Sample details: 1d4b0fc476b7d20f1ef590bcaa78dc5d --

Hashes
MD5: 1d4b0fc476b7d20f1ef590bcaa78dc5d
SHA1: 8a86284e9ae67b16d315a0a635252a52b1bedda1
SHA256: 1b76fdbd4cd92c7349bc99291137637614f4fb9598ae29df0a39a422611b86f8
SSDEEP: 6144:eS/4o40hfee6u2UnaCCYp5dQPnx2ck4ThGOuKBu0MpX6r:eHop5SUna+p5OnxhlThGJKBPMpa
Details
File Type: PE32
Yara Hits
YRP/Armadillo_v2xx_CopyMem_II_additional | YRP/Microsoft_Visual_Cpp_70_MFC | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasRichSignature | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/System_Tools | YRP/Dropper_Strings | YRP/WMI_strings | YRP/screenshot | YRP/keylogger | YRP/spreading_file | YRP/rat_webcam | YRP/win_registry | YRP/win_files_operation | YRP/win_hook | YRP/CRC32_poly_Constant | YRP/CRC32_table | YRP/BASE64_table | YRP/VC8_Random | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/Str_Win32_Internet_API | FlorianRoth/Explosive_EXE | FlorianRoth/Explosion_Generic_1 | FlorianRoth/Explosive_UA |
Source
http://94.130.104.170/1b76fdbd4cd92c7349bc99291137637614f4fb9598ae29df0a39a422611b86f8
Strings
		!This program cannot be run in DOS mode.
;RichR
`.rdata
@.data
.shared
^<9^<u
8;^(r	
t	;Ftt
MDG;}\r
HN#u<;t
~(9~$u
F$WWWWW
VHWWWWW
FP;FTt
t.VVVVV
t&97u"j
Ht>Ht*H
uK9^<u
FP_9^Xtx
YYu}9E
uJ9^<u
FP_9^Xtv
YYu{9E
vzSSSS
RSj0h 
<8\YVt
w9} vK
E HPSWV
u0SWVP
YYv&Vh
QQSVW3
<8\YVt
WWhUcA
YYSSh8
SShZcA
t[SVh|
VSVVVVVVh
u0SWVP
r AA@@;M
PWj0_W
E$HPSWV
u0SWVP
< t<<$t3<+t*<vu2
< t<<$t3<+t*<vu2
< t9<$t0<+t'<vu/
VC20XC00U
QQSVWd
t.;t$$t(
.;1s(N
HHteHHtPHt+H
atxHtfHt'Ht
SWVt,j
tIHt,Ht
te<%t4
PPPPPPPP
t!SS9]
F,98uX
t%<.u(
u5SSWhl
E SSSS
sVS;7|B;w
E VVVVW
HHt`HHt\
zu^SSS
Yt:SVW
;F(r(8_
>:u>FV
VVVVVUWUUj
VVVVVj
btFHt+
t$<"u	3
QQSVW3
t#SSUP
t$$VSS
_^][YY
WWWWVSW
t2WWVPVSW
WuO95 
Wu)95$
C PjPVj
C$PjQVj
C*PjTVj
C+PjUVj
C,PjVVj
C-PjWVj
C.PjRVj
C/PjSVj
It[IItM
PPPPPPPP
v	N+D$
HHtjHHtF
t|hl$D
u+WWSW
t!VV9u
SVWj ^
+t"HHt
YYtGhD%D
YYt3h<%D
YYt"h4%D
uxhP%D
vBWSSSj
Qkkbal
 inflate 1.1.3 Copyright 1995-1998 Mark Adler 
 unzip 0.15 Copyright 1998 Gilles Vollant 
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
need dictionary
<*`!Q@W#E4r`*>
Delete
NoRemove
ForceRemove
registerapp
%i && exit
 /c taskkill /f /PID 
PathProcess
ct_tally: bad match
invalid length
output buffer too small for in-memory compression
wild scan
no future
insufficient lookahead
more < 2
invalid distance code
invalid literal/length code
incomplete dynamic bit lengths tree
oversubscribed dynamic bit lengths tree
incomplete literal/length tree
oversubscribed literal/length tree
empty distance tree with lengths
incomplete distance tree
oversubscribed distance tree
WindowsHelpServices
Windows Help Services
sc stop WindowsHelpServices
bad cast
inconsistent bit counts
too many codes
not enough codes
bad d_code
bad pack level
invalid bit length repeat
too many length or distance symbols
invalid stored block lengths
invalid block type
incorrect data check
incorrect header check
invalid window size
unknown compression method
%s%s%s
1ConnectSocket2 failed with error: %d
0ConnectSocket2 failed with error: %ld
ct_init: 256+dist != 512
ct_init: dist != 256
ct_init: length != 256
bad compressed size
<~||~>
(Default)
<~`|~`>
(%d) %s
<~*|~*>
HKEY_CURRENT_USER
\HKEY_LOCAL_MACHINE\
\HKEY_CURRENT_USER\
<~#|~#>HKEY_LOCAL_MACHINE
Couldn't access system information!
errorx
 %Y-%m-%d
NULL NULL|
%s %s|
ini.sys
AWindows Help
:\tools.dll
:\autorun.exe
ieservice.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
UNKNOWN
-crpt.sys
-rpt.sys
System
%username%
ieproxy.sys
tools.dll
data.sys
hist.sys
iniz.sys
servdata.sys
wintmp.dat
\tools.dll
\Config.Msi
Application Data\Microsoft
Microsoft
appdata
invalid map/set<T> iterator
/c wmic path win32_perfformatteddata_perfproc_process where (PercentProcessorTime ^> 40) get  IDProcess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
\%s-%i.%i.%i.%i.%i.%i.sys
</b></font></li><ul>
<li><b><font color="maroon">The Active Window Title:
<font color="navy" style="font-size:11px"><strong> [right] </strong></font>
<font color="navy" style="font-size:11px"><strong> [DOWN] </strong></font>
<font color="navy" style="font-size:11px"><strong> [PRINT] </strong></font>
<font color="navy" style="font-size:11px"><strong> [INSERT] </strong></font>
<font color="navy" style="font-size:11px"><strong> [DEL] </strong></font>
<font color="navy" style="font-size:11px"><strong> [LCTRL] </strong></font>
<font color="navy" style="font-size:11px"><strong> [RCTRL] </strong></font>
] </strong></font>
<font color="navy" style="font-size:11px"><strong> [
<font color="navy" style="font-size:11px"><strong> [UP] </strong></font>
<font color="navy" style="font-size:11px"><strong> [BK] </strong></font>
<font color="navy" style="font-size:11px"><strong> [TAB] </strong></font>
<font color="navy" style="font-size:11px"><strong> [Enter] </strong></font><br>
<font color="navy" style="font-size:11px"><strong> [CAPLOCK] </strong></font>
<font color="navy" style="font-size:11px"><strong> [ESC] </strong></font>
<font color="navy" style="font-size:11px"><strong> [END] </strong></font>
<font color="navy" style="font-size:11px"><strong> [left] </strong></font>
^*!#^`|
%drp.exe
%s_%s%d.exe
autorun.exe
OCreateNewFile
##EndData##
##Data##: Active Window--> 
winrpt
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: 
 HTTP/1.1
 ConDll Err x0
s failed with error: %ld
www.google.com
www.microsoft.com
http://
?win=4
open=autorun.exe
[autorun]
:\autorun.inf
SetWinHoK
map/set<T> too long
Program Manager
<*ENUM*>
<*`size`*><%d>
*EnumWindows*<
The command completed successfully.
GetAllData
GetIEHistory
<!*ok*!>
*UnZip*<
*Zip*<
*CutPasteFiles*<
*CopyPasteFiles*<
*DeleteFiles*<
*ClipboardLog*
*KeyLog*
*DumpHist*
*DumpPass*
*ScShot*
*GetFile*
" /s /q & exit
cmd /c RMDIR "
*DelDir*<
*AddDir*<
*GetRegValue*
*EnumRootKeys*
*EnumKeys*
*EnumWindows*
*RunCmd*|
*GetDrives*<
*KillProcess
*ListProcess
*GetDrivesFolder
*OpenPF*[
**CloseFile**
error.renamefile
.renamefile
*FileSend*<
<!*KILL*!>
& RMDIR "%s" /s  /q & RMDIR "%s" /s  /q & DEL   /f /q "%s"  & DEL   /f /q "%s" & DEL /f   /f /q "%s" & DEL   /f /q "%s" & DEL   /f /q "%s" & DEL   /f /q "%s" & sc stop WindowsHelpServices & sc delete WindowsHelpServices & exit
/c taskkill /f /PID 
<!*DEL*!>
<!*EndTask*!>
<*`EOF`*>
An Error xxxx
An Error Occ
</PORT>
<PORT>
ieservice
:DLD-C0
DLD-C0:
:DLD-C
DLD-C:
:DLD-E
DLD-E:
:DLD-P
DLD-P:
:DLD-S
DLD-S:
?win=1
:DLD-D
DLD-D:
:DLD-ACT
DLD-ACT:
:DLD-USI
DLD-USI:
:DLD-USA
DLD-USA:
:DLD-PRT
DLD-PRT:
:DLD-IP
DLD-IP:
:DLD-RN
DLD-RN:
:DLD-TN
DLD-TN:
Error UnInstalling Service
Service UnInstalled Sucessfully
 /c sc start WindowsHelpServices
Internet Explorer
127.0.0.1
ios_base::eofbit set
ios_base::failbit set
ios_base::badbit set
invalid string position
string too long
0123456789abcdefABCDEF
bad allocation
+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v+ $v $++$ v+$ v$ v++$ v$ +v
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
CorExitProcess
mscoree.dll
Unknown exception
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
Microsoft Visual C++ Runtime Library
Program: 
<program name unknown>
A buffer overrun has been detected which has corrupted the program's
internal state.  The program cannot safely continue execution and must
now be terminated.
Buffer overrun detected!
A security error of unknown cause has been detected which has
corrupted the program's internal state.  The program cannot safely
continue execution and must now be terminated.
Unknown security failure detected!
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
kernel32.dll
`h````
ppxxxx
(null)
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GAIsProcessorFeaturePresent
KERNEL32
runtime error 
TLOSS error
SING error
DOMAIN error
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Runtime Error!
Program: 
InitializeCriticalSectionAndSpinCount
Paraguay
Uruguay
Ecuador
Argentina
Colombia
Venezuela
Dominican Republic
South Africa
Panama
Luxembourg
Costa Rica
Switzerland
Guatemala
Canada
Spanish - Modern Sort
Australia
English
Austria
German
Belgium
Mexico
Spanish
Basque
Sweden
Swedish
Iceland
Icelandic
France
French
Finland
Finnish
Spanish - Traditional Sort
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
1#QNAN
1#SNAN
wsprintfA
GetDesktopWindow
SendMessageA
ReleaseDC
CloseClipboard
GetClientRect
GetClipboardData
OpenClipboard
BeginPaint
GetSystemMetrics
GetWindowTextW
GetWindowTextLengthW
GetForegroundWindow
GetKeyNameTextA
ToUnicodeEx
MapVirtualKeyExA
ToAscii
MapVirtualKeyA
GetKeyState
GetKeyboardState
GetKeyboardLayout
GetWindowThreadProcessId
CallNextHookEx
DefWindowProcA
MsgWaitForMultipleObjects
DispatchMessageA
PeekMessageA
GetWindowTextA
IsWindowVisible
EnumWindows
TranslateMessage
GetMessageA
CreateWindowExA
RegisterClassExA
USER32.dll
GetProcessMemoryInfo
PSAPI.DLL
InterlockedExchange
GetACP
GetLocaleInfoA
GetVersionExA
RaiseException
InitializeCriticalSection
DeleteCriticalSection
FreeLibrary
GetProcAddress
LoadLibraryA
CloseHandle
OpenProcess
GetCurrentProcessId
FileTimeToSystemTime
ReadFile
SetFilePointer
GetFileSize
GetFileInformationByHandle
MapViewOfFile
CreateFileMappingA
CreateFileA
WriteFile
SystemTimeToFileTime
GetLocalTime
LocalFileTimeToFileTime
CreateDirectoryA
GetFileAttributesA
GetModuleFileNameA
GetModuleHandleA
WinExec
GetCurrentDirectoryA
SetFileTime
UnmapViewOfFile
GetTickCount
InterlockedDecrement
SetCurrentDirectoryA
FindClose
FindNextFileA
FindFirstFileA
GetVolumeInformationA
GetDriveTypeA
SetFileAttributesA
DeleteFileA
GetLastError
CreateProcessA
CreatePipe
CopyFileA
GetComputerNameA
ExpandEnvironmentStringsA
MoveFileA
GetSystemTime
GetCompressedFileSizeA
GlobalUnlock
GlobalLock
CreateThread
CreateEventA
Process32Next
Process32First
CreateToolhelp32Snapshot
lstrcmpA
CopyFileExA
MultiByteToWideChar
WideCharToMultiByte
LocalFree
KERNEL32.dll
DeleteObject
BitBlt
SelectObject
CreateCompatibleBitmap
CreateCompatibleDC
GDI32.dll
SetServiceStatus
CloseServiceHandle
CreateServiceA
OpenSCManagerA
DeleteService
OpenServiceA
RegEnumValueA
RegEnumKeyExA
RegQueryInfoKeyA
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegisterServiceCtrlHandlerA
StartServiceA
StartServiceCtrlDispatcherA
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
CoUninitialize
CoCreateInstance
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
capCreateCaptureWindowA
AVICAP32.dll
InternetCloseHandle
DeleteUrlCacheEntry
WININET.dll
WS2_32.dll
GdipFree
GdipAlloc
GdipDeleteGraphics
GdipDisposeImage
GdipSaveImageToFile
GdipGetImageWidth
GdipGetImageHeight
GdipGetImagePixelFormat
GdipCreateBitmapFromScan0
GdipCreateBitmapFromHBITMAP
GdipGetImageEncodersSize
GdipGetImageEncoders
GdipGetImageGraphicsContext
GdipDrawImageRectI
GdipCloneImage
GdiplusStartup
gdiplus.dll
InterlockedIncrement
EnterCriticalSection
LeaveCriticalSection
ExitProcess
HeapFree
TerminateProcess
GetCurrentProcess
HeapAlloc
RtlUnwind
GetCPInfo
GetTimeFormatA
GetDateFormatA
ExitThread
ResumeThread
GetStartupInfoA
GetCommandLineA
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
HeapReAlloc
CompareStringA
CompareStringW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
VirtualQuery
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
IsBadWritePtr
GetOEMCP
TlsAlloc
SetLastError
TlsFree
TlsSetValue
TlsGetValue
SetUnhandledExceptionFilter
FlushFileBuffers
SetHandleCount
GetStdHandle
GetFileType
GetTimeZoneInformation
VirtualProtect
GetSystemInfo
UnhandledExceptionFilter
HeapSize
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
IsValidCodePage
IsBadReadPtr
IsBadCodePtr
GetLocaleInfoW
SetStdHandle
SetEnvironmentVariableA
SetEndOfFile
FileTimeToLocalFileTime
RemoveDirectoryA
GetFullPathNameA
http://www.microsoft.com/en-us/default.aspx
!This program cannot be run in DOS mode.
*hRich_
`.rdata
@.data
T$PRVP
WVWWWWWWh
QQSVWd
t.;t$$t(
sVS;7|B;w
t!SS9]
VC20XC00U
u,h[~@
btFHt+
HHt`HHt\
t$<"u	3
QQSVW3
t#SSUP
t$$VSS
_^][YY
WWWWVSW
t2WWVPVSW
v	N+D$
HHtXHHtF
vBWSSSj
>:u>FV
VVVVVUWUUj
VVVVVj
PPPPPPPP
c:\Program Files\Internet Explorer\ieservice.exe
c:\Program Files\Internet Explorer\
\Config.Msi
Application Data\Microsoft
Microsoft
appdata
xInvisible
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
invalid string position
string too long
bad allocation
Unknown exception
Microsoft Visual C++ Runtime Library
Program: 
<program name unknown>
A buffer overrun has been detected which has corrupted the program's
internal state.  The program cannot safely continue execution and must
now be terminated.
Buffer overrun detected!
A security error of unknown cause has been detected which has
corrupted the program's internal state.  The program cannot safely
continue execution and must now be terminated.
Unknown security failure detected!
CorExitProcess
mscoree.dll
`h````
ppxxxx
(null)
runtime error 
TLOSS error
SING error
DOMAIN error
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Runtime Error!
Program: 
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CopyFileA
SetFileAttributesA
GetCurrentProcess
GetModuleFileNameA
KERNEL32.dll
DefWindowProcA
CreateWindowExA
RegisterClassExA
USER32.dll
ShellExecuteA
SHELL32.dll
GetModuleBaseNameA
PSAPI.DLL
RtlUnwind
RaiseException
ExitProcess
HeapFree
HeapAlloc
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersionExA
SetUnhandledExceptionFilter
LCMapStringA
WideCharToMultiByte
MultiByteToWideChar
GetLastError
LCMapStringW
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
IsBadWritePtr
WriteFile
CloseHandle
ReadFile
SetFilePointer
SetHandleCount
GetStdHandle
GetFileType
GetProcAddress
TerminateProcess
HeapSize
UnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetStringTypeA
GetStringTypeW
IsBadReadPtr
IsBadCodePtr
GetLocaleInfoA
GetCPInfo
VirtualProtect
GetSystemInfo
VirtualQuery
LoadLibraryA
InterlockedExchange
FlushFileBuffers
SetStdHandle
CreateFileA
CompareStringA
CompareStringW
GetACP
GetOEMCP
SetEnvironmentVariableA
SetEndOfFile
FindClose
FileTimeToSystemTime
FileTimeToLocalFileTime
GetDriveTypeA
FindFirstFileA
CreateDirectoryA
GetFullPathNameA
GetCurrentDirectoryA
GetTimeZoneInformation
.?AVexception@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_alloc@std@@
.?AVtype_info@@
wwwwwwwwwwwwww
wwwwwwwwwwwwww
DDDDDDDDD@
DDDDDDDDDGpw
DDDDDDDDDGpw
DDDDDDDDDDDDDD
wwwwwwwwwwwwww
DDDDDD
wwwwww
.?AVexception@@
.?AVbad_cast@@
.?AVlogic_error@std@@
.?AVout_of_range@std@@
.?AVlength_error@std@@
.?AV_com_error@@
.?AVfacet@locale@std@@
.?AV_Locimp@locale@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVfailure@ios_base@std@@
.?AVcodecvt_base@std@@
.?AUctype_base@std@@
.?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$ctype@D@std@@
.?AV?$codecvt@DDH@std@@
.?AV?$numpunct@D@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
Copyright (c) 1992-2001 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVbad_alloc@std@@
.?AUmessages_base@std@@
.?AUmoney_base@std@@
.?AUtime_base@std@@
.?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$codecvt@_WDH@std@@
.?AV?$codecvt@GDH@std@@
.?AV?$ctype@_W@std@@
.?AV?$ctype@G@std@@
.?AV?$collate@_W@std@@
.?AV?$messages@_W@std@@
.?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$_Mpunct@_W@std@@
.?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$collate@G@std@@
.?AV?$messages@G@std@@
.?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$_Mpunct@G@std@@
.?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AV?$numpunct@G@std@@
.?AV?$moneypunct@_W$0A@@std@@
.?AV?$moneypunct@_W$00@std@@
.?AV?$moneypunct@G$0A@@std@@
.?AV?$moneypunct@G$00@std@@
.?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$collate@D@std@@
.?AV?$messages@D@std@@
.?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$_Mpunct@D@std@@
.?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$moneypunct@D$0A@@std@@
.?AV?$moneypunct@D$00@std@@
.?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVtype_info@@
111DLD-TN:69@120@112@108@111@115@105@118@101@:DLD-TN"DLD-RN:104@116@116@112@100@:DLD-RN;DLD-IP:50@49@51@46@50@48@52@46@49@50@50@46@49@51@48@:DLD-IP
DLD-PRT:49@52@52@52@51@:DLD-PRT
DLD-USA:0:DLD-USA
DLD-USI:true:DLD-USI
DLD-ACT:true:DLD-ACT
DLD-D:104@116@116@112@58@47@47@99@97@114@105@109@97@50@48@49@50@46@115@105@116@101@57@48@46@99@111@109@47@105@110@100@101@120@46@112@104@112@:DLD-D
DLD-S:redotntexplore:DLD-S1DLD-P:47@101@120@47@105@101@46@112@104@112@:DLD-P
DLD-E:.info:DLD-E,DLD-C:105@101@115@101@114@118@101@114@:DLD-C.DLD-C0:105@101@115@101@114@118@101@114@:DLD-C0.