Static | ZeroBOX

PE Compile Time

2023-12-14 10:46:57

PE Imphash

5405ad0c6ec36ec4edf07d66fcb3fc73

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008cb91 0x0008cc00 6.67171855386
.rdata 0x0008e000 0x0002dfa4 0x0002e000 5.76453266643
.data 0x000bc000 0x00008e6c 0x00005200 1.19532498504
.rsrc 0x000c5000 0x00016334 0x00016400 6.13456951546
.reloc 0x000dc000 0x000070a4 0x00007200 6.77348238533

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000d5eb4 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_MENU 0x000d631c 0x00000050 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d84dc 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_RCDATA 0x000d979c 0x0000175f LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED ISO-8859 text, with very long lines, with CRLF line terminators
RT_RCDATA 0x000d979c 0x0000175f LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED ISO-8859 text, with very long lines, with CRLF line terminators
RT_GROUP_ICON 0x000daf9c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000daf9c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000daf9c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000daf9c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000dafb0 0x000001a0 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x000db150 0x000001e1 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library WSOCK32.dll:
0x48e7c8 send
0x48e7cc socket
0x48e7d0 inet_ntoa
0x48e7d4 ntohs
0x48e7d8 recvfrom
0x48e7dc sendto
0x48e7e0 recv
0x48e7e4 __WSAFDIsSet
0x48e7e8 WSAStartup
0x48e7ec select
0x48e7f0 accept
0x48e7f4 listen
0x48e7f8 bind
0x48e7fc closesocket
0x48e800 WSACleanup
0x48e804 ioctlsocket
0x48e808 htons
0x48e80c WSAGetLastError
0x48e810 inet_addr
0x48e814 gethostbyname
0x48e818 gethostname
0x48e81c connect
0x48e820 setsockopt
Library VERSION.dll:
0x48e76c GetFileVersionInfoW
0x48e770 VerQueryValueW
Library WINMM.dll:
0x48e7b8 timeGetTime
0x48e7bc waveOutSetVolume
0x48e7c0 mciSendStringW
Library COMCTL32.dll:
0x48e08c ImageList_Destroy
0x48e090 ImageList_Remove
0x48e098 ImageList_BeginDrag
0x48e09c ImageList_DragEnter
0x48e0a0 ImageList_DragLeave
0x48e0a4 ImageList_EndDrag
0x48e0a8 ImageList_DragMove
0x48e0b0 ImageList_Create
Library MPR.dll:
0x48e3f8 WNetUseConnectionW
0x48e400 WNetGetConnectionW
0x48e404 WNetAddConnection2W
Library WININET.dll:
0x48e77c InternetReadFile
0x48e780 InternetCloseHandle
0x48e784 InternetOpenW
0x48e788 InternetSetOptionW
0x48e78c InternetCrackUrlW
0x48e790 HttpQueryInfoW
0x48e794 InternetConnectW
0x48e798 HttpOpenRequestW
0x48e79c HttpSendRequestW
0x48e7a0 FtpOpenFileW
0x48e7a4 FtpGetFileSize
0x48e7a8 InternetOpenUrlW
Library PSAPI.DLL:
Library IPHLPAPI.DLL:
0x48e154 IcmpCreateFile
0x48e158 IcmpCloseHandle
0x48e15c IcmpSendEcho
Library USERENV.dll:
0x48e750 UnloadUserProfile
0x48e75c LoadUserProfileW
Library UxTheme.dll:
0x48e764 IsThemeActive
Library KERNEL32.dll:
0x48e164 DuplicateHandle
0x48e168 CreateThread
0x48e16c WaitForSingleObject
0x48e170 HeapAlloc
0x48e174 GetProcessHeap
0x48e178 HeapFree
0x48e17c Sleep
0x48e180 GetCurrentThreadId
0x48e184 MultiByteToWideChar
0x48e188 MulDiv
0x48e18c GetVersionExW
0x48e190 IsWow64Process
0x48e194 GetSystemInfo
0x48e198 FreeLibrary
0x48e19c LoadLibraryA
0x48e1a0 GetProcAddress
0x48e1a4 SetErrorMode
0x48e1a8 GetModuleFileNameW
0x48e1ac WideCharToMultiByte
0x48e1b0 lstrcpyW
0x48e1b4 lstrlenW
0x48e1b8 GetModuleHandleW
0x48e1c0 VirtualFreeEx
0x48e1c4 OpenProcess
0x48e1c8 VirtualAllocEx
0x48e1cc WriteProcessMemory
0x48e1d0 ReadProcessMemory
0x48e1d4 CreateFileW
0x48e1d8 SetFilePointerEx
0x48e1dc SetEndOfFile
0x48e1e0 ReadFile
0x48e1e4 WriteFile
0x48e1e8 FlushFileBuffers
0x48e1ec TerminateProcess
0x48e1f4 Process32FirstW
0x48e1f8 Process32NextW
0x48e1fc SetFileTime
0x48e200 GetFileAttributesW
0x48e204 FindFirstFileW
0x48e20c GetLongPathNameW
0x48e210 GetShortPathNameW
0x48e214 DeleteFileW
0x48e218 FindNextFileW
0x48e21c CopyFileExW
0x48e220 MoveFileW
0x48e224 CreateDirectoryW
0x48e228 RemoveDirectoryW
0x48e22c SetSystemPowerState
0x48e234 FindResourceW
0x48e238 LoadResource
0x48e23c LockResource
0x48e240 SizeofResource
0x48e244 EnumResourceNamesW
0x48e248 OutputDebugStringW
0x48e24c GetTempPathW
0x48e250 GetTempFileNameW
0x48e254 DeviceIoControl
0x48e258 GetLocalTime
0x48e25c CompareStringW
0x48e260 GetCurrentProcess
0x48e26c GetStdHandle
0x48e270 CreatePipe
0x48e274 InterlockedExchange
0x48e278 TerminateThread
0x48e27c LoadLibraryExW
0x48e280 FindResourceExW
0x48e284 CopyFileW
0x48e288 VirtualFree
0x48e28c FormatMessageW
0x48e290 GetExitCodeProcess
0x48e2b8 GetDriveTypeW
0x48e2bc GetDiskFreeSpaceExW
0x48e2c0 GetDiskFreeSpaceW
0x48e2c8 SetVolumeLabelW
0x48e2cc CreateHardLinkW
0x48e2d0 SetFileAttributesW
0x48e2d4 CreateEventW
0x48e2d8 SetEvent
0x48e2e4 GlobalLock
0x48e2e8 GlobalUnlock
0x48e2ec GlobalAlloc
0x48e2f0 GetFileSize
0x48e2f4 GlobalFree
0x48e2fc Beep
0x48e300 GetSystemDirectoryW
0x48e304 HeapReAlloc
0x48e308 HeapSize
0x48e30c GetComputerNameW
0x48e314 GetCurrentProcessId
0x48e31c CreateProcessW
0x48e320 GetProcessId
0x48e324 SetPriorityClass
0x48e328 LoadLibraryW
0x48e32c VirtualAlloc
0x48e330 IsDebuggerPresent
0x48e338 lstrcmpiW
0x48e33c DecodePointer
0x48e340 GetLastError
0x48e344 RaiseException
0x48e358 GetCurrentThread
0x48e35c CloseHandle
0x48e360 GetFullPathNameW
0x48e364 EncodePointer
0x48e368 ExitProcess
0x48e36c GetModuleHandleExW
0x48e370 ExitThread
0x48e378 ResumeThread
0x48e37c GetCommandLineW
0x48e384 IsValidCodePage
0x48e388 GetACP
0x48e38c GetOEMCP
0x48e390 GetCPInfo
0x48e394 SetLastError
0x48e3a0 TlsAlloc
0x48e3a4 TlsGetValue
0x48e3a8 TlsSetValue
0x48e3ac TlsFree
0x48e3b0 GetStartupInfoW
0x48e3b4 GetStringTypeW
0x48e3b8 SetStdHandle
0x48e3bc GetFileType
0x48e3c0 GetConsoleCP
0x48e3c4 GetConsoleMode
0x48e3c8 RtlUnwind
0x48e3cc ReadConsoleW
0x48e3d4 GetDateFormatW
0x48e3d8 GetTimeFormatW
0x48e3dc LCMapStringW
0x48e3e8 WriteConsoleW
0x48e3ec FindClose
Library USER32.dll:
0x48e4cc AdjustWindowRectEx
0x48e4d0 CopyImage
0x48e4d4 SetWindowPos
0x48e4d8 GetCursorInfo
0x48e4dc RegisterHotKey
0x48e4e0 ClientToScreen
0x48e4e8 IsCharAlphaW
0x48e4ec IsCharAlphaNumericW
0x48e4f0 IsCharLowerW
0x48e4f4 IsCharUpperW
0x48e4f8 GetMenuStringW
0x48e4fc GetSubMenu
0x48e500 GetCaretPos
0x48e504 IsZoomed
0x48e508 MonitorFromPoint
0x48e50c GetMonitorInfoW
0x48e510 SetWindowLongW
0x48e518 FlashWindow
0x48e51c GetClassLongW
0x48e524 IsDialogMessageW
0x48e528 GetSysColor
0x48e52c InflateRect
0x48e530 DrawFocusRect
0x48e534 DrawTextW
0x48e538 FrameRect
0x48e53c DrawFrameControl
0x48e540 FillRect
0x48e544 PtInRect
0x48e550 SetCursor
0x48e554 GetWindowDC
0x48e558 GetSystemMetrics
0x48e55c GetActiveWindow
0x48e560 CharNextW
0x48e564 wsprintfW
0x48e568 RedrawWindow
0x48e56c DrawMenuBar
0x48e570 DestroyMenu
0x48e574 SetMenu
0x48e57c CreateMenu
0x48e580 IsDlgButtonChecked
0x48e584 DefDlgProcW
0x48e588 CallWindowProcW
0x48e58c ReleaseCapture
0x48e590 SetCapture
0x48e598 mouse_event
0x48e59c ExitWindowsEx
0x48e5a0 SetActiveWindow
0x48e5a4 FindWindowExW
0x48e5a8 EnumThreadWindows
0x48e5ac SetMenuDefaultItem
0x48e5b0 InsertMenuItemW
0x48e5b4 IsMenu
0x48e5b8 TrackPopupMenuEx
0x48e5bc GetCursorPos
0x48e5c0 DeleteMenu
0x48e5c4 SetRect
0x48e5c8 GetMenuItemID
0x48e5cc GetMenuItemCount
0x48e5d0 SetMenuItemInfoW
0x48e5d4 GetMenuItemInfoW
0x48e5d8 SetForegroundWindow
0x48e5dc IsIconic
0x48e5e0 FindWindowW
0x48e5e4 MonitorFromRect
0x48e5e8 keybd_event
0x48e5ec SendInput
0x48e5f0 GetAsyncKeyState
0x48e5f4 SetKeyboardState
0x48e5f8 GetKeyboardState
0x48e5fc GetKeyState
0x48e600 VkKeyScanW
0x48e604 LoadStringW
0x48e608 DialogBoxParamW
0x48e60c MessageBeep
0x48e610 EndDialog
0x48e614 SendDlgItemMessageW
0x48e618 GetDlgItem
0x48e61c SetWindowTextW
0x48e620 CopyRect
0x48e624 ReleaseDC
0x48e628 GetDC
0x48e62c EndPaint
0x48e630 BeginPaint
0x48e634 GetClientRect
0x48e638 GetMenu
0x48e63c DestroyWindow
0x48e640 EnumWindows
0x48e644 GetDesktopWindow
0x48e648 IsWindow
0x48e64c IsWindowEnabled
0x48e650 IsWindowVisible
0x48e654 EnableWindow
0x48e658 InvalidateRect
0x48e65c GetWindowLongW
0x48e664 AttachThreadInput
0x48e668 GetFocus
0x48e66c GetWindowTextW
0x48e670 ScreenToClient
0x48e674 SendMessageTimeoutW
0x48e678 EnumChildWindows
0x48e67c CharUpperBuffW
0x48e680 GetParent
0x48e684 GetDlgCtrlID
0x48e688 SendMessageW
0x48e68c MapVirtualKeyW
0x48e690 PostMessageW
0x48e694 GetWindowRect
0x48e69c CloseDesktop
0x48e6a0 CloseWindowStation
0x48e6a4 OpenDesktopW
0x48e6b0 OpenWindowStationW
0x48e6b8 MessageBoxW
0x48e6bc DefWindowProcW
0x48e6c0 SetClipboardData
0x48e6c4 EmptyClipboard
0x48e6cc CloseClipboard
0x48e6d0 GetClipboardData
0x48e6d8 OpenClipboard
0x48e6dc BlockInput
0x48e6e0 GetMessageW
0x48e6e4 LockWindowUpdate
0x48e6e8 DispatchMessageW
0x48e6ec TranslateMessage
0x48e6f0 PeekMessageW
0x48e6f4 UnregisterHotKey
0x48e6f8 CheckMenuRadioItem
0x48e6fc CharLowerBuffW
0x48e700 MoveWindow
0x48e704 SetFocus
0x48e708 PostQuitMessage
0x48e70c KillTimer
0x48e710 CreatePopupMenu
0x48e718 SetTimer
0x48e71c ShowWindow
0x48e720 CreateWindowExW
0x48e724 RegisterClassExW
0x48e728 LoadIconW
0x48e72c LoadCursorW
0x48e730 GetSysColorBrush
0x48e734 GetForegroundWindow
0x48e738 MessageBoxA
0x48e73c DestroyIcon
0x48e744 LoadImageW
0x48e748 GetClassNameW
Library GDI32.dll:
0x48e0c4 StrokePath
0x48e0c8 DeleteObject
0x48e0d0 ExtCreatePen
0x48e0d4 GetDeviceCaps
0x48e0d8 EndPath
0x48e0dc SetPixel
0x48e0e0 CloseFigure
0x48e0e8 CreateCompatibleDC
0x48e0ec SelectObject
0x48e0f0 StretchBlt
0x48e0f4 GetDIBits
0x48e0f8 LineTo
0x48e0fc AngleArc
0x48e100 MoveToEx
0x48e104 Ellipse
0x48e108 DeleteDC
0x48e10c GetPixel
0x48e110 CreateDCW
0x48e114 GetStockObject
0x48e118 GetTextFaceW
0x48e11c CreateFontW
0x48e120 SetTextColor
0x48e124 PolyDraw
0x48e128 BeginPath
0x48e12c Rectangle
0x48e130 SetViewportOrgEx
0x48e134 GetObjectW
0x48e138 SetBkMode
0x48e13c RoundRect
0x48e140 SetBkColor
0x48e144 CreatePen
0x48e148 CreateSolidBrush
0x48e14c StrokeAndFillPath
Library COMDLG32.dll:
0x48e0b8 GetOpenFileNameW
0x48e0bc GetSaveFileNameW
Library ADVAPI32.dll:
0x48e000 GetAce
0x48e004 RegEnumValueW
0x48e008 RegDeleteValueW
0x48e00c RegDeleteKeyW
0x48e010 RegEnumKeyExW
0x48e014 RegSetValueExW
0x48e018 RegOpenKeyExW
0x48e01c RegCloseKey
0x48e020 RegQueryValueExW
0x48e024 RegConnectRegistryW
0x48e02c InitializeAcl
0x48e034 OpenThreadToken
0x48e038 OpenProcessToken
0x48e040 DuplicateTokenEx
0x48e04c GetLengthSid
0x48e050 CopySid
0x48e054 LogonUserW
0x48e060 RegCreateKeyExW
0x48e064 FreeSid
0x48e068 GetTokenInformation
0x48e070 GetAclInformation
0x48e074 AddAce
0x48e07c GetUserNameW
Library SHELL32.dll:
0x48e48c DragQueryPoint
0x48e490 ShellExecuteExW
0x48e494 DragQueryFileW
0x48e498 SHEmptyRecycleBinW
0x48e4a0 SHBrowseForFolderW
0x48e4a4 SHCreateShellItem
0x48e4a8 SHGetDesktopFolder
0x48e4b0 SHGetFolderPathW
0x48e4b4 SHFileOperationW
0x48e4b8 ExtractIconExW
0x48e4bc Shell_NotifyIconW
0x48e4c0 ShellExecuteW
0x48e4c4 DragFinish
Library ole32.dll:
0x48e828 CoTaskMemAlloc
0x48e82c CoTaskMemFree
0x48e830 CLSIDFromString
0x48e834 ProgIDFromCLSID
0x48e838 CLSIDFromProgID
0x48e840 MkParseDisplayName
0x48e848 CoCreateInstance
0x48e84c IIDFromString
0x48e850 StringFromGUID2
0x48e858 CoInitialize
0x48e85c CoUninitialize
0x48e868 CoGetObject
0x48e870 CoCreateInstanceEx
0x48e874 CoSetProxyBlanket
Library OLEAUT32.dll:
0x48e40c LoadTypeLibEx
0x48e410 VariantCopyInd
0x48e414 SysReAllocString
0x48e418 SysFreeString
0x48e428 SafeArrayAccessData
0x48e42c SafeArrayAllocData
0x48e438 RegisterTypeLib
0x48e43c CreateStdDispatch
0x48e440 DispCallFunc
0x48e444 VariantChangeType
0x48e448 SysStringLen
0x48e450 VarR8FromDec
0x48e454 SafeArrayGetVartype
0x48e458 VariantCopy
0x48e45c VariantClear
0x48e460 OleLoadPicture
0x48e470 UnRegisterTypeLib
0x48e474 CreateDispTypeInfo
0x48e478 SysAllocString
0x48e47c VariantInit

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
It2It:II
t$8]4t
9^Xt=9^\tE
WWjdh,
PWWWWh
t4j"Yf;
L$$9N@
<SVWj,
j\_f98
8F0ti!E
Yj?Yj0Z
j9Zj._f9<A
r%j9Yf;
<{=tfjB
|$pAU3!
?#tRf9t
f98t?j
t+HuA9
Ht;Ht.H
Ht7HtPHt
D$@TCL
D$hTCL
D$<TCL
D$hTCL
D$@;D$Dr
9D$tu;
9t$tv3
F;t$tr
jNYf9H
9t$(v-
F;t$(r
D$$PVj
D$(PVj
09L$ v"
Ht)Ht&H
L$X;|$8
D$0FVP
D$(;D$8
 !"#$
 !"#$%%%%%%&&'()*+%%%%%%&&'()*+,,,,,,--./012RRRRRRRRRRRR3345566789::::;<=<=>?>@ABC>@ABCRRRRRDEFGHIJKLMNO
~:9~4~)
^$9^,u
D$49G@
\$ j|Zf9
L$LjxXf
YYj!Yf;
`~EjaX;
<SVWjw
+t\HHtT
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
9E v\PWj
9u(v?VSj
YYHtIHt8
HHtPHHt-H
HthHt3
th$"L
~pjCXf
VWh`#I
uHjAXf;
uWjAXf;
htHjlZ;
HHtXHHt
nt'joZ;
YYjgXf9
>0t<NAj0X
PVVVVQ
+tIIt
-t*j0X;
+t"HHt
j@j _W
HHtVHHt
PP9E u
URPQQh
f- 8f=
f-00f=
f-00f=
tfHtWHtHHt/
SSPQSW
tx8tt
?:uBGW
} kE$<
jA[jZZ+
QQSVWh
j"_f9y
PWWWWV
PSSSSV
~';_t|%3
,SVWj0X
Wj0XPV
Ht+Ht$Ht
HtHHt
tHHt*Ht#
;t$,v-
UQPXY]Y[
+tHHt
+t"HHt
HAO8t
bWWWWj
7t;Ht5Ht"H
QPQWVS
QPQWVS
QPQWVS
QPQWVS
t4HHt
t5j'Zf;
|$tEA06
L$ hPRK
D$L;D$8
f98t#V
t2Ht%H
HHt?HHu7
~Ej Yj.Z
Yj Yj.Z;
Hu@IyG
t$L9D$
D$8QVP
L$0FVQ
\$d@SP
QQQQQ3
t0;V|r+
;F|s$f
t-;V|r(
;N|s!f
t-;V|r(
;N|s!f
B9A vL
B9A vL
E(GC;x0
FP;~L~
AP;yL~
t;;J s%
'taj0Zj9X
r9j7Yf;
j$Xj(f
Mj$Xj(f
&j$Xj(f
Cj$Xj(f
f;H,sB
t$j\Xf9
\SVWQQ
SSh0GK
PPShbyE
QQSVWh
u5SVh+
j#_f98u
t1j;Yf;
t)j]Yf;
D$ +D$
D$$+D$
uDh8IK
u,hPIK
Q,8^=u
^<9^4t
^,9^0t
^09^(t
f;D$tu
f;D$@u
f;D$Hu
|$\9T$D}
f;D$tu
~f;D$@ulIyt
|$`[9D$
8f;D$Hu
#D$,SP
f91t,SWj,[j.
T$8Y9D$(
t$8f9D$$ue
t$4QVPR
D$<;D$(
|$jZ;
8jXf;
j|Zj f
j;Zj f
j XAf9
Oj;_f;
~%j;[f9
j;_f9;j
t$j'Zf;
SVWj ^j
4Bj"Yf;
<"t|<%tx<'tt<$tp<&tl<!th<otd<]t`<[t\<\tX<
tP<_tL<
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
G'QSPh
G(QSPh
G$QSPj
G%QSPj
G)QSPj[
DSVWj,3
j.^f90u
PSSSSSSh
tEh@VK
t4hPVK
f9t$Ht
YSPVWj
j0Xjxf
PPPPVWPP
QQSPVWQQ
D$,Yu)
JtsJJt8
HHt%Ht
Ht]Ht#j
u+Sj)^j
FLjDWP
;GLujDj$X+
PWWWWW
WWWWWh
WWWWPh
HHt@Ht3Ht&Ht
D$ SSP
T$$Rh,
T$PSRP
T$PSRP
T$PSRP
D$0SSP
|$ f94_uA@
t@Ht'Ht
t7Ht"Ht
Nt,NNt
tfHtYHt8Ht,Ht
HtQHtL
QQSVW3
BtFHHt>
t8HHt0
HtIHtAHuFj
smWh\|K
D$<PSW
u&VVWSh
VVVh(|K
t4PhL'
@9D$ v=
t$0;t$$t"F
GWhp~K
Gt.Ht$
jNZf9P
tKHt:HuQ
@uIBj3
jNYf9J
j3Zf9P
jGXf9A
D$,PSR
RtUHt5Ht"Ht
YjNf9H
jNXf9A
jGXf9A
RtKHt/Ht
+jHXf;
j%YFf;
j$Yj@FZf;
X+D$8P
9u 8]
j;YFf9
D$ ;D$
t/Ht%Ht
SVWjD^V3
D$tPVj
L$(VQV
9t$<t0
L$ VQV
t$ PV3
t$ PV3
j\^f90uJj
f90u;j
HthHtSHt?H
HtEHt#Ht
L$,SWPV
D$$WPV
D$$WPV
D$$WPV
QQQQPVh
L$PQVh2
L$PQVh9
t$H+t$@
D$LF+D$Dj
L$<+L$
D$,+D$$
\$,WSPV
D$$SPV
D$$SPV
D$$SPV
\$(+\$
|$,+|$$
QQSVWj$
F;5T8L
f9t^SQ
#M,@PQ
f91t%QV
4SVWj,
8SVWj,3
QQQQQP
SSSSPSh(
tCHt8HuO
tDf91t?
@PPj!j
u<@PPj!j
uS9q4uN
Wj!j j
Ht^HtIHt6
D$TPVhL
HHtLHt*H
HHt,Ht,
D$0VPS
D$0VPS
*;5p8L
_9=T8L
G;=T8L
)GHjG3
PPj PPP
T$L;t$
D$\PWV
;|$<}+
+G<+W@
D$TPVh>
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$@PVh
D$|PVhK
D$(PVh
D$TPVh>
D$0Ft>
uLPPRj
w,9G0~X
tXj]Zf
jHX_^[
SVWj0Zf;
rEj9_f;
r;j9[f;
r0j9[f;
GetNativeSystemInfo
kernel32.dll
[:>:]]
[:<:]]
bad allocation
CorExitProcess
RoInitialize
RoUninitialize
Unknown exception
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
_hypot
_nextafter
(null)
`h````
xpxxxx
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
<8bunz8
l,kg<i
<@En[vP
?Dj0Q:W$=
5s3R6=
RUUUUU
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
?UUUUUU
|u?!u$
Nu?-HF
d? cf>
&2@UUUUUU
UUUUUU
#wi#:=
&2@UUUUUU
Nu?-HF
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
`h`hhh
xppwpp
CreateFile2
i^^?(>
Y:/(A6>
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
1#SNAN
1#QNAN
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
pqrstuvwxyz{$--%"!'
`abcdefghijkmno]
 !"#$%&'()))*+,-./0123456789:;<=>?@ABBCDEFGHIGJKLLBMBBNOPQRSTUVWXYZ[\]^G___________________________________________________`___________________________________________________________________________________________________________________________________________________________________abccccccccdeefghijklmnopqrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstuvwxrstyzzzzzzzzzzzzzzzz{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{__|}~
OOOOOO
OOOOOOOOO
OOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOG
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOO_____________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________
________________________________
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO____
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
This is a third-party compiled AutoIt script.
DllGetClassObject
Qkkbal
xdigit
ACCEPT
COMMIT
no error
\ at end of pattern
\c at end of pattern
unrecognized character follows \
numbers out of order in {} quantifier
number too big in {} quantifier
missing terminating ] for character class
invalid escape sequence in character class
range out of order in character class
nothing to repeat
operand of unlimited repeat could match the empty string
internal error: unexpected repeat
unrecognized character after (? or (?-
POSIX named classes are supported only within a class
missing )
reference to non-existent subpattern
erroffset passed as NULL
unknown option bit(s) set
missing ) after comment
parentheses nested too deeply
regular expression is too large
failed to get memory
unmatched parentheses
internal error: code overflow
unrecognized character after (?<
lookbehind assertion is not fixed length
malformed number or name after (?(
conditional group contains more than two branches
assertion expected after (?(
(?R or (?[+-]digits must be followed by )
unknown POSIX class name
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
spare error
character value in \x{} or \o{} is too large
invalid condition (?(0)
\C not allowed in lookbehind assertion
PCRE does not support \L, \l, \N{name}, \U, or \u
number after (?C is > 255
closing ) for (?C expected
recursive call could loop indefinitely
unrecognized character after (?P
syntax error in subpattern name (missing terminator)
two named subpatterns have the same name
invalid UTF-8 string
support for \P, \p, and \X has not been compiled
malformed \P or \p sequence
unknown property name after \P or \p
subpattern name is too long (maximum 32 characters)
too many named subpatterns (maximum 10000)
repeated subpattern is too long
octal value is greater than \377 in 8-bit non-UTF-8 mode
internal error: overran compiling workspace
internal error: previously-checked referenced subpattern not found
DEFINE group contains more than one branch
repeating a DEFINE group is not allowed
inconsistent NEWLINE options
\g is not followed by a braced, angle-bracketed, or quoted name/number or by a plain number
a numbered reference must not be zero
an argument is not allowed for (*ACCEPT), (*FAIL), or (*COMMIT)
(*VERB) not recognized or malformed
number is too big
subpattern name expected
digit expected after (?+
] is an invalid data character in JavaScript compatibility mode
different names for subpatterns of the same number are not allowed
(*MARK) must have an argument
this version of PCRE is not compiled with Unicode property support
\c must be followed by an ASCII character
\k is not followed by a braced, angle-bracketed, or quoted name
internal error: unknown opcode in find_fixedlength()
\N is not supported in a class
too many forward references
disallowed Unicode code point (>= 0xd800 && <= 0xdfff)
invalid UTF-16 string
name is too long in (*MARK), (*PRUNE), (*SKIP), or (*THEN)
character value in \u.... sequence is too large
invalid UTF-32 string
setting UTF is disabled by the application
non-hex character in \x{} (closing brace missing?)
non-octal character in \o{} (closing brace missing?)
missing opening brace after \o
parentheses are too deeply nested
invalid range in character class
group name must start with a non-digit
Arabic
Armenian
Avestan
Balinese
Bengali
Bopomofo
Brahmi
Braille
Buginese
Canadian_Aboriginal
Carian
Chakma
Cherokee
Common
Coptic
Cuneiform
Cypriot
Cyrillic
Deseret
Devanagari
Egyptian_Hieroglyphs
Ethiopic
Georgian
Glagolitic
Gothic
Gujarati
Gurmukhi
Hangul
Hanunoo
Hebrew
Hiragana
Imperial_Aramaic
Inherited
Inscriptional_Pahlavi
Inscriptional_Parthian
Javanese
Kaithi
Kannada
Katakana
Kayah_Li
Kharoshthi
Lepcha
Linear_B
Lycian
Lydian
Malayalam
Mandaic
Meetei_Mayek
Meroitic_Cursive
Meroitic_Hieroglyphs
Mongolian
Myanmar
New_Tai_Lue
Ol_Chiki
Old_Italic
Old_Persian
Old_South_Arabian
Old_Turkic
Osmanya
Phags_Pa
Phoenician
Rejang
Samaritan
Saurashtra
Sharada
Shavian
Sinhala
Sora_Sompeng
Sundanese
Syloti_Nagri
Syriac
Tagalog
Tagbanwa
Tai_Le
Tai_Tham
Tai_Viet
Telugu
Thaana
Tibetan
Tifinagh
Ugaritic
GetModuleHandleExW
GetSystemWow64DirectoryW
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
DEFINE
UTF16)
NO_AUTO_POSSESS)
NO_START_OPT)
LIMIT_MATCH=
LIMIT_RECURSION=
ANYCRLF)
BSR_ANYCRLF)
BSR_UNICODE)
WSOCK32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
timeGetTime
mciSendStringW
waveOutSetVolume
WINMM.dll
InitCommonControlsEx
ImageList_Create
ImageList_ReplaceIcon
ImageList_Destroy
ImageList_Remove
ImageList_SetDragCursorImage
ImageList_BeginDrag
ImageList_DragEnter
ImageList_DragLeave
ImageList_EndDrag
ImageList_DragMove
COMCTL32.dll
WNetAddConnection2W
WNetUseConnectionW
WNetCancelConnection2W
WNetGetConnectionW
MPR.dll
InternetCloseHandle
InternetOpenW
InternetSetOptionW
InternetCrackUrlW
HttpQueryInfoW
InternetQueryOptionW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
InternetReadFile
InternetQueryDataAvailable
WININET.dll
GetProcessMemoryInfo
PSAPI.DLL
IcmpCreateFile
IcmpSendEcho
IcmpCloseHandle
IPHLPAPI.DLL
LoadUserProfileW
CreateEnvironmentBlock
UnloadUserProfile
DestroyEnvironmentBlock
USERENV.dll
IsThemeActive
UxTheme.dll
InterlockedIncrement
InterlockedDecrement
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
RaiseException
GetLastError
DecodePointer
lstrcmpiW
GetCurrentDirectoryW
IsDebuggerPresent
SetCurrentDirectoryW
GetFullPathNameW
CloseHandle
GetCurrentThread
GetCurrentProcess
DuplicateHandle
CreateThread
WaitForSingleObject
HeapAlloc
GetProcessHeap
HeapFree
GetCurrentThreadId
MultiByteToWideChar
MulDiv
GetVersionExW
IsWow64Process
GetSystemInfo
FreeLibrary
LoadLibraryA
GetProcAddress
SetErrorMode
GetModuleFileNameW
WideCharToMultiByte
lstrcpyW
lstrlenW
GetModuleHandleW
QueryPerformanceCounter
VirtualFreeEx
OpenProcess
VirtualAllocEx
WriteProcessMemory
ReadProcessMemory
CreateFileW
SetFilePointerEx
SetEndOfFile
ReadFile
WriteFile
FlushFileBuffers
TerminateProcess
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
SetFileTime
GetFileAttributesW
FindFirstFileW
FindClose
GetLongPathNameW
GetShortPathNameW
DeleteFileW
FindNextFileW
CopyFileExW
MoveFileW
CreateDirectoryW
RemoveDirectoryW
SetSystemPowerState
QueryPerformanceFrequency
FindResourceW
LoadResource
LockResource
SizeofResource
EnumResourceNamesW
OutputDebugStringW
GetTempPathW
GetTempFileNameW
DeviceIoControl
GetLocalTime
CompareStringW
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
CreatePipe
InterlockedExchange
TerminateThread
LoadLibraryExW
FindResourceExW
CopyFileW
VirtualFree
FormatMessageW
GetExitCodeProcess
GetPrivateProfileStringW
WritePrivateProfileStringW
GetPrivateProfileSectionW
WritePrivateProfileSectionW
GetPrivateProfileSectionNamesW
FileTimeToLocalFileTime
FileTimeToSystemTime
SystemTimeToFileTime
LocalFileTimeToFileTime
GetDriveTypeW
GetDiskFreeSpaceExW
GetDiskFreeSpaceW
GetVolumeInformationW
SetVolumeLabelW
CreateHardLinkW
SetFileAttributesW
CreateEventW
SetEvent
GetEnvironmentVariableW
SetEnvironmentVariableW
GlobalLock
GlobalUnlock
GlobalAlloc
GetFileSize
GlobalFree
GlobalMemoryStatusEx
GetSystemDirectoryW
HeapReAlloc
HeapSize
GetComputerNameW
GetWindowsDirectoryW
GetCurrentProcessId
GetProcessIoCounters
CreateProcessW
GetProcessId
SetPriorityClass
LoadLibraryW
VirtualAlloc
KERNEL32.dll
DestroyIcon
MessageBoxA
GetForegroundWindow
GetSysColorBrush
LoadCursorW
LoadIconW
RegisterClassExW
CreateWindowExW
ShowWindow
SetTimer
RegisterWindowMessageW
CreatePopupMenu
KillTimer
PostQuitMessage
SetFocus
MoveWindow
DefWindowProcW
MessageBoxW
GetUserObjectSecurity
OpenWindowStationW
GetProcessWindowStation
SetProcessWindowStation
OpenDesktopW
CloseWindowStation
CloseDesktop
SetUserObjectSecurity
GetWindowRect
PostMessageW
MapVirtualKeyW
SendMessageW
GetDlgCtrlID
GetParent
GetClassNameW
CharUpperBuffW
EnumChildWindows
SendMessageTimeoutW
ScreenToClient
GetWindowTextW
GetFocus
AttachThreadInput
GetWindowThreadProcessId
GetWindowLongW
InvalidateRect
EnableWindow
IsWindowVisible
IsWindowEnabled
IsWindow
GetDesktopWindow
EnumWindows
DestroyWindow
GetMenu
GetClientRect
BeginPaint
EndPaint
ReleaseDC
CopyRect
SetWindowTextW
GetDlgItem
SendDlgItemMessageW
EndDialog
MessageBeep
DialogBoxParamW
LoadStringW
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
SendInput
keybd_event
SystemParametersInfoW
FindWindowW
IsIconic
SetForegroundWindow
GetMenuItemInfoW
SetMenuItemInfoW
GetMenuItemCount
GetMenuItemID
CheckMenuRadioItem
DeleteMenu
GetCursorPos
TrackPopupMenuEx
IsMenu
InsertMenuItemW
SetMenuDefaultItem
EnumThreadWindows
FindWindowExW
SetActiveWindow
ExitWindowsEx
mouse_event
CreateIconFromResourceEx
LoadImageW
MonitorFromRect
CharLowerBuffW
UnregisterHotKey
PeekMessageW
TranslateMessage
DispatchMessageW
LockWindowUpdate
GetMessageW
BlockInput
OpenClipboard
IsClipboardFormatAvailable
GetClipboardData
CloseClipboard
CountClipboardFormats
EmptyClipboard
SetClipboardData
SetRect
AdjustWindowRectEx
CopyImage
SetWindowPos
GetCursorInfo
RegisterHotKey
ClientToScreen
GetKeyboardLayoutNameW
IsCharAlphaW
IsCharAlphaNumericW
IsCharLowerW
IsCharUpperW
GetMenuStringW
GetSubMenu
GetCaretPos
IsZoomed
MonitorFromPoint
GetMonitorInfoW
SetWindowLongW
SetLayeredWindowAttributes
FlashWindow
GetClassLongW
TranslateAcceleratorW
IsDialogMessageW
GetSysColor
InflateRect
DrawFocusRect
DrawTextW
FrameRect
DrawFrameControl
FillRect
PtInRect
DestroyAcceleratorTable
CreateAcceleratorTableW
SetCursor
GetWindowDC
GetSystemMetrics
GetActiveWindow
CharNextW
wsprintfW
RedrawWindow
DrawMenuBar
DestroyMenu
SetMenu
GetWindowTextLengthW
CreateMenu
IsDlgButtonChecked
DefDlgProcW
CallWindowProcW
ReleaseCapture
SetCapture
USER32.dll
GetDeviceCaps
DeleteObject
GetTextExtentPoint32W
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
StretchBlt
GetDIBits
DeleteDC
GetPixel
CreateDCW
GetStockObject
GetTextFaceW
CreateFontW
SetTextColor
CreateSolidBrush
CreatePen
SetBkColor
RoundRect
SetBkMode
GetObjectW
SetViewportOrgEx
Rectangle
BeginPath
PolyDraw
Ellipse
MoveToEx
AngleArc
LineTo
CloseFigure
SetPixel
EndPath
StrokePath
StrokeAndFillPath
ExtCreatePen
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
RegConnectRegistryW
InitializeSecurityDescriptor
InitializeAcl
AdjustTokenPrivileges
OpenThreadToken
OpenProcessToken
LookupPrivilegeValueW
DuplicateTokenEx
CreateProcessAsUserW
CreateProcessWithLogonW
GetLengthSid
CopySid
LogonUserW
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
GetTokenInformation
GetSecurityDescriptorDacl
GetAclInformation
GetAce
AddAce
SetSecurityDescriptorDacl
InitiateSystemShutdownExW
GetUserNameW
RegCreateKeyExW
RegSetValueExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumValueW
ADVAPI32.dll
ShellExecuteW
Shell_NotifyIconW
ExtractIconExW
SHFileOperationW
SHGetFolderPathW
SHGetSpecialFolderLocation
SHGetDesktopFolder
SHCreateShellItem
SHBrowseForFolderW
SHGetPathFromIDListW
SHEmptyRecycleBinW
DragQueryFileW
ShellExecuteExW
DragQueryPoint
DragFinish
SHELL32.dll
CoTaskMemAlloc
CoTaskMemFree
CLSIDFromString
ProgIDFromCLSID
CLSIDFromProgID
OleSetMenuDescriptor
MkParseDisplayName
OleSetContainedObject
CoCreateInstance
IIDFromString
StringFromGUID2
CreateStreamOnHGlobal
CoInitialize
CoUninitialize
GetRunningObjectTable
CoGetInstanceFromFile
CoGetObject
CoInitializeSecurity
CoCreateInstanceEx
CoSetProxyBlanket
ole32.dll
OLEAUT32.dll
EncodePointer
ExitProcess
GetModuleHandleExW
ExitThread
GetSystemTimeAsFileTime
ResumeThread
GetCommandLineW
IsProcessorFeaturePresent
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetStringTypeW
SetStdHandle
GetFileType
GetConsoleCP
GetConsoleMode
RtlUnwind
ReadConsoleW
GetTimeZoneInformation
GetDateFormatW
GetTimeFormatW
LCMapStringW
GetEnvironmentStringsW
FreeEnvironmentStringsW
WriteConsoleW
SetEnvironmentVariableA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AU3!@I
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
y]#n_}
PSU!*aB
)0cJ->
"?9r|+cL
-mM2)q
L"U+PsF
c0(3Au>
e@wE e
lk3[.e
l;xt+ch
uUfIT.v
IDATnp
CPp.%*K
O7,.Aly
%=8I"/=
=c:*+*|I
Ytr6+7
_2b4>
3i&0fM
M)U#@p
k'U@?Y
VWe)'Z
Zz9Z/g
y.(,M.
}&UUUX
GH3aE{9
K<V6b]P
R]EiFs
_inzLX
*2?9mX
p`0-^0
-2pHI[
XVyf+H
%1N07"
X=n;bN
K^cJ_B
'q^`g]
<D!u$R
y.@cO:
IDATh)
RJ8RBV*
MH?0MH?
MH?0MH?
MH?0MH?
MH?0MH?
MH? MH?
@<50@<5
@<50@<5
@<50@<5
@<50@<5
@<50@<5
@<50@<5
@<50@<5
@<50@<5
MH? MH?pMH?
30*p30*
MH? MH?pMH?
MH? MH?pMH?
MH?PMH?
@<5P@<5
@<5P@<5
@<5P@<5
@<5P@<5
@<5P@<5
@<5P@<5
MH? MH?pB>6
30*p30*
MH? MH?phd]
MH? MH?phd]
MH? hd]
nh_p@<5
@<5PMIB
@<5P@<5
@<5P@<5
@<5P@<5
qZ'PnW&
MH? MH?pvrk
30*p30*
MH? MH?pvrk
@<5P@<5
@<5P@<5
@<5PFB;
MH? fbZp
MH? fbZp
@<5`QG5
@<5`QG5
qZ(pmV%
@<5PSH6
@<5PSH5
H}AU3!EA06M
'7r"Uhh
I@s~-^
Y5>f0p
?}%(#FI
$xl*{vm{"
AU3!EA06PAGlobal Const $tagPOINT = "struct;long X;long Y;endstruct"
Global Const $tagRECT = "struct;long Left;long Top;long Right;long Bottom;endstruct"
Global Const $tagREBARBANDINFO = "uint cbSize;uint fMask;uint fStyle;dword clrFore;dword clrBack;ptr lpText;uint cch;" & "int iImage;hwnd hwndChild;uint cxMinChild;uint cyMinChild;uint cx;handle hbmBack;uint wID;uint cyChild;uint cyMaxChild;" & "uint cyIntegral;uint cxIdeal;lparam lParam;uint cxHeader" &((@OSVersion = "WIN_XP") ? "" : ";" & $tagRECT & ";uint uChevronState")
Global Const $HGDI_ERROR = Ptr(-1)
Global Const $INVALID_HANDLE_VALUE = Ptr(-1)
Global Const $KF_EXTENDED = 0x0100
Global Const $KF_ALTDOWN = 0x2000
Global Const $KF_UP = 0x8000
Global Const $LLKHF_EXTENDED = BitShift($KF_EXTENDED, 8)
Global Const $LLKHF_ALTDOWN = BitShift($KF_ALTDOWN, 8)
Global Const $LLKHF_UP = BitShift($KF_UP, 8)
Global Const $tagOSVERSIONINFO = 'struct;dword OSVersionInfoSize;dword MajorVersion;dword MinorVersion;dword BuildNumber;dword PlatformId;wchar CSDVersion[128];endstruct'
Global Const $__WINVER = __WINVER()
Func __WINVER()
Local $tOSVI = DllStructCreate($tagOSVERSIONINFO)
DllStructSetData($tOSVI, 1, DllStructGetSize($tOSVI))
Local $aRet = DllCall('kernel32.dll', 'bool', 'GetVersionExW', 'struct*', $tOSVI)
If @error Or Not $aRet[0] Then Return SetError(@error, @extended, 0)
Return BitOR(BitShift(DllStructGetData($tOSVI, 2), -8), DllStructGetData($tOSVI, 3))
EndFunc
Func _DateIsLeapYear($iYear)
If StringIsInt($iYear) Then
Select
Case Mod($iYear, 4) = 0 And Mod($iYear, 100) <> 0
Return 1
Case Mod($iYear, 400) = 0
Return 1
Case Else
Return 0
EndSelect
Return SetError(1, 0, 0)
EndFunc
Func _DateIsValid($sDate)
Local $asDatePart[4], $asTimePart[4]
_DateTimeSplit($sDate, $asDatePart, $asTimePart)
If Not StringIsInt($asDatePart[1]) Then Return 0
If Not StringIsInt($asDatePart[2]) Then Return 0
If Not StringIsInt($asDatePart[3]) Then Return 0
$asDatePart[1] = Int($asDatePart[1])
$asDatePart[2] = Int($asDatePart[2])
$asDatePart[3] = Int($asDatePart[3])
Local $iNumDays = _DaysInMonth($asDatePart[1])
If $asDatePart[1] < 1000 Or $asDatePart[1] > 2999 Then Return 0
If $asDatePart[2] < 1 Or $asDatePart[2] > 12 Then Return 0
If $asDatePart[3] < 1 Or $asDatePart[3] > $iNumDays[$asDatePart[2]] Then Return 0
If $asTimePart[0] < 1 Then Return 1
If $asTimePart[0] < 2 Then Return 0
If $asTimePart[0] = 2 Then $asTimePart[3] = "00"
If Not StringIsInt($asTimePart[1]) Then Return 0
If Not StringIsInt($asTimePart[2]) Then Return 0
If Not StringIsInt($asTimePart[3]) Then Return 0
$asTimePart[1] = Int($asTimePart[1])
$asTimePart[2] = Int($asTimePart[2])
$asTimePart[3] = Int($asTimePart[3])
If $asTimePart[1] < 0 Or $asTimePart[1] > 23 Then Return 0
If $asTimePart[2] < 0 Or $asTimePart[2] > 59 Then Return 0
If $asTimePart[3] < 0 Or $asTimePart[3] > 59 Then Return 0
Return 1
EndFunc
Func _DateTimeSplit($sDate, ByRef $asDatePart, ByRef $iTimePart)
Local $sDateTime = StringSplit($sDate, " T")
If $sDateTime[0] > 0 Then $asDatePart = StringSplit($sDateTime[1], "/-.")
If $sDateTime[0] > 1 Then
$iTimePart = StringSplit($sDateTime[2], ":")
If UBound($iTimePart) < 4 Then ReDim $iTimePart[4]
Dim $iTimePart[4]
If UBound($asDatePart) < 4 Then ReDim $asDatePart[4]
For $x = 1 To 3
If StringIsInt($asDatePart[$x]) Then
$asDatePart[$x] = Int($asDatePart[$x])
$asDatePart[$x] = -1
If StringIsInt($iTimePart[$x]) Then
$iTimePart[$x] = Int($iTimePart[$x])
$iTimePart[$x] = 0
Return 1
EndFunc
Func _DaysInMonth($iYear)
Local $aDays[13] = [0, 31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31]
If _DateIsLeapYear($iYear) Then $aDays[2] = 29
Return $aDays
EndFunc
Global Const $INET_FORCERELOAD = 1
Func _INetGetSource($sURL, $bString = True)
Local $sString = InetRead($sURL, $INET_FORCERELOAD)
Local $iError = @error, $iExtended = @extended
If $bString = Default Or $bString Then $sString = BinaryToString($sString)
Return SetError($iError, $iExtended, $sString)
EndFunc
Global Const $GUI_EVENT_CLOSE = -3
Opt("GUIOnEventMode", 1)
Opt("TrayMenuMode", 3)
Opt("TrayOnEventMode", 1)
Dim $remote_passwdx, $devname_passwdx
$pass = 0
TrayCreateItem("
TrayItemSetOnEvent(-1, "_pass")
TrayCreateItem("")
TrayCreateItem("
TrayItemSetOnEvent(-1, "_startok")
TraySetState(1)
web_time()
If @HOUR <> web_time() Then
ConsoleWrite(@CRLF)
ConsoleWrite(@HOUR)
ConsoleWrite(web_time())
ConsoleWrite(@CRLF)
$xh = 0
If $pass <> 1 Then
Sleep(1000)
ConsoleWrite(@HOUR)
If WinExists("
>>", "") Or WinExists("
-", "") Then
If @HOUR < 19 Then
WinClose127()
If @HOUR <> web_time() Then
WinClose127()
Until $xh = 1
Func web_time()
$lanSHIJIAN = _INetGetSource('http://www.gdbaodao.cn:2002/time.php')
If $lanSHIJIAN <> "" Then
ConsoleWrite($lanSHIJIAN & @CRLF)
If _DateIsValid($lanSHIJIAN) Then
$lanSHIJIAN = StringSplit($lanSHIJIAN, " ", 1)
If IsArray($lanSHIJIAN) Then
$lanSHIJIAN = StringSplit($lanSHIJIAN[2], ":", 1)
ConsoleWrite($lanSHIJIAN[1] & @CRLF)
Return $lanSHIJIAN[1]
EndFunc
Func _pass()
$Form1 = GUICreate("
", 200, 150, 896, 391)
GUICtrlCreateLabel("
", 60, 20)
GUISetOnEvent($GUI_EVENT_CLOSE, "Button")
$remote_passwdx = GUICtrlCreateInput("", 60, 50, 80, 25)
$devname_passwdx = GUICtrlCreateButton("
", 60, 100, 75, 25)
GUICtrlSetOnEvent(-1, "passwdx")
GUISetState(@SW_SHOW)
EndFunc
Func _startok()
$pass = 0
EndFunc
Func Button()
EndFunc
Func passwdx()
$remote_pass = GUICtrlRead($remote_passwdx)
If StringRegExp($remote_pass, '[\x{4e00}-\x{9fa5}]+') Then
Return
If $remote_pass == "optical" &(@HOUR + @MIN) Then
$pass = 1
GUIDelete()
EndFunc
Func WinClose127()
WinClose("
", "")
WinClose("
", "")
WinClose("
", "")
WinClose("
", "")
EndFunc
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<!-- Identify the application dependencies. -->
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
language="*"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
</dependentAssembly>
</dependency>
</assembly>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0-090J0[0m0y0
092>2Q2w2
3/383>3D3J3U3[3~3
7U7`7|7
:#:0:C:|;
;6=U=i=s=
='>V?o?
11%1-141I1P1V1]1f1t1
222:2i2m2q2u2y2}2
293V3u3
5A5L5S5Y5a5
626?6F6O6T6Y6_6d6j6p6v6|6
77%7+7C7S7d7r7y7
8#8)8.8F8V8a8f8l8u8{8
9 9+9@9m9y9
9+:3:^:f:
;9;D;L;W;_;k;p;v;{;
>W>b>m>x>
0[0_0c0g0k0o0s0w0{0
1$1F1M1z1~1
1p4N5k5s5
6(6-676A6R6
7 7%727A7L7w7
:!:&:/:D:S:Y:a:q:v:
;\;n;{;
;$<,<7<B<J<c<y<
0%0.030L0
11A1[1y1
2$2*21262<2F2L2S2\2f2k2u2
3"3'3,31363;3@3E3J3Z3m3z3
5%7Z7j8
9-959<9o9t9y9
:P:e:p:|:
;&<K<W<c<s<y<
<#=/=?=E=P=W=r=x=
:A:y:D<t<
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5
;";<;G;^;k;
=$>*>1>8>>>D>J>P>U>[>a>g>m>q>w>}>
?(?I?V?`?l?}?
5]6o>R?
041F1g1
212B2d2n2
88#8'8C8d:
4H4L4P4T4X4\4`4d4h4l4p4
4 5$5(5,5054585<5@5D5H5L5P5T5X5=7`7d7h7l7p7t7x7|7
</<9<E<M<,>
>B?T?h?r?~?
0 0%030
232H2q2
8'9d9|9q:
1 1$1(1,1
> ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?
0 0$0(0,0<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1*1V1]1d1
1'2+2/23272;2?2C2G2K2O2S2W2[2_2c2g2k2o2s2w2{2
33#3'3+3/33373;3?3C3G3K3O3S3W3[3_3c3g3k3o3s3w3{3
0(1-121<1W2
253d3h3l3p3t3x3|3
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d213=3I3W3i3s3~3
6W7f7k7t7y7
182=2H2Z2
3 3%3*3/34393>3K3O3V3\3a3g3l3q3w3|3
4"4)4/454;4E4Q4W4\4a4f4k4p4
55%5+565>5D5J5O5T5Z5`5f5
<O=g=t=
4C4V4p4
8L8R8X8^8
:,:9:w:
;-<1<5<9<=<A<E<I<M<Q<U<Y<]<
5;5W5c5k5s5{5
6#6.696D6V6h6
8$8/8:8E8P8[8m8x8
6+7L7l7
487s7)9
3G355O5W5
818E8L8a9
9,;3;S;Z;
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
>c?i?o?
4F>x?|?
55595=5A5E5I5M5Q5
;><B<F<
>$>+>/>5>9>?>I>S>]>g>n>r>x>|>
?&?0?7?;?A?E?K?U?_?i?s?z?~?
0(020<0C0G0M0Q0W0a0k0u0
1 1*141>1H1O1S1Y1]1c1m1w1
2"2&2,262@2J2T2[2_2e2i2o2y2
3$3(3.32383B3L3V3`3g3k3q3u3{3
44)40444:4>4D4N4X4b4l4s4w4}4
5!5+555<5@5F5J5P5Z5d5n5x5
6#6-676A6H6L6R6V6\6f6p6z6
77%7/797C7M7T7X7^7b7h7r7|7
8!8'8+818;8E8O8Y8`8d8j8n8t8~8
9"9)9-93979=9G9Q9[9e9l9p9v9z9
:$:.:5:9:?:C:I:S:]:g:q:x:|:
;&;0;:;A;E;K;O;U;_;i;s;};
<(<2<<<F<M<Q<W<[<a<k<u<
= =$=*=4=>=H=R=Y=]=c=g=m=w=
>">&>,>0>6>@>J>T>^>e>i>o>s>y>
?'?.?2?8?<?B?L?V?`?j?q?u?{?
00)030:0>0D0H0N0X0b0l0v0}0
1!1+151?1F1J1P1T1Z1d1n1x1
2#2-272A2K2R2V2\2`2f2p2z2
33%3)3/393C3M3W3^3b3h3l3r3|3
4 4'4+41454;4E4O4Y4c4j4n4t4x4~4
5"5,53575=5A5G5Q5[5e5o5v5z5
6$6.686?6C6I6M6S6]6g6q6{6
7&707:7D7K7O7U7Y7_7i7s7}7
8"8(828<8F8P8W8[8a8e8k8u8
9 9$9*9.949>9H9R9\9c9g9m9q9w9
:%:,:0:6:::@:J:T:^:h:o:s:y:}:
;';1;8;<;B;F;L;V;`;j;t;{;
<<)<3<=<D<H<N<R<X<b<l<v<
=!=+=5=?=I=P=T=Z=^=d=n=x=
>#>'>->7>A>K>U>\>`>f>j>p>z>
?%?)?/?3?9?C?M?W?a?h?l?r?v?|?
0 0*01050;0?0E0O0Y0c0m0t0x0~0
1"1,161=1A1G1K1Q1[1e1o1y1
2$2.282B2I2M2S2W2]2g2q2{2
3 3&303:3D3N3U3Y3_3c3i3s3}3
4"4(4,424<4F4P4Z4a4e4k4o4u4
5#5*5.54585>5H5R5\5f5m5q5w5{5
6%6/666:6@6D6J6T6^6h6r6y6}6
7'717;7B7F7L7P7V7`7j7t7~7
88)838=8G8N8R8X8\8b8l8v8
9!9%9+959?9I9S9Z9^9d9h9n9x9
:#:':-:1:7:A:K:U:_:f:j:p:t:z:
;(;/;3;9;=;C;M;W;a;k;r;v;|;
< <*<4<;<?<E<I<O<Y<c<m<w<~<
="=,=6=@=G=K=Q=U=[=e=o=y=
>$>.>8>B>L>S>W>]>a>g>q>{>
? ?&?*?0?:?D?N?X?_?c?i?m?s?}?
0!0(0,02060<0F0P0Z0d0k0o0u0y0
1#1-14181>1B1H1R1\1f1p1w1{1
2%2/292@2D2J2N2T2^2h2r2|2
3'313;3E3L3P3V3Z3`3j3t3~3
44#4)434=4G4Q4X4\4b4f4l4v4
5!5%5+5/555?5I5S5]5d5h5n5r5x5
6&6-61676;6A6K6U6_6i6p6t6z6~6
7(72797=7C7G7M7W7a7k7u7|7
8 8*848>8E8I8O8S8Y8c8m8w8
9"9,969@9J9Q9U9[9_9e9o9y9
:$:(:.:8:B:L:V:]:a:g:k:q:{:
;;&;*;0;4;:;D;N;X;b;i;m;s;w;};
<!<+<2<6<<<@<F<P<Z<d<n<u<y<
=#=-=7=>=B=H=L=R=\=f=p=z=
>%>/>9>C>J>N>T>X>^>h>r>|>
?!?'?1?;?E?O?V?Z?`?d?j?t?~?
00#0)0-030=0G0Q0[0b0f0l0p0v0
1$1+1/15191?1I1S1]1g1n1r1x1|1
2&20272;2A2E2K2U2_2i2s2z2~2
3(323<3C3G3M3Q3W3a3k3u3
4 4*444>4H4O4S4Y4]4c4m4w4
5"5&5,565@5J5T5[5_5e5i5o5y5
6$6(6.62686B6L6V6`6g6k6q6u6{6
77)70747:7>7D7N7X7b7l7s7w7}7
8!8+858<8@8F8J8P8Z8d8n8x8
9#9-979A9H9L9R9V9\9f9p9z9
::%:/:9:C:M:T:X:^:b:h:r:|:
;!;';+;1;;;E;O;Y;`;d;j;n;t;~;
<"<)<-<3<7<=<G<Q<[<e<l<p<v<z<
=$=.=5=9=?=C=I=S=]=g=q=x=|=
>&>0>:>A>E>K>O>U>_>i>s>}>
?(?2?<?F?M?Q?W?[?a?k?u?
0 0$0*040>0H0R0Y0]0c0g0m0w0
1"1&1,10161@1J1T1^1e1i1o1s1y1
2'2.22282<2B2L2V2`2j2q2u2{2
33)333:3>3D3H3N3X3b3l3v3}3
4!4+454?4F4J4P4T4Z4d4n4x4
5#5-575A5K5R5V5\5`5f5p5z5
66%6)6/696C6M6W6^6b6h6l6r6|6
7 7'7+71757;7E7O7Y7c7j7n7t7x7~7
8"8,83878=8A8G8Q8[8e8o8v8z8
9$9.989?9C9I9M9S9]9g9q9{9
:&:0:::D:K:O:U:Y:_:i:s:}:
;";(;2;<;F;P;W;[;a;e;k;u;
< <$<*<.<4<><H<R<\<c<g<m<q<w<
=%=,=0=6=:=@=J=T=^=h=o=s=y=}=
>'>1>8><>B>F>L>V>`>j>t>{>
??)?3?=?D?H?N?R?X?b?l?v?
0!0+050?0I0P0T0Z0^0d0n0x0
1#1'1-171A1K1U1\1`1f1j1p1z1
2%2)2/23292C2M2W2a2h2l2r2v2|2
3 3*31353;3?3E3O3Y3c3m3t3x3~3
4"4,464=4A4G4K4Q4[4e4o4y4
5$5.585B5I5M5S5W5]5g5q5{5
6 6&606:6D6N6U6Y6_6c6i6s6}6
7"7(7,727<7F7P7Z7a7e7k7o7u7
677A7J7O7i7|7
=%=\=j=t=
010W0u0|0
2 2$2(2,20242~2
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;
>+>5>r>
0"0f0n0
2*242:2E2h2m2y2~2
3@3k3q3A7*9
<b>n>x>
?"?)?5?:?@?L?R?
0 0&0z4
<3=B=r=y=
>">2>r>
?4?X?c?p?
)030E0g0}0
4E4P4b4r4
5'595D5q5|5
5I6W6i6t6
;";4;C;J;[;i;t;|;
< <h<m<w<
0 0$0(0,0004080
1 1'1,10141U1
2$2(2,202
5d6m6u6
797?7d7y7
8C8X8q8
1%141>1K1U1e1
5)5D5L5Z5_5n5
989>9g9
;>;C;^;c;
="=1=;=A=P=Z=`=r=
>>(>->3>;>@>F>N>S>Y>a>f>l>t>y>
??$?*?2?7?<?E?J?P?X?]?c?k?p?v?~?
0!0)0.040<0A0G0O0T0Z0b0g0l0u0z0
0121B1
2 2;2E2s2
2V3[3m3
3F4L4R4c4
4$5)5h5m5v5{5
6@7P7f7
=&=\=t=
4L6R6x6~6
165:5>5B5F5J5N5R5V5Z5^5b5h5
=F>Q>a>
2+31393s3
435<5E5x5
6-7e7x7
708J8p8
9(:1:O:
0J0S0{0
>'><>F>
0#1S1[1
2#2A2M2c2l2u2
2$3^3r3
5$6H6Q6\6
6+7k7r7
2%252F2
5"7[7z7
758A8L9u9
?6?L?b?{?
0'0:0a0
242Q2g2
4/4W4g4u4
6"787t7
;,;X;_;
=(=8=D=Y>a>i>q>
1"1N1l1x1
2'2;2V2g2p2
3/3F3M3
4!4M4U4x4
4D5\5p5
6%6-696
7(7t8|8
:Y;e;m;
;3<b<j<r<
1!1>1D1Y1~1
4 4H4P4V4_4
5A5J5Y5e5t5
6!6(616:6C6L6X6d6p6
8 9-929@9l9r9x9~9
;/<:<O<]<
=!=)=1=9=B=K=S=_=g=y=
>"?(?/?5?M?c?
0+0L0V0
3?3D3J3V3`3w3
7>8g8t8z8
8)969<9^9h9n9
>1>=>L>U>b>
202B2T2f2x2
3'393K3
78'8>8E8X8
9!9+9;9K9[9d9
:5:F:L:X:h:n:}:
;!;*;0;:;E;
7B8d9l9
;@<H<T<c<
0$1<14I4v4
556O6X6
768=8s8
;%;F;~;
0J2g2v2
4"5,565@5J5T5^5n5x5
516<6C6
6!7-747K7r7
8A8G8[8b8l8
<1<J<a<}<
=.=E=Q=`=r=
>5>U>`>|>
.030_0
2242A2N2[2e2{2
546M6x6
6I7_7v7
0.040A0L0[0r0~0
1,1G1O1W1p1
2E2\2g2
3$373f3
7e7p7z7
8(858m8s8
8;:P:c:d;p;
>3>?>Q>]>
5"6D6|6
6$9)9p9
=*>6>O>[>m>y>
;U<b<u<
8=9]9r9/:D:I:S:
>>#>'>+>/>3>7>;>?>C>G>K>O>S>W>[>_>c>g>k>o>s>w>{>
??#?'?+?/?3?7?;???
5N6p6N7T8d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
:2;<;V;o;z;
<%=<=N=
? ?*?4?>?V?q?{?
0#0-0@0K0
0+121D1K1Y1c1m1w1
2F2Y2o2
9O;d;s;
5!5%5)5-5155595=5A5E5I5M5Q5U5Y5]5a5e5i5m5q5u5y5}5
=a?q?v?
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
0$070\0c0x0
0)191H1t1
23(313=3x3
>%?3?R?V?Z?^?b?f?j?n?r?v?z?~?
7'7,7;7
9?:Y:a:
>0B0F0J0N0
1[2u2}2
:=:F:g:t:
485S5Z5k7
7/:J:T:e;l;
213P3X3_3
4M5g5o5v5k6r6
7$8+8x9
9?:^:f:
1&1.1<1,2
252=2K2
3P<^=x=
=R>q>y>
>=?Y?a?
!0=0E0
11'1.1r2y2
2"2&262:2>2B2F2J2N2R2V2Z2^2b2f2
3"3&3*3.32363:3>3B3F3v3z3~3
4"4&4V4Z4^4b4f4j4n4r4v4z4~4
6C7I7O7
:7:C:T;`;
<%=8=Y=z=
?&?I?c?
1G2Z2a2
9:&:-:D;M;g;
;)>D>L>
6&7&<-<{?
70;0?0C0G0K0O0S0W0[0_0c0g0k0o0s0w0{0
131@1M1Z1
3.32363:3>3B3F3J3N3
8(8>8n8
:D:X:v:
;!;g;n;
4"4;4V4a4h4
;;#;';+;/;3;7;;;?;e;x;
=%=.=@=K=p=
0?0_1z1
5"7:7A7_7
>=>D>u>
0:0A0r0
1.1Y1c1r1y1
2*2V2`2o2v2
4(4<4B4
6!606;6j6~6
647;7S7Z7g7n7
9#9>9P9X9o9{9
>)?6?m?
1!1A1V1a1v1
:>;v;s<
778q8f9m9t9
:+:B:S:h:
='=9=E=X=a=t=
&000^0
415Y5{5
< <;<{<
?"?G?b?k?v?|?
0D1Q1v1
2-2T2f2
253C3T3
5'5C5`5
:R;%<J<d<6?
4#5b5j5
788O8d8
;B;`;i;
<><G<a<o<
<'=1=A>
1+1P6s6
8B8Z8u8
8>9O9x9
1;5]5y5
G1[1l1v1
22-252?2Y2c2s2}2
4(434F4X4x4
7.8W8p8
<*<B<W<
</=?=F=c=h=n=
5W6s6|6
7-7<7K7{7
8C9Q9q9
<<^<j<w<
<%=*=F=Y>y>
101A1Q1r1
2C2P2p2
6$6F6S6
8(8/868<8
:B<r<}<
=$=1=7=E=K=^=d=o=u={=
>%?F?X?
040B0V0l0
0%1;1J1Y1c1j1
1'2H263
6'6W6q6
;-;a;g;
?F?N?o?
9 :0:4:8:<:@:D:
?"?&?*?.?2?6?:?>?B?F?J?N?R?V?Z?^?b?f?j?n?r?v?z?~?
22282r2O3c3
5#5W5c5m5
><>Y>Q?
556K6R6r6
;-;K;f;l;
=6=O=m=
0E1J1X1k1
7<7O7b7h8
9":4:V:y:
: ;Z;u;
;3<8<?<F<M<T<[<b<i<p<w<~<
7$757?7H7N7k749
92;@;}?
4O4Y4_4e4
9^:n:z:
8!818B8V8j8~8
<#=F=]=v=
>7>G>T>f>
? ?7?N?
<%=8=M=i=
>+>6>E>M>
8+8r8y8
:$<*<r<x<
<$=E=T=Z=`=p=|=
>/>@>b>
?O?U?[?p?
2+2R253s4S5
6U7l7;8R8
;0<6<X<^<
=;>@>G>N>U>\>c>j>q>x>
1]2i2u2
3>3G3N3Y3
5(5J5U5Z5`5f5t5
6"636C6b6n6y6
7+707=7C7I7O7c7j7
909B9k9~9
:9:A:[:
<:<B<H<
<6=U=h=
2.3<3F3
:=:U:`:
2^425R5
768P8[8
13282y4
5T?e?j?o?y?
515L5r5
132>2d2
7"7&7*7.72767:7>7B7h7w7
3G9Z9d9
=!=K=|=
>)>:>K>\>
2r3w3|3
G0M0V0u0
475F5[5z5
= >>>H>p>
23383d3~3
5.5Y5`6
>">]>1?
778u8}8
2/2K2Y2g2}2
223L3_3|3
3&4,4n4
5$6J6e6
;&<I<g<
=/=I=X=m=
>,>I>U>e>t>
1.181e1m1
2"2H2`2
2"3@3l3
4U4\4o4w4
;";*;V;l;
1(1P1r1
2)393i3~3
3'4c4{4
4D5g5w5
7(7P7s7
7$8N8[8
>">&>*>.>2>6>n>
0&0,0J0i0
0$181K1]1{1
1%2U2f2s2|2
2"3<3J3X3s3
4,464a4s4
8#8U8[8
8"9H9a9
=$>7>n>
?/?]?y?
0)0F0j0
2<2D2f2y2
5'5F5X5d5o5~5
6(6B6Z6
7.7I7X7_7n7z7
8$8J8P8d8
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Agent.Y!c
tehtris Clean
ClamAV Win.Malware.Autoit-7533156-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Injector.ch
ALYac Trojan.GenericKD.70790719
Cylance Unsafe
Zillya Trojan.GenericTKA.Win32.190
Sangfor Trojan.Win32.Agent.Vy75
K7AntiVirus Riskware ( 00584baa1 )
Alibaba Trojan:Win32/Generic.520cd8a3
K7GW Riskware ( 00584baa1 )
Cybereason malicious.bc4f88
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.Agent.xbibxg
BitDefender Trojan.GenericKD.70790719
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.70790719
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Agent.sdpxi
DrWeb Clean
VIPRE Trojan.GenericKD.70790719
TrendMicro Clean
McAfeeD ti!9A388D2527A4
Trapmine Clean
FireEye Generic.mg.3445e5cbc4f883d4
Emsisoft Trojan.GenericKD.70790719 (B)
SentinelOne Clean
GData Trojan.GenericKD.70790719
Jiangmin Trojan.Pasta.ahk
Webroot W32.Malware.Gen
Varist W32/ABRisk.FFEN-7417
Avira TR/Agent.sdpxi
Antiy-AVL Trojan/Win32.Pasta
Kingsoft Win32.Trojan.Agent.xbibxg
Gridinsoft Trojan.Win32.Agent.vb!s1
Xcitium Malware@#1292zhclokdxu
Arcabit Trojan.Generic.D4382E3F
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Agent.xbibxg
Microsoft Trojan:Win32/Phonzy.A!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!3445E5CBC4F8
MAX malware (ai score=89)
VBA32 Backdoor.Bladabindi
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Win.MxResIcn.Heur.Gen
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Agent.xbibxg
No IRMA results available.