Static | ZeroBOX

PE Compile Time

2024-06-07 00:02:40

PE Imphash

948cc502fe9226992dce9417f952fce3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0009ab1d 0x0009ac00 6.66827358139
.rdata 0x0009c000 0x0002fb82 0x0002fc00 5.69181154748
.data 0x000cc000 0x0000706c 0x00004800 0.584666698698
.rsrc 0x000d4000 0x00009000 0x00009000 4.97863991461
.reloc 0x000dd000 0x00007594 0x00007600 6.79721281814

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000da038 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000da4a0 0x00000050 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000dc660 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_RCDATA 0x000dc7b8 0x000002c8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000dcb20 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000dcb20 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000dcb20 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000dcb20 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000dcb34 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000dcc10 0x000003ef LANG_ENGLISH SUBLANG_ENGLISH_UK ASCII text, with CRLF line terminators

Imports

Library WSOCK32.dll:
0x49c7d8 gethostbyname
0x49c7dc recv
0x49c7e0 send
0x49c7e4 socket
0x49c7e8 inet_ntoa
0x49c7ec setsockopt
0x49c7f0 ntohs
0x49c7f4 WSACleanup
0x49c7f8 WSAStartup
0x49c7fc sendto
0x49c800 htons
0x49c804 __WSAFDIsSet
0x49c808 select
0x49c80c accept
0x49c810 listen
0x49c814 bind
0x49c818 inet_addr
0x49c81c ioctlsocket
0x49c820 recvfrom
0x49c824 WSAGetLastError
0x49c828 closesocket
0x49c82c gethostname
0x49c830 connect
Library VERSION.dll:
0x49c77c GetFileVersionInfoW
0x49c780 VerQueryValueW
Library WINMM.dll:
0x49c7c8 timeGetTime
0x49c7cc waveOutSetVolume
0x49c7d0 mciSendStringW
Library COMCTL32.dll:
0x49c08c ImageList_Destroy
0x49c090 ImageList_Remove
0x49c098 ImageList_BeginDrag
0x49c09c ImageList_DragEnter
0x49c0a0 ImageList_DragLeave
0x49c0a4 ImageList_EndDrag
0x49c0a8 ImageList_DragMove
0x49c0b0 ImageList_Create
Library MPR.dll:
0x49c408 WNetGetConnectionW
0x49c410 WNetUseConnectionW
0x49c414 WNetAddConnection2W
Library WININET.dll:
0x49c78c HttpOpenRequestW
0x49c790 InternetCloseHandle
0x49c794 InternetOpenW
0x49c798 InternetSetOptionW
0x49c79c InternetCrackUrlW
0x49c7a0 HttpQueryInfoW
0x49c7a8 InternetConnectW
0x49c7ac HttpSendRequestW
0x49c7b0 FtpOpenFileW
0x49c7b4 FtpGetFileSize
0x49c7b8 InternetOpenUrlW
0x49c7bc InternetReadFile
Library PSAPI.DLL:
Library IPHLPAPI.DLL:
0x49c154 IcmpSendEcho
0x49c158 IcmpCloseHandle
0x49c15c IcmpCreateFile
Library USERENV.dll:
0x49c764 LoadUserProfileW
0x49c76c UnloadUserProfile
Library UxTheme.dll:
0x49c774 IsThemeActive
Library KERNEL32.dll:
0x49c164 DuplicateHandle
0x49c168 CreateThread
0x49c16c WaitForSingleObject
0x49c170 HeapAlloc
0x49c174 GetProcessHeap
0x49c178 HeapFree
0x49c17c Sleep
0x49c180 GetCurrentThreadId
0x49c184 MultiByteToWideChar
0x49c188 MulDiv
0x49c18c GetVersionExW
0x49c190 IsWow64Process
0x49c194 GetSystemInfo
0x49c198 FreeLibrary
0x49c19c LoadLibraryA
0x49c1a0 GetProcAddress
0x49c1a4 SetErrorMode
0x49c1a8 GetModuleFileNameW
0x49c1ac WideCharToMultiByte
0x49c1b0 lstrcpyW
0x49c1b4 lstrlenW
0x49c1b8 GetModuleHandleW
0x49c1c0 VirtualFreeEx
0x49c1c4 OpenProcess
0x49c1c8 VirtualAllocEx
0x49c1cc WriteProcessMemory
0x49c1d0 ReadProcessMemory
0x49c1d4 CreateFileW
0x49c1d8 SetFilePointerEx
0x49c1dc SetEndOfFile
0x49c1e0 ReadFile
0x49c1e4 WriteFile
0x49c1e8 FlushFileBuffers
0x49c1ec TerminateProcess
0x49c1f4 Process32FirstW
0x49c1f8 Process32NextW
0x49c1fc SetFileTime
0x49c200 GetFileAttributesW
0x49c204 FindFirstFileW
0x49c208 FindClose
0x49c20c GetLongPathNameW
0x49c210 GetShortPathNameW
0x49c214 DeleteFileW
0x49c218 IsDebuggerPresent
0x49c21c CopyFileExW
0x49c220 MoveFileW
0x49c224 CreateDirectoryW
0x49c228 RemoveDirectoryW
0x49c22c SetSystemPowerState
0x49c234 LoadResource
0x49c238 LockResource
0x49c23c SizeofResource
0x49c240 OutputDebugStringW
0x49c244 GetTempPathW
0x49c248 GetTempFileNameW
0x49c24c DeviceIoControl
0x49c250 LoadLibraryW
0x49c254 GetLocalTime
0x49c258 CompareStringW
0x49c25c GetCurrentThread
0x49c268 GetStdHandle
0x49c26c CreatePipe
0x49c270 InterlockedExchange
0x49c274 TerminateThread
0x49c278 LoadLibraryExW
0x49c27c FindResourceExW
0x49c280 CopyFileW
0x49c284 VirtualFree
0x49c288 FormatMessageW
0x49c28c GetExitCodeProcess
0x49c2b4 GetDriveTypeW
0x49c2b8 GetDiskFreeSpaceExW
0x49c2bc GetDiskFreeSpaceW
0x49c2c4 SetVolumeLabelW
0x49c2c8 CreateHardLinkW
0x49c2cc SetFileAttributesW
0x49c2d0 CreateEventW
0x49c2d4 SetEvent
0x49c2e0 GlobalLock
0x49c2e4 GlobalUnlock
0x49c2e8 GlobalAlloc
0x49c2ec GetFileSize
0x49c2f0 GlobalFree
0x49c2f8 Beep
0x49c2fc GetSystemDirectoryW
0x49c300 HeapReAlloc
0x49c304 HeapSize
0x49c308 GetComputerNameW
0x49c310 GetCurrentProcessId
0x49c318 CreateProcessW
0x49c31c GetProcessId
0x49c320 SetPriorityClass
0x49c324 VirtualAlloc
0x49c32c lstrcmpiW
0x49c330 DecodePointer
0x49c334 GetLastError
0x49c338 RaiseException
0x49c34c ResetEvent
0x49c360 GetCurrentProcess
0x49c364 CloseHandle
0x49c368 GetFullPathNameW
0x49c36c GetStartupInfoW
0x49c374 InitializeSListHead
0x49c378 RtlUnwind
0x49c37c SetLastError
0x49c380 TlsAlloc
0x49c384 TlsGetValue
0x49c388 TlsSetValue
0x49c38c TlsFree
0x49c390 EncodePointer
0x49c394 ExitProcess
0x49c398 GetModuleHandleExW
0x49c39c ExitThread
0x49c3a0 ResumeThread
0x49c3a8 GetACP
0x49c3ac GetDateFormatW
0x49c3b0 GetTimeFormatW
0x49c3b4 LCMapStringW
0x49c3b8 GetStringTypeW
0x49c3bc GetFileType
0x49c3c0 SetStdHandle
0x49c3c4 GetConsoleCP
0x49c3c8 GetConsoleMode
0x49c3cc ReadConsoleW
0x49c3d4 FindFirstFileExW
0x49c3d8 IsValidCodePage
0x49c3dc GetOEMCP
0x49c3e0 GetCPInfo
0x49c3e4 GetCommandLineA
0x49c3e8 GetCommandLineW
0x49c3fc FindNextFileW
0x49c400 WriteConsoleW
Library USER32.dll:
0x49c4e0 IsCharAlphaW
0x49c4e4 IsCharAlphaNumericW
0x49c4e8 IsCharLowerW
0x49c4ec IsCharUpperW
0x49c4f0 GetMenuStringW
0x49c4f4 GetSubMenu
0x49c4f8 GetCaretPos
0x49c4fc IsZoomed
0x49c500 GetMonitorInfoW
0x49c504 SetWindowLongW
0x49c50c FlashWindow
0x49c510 GetClassLongW
0x49c518 IsDialogMessageW
0x49c51c GetSysColor
0x49c520 InflateRect
0x49c524 DrawFocusRect
0x49c528 DrawTextW
0x49c52c FrameRect
0x49c530 DrawFrameControl
0x49c534 FillRect
0x49c538 PtInRect
0x49c544 SetCursor
0x49c548 GetWindowDC
0x49c54c GetSystemMetrics
0x49c550 GetActiveWindow
0x49c554 CharNextW
0x49c558 wsprintfW
0x49c55c RedrawWindow
0x49c560 DrawMenuBar
0x49c564 DestroyMenu
0x49c568 SetMenu
0x49c570 CreateMenu
0x49c574 IsDlgButtonChecked
0x49c578 DefDlgProcW
0x49c57c CallWindowProcW
0x49c580 ReleaseCapture
0x49c584 SetCapture
0x49c588 PeekMessageW
0x49c58c GetInputState
0x49c590 UnregisterHotKey
0x49c594 CharLowerBuffW
0x49c598 MonitorFromPoint
0x49c59c MonitorFromRect
0x49c5a0 LoadImageW
0x49c5a4 mouse_event
0x49c5a8 ExitWindowsEx
0x49c5ac SetActiveWindow
0x49c5b0 FindWindowExW
0x49c5b4 EnumThreadWindows
0x49c5b8 SetMenuDefaultItem
0x49c5bc InsertMenuItemW
0x49c5c0 IsMenu
0x49c5c4 ClientToScreen
0x49c5c8 GetCursorPos
0x49c5cc DeleteMenu
0x49c5d0 CheckMenuRadioItem
0x49c5d4 GetMenuItemID
0x49c5d8 GetMenuItemCount
0x49c5dc SetMenuItemInfoW
0x49c5e0 GetMenuItemInfoW
0x49c5e4 SetForegroundWindow
0x49c5e8 IsIconic
0x49c5ec FindWindowW
0x49c5f4 LockWindowUpdate
0x49c5f8 SendInput
0x49c5fc GetAsyncKeyState
0x49c600 SetKeyboardState
0x49c604 GetKeyboardState
0x49c608 GetKeyState
0x49c60c VkKeyScanW
0x49c610 LoadStringW
0x49c614 DialogBoxParamW
0x49c618 MessageBeep
0x49c61c EndDialog
0x49c620 SendDlgItemMessageW
0x49c624 GetDlgItem
0x49c628 SetWindowTextW
0x49c62c CopyRect
0x49c630 ReleaseDC
0x49c634 GetDC
0x49c638 EndPaint
0x49c63c BeginPaint
0x49c640 GetClientRect
0x49c644 GetMenu
0x49c648 DestroyWindow
0x49c64c EnumWindows
0x49c650 GetDesktopWindow
0x49c654 IsWindow
0x49c658 IsWindowEnabled
0x49c65c IsWindowVisible
0x49c660 EnableWindow
0x49c664 InvalidateRect
0x49c668 GetWindowLongW
0x49c670 AttachThreadInput
0x49c674 GetFocus
0x49c678 GetWindowTextW
0x49c67c SendMessageTimeoutW
0x49c680 EnumChildWindows
0x49c684 CharUpperBuffW
0x49c688 GetClassNameW
0x49c68c GetParent
0x49c690 GetDlgCtrlID
0x49c694 SendMessageW
0x49c698 MapVirtualKeyW
0x49c69c PostMessageW
0x49c6a0 GetWindowRect
0x49c6a8 CloseDesktop
0x49c6ac CloseWindowStation
0x49c6b0 OpenDesktopW
0x49c6b4 RegisterHotKey
0x49c6b8 GetCursorInfo
0x49c6bc SetWindowPos
0x49c6c0 CopyImage
0x49c6c4 AdjustWindowRectEx
0x49c6c8 SetRect
0x49c6cc SetClipboardData
0x49c6d0 EmptyClipboard
0x49c6d8 CloseClipboard
0x49c6dc GetClipboardData
0x49c6e4 OpenClipboard
0x49c6e8 BlockInput
0x49c6ec TrackPopupMenuEx
0x49c6f0 GetMessageW
0x49c6fc OpenWindowStationW
0x49c704 MessageBoxW
0x49c708 DefWindowProcW
0x49c70c MoveWindow
0x49c710 SetFocus
0x49c714 PostQuitMessage
0x49c718 KillTimer
0x49c71c CreatePopupMenu
0x49c724 SetTimer
0x49c728 ShowWindow
0x49c72c CreateWindowExW
0x49c730 RegisterClassExW
0x49c734 LoadIconW
0x49c738 LoadCursorW
0x49c73c GetSysColorBrush
0x49c740 GetForegroundWindow
0x49c744 MessageBoxA
0x49c748 DestroyIcon
0x49c74c DispatchMessageW
0x49c750 keybd_event
0x49c754 TranslateMessage
0x49c758 ScreenToClient
Library GDI32.dll:
0x49c0c4 EndPath
0x49c0c8 DeleteObject
0x49c0d0 ExtCreatePen
0x49c0d4 StrokeAndFillPath
0x49c0d8 GetDeviceCaps
0x49c0dc SetPixel
0x49c0e0 CloseFigure
0x49c0e4 LineTo
0x49c0e8 AngleArc
0x49c0ec MoveToEx
0x49c0f0 Ellipse
0x49c0f8 CreateCompatibleDC
0x49c0fc PolyDraw
0x49c100 BeginPath
0x49c104 Rectangle
0x49c108 SetViewportOrgEx
0x49c10c GetObjectW
0x49c110 SetBkMode
0x49c114 RoundRect
0x49c118 SetBkColor
0x49c11c CreatePen
0x49c120 SelectObject
0x49c124 StretchBlt
0x49c128 CreateSolidBrush
0x49c12c SetTextColor
0x49c130 CreateFontW
0x49c134 GetTextFaceW
0x49c138 GetStockObject
0x49c13c CreateDCW
0x49c140 GetPixel
0x49c144 DeleteDC
0x49c148 GetDIBits
0x49c14c StrokePath
Library COMDLG32.dll:
0x49c0b8 GetSaveFileNameW
0x49c0bc GetOpenFileNameW
Library ADVAPI32.dll:
0x49c000 GetAce
0x49c004 RegEnumValueW
0x49c008 RegDeleteValueW
0x49c00c RegDeleteKeyW
0x49c010 RegEnumKeyExW
0x49c014 RegSetValueExW
0x49c018 RegOpenKeyExW
0x49c01c RegCloseKey
0x49c020 RegQueryValueExW
0x49c024 RegConnectRegistryW
0x49c02c InitializeAcl
0x49c034 OpenThreadToken
0x49c038 OpenProcessToken
0x49c040 DuplicateTokenEx
0x49c04c GetLengthSid
0x49c050 CopySid
0x49c054 LogonUserW
0x49c060 FreeSid
0x49c064 GetTokenInformation
0x49c068 RegCreateKeyExW
0x49c070 GetAclInformation
0x49c074 GetUserNameW
0x49c078 AddAce
Library SHELL32.dll:
0x49c49c DragFinish
0x49c4a0 DragQueryPoint
0x49c4a4 ShellExecuteExW
0x49c4a8 DragQueryFileW
0x49c4ac SHEmptyRecycleBinW
0x49c4b4 SHBrowseForFolderW
0x49c4b8 SHCreateShellItem
0x49c4bc SHGetDesktopFolder
0x49c4c4 SHGetFolderPathW
0x49c4c8 SHFileOperationW
0x49c4cc ExtractIconExW
0x49c4d0 Shell_NotifyIconW
0x49c4d4 ShellExecuteW
Library ole32.dll:
0x49c838 CoTaskMemAlloc
0x49c83c CoTaskMemFree
0x49c840 CLSIDFromString
0x49c844 ProgIDFromCLSID
0x49c848 CLSIDFromProgID
0x49c850 MkParseDisplayName
0x49c858 CoCreateInstance
0x49c85c IIDFromString
0x49c860 StringFromGUID2
0x49c868 OleInitialize
0x49c86c OleUninitialize
0x49c870 CoInitialize
0x49c874 CoUninitialize
0x49c880 CoGetObject
0x49c888 CoCreateInstanceEx
0x49c88c CoSetProxyBlanket
Library OLEAUT32.dll:
0x49c41c CreateStdDispatch
0x49c420 CreateDispTypeInfo
0x49c424 UnRegisterTypeLib
0x49c430 RegisterTypeLib
0x49c434 LoadTypeLibEx
0x49c438 VariantCopyInd
0x49c43c SysReAllocString
0x49c440 SysFreeString
0x49c444 VariantChangeType
0x49c450 SafeArrayAccessData
0x49c454 SafeArrayAllocData
0x49c460 SysStringLen
0x49c468 SysAllocString
0x49c46c VariantInit
0x49c470 VariantClear
0x49c474 DispCallFunc
0x49c47c VarR8FromDec
0x49c480 SafeArrayGetVartype
0x49c488 VariantCopy
0x49c48c OleLoadPicture

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
WWjdh,
PWWWWh
<SVWj,
@SVWj0
jJXf9E
jJXf9E
t4j"Yf;
t$8]4t
D$(;D$4
f98t>j
D$<9D$ tJj
L$p;\$t
 !"#$
 !"#$%%%%%%&&'()*+%%%%%%&&'()*+,,,,,,--./012RRRRRRRRRRRR3345566789::::;<=<=>?>@ABC>@ABCRRRRRDEFGHIJKLMNO
>0t;h@
|$D;|$@
D$<f9D$H
D$D9D$8
D$Hf9D$<
D$ PVj
D$hD%M
D$dD%M
D$@f9D$D
D$\f9D$x
D$`D%M
D$dD%M
L$@9D$hr
D$xf9D$\s'
D$xf9D$\
D$xf9D$\s#
L$$PWVj
9D$Hu;
D$09D$H
D$0;D$H
C(_^[]
\$(j|Xf9
L$@jxXf
j?Xf9F
j#Xf9F
j\Xf9F
j-Xf9F
jEYf9N
jQYf9N
j#Xj(Yj?Zf9N
j]Xf9F
YYj!Yf;
jOXf9E
T$ j*Xf9
09L$$v&
QQSVWd
URPQQh08B
tH9] uC
u PWQR
;t$,v-
UQPXY]Y[
SVWjA_jZ+
uBjAYjZ+
u0jAXf;
u0jAXf;
Tt1jhZ;
Tt1jhZ;
^$+^8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
F2jgYf;
SVjA[jZ^+
jAZjZ^
u%j0Zf;
Qj)Zf9
QQQWPQ
j"^f91j\^u8
j"^f9q
t/j=[f;
QSSSSj
Wj0XPV
QQSWj0j@
PPPPPWS
PP9E u:PPVWP
D8(HXt:f
D8(Ht5F
f- 8f=
f-00f=
f-00f=
SSPQSS
u kE$<
>:uBFV
taj*Xf
VWj\^j:
WWWPWS
SSVWh
f9:t!V
|VWj=S
v!j"X_^[
PPPPPPPP
PVVVhX
f98t#V
D$Hh,gL
QPQWVS
QPQWVS
QPQWVS
QPQWVS
YVhHfL
QQQQQ3
;Fxtt;
t$;F|r
}G;F|s
f;F6tw
}V;~|s,
D$@9D$<
D$@;D$<
L$@9D$
H#D$$j
L$(PWV
L$(PWV
?j)Zf9
?j)Zf9
xc;NH~
t'j+Zf;
tj?Zf;
uLjC[f9^
M(j?Xf9B
t$j![f;
j&Xf9F
t(j+Xf;
BL;z0}:
U(FG;z0|
t%j-Y;
U(j<_j>
9B0~`;O
Pwnt)j
v8jo[;
t#j-Yf;
[j9Zf;
Yj9Xf;
t jsZf;
9W0~@S
CP;SL~
CP;{L~
jEZf9Q
jE[f9^
j]Yf9H
j\Xf9F
jEYf9N
j\[jE_f9~
u4jQXf9F
Zj9Xf;
[j9Xf;
t4;H s#
j7Xj0Z
<Gf97t
SQj@Z
BY9T$$
BY9T$$
j$Xj(f
qj$Xj(f
j$Xj(f
j$Xj(f
f;H,sC
Gf;x,r
Gf;x,r
t$j\Xf9
dSVWQQ
PSSSSSSh
QQSVWh
u3SVh+
P}&j%h
j#_f98u
t1j;Yf;
t)j]Yf;
D$ +D$
D$$+D$
9, <^w#A;
t1j;Yf;
t)j]Yf;
u-9G(u(
D$ Ph4]L
D$ Ph4]L
tXSVWj
Q,8^=u
^<9^4t
^,9^0t
^09^(t
$SVWjc
D$Tf9Y
f;D$Xu
f;D$\u
zf;D$Xuh
L$P9D$
8f;D$\u
#D$dSP
f99t7SVj.
t$<9|$
T$4Y9D$$
t$8f9D$ uh
t$0QVPR
D$4;D$$
r&j[f;
:jXf;
j|Zj f
j;Zj f
j XAf9
Oj;^f;
~%j;[f9
jZjHYj
tP97tL
tQ9>tM
t j'Zf;
<"t{<%tw<'ts<$to<&tk<!tg<otc<]t_<[t[<\tW<
tO<_tK<
D$$Pj}Y
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
DSVWj,3
j.^f90u
txhD#L
f9t$Ht
PPPhDiL
WWWhDiL
YSPVWj
j0Xjxf
PPPPWSPP
u&hljL
u+Sj)^j
FLjDWP
;GLujDj$X+
PPPPPh
D$(SSP
|$8f;:t/W
D$Dh|kL
t$4f;1t/V
T$pSRP
T$pSRP
T$pSRP
D$|h<jL
D$pQhTkL
D$hhhkL
D$8SSP
D$0htkL
D$@htkL
\$ f94{u7@
F9t$$v&V
F;t$$r
t6h|kL
t6h|kL
L$$WSPV
D$(SPV
D$@h|nL
QQSVW3
D$<PSW
u&VVSWh
9t$ v=
t$0;t$$t"F
\$0PWS
tBhTrL
@PhXpL
j3_f9x
j3Zf9P
jN_f9z
j3^f9p
AjNXf9E
"jHXf;
j5[f9X
j%YFf;
j$Yj@FZf;
D$l!|$L
X+D$ P
j;YFf9
SVWjD^V3
D$tPVW
D$tPVj
thXxL
L$ SSSQ
9D$<t]
L$ RQR
t$ PV3
t$ PV3
t"hXxL
j\^f90uJj
f90u;j
L$$VWh
~jeXf9
>jeYf;
t j-_f;
D$$SPV
D$$SPV
D$$SPV
u!SSh2
VVVVPPPP
L$XQVh2
t$P+t$H
D$TF+D$Lj
L$@+L$ ;
D$,+D$$
|$,SWPV
D$$WPV
D$$WPV
D$$WPV
\$(+\$
|$,+|$$
taVWj$
QQSVWj$
f9t^SQ
PVh0~L
f92t'RV
4SVWj,
8SVWj,3
j7XSVW
QQQQQP
SSSSPSh
tKf91tF3
@PPj!j
u<@PPj!j
uS9q4uN
Wj!j j
D$\PWhL
D$8+D$0j
D$<+D$4@P
D$8+D$0j
D$<+D$4P
D$0VPS
D$0VPS
GVPPPPP
PPj PPP
T$L;t$
D$\PWV
;|$8}+
+G<+W@
D$TPVh>
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$0Ft9
u\PPRj
{,9C0~[
j\Xf;u
jHX_^[
4Ff9>t
4Ff9>t
SVWj0_j
N;S|sa
GetNativeSystemInfo
kernel32.dll
[:>:]]
[:<:]]
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
Unknown exception
bad allocation
bad array new length
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
`h````
xpxxxx
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
CompareStringEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
GetDateFormatEx
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
RoInitialize
RoUninitialize
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
RUUUUU
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
UUUUUU
?UUUUUU
UUUUUU
?UUUUUU
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
<8bunz8
l,kg<i
<@En[vP
?Dj0Q:W$=
5s3R6=
i^^?(>
Y:/(A6>
?ZEM-'^
?{yK+;
?765@Z
?e')lW
?UUUUUU
|u?!u$
Nu?-HF
d? cf>
&2@UUUUUU
UUUUUU
#wi#:=
&2@UUUUUU
Nu?-HF
?uZEeu
?uZEeu
?5Wg4p
%S#[k=
"B <1=
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
pqrstuvwxyz{$--%"!'
`abcdefghijkmno]
 !"#$%&'()))*+,-./0123456789:;<=>?@ABBCDEFGHIGJKLLBMBBNOPQRSTUVWXYZ[\]^G___________________________________________________`___________________________________________________________________________________________________________________________________________________________________abccccccccdeefghijklmnopqrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstyzzzzzzzzzzzzzzzz{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{__|}~
_____________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
________________________________
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
Wow64RevertWow64FsRedirection
Wow64DisableWow64FsRedirection
Qkkbal
no error
\ at end of pattern
\c at end of pattern
unrecognized character follows \
numbers out of order in {} quantifier
number too big in {} quantifier
missing terminating ] for character class
invalid escape sequence in character class
range out of order in character class
nothing to repeat
internal error: invalid forward reference offset
internal error: unexpected repeat
unrecognized character after (? or (?-
POSIX named classes are supported only within a class
missing )
reference to non-existent subpattern
erroffset passed as NULL
unknown option bit(s) set
missing ) after comment
parentheses nested too deeply
regular expression is too large
failed to get memory
unmatched parentheses
internal error: code overflow
unrecognized character after (?<
lookbehind assertion is not fixed length
malformed number or name after (?(
conditional group contains more than two branches
assertion expected after (?( or (?(?C)
(?R or (?[+-]digits must be followed by )
unknown POSIX class name
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
spare error
character value in \x{} or \o{} is too large
invalid condition (?(0)
\C not allowed in lookbehind assertion
PCRE does not support \L, \l, \N{name}, \U, or \u
number after (?C is > 255
closing ) for (?C expected
recursive call could loop indefinitely
unrecognized character after (?P
syntax error in subpattern name (missing terminator)
two named subpatterns have the same name
invalid UTF-8 string
support for \P, \p, and \X has not been compiled
malformed \P or \p sequence
unknown property name after \P or \p
subpattern name is too long (maximum 32 characters)
too many named subpatterns (maximum 10000)
repeated subpattern is too long
octal value is greater than \377 in 8-bit non-UTF-8 mode
internal error: overran compiling workspace
internal error: previously-checked referenced subpattern not found
DEFINE group contains more than one branch
repeating a DEFINE group is not allowed
inconsistent NEWLINE options
\g is not followed by a braced, angle-bracketed, or quoted name/number or by a plain number
a numbered reference must not be zero
an argument is not allowed for (*ACCEPT), (*FAIL), or (*COMMIT)
(*VERB) not recognized or malformed
number is too big
subpattern name expected
digit expected after (?+
] is an invalid data character in JavaScript compatibility mode
different names for subpatterns of the same number are not allowed
(*MARK) must have an argument
this version of PCRE is not compiled with Unicode property support
\c must be followed by an ASCII character
\k is not followed by a braced, angle-bracketed, or quoted name
internal error: unknown opcode in find_fixedlength()
\N is not supported in a class
too many forward references
disallowed Unicode code point (>= 0xd800 && <= 0xdfff)
invalid UTF-16 string
name is too long in (*MARK), (*PRUNE), (*SKIP), or (*THEN)
character value in \u.... sequence is too large
invalid UTF-32 string
setting UTF is disabled by the application
non-hex character in \x{} (closing brace missing?)
non-octal character in \o{} (closing brace missing?)
missing opening brace after \o
parentheses are too deeply nested
invalid range in character class
group name must start with a non-digit
parentheses are too deeply nested (stack check)
digits missing in \x{} or \o{}
regular expression is too complicated
xdigit
ACCEPT
COMMIT
Arabic
Armenian
Avestan
Balinese
Bassa_Vah
Bengali
Bopomofo
Brahmi
Braille
Buginese
Canadian_Aboriginal
Carian
Caucasian_Albanian
Chakma
Cherokee
Common
Coptic
Cuneiform
Cypriot
Cyrillic
Deseret
Devanagari
Duployan
Egyptian_Hieroglyphs
Elbasan
Ethiopic
Georgian
Glagolitic
Gothic
Grantha
Gujarati
Gurmukhi
Hangul
Hanunoo
Hebrew
Hiragana
Imperial_Aramaic
Inherited
Inscriptional_Pahlavi
Inscriptional_Parthian
Javanese
Kaithi
Kannada
Katakana
Kayah_Li
Kharoshthi
Khojki
Khudawadi
Lepcha
Linear_A
Linear_B
Lycian
Lydian
Mahajani
Malayalam
Mandaic
Manichaean
Meetei_Mayek
Mende_Kikakui
Meroitic_Cursive
Meroitic_Hieroglyphs
Mongolian
Myanmar
Nabataean
New_Tai_Lue
Ol_Chiki
Old_Italic
Old_North_Arabian
Old_Permic
Old_Persian
Old_South_Arabian
Old_Turkic
Osmanya
Pahawh_Hmong
Palmyrene
Pau_Cin_Hau
Phags_Pa
Phoenician
Psalter_Pahlavi
Rejang
Samaritan
Saurashtra
Sharada
Shavian
Siddham
Sinhala
Sora_Sompeng
Sundanese
Syloti_Nagri
Syriac
Tagalog
Tagbanwa
Tai_Le
Tai_Tham
Tai_Viet
Telugu
Thaana
Tibetan
Tifinagh
Tirhuta
Ugaritic
Warang_Citi
This is a third-party compiled AutoIt script.
DllGetClassObject
GetModuleHandleExW
GetSystemWow64DirectoryW
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
DEFINE
UTF16)
NO_AUTO_POSSESS)
NO_START_OPT)
LIMIT_MATCH=
LIMIT_RECURSION=
ANYCRLF)
BSR_ANYCRLF)
BSR_UNICODE)
argument is not a compiled regular expression
argument not compiled in 16 bit mode
internal error: opcode not recognized
internal error: missing capturing bracket
failed to get memory
.text$di
.text$lp00AutoItSC
.text$mn
.text$np
.text$x
.text$yd
.text$zy
.text$zz
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$00
.rdata$T
.rdata$r
.rdata$zz
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$00
.data$dk00
.data$r
.data$zz
.bss$00
.bss$dk00
.bss$zz
.rsrc$01
.rsrc$02
WSOCK32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
timeGetTime
mciSendStringW
waveOutSetVolume
WINMM.dll
InitCommonControlsEx
ImageList_Create
ImageList_ReplaceIcon
ImageList_Destroy
ImageList_Remove
ImageList_SetDragCursorImage
ImageList_BeginDrag
ImageList_DragEnter
ImageList_DragLeave
ImageList_EndDrag
ImageList_DragMove
COMCTL32.dll
WNetAddConnection2W
WNetUseConnectionW
WNetCancelConnection2W
WNetGetConnectionW
MPR.dll
InternetCloseHandle
InternetOpenW
InternetSetOptionW
InternetCrackUrlW
HttpQueryInfoW
InternetQueryOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
InternetReadFile
InternetQueryDataAvailable
WININET.dll
GetProcessMemoryInfo
PSAPI.DLL
IcmpCreateFile
IcmpSendEcho
IcmpCloseHandle
IPHLPAPI.DLL
LoadUserProfileW
CreateEnvironmentBlock
UnloadUserProfile
DestroyEnvironmentBlock
USERENV.dll
IsThemeActive
UxTheme.dll
InterlockedIncrement
InterlockedDecrement
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
RaiseException
GetLastError
DecodePointer
lstrcmpiW
GetCurrentDirectoryW
IsDebuggerPresent
SetCurrentDirectoryW
GetFullPathNameW
CloseHandle
GetCurrentThread
GetCurrentProcess
DuplicateHandle
CreateThread
WaitForSingleObject
HeapAlloc
GetProcessHeap
HeapFree
GetCurrentThreadId
MultiByteToWideChar
MulDiv
GetVersionExW
IsWow64Process
GetSystemInfo
FreeLibrary
LoadLibraryA
GetProcAddress
SetErrorMode
GetModuleFileNameW
WideCharToMultiByte
lstrcpyW
lstrlenW
GetModuleHandleW
QueryPerformanceCounter
VirtualFreeEx
OpenProcess
VirtualAllocEx
WriteProcessMemory
ReadProcessMemory
CreateFileW
SetFilePointerEx
SetEndOfFile
ReadFile
WriteFile
FlushFileBuffers
TerminateProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
SetFileTime
GetFileAttributesW
FindFirstFileW
FindClose
GetLongPathNameW
GetShortPathNameW
DeleteFileW
FindNextFileW
CopyFileExW
MoveFileW
CreateDirectoryW
RemoveDirectoryW
SetSystemPowerState
QueryPerformanceFrequency
LoadResource
LockResource
SizeofResource
OutputDebugStringW
GetTempPathW
GetTempFileNameW
DeviceIoControl
LoadLibraryW
GetLocalTime
CompareStringW
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
CreatePipe
InterlockedExchange
TerminateThread
LoadLibraryExW
FindResourceExW
CopyFileW
VirtualFree
FormatMessageW
GetExitCodeProcess
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileSectionW
WritePrivateProfileSectionW
GetPrivateProfileSectionNamesW
FileTimeToLocalFileTime
FileTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
GetDriveTypeW
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetVolumeInformationW
SetVolumeLabelW
CreateHardLinkW
SetFileAttributesW
CreateEventW
SetEvent
GetEnvironmentVariableW
SetEnvironmentVariableW
GlobalLock
GlobalUnlock
GlobalAlloc
GetFileSize
GlobalFree
GlobalMemoryStatusEx
GetSystemDirectoryW
HeapReAlloc
HeapSize
GetComputerNameW
GetWindowsDirectoryW
GetCurrentProcessId
GetProcessIoCounters
CreateProcessW
GetProcessId
SetPriorityClass
VirtualAlloc
KERNEL32.dll
DestroyIcon
MessageBoxA
GetForegroundWindow
GetSysColorBrush
LoadCursorW
LoadIconW
RegisterClassExW
CreateWindowExW
ShowWindow
SetTimer
RegisterWindowMessageW
CreatePopupMenu
KillTimer
PostQuitMessage
SetFocus
MoveWindow
DefWindowProcW
MessageBoxW
GetUserObjectSecurity
OpenWindowStationW
GetProcessWindowStation
SetProcessWindowStation
OpenDesktopW
CloseWindowStation
CloseDesktop
SetUserObjectSecurity
GetWindowRect
PostMessageW
MapVirtualKeyW
SendMessageW
GetDlgCtrlID
GetParent
GetClassNameW
CharUpperBuffW
EnumChildWindows
SendMessageTimeoutW
ScreenToClient
GetWindowTextW
GetFocus
AttachThreadInput
GetWindowThreadProcessId
GetWindowLongW
InvalidateRect
EnableWindow
IsWindowVisible
IsWindowEnabled
IsWindow
GetDesktopWindow
EnumWindows
DestroyWindow
GetMenu
GetClientRect
BeginPaint
EndPaint
ReleaseDC
CopyRect
SetWindowTextW
GetDlgItem
SendDlgItemMessageW
EndDialog
MessageBeep
DialogBoxParamW
LoadStringW
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
SendInput
keybd_event
SystemParametersInfoW
FindWindowW
IsIconic
SetForegroundWindow
GetMenuItemInfoW
SetMenuItemInfoW
GetMenuItemCount
GetMenuItemID
CheckMenuRadioItem
DeleteMenu
GetCursorPos
TrackPopupMenuEx
IsMenu
InsertMenuItemW
SetMenuDefaultItem
EnumThreadWindows
FindWindowExW
SetActiveWindow
ExitWindowsEx
mouse_event
LoadImageW
MonitorFromRect
MonitorFromPoint
CharLowerBuffW
UnregisterHotKey
GetInputState
PeekMessageW
TranslateMessage
DispatchMessageW
LockWindowUpdate
GetMessageW
BlockInput
OpenClipboard
IsClipboardFormatAvailable
GetClipboardData
CloseClipboard
CountClipboardFormats
EmptyClipboard
SetClipboardData
SetRect
AdjustWindowRectEx
CopyImage
SetWindowPos
GetCursorInfo
RegisterHotKey
ClientToScreen
GetKeyboardLayoutNameW
IsCharAlphaW
IsCharAlphaNumericW
IsCharLowerW
IsCharUpperW
GetMenuStringW
GetSubMenu
GetCaretPos
IsZoomed
GetMonitorInfoW
SetWindowLongW
SetLayeredWindowAttributes
FlashWindow
GetClassLongW
TranslateAcceleratorW
IsDialogMessageW
GetSysColor
InflateRect
DrawFocusRect
DrawTextW
FrameRect
DrawFrameControl
FillRect
PtInRect
DestroyAcceleratorTable
CreateAcceleratorTableW
SetCursor
GetWindowDC
GetSystemMetrics
GetActiveWindow
CharNextW
wsprintfW
RedrawWindow
DrawMenuBar
DestroyMenu
SetMenu
GetWindowTextLengthW
CreateMenu
IsDlgButtonChecked
DefDlgProcW
CallWindowProcW
ReleaseCapture
SetCapture
USER32.dll
GetDeviceCaps
DeleteObject
GetTextExtentPoint32W
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
StretchBlt
GetDIBits
DeleteDC
GetPixel
CreateDCW
GetStockObject
GetTextFaceW
CreateFontW
SetTextColor
CreateSolidBrush
CreatePen
SetBkColor
RoundRect
SetBkMode
GetObjectW
SetViewportOrgEx
Rectangle
BeginPath
PolyDraw
Ellipse
MoveToEx
AngleArc
LineTo
CloseFigure
SetPixel
EndPath
StrokePath
StrokeAndFillPath
ExtCreatePen
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
RegConnectRegistryW
InitializeSecurityDescriptor
InitializeAcl
AdjustTokenPrivileges
OpenThreadToken
OpenProcessToken
LookupPrivilegeValueW
DuplicateTokenEx
CreateProcessAsUserW
CreateProcessWithLogonW
GetLengthSid
CopySid
LogonUserW
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
GetTokenInformation
GetSecurityDescriptorDacl
GetAclInformation
GetAce
AddAce
SetSecurityDescriptorDacl
InitiateSystemShutdownExW
GetUserNameW
RegCreateKeyExW
RegSetValueExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumValueW
ADVAPI32.dll
ShellExecuteW
Shell_NotifyIconW
ExtractIconExW
SHFileOperationW
SHGetFolderPathW
SHGetSpecialFolderLocation
SHGetDesktopFolder
SHCreateShellItem
SHBrowseForFolderW
SHGetPathFromIDListW
SHEmptyRecycleBinW
DragQueryFileW
ShellExecuteExW
DragQueryPoint
DragFinish
SHELL32.dll
CoTaskMemAlloc
CoTaskMemFree
CLSIDFromString
ProgIDFromCLSID
CLSIDFromProgID
OleSetMenuDescriptor
MkParseDisplayName
OleSetContainedObject
CoCreateInstance
IIDFromString
StringFromGUID2
CreateStreamOnHGlobal
OleInitialize
OleUninitialize
CoInitialize
CoUninitialize
GetRunningObjectTable
CoGetInstanceFromFile
CoGetObject
CoInitializeSecurity
CoCreateInstanceEx
CoSetProxyBlanket
ole32.dll
OLEAUT32.dll
ResetEvent
WaitForSingleObjectEx
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
SetLastError
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
ExitProcess
GetModuleHandleExW
ExitThread
ResumeThread
FreeLibraryAndExitThread
GetACP
GetDateFormatW
GetTimeFormatW
LCMapStringW
GetStringTypeW
GetFileType
SetStdHandle
GetConsoleCP
GetConsoleMode
ReadConsoleW
GetTimeZoneInformation
FindFirstFileExW
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
wwwwwwwwwwwwwx
wwwwwwwwwwwwwx
xwxwxx
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
jqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqj
~~~~~z~zzzzzzzzzzzzzzz
vvvvvvvvvvvvvvzvvvv~zz~zzzzzwzwzvzvz
knnnnnnnnnnnnnnnnnkv~z~zzzzzzzzxzxxxx
nGGHHH
nv~zsssssssszxzzzzx
nGGGHH
nv~~~~~~~z~zzzzxzxy
n..GGHHH
nv~~ssssssss{zzzyyy
n...GGHHH
nv~~~~~~~~~{{zzzzyz
n+....HGHHHH
ssssssst~{{zzyy
n++....G.HHH
~~~~{~{{{{
n!!+....HGHHHH
ssssstts~{~{{{{
n!!++.....HHHHHH
~~~~~~{~{{
n!!!++....GGHHH
n!!""....-HHHH
!!"".....HHHHnv
ssssssss
"""+....G-Hnv
""""..-.-Gnv
ssssssss
"""...-.nv
""""..-nv
ssssssss
nU_[_[D
!""".+nv
nOTUTU[[ED'"""+nv
ssssssss
nCODOSSSWWWWXWLWaanv
n;;>D;DDDEESLWLLLLnv
ssssssss
;;:::3***3444nv
'''*"31nv
ssssssss
'*nv
mnnnnnnnnnnnnnnnnnm
ssssssss
jurrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrruj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
J>>>>>>>>>>>>>>>>ACA>>>>>>>>>G
>S]]]]]]]]]]]]]]]]]]]]]]]]]]]>
>S]]a]aaa]]]]]]a```____R_R_U]>
>_]]QQQQQQRQRQQQ_``__STTRRRR]>
>\]FIIIIIIIIIIFQ`LLLLLL_TRRR]>
>_]I$$$
IQ```a\a_`_URR]>
IQ^LLLLLL___RR]>
IQ`_``a\a\_SRU]>
IQ````ca\a__a]]>
IQ`LLLLLL\]a_a]>
$$$IQ````aca_a\]_]>
$$IQ`LLLLLL]`
IQ``_`a\a`a
IQ`LLLLLLa\$
>_]IE=,
IQ``````a\a
>_]I66;;80-&&7IQ`LLLLLL`\
>]]I11255880::IQ`````a\ac
C]]I****,+...-IQ`LLLLLLca
 ""IQ````aca\c
C]]HIIIIIIIIIIH]aLLLLLLa\
C]]]]]]]]]]]]]]]]]]]]]]]]]]]]>
C_]a`a]]ac]a]a]a]a`a\a\a\ac]]>
DKLKKKLKKLKKKKLKLKLKLMKKKKLKL>
APOOOOOOOOOOOOOOOOOOOOO
>>>>>>>>>>>>>>>>>>>>>>>>>>>>J
H}AU3!EA06M
XOg;Mm
AU3!EA06
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
</assembly>
0(090K0W0`0k0|0
1 1*13171<1K1R1W1\1a1k1u1
2 2%2*2024292>2C2I2M2R2W2\2b2f2k2p2u2z2
3*33383=3B3G3L3Q3W3\3a3f3l3~3
3+4U4[4
8M:Y:_:g:m:s:x:~:
;B<S<Y<e<q<x<~<
=,=R=`=
;1;7;F;Q;m;
<2<<<B<H<N<T<g<p<
=&=-=3=8=>=D=I=a=q=|=
>P?e?z?
1$1P1x1
2)2.242:2@2H2M2Z2i2{3h4n4u4|4
5(5:5a5l5
5[6a6g6s6|6
7"7'7,747:7@7F7[7a7j7p7v7|7
919O9q9
<!<,<7<A<R<[<f<o<|<
>(>2><>F>Q>u>
242=2B2[2
3'323I3_3m3y3
4$4+494P4V4a4h4}4
7(9V9i:
==%=+=1=5=;=A=G=M=S=]=c=i=o=u={=
>!>%>0>;>A>L>\>d>o>v>
:#;D;w;
;<$<*<|<
/0N0b0l0
1"1*1K1h2E577T7
808H8`8t8
9#:0:8:
:R<h<|<
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1>2F2L2
:+=G?N?
4 4$4(4,4044484<4@4D4H4L4P4T4X4-868C8c8
;7;;;?;C;G;K;O;
>@?Q?b?
0H1L1P1T1X1\1`1d1h1l1p1
1,2024282<2@2D2H2L2P2T2X2\2`2
3l3p3t3x3|3
7-8:8G8
;";.;3;=;J;];l;
0 0$0(0,00040801R1
2<2@2D2H2L2P2T2X2303.4
5074787<7@7D7H7L7P7T7X7
818>8T8i8
:*;P;e;};
;#<)</<5<
< =$=(=,=0=4=8=<=@=D=H=
=(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
4$4/464
8(919S9_9
< <$<(<,<0<4<8<<<[<
<.=5=o=
=4>_>k>
2f3v3{3
3@4I4`4m4,555L5Y5|5
8!999 :M:
;F;N;a;
=;>I>U>b>t>
?g?x?|?
@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3*3f3|3
9D9^9y9
:!:':+:1:;:E:O:Z:b:f:l:p:v:
;);1;5;;;?;E;O;Y;c;n;v;z;
<(<2<=<E<I<O<S<Y<c<m<w<
="=(=2=<=F=Q=Y=]=c=g=m=w=
> >(>,>2>6><>F>P>Z>e>m>q>w>{>
??)?4?<?@?F?J?P?Z?d?n?y?
00)030=0H0P0T0Z0^0d0n0x0
11#1)1-131=1G1Q1\1d1h1n1r1x1
2 2+23272=2A2G2Q2[2e2p2x2|2
3 3*343?3G3K3Q3U3[3e3o3y3
4 4$4*444>4H4S4[4_4e4i4o4y4
5"5*5.54585>5H5R5\5g5o5s5y5}5
6!6+666>6B6H6L6R6\6f6p6{6
7!7+757?7J7R7V7\7`7f7p7z7
8!8%8+8/858?8I8S8^8f8j8p8t8z8
9"9-95999?9C9I9S9]9g9r9z9~9
:":,:6:A:I:M:S:W:]:g:q:{:
;";&;,;6;@;J;U;];a;g;k;q;{;
<$<,<0<6<:<@<J<T<^<i<q<u<{<
=#=-=8=@=D=J=N=T=^=h=r=}=
>#>->7>A>L>T>X>^>b>h>r>|>
?#?'?-?1?7?A?K?U?`?h?l?r?v?|?
0$0/070;0A0E0K0U0_0i0t0|0
1$1.181C1K1O1U1Y1_1i1s1}1
2$2(2.282B2L2W2_2c2i2m2s2}2
3&3.32383<3B3L3V3`3k3s3w3}3
4%4/4:4B4F4L4P4V4`4j4t4
55%5/595C5N5V5Z5`5d5j5t5~5
6%6)6/63696C6M6W6b6j6n6t6x6~6
7&71797=7C7G7M7W7a7k7v7~7
8&808:8E8M8Q8W8[8a8k8u8
9 9&9*909:9D9N9Y9a9e9k9o9u9
:(:0:4:::>:D:N:X:b:m:u:y:
;';1;<;D;H;N;R;X;b;l;v;
<!<'<1<;<E<P<X<\<b<f<l<v<
=='=+=1=5=;=E=O=Y=d=l=p=v=z=
>(>3>;>?>E>I>O>Y>c>m>x>
?(?2?<?G?O?S?Y?]?c?m?w?
0"0(0,020<0F0P0[0c0g0m0q0w0
11*12161<1@1F1P1Z1d1o1w1{1
22)232>2F2J2P2T2Z2d2n2x2
33#3)333=3G3R3Z3^3d3h3n3x3
4!4)4-43474=4G4Q4[4f4n4r4x4|4
5 5*555=5A5G5K5Q5[5e5o5z5
6 6*646>6I6Q6U6[6_6e6o6y6
7 7$7*7.747>7H7R7]7e7i7o7s7y7
8!8,84888>8B8H8R8\8f8q8y8}8
9!9+959@9H9L9R9V9\9f9p9z9
:!:%:+:5:?:I:T:\:`:f:j:p:z:
;#;+;/;5;9;?;I;S;];h;p;t;z;~;
<"<,<7<?<C<I<M<S<]<g<q<|<
="=,=6=@=K=S=W=]=a=g=q={=
>">&>,>0>6>@>J>T>_>g>k>q>u>{>
?#?.?6?:?@?D?J?T?^?h?s?{?
0#0-070B0J0N0T0X0^0h0r0|0
1#1'1-171A1K1V1^1b1h1l1r1|1
2%2-21272;2A2K2U2_2j2r2v2|2
3$3.393A3E3K3O3U3_3i3s3~3
4$4.484B4M4U4Y4_4c4i4s4}4
5$5(5.52585B5L5V5a5i5m5s5w5}5
6%60686<6B6F6L6V6`6j6u6}6
7%7/797D7L7P7V7Z7`7j7t7~7
88%8)8/898C8M8X8`8d8j8n8t8~8
9'9/93999=9C9M9W9a9l9t9x9~9
:&:0:;:C:G:M:Q:W:a:k:u:
; ;&;0;:;D;O;W;[;a;e;k;u;
<&<*<0<4<:<D<N<X<c<k<o<u<y<
='=2=:=>=D=H=N=X=b=l=w=
>'>1>;>F>N>R>X>\>b>l>v>
?!?'?+?1?;?E?O?Z?b?f?l?p?v?
0)01050;0?0E0O0Y0c0n0v0z0
1(121=1E1I1O1S1Y1c1m1w1
2"2(222<2F2Q2Y2]2c2g2m2w2
3 3(3,32363<3F3P3Z3e3m3q3w3{3
44)444<4@4F4J4P4Z4d4n4y4
55)535=5H5P5T5Z5^5d5n5x5
66#6)6-636=6G6Q6\6d6h6n6r6x6
7 7+73777=7A7G7Q7[7e7p7x7|7
8 8*848?8G8K8Q8U8[8e8o8y8
9 9$9*949>9H9S9[9_9e9i9o9y9
:":*:.:4:8:>:H:R:\:g:o:s:y:}:
;!;+;6;>;B;H;L;R;\;f;p;{;
<!<+<5<?<J<R<V<\<`<f<p<z<
=!=%=+=/=5=?=I=S=^=f=j=p=t=z=
>">->5>9>?>C>I>S>]>g>r>z>~>
?"?,?6?A?I?M?S?W?]?g?q?{?
0"0&0,060@0J0U0]0a0g0k0q0{0
1$1,10161:1@1J1T1^1i1q1u1{1
2#2-282@2D2J2N2T2^2h2r2}2
3#3-373A3L3T3X3^3b3h3r3|3
4#4'4-41474A4K4U4`4h4l4r4v4|4
5$5/575;5A5E5K5U5_5i5t5|5
6$6.686C6K6O6U6Y6_6i6s6}6
7$7(7.787B7L7W7_7c7i7m7s7}7
8&8.82888<8B8L8V8`8k8s8w8}8
9%9/9:9B9F9L9P9V9`9j9t9
::%:/:9:C:N:V:Z:`:d:j:t:~:
;%;);/;3;9;C;M;W;b;j;n;t;x;~;
<&<1<9<=<C<G<M<W<a<k<v<~<
=&=0=:=E=M=Q=W=[=a=k=u=
> >&>*>0>:>D>N>Y>a>e>k>o>u>
?(?0?4?:?>?D?N?X?b?m?u?y?
0'010<0D0H0N0R0X0b0l0v0
1!1'111;1E1P1X1\1b1f1l1v1
22'2+21252;2E2O2Y2d2l2p2v2z2
3(333;3?3E3I3O3Y3c3m3x3
4(424<4G4O4S4Y4]4c4m4w4
5"5(5,525<5F5P5[5c5g5m5q5w5
66*62666<6@6F6P6Z6d6o6w6{6
:!:*:>:\:x:
=#=*=3=A=
Y0k0|0
2'2C2p2{2
2#3Y3b3
6%636N6Y6q6w6}6
8B8d8}8
9 9$9T9Z9b9
5585c8~8
B6F7M7s7w7{7
020b0f0j0n0r0v0z0~0
1"1&1*1.12161:1>1B1F1J1N1R1V1Z1^1b1f1j1n1r1v1z1~1
3+3m6t6
7O7S7W7[7_7c7g7k7o7s7w7{7
85999=9A9E9I9M9Q9U9Y9]9a9e9i9m9q9u9y9}9
;;#;';+;/;3;7;;;?;y;
a1g1R2r2|2G3
868R8^8f8n8v8~8
9$9/9:9E9W9i9
;%;0;;;F;Q;\;n;y;
?"?/?8?=?B?G?L?Q?V?[?`?e?j?o?t?y?~?
2)2-2125292=2A2E2I2z2
6.6<6c6
8=8B8G8L8Q8V8\8a8
9R<">5>
?'?:?F?V?g?}?
80E0l0t0
1#1)141:1I1P1U1^1c1l1
2#2+272H2O2w2
3"3(3/3n3
3)4>4C4H4i4n4{4
6/6`6}6
6e7n7v7
989B9u9
9$:1:N:
:&;/;<;B;l;
<(<1<<<C<c<i<o<u<{<
=.=7=K=h=w=
0+1014181<1
3 3$3(3,30343u3
9+:0:4:8:<:8=
3N3S3c3
44-4H4Y4e4
5"565L5r5
6*676@6E6J6e6o6{6
67/777<7G7j7|7
9;9@9g9
<'<=<T<[<g<z<
=$=-=u=
= >2>8>L>
?F?a?l?
+4|4&54;
= =B=T=
>q?u?y?}?
1&1;1Q1^1l1z1
4,555m55696=6A6E6I6M6Q6U6Y6
6#<X>`>
:L:S:y=2?:?q?x?
1@1h1~1
2/7l7y7
334Q4-5{6
2.3h3r3
3-4G4T4
8;8^8i8{8
899I9[9f9
7:7d7F8Q8
7a7k7q7w7
7$8/84:>:]:d:
>#>.>B>
1'2,292E2[2n2
3*3/3<3J3Q3Y3r3
7&737f7x7
<F=M=z=
>=>N>h>q>~>
?"?;?h?o?z?
)090P0X0
0)1M1i1t1y1~1
2 2%2*2E2O2k2v2{2
3*3F3Q3V3[3v3
4!4B4R4n4y4~4
5)5R5]5b5g5
663686=6_6m6|6
787W7N8T8\9
6"6)6G6F8v8
=1=>=C=Q=
1,141]1d1{1
2$2N2a2k2
474S4r4
<'<u<Y?`?
6#696A6
<U=g=y=
>%>0>k>
0I0U0m0u0
4A5p5=6Q6i6q6
888@8M8N9
/0N0d0
:';:;p;|;
?/?^?u?
3f4n4v4~4
:";*;G;W;c;r;*<2<F<P<n<z<
=$=0=d=n=v=
>T>c>k>q>
0i1u1}1
2#2/2V2x2
3R4Z4f4
6!6-666
6.7;7G7
7&9.969
:#:B:]:f:n:[;
;I<U<e<q<
>!>>>D>Y>~>
>J?`?p?
#0H0T0`0s0
1&121>1Q1u1
3$333>3B3J3P3V3\3
4O6W6c6p6x6
7/878v8~8
90969<9
747;7B7I7c7r7|7
738N8`:
:$;9;G;P;
<==o=t=z=
?D?O?\?m?{?
2o3v3}3
4T5]5u5
5R6d6v6
7*7K7]7o7
9':t:L;
2!3'3c3
5w5J=R=
4>8E8L8S8
939M9s9
1M2g2t2
6y7Y8a8i8q8y8
9!9-999Y9
;-;K;_;e;
4'464@4J4T4^4h4r4|4
;0;5;<;G;U;b;g;r;
=*=3=;=T=y=
>*>6>O>m>
3L4\4a4z4
666K6h6n6t6z6
7(737>7D7O7U7[7f7q7w7
<%<4<<<
4#4M4p4
2155595=5A5
8_:t:P=
D1Z6g6o6v6
0@0I0j0w0
1Y3`3y3
51888^8e8A;S;Z;_<f<
=$=+='?:?A?
:L;[;c;
0<1I1Q1_1
9h>e?r?z?
T0c0k0r0
1e2r2z2
4E5L5?7L7T7
7P8`8h8|8
4J5Y5a5
6(60676U7\7}7
7`8r8z8
:a;n;v;
6)7-797=7M7Q7a7e7i7m7q7u7y7}7
8!8%8)8-8185898=8A8E8I8M8Q8U8Y8]8a8e8i8m8q8
9!9%9)9-9195999=9A9E9I9M9Q9
8.8=8E8
2#2+262P2d2u2
77#7'7+7/73777;7?7C7G7K7O7S7W7[7_7c7g7k7o7s7w7{7
<<#<'<+</<3<7<;<H<
=5>A>F>W>
7/8P9M:x;
<+<?<m<
=#='=+=/=3=7=;=?=C=G=K=O=S=W=[=_=c=g=k=o=s=w={=
0&0.080E0S0
839E9^:
:V;Z;^;b;f;j;n;r;v;z;~;
<"<&<*<.<2<6<:<><B<F<J<N<R<V<Z<^<b<f<j<n<r<v<z<~<
="=&=*=.=2=6=:=>=B=F=J=N=R=V=Z=^=b=f=j=n=r=v=z=~=
C3`3z3
99)969]9k9s9}9
="=&=*=.=2=6=:=>=B=F=J=N=R=V=Z=^=b=f=j=n=r=v=z=~=
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
:):w<~<
1!2%2)2-2125292=2A2E2I2M2Q2U2Y2]2a2e2i2m2q2u2y2
3!3%3)3-3F4E5Q6U6Y6]6a6e6i6m6q6u6y6}6
7E8R8\8r8
8 9g9u9
:0:>:O:b:
;=<H<`<
=3=L=w=}=
><>T>j>
?E?Q?f?
0,0:0s0y0
2B2K2R2
2"3`3t3
3/4T4k4w4
455B5[5t5
7N8d8_?
1:1W1t1
4A5N5U5
=Y>n>w>
9/;6;W<~<
=.>a>e>i>m>q>u>y>}>
384R4l4
<%</<H<U<`<j<u<
>!>%>)>->1>5>9>=>A>E>I>M>m>q>u>y>}>
Z0l0s0
1"2,2C2\2g2
646O6Y6g6n6y6
7"7-747?7F7Q7X7c7o7w7
7,838E8L8Z8d8n8x8
9*9=9P9f9|9
9^;i;p;~;
4.4?4V4p4v4
:':=:i:q:|:
-0H0V0f0r0
= =:=G=W=g=z=
=+><>|>
?7?I?c?p?
0,080G0N0d0
1"11181O1m1t1
3+4]4j4q4|4
5"5Q5e5
6 666=6J6Q6
858P8b8j8
=&>h>{>
>"?Y?q?
070P0f0x0
101O1z1
3%4T4}4
8#9_9Y:`:g:
;,;A;P;g;
=;=f=|=
?H?Z?a?n?
7*7F7{7
=o=T>q>
0+0>0X0
2 2:2C2
283G3T3F4S4
506T6l6
67?7R7j7
889U9k9
9(:0:B:H:^:
:+;w;~;
<1<Z<q<
<[=k=}=
=3>F>\>i>
2,363_3
9H:Y:t:
2>2C2O2m2
6&696i6
8%9K9|9
888K8h8
9.9V9n9
<$=*=Y=
5E6L6r6
6F9J9N9R9V9Z9^9b9f9j9n9r9v9z9~9
0(1S1g1n1w1}1
2W3g3}3
1[2c2r2
4$5=5p5{5
6L6S6b6i6z6
758L8U8
9*9T9~9
:;:@:F:@<
192U2f2
;*;1;A;R;Y;
;"<H<o<z<
= =h=q=
>D>^>k>
222A2H2O2U2
7"7)757B7H7V7\7o7u7
949T9g9
:7:E:Y:o:
:2;H;W;f;p;w;
;.<Q<,=
0"0R0m0u0
71G1i1
405B5h5n5
6:6@6d6
8Y9a9}9
9!=*=6=
E1^2t2{2
5&6Y6h6t6
8%8E9I9M9Q9U9Y9]9a9e9i9m9q9u9y9}9
=^?k?u?
0+0:0@0L0T0k0z0
01090F0&1
5#5>5D5l5
7%7C7^7d7
9$90999M9W9h9
=W>b>m>
0)0E0s0
727E7X7n8
<8=G=K=O=S=W=[=_=c=g=k=o=s=w={=
4"4E4L4S4Z4a4
5;6E6L6R6h6
7!8^8m8u9
<P=Y=|=
0Y2i2u2
W0h0y0
737d7t7
8&8<8K8b8y8
8'9X9~9
9.:A:R:X:
:,;D;Q;e;
0O0&131
192F2t2
3$383C3
455K5V5
;~;\<g=
@0R0<1/2Y2a2
6#6?607
;%;+;1;E;Q;
;$<F<W<y<
>E>K>Q>W>`>
6*686w6
< =&=a=g=
'0b0l0
2-2125292=2A2E2I2M2Q2U2Y2]2a2e2
657@7F7l8
9+9P9[9`9f9l9z9
:-:>:K:r:~:
:!;';4;:;G;N;T;Z;o;v;
='=;=d=w=
>2>:>T>
030;0A0|0
1B2~2z3
3[4e4p4
78N8f8
889Y9m9
;!<G<^<n<
7-7K7U7
1*2p2k3
9 9,9m9
2;3T3_3p3
4'525d5u5
5(6R6y6
7&7O7w7
2^3b3f3j3n3r3v3z3~3
7]9h9p9v9
2j3)474j4
>:?J?i?
2J2Y2i2
99:G:P:c:
=*=J=s=A>|?
0j1o1t1
193?3H3d3
959V9q9
</<O<r<
*1?1F1
3*3A3"4
2&3.3A3f3n3u3
8&848B8
=%=0=<=x=
>5>Q>j>
01I1O1
4/5M5V5
5#6^6d6
868[8x8
8'9<9V9e9z9
:L:X:h:w:
;B;q;,<{<
=&=0=]=e=
?*?V?|?
0=0D0W0_0j0t0~0
1'2E2x2
7J7`7{7
585F5L5\5a5
8+9M9Q9U9Y9]9a9e9i9m9q9u9y9}9
:!;A;a;g;
</<><M<d<p<
>E>[>t>
?!?G?V?
080>0[0q0w0
3'4]4e4
9%959p9
:';=;V;
;5<L<V<u<
>6>Y>a>
??)?z?
111P1b1n1y1
222L2d2
3/3:3Q3r3
4'4=4M4s4y4
4,5V5t5
6$636C6L6W6a6g6
7"747Z7
8+8C8S8|8
9&9M9T9e9p9x9
:(:9:G:\:
;+;3;>;T;];f;k;
<<4<A<I<W<`<u<
=,=D=m=
=5>M>q>
>9?E?R?{?
14191T1|1
2N2S2t2~2
55.575
6#6C6s6
8P:Z:r:
;;X;m;s;y;
<'<R<r<
=)=@=\=l=w=>d>
000`0e0
111I1g1~1
2'2@2W2y2
2!3P3s3
4%414N4c4n4
9*909=9C9L9X9~9
;.;U;j;w;
=-=P=Y=
?3?=?H?|?
*050&2D2e2
4$717A7H7p7|7
7W8`8n8x8
?$?+?5?
7,7?7I7P7
9 9$9(9,9094989<9@9D9H9
9094989<9@9D9\9`9d9h9l9p94<8<<<L<P<T<X<\<`<d<h<l<
>,>0>4>8>
0 0$080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
6 6$6(6,6064686<6
8 8$8(8,8
< <$<(<,<0<4<8<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=
=$=,=4=<=D=L=T=\=d=l=t=
7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
Antivirus Signature
Bkav W32.BookisWasvkW.Trojan
Lionic Trojan.Win64.Injects.ts93
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Genericuh.ch
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Autoit.Vp3x
K7AntiVirus Clean
Alibaba Trojan:Win32/Generic.0f9b5b29
K7GW Trojan ( 005b3f351 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.AutoIT.DZH
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Autoit.OQO
APEX Clean
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.73058167
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.73058167
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1372185
DrWeb Clean
VIPRE Clean
TrendMicro TrojanSpy.Win32.RISEPRO.YXEFGZ
McAfeeD Real Protect-LS!AAF735AAFA73
Trapmine Clean
FireEye Generic.mg.aaf735aafa732fc9
Emsisoft Trojan.GenericKD.73058167 (B)
SentinelOne Clean
GData Win32.Trojan.Agent.WMOG59
Jiangmin Trojan.Script.awbz
Webroot W32.Malware.Gen
Varist W32/AutoIt.XQ.gen!Eldorado
Avira HEUR/AGEN.1372185
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Generic.D45AC777
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!AAF735AAFA73
MAX malware (ai score=86)
VBA32 Clean
Malwarebytes Trojan.Downloader.AutoIt
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.RISEPRO.YXEFGZ
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Autoit
MaxSecure Trojan.Malware.121218.susgen
Fortinet AutoIt/Agent.OQO!tr
BitDefenderTheta Gen:NN.ZexaCO.36806.3uW@ay04qToi
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.