Sample details: 2c3100b76672746691dc6db0d9d78541 --

Hashes
MD5: 2c3100b76672746691dc6db0d9d78541
SHA1: e9a1bf0a38e3097b93d91cf31e0d040d9e6a7423
SHA256: 99433530e582cc7ffac86b5ecb6931db40cbdff4af7114014e056587d5fc3886
SSDEEP: 12288:J5AEoj0wSTOH5UV+VNl46qjBQ+e6wqfKz:vAEojQOCk4ljBQDZ
Details
File Type: PE32+
Yara Hits
YRP/Microsoft_Visual_Cpp_80 | YRP/Microsoft_Visual_Cpp_80_DLL | YRP/IsPE64 | YRP/IsWindowsGUI | YRP/HasDebugData | YRP/IsBeyondImageSize | YRP/HasRichSignature | YRP/domain | YRP/contentis_base64 | YRP/Check_OutputDebugStringA_iat | YRP/anti_dbg | YRP/screenshot | YRP/keylogger | YRP/win_registry | YRP/win_files_operation | YRP/win_hook | FlorianRoth/Dropper_MyWScript |
Source
http://stahlke.ca/svchost.exe
Strings
		!This program cannot be run in DOS mode.
u'Rich
`.rdata
@.data
.pdata
@.gfids
@.giats
@.reloc
@WAVAWH
x H;O }
0A_A^_
@USVWAVH
A^_^[]
t$ ATAVAWH
 Hcl$`M
 A_A^A\
t$ AVH
l$0fff
WAVAWH
 A_A^_
UATAUAVAWH
A_A^A]A\]
l$ VWAWH
t$ AWH
ATAVAWH
@A_A^A\
|$ AVH
VWATAUAVH
 A^A]A\_^
UVWAVAWH
D$xD9x
A_A^_^]
|$ ATAVAWH
@A_A^A\
VWATAVAWH
 A_A^A\_^
@WATAUAVAWH
0A_A^A]A\_
@WAVAWH
0A_A^_
UVWATAUAVAWH
 A_A^A]A\_^]
WAVAWH
@WAVAWH
tJLcG M
@A_A^_
@A_A^_
UVWAVAWH
pA_A^_^]
@UVWATAUAVAWH
A_A^A]A\_^]
@UVWAVAWH
A_A^_^]
@UVWAVAWH
9\$Xt&H
`A_A^_^]
@UVWAVAWH
0A_A^_^]
@VWAVH
@VWATAVAWH
t?H93t23
0A_A^A\_^
UVWATAUAVAWH
@A_A^A]A\_^]
@A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
|$Rxu	
A_A^A]A\_^]
USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
t$ AWH
@UVWATAUAVAWH
A_A^A]A\_^]
HcD$ H
u^9K,tY
t3LcL$(H
WATAUAVAWH
D$0Lcx
A_A^A]A\_
UVWAVAWH
0A_A^_^]
@UVWATAUAVAWH
uWHcL$$H
K8HcA@H
BH;B@tl
ZPHcBXH
t3McH McP$E
u=HcL$<H
A_A^A]A\_^]
@UVWATAUAVAWH
F0 u_I
D$HLcW
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
L$ SVWH
WATAUAVAWH
H9{H~=
x-H;sH}'H
A_A^A]A\_
@UVWATAUAVAWH
A_A^A]A\_^]
@UVWATAUAVAWH
fD9<Gu
A_A^A]A\_^]
@UVWATAUAVAWH
fA94Fu
A_A^A]A\_^]
WAVAWH
 A_A^_
@VAVAWH
0A_A^^
SVWAVH
(A^_^[
WAVAWH
0A_A^_
UWATAVAWH
A_A^A\_]
UATAUAVAWH
A_A^A]A\]
@UVWATAUAVAWH
A_A^A]A\_^]
@UVWAVAWH
A_A^_^]
@UVWAVAWH
fD9<Fu
A_A^_^]
@UVWAVAWH
D$pt<fD
@A_A^_^]
@USVWATAUAVAWH
XA_A^A]A\_^[]
VWATAVAWH
fD9$Gu
A_A^A\_^
WAVAWH
0A_A^_
t$ 9wHtfL
|$ 9{H
@VWAVH
@VWAVH
x'H;HP}!H
UWAUAVAWH
fD9<Cu
A_A^A]_]
@UVWAVAWH
@A_A^_^]
WATAUAVAWH
x7I;}P}1I
A_A^A]A\_
@SVWATAUAVAWH
PA_A^A]A\_^[
WAVAWH
L8@A2L)
 A_A^_
@VWATAVAWH
\$`HcK
0A_A^A\_^
WATAUAVAWH
 A_A^A]A\_
WAVAWH
 A_A^_
L$ SVWH
UAVAWH
D$HH9D$@
WAVAWH
@A_A^_
H SUVWAVH
@A^_^][
\$ UVWH
ATAVAWH
0A_A^A\
\$ UVWH
@SVWATAUAVAWH
A_A^A]A\_^[
|$ UATAUAVAWH
A_A^A]A\]
tBH9x(t1H
WATAUAVAWH
 A_A^A]A\_
x UATAUAVAWH
fD9 t&E
fD9 t*E
fD9 t!E
fD9 t!E
f98t,D
f98t,D
A_A^A]A\]
WAVAWH
 A_A^_
t$ UWAVH
UVWATAUAVAWH
`A_A^A]A\_^]
@VWATAVAWH
0A_A^A\_^
UVWATAUAVAWH
`A_A^A]A\_^]
UAVAWH
bH9Y@t
UATAUAVAWH
A_A^A]A\]
t<H9x@u+
WAVAWH
@A_A^_
VWATAVAWH
0A_A^A\_^
x ATAVAWH
 A_A^A\
UATAUAVAWH
M9l$@@
A_A^A]A\]
WAVAWH
 A_A^_
@SVWATAUAVAWH
A_A^A]A\_^[
@SUVWATAVAWH
A_A^A\_^][
WAVAWH
H9X(ud
H9_@t~H;
t;9X u
WAVAWH
0A_A^_H
VWATAVAWH
A_A^A\_^
WATAUAVAWH
E8D9m(rUA
0A_A^A]A\_
WAVAWH
A8H9A@t$H
q0+A@Hc
H9A8t1H
0A_A^_
UVWATAUAVAWH
0A_A^A]A\_^]
x ATAVAWH
E8D;}(s|H
M8H;MHuxM
0A_A^A\
VWATAVAWH
0A_A^A\_^
@WAVAWH
@A_A^_
;S0s~H
H;F@u%H
WAVAWH
@A_A^_
;S0seH
;A0sNH
WAVAWH
 A_A^_
-D9	u$
t$ WAVAWH
 A_A^_
VWAUAVAWH
0A_A^A]_^
@UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
0A_A^A]A\_
SVWATAUAVAWH
uWH9p u
H9p t9H9p(t3H
H9t$xt5H
u fA9w
I9w u#
I9w u#L
L$P9t$hu
H9t$xt)H
A_A^A]A\_^[
x ATAVAWH
0A_A^A\
l$ VWAUAVAWH
A_A^A]_^
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
d$XH+G
 A_A^A\_^
WATAUAVAWH
x2M9o(t,I
A_A^A]A\_
WAVAWH
 A_A^_
@VWAVH
@USVWATAUAVAWH
A_A^A]A\_^[]
x ATAVAWH
A0H;A@v
w8+w0H
 A_A^A\
WAVAWH
A0L;A@w
(I;N@w
 A_A^_
w>H;Q8v
H;N8waH
F0H;F@v
9|$8s	
WAVAWH
D8x(uVL
H9t$Pu
UVWATAUAVAWH
A_A^A]A\_^]
UVWAVAWH
A_A^_^]
@USVWH
x UATAVH
L$ SUVWH
SVWATAVAWH
HA_A^A\_^[
WAVAWH
 A_A^_
@UWAVH
tsH9YXuE
H9YXuN
wPH9_`u%H
UVWATAUAVAWH
0A_A^A]A\_^]
;E@t'A
@SVWATAVH
@A^A\_^[
@VWAVH
@SUVWAUAVAWH
H;D$(t
3L9|$(t
A_A^A]_^][
x ATAVAWH
 A_A^A\H
WAVAWH
0A_A^_H
|$ AVH
D$0DiT$0
t$ WAVAWH
D$HiL$H
 A_A^_
D$0iL$0
D$0iL$0
WATAUAVAWH
tffE9(t`H
0A_A^A]A\_
H9X8ud
H9X@ud
H9X0ud
t$ UWAVH
z&u$fA
WAVAWH
WAVAWH
 A_A^_
@USVWATAVAWH
@A_A^A\_^[]
T$HtSL
ATAVAWH
0A_A^A\
WAVAWH
0A_A^_
WATAUAVAWH
fD9:taf
 A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
@VWAVH
@SUVWAVH
A^_^][
@SUVWAVAWH
A_A^_^][
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
f9D$HrC
1H9w t
\$ UVWAVAWH
pA_A^_^]
UWATAVAWH
A_A^A\_]
@USVWATAUAVAWH
A_A^A]A\_^[]
x ATAVAWH
0A_A^A\
@SUVWH
WAVAWH
0A_A^_
@VWAVH
UVWAVAWH
 A_A^_^]
UVWATAUAVAWH
@A_A^A]A\_^]
@USVWATAVAWH
0A_A^A\_^[]
@USVWAVH
0A^_^[]
@USVWATAVAWH
A_A^A\_^[]
|$ AVH
D$0DiT$0
USVWAVH
@A^_^[]
WAVAWH
0A_A^_
UVWATAUAVAWH
A_A^A]A\_^]
UATAUAVAWH
A_A^A]A\]
WAVAWH
 A_A^_
WAVAWH
 A_A^_
@UVWAVAWH
0A_A^_^]
@USVWATAUAVAWH
8A_A^A]A\_^[]
UWATAVAWH
A_A^A\_]
@USVWATAVAWH
H!t$8H!t$0
!t$ E3
`A_A^A\_^[]
VWAUAVAWH
A_A^A]_^
@UVWATAVH
@A^A\_^]
UVWATAUAVAWH
@A_A^A]A\_^]
@UVWATAVH
@A^A\_^]
H!{ H!{
@VWAVH
@VWAVH
UVWATAUAVAWH
`A_A^A]A\_^]
ATAVAWH
x@H;^x}:H
H;^x}#Lc
xxH;^P}rH
H;^P}OLc
H;^P}@H
H;^P})Lc
0A_A^A\
WAVAWH
0A_A^_
SVWAVH
8A^_^[
WAVAWH
 H3E H3E
VWATAVAWH
A_A^A\_^
B(I9A(
UATAUAVAWH
G0Hc	H
L9`8tA
A_A^A]A\]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
 A_A^A]A\_
AUAVAWH
I9}(t9H
0A_A^A]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
r 9_ t
ri9V vdH
A_A^A]A\_
fA;8utI
fA;0t)fA98t
ffffff
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
 A_A^A\_^
x ATAVAWH
 A_A^A\
H;xXu9
WATAUAVAWH
 A_A^A]A\_
@8l$8t
t$ UWATAVAWH
D8d$pt
A_A^A\_]
D$0H;G
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
t$ WAVAWH
 A_A^_
WATAUAVAWH
 A_A^A]A\_
x ATAUAWH
0A_A]A\
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
'D8l$@
t)D8l$@t
WD8l$@t
D8l$@t
A_A^A]A\_
D$0HcH
WATAUAVAWH
D$PHcX H
 A_A^A]A\_
UVWATAUAVAW
J;D10t	H
A_A^A]A\_^]
L$ UVWATAUAVAWH
0A_A^A]A\_^]
WATAUAVAWH
 A_A^A]A\_
WAVAWH
@A_A^_
@UAVAWH
epA_A^]
D$@H!D$ 3
w`HcE H
Hc;9E0t
HcE H+
fD9	t(I
fD9!u7A
UVWAVAWH
0A_A^_^]
WAVAWH
A86taH
0A_A^_
WAVAWH
fA96tdH
fA94nu
0A_A^_
9 w	f9
u3HcH<H
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
 A_A^A\
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
I9\$ ~@H
fD9t$b
WATAUAVAWH
 A_A^A]A\_
@SUVWATAUAVAWH
D88Hte
8A_A^A]A\_^][
SUVWATAUAVAWH
D88Ht!
D98Ht;H
8A_A^A]A\_^][
VATAUAVAWH
 A_A^A]A\^
UVWATAUAVAWH
D(8Ht}
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
 A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
D08@t	
`A_A^A]A\_^]
WATAUAVAWH
 A_A^A]A\_
D$@H=@W
p WATAUAVAWH
A_A^A]A\_
T$pkD$x<
uAiD$@
UVWAUAVH
D83t	H
U8D83A
0A^A]_^]
@USVWH
9u@u	H
UVWATAUAVAWH
fA9<Bu
fC9<hu
A_A^A]A\_^]
WATAUAVAWH
fD9,yu
0A_A^A]A\_
\$ UVWAVAWH
A_A^_^]
f9|$^t&f
f9|$`t
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
UVWATAUAVAWH
0A_A^A]A\_^]
I96t4H
xWI96tRI
@8t$p@
@UATAUAVAWH
e0A_A^A]A\]
SVWATAUAWH
HA_A]A\_^[
@UATAUAVAWH
H!T$0D
uf!T$(H!T$ 
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
l$ WAVAWH
 A_A^_
@UATAVH
ffffff
fffffff
|$ ATAVAWH
\$@@8=}
 A_A^A\
@USVWATAUAVAWH
e8A_A^A]A\_^[]
USVWAVH
A^_^[]
LcA<E3
HPQRAPAQH
 AYAXZYX
IsolationAware function called after IsolationAwareCleanup
CStringArray
COleException
CException
CSimpleException
CMemoryException
CNotSupportedException
CInvalidArgException
InitCommonControlsEx
SetDefaultDllDirectories
RegisterTouchWindow
UnregisterTouchWindow
GetTouchInputInfo
CloseTouchInputHandle
GetGestureInfo
CloseGestureInfoHandle
HtmlHelpW
CWinThread
CArchiveException
CObject
CCmdTarget
COleDispatchException
CMapStringToString
CPtrArray
CMemFile
CWinApp
CFormView
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
CMapPtrToPtr
CResourceException
CUserException
CGdiObject
D2D1CreateFactory
D2D1MakeRotateMatrix
DWriteCreateFactory
CD2DResource
CRenderTarget
CHwndRenderTarget
CDCRenderTarget
?TaskDialogIndirect
GetLocaleInfoEx
GetThreadPreferredUILanguages
CompareStringEx
RegisterApplicationRestart
RegisterApplicationRecoveryCallback
ApplicationRecoveryInProgress
ApplicationRecoveryFinished
SHGetKnownFolderPath
CDialog
CPropertyPage
CPropertySheet
CFileException
CreateFileTransactedW
GetFileTitleW
GetFileAttributesTransactedW
RegDeleteKeyExW
CScrollView
CByteArray
CObList
CCommonDialog
CStringList
CTaskDialog
CObArray
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
Unknown exception
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
 delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
 new[]
 delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator "" 
 Type Descriptor'
 Base Class Descriptor at (
 Base Class Array'
 Class Hierarchy Descriptor'
 Complete Object Locator'
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
SetThreadStackGuarantee
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
1<.	/>:
/>58d%
>jtm}S
)>6{1n
r	Vr.>T
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^	c:>
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
	kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
CEnumVariant
WScript
package
runtime
description
example
unnamed
reference
object
resource
TypeLib\
\CLSID
\CurVer
Wow6432Node\TypeLib\
Windows Script Host
CScriptUtils
CResourceUtils
CTextStream
CArguments
CNamedArguments
CUnnamedArguments
C:\Projets\vbsedit_source\vbsedit_source\x64\Release\mywscript.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.gfids$x
.gfids$y
.giats$y
.tls$ZZZ
.rsrc$01
.rsrc$02
SizeofResource
LockResource
LoadResource
FindResourceW
MultiByteToWideChar
WideCharToMultiByte
GetACP
GetLastError
FormatMessageW
GetModuleFileNameW
ExpandEnvironmentStringsW
CreateThread
GetStdHandle
LocalFree
ExitProcess
WaitForSingleObject
GetExitCodeProcess
CloseHandle
ReadFile
SetFilePointer
FlushFileBuffers
GetFileType
GetConsoleOutputCP
SetConsoleOutputCP
WriteFile
GetCommandLineW
GetModuleHandleW
HeapFree
InitializeCriticalSectionEx
HeapSize
HeapReAlloc
RaiseException
HeapAlloc
DecodePointer
DeleteCriticalSection
GetProcessHeap
OutputDebugStringA
SetLastError
InitializeCriticalSectionAndSpinCount
GetModuleHandleExW
LoadLibraryW
CreateActCtxW
ActivateActCtx
DeactivateActCtx
FindActCtxSectionStringW
QueryActCtxW
GlobalAlloc
GlobalLock
GlobalUnlock
GlobalFree
EncodePointer
GetCurrentThreadId
GetSystemDirectoryW
FreeLibrary
GetProcAddress
LoadLibraryExW
GlobalDeleteAtom
lstrcmpW
GlobalAddAtomW
GlobalFindAtomW
SetEvent
CreateEventW
lstrcmpA
GetCurrentThread
GetVersionExW
SetErrorMode
GetCurrentProcessId
FileTimeToSystemTime
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GlobalReAlloc
GlobalHandle
LocalAlloc
LocalReAlloc
CompareStringW
GetLocaleInfoW
GetSystemDefaultUILanguage
GetUserDefaultUILanguage
GlobalFlags
VirtualProtect
CreateFileW
DeleteFileW
FindClose
FindFirstFileW
GetFileSize
GetFullPathNameW
GetVolumeInformationW
LockFile
SetEndOfFile
UnlockFile
DuplicateHandle
GetCurrentProcess
FileTimeToLocalFileTime
GetFileAttributesW
GetFileAttributesExW
GetFileSizeEx
GetFileTime
SystemTimeToTzSpecificLocalTime
GetPrivateProfileIntW
GetPrivateProfileStringW
WritePrivateProfileStringW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
ResetEvent
WaitForSingleObjectEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
KERNEL32.dll
MessageBoxW
GetActiveWindow
MsgWaitForMultipleObjects
PeekMessageW
TranslateMessage
DispatchMessageW
GetClientRect
SetRectEmpty
OffsetRect
GetParent
GetSubMenu
GetMenuItemID
GetMenuItemCount
UnhookWindowsHookEx
RegisterWindowMessageW
GetMessagePos
GetMessageTime
SendMessageW
PostMessageW
DefWindowProcW
CallWindowProcW
RegisterClassW
GetClassInfoW
GetClassInfoExW
CreateWindowExW
IsWindow
IsMenu
DestroyWindow
SetWindowPos
BeginDeferWindowPos
DeferWindowPos
EndDeferWindowPos
IsWindowVisible
IsIconic
GetDlgItem
GetDlgCtrlID
GetFocus
GetKeyState
GetCapture
EnableWindow
GetMenu
SetMenu
UpdateWindow
GetForegroundWindow
SetForegroundWindow
BeginPaint
EndPaint
ValidateRect
RedrawWindow
GetScrollPos
SetPropW
GetPropW
RemovePropW
GetWindowTextW
GetWindowRect
AdjustWindowRectEx
ScreenToClient
MapWindowPoints
GetSysColor
CopyRect
PtInRect
GetWindowLongW
SetWindowLongW
GetWindowLongPtrW
SetWindowLongPtrW
GetClassLongPtrW
GetClassNameW
GetTopWindow
GetLastActivePopup
GetWindow
SetWindowsHookExW
CallNextHookEx
LoadIconW
WinHelpW
MonitorFromWindow
GetMonitorInfoW
GetMessageW
GetCursorPos
CheckMenuItem
EnableMenuItem
SetMenuItemBitmaps
GetMenuCheckMarkDimensions
SetMenuItemInfoW
LoadBitmapW
PostQuitMessage
ShowWindow
IsWindowEnabled
SetWindowTextW
GetWindowThreadProcessId
GetSystemMetrics
ReleaseDC
GetSysColorBrush
LoadCursorW
DrawTextW
DrawTextExW
GrayStringW
TabbedTextOutW
ClientToScreen
DestroyMenu
RealChildWindowFromPoint
CharUpperW
SetCursor
SetTimer
KillTimer
InvalidateRect
USER32.dll
GetDeviceCaps
SetBkColor
SetTextColor
CreateBitmap
DeleteDC
DeleteObject
Escape
GetClipBox
GetStockObject
PtVisible
RectVisible
RestoreDC
SaveDC
SelectObject
SetMapMode
TextOutW
ExtTextOutW
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
OffsetViewportOrgEx
ScaleViewportExtEx
ScaleWindowExtEx
GDI32.dll
OpenPrinterW
DocumentPropertiesW
ClosePrinter
WINSPOOL.DRV
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegQueryValueExW
CreateProcessWithLogonW
RegCreateKeyExW
RegDeleteKeyW
RegEnumKeyW
RegQueryValueW
RegDeleteValueW
RegSetValueExW
RegEnumValueW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
PathFindExtensionW
PathFindFileNameW
PathIsUNCW
PathStripToRootW
SHLWAPI.dll
CLSIDFromProgID
CoCreateInstance
CLSIDFromString
CoGetObject
StringFromGUID2
CoInitialize
CoTaskMemFree
CoDisconnectObject
CoUninitialize
CoCreateGuid
ole32.dll
OLEAUT32.dll
LresultFromObject
CreateStdAccessibleObject
OLEACC.dll
OutputDebugStringW
RtlPcToFileHeader
RtlUnwindEx
GetCommandLineA
GetSystemInfo
VirtualAlloc
VirtualQuery
HeapQueryInformation
GetStringTypeW
SetFilePointerEx
GetConsoleMode
ReadConsoleW
GetConsoleCP
LCMapStringW
GetTimeZoneInformation
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
SetStdHandle
WriteConsoleW
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVCStringArray@@
.?AVCAfxStringMgr@@
.?AVCException@@
.?AVCOleException@@
.PEAVCOleException@@
.PEAVCObject@@
.PEAVCMemoryException@@
.?AVCSimpleException@@
.?AVCMemoryException@@
.?AVCNotSupportedException@@
.?AVCInvalidArgException@@
.PEAVCSimpleException@@
.PEAVCNotSupportedException@@
.PEAVCInvalidArgException@@
.?AVCNoTrackObject@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AVAFX_MODULE_STATE@@
.?AV_AFX_THREAD_STATE@@
.?AV_AFX_BASE_MODULE_STATE@@
.?AVCWnd@@
.?AVCCmdUI@@
.?AVCComObjectRootBase@ATL@@
.PEAVCUserException@@
.?AUIOleWindow@@
.?AUIAccessibleProxy@@
.?AUIAccessible@@
.?AVXAccessible@CWnd@@
.?AVXAccessibleServer@CWnd@@
.?AV_AFX_HTMLHELP_STATE@@
.?AVCAccessibleProxy@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AV?$IAccessibleProxyImpl@VCAccessibleProxy@ATL@@@ATL@@
.?AVCTestCmdUI@@
.?AV?$CComObjectNoLock@VCAccessibleProxy@ATL@@@ATL@@
.?AVCWinThread@@
.PEAVCArchiveException@@
.?AVCArchiveException@@
.?AV?$CArray@VCVariantBoolPair@@AEBV1@@@
.PEAVCOleDispatchException@@
.?AVCOleDispatchImpl@@
.?AVCOleDispatchException@@
.?AVCMapStringToString@@
.?AVCTypeLibCacheMap@@
.?AVCMapPtrToPtr@@
.?AVCPtrArray@@
.?AVCFile@@
.?AVCMemFile@@
.?AVCWinApp@@
.?AV?$CArray@W4LoadArrayObjType@CArchive@@AEBW412@@@
.?AUCThreadData@@
.?AVCResourceException@@
.?AVCUserException@@
.?AVCGdiObject@@
.?AVCDC@@
.?AVCMenu@@
.?AV_AFX_D2D_STATE@@
.?AVCHandleMap@@
.?AVCFileException@@
.PEAVCFileException@@
.?AVCDataRecoveryHandler@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PEB_WV12@PEB_W@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PEB_WPEAVCDocument@@PEAV3@@@
.?AV?$CMap@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PEB_W_N_N@@
.?AV?$CMap@PEAVCDocument@@PEAV1@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@PEB_W@@
.?AVCByteArray@@
.?AVCObList@@
.?AVCStringList@@
.?AV?$CArray@U_CTaskDialogButton@CTaskDialog@@AEBU12@@@
.?AVCTaskDialog@@
.?AVCObArray@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVCObject@@
.?AV?$CArray@PEAVExposedObject@@PEAV1@@@
.?AUIUnknown@@
.?AVActiveScriptSite@@
.?AUIActiveScriptSiteWindow@@
.?AUIActiveScriptSite@@
.?AVCAppEventListener@@
.?AUIDispatch@@
.?AVCCmdTarget@@
.?AVXEnumVARIANT@CEnumVariant@@
.?AVCEnumVariant@@
.?AUIEnumVARIANT@@
.PEAVCException@@
.?AVExposedObject@@
.?AVCOleDispatchDriver@@
.?AVScriptEngineFactory@@
.?AVCResourceUtils@@
.?AVCScriptUtils@@
.?AVCUnnamedArguments@@
.?AVCNamedArguments@@
.?AVCArguments@@
.?AVCTextStream@@
.?AUIAtlStringMgr@ATL@@
tb>_"l
;	gdFI
_Qj7H`
WWZu(,*,wz
%xnI5U
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING