Static | ZeroBOX

PE Compile Time

2007-10-19 00:43:35

PE Imphash

b1e8eb7760736462773774d39bf9187b

PEiD Signatures

UPX 2.93 - 3.00 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0013d000 0x00000000 0.0
UPX1 0x0013e000 0x00045000 0x00044e00 7.99850939237
.rsrc 0x00183000 0x00007000 0x00006a00 3.70499686728

Resources

Name Offset Size Language Sub-language File type
PICKLE 0x001433c8 0x00000008 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00143638 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00143638 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x00143638 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x001865a8 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x00148f04 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x00148f04 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x00148f04 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00188b54 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00188bb4 0x00000760 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00189318 0x00000356 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x589724 LoadLibraryA
0x589728 GetProcAddress
0x58972c VirtualProtect
0x589730 VirtualAlloc
0x589734 VirtualFree
0x589738 ExitProcess
Library ADVAPI32.dll:
0x589740 RegCloseKey
Library iphlpapi.dll:
0x589748 GetAdaptersInfo
Library ole32.dll:
0x589750 CoInitialize
Library OLEAUT32.dll:
0x589758 SysFreeString
Library SHELL32.dll:
0x589760 SHGetMalloc
Library USER32.dll:
0x589768 GetDC
Library VERSION.dll:
0x589770 VerQueryValueW

!This program cannot be run in DOS mode.
g@=(gtw
'MpL-u
Mm:#476%
P-WpZe
6fp=dB2
TKBWLk
^4yfo.
aAaz]"
hXEFX*
lKfBV>
vb\+D3
WS[I35
k}1XKWw
c6C"bfc
WV}+N<
XQ3=oK
DZh9Z[
?kdGoF1
[eGRbg
v<.T+h
lh$D`;!
RFnBT.
K7ZQ*Q
Wiql"v
&r=w83Fa
]i-2ia
"G9END
`*%pV)=
F[=5wu
L5;(wi
9Ga*=!
yzKM[~
JrI'L&
KyP|u?Mc]TV6
&iZ,Mw
$^c{{/
k5-P^8
,d>nge
2}Kr!D
@k`_1]L
iiL>N\
pQ|Unu
o*3Xs(
H~: WU
mX%QKI
pJi4Ej
nfNWg,
;Z9&|N
`;{lkJ[
S)[+I$
8,+a9-
UZ,_GA
{xV2\j}Y
M{z"%Af
h1,X\=l~
QE%0KMlWSp-
SksjJ6"
n%z-gJ5
*bbZ7
$KM+K\
XpRRNK
3[bBbK
vSJ"(gh
lI+K.7
+\w)fc
hKH`8P
K i]=^?
]R'c7&L
yo#D&b
pvy9O!
,DgK+H9$
@oQ59N^@
R]nxn@
p7Lp|(
I))aM1T
|(9ztCOzk|I
=B=g;s
rG[\ER
>f0Jhs
3UC`*1
9GC1".
2%h'Gh
!bJeya
93ZSVe
:% 0A/
j{I=}7
\G?3Uw
vfF@D*
t]a4|K
+ohdWs@
r$OYPt
Bd"sL.Y
LTr<:
Vn9Tg
Um&`Gd
IB<7%<
9x'1C#A
`|HG#\
^+Nx~^
4RR*D^
/I1dUV
nn;J7Z0m
p^)ei.
ajV4|^<B
WJcd"Zn
Pl*ox*
%l5y}l
7.\$Le
J`AK!Z
DB=!)L1
-/"[rqkj
d2sw>HP
/]5A3I_U
9O&>PRG
X{|| e
P5k4N:<a
ACxQ;=
s\&r!S
-p'jJj
%~Qaw4
W`=mC_[
8QsuX/5
yTo@9x
"v?-O7
}~XI}+
5K*HZG
f|^G={
%%CuqQK
\@6jZ"9o
N32]cW
O22hPRTn
bCq8%4
<-u 0m
_g^plMlb
3o3sS_C
}vYFf^
!kM2cD
my9g:Eh
-=I1H[j
`U{%@,.E]\
ohK"m3
/{4~:a_#b
*ao-eQk7
lawN[
'_e*99i7
6Hlgyp
t2ZlFE
pP3x(|1l
$><zZi
U]NE'H
/RTRXT
N4[V^l
}>/1eT
Wm^UHSD!
KHxM6\
Ta[3ox#
,cII'@'-
<_UL C
fIeI;pm
j?4LHy
vK0k,}
790Qg[
DR/{BX
)snT{,N
a9F:v/
?]\Yy0s
>Rd|*?
s3ai3~*!+
5PROssz
<NW d"
w[<$J9
/$Tf2(6
Iq`_"]t
dx{(eb
iMnURC
$&o?Mj1ej
YNP9 |Q
O135GySx"
~o=}{%
$rf%)Y
<r|}(
[|\a}j
XD3M6
!6n6\|
Enme)z
`8^sIt
s7s2A<
;@dH2
80Jf.)o
P-BI/M
`fOJ"V
j0~EWsG
TJ}-#f
P3"IV/
shdU3
c=R?@.B-
VH$SQi
1rPO5}z
i@{}.{]
xE4E@0N
_W7=-y
sv*a3c
/p-60-1
6yI~B^R
%H9_,^
}{a<jiGK
c0WEM
mec%+[
OnH?OI
cnP+A6 ey1y
h>,edJ
e|'zw6
G$fK\j
:,HG2In
mzY(]s
m-7oGD
^hgfmB
OKbz1l
9kuEM
Z6u!Xn
tCdm8&
]9E4\C
zkqCD}
Z9YL#1G1#
O3]4|
>cQ&!g
JXr5|j
i{H|r=
^b<.k\
pBByOQqK& JK
k1l}&
N<1EGwh
<_'M`%
,n$FQV
D$;z+3
o2;Y
h<bO)Y0
V:~kR|
8Lzw,J
%:gF>W
GT(XS(
z}mu*b
nHUlr"LK)
A7|1mA
R{^P[
_n6dF%
pQD2saj
uc*s\D
n"QG0_my%
W{in)U
\_Rs#q
?AJUk\
\+L<3&:
X,@Ugn!
Zcl.j4
YC4,im3s
|h{u;
<IP:9L
>]ny][z^
<Epfw!
T2WA^P
E5rEF
`79gB)
wD1of)B
B6Ghx.
q/>|t)
{-\"1W
"r7g+A"
bD=to*
tIDAe4
M'os2*
D(FHo5
3"z=Wq
W/Yt]>
LdYf_Y
Wh'FCSF
rZuCDnD&
v@DGOs
68{(vC
F$AJ[_
z1Z's!
eCr0#p
&wA(>p
LxX=s^1
|& 8hD
s5{O^"
aV<8/d
5oy#W"
e74z~c.3r
X6RLPP
_[?3t{Q
Og2<iL
2I}^}(
$^dmGv
fljD60E
OS*PBi
tIoE/*
B4e?5{L
.&!gD8
x+::.q
n~AIOb
ztt7jY)
uNR{&#
b}o-1*
.f4w@n
_8iVlK
2JCnj`
*2fVKSH
>'`2 ]<
B{5)xog
YQ_Z{*bfX
WCO>?b
aw\.|$
2Vpn0ek
`uq)Zr
~2F~s=
,a<~i/=kYS
+*7Y[M|
wkL#JW_
8VF@c/
Z'`FZ
~<tkXNY
@ob)M$
o/S%HY
/)uUL
TDD~>H
x7O+N9
#w?.3>
XlNv?
gI=tA
6,<bNr
wycOtH
>q\^Q7w0
9nWetp8
Wa?4xv
?(W?@"
;+g`f-
Grq/IJqBv
na(Hd]
v3VR!A
YB0mxxV
#gk__M
)A@+v+
,m`6qaF<
z{ TDd
BXGRm.$
CdDi%S
wWDaA0
sH4Tgm
"NH%rO
iV<CILM
=,}=gZ
\7F ;B
.cK;g0,
vCN7j
;5=C"c
bU:Zto
c( 7[8
<o"9).
j*saR*
q~:9d
26qBZZ
y4E8e!
4pFfo-
lBqC'R
PGq*]^
Qh)!Jo
<#32ywi
P?KU^yeA
s)%ne-
^MzZ(v
16VjFD}R|Y
%H$o,G
g@wP^tZ
v1^DuU
CP.+;A
E} 2xi]3
K]z%L\
X\^PY
?C,(\k
{(sH(>P4
3Wn+1^
ot:67\h
Lm;n*3
-9z"7gv
w#@^\6
!BG]<o
D$fK8f
r&JocdD
vs?Gl!
gZ^w}V
;`Mrlm
S+G/:c
giTmq~
&+Z^&A
{4g(M'
K5g_&\
[2"4 k@
(BHb<Nb
>&7u6;
-h%{f-
~T*N}3
zwyP'&
5CEr\/
<C61+6
;vk~8
(>5a1M8
:;gnl}
"jh<~I
j/9=9:
T_G!J5
?4rBIH*
wsjv&af
Ax&zpi,pWF
#:=$;H
Rgb36r
C ep'[
ZA$\)D
h%p}UY!]}}
ERTL@
B__8D /
>j7O"l
|Tf-|l
JMCvv 2
rM5q\>
<4VF>b
-L[pQO
}ysSgW
VkC7 dv
d6!$vr
k!C:"u
WzPPXmY
A_+W4
,DP/h(DM6
IZwfkA
6w*=J2
L(ugrG6
JxI}WA.
li XD.
{|UrB7
x7M8B
]i2eJh
*SW:ve
6y SUW
g4F1r~
<h"M$\-S
%v}T!V
Mp?xir~
0KFgH)
got,Fy
;//xB1
8VcCv
0r)\eG
X;QQH#Q
aa82RY|
tqIgzbt
&@:;h!
25&g f
eT\f/x
&GAcZx
<8m[c( X
T&i3$y
0$#fGg
Ja8&lw
Jxao.vd
J-oX-B
I\8@uB
t|2m{7
OzYXGH
]#8bXU
j- (\w
f)b1|Y
Sb`KWkS@
(>LnQV
^ @VmxD
0` ]7d5
}C+|cvnf
9Ko:1L/
j&{B[bB
$FF0z(
h_ey_l
\;j(Ot
s9rYu`
,2*5U'
4K:okF5I
/l4wv4
BD"L3U
koZ[T<
Th_tbP0#
x?=yZF
R#:|Am
0v971#Y
4yG4:
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
+++++++++++++++++++++++++++++++++++++++
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a+++a
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="x86"
name="WAT Fix.exe"
type="win32"
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
</dependentAssembly>
</dependency>
<!-- Identify the application security requirements. -->
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
KERNEL32.DLL
ADVAPI32.dll
iphlpapi.dll
ole32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
VERSION.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegCloseKey
GetAdaptersInfo
CoInitialize
SHGetMalloc
VerQueryValueW
112358R
QQQQQQ
QQQQQQ
QQQQQQ
MemoryBlock
Long%i4%o<MemoryBlock>i4
#Ptr%o<MemoryBlock>%o<MemoryBlock>i4
Short%i4%o<MemoryBlock>i4
UShort%i4%o<MemoryBlock>i4
Byte%i4%o<MemoryBlock>i4
PString%s%o<MemoryBlock>i4
CString%s%o<MemoryBlock>i4
WString%s%o<MemoryBlock>i4
SingleValue%f8%o<MemoryBlock>i4
DoubleValue%f8%o<MemoryBlock>i4
!=StringValue%%o<MemoryBlock>i4i4s
/StringValue%s%o<MemoryBlock>i4i4o<TextEncoding>
BooleanValue%b%o<MemoryBlock>i4
ColorValue%c%o<MemoryBlock>i4i4
MemoryBlock%%o<MemoryBlock>i4
!Operator_Convert%s%o<MemoryBlock>
!Operator_Convert%%o<MemoryBlock>s
8Operator_Add%o<MemoryBlock>%o<MemoryBlock>o<MemoryBlock>
0Operator_Compare%i4%o<MemoryBlock>o<MemoryBlock>
!Operator_Convert%p%o<MemoryBlock>
!Operator_Convert%%o<MemoryBlock>p
%LeftB%o<MemoryBlock>%o<MemoryBlock>i4
$MidB%o<MemoryBlock>%o<MemoryBlock>i4
&MidB%o<MemoryBlock>%o<MemoryBlock>i4i4
&RightB%o<MemoryBlock>%o<MemoryBlock>i4
=ColorValue%%o<MemoryBlock>i4i4c
=BooleanValue%%o<MemoryBlock>i4b
=DoubleValue%%o<MemoryBlock>i4f8
=SingleValue%%o<MemoryBlock>i4f8
=WString%%o<MemoryBlock>i4s
=CString%%o<MemoryBlock>i4s
=PString%%o<MemoryBlock>i4s
=Byte%%o<MemoryBlock>i4i4
=UShort%%o<MemoryBlock>i4i4
=Short%%o<MemoryBlock>i4i4
$=Ptr%%o<MemoryBlock>i4o<MemoryBlock>
=Long%%o<MemoryBlock>i4i4
=Int32Value%%o<MemoryBlock>i4i4
Int32Value%i4%o<MemoryBlock>i4
=Int8Value%%o<MemoryBlock>i4i1
=Int16Value%%o<MemoryBlock>i4i2
=Int64Value%%o<MemoryBlock>i4i8
Int8Value%i1%o<MemoryBlock>i4
Int16Value%i2%o<MemoryBlock>i4
Int64Value%i8%o<MemoryBlock>i4
=UInt8Value%%o<MemoryBlock>i4u1
=UInt16Value%%o<MemoryBlock>i4u2
=UInt32Value%%o<MemoryBlock>i4u4
=UInt64Value%%o<MemoryBlock>i4u8
UInt8Value%u1%o<MemoryBlock>i4
UInt16Value%u2%o<MemoryBlock>i4
UInt32Value%u4%o<MemoryBlock>i4
UInt64Value%u8%o<MemoryBlock>i4
CurrencyValue%e%o<MemoryBlock>i4
!=CurrencyValue%%o<MemoryBlock>i4e
LittleEndian%b%
Size%i4%
"Operator_Compare%i4%o<Date>o<Date>
Constructor%%o<Date>
Constructor%%o<Date>o<Date>
Year%i4%
Month%i4%
Day%i4%
Hour%i4%
Minute%i4%
Second%i4%
DayOfWeek%i4%
DayOfYear%i4%
WeekOfYear%i4%
ShortDate%s%
LongDate%s%
AbbreviatedDate%s%
ShortTime%s%
LongTime%s%
TotalSeconds%f8%
SQLDate%s%
SQLDateTime%s%
GMTOffset%f8%
NetworkInterface
MACAddress%s%
IPAddress%s%
SubnetMask%s%
Network
IsConnected%b%o<Network>
LookupIPAddress%s%o<Network>s
LookupDNSAddress%s%o<Network>s
WakeOnLAN%%o<Network>ss
FunctionNotFoundException
Stack%A1s%o<RuntimeException>
RegistryAccessErrorException
TypeMismatchException
OutOfBoundsException
ThreadEndException
RuntimeException
Message%s%
ErrorNumber%i4%
NilObjectException
IllegalCastException
ResourceFork
Close%%o<ResourceFork>
ResourceType%s%o<ResourceFork>i4
GetResource%s%o<ResourceFork>si4
$GetNamedResource%s%o<ResourceFork>ss
!ResourceCount%i4%o<ResourceFork>s
ResourceID%i4%o<ResourceFork>si4
!ResourceName%s%o<ResourceFork>si4
!AddResource%%o<ResourceFork>ssi4s
"RemoveResource%%o<ResourceFork>si4
GetHandle%i4%o<ResourceFork>si4
ReleaseHandle%%o<ResourceFork>i4
#ResourceLocked%b%o<ResourceFork>si4
&ResourceProtected%b%o<ResourceFork>si4
$ResourcePreload%b%o<ResourceFork>si4
&ResourcePurgeable%b%o<ResourceFork>si4
$ResourceSysHeap%b%o<ResourceFork>si4
%=ResourceSysHeap%%o<ResourceFork>si4b
'=ResourcePurgeable%%o<ResourceFork>si4b
%=ResourcePreload%%o<ResourceFork>si4b
'=ResourceProtected%%o<ResourceFork>si4b
$=ResourceLocked%%o<ResourceFork>si4b
TypeCount%i4%
ConsoleApplication
!DoEvents%%o<ConsoleApplication>i4
!Daemonize%b%o<ConsoleApplication>
5_AddPollableObject%%o<ConsoleApplication>o<_Pollable>
8_RemovePollableObject%%o<ConsoleApplication>o<_Pollable>
(YieldToNextThread%%o<ConsoleApplication>
'__DependencyList%%o<ConsoleApplication>
UnhandledException
ExecutableFile%o<FolderItem>%
CurrentThread%o<Thread>%
MajorVersion%i4%
MinorVersion%i4%
BugVersion%i4%
StageCode%i4%
NonReleaseVersion%i4%
RegionCode%i4%
ShortVersion%s%
LongVersion%s%
PackageInfo%s%
Thread
Run%%o<Thread>
Suspend%%o<Thread>
Resume%%o<Thread>
Sleep%%o<Thread>i4b
Kill%%o<Thread>
StackSize%i4%
ThreadID%i4%
Priority%i4%
State%i4%
FolderItem
FolderItem%%o<FolderItem>
FolderItem%%o<FolderItem>si4
&FolderItem%%o<FolderItem>o<FolderItem>
"Item%o<FolderItem>%o<FolderItem>i4
&TrueItem%o<FolderItem>%o<FolderItem>i4
"Child%o<FolderItem>%o<FolderItem>s
&TrueChild%o<FolderItem>%o<FolderItem>s
/OpenAsTextFile%o<TextInputStream>%o<FolderItem>
2AppendToTextFile%o<TextOutputStream>%o<FolderItem>
0CreateTextFile%o<TextOutputStream>%o<FolderItem>
2CreateVirtualVolume%o<VirtualVolume>%o<FolderItem>
2OpenAsVirtualVolume%o<VirtualVolume>%o<FolderItem>
/OpenAsBinaryFile%o<BinaryStream>%o<FolderItem>b
/CreateBinaryFile%o<BinaryStream>%o<FolderItem>s
.OpenResourceFork%o<ResourceFork>%o<FolderItem>
1CreateResourceFork%o<ResourceFork>%o<FolderItem>s
Delete%%o<FolderItem>
CreateAsFolder%%o<FolderItem>
&CopyFileTo%%o<FolderItem>o<FolderItem>
&MoveFileTo%%o<FolderItem>o<FolderItem>
*GetSaveInfo%s%o<FolderItem>o<FolderItem>i4
(GetRelative%o<FolderItem>%o<FolderItem>s
"_MakeFileExecutable%%o<FolderItem>
Permissions%i4%o<FolderItem>
)=Permissions%%o<FolderItem>o<Permissions>
=Permissions%%o<FolderItem>i4
AbsolutePath%s%
Count%i4%
Name%s%
DisplayName%s%
Length%u8%
ResourceForkLength%i4%
ExtensionVisible%b%
Locked%b%
Exists%b%
Alias%b%
Visible%b%
Directory%b%
Type%s%
Parent%o<FolderItem>%
CreationDate%o<Date>%
ModificationDate%o<Date>%
MacType%s%
MacCreator%s%
DesktopFolder%o<FolderItem>%
TrashFolder%o<FolderItem>%
SharedTrashFolder%o<FolderItem>%
TemporaryFolder%o<FolderItem>%
VirtualVolume%o<VirtualVolume>%
IsReadable%b%
IsWriteable%b%
LastErrorCode%i4%
MacVRefNum%i4%
MacDirID%i4%
ShellPath%s%
URLPath%s%
Group%s%
Owner%s%
Permissions
Permissions%%o<Permissions>i4
StickyBit%b%
GidBit%b%
UidBit%b%
OwnerExecute%b%
OwnerWrite%b%
OwnerRead%b%
GroupExecute%b%
GroupWrite%b%
GroupRead%b%
OthersExecute%b%
OthersWrite%b%
OthersRead%b%
VirtualVolume
Root%o<FolderItem>%
Writeable
TextOutputStream
WriteLine%%o<TextOutputStream>s
Write%%o<TextOutputStream>s
Close%%o<TextOutputStream>
Flush%%o<TextOutputStream>
WriteError%b%o<TextOutputStream>
$Constructor%%o<TextOutputStream>i4i4
Handle%i4%o<TextOutputStream>i4
Delimiter%s%
TextInputStream
*Read%s%o<TextInputStream>i4o<TextEncoding>
,ReadLine%s%o<TextInputStream>o<TextEncoding>
+ReadAll%s%o<TextInputStream>o<TextEncoding>
Close%%o<TextInputStream>
EOF%b%o<TextInputStream>
ReadError%b%o<TextInputStream>
#Constructor%%o<TextInputStream>i4i4
Handle%i4%o<TextInputStream>i4
Encoding%o<TextEncoding>%
PositionB%u8%
Readable
BinaryStream
ReadByte%i4%o<BinaryStream>
ReadShort%i4%o<BinaryStream>
ReadLong%i4%o<BinaryStream>
,ReadPString%s%o<BinaryStream>o<TextEncoding>
ReadSingle%f8%o<BinaryStream>
ReadDouble%f8%o<BinaryStream>
ReadBoolean%b%o<BinaryStream>
'Read%s%o<BinaryStream>i4o<TextEncoding>
WriteByte%%o<BinaryStream>i4
WriteShort%%o<BinaryStream>i4
WriteLong%%o<BinaryStream>i4
WritePString%%o<BinaryStream>s
WriteSingle%%o<BinaryStream>f8
WriteDouble%%o<BinaryStream>f8
WriteBoolean%%o<BinaryStream>b
Write%%o<BinaryStream>s
Close%%o<BinaryStream>
Flush%%o<BinaryStream>
WriteError%b%o<BinaryStream>
EOF%b%o<BinaryStream>
ReadError%b%o<BinaryStream>
Constructor%%o<BinaryStream>s
*Constructor%%o<BinaryStream>o<MemoryBlock>
Constructor%%o<BinaryStream>i4i4
Handle%i4%o<BinaryStream>i4
ReadInt8%i1%o<BinaryStream>
ReadInt16%i2%o<BinaryStream>
ReadInt32%i4%o<BinaryStream>
ReadInt64%i8%o<BinaryStream>
ReadUInt8%u1%o<BinaryStream>
ReadUInt16%u2%o<BinaryStream>
ReadUInt32%u4%o<BinaryStream>
ReadUInt64%u8%o<BinaryStream>
WriteInt8%%o<BinaryStream>i1
WriteInt16%%o<BinaryStream>i2
WriteInt32%%o<BinaryStream>i4
WriteInt64%%o<BinaryStream>i8
WriteUInt8%%o<BinaryStream>u1
WriteUInt16%%o<BinaryStream>u2
WriteUInt32%%o<BinaryStream>u4
WriteUInt64%%o<BinaryStream>u8
ReadCurrency%e%o<BinaryStream>
WriteCurrency%%o<BinaryStream>e
Position%u8%
RegistryItem
RegistryItem%%o<RegistryItem>sb
,RegistryItem%%o<RegistryItem>o<RegistryItem>
*AddFolder%o<RegistryItem>%o<RegistryItem>s
Delete%%o<RegistryItem>s
Value%v%o<RegistryItem>s
Value%v%o<RegistryItem>i4
DefaultValue%v%o<RegistryItem>
&Child%o<RegistryItem>%o<RegistryItem>s
&Item%o<RegistryItem>%o<RegistryItem>i4
Name%s%o<RegistryItem>i4
KeyType%i4%o<RegistryItem>i4
=DefaultValue%%o<RegistryItem>v
=Value%%o<RegistryItem>i4v
=Value%%o<RegistryItem>sv
Parent%o<RegistryItem>%
KeyCount%i4%
FolderCount%i4%
Path%s%
_Encodings
+GetFromCode%o<TextEncoding>%o<_Encodings>i4
_Count%i4%o<_Encodings>
%_Item%o<TextEncoding>%o<_Encodings>i4
UTF8%o<TextEncoding>%
UTF16%o<TextEncoding>%
UCS4%o<TextEncoding>%
MacRoman%o<TextEncoding>%
MacJapanese%o<TextEncoding>%
MacChineseTrad%o<TextEncoding>%
MacKorean%o<TextEncoding>%
MacArabic%o<TextEncoding>%
MacHebrew%o<TextEncoding>%
MacGreek%o<TextEncoding>%
MacCyrillic%o<TextEncoding>%
MacDevanagari%o<TextEncoding>%
MacGurmukhi%o<TextEncoding>%
MacGujarati%o<TextEncoding>%
MacOriya%o<TextEncoding>%
MacBengali%o<TextEncoding>%
MacTamil%o<TextEncoding>%
MacTelugu%o<TextEncoding>%
MacKannada%o<TextEncoding>%
MacMalayalam%o<TextEncoding>%
MacSinhalese%o<TextEncoding>%
MacBurmese%o<TextEncoding>%
MacKhmer%o<TextEncoding>%
MacThai%o<TextEncoding>%
MacLaotian%o<TextEncoding>%
MacGeorgian%o<TextEncoding>%
MacArmenian%o<TextEncoding>%
MacChineseSimp%o<TextEncoding>%
MacTibetan%o<TextEncoding>%
MacMongolian%o<TextEncoding>%
MacEthiopic%o<TextEncoding>%
#MacCentralEurRoman%o<TextEncoding>%
MacVietnamese%o<TextEncoding>%
MacExtArabic%o<TextEncoding>%
MacSymbol%o<TextEncoding>%
MacDingbats%o<TextEncoding>%
MacTurkish%o<TextEncoding>%
MacCroatian%o<TextEncoding>%
MacIcelandic%o<TextEncoding>%
MacRomanian%o<TextEncoding>%
MacCeltic%o<TextEncoding>%
MacGaelic%o<TextEncoding>%
ISOLatin1%o<TextEncoding>%
ISOLatin2%o<TextEncoding>%
ISOLatin3%o<TextEncoding>%
ISOLatin4%o<TextEncoding>%
!ISOLatinCyrillic%o<TextEncoding>%
ISOLatinArabic%o<TextEncoding>%
ISOLatinGreek%o<TextEncoding>%
ISOLatinHebrew%o<TextEncoding>%
ISOLatin5%o<TextEncoding>%
ISOLatin6%o<TextEncoding>%
ISOLatin7%o<TextEncoding>%
ISOLatin8%o<TextEncoding>%
ISOLatin9%o<TextEncoding>%
DOSLatinUS%o<TextEncoding>%
DOSGreek%o<TextEncoding>%
DOSBalticRim%o<TextEncoding>%
DOSLatin1%o<TextEncoding>%
DOSGreek1%o<TextEncoding>%
DOSLatin2%o<TextEncoding>%
DOSCyrillic%o<TextEncoding>%
DOSTurkish%o<TextEncoding>%
DOSPortuguese%o<TextEncoding>%
DOSIcelandic%o<TextEncoding>%
DOSHebrew%o<TextEncoding>%
"DOSCanadianFrench%o<TextEncoding>%
DOSArabic%o<TextEncoding>%
DOSNordic%o<TextEncoding>%
DOSRussian%o<TextEncoding>%
DOSGreek2%o<TextEncoding>%
DOSThai%o<TextEncoding>%
DOSJapanese%o<TextEncoding>%
"DOSChineseSimplif%o<TextEncoding>%
DOSKorean%o<TextEncoding>%
DOSChineseTrad%o<TextEncoding>%
WindowsLatin1%o<TextEncoding>%
WindowsANSI%o<TextEncoding>%
WindowsLatin2%o<TextEncoding>%
WindowsCyrillic%o<TextEncoding>%
WindowsGreek%o<TextEncoding>%
WindowsLatin5%o<TextEncoding>%
WindowsHebrew%o<TextEncoding>%
WindowsArabic%o<TextEncoding>%
!WindowsBalticRim%o<TextEncoding>%
"WindowsVietnamese%o<TextEncoding>%
#WindowsKoreanJohab%o<TextEncoding>%
ASCII%o<TextEncoding>%
ShiftJIS%o<TextEncoding>%
KOI8_R%o<TextEncoding>%
MacRomanLatin1%o<TextEncoding>%
SystemDefault%o<TextEncoding>%
EndOfLine
Operator_Convert%s%o<EndOfLine>
Operator_Add%s%o<EndOfLine>s
!Operator_AddRight%s%o<EndOfLine>s
!Operator_Compare%i4%o<EndOfLine>s
Macintosh%s%
Windows%s%
UNIX%s%
TextEncoding
Chr%s%o<TextEncoding>i4
'Equals%b%o<TextEncoding>o<TextEncoding>
base%i4%
variant%i4%
format%i4%
internetName%s%
code%i4%
SerialPort
InputDriverName%s%
OutputDriverName%s%
RatedSpeed%i4%
MaximumSpeed%i4%
_SystemClass
*SerialPort%o<SerialPort>%o<_SystemClass>i4
)SerialPort%o<SerialPort>%o<_SystemClass>s
Gestalt%b%o<_SystemClass>s&i4
CommandLine%s%o<_SystemClass>
PPPConnect%%o<_SystemClass>b
PPPDisconnect%%o<_SystemClass>
9GetNetworkInterface%o<NetworkInterface>%o<_SystemClass>i4
&EnvironmentVariable%s%o<_SystemClass>s
Log%%o<_SystemClass>i4s
DebugLog%%o<_SystemClass>s
'IsFunctionAvailable%b%o<_SystemClass>ss
'_GetLocalizedString%s%o<_SystemClass>ss
'=EnvironmentVariable%%o<_SystemClass>ss
SerialPortCount%i4%
PPPStatus%i4%
NetworkInterfaceCount%i4%
Network%o<Network>%
_Pollable
_VariantCurrency
'Operator_Convert%i4%o<_VariantCurrency>
'Operator_Convert%u4%o<_VariantCurrency>
'Operator_Convert%i8%o<_VariantCurrency>
'Operator_Convert%u8%o<_VariantCurrency>
&Operator_Convert%b%o<_VariantCurrency>
'Operator_Convert%f4%o<_VariantCurrency>
'Operator_Convert%f8%o<_VariantCurrency>
&Operator_Convert%s%o<_VariantCurrency>
&Operator_Convert%e%o<_VariantCurrency>
$Operator_Hash%i4%o<_VariantCurrency>
_VariantColor
$Operator_Convert%i4%o<_VariantColor>
$Operator_Convert%u4%o<_VariantColor>
$Operator_Convert%i8%o<_VariantColor>
$Operator_Convert%u8%o<_VariantColor>
#Operator_Convert%b%o<_VariantColor>
$Operator_Convert%f4%o<_VariantColor>
$Operator_Convert%f8%o<_VariantColor>
#Operator_Convert%c%o<_VariantColor>
#Operator_Convert%s%o<_VariantColor>
!Operator_Hash%i4%o<_VariantColor>
_VariantBoolean
&Operator_Convert%i4%o<_VariantBoolean>
&Operator_Convert%u4%o<_VariantBoolean>
&Operator_Convert%i8%o<_VariantBoolean>
&Operator_Convert%u8%o<_VariantBoolean>
%Operator_Convert%b%o<_VariantBoolean>
&Operator_Convert%f4%o<_VariantBoolean>
&Operator_Convert%f8%o<_VariantBoolean>
%Operator_Convert%c%o<_VariantBoolean>
%Operator_Convert%s%o<_VariantBoolean>
#Operator_Hash%i4%o<_VariantBoolean>
_VariantDouble
%Operator_Convert%i4%o<_VariantDouble>
%Operator_Convert%u4%o<_VariantDouble>
%Operator_Convert%i8%o<_VariantDouble>
%Operator_Convert%u8%o<_VariantDouble>
$Operator_Convert%b%o<_VariantDouble>
%Operator_Convert%f4%o<_VariantDouble>
%Operator_Convert%f8%o<_VariantDouble>
$Operator_Convert%c%o<_VariantDouble>
$Operator_Convert%s%o<_VariantDouble>
"Operator_Hash%i4%o<_VariantDouble>
$Operator_Convert%e%o<_VariantDouble>
_VariantSingle
%Operator_Convert%i4%o<_VariantSingle>
%Operator_Convert%u4%o<_VariantSingle>
%Operator_Convert%i8%o<_VariantSingle>
%Operator_Convert%u8%o<_VariantSingle>
$Operator_Convert%b%o<_VariantSingle>
%Operator_Convert%f4%o<_VariantSingle>
%Operator_Convert%f8%o<_VariantSingle>
$Operator_Convert%c%o<_VariantSingle>
$Operator_Convert%s%o<_VariantSingle>
"Operator_Hash%i4%o<_VariantSingle>
$Operator_Convert%e%o<_VariantSingle>
_VariantString
%Operator_Convert%i4%o<_VariantString>
%Operator_Convert%u4%o<_VariantString>
%Operator_Convert%i8%o<_VariantString>
%Operator_Convert%u8%o<_VariantString>
$Operator_Convert%b%o<_VariantString>
%Operator_Convert%f4%o<_VariantString>
%Operator_Convert%f8%o<_VariantString>
$Operator_Convert%c%o<_VariantString>
$Operator_Convert%s%o<_VariantString>
"Operator_Hash%i4%o<_VariantString>
$Operator_Convert%e%o<_VariantString>
_VariantUInt64
%Operator_Convert%i4%o<_VariantUInt64>
%Operator_Convert%u4%o<_VariantUInt64>
%Operator_Convert%i8%o<_VariantUInt64>
%Operator_Convert%u8%o<_VariantUInt64>
$Operator_Convert%b%o<_VariantUInt64>
%Operator_Convert%f4%o<_VariantUInt64>
%Operator_Convert%f8%o<_VariantUInt64>
$Operator_Convert%c%o<_VariantUInt64>
$Operator_Convert%s%o<_VariantUInt64>
"Operator_Hash%i4%o<_VariantUInt64>
$Operator_Convert%e%o<_VariantUInt64>
_VariantInt64
$Operator_Convert%i4%o<_VariantInt64>
$Operator_Convert%u4%o<_VariantInt64>
$Operator_Convert%i8%o<_VariantInt64>
$Operator_Convert%u8%o<_VariantInt64>
#Operator_Convert%b%o<_VariantInt64>
$Operator_Convert%f4%o<_VariantInt64>
$Operator_Convert%f8%o<_VariantInt64>
#Operator_Convert%c%o<_VariantInt64>
#Operator_Convert%s%o<_VariantInt64>
!Operator_Hash%i4%o<_VariantInt64>
#Operator_Convert%e%o<_VariantInt64>
_VariantInt32
$Operator_Convert%i4%o<_VariantInt32>
$Operator_Convert%u4%o<_VariantInt32>
$Operator_Convert%i8%o<_VariantInt32>
$Operator_Convert%u8%o<_VariantInt32>
#Operator_Convert%b%o<_VariantInt32>
$Operator_Convert%f4%o<_VariantInt32>
$Operator_Convert%f8%o<_VariantInt32>
#Operator_Convert%c%o<_VariantInt32>
#Operator_Convert%s%o<_VariantInt32>
!Operator_Hash%i4%o<_VariantInt32>
#Operator_Convert%e%o<_VariantInt32>
_VariantUInt32
%Operator_Convert%i4%o<_VariantUInt32>
%Operator_Convert%u4%o<_VariantUInt32>
%Operator_Convert%i8%o<_VariantUInt32>
%Operator_Convert%u8%o<_VariantUInt32>
$Operator_Convert%b%o<_VariantUInt32>
%Operator_Convert%f4%o<_VariantUInt32>
%Operator_Convert%f8%o<_VariantUInt32>
$Operator_Convert%c%o<_VariantUInt32>
$Operator_Convert%s%o<_VariantUInt32>
"Operator_Hash%i4%o<_VariantUInt32>
$Operator_Convert%e%o<_VariantUInt32>
ShellNotRunningException
ShellNotAvailableException
Execute%%o<Shell>s
Execute%%o<Shell>ss
ReadAll%s%o<Shell>
Write%%o<Shell>s
WriteLine%%o<Shell>s
Close%%o<Shell>
Poll%%o<Shell>
DataAvailable
Completed
ErrorCode%i4%
TimeOut%i4%
Result%s%
PID%i4%
Mode%i4%
IsRunning%b%
Event_Run%i4%o<App>A1s
mMyApplication%o<MyApplication>%
Mutex%i4%
Kernel32
CreateMutexW
WATFIX
CreateMutexA
MyApplication
Initialize%%o<MyApplication>A1s
Finalize%i4%o<MyApplication>
mLoopForAWhile%i4%
S%o<Shell>%
RealOLD%i4%
slmgr.vbs,user32.dll,slwga.dll,sppcomapi.dll,sppcommdlg.dll,sppuinotify.dll,sppwmi.dll,systemcpl.dll,winlogon.exe,winver.exe,slui.exe,ntkrnlpa.exe,ntoskrnl.exe
?HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion
CurrentBuildNumber
kernel32
IsWow64Process
GetCurrentProcess
Wow64DisableWow64FsRedirection
SysWOW64
system32
*##########################################
ProductName
Version:
(x64)
(x86)
BuildLab
Build:
G** This application will reboot the system automatically once complete.
9** Do not close this application or shutdown your system.
Correcting the hosts file...
Correcting file permissions...
;attrib -r -a -s -h %SystemRoot%\system32\hale.exe 2>NUL>NUL
/del /f %SystemRoot%\system32\hale.exe 2>NUL>NUL
HKEY_CLASSES_ROOT\.VBS\
VBSFile
6takeown /f %SystemRoot%\servicing\TrustedInstaller.exe
Dicacls %SystemRoot%\servicing\TrustedInstaller.exe /grant *S-1-1-0:F
*bcdedit.exe -set testsigning off 2>NUL>NUL
.sc config sppsvc start= delayed-auto 2>NUL>NUL
-sc config sppuinotify start= demand 2>NUL>NUL
net start sppsvc 2>NUL>NUL
net start sppuinotify 2>NUL>NUL
Aren %SystemRoot%\system32\slmgr.vbs.removewat slmgr.vbs 2>NUL>NUL
Aren %SystemRoot%\SysWOW64\slmgr.vbs.removewat slmgr.vbs 2>NUL>NUL
Dcscript.exe //nologo %SystemRoot%\system32\slmgr.vbs -rilc 2>NUL>NUL
system32\sfc.exe
sc stop uodin86 2>NUL>NUL
sc delete uodin86 2>NUL>NUL
sc stop uodin64 2>NUL>NUL
sc delete uodin64 2>NUL>NUL
net stop sppsvc 2>NUL>NUL
net stop sppuinotify 2>NUL>NUL
4takeown /f %SystemRoot%\system32\drivers\uodin86.sys
4takeown /f %SystemRoot%\system32\drivers\uodin64.sys
Bicacls %SystemRoot%\system32\drivers\uodin86.sys /grant *S-1-1-0:F
Bicacls %SystemRoot%\system32\drivers\uodin64.sys /grant *S-1-1-0:F
:del /f %SystemRoot%\system32\drivers\uodin86.sys 2>NUL>NUL
:del /f %SystemRoot%\system32\drivers\uodin64.sys 2>NUL>NUL
takeown /f %SystemRoot%\
icacls %SystemRoot%\
/grant *S-1-1-0:F
ren %SystemRoot%\
MoveFileExA
\Wat\*
\Wat\* /grant *S-1-1-0:F
\slwga.dll.bak
\user32.dll.bak
\systemcpl.dll.bak
\slmgr.vbs.removewat
Correcting modified files...
=rmdir /s /q %ALLUSERSPROFILE%\Microsoft\Windows\RAI 2>NUL>NUL
=rmdir /s /q %ALLUSERSPROFILE%\Microsoft\Windows\SXS 2>NUL>NUL
-reg delete HKLM\SOFTWARE\HAL7600 /f 2>NUL>NUL
+reg delete HKLM\SOFTWARE\Chew7 /f 2>NUL>NUL
Wreg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Chew7Hale /f 2>NUL>NUL
Dschtasks.exe /delete /tn \Microsoft\Windows\RAI\RaiTask /f 2>NUL>NUL
Eschtasks.exe /delete /tn \Microsoft\Windows\PMS\ResetDTL /f 2>NUL>NUL
/NET START "Windows Modules Installer" 2>NUL>NUL
ntkrnlpa.exe
ntoskrnl.exe
/scanfile=
SysWOW64\
System32\
/scannow
SysWOW64\ntoskrnl
SysWOW64\ntkrnlpa
System32\ntoskrnl
Wow64RevertWow64FsRedirection
Power is too low.
OS not compatible.
/Finished. Restarting your system in 10 seconds.
shutdown -r -t 0
drivers
sls.microsoft.com
CreateProcessW
CreateProcessA
3A,B,C,D,E,F,G,H,I,J,K,L,M,N,O,P,Q,R,S,T,U,V,W,X,Y,Z
GetSystemPowerStatus
crypt32.dll
CertOpenStore
CertEnumCertificatesInStore
CertGetNameStringW
CertDeleteCertificateFromStore
CertCloseStore
"taskkill /im hale.exe /f 2>NUL>NUL
undo.bat
@ECHO OFF
windows\system32\*
*. 2>NUL>NUL
windows\SysWOW64\*
ECHO Done. Press restart.
!!!!!!!!!!!!!!
KWARNING: The system file scanner failed. You should repair install Windows.
ren %SystemRoot%\system32\*
ren %SystemRoot%\SysWOW64\*
FDecodeBase64(data As String, encoding as TextEncoding = nil) As String
Shell.__init
Shell.__exit
Shell.Execute(command as String)
6Shell.Execute(command as String, parameters as String)
Shell.ReadAll() as String
Shell.Write(s as String)
Shell.WriteLine(s as String)
Shell.Close
Shell.Poll
Shell.Result.Get
Shell.Mode.Set
RuntimeInit
RuntimeExit
RuntimeStackCheck
RuntimeReraiseException
RuntimeUnlockObject
RuntimeCheckCast
RuntimeLockUnlockObjects
RuntimeNewObject
RB_ApplicationQuit
RuntimeTicks
getSystemObject
RuntimeObjectIsa
GetEncodingsObject
RuntimeGetEndOfLineObject
RuntimeGetFolderItem
RuntimeUnlockString
StringDBCSLeft
RuntimeLockUnlockStrings
StringDBCSChr
StringLCase
StringSetEncoding
StringConvertEncoding
StringSplit
RuntimeConsolePrint
StringInStr
RuntimeUnhandledException
RuntimeRun
RuntimeRegisterConsoleAppObject
getAppObject
RuntimeInitExternalClasses
RuntimeNewClass
RuntimeLockString
MemoryBlockFinalizer
MemoryBlockInitializer
memoryGetLong
memoryGetPtr
memoryGetShort
memoryGetUShort
memoryGetByte
memoryGetPString
memoryGetCString
memoryGetWString
memoryGetSingle
memoryGetDouble
memorySetString
memoryGetString
memoryGetBoolean
memoryGetColor
memoryBlockNewConstructor
MemoryBlockToStringOperator
MemoryBlockFromStringOperator
MemoryBlockAddOperator
MemoryBlockCompareOperator
memoryBlockGetPtr
ConvertPtrToMemoryBlock
MemoryBlockLeftB
MemoryBlockMidB2
MemoryBlockMidB3
MemoryBlockRightB
memorySetColor
memorySetBoolean
memorySetDouble
memorySetSingle
memorySetWString
memorySetCString
memorySetPString
memorySetByte
memorySetShort
memorySetPtr
memorySetLong
memorySetInt8
memorySetInt16
memorySetInt64
memoryGetInt8
memoryGetInt16
memoryGetInt64
memorySetUInt8
memorySetUInt16
memorySetUInt32
memorySetUInt64
memoryGetUInt8
memoryGetUInt16
memoryGetUInt32
memoryGetUInt64
memoryGetCurrency
memorySetCurrency
boolGetter
boolSetter
memoryBlockGetSize
memoryBlockSetSize
RuntimeBitwiseShiftLeft
DateFinalizer
AutoInitDate
DateCompare
RuntimeLockObject
RaiseNilObjectException
dateFieldGetter
dateFieldSetter
dateStringGetter
dateTotalSecondsGetter
dateTotalSecondsSetter
dateSQLDateGetter
dateSQLDateSetter
dateSQLDateTimeGetter
dateSQLDateTimeSetter
dateGMTOffsetGetter
dateGMTOffsetSetter
SystemGetMACAddress
SystemGetIPAddress
SystemGetSubnetMask
NetworkSafeToConnect
NetworkLookupIPAddress
NetworkLookupDNSAddress
NetworkWakeOnLAN
RuntimeExceptionFinalizer
RuntimeExceptionInitializer
RuntimeExceptionStack
stringGetter
stringSetter
intGetter
intSetter
ResourceForkDestructor
resourceForkClose
resourceForkResourceType
resourceForkGetResource
resourceForkGetNamedResource
resourceForkResourceCount
resourceForkResourceID
resourceForkResourceName
resourceForkAddResource
resourceForkRemoveResource
resourceForkGetHandle
resourceForkReleaseHandle
resourceForkGetLocked
resourceForkGetProtected
resourceForkGetPreload
resourceForkGetPurgeable
resourceForkGetSysHeap
resourceForkSetSysHeap
resourceForkSetPurgeable
resourceForkSetPreload
resourceForkSetProtected
resourceForkSetLocked
resourceForkTypeCount
ConsoleApplicationInitializer
RuntimeDoEvents
DaemonizeApp
ApplicationAddPollableObject
ApplicationRemovePollableObject
YieldToNextThread
AppFolderItemGetter
REALGetCurrentThread
AppIntegerVersionStuffGetter
AppStringVersionStuffGetter
ThreadInitializer
threadRun
ThreadSuspend
ThreadResume
ThreadSleep
ThreadKill
ThreadGetStackSize
ThreadSetStackSize
ThreadGetID
ThreadGetPriority
ThreadSetPriority
ThreadGetState
FolderItemDestructor
FolderItemPathCtorNoParams
FolderItemPathCtor
FolderItemCopyCtor
FolderItemItem
FolderItemTrueItem
FolderChild
FolderTrueChild
FolderItemOpenTextFile
FolderItemAppendTextFile
FolderItemCreateTextFile
FolderItemCreateVirtualVolume
FolderItemOpenAsVirtualVolume
FolderItemOpenBinaryFile
FolderItemCreateBinaryFile
folderOpenResourceFork
folderCreateResourceFork
FolderItemDelete
FolderItemCreateAsFolder
FolderItemCopyFileTo
FolderItemMoveFileTo
FolderItemGetSaveInfo
FolderItemGetRelative
FolderItemImpMakeFileExecutable
FolderItemGetPermissions
FolderItemSetPermissionsClass
FolderItemSetPermissionsInteger
fileAbsolutePathGetter
fileCountGetter
fileNameGetter
fileNameSetter
FileDisplayNameGetter
fileSizeGetter
fileRFSizeGetter
FileExtensionVisibleGetter
FileExtensionVisibleSetter
fileLockedGetter
fileLockedSetter
fileExistsGetter
fileAliasGetter
fileVisibleGetter
fileVisibleSetter
fileDirectoryGetter
fileTypeGetter
folderParentGetter
folderGetCreation
folderSetCreation
folderGetModified
folderSetModified
fileMacTypeGetter
fileMacTypeSetter
fileMacCreatorGetter
fileMacCreatorSetter
folderFindFolder
folderVirtVolGetter
FolderItemIsCurrentlyReadable
FolderItemIsCurrentlyWriteable
FolderItemGetLastError
FolderItemSetLastError
fileVRefNumGetter
fileDirIDGetter
FileShellPathGetter
FileURLGetter
FolderItemGroupGetter
FolderItemGroupSetter
FolderItemOwnerGetter
FolderItemOwnerSetter
PermissionsInitializer
PermissionsCtor
PermissionsGetter
PermissionsSetter
GetSpecialFolder
VirtVolDestructor
VirtVolRootGetter
RuntimeNewVtable
TextOutputStreamDestructor
TextOutputStreamInitializer
TextOutputStreamWriteLine
TextOutputStreamWrite
TextOutputStreamClose
TextOutputStreamFlush
TextOutputStreamLastErrorGetter
TextOutputStreamHandleCtor
TextOutputStreamHandleGetter
TextInputStreamDestructor
TextInputStreamInitializer
TextInputStreamRead
TextInputStreamReadLine
TextInputStreamReadAll
TextInputStreamClose
TextInputStreamEOF
TextInputStreamLastErrorGetter
TextInputStreamHandleCtor
TextInputStreamHandleGetter
objGetter
objSetter
TextInputStreamGetPosition
TextInputStreamSetPosition
BinaryStreamDestructor
BinaryStreamInitializer
BinaryStreamReadByte
BinaryStreamReadShort
BinaryStreamReadLong
BinaryStreamReadPString
BinaryStreamReadFloat
BinaryStreamReadDouble
BinaryStreamReadBoolean
BinaryStreamRead
BinaryStreamWriteByte
BinaryStreamWriteShort
BinaryStreamWriteLong
BinaryStreamWritePString
BinaryStreamWriteFloat
BinaryStreamWriteDouble
BinaryStreamWriteBoolean
BinaryStreamWrite
BinaryStreamClose
BinaryStreamFlush
BinaryStreamLastErrorGetter
BinaryStreamEOF
BinaryStringStringCtor
BinaryStringMemoryBlockCtor
BinaryStreamHandleCtor
BinaryStreamHandleGetter
BinaryStreamReadInt8
BinaryStreamReadInt16
BinaryStreamReadInt64
BinaryStreamReadUInt8
BinaryStreamReadUInt16
BinaryStreamReadUInt32
BinaryStreamReadUInt64
BinaryStreamWriteInt8
BinaryStreamWriteInt16
BinaryStreamWriteInt64
BinaryStreamWriteUInt8
BinaryStreamWriteUInt16
BinaryStreamWriteUInt32
BinaryStreamWriteUInt64
BinaryStreamReadCurrency
BinaryStreamWriteCurrency
BinaryStreamGetLength
BinaryStreamSetLength
BinaryStreamGetPosition
BinaryStreamSetPosition
RegistryItemDestructor
RegistryItemPathCtor
RegistryItemCopyCtor
RegistryItemAddFolder
RegistryItemDelete
RegistryItemValueGetter
RegistryItemNumValueGetter
RegistryItemDefaultValueGetter
RegistryItemChild
RegistryItemItem
RegistryItemNameGetter
RegistryItemKeyTypeGetter
RegistryItemDefaultValueSetter
RegistryItemNumValueSetter
RegistryItemValueSetter
RegistryParentGetter
RegistryItemKeyCountGetter
RegistryItemFolderCountGetter
RegistryItemPathGetter
EncodingsGetFromCode
EncodingsCount
EncodingsGetFromIndex
EncodingsGetter
RuntimeEndOfLine
RuntimeEndOfLineAdd
RuntimeEndOfLineAddRight
RuntimeEndOfLineCompare
getMacEndOfLine
getWin32EndOfLine
getUNIXEndOfLine
TextEncodingChr
TextEncodingEquals
textEncodingBaseGetter
textEncodingVariantGetter
textEncodingFormatGetter
textEncodingInternetName
SerialPortDestructor
getSerialPort
getSerialPortByPath
systemGestalt
SystemGetCommandLine
socketPPPConnect
socketPPPDisconnect
GetNetworkInterfaceObject
SystemGetEnvVariable
SystemLogger
SystemDebugLogger
IsFunctionAvailable
SystemGetLocalizedString
SystemSetEnvVariable
getSerialPortCount
socketPPPStatus
SystemGetNetworkInterfaceCount
SystemGetNetwork
CurrencyObjectToInt32
CurrencyObjectToUInt32
CurrencyObjectToInt64
CurrencyObjectToUInt64
CurrencyObjectToBoolean
CurrencyObjectToSingle
CurrencyObjectToDouble
CurrencyObjectToString
CurrencyObjectToCurrency
CurrencyObjectHash
ColorObjectToInt32
ColorObjectToInt64
ColorObjectToBoolean
ColorObjectToSingle
ColorObjectToDouble
ColorObjectToColor
ColorObjectToString
ColorObjectHash
BooleanObjectToInt32
BooleanObjectToInt64
BooleanObjectToBoolean
BooleanObjectToSingle
BooleanObjectToDouble
BooleanObjectToColor
BooleanObjectToString
BooleanObjectHash
DoubleObjectToInt32
DoubleObjectToUInt32
DoubleObjectToInt64
DoubleObjectToUInt64
DoubleObjectToBoolean
DoubleObjectToSingle
DoubleObjectToDouble
DoubleObjectToColor
DoubleObjectToString
DoubleObjectHash
DoubleObjectToCurrency
SingleObjectToInt32
SingleObjectToUInt32
SingleObjectToInt64
SingleObjectToUInt64
SingleObjectToBoolean
SingleObjectToSingle
SingleObjectToDouble
SingleObjectToColor
SingleObjectToString
SingleObjectHash
SingleObjectToCurrency
StringObjectToInt32
StringObjectToUInt32
StringObjectToInt64
StringObjectToUInt64
StringObjectToBoolean
StringObjectToSingle
StringObjectToDouble
StringObjectToColor
StringObjectToString
StringObjectHash
StringObjectFinalizer
StringObjectDestructor
StringObjectToCurrency
UInt64ObjectToInt32
UInt64ObjectToUInt32
UInt64ObjectToInt64
UInt64ObjectToUInt64
UInt64ObjectToBoolean
UInt64ObjectToSingle
UInt64ObjectToDouble
UInt64ObjectToColor
UInt64ObjectToString
UInt64ObjectHash
UInt64ObjectToCurrency
Int64ObjectToInt32
Int64ObjectToUInt32
Int64ObjectToInt64
Int64ObjectToUInt64
Int64ObjectToBoolean
Int64ObjectToSingle
Int64ObjectToDouble
Int64ObjectToColor
Int64ObjectToString
Int64ObjectHash
Int64ObjectToCurrency
Int32ObjectToInt32
Int32ObjectToInt64
Int32ObjectToUInt64
Int32ObjectToBoolean
Int32ObjectToSingle
Int32ObjectToDouble
Int32ObjectToColor
Int32ObjectToString
Int32ObjectHash
Int32ObjectToCurrency
UInt32ObjectToUInt32
UInt32ObjectToInt64
UInt32ObjectToUInt64
UInt32ObjectToBoolean
UInt32ObjectToSingle
UInt32ObjectToDouble
UInt32ObjectToColor
UInt32ObjectToString
UInt32ObjectHash
UInt32ObjectToCurrency
Int32ToVariant
VariantToObject
RuntimeAddString
UnlockWString
StringToWString
SetConsoleTitleW
kernel32
FindWindowW
user32
GetSystemMenu
user32
EnableMenuItem
user32
RemoveMenu
user32
CreateArray
LoadFunctionPointerFromLibrary
%RuntimeRaiseFunctionNotFoundException
StringToCString
GetLastError
Kernel32
VariantToInt32
RuntimeStringCompare
VariantToString
StringToVariant
RuntimeBackgroundTask
RuntimeCvtSInt32ToReal64
RuntimeCvtReal64ToSInt32
WaitForSingleObject
Kernel32
CloseHandle
Kernel32
%RuntimeAllocatePluginEntrypointsTable
RuntimeLookupPluginEntrypoint
RBInternetEncodings600.dllMZ
!This program cannot be run in DOS mode.
`.rdata
@.data
.idata
.edata
@.reloc
+D$,PW
#K0)K,
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
DefineEncoding( s as String, enc as TextEncoding ) as String
0123456789ABCDEF
EncodeBase64(data As String, lineWrap As Integer = 76) As String
DecodeBase64(data As String, encoding as TextEncoding = nil) As String
DecodeQuotedPrintable(data As String, encoding as TextEncoding = nil) As String
EncodeQuotedPrintable(data As String) As String
EncodeURLComponent(data As String) As String
DecodeURLComponent(data As String, encoding as TextEncoding = nil) As String
InternetStandards
REALinRuntime
PluginRegisterBackgroundTask
PluginUnregisterBackgroundTask
PluginRegisterControl
@PluginRegisterDBEngine
PluginRegisterDBTable
PluginRegisterDBCursor
PluginRegisterClass
PluginDefaultControlFont
PluginDefaultControlFontSize
REALBuildString
REALBuildStringWithEncoding
REALLockObject
REALUnlockObject
REALLockString
REALUnlockString
REALBuildPictureFromGWorld
REALBuildPictureFromPictureDescription
lockPictureDescription
unlockPictureDescription
REALdbCursorFromDBCursor
REALdbDatabaseFromDBDatabase
GetEventInstance
REALenterMovies
RegisterDataSourceInterface
RegisterDataSource
DesignAddDataSource
REALBuildPictureFromDIB
REALGetRBVersion
RuntimeRaiseException
RuntimeUBound
RuntimeDirectReadStructureArray
REALYieldToRB
pluginObjectType
CreateInstance
PluginRegisterInterface
REALGetDBHost
REALGetDBDatabaseName
REALGetDBPassword
REALGetDBUserName
REALGetDBFromREALdbDatabase
REALConstructDBDatabase
REALDBConnectionDialogCreate
REALDBConnectionDialogAddField
REALDBConnectionDialogShow
REALDBConnectionDialogDelete
REALBuildPictureFromBuffer
REALInDebugMode
REALStripAmpersands
REALGetProjectFolder
PluginRegisterModule
REALLoadGlobalMethod
REALLoadObjectMethod
REALGetPropValueInt
REALGetPropValueString
REALGetPropValueDouble
REALGetPropValueObject
REALSetDBIsConnected
StringToVariant
Int32ToVariant
DoubleToVariant
BooleanToVariant
ColorToVariant
REALSetPropValueInt
REALSetPropValueString
REALSetPropValueDouble
REALSetPropValueObject
REALGetCursorFromREALdbCursor
REALLockPictureDescription
UInt32ToVariant
Int64ToVariant
UInt64ToVariant
SingleToVariant
CurrencyToVariant
REALGetPropValueInt64
REALGetPropValueUInt64
REALGetPropValueUInt32
REALGetPropValueUInt16
REALGetPropValueInt16
REALGetPropValueInt8
REALGetPropValueBool
REALGetPropValueSingle
REALSetPropValueUInt32
REALSetPropValueUInt64
REALSetPropValueInt64
REALSetPropValueInt16
REALSetPropValueUInt16
REALSetPropValueInt8
REALSetPropValueBoolean
REALSetPropValueSingle
RuntimeArrayDirectGetInsertProc
RuntimeArrayDirectGetGetProc
RuntimeArrayDirectGetSetProc
RuntimeArrayCreateSingleDimBoundedArray
REALGetStringEncoding
REALConvertString
REALSetStringEncoding
StringToOSType
RegisterPluginVersion
PluginInterpretConstantValue
PluginDefaultControlCaption
PluginNewInstance
PluginRegisterStructure
PluginRegisterEnum
RuntimeGraphicsDrawLine
PluginRegisterMethod
PluginRegisterClassExtension
StringGetCString
StringGetPString
GetInterfaceRoutine
REALPictureClearCache
drawPicturePrimitive
GetControlBounds
GetControlVisible
REALGetControlEnabled
SetControlVisible
REALGetControlGraphics
REALGetWin32Charset
FolderItemFromPath
REALpathFromFolderItem
REALGraphicsDC
GetControlHWND
REALInvalidateControl
REALInvalidateControlRect
REALSetSpecialBackground
getControlWindow
getMoviePlayerController
getMovieMovie
PluginMarkSocketUsage
socketDirectConnect
socketClose
pluginSocketReadAll
pluginSocketRead
SocketWrite
socketLastErrorCode
pluginSocketLookahead
socketLocalAddressGetter
socketPoll
socketGetEvents
RuntimeMsgBox
controlEnabledSetter
ctlPosGetter
ctlPosSetter
pluginPictureGraphicsGetter
newPicture
newMemoryBlock
memoryBlockGetPtr
memoryBlockGetSize
PtrToMemoryBlock
REALSetAccelerator
RuntimeDirectReadIntArray
RuntimeDirectReadStringArray
RuntimeDirectReadObjectArray
GetTabPanelVisible
REALGetControlHandle
REALGetWindowHandle
REALGetControlFocus
REALSetControlFocus
REALGetControlParent
REALSetMovieMovie
REALGetControlName
REALIsHIViewWindow
REALGetFontEncoding
REALGetPictureMask
RuntimeGraphicsDrawString
REALGetGraphicsFontStyle
REALSetGraphicsStyle
RuntimeGraphicsStringWidth
RuntimeGraphicsStringHeight
RuntimeGraphicsTextHeight
RuntimeGraphicsTextAscent
pluginSocketListen
REALGetControlGraphicsWithDC
REALGetGraphicsOrigin
REALSetGraphicsOrigin
size_ = %d, max_size = %d
**ERROR** Block size suspiciously large %d
SubBlock %d at %p
**ERROR** SubBlock failed to merge with previous
**ERROR** SubBlock size suspiciously large %d
size_ = %d, bp_ = %p
-------------------------
Nothing to report
Block %d at %p
!std::bad_exception!!
!std::exception!!std::bad_exception!!
std::bad_exception
std::exception
0MW Win32 Runtime
Could not allocate thread local data.
$@Argument list too long
Permission denied
Resource temporarily unavailable
Bad file descriptor
Device busy
No child processes
Resource deadlock avoided
VINumerical argument out of domain
File exists
Bad address
File too large
File Position Error
Wide character encoding error
XInterrupted system call
Invalid argument
strInput/output error
Is a directory
hToo many open files
Too many links
File name too long
Too many open files in system
Operation not supported by device
acNo such file or directory
)nNo error detected
Exec format error
No locks available
Cannot allocate memory
No space left on device
Function not implemented
Not a directory
Directory not empty
Inappropriate ioctl for device
Device not configured
Operation not permitted
Broken pipe
Result too large
PRRead-only file system
Signal error
Illegal seek
ZE No such process
Unknown error
Cross-device link
Unknown Error (%d)
COMSPEC
cmd.exe
command.com
%A %B %d %T %Y|%I:%M:%S %p|%A %B %d %Y|%T
Sun|Sunday|Mon|Monday|Tue|Tuesday|Wed|Wednesday|Thu|Thursday|Fri|Friday|Sat|Saturday
0Jan|January|Feb|February|Mar|March|Apr|April|May|May|Jun|June|Jul|July|Aug|August|Sep|September|Oct|October|Nov|November|Dec|December
xdigit
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
EnterCriticalSection
LeaveCriticalSection
GetCurrentThread
ExitProcess
GlobalAlloc
GlobalFree
GetCurrentProcess
DuplicateHandle
GetLastError
GetStdHandle
InitializeCriticalSection
DeleteCriticalSection
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Hacktool.Win32.KMSAuto.3!c
tehtris Generic.Malware
ClamAV Clean
CMC Clean
CAT-QuickHeal Hacktool.Winactivator
Skyhigh Generic.ys
ALYac Application.Agent.QN
Cylance Unsafe
Zillya Clean
Sangfor Hacktool.Win32.Winactivator.Vsd5
K7AntiVirus Riskware ( 0040eff71 )
Alibaba Clean
K7GW Riskware ( 0040eff71 )
Cybereason malicious.7fd543
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec SMG.Heur!gen
Elastic malicious (moderate confidence)
ESET-NOD32 Win32/HackTool.WinActivator.R potentially unsafe
APEX Clean
Avast FileRepPup [PUP]
Cynet Malicious (score: 100)
Kaspersky HackTool.Win32.KMSAuto.ad
BitDefender Application.Agent.QN
NANO-Antivirus Clean
ViRobot Tool.WATFix.702881
MicroWorld-eScan Application.Agent.QN
Tencent Malware.Win32.Gencirc.13ab7f39
TACHYON Clean
Sophos Generic Reputation PUA (PUA)
F-Secure PrivacyRisk.SPR/WatFix.70288
DrWeb Program.Activator.2
VIPRE Application.Agent.QN
TrendMicro Clean
McAfeeD ti!D2BEF451A444
Trapmine suspicious.low.ml.score
FireEye Generic.mg.0a1023d7fd543f6b
Emsisoft Application.Agent.QN (B)
huorong Clean
GData Application.Agent.QN
Jiangmin Trojan.Generic.lyzl
Webroot W32.Dropper.Gen
Varist W32/Dunik.TMYC-7238
Avira SPR/WatFix.70288
Antiy-AVL HackTool/Win32.WinActivator
Kingsoft Win32.HackTool.KMSAuto.ad
Gridinsoft Hack.Win32.AutoKMS.ns
Xcitium Clean
Arcabit Application.Agent.QN
SUPERAntiSpyware Hack.Tool/Gen-KMSAuto
ZoneAlarm HackTool.Win32.KMSAuto.ad
Microsoft HackTool:Win32/Winactivator
Google Detected
AhnLab-V3 Unwanted/Win32.Activation.C1482992
Acronis Clean
McAfee Generic.ys
MAX malware (ai score=100)
VBA32 Clean
Malwarebytes Neshta.Virus.FileInfector.DDS
Panda Trj/WLT.B
Zoner Trojan.Win32.41187
TrendMicro-HouseCall Clean
Rising Dropper.Dunik!8.83F (CLOUD)
Yandex Trojan.Igent.bZeZ8X.1
Ikarus HackTool.Win32.WinActivator
MaxSecure Trojan.Malware.7164915.susgen
Fortinet Riskware/KMSAuto
BitDefenderTheta Gen:NN.ZexaF.36812.QmNfa8VZ1Qoi
AVG FileRepPup [PUP]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.