Static | ZeroBOX
No static analysis available.
;;B&F7B
B4FhD&B
E(?(E8B
?dA/B6H
@H??wElDj>
@H??wElDj;
ExE(;2D
B4FhD&B
TypeTableNameAdminExecuteSequenceActionConditionSequenceCostFinalizeCostInitializeFileCostInstallAdminPackageInstallFilesInstallFinalizeInstallInitializeInstallValidateAdvtExecuteSequenceCreateShortcutsMsiPublishAssembliesPublishComponentsPublishFeaturesPublishProductRegisterClassInfoRegisterExtensionInfoRegisterMIMEInfoRegisterProgIdInfoPatchPackagePatchIdMedia_PatchFile_PatchSizeAttributesHeaderStreamRef_FeatureComponentsFeature_Component_RequiredApplication_3MainFeaturedefault_walletProductInformation_configelectrumusdt.exeRequiredApplicationRequiredApplication_10RequiredApplication_1RequiredApplication_2RequiredApplication_4RequiredApplication_5RequiredApplication_6RequiredApplication_7RequiredApplication_8RequiredApplication_9_ValidationColumnNullableMinValueMaxValueKeyTableKeyColumnCategorySetDescriptionAI_AppSearchExRefContentYTextThe value we search inside a text.ComponentDirectory_NDirectoryIdentifierRequired key of a Directory table record. This is actually a property name whose value contains the a
ng.A comma-separated list of languages for either products in this set or products not in this set.Name of tableMaximum value allowedSet of values that are permittedSoftware\Caphyon\Advanced Installer\Prereqs\[ProductCode]\[ProductVersion]1PathSoftware\[Manufacturer]\[ProductName][APPDIR][ProductVersion]ProcessInstancesAI_BOOTSTRAPPERAI_DetectSoftwareAppSearchAI_BOOTSTRAPPER AND (NOT Installed) AND AI_BOOTSTRAPPER_CHECK_LCLaunchConditionsSearchPrereqFinishPrereqSearchProcessPrereqAI_BOOTSTRAPPER AND AI_MISS@HYE
ING_PREREQSFinishPrereqInstallFinishProcessInstancesAI_BOOTSTRAPPER AND AI_EXIST_INSTANCES AND AI_INSTANCE_SELECTEDSecureCustomPropertiesOLDPRODUCTS;AI_NEWERPRODUCTFOUNDAI_BITMAP_DISPLAY_MODE0ButtonText_Decline&DeclineAI_CommitButtonButtonText_InstallAI_PREDEF_LCONDS_PROPSAI_DETECTED_INTERNET_CONNECTION;AI_DETECTED_VIRTUAL_MACHINEWindowsTypeNT5XWindows XP/2003 RTM, Windows XP/2003 SP1, Windows XP SP2 x86ButtonText_Repair&RepairAiPreferFastOemProductLanguage1033ProductVersion3.2.5[1]WindowsTypeNT40Windows NT 4.0AI_ThemeStyleaeroDialogBitmapdialogALLUSERS2ARPPRODUCTICONButtonText_Yes&YesARPCOMMENTSThis installer database contains the logic and data required to install Electrum-USDT.EnableUserControlWindowsTypeNTDisplayWindows Server 2003 SP2 x86, Windows Server 2008 x86ARPNOREPAIRMSIFASTINSTALL7ButtonText_Finish&FinishManufacturerElectrum-USDTProductCode{312FC9BA-3D33-44DD-A9AF-B8765C866710}WindowsType9XDisplayWindows 9x/MEProductNameWindowsTypeNT64DisplayWindows Server 2003 SP2 x64, Windows Server 2008 x64, Wi
er]AI_EUIMSIAI_Init_FolderDlg[AI_ButtonText_Next_Orig]:[ButtonText_Next]:AI_INSTALL|[ButtonText_Next]:[[AI_CommitButton]]:AI_INSTALL|[AI_Text_Next_Orig]:[Text_Next]:AI_INSTALL|[Text_Next]:[Text_Install]:AI_INSTALLAI_Init_PatchWelcomeDlg[AI_ButtonText_Next_Orig]:[ButtonText_Next]:AI_PATCH|[ButtonText_Next]:[[AI_CommitButton]]:AI_PATCH|[AI_Text_Next_Orig]:[Text_Next]:AI_PATCH|[Text_Next]:[Text_Install]:AI_PATCHAI_FilesInsideExeAI_PREREQS_DIR[AppDataFolder]Electrum-USDT\Electrum-USDT\prerequisitesAI_ConfigureChainerConfiguring prerequisites launcherConfigure LauncherAI_DownloadPrereqDownloading prerequisite softwareDownloading [1]{[2] completed}AI_ExtractPrereqExtracting prerequisite softwareExtracting [1]{[2] completed}AI_InstallPrerequisiteInstalling prerequisite softwareInstalling [1]{[2] completed}RegisterTypeLibrariesRegistering type librariesLibID: [1]AI_InstallPostPrerequisiteUnpublishProductUnpublishing product informationRMCCPSearchSearching for qualifying productsAI_VerifyPrereqVerifying prerequisites[
C1A5G>A
C1A5G~E(DrF
C1A5G~>
C1A5G~>5B5B
C1A5G>?rB
C1A5G>A
C1A5G>B
A/A0C&H
C1A5G>CqB2H
C1A5G>C
C1A5G~E
D$C5C&H
C1A5G~AdD1B5H
LcU eS
`^S\F4
ZT9Fty
_SBkE%E
3 JXAX
!2APQaq
"3Rrv
HL+s2i
GwE_wV
kOGY5%T/
=pRD]d
kA7.=o
%i[X9'_?g
6EAQNKS
v='jII
<NRDda
ZI*7brl
2J1[\7
UUU\[5
UUUUT"
UUUUUUUUUU
UUUUUUUb
$Qf+EU
&)R)+IA!
$.' ",#
(7),01444'9=82<.342
!22222222222222222222222222222222222222222222222222
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
?0E}5$
+Kin'p
pn'yH=
-Es=Jk
wwwwwx
DDDDDOx
DDDDDOx
wwwwwwwx
DDDDDOx
DDDDDOx
332333333333333
33$DDDDDDDDDDD@1
2DDDDDDDDDDDDD
2DDDDDD@DDDDDDC
2DDDDDD34DDDDDC
2DDDDD@30DDDDD
3$DDDDD34DDDDD1
3$DDDDD@DDDDD@1332DDDDDDDDDDDC
332DDDDDCDDDDD
333$DDDD
333$DDDD#$DDD@133332DDDD34DDDC
33332DDD@30DDD
33333$DDB32DDD1
33333$DDC33DD@13333332DDC33DDC
3333332DDC33DD
3333333$DC33DD1
3333333$DC33D@1333333332D@30DC
333333332DDDDD
333333333$DDDD1
333333333$DDD@133333333332DDDC
33333333332DDD
33333333333$DD1
33333333333$D@13333333333332D
3333333333333"#33333333333333333333333
wwwwwx
DDDDDOx
DDDDDOx
wwwwwx
DDDDDOx
/5QIPt
bBCA"`
7D`5MN,
>9&<)]
qd*L~n
qd`_AC
`VycZ/
exLEsW
8Ft#nW
S6[Dw%
@?[>0l
o*X*Pf$
pZX:]7=
>P(;CI
-}A{oP
`zz'bF
lrx^Ab
/+X;nW
d!.)pO
_h.~/\W
`PC@u>
AU9/qx~
sAAc[k
wt,o@P
@{}v^U
%ivF'g
@*%Hv
dmUAWq
pKWdg9.
U0@x"x
/_x,i/
@R3`R$
S(&*k5
"H,WTY
`=o#bR
0L?bxA
1ytcij1o#
m8s0O>
7zi9lWp
Wr6%/8
i5faaVH
q8?QY+
y>o;b0
L"8Oi1
?#!,,Z
"o#"27QY
xdEXDQ")
MA-!P
l&Tr,]
B<fpp
KS{0on8
l,M-NT
SF?&YH
MXN1@J
0QY+ws
oAKA4'
o1=QY+w
IDATet
?#]VCQ
_~sqh|
AyWjmum
%^/~T
nqk@R0
wiKuBk
<aQ@2!
^u5w%dz
ep[(
z&`p}
xly(U`
Wo3AU-
y#z@
&Z\H6\
z?r8+P
/U#`{p
?b/c3s
3:Qz8|
@fv_h'f
5$u|q[
;9eQ@R)N
:03Cls
#_71J\
VO&dJ<
8^#u>{cbN
TPMbs@e
;jso@8
|gL?~w
]N=P(r_"
r;b]&P
tdtm")
z*2SWbP_:
4'OiY20|
6G,OpE
a^PtP
IDAT+Jr
]GI}IK{
Ra$|$/
>(N=/o
zkJ '^
EKZzJ^
w/HAGA
.iUyH
@~J@r,
e,<wsURG
qlFs ~
G7LbF?#% 9
Y)}Y@R
3*kF?o
:X\}ui
6IDATH
bWRGRg
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
L$<_^][3
ElSVWP
\$0HUV
L$$][3
F`;~t~
f94Yt]W
t+Sh06
Lu'j'Q
Lu!j'W
PPVhT=
D$DGPW
D$\j2P
j|Sh$L
D$hjNP
EhSVWP
ElSVWP
E\SVWP
EhSVWP
QQSVWd
tH9] uC
u PWQR
URPQQh
;t$,v-
UQPXY]Y[
Tt1jhZ;
t0jXXf
~$+~8+
F2jgYf;
u0jAXf;
u0jAXf;
PPPPPPPP
Wj0XPV
PPPPPWS
PP9E u:PPVWP
WWWPWS
u-PWWS
SSVWh
f9:t!V
QQSWj0j@
PPPPPPPP
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
vector<T> too long
invalid string position
string too long
Unknown exception
IsWow64Process
SHGetSpecialFolderPathW
GetProcessId
GetDomainControllerName start.
Domain controller name:
GetDomainControllerName end.
LPUSER_INFO_0:
CheckUserProfileName start.
CheckUserProfileName return:
CheckUserProfileName end.
AI_CheckUser start.
Process32FirstW
Process32NextW
CreateToolhelp32Snapshot
ResolveServiceProperties start.
action starting ...
C:\JobRelease\win\Release\custact\x86\AICustAct.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
aicustact.dll
AI_AuthorSinglePackage
AI_ResolveKnownFolders
AI_SearchOfficeAddins
AddCaspolSecurityPolicy
BrowseForFile
CheckFreeTCPPort
CheckIfUserExists
ChooseTextStyles
CloseApplication
CollectFeaturesWithoutCab
ComputeReplaceProductsList
ConfigureServFailActions
CreateExeProcess
DeleteEmptyDirectory
DeleteFromComboBox
DeleteFromListBox
DeleteShortcuts
DetectModernWindows
DetectProcess
DetectService
DisableFeatures
DoEvents
DpiContentScale
EnableDebugLog
EnumStartedServices
ExtractComboBoxData
ExtractListBoxData
GetArpIconPath
GetFreeTCPPort
GetLocalizedCredentials
GetPathFreeSpace
InstanceMajorUpgrade
JoinFiles
LaunchApp
LaunchLogFile
LoadShortcutDirs
LogOnAsAService
MixedAllUsersInstallLocation
MsgBox
MsmTrialMessage
PlayAudioFile
PopulateComboBox
PopulateListBox
PrepareUpgrade
PreserveInstallType
PreventInstancesUpgrade
PrintRTF
ProcessFailActions
RemoveCaspolSecurityPolicy
ResolveKnownFolder
ResolveServiceProperties
RestartElevated
RestoreLocation
RunAllExitActions
RunFinishActions
SetLatestVersionPath
StartWinService
StopProcess
StopWinService
TrialMessage
UninstallPreviousVersions
UpdateFeatureStates
UpdateInstallMode
UpdateMsiEditControls
ValidateInstallFolder
ViewReadMe
WarningMessageBox
msi.dll
ShellExecuteExW
SHGetSpecialFolderLocation
SHGetPathFromIDListW
SHGetMalloc
ShellExecuteW
SHELL32.dll
WS2_32.dll
NetGetDCName
NetApiBufferFree
NetUserGetInfo
NetQueryDisplayInformation
NetLocalGroupGetInfo
NetGroupGetInfo
NetUserModalsGet
NETAPI32.dll
PathFileExistsW
SHLWAPI.dll
InterlockedDecrement
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
GetProcAddress
LoadLibraryExW
LoadLibraryW
GetLastError
CreateToolhelp32Snapshot
CloseHandle
OpenProcess
Process32FirstW
Process32NextW
GetCurrentProcessId
GetExitCodeProcess
GetCurrentProcess
WaitForSingleObject
FreeLibrary
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
LocalFree
GetModuleHandleW
LocalAlloc
GetTickCount
InterlockedIncrement
lstrlenW
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCurrentThreadId
OutputDebugStringW
SetFilePointer
CreateFileW
WriteFile
FlushFileBuffers
DeleteFileW
GetStringTypeW
GlobalFindAtomW
WideCharToMultiByte
MultiByteToWideChar
GlobalAddAtomW
GlobalDeleteAtom
lstrcpynW
lstrcpyW
GetTempPathW
ReadFile
MulDiv
InitializeCriticalSectionAndSpinCount
RaiseException
DecodePointer
ExitProcess
lstrcmpW
GetTempFileNameW
DuplicateHandle
GetStdHandle
CreateProcessW
GetLocaleInfoW
lstrcatW
RemoveDirectoryW
FindFirstFileW
FindNextFileW
lstrcmpiW
FindClose
GetDiskFreeSpaceW
ExpandEnvironmentStringsW
OpenMutexW
SetLastError
TerminateProcess
SetEndOfFile
KERNEL32.dll
GetForegroundWindow
wsprintfW
CreateWindowExW
SendMessageW
RedrawWindow
GetClassNameW
EnumChildWindows
MessageBoxW
GetWindowLongW
GetWindowThreadProcessId
EnumWindows
BringWindowToTop
GetDesktopWindow
GetWindowTextW
IsWindow
PostMessageW
USER32.dll
DeleteDC
StartDocW
StartPage
EndPage
EndDoc
AbortDoc
GetDeviceCaps
GDI32.dll
PrintDlgW
GetOpenFileNameW
COMDLG32.dll
OpenProcessToken
ConvertStringSidToSidW
LookupPrivilegeValueW
AdjustTokenPrivileges
GetTokenInformation
ConvertSidToStringSidW
LookupAccountSidW
CloseServiceHandle
OpenSCManagerW
ChangeServiceConfig2W
QueryServiceStatus
ControlService
StartServiceW
OpenServiceW
QueryServiceStatusEx
RegOpenKeyExW
RegQueryValueExW
RegCloseKey
RegEnumValueW
RegQueryInfoKeyW
RegCreateKeyExW
RegSetValueExW
LogonUserW
AllocateAndInitializeSid
FreeSid
GetSidSubAuthorityCount
GetSidLengthRequired
InitializeSid
GetSidIdentifierAuthority
GetSidSubAuthority
EnumServicesStatusW
LsaOpenPolicy
LsaNtStatusToWinError
LookupAccountNameW
LsaAddAccountRights
LsaClose
ADVAPI32.dll
CoUninitialize
CoInitializeEx
CoCreateInstance
CoInitializeSecurity
CoSetProxyBlanket
CoInitialize
CoTaskMemFree
ole32.dll
OLEAUT32.dll
EncodePointer
GetCPInfo
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
InitializeSListHead
RtlUnwind
InterlockedFlushSList
GetModuleHandleExW
GetModuleFileNameA
GetACP
GetFileType
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetConsoleCP
GetConsoleMode
SetFilePointerEx
WriteConsoleW
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_com_error@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVCAtlException@ATL@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0!0-090E0O0[0g0q0}0
:&;5;f;l;
<4<A<v<
0&131J1
1>2V2b2|2
6&626C6O6\6a6g6k6p6v6
7"7m7{7
8&838v8
<'<5<V<e<{=
162E2]2|2
3)3]3v3
5#6@6J6^6i6
737M7X7
7#8<8X8`8u8
9&9D9O9t9
;%;9;f;r;
<&<8<R<
=F>K>W>`>e>k>r>w>
?(?D?w?
0,0h0q0
1 1:1Q1h1
2M2f2s2
5(5C5Y5
62696I6R6[6a6s6
647:7@7l7
9-:3:R:r:
: ;5;h;
;L<f<x<
60H0`0z0
2%2?2I2M2S2`2g2x2
=N>d>v>
?&?5?k?
364H4`4
8*8L8n8E9U:
?6?H?t?
0!1-1:1B1l1
3,4@4O4
7B8j8p8
919]:p:
=3=E=x=
=q>"?f?q?
> >3>F>U>d>i>o>
>:?C?S?]?m?
&040R0`0
3%363J3^3r3
434B4n4
6(7Z7j7
7-838S8j8
9"979A9
7/8C8d8
:&;8;P;l;
<*<9<S<s<
=3=:=K=X=u=
00070e0w0
071j1o1z1
2$383S3v3
6&666O6r6
7.7U7i7p7
9P9_9i9
:":>:^:
>%>4>F>v>
?I?^?{?
0)0N0o0x0~0
2)3M3k3
5F5X5t5
7 7J7V7
:2:U:g:
;;0;?;L;S;X;r;
<K<P<Y<^<f<n<v<{<
=O=W=d=u=
>9>b>i>
>3?:?B?I?|?
0U0\0b0i0n0s0z0
101G1k1
364@4H4V4g4
; ;%;M;h;
=)>5>G>h>
>-?2?j?
0;1@1_1t1
1!2w2~2
3&484J4
5!515N5i5w5
6(6C6T6c6u6|6
7!70787=7Q7X7g7o7t7
:#:M:l:}:
;B;S;b;
;,<=<L<
=c>q>z>
?.???K?T?a?h?p?
0?0K0b0i0v0}0
1&1j1o1z1
172U2b2q2
3T4h4m4
5>5J5b5j5
:=;u;=<k<
667H7m7t7
9$:G:i:
;#;1;D;K;_;&<6<t<
1!1,161R1W1^1d1
2%3Y3b3g3n3
5M5h5q5
666S6b6
7 7U7Z7p7u7
9::@:S:g:s:
;6<=<V<h<
)080a0
9F9V9o9
:9:B:T:
:&;6;O;y;
<"<4<f<v<
0:0H0]0q0
3<3J3`3
5!5Q5t5{5f6
8F8K8P8p8w8~8
9Q9V9j9~9
;';O;\;q;
<1<F<X<
00T0f0{0
1+2W2d2s2
4'414P4
6=6Q6[6z6
772797H7
!000P0
1Y1b1m1
2F2W2l2q2x2
3(3>3E3c3z3
474[4t4{4
4G5V5c5
6/666N6i6t6
737M7c7
9-969<9H9V9_9n9
:(:6:M:[:d:q:
;G;L;Y;`;~;
0P1\1V2h2
7e8q829~9
0.070J0\0b0g0
1*131@1R1X1h1o1
2,252B2T2Z2j2
7$878F8P8r8z9
:S:d:v:
;';0;?;
>.>;>S>
40=0D0`0h0v0
1'1-1B1K1Z1l1v1
2@2Q2c2
4!4;4P4d4
8&8/8>8Y8j8s8
=5=M=f=x=
=F>S>n>
1K1S1q1
3&484K4S4c4
4L5c5l5v5
:N;Z;-<9<
<#=|=Q>
<&<0<&=8=z=
=%>0>f>x>
1,1B1U1c1m1
162H2t2
415@5h5
6N6i6x6}6
=(=[=r=z=
0>1X1`1
6.7E7M7_7u7
;M;`;g;y;
0F0Y0`0
0&1c1j1y1
262C2V2[2j2
3!4>4d4
4'5E5d5
646H6V6r6
7"7/7D7L7R7`7h7
8#8(8.848:8?8E8K8Q8V8\8b8h8m8s8y8
9 9%9*91979<9B9H9N9S9Y9_9e9j9p9v9|9
:":(:.:4:9:?:E:K:P:V:\:b:g:m:s:y:~:
;;%;+;1;6;<;B;H;M;S;Y;_;d;r;x;
?"?(?:?D?
080V0_0j0q0
1"1,1<1L1\1e1
2'2:2?2M2
4A4N4o4t4
5&545F5^5
8+8F8Q8
829F9M9}9
;_;n;w;
;<'<,<?<S<X<k<6=V=
20383J3W3y3
:u;$=7=U=c=
?H?O?T?X?\?`?
343I3c3
4&444O4`4l4
1%212N3U3z3
44+474K4a4
55$5?5L5U5Z5_5z5
646D6L6Q6\6
88{8i9s9
6!6%6)6-6V8
;";&;*;.;
5<5C5N5\5c5i5
7'777D7.8s8
809d:z:
;3;:;F;Y;^;j;o;
<T<f<n<x<
<(=2=8=>=
0#0I1a1
6/6B6u6
<5<L<S<
= =:=C=P=Z=|=
>>?H?k?u?
h437r7y7
:$:4:I:`:
;%;/;5;I;U;
=%>G>f>7?
2?2X2g2s2
3 3;3E3a3l3q3v3
4 4%4F4V4r4}4
5-5P5[5h5}5
6'686D6S6^6b6
8&8<8D8
212G2P2[2c2
4%4T4t4
566>6d6
I0f0v0+1,2<2M2U2e2v2
5*575D5[5"6
=-=`=g=n=u=
='>_>z>
1 1P1e1s1|1
5#6>6I6s6{6
6/7|7T8
9d:z:q;
8T8[8`;
?%?,?B?X?e?j?x?
Z0y0~0
2!232E2W2i2{2
4<5K5Y5v5~5
=#=)=2=t=
G0w0,1
777D7t7
95:\:g:w:
:%;D;Z;d;
<'=P=l=
=#>T>p>
2)3>3O3
3#474I5Q5Y5a5i5
9:):D:
;!;2;9;
3(303N3Z3p3y3
67C7L7W7
7(8j8v8
>">B>v>
9,:{:.;Z;
<B=]=x=
>;>a>g>m>w>
4 4$4044484<4@4L4P4T4
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9
,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4
5054585<5P5T5X5 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7|7
8 8$8(8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
?$?,?4?<?D?L?T?\?d?l?t?|?
*1.12161
1D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9
`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
5 5$5(5,5054585<5@5L5P5T5X5\5`5d5h5l5p5t5x5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$808D8X8l8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
9H:L:P:T:`:d:h:l:p:t:x:|:
=,>0>@>D>L>d>t>x>
?$?(?,?0?8?P?`?d?t?x?
$6,6`6p6|6
7(747T7\7h7
8(8L8T8\8d8l8t8|8
9$90989l9|9
:,:8:X:`:l:
;$;,;4;<;D;L;T;\;d;l;t;|;
< <0<T<\<d<l<t<|<
=$=,=4=<=D=L=X=x=
><>H>h>p>x>
?$?,?8?X?`?h?t?
0$000P0X0d0
1 1@1L1l1t1
2<2H2h2p2x2
3$3,343<3D3L3T3\3d3l3t3
4<4D4L4T4`4
5$5,545<5D5P5p5x5
6 6(646T6\6h6
7$7,787X7d7
8<8D8L8T8\8h8
949<9d9l9
9$:,:t:|:
; ;@;P;t;|;
< <D<L<T<\<d<l<t<|<
=(=0=8=@=L=l=t=|=
>$>,>4>@>`>h>x>
?<?H?l?t?|?
0$000P0\0|0
1$1,181X1`1h1t1
2<2D2P2p2x2
3,343@3`3h3p3x3
444<4H4h4p4x4
5$5,545@5`5h5p5x5
6$606P6X6d6
747<7D7L7\7d7l7t7|7
8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2 202T2\2d2l2t2|2
3$3,343<3D3P3t3|3
4$4,444<4D4L4X4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6H6l6t6|6
7$7,747<7D7L7T7`7
8$8D8L8T8`8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
? ?,?L?T?\?d?p?
0$0,040<0D0L0T0`0
1$1,141<1D1L1T1\1d1l1t1|1
2 2(20282H2l2t2|2
3 3(343T3`3
4 4(4044484@4T4\4d4l4p4t4|4
505P5p5
686D6L6t6x6
787X7x7
888X8x8
9$9@9`9
1 1$1(1
1 202@2P2`2x2
283<3p8
9 9$9,90989<9D9H9P9T9X9\9`9d9h9l9p9t9x9|9
: :(:,:4:8:@:D:L:P:X:\:d:h:p:t:|:
;,;L;d;
thawte, Inc.1(0&
Certification Services Division1806
/(c) 2006 thawte, Inc. - For authorized use only10
thawte Primary Root CA0
131210000000Z
231209235959Z0L1
thawte, Inc.1&0$
thawte SHA256 Code Signing CA0
http://t2.symcb.com0
!http://t1.symcb.com/ThawtePCA.crl0
SymantecPKI-1-5680
UwM^6)
thawte, Inc.1&0$
thawte SHA256 Code Signing CA0
170224000000Z
200224235959Z0
Bucuresti1
Caphyon SRL1'0%
SECURE APPLICATION DEVELOPMENT1
Caphyon SRL0
http://tl.symcb.com/tl.crl0
https://www.thawte.com/cps0/
!https://www.thawte.com/repository0W
http://tl.symcd.com0&
http://tl.symcb.com/tl.crt0
thawte, Inc.1&0$
thawte SHA256 Code Signing CA
"https://www.advancedinstaller.com 0
20181026154629Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G2
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
170102000000Z
280401235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G20
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-50
\Z^ k;
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
181026154629Z0/
/1(0&0$0"
DDDDDOx
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
wDj WP
\$ UVW
u)9q u$_^]
D$<SUVW
u&8Gbt!
Pt&j+W
f9,Bt_W
ElSVWP
wzjTWP
QQSVWd
tH9] uC
u PWQR
URPQQh
;t$,v-
UQPXY]Y[
SVWjA_jZ+
uBjAYjZ+
Tt1jhZ;
t0jXXf
~$+~8+
F2jgYf;
SVjA[jZ^+
jAZjZ^
u0jAXf;
u0jAXf;
PPPPPPPP
t#Vh,r
Wj0XPV
PPPPPWS
PP9E u:PPVWP
WWWPWS
u-PWWS
SSVWh
f9:t!V
QQSWj0j@
PPPPPPPP
D8(HXt:f
D8(Ht5F
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad array new length
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
ConvertStringSidToSidW
string too long
LockServiceDatabase
UnlockServiceDatabase
DllGetVersion
SHGetFolderPathW
ProgramFiles
IsWow64Process
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
Unknown exception
GlobalMemoryStatusEx
Detected working Internet connection.
Process is running in a VM
Process is not running in a VM
Detected screen resolution X :
Detected screen resolution Y :
User hasn't share point deployment permissions
Share point services are stopped
Share point solutions are already installed
Minor upgrade was detected for the installed version [
Perform searches for property [
Was not found a predefined search, trying to get a custom detection
Was not found a custom detection, the property doesn't have any detection info
Search result [
Something wrong! Predefined detections are bad declared.
Was specified a custom detector
OnDetectSoftware start.
OnDetectSoftware end.
OnResolveProps start.
OnResolveProps end.
RSDSIT\
C:\JobRelease\win\Release\custact\x86\SoftwareDetector.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
SoftwareDetector.dll
OnDetectSoftware
OnResolveProps
msi.dll
InternetCrackUrlW
InternetCloseHandle
InternetSetStatusCallbackW
InternetSetOptionW
InternetOpenW
InternetGetLastResponseInfoW
InternetReadFile
InternetQueryDataAvailable
FtpGetFileSize
InternetQueryOptionW
HttpQueryInfoW
InternetConnectW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpCommandW
WININET.dll
NetLocalGroupGetMembers
NetApiBufferFree
NetUserGetLocalGroups
NETAPI32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
WNetAddConnection2W
MPR.dll
GetUserNameExW
Secur32.dll
CopyFileExW
GetLastError
FileTimeToSystemTime
SystemTimeToFileTime
CompareFileTime
DeleteFileW
MoveFileW
CopyFileW
CreateFileW
CloseHandle
HeapDestroy
HeapSize
HeapReAlloc
HeapFree
HeapAlloc
GetProcessHeap
SizeofResource
LockResource
LoadResource
FindResourceW
FindResourceExW
RaiseException
LocalFree
LocalAlloc
LoadLibraryW
GetProcAddress
FreeLibrary
GetFileSize
FindFirstFileW
CreateProcessW
WaitForSingleObject
GetExitCodeProcess
GetWindowsDirectoryW
GetCurrentProcess
SetFilePointer
ReadFile
FindClose
MultiByteToWideChar
WideCharToMultiByte
GetFileTime
InterlockedDecrement
GetSystemDirectoryW
LoadLibraryExW
SetLastError
GetTempPathW
GetTempFileNameW
FindNextFileW
RemoveDirectoryW
CreateDirectoryW
GetLogicalDriveStringsW
GetDriveTypeW
WriteFile
GetEnvironmentVariableW
GetModuleFileNameW
lstrcmpiW
GetModuleHandleW
InterlockedIncrement
lstrlenW
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCurrentProcessId
GetCurrentThreadId
OutputDebugStringW
FlushFileBuffers
GetStringTypeW
ResetEvent
CreateEventW
SetEvent
GlobalFree
GlobalFindAtomW
DuplicateHandle
GetStdHandle
LockFile
UnlockFile
lstrcmpW
InitializeCriticalSectionAndSpinCount
DecodePointer
KERNEL32.dll
GetSystemMetrics
USER32.dll
GetDeviceCaps
GDI32.dll
RegCloseKey
RegQueryValueExW
RegEnumKeyExW
RegEnumValueW
RegOpenKeyExW
GetSecurityDescriptorDacl
SetEntriesInAclW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
LookupAccountSidW
CloseServiceHandle
OpenSCManagerW
OpenServiceW
QueryServiceStatus
ADVAPI32.dll
SHGetFolderPathW
SHGetSpecialFolderLocation
SHGetPathFromIDListW
SHGetMalloc
SHELL32.dll
CoUninitialize
CoInitializeEx
CoCreateInstance
CoInitializeSecurity
CoSetProxyBlanket
ole32.dll
OLEAUT32.dll
PathFileExistsW
SHLWAPI.dll
IsDebuggerPresent
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
InitializeSListHead
RtlUnwind
InterlockedFlushSList
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
GetACP
GetFileType
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetConsoleCP
GetConsoleMode
SetFilePointerEx
SetEndOfFile
ReadConsoleW
WriteConsoleW
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_com_error@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVCAtlException@ATL@@
.?AVexception@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
060B0v0
1"1F1R1W1g1l1}1
2"242=2C2L2R2\2f2u2
3"3+313;3E3T3f3o3u3
4!404B4K4Q4Z4`4j4t4
55(5.575=5G5Q5d5n5w5|5
6$6.6A6J6P6Y6_6i6s6
7$7.7<7E7J7P7c7l7r7{7
8&8+8;8@8h8
9"9G9P9U9e9j9
9:):3:S:\:a:q:v:
;+;4;9;I;N;s;};
< <@<`<j<t<
<$=-=2=B=G=l=u=z=
>0>9>>>N>S>x>
? ?$?*?J?S?X?h?m?
0&0/040D0I0n0w0|0
1!1F1P1Z1z1
2(2-2R2[2`2p2u2
2$3D3d3
4#4H4Q4V4f4k4
5*5/5T5]5b5r5w5
6,666D6H6N6n6w6|6
7 7*7J7S7X7h7m7
7"8+808@8E8j8t8~8
9.979<9L9Q9v9
="=J=V=[=k=p=
> >0>=>B>K>]>a>g>
?7?W?d?q?v?
0#0H0h0
111:1?1O1T1y1
2#2(282=2b2k2p2
3!3%3+3K3T3Y3i3n3
4(454:4C4T4
6,656:6J6O6v6
7=7F7K7[7`7
818:8?8O8T8{8
9?9H9M9]9b9
:#:(:1:8:?:N:R:X:z:
;0;R;\;f;
<><`<l<q<z<
=+=0=W=y=
>$>)>9>>>e>
?*?/?V?_?d?t?y?
0#0(080=0d0m0r0
1)1-131U1^1c1s1x1
2-272A2c2l2q2
3;3G3L3U3\3c3r3v3|3
424T4v4
9(9H9h9
9&:2:\:h:m:}:
;:;G;Q;s;|;
<)<K<W<\<e<l<s<
>'>,>S>u>
?D?M?R?b?g?
0&0+0R0[0`0p0u0
1!1C1L1Q1a1f1
2%2/2Q2Z2_2o2t2
3)353:3C3J3Q3b3
5"5J5V5[5k5p5
6 606=6B6K6]6a6g6
777W7d7q7v7
8#8H8h8
919:9?9O9T9y9
;&;+;;;@;h;q;v;
<-<1<7<W<`<e<u<z<
='=4=A=F=O=^=b=h=
>8>X>e>r>w>
??$?I?i?
181A1F1V1[1
2 2-222;2M2Q2W2w2
3%3*3O3X3]3m3r3
4@4I4N4^4c4
5%52575@5O5S5Y5y5
6'6,6Q6Z6_6o6t6
7B7K7P7`7e7
8'84898B8Q8U8[8{8
9)9.9S9\9a9q9v9
::D:M:R:b:g:
;);6;;;D;S;W;];};
<+<0<U<^<c<s<x<
=!=F=O=T=d=i=
>+>8>=>F>U>Y>_>
?-?2?W?`?e?u?z?
0#0H0Q0V0f0k0
0 1-1:1?1H1W1[1a1
22/242Y2b2g2w2|2
3 3%3J3S3X3h3m3
3"4/4<4A4J4Y4]4c4
5!51565[5d5i5y5~5
6"6'6L6U6Z6j6o6
6$717>7C7L7[7_7e7
8#83888]8f8k8{8
9$9)9N9W9\9l9q9
:&:3:@:E:N:_:
>*>6>;>K>P>x>
????H?M?]?b?
0"0(0H0Q0V0f0k0
1'1+111Q1Z1_1o1t1
2!2.2;2@2I2X2\2b2
323R3_3l3q3z3
5,555:5J5O5t5
6#63686]6f6k6{6
7 7&7F7O7T7d7i7
8#80858>8M8Q8W8w8
9'9G9T9a9f9o9~9
:8:X:x:
:!;*;/;?;D;i;
<(<-<R<[<`<p<u<
=;=D=I=Y=^=
>%>*>3>B>F>L>l>u>z>
?<?I?V?[?d?u?
3(3H3h3x3
474W4w4
4 5@5`5
6)6I6i6
727R7r7
8;8[8{8
99D9d9
<<F<O<T<d<i<
=<=E=J=Z=_=
> >%>.>5><>N>R>X>z>
?,?1?X?a?f?v?{?
00$0K0T0Y0i0n0
1<1E1J1Z1_1
2#2(282=2d2m2r2
3+303W3y3
4!4H4Q4V4f4k4
4&5/545D5I5X5c5
6;6]6i6n6w6~6
7(7-7T7]7b7r7w7
8%8G8P8U8e8j8
89+90999@9G9V9Z9`9
::$:4:9:`:i:n:~:
;';,;S;\;a;q;v;
<"<D<M<R<b<g<
<"=+=0=@=E=l=u=z=
>#>3>8>_>
?$?)?P?Y?^?n?s?
0.070<0L0Q0`0k0
0!1C1e1q1v1
2 20252\2e2j2z2
3"3-3O3X3]3m3r3
4'43484A4H4O4`4
8:8F8K8[8`8
9 9-929;9M9Q9W9w9
:':G:T:a:f:o:~:
;8;X;x;
;!<*</<?<D<i<
=(=-=R=[=`=p=u=
>;>D>I>Y>^>
?%?*?3?B?F?L?l?u?z?
0<0I0V0[0d0s0w0}0
1-1M1m1z1
22$24292^2~2
5 5H5Q5V5f5k5
5 6)6.6>6C6R6c6p6u6~6
7 7%7J7S7X7h7m7
8'8,858D8H8N8n8w8|8
9!9F9O9T9d9i9
:":+:0:@:E:j:s:x:
;B;K;P;`;e;t;
<'<,<<<A<f<o<t<
=(=6=C=H=Q=`=d=j=
>#>(>8>=>b>k>p>
?>?G?L?\?a?
00$04090^0g0l0|0
1:1C1H1X1]1
2 20252D2R2_2d2m2|2
363?3D3T3Y3~3
6"6L6X6]6m6r6
70797>7N7S7z7
7&8/848D8I8p8
9#9(989=9d9m9r9
:B:K:P:`:e:t:
;5;W;y;
;&</<4<D<I<p<y<~<
Antivirus Signature
Lionic Trojan.Win32.RA-Based.m!c
ClamAV Clean
CTX msi.trojan.based
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.Generic.37540644
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Trojan.MSI.Agent.GAB
Symantec Trojan.Gen.MBT
ESET-NOD32 PowerShell/RA-based.J
TrendMicro-HouseCall Clean
Avast Other:Malware-gen [Trj]
Cynet Clean
Kaspersky Backdoor.OLE2.RA-Based.a
BitDefender Trojan.Generic.37540644
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.Generic.37540644
Tencent Win32.Backdoor.Ra-based.Oqil
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.Generic.37540644
TrendMicro Clean
Trapmine Clean
CMC Clean
Emsisoft Trojan.Generic.37540644 (B)
Ikarus Trojan-Dropper.Win32.Agent
GData Trojan.Generic.37540644
Jiangmin Clean
Varist ABBackdoor.GGUT
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D23CD324
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!ACBF94EAD947
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet PowerShell/RA_based.J!tr
AVG Other:Malware-gen [Trj]
Panda Clean
alibabacloud Backdoor:Win/RA-based.J
No IRMA results available.