Static | ZeroBOX

PE Compile Time

2023-08-01 18:26:15

PDB Path

D:\Projects\WinRAR\sfx\build\sfxzip32\Release\sfxzip.pdb

PE Imphash

fa8d20faea9ef7b4e2b7fbfe93442593

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00027d0c 0x00027e00 6.69415089194
.rdata 0x00029000 0x0000a6e6 0x0000a800 5.24673949572
.data 0x00034000 0x00035ca0 0x00001000 4.16008979023
.didat 0x0006a000 0x00000178 0x00000200 3.20225358102
.rsrc 0x0006b000 0x00015214 0x00015400 4.05561792507
.reloc 0x00081000 0x00002954 0x00002a00 6.70380031412

Resources

Name Offset Size Language Sub-language File type
PNG 0x0006c06c 0x000015a9 LANG_RUSSIAN SUBLANG_NEUTRAL PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
PNG 0x0006c06c 0x000015a9 LANG_RUSSIAN SUBLANG_NEUTRAL PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
RT_ICON 0x0006d618 0x00010828 LANG_NEUTRAL SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_DIALOG 0x0007e78c 0x0000024a LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007f9c4 0x000000e6 LANG_RUSSIAN SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0007faac 0x00000014 LANG_NEUTRAL SUBLANG_DEFAULT data
RT_MANIFEST 0x0007fac0 0x00000753 LANG_RUSSIAN SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x429000 GetLastError
0x429004 SetLastError
0x429008 FormatMessageW
0x42900c GetFileType
0x429010 GetStdHandle
0x429014 WriteFile
0x429018 ReadFile
0x42901c FlushFileBuffers
0x429020 SetEndOfFile
0x429024 SetFilePointer
0x429028 SetFileTime
0x42902c CloseHandle
0x429030 CreateFileW
0x429034 GetCurrentProcessId
0x429038 CreateDirectoryW
0x42903c SetFileAttributesW
0x429040 GetFileAttributesW
0x429044 DeleteFileW
0x429048 MoveFileW
0x42904c FindClose
0x429050 FindFirstFileW
0x429054 FindNextFileW
0x429058 GetVersionExW
0x429060 GetFullPathNameW
0x429064 FoldStringW
0x429068 GetModuleFileNameW
0x42906c GetModuleHandleW
0x429070 FindResourceW
0x429074 FreeLibrary
0x429078 GetProcAddress
0x42907c ExitProcess
0x429084 Sleep
0x429088 LoadLibraryW
0x42908c GetSystemDirectoryW
0x429090 CompareStringW
0x429094 AllocConsole
0x429098 FreeConsole
0x42909c AttachConsole
0x4290a0 WriteConsoleW
0x4290b8 GetCPInfo
0x4290bc IsDBCSLeadByte
0x4290c0 MultiByteToWideChar
0x4290c4 WideCharToMultiByte
0x4290c8 GlobalAlloc
0x4290cc LockResource
0x4290d0 GlobalLock
0x4290d4 GlobalUnlock
0x4290d8 GlobalFree
0x4290dc LoadResource
0x4290e0 SizeofResource
0x4290e8 GetTimeFormatW
0x4290ec GetDateFormatW
0x4290f0 LocalFree
0x4290f4 GetCurrentProcess
0x4290f8 GetExitCodeProcess
0x4290fc WaitForSingleObject
0x429100 GetLocalTime
0x429104 GetTickCount
0x429108 MapViewOfFile
0x42910c UnmapViewOfFile
0x429110 CreateFileMappingW
0x429114 OpenFileMappingW
0x429118 GetCommandLineW
0x429124 GetTempPathW
0x429128 MoveFileExW
0x42912c GetLocaleInfoW
0x429130 GetNumberFormatW
0x429134 GetOEMCP
0x429138 DecodePointer
0x42913c SetFilePointerEx
0x429140 GetConsoleMode
0x429144 GetConsoleCP
0x429148 HeapSize
0x42914c SetStdHandle
0x429150 GetProcessHeap
0x42915c RaiseException
0x429160 GetSystemInfo
0x429164 VirtualProtect
0x429168 VirtualQuery
0x42916c LoadLibraryExA
0x429174 IsDebuggerPresent
0x429180 GetStartupInfoW
0x429188 GetCurrentThreadId
0x429190 InitializeSListHead
0x429194 TerminateProcess
0x429198 RtlUnwind
0x42919c EncodePointer
0x4291b0 TlsAlloc
0x4291b4 TlsGetValue
0x4291b8 TlsSetValue
0x4291bc TlsFree
0x4291c0 LoadLibraryExW
0x4291c8 GetModuleHandleExW
0x4291cc GetModuleFileNameA
0x4291d0 GetACP
0x4291d4 HeapFree
0x4291d8 HeapAlloc
0x4291dc HeapReAlloc
0x4291e0 GetStringTypeW
0x4291e4 LCMapStringW
0x4291e8 FindFirstFileExA
0x4291ec FindNextFileA
0x4291f0 IsValidCodePage
0x4291f4 GetCommandLineA
Library OLEAUT32.dll:
0x4291fc VariantClear
Library gdiplus.dll:
0x429208 GdipAlloc
0x42920c GdipCloneImage
0x429210 GdipDisposeImage
0x42921c GdiplusStartup
0x429220 GdiplusShutdown
0x429224 GdipFree

!This program cannot be run in DOS mode.
SRichF
`.rdata
@.data
.didat
@.reloc
t,j.Xj\f
_^][YY
tmSUVj
_^][YY
j*_f9y
_^][YY
j\Zf9TN
WVj\^f;
0j\Yf9
f9.t[S
o 9w$v'S
YY;w$r
SVWj\XP
EDj*Zf9
j Xf9DK
:f;}(t
Aj Xf9
Af;U(t
j"Xf9Dw
wj"Xf9
j"Xf9Dw
wj"Xf9
~0YY9^$v
F h0=@
D$`jPP
L$4+L$,
t$8A+t$0
t$DVSj
jd^+L$4
|$,Pjd
D$$3L$0
L$ 3L$
W83W$3W
3w 373w
T$(3t$
t$TWj8[
tFv-j@Y;
?vUUj@^+
l$xBV3
tySSWV
D$$+L$
9VWPQS
SVWjx^
uUSSSj
u(jIXf9
D$ Phh
t$ WPV
QSVWh@
t$DjD3
t$490v
D$@;\$4
9D$ tC
;t$@}c
;t$D}c
D$ _^][
|$(9L$
L$(;L$
D$0PWWj
;l$$}j
hSUVWj8
f;T$4u
_^][YY
Yj"ZQP
$SUVWP
Y][_^YY
tJ9o$uE9o t@
V,]^[Y
,__f9~
[_^]YY
D$,+D$$PV
tJ9s$uE9s t@
D$0UPj
W;L$<u
D$dXWWf
$SUVWj
tGSVWj\
EZ;l$(
Yj"8D$
t$,SVW
f98tNV
.u'f9O
Yj\Yf9
tfj"]f9+u
f9(tSVWS
Uj"Yf;
l$$j"Xf;
Aj"Xf;
t\USSVW
tDUVhh
QRPh\ C
QRPh| C
QQSVWd
URPQQh
UQPXY]Y[
Tt1jhZ;
^$+^8+
t0jXXf
~$+~8+
F2jgYf;
u0jAXf;
u0jAXf;
Wj0XPV
PPPPPWS
PP9E u:PPVWP
WWWPWS
u-PWWS
PQh8IC
PQh@JC
SSVWh
f9:t!V
QQSWj0j@
tl=pMC
PPPPPPPP
*messages***
Unknown exception
bad array new length
vector too long
CryptProtectMemory
CryptUnprotectMemory
xlistpos
SetDllDirectoryW
SetDefaultDllDirectories
string too long
map/set too long
s:IDS_BROWSETITLE
s:IDS_CMDEXTRACTING
s:IDS_SKIPPING
s:IDS_UNEXPEOF
s:IDS_FILEHEADERBROKEN
s:IDS_HEADERBROKEN
s:IDS_MAINHEADERBROKEN
s:IDS_CMTHEADERBROKEN
s:IDS_CMTBROKEN
s:IDS_OUTOFMEMORYERROR
s:IDS_UNKNOWNMETHOD
s:IDS_CANNOTOPEN
s:IDS_CANNOTCREATE
s:IDS_CANNOTMKDIR
s:IDS_ENCRCRCFAILED
s:IDS_EXTRCRCFAILED
s:IDS_PACKEDDATACRCFAILED
s:IDS_WRITEERROR
s:IDS_READERROR
s:IDS_CLOSEERROR
s:IDS_CANNOTFINDVOL
s:IDS_BADARCHIVE
s:IDS_EXTRACTING
s:IDS_ASKNEXTVOLTITLE
s:IDS_ARCHEADERBROKEN
s:IDS_DONE
s:IDS_ERROR
s:IDS_ERRORS
s:IDS_BYTES
s:IDS_MODIFIEDON
s:IDS_BADFOLDER
s:IDS_CREATEERRORS
s:IDS_RESTARTHINT
s:IDS_CRCERRORS
s:IDS_ALLFILES
s:IDS_TITLE1
s:IDS_TITLE1A
s:IDS_TITLE2
s:IDS_TITLE3
s:IDS_TITLE4
s:IDS_TITLE5
s:IDS_TITLE6
s:IDS_ARCBROKEN
s:IDS_EXTRFILESTO
s:IDS_EXTRFILESTOTEMP
s:IDS_EXTRACTBUTTON
s:IDS_EXTRACTPROGRESS
s:IDS_MAXPATHLIMIT
s:IDS_UNKENCMETHOD
s:IDS_WRONGPASSWORD
s:IDS_WRONGFILEPASSWORD
s:IDS_COPYERROR
s:IDS_CANNOTCREATELNKS
s:IDS_CANNOTCREATELNKH
s:IDS_ERRLNKTARGET
s:IDS_NEEDADMIN
s:IDS_PAUSE
s:IDS_CONTINUE
s:IDS_SECWARNING
s:IDS_SECDELDLL
$STARTDLG:SIZE
$STARTDLG:CAPTION
$STARTDLG:IDC_DESTEDITTITLE
$STARTDLG:IDC_CHANGEDIR
$STARTDLG:IDC_PROGRESSBARTITLE
$STARTDLG:IDOK
$STARTDLG:IDCANCEL
$REPLACEFILEDLG:SIZE
$REPLACEFILEDLG:CAPTION
$REPLACEFILEDLG:IDC_OWRFILEEXISTS
$REPLACEFILEDLG:IDC_OWRASKREPLACE
$REPLACEFILEDLG:IDC_OWRQUESTION
$REPLACEFILEDLG:IDC_OWRYES
$REPLACEFILEDLG:IDC_OWRALL
$REPLACEFILEDLG:IDC_OWRRENAME
$REPLACEFILEDLG:IDC_OWRNO
$REPLACEFILEDLG:IDC_OWRNOALL
$REPLACEFILEDLG:IDC_OWRCANCEL
$RENAMEDLG:SIZE
$RENAMEDLG:CAPTION
$RENAMEDLG:IDOK
$RENAMEDLG:IDCANCEL
$RENAMEDLG:IDC_RENAMEFROM
$RENAMEDLG:IDC_RENAMETO
$GETPASSWORD1:SIZE
$GETPASSWORD1:CAPTION
$GETPASSWORD1:IDC_PASSWORDENTER
$GETPASSWORD1:IDOK
$GETPASSWORD1:IDCANCEL
$LICENSEDLG:SIZE
$LICENSEDLG:CAPTION
$LICENSEDLG:IDOK
$LICENSEDLG:IDCANCEL
$ASKNEXTVOL:SIZE
$ASKNEXTVOL:CAPTION
$ASKNEXTVOL:IDC_NEXTVOLINFO1
$ASKNEXTVOL:IDC_NEXTVOLFIND
$ASKNEXTVOL:IDC_NEXTVOLINFO2
$ASKNEXTVOL:IDOK
$ASKNEXTVOL:IDCANCEL
USER32.dll
GDI32.dll
ADVAPI32.dll
SHELL32.dll
ole32.dll
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
bad allocation
SHLWAPI.dll
COMCTL32.dll
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
`h````
xpxxxx
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
D:\Projects\WinRAR\sfx\build\sfxzip32\Release\sfxzip.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.didat$5
.rsrc$01
.rsrc$02
ShowWindow
GetDlgItem
EnableWindow
SetWindowTextW
GetParent
SetWindowPos
SetDlgItemTextW
GetSystemMetrics
GetClientRect
GetWindowRect
GetWindowLongW
SetWindowLongW
SetProcessDefaultLayout
GetWindow
LoadStringW
OemToCharBuffA
CharUpperW
DefWindowProcW
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
UpdateWindow
MapWindowPoints
CopyRect
LoadCursorW
SendMessageW
ReleaseDC
MessageBoxW
FindWindowExW
GetClassNameW
CopyImage
wvsprintfW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
PostMessageW
WaitForInputIdle
IsWindowVisible
DialogBoxParamW
EndDialog
GetDlgItemTextW
SendDlgItemMessageW
SetFocus
SetForegroundWindow
GetSysColor
LoadBitmapW
LoadIconW
DestroyIcon
IsDialogMessageW
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
GetDeviceCaps
SelectObject
StretchBlt
CreateDIBSection
GetObjectW
OpenProcessToken
GetTokenInformation
CopySid
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SetEntriesInAclW
SHGetMalloc
SHGetPathFromIDListW
SHBrowseForFolderW
SHFileOperationW
ShellExecuteExW
SHGetFileInfoW
SHGetFolderLocation
SHChangeNotify
CoCreateInstance
CreateStreamOnHGlobal
CLSIDFromString
OleInitialize
OleUninitialize
SHAutoComplete
InitCommonControlsEx
sfxzip.exe
GetLastError
SetLastError
FormatMessageW
GetFileType
GetStdHandle
WriteFile
ReadFile
FlushFileBuffers
SetEndOfFile
SetFilePointer
SetFileTime
CloseHandle
CreateFileW
GetCurrentProcessId
CreateDirectoryW
SetFileAttributesW
GetFileAttributesW
DeleteFileW
MoveFileW
FindClose
FindFirstFileW
FindNextFileW
GetVersionExW
GetCurrentDirectoryW
GetFullPathNameW
FoldStringW
GetModuleFileNameW
GetModuleHandleW
FindResourceW
FreeLibrary
GetProcAddress
ExitProcess
SetThreadExecutionState
LoadLibraryW
GetSystemDirectoryW
CompareStringW
AllocConsole
FreeConsole
AttachConsole
WriteConsoleW
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
FileTimeToSystemTime
GetCPInfo
IsDBCSLeadByte
MultiByteToWideChar
WideCharToMultiByte
GlobalAlloc
LockResource
GlobalLock
GlobalUnlock
GlobalFree
LoadResource
SizeofResource
SetCurrentDirectoryW
GetTimeFormatW
GetDateFormatW
LocalFree
GetCurrentProcess
GetExitCodeProcess
WaitForSingleObject
GetLocalTime
GetTickCount
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
OpenFileMappingW
GetCommandLineW
SetEnvironmentVariableW
ExpandEnvironmentStringsW
GetTempPathW
MoveFileExW
GetLocaleInfoW
GetNumberFormatW
KERNEL32.dll
OLEAUT32.dll
GdipAlloc
GdipFree
GdipCloneImage
GdipDisposeImage
GdipCreateBitmapFromStream
GdipCreateBitmapFromStreamICM
GdipCreateHBITMAPFromBitmap
GdiplusStartup
GdiplusShutdown
gdiplus.dll
RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
TerminateProcess
RtlUnwind
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
QueryPerformanceFrequency
GetModuleHandleExW
GetModuleFileNameA
GetACP
HeapFree
HeapAlloc
HeapReAlloc
GetStringTypeW
LCMapStringW
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
GetConsoleCP
GetConsoleMode
SetFilePointerEx
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AW4RAR_EXIT@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AV_com_error@@
.?AVbad_exception@std@@
.?AVtype_info@@
vuOuefweV$y
d{a?b\l
c_qQ_}
'_c?!k
-[jE>y,
xT28FX
401pQm
o1CpQm0
3z.g-]`
,\`2E&X
om\^\p
SYc61r
u_Agr,
6y3&T.
Gv&F~2
QM~2^~
)'/<4t
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="*"
name="WinRAR SFX"
type="win32"/>
<description>WinRAR SFX module</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"/>
</dependentAssembly>
</dependency>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!--The ID below indicates application support for Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!--The ID below indicates application support for Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0&010A0K0a0k0
1E1V1m1
2"2,2h2
>?>\>m>
6696B7p7
9:&:a:
;@<n<z<
0G2|2z4 556|6
2\3c3j3q3
758<8C8_8q8
8!9/9[9g9
:(:4:N:m:u:
<!<.<Q<W<f<w<~<
=#=*=1=8=?=F=X=_=f=m=t={=
0#0/0=0X0_0m0w0
0>1E1Q1]1n1x1
2D2P2_2n2
3l4w4~4
5"616@6O6T7
9"9-9w9
<+<4<;<B<[<i<t<
=$=,=4=<=D=O=Z=e=p={=
> >+>6>A>L>W>b>m>x>
1!1+121X1_1j1p1x1
10171?1D1i1
2.252A2N2Y2e2x2
3/3;3[3a3
3K4i4p4
495>5U5[5c5k5s5{5
6/6?6L6Y6f6m6
7*70787C7L7U7
8)81898A8L8U8[8c8n8
9+919E9K9k9q9v9
:(:/:R:[:r:y:
;,;F;S;];b;
>-><>W>j>
?"?2?q?w?
0&0C0T0Z0`0k0
1/1\1c1h1|1
10282?2E2K2Q2b2v2
3$3.363<3E3R3\3g3~3
3$4,42484=4F4N4[4d4w4}4
5)535=5Q5c5n5
6)6N6W6_6g6o6
;*;1;C;H;P;V;\;g;m;s;~;
=/=;=H=Q=X=v=|=
>&>0>6>=>C>
?A?G?N?T?_?e?
2#2+2A2J2P2V2k2t2|2
3#333@3H3V3[3a3f3q3w3|3
4"4-4a4i4p4v4
5 5*5/5>5G5Z5_5g5n5u5{5
6 6*6J6Z6v6
7,7?7W7|7
7[<e<s<x<}<
=1=9=?=G=O=Z=d=n=
>&>.>@>M>S>
>G?O?]?
b0k0}0
1K1T1f1s1y1
3&383E3K3Q3
4Q4Z4`4f4k4v4~4
5"5'5j5r5
6 6(6<6I6Q6V6
6A7T7Z7b7k7
8#80878
8@9F9N9W9k9x9
<%<G<X<]<c<n<s<
= ='=.=5=E=T=]=o=|=
=?>H>Z>g>m>s>
?)?5?Q?c?m?
050G0Q0
051R1f1p1
2"2(2:2E2M2Z2d2o2
3*343:3E3R3Y3o3
4-434O4g4~4
5!525A5R5X5i5
6"626E6P6^6i6t6z6
6G7U7^7i7r7
8"8:8B8R8j8
9"9(9.949g9w9}9
: :<:V:^:d:j:|:
:+;3;;;C;S;b;q;
< <&<,<4<<<E<M<S<e<m<t<
=(=7=>=D=I=N=S=Y=_=d=j=r=z=
>%>2><>E>K>T>_>p>w>
0!0-0H0N0\0b0j0q0w0
1[3g4w4
5$5;5H5N5V5f5n5
66.6>6L6V6^6y6
7O8Z8`8e8
9/9>9H9R9
9":,:;:D:J:[:m:s:
6 6*696T6e6p6u6
7/797I7Z7a7
;7<L<S<Z<a<h<z<
151K1_1
2!2,2O2x2
7K7]7u7~7
99Q9s9
:f:t:}:
</<B<O<Z<q<
= =5=H=V=a=x=
>?>H>t>
0+0B0N0i0
1$1g1x1
2$2?2P2t2
474K4_4
6<6I6V6~6
77A7R7`7n7
7$868N8q8w8
:+:E:U:Z:o:
; ;=;J;R;X;\;|;
=2=Z=e=
=0>H>S>v>m?
2"2-282Y2_2
3 333C3Q3r3
4#4,4C4K4a4t4
5#5*505
6$62686|6
6/7G7T7Z7i7p7
7#878K8`8i8
9*999A9O9Z9a9n9t9
;%;0;5;:;@;L;W;c;z;
<$<*<0<?<K<X<e<
=,=6=L=T=Z=p=
=#>.>6>R>Y>
11+151A1g1u1
4)4=4y4
737>7e7p7
909Q9m9y9
;N;\;j;
0Q0_0n0
1#11171=1F1U1
12&2/243>3[3m3
4)40464A4J4Z4n4v4
5$5)555:5G5V5g5l5q5v5{5
6.696d6m6
7 7+7>7J7S7X7d7t7y7
8/888a8g8m8s8
8K9Q9\9
: :5:<:N:V:\:b:m:
;$;*;0;:;@;S;^;d;q;|;
<8<E<S<]<g<q<{<
=%=/=9=C=M=W=a=k=u=
>>)>3>=>G>Q>^>l>v>
?'?1?;?H?V?`?j?t?~?
0$0*090@0I0O0U0^0e0
0<1E1N1Y1_1e1n1
2&272D2`2g2m2w2
303;3Q3c3}3
4`4l4r4
5!5P5o5
6%6+61676=6C6I6O6U6
8A8g8v8
?$?-?6?K?T?
3E3k3t3z3
44-43494?4E4K4R4Y4`4g4n4u4|4
6 798P8
^:b:f:j:n:r:v:z:~:
<G<O<a<n<
?C?W?s?}?
:U;`=e=
>!>:?A?s?
0 0,0H0W0\0a0|0
101:1F1K1P1q1
1[2I3S3`3
>)?-?1?5?9?=?A?E?
I0M0Q0U0Y0]0a0e057
: :$:(:,:0:4:8:
<4<=<C<M<R<W<\<
000c0u0
1@2V2}2
3.353A3T3Y3e3j3{3
4O4a4i4s4|4
6=6H6=8p8u8
:!:+:0:;:F:Z:
>A>F>a>m>
??*?0?;?A?O?X?]?j?o?|?
0)020y0
0E1R1c1m1s1
2A2J2R2o2S3
5~677>7k7r7
7.8?8Y8b8q8{8
829L9f9
:!;W;t<
5%555D5K5c5j5
8=8`8m8{8
8 9P9k9
0K0R0e0s0z0
1!1)1P1i1x1
2'2,212L2V2r2}2
3!3,31363W3g3
4 4>4a4l4y4
819X9a:
;*;H;R;c;h;};
?*?/?B?V?a?x?
3B4I4b4q4
5=5[5f5
6F6S6`6m6
7(8V8!9;9{9
:':=:x:
:';9;K;];o;
; <2<D<V<h<
=0D0K0R0
3)4V4F6L6U6`6p6
7+7=728r8
949X9c9p9
=$=C=a=
=@>j>r>
4<5G5R5X5a5
3061G163<3A3Q3b3
<2<N<j<v<
,282<2@2D2H2L2P2T2X2\2`2d2p2t2x2|2
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
30343t3x3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
2 2(2,2024282<2@2D2L2P2T2X2\2`2d2h2t2|2
8 8$8(8,8084888<8@8D8H8T8X8\8`8d8h8l8p8t8x8|8
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1
L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8
h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
=$=,=4=<=D=L=T=\=d=l=t=|=
?(?,?0?8?P?`?d?t?x?|?
040D0H0X0\0`0d0l0
0P6p6x6
7,787X7`7h7l7p7x7
8$8,848<8D8L8T8d8
9 9@9L9x9
: :,:h:p:x:
; ;(;<;D;L;T;X;\;d;x;
<(<0<4<P<X<\<l<
=(=H=h=p=t=
>0>P>p>
?0?P?p?
080T0X0
1X1d1p1|1
2$202<2H2T2`2l2x2
3 3,383D3P3\3h3t3
4(444@4L4X4d4p4|4
5$505<5H5T5`5l5x5
6$6(6,6064686<6@6D6H6L6P6T6X6
80848<8`=p=t=x=|=
>0>L>h>
0 0$0(00080<0@0D0H0L0P0T0X0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1`1d1h1l1p1
RF6tg7YH.exe
7cd0V`
Ur.sy5A
V)?@e_
||;Q;Mh_
`ywI1t+
:G-.T0
1R!ZT'
<"Pa!`x
?X!W!k%
+$ttE|
AS6&m1
q2UlJ^
b3GTQ=
gbA6Fs
3X$CS*<
GET<'+*
+!A-ZE
<_mb3E
[-: X~
@Z<m+C
i|C/6LY
(+%.wu
|L'L4?
ZbmcmWnM
|b7|%1_
+EN<,b
J1c,[D
UdYdghWq&
TU`Msl
@."_MDojS
jCWgVx-@
hGrn25
cm=zM,i
&:*22d
OUV$pY3
ffabi-Z
0EqrEJ
AlB%P0
_:7$@H
":wF52
*qQFA^-n
1@:Wp3
$Z">>r
96T<<C
h#5aA[].
Cw|4_y
Sc3YMT
Fh_K]O
@ue9O3
O {,o7
'-y&<#
z-/3i5MD0i
IiTgxfGeMUqy
+Dk?oF
:%B37d
t3t5sc
=R+[RMvP
R#0GE ?
Ah.(\R
7Fb)L*
u6 ?Ib
DB{8jG
A\+{}8
?H.OV6
#/'9z'
h)GOFu4
VT*ir?
-sX-G
uTV{PY
fi:*_xP
0 WGe\@
"i)G[Rj
K;9zB
!d&GWs
8:@T6q
6stb|5
yNZi3X
5L3<o)
T/H185
2lX"slX:]-N
R*[!dW
73IhzK
i4Sx2{
2Z(E2{
)r?e1Z
?${ETJ
qd."s=
a*1-2=c
3VCH|HZHN
WC/\M2
[WW[U1
V]2i@o
Xyy^MC}m
RV^6`f
Dl3Ey&
V+W/s&@
Cs:iw+
]0DQ:9lE
fu>`D#x
+AYTTD
HR'gJp
N q0%n
b bE=:#
t`sG5"'Fg&YlCZ
b:*6fy
Ts-hFh
pe)$Dp
dZMvs"
`c3|bD
`c*-n#'
1qXnO*m
E8\eNiT
q$2Px8
$JYgr<
)Ex|f"B
gsDYl;
xt~~\,
:D26##Ip<:B
-R!n.3NO
"D:Y4jQ
nPDUiFNk
7j{J(p
YDnRGp
gw8p/t
zIQ,m`j
.MDCt&
9h QGk
2/&@Yt
G$T2=z"}
CCYfP+
]#6)Ej
\HW*=@d
Ug61l}yF'"
V^\V^^QQV
NcYQquY
rZYi])D
pLUmHl
m4vl]V^L5
M1k=,RWI
DIm%I"
' WJ#+
4?Br\pv
VHZUcO
QRFm+n^JF
5+*-jNAr
]5M~Zq+
{7_0Yg=
]+giY
]c|>X9
p|M8m|v
_m8]go
go>gLd
T4+vo
JVvkL
/<:aH3];0p
-vdC=G
wwF6jY
&_Xi(~G
IouZnU,;
p}G:}x
`GS[E[t
_N~I{v
=3*;dQ
yZwodR
+-_-(Ov
x["aJV
Ru)Cx\w'
]ndiV#
Ytm#A~
^6|x3n
n^=u>
q:yE~b
BTWYzv
F4ND;{
)5%* P
7YI&84w
j*8mmE
v0uyB\
#KL<N9
q5L$VR
kh7.e\
#/4_[n
bW5AQaa
b$"5DR
K"I.C2
wCI(mZ
}aogNy
lvS$IQ
Js(Mrp
Qq,R9)
Dq<Y7so
b)BfkY'
u%q_o^
gz!x*[
Y^Z|.FL
gw"6YH:
`F@GDN
Yp}(qS
XD'1/
xz/ASl
5L{VF;
\cf/8~
%TeP,;
?I:E)[
ZE$Up'
vb#*N.Y{
Q*AoOi%
>r+^uw0M
<~IdJcyH*
/`x|CFDb
hRc7Ie
jNHEiXC
pl)!jz
3]GMrA
C2'N]$
3#0`4a
BWrwuH
vM|[wz
0rS_M_
WzvD/
%3\tT8Q
:YWZ3x
<'o/fz
\Fo-R.
M!Ogyt
iE'gEq}8
Tp"aMm
T1Tebkl
h&&2G1
4o)2A
JuNY0t
?Z{^$a[
=(z=v)
+)n1K~i"
CG3!8B
zl7f)4
#~dfm~NF
QHg,|-0_s
n~0QFvN
958ZIC
H3SZbg
%5b">a
Wzp>+OG
j-6|VS
}'{.4$
W6isM
3>=|cv
q#[z.qY
?Ntc]:
q+9*U7
@#R(|Q
,HR!n=
!d5DcN1
V}:`r\o
msoF7o
,O|40`s
XR3NJyr
}`|,[,
>4d'et
r DGnz
'ynIAg
XVhSvn
zow+c]m
`^n0HvAQ
$oh"j8|
6*=/ju
?)d!FC
&27iMq
\m{^ 5V
R/9`>j
XU`|J*
]R^Fm#
`{e\yf@
XLoJA
k!m|4
K]48JJ/x@
l<fJeU
?J2St,
@wh0tr'
7nWkl&
n{n^7uzj
y,.-R(:
-qH<C:
<IB&lo
|Y~r}
J.^FIF
g9&0)2
!Grs"vN
ytHwL<
v}uA+m
*1Sc1`
><oA8OB
M(sBUf
(**/m(A
L^2SG-h
q{~xCY
rgTZaf
g%ypRf,J
$8zU|m
uzE'Em#8
bY#Niz
u.3HB5
uwZAS7
(5n9uw</
:W%I\SIp[k
a$M{>$
SBJIxw
\|><lFA
5p.Zd+
R#]Phd
A93/yxV
iV3lP:
s]$E5p&
`8UDJE
BFxVeh
! iAK`"
U&/o@Aj
7qv0qu
cd(bqk
O=Z48<,
$>N9;b73
T ;BL4B8n
UnUzp[
iBbPvOk$
jd,4"q
zi5*@G
g30MXl
8(.Dl~
y,jY]D
2%&W$A
:ifE`H+
%gmdD#
|fX~i*
uUDg~w
PY/V+}K
-ax# x
@P;3X[
E "UhMi
(\W4J6
]jPUCYp
z0YaoN\
NPE*v_
.PlR?`8
_8s3K%
Cf/hd{
%RP6_5
|>s2{*
!V;=yOW
D+-'X2
;90RrkCD
]fF*TwH
}#8e e}R<7.
@x9%Q:
Fd&=V(
'w)DV[~K
"X2;i==
bnsT31d
5a}rHo
ol<s16
P1hi[h
{&=)Mm
S_T!]J
A05WnD
Fi<u1;
ey8$e]
'r2k(iXk
aQR~`k
HlsGYu
g^Iuj:L
/|z7"2.
|:Dq2"}1
0UnK7#
y0z{(
Pbakc,
L&dD%<3
8+w:MI
TT#'Et5R
OCrX8e
%KBHq~
3>B4N[
_YiZ"W!
s0 Gi"
.K<m8,
_qt9y+
BC]eo'
bF{GF|
14:kr;
IS(Z?I
YR$LbC9
v#%HIC
SEd uvo
|8d#2C 3G~J
N('Rsrg
5kp[rLX
oK._Vz
`!jz+Q
+n7#mh2HA%
y7][PWwai
G?H<7g
)ag@0_x9
c'\9u16
if_[Z
au!+}~y
bA<=g^
X*190@
LnyLeW:
.Mg?Gd
7rh?n4
zvs+6>
8cE?/^
6l4lx?
_Q%5\7
n+zRE+Q0wCO
/%Ma"1
*S={#_
iY|+#)L
jP,B/t
%\ken^~
BZ}m }
$@<@"t
-LS7NJ
, \0n
~h:dfT
q5=Q3'
72U{F=s
<c5JXl
TK?q[+
6y+mpmh`
=hyX@+
7@w=Mh
)CI.Us
*Y}z)!gl
$(H3oH
EP9v~{%t~
bw3p*4v
LaMjW*
kfIN){h
Z/fHv!
!Q{P7uFp
YBWkwe
iJef/L
#XVd"e
X)bz%;
<Tk2h&
yC.V[2p
qsXT?UyK
|Q5Pc&
KFw&wdc
;Y3xW'1M_
w%@Xb90
dw78xh
?h7RJ0
k2vWq[
s{8]mG
NSx[aN>
l3Wj~{*-
oz}Y(]
8)AkkJ
N1MilP
t]p]k(k
0_8Yt)x
GaH3,<V
'^E:{7
j~dR)p
}w+z:M3
ZR&vTg
zS?f](
*|{*_f
!"]<AZ
6<*B$G
FbpUrDl
sTY2Boazrc
P5>+o*
>T0b5lp
Z#q+%N
AM7}gh
p[Zw N
_uo7!n
TKO"OZ
N1<GA|'
L'}{9E
f86L?VG
D^-gEG
s(q=A|
~Rf&&?
d#\\>,
|z<+*p
lz%-]@
.laPNEo
Z@0\Ql`
;]""0U
JYq'p#
huqB.r
pD=|"E;
4tQu:j
(/tv&n
0b#+yj
G4oQ!2
!'$OR3
Kw1CYf_
PEqvH")
c2h;I;
<p?kQMy
N6eNwb:c)Vt
?T'Y_tC
he<JNp
[e}t_\ g
,P55e-,
hWh ~zG
?h@ZxQ
0q}8y\
23I).5
dDLQ|A
K6jmnl;
uC1=`;&
8cf+3~
;Sit<&SS
D)}utv
/h"uJB
?6D]>A=
fbB)cn
1&n/z`
#%]kha
c\<{u1
gKyOoMR
D}%6J{
[iYU|F<
yAGXulg
Nf[(rmf>
b9G1~9
HE">1M
RUi>&i
_sN/Q`
j;>lmY
FP@[qN
@?Ii`v
'h[e^~
-qQz8V
sc-YCp[
4{;Xs_
)zSAp
,*^x[S
(km%V^
~;`km#
Pn\IbK
x(uxM;p
g/=d&:_
erB`Hr
@c8&24x:
*IKmGgX
|[t9t^*C
M%GJj
lm51&
$h%*I>
[uinx"zV
V"EIJy
M^+r"&
o*!Qkn
{Vf^|^
I+n]-
wbs=&U
v0J$/.Wv
m-^A:z#
4[w FW!r
SNK!]
s1C+U]
Ykjg)H
+3qm"C
x?O<!))<
0afg6`a
?hh~hh
g0a`3f
RF6tg7YH.exe
Path=%appdata%
Setup=RF6tg7YH.exe
TempMode
Silent=1
Overwrite=1
Update=U
?*<>|"
*messages***
STRINGS
DIALOG
DIRECTION
s$%s:%s
CAPTION
Maximum allowed array size (%u) is exceeded
gCrypt32.dll
CryptProtectMemory failed
CryptUnprotectMemory failed
kernel32
version.dll
DXGIDebug.dll
sfc_os.dll
SSPICLI.DLL
rsaenh.dll
UXTheme.dll
dwmapi.dll
cryptbase.dll
lpk.dll
usp10.dll
clbcatq.dll
comres.dll
ws2_32.dll
ws2help.dll
psapi.dll
ieframe.dll
ntshrui.dll
atl.dll
setupapi.dll
apphelp.dll
userenv.dll
netapi32.dll
shdocvw.dll
crypt32.dll
msasn1.dll
cryptui.dll
wintrust.dll
shell32.dll
secur32.dll
cabinet.dll
oleaccrc.dll
ntmarta.dll
profapi.dll
WindowsCodecs.dll
srvcli.dll
cscapi.dll
slc.dll
imageres.dll
dnsapi.DLL
iphlpapi.DLL
WINNSI.DLL
netutils.dll
mpr.dll
devrtl.dll
propsys.dll
mlang.dll
samcli.dll
samlib.dll
wkscli.dll
dfscli.dll
browcli.dll
rasadhlp.dll
dhcpcsvc6.dll
dhcpcsvc.dll
XmlLite.dll
linkinfo.dll
cryptsp.dll
RpcRtRemote.dll
aclui.dll
dsrole.dll
peerdist.dll
uxtheme.dll
Please remove %s from %s folder. It is unsecure to run %s until it is done.
%s: %s
AES-0017
z%s%02d
#+3;CScs
#+3;CScs
@UnZip: Internal error 1
@@ARarHtmlClassName
Shell.Explorer
about:blank
<html>
<head><meta http-equiv="content-type" content="text/html; charset=
utf-8"></head>
</html>
<style>
</style>
<style>body{font-family:"Arial";font-size:12;}</style>
&nbsp;
riched20.dll
RarSFX
STATIC
REPLACEFILEDLG
RENAMEDLG
GETPASSWORD1
winrarsfxmappingfile.tmp
sfxname
%4d-%02d-%02d-%02d-%02d-%02d-%03d
sfxstime
STARTDLG
sfxcmd
sfxpar
LICENSEDLG
__tmp_rar_sfx_access_check_%u
-el -s2 "-d%s" "-sp%s"
Delete
Silent
Overwrite
TempMode
License
Presetup
Shortcut
SavePath
Update
SetupCode
%s.%d.tmp
Software\Microsoft\Windows\CurrentVersion
ProgramFilesDir
%s%s%u
Install
Software\WinRAR SFX
KERNEL32.DLL
B<pi-ms-win-core-fibers-l1-1-1
<pi-ms-win-core-synch-l1-2-0
api-ms-
(null)
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
(
((((( H
Bapi-ms-win-appmodel-runtime-l1-1-1
<pi-ms-win-core-datetime-l1-1-1
<pi-ms-win-core-fibers-l1-1-1
<pi-ms-win-core-file-l2-1-1
<pi-ms-win-core-localization-l1-2-1
<pi-ms-win-core-localization-obsolete-l1-2-0
<pi-ms-win-core-processthreads-l1-1-2
<pi-ms-win-core-string-l1-1-0
<pi-ms-win-core-synch-l1-2-0
<pi-ms-win-core-sysinfo-l1-2-1
<pi-ms-win-core-winrt-l1-1-0
<pi-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Bja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ASKNEXTVOL
GETPASSWORD1
LICENSEDLG
RENAMEDLG
REPLACEFILEDLG
STARTDLG
MS Shell Dlg 2
MS Shell Dlg 2
MS Shell Dlg 2
MS Shell Dlg 2
MS Shell Dlg 2
WinRAR
MS Shell Dlg 2
hRichEdit20W
jmsctls_progress32
"%s"
Windows.U
V<ul><li>
<b><i>
</i></b>,
.</li><br><br>S<ul><li>
<b><i>
</i></b>,
.</li><br><br>><li>
<b><i>
</i></b>
.</li><br><br>2<li>
.</li></ul>
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Variant.Zusy.487547
ClamAV Win.Dropper.njRAT-9986242-0
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.487547
K7GW Clean
CrowdStrike win/malicious_confidence_90% (D)
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.G
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos Generic ML PUA (PUA)
F-Secure Backdoor.BDS/Backdoor.Gen
DrWeb Clean
Zillya Trojan.Zenpak.Win32.19996
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
Trapmine Clean
FireEye Generic.mg.88c5868c1384d86f
Emsisoft Gen:Variant.Lazy.388394 (B)
Ikarus Trojan.MSIL.Agent
GData Gen:Variant.Lazy.388394
Jiangmin Clean
Webroot Clean
Avira BDS/Backdoor.Gen
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.D5ED2A
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-PSW.MSIL.Stealer.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=88)
DeepInstinct MALICIOUS
VBA32 Trojan.Zenpak
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36662.xq0@aKUqWUhi
AVG Win32:SpywareX-gen [Trj]
Cybereason malicious.7fef93
Avast Win32:SpywareX-gen [Trj]
No IRMA results available.