PE Compile Time

1971-05-16 03:00:00

PE Imphash

ace3ae037e90280ce02cd485f8319367

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.rsrc 0x00001000 0x00014440 0x00014600 6.91175633854
.data 0x00016000 0x00001094 0x00001200 5.12765388522
.rdata 0x00018000 0x0009e304 0x0009e400 7.90737838058
.rdata 0x000b7000 0x000027e4 0x00000000 0.0
.CRT 0x000ba000 0x0000000c 0x00000200 0.110557131259
.rdata 0x000bb000 0x000009a5 0x00000a00 4.9525955158
.rsrc 0x000bc000 0x0002703c 0x00027200 6.38034726923
.l1 0x000e4000 0x00001000 0x00001000 4.69373738141
.text 0x000e5000 0x00027200 0x00027200 6.36377170263
CPADinfo 0x0010d000 0x00001000 0x00000e00 5.34529946419
.text 0x0010e000 0x00001000 0x00000200 4.43167922584
.text 0x0010f000 0x00001000 0x00000800 4.75302840285
.pdata 0x00110000 0x00001000 0x00000800 4.68925862578
.idata 0x00111000 0x00001000 0x00000200 2.65139201815
.idata 0x00112000 0x00001000 0x00000400 3.00356459909
.idata 0x00113000 0x00001000 0x00000200 2.75460313071

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_ICON 0x0010b53c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2835 x 2835 px/m
RT_GROUP_ICON 0x0010b9a4 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0010ba00 0x00000644 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library kernel32.dll:
0x4e41e4 GetLastError
0x4e41e8 SetLastError
0x4e41ec GetTickCount
0x4e41f0 ExitProcess
0x4e41f4 GetStartupInfoA
0x4e41f8 GetStdHandle
0x4e41fc GetCommandLineA
0x4e4200 GetCurrentProcessId
0x4e4204 GetCurrentThreadId
0x4e4208 GetCurrentProcess
0x4e420c ReadProcessMemory
0x4e4210 GetModuleFileNameA
0x4e4214 GetModuleHandleA
0x4e4218 WriteFile
0x4e421c ReadFile
0x4e4220 CloseHandle
0x4e4224 SetFilePointer
0x4e4228 FreeLibrary
0x4e422c LoadLibraryA
0x4e4230 GetProcAddress
0x4e4234 DeleteFileW
0x4e4238 MoveFileW
0x4e423c CreateFileW
0x4e4240 GetFileAttributesW
0x4e4244 GetConsoleMode
0x4e4248 GetConsoleOutputCP
0x4e424c GetOEMCP
0x4e4250 GetProcessHeap
0x4e4254 HeapAlloc
0x4e4258 HeapFree
0x4e425c TlsAlloc
0x4e4260 TlsGetValue
0x4e4264 TlsSetValue
0x4e4268 CreateThread
0x4e426c ExitThread
0x4e4270 LocalAlloc
0x4e4274 LocalFree
0x4e4278 Sleep
0x4e427c SuspendThread
0x4e4280 ResumeThread
0x4e4284 TerminateThread
0x4e4288 WaitForSingleObject
0x4e428c SetThreadPriority
0x4e4290 GetThreadPriority
0x4e4294 CreateEventA
0x4e4298 ResetEvent
0x4e429c SetEvent
0x4e42b4 MultiByteToWideChar
0x4e42b8 WideCharToMultiByte
0x4e42bc GetACP
0x4e42c0 GetConsoleCP
0x4e42c8 EnumResourceTypesA
0x4e42cc EnumResourceNamesA
0x4e42d4 FindResourceA
0x4e42d8 FindResourceExA
0x4e42dc LoadResource
0x4e42e0 SizeofResource
0x4e42e4 LockResource
0x4e42e8 FreeResource
0x4e42f0 CopyFileA
0x4e42f4 CreateProcessA
0x4e42f8 GetVersionExA
0x4e42fc CompareStringA
0x4e4300 GetLocaleInfoA
0x4e4304 EnumCalendarInfoA
0x4e4308 FormatMessageW
0x4e430c CompareStringW
0x4e4310 TerminateProcess
0x4e4314 GetThreadLocale
0x4e4318 SetThreadLocale
0x4e431c GetUserDefaultLCID
Library oleaut32.dll:
0x4e4324 SysAllocStringLen
0x4e4328 SysFreeString
0x4e432c SysReAllocStringLen
Library user32.dll:
0x4e4334 MessageBoxA
0x4e4338 CharUpperBuffW
0x4e433c CharLowerBuffW
0x4e4340 CharUpperA
0x4e4344 CharUpperBuffA
0x4e4348 CharLowerA
0x4e434c CharLowerBuffA
0x4e4350 GetSystemMetrics
0x4e4354 MessageBeep
Library RPCRT4.DLL:
Library user32.dll:
0x400000 GetKeyState
0x400004 GetSysColorBrush
0x400008 PeekMessageA
0x400010 DestroyCursor
0x400014 OffsetRect
0x400018 GetWindow
0x40001c DefWindowProcW
0x400020 CheckDlgButton
0x400024 IsDlgButtonChecked
0x400028 DispatchMessageA
0x40002c GetDlgItem
0x400030 InSendMessage
0x400034 wvsprintfW
0x400038 GetWindowWord
Library untfs.dll:
0x400000 Recover
0x400004 FormatEx
Library kernel32.dll:
0x400000 GetFileAttributesW
0x400004 GetVolumePathNameA
0x400008 FindNextFileW
0x400010 CreateFileMappingW
0x400014 AddAtomW
0x400018 ReplaceFileA
0x40001c IsBadReadPtr
0x400020 GetNumberFormatW
0x400024 GetModuleFileNameA
0x400028 CreateMutexW
0x40002c GlobalReAlloc
0x400034 SetFileTime
0x400038 BackupWrite
Library urlmon.dll:
0x400000 IsLoggingEnabledW

!This program cannot be run in DOS mode.
.rdata
.rdata
.rdata
@CPADinfo
@.text
@.text
`.pdata
@.idata
@.idata
@.idata
&>6p0K
??H6<=i|
tfvur4
ft}v^U@,
nt|v^U
vUvD^>
y|fDwY
mvqq@'
u>7<u25
> C|g^
vwt_RM
U4]v>&4
hvPz?%
<ef<1
Jf\g|q
}\}vUz>=
tvwt@-
>6< {~
1= }#p
v^Ud>
<(GvN5
>?>0C|f
E?4=0w
==0sqw
pcvwE=
pcvwE=
a4Ij>"v
u>&\Z43
<5K|qLD
H|E\M~
u>6:0KO
K&>67H
|R&>64N
K&>6> K~
<5K$_%H
\r>-_$I
%<0g$W
iplz9K
t>6<0K~
|R&>64N
> KvMt
q>,\b4
q>2\~pq
>">8[~
>?H`7v
L>6<v.
\r>-_PI
\1>-_8Q
|R&>6_`#
u%vOt4%
<0KvwQ
u>7<0K
<0G4Wq>6<0K
>e4Z?u
~>-_XH
|R&>6_pK
|R&>6HF_
|R&>6_
< K<tu
HpAz9N
Zqtv|G
Zqtv|G
K\G4Ww>7
|R&>4>
|R&>4>
|R&>4>
<5K$_%<
|R&>4>
<5K$_%<
uDPqpg
c&>6> K~
!< [x=
Y>6Hf>32
t>6<0S~
<(o|oP
gvpq\
|R&>6H
>4< [~
%< ope
v_E>64
H\ov_t=
Hvwt>p
<0C<u}
<0C<tu
!: {|G
>6<0K|
v_t>7<
:0KOHu
Hv_w>6_
|R&>4>
|R&>4>
Hv_w~6
Hv_w~6
<5Kvwt45
<5Kvwt_n
v_t>7<0{
v_t>3>
u>6<0K
#?6> K|y
#?6> K|y
uDP< gx
wv]}:
<5Kvwt>
7:7L|q
#>3p0K
:8KO/&
<5Kvwt4
9:0O|n
<5Kvwt>7<0
>f<usu
Hv_t>4
c&>6p0c
H|o.~6
H|m\u|G
Hvwt4'
g&>6p0g
^UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
uswI|W
?H_J$K
16r7n~
jOb-mM
~uc#NF
zhO^'n
[eIU _
8,C/96
"}f_!?
(A<:5!
]SPuDFIzvr
27u[SS
>7G/:z8
0ni6<n>
+IS zB)
'OeG~f
8]eiJ0
[g0n~iB,
W:z8d
<VDv2M
.Khn{{1
2jb;yy
=2*/pG}
k{q3Go:z8
kSuhQk
3QvSfF
;-{DKR^F
K[}6.X
(5.:6O
qUtFu?
!eiB)l
Fm,Iv_
mU:?XC
uF6xS$
Vms-RD
dofV,lS
mbf!!FRj
)@ix}M
cFvZ$
;'O|g]
(jEIB~w
}\JRHK19
Po1F}m
"Qd]dF,
3pK1Ge
W2dddC
:DFbH9
hx}2pS2~
e>5qy~
jSkao.
PmRfjz
<nH[1E
CXXPGz
{*W:2I
XSSzhf
zB)-oo
.x]:@r
3'|LF/O
H.z i2
ywL<n*
vKV/{0
w9cq~>D
XkozhL
+`tFbF
3pK1Ge
8,C/96
Faiz8n>
w>VB=
^yyc`p
eH&xOQ
6+`tVZ
]JW.p
syyk`p
OFyyc`p
H{#/:
NJI~}k
+;[eUU$
?H]SGp
V?#)\w
#Z\JLn
Z$q+;[U]
!r}ryb
_&HTV^"
ULO7C$l
y7o<n(c
IjAg.K9a
s0 y:ZIs
/'j,8_
$zpIAeh3?_uy
~i>2kMR6hu_.e
2Zh9+;_
"8Ht,LA
ymcF{D
0y<n>
;z81jv
4(qj$9f
?H=GSWL
,zB\Uw
W:r~Et
ym#n5e
"8Ht,G
//x,8=
yoI<nJ
M,2~2hk
/g0,8Y
z>EIjq
[eyU<-pyj1P
sTfzzP1{2UG
7dWMyzE
)HBP i&g5
"VksC)\
h|Buw|
yyZ8S^
)@khy3
+;]mq6
:zLOOM
E<d:d;
U_o8btF-~
Mxj~28
0[x ZI
>Hxr/-R\
9MDacy,
LM$,nO
^@x?M
L4OfBm
]O$G 9
.@Q:@G
|~u#y>
.Igsy#
\xA?H>
O^HhmZw
L%FLi8C^E
233we9q~t
,nIyJjN
9{]=Wa
{hJ^'ms
hxm3q`
4a2{Vr
wi0q~p
Vkk-7H
Df?[6L
0C cy~
+I[(iB)~5
:dX@pm
sxDy:\
I9m?~:
d"8Os'
pn-"|
h+`rF^i
I{Mb'/
(J_5HB
+;]eqt
h~}?q\
BrInK,\
"LP.,8+
1p3zh8
[pG}"}
?Fxt0[
"N@",8+
1G;:z8
zPB7$z
i8C^E
=zhJ^Gm
!ivg-|6
"KL|vC8
<nL[1Z
_g ym'
kRo&x`2
"8Nc7N
/e33~c
9btF-~
T:dX@H
6Z.<q2@
~X&(m[%9
/ePGrT;
_~u#qp
?o>NHr
#8HsK/
FcIh%d
TRu8EZ
mS3qPV(@k~
KIz&+n
CXs3[]c
8bvF!p
ZkOqzj
?Lc/D.A
nv@0E7
j"g8p.$T
@O@HE*
e>+VV
M]]tF^
It]J *>
QQP"UE6
z2SG=v
K.{tI9+
'HRfrzT
U|z~<s,
s+,;Ex
4_@\&=k
l"9pBfW
=nL[9ZP~*;
;@tS0n
(@mx}R
"HRF~w
Tzu8EZ
4(]<]7z/"
,(rzB_
=oxvw^
Jx)gyL
#r{j8+
slno>H)
.eRGnZ
xJAoG}
vuj=g1pm
y&?1|<
bC:.DjC
:zN_+~
%9goOi
na2{Vr
FI?Lm/7
p}k{)R\
?H>J^<|
%jA^pNEA
kG#Qca
?LTVW
9DvuFh:
;zJ_/.
#|shUEH
;d^@<mJC
&Qd]fP
x;d^@xm
{a2sVr
<+TtEx
XO{h/
~U[3k+
ZzS&H&#
0_GHxm
-1[xm/
k{QR<a
<nJ[!Zt
0L5M-n
~EpH|E
!Ia\>~
k%>)B/
v/J.{tI=+i
LC;\sz
>R`O;z
&Lb^@@m>\
It>*b=
y3U3Mei ,
cF*,#:L
<nJ[1E
xmeQ|D
h1N/eP
0>-~B)
~Q.3kK
"LP2,8+
Hz7!ip
~fy{"4
x}WqTf1n
k,%Rq
?+e8 i
8btF-<
4k{'=G
`Ff+1:WY
9}]14jj;yy
ymeApF
In]$9p
PvX<f!G
OCHzB)
Fe{zBr
Zoa~2~
I[(zB)~5
3(@mx!R
R@^gIa
j~-?EOjUmQ
=HCzh8
uB@=ozv{
QuN&x[
pq m#8
^*49Kg
Ep@(E'
8ypfkZo
o;Tzz
^r:x}28~2~
=21~hK
>Rd1;zJ_+.
t0~wv}
Lc;\rx
UFN7(w
<qXl1n
,8^@Y~
;:c+.@@
>f5}Fa
!,n;Z0|
*;)F;A)
9El;d
Ira%v2
"IUm=~
-HQ2~[
vS8oM;
a3y~}
7.<n~i
"k?qgC
XG\xhJ\$
5;N?H)
e2>E=ID8
GzS.e$
1k8+;)$
;@3zh8
ip;F!0
"r7&H&,9
w/n(,n;
\ks}1_?:z8
4b&;yy
H'zh8"N
-2NwM:
a>k%;0zY
hTqS1s5
I@A(L
2<u2~IM
b|EvP8&
qN8MfB
ZBA,oO
(#2{.'[
!#0"Rw
yF!e!d
A\G`E6h
b =,W)
RJD+oD
(Fg?3>
#9pIjD
I&:N]C
!1wxO;
0)~8,n;
eSW/ZX
j&;yyE
zzSppy~
:S{'=
G]Z,KM/~f
!N-Pjd+
B5NH{kJ
}]u6zV;yy
QL",lX
:S{'=
{2UWa&
0MsFrV
q|BOn
H"=9<\
3y:}1ER
u[JKa:
r|#O^s
N4S@FrUQ
lh%zIh8
feQxD
iZsn>xDq
PFRfzz
?_Kg2v|'w
<n)7{M
-8 9v;
37f%B]
'Dqe/M3/
ryg;?~
/:W,W
~f{{*6
b&2=sJZ
}]9<?2
7zhN^'r
~2j&zgr
/zeJ6B=
\d3?Hu
r%mybu
J&JvxxtgK
e8F?_}
Z@D+;>i
uQ@5X8
<y;p2Mei8
%:zh8@
8,C/96
<ykw2M
p}>HDcoW
&e2&>VmE
~ew2kI
]XsWiKV
Dsdy N
q4{)@)
]kCy:.
pyhV#|
sH&Ipz@<{2W
/Ll/{L9
<VxK"w
LqC,nIIV2
6qkJ:C
q`?0nh>
F7moOI,K
rQ~ybsV^
;{2SGqv
,/{tI1+
&:.LjC
q}m|>3
/KG,8]
xYpfQ
y{r2Mg
~9~2k)
vFF9)&
d+`rF6
:su|{z
y&HRfr[,
=x3Kpf2
b&2=sJZ
?-m< i
}G%V,M
g[J$*r
ut(DiDL
6vL"Od
5SUzpG
y~*: C
~Ni-:~
rE*&(3
\L9?H=
%+4"03
{yF,E-T
JaHaH0
6$2\),
5Du83P
TfED-xx
=VtyX:
;YS!&7A
uBz9@|
B-GAE@
N}@m*(V
.)<moL
,wO}Q3iZbAk
O>NnI/
0wI"Z)~
]z]|ic0_+
O8lNbx
tr=XdI
wp8nEc
,t`k~+ar
|pl_DR
>*&hS:O
)X0}Nk
[(L9OU
@6BqDI
k=BPMRF
f,)f ^
{@}FzNh.
0Jfw2P
-\Gv<u
P#<E\bi
N!R[>@i
|wJwop
GnLv$<v
"|O5(5Y
:\VVm(xQ
a>Q%}pc
mtu8nYP
E/wzf@"
L/;,R+
p_yo/Z2QU
6]?&f0H
fm(kSM
uP91~C{m
8Z(iEn\
N:hc_>
>Wiyi)
kY?nZf}=
ge`]#P
9wR=n\5
ORZ'l$r
H>Zi'V
0;}%VZaFk
Yq\<lv8
6m#e?W
iFo6.}
aXYOSI
de%&4G
<, uPu
~jT?7
l:)h>1,
m8/o(v"
.x^=R,
m)FdrV
.6~Ky!X
AQ:HtxB
*Zr(8F
St{ze?
y8cqVM
wA_Vh<
4N#`B1bf
(g<'21/
zL<&Zf
.H*.?[OT
6t>&gtLd
\ l2fg^
x7riQ9
IvvQ_Z
ZIF}[bC
/HOBw`<
xWpF>)B
1+N{!||
0#B^<pW@m
p7oC.K
x}h30+
ex+*,fh3!
aw'7]{
m8b]S
1bJ{(2B
&n[9-+
Dhs'lncH
W{ oMH
dVCxYR
_iiR7P&
[CNI_:|@
6M-%Vs_
~j"u8
9tTbyO`
#>4>Zz
Tcl`Q]tm
&>e9h1
:dZD#q,
vA}>Em
'=G~f
DxHpG}
2pf%A"8:>,8+K"A
$)@3~E
O2"zh8
5pf%E"8:?,8+J"A
:<f!E0n~
&H&%ym
~5W~9?3I
O24zh8
5T:,e^
DxGpG}
KyA?H)
'=E~f
;)@;~E
2,n;0q}5>E=%:z8
O25zh8
O27zh8
P~a)L#N;Mhl#F W
H2'=C
|Z>E=':z8
6,8+@"A
8<f!F0n~
4zc\?H)
b}q}8
3pf%B{ac5
'=G~f
DxFpG}
8,n;=q};
)@6~E
DxLpG}
Ky@?H)
&H&#ym
3pf%C"8:>
>)@=~E
z68:d,
t:3X?H)
py~?a
c'=B~f
&H&"ym
Gx:z8
>)@<~E
Zb'=W~f
8<f!G0n~
O26zh8
~2~*!o
Cy:.G+1
>)@<~E
'=I~f
9)@>~E
iJ(lncqF|
2+;)4zB)
&H&'9-5
pf%["8:=,8+C"A
8<f!G0n~
5,n;8q}?>E=/:z8
K{yc-t~f
O29zh8
]<rd$J"8:6
0pf%A"8:5,8+C"A
<n>2M
-+;)"zB)
DxEpG}
KyE?H)
\FP_YA
8<f!G0n~
8<f!G1o
<q}>>E=-
8<f!G0n~
q}pf%C
,8+L"A
2D*A>29X
+;)!Lt
DxGpG}
KyC?H)
'=F~f
=)@9~E
Qg'=G
[O.466
O26zh8
Yv z*@
KyC?H)
P{:o
[30 6=SG
ly=UoK
-VhvN\x
Vu,14q
bRf NdZ
m^('yn
fgAxc<
*Fc~-<
$P)r{H
\+:3K,
HmVTS/z
-8tcpsf
xp.q?b
&s ]'7
/WS?t2
:-?g9g
(}^w#V4Y
'[2skQ*
d88<c-
_1{>^dm
h:%|Q/
$UjI.
CE:oTp
y# k~
!~p?7sU~
ay/{HO
-& 8u&
10su[Ao
oz!iIJ
9T 9M
B*2fK"=
R#qnfL
<\8#3?
+hxi+6
ZB2Y`
GRDi43
(BL/fx
W,"<?E
Z^>F&G
MK $?D
{W5U
q%|OF)
((XlI'
?BG([G
4B(y\*
cbPqUK
WsU;Ce
H-i28E
&7+9A[Q
*s!@9i^
Rh3$QvJ
&O[C>
Sjq||4
TlPQ-0
>]6%{I
CL{Dy"
QY.i;H
1;mfF{
'4!iKY
j/ {!.DF8aN
Hd.,F?
yn}kIY
c85vGI,
f]/`b;
*M$?RXE
?TgZ[x
>Y!}4!k
PE=bgc
H&Vbe#
.oB-A
rqnWU
IvL)=prs
`Z\ngZa
H(2+07
w42|g @Y
nPQj?:
v19Y-3$
K -n#@
LX_R0OC
r:]i2HF2
}`Q>WQ
6E@n*f
z2RQz@
)Fsx^Si\M%-
``S^2@
BG>#ac
0u\z"h
NZTu(\
Xi1nWr
O3Q!DC
9o Ulf
&Vnm2f
P^w[m7Cg
08L-[v
O4hcc*
jn}5Sq
p7zQQ*",
-|eG)
uAD\0LM `
/4#~)p_
[" f%4]
;HkfB(*
Cj(>:ZE
q{8]D%+,\"
?r[~Y
\'j5p[&
DxDpG}
?e#P0n~
8,n;<q}=
O27zh8
pf%M"8:2,8+A"A
6,n;7q}7>E=(:z8
O22zh8
1pf%C"8:6
:<f!E0n~
(+;)%zB)
8<f!G0n~
=,n;1oc
n-C'j.e$
:<f!O0n~
&H&%ym
DxBpG}
KyH?H)
'=L~f
4)@5~E
:,n;8q}5>E=>:z8
9,n;>q};>E=%Y
fo{7L48f.
B~NpG}
8,n;=}q
>)@=~E
pN'=A
8,n;=q}:
>E=$:z8
<f!L0n~
3pf%B"8:6,8+C
>)@=~E
8,n;=q};
O2=zh8
)@2~E
+oeTpG}
1!<f!F
KyC?H)
&H&#ym
g.)-2k?
3pf%B"8:2zn
KyJ?H)
>)@=~E
wi)@8
Ky@6A,
&H&"ym
3pf%@"8:?
>)@<~E
8<f!F0n~
<q}>>E=-:z8
&H&%ym
&>.<%zB)
&H& ym
sr$0.^"A
py~b<%=
?D=4:z8
O26zh8$z
KyO?H)
'=F~f
>)@?~E
,8+G"A
b&;yy2
O22zh8
3pf%B"8:7,8+A"A
&H& ym
DxEpG}
3pf%@g}
'=G~f
,+;) 8
,+;) tL/
h~(M"8:3,8+A"A
N(<f!F0n~
,+;) zB)
/A-@.e$
I~-hF20
kZb.t$
>)@=~E
9,n;=q}<>E=-:z8
GetLastError
SetLastError
GetTickCount
ExitProcess
GetStartupInfoA
GetStdHandle
GetCommandLineA
GetCurrentProcessId
GetCurrentThreadId
GetCurrentProcess
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
WriteFile
ReadFile
CloseHandle
SetFilePointer
FreeLibrary
LoadLibraryA
GetProcAddress
DeleteFileW
MoveFileW
CreateFileW
GetFileAttributesW
GetConsoleMode
GetConsoleOutputCP
GetOEMCP
GetProcessHeap
HeapAlloc
HeapFree
TlsAlloc
TlsGetValue
TlsSetValue
CreateThread
ExitThread
LocalAlloc
LocalFree
SuspendThread
ResumeThread
TerminateThread
WaitForSingleObject
SetThreadPriority
GetThreadPriority
CreateEventA
ResetEvent
SetEvent
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
MultiByteToWideChar
WideCharToMultiByte
GetACP
GetConsoleCP
SetUnhandledExceptionFilter
EnumResourceTypesA
EnumResourceNamesA
EnumResourceLanguagesA
FindResourceA
FindResourceExA
LoadResource
SizeofResource
LockResource
FreeResource
GetWindowsDirectoryA
CopyFileA
CreateProcessA
GetVersionExA
CompareStringA
GetLocaleInfoA
EnumCalendarInfoA
FormatMessageW
CompareStringW
TerminateProcess
GetThreadLocale
SetThreadLocale
GetUserDefaultLCID
SysAllocStringLen
SysFreeString
SysReAllocStringLen
MessageBoxA
CharUpperBuffW
CharLowerBuffW
CharUpperA
CharUpperBuffA
CharLowerA
CharLowerBuffA
GetSystemMetrics
MessageBeep
kernel32.dll
oleaut32.dll
user32.dll
pages initiated remotely by the program (measured explicitly in the program as Received Dat
PovDk'
EDvyQ`E
S-5Zi=4
^Q?Cor0
fEXR(i
@"9zNM
Y|NZf@[9
CHtenJ
adDsJT@% V
0mM^6M.
=9'-L>
*|nb'J
:iJM`ZN
saiN8}
krm]\y
Iakf(b}G
gs3[-?
YW\S*d4Z
R7o\X-
pXYbyd
`D^v:G
/O->B
!E1{nU
gXs1EF
D nh~F
kqQR(1
+A-:~^
SI.CTz
8GEQlY
xmyt;!
.hKtE:
_yhQ|}
:QkSYQ9
kTkh'NA|
5_O)7?
UaM>9A
.lnG_nT
A?n(V#&6
m,B%6
^gW^ZUw
_8@;kK5
{Oa'MAy
5>`|6}
jF!7=y
fs@F'D(&
Bp|z1L
Ni}H4d
bbIDAT
R^wtdd
]PU_F-
2>k7s{
=e|qp4
EM@@SG
*`z6^lc
Ofnvs
*WeTt*
V?UV!-
WhF!;;_^7
j@I4r5
]'P5L%q}
&e:k92r
8o8<K.
f-F {w
7'#2J!
,ENJi^l
Q$Au#0>
mO!:~CZ
q3l6[U
Vyx-gU
iJs!nFjz
x\U%v1v
^z5j>3Z
hv!eT)@F
y${:~W
dkGiO@P
h'Q"iMC^
mamAT
!Ud>qn
L8c0dH!
t]5TU
%j{myy$
Umd-3E;
II*)}/
zo$S{t
x2~%n_
7UUuQUU+
]|5/\CK
re!`qu
uefUQL
VWW9p
)00rp%%k
i22y{33y
66|{JJ
i44xx77zy
&&e}@@xR
3GGzY33rv00s
88x|KK
==|qCC}e55rs$$e
88xF11vI
%%il##e
&&iU!!#
::{ ((oc
!!nv**t^{{
%%hW##fhgs
##hnev
k_""nMPP
%%h= fK
hW""iO
""g"h)
PA<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="CompanyName.ProductName.AppName" type="win32"/>
<description>Your application description.</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />
<!-- Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />
<!-- Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />
<!-- Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />
<!-- Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>False</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>THE FEES PAID TO ORACLE FOR THE PROGRAM LICENSE AND ANY UNUSED, PREPAID TECHNICAL
found to be counterfeit or improperly licensed, activation will fail. The software will notify you if the
agreement and any Oracle ordering document shall supersede the terms in any purchase order or other non-Oracle ordering
revenue-generating activities.
the program, then sold within the previous 12 months.
1. Third Party Programs. The software may include third pard@
GetLastError
SetLastError
GetTickCount
ExitProcess
GetStartupInfoA
GetStdHandle
GetCommandLineA
GetCurrentProcessId
GetCurrentThreadId
GetCurrentProcess
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
WriteFile
ReadFile
CloseHandle
SetFilePointer
FreeLibrary
LoadLibraryA
GetProcAddress
DeleteFileW
MoveFileW
CreateFileW
GetFileAttributesW
GetConsoleMode
GetConsoleOutputCP
GetOEMCP
GetProcessHeap
HeapAlloc
HeapFree
TlsAlloc
TlsGetValue
TlsSetValue
CreateThread
ExitThread
LocalAlloc
LocalFree
SuspendThread
ResumeThread
TerminateThread
WaitForSingleObject
SetThreadPriority
GetThreadPriority
CreateEventA
ResetEvent
SetEvent
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
MultiByteToWideChar
WideCharToMultiByte
GetACP
GetConsoleCP
SetUnhandledExceptionFilter
EnumResourceTypesA
EnumResourceNamesA
EnumResourceLanguagesA
FindResourceA
FindResourceExA
LoadResource
SizeofResource
LockResource
FreeResource
GetWindowsDirectoryA
CopyFileA
CreateProcessA
GetVersionExA
CompareStringA
GetLocaleInfoA
EnumCalendarInfoA
FormatMessageW
CompareStringW
TerminateProcess
GetThreadLocale
SetThreadLocale
GetUserDefaultLCID
SysAllocStringLen
SysFreeString
SysReAllocStringLen
MessageBoxA
CharUpperBuffW
CharLowerBuffW
CharUpperA
CharUpperBuffA
CharLowerA
CharLowerBuffA
GetSystemMetrics
MessageBeep
CreateStubFromTypeInfo
kernel32.dll
oleaut32.dll
user32.dll
RPCRT4.DLL
PovDk'
EDvyQ`E
S-5Zi=4
^Q?Cor0
fEXR(i
@"9zNM
Y|NZf@[9
CHtenJ
adDsJT@% V
0mM^6M.
=9'-L>
*|nb'J
:iJM`ZN
saiN8}
krm]\y
Iakf(b}G
gs3[-?
YW\S*d4Z
R7o\X-
pXYbyd
`D^v:G
/O->B
!E1{nU
gXs1EF
D nh~F
kqQR(1
+A-:~^
SI.CTz
8GEQlY
xmyt;!
.hKtE:
_yhQ|}
:QkSYQ9
kTkh'NA|
5_O)7?
UaM>9A
.lnG_nT
A?n(V#&6
m,B%6
^gW^ZUw
_8@;kK5
{Oa'MAy
5>`|6}
jF!7=y
fs@F'D(&
Bp|z1L
Ni}H4d
bbIDAT
R^wtdd
]PU_F-
2>k7s{
=e|qp4
EM@@SG
*`z6^lc
Ofnvs
*WeTt*
V?UV!-
WhF!;;_^7
j@I4r5
]'P5L%q}
&e:k92r
8o8<K.
f-F {w
7'#2J!
,ENJi^l
Q$Au#0>
mO!:~CZ
q3l6[U
Vyx-gU
iJs!nFjz
x\U%v1v
^z5j>3Z
hv!eT)@F
y${:~W
dkGiO@P
h'Q"iMC^
mamAT
!Ud>qn
L8c0dH!
t]5TU
%j{myy$
Umd-3E;
II*)}/
zo$S{t
x2~%n_
7UUuQUU+
]|5/\CK
re!`qu
uefUQL
VWW9p
)00rp%%k
i22y{33y
66|{JJ
i44xx77zy
&&e}@@xR
3GGzY33rv00s
88x|KK
==|qCC}e55rs$$e
88xF11vI
%%il##e
&&iU!!#
::{ ((oc
!!nv**t^{{
%%hW##fhgs
##hnev
k_""nMPP
%%h= fK
hW""iO
""g"h)
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="CompanyName.ProductName.AppName" type="win32"/>
<description>Your application description.</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />
<!-- Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />
<!-- Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />
<!-- Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />
<!-- Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>False</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
contracts and other receivables, owned or managed for others, active on the program, plus (4) Book value of non earning
are responsible for ensuring that the named user plus per processor minimums are maintained for the programs contained in the
MICROSOFT WILL SEEK TO HAVE A NY DISPUTE HEARD AS A CLASS ACTION, PRIVATE
access the documentation online at http://oracle.com/contracts. Services are provided based on Oracle's policies for the
the TRMs. TRMs are provided to you "as-is" without any warranty of any kind. Upon termination, you shall cease using, and
G. Indemnification
processed through this application. This does not include communication on the same purchase order. For each application,
computer or device. During activation, the software will automatically contact Microsoft or its affiliate to
includes introductory terms; the Additional Terms and Limited Warranty follow and contain greater detail.
You must be a
Home Use Program User
to use software marked as
Home Use Program.
To be a
MetaLink has information on which products have been translated for the supported languages (http://metalink.oracle.com).
the forward link into your browser window. THE ADDITIONAL TERMS CONTA IN A BINDING
CONSUMER RIGHTS UNDER YOUR LOCAL LAWS WHICH THIS AGREEMENT CANNOT CHA NGE. TO
program license specifying a 1 Year Oracle Hosted Term must be hosted by Oracle.com via Computer and Administration
How can I use the software? The software is licensed, not sold. Under this agreement we grant you
Statement at r.office.microsoft.com/r/rlidOOPrivacyState15HighLight?clid=1033.
order and shall continue for a period of 1 year. At the end of the 1 year the program license shall terminate. A program license
another computer or user. You may transfer the software directly to a third party only as installed on
dispute under this agreement to which Section B applies must be filed within one year in small claims
1 Year Hosting Term: A program license specifying a 1 Year Hosting Term shall commence on the effective date of the
IRE_OLSA_V120103_Def_V122304 Page 9 of 11
notifies the Provider promptly in writing, not later than 30 days after the Recipient receives notice of the claim (or sooner if
residence or King County, Washington, if the dispute meets all requirements to be heard in the small
Program Documentation: is defined as the program user manual and program installation manuals.
must be measured at the multiplexing front end. Automated batching of data from computer to computer is permitted. You
Microsoft for information about Microsoft
s refund policies. See microsoft.com/worldwide, or in North
software acquires that copy, and lasts for one year. Any supplements, updates, or replacement software
be required to execute standard Oracle ordering materials when using learning credits to order products or services.
Full Time Equivalent (FTE) Student: is defined as any full-time student enrolled in your institution and any part-time
Microsoft provides limited support services for properly licensed software as described at
Each Implementation Service, Packaged Method, Architecture Service, Accelerator Service, Assessment Service and
license you have.
GetKeyState
GetSysColorBrush
PeekMessageA
CreateAcceleratorTableA
DestroyCursor
OffsetRect
GetWindow
DefWindowProcW
CheckDlgButton
IsDlgButtonChecked
DispatchMessageA
GetDlgItem
InSendMessage
wvsprintfW
GetWindowWord
user32.dll
.rdata
Collaboration Program User: is defined as an individual authorized by you to use the programs which are installed on a
software, which is licensed
and without express warranties, guarantees and
own most important confidential information or a reasonable degree of care, whichever is greater; (b) to maintain agreements
authorized by you to use the application programs which are installed on a single server or multiple servers, regardless of
Serving member of the Canadian Forces (CF) or their spouse;
Trainee: is defined as an employee, contractor, student or other person who is being recorded by the program.
features or not use them. For more informa tion about these features, see the Office 2013 Privacy
Workshops
The following software features use Internet protocols, which send to Microsoft (or its suppliers or service
Purchasing, Professional Users
External are allowed to manually enter orders directly into these programs but any orders
products included on an Applications NLS Supplement CD Pack have been translated. For existing supported customers,
MetaLink has information on which products have been translated for the supported languages (http://metalink.oracle.com).
were disclosed; (d) maintain the TRMs at all times on your premises; and (e) not to remove or destroy any proprietary or
microsoft.com/office/backup. You may not distribute the backup copy of the software. You may use it
How does Microsoft use your information? Microsoft uses the information it collects through the
policies. Oracle
s consulting services policies may be accessed at http://oracle.com/contracts, and are subject to change.
orders during any 12 month period.
that cannot be printed, copied or sent to others without your permission. You may need to connect to
Transaction Volume once.
Member of the Canadian Corps of Commissionaires when residing or employed on a Base/Wing;
Statement at r.office.microsoft.com/r/rlidOOPrivacyState15HighLight?clid=1033.X
information on geographic and export restrictions, visit go.microsoft.com/fwlink/?LinkId=141397 and
LIABILITY, SHALL BE: (A) THE CORRECTION OF PROGRAM ERRORS THAT CAUSE BREACH OF THE
single server or on multiple servers regardless of whether the individual is actively using the programs at any given time. For
authorized by you to use the application programs which are installed on a single server or multiple servers, regardless of
You should review the entire agreement, including any linked terms, because all of the terms are
remove or modify any program markings or any notice of Oracle
s proprietary rights;
representation of identifiable individuals, governments, logos, trademarks, or emblems or use these types
Privacy Statement connect to Microsoft or service provider computer systems over the Internet. In some
policy, which might require you to return the software with the entire computer on which the software is
Implementation Services, Packaged Methods, Architecture Services, Accelerator Services, Assessment Services and
individual is actively using the programs at any given time. For the purposes of Order Management, Advanced Pricing and
you to use the applicable licensed application programs which are installed on a single server or on multiple servers regardless
Oracle University Online Service: the Oracle University Online Service is a web based learning environment comprised of
Are there things I
m not allowed to do with the software? Yes. Because the software is licensed,
or service that is subject to a discount or a promotion when you order the relevant product or service. The list price will be
purposes of counting the number of processors which require licensing, a multicore chip with "n" processor cores shall be
and you and Oracle agree to submit to the exclusive jurisdiction of, and venue in, the courts in Ireland in any dispute arising
reference to information contained in a URL or referenced policy), together with the applicable order, are the completeX+
Recover
FormatEx
untfs.dll
.rdata
GetFileAttributesW
GetVolumePathNameA
FindNextFileW
GetTimeZoneInformation
CreateFileMappingW
AddAtomW
ReplaceFileA
IsBadReadPtr
GetNumberFormatW
GetModuleFileNameA
CreateMutexW
GlobalReAlloc
FlushInstructionCache
SetFileTime
BackupWrite
kernel32.dll
.idata
IsLoggingEnabledW
urlmon.dll
.rdata
!This program cannot be run in DOS mode.
.rdata
.idata
eTX{lZ
hZX+lR
)nUZ$P
Xx8sP
t#8sP#8cR#8#R
7_!/WD
HO!_W;
HO!_W;
X+loP
X+jiX
];dTX*
,=_xk
X+da\+
X$Z[|#
T$Z[|/
%,^X+
X$boX+
3l[|'n
$X[|/jW
XMfc|/
-6l[|'l
$X[|/^_X+
H$XS|/l[|'l
;l[|'nG\
;l[|/lW\$K
SX+l[|#l
X+]X+
X+XX+
$'l[|# X+
>l[|/ X+
X+_X+
X+YX+
%k^MfZ
MlZ@Mn
rX+db
X+gj@
X$inX+
X+]X+
X+]X+
jOY$XZ
;HMfS|?
n[|;<[|;:[|#9
_$']X+
X+YX+
_$']X+
X+j+Z$X
X+j+Z$X
X$Q[]
X+j+Z$XZ
X$Q[]
}jiXMfr
ajiXMf
$:jZT
X+jZT
X+jiX
**6gcU
V;%#n
-,YX+
Y!g$X^
|$kiX+
l[|'dY
X+nk|3gc|/
-g#|!
n[|3l[|3j{|7
NX+lJT
lZH25>
|M _Z*
8X+jZ
j^MF?(`
|jYY{lR
jRMF?(`
`X+]X+
?ycn+k^M
_Ml*x[
,.g X^
X+j{|#
%-lS|/
[|/!X
MlZPMn
'k^Ml_
X+$X+
Xxj{|
{X+lK|/l
YX+d X^
d'X$cGZ+
+$X~n
X+d#|+
+n[|?l[|7l
,>l[|'jO\
X+d'X_
,-ddP+
V--db
fTXMf'X+
p$Xxl
,"Fo(`
fTXM X+l
X+jiX
P7X+lZ
iTX.CX+n
X+ \P+
X+ \x+
$zjOD
, lmP
,"lYT
X+ ^H+
,-dTP/
X+jiX
eCiTX+
X$aeX+
sX+nIT
sX+nmP
X+jiX
wX+lZ
/n[|#l
-zl[|/l
,, ]P+
X+lDT
,"lLT
/8jYK
WX+ddH+
MAINICON
MAINICON
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Evo-gen [Trj]
C4S ClamAV (Linux) Win.Packed.Razy-9836307-0
Trellix (Linux) Trojan-FVOQ
Sophos Anti-Virus (Linux) Troj/Agent-BFEY
Bitdefender Antivirus (Linux) Gen:Variant.Barys.318206
G Data Antivirus (Windows) Virus: Gen:Variant.Barys.318206 (Engine A), Win32.Trojan.PSE.707O5V (Engine B)
WithSecure (Linux) Trojan.TR/Dropper.Gen
ESET Security (Windows) a variant of Win32/Kryptik.GIRH trojan
DrWeb Antivirus (Linux) Trojan.Packed2.49423
ClamAV (Linux) Win.Packed.Razy-9836307-0
eScan Antivirus (Linux) Gen:Variant.Barys.318206(DB)
Kaspersky Standard (Windows) HEUR:Trojan.Win32.Generic
Emsisoft Commandline Scanner (Windows) Gen:Variant.Barys.318206 (B)
Cuckoo

We're processing your submission... This could take a few seconds.