Static | ZeroBOX

PE Compile Time

2021-06-18 22:45:41

PE Imphash

6b43713c2dcdf19e54a9964767500d9f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00042278 0x00042400 6.39261195882
.rdata 0x00044000 0x00013ddc 0x00013e00 6.34890608051
.data 0x00058000 0x00012588 0x00002400 4.1200481277
.pdata 0x0006b000 0x000030cc 0x00003200 5.59599617023
.rsrc 0x0006f000 0x0000a2cd 0x0000a400 6.29571655514

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000743d0 0x00004890 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000743d0 0x00004890 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000743d0 0x00004890 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000743d0 0x00004890 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000743d0 0x00004890 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00078c60 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00078cac 0x0000049c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00079148 0x00000185 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library WINMM.dll:
0x444558 timeGetTime
Library WININET.dll:
0x4444f8 InternetCloseHandle
0x444500 InternetOpenA
0x444508 HttpSendRequestA
0x444510 InternetErrorDlg
0x444518 HttpOpenRequestA
0x444520 InternetSetOptionA
0x444528 InternetReadFile
0x444530 InternetCrackUrlA
0x444538 InternetConnectA
0x444540 InternetOpenUrlA
0x444548 HttpQueryInfoA
Library VERSION.dll:
0x4444b0 GetFileVersionInfoA
0x4444b8 VerQueryValueA
Library WINHTTP.dll:
0x4444d0 WinHttpCloseHandle
0x4444d8 WinHttpOpen
Library COMCTL32.dll:
Library KERNEL32.dll:
0x444050 GetLocaleInfoA
0x444058 GetStringTypeW
0x444060 LCMapStringW
0x444068 LCMapStringA
0x444078 RtlVirtualUnwind
0x444080 GetCurrentProcessId
0x444088 GetTickCount
0x444098 GetStringTypeA
0x4440a0 HeapReAlloc
0x4440a8 MoveFileExA
0x4440b0 FreeLibrary
0x4440b8 Sleep
0x4440c0 GetProcAddress
0x4440c8 LoadLibraryA
0x4440d0 GetVersion
0x4440d8 WaitForSingleObject
0x4440e0 SetEvent
0x4440e8 TerminateThread
0x4440f0 CreateEventA
0x4440f8 GetLastError
0x444100 GetModuleHandleA
0x444108 CloseHandle
0x444110 CreateMutexA
0x444118 ReleaseMutex
0x444120 CreateThread
0x444130 GlobalFree
0x444138 DeleteFileA
0x444150 SetStdHandle
0x444160 GetExitCodeProcess
0x444168 CreateProcessA
0x444178 lstrlenA
0x444180 FormatMessageA
0x444188 GetShortPathNameA
0x444198 LocalAlloc
0x4441a0 GetVersionExA
0x4441a8 LocalFree
0x4441d0 SetFilePointer
0x4441d8 HeapSize
0x4441e0 ReadFile
0x4441e8 FlushFileBuffers
0x4441f0 GetConsoleMode
0x4441f8 GetConsoleCP
0x444200 GetStartupInfoA
0x444208 GetFileType
0x444210 SetHandleCount
0x444218 GetOEMCP
0x444220 GetACP
0x444228 GetCPInfo
0x444230 FlsAlloc
0x444238 TlsSetValue
0x444240 SetLastError
0x444248 FlsFree
0x444250 TlsFree
0x444258 FlsSetValue
0x444260 WriteConsoleA
0x444268 GetConsoleOutputCP
0x444270 WriteConsoleW
0x444278 CreateFileA
0x444280 CompareStringA
0x444288 CompareStringW
0x444290 SetEndOfFile
0x4442a0 RaiseException
0x4442a8 HeapFree
0x4442b0 HeapAlloc
0x4442c8 FindFirstFileA
0x4442d0 FindNextFileA
0x4442d8 FindClose
0x4442e0 MoveFileA
0x4442e8 ExitProcess
0x4442f0 GetCurrentProcess
0x4442f8 GetDateFormatA
0x444300 GetTimeFormatA
0x444308 GetDriveTypeA
0x444310 GetFullPathNameA
0x444328 ExitThread
0x444330 GetCurrentThreadId
0x444338 MultiByteToWideChar
0x444340 WideCharToMultiByte
0x444348 GetFileAttributesA
0x444350 CreateDirectoryA
0x444358 RemoveDirectoryA
0x444360 GetCommandLineA
0x444368 GetProcessHeap
0x444370 HeapSetInformation
0x444378 HeapCreate
0x444380 WriteFile
0x444388 GetStdHandle
0x444390 GetModuleFileNameA
0x444398 RtlUnwindEx
0x4443a0 TerminateProcess
0x4443b8 IsDebuggerPresent
0x4443c0 RtlCaptureContext
0x4443c8 FlsGetValue
Library USER32.dll:
0x4443d8 SetTimer
0x4443e0 GetWindowRect
0x4443e8 KillTimer
0x4443f0 SetWindowPos
0x4443f8 GetDesktopWindow
0x444400 DestroyWindow
0x444408 GetMessageA
0x444410 GetWindowLongPtrA
0x444418 PostThreadMessageA
0x444420 MonitorFromPoint
0x444428 LoadIconA
0x444430 SendMessageA
0x444438 GetMonitorInfoA
0x444440 TranslateMessage
0x444448 CreateWindowExA
0x444450 PeekMessageA
0x444458 DefWindowProcA
0x444460 GetCursorPos
0x444468 ShowWindow
0x444470 SetWindowLongPtrA
0x444478 DispatchMessageA
0x444488 LoadCursorA
0x444490 ValidateRect
0x444498 RegisterClassA
Library ADVAPI32.dll:
0x444010 GetUserNameA
0x444018 EqualSid
0x444030 SetEntriesInAclA

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@SUVWH
@SUVWATH
A\_^][
@SUVWATH
A\_^][
@SUVWATAUAVAWH
(A_A^A]A\_^][
SUVWATAUAVAW
A_A^A]A\_^][
@SUVWH
@SUVWATAUH
8A]A\_^][
SUVWATAUAVAW
A_A^A]A\_^][
SUVWATAUAVAW
D$|+CD
D$h+CD
D$l+CH
@SUVWH
@SUVWATAUAV
u'I9|$(t H
A^A]A\_^][
SUWATAUAVAWH
`A_A^A]A\_][
@SUVWH
@SUVWATAUAVH
0A^A]A\_^][
@SUVWATAUAVH
0A^A]A\_^][
@SUVWH
@SUVWATAUH
(A]A\_^][
H93tIH
H93tIH
@SVWATAWH
A_A\_^[
SUVWATAUAVAWH
+l$T+-h
T$P}NH
np9Fp~
T$P}TL
A_A^A]A\_^][
@SUVWH
@SUVWH
@SUVWATAUH
8A]A\_^][
@SUVWATAUAVH
0A^A]A\_^][
@SUVWATH
0A\_^][
@SUVWH
@SUVWH
@SUVWATAUH
(A]A\_^][
@SUVWATH
A\_^][
tjSUVWATH
A\_^][
SUVWATAUAVAW
t<L9/t7D9o
A_A^A]A\_^][
@USVWATH
A\_^[]
D$(tTH
H9l$(u
@SUVWH
@SUVWATH
A\_^][
@SUVWATAUH
hA]A\_^][
@SUVWATAUAVH
A^A]A\_^][
@SUVWATH
A\_^][
<;!t"H
@SUVWATAUAVH
u*B:,+u
A^A]A\_^][
@SUVWATAUAVAWH
Hc\$pHc
(A_A^A]A\_^][
@SUVWH
@s"fff
T9D$PueI
A <$D+
H3C(H3
H3CXH3
H3C8H3
H3C`H3
H3ChH3
H3CpH3
H3C H3CHH
l$8r[3
l$8rAL
\$@tGH
D$,<Zu@3
d$ r%A
uD9D$ H
@SUVWATAUAVAWL
D$`u$3
t$HcG<
H;|80u
xA_A^A]A\_^][
|$Hfff
9t$xt^H
9t$xt^H
D$8t#A
D9T$@t~I
D$Ht#A
D8d$Xt
D8d$Xt
D8t$Xt
~gHcD$0H
HcD$8H
9t$4t'H
HcD$0H+
;@8|$Ht
D$0L;5d
t^9l$@uX
MZuSHc
|$Xt>H
|$Xt:H
l$`+l$D+
D9|$0t
HcL$4H
t$Vt6fff
@8l$&H
T$&t;f
D$Xt&A
u!8D$ht
LcA<E3
f;D$@uhA
f;D$@u:A
t2HcD$DH
t2HcD$DH
@8t$Ht
|$x<at@<rt4<wt&
<dt(<it$<ot <xt
L$HtuA
\$@uJD
|$Xt>H
|$Xt=H
l$`+l$D+
Hct$PH
slHcD$0H
D$PH;58
D$@H;58
D$Pt#A
T$(t#A
T$(t#A
T$(t#A
D$8t#A
8@8|$Au"@
D$Xt&A
u!8D$ht
D$@H;=
t'H9-P
x~H9/tyH
d$@utH
gfffffffH
D$8t#A
\$`fff
D$Ht#A
D$Ht#A
T$Dr%ff
D$0u?3
t$`D+=
D$0u?3
t$`D+=
r,f9l$8H
u!A9u
r:f9\$2D
\$hfD3
\$xyFA
l$0u.fff
@SUVWH
@SUVWATH
A\_^][
@SUVWATH
9|$ t@L
@A\_^][
@SUVWH
9|$ t6H
@SUVWATH
A\_^][
@SUVWH
@SUVWH
@SUVWH
9/~ A
@SUVWH
L$ SUVWATAUAVAWH
A_A^A]A\_^][
@SUVWATH
PA\_^][
@SUVWH
@SUVWH
@SUVWATAUH
(A]A\_^][
@SUVWH
@SUVWATAUH
HA]A\_^][
@SUVWH
@SUVWH
@SUVWATH
@A\_^][
@SUVWATAUH
(A]A\_^][
@SUVWATAUAVAWH
(A_A^A]A\_^][
SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
@SUVWATAUH
A]A\_^][
@SUVWATAUL
A]A\_^][
@SUVWATAUAVAWH
HA_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
@SUVWATH
A\_^][
@SUVWATL
A\_^][
L$ SVWH
@SUVWH
@SUVWATL
A\_^][
@SUVWH
9D$@~+H
SUVWATAUAVAW
A_A^A]A\_^][
SUVWATAUAVAW
L$0u)I
L$(u&H
A_A^A]A\_^][
99t6~4
SUVWATAUAVAW
L$ uI
A_A^A]A\_^][
@SUVWATAUH
xA]A\_^][
u 9D$Ht
@SUVWATH
@A\_^][
@SUVWATAUH
(A]A\_^][
@SUVWATH
@A\_^][
@SUVWATH
@A\_^][
@SUVWATAUAVAWH
D$ ~qL
HA_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
t$ AWH
H9APt,
D$pH)C
WAVAWH
PA_A^_
|$ AVH
@UWAVH
|$ AVH
@SUVWATAUAVAWH
A_A^A]A\_^][
WATAUAVAWH
C`H9Ch
uID8kLt8
A_A^A]A\_
|$ AVH
@UVWAUH
8A]_^]
8A]_^]
\$0H9n
@SATAUAVAWH
@A_A^A]A\[
@A_A^A]A\[
WATAUAVAWH
A_A^A]A\_
\$ AVH
t$8H9C
UWAUAWH
A_A]_]
A_A]_]
A_A]_]
UVWATAUAVAWH
0A_A^A]A\_^]
SATAWH
`A_A\[
t$PH9u
`A_A\[
UAVAWH
H9A t1H
SUVWATAUAVAWH
HA_A^A]A\_^][
WATAUAVAWH
0A_A^A]A\_
|$ AVH
\$ UVAVL
\$8A^^]
@SATAVAWH
A_A^A\[
|$ AVH
WAVAWH
KpH;Kxs
Cp8CHt
gdiplus.dll
sha224
abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq
sha256
md != NULL
.\src\hashes\sha2\sha256.c
in != NULL
out != NULL
c:\users\simplehelp\workspace\runner\native\libtom\libtomcrypt\src\hashes\sha2\sha224.c
ltc_mp.name != NULL
key != NULL
.\src\pk\rsa\rsa_import.c
Doing PSS decode
2) RSA Decode failed
1) RSA Decode failed
stat != NULL
sig != NULL
hash != NULL
.\src\pk\rsa\rsa_verify_hash.c
sha3_256
.\src\hashes\sha3\sha3_256.c
.\src\misc\crypt\crypt_register_hash.c
name != NULL
.\src\misc\crypt\crypt_find_hash.c
.\src\hashes\mixedhash\mixed.c
LibTomMath
a != NULL
.\src\math\ltm_desc.c
a != ((void *)0)
b != NULL
c != NULL
d != NULL
LTC_ARGCHK '%s' failure on line %d of file %s
.\src\pk\asn1\der\sequence\der_decode_sequence_multi.c
list != NULL
.\src\pk\asn1\der\sequence\der_decode_sequence_ex.c
res != NULL
msghash != NULL
.\src\pk\pkcs1\pkcs_1_pss_decode.c
outlen != NULL
.\src\pk\rsa\rsa_exptmod.c
.\src\pk\rsa\rsa_make_key.c
modulus != NULL
kB != NULL
kA != NULL
C != NULL
B != NULL
A != NULL
.\src\pk\ecc\ltc_ecc_mul2add.c
mp != NULL
P != NULL
.\src\pk\ecc\ltc_ecc_map.c
R != NULL
.\src\pk\ecc\ltc_ecc_projective_dbl_point.c
Q != NULL
.\src\pk\ecc\ltc_ecc_projective_add_point.c
G != NULL
k != NULL
.\src\pk\ecc\ltc_ecc_mulmod.c
inlen != NULL
.\src\pk\asn1\der\choice\der_decode_choice.c
.\src\pk\asn1\der\sequence\der_length_sequence.c
.\src\pk\asn1\der\utctime\der_decode_utctime.c
.\src\pk\asn1\der\utf8\der_length_utf8_string.c
.\src\pk\asn1\der\utf8\der_decode_utf8_string.c
octets != NULL
.\src\pk\asn1\der\printable_string\der_length_printable_string.c
.\src\pk\asn1\der\printable_string\der_decode_printable_string.c
.\src\pk\asn1\der\ia5\der_length_ia5_string.c
.\src\pk\asn1\der\ia5\der_decode_ia5_string.c
words != NULL
.\src\pk\asn1\der\object_identifier\der_length_object_identifier.c
.\src\pk\asn1\der\object_identifier\der_decode_object_identifier.c
.\src\pk\asn1\der\octet\der_length_octet_string.c
.\src\pk\asn1\der\octet\der_decode_octet_string.c
.\src\pk\asn1\der\bit\der_length_bit_string.c
.\src\pk\asn1\der\bit\der_decode_bit_string.c
.\src\pk\asn1\der\short_integer\der_length_short_integer.c
num != NULL
.\src\pk\asn1\der\short_integer\der_decode_short_integer.c
.\src\pk\asn1\der\integer\der_length_integer.c
.\src\pk\asn1\der\integer\der_decode_integer.c
.\src\pk\asn1\der\boolean\der_length_boolean.c
.\src\pk\asn1\der\boolean\der_decode_boolean.c
out != ((void *)0)
.\src\misc\zeromem.c
mask != NULL
.\src\pk\pkcs1\pkcs_1_mgf1.c
seed != NULL
N != NULL
.\src\math\rand_prime.c
utctime != NULL
.\src\pk\asn1\der\utctime\der_length_utctime.c
@@@
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
W/q#IX
Dx,2$E
Ho*[8'
4JpI?=
=dn"M,
AA40J6
Jjw[Sc
YOQ=Nm}
(noLb5
87;y)5'
!puhQ*
Pd#93-
I.S(ja
SY?gds
82Ff0$
M'(:fjgl4
z*1j=?~
-*Tl}T
8=]V,q
Nt`#^;
XZM4P?
lwP+WE
XM<UMF
zs;~m*
KopCw;n
W=m8I`X
R+42W
tgL/dn
CorExitProcess
mscoree.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
bad allocation
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
KERNEL32.DLL
DecodePointer
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
InitializeCriticalSectionAndSpinCount
kernel32.dll
UTF-16LE
UNICODE
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
CONOUT$
1#QNAN
1#SNAN
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+/
WARNING: Error registering mixed hash
ERROR - unable to import public key.
ERROR - signature verification failed.
[Extractor] Performing reinstall...
[Extractor] Performing repair...
JWrapper-
[Extractor] Creating unrestricted directory under %s
unrestricted
[Extractor] Creating %s
JWApps
JWAppsSharedConfig
jwutils_win64.dll
[Extractor] Located existing JW DLL: %s
[Extractor] Successfully loaded DLL. JW looks good.
LoadLibrary
Extractor
[Extractor] [SEVERE] Unable to load existing JW dll.
[Extractor] [SEVERE] Unable to locate existing JW dll.
windowslauncher.exe
javaw.exe
java.exe
unpack200.exe
[Locating UP200] %s
[Locating UP200] Result is %s
%Y-%m-%d-%H-%M-%S
%s-%03d.log
Wrapper-
[Extractor] Logging to %s
[Extractor] Opening the file for writing returned %d
[Extractor] Working dir is '%s'
[Extractor] Base64 deconding failed as input_length is not aligned
[Extractor] Base64 deconding failed as malloc failed to init %d
[Rename] The target already exists. Deleting.
[Rename] Could not rename '%s' to '%s' [%d]
[Rename] Windows - this FS seems to not supported renaming. Trying alternative method...
[Rename] MoveFileEx worked. Assuming success.
MoveFileEx
[Rename] [FAIL] Could not rename '%s' to '%s' [%d]
[Rename] Can do no better than a copy on this filesystem
[Rename] Created folder %s
[Rename] Copy failed too! Severe filesystem issues.
[Rename] Copied %s to %s
[Rename] File '%s' renamed to '%s'
[Extractor] Copying FILE %s
[Extractor] *************************** Unable to open source file for copy %s
[Extractor] *************************** Unable to open destination file for copy %s
[CopyFolder] SourceDir from '%s' is NULL
[CopyFolder] Copying DIR %s
[CopyFolder] *************************** Failed to copy %s to %s (could not create target folder)
[CopyFolder] *************************** Failed to copy %s to %s
[CopyFolder] Copying FILE %s
[CopyFolder] *************************** Unable to open source file for copy %s
[CopyFolder] *************************** Unable to open destination file for copy %s
-complete
%ld-%ld
JWrapperTemp-
%lu-%ld
JWLaunchProperties-
[Extractor][Spawn][%d] %s
Launching
[Extractor] Launching '%s' from master folder '%s' of class %d using JRE '%s'
JWrapperLaunch
Unable to open launch file %s
LaunchFile VER
Class OnUpdate
App Name
OS ICNS
URL Required
jvmMem (old)
jvmStack (old)
[Extractor] Using private JRE %s
No private JRE available!
JRE-LastSuccessfulOptions-
[Extractor] JRE LSO file is %s
[Extractor] Checking for existing system JRE %s
-Xmx%dm%c
-Xms%dm%c
[Extractor] Building classpath
Classpath Count
Classpath Entry
[Extractor] Creating launch properties
update_url
app_dir
jre_name
launched_from_dynprops
[Extractor] Checking LSO file
[Extractor] Reading %s
[Extractor] LSO file does exist. Retrying (%d)...
[Extractor] JRE LSO file exists
LSO Count
[Extractor] Found %ld JVM Options
jvm_options_count
LSO Entry
jvm_options_%d
[Extractor] Launch Prop: %s = %s
[Extractor] Launch Prop: %s = %s...
JRE LSO file does not exist
Not a private JRE (no need to check for LSO file)
[Extractor] Writing launch properties file
[Extractor] Writing launch properties to %s (length: %d)
[Retry] Writing launch properties to %s
Unable to write Launch Properties file! Cannot run!
[Extractor] Writing to file
[Extractor] Finished writing launch properties file
Extra Args Count
[Extractor] Reading %ld extra args
Extra Args Entry
Main Class JRECompatibility
[Extractor] Read JRE compatibility class %s
Main Class PostInstall
Main Class PreUninstall
App JVM Option Count
[Extractor] jvmArgCount:%d emptyArgs:%d so addToJVM:%d
[Extractor] Additional JRE option count is %d
App JVM Option Entry
[Extractor] Added option %s
[Extractor] Skipping option %s
Must Fork
[Extractor] Appending %d command line args
[Extractor] [Launch] Executable: %s
[Extractor] [Launch] Class: %s
[Extractor] [Launch] JVM Argument %d: %s
[Extractor] [Launch] ClassPath %d: %s
[Extractor] [Launch] App Argument %d: %s
[Extractor] This is a newer extractor... launchclass is %d
[Extractor] JRE folder is %s
[Extractor] Force spawn is %d so attempting to launch via JNI
JNI Launch
[Extractor] Return code for JNI launch was %d
[Extractor] JNI launch failed. Attempting legacy spawn instead
[Extractor] Attempting spawn launch
Spawn launch
***************************
[ERROR] Attempt to launch app failed with return code %ld! (app likely did not launch at all)
http://0.0.254.254
[Extractor] Invalid Update URL. Skipping...
-version.txt
?time=
[Extractor] Asked to set the Windows APP ID to '%s'
[Extractor] Loading shell32
shell32.dll
[Extractor] Finding procedure address for SetCurrentProcessExplicitAppUserModelID
SetCurrentProcessExplicitAppUserModelID
[Extractor] Setting app ID to %S (%s)
[Extractor] Set App ID OK
[Extractor] Versions for JREs could not be detected (%d,%d)
[Extractor] Checking JRE version requirements: %s vs required %s
[JavaCheck] Checking file version of %s
[JavaCheck] Got version size
[JavaCheck] Got version info
[JavaCheck] Queried value
[JavaCheck] Size OK
[JavaCheck] file version MS is %ld
[JavaCheck] file version LS is %ld
[JavaCheck] signature is wrong
[JavaCheck] size is null
[JavaCheck] ver query value function call failed
[JavaCheck] get file version info call failed
[JavaCheck] verSize is zero
[Extractor] Authorised to override the splash image.
[Extractor] DynamicSplash is %d, size is %d
[Extractor] Overwriting splash image at %s
[JRESearch] Checking for JRE %d
PROGRAMFILES
Java_JWAutoTest
[JRESearch] Looking at JRE %s
[JRESearch] JRE binary exists
[JRESearch] JRE binary does NOT exist
[JRESearch] JRE up200 exists
[JRESearch] JRE up200 does NOT exist
[JRESearch] JRE version is OK
[JRESearch] JRE version is NOT OK
[JRESearch] JRE unpack200 exists %s
JWrapper
[JRESearch] ********************* No latest App version even after download!
[JRESearch] JRE is valid, copying...
[JRESearch] JRE copied to %s OK
00000000000
[JRESearch] Copied JRE version is %s
[JRESearch] JRE copy failed, cannot pick up existing JRE
[JRESearch] JRE failed compatibility test
[JRESearch] JRE does not exist or does not have unpack200
cacerts
security
[Extractor] CACerts path %s exists
[Extractor] TargetCACerts path is %s
[Extractor] Removing old cacerts file
[Extractor] Result = %d
[Extractor] Override CACerts does not exist.
[Extractor] *********************** Failed to extract wrapper params - couldn't open file %s
Params
[Extractor] ************************* Failed to extract wrapper tail - couldn't open file %s
[Extractor] Found tail marker
[Extractor] The absolute wrapper path is %s
[Extractor] The executable name is %s
[Extractor] Found Params marker. Extracting now...
Params Count
++++++++++++++++++++++++++++++++++++++++++++++++
+++ Processing %d dynamic properties
Param Name
Param Value
[DynProps] Dynamic Param %d: %s=[%s...]
[DynProps] Dynamic Param %d: %s=[%s]
[DynProps] Dynamic Update URL: %s
match_versions
wrapper_autotest
show_no_ui
repair
reinstall
force_spawn
splash_buffer
splash_image
[DynProps] Splash Image is %s
[DynProps] Splash Image is %s...
[DynProps] Base64 decoding image...
[DynProps] Decode complete [image size is %d]
[DynProps] JRE name from dynamic launch properties is %s
windows_app_id
[DynProps] Windows APP ID is %s
Processing dynamic properties
[Extractor] This is an elevated run purely to prepare an installation. Will not show UI or launch an app
Extracting wrapper tail
App Version
JRE Version
GU Version
Min Splash MS
Signature Public Key
Can Override Splash
Install Type
Silent Parameter
Required Java Version
Update URL
Skip System JRE
Repair Parameter
Reinstall Parameter
[Extractor] Required Java version %s
[Extractor] Skipping System JRE
[Extractor] Will use Dynamic Update URL: %s
[Extractor] Will use Static Update URL: %s
[Extractor] Silent install is %d
[Extractor] Repair install is %d
[Extractor] Reinstall is %d
Extracting tail
[Extractor] Setting up static properties
install_type
min_splash_ms
jwsig_public_key
can_override_splash
app_name
wrapper_app_version
wrapper_gu_version
silent_parameter
java_version
skip_system_jre
[Extractor] Processed public key of length %d
[Extractor] Hex: %s
[Extractor] Public Key: %08X
[Extractor] Public key empty (no public key)
[Extractor] Public key length %d (no public key)
[Extractor] Shared dir is %s
[Extractor] Update URL is currently '%s'
[Extractor] Update URL is now '%s'
[Extractor] Master folder is %s
JreNameOverride
[JREOverride] Processing JRE Override file (JreNameOverride)
JRE Override App Name
[JREOverride] Ignoring JRE name -, keeping %s
[JREOverride] Ignoring empty JRE name, keeping %s
[JREOverride] JRE name overriden to %s
[JREOverride] No JRE name override, will continue to use %s
[Extractor] No GenericUpdater embedded, we are just a launcher
[Extractor] GenericUpdater version is %s
[Extractor] ONLINE wrapper: No App embedded, GU will download and run
[Extractor] OFFLINE wrapper: App version is %s
[Extractor] Checking for a latest valid GU
Damaged
[Extractor] The existing JWrapper install is broken. Instructing the wrapper to update.
rt.jar
[Extractor] The existing JRE is broken. Instructing the wrapper to update.
[Extractor] Latest GU version exists: %s
[Extractor] Existing JRE exists: %s
[Extractor] Our GU version is newer than existing latest version so will extract and run
[Extractor] Latest GUversion is newer or same as our version so will just run
[Extractor] Our App version is newer than existing latest version so will extract and run
[Extractor] Latest App version is newer or same as our version so will just run
[Extractor] No app version found and we are offline so will extract
[Extractor] Running without extraction now
[Extractor] No latest GU or JRE version exists, will check tail for online/offline info
[Extractor] Note: No latest JRE version exists
[Extractor] Note: Latest JRE version does exist
[Extractor] Note: No latest GU version exists
[Extractor] Note: Latest GU version does exist
[Extractor] Unable to run (we are just a launcher)
[Extractor] GU folder is %s
[Extractor] GU temp is %s
[Extractor] Unable to create GU Temp folder - assuming elevation required
nativesplash.png
[Extractor] Extracted GU and GU Version
[Extractor] Renaming GU folder to %s
[Extractor] Recreating GU location
[Extractor] CACerts override path is %s
verpatch.exe
[Extractor] Native Splash PNG path is %s
[Extractor] Configuring splash
[Extractor] Showing splash
[Extractor] Setting up a JRE (switched:%d)
Extracting Offline JRE
[Extractor] We want to query the JRE version to enable proxy detection.
[Extractor] Offline installer - no need to download JRE, will extract
[Extractor] UP200 path is %s
[Extractor] Extracting JRE archive...
[Extractor] Extracted JRE %s
[Extractor] Regenerating jsa...
-Xshare:dump
Setting up online JRE
[Extractor] Online installer - no stored JRE. Skipping system JRE.
[Extractor] Online installer - no stored JRE, will check for compatible system JRE
[Extractor] We are copying the JRE. We want to query the JRE version to enable proxy detection.
[JREDownload] Failed to pick up any existing system JRE, will download
[JREDownload] Fetching JRE Version from %s
[JREDownload] Saving into %s
[JREDownload] JRE version downloaded OK [%s]
[JREDownload] ************************** Unable to open version file! [%d]
[JREDownload] Extracting version:
[JREDownload] Spaces in version file, assuming EOF
[JREDownload] Version invalid (too long)
[JREDownload] JRE Version is %s
[JREDownload] Failed to download JRE version file
-archive.p2.l2
[JREDownload] Extracting JRE archive to %s
[JREDownload] Failed to download and extract JRE archive.
[JREDownload] Regenerating jsa...
[JREDownload] Downloaded JRE is now ready.
[JREDownload] Failed to detect or download a JRE (no jre version)
[JREDownload] Finalising setup of new JRE %s
[Extractor] Renamed JRE folder to %s
[Extractor] JRE setup. Overriding cacerts.
[Extractor] Using existing JRE of %s
DetectedProxy
[Extractor] Saving proxy configuration
[Extractor] Offline installer - app to extract.
[Extractor] APP folder is %s
[Extractor] APP temp is %s
Unable to create App Temp folder
[Extractor] Extracting App...
[Extractor] Setting permissions...
[Extractor] Online installer - no app to extract
[Extractor] Renaming App folder to %s
No latest App version even after download!
[Extractor] Will now run latest GU %s
Error starting SplashThread
JWrapperSplashWindow
Unable to register class SplashWnd
msctls_progress32
Unable to create SplashWnd
[HttpDownloader] No existing proxy settings found, so saving.
[HttpDownloader] Asked to save working proxy settings, but settings already exist, so skipping.
[HttpDownloader] Querying internet settings for proxy.
[HttpDownloader] InternetQueryOption failed! (%d)
[HttpDownloader] Direct connection (no proxy) found.
[HttpDownloader] Detected proxy: %d '%s' '%s'
[HttpDownloader] [%s] Skipping for debug purposes.
[HttpDownloader] [%s] [1] Starting download...
JWrapperDownloader
[HttpDownloader] [%s] Unable initialise HTTP connection
InternetOpen
HttpDownloader
[HttpDownloader] [%s] Attempting to crack URL
[HttpDownloader] [%s] Crack result is %d
[HttpDownloader] Hostname = %s
[HttpDownloader] nPort = %d
[HttpDownloader] lpszUrlPath = %s
[HttpDownloader] secure = %d
InternetConnect
HTTP/1.1
CrackURL
HttpOpenRequest/InternetOpenUrl
[HttpDownloader] [%s] [3] Starting download...
InternetSetOption
[HttpDownloader] Unable to set internet option correctly
HttpSendRequest
[HttpDownloader] [%s] [4] Starting download...
[HttpDownloader] [%s] Proxy thread returning as another has connected to the proxy
[HttpDownloader] [%s] Status code is %d
[HttpDownloader] [%s] InternetErrorDlg return code is %d
[HttpDownloader] [%s] Could not get proxy credentials.
[HttpDownloader] [%s] Connection setup, querying length
[HttpDownloader] [%s] Required file size is %d
[HttpDownloader] [%s] Required file size is unknown!
[HttpDownloader] [%s] Download is now active.
[HttpDownloader] [%s] Thread returning as another has worked
[HttpDownloader] [%s] Opened file. Set downloadWorked to TRUE (%d)
[HttpDownloader] [%s] Copying proxy settings.
[HttpDownloader] [%s] Using override proxy settings.
[HttpDownloader] [%s] No proxy settings detected.
Proxy Non Auto
[HttpDownloader] [%s] [Special Case] No existing proxy settings found.
[HttpDownloader] [%s] Starting to write data to file...
[HttpDownloader] [%s] Read 0 bytes so finishing.
InternetReadFile
[HttpDownloader] [%s] Warning: download complete but required length is still %d.
[HttpDownloader] [%s] Closing buffer... (download took %lf)
[HttpDownloader] Cleaning up...
[HttpDownloader] [%s] Downloading with proxy settings (%s, %s)
[HttpDownloader] [%s] Finishing off thread...
[HttpDownloader] [%s] --- End --- (worked=%d,threads=%d)
[HttpDownloader] [State Proxy] +++ Start +++
[HttpDownloader] [State Proxy] Got lock - running now.
State Proxy
[HttpDownloader] [State Proxy] Starting download attempt...
[HttpDownloader] [WPAD] +++ Start +++
[HttpDownloader] [WPAD] Got lock - running now.
[HttpDownloader] [WPAD] Detecting WPAD proxy configuration
[HttpDownloader] [WPAD] Starting download attempt...
[HttpDownloader] [Windows Proxy] +++ Start +++
[HttpDownloader] [Windows Proxy] Got lock - running now.
[HttpDownloader] [Windows Proxy] Starting download attempt...
Windows Proxy
[HttpDownloader] [Proxy Non Auto] +++ Start +++
[HttpDownloader] [Proxy Non Auto] Got lock - running now.
[HttpDownloader] [Proxy Non Auto] Starting download attempt...
[HttpDownloader] [Direct] +++ Start +++
[HttpDownloader] [Direct] Got lock - running now.
[HttpDownloader] [Direct] Starting download attempt...
Direct
[HttpDownloader] Download Tasks Complete! (success=%d)
[HttpDownloader] Saving any detected proxy settings
[HttpDownloader] Downloads failed. Closing buffer.
-Djava.class.path=
_JAVA_OPTIONS
JAVA_TOOL_OPTIONS
[JNILaunch] [ERROR] Unable to load JRE library!
JNI_CreateJavaVM
[JNILaunch] ------- JNI Launch call -------
[JNILaunch] JVM Argument %d = %s
[JNILaunch] CP Argument %d = %s
[JNILaunch] App Argument %d = %s
[JNILaunch] JNI Option %d=%s
[JNILaunch] Creating VM...
[JNILauncher] Create Java VM Failed!
[JNILaunch] Created VM.
[JNILauncher] Searching for clazz %s
[JNILauncher] Searching for clazz failed!
[JNILauncher] Searching for main method %s
([Ljava/lang/String;)V
java/lang/String
[JNILauncher] Set argument %d to %s
[JNILauncher] About to execute static void method.
[JNILauncher] Run complete.
[JNILauncher] Destroying runtime.
[JNILauncher] Done!
[Proxy] Saved proxy list
[Proxy] Saved proxy bypass list
[Proxy] Saving proxy settings now.
[Proxy] No working proxy was found, so no proxy to be saved.
[Proxy] Opening HTTP Session
[Proxy] Using auto config URL: %S
[Proxy] Attempting to detect proxy for URL %S
[Proxy] Configuration found
[Proxy] Direct connection used
[Proxy] %S
[Proxy] Configuration NOT found (%d)
[Proxy] Proxy detection invoked for %s
[Proxy] Got IE Proxy Configuration
[Proxy] IE Setting - autodetect
[Proxy] IE Setting - autoconfig
[Proxy] IE Setting - explicit
[RB %d] Closing
[RB %d] [Write] Waiting as not enough space for data... (length:%d > available:%d, start:%d, end:%d)
[RB %d] [Write] Failed to write data into buffer.
[RB %d] [Write] Wrote %d...
[RB %d] [Read] PRE Available: %d (start:%d end%d)
[RB %d] [Read] Closing...
[RB %d] [Read] Failed to read data into buffer.
[RB %d] [Read] POST Available: %d (start:%d end%d)
[RB %d] [ReadUntil] Waiting as no data (readUntil)...
[RB %d] [Read] RingBuffer_read %d...
[RB %d] [Read] RingBuffer_read DONE
runner.cfg
--test-macos-arch
-TESTSPLASH
[TestSplash] Initialising splash
[TestSplash] Configure splash to use sh_logo.png
sh_logo.png
[TestSplash] Show
[TestSplash] SetProgress -1
[TestSplash] Sleep
[TestSplash] SetProgress %d
[TestSplash] SetProgress 100
JWPREPARE_FOR_LAUNCH_ONLY
Extracting wrapper tail...
--simplehelp-proxytest
ProxyList: %s
Proxy list was empty!
ProxyBypassList: %s
Proxy bypass list was empty!
--mkdir
--simplehelp-extracttest
test.p2.l2
30820222300D06092A864886F70D01010105000382020F003082020A0282020100809117AD80272B656E1933627989FC63E4D7781D3DC18CD14BA3557B439DAC2945B118DEE7A7C2F8AD0DAD4F0801110DBB9165CA9834B48813C760A9D96A7F4A4B845B8AE157787C8B34C57EAA2E78EB02D8D31AE4E958D2F2CCD72AED2D77D76AADD60CB7B31BAEE11FAA888904CED7A2D586F28BFC437A09E6D65F8BC98DCDC8C9911196E4A2944F0AE8BB51FD58E2E613D9AB7F214AC43F58BBCB543A6D5E5B38EA37463FDE2042192F6ACA10FF51D2525ED868BD023BB9954F002460E0D410106AAF7CF5525250701EAD733345DD88B2197BEC94485FD6D25300FD45DDFC0165AE6A92D3374BEE3C1A50B0626C0C73C90C69F7F92736E50FE67976E22657901C2F1FAF3B1C0493087C07B553A008D507C4CF4A94D43741C33202E44ED5047CC6A9C09AD8596D00D8B4D85FBC1A850AD6AF2F97467FA817C122D7D45C0A6513D5AA57B0D87A7CD855F77C57EDAD30BA03DBA2CD7BE409F929A36500B3CF6B3AF6154E09895268E8736E6FD70C7AE011896ED1D79B660200598A24416FAA98457B90C184ACE27FFCB28A4035D4F5804CD919C37540E640F53E066AFA9500866635563A32988542BA0FC220F1D01C770DD3F20382BD640098CC432A3F6C4C1A25C90CFEBAA7195320DD518D477D86D313D3340567FC4E49934868AB78E23B
C:\TEMP
Could not open test.p2.l2
--simplehelp-downloadtest2
[DEBUG] Downloading %s
C:\Users\simplehelp\AppData\Local\Temp
[DEBUG] Download worked!
[DEBUG] Download FALED!
--simplehelp-downloadtest
deleteme.tmp
Working proxy list is NULL
[Spawner] Creating spawner
[Spawner] Appended argument %s
[Spawner] WARNING: couldn't append argument %s
[Spawner] Setting spawner exe to %s
[Spawner] Constructing command line...
[Spawner] Creating command line '%s'
CreateProcess failed (%d).
[Spawner] runSpawnerAndWait returned %d
[Spawner] Constructing command...
[Spawner] Executing command '%s'
[Spawner] Create process seems to have worked
[Streamer] [Downloader] Starting...
[Streamer] [Downloader] Done (%d).
[Streamer] [UnLZMAer] Starting...
[Streamer] [UnLZMAer] Done (%d).
[Streamer] [UnArchiver] Starting...
[Streamer] [UnArchiver] Done.
[Streamer] [FileSaver] Starting...
[Streamer] [FileSaver] Done.
[Streamer] [FileReader] Starting...
[Streamer] [FileReader] Done.
[Streamer] Downloading from %s into %s
jwstat_
jwdyna_
***WARNING - STRING TOO LONG FOR ALLOC %d>%d! (READSTRING) [%s]
jwArcSpBlock_
[Unarchiver] Found special block %s
DigitalSignature1
Archive File Type
[Unarchiver] WARNING. EOF encountered.
Archive File Path
[Unarchiver] Extracting %s (::%ld from %s)
[Unarchiver] Created folder %s
Archive File Length
[Unarchiver] Skipping empty file %s
Signature Length
Signature Hex
[Unarchiver] .p2.l2 detected. Performing in sync unarchive.
[Unarchiver] .p2.l2 in sync unarchive complete.
[Unarchiver] Extracting to file %s (length:%ld)
[Unarchiver] *************************** Unable to extract archive file. Unable to open file for writing.
[Unarchiver] Extracted %s length:%d
[Unarchiver] Requires unpacking200...
[Unarchiver] ERROR: unpack200 executable (%s) does not exist!
[Unarchiver] ERROR: Unpacked target (%s) does not exist!
[Unarchiver] [START] Extracting archive %s
[Unarchiver] Verifying signature
[Unarchiver] Produced a signature of length %d
[Unarchiver] Archive signature verified.
***********************************************************************
[Unarchiver] ERROR - unable to verify signature of hash of archive.
[Unarchiver] JWrapper will disregard this update.
[Unarchiver] [END] Extracting archive %s
Memory allocation failed
Unsupported decompressor flags
Unknown error, possibly a bug
Error initializing the decoder: %s (error code %u)
lzma_code failed: %d
[%s] %s failed with error %d: %s
kernel32
SetDllDirectoryA
[JNILaunch] Bin folder is %s
jvm.dll
server
[Utils] Located DLL (%s)
client
[Extractor] Successfully loaded DLL (%s). JVM looks good.
[Extractor] [SEVERE] Unable to load existing JVM dll.
[Utils] ERROR - HexToBytes is writing too far! %d %d
[DeleteFolder] Deleting from '%s' is NULL
Deleting DIR %s
Failed to delete %s
Deleting FILE %s
Failed to delete file %s
[Utils] File exists: %s
[Utils] File does NOT exist: %s
Checking if string is cAscii %s
Checking if %s contains a !
[%d] %d %d
[Utils] Checking if %s exists
S-1-5-32-545
[Utils] Converted SID for USERS
[Utils] Unable to convert SID
GetNamedSecurityInfo Error %u
GetExplicitEntriesFromAcl failed %u
[Utils] Got %u ACEs for folder
[Utils] Trustee %u is SID
[Utils] Trustee %u is Users. Permissions is %u. Trimming...
[Utils] Unknown trustee at %u
[Utils] Trimmed ACE size is %u
PROGRAMDATA
SetEntriesInAcl Error %u
SetNamedSecurityInfo Error %u
[Utils] Converted SID
ALLUSERSPROFILE
JWUser-
APPDATA
[Extractor] Roaming AppData directory detected
[Extractor] Local AppData directory detected
LOCALAPPDATA
[Extractor] Local AppData directory resolved to %s
USERPROFILE
Local Settings
Application Data
Validating directory...
Shared dir detected is %s
The directory %s appears invalid.
Trying the short path instead.
Got short path of %s
Shared directory appears valid.
Could not find marker: %s
+%-8llu
*******************************************
+++ Start: %s
------------------------------------------------
--- End: %s
[Utils] Closing logging file.
[Windows Subsystem] Fixing %s
[Windows Subsystem] Could not open file %s
[Windows Subsystem] Opened %s
SS edit - PE sig
[Windows Subsystem] Found marker OK at %d [+%d = %d]
[Windows Subsystem] Skipped to relevant spot %d
[Windows Subsystem] Was %02X
[Windows Subsystem] Now %02X
[PickFolder] Folder %s matches %s with version %ld
[PickFolder] Set latest to %ld %s
perm_all
Permanent install for all users
perm_user
Permanent install for current user
Temporary install
ERROR: Unable to get shared dir!
.plugin
GdiplusShutdown
GdipFree
GdipAlloc
GdipDisposeImage
GdipCreateBitmapFromFile
GdipCloneImage
GdiplusStartup
GdipDeleteBrush
GdipDeletePen
GdipGetImageHeight
GdipDrawImagePointRectI
GdipCreateBitmapFromScan0
GdipDeleteGraphics
GdipGetImageGraphicsContext
GdipDrawImageRectI
GdipCreateSolidFill
GdipDrawImageI
GdipFillRectangleI
GdipGetImageWidth
GdipCreatePen1
GdipCreateFromHWND
GdipDrawRectangleI
timeGetTime
WINMM.dll
HttpQueryInfoA
InternetOpenUrlA
InternetConnectA
InternetCrackUrlA
InternetReadFile
InternetSetOptionA
HttpOpenRequestA
InternetErrorDlg
HttpSendRequestA
InternetOpenA
InternetCloseHandle
InternetQueryOptionA
WININET.dll
VerQueryValueA
GetFileVersionInfoSizeA
GetFileVersionInfoA
VERSION.dll
WinHttpGetIEProxyConfigForCurrentUser
WinHttpCloseHandle
WinHttpOpen
WinHttpGetProxyForUrl
WINHTTP.dll
InitCommonControlsEx
COMCTL32.dll
MoveFileExA
FreeLibrary
GetProcAddress
LoadLibraryA
GetVersion
WaitForSingleObject
SetEvent
TerminateThread
CreateEventA
GetLastError
GetModuleHandleA
CloseHandle
CreateMutexA
ReleaseMutex
CreateThread
SetEnvironmentVariableA
GlobalFree
DeleteFileA
InitializeCriticalSection
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
GetExitCodeProcess
CreateProcessA
GetCurrentDirectoryA
lstrlenA
FormatMessageA
GetShortPathNameA
SetCurrentDirectoryA
LocalAlloc
GetVersionExA
LocalFree
KERNEL32.dll
RegisterClassA
ValidateRect
LoadCursorA
SystemParametersInfoA
DispatchMessageA
SetWindowLongPtrA
ShowWindow
GetCursorPos
DefWindowProcA
PeekMessageA
CreateWindowExA
TranslateMessage
GetMonitorInfoA
SendMessageA
LoadIconA
MonitorFromPoint
PostThreadMessageA
GetWindowLongPtrA
GetMessageA
DestroyWindow
GetDesktopWindow
SetWindowPos
KillTimer
GetWindowRect
SetTimer
USER32.dll
SetEntriesInAclA
SetNamedSecurityInfoA
ConvertStringSidToSidA
EqualSid
GetUserNameA
GetNamedSecurityInfoA
GetExplicitEntriesFromAclA
ADVAPI32.dll
RaiseException
HeapFree
HeapAlloc
FileTimeToSystemTime
FileTimeToLocalFileTime
FindFirstFileA
FindNextFileA
FindClose
MoveFileA
ExitProcess
GetCurrentProcess
GetDateFormatA
GetTimeFormatA
GetDriveTypeA
GetFullPathNameA
GetTimeZoneInformation
GetSystemTimeAsFileTime
ExitThread
GetCurrentThreadId
MultiByteToWideChar
WideCharToMultiByte
GetFileAttributesA
CreateDirectoryA
RemoveDirectoryA
GetCommandLineA
GetProcessHeap
HeapSetInformation
HeapCreate
WriteFile
GetStdHandle
GetModuleFileNameA
RtlUnwindEx
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RtlCaptureContext
FlsGetValue
FlsSetValue
TlsFree
FlsFree
SetLastError
TlsSetValue
FlsAlloc
GetCPInfo
GetACP
GetOEMCP
SetHandleCount
GetFileType
GetStartupInfoA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
ReadFile
HeapSize
SetFilePointer
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
RtlVirtualUnwind
RtlLookupFunctionEntry
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapReAlloc
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
CompareStringA
CompareStringW
SetEndOfFile
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
sssssssssttt@
sssssssssttt
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
.?AVGdiplusBase@Gdiplus@@
.?AVImage@Gdiplus@@
.?AVBitmap@Gdiplus@@
%|8)(};t*};
#|6P(|9
!{6U&{:
|/F!|6{$}7
${7x!}6=
{2['|9
)|<{,|:#/
D1%~7E*|=
L9&|8D,
Od!}6/,
HWIDATx
l@ayC5H8
=R~]P6
L:!y7q@r,
c4i\{Y
b!$EC\
~9Qsg?Qr#
kD&]P\
d6AvI\
pZQSy|
^V+:Mx
^^MITn
X98XIU
z&`]w$:vK
hm8j_.@
#pd5 U9
}UO0Xu^
E@E"7B,
,qd5 Uy$e
^(![bC
+dMj]8
TnI9/}J
QEI:/
#mx-e<V4
Cz7N)Z9
R|(Z^E6
Kbw@~l
xH/m"IO
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
C*P[zd#G!$
pf^-@`uC0
K,rY0D:</Dx+&eqq9s%#
U,/BcRemote Access
00089360978
30820222300D06092A864886F70D01010105000382020F003082020A0282020100809117AD80272B656E1933627989FC63E4D7781D3DC18CD14BA3557B439DAC2945B118DEE7A7C2F8AD0DAD4F0801110DBB9165CA9834B48813C760A9D96A7F4A4B845B8AE157787C8B34C57EAA2E78EB02D8D31AE4E958D2F2CCD72AED2D77D76AADD60CB7B31BAEE11FAA888904CED7A2D586F28BFC437A09E6D65F8BC98DCDC8C9911196E4A2944F0AE8BB51FD58E2E613D9AB7F214AC43F58BBCB543A6D5E5B38EA37463FDE2042192F6ACA10FF51D2525ED868BD023BB9954F002460E0D410106AAF7CF5525250701EAD733345DD88B2197BEC94485FD6D25300FD45DDFC0165AE6A92D3374BEE3C1A50B0626C0C73C90C69F7F92736E50FE67976E22657901C2F1FAF3B1C0493087C07B553A008D507C4CF4A94D43741C33202E44ED5047CC6A9C09AD8596D00D8B4D85FBC1A850AD6AF2F97467FA817C122D7D45C0A6513D5AA57B0D87A7CD855F77C57EDAD30BA03DBA2CD7BE409F929A36500B3CF6B3AF6154E09895268E8736E6FD70C7AE011896ED1D79B660200598A24416FAA98457B90C184ACE27FFCB28A4035D4F5804CD919C37540E640F53E066AFA9500866635563A32988542BA0FC220F1D01C770DD3F20382BD640098CC432A3F6C4C1A25C90CFEBAA7195320DD518D477D86D313D3340567FC4E49934868AB78E23B
perm_all
/REPAIR
/REINSTALL
nativesplash.png
HK0!H2
{kO@Sp
;lF>NX
8a}im[
]$xHzJ
Z{_?=?
cacerts
JWrapper-JWrapper-00089360978-archive.p2.l2
1145491
)LwsM/
-OcwLz
`O"`<A
0Lz"5j4c
n5\B^K8
c?39r?
!VPZBP
;T4*1,
ya SAi
`fnwn/
6jmp|NP
S2luN'r
zFAQ),
x)ctM4'
jfrz7Oq
.0DxG!!0
u9EPij
]FKKI.
~D.a^
wy*L:?7
K2~ St6$
E0s1gQ
P>q|UD
qEyAzJ
r9,'&(
.tH{JR
GlR#9Hyz
O!,!Z:
.Pk<hW
xNF6hy
+Lb#27
p-B20W
Kv)C5I
4IClIBwKp;
d3$ulAC
>t5ZOQa
k;F.74
~X.Ly0t
Sxn%Lx
D9@nl|
fhU<,cj
p hUE7
$N )$=
(}jCCN
u"`aPA
vESD5@
6[MzDS
#6FIg?
NTr-n$
53w:#yC
G@6AW?N
wyREx?
n[Wy+P&K!
K(y/9'
xPGFta
Td~kZF]dy
;uaSU%
3m{SP4i
KNmhXH
Fa]e^F6&n
3hDt]<[,
9|>!ci
{fv]@m
}CKcBF)q
3"pqR7
({#I:@E
"c:C%d
*#"RMp
Dy2F?6
tnW<r~]
dNTPVX
Li(21M
e"GnBKA
t@<f+R
wTJ~o$
D$rjV
AB}T4{
z=@k0o
([q+Ip
``TlN?
]o.3I?]]V Njr
x5e.Ab
v<^hD1N
MZ47=E
B?"55_w
fgDOk
d)r&y\
R31U4_
bBuyb
F:{t?7
\GCtyg
D2i0sS
_z!~2A
Yl[EIS
/s3ho{Z
{2s`d
fgvoW6|
W[,AOC@
u=*TIP
JA35v(
wYA0kN
D\I6o/
Z</^sZ
iI/af
@ETI%w#
pSln6u[
8Rxx0s
Rz'3yj}
8NDDByc`
:-M*L&
7^zwm=
F`78#m
S[`di.
3,{*<mYs
-^0C8>{J
5dR*`m
e@hm\t
M#jRu2&
( U-EA(
7Jx# _
n(+q$
1r"M3Wt
wdbTL"U=\
XV Zvb
s,jm*^
@a8x^j
Emjvdz5
G6{0x=
K'JuJO
{m]Dwf
joDqqz
BxIocu
b~VLRw
5b|D\
,h1mlM
=G$6AG
2XlS(xK
~vGUpB
|2j|]?<
a]-M'E
'm]t#1
;]#u&Wl
k|mdZM
2=f(45*fY\
^i*%NT
f#9_&)
c3a 0I
<0>.gE>d
S&u7GML
!GV^s<$
Jmn3pSaR}
,+.q^5
;Qk[2C
{+UCQg
tZD}vN
MAB3P`
FCNNOWb
qs9tQ#e
+|f?+Z
&/E9+\z
=7H:m%
[Y(~ol
(WLQ\
-u5*&+O
d'H*DdV
_B$)k
jd\Hi/
IF$0V2
t4IWz+
'9S'{;f
pxY>|CCs
j#H@7t
nrgst(
h(<)5$*
x4(=#3
8C"EE,
6!L!eQP9b
rzdEi>
p'aN%j
&r%uIz
iH2O<d
N-PTL/
B,ZgkT
jWc[P$
i=C7&z<9c
X *56:a
sSH$J!C
=~~h;D6'c
52;r2V
{.kpDC6
!b=4[1
\xl}i
eA3H,~O
r>l,v|
Q)&Nlh
>SJu"O
xT!<{]
UGZXZ>
5c23LyS
/O#+5
6tDuSG
yi_0[X
~i1tz
WFY<<$?M
xHTj=c
nlGF63e
Bk+$a>
&I1X*E
UZ Y?JosHV9
[#/3>L
K KFoEk
@0dS3!r
=2`amk
<@81K)
m,V,6f
j?@Dd(}
xj$OyA
dv43{h]98`
wM1P?
>ZM)eF:A
dxHd5g
b_IP(f
8[Thnw
=OA9AWWe
$A9L=~
,2e5bb
D:T$|cG
\p~PK
o0[a'#
|_J.Ky
$PQ0BCr
X-w@7@
kKl<-f
\{0dO*
XRu[vU
Oz=C>-
I-jCso
#+6U@l
3s`C~$
j7e2=S
zh:FJq
23-!keb
vJ'>to
tOZR)(
^Omib)K9lq
?6ih`]
%e*vbc
CrUSC_(k
77VWv
g8uMU6
8|18w$u
1Rdp>W
-0m!xJk
e{8Dmw
D)YH"gm
gu~(~BZc
vLAVYwI
%"wz;&0!
9mMX^+
9QJ&u~vG
pp_2m<
+&B\he
hasNNq
wB?h0A
S?_mbf[
vx=]FN
\ia&*y
7IdvKx
u5O+*#
Z3VQ#
y:~#;=
JBe4X]
0F=;aF
4/2h{QA)b'
#I:MEGj7
<QC)pk
ePSw%K
5?r;B+
3"T|N(
9Ifgxn
lQ=J)08
PFaiSc
!@WttC
,VhkAN
Eq"f 6
3mMi;|3
M&>@tFg
^[&S.P
R9PDg
X6TUtmE
&Cz 'n
:2<~t$`C
#,9~gi
}?-L2o
$x%kn^
0O/a/W
W?Oj"
]KF/NE
dVRl%
u-+V\x
`(>T-v
*S65_P
77G82<
uQJ!_C
}tM4,l
@7E~4W
,fEoLn4
So)rF@B
85_1Lu
>zGV4(0
x%O'*?
fk3aWW
*MBU,"8
agSfQ
BnkW$8
1tJpAr
vb]:g&u
H.blaOvWtn
Ohz9e,
xgij3LP
[|VX_@
<kk)aKT_
R'r:F,
=!OhU`G^
l]|MG;
Iem]}S
w0oqb2
'obkc5
+CK"'Y
7#j:e>
gLatlQ3
iQPvVF
&"zL;;]
!#N9PE
.sN&JY
7a6*`#
R/x;=4w
/Yd6YUP
3ZHn23
]!K\9S
CPH{"H1
&"4m(*W
UCf~2r
jxt/t=
&yks0 i+
+H.91p
DP:u*,F#9
}ie0L'tL
H`K&4pJ4b
#MX@Ho
&C4<nmz
RC.nprU
t+f0k>
YOxAN6
wCBRo:
1LkY1H
;=MmX{
(qfC/k
Rz8@f
jQtCUc`
`` RST
<%Czn:
,jW!R4
~gI,$
61mgYp)
CI5/^;N)<
^e)Q+x/
B)p6'Q1
4AV*}{o,
;>j'{V0+G
!{I7[T
ykh95eI~E
]{sWsS
(ino7D
\fQUS9
n<)*>$
(5&x,2l(
)dH6RS
T@WI8(KV
s>T(W
Q3Q*):
d\L`dS
UaN{ZV
>Vo}h/
O5h9vmht
[/aF^1v@+
c`.m<B
8.9<_40
`&xws/t
'`6zz;_`
Wj>?HL
1:'L^P|ES)N
Sgbl8R
/_)y8)
X1TSYD
XK~DuQ
Vq's9$
z_S7{l'
(0h(a[
(\S4X~
jxmu&ej
X1)A`9
0/($Hj
MR#A0
tR;ZAZt
:k7Cv_@
&u@>RR
ZYSrRQ
LFSj6q X]
ntt__`
0vxM3
yGAJIvh<0
dz9!$d
.iKljA_
83`My%
2Np\Tk`6
s#fGsM
sml|^U
;FK\$"
vWKV=Y?
*t&:amSkAlZ
XUHOx'Ss
9"2%q$~3
P)0+[,
';Sw.%
PXBix5
uBraAv
1AZ1hr
n1'M)#L
;pV^`2
&");&S
4~OoTK
[op>rH
0 $S]N
zc\yJx
%y5,<`
f5*H5fY
_X[kUJ
N {gE0P
zH_R,q
#xC)dD
%|pX9.
;M%Cb
]}nV)W
cegz2S
|P{H-j
V::wWKK
#/}3Wz
9&+=E\
z'6gVl
DSq$:?b
%|][$6
P=W@*e
)ueWW*
/#ZPdc+
&aE@k~
%reak
{ a@3n
>SW3e=
d%LY1~
F%AFNE
yHDq~i@
:xlcD(?
I!?,Vw
_Q9~6U
}95J]
zqzP_v
we1Ugh
R-B vy3+
7#A#jNHL
};U&mp
`Q3*(yS
\pk|Di7}
gtc0C*
BrZ_%H
CD5S"T
=xWy<B6
apLuTH
$bC#:f0
I*Yu|y
IKS\;N
j?X,HC
KGE{zl
VQVQ)wG
gl9!ag
zN_n~
/:_U7Bt
1k#(sM
<:oU.E1
P\Nf&I9>z
+G([Io
jI9>oh^
]]tx3/
"WQ\FR~
wmWW'L
u ,qEQASX
t6q%F\
?cbllC"DGV
>]!7Xh
g];s.>
Y4<3,$(
Z{ublR
aq}+C
a ._rBlK
&:nVS`
~=;?Y-
sx88Jq
dNw<qA
lDCK&4
Um~]y
Mkb+ SS
NW>}GJ.e
"+2<U]v
H]^UvQI
hqB/;t
%^kLz:Hg=
lP|/vQK
Gs&Ms]
5Yg-w%{(q
.Pm;nFR
v^%v?/
N|avyx
!F[ICf
|CD'oIgDV5
hc?kB"
_o_i[
l|ao(+>'I
`{:GOUa
Bv.|hOB
eXc}rT
l(wTs
jBZ mgA
qB*b(l
GT8T:xw
]:mWB(
q8(aG/
6J6K-n
}&+b+]'
9:])3>~
va)Df}/
tgipj5=Z
%D33!g
56s8E<
@DB/.>]L
g:$-&
!Wm:T&<
0[]A.U
-*abA.V
8[!6]J%
*nl6{T
SYIW&)a
x8x~~F
Lc`FI
<1WH:bE
&w3HO~
yW+YbAav
srlJRb
-:UO<G
g*$W.n_
_v_4O>
Antivirus Signature
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
Skyhigh Artemis
ALYac Clean
Cylance unsafe
Zillya Tool.Remsim.Win64.1
Sangfor Clean
K7AntiVirus Trojan ( 005acd7b1 )
Alibaba Clean
K7GW Trojan ( 005acd7b1 )
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky not-a-virus:HEUR:RemoteAdmin.Win64.Remsim.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Clean
Tencent Clean
Emsisoft Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
CMC Clean
Sophos Generic Reputation PUA (PUA)
Ikarus Clean
MAX Clean
Jiangmin RemoteAdmin.Remsim.b
Webroot Clean
Google Clean
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm not-a-virus:HEUR:RemoteAdmin.Win64.Remsim.gen
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!065F0871B602
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Hacktool.Remsim!8.180EE (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.207043384.susgen
Fortinet Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike Clean
No IRMA results available.