LoadLibraryA
LeaveCriticalSection
IsDBCSLeadByte
InitializeCriticalSection
GlobalFindAtomA
GlobalDeleteAtom
GlobalAddAtomA
GetWindowsDirectoryA
GetVersionExA
GetTickCount
GetThreadLocale
GetTempPathA
GetSystemDirectoryA
GetStringTypeExA
GetStdHandle
GetShortPathNameA
GetProcAddress
GetPrivateProfileStringA
GetModuleHandleA
GetModuleFileNameA
GetLocaleInfoA
GetLocalTime
GetLastError
GetFullPathNameA
GetFileSize
GetFileAttributesA
GetExitCodeProcess
GetEnvironmentVariableA
GetDriveTypeA
GetDiskFreeSpaceA
GetDateFormatA
GetCurrentThreadId
GetCurrentProcessId
GetComputerNameA
GetCPInfo
GetACP
FreeLibrary
FormatMessageA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
EnumCalendarInfoA
EnterCriticalSection
DosDateTimeToFileTime
DeviceIoControl
DeleteFileA
CreateProcessA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
gdi32.dll
SelectObject
MoveToEx
LineTo
GetTextMetricsA
GetTextExtentPoint32A
GetDeviceCaps
DeleteObject
CreateSolidBrush
CreatePen
CreateFontA
user32.dll
CreateWindowExA
UnregisterClassA
TranslateMessage
SystemParametersInfoA
ShowWindow
SetWindowPos
SetWindowLongA
SetTimer
SetFocus
SetActiveWindow
SendMessageA
ReleaseDC
RegisterWindowMessageA
RegisterClassA
PostQuitMessage
PostMessageA
PeekMessageA
MessageBoxA
LoadStringA
LoadIconA
LoadCursorA
KillTimer
IsWindowVisible
GetWindowThreadProcessId
GetWindowTextA
GetWindowRect
GetWindowLongA
GetSystemMetrics
GetSystemMenu
GetSysColor
GetWindow
GetMessageA
GetFocus
GetDesktopWindow
GetClientRect
GetActiveWindow
FindWindowA
FillRect
EnumWindows
EndPaint
EnableWindow
EnableMenuItem
DrawIcon
DispatchMessageA
DefWindowProcA
BeginPaint
CharNextA
CharToOemA
kernel32.dll
shell32.dll
ShellExecuteA
comctl32.dll
InitCommonControls
0,080<0@0D0H0L0P0T0b0j0r0z0
1"1*121:1B1J1R1Z1b1j1r1z1
656A6\6
9 9.949<9N9Z9i9u9}9
: :7:B:c:{:
=&=/=8=C=L=S=b=i=
?%?j?s?
0:0d0m0}0
101H1T1\1s1
242X2v2
3#3,3}3
4%5+535W5w5
2J3S3[3
7/7i779
9":>:J:^:h:{:
;Q;X;z;
0#0+010?0Z0o0y0~0
0B1K1q1~1
595B5N5U5
6I6k6w6~6
7%7/7V7k7|7
8$848E8V8b8g8l8s8z8
9&9.969>9F9N9V9^9f9n9v9~9
:&:.:6:>:F:N:V:^:f:n:v:~:
;&;.;6;>;F;N;V;^;f;n;v;~;
<&<.<6<><F<N<V<^<f<n<v<~<
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1(1<1D1H1L1P1T1X1\1`1d1r1
2 2$2(2<2\2d2h2l2p2t2x2|2
3 3$3(3,30343L3l3t3x3|3
4$4(4,4044484<4@4D4T4t4|4
5(5054585<5@5D5H5L5P5`5
60686<6@6D6H6L6P6T6X6h6
7 7@7H7L7P7T7X7\7`7d7h7|7
8 8$848T8\8`8d8h8l8p8t8x8|8
9 9$9(9,909D9d9l9p9t9x9|9
: :(:,:0:4:8:<:@:D:H:\:|:
0)262z2
8!8%8)8-8185898=8A8E8
<E<`<d<h<l<p<
708k8z8
9<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:a;{;
1R2j2o2{2
3"464g4v4
;+;2;J;Q;d;|;
<<<K<_<
0!0(02070=0B0H0M0S0Z0`0e0k0p0v0}0
1(111:1@1Q1\1a1
494M4s4
7)707B7G7W7a7
708F8o8}8
9"9A9O9n9
:":E:g:v:
;><O<r<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>,>0>8><>D>H>P>T>\>`>h>l>t>x>
? ?(?,?4?8?@?D?L?P?X?\?d?h?p?t?|?
0 0+050?0E0O0U0_0j0t0
1"141K1W1_1i1t1|1
2$262C2O2\2n2
2>3J3x4X5
>">(>O>
>B?V?v?
0F1S1u1
4 5-5`5
6+696N6\6
:!:.:3:@:E:R:W:d:i:v:{:
="='=4=9=F=K=X=]=j=o=|=
>#>0>5>B>G>T>Y>f>k>x>}>
11,1>1u1
;5<O<q<
=4>W>c>p>
516j6o6
0G0O0W0
88.8G8
0?1h1u1
3&4C4l4
6$6.696C6N6X6c6m6x6
7U8]8b8y8
<2<H<.=
?T?f?n?
717<7G7R7{7
8X9e9m9r9~9
:-:T:n:
:);8;E;
= =$=(=,=0=
>.>=>T>
162:2>2B2F2J2N2R2V2Z2^2b2f2j2n2
6l8p8t8x8|8
;V;d;~;
<%<-<8<
97:C<O<\<n<u<
>(>:>X>d>
>S?^?s?
040n0w0
1/1F1R1X1b1i1t1
2(272[2j2y2
:(:0:4:8:<:@:D:H:L:P:^:f:n:
9#9l9{9
;.;A;_;r;
<'<3<@<R<x<
??&?8?J?
202e2u2~2
5=6T6Y6
677D7I7Z7i7w7
0P0t0
555:5X5]5y5
6!6]6{6
=S=Z=s=w={=
>.>I>d>
63686T6Y6u6z6
77O7T7o7
;';.;8;B;L;V;`;j;t;~;
728H8V8c8x8
9*999K9U9b9t9
=#>=>B>Z>
>W?q?v?
5#54595K5
6$6)6=6
7(7-7A7
898>8P8
9-:I:N:\:
;3;8;J;
<0<;<E<R<\<i<s<
>">@>J>h>r>
1,111>1N1_1
4\5u5z5
>'>,>@>
>-?5?C?O?V?`?j?|?
$0,01060@0F0W0
1&1+101:1@1W1
1,24292>2H2N2k2
2>3F3K3P3Z3`3w3
3)4R4o4
45n5s5
7757Y7p7
81969J9
>>,>>>N>c>h>m>z>
0S0X0s0x0
0"1S1o1t1
6.6[6`6q6
7!8M8Z8r8
?3?8?U?b?
0#0(0H0j0o0
0A1N1`1n1
6I6d6r6
6/7;7H7Z7
<+=X=i=
?O?W?d?
2+20252B2Y2`2
536A6P6n6x6
8M8X8g8
8)9S9m9
:/:7:<:[:c:h:
>B>L>o>
1!292V2
5=5G5V5
8D8N8{8
!010>0P0D1
292C2Y2k2
5!5=5c5m5x5
6N6d6w6
;";,;1;@;y;
<%<O<u<
<7=C=P=b=
>!>%>)>->1>5>9>=>A>E>I>M>Q>U>Y>]>b>n>v>
B0J0O0_0
1b2~213@3J3
4#53585V5g5|5
6F7Q7^7
768j8v8
9L9^9s9
:";J;T;g;
<*<@<J<
0R0j0|0%202:2^2c2z2
353F3U3
585C5J5W5^5n5
6 666K6U6`6x6
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,90989C9
4080<0H3P3T3x3|3
4 4$4(4,404l4t4|4
5D5H5L5P5T5X5\5`5d5h5
<$<H<L<P<T<X<\<`<d<(=<=@=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
StubInformDlg
UWin64
yQMsgBox
UTypes
System
SysInit
RichEdit
3Messages
KWindows
SysUtils
SysConst
*ShellAPI
Process
TlHelp32
InetHTTP
UnPack
Common
QSetupBridge
ShellDir
RunTimeDir
xLangRes0
Global
/SLangId
BZLibOpen
StubGlob
\StubUtil
StubAU
StubSetup
StubWin
-QDebug
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
name="Borland.Delphi.XPApplication"
processorArchitecture="x86"
version="7.0.2.99"
type="win32"
<description>
Windows Shell
</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
</application>
</compatibility>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
|http:/|.info|.exe|fueueiiwiggghdgbgsgwfugtfbifidgxbghhhefwiwtfiv|1|
ASA3TdVU
f@ZYsB
VoayZ=
\mjLs'
D:?'Zz
k>^Ww.
s@H3ms0]_0_
+4tJkPICC
*]Z;BM#
&fcQp.
t- Ww/
MA7-(3
d:H8-.g
iJ`j;3Q)M
a">!)q
#97gR~N
X!u}z=5X
|]p^2b
$0Q>|u
7{tF<A
#!#~#&
5,lKJK
l96^Ah
MFLl9:9G
O*2xgZ
6ZnW>Z3
@QE.mosM
:fRRV]?
EA{58?/
i.+-O6
$}QT;E
g6d-lJ
)A7DAB
;#.->)%
S[@rl_:
_t|\LtRR
0)*!
gS[L1Q2%
w?9x/q
:,w+-;8
QP`z+A-
}9GnYa
k'aWoH
22b]LJM
9EDElVHAw
Sgd/o@
RqP*1K
|mf,-H
URBZYP
>ddHP
I!x7 AfZ
raPhi4
{?[qg$<$
SSgIs!
L7L[Vqn
x<p]1AK1
7At-*H
@Lz8cqD
uNoup>
L|V;h_
RYqKYm2f
V:CEh2
3~GdJ-
${nn~"#`
B8<XH=
9glnEQ
EM:M'!
|{wphIw
t,vw/#
8B4~?)x
4~r>&x
JoTFzS"
ND;i*#Y
U$~rol
M"533!
@RkOtc
KpO_L;
X(2UEx
q~7-b$.
j\LLo~
A=0.Mc
5ebd<=
#&[Wo.7
fTUoS/c
K/ou%%P
4@2#b#C
dsGcXk0
t$6t50
\q\g,p
pknx`w
T3[`_3
d`d.H{
KCY#Vs
Uqz2}2
}t42QY
:w@~'KR
Xe!2YA
)3:~L+\
h'7hL;
#P!+.H
h:~y/f
OwF3ONBM
lw9_+Y
/Zi9F'
cwZ"zJ3
%RfSMd
MA@j$4
?*]?t5
_N"GP@n
VneSy?
Tgf.u!
pl\)([+
+{iBm_
6py_PG
%s;%M+
~^+1Jz
\m")i~
}4{*P@M]
C|MWx:{m
C7~l5]}
L0}|!@
}cn3js
~YZ/g|
z8~,kM
`%j;S9Z
@m;QH;
[8^DoH*
ChR*>&6
>$F3Ys
5;poa-HcS@
=\C)|;
Vp2N")
[`Ym_K
-a+mwK@p`5~
c!8vb|
P8E(t
JrG;^rt3
dUUB[xQ
00$t\n
f$yKtl
N`t^N^"e
Eu"]?a%
w40d#Tqd
7hZV$HZ
F!4Als
*|n+G'
*;|=z:
1NSd<^
+i/aqD+)tU
ZApFsR
Z*i]^+
yPd;K_
f`%:+gK
7l|_%,
a$^u K
u=jP$Ev
Rt4ExZn_
4f>v=K
5S'0gS
kj6}}E_V:~
{O]v.s
jK7n|n
.$p$tP
A`H:.W
~pI3HD
MbW6ZJf
~VSA2m
<V1x&g
\LsA'%
V*s1/sy
U#Z5ED
WI$iakI
>]>jBAWRf*
1[9V3j
7}gk+3
O4:p.A
/`V]={
?H#-I!
XWw'$x
2p@NZm
\y$6<l
t"}|Z?
!{ENr(#
$FP*;=K
P}E@1#
yYR.%$
|6X_C{
X**_EWP
c%?MN-
j?xQ6_+
Hm9w4z
tfe9ZO
Tk 6"W48
h2}%Bb
O.VFrYQem
c}lx&6A
TP&T"3
zra._^
5c XmG7
_j$lDO
Hzk'*5
*J`uX%
#%gjRTJ
?,4nkF
&0s\`i
E"f{gK
M1xPrsbJ
BRTwl
usCK&M
?:|6loP
dHuNyTgf|
=\5],q{
5&9*]`
|YXjSD
_PJeBv
BsG^??Y
|-EYLvq
CN455j
9b/r,@6
J!RNCm
r3kpL-(
}m/otL
"QDjBV>
"8=yvq
mNdmI/
n1ZNbv'
6u$LY-n*
[{S@S:@
=J)tsC
JQF*EY
{Dt) d p
XS0,D;`
g'3/j=
H&dR]
Aze^%.)u
q+*)"9
c@.~W}
_-ECR!
8zxTD2
Ut1wNz
H-C/_o
5vX~)J
<G.uk.
R8w\m]
\(MiO?
>e5Q+"
A|b~e8
VC;a]{
@"k]=
S"e!?5
`8YAd4
T/}FFu
^`,1=5
Yw*dBZ
dkN{zg
`+{W"N
JRlkXr
4 R"#%
Az|*rs
KHeK}r
eV.fDZ$M
PFVN^AQI
#u7{^<
\!E LML
P%`n~&5
&o_Y@|X?+
5cOpp;
ag1>[
nn(:us
s9[e?3<Q
!Z\%FI"-b
i%$l6XJ
o!5n>UOOm
9`Eb#&
7$C01?#E
|Ukh=z
0ozhBxhr8^
D,u^Z9[
/Study
yz[".@
1Yu1cWu
p!87}8
wGV*W?
#.Roqlt
HMbdnT
EkDcr-
8;p^z+8r
;z5-`|
W]e?3,
+J9"t%C
2&TB'-
b{c}s>
'P!KJSR
3t`W[)J
PSl9q}
=^6L>I
^9h}l*(
c%uZ\nqB
qh@GY>a
)1Iljc*
<]r)uv
'.::1F@K
f\,;E~
)4`0S{
\h0Utj
gj_G3T
Y2g;|\:t}=
qF}SH
]q3ZewH
mt,zd#
H8O/2n{
2GCx@\A
eWo!kR:
&Di^^{
#jm7]J
K|U$`X
Wtnbz/
iuu!?{/"
ldsodTl
`WD"?=9
`Kfcu
V+ W,_
`q8{qW
vE/=<-
HgY<_sw
.(~5%h
>xH&:3
ar9.+kn+
RT>NNu
i%"JL,
78D;[~E$c
\/f("_
4NE^Ug
\4h%a3
-#34\h
N(u0s_
->Bz~
<"[BSk[
4TO7S^b
D&'+(
~2Y6Gi1v
;Z_Tqv
:CXWf"
~4Yb*d
<1'fbS
){`HX -
&'89ui
$"AS~:
lm"K0Q
hS/dkiW
yUz//k_d
#;yT|f
U7mQ)1
~xI zu
.!E
mE@..I
BpglAy`
qoE^}{
&D8]40
Pf$^~h
tccKBt
Jt]e'
yt!*^ip
v^>tz]C
G+Oe>w-
9*.`Uq
C9V5Su
)qSL>.
*f":19
V]1AKw^_
Mo#A(C
,S(`D2q
vr[>;zb7I
}b&Q:~
BYe]}=
nGF\iS|
g]VRm6
3xi)[0"
puB V7tu5T
K<E\}9
E2X6m+
#x)Rek
{e'_6:
*ZS/&5
0;WPW87
-^bsQ^
DFw)C@
~'0cZ>#
V~@@i;
8e[@Zj<N
f<W%)x]
M0vw@U=
')%%siy
):jF9;
D0>glf
J4u:xS
i^y'fL
R8a6h+
Ot|UJX
50?~Y&
'(GfuNt
w8Bq+'
%T*-wMB
)*9;(<A
eFaR"/
j}a[*/
ogw|@f
0`W&}VA
zf^v^k]W
PZ#H\sSI
^L~==s
lBRaVXvm
wa{Qf4
)]NiGr
4 {hS2
X;fd7Q]
Nr9=U;t
lgtHwu
:zrfOxX(
Y!33(q
%[E@!$
qO7iz^
ZInM}"
|o~4{8gS
D>X]v@
=376,`
v$Om3:
lb[vk$
k_%Yz-
:_w6(
.lGzqV}
=bJOCn
CNq;zv
Hg'\Gu29
?pCqp1
"E>"sg?
zYbYQp
8,>~f
|}mUKkU
yt.rZ
`TP~#lu
%aEFpO2@r
OzF1W^
sI*gr
ia,k1@S
g@%Z3b(
.}+?>#
qZY=.8+t
]weXM&%
Ft'a/x
.m(hXS
=k/BjJH2
#98s=P
\VKCQA
GQJ}CR
\wUfL
"SewI8
7lxg AH
"o6vm/?}x[
i~LG=z2
KBbH(U$
<[rP3S
(#erEum
&yB SW
i)1??/
(GT;.,
1O}$"Y/mJ
WxipHd
?j:)hB
6FzE(p
C9ugL;
Z9 \86P
?qI=Rf
PAjJmo
O@y]/
M}s }F
PbpxbDs
dzIHdM
0*v%@F
{d~eD3&}
-EPgxW
Rko-iL
!uT]VK
\E~FrnfI2u
9\CkCn
EC5L/7
6[!#(B
D;9XUX
o^tiJ`,)
w.vhKw
aNJS>%
[IzT}
rtuMfr
pr9$yT
>7C7FBsK_k
wU4j58E
"^m}p
l5g,{b
<jn*^jn
,[LFG]Q]<W,
$@1w1^Z
P_ (!#6=
L#[i*:
;2`yR]
LMU7P^G
Ww44aj
N/LB^r6
y)u4wp
'?_/|~
fd2%96-
V%\c`^7$Gb<b>
7pcEF
44KyrOT
]?*jDT
Trx_wDC/j
|dpf"%76+!
RZr\,e
s*)Y<v
m`d $N0
qHB&WSK
Ot''>LOp
Tc$.${<
lm&wsf
z_ai'.
sTb*}(
kW~FXGIIH
[~Cx#"
19am{i
MOQ|Rt
~` WOfQ
9YN\|SM
t8]qF|
_?jU!u(
u1"pO`
153)]7
{ERWtI
hnO<|E
7K!wC
W<9DWxo
VP1OJ}
y QhS;
&%y0u
#{`JGi
?ABm}&
3&xlqh
rppU4%Ds
cY2u|,
?n*RhA
~o8S3,u
nvH:z;
kJR4)T
hHrB(*J T
@l@|-+
A6OX_K
.j>jC){
i#7JoA
v,o6;?
MC8uP|
;l'Rr6
<H-^,.
=l?Imi^
;or39,
RhL '; /
-|sq:W
@;={{6
t& 1K+
!+00riO
h%!199Y
S9x;(53
"Ik8X$m
*pUUd*
~"F`x
mB%i}T
4g.#.c
}<Ig\JW
vi;8i0
hQ{~H{
b%<$;C
~/H Oc
vj`Pt|
RV9,)s
*]P[z_
>aBpir
7AK|mSc
UYAL/+
eY)jOu
GO8Ck
fy$h@a
AAto_O
pnyh]Q
}8zQ\wk
b4zEB9/
e-TFB0
mD f3:8
kny>Zj
('n)6:
Ye$E%'
f$31f9
|3Yj=`
*2/{.U
=[M3/P
&'pLW}
JO^UW(
Vv~g!ea
\&Q(qx
v2[6]BH|
Jri[|0
pLr%<%0Bi
(t$7t.
>68XM#
R9xf[?
;-%>:3
$&J&Of$
x-v:1L}Z
x"'3)-
knZJzt
e[[GQD}=
Few(Bx
jzr9T+
^X%aYb"
T^4K7M
#$FNI'
WyrnWE
|pFzZ"
wy=#:5
W&;:-6
9Db@z:
9iR\&8
E,p$V!
L{9~_
?bbF,b
[BZGV$-
/2 `[s
2:+>6):
+s_Rpl
:~Jx)
lM1ciW
PJln?B
B{SeU3
li{1{n
Oogg?:
-{.Y]}
sffRbZ
[6Cos-On
%JQ)*e
!Y\[?m
P&f*$t
lyLCf"
a:Gy->
<IyY{O
O\fH=
`97T5z
KN?G"II7
Z"Uz!w
p<2F96o$
s&6Nrs
XZVNLN
zfrz"
39..>]
kY!\H`O
EnK|^p
)4-~5,*
5955!:3
+kGvzzX
?h#vnf%cW-
Z%c"Av
+8[iWi
W/mo-q3
Ax@aeE
=doq^^
@R@m[]
]!#)=m)`7
CR@?!H
DVzE/x4|
dN2367
oE"YfX
HBU#v1
ofNT27
:qV{;n
dq1UMQ
s<lUe0
c=W"VE
OD`3<1
+S`e2_a4
-1e?%9
iI/Zl,
,Yh*0|
reJBDtO)
DhlxVC7
" N?&z
>[lVy=
/:GC3.
6t]RV%
i^)i=k
F{Wz,oIt
6hF4uo
DRsk\3
YKif;)
GB}=/T
.pEb^H
nVrhU#
Bz3H\Y
d&e32r
v<#Jq~y
<t6q_{B
XX&A]CT
C/G9*!
DJKuyb%b[t
(lZd>5
,b>3y'
jn6]#T
:A@V3$_
?k8f2)
(sbl}[
\+"Fe{
9 !>:&
:" (]J
kNj95;
Bm:9`S
;}ppz>
v?xv~
Lj&|nZl
K?);#<
O6Ozvf
wUW/jQHp
}u\p[5V.
{vct"D
,J,})ytU
L5\t?s
oO8q9=i
.LaUl#
qYD*sAY
))Iiq'
2rEoI6
RQvej|f[
zVl/+n
6UG.-r
Y,M](J
0RkK8n
n:H1!(>
kDXn&W*W
\me!V|W[`
X#x/K<Y
?oYc7!
*K>(fg`b\
TQ`fuKw
\`z<';
LR2J\i
sp<(Dq6rA
x$HX(>6G
#Hlvq_
2k0b<Vq
OGv~7:p/k`a
w>"01j
-x8D3,
JZbrz*
)-=!)Yb
)}a.pK
/;bYiUc]w
~m a;K
=}=IU7}
2hx\TH
'CgZEVQn)
%v]Fxx
-d`ty{C
e|=822B
fUfAe?{
}ny1N
[Af%(1
g3/=F
-0}CWq
H3b"fR
:)"hTr
}oq5fl
=:dot"R
NJ6P`b
}Y~|Tp
m+5fhNhu
tT(`A
t(hCaM"
OmbI^C
vbp?OD
^\_C9O
\texeHx.
c{%/ `
'9.!-#
0S,HH3
%++=6QLhH
g0U4t5
^K>;Y6
Raaf?
7> 88s
(+=[)$
k.Ta6Y
XLh51AS3
pj8?v@
EsNhwh
YUoiUf
|RrNTM
l-P<h:
>3kKPX/
]Qo6.
ClV, xP~;($
Y2WH6
M:4`-m
hNy1[+
?MG#B:#Lad
ARQOQa
d'X.e7,
@,MvZ61
Ttw_>AZ
yj0XXVY#
Z}*-;-w{f
~&_R5ac
TLZ\!]R
pViDP8
IgN5re
Fou=jerF]
jtXcUF
Ga?R/G
Z]j)^O
jbW~_F
:DW([jT
~NSbaq9
i6;wI:
Q\hx11+Z
98*U=_
YuHoZP`
N[.Ku9
a+r|"N
k2Rurm
:#T,9cV+K
.Qz0U
lD33]ok
3+Q/ly
MKu|rE
(Og#)[d
aToKr#
8T*"h ug
,<WS"\
y_d_IC'
o3qIFB|
PmWdCi
Kb*O|[
flBquZ
x3!FqYb
6XBh}`
%!9 CG
25\VF@
{^f4jm
@=fG5j
9;~.FV
It(P360&on}IeP
vXoc=QfO%
^pQ(E'
sosKdGe[
+{US
YBDDF1
y3KG7/
AoUB*!
ff~>r'
>@3Sdc@
FY#m;[
&x#xVX
~o>C05w
|=RSXy
T_.B8Z
yI#WFhp
<*Y\Z]q%
H?Y6s
B(OU'(
CB\&y+
n6HGoH
Ix:"/c
F$S-\x
H{rtvy9Ib)
IO,EB
{e}5h5u
XF"g+{
~?hJ]=!
>a`YUf
E=fnaL
G7EE!Q
7k)>yO2
8sRnI
nToj85
c~]~}~
\@WcWwW_
<L<+=a
&d3u(|
E;V^#-&Y
VweM$o
KJ6}(S7
3LCR=njQ,
;(0=K+
^pj^#
aRR*3j]
l>1 0R
sz5YyF7
z)yK5kp
zjbZl,
J3!^l(
??h>7H5
mIU0hS
0Lm8F{
OV}xXPT
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Agent.Vzhy
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Elastic Clean
ESET-NOD32 a variant of Win32/Packed.QSetup.AX suspicious
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Trojan.Win32.SMOKELOADER.YXDELZ
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Microsoft Trojan:Script/Phonzy.C!ml
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!FE415FE7497F
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.SMOKELOADER.YXDELZ
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Riskware/Application
AVG FileRepMalware [Misc]
Cybereason Clean
Avast FileRepMalware [Misc]
No IRMA results available.