Please wait ...

Found 14 Datasets
Create a Dataset



Description: Extract the printable strings from all samples and clean them to work with CSV format.

Dataset SHA256: e506f5b4f2da2110ba78359e56ed9efbc0acb1778e7843c3993056f225605ad5

Features (sample):



category label strings SHA256
0 Ransomware 1 This program must be run under Win32 `.itext `.data .idata .didata .edata .rdata @.reloc B.rsrc Boolean System AnsiChar ShortInt SmallInt Integer Pointer Cardinal UInt64 NativeInt NativeUInt Single Extended Double Currency ShortString PAnsiChar0 PWideCharL ByteBool System WordBool System LongBool System string WideString AnsiString Variant TClass HRESULT &op_Equality &op_Inequality PInterfaceEntry TInterfaceEntry VTable IOffset ImplGetter PInterfaceTable TInterfaceTable EntryCount Entries TMethod &op_Equality &op_Inequality &op_GreaterThan &op_GreaterThanOrEqual &op_LessThan &op_LessThanOrEqual TObject& Create DisposeOf InitInstance Instance CleanupInstance ClassType ClassName ClassNameIs ClassParent ClassInfo InstanceSize InheritsFrom AClass MethodAddress MethodAddress MethodName Address QualifiedClassName FieldAddress FieldAddress GetInterface GetInterfaceEntry GetInterfaceTable UnitName UnitScope Equals GetHashCode ToString SafeCallException ExceptObject ExceptAddr AfterConstruction BeforeDestruction Dispatch Message DefaultHandler Message NewInstance FreeInstance Destroy TObject System TCustomAttribute TCustomAttribute|@ System WeakAttribute4 @ WeakAttribute System VolatileAttribute VolatileAttribute System IInterface System IEnumerable System IDispatch System FRefCount TInterfacedObject1 AfterConstruction BeforeDestruction NewInstance TInterfacedObject@"@ System RefCount PShortString PAnsiString PWideString PUnicodeString UTF8String RawByteString PLongInt PInt64 PExtended PCurrency PVariant TDateTime TVarArrayBound ElementCount LowBound TVarArrayBoundArray PVarArray\%@ TVarArray DimCount ElementSize LockCount Bounds TVarRecord PRecord RecInfo TVarData Reserved1 Reserved2 Reserved3 VSmallInt VInteger VSingle VDouble VCurrency VOleStr VDispatch VError VBoolean VUnknown VShortInt VLongWord VInt64 VUInt64 VString VArray VPointer VUString VRecord VLongs VWords VBytes RawData TTypeKind tkUnknown tkInteger tkChar tkEnumeration tkFloat tkString tkClass tkMethod tkWChar tkLString tkWString tkVariant tkArray tkRecord tkInterface tkInt64 tkDynArray tkUString tkClassRef tkPointer tkProcedure System TVarRec VInteger VBoolean VExtended VString VPointer VPChar VObject VClass VWideChar VPWideChar VAnsiString VCurrency VVariant VInterface VWideString VInt64 VUnicodeString _Reserved1 TPtrWrapper Create AValue Create AValue ToPointer ToInteger &op_Equality &op_Inequality TMarshal& Create InString OutString InOutString AsAnsi AsAnsi AllocMem ReallocMem OldPtr NewSize FreeMem StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex StartIndex ReadByte ReadInt16 ReadInt32 ReadInt64 ReadPtr WriteByte WriteInt16 WriteInt32 WriteInt64 WritePtr WriteByte WriteInt16 WriteInt32 WriteInt64 WritePtr FixString UnfixString UnsafeFixString UnsafeAddrOf AllocStringAsAnsi AllocStringAsAnsi CodePage AllocStringAsUnicode AllocStringAsAnsi AllocStringAsAnsi CodePage AllocStringAsUtf8 AllocStringAsUtf8 ReadStringAsAnsi ReadStringAsAnsi CodePage ReadStringAsUnicode ReadStringAsUtf8 ReadStringAsAnsiUpTo CodePage MaxLen ReadStringAsUnicodeUpTo MaxLen ReadStringAsUtf8UpTo MaxLen WriteStringAsAnsi MaxCharsIncNull WriteStringAsAnsi MaxCharsIncNull CodePage WriteStringAsAnsi MaxCharsIncNull WriteStringAsAnsi MaxCharsIncNull CodePage WriteStringAsUnicode MaxCharsIncNull WriteStringAsUnicode MaxCharsIncNull WriteStringAsUtf8 MaxCharsIncNull WriteStringAsUtf8 MaxCharsIncNull TMarshal System TTypeTable PTypeTableHD@ PPackageTypeInfo TPackageTypeInfo TypeCount TypeTable UnitCount UnitNames TArray<System.Byte> System TArray<System.Char> SystemL TArray<System.Word> System TArray<System.ShortInt> Systemd TArray<System.SmallInt> System TArray<System.Integer> System TArray<System.Int64> System TArray<System.TPtrWrapper> SystemX+@ PLibModule TLibModule Instance CodeInstance DataInstance ResInstance TypeInfo Reserved PResStringRec TResStringRec Module Identifier TFloatSpecial fsZero fsNZero fsDenormal fsNDenormal fsPositive fsNegative fsNInf System TExtended80Rec aExtended80 Exponent Fraction Mantissa SpecialType BuildUp SignFlag Mantissa Exponent &op_Explicit &op_Explicit PExceptionRecord TExceptionRecordP ExceptionCode ExceptionFlags ExceptionRecord ExceptionAddress NumberParameters ExceptionInformation ExceptAddr ExceptObject An unexpected memory leak has occurred. The unexpected small block leaks are: The sizes of unexpected leaked medium and large blocks are: bytes: Unknown AnsiString UnicodeString Unexpected Memory Leak ~]x[[) _^[YY] GetLogicalProcessorInformation YZXtm1 ZTUWVSPR _^[YY] _^[YY] ;Z]_^[ SVWRPj Z_^[XX tWI|TVS tdI|aVS zh-TW zh-Hant zh es-ES_tradnl nb-NO nb no tg-Cyrl-TJ az-Latn-AZ uz-Latn-UZ mn-MN mn-Cyrl mn iu-Cans-CA ha-Latn-NG qps-ploc en qps-ploca ja zh-CN zh-Hans zh nn-NO nn no sr-Latn-CS az-Cyrl-AZ dsb-DE dsb hsb uz-Cyrl-UZ mn-Mong-CN iu-Latn-CA tzm-Latn-DZ qps-plocm ar zh-HK zh-Hant zh sr-Cyrl-CS zh-SG zh-Hans zh smj-NO smj se zh-MO zh-Hant zh bs-Latn-BA smj-SE smj se sr-Latn-BA sma-NO sma se sr-Cyrl-BA sma-SE sma se bs-Cyrl-BA sms-FI sms se sr-Latn-RS smn-FI smn se sr-Cyrl-RS sr-Latn-ME sr-Cyrl-ME GetThreadPreferredUILanguages SetThreadPreferredUILanguages GetThreadUILanguage tdBHu GetLongPathNameW _^[YY] $Z]_^[ $Z]_^[ YZ]_^[ _^[YY] _^[YY] TStringDynArray System.Types TDuplicates dupIgnore dupAccept dupError System.Types TDirection FromBeginning FromEnd System.Types Create Create &op_Equality &op_Inequality &op_Addition &op_Subtraction Distance IsZero Subtract TSmallPoint Create Create Create &op_Equality &op_Inequality &op_Addition &op_Subtraction Distance IsZero Subtract TPoint Create Create &op_Equality &op_Inequality &op_Addition &op_Subtraction &op_Implicit &op_Explicit PointInCircle Center Radius Distance SetLocation SetLocation Offset Offset Subtract IsZero APoint TSplitRectType srLeft srRight srBottom System.Types Bottom TopLeft BottomRight Create Origin Create Origin Height Create Bottom Create Normalize Create Normalize &op_Equality &op_Inequality &op_Addition &op_Multiply NormalizeRect IsEmpty Contains Contains IntersectsWith Intersect Intersect Points Offset Offset SetLocation SetLocation Inflate Inflate CenterPoint SplitRect SplitType SplitRect SplitType Percent TWaitResult wrSignaled wrTimeout wrAbandoned wrError wrIOCompletion System.Types TOpenOption ofReadOnly ofOverwritePrompt ofHideReadOnly ofNoChangeDir ofShowHelp ofNoValidate ofAllowMultiSelect ofExtensionDifferent ofPathMustExist ofFileMustExist ofCreatePrompt ofShareAware ofNoReadOnlyReturn ofNoTestFileCreate ofNoNetworkButton ofNoLongNames ofOldStyleDialog ofNoDereferenceLinks ofEnableIncludeNotify ofEnableSizing ofDontAddToRecent ofForceShowHidden System.UITypes TOpenOptions TOpenOptionEx ofExNoPlacesBar System.UITypes TOpenOptionsEx TBorderIcon biSystemMenu biMinimize biMaximize biHelp System.UITypes TBorderIcons TWindowState wsNormal wsMinimized wsMaximized System.UITypes TEditCharCase ecNormal ecUpperCase ecLowerCase System.UITypes TFontCharset TFontPitch fpDefault fpVariable fpFixed System.UITypes TFontQuality fqDefault fqDraft fqProof fqNonAntialiased fqAntialiased fqClearType fqClearTypeNatural System.UITypes TFontStyle fsBold fsItalic fsUnderline fsStrikeOut System.UITypes TFontStyles TFontName TFontDataName| TFontStylesBase TCloseAction caNone caHide caFree caMinimize System.UITypes TMouseButton mbLeft mbRight mbMiddle System.UITypes TMouseActivate maDefault maActivate maActivateAndEat maNoActivate maNoActivateAndEat System.UITypes TTabOrder TModalResult TDragMode dmManual dmAutomatic System.UITypes TDragState dsDragEnter dsDragLeave dsDragMove System.UITypes TDragKind dkDrag dkDock System.UITypes TAnchorKind akLeft akRight akBottom System.UITypes TAnchors TScrollCode scLineUp scLineDown scPageUp scPageDown scPosition scTrack scBottom scEndScroll System.UITypes TPrinterState psNoHandle psHandleIC psHandleDC System.UITypes TPrinterOrientation poPortrait poLandscape System.UITypes TPrinterCapability pcCopies pcOrientation pcCollation System.UITypes TPrinterCapabilities TCursor TColor TAlphaColor TImageIndex TScrollStyle ssNone ssHorizontal ssVertical ssBoth System.UITypes PListEntry| _LIST_ENTRY PRTLCriticalSection PRTLCriticalSectionDebug _RTL_CRITICAL_SECTION_DEBUG Type_18 CreatorBackTraceIndex CriticalSection ProcessLocksList EntryCount ContentionCount _RTL_CRITICAL_SECTION DebugInfo LockCount RecursionCount OwningThread LockSemaphore Reserved HACCEL HBITMAP HBRUSH HPALETTE PSecurityAttributes _SECURITY_ATTRIBUTES nLength lpSecurityDescriptor bInheritHandle _FILETIME dwLowDateTime dwHighDateTime _SYSTEMTIME wMonth wDayOfWeek wMinute wSecond wMilliseconds _TIME_ZONE_INFORMATION StandardName StandardDate StandardBias DaylightName DaylightDate DaylightBias _WIN32_FIND_DATAWP dwFileAttributes ftCreationTime ftLastAccessTime ftLastWriteTime nFileSizeHigh nFileSizeLow dwReserved0 dwReserved1 cFileName cAlternateFileName tagBITMAP bmType bmWidth bmHeight bmWidthBytes bmPlanes bmBitsPixel bmBits tagBITMAPINFOHEADER( biSize biWidth biHeight biPlanes biBitCount biCompression biSizeImage biXPelsPerMeter biYPelsPerMeter biClrUsed biClrImportant PDeviceModeW\ _devicemodeW dmDeviceName dmSpecVersion dmDriverVersion dmSize dmDriverExtra dmFields dmOrientation dmPaperSize dmPaperLength dmPaperWidth dmScale dmCopies dmDefaultSource dmPrintQuality dmColor dmDuplex dmYResolution dmTTOption dmCollate dmFormName dmLogPixels dmBitsPerPel dmPelsWidth dmPelsHeight dmDisplayFlags dmDisplayFrequency dmICMMethod dmICMIntent dmMediaType dmDitherType dmICCManufacturer dmICCModel dmPanningWidth dmPanningHeight tagDIBSECTIONT dsBmih dsBitfields dshSection dsOffset tagMSG message wParam lParam tagNMHDR hwndFrom idFrom odSelected odGrayed odDisabled odChecked odFocused odDefault odHotLight odInactive odNoAccel odNoFocusRect odReserved1 odReserved2 odComboBoxEdit Winapi.Windows TOwnerDrawState GESTURECONFIG dwWant dwBlock TDWordFiller TMessage WParam LParam Result WParamLo WParamHi WParamFiller LParamLo LParamHi LParamFiller ResultLo ResultHi ResultFiller TWMKey MsgFiller CharCode Unused CharCodeUnusedFiller KeyData KeyDataFiller Result TWMMenuChar MsgFiller MenuFlag UserMenuFlagFiller Result  !"#$%&'(!)*+ -./0' 56789: ;<<<<<<<<========================= @ABCDEFGHHHIJKLMHNHOHHHHHHHHHHHHHHH PQHHHHHHHHHHH RHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHSTUVWXYZHHHHHHHHHHHHHHHHHHHHHHHH[\]HHHHHHHHHHHHH _HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH `HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH ?333333 ?tE)!XU ?tE)!XU TFileName TSearchRecp ExcludeAttr FindHandle FindData TLangRec FLocaleName FSysLangs TLanguages& Create Destroy GetLocaleIDFromLocaleName LocaleName IndexOf IndexOf LocaleName GetName GetNameFromLocaleID GetNameFromLCID GetLocaleName GetLocaleID GetLocaleIDFromName LocaleName GetExt TLanguages System.SysUtils NameFromLocaleID NameFromLCID LocaleName LocaleID LocaleIDFromName FMessage FHelpContext FInnerException FStackInfo FAcquireInnerException Exception3 Create CreateFmt CreateRes CreateRes ResStringRec CreateResFmt CreateResFmt ResStringRec CreateHelp AHelpContext CreateFmtHelp AHelpContext CreateResHelp AHelpContext CreateResHelp ResStringRec AHelpContext CreateResFmtHelp ResStringRec AHelpContext CreateResFmtHelp AHelpContext Destroy GetBaseException ToString RaiseOuterException ThrowOuterException Exception System.SysUtils BaseException HelpContext InnerException Message StackTrace StackInfo EArgumentException EArgumentException0 System.SysUtils EArgumentOutOfRangeException EArgumentOutOfRangeException System.SysUtils EPathTooLongException EPathTooLongException System.SysUtils ENotSupportedException ENotSupportedExceptionl System.SysUtils EDirectoryNotFoundException EDirectoryNotFoundException System.SysUtils EFileNotFoundException EFileNotFoundException System.SysUtils EListError EListError System.SysUtils EInvalidOpException EInvalidOpException\ System.SysUtils EAbort EAbort System.SysUtils AllowFree EHeapException FreeInstance EHeapException System.SysUtils EOutOfMemory EOutOfMemory System.SysUtils ErrorCode EInOutError EInOutError\ System.SysUtils ExceptionRecord EExternal EExternal System.SysUtils EExternalException EExternalException System.SysUtils EIntError EIntError System.SysUtils EDivByZero EDivByZeroD System.SysUtils ERangeError ERangeError System.SysUtils EIntOverflow EIntOverflow System.SysUtils EMathError EMathError< System.SysUtils EInvalidOp EInvalidOp System.SysUtils EZeroDivide EZeroDivide System.SysUtils EOverflowP EOverflow4 System.SysUtils EUnderflow EUnderflow System.SysUtils EInvalidPointer EInvalidPointer System.SysUtils EInvalidCast EInvalidCast0 System.SysUtils EConvertError EConvertError System.SysUtils EAccessViolation EAccessViolation System.SysUtils EPrivilege EPrivilege4 System.SysUtils EStackOverflow EStackOverflow System.SysUtils EControlC EControlC System.SysUtils EVariantErrorP EVariantError0 System.SysUtils EPropReadOnly EPropReadOnly System.SysUtils EPropWriteOnly EPropWriteOnly System.SysUtils EAssertionFailed EAssertionFailed8 System.SysUtils EAbstractError EAbstractError System.SysUtils EIntfCastError EIntfCastError System.SysUtils ErrorCode EOSError EOSErrorH System.SysUtils ESafecallException ESafecallException System.SysUtils EMonitor EMonitor System.SysUtils EMonitorLockException EMonitorLockException\ System.SysUtils ENoMonitorSupportException ENoMonitorSupportException System.SysUtils ENotImplemented ENotImplemented System.SysUtils EObjectDisposed EObjectDisposed System.SysUtils TArray<System.SysUtils.TLangRec> System TFormatSettings.TEraInfo EraName EraOffset EraStart EraEnd :TFormatSettings.:10 :TFormatSettings.:20 :TFormatSettings.:3 :TFormatSettings.:4 :TFormatSettings.:5 System.SysUtils TFormatSettings CurrencyString CurrencyFormat CurrencyDecimals DateSeparator TimeSeparator ListSeparator ShortDateFormat LongDateFormat TimeAMString TimePMString ShortTimeFormat LongTimeFormat ShortMonthNames LongMonthNames ShortDayNames LongDayNames EraInfo ThousandSeparator DecimalSeparator TwoDigitYearCenturyWindow NegCurrFormat NormalizedLocaleName Create Create Locale Create LocaleName GetEraYearOffset System.SysUtils System.SysUtils IReadWriteSync System.SysUtils PThreadInfo TThreadInfo ThreadID Active RecursionCount FHashTable TThreadLocalCounter' Destroy Thread Delete Thread Thread TThreadLocalCounter System.SysUtils FSentinel FReadSignal FWriteSignal FWaitRecycle FWriteRecursionCount FWriterID FRevisionLevel $TMultiReadExclusiveWriteSynchronizer& Create Destroy BeginRead EndRead BeginWrite EndWrite $TMultiReadExclusiveWriteSynchronizer System.SysUtils RevisionLevel FLength FMaxCapacity TStringBuilder& Create Create aCapacity Create Create aCapacity aMaxCapacity Create aCapacity Create StartIndex Length aCapacity Append Append Append Append Append Append Append Append Append Append Append Append Append Append Append Append Append Append Append RepeatCount Append StartIndex CharCount Append StartIndex AppendFormat Format AppendLine AppendLine CopyTo SourceIndex Destination DestinationIndex EnsureCapacity aCapacity Equals StringBuilder Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert Insert startIndex charCount Remove StartIndex RemLength Replace OldChar NewChar Replace OldValue NewValue Replace OldChar NewChar StartIndex Replace OldValue NewValue StartIndex ToString ToString StartIndex StrLength GetChars SetChars TStringBuilder System.SysUtils Capacity Length MaxCapacity EEncodingError EEncodingError System.SysUtils IEnumerable<System.string>0!@ System TArray<System.string> System FIsSingleByte FMaxCharSize TEncoding% Convert Source Destination Convert Source Destination Convert Source Destination StartIndex Convert Source Destination StartIndex FreeEncodings IsStandardEncoding AEncoding GetBufferEncoding Buffer AEncoding GetBufferEncoding Buffer AEncoding ADefaultEncoding GetByteCount GetByteCount GetByteCount GetByteCount CharIndex CharCount GetByteCount CharIndex CharCount GetByteCount GetByteCount CharIndex CharCount GetBytes GetBytes GetBytes GetBytes CharIndex CharCount GetBytes CharIndex CharCount GetBytes CharIndex CharCount ByteIndex GetBytes CharIndex CharCount ByteIndex GetBytes GetBytes CharIndex CharCount ByteIndex GetCharCount GetCharCount GetCharCount ByteIndex ByteCount GetCharCount ByteIndex ByteCount GetChars GetChars GetChars ByteIndex ByteCount GetChars ByteIndex ByteCount GetChars ByteIndex ByteCount CharIndex GetChars ByteIndex ByteCount CharIndex GetEncoding CodePage GetEncoding EncodingName GetMaxByteCount CharCount GetMaxCharCount ByteCount GetPreamble GetString GetString ByteIndex ByteCount TEncoding$ System.SysUtils CodePage EncodingName IsSingleByte FCodePage FMBToWCharFlags FWCharToMBFlags TMBCSEncoding& Create Create CodePage Create CodePage MBToWCharFlags WCharToMBFlags GetMaxByteCount CharCount GetMaxCharCount ByteCount GetPreamble TMBCSEncoding System.SysUtils TUTF7Encoding& Create GetMaxByteCount CharCount GetMaxCharCount ByteCount TUTF7Encoding System.SysUtils TUTF8Encoding& Create GetMaxByteCount CharCount GetMaxCharCount ByteCount GetPreamble TUTF8Encoding System.SysUtils TUnicodeEncoding& Create GetMaxByteCount CharCount GetMaxCharCount ByteCount GetPreamble TUnicodeEncoding System.SysUtils TBigEndianUnicodeEncoding% GetPreamble TBigEndianUnicodeEncoding System.SysUtils TMarshaller.PDisposeRec TMarshaller.TDisposeProc TMarshaller.TDisposeRec TMarshaller.IDisposer System.SysUtils FInline FOverflow FCount TMarshaller.TDisposer' Destroy TMarshaller.TDisposert System.SysUtils TMarshaller FDisposer InString MaxLen OutString InOutString MaxLen AsAnsi AsAnsi AsAnsi CodePage AsAnsi CodePage AsUtf8 AsUtf8 AllocMem ReallocMem OldPtr NewSize FixString UnsafeFixString AllocStringAsAnsi AllocStringAsAnsi CodePage AllocStringAsUtf8 AllocStringAsUnicode /TArray<System.SysUtils.TMarshaller.TDisposeRec> System System.SysUtils _^[YY] YZ]_^[ YZ]_^[ TStrData System.SysUtilsL System.SysUtilsL QQQQQQQQSV YZ]_^[ $Z]_^[ _^[YY] <@t!QS<$t $*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $) _^[YY] _^[YY] $YZ_^[ System.SysUtilsL t HtYH :TInternalEraInfoRecord.:1 System.SysUtils TInternalEraInfoRecord EraCount EraInfo _^[YY] System.SysUtils _^[YY] _^[YY] _^[YY] _^[YY] $Z]_^[ _^[YY] $YZ_^[ $Z]_^[ PUnitHashEntryD TUnitHashEntry LibModule UnitName DupsAllowed FullHash TModuleInfo Validated UnitHashArray &TArray<System.SysUtils.TUnitHashEntry> SystemD YZ]_^[ YZ]_^[ YZ]_^[ <pYZ_^[ _^[YY] _^[YY] VariantChangeTypeEx VarNeg VarNot VarAdd VarSub VarMul VarDiv VarIdiv VarMod VarAnd VarXor VarCmp VarI4FromStr VarR4FromStr VarR8FromStr VarDateFromStr VarCyFromStr VarBoolFromStr VarBstrFromCy VarBstrFromDate VarBstrFromBool TVarCompareResult crLessThan crEqual crGreaterThan System.Variants FVarType TCustomVariantType& Create Create RequestedVarType Destroy IsClear Source CastTo Source AVarType CastToOle Source Source Indirect BinaryOp Operator UnaryOp Operator CompareOp Operator Compare Relationship TCustomVariantTypep'C System.Variants VarType TVarDataArray System.Variants8&@ EVariantInvalidOpError EVariantInvalidOpError System.Variants EVariantTypeCastError EVariantTypeCastError System.Variants EVariantOverflowErrorh.C EVariantOverflowError@.C System.Variants EVariantInvalidArgError EVariantInvalidArgError System.Variants EVariantBadVarTypeError EVariantBadVarTypeError System.Variants EVariantBadIndexError EVariantBadIndexError|0C System.Variants EVariantArrayLockedError EVariantArrayLockedError81C System.Variants EVariantArrayCreateError EVariantArrayCreateError System.Variants EVariantNotImplError EVariantNotImplError System.Variants EVariantOutOfMemoryError EVariantOutOfMemoryErrorp3C System.Variants EVariantUnexpectedError EVariantUnexpectedError04C System.Variants EVariantDispatchError EVariantDispatchError System.Variants EVariantInvalidNullOpError EVariantInvalidNullOpError System.Variants TStringRef Unicode FromAnsi FromUnicode @^[YY] QQQQQSV _^[YY] QQQQSV System.Variants _^[YY] tagSTATSTGH pwcsName dwType cbSize grfMode grfLocksSupported grfStateBits reserved ISequentialStream Winapi.ActiveX IStream( Winapi.ActiveX PExcepInfo TFNDeferredFillIn ExInfo tagEXCEPINFO wReserved bstrSource bstrDescription bstrHelpFile dwHelpContext pvReserved pfnDeferredFillIn TSingletonImplementation TSingletonImplementationt System.Generics.Defaults TStringComparer' Ordinal TStringComparer8 System.Generics.Defaults TOrdinalIStringComparerD Compare Equals GetHashCode TOrdinalIStringComparer$ System.Generics.Defaults IEqualityComparer<System.string> System.Generics.Defaults IComparer<System.string> System.Generics.Defaults TCustomComparer<System.string> TCustomComparer<System.string>D System.Generics.Defaults _^[YY] TOrdinalStringComparerD Compare Equals GetHashCode TOrdinalStringComparer System.Generics.Defaults TCollectionNotification cnAdded cnRemoved cnExtracted System.Generics.Collections doOwnsKeys doOwnsValues System.Generics.Collections TDictionaryOwnerships EInsufficientRtti@ EInsufficientRtti System.Rtti EInvocationError EInvocationError System.Rtti ENonPublicType ENonPublicTypex System.Rtti IValueData System.Rtti TValueData FTypeInfo FValueData FAsUByte FAsUWord FAsULong FAsObject FAsClass FAsSByte FAsSWord FAsSLong FAsSingle FAsDouble FAsExtended FAsComp FAsCurr FAsUInt64 FAsSInt64 FAsMethod FAsPointer TValue &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit &op_Implicit FromVariant FromOrdinal ATypeInfo AValue FromArray ArrayTypeInfo Values IsObject AsObject IsInstanceOf AClass IsClass AsClass IsOrdinal AsOrdinal TryAsOrdinal AResult IsType ATypeInfo ATypeInfo TryCast ATypeInfo AResult AsInteger AsBoolean AsExtended AsInt64 AsUInt64 AsInterface AsString AsVariant AsCurrency IsArray GetArrayLength GetArrayElement SetArrayElement AValue ABuffer ATypeInfo Result AValue ATypeInfo Result MakeWithoutCopy ABuffer ATypeInfo Result ExtractRawData ABuffer ExtractRawDataNoCopy ABuffer GetReferenceToRawData GetReferenceToRawArrayElement ToString FHandle FRttiDataSize FPackage FParent FAttributeGetter TRttiObject' Destroy GetAttributes TRttiObject System.Rtti Handle RttiDataSize Parentx%D Package TRttiNamedObject TRttiNamedObject\ System.Rtti TRttiType3 ToString GetMethods GetFields GetProperties GetIndexedProperties GetMethod GetMethods GetField GetProperty GetIndexedProperty GetDeclaredMethods GetDeclaredProperties GetDeclaredFields GetDeclaredIndexedProperties TRttiType4 System.Rtti Handle QualifiedName IsPublicType TypeKind TypeSize IsManaged@ BaseType8 AsInstance IsInstance AsOrdinal IsOrdinall AsRecord IsRecord TRttiMember TRttiMemberD System.Rtti Parent Visibility TRttiStructuredType TRttiStructuredTypeD System.Rtti TRttiFieldE GetValue Instance SetValue Instance AValue ToString TRttiField8 System.Rtti FieldType Offset TRttiManagedFieldD TRttiManagedField System.Rtti FieldType FieldOffset FMethOfs TRttiRecordType< GetDeclaredFields GetDeclaredMethods GetAttributes TRttiRecordType( System.Rtti ManagedFields TRttiPropertyE GetValue Instance SetValue Instance AValue TRttiProperty( System.Rtti PropertyType IsReadable IsWritable TRttiInstanceProperty3 ToString TRttiInstanceProperty System.Rtti PropertyType Default NameIndex PropInfo TRttiParameter3 ToString TRttiParameter System.Rtti Flags@ ParamType TDispatchKind dkStatic dkVtable dkDynamic dkMessage dkInterface System.Rtti TMethodImplementationCallback System.Rtti TMethodImplementation.TFloatReg RegSingle RegDouble RegExtended RegComp RegCurr Unused1 Unused2 Unused3 ):TMethodImplementation.TInterceptFrame.:1 %TMethodImplementation.TInterceptFrame( RegEAX RegEDX RegECX PreviousFrame RetAddr *TMethodImplementation.TFirstStageIntercept PushEBP_55 MovEBP_ESP_1_89 MovEBP_ESP_2_E5 Push_68 PushVal JmpRel_E9 RelTarget %TMethodImplementation.PInterceptFrame *TMethodImplementation.PFirstStageIntercept TMethodImplementation.TParamLoc FTypeInfo FByRefParam FOffset Create AByRef GetArgLoc AFrame GetArg AFrame SetArg AFrame FCallerPopsStack FResultFP FHasSelf FStackSize FParams FResultLoc FParamList FReturnType FCallConv !TMethodImplementation.TInvokeInfoK Create ACallConv AHasSelf Destroy GetParamLocs AddParameter !TMethodImplementation.TInvokeInfoX System.Rtti ReturnType FUserData FCallback FInvokeInfo TMethodImplementation& Create Destroy TMethodImplementation@ System.Rtti CodeAddress FInvokeInfo TRttiMethod' Destroy Invoke Instance Invoke Instance Invoke Instance CreateImplementation AUserData ACallback GetParameters ToString TRttiMethod System.Rtti ReturnType HasExtendedInfoLnH MethodKind DispatchKind IsConstructor IsDestructor IsClassMethod IsStatic VirtualIndex\qH CallingConvention CodeAddress FReadMethod FWriteMethod TRttiIndexedPropertyS GetValue Instance SetValue Instance ToString TRttiIndexedProperty System.Rtti Handle@ PropertyTypel ReadMethodl WriteMethod IsReadable IsWritable IsDefault FProps FMeths FVirtCount FIndexedProps FClassTab FReadPropData FReadMethData TRttiInstanceType@ GetDeclaredProperties GetDeclaredMethods GetDeclaredFields GetDeclaredIndexedProperties GetDeclaredImplementedInterfaces GetImplementedInterfaces GetAttributes TRttiInstanceType System.Rtti BaseType DeclaringUnitName MetaclassType VmtSize FMethods FTotalMethodCount TRttiInterfaceType= GetDeclaredMethods TRttiInterfaceType| System.Rtti BaseType IntfFlags DeclaringUnitName TRttiOrdinalType TRttiOrdinalType System.Rtti OrdType MinValue MaxValue TRttiInt64Type TRttiInt64Type System.Rtti MinValue MaxValue FProcSig TRttiInvokableTypeS Invoke ProcOrMeth GetParameters ToString TRttiInvokableType` System.Rtti ReturnType\qH CallingConvention TRttiMethodTypeQ Invoke Callable ToString TRttiMethodType System.Rtti MethodKind 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 Ransomware 1 !This program cannot be run in DOS mode. `.rdata @.data .mysec `.mysec3 `.mysec2 `.rcrs @.reloc PPPPPPP 0WWWWW _VVVVV 0WWWWW jXh ?B QQSVWd HHtXHHt >If90t tM<it-<ot)<ut%<xt!<Xt <dty<itu<otq<utm<xti<Xte HIf98t 0SSSSS <at9<rt <wt URPQQh >=Yt1j QQSVWh j@j ^V j hXBB HtHu4j s[S;7|G;w tR99u2 0A@@Ju ^SSSSS j"^SSSSS HHtYHHt tGHt.Ht& ^SSSSS 8VVVVV ;t$ v- UQPXY]Y[ HHt*HHt <0|<9 tK<_t<<$t8<<t4<>t0<-t <a| <z~$<A| <0|O<9 tU<A|B<P tY<@tO<Zt t\<@tXj' NtFNt#NuV t.<@t5V TtUHtKHtAHt 0t-HHt AtIHt0Hu j hhFB _VVVVV _VVVVV 0SSSSS 0SSSSS 0WWWWW AAFFf; t"SS9] C PjPV C$PjQV C*PjTV C+PjUV C PjVV C-PjWV C.PjRV C/PjSV .;1s(N HHt4HHt Ht\Ht teHtFHt&Hu ty<%tA PPPPPPPP tNh<8B t=h88B Vj@h`5B u%h@8B PPPPPPPP 0WWWWW u VVWV t VV9u t+WWVPV ^SSSSS ^SSSSS >:u8FV VVVVVQRSSj ^SSSSS ^SSSSS 0SSSSS ^SSSSS ^WWWWW 0SSSSS 8VVVVV string too long invalid string position invalid string argument Unknown exception (null) `h```` xpxxxx UTF-16LE UNICODE CorExitProcess runtime error TLOSS error SING error DOMAIN error An application has made an attempt to load the C runtime library incorrectly. Please contact the application's support team for more information. - Attempt to use MSIL code from this assembly during native code initialization This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain. - not enough space for locale information - Attempt to initialize the CRT more than once. This indicates a bug in your application. - CRT not initialized - unable to initialize heap - not enough space for lowio initialization - not enough space for stdio initialization - pure virtual function call - not enough space for _onexit/atexit table - unable to open console device - unexpected heap error - unexpected multithread lock error - not enough space for thread data This application has requested the Runtime to terminate it in an unusual way. Please contact the application's support team for more information. - not enough space for environment - not enough space for arguments - floating point support not loaded Microsoft Visual C++ Runtime Library <program name unknown> Runtime Error! Program: EncodePointer DecodePointer FlsFree FlsSetValue FlsGetValue FlsAlloc bad exception LC_TIME LC_NUMERIC LC_MONETARY LC_CTYPE LC_COLLATE LC_ALL  !"#$%&'()*+ -./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ `h`hhh xppwpp Complete Object Locator' Class Hierarchy Descriptor' Base Class Array' Base Class Descriptor at ( Type Descriptor' `local static thread guard' `managed vector copy constructor iterator' `vector vbase copy constructor iterator' `vector copy constructor iterator' `dynamic atexit destructor for ' `dynamic initializer for ' `eh vector vbase copy constructor iterator' `eh vector copy constructor iterator' `managed vector destructor iterator' `managed vector constructor iterator' `placement delete[] closure' `placement delete closure' `omni callsig' delete[] new[] `local vftable constructor closure' `local vftable' `udt returning' `copy constructor closure' `eh vector vbase constructor iterator' `eh vector destructor iterator' `eh vector constructor iterator' `virtual displacement map' `vector vbase constructor iterator' `vector destructor iterator' `vector constructor iterator' `scalar deleting destructor' `default constructor closure' `vector deleting destructor' `vbase destructor' `string' `local static guard' `typeof' `vcall' `vbtable' `vftable' operator delete __unaligned __restrict __ptr64 __clrcall __fastcall __thiscall __stdcall __pascal __cdecl __based( {flat} `non-type-template-parameter unsigned short <ellipsis> <ellipsis> throw( `template-parameter cli::pin_ptr< cli::array< `anonymous namespace' generic-type- template-parameter- `unknown ecsu' union struct class coclass cointerface extern "C" [thunk]: public: protected: private: virtual static `template static data member destructor helper' `template static data member constructor helper' `local static destructor helper' `adjustor{ `vtordisp{ `vtordispex{ const volatile volatile volatile signed double UNKNOWN __int128 wchar_t __int64 __int16 __int32 __int8 __w64 SystemFunction036 ADVAPI32.DLL GetProcessWindowStation GetUserObjectInformationA GetLastActivePopup GetActiveWindow MessageBoxA USER32.DLL  !"#$%&'()*+ -./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~  !"#$%&'()*+ -./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ HH:mm:ss dddd MMMM dd yyyy MM/dd/yy December November October September August February January Saturday Friday Thursday Wednesday Tuesday Monday Sunday united-states united-kingdom trinidad & tobago south-korea south-africa south korea south africa slovak puerto-rico pr-china pr china new-zealand hong-kong holland great britain england britain america swedish-finland spanish-venezuela spanish-uruguay spanish-puerto rico spanish-peru spanish-paraguay spanish-panama spanish-nicaragua spanish-modern spanish-mexican spanish-honduras spanish-guatemala spanish-el salvador spanish-ecuador spanish-dominican republic spanish-costa rica spanish-colombia spanish-chile spanish-bolivia spanish-argentina portuguese-brazilian norwegian-nynorsk norwegian-bokmal norwegian italian-swiss irish-english german-swiss german-luxembourg german-lichtenstein german-austrian french-swiss french-luxembourg french-canadian french-belgian english-usa english-us english-uk english-trinidad y tobago english-south africa english-nz english-jamaica english-ire english-caribbean english-can english-belize english-aus english-american dutch-belgian chinese-traditional chinese-singapore chinese-simplified chinese-hongkong chinese canadian belgian australian american-english american english american Norwegian-Nynorsk CONIN$ CONOUT$ SunMonTueWedThuFriSat JanFebMarAprMayJunJulAugSepOctNovDec bad allocation paluci begohicixezufemure wutatodebamaxokikedotezuno telokagikavetitogone vukuxekewa %f ruyejegomu LockFile GetFileAttributesExA GetTickCount LoadLibraryW lstrlenW CreateMailslotW GetLastError GetProcAddress LocalAlloc VirtualProtect DuplicateHandle CloseHandle KERNEL32.dll SetAclInformation OpenSCManagerA AreAnyAccessesGranted ADVAPI32.dll GetStartupInfoW RaiseException RtlUnwind TerminateProcess GetCurrentProcess UnhandledExceptionFilter SetUnhandledExceptionFilter IsDebuggerPresent HeapAlloc HeapFree WriteFile WideCharToMultiByte GetConsoleCP GetConsoleMode FlushFileBuffers DeleteCriticalSection LeaveCriticalSection FatalAppExitA EnterCriticalSection GetModuleHandleW ExitProcess GetStdHandle GetModuleFileNameA GetModuleFileNameW FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineW SetHandleCount GetFileType GetStartupInfoA TlsGetValue TlsAlloc TlsSetValue TlsFree InterlockedIncrement SetLastError GetCurrentThreadId InterlockedDecrement GetCurrentThread HeapCreate HeapDestroy VirtualFree QueryPerformanceCounter GetCurrentProcessId GetSystemTimeAsFileTime SetFilePointer GetCPInfo GetACP GetOEMCP IsValidCodePage VirtualAlloc HeapReAlloc WriteConsoleA GetConsoleOutputCP WriteConsoleW MultiByteToWideChar SetStdHandle InitializeCriticalSectionAndSpinCount CreateFileA HeapSize SetConsoleCtrlHandler FreeLibrary InterlockedExchange LoadLibraryA LCMapStringA LCMapStringW GetStringTypeA GetStringTypeW GetTimeFormatA GetDateFormatA GetUserDefaultLCID GetLocaleInfoA EnumSystemLocalesA IsValidLocale SetEndOfFile GetProcessHeap ReadFile GetLocaleInfoW GetTimeZoneInformation CompareStringA CompareStringW SetEnvironmentVariableA .?AVlogic_error@std@@ .?AVinvalid_argument@std@@ .?AVlength_error@std@@ .?AVout_of_range@std@@ .?AVbad_cast@std@@ .?AVbad_typeid@std@@ .?AV__non_rtti_object@std@@ .?AVtype_info@@ .?AVbad_exception@std@@ abcdefghijklmnopqrstuvwxyz ABCDEFGHIJKLMNOPQRSTUVWXYZ abcdefghijklmnopqrstuvwxyz ABCDEFGHIJKLMNOPQRSTUVWXYZ .?AVexception@std@@ .?AVbad_alloc@std@@ 3/9*"?8 19-<- 9 +04?21 .-- 99 ' !>?=*3 +042>1 '<%3#? (5"#6(( 4)2052>>< 325"&7 1663/.1 &+#+.7 *--9$% 702;(! 4?*<) *)*$=80= :(&&=$ -'0'+$".:5 *#<#-* +5$86!;' 88#5**3"1# % ":&<! ; 66458)3 *+!3(($ ';-(/: ')2052>>< 5)%&$8 9<.& +0<'!;! ?20753(69# 8"(:1>.! : =: (-*?1 #9?;"& "0 /2$3 8(6$$. (=)8 ":6 <<("4. .=6-0-' 899("+ 0' 0*2 );"#3)< '9&114. *1$//! (5=7)* /')/'&5 97 ;8# <3$76<4:% ;3736<: * . *'99 *?/: "4759+/9. 4?&+3 8 ))<> '3); 7$5$ "'1& 7'; : 300)<&?.) 7'7'((. &352.: -*:> # ? -+ % /2%9;6 #71*!# - >$0#+*&<; 9;+9:/ 176;916 54>*#6 )$<24< >.0;5!- 602 .9/ 0>!*6%5 ?!1*"5>2 )/?>(85 "42)7$ *-/2 8#$>($ 79=&<9? /6) +: &??.(7  140; 4:4'+<! :*4/> 8<<*+7 +7::7:7(? ? 64.7-0 ($/7<.+$8)77 <%*;34< =* #-6 9 44#(;.( 1#0+%2 >89<5'.$ <9:0<' 93(22/ 54?598 %56;64127 0 *$6<#8 .6:182#<#/ $1=9?8? #2%96 -)#7*# !/2 6: 9$+757 <#-+:* 75:&.? 042+$<; 67 ";2 7.?#:-+:&) =%/$+: !*023 .%6".8 4 990'* 4(!>$9 ( =8"28(0": !.<%# ;9"-$$ / =55< >#6:7&&2 732#$+--'()+9 0>"&") #9( >#0!"0" 5%?$)&; < ;251& :>)111 > 6<3$4/34 $%;)" (8(-.# .94<); $-***2! 26(4!'+=" *6 :#* >$9? 3 .5)<!/ 6+/ )/ 5)?1!= .-#$*%; 7;#* 2:1; * 07#=(- %()>#0;#=1$ ) $>8?> $+=&.: 98-=-= %?=-8"&*7. 843 #3 "!987? 4 .&7-- ># 2&;;2( -?5=&* :-$#57 ;:835 %(%0#+ /$:;'# 3>*71' '! *"% *=$ )%%53 -9)>=;&9/7( "24.+9 !88/5$ !;9<53 %&#=+< 7*#';!4*'9 &+938! )99%/30 75' $* 7=7%14 36!;<3. 8:49$/ ; 5%> 85):>71#( 5=%" # 4"%<?-3 &(/ /+8 "8? #! 2 #%2' 9&7-(+ =5%%>? ;7(<; 7=<-3 ?) +93#5 '1-*?? ) *5# 025'6$1: 45-- . 11-=19 ;4! 3&(5' "760( (.:=%$ 50&(4?? 2*$$"?" 29!5$ +7 "4 <;- )+6(837 ?=1= < 6:**:<2 *;65=&4 7%7=)4? !/283*< > !. ->5 = "#?1: : 1*)1-8 5'/&6' ?-0+-& .+2(6? /&#3<; !+/53(<4'< ;""50' #&4"5 7 4;-23 5.923# 9(1 !266!&9&> %<6 = --$+50> ; 2<< <'5 ( 4!66 85 06+ =(1$1* $%728&--<%) ;1=>08 <2'6>4"+ 4+)64"1)%- 3:<;? 32> ?18 :1%=9> 0"/'/)!% >?'3*1 3*2=9 8'92*7 &+$?9 6-.(;4 /!:+& 35+4" 2$$? )+0 + 2( (-7 #( 4 6% ( /7-(( 985 ; &581$ >63<-> .-!4$:59/ $-?30-:2*> * +-9328 $08).)* %0394+ ;>)!98 73 5?- >!/8+)*?.)(?33 >0)1+; -;#2=" %/0&8* !)1?/$ >$)"&>3?? '<9 '< >'9# %4?8$899#3=" ?(;#* ( :(% 2+..73 7$;1?4 ;6)65 8 0=>. %56; 3> 0 5 0-> .5#66.00* ?? $: -73=83%0 %.:0"! ?+4+#5' ($-:( -='8)<2 #>734(? "+#4% 63$13: />-73% +% )75?- )#"=%6 )6#)'+ 20?25 0 !'0%>* 7'02 2$>--= ==!-*'?9 +"-";!1984 09>> 3? .&> ?+20 #?-43" ;;.?(0 '>: +! /0: 9 $<%*. 464 75 966 #6 ;+?3$49 ;1& +: ?!5&+ ?;4':= 5&&5 1< /92..8 &># 710& . $5) !!290'& '1 68 %6;/<=8 "*2/4+ +(?;>< :/*# ?: )"$; : >#%1&=( "63" 8 #339>. "?4#616. *7-!5 -$5(<=!!!;; !67>#" <7>(#/6 11-;>-'1 1!)4)7& "1:6'86 ! 7+ . #'+"6; "'$1.0" :48< %' >(!%619/ (476# 1-2%9> 039;++ !939:8. .- 276! ;><83 11-#474 7/6:';" ( 5# -5 :!+1:?4! 0 6= *':;.>"*" #>/## =2226(3*.-" !-/--3 (8!%'2 8$'5># -.'"$6# 88$9<=<&9 !!5'9: $#$+7' 3=*7:: = # 6>( %;4;'5< 7.#1+: ?#-8&2 $%=+80/0 0?819+<# 850(9! 83.(= (!33 8' %*'8!4 +31/2 <'!82!6 52: 3 !; =-& ':% ;9$&;13 (50)+: >;591) $'2:#0 +?.(=48 (!-..' 7'?-(5 +5%2 #5?:7< $1 9(#;/ <.(%$2? -6=)+" 6$!7/6=< !2/' ' !3"&"513 '9=974 +7&%&% $<-"6 ' =#$$5 0*!?+4>) 00#4? %'$%!(8<% /1 ((*24#5 $>4+ $ $.!;&=& "$>4/9= + 6'14 #:0%7$# !6*;;. 5$?4''=6)' (72:8! 543:>+8/ 1$83578 0&9/ &5 :(&.0? (57+5 33?7 7936+!<%= "3?)89$%( !$32*= /(567< 0=;*$ <%' &":2 ;><=( (*?:">&1 5#&?& =;%!<9 !%<5(24 $!2'5!& 082/7< 0)4397? (?'76-9 &$34* 0"30#& 80$?)'3 9(.5 > #!&9) %7/=?(# +/<7$ 5 -2/) !44%)# 4!;*-4 ?6-++) $ 2;5.5 ):.<6'7 -1'%!1 %570#464 (74&24 &:%!9/ ? ') + $& ;<% ! %: ?!"2 27')* "=-'&- 01=9-/ !'56=0$6 05< ')(7.6% +/'#<% *'63" 6&+!0.9. :6#*$ 888-7? 5*?4.!" ?'&$6%> ;2&"0" 2<11-(- "#(682 :$:?"6 " 3 9/<=**'3 +77!$% 5$!<96 ; (!416 /:*0# -217:7 :=#'%$0 %7- 8+ #;)?%.7 :#+ # ?825>-" - <-/: #+>;6:6- $/:6.%?8 ))9)#)( "&"!&4 ): ;10= #57 =: <=<9$- " ; =?7 2'&<5> =80'<*%8 # :34"7 2.2# & :+<= /%">""/6 4'73>" &&? $ ("0 &9 3/:2$=$ (01.05 #<>-.- #'% =5$9- /&5;4:-2 -13>?4 =529<= =>=+9.$ #8&;?( 9;987$$$ + ";!(*:? +957& '&?883) '&19=? &&8+8<56" #4;(%; &181. <=7=2=$ ?-4:(. >';%4 .: 50>: !%7))8 61.>5- 4.'<:51 ;6(>06 %+435 >+( (. 243=)-+ $32-?8" +-)++; )*<> ..52>$ 7*341 +> ++#':% '%>(*/ =<=++3? "+'306 *.>!;= "+% +:(< 5&#8?. ;1&%(" 7)6! 7 ; 4-=!9 ; .8")==$ 5/2> 9+ 80;.7 < 4= 7--6 <$3 ))3%38 1#!9:; < .%-6 8+/'15>- !:!)? !&!6758 !+65$7 +!- <$ "+9/"5 9 )-;:3 ;(6/9 6(.%(+& 1"5<#<1 7>8=$2($ 8*$ 4-5 0&<"9.3 %1=%2#? %<"< :! <'9 7+ 5:""# '"26)1 &-:0"/ 11 *$(4 $);7' %1<: 947>:7 ?<%5'2 $ *.=() +;><'+2 =4 *(. "&6#29 5<(?=- ?/(99-9<( 33#( = .8(9'! -+;;* 8>6 =0%#93 !2!!!#9 )9*91 7=&.11 1*/++90( 266< *=+ :/*1!5) -)=2(7 ;. <!) !=<8#5 ''312"$ .=%1+? &9%*) =9.6=62 )4/27# 0%->. <9 ;#=3%< %-'<(2 !>$%>2"> !(;+8#+* 85%>"%6.< %?*?3*=$ 3=7)-( #1#/4 > %& '> %1(?0+*1 ? <+(1! $&-0< /)5*1+& 55 #4?+=> # *'7& #&2"& " ;)?* "("%=1 2".$;3 ;.+"#$0 <$11'* 706&<#. :4//' 2/!"==(!- 1;?/9;3 $?!*+$$ & %)6> 7 *0:' =*?>70&/92($ 6%4)6 :%*=7&' !1:%( ;;$< 4$4+5#=+ ##%%&"(/ 1.-*<19 0( :"' "(?.6)4 (=)$=# !6/2 &4 -%(18: *9?%;9 >? .;= :* $?0 720)%) '!0$-$# ;*"<&..91 5$6")7:! 8(%"* 6 8-&4=#+ ;*#%&6* +?(->? %./#90! & 203#9 66<*750 $<06 )9 /%!<&- !...#$: -7 2)3 ?3##=%1 6&-<+/. ;98%!/) >; 1;6 56' #7 -3$$?5+ 9..!-. !-0)$/ 2'3?02 97:% " .39; &:" 4*!(.0% %'!=$0; 33?5376 <(2;?( 72#%$9 0:2)<% '7#3<( *"&3"" "%5: 7933 .2= 9 ">00 7>+*->.= '9+4( 4%0.1<?$ 3!$ *8 ; 331$ 3%5:6"+ 5-<67< *'61 ??. ;#.:=< '2& 98: 92/0<&( 4:%!878 <>%$>= -:$7%(-11 70< 27$>0 6*'(*(+ "3/!74 ;(++<!-0:;!"1 ;!+ :/ 6;:)1/"% %"! -0 =/& $? >9:> 4'% )$'%8&=;+ 46$)82 #905 8-<$&>1!*14 $ !& # "'## 9/9( . '$0%)$ )! 3=62 )!61>= 0/7)62 /:4-. .)#2 " :3)7$ 32; %' )!>8&6 74 ./ $=; '5 3076<4:% ;3736<: 5$5.> 80995+ 136=20 =*%9'28 3 3"76 62%?-: /)26>'2? 2/;5+/3 .54)#8/ 3;65:'!;8. "1#&>* ) 8-959%#> :/'9*0/8 '+0$ ? ;&?>%0> 9=7>-/ "((2#+)(  +'-:& <2.18-7:?&*<- 8'.% *#+/3 8 )506 %6:"(* 26-&'. #0)8:6 >09 )$ -609: =$(# 9 6=%<$' 6 1*59 4$97*4 6:+.68 9#<2#= .3<30:'/+ %0>%92'" /0*14: (09:3/ :-4<+2) #/; 4 :=4><6 *&-'6:? ?&%>0? ;>$:)-82 4./>? 68 6+7 5=# 5;*/47 7&8-25'- 7!-=*= 1/2$31 361 !)- 33+ 7?/05.*0+ -$;6;14'?'( ?476#! 9$448"* :>13>$'/#/ 443 )8"('3. ;.;.=/ 5#2+/ ! )(!- /#:!;6) .#;#+*6 65#%*+ ! 6=61? < /'5*<:< 7(0?#; /!'0&) #3107- $'8 ;: >67!&(>(? = =":=>&.- /86 )$ +="##2= /??999<.1 /?/<3!< 2 ;%/5 /!<*<- 3!8$+ #/5.;39 6(01%* 2=("+2!0#4 9:?+=9 !.8$&-6=8 .)8/7$ '>!3 (' &$7:(" '/->>4 = &"<'7'$ 435"+49 *5&01= $4' <.? '/#&#; %7+-'1* *+>71 5> ?-#- ;2"!*& #%61/) ':?7+? -!?967( )")<9?'? 1?14# 4=964.: =32; 8 8:+%2& 7%*38& )3%56" +>*10 $>;55 &;.<> 1 +4!$!56 $>80> -+':4:- )>'<8"$$ '#-38';# >##+-- 4?83./! ( <+:'5 ##(*? -2 !8&%00 :5?2>" !8(;%( *+# $5 =7/:)$! 67+;:05 6!<"<4* 0'&!!%' #7>5/ 5=: 3++& 5'%5)6 9:*-21/ ;!0jR;#4 2z;=y6 &k__k9 0 0:0I0 182=2c2h2p2x2 5:6N6T6Z6`6e6q6w6}6 7#7(7-737J7S7]7 8&8.8;8E8 >">(>.>4>:>@>F>L>R>^>}> ?M?Z?m? 0;0L0V0s0 3:4R4j4 ;?;F;L;^;f;q; 01X1}1 3-3S3q3x3|3 3V4a4|4 5 5$5(5 505z5 7*757R7 9E:M:b:m: ;'<:<U< 2I2n2Q4M6Q6U6Y6]6a6e6i6 :%;7;x; <'<^<o< ==0=S= 1l253f3|3 6l6s6}6 7&797L7p7 8%8-838M8\8i8u8 :\;d;|; >+?;?h?p? 2?2X2_2g2l2p2t2 3N3T3X3\3`3 4!4K4}4 9?:T:j: ; ;M;h;n;w;~; ;%<a<w< =&=6=K= ??*?N?W?^?g? 010I0[0q0 3b3m3w3 55$5*5 66@6F6x6 7!7I7b7 778=8a8 9)959J9Q9e9l9 :!:+:1:=:L:R:g:x: ;&;;;a; =d=t=z= >%>+>3>:>?>G>P>\>a>f>l>p>v>{> ?)?/?K?{? 0:0G0S0[0c0o0 4)4.4>4C4I4O4e4l4 ;(;b;o;y; ?#?+?B?[?w? 4&4P4\4 7:8S8d8 232=2I2R2 3.373C3z3 4#4/4H4v5 :":&:*:0:;:J: ;0;5;x= >%>B>H>S>X>`>f>p>w> 3.34393H3Q3^3i3{3 6D7J7q7}7 8U8(:3:;:V:d:l:y: 1=1p1z1 1=2Y2b2w2 3#3(363 4-4A4G4>6 6)7<7X7j7}7 :+;T;q;|; 4 4;4S4r4 9!9&919>9L9Z9h9v9 =&=6===Y=:>@>Q>W>`>g>n>w> 1"2C2T2 6 777<7 9f:x:~: <*<a<e<i<m<q<u<y<}< =%=+=7=>=G=L=c=v= 282C2}2 333k3u3~3H4S4X4x4 4 515@5`526O6^6n6 6*7H7d7 838A8Q8h8 >6>F>Y> 60A0R0l0r0 1#1b1q1 393@3G3 090A0V0p0 1-1=1z1 839r9w9 =9=>=_=k=~= 00%0+010X0 2F3T3b3 44#4'4@4 7 7H7M7R7W7`7{7 8$9W9a9g9t9 :;$;+;0;7;<; ??7?=?L?R?a?g?u?~? 4!4 4\4 0*0<0N0 9(929]9e9 192L2{2 8 8$8(8 8084888<8@8D8H8L8P8T8X8\8`8d82= h>l>p>t>x>|> 1G2M2q2 595V5r5 3#404P4j4 4X5=6C6y6 (0O0j0t0{0 202i2v2U3d3:4s4 4$5\5b5h5n5 546=6C6H6`6z6 77.757B7b7l7 94:=:a:g:m:y: :!;);5;B;I;Q;Y;a;j;s; 123k6r6 =*=3=?=I=U=`= 3:3F3U3a3 7$7*70767<7B7H7N7T7Z7`7f7l7r7x7~7 8 8&8 82888>8D8J8P8V8\8b8h8n8t8z8 979I9S9e9p9t9y9 2T2X2\2t2x2|2 2 :0:4:8:L:P: 2 2$2(2 2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2 3 3$3(3 3034383<3 `5h5p5x5 6 6(60686@6H6P6X6`6h6p6x6 7 7(70787@7H7P7X7`7h7p7x7 : :(:@:P:T:d:h:l:p:x: ;0;@;D;T;X;h;l;p;x; < <<<@<P<T<\<t< = =(=@= > >(>4>T>X>\>d>x> ?4?8?@?D?`? 0 0@0`0 1(141P1X1\1t1x1 2 282@2p2x2|2 3 303L3P3p3 4$4@4L4X4x4 5 5<5@5`5|5 6 6@6`6 7 7@7`7 8 8@8`8 809@9T9h9t9|9 0$0H0h0 3@6P6\6d6l6t6|6 =(=8=H=X=|= > >$>(> >0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|> (null) mscoree.dll KERNEL32.DLL ((((( H h(((( H H kernel32.dll AFX_DIALOG_LAYOUT bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ...
2400 Accessibility 0 !This program cannot be run in DOS mode. `.rdata @.data .ndata Instu` softuW NulluN UVWj _3 L$bf-S D$ Pj( D$ UPU Vj%UUU f9=H/B D$$+D$ D$ +D$$P WWWWjn \u f9O 90u'AAf l$(9l$(tr +D$(PV UXTHEME USERENV SETUPAPI APPHELP PROPSYS DWMAPI CRYPTBASE OLEACC CLBCATQ NTMARTA RichEd32 RichEd20 RegEnumValueW RegEnumKeyW RegQueryValueExW RegSetValueExW RegCloseKey RegDeleteValueW RegDeleteKeyW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken RegOpenKeyExW RegCreateKeyExW ADVAPI32.dll SHFileOperationW SHGetFileInfoW SHBrowseForFolderW SHGetPathFromIDListW ShellExecuteExW SHELL32.dll CoTaskMemFree IIDFromString CoCreateInstance OleUninitialize OleInitialize ole32.dll ImageList_Destroy ImageList_AddMasked ImageList_Create COMCTL32.dll EndPaint DrawTextW FillRect GetClientRect BeginPaint DefWindowProcW SendMessageW InvalidateRect EnableWindow ReleaseDC LoadImageW SetWindowLongW GetDlgItem IsWindow FindWindowExW SendMessageTimeoutW wsprintfW ShowWindow SetForegroundWindow PostQuitMessage SetWindowTextW SetTimer CreateDialogParamW DestroyWindow ExitWindowsEx CharNextW DialogBoxParamW GetClassInfoW CreateWindowExW SystemParametersInfoW RegisterClassW EndDialog ScreenToClient GetWindowRect EnableMenuItem GetSystemMenu SetClassLongW IsWindowEnabled GetWindowLongW SetWindowPos GetSysColor SetCursor LoadCursorW CheckDlgButton GetMessagePos CallWindowProcW IsWindowVisible CloseClipboard SetClipboardData EmptyClipboard OpenClipboard TrackPopupMenu AppendMenuW CreatePopupMenu GetSystemMetrics SetDlgItemTextW GetDlgItemTextW MessageBoxIndirectW CharPrevW CharNextA wsprintfA DispatchMessageW PeekMessageW USER32.dll SelectObject SetTextColor SetBkMode CreateFontIndirectW CreateBrushIndirect DeleteObject GetDeviceCaps SetBkColor GDI32.dll MulDiv DeleteFileW FindFirstFileW FindNextFileW FindClose SetFilePointer ReadFile MultiByteToWideChar lstrlenA GetPrivateProfileStringW WritePrivateProfileStringW FreeLibrary LoadLibraryExW GetModuleHandleW GlobalAlloc GlobalFree ExpandEnvironmentStringsW lstrcmpW lstrcmpiW CloseHandle SetFileTime CompareFileTime SearchPathW GetShortPathNameW GetFullPathNameW MoveFileW SetCurrentDirectoryW GetFileAttributesW SetFileAttributesW GetTickCount CreateFileW GetFileSize GetModuleFileNameW GetCurrentProcess ExitProcess CopyFileW SetEnvironmentVariableW GetWindowsDirectoryW GetTempPathW GetCommandLineW GetVersionExW SetErrorMode lstrlenW lstrcpynW WideCharToMultiByte GetDiskFreeSpaceW GlobalUnlock GlobalLock CreateThread GetLastError CreateDirectoryW CreateProcessW RemoveDirectoryW lstrcmpiA GetTempFileNameW WriteFile lstrcpyA MoveFileExW lstrcatW GetSystemDirectoryW GetProcAddress GetModuleHandleA GetExitCodeProcess WaitForSingleObject KERNEL32.dll VerQueryValueW GetFileVersionInfoW GetFileVersionInfoSizeW VERSION SHGetFolderPathW SHFOLDER SHAutoComplete SHLWAPI SHGetKnownFolderPath SHELL32 InitiateShutdownW RegDeleteKeyExW ADVAPI32 GetUserDefaultUILanguage GetDiskFreeSpaceExW SetDefaultDllDirectories KERNEL32 [Rename] %ls=%ls P;?@@? P;?@@@@? DdEBA@@@@= (*MXob hpppiffT ZaZaZXKJ Z_ZT_PI 075kmn _VTTPPI )-.Yln V_VPTPIG &+ Nlo !/45km zzz|||| CDE*&&' {{{s<. {ssuBBs@@@<4 puqqqqq<770 punqq974. O_mcs]0 NX\kqphZUQ3 RYjgfW2+* rlbA?4) }7" 5! z}z}z{v wwwwww wwwwww wwwwwwp wwwwwwp wwwwww wxwwwwww wwwwwwwx fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox wwwwww wwwwwx <?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v3.09</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/></appl NullsoftInst G!+ nT OT)X(C VDw~# i nZ-zmX >7G#Ka AtJT6: Ra6+hQ' nl *] #/&lWv `R}di}_"C 3/ HCs 4\J5q# ty:;dY =]?p=J 5@~\*Nei $;b"Fh \zPLFm a<{xF) [_ZpfO }z|8e=v qYPb7z0 a3UbpC 0i.AfGk8 tpp_>( aWZ p( Unypt 2Mm_!I& f4Q`F` h-'hJv egheil {L`f1|a R]?yfr5 KCt=(p RR^<@j 40vfI@ a KN_WKX peMz;k \s_&srv! =g7**4 1g9N}W %Ur+7AA& W[+'/V *J9]SU ZUf06+?Ue ~m;St@ DBm@AC &.v9*0PB$ a3t`N <nN3!F nEG*)P z*-W|Z/ VKJ}#/ :J)F7$ M#l7o ;6_9z3 ^<73&5g ZC?x RJ XdPGi/ Vq[#8?T"I _q)R%2 >9/~7U jCY:>G 0(RtAV #*fc5za N@'Z.~ Oxb8Yq6 uX9o< flzT!Y u7bTj{C \=DC|w |+(t q} BV@ ES T.gy"V hm_k|v :RD'.' oJ`` - _T*Soe t62cb&d2pEK B<%-{81 /_G6: =oOoa) TlbgUDOwd 8`CEbK -HG`R[X IvMww8 q$5R|RN I&snsVR FoAYG5\[ fCx/Cto )N^&AW Mn*l:5dy 8m}7A;c Wam&aL8 Z%j@fO]Z :h5S!Zt 9QVM5@ hc#yaE 7(9Z8qM %np~k> !!tQ(7 w?TlVL (2't!% 3AW0QU 6AoOU *?9o`v m%1k8 \RR~Z50V_ k9BhOa YuXvMN sS7xD_ Z<&EQcux 6R3B :Flfek[T HL8$x}% pMc{1g %.2-!Z~ Y|:SkT x|lqWE 4tw&0> IR@TD.zj}eLJny8 WU\E@! 8o}u7.0V oSIvU} a.0ay/ 7fZO_G YnLM}+k p)-(3i KRp8H+ #8x=<4; B"q_S- ;7X|I) _i%@q! |l{}hh qz2@fF R4|n{|Wx SkyYcjn }E[/h* CbQ2~A Lh8-x: e>16oWi e'[veY %l7ld0 (#:G~Y dIM8QSn l=>Yz3 PR 3t@ |4jLKA _afJT! 8ic2#R |r/{r`8 5'NodF! /co!tg &64A]f h\{OV)q#cV =\y*~* \N*{#3kV6 UnF4{A6x 5YE:2 \9V"_3 Mq/2)0-t 6@Pwm <-a){J/ G1dQMcH ^Oe:wvz *+vu"en hH;mo|z ELi+F) 3uYy7Z V$C(";D =Og@=#@ q<)zY>' ]-p;ia[ )W8:Pq1" x0[j=G =o!*50a B<&/Tk o'KF4\ RPf@.5 W><o28j bwg{l$g@ D X5H= b9R&#/K K_l3/VEx .dPOA }i`XrUD4x U{kE"& %=0wq` `bf#_b{Kxb 7(B\8u xJTS>% w"Q@rIv SB8vVB MN51qB m)8tk' AEwM>^ 1*2[ \o -xY)M$ VhAQ! ;q{@[E \>JA*'_ jDX)9|X# D_~0C1 5>4&z^ p0~R3<) P-xo{o\ i9d:Q< s?~hq ]iG4<S X(d[g{ )ejK9% ]bAYJl|> ?Dm8xB;%] BAM PA7 XTIg Z J[^RwSg [N=EA yTjxwZ hg-gI^U =eaZbD tZ|>7= _6/ E{ 8.g9L[ x|8aiq# i|g{pZh Y?WS?% ]{]bZR *u^rt[ (A/--[ 2D;#1` "upHm}t ?Weowd ^>Jsq{Q Mh>V}#D {r^k8RaP rBSw*. <2K;:|1= }00&:@ 7g_!x<D Bpv]>-Wyl^<gj -P6Awmh z0D;y~ W`2rdC twv)G: Nw6KU& }`XG u|0 x"c)I" U2h7Pc @P~~Pa j7)"Ok Yu#:G*C Uui.]} q+Y7D9J p$|X2i |}&@eD 4Ct6A* s])r[d *er2|Xp vEze8* }NSdZ<f{V Xg'9o; 'CRF h% PO\Wm_ hdOCKoY K\S.;o ]V17s? '0bfBx .y~Hwu F.;^R? MJ`.)& z[lKL5 7Xamti Rs-vBf EFpG k3 xISdrK _1ACsq ru7{XZ "WS@u( X'o\%e i~X={jg. ww5>$SBWL 'O|T1UL }L~1[/' `C9k<u} "cPj&! K)#6nx %_BGf@ .MwyEg '=RO ~ KrAwoK lQ|}wL '_9~D*x 5b_e!y -hQ'zm 4q_nYr cPGF*_^ _8pWhuP x 3R7e B}(B<i T3lkJ) X}3:3Q4i Vpi<u oq6rI }eIMq6 S2f"Ax I|a091 MRiQEh3[; +~lkKL 7 QhAzReE 23:me pw^?Hd 90M9oG F9/N:YV [kFKJS @~;+:e T!di}D Pk@rL 2C/}_d I#>l8f {4xMhE n!XqO `0$sKZW :M24tn' .DbeAFiv G74(= - dO}""F 7>&x\> z6$my9 *h}F5- s7h{;DG td;a66 t)BiWB )o]4@w >D(GeO h[MAmZzv #)Zv%TL D})D-7 T;UOFU ?Or(`x ceha=i. X}njF[s $C~C`v' Zq3*IbO @)l|qe jIsU{^ tFgH=n5 $:[*H) EURvvtC F$0&FpT\ v5ee."4 xc5#(YA Q8Un2e gPPxRr eMaf48= D\dZydm '|Z!T> Rj7=U TxKI} KD%g@2 6=.(h $ nWUGmb {O*UwB nv2!3l5 l^(4x_ }{W*kg ]id1J> .Gls3 $!J1dn Vj~Udc3 WxaUg^ 8xq0pc MA'<YLZ {Sy/tbE BF{uGR BRg'`"xcz clZG=M bq/Mvt n&<W)T! O:A6]| EIes[L 7zPTd$ 9V/$UB 4*nK-v GM k )[-VIB enW}+L0h =z]by ;XFqmr J]a7g dADDo]n) hAre=U [kQ8u} jwYp=L> v`=CtV a.) V SMTnKO% 6Z+"'<"  7F: H'kipq g~(Ekp rXqbl %#u296\K [C~BQ}E d9CQcM HdyrWe PTNt0; 5lWMi 6RKrcah ]kru{= @]'4<%O wX~)* Ya8#f(\ Q@?@lS v?x%z=B l D"_U L6s-]s 6}-Zy0 KvdRyp K? }2j o_YBzV E7~mRF ZQiFH9 d~kI2| E.dd#w IXdb:{ ))}H~o JstpAV A#x"!l7 {wt(E[ jPDmqr -8}-#RC 6?%2Qw K'cIa} $TnG!R m}X\-6 !q # ^ l"y-O= "F5(W !("Y9mm F"zjp_; V PGT8 1>~+NJ @s0e3v 8dC$T +*BO(G fkoE:` X<nE8O T~K%qf4 U;r'n5I vd.*dW uB{eF6 Of( u2 -2/ !%HM )4'@x8 ?79$ ~'9`cZ Hukmv- hfB5Ivq "Jm~Wp f@R}P!xW 8YlSq*jZS DDzY/ -%lBY) "e5I|B CJE>@V -f^:rk7& :bT:DG Ofa.26 \KIRya RF]A+ Df;wOs O~"_. ]Ul0yN Xk?ji6 Po%f> !r5;~=m@ t"!n;p& /uOt8e @&^ib3 Bd\=\e sAb G3 ##V9- `#h%Fv 3#9}Ph P:]L7kDc tf(qp ?#79w5 RD1m'Tu +Nw<0$ 64o[a. =OD!-u Lj+IkB" sRTMID ?5r-[d %L MmU ~~;y}Y6X n[>;~C @;Y<;#Ze 8Gpy/KOU 5KS}<9H LCxHHMo /o5qX} Tw@F47 SvHts. t 73%m mcc$5vB 4S:?~2 C+y28q Q1^]cs# >?CCaB @\paMo b;TeHQ Jm=0gT EEHFga <`y(s BWAgqt Y17z/E =#BQ6f VjI#jK\ X5a<y~ 2!xUiXq 55rWTi $Yji)k "1[R{4 @ITN[Y h)\wTdy q-kp)$ 3iSN>N Blo`d1 l$c;\+ N%Pf)b@ "Tvbl{ C.poD thC.LBU#' M"4*I1 A+)$`[ 3K2#k{ ?C{k%E Lb;-w`x"Y i7CozQj gw3D=" '2~8JX MR$O`I PH'\#n .\N (V 5)s=df %iTO~J )\l} f<I gH +"VxL` 9/Qo & C`A<4n x>S:>fnI8: %aN**V )a01CW gm>;]y L'N7@t d?65r@ fFRt#S) .H757 Qpf6g@ _dPPuq I)'z[_ e.]#@x C%4&Qz d(CYFH 88 I|:# }T0?'c #yc+;D@ NtP[-#^ Jjqu1' wtIMOIR Xt[_pJ KJJ]t3 _m(Cbs Yb'Ti8I P|p@|iH ?1xrg}2G Z26oA M`y\PLX ?oI:w=NsXu4~ [FfDt'C b(%T5W |VW:we 0yY.lo IMl8Pq^ HLf:q! u!yZD q-x=G28*B)( & oiid] qMKHUa e!{Ohc s1>?vFQc 494uLL 6<+Trp "#Ss ^ 7QT|" ~r-=-5 >i| =Fp Gn4-D0# }8u.// F[h*m3 J&: oC )@VgE}m|{ wnC'L;u 7<x `%H @eKhuM V .UIZ e?'-"Z XF!W'H Mk"-h< UZ0?u \Li6#e 9G8;?$ /RLl%Wq @12wQ1 SVjH{AE C|9-$/ l}~Xe@ syJE|O bVM:3` I"Lm<< '@wNkX G%7>m`* ?t(fim =k]7cl tfhjM+g 2TZB&UL eV:)'$ 4x^7{8# X%p. v $z$Bgk T#m^84$$H? ]_AN? 1z&3k_]1 {FpuVG `)D7Xo !/ hjd F`{I_nt ix D@I ycj%s. q'!3q]n G8gSq< @AIl:R Ex\{5< AdR5N1E`3R 1vA? ; JDyWP^5 CDkFmF* C:_aun yPb^q/ bK6aC? .V1.w{ uY8n"H nlkNz7 L]Np`F ?T%r8@ Ry^"?& e2MjR vOGh(! g 8MU# g~oGNt lsROta >(=.Xe .jQR]0EjW5 ~!iKhbu pXe'y\_ NS@a<bd 0&DuUoA$:t 1nE#p@ NoGzs]N _g(AvW I}iK^8 OtUCAv 'LO:jf(X oZkgk@ aYH%SG 6UTr5e LCH><g dK(r{2 !T+oJ3g U+$9sL Q7O _ BW~fM&E enVdB% xGr@Bs XwKmBQ II^0GY 0^-`\N} s$xgV< ;`'T"W 0xr**$ {-B7WL R+@xZ\_ >ekKu~ tg2x4*( Y=2\=e Wa-HpC=r /d{?07 npW<eY)u Vlk9s8Qv-9 ouyDBJ d@m2b@ ET"U1F "06a:Y :vX0{1 %>zp[h ^P:JmoA2v u3a/LG Ezg'l; {K%ztx 5V$p-@ b7JFK / %0a+zT sOMx#5 J-h~jq Qo^IY+ W"8YI{ 7g|Ncm 85_YI5:1 b-!>b1 S'tUET JTm6pX ~*lW*Y\ 4gflChM jJ!Y)A M.2=cn eQ|~C]T q\.FT8| xFP(`E BClt9" 30Scu0 =Y#[s 0@Y<v*=~ W>d5lX< 2]Ojn* nA ~i`$ w@[.)(A 5tZM H 5_8/K jmnYTO #%[<!L zK#uhVM$` `+59=a eW4_g k[T6t1(1?% nWqNv @ Y5yv u*j$][A n^@HVt I{;x.J< *UXq8f 9g;Vk06:]pZ81!@T$ z'M Eq7 (P}0Zi v*I'ra_] 9'k"Nj t?dz1/ %F8d.A xkKn#J rR0[$tAQ v(v810 s)$"sb Y &(0 b _A#^tX Wygrj 7[xGr>s :8_gR-n )Nx@3@\E @ElaU%? A:87"8 7AB"GS'MA k^lV*/ hh#)+ l#rlb9f~ lD7{nJ 7o!A??k "LH^c) "s*bh bto^Xqj yYw(ZD |p*hnB 1k6gD! /WL]6\ h_Q0OX qc^8!# 2N"~d3 @Wl7fQ DG|ge* e3_{a7 L`<?uB b5+[V yfJU'Fkj LX/.<d XbP-YP eH&|8@?z -'=.2GE5 ^AQ>1n pf.[pL /["O s ~@=]dX7N|mh^l t}_xsk ~\rJqs 54L2kpr@ Zi>aMqAs "o)ItA {Gi0(r# "\wL_f 9eG/sl bZ9en/ yBS1A29E Og}[j slH~Zk m%ORe/ zNQza> 3NG{Ij xSYxDp )S>%HH 32\Z@9 oTLDBg yq5'=b bV)I? x7\heud v]LoC@ of`sWJt .7jrR7 p_;%cZb !pO$_g \S !RT Pb \1=C q`>r $nR _zq|TB G]'yt%_Q ]0RL+j up.#SV Mpk<7o 1k7~O/ vAm1x@ X RChn sh}^n= =Jk-^y[ |Im.'b 59[A~$ SbH<U|+ W 2KBH o O}x) 1p-@vW bElLS) @p4O `%fX AGs:C hwpj> P:\Aal 2ggCa= ^&#~o ?W.Dgm >*p)XP [y|L. rL^tmwGV .+j-%d l1.#Db :{h$\Sh OO|L)\'? }-]w$5>* q<xI!N +<aY!V} [c]H[zL} &AJRc. `(;vAH xS;J{f )#H"Z r`oA^B Ckr?XA rSSqE| UUsno= +X'S+@^ (-f@5/Z ]<'UY8Jl J4Ku%[v [4Lxw~~= SBMO2A .)@|N{bM4 nAUeehk< 3Dx3^+ %Zxxj.8 ]6Dcy9 FplvKQ9 l{To^A .t/\d7 ksAlRu v3j=66 =9zlB_ @sHGpzw /{r&;; mt5rr0 Lq\N<(` WV1kbp: 6o<[q% YtAtsg Osi9Vy 8=6t\% p8`%g (c-J5 |Gk_1Y%Y Lr/>=r 1Yyg + IwS$Tv y1uSfcM 6+3k};i yBwwWP )Ey8/: (Lv&g` G:VO}# h#5Y0%s xS'=%_d UW"y"7 /2$s1u *XcmEy%+ xPDv\jr (D[3Vq RvwADa %`yNb( M< .p@ byU8 - E9SkA2l_j iT3^sJ&66 $]fG55 :a:0gv )#|0E Qy\m{u! ik]!()4 /4sR32 6A*AI>o +2q X?K I+/2Yh ~rN>d[ $::kcX QgtsK~ !G#B[i [}}HR( nqc_6B [/6J@sd 9)zIF) $9b!dr ~UdfLs `?MP%N d<WRk( ~(AlxS mZN78- z&~baL J6>"c& y7*jn"Y 62m}BYc E1KYnf aY8E(-o -O4~`S n:U J] yX4T$Du f*@R<Nz ~"@5}H WIC=i5 fU|10] ~SJe&Yv ~o"}di yj`x2Wo P+Xp.o 5j`A"y u-$<Vd yNnP0Q .h/0'@ kC&Bv u{|T}~ Qw>D<~ HDv!c!o {=Z`F* 1GCjLLg` -a-?6`g TbUhQ# UN>V4V CFNZ{P M-KS#xm )~p'4C #jNUrd r+~*lw B=A2%wO >\}q&_t Inem5} O]pmpD f%;v]d^ GpWC`O bi/e65) #'PaYut[c NzN2eU+ C K'q]= \ax3)v NlmL\H 1q]|;t r@DkJ= NeoW?S: ;&Dq=lI pPXVX{6 ~hWmPD[(~e A&?+a2 SX#V#d .0 Fh ){\TE## <d>w+( ?-HO2p< #/O(M" o2tNeL aSg>HDY <J$X6} P\26x+[ ;di^R"4 M{w4z#o^d6 QbRHmR ty$TY; P8m"2; 4+)W$I.D 8&5+*u 9oKk6w YY*k{x "{1JE< |I8Qq C$ "8*dj- v<LpPQ P:&90k V[/UfA us]_Ql L(D]` ;3pS7 ="R{"5;v AO8~N'( s"\Y0v gMBC?$ D#DT3/}_^ HQ^\f] L$2A!i%- *@-ukB <2@y+:63 Jh3Zsc knG[sz&B5 ]t{4^s pQ9_^I Z/b~3M }Q{+Z48 /"U&gr .Kg#P? A%2NG 0%ms.Ha h=Q<K8 ITff5D PQ<)Ob +II7uw "@w~fI YrzAp1 t:MN66 svx\Stv %D }yC 9Q\4C\ Z-aX6lqs OPE(w.h@ p[-7vz '-Q(0" J!<_j~ VD`BGf <BF}>a A61=r< X+z~A7 ?)|P(wD{ \Fwvj^z @4W$bG m_Ei&$( @OE.~+01 U\30KV A$KLT9 Ds<`-uW' V]dT%D!Z Wl>`[S ]}-}+W!b h5l+B?. G6{"p" cK1rl(up ^_=I(V 2Ov3jB9#4 ?r:?5=D ';k:Qbo '[2kXz %6_;<='s 2=ox1E .gIc2a<#.6P Ib*m1 Hx)m^$YD ~gr)v_ 2S5-}M R8Lm78 I5u;M& )w{BZy 8cE\D(F ]~!mUu ]3w S:U N<;OzE pbfD=b >[S{ST sfstb$ 6\yoj# "^83!}&n E5DrBOicU Vh(]o@ F^%q5\ !H5lme K2<HAy>n '+jYAg oTd| rU!%\@ NE2FlFl v;-10dE H2_.x< &=`~3 b+oQe<S #ys!OX <x8):@ aVFC!M ^V'$O( /v&$}] OCR=`v! pqLsu LCBk = b30M${ .@O^YWlhn R.M=4v nMb [a c- 34; CNJ:8nnj b=+jGA *C\c~EK: c}Cj)HX.9 M_6U@O @A:~"] "MrHbY {975]8 gISt3@% L<nRK [Fr5V^| e*.3Bi j)B'7YL c+5T{N_\ 'WFShf 0o-.L8 G)(2+3 Ih MJy UO$wFA r:7g[ m?T-rr(' R~)mh%w !$7Gsp +ZQl7HT n[$dodZ ~HuHt !q0<XW wO#0}0R cqDfB-l C\fd?+s0 xj|9q~ |XZj\9 9}}70f 9'}[kf tt(x%) KH'pbG }UyZBNo bu?nH\ \Z0aW> dP|i;q )W4w{W AysW9o jG>4:\j wM|K\% iNl9~MN {w s}b{0 Q6uO#x :>|p2| tSJs>} W]v2[c/ %#fx)f hJ9n{n s]~!B0 xLcvHiF lR`kK- b! cT9 k)?9!n 4-LUn4Qv 5Na%OMTG >2o<#U O~>0>1k} XIHmT| OoT/t:Pj TJC(\C }is+/B DZZr@"f HmXWY8 */T?-H "uw+eJi+ LD/.=V S!MAU9 GL-v.h R)$WIgq -#Zg"@*?mH leKU49 EG~P8C s.fo8# !+%*.14Nk `IIn0G 9<P+E7%1 p<0AEX W\d#m2 ;58O"e lINL*_ VgX@FRY R*7|[c w4CKgV Ou^i"*d / XXU# #;x@d 7KqPA)YW /%T1!U 4y E6* {^0K4_ (S3Kkn aAF7K"$ xhg~xO8 F@/.2WHTm1 fMXx3 |ckRtuJJ iH/WT& B2CL l _lY*"^ jfx>SNo !cj:h' %C|LJPb=[ #xb"}c y 2Y[g ^M'JjB Uie>-uN E5y])p _'X(BU"5 Sw*`8* "D=)i~ 7<#N<) g({a%Y >KKsw z6@ssC vwqq;8Z5 _y#e~We }dYf_n ~!pgi6 I!=f!e ;j 6~s #49qGF K6y2}fK : VM)' =sRKZ zc&S\C "8zzy<_W {}DYw6 3Gn_g {z(B:#s ?z-Lsv l$/h[q: [Dsb"d _nF84 f T[5yEX S{{fAv <=_NSi~- TM]:vY x9/y-E ^"_wLh \l:lDZl 1EsCi@ Jz1ih ELLU0XoN BB>CkLUq G'Mg9( :Du2uUhF ~rhE` %Ogso"1 8aJTw( P03}(6 S:h/Mx j_9|~Q iG] ko 2S?kv% pj.c" 5 "r?0WK nE(2Op Yb8T_8mt auzmruh #s5Un< N)?:O9jr %@N6+As .kf2j+ ry^YPf |{QF;) wQ*16Tv Bf?]j+ ~.=us/D z`_V2t btC&f) /H1abl V65n9 9o.|y[ RnT" o *#E&]` "vh@!R N:PxB[ 09gFN3 w}._9Q 8mx2)/n>yO -9At cG L5u6-9 vTM-^v .w|<== {isIu]r d]70aB IIBrp lV$_#6 Z<!)5#c ` P|1n- fV(Y%m FIKXj1] x? Kzu }rBe\s LmPJju $Ph^{iI I^&!(& wIm/+i ){<D i U{!'m- ?v#>8r TIu;&; 2f$ax[ .{==x_ 0#7feS PI=Fl? ih|YQP% /"F2b_YI <h.?2$ r]c67} 3_ob5$ iDY<6= q1/PVG vGJg[ Zb;]*9LK p_OK*{ K=oc4 m :/YGUn 5ogEF} of\:1r. S]DNTP {" Xz/`S[e% !!P&y0 KwpH;2 / ya&O&6nu Qsf4k>b )pVmur JfJ3&a 5^QSkF E3R _!Z @lf3ya !%Y mfSo \8Ye~\U IuKl24 N\i H1 Mgfv&j UIX9?$X 0+Imls\ pH!U5C ]UN1Uc Kcu72h; y$w):s 0s "o[ $bq }Z[n %WMkw? C.W$bV J.F[%+ &1s=EBf' 0lIr.0 tDV3C2P $6Rh?0 f # #]%n n0jsgA )mTEdZ B&p x% \('gN-v I!a"9&} yp%^\)[Z5[ +gy-9<y] !%$!wg3 >7e^~R abw@2b R.TB06!) +^U"Mx Uc RWf Lg^<eT CwAq: mRE}N 5#>G|* b5{@dR L7 j7cr+L. K!xyley ?{!N'6w #c h<k F(6^5y TL-qI Rv"6S@4\ld >!`>fT G{><;` iOG0?c $5b4:p} )Wm+wRi; >N2ku]N ;T_"n .s<O$b3 $]xJ`b nS(s49 8_n/|8 0&& ~@lZ r_}HZy yK3OX$ sItr~) N-D!rOMq }UgNl3 N9Kr|eVP thI?N 8q^>esY xWu(rr s8+z-O_Y pt}o}e B1~|Zv QS yW! IvK5)P "v6xVk Ox0fo" ki`X"58 &:MrK-Hq i ' H+ :2xbi+mE <u"dV7 *X-in< E;/$rh? -3q|$f UoQkFY V?i'tx Ut< [wC zU< .'m 1((>tw ]R$w|D* }tSYr1 fuhp<s K71e31 #:HJBC lJ'h8L RvC>8bm /+z}~' n#iBd4zR Q7u__|` *"0n@a uIRnG1} Yl{|4S G@\Vg5 rEgB o XtuFiy M{N$ARi *Y)*XYu2 RJ+s]P q\77F`ck uFR%Zk -j72]l ^N!hJp{qgR-+> "B|n\n &ukG7` 0rWC;t5 HS/~zU 2sQ@<c 9#X slX R$r[aDI yao2(d FEZ*kp R!*Wj" AO7sjKR ABCM~Y R23c<E -%^POf ulTL zU k6yuS W<Tz\`S GP4*! iVNY8e ZyF16p (_lABf *R+8P7' &:1mS~Gd QV~h9W &2e)CRn @R#G[| mLTd?:ZKH e?W_ye {h$2yN m(X\vVHD -LK=y% :a\p:h eBelay 9:'aPrp~ C!zbu/ h*b!%c YFfN'@ 9H!ua1 VF%)LTA2 {efAN Pwnef$C c{w]iJ $t8 nqjw o)h_XI WGwaN CNa(PBdc "&@Dnl9 6B$TCSr C>o8p* n|0Z.XY `A\)*p ^h2-u^ rBv^Sn .xU2r(C y1}%1e2 >1%[wU }L7Kn1 4:?] > '}fS\ DP]Qr( NK7(w) DlE " Fd:0~PX dYu)Bq CZn@fI CO"?b7 Z<29$k <}y~#[ ^Nr]iA LA31iM/ %F>hQK HxV]4) L An|(p n9nNXv qp`J"J _QkCPd U4T?'J%)N B`8m.= P:7J6Qt+ 9K^r* 3D& h- j0X@7@ pA)[al `WhW07 Na!]t: ^@RBoN R#u7R| Tw".7\ s@D|J<o +"?4XK0 _ uU? v]x*(h ZHvda5 .;6L*A E52^h- SuK[oV BrPh<SFBJ iBq~5(+ IsjD4 Q6@>Im) *Ez-g i4[PEL &t"Qzl _o+[c; #Fe@j+Pe: D\7FXf g.W-nE7 ]4|2$r # #Nu!-Yo C /vsq )REApc 5[%P; G(lQZ{J 3:J|2[% S0+AW '6.'#@ \2T;_8|k [z_H|' JgWqPO Q4MX~U? /aO2^{ ^#UIw5VX [j{:zw HLph! d b*k o <JATd1- Ij.Pq` $+-4P +v~z.! &H!X5F 7WWb:M p)"hh! 6ckp]D -i{09^ QH]jbi $K_y^ 4WFVA't zKduVY V^+]uBN Sl&H` 0 :}<d|d Y23zsr 0%l =V a;=4UE .]sPS$ ch9j=d 8`u6m 'dUgY/q% Sj0S | yC$%b? VA.".n }M-9") <A%+'W Mr+IPX %&-6M0 2/1r H oAZ+Ix mM3+B6 Fh;_L. <\tIJ5 ~;2R~5 2uz6~Ob L?m)+"K Sgm2Na aW)SBV@rkI)[ ]##b+e' jhJ@:A| +f[h+` _\O>D)' )NKIbg \PN?fR rPlt/WbfA (4 {@}\ }zFej2 Vi#}!c G>w.B C.iV$ #G4nl7 HptUr"\ DY{L&-? jx"yd vB d2_L]\ .So6PP &z("k;u8. M!HIMw Ii7`WJ _%45XCp_ 7A4VJ`o< %;cy6\ gI~@DC o) Sy4) '28=Z* yabV5 3jJsI( <<[v4A9 _Y*V^SJ -LMTZ4Tw 4Qdc%': |(:4l{ K5RX"* wC>FH0 8/Q1xE& =O-!dFG8 h\YEJG F$X?]@ :yYlIvqt 3[Z0 @ \LVGQ\q}X \I g{B bmufp` U$K]Kn0 +]j`]4k5} ~K|3Q: =z@93k aF9Wv^ ybm.df :"?^kq1G |5cOhO 2cYn5$ C*PFG- _:xduc o'&a> !ansxB l2xYC< j8>/|X Q~/Y6& <$z5;0WJ wA:@ ) Cr-S9P Lf6T+* "V|@W^ eg"#7: ozUr 2\tw9C ~:&S4K lc!!!k 7OYM/!s A>VTB? q0c.}f 5`{h4hZ >-FCj\ m5{rP= lxO8J| T-^M(( /?`$~ $DKJm8 wj{6JV *d)kV. #/:^Xf oA4Sk //wVA= ?4@YB# vIO`u =h4'?" **!4`? JV.y5G]6 7A&vC% C<N8f[ ^O.&/[ g[1u`jP 9}`nwx: tJ /0U =+_4v.." 0tPVA3 ejJJ;f ?[Pvf? kwZ 78 j$c3DR >w:}5IK6 W]4Zpz -[#0sV :hSqm< b)6jZW<Y* T6J&}V $w5+`S ^HmD }0S hcFNq- g28ak \}W*E$l C@dA6i -tpfT$ BTJ /zavtX I~3ugG Wzn'X%v #!mS$'+ {sJ=JkD 0HnAnI B[_5vb 2N$GT- @feVA i}N;h{s 9- )ws^W& ?v{1] t3UG7$ rK%x= Yq'KmY YY?c2eS g9H/Rt k%b3mn 6nVDwR}% {*K @aV< 2f&;Z_ A=)=6+ sfDJ?u H*GoKz b`an`# deYC~A /%xvBP* 117b306b65da5f061cf92f5ec4091267db1d282bf31bb9af3cc1e7cdb4c7830f
2401 Accessibility 0 !This program cannot be run in DOS mode. `.rdata @.data .ndata Instu` softuW NulluN UVWj _3 L$bf-S D$ Pj( D$ UPU Vj%UUU f9=H/B D$$+D$ D$ +D$$P WWWWjn \u f9O 90u'AAf l$(9l$(tr +D$(PV UXTHEME USERENV SETUPAPI APPHELP PROPSYS DWMAPI CRYPTBASE OLEACC CLBCATQ NTMARTA RichEd32 RichEd20 RegEnumValueW RegEnumKeyW RegQueryValueExW RegSetValueExW RegCloseKey RegDeleteValueW RegDeleteKeyW AdjustTokenPrivileges LookupPrivilegeValueW OpenProcessToken RegOpenKeyExW RegCreateKeyExW ADVAPI32.dll SHFileOperationW SHGetFileInfoW SHBrowseForFolderW SHGetPathFromIDListW ShellExecuteExW SHELL32.dll CoTaskMemFree IIDFromString CoCreateInstance OleUninitialize OleInitialize ole32.dll ImageList_Destroy ImageList_AddMasked ImageList_Create COMCTL32.dll EndPaint DrawTextW FillRect GetClientRect BeginPaint DefWindowProcW SendMessageW InvalidateRect EnableWindow ReleaseDC LoadImageW SetWindowLongW GetDlgItem IsWindow FindWindowExW SendMessageTimeoutW wsprintfW ShowWindow SetForegroundWindow PostQuitMessage SetWindowTextW SetTimer CreateDialogParamW DestroyWindow ExitWindowsEx CharNextW DialogBoxParamW GetClassInfoW CreateWindowExW SystemParametersInfoW RegisterClassW EndDialog ScreenToClient GetWindowRect EnableMenuItem GetSystemMenu SetClassLongW IsWindowEnabled GetWindowLongW SetWindowPos GetSysColor SetCursor LoadCursorW CheckDlgButton GetMessagePos CallWindowProcW IsWindowVisible CloseClipboard SetClipboardData EmptyClipboard OpenClipboard TrackPopupMenu AppendMenuW CreatePopupMenu GetSystemMetrics SetDlgItemTextW GetDlgItemTextW MessageBoxIndirectW CharPrevW CharNextA wsprintfA DispatchMessageW PeekMessageW USER32.dll SelectObject SetTextColor SetBkMode CreateFontIndirectW CreateBrushIndirect DeleteObject GetDeviceCaps SetBkColor GDI32.dll MulDiv DeleteFileW FindFirstFileW FindNextFileW FindClose SetFilePointer ReadFile MultiByteToWideChar lstrlenA GetPrivateProfileStringW WritePrivateProfileStringW FreeLibrary LoadLibraryExW GetModuleHandleW GlobalAlloc GlobalFree ExpandEnvironmentStringsW lstrcmpW lstrcmpiW CloseHandle SetFileTime CompareFileTime SearchPathW GetShortPathNameW GetFullPathNameW MoveFileW SetCurrentDirectoryW GetFileAttributesW SetFileAttributesW GetTickCount CreateFileW GetFileSize GetModuleFileNameW GetCurrentProcess ExitProcess CopyFileW SetEnvironmentVariableW GetWindowsDirectoryW GetTempPathW GetCommandLineW GetVersionExW SetErrorMode lstrlenW lstrcpynW WideCharToMultiByte GetDiskFreeSpaceW GlobalUnlock GlobalLock CreateThread GetLastError CreateDirectoryW CreateProcessW RemoveDirectoryW lstrcmpiA GetTempFileNameW WriteFile lstrcpyA MoveFileExW lstrcatW GetSystemDirectoryW GetProcAddress GetModuleHandleA GetExitCodeProcess WaitForSingleObject KERNEL32.dll VerQueryValueW GetFileVersionInfoW GetFileVersionInfoSizeW VERSION SHGetFolderPathW SHFOLDER SHAutoComplete SHLWAPI SHGetKnownFolderPath SHELL32 InitiateShutdownW RegDeleteKeyExW ADVAPI32 GetUserDefaultUILanguage GetDiskFreeSpaceExW SetDefaultDllDirectories KERNEL32 [Rename] %ls=%ls P;?@@? P;?@@@@? DdEBA@@@@= (*MXob hpppiffT ZaZaZXKJ Z_ZT_PI 075kmn _VTTPPI )-.Yln V_VPTPIG &+ Nlo !/45km zzz|||| CDE*&&' {{{s<. {ssuBBs@@@<4 puqqqqq<770 punqq974. O_mcs]0 NX\kqphZUQ3 RYjgfW2+* rlbA?4) }7" 5! z}z}z{v wwwwww wwwwww wwwwwwp wwwwwwp wwwwww wxwwwwww wwwwwwwx fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox fffffox wwwwww wwwwwx <?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v3.09</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/></appl NullsoftInst G!+ nT OT)X(C VDw~# i nZ-zmX >7G#Ka AtJT6: Ra6+hQ' nl *] #/&lWv `R}di}_"C 3/ HCs 4\J5q# ty:;dY =]?p=J 5@~\*Nei $;b"Fh \zPLFm a<{xF) [_ZpfO }z|8e=v qYPb7z0 a3UbpC 0i.AfGk8 tpp_>( aWZ p( Unypt 2Mm_!I& f4Q`F` h-'hJv egheil {L`f1|a R]?yfr5 KCt=(p RR^<@j 40vfI@ a KN_WKX peMz;k \s_&srv! =g7**4 1g9N}W %Ur+7AA& W[+'/V *J9]SU ZUf06+?Ue ~m;St@ DBm@AC &.v9*0PB$ a3t`N <nN3!F nEG*)P z*-W|Z/ VKJ}#/ :J)F7$ M#l7o ;6_9z3 ^<73&5g ZC?x RJ XdPGi/ Vq[#8?T"I _q)R%2 >9/~7U jCY:>G 0(RtAV #*fc5za N@'Z.~ Oxb8Yq6 uX9o< flzT!Y u7bTj{C \=DC|w |+(t q} BV@ ES T.gy"V hm_k|v :RD'.' oJ`` - _T*Soe t62cb&d2pEK B<%-{81 /_G6: =oOoa) TlbgUDOwd 8`CEbK -HG`R[X IvMww8 q$5R|RN I&snsVR FoAYG5\[ fCx/Cto )N^&AW Mn*l:5dy 8m}7A;c Wam&aL8 Z%j@fO]Z :h5S!Zt 9QVM5@ hc#yaE 7(9Z8qM %np~k> !!tQ(7 w?TlVL (2't!% 3AW0QU 6AoOU *?9o`v m%1k8 \RR~Z50V_ k9BhOa YuXvMN sS7xD_ Z<&EQcux 6R3B :Flfek[T HL8$x}% pMc{1g %.2-!Z~ Y|:SkT x|lqWE 4tw&0> IR@TD.zj}eLJny8 WU\E@! 8o}u7.0V oSIvU} a.0ay/ 7fZO_G YnLM}+k p)-(3i KRp8H+ #8x=<4; B"q_S- ;7X|I) _i%@q! |l{}hh qz2@fF R4|n{|Wx SkyYcjn }E[/h* CbQ2~A Lh8-x: e>16oWi e'[veY %l7ld0 (#:G~Y dIM8QSn l=>Yz3 PR 3t@ |4jLKA _afJT! 8ic2#R |r/{r`8 5'NodF! /co!tg &64A]f h\{OV)q#cV =\y*~* \N*{#3kV6 UnF4{A6x 5YE:2 \9V"_3 Mq/2)0-t 6@Pwm <-a){J/ G1dQMcH ^Oe:wvz *+vu"en hH;mo|z ELi+F) 3uYy7Z V$C(";D =Og@=#@ q<)zY>' ]-p;ia[ )W8:Pq1" x0[j=G =o!*50a B<&/Tk o'KF4\ RPf@.5 W><o28j bwg{l$g@ D X5H= b9R&#/K K_l3/VEx .dPOA }i`XrUD4x U{kE"& %=0wq` `bf#_b{Kxb 7(B\8u xJTS>% w"Q@rIv SB8vVB MN51qB m)8tk' AEwM>^ 1*2[ \o -xY)M$ VhAQ! ;q{@[E \>JA*'_ jDX)9|X# D_~0C1 5>4&z^ p0~R3<) P-xo{o\ i9d:Q< s?~hq ]iG4<S X(d[g{ )ejK9% ]bAYJl|> ?Dm8xB;%] BAM PA7 XTIg Z J[^RwSg [N=EA yTjxwZ hg-gI^U =eaZbD tZ|>7= _6/ E{ 8.g9L[ x|8aiq# i|g{pZh Y?WS?% ]{]bZR *u^rt[ (A/--[ 2D;#1` "upHm}t ?Weowd ^>Jsq{Q Mh>V}#D {r^k8RaP rBSw*. <2K;:|1= }00&:@ 7g_!x<D Bpv]>-Wyl^<gj -P6Awmh z0D;y~ W`2rdC twv)G: Nw6KU& }`XG u|0 x"c)I" U2h7Pc @P~~Pa j7)"Ok Yu#:G*C Uui.]} q+Y7D9J p$|X2i |}&@eD 4Ct6A* s])r[d *er2|Xp vEze8* }NSdZ<f{V Xg'9o; 'CRF h% PO\Wm_ hdOCKoY K\S.;o ]V17s? '0bfBx .y~Hwu F.;^R? MJ`.)& z[lKL5 7Xamti Rs-vBf EFpG k3 xISdrK _1ACsq ru7{XZ "WS@u( X'o\%e i~X={jg. ww5>$SBWL 'O|T1UL }L~1[/' `C9k<u} "cPj&! K)#6nx %_BGf@ .MwyEg '=RO ~ KrAwoK lQ|}wL '_9~D*x 5b_e!y -hQ'zm 4q_nYr cPGF*_^ _8pWhuP x 3R7e B}(B<i T3lkJ) X}3:3Q4i Vpi<u oq6rI }eIMq6 S2f"Ax I|a091 MRiQEh3[; +~lkKL 7 QhAzReE 23:me pw^?Hd 90M9oG F9/N:YV [kFKJS @~;+:e T!di}D Pk@rL 2C/}_d I#>l8f {4xMhE n!XqO `0$sKZW :M24tn' .DbeAFiv G74(= - dO}""F 7>&x\> z6$my9 *h}F5- s7h{;DG td;a66 t)BiWB )o]4@w >D(GeO h[MAmZzv #)Zv%TL D})D-7 T;UOFU ?Or(`x ceha=i. X}njF[s $C~C`v' Zq3*IbO @)l|qe jIsU{^ tFgH=n5 $:[*H) EURvvtC F$0&FpT\ v5ee."4 xc5#(YA Q8Un2e gPPxRr eMaf48= D\dZydm '|Z!T> Rj7=U TxKI} KD%g@2 6=.(h $ nWUGmb {O*UwB nv2!3l5 l^(4x_ }{W*kg ]id1J> .Gls3 $!J1dn Vj~Udc3 WxaUg^ 8xq0pc MA'<YLZ {Sy/tbE BF{uGR BRg'`"xcz clZG=M bq/Mvt n&<W)T! O:A6]| EIes[L 7zPTd$ 9V/$UB 4*nK-v GM k )[-VIB enW}+L0h =z]by ;XFqmr J]a7g dADDo]n) hAre=U [kQ8u} jwYp=L> v`=CtV a.) V SMTnKO% 6Z+"'<"  7F: H'kipq g~(Ekp rXqbl %#u296\K [C~BQ}E d9CQcM HdyrWe PTNt0; 5lWMi 6RKrcah ]kru{= @]'4<%O wX~)* Ya8#f(\ Q@?@lS v?x%z=B l D"_U L6s-]s 6}-Zy0 KvdRyp K? }2j o_YBzV E7~mRF ZQiFH9 d~kI2| E.dd#w IXdb:{ ))}H~o JstpAV A#x"!l7 {wt(E[ jPDmqr -8}-#RC 6?%2Qw K'cIa} $TnG!R m}X\-6 !q # ^ l"y-O= "F5(W !("Y9mm F"zjp_; V PGT8 1>~+NJ @s0e3v 8dC$T +*BO(G fkoE:` X<nE8O T~K%qf4 U;r'n5I vd.*dW uB{eF6 Of( u2 -2/ !%HM )4'@x8 ?79$ ~'9`cZ Hukmv- hfB5Ivq "Jm~Wp f@R}P!xW 8YlSq*jZS DDzY/ -%lBY) "e5I|B CJE>@V -f^:rk7& :bT:DG Ofa.26 \KIRya RF]A+ Df;wOs O~"_. ]Ul0yN Xk?ji6 Po%f> !r5;~=m@ t"!n;p& /uOt8e @&^ib3 Bd\=\e sAb G3 ##V9- `#h%Fv 3#9}Ph P:]L7kDc tf(qp ?#79w5 RD1m'Tu +Nw<0$ 64o[a. =OD!-u Lj+IkB" sRTMID ?5r-[d %L MmU ~~;y}Y6X n[>;~C @;Y<;#Ze 8Gpy/KOU 5KS}<9H LCxHHMo /o5qX} Tw@F47 SvHts. t 73%m mcc$5vB 4S:?~2 C+y28q Q1^]cs# >?CCaB @\paMo b;TeHQ Jm=0gT EEHFga <`y(s BWAgqt Y17z/E =#BQ6f VjI#jK\ X5a<y~ 2!xUiXq 55rWTi $Yji)k "1[R{4 @ITN[Y h)\wTdy q-kp)$ 3iSN>N Blo`d1 l$c;\+ N%Pf)b@ "Tvbl{ C.poD thC.LBU#' M"4*I1 A+)$`[ 3K2#k{ ?C{k%E Lb;-w`x"Y i7CozQj gw3D=" '2~8JX MR$O`I PH'\#n .\N (V 5)s=df %iTO~J )\l} f<I gH +"VxL` 9/Qo & C`A<4n x>S:>fnI8: %aN**V )a01CW gm>;]y L'N7@t d?65r@ fFRt#S) .H757 Qpf6g@ _dPPuq I)'z[_ e.]#@x C%4&Qz d(CYFH 88 I|:# }T0?'c #yc+;D@ NtP[-#^ Jjqu1' wtIMOIR Xt[_pJ KJJ]t3 _m(Cbs Yb'Ti8I P|p@|iH ?1xrg}2G Z26oA M`y\PLX ?oI:w=NsXu4~ [FfDt'C b(%T5W |VW:we 0yY.lo IMl8Pq^ HLf:q! u!yZD q-x=G28*B)( & oiid] qMKHUa e!{Ohc s1>?vFQc 494uLL 6<+Trp "#Ss ^ 7QT|" ~r-=-5 >i| =Fp Gn4-D0# }8u.// F[h*m3 J&: oC )@VgE}m|{ wnC'L;u 7<x `%H @eKhuM V .UIZ e?'-"Z XF!W'H Mk"-h< UZ0?u \Li6#e 9G8;?$ /RLl%Wq @12wQ1 SVjH{AE C|9-$/ l}~Xe@ syJE|O bVM:3` I"Lm<< '@wNkX G%7>m`* ?t(fim =k]7cl tfhjM+g 2TZB&UL eV:)'$ 4x^7{8# X%p. v $z$Bgk T#m^84$$H? ]_AN? 1z&3k_]1 {FpuVG `)D7Xo !/ hjd F`{I_nt ix D@I ycj%s. q'!3q]n G8gSq< @AIl:R Ex\{5< AdR5N1E`3R 1vA? ; JDyWP^5 CDkFmF* C:_aun yPb^q/ bK6aC? .V1.w{ uY8n"H nlkNz7 L]Np`F ?T%r8@ Ry^"?& e2MjR vOGh(! g 8MU# g~oGNt lsROta >(=.Xe .jQR]0EjW5 ~!iKhbu pXe'y\_ NS@a<bd 0&DuUoA$:t 1nE#p@ NoGzs]N _g(AvW I}iK^8 OtUCAv 'LO:jf(X oZkgk@ aYH%SG 6UTr5e LCH><g dK(r{2 !T+oJ3g U+$9sL Q7O _ BW~fM&E enVdB% xGr@Bs XwKmBQ II^0GY 0^-`\N} s$xgV< ;`'T"W 0xr**$ {-B7WL R+@xZ\_ >ekKu~ tg2x4*( Y=2\=e Wa-HpC=r /d{?07 npW<eY)u Vlk9s8Qv-9 ouyDBJ d@m2b@ ET"U1F "06a:Y :vX0{1 %>zp[h ^P:JmoA2v u3a/LG Ezg'l; {K%ztx 5V$p-@ b7JFK / %0a+zT sOMx#5 J-h~jq Qo^IY+ W"8YI{ 7g|Ncm 85_YI5:1 b-!>b1 S'tUET JTm6pX ~*lW*Y\ 4gflChM jJ!Y)A M.2=cn eQ|~C]T q\.FT8| xFP(`E BClt9" 30Scu0 =Y#[s 0@Y<v*=~ W>d5lX< 2]Ojn* nA ~i`$ w@[.)(A 5tZM H 5_8/K jmnYTO #%[<!L zK#uhVM$` `+59=a eW4_g k[T6t1(1?% nWqNv @ Y5yv u*j$][A n^@HVt I{;x.J< *UXq8f 9g;Vk06:]pZ81!@T$ z'M Eq7 (P}0Zi v*I'ra_] 9'k"Nj t?dz1/ %F8d.A xkKn#J rR0[$tAQ v(v810 s)$"sb Y &(0 b _A#^tX Wygrj 7[xGr>s :8_gR-n )Nx@3@\E @ElaU%? A:87"8 7AB"GS'MA k^lV*/ hh#)+ l#rlb9f~ lD7{nJ 7o!A??k "LH^c) "s*bh bto^Xqj yYw(ZD |p*hnB 1k6gD! /WL]6\ h_Q0OX qc^8!# 2N"~d3 @Wl7fQ DG|ge* e3_{a7 L`<?uB b5+[V yfJU'Fkj LX/.<d XbP-YP eH&|8@?z -'=.2GE5 ^AQ>1n pf.[pL /["O s ~@=]dX7N|mh^l t}_xsk ~\rJqs 54L2kpr@ Zi>aMqAs "o)ItA {Gi0(r# "\wL_f 9eG/sl bZ9en/ yBS1A29E Og}[j slH~Zk m%ORe/ zNQza> 3NG{Ij xSYxDp )S>%HH 32\Z@9 oTLDBg yq5'=b bV)I? x7\heud v]LoC@ of`sWJt .7jrR7 p_;%cZb !pO$_g \S !RT Pb \1=C q`>r $nR _zq|TB G]'yt%_Q ]0RL+j up.#SV Mpk<7o 1k7~O/ vAm1x@ X RChn sh}^n= =Jk-^y[ |Im.'b 59[A~$ SbH<U|+ W 2KBH o O}x) 1p-@vW bElLS) @p4O `%fX AGs:C hwpj> P:\Aal 2ggCa= ^&#~o ?W.Dgm >*p)XP [y|L. rL^tmwGV .+j-%d l1.#Db :{h$\Sh OO|L)\'? }-]w$5>* q<xI!N +<aY!V} [c]H[zL} &AJRc. `(;vAH xS;J{f )#H"Z r`oA^B Ckr?XA rSSqE| UUsno= +X'S+@^ (-f@5/Z ]<'UY8Jl J4Ku%[v [4Lxw~~= SBMO2A .)@|N{bM4 nAUeehk< 3Dx3^+ %Zxxj.8 ]6Dcy9 FplvKQ9 l{To^A .t/\d7 ksAlRu v3j=66 =9zlB_ @sHGpzw /{r&;; mt5rr0 Lq\N<(` WV1kbp: 6o<[q% YtAtsg Osi9Vy 8=6t\% p8`%g (c-J5 |Gk_1Y%Y Lr/>=r 1Yyg + IwS$Tv y1uSfcM 6+3k};i yBwwWP )Ey8/: (Lv&g` G:VO}# h#5Y0%s xS'=%_d UW"y"7 /2$s1u *XcmEy%+ xPDv\jr (D[3Vq RvwADa %`yNb( M< .p@ byU8 - E9SkA2l_j iT3^sJ&66 $]fG55 :a:0gv )#|0E Qy\m{u! ik]!()4 /4sR32 6A*AI>o +2q X?K I+/2Yh ~rN>d[ $::kcX QgtsK~ !G#B[i [}}HR( nqc_6B [/6J@sd 9)zIF) $9b!dr ~UdfLs `?MP%N d<WRk( ~(AlxS mZN78- z&~baL J6>"c& y7*jn"Y 62m}BYc E1KYnf aY8E(-o -O4~`S n:U J] yX4T$Du f*@R<Nz ~"@5}H WIC=i5 fU|10] ~SJe&Yv ~o"}di yj`x2Wo P+Xp.o 5j`A"y u-$<Vd yNnP0Q .h/0'@ kC&Bv u{|T}~ Qw>D<~ HDv!c!o {=Z`F* 1GCjLLg` -a-?6`g TbUhQ# UN>V4V CFNZ{P M-KS#xm )~p'4C #jNUrd r+~*lw B=A2%wO >\}q&_t Inem5} O]pmpD f%;v]d^ GpWC`O bi/e65) #'PaYut[c NzN2eU+ C K'q]= \ax3)v NlmL\H 1q]|;t r@DkJ= NeoW?S: ;&Dq=lI pPXVX{6 ~hWmPD[(~e A&?+a2 SX#V#d .0 Fh ){\TE## <d>w+( ?-HO2p< #/O(M" o2tNeL aSg>HDY <J$X6} P\26x+[ ;di^R"4 M{w4z#o^d6 QbRHmR ty$TY; P8m"2; 4+)W$I.D 8&5+*u 9oKk6w YY*k{x "{1JE< |I8Qq C$ "8*dj- v<LpPQ P:&90k V[/UfA us]_Ql L(D]` ;3pS7 ="R{"5;v AO8~N'( s"\Y0v gMBC?$ D#DT3/}_^ HQ^\f] L$2A!i%- *@-ukB <2@y+:63 Jh3Zsc knG[sz&B5 ]t{4^s pQ9_^I Z/b~3M }Q{+Z48 /"U&gr .Kg#P? A%2NG 0%ms.Ha h=Q<K8 ITff5D PQ<)Ob +II7uw "@w~fI YrzAp1 t:MN66 svx\Stv %D }yC 9Q\4C\ Z-aX6lqs OPE(w.h@ p[-7vz '-Q(0" J!<_j~ VD`BGf <BF}>a A61=r< X+z~A7 ?)|P(wD{ \Fwvj^z @4W$bG m_Ei&$( @OE.~+01 U\30KV A$KLT9 Ds<`-uW' V]dT%D!Z Wl>`[S ]}-}+W!b h5l+B?. G6{"p" cK1rl(up ^_=I(V 2Ov3jB9#4 ?r:?5=D ';k:Qbo '[2kXz %6_;<='s 2=ox1E .gIc2a<#.6P Ib*m1 Hx)m^$YD ~gr)v_ 2S5-}M R8Lm78 I5u;M& )w{BZy 8cE\D(F ]~!mUu ]3w S:U N<;OzE pbfD=b >[S{ST sfstb$ 6\yoj# "^83!}&n E5DrBOicU Vh(]o@ F^%q5\ !H5lme K2<HAy>n '+jYAg oTd| rU!%\@ NE2FlFl v;-10dE H2_.x< &=`~3 b+oQe<S #ys!OX <x8):@ aVFC!M ^V'$O( /v&$}] OCR=`v! pqLsu LCBk = b30M${ .@O^YWlhn R.M=4v nMb [a c- 34; CNJ:8nnj b=+jGA *C\c~EK: c}Cj)HX.9 M_6U@O @A:~"] "MrHbY {975]8 gISt3@% L<nRK [Fr5V^| e*.3Bi j)B'7YL c+5T{N_\ 'WFShf 0o-.L8 G)(2+3 Ih MJy UO$wFA r:7g[ m?T-rr(' R~)mh%w !$7Gsp +ZQl7HT n[$dodZ ~HuHt !q0<XW wO#0}0R cqDfB-l C\fd?+s0 xj|9q~ |XZj\9 9}}70f 9'}[kf tt(x%) KH'pbG }UyZBNo bu?nH\ \Z0aW> dP|i;q )W4w{W AysW9o jG>4:\j wM|K\% iNl9~MN {w s}b{0 Q6uO#x :>|p2| tSJs>} W]v2[c/ %#fx)f hJ9n{n s]~!B0 xLcvHiF lR`kK- b! cT9 k)?9!n 4-LUn4Qv 5Na%OMTG >2o<#U O~>0>1k} XIHmT| OoT/t:Pj TJC(\C }is+/B DZZr@"f HmXWY8 */T?-H "uw+eJi+ LD/.=V S!MAU9 GL-v.h R)$WIgq -#Zg"@*?mH leKU49 EG~P8C s.fo8# !+%*.14Nk `IIn0G 9<P+E7%1 p<0AEX W\d#m2 ;58O"e lINL*_ VgX@FRY R*7|[c w4CKgV Ou^i"*d / XXU# #;x@d 7KqPA)YW /%T1!U 4y E6* {^0K4_ (S3Kkn aAF7K"$ xhg~xO8 F@/.2WHTm1 fMXx3 |ckRtuJJ iH/WT& B2CL l _lY*"^ jfx>SNo !cj:h' %C|LJPb=[ #xb"}c y 2Y[g ^M'JjB Uie>-uN E5y])p _'X(BU"5 Sw*`8* "D=)i~ 7<#N<) g({a%Y >KKsw z6@ssC vwqq;8Z5 _y#e~We }dYf_n ~!pgi6 I!=f!e ;j 6~s #49qGF K6y2}fK : VM)' =sRKZ zc&S\C "8zzy<_W {}DYw6 3Gn_g {z(B:#s ?z-Lsv l$/h[q: [Dsb"d _nF84 f T[5yEX S{{fAv <=_NSi~- TM]:vY x9/y-E ^"_wLh \l:lDZl 1EsCi@ Jz1ih ELLU0XoN BB>CkLUq G'Mg9( :Du2uUhF ~rhE` %Ogso"1 8aJTw( P03}(6 S:h/Mx j_9|~Q iG] ko 2S?kv% pj.c" 5 "r?0WK nE(2Op Yb8T_8mt auzmruh #s5Un< N)?:O9jr %@N6+As .kf2j+ ry^YPf |{QF;) wQ*16Tv Bf?]j+ ~.=us/D z`_V2t btC&f) /H1abl V65n9 9o.|y[ RnT" o *#E&]` "vh@!R N:PxB[ 09gFN3 w}._9Q 8mx2)/n>yO -9At cG L5u6-9 vTM-^v .w|<== {isIu]r d]70aB IIBrp lV$_#6 Z<!)5#c ` P|1n- fV(Y%m FIKXj1] x? Kzu }rBe\s LmPJju $Ph^{iI I^&!(& wIm/+i ){<D i U{!'m- ?v#>8r TIu;&; 2f$ax[ .{==x_ 0#7feS PI=Fl? ih|YQP% /"F2b_YI <h.?2$ r]c67} 3_ob5$ iDY<6= q1/PVG vGJg[ Zb;]*9LK p_OK*{ K=oc4 m :/YGUn 5ogEF} of\:1r. S]DNTP {" Xz/`S[e% !!P&y0 KwpH;2 / ya&O&6nu Qsf4k>b )pVmur JfJ3&a 5^QSkF E3R _!Z @lf3ya !%Y mfSo \8Ye~\U IuKl24 N\i H1 Mgfv&j UIX9?$X 0+Imls\ pH!U5C ]UN1Uc Kcu72h; y$w):s 0s "o[ $bq }Z[n %WMkw? C.W$bV J.F[%+ &1s=EBf' 0lIr.0 tDV3C2P $6Rh?0 f # #]%n n0jsgA )mTEdZ B&p x% \('gN-v I!a"9&} yp%^\)[Z5[ +gy-9<y] !%$!wg3 >7e^~R abw@2b R.TB06!) +^U"Mx Uc RWf Lg^<eT CwAq: mRE}N 5#>G|* b5{@dR L7 j7cr+L. K!xyley ?{!N'6w #c h<k F(6^5y TL-qI Rv"6S@4\ld >!`>fT G{><;` iOG0?c $5b4:p} )Wm+wRi; >N2ku]N ;T_"n .s<O$b3 $]xJ`b nS(s49 8_n/|8 0&& ~@lZ r_}HZy yK3OX$ sItr~) N-D!rOMq }UgNl3 N9Kr|eVP thI?N 8q^>esY xWu(rr s8+z-O_Y pt}o}e B1~|Zv QS yW! IvK5)P "v6xVk Ox0fo" ki`X"58 &:MrK-Hq i ' H+ :2xbi+mE <u"dV7 *X-in< E;/$rh? -3q|$f UoQkFY V?i'tx Ut< [wC zU< .'m 1((>tw ]R$w|D* }tSYr1 fuhp<s K71e31 #:HJBC lJ'h8L RvC>8bm /+z}~' n#iBd4zR Q7u__|` *"0n@a uIRnG1} Yl{|4S G@\Vg5 rEgB o XtuFiy M{N$ARi *Y)*XYu2 RJ+s]P q\77F`ck uFR%Zk -j72]l ^N!hJp{qgR-+> "B|n\n &ukG7` 0rWC;t5 HS/~zU 2sQ@<c 9#X slX R$r[aDI yao2(d FEZ*kp R!*Wj" AO7sjKR ABCM~Y R23c<E -%^POf ulTL zU k6yuS W<Tz\`S GP4*! iVNY8e ZyF16p (_lABf *R+8P7' &:1mS~Gd QV~h9W &2e)CRn @R#G[| mLTd?:ZKH e?W_ye {h$2yN m(X\vVHD -LK=y% :a\p:h eBelay 9:'aPrp~ C!zbu/ h*b!%c YFfN'@ 9H!ua1 VF%)LTA2 {efAN Pwnef$C c{w]iJ $t8 nqjw o)h_XI WGwaN CNa(PBdc "&@Dnl9 6B$TCSr C>o8p* n|0Z.XY `A\)*p ^h2-u^ rBv^Sn .xU2r(C y1}%1e2 >1%[wU }L7Kn1 4:?] > '}fS\ DP]Qr( NK7(w) DlE " Fd:0~PX dYu)Bq CZn@fI CO"?b7 Z<29$k <}y~#[ ^Nr]iA LA31iM/ %F>hQK HxV]4) L An|(p n9nNXv qp`J"J _QkCPd U4T?'J%)N B`8m.= P:7J6Qt+ 9K^r* 3D& h- j0X@7@ pA)[al `WhW07 Na!]t: ^@RBoN R#u7R| Tw".7\ s@D|J<o +"?4XK0 _ uU? v]x*(h ZHvda5 .;6L*A E52^h- SuK[oV BrPh<SFBJ iBq~5(+ IsjD4 Q6@>Im) *Ez-g i4[PEL &t"Qzl _o+[c; #Fe@j+Pe: D\7FXf g.W-nE7 ]4|2$r # #Nu!-Yo C /vsq )REApc 5[%P; G(lQZ{J 3:J|2[% S0+AW '6.'#@ \2T;_8|k [z_H|' JgWqPO Q4MX~U? /aO2^{ ^#UIw5VX [j{:zw HLph! d b*k o <JATd1- Ij.Pq` $+-4P +v~z.! &H!X5F 7WWb:M p)"hh! 6ckp]D -i{09^ QH]jbi $K_y^ 4WFVA't zKduVY V^+]uBN Sl&H` 0 :}<d|d Y23zsr 0%l =V a;=4UE .]sPS$ ch9j=d 8`u6m 'dUgY/q% Sj0S | yC$%b? VA.".n }M-9") <A%+'W Mr+IPX %&-6M0 2/1r H oAZ+Ix mM3+B6 Fh;_L. <\tIJ5 ~;2R~5 2uz6~Ob L?m)+"K Sgm2Na aW)SBV@rkI)[ ]##b+e' jhJ@:A| +f[h+` _\O>D)' )NKIbg \PN?fR rPlt/WbfA (4 {@}\ }zFej2 Vi#}!c G>w.B C.iV$ #G4nl7 HptUr"\ DY{L&-? jx"yd vB d2_L]\ .So6PP &z("k;u8. M!HIMw Ii7`WJ _%45XCp_ 7A4VJ`o< %;cy6\ gI~@DC o) Sy4) '28=Z* yabV5 3jJsI( <<[v4A9 _Y*V^SJ -LMTZ4Tw 4Qdc%': |(:4l{ K5RX"* wC>FH0 8/Q1xE& =O-!dFG8 h\YEJG F$X?]@ :yYlIvqt 3[Z0 @ \LVGQ\q}X \I g{B bmufp` U$K]Kn0 +]j`]4k5} ~K|3Q: =z@93k aF9Wv^ ybm.df :"?^kq1G |5cOhO 2cYn5$ C*PFG- _:xduc o'&a> !ansxB l2xYC< j8>/|X Q~/Y6& <$z5;0WJ wA:@ ) Cr-S9P Lf6T+* "V|@W^ eg"#7: ozUr 2\tw9C ~:&S4K lc!!!k 7OYM/!s A>VTB? q0c.}f 5`{h4hZ >-FCj\ m5{rP= lxO8J| T-^M(( /?`$~ $DKJm8 wj{6JV *d)kV. #/:^Xf oA4Sk //wVA= ?4@YB# vIO`u =h4'?" **!4`? JV.y5G]6 7A&vC% C<N8f[ ^O.&/[ g[1u`jP 9}`nwx: tJ /0U =+_4v.." 0tPVA3 ejJJ;f ?[Pvf? kwZ 78 j$c3DR >w:}5IK6 W]4Zpz -[#0sV :hSqm< b)6jZW<Y* T6J&}V $w5+`S ^HmD }0S hcFNq- g28ak \}W*E$l C@dA6i -tpfT$ BTJ /zavtX I~3ugG Wzn'X%v #!mS$'+ {sJ=JkD 0HnAnI B[_5vb 2N$GT- @feVA i}N;h{s 9- )ws^W& ?v{1] t3UG7$ rK%x= Yq'KmY YY?c2eS g9H/Rt k%b3mn 6nVDwR}% {*K @aV< 2f&;Z_ A=)=6+ sfDJ?u H*GoKz b`an`# deYC~A /%xvBP* 117b306b65da5f061cf92f5ec4091267db1d282bf31bb9af3cc1e7cdb4c7830f

2402 rows × 4 columns

Created by: Avinash
Downloaded 1 times
Comments: 0

Description: Using Registry information to detect ransomware

Dataset SHA256: d84c7f802e81c0cfa32569444019c6d2fd6e9d82b435477b190fbbfa5c07f335

Features (sample):



category label Persistant Backup PercentageKeyOpen PercentageKeyClosed PercentageCreated PercentageKeyUnique SHA256
0 Ransomware M 0 0 0 0 0 0 bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
1 Ransomware M 8 0 22 0 0 24 3ae96f73d805e1d3995253db4d910300d8442ea603737a1428b613061e7f61e7
... ... ... ... ... ... ... ... ... ...
2938 Ransomware M 29 0 33 0 0 0 7757c11c449860e2dd54ae97e05835fb39f89a9c93f32dfc23b258ad49c3622e
2939 Ransomware M 89 0 32 0 2 1 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

2940 rows × 9 columns

Created by: Avinash
Downloaded 2 times
Comments: 0

Description: This dataset explores using various file operations as features.

Dataset SHA256: 6c1b2b7904f20d2691141fcd487763a38fadf273d1f9ff4ba3b4a28e877b1f75

Features (sample):



sha256 label PercentageOfFileAPICalls PercentageOfUniqueFiles PercentageOfUniqueFileLocations PercentageOfUniqueFileExtensions PercentageOfPotentialCustomExtensions PercentageOfRansomwareExtensions PercentageOfFileExtensionsDocuments PercentageOfFileExtensionsImages PercentageOfFileExtensionsVideos PercentageOfFileExtensionsAudio PercentageOfFileExtensionsDatabase PercentageOfFileExtensionsArchives PercentageOfFileExtensionsExecutables PercentageOfFileExtensionsSystem PercentageOfFileExtensionsBackup PercentageOfFileExtensionsEmail PercentageOfFileExtensionsVMImages PercentageOfFileExtensionsGames PercentageOfFileExtensionsDevelopment APICallsPerSecond SHA256
0 3b4497c7f8c89bf22c984854ac7603573a53b95ed147e80c0f19e549e2b65693 M 60 4 4 1 2 14 2 0 0 0 0 0 96 0 0 0 0 0 0 72 3b4497c7f8c89bf22c984854ac7603573a53b95ed147e80c0f19e549e2b65693
1 8fec485e47fd1231aeb1a4107a4918f92c2b15fa66e9171be39a765d26a12acb M 12 25 25 25 0 0 0 0 0 0 0 0 100 0 0 0 0 0 0 75 8fec485e47fd1231aeb1a4107a4918f92c2b15fa66e9171be39a765d26a12acb
... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ...
2650 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51 M 8 14 14 14 100 0 0 0 0 0 0 0 0 0 0 0 0 0 0 16 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51
2651 7d6d38f2cbe320aff29eb02998476e731d02ca27ca0e2f79063b207fc10229e8 M 97 0 0 0 0 1 0 0 0 0 0 91 0 0 0 0 0 0 9 6892 7d6d38f2cbe320aff29eb02998476e731d02ca27ca0e2f79063b207fc10229e8

2652 rows × 23 columns

Created by: Avinash
Downloaded 1 times
Comments: 0

Description: Gets running total of the time interval for each API call types for each sample

Dataset SHA256: b992f317ac8315c02511c4e00f5f85a3c857a8d0d2001c1cf756433eaac06969

Features (sample):

Ransomware(2512), Development(20), Education(9), Games(52), Graphics(55), Internet(83), Music / Video(47), Office(54), Security(30), Utilities(222)

Sample Name category label SetErrorModeTemporalInterval OleInitializeTemporalInterval LdrGetDllHandleTemporalInterval LdrLoadDllTemporalInterval LdrGetProcedureAddressTemporalInterval NtOpenSectionTemporalInterval NtMapViewOfSectionTemporalInterval RegOpenKeyExWTemporalInterval RegQueryValueExWTemporalInterval RegCloseKeyTemporalInterval NtCloseTemporalInterval NtOpenKeyTemporalInterval NtQueryValueKeyTemporalInterval GetSystemWindowsDirectoryWTemporalInterval NtCreateFileTemporalInterval NtCreateSectionTemporalInterval RegOpenKeyExATemporalInterval CreateActCtxWTemporalInterval GetSystemDirectoryWTemporalInterval GetVolumeNameForVolumeMountPointWTemporalInterval NtDuplicateObjectTemporalInterval LoadStringWTemporalInterval NtCreateMutantTemporalInterval GetNativeSystemInfoTemporalInterval RegEnumKeyWTemporalInterval NtQuerySystemInformationTemporalInterval RegQueryValueExATemporalInterval NtQueryDirectoryFileTemporalInterval GlobalMemoryStatusExTemporalInterval CoCreateInstanceTemporalInterval NtAllocateVirtualMemoryTemporalInterval CreateDirectoryWTemporalInterval DeleteFileWTemporalInterval GetFileSizeExTemporalInterval NtReadFileTemporalInterval GetFileInformationByHandleExTemporalInterval GetSystemTimeAsFileTimeTemporalInterval GetVolumePathNamesForVolumeNameWTemporalInterval LdrUnloadDllTemporalInterval CoInitializeExTemporalInterval NtOpenProcessTemporalInterval CoUninitializeTemporalInterval NtFreeVirtualMemoryTemporalInterval NtOpenFileTemporalInterval NtQueryInformationFileTemporalInterval GetFileAttributesWTemporalInterval FindFirstFileExWTemporalInterval NtQueryAttributesFileTemporalInterval NtUnmapViewOfSectionTemporalInterval SetFilePointerExTemporalInterval SetFilePointerTemporalInterval GetTempPathWTemporalInterval GetFileSizeTemporalInterval NtWriteFileTemporalInterval FindResourceExWTemporalInterval LoadResourceTemporalInterval SHGetFolderPathWTemporalInterval NtProtectVirtualMemoryTemporalInterval GetFileTypeTemporalInterval ReadProcessMemoryTemporalInterval GetForegroundWindowTemporalInterval GetSystemMetricsTemporalInterval SetFileTimeTemporalInterval NtSetInformationFileTemporalInterval SearchPathWTemporalInterval NtOpenMutantTemporalInterval RegEnumKeyExWTemporalInterval DrawTextExWTemporalInterval GetAsyncKeyStateTemporalInterval GetDiskFreeSpaceExWTemporalInterval GetKeyStateTemporalInterval FindWindowWTemporalInterval FindWindowExATemporalInterval CreateThreadTemporalInterval MoveFileWithProgressWTemporalInterval SetFileAttributesWTemporalInterval RemoveDirectoryWTemporalInterval NtTerminateProcessTemporalInterval CreateToolhelp32SnapshotTemporalInterval Process32FirstWTemporalInterval Process32NextWTemporalInterval FindWindowExWTemporalInterval SetEndOfFileTemporalInterval GetCursorPosTemporalInterval SetUnhandledExceptionFilterTemporalInterval OutputDebugStringATemporalInterval GetSystemInfoTemporalInterval FindResourceWTemporalInterval SizeofResourceTemporalInterval NtDelayExecutionTemporalInterval GetKeyboardStateTemporalInterval WSAStartupTemporalInterval socketTemporalInterval setsockoptTemporalInterval NtDeviceIoControlFileTemporalInterval closesocketTemporalInterval GetBestInterfaceExTemporalInterval GetAdaptersAddressesTemporalInterval NtQueryKeyTemporalInterval RegCreateKeyExWTemporalInterval GetAddrInfoWTemporalInterval GetUserNameExWTemporalInterval RegSetValueExWTemporalInterval RegDeleteValueWTemporalInterval InternetQueryOptionATemporalInterval URLDownloadToFileWTemporalInterval IsDebuggerPresentTemporalInterval CreateProcessInternalWTemporalInterval GetTimeZoneInformationTemporalInterval LookupAccountSidWTemporalInterval SendNotifyMessageWTemporalInterval UuidCreateTemporalInterval GetFileVersionInfoSizeWTemporalInterval GetFileVersionInfoWTemporalInterval NtEnumerateValueKeyTemporalInterval EnumWindowsTemporalInterval OpenSCManagerWTemporalInterval GetComputerNameWTemporalInterval GetUserNameWTemporalInterval NetShareEnumTemporalInterval GetFileInformationByHandleTemporalInterval DeviceIoControlTemporalInterval ShellExecuteExWTemporalInterval RegQueryInfoKeyWTemporalInterval RegEnumValueWTemporalInterval RegDeleteKeyWTemporalInterval NtReadVirtualMemoryTemporalInterval NtOpenKeyExTemporalInterval NtSetValueKeyTemporalInterval NtCreateKeyTemporalInterval GetVolumePathNameWTemporalInterval GetFileAttributesExWTemporalInterval GetUserNameExATemporalInterval RegCreateKeyExATemporalInterval CryptAcquireContextWTemporalInterval NtEnumerateKeyTemporalInterval NtDeleteKeyTemporalInterval OpenServiceWTemporalInterval NtOpenDirectoryObjectTemporalInterval CreateJobObjectWTemporalInterval SetInformationJobObjectTemporalInterval RegEnumKeyExATemporalInterval __exception__TemporalInterval GetShortPathNameWTemporalInterval LoadStringATemporalInterval FindResourceATemporalInterval DrawTextExATemporalInterval RegQueryInfoKeyATemporalInterval RegSetValueExATemporalInterval SHGetSpecialFolderLocationTemporalInterval NtCreateThreadExTemporalInterval NtResumeThreadTemporalInterval gethostbynameTemporalInterval GetSystemDirectoryATemporalInterval FindResourceExATemporalInterval GetDiskFreeSpaceWTemporalInterval CertOpenStoreTemporalInterval CryptDecodeObjectExTemporalInterval CertControlStoreTemporalInterval CryptHashDataTemporalInterval NtOpenThreadTemporalInterval MessageBoxTimeoutWTemporalInterval LookupPrivilegeValueWTemporalInterval CryptAcquireContextATemporalInterval SetFileInformationByHandleTemporalInterval RemoveDirectoryATemporalInterval SetWindowsHookExWTemporalInterval CopyFileWTemporalInterval GetFileVersionInfoSizeExWTemporalInterval GetFileVersionInfoExWTemporalInterval CoInitializeSecurityTemporalInterval WSASocketWTemporalInterval WSAConnectTemporalInterval UnhookWindowsHookExTemporalInterval CertOpenSystemStoreWTemporalInterval getaddrinfoTemporalInterval InternetCrackUrlWTemporalInterval CoCreateInstanceExTemporalInterval CoGetClassObjectTemporalInterval IWbemServices_ExecQueryTemporalInterval SetStdHandleTemporalInterval GlobalMemoryStatusTemporalInterval NetGetJoinInformationTemporalInterval CryptCreateHashTemporalInterval GetComputerNameATemporalInterval InternetOpenATemporalInterval InternetOpenUrlATemporalInterval InternetCloseHandleTemporalInterval ReadCabinetStateTemporalInterval InternetOpenWTemporalInterval InternetConnectWTemporalInterval HttpOpenRequestWTemporalInterval HttpSendRequestWTemporalInterval NtDeleteValueKeyTemporalInterval HttpQueryInfoATemporalInterval RegEnumValueATemporalInterval CryptProtectMemoryTemporalInterval CreateServiceWTemporalInterval WriteConsoleATemporalInterval CopyFileATemporalInterval WriteProcessMemoryTemporalInterval SendNotifyMessageATemporalInterval RegDeleteKeyATemporalInterval WriteConsoleWTemporalInterval JsGlobalObjectDefaultEvalHelperTemporalInterval ObtainUserAgentStringTemporalInterval StartServiceWTemporalInterval NtQueueApcThreadTemporalInterval RtlAddVectoredContinueHandlerTemporalInterval CryptExportKeyTemporalInterval CryptGenKeyTemporalInterval CryptEncryptTemporalInterval NetUserGetInfoTemporalInterval GetUserNameATemporalInterval InternetOpenUrlWTemporalInterval systemTemporalInterval GetAdaptersInfoTemporalInterval Module32FirstWTemporalInterval NtGetContextThreadTemporalInterval Module32NextWTemporalInterval RtlAddVectoredExceptionHandlerTemporalInterval NtSuspendThreadTemporalInterval OpenSCManagerATemporalInterval OpenServiceATemporalInterval NtQueryMultipleValueKeyTemporalInterval MessageBoxTimeoutATemporalInterval ControlServiceTemporalInterval NtTerminateThreadTemporalInterval EncryptMessageTemporalInterval DecryptMessageTemporalInterval DeleteServiceTemporalInterval FindWindowATemporalInterval RtlRemoveVectoredExceptionHandlerTemporalInterval ioctlsocketTemporalInterval connectTemporalInterval selectTemporalInterval SetWindowsHookExATemporalInterval CreateServiceATemporalInterval bindTemporalInterval listenTemporalInterval getsocknameTemporalInterval acceptTemporalInterval InternetCrackUrlATemporalInterval InternetConnectATemporalInterval HttpOpenRequestATemporalInterval HttpSendRequestATemporalInterval sendtoTemporalInterval shutdownTemporalInterval RtlDecompressBufferTemporalInterval NtSetContextThreadTemporalInterval Thread32FirstTemporalInterval Thread32NextTemporalInterval CreateRemoteThreadTemporalInterval InternetReadFileTemporalInterval CreateRemoteThreadExTemporalInterval timeGetTimeTemporalInterval DnsQuery_ATemporalInterval InternetGetConnectedStateTemporalInterval RegisterHotKeyTemporalInterval CryptDecryptTemporalInterval CopyFileExWTemporalInterval NtDeleteFileTemporalInterval sendTemporalInterval DeleteUrlCacheEntryATemporalInterval EnumServicesStatusWTemporalInterval recvTemporalInterval NtWriteVirtualMemoryTemporalInterval InternetSetOptionATemporalInterval NtLoadDriverTemporalInterval __anomaly__TemporalInterval EnumServicesStatusATemporalInterval RegDeleteValueATemporalInterval CertCreateCertificateContextTemporalInterval InternetSetStatusCallbackTemporalInterval IWbemServices_ExecMethodTemporalInterval AssignProcessToJobObjectTemporalInterval StartServiceATemporalInterval CryptProtectDataTemporalInterval CryptUnprotectDataTemporalInterval CryptUnprotectMemoryTemporalInterval SHA256
0 EternalRocks Ransomware 1 64.07900 0.000000 91.125000 64.328000 91.281000 51.469000 62.34400 64.390000 64.406000 64.406000 91.281000 61.093000 61.093000 0.203000 62.328000 62.3280 0.078000 7.656000 1.610000 0.00000 90.625000 0.016000 61.42200 0.000000 0.000000 61.079 0.000000 60.328000 60.281 0.000000 64.172000 51.094000 0.000000 0.000000 60.203000 0.000000 61.453000 0.00000 6.297000 4.594000 60.859000 0.000000 63.265000 60.297000 0.00000 61.125000 0.000000 0.063000 1.610000 0.0 51.329000 0.0 60.407000 51.671000 0.000 0.00 0.797000 63.110000 52.53200 0.0 0.000000 0.000000 0.000000 0.00 0.0 59.844 60.062000 0.000 0.0 0.0 0.0 0.0 0.0 5.579000 0.00000 0.0000 0.0 0.000000 0.0 0.0 0.0 0.000000 0.0000 0.0 0.000000 0.0 60.625000 0.0 0.0 118.000000 0.0 0.000000 0.000000 0.063000 0.000000 0.063000 0.000000 0.000000 61.265000 0.000000 0.000000 0.000000 0.000000 0.000000 0.0 0.0 0.000000 0.00000 2.141 0.00000 0.0 0.000000 0.000000 0.000000 0.0 0.000 0.00 0.000000 0.0 0.0 0.0 0.0 0.00000 0.687000 0.375000 0.0 0.0 61.265 0.0 0.0 0.00000 58.985000 0.0 0.000000 0.0 0.0 0.0 0.00 0.000000 0 0 0.000000 0.0 0.0 0.000000 0.0 0.0 0.0 0.000000 0.000000 0.0 60.641000 0.0 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.0 0.000000 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.406 0.0 0.0 0 0.0 0.000000 0.00000 0.000000 0.00000 0.0 0.000000 0.0 0.0 0.00000 0.000000 0.000000 0.000000 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.000 0.0 0.000000 0.0 0.000000 0.0 0.0 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.000000 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.000 3b4497c7f8c89bf22c984854ac7603573a53b95ed147e80c0f19e549e2b65693
1 GandCrab.exe Ransomware 1 0.00000 0.000000 0.000000 13.172000 13.172000 0.000000 0.00000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.0000 0.000000 0.000000 0.000000 0.00000 0.000000 0.000000 0.00000 0.000000 0.000000 0.000 0.000000 0.000000 0.000 0.000000 6.141000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.00000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.00000 0.000000 0.000000 0.000000 0.000000 0.0 0.000000 0.0 0.000000 0.000000 0.000 0.00 0.000000 0.000000 0.00000 0.0 0.000000 0.000000 0.000000 0.00 0.0 0.000 0.000000 0.000 0.0 0.0 0.0 0.0 0.0 0.000000 0.00000 0.0000 0.0 0.641000 0.0 0.0 0.0 0.000000 0.0000 0.0 0.000000 0.0 0.000000 0.0 0.0 0.000000 0.0 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.000000 0.0 0.0 0.000000 0.00000 0.000 0.00000 0.0 0.000000 0.000000 0.000000 0.0 0.000 0.00 0.000000 0.0 0.0 0.0 0.0 0.00000 0.000000 0.000000 0.0 0.0 0.000 0.0 0.0 0.00000 7.016000 0.0 0.000000 0.0 0.0 0.0 0.00 0.000000 0 0 0.000000 0.0 0.0 0.000000 0.0 0.0 0.0 0.000000 0.000000 0.0 0.000000 0.0 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.0 0.000000 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.000 0.0 0.0 0 0.0 0.000000 0.00000 0.000000 0.00000 0.0 0.000000 0.0 0.0 0.00000 0.000000 0.000000 0.000000 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.000 0.0 0.000000 0.0 0.000000 0.0 0.0 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.000000 0.000000 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.000 bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ...
3081 Zeppelin_4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a.exe Ransomware 1 87.67075 8.968875 379.464750 150.029499 461.498000 8.717875 77.95225 149.092375 149.092375 459.998875 535.024749 534.868749 534.868749 78.607125 517.481499 76.1410 229.779875 8.952875 78.513625 41.01575 80.077250 143.748874 41.01375 78.700625 7.124875 0.047 211.952625 287.313625 0.000 68.892499 514.122249 8.859875 66.012875 7.077875 237.921624 6.702875 306.502500 40.98375 518.730249 297.361750 213.405375 301.112750 293.060375 66.281250 73.64125 286.233875 510.715625 63.968500 310.688751 0.0 237.921624 0.0 6.859875 289.406375 0.312 0.25 7.140875 54.937875 151.33975 0.0 7.124875 70.436125 138.891125 2.25 0.0 0.000 31.937375 3.875 0.0 0.0 0.0 0.0 0.0 42.437375 137.75025 137.4215 0.0 523.235250 0.0 0.0 0.0 0.905875 137.3905 0.0 65.672875 0.0 20.716375 0.0 0.0 255.750376 0.0 20.406125 20.375125 20.375125 54.297125 20.375125 17.813125 17.766125 29.969375 138.188125 17.765125 65.000125 138.391125 30.328375 0.0 0.0 0.124375 221.87450 0.000 68.26675 0.0 0.936875 33.422375 33.422375 0.0 32.203 2.25 69.203125 0.0 0.0 0.0 0.0 27.50025 65.579375 6.781875 0.0 0.0 0.000 0.0 0.0 64.37525 7.139875 0.0 34.469125 0.0 0.0 0.0 2.25 76.794625 0 0 138.141375 0.0 0.0 54.953875 0.0 0.0 0.0 34.469125 140.297375 0.0 35.922500 0.0 6.765875 0.0 0.0 0.0 0.0 0.0 0.0 64.000375 0.0 256.297000 6.764875 0.0 0.0 0.0 0.0 0.0 0.0 66.094750 0.000 0.0 0.0 0 0.0 0.124375 35.35900 64.688125 35.59425 0.0 6.749875 0.0 0.0 1.26650 37.813125 15.187125 35.141125 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.141 0.0 0.015375 0.0 110.813125 0.0 0.0 133.918375 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 110.813125 15.187125 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.156 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
3082 Zeppelin_eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5.exe Ransomware 1 2.89075 0.000000 214.782875 67.938625 339.157374 0.000000 4.40750 66.080000 66.080000 337.016749 352.314874 352.000874 352.000874 46.795500 324.392375 4.4075 202.232999 0.000000 47.187250 0.01500 66.905875 47.250250 0.00000 47.187250 0.000000 0.000 180.549250 133.314499 0.000 67.657625 341.406625 0.000000 15.172125 0.000000 149.858625 0.000000 199.314625 0.00000 325.171375 200.314125 180.374500 199.375875 196.764750 10.452375 0.01500 181.331750 322.078249 64.202625 182.842875 0.0 139.389750 0.0 0.000000 247.188625 0.000 0.00 0.000000 0.000000 9.68600 0.0 0.000000 64.878000 66.593000 0.00 0.0 0.000 0.000000 0.000 0.0 0.0 0.0 0.0 0.0 15.172125 66.59300 66.6250 0.0 336.795125 0.0 0.0 0.0 0.000000 66.5470 0.0 3.094125 0.0 0.000000 0.0 0.0 131.859125 0.0 20.390125 20.390125 20.390125 63.609125 20.390125 17.813125 17.766125 20.344125 130.749625 17.765125 0.594250 128.202625 17.797125 0.0 0.0 0.578250 183.03125 0.000 13.07775 0.0 0.000000 0.000000 0.000000 0.0 0.000 0.00 13.062750 0.0 0.0 0.0 0.0 0.00000 0.172250 0.000000 0.0 0.0 0.000 0.0 0.0 0.00000 0.000000 0.0 36.266125 0.0 0.0 0.0 0.00 0.593250 0 0 0.000000 0.0 0.0 64.202625 0.0 0.0 0.0 36.266125 0.016000 0.0 15.172125 0.0 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 0.484750 0.0 182.327875 0.000000 0.0 0.0 0.0 0.0 0.0 0.0 2.780875 0.000 0.0 0.0 0 0.0 0.594250 0.46925 0.438250 0.10925 0.0 0.000000 0.0 0.0 2.37475 39.594125 15.172125 36.938125 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.000 0.0 0.110250 0.0 113.172125 0.0 0.0 7.828000 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 0.0 113.172125 15.172125 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0 0.0 0.0 0.0 0.0 0.0 0.000 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

3083 rows × 284 columns

Created by: VHUHWAVHO
Downloaded 3 times
Comments: 0

Description: Frequency of API call types in samples

Dataset SHA256: 257fc6dbd5b73a55e29041724b767242353e6fcf51fd5bf0eb9c869c793c605c

Features (sample):

Ransomware(2512), Development(20), Education(9), Games(52), Graphics(55), Internet(83), Music / Video(47), Office(54), Security(30), Utilities(222)

Sample Name category label SetErrorMode OleInitialize LdrGetDllHandle LdrLoadDll LdrGetProcedureAddress NtOpenSection NtMapViewOfSection RegOpenKeyExW RegQueryValueExW RegCloseKey NtClose NtOpenKey NtQueryValueKey GetSystemWindowsDirectoryW NtCreateFile NtCreateSection RegOpenKeyExA CreateActCtxW GetSystemDirectoryW GetVolumeNameForVolumeMountPointW NtDuplicateObject LoadStringW NtCreateMutant GetNativeSystemInfo RegEnumKeyW NtQuerySystemInformation RegQueryValueExA NtQueryDirectoryFile GlobalMemoryStatusEx CoCreateInstance NtAllocateVirtualMemory CreateDirectoryW DeleteFileW GetFileSizeEx NtReadFile GetFileInformationByHandleEx GetSystemTimeAsFileTime GetVolumePathNamesForVolumeNameW LdrUnloadDll CoInitializeEx NtOpenProcess CoUninitialize NtFreeVirtualMemory NtOpenFile NtQueryInformationFile GetFileAttributesW FindFirstFileExW NtQueryAttributesFile NtUnmapViewOfSection SetFilePointerEx SetFilePointer GetTempPathW GetFileSize NtWriteFile FindResourceExW LoadResource SHGetFolderPathW NtProtectVirtualMemory GetFileType ReadProcessMemory GetForegroundWindow GetSystemMetrics SetFileTime NtSetInformationFile SearchPathW NtOpenMutant RegEnumKeyExW DrawTextExW GetAsyncKeyState GetDiskFreeSpaceExW GetKeyState FindWindowW FindWindowExA CreateThread MoveFileWithProgressW SetFileAttributesW RemoveDirectoryW NtTerminateProcess CreateToolhelp32Snapshot Process32FirstW Process32NextW FindWindowExW SetEndOfFile GetCursorPos SetUnhandledExceptionFilter OutputDebugStringA GetSystemInfo FindResourceW SizeofResource NtDelayExecution GetKeyboardState WSAStartup socket setsockopt NtDeviceIoControlFile closesocket GetBestInterfaceEx GetAdaptersAddresses NtQueryKey RegCreateKeyExW GetAddrInfoW GetUserNameExW RegSetValueExW RegDeleteValueW InternetQueryOptionA URLDownloadToFileW IsDebuggerPresent CreateProcessInternalW GetTimeZoneInformation LookupAccountSidW SendNotifyMessageW UuidCreate GetFileVersionInfoSizeW GetFileVersionInfoW NtEnumerateValueKey EnumWindows OpenSCManagerW GetComputerNameW GetUserNameW NetShareEnum GetFileInformationByHandle DeviceIoControl ShellExecuteExW RegQueryInfoKeyW RegEnumValueW RegDeleteKeyW NtReadVirtualMemory NtOpenKeyEx NtSetValueKey NtCreateKey GetVolumePathNameW GetFileAttributesExW GetUserNameExA RegCreateKeyExA CryptAcquireContextW NtEnumerateKey NtDeleteKey OpenServiceW NtOpenDirectoryObject CreateJobObjectW SetInformationJobObject RegEnumKeyExA __exception__ GetShortPathNameW LoadStringA FindResourceA DrawTextExA RegQueryInfoKeyA RegSetValueExA SHGetSpecialFolderLocation NtCreateThreadEx NtResumeThread gethostbyname GetSystemDirectoryA FindResourceExA GetDiskFreeSpaceW CertOpenStore CryptDecodeObjectEx CertControlStore CryptHashData NtOpenThread MessageBoxTimeoutW LookupPrivilegeValueW CryptAcquireContextA SetFileInformationByHandle RemoveDirectoryA SetWindowsHookExW CopyFileW GetFileVersionInfoSizeExW GetFileVersionInfoExW CoInitializeSecurity WSASocketW WSAConnect UnhookWindowsHookEx CertOpenSystemStoreW getaddrinfo InternetCrackUrlW CoCreateInstanceEx CoGetClassObject IWbemServices_ExecQuery SetStdHandle GlobalMemoryStatus NetGetJoinInformation CryptCreateHash GetComputerNameA InternetOpenA InternetOpenUrlA InternetCloseHandle ReadCabinetState InternetOpenW InternetConnectW HttpOpenRequestW HttpSendRequestW NtDeleteValueKey HttpQueryInfoA RegEnumValueA CryptProtectMemory CreateServiceW WriteConsoleA CopyFileA WriteProcessMemory SendNotifyMessageA RegDeleteKeyA WriteConsoleW JsGlobalObjectDefaultEvalHelper ObtainUserAgentString StartServiceW NtQueueApcThread RtlAddVectoredContinueHandler CryptExportKey CryptGenKey CryptEncrypt NetUserGetInfo GetUserNameA InternetOpenUrlW system GetAdaptersInfo Module32FirstW NtGetContextThread Module32NextW RtlAddVectoredExceptionHandler NtSuspendThread OpenSCManagerA OpenServiceA NtQueryMultipleValueKey MessageBoxTimeoutA ControlService NtTerminateThread EncryptMessage DecryptMessage DeleteService FindWindowA RtlRemoveVectoredExceptionHandler ioctlsocket connect select SetWindowsHookExA CreateServiceA bind listen getsockname accept InternetCrackUrlA InternetConnectA HttpOpenRequestA HttpSendRequestA sendto shutdown RtlDecompressBuffer NtSetContextThread Thread32First Thread32Next CreateRemoteThread InternetReadFile CreateRemoteThreadEx timeGetTime DnsQuery_A InternetGetConnectedState RegisterHotKey CryptDecrypt CopyFileExW NtDeleteFile send DeleteUrlCacheEntryA EnumServicesStatusW recv NtWriteVirtualMemory InternetSetOptionA NtLoadDriver __anomaly__ EnumServicesStatusA RegDeleteValueA CertCreateCertificateContext InternetSetStatusCallback IWbemServices_ExecMethod AssignProcessToJobObject StartServiceA CryptProtectData CryptUnprotectData CryptUnprotectMemory SHA256
0 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a.exe Ransomware 1 245 6 141 253 1426 49 64 1547 1308 7834 18734 413 172 58 7398 41 6553 6 25 21 46 243 24 9 8 7 6417 920 1 53 3346 9 12 6 11208 3 192 48 74 34 15 40 3771 65 15 149 17478 14 50 0 51483 1 14 40704 32 31 8 6 406 0 4 670 3317 6 0 1 128 86 0 0 0 0 0 6 3507 7016 0 75 0 0 0 134 3314 0 21 0 10 2 1 6552 0 8 6 6 48 6 4 2 12 235 2 8 271 69 0 0 2 28 1 6 0 2 9 9 0 6 2 15 0 1 0 0 5 72 128 0 0 0 0 0 5 16 0 4 1 0 0 2 7 0 0 90 1 0 93 0 0 0 4 6 1 4 0 4 0 0 0 0 0 0 8 0 6 2 0 0 0 1 0 0 8 0 0 0 0 0 4 8 10 4 0 2 0 0 2 3 2 7 0 0 0 0 0 0 0 0 4 0 2 0 3 0 0 108 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 36 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 GandCrab.exe Ransomware 1 2 0 11 2 24 0 0 0 0 0 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 6 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 3 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 22299 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ...
3081 Zeppelin_7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51.exe Ransomware 1 0 0 14 20 252 0 0 33 17 28 44 8 2 0 1 0 25 0 1 0 3 0 0 1 0 0 0 0 0 5 21 0 1 0 0 0 3 0 0 3 0 3 2 0 0 0 22 4 0 0 0 0 0 1 0 0 0 12 0 0 0 5 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 23 0 4 3 3 22 3 2 1 4 4 1 0 7 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 31 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51
3082 Zeppelin_eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5.exe Ransomware 1 71 0 68 60 324 0 13 155 230 6836 20656 143 79 10 8282 11 6413 0 5 3 16 6 2 3 0 0 6325 1209 0 30 7682 0 3 0 12412 0 32 8 27 12 6 12 10603 52 2 20 19088 12 12 0 58288 0 0 47094 0 0 0 0 82 0 0 9 3836 3 0 0 2 0 0 0 0 0 0 2 3836 8070 0 39 0 0 0 0 3836 0 10 0 0 0 0 6407 0 14 12 12 67 12 4 2 8 337 2 4 347 5 0 0 2 14 0 4 0 0 0 0 0 0 1 13 0 0 0 0 1 2 0 0 0 0 0 0 1 0 0 4 0 0 0 1 2 0 0 7 1 0 93 0 0 0 4 2 0 2 0 0 0 0 0 0 0 0 6 0 6 0 0 0 0 1 0 0 4 0 0 0 0 0 4 6 6 2 0 0 0 0 2 3 2 7 0 0 0 0 0 0 0 0 0 0 2 0 6 0 4 53 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

3083 rows × 284 columns

Created by: VHUHWAVHO
Downloaded 4 times
Comments: 0

Description: A dataset of Portable Executable files and the features extracted from their imports (PE Imports). The following are the features extracted: 1. The number of functions utilized per DLL imported as a ratio, 2. The number of 'bogus' functions, that is functions that are made-up and typically have additional (non-alphabetic) characters in the name, 3. The number of functions utilized by that PE file that are blacklisted as functions typically imported by ransomware files, 4. The number of functions utilized by that PE file that are typically imported and used exclusively by good-ware files 'whitelisted' functions, 5. The difference of the number of register keys opened/ created and those deleted by the end of the application, and 6. The number of native functions utilized by the PE file.

Dataset SHA256: 76085f3bf41a81a90012299623d7cf6fcc0dac059e3dab271e0346b94e436316

Features (sample):



label ave_functions_utilised_from_dlls_imported bogus_functions num_blacklisted_functions num_whitelisted_functions persistent_reg_key num_native_functions SHA256
0 M 1.115312 37 2 1 -1 0 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 M 24.500000 0 1 0 0 0 bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ... ... ... ... ...
1829 M 2.950617 2 3 0 0 0 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51
1830 M 0.813333 0 0 1 0 0 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

1831 rows × 8 columns

Created by: Tanatswa Dendere
Downloaded 4 times
Comments: 0
Related Dataset: Ransomware_Detection_Using_PE_Imports

Description: A dataset of features of the imports of portable executables (PE Imports). The features extracted are: a ratio of the number of functions utilized per DLL imported, the number of functions that have additional (non-alphabetic) characters, the number of 'blacklisted functions' utilized by that PE file, the number of 'whitelisted' functions, whether all Register keys opened/ created are deleted at the end of the application, the number of native functions utilized, and how many times a function is accessed from Python.

Dataset SHA256: 3d2c04d8760adc7ea174836c158d1ce92cfbb8665419113b79aedff27139c2cc

Features (sample):



label ave_functions_utilised_from_dlls_imported bogus_functions num_blacklisted_functions num_whitelisted_functions persistent_reg_key num_of_native_functions num_of_accesses_from_python SHA256
0 M 1.115312 37 0.133333 0.333333 1 0 0 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 M 24.500000 0 0.066667 0.000000 0 0 0 bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ... ... ... ... ... ...
1829 M 2.950617 2 0.200000 0.000000 0 0 0 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51
1830 M 0.813333 0 0.000000 0.333333 0 0 0 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

1831 rows × 9 columns

Created by: Tanatswa Dendere
Downloaded 4 times
Comments: 0
Related Dataset: Ransomware_Detection_Using_PE_Imports

Description: This dataset explores the API calls that utilize Crypt functionality as outlined by the study S. H. Kok, A. Abdullah, and N. Z. Jhanjhi, “Early detection of crypto-ransomware using pre-encryption detection algorithm,” Journal of King Saud University - Computer and Information Sciences, vol. 34, no. 5, pp. 1984–1999, May 2022, doi: 10.1016/j.jksuci.2020.06.012.

Dataset SHA256: 1d77c1e8b05797c10503055f23d51b8dd675731f039823193b89c0176111ee4a

Features (sample):



category label NtWriteVirtualMemory UuidCreate NtDelayExecution NtSetInformationFile NtWriteFile CreateThread NtReadVirtualMemory VirtualFreeEx CreateDirectoryW VirtualProtectEx SetFilePointer SHA256
0 Ransomware M 0 0 0 0 0 0 0 0 0 0 51 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 Ransomware M 0 0 0 0 0 0 0 0 2 0 0 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
... ... ... ... ... ... ... ... ... ... ... ... ... ... ...
11428 Ransomware M 0 0 0 0 0 0 0 0 0 0 1 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5
11429 Ransomware M 0 0 0 0 0 0 0 0 0 0 1 eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

11430 rows × 14 columns

Created by: Avinash
Downloaded 4 times
Comments: 0
Related Dataset: API statistics of Ransomware

Description: A dataset of the function names of PE imports and the DLL the functions are called from.

Dataset SHA256: 239115234c1ba81d16badf2babd1c3d48b28541c137628739d5919d458449313

Features (sample):



function_name dll category label SHA256
0 SysFreeString oleaut32.dll Ransomware M 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 SysReAllocStringLen oleaut32.dll Ransomware M 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
... ... ... ... ... ...
140259 VariantClear oleaut32.dll Ransomware M eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5
140260 VariantInit oleaut32.dll Ransomware M eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

140261 rows × 5 columns

Created by: Tanatswa Dendere
Downloaded 5 times
Comments: 0

Description: This dataset extracts the printable strings from the cuckoo reports which will be used for machine learning for ransomware detection.

Dataset SHA256: b56e760893fbb064d5143346f2ef96c635bbb56af7aa06b6d60f2c7979ae29f8

Features (sample):

category label strings SHA256
0 Ransomware M This program must be run under Win32\n`.itext\n`.data\n.idata\n.didata\n.edata\n.rdata\n@.reloc\nB.rsrc\nBoolean\nSystem\nAnsiChar\nShortInt\nSmallInt\nInteger\nPointer\nCardinal\nUInt64\nNativeInt\nNativeUInt\nSingle\nExtended\nDouble\nCurrency\nShortString\nPAnsiChar0\nPWideCharL\nByteBool\nSystem\nWordBool\nSystem\nLongBool\nSystem\nstring\nWideString\nAnsiString\nVariant\nTClass\nHRESULT\n&op_Equality\n&op_Inequality\nPInterfaceEntry\nTInterfaceEntry\nVTable\nIOffset\nImplGetter\nPInterfaceTable\nTInterfaceTable\nEntryCount\nEntries\nTMethod\n&op_Equality\n&op_Inequality\n&op_GreaterThan\n&op_GreaterThanOrEqual\n&op_LessThan\n&op_LessThanOrEqual\nTObject&\nCreate\nDisposeOf\nInitInstance\nInstance\nCleanupInstance\nClassType\nClassName\nClassNameIs\nClassParent\nClassInfo\nInstanceSize\nInheritsFrom\nAClass\nMethodAddress\nMethodAddress\nMethodName\nAddress\nQualifiedClassName\nFieldAddress\nFieldAddress\nGetInterface\nGetInterfaceEntry\nGetInterfaceTable\nUnitName\nUnitScope\nEquals\nGetHashCode\nToString\nSafeCallException\nExceptObject\nExceptAddr\nAfterConstruction\nBeforeDestruction\nDispatch\nMessage\nDefaultHandler\nMessage\nNewInstance\nFreeInstance\nDestroy\nTObject\nSystem\nTCustomAttribute\nTCustomAttribute|@\nSystem\nWeakAttribute4 @\nWeakAttribute\nSystem\nVolatileAttribute\nVolatileAttribute\nSystem\nIInterface\nSystem\nIEnumerable\nSystem\nIDispatch\nSystem\nFRefCount\nTInterfacedObject1\nAfterConstruction\nBeforeDestruction\nNewInstance\nTInterfacedObject@"@\nSystem\nRefCount\nPShortString\nPAnsiString\nPWideString\nPUnicodeString\nUTF8String\nRawByteString\nPLongInt\nPInt64\nPExtended\nPCurrency\nPVariant\nTDateTime\nTVarArrayBound\nElementCount\nLowBound\nTVarArrayBoundArray\nPVarArray\%@\nTVarArray\nDimCount\nElementSize\nLockCount\nBounds\nTVarRecord\nPRecord\nRecInfo\nTVarData\nReserved1\nReserved2\nReserved3\nVSmallInt\nVInteger\nVSingle\nVDouble\nVCurrency\nVOleStr\nVDispatch\nVError\nVBoolean\nVUnknown\nVShortInt\nVLongWord\nVInt64\nVUInt64\nVString\nVArray\nVPointer\nVUString\nVRecord\nVLongs\nVWords\nVBytes\nRawData\nTTypeKind\ntkUnknown\ntkInteger\ntkChar\ntkEnumeration\ntkFloat\ntkString\ntkClass\ntkMethod\ntkWChar\ntkLString\ntkWString\ntkVariant\ntkArray\ntkRecord\ntkInterface\ntkInt64\ntkDynArray\ntkUString\ntkClassRef\ntkPointer\ntkProcedure\nSystem\nTVarRec\nVInteger\nVBoolean\nVExtended\nVString\nVPointer\nVPChar\nVObject\nVClass\nVWideChar\nVPWideChar\nVAnsiString\nVCurrency\nVVariant\nVInterface\nVWideString\nVInt64\nVUnicodeString\n_Reserved1\nTPtrWrapper\nCreate\nAValue\nCreate\nAValue\nToPointer\nToInteger\n&op_Equality\n&op_Inequality\nTMarshal&\nCreate\nInString\nOutString\nInOutString\nAsAnsi\nAsAnsi\nAllocMem\nReallocMem\nOldPtr\nNewSize\nFreeMem\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nStartIndex\nReadByte\nReadInt16\nReadInt32\nReadInt64\nReadPtr\nWriteByte\nWriteInt16\nWriteInt32\nWriteInt64\nWritePtr\nWriteByte\nWriteInt16\nWriteInt32\nWriteInt64\nWritePtr\nFixString\nUnfixString\nUnsafeFixString\nUnsafeAddrOf\nAllocStringAsAnsi\nAllocStringAsAnsi\nCodePage\nAllocStringAsUnicode\nAllocStringAsAnsi\nAllocStringAsAnsi\nCodePage\nAllocStringAsUtf8\nAllocStringAsUtf8\nReadStringAsAnsi\nReadStringAsAnsi\nCodePage\nReadStringAsUnicode\nReadStringAsUtf8\nReadStringAsAnsiUpTo\nCodePage\nMaxLen\nReadStringAsUnicodeUpTo\nMaxLen\nReadStringAsUtf8UpTo\nMaxLen\nWriteStringAsAnsi\nMaxCharsIncNull\nWriteStringAsAnsi\nMaxCharsIncNull\nCodePage\nWriteStringAsAnsi\nMaxCharsIncNull\nWriteStringAsAnsi\nMaxCharsIncNull\nCodePage\nWriteStringAsUnicode\nMaxCharsIncNull\nWriteStringAsUnicode\nMaxCharsIncNull\nWriteStringAsUtf8\nMaxCharsIncNull\nWriteStringAsUtf8\nMaxCharsIncNull\nTMarshal\nSystem\nTTypeTable\nPTypeTableHD@\nPPackageTypeInfo\nTPackageTypeInfo\nTypeCount\nTypeTable\nUnitCount\nUnitNames\nTArray<System.Byte>\nSystem\nTArray<System.Char>\nSystemL\nTArray<System.Word>\nSystem\nTArray<System.ShortInt>\nSystemd\nTArray<System.SmallInt>\nSystem\nTArray<System.Integer>\nSystem\nTArray<System.Int64>\nSystem\nTArray<System.TPtrWrapper>\nSystemX+@\nPLibModule\nTLibModule\nInstance\nCodeInstance\nDataInstance\nResInstance\nTypeInfo\nReserved\nPResStringRec\nTResStringRec\nModule\nIdentifier\nTFloatSpecial\nfsZero\nfsNZero\nfsDenormal\nfsNDenormal\nfsPositive\nfsNegative\nfsNInf\nSystem\nTExtended80Rec\naExtended80\nExponent\nFraction\nMantissa\nSpecialType\nBuildUp\nSignFlag\nMantissa\nExponent\n&op_Explicit\n&op_Explicit\nPExceptionRecord\nTExceptionRecordP\nExceptionCode\nExceptionFlags\nExceptionRecord\nExceptionAddress\nNumberParameters\nExceptionInformation\nExceptAddr\nExceptObject\nAn unexpected memory leak has occurred. \nThe unexpected small block leaks are:\nThe sizes of unexpected leaked medium and large blocks are: \n bytes: \nUnknown\nAnsiString\nUnicodeString\nUnexpected Memory Leak\n~]x[[)\n_^[YY]\nGetLogicalProcessorInformation\nYZXtm1\nZTUWVSPR\n_^[YY]\n_^[YY]\n;Z]_^[\nSVWRPj\nZ_^[XX\ntWI|TVS\ntdI|aVS\nzh-TW,zh-Hant,zh\nes-ES_tradnl\nnb-NO,nb,no\ntg-Cyrl-TJ\naz-Latn-AZ\nuz-Latn-UZ\nmn-MN,mn-Cyrl,mn\niu-Cans-CA\nha-Latn-NG\nqps-ploc,en\nqps-ploca,ja\nzh-CN,zh-Hans,zh\nnn-NO,nn,no\nsr-Latn-CS\naz-Cyrl-AZ\ndsb-DE,dsb,hsb\nuz-Cyrl-UZ\nmn-Mong-CN\niu-Latn-CA\ntzm-Latn-DZ\nqps-plocm,ar\nzh-HK,zh-Hant,zh\nsr-Cyrl-CS\nzh-SG,zh-Hans,zh\nsmj-NO,smj,se\nzh-MO,zh-Hant,zh\nbs-Latn-BA\nsmj-SE,smj,se\nsr-Latn-BA\nsma-NO,sma,se\nsr-Cyrl-BA\nsma-SE,sma,se\nbs-Cyrl-BA\nsms-FI,sms,se\nsr-Latn-RS\nsmn-FI,smn,se\nsr-Cyrl-RS\nsr-Latn-ME\nsr-Cyrl-ME\nGetThreadPreferredUILanguages\nSetThreadPreferredUILanguages\nGetThreadUILanguage\n,tdBHu\nGetLongPathNameW\n_^[YY]\n$Z]_^[\n$Z]_^[\nYZ]_^[\n_^[YY]\n_^[YY]\nTStringDynArray\nSystem.Types\nTDuplicates\ndupIgnore\ndupAccept\ndupError\nSystem.Types\nTDirection\nFromBeginning\nFromEnd\nSystem.Types\nCreate\nCreate\n&op_Equality\n&op_Inequality\n&op_Addition\n&op_Subtraction\nDistance\nIsZero\nSubtract\nTSmallPoint\nCreate\nCreate\nCreate\n&op_Equality\n&op_Inequality\n&op_Addition\n&op_Subtraction\nDistance\nIsZero\nSubtract\nTPoint\nCreate\nCreate\n&op_Equality\n&op_Inequality\n&op_Addition\n&op_Subtraction\n&op_Implicit\n&op_Explicit\nPointInCircle\nCenter\nRadius\nDistance\nSetLocation\nSetLocation\nOffset\nOffset\nSubtract\nIsZero\nAPoint\nTSplitRectType\nsrLeft\nsrRight\nsrBottom\nSystem.Types\nBottom\nTopLeft\nBottomRight\nCreate\nOrigin\nCreate\nOrigin\nHeight\nCreate\nBottom\nCreate\nNormalize\nCreate\nNormalize\n&op_Equality\n&op_Inequality\n&op_Addition\n&op_Multiply\nNormalizeRect\nIsEmpty\nContains\nContains\nIntersectsWith\nIntersect\nIntersect\nPoints\nOffset\nOffset\nSetLocation\nSetLocation\nInflate\nInflate\nCenterPoint\nSplitRect\nSplitType\nSplitRect\nSplitType\nPercent\nTWaitResult\nwrSignaled\nwrTimeout\nwrAbandoned\nwrError\nwrIOCompletion\nSystem.Types\nTOpenOption\nofReadOnly\nofOverwritePrompt\nofHideReadOnly\nofNoChangeDir\nofShowHelp\nofNoValidate\nofAllowMultiSelect\nofExtensionDifferent\nofPathMustExist\nofFileMustExist\nofCreatePrompt\nofShareAware\nofNoReadOnlyReturn\nofNoTestFileCreate\nofNoNetworkButton\nofNoLongNames\nofOldStyleDialog\nofNoDereferenceLinks\nofEnableIncludeNotify\nofEnableSizing\nofDontAddToRecent\nofForceShowHidden\nSystem.UITypes\nTOpenOptions\nTOpenOptionEx\nofExNoPlacesBar\nSystem.UITypes\nTOpenOptionsEx\nTBorderIcon\nbiSystemMenu\nbiMinimize\nbiMaximize\nbiHelp\nSystem.UITypes\nTBorderIcons\nTWindowState\nwsNormal\nwsMinimized\nwsMaximized\nSystem.UITypes\nTEditCharCase\necNormal\necUpperCase\necLowerCase\nSystem.UITypes\nTFontCharset\nTFontPitch\nfpDefault\nfpVariable\nfpFixed\nSystem.UITypes\nTFontQuality\nfqDefault\nfqDraft\nfqProof\nfqNonAntialiased\nfqAntialiased\nfqClearType\nfqClearTypeNatural\nSystem.UITypes\nTFontStyle\nfsBold\nfsItalic\nfsUnderline\nfsStrikeOut\nSystem.UITypes\nTFontStyles\nTFontName\nTFontDataName|\nTFontStylesBase\nTCloseAction\ncaNone\ncaHide\ncaFree\ncaMinimize\nSystem.UITypes\nTMouseButton\nmbLeft\nmbRight\nmbMiddle\nSystem.UITypes\nTMouseActivate\nmaDefault\nmaActivate\nmaActivateAndEat\nmaNoActivate\nmaNoActivateAndEat\nSystem.UITypes\nTTabOrder\nTModalResult\nTDragMode\ndmManual\ndmAutomatic\nSystem.UITypes\nTDragState\ndsDragEnter\ndsDragLeave\ndsDragMove\nSystem.UITypes\nTDragKind\ndkDrag\ndkDock\nSystem.UITypes\nTAnchorKind\nakLeft\nakRight\nakBottom\nSystem.UITypes\nTAnchors\nTScrollCode\nscLineUp\nscLineDown\nscPageUp\nscPageDown\nscPosition\nscTrack\nscBottom\nscEndScroll\nSystem.UITypes\nTPrinterState\npsNoHandle\npsHandleIC\npsHandleDC\nSystem.UITypes\nTPrinterOrientation\npoPortrait\npoLandscape\nSystem.UITypes\nTPrinterCapability\npcCopies\npcOrientation\npcCollation\nSystem.UITypes\nTPrinterCapabilities\nTCursor\nTColor\nTAlphaColor\nTImageIndex\nTScrollStyle\nssNone\nssHorizontal\nssVertical\nssBoth\nSystem.UITypes\nPListEntry|\n_LIST_ENTRY\nPRTLCriticalSection\nPRTLCriticalSectionDebug\n_RTL_CRITICAL_SECTION_DEBUG \nType_18\nCreatorBackTraceIndex\nCriticalSection\nProcessLocksList\nEntryCount\nContentionCount\n_RTL_CRITICAL_SECTION\nDebugInfo\nLockCount\nRecursionCount\nOwningThread\nLockSemaphore\nReserved\nHACCEL\nHBITMAP\nHBRUSH\nHPALETTE\nPSecurityAttributes\n_SECURITY_ATTRIBUTES\nnLength\nlpSecurityDescriptor\nbInheritHandle\n_FILETIME\ndwLowDateTime\ndwHighDateTime\n_SYSTEMTIME\nwMonth\nwDayOfWeek\nwMinute\nwSecond\nwMilliseconds\n_TIME_ZONE_INFORMATION\nStandardName\nStandardDate\nStandardBias\nDaylightName\nDaylightDate\nDaylightBias\n_WIN32_FIND_DATAWP\ndwFileAttributes\nftCreationTime\nftLastAccessTime\nftLastWriteTime\nnFileSizeHigh\nnFileSizeLow\ndwReserved0\ndwReserved1\ncFileName\ncAlternateFileName\ntagBITMAP\nbmType\nbmWidth\nbmHeight\nbmWidthBytes\nbmPlanes\nbmBitsPixel\nbmBits\ntagBITMAPINFOHEADER(\nbiSize\nbiWidth\nbiHeight\nbiPlanes\nbiBitCount\nbiCompression\nbiSizeImage\nbiXPelsPerMeter\nbiYPelsPerMeter\nbiClrUsed\nbiClrImportant\nPDeviceModeW\\n_devicemodeW\ndmDeviceName\ndmSpecVersion\ndmDriverVersion\ndmSize\ndmDriverExtra\ndmFields\ndmOrientation\ndmPaperSize\ndmPaperLength\ndmPaperWidth\ndmScale\ndmCopies\ndmDefaultSource\ndmPrintQuality\ndmColor\ndmDuplex\ndmYResolution\ndmTTOption\ndmCollate\ndmFormName\ndmLogPixels\ndmBitsPerPel\ndmPelsWidth\ndmPelsHeight\ndmDisplayFlags\ndmDisplayFrequency\ndmICMMethod\ndmICMIntent\ndmMediaType\ndmDitherType\ndmICCManufacturer\ndmICCModel\ndmPanningWidth\ndmPanningHeight\ntagDIBSECTIONT\ndsBmih\ndsBitfields\ndshSection\ndsOffset\ntagMSG\nmessage\nwParam\nlParam\ntagNMHDR\nhwndFrom\nidFrom\nodSelected\nodGrayed\nodDisabled\nodChecked\nodFocused\nodDefault\nodHotLight\nodInactive\nodNoAccel\nodNoFocusRect\nodReserved1\nodReserved2\nodComboBoxEdit\nWinapi.Windows\nTOwnerDrawState\nGESTURECONFIG\ndwWant\ndwBlock\nTDWordFiller\nTMessage\nWParam\nLParam\nResult\nWParamLo\nWParamHi\nWParamFiller\nLParamLo\nLParamHi\nLParamFiller\nResultLo\nResultHi\nResultFiller\nTWMKey\nMsgFiller\nCharCode\nUnused\nCharCodeUnusedFiller\nKeyData\nKeyDataFiller\nResult\nTWMMenuChar\nMsgFiller\nMenuFlag\nUserMenuFlagFiller\nResult\n !"#$%&'(!)*+,-./0'\n56789:\n;<<<<<<<<=========================\n@ABCDEFGHHHIJKLMHNHOHHHHHHHHHHHHHHH\nPQHHHHHHHHHHH\nRHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHSTUVWXYZHHHHHHHHHHHHHHHHHHHHHHHH[\]HHHHHHHHHHHHH\n_HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH\n`HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH\n?333333\n?tE)!XU\n?tE)!XU\nTFileName\nTSearchRecp\nExcludeAttr\nFindHandle\nFindData\nTLangRec\nFLocaleName\nFSysLangs\nTLanguages&\nCreate\nDestroy\nGetLocaleIDFromLocaleName\nLocaleName\nIndexOf\nIndexOf\nLocaleName\nGetName\nGetNameFromLocaleID\nGetNameFromLCID\nGetLocaleName\nGetLocaleID\nGetLocaleIDFromName\nLocaleName\nGetExt\nTLanguages\nSystem.SysUtils\nNameFromLocaleID\nNameFromLCID\nLocaleName\nLocaleID\nLocaleIDFromName\nFMessage\nFHelpContext\nFInnerException\nFStackInfo\nFAcquireInnerException\nException3\nCreate\nCreateFmt\nCreateRes\nCreateRes\nResStringRec\nCreateResFmt\nCreateResFmt\nResStringRec\nCreateHelp\nAHelpContext\nCreateFmtHelp\nAHelpContext\nCreateResHelp\nAHelpContext\nCreateResHelp\nResStringRec\nAHelpContext\nCreateResFmtHelp\nResStringRec\nAHelpContext\nCreateResFmtHelp\nAHelpContext\nDestroy\nGetBaseException\nToString\nRaiseOuterException\nThrowOuterException\nException\nSystem.SysUtils\nBaseException\nHelpContext\nInnerException\nMessage\nStackTrace\nStackInfo\nEArgumentException\nEArgumentException0\nSystem.SysUtils\nEArgumentOutOfRangeException\nEArgumentOutOfRangeException\nSystem.SysUtils\nEPathTooLongException\nEPathTooLongException\nSystem.SysUtils\nENotSupportedException\nENotSupportedExceptionl\nSystem.SysUtils\nEDirectoryNotFoundException\nEDirectoryNotFoundException,\nSystem.SysUtils\nEFileNotFoundException\nEFileNotFoundException\nSystem.SysUtils\nEListError\nEListError\nSystem.SysUtils\nEInvalidOpException\nEInvalidOpException\\nSystem.SysUtils\nEAbort\nEAbort\nSystem.SysUtils\nAllowFree\nEHeapException,\nFreeInstance\nEHeapException\nSystem.SysUtils\nEOutOfMemory\nEOutOfMemory\nSystem.SysUtils\nErrorCode\nEInOutError\nEInOutError\\nSystem.SysUtils\nExceptionRecord\nEExternal\nEExternal \nSystem.SysUtils\nEExternalException\nEExternalException\nSystem.SysUtils\nEIntError\nEIntError\nSystem.SysUtils\nEDivByZero\nEDivByZeroD\nSystem.SysUtils\nERangeError\nERangeError\nSystem.SysUtils\nEIntOverflow\nEIntOverflow\nSystem.SysUtils\nEMathError\nEMathError<\nSystem.SysUtils\nEInvalidOp\nEInvalidOp\nSystem.SysUtils\nEZeroDivide\nEZeroDivide\nSystem.SysUtils\nEOverflowP\nEOverflow4\nSystem.SysUtils\nEUnderflow\nEUnderflow\nSystem.SysUtils\nEInvalidPointer\nEInvalidPointer\nSystem.SysUtils\nEInvalidCast\nEInvalidCast0\nSystem.SysUtils\nEConvertError\nEConvertError\nSystem.SysUtils\nEAccessViolation\nEAccessViolation\nSystem.SysUtils\nEPrivilege\nEPrivilege4\nSystem.SysUtils\nEStackOverflow\nEStackOverflow\nSystem.SysUtils\nEControlC\nEControlC\nSystem.SysUtils\nEVariantErrorP\nEVariantError0\nSystem.SysUtils\nEPropReadOnly\nEPropReadOnly\nSystem.SysUtils\nEPropWriteOnly\nEPropWriteOnly\nSystem.SysUtils\nEAssertionFailed\nEAssertionFailed8\nSystem.SysUtils\nEAbstractError\nEAbstractError\nSystem.SysUtils\nEIntfCastError\nEIntfCastError\nSystem.SysUtils\nErrorCode\nEOSError\nEOSErrorH\nSystem.SysUtils\nESafecallException\nESafecallException\nSystem.SysUtils\nEMonitor\nEMonitor\nSystem.SysUtils\nEMonitorLockException\nEMonitorLockException\\nSystem.SysUtils\nENoMonitorSupportException\nENoMonitorSupportException\nSystem.SysUtils\nENotImplemented\nENotImplemented\nSystem.SysUtils\nEObjectDisposed\nEObjectDisposed\nSystem.SysUtils\n TArray<System.SysUtils.TLangRec>\nSystem\nTFormatSettings.TEraInfo\nEraName\nEraOffset\nEraStart\nEraEnd\n:TFormatSettings.:10\n:TFormatSettings.:20\n:TFormatSettings.:3\n:TFormatSettings.:4\n:TFormatSettings.:5\nSystem.SysUtils,\nTFormatSettings\nCurrencyString\nCurrencyFormat\nCurrencyDecimals\nDateSeparator\nTimeSeparator\nListSeparator\nShortDateFormat\nLongDateFormat\nTimeAMString\nTimePMString\nShortTimeFormat\nLongTimeFormat\nShortMonthNames\nLongMonthNames\nShortDayNames\nLongDayNames\nEraInfo\nThousandSeparator\nDecimalSeparator\nTwoDigitYearCenturyWindow\nNegCurrFormat\nNormalizedLocaleName\nCreate\nCreate\nLocale\nCreate\nLocaleName\nGetEraYearOffset\nSystem.SysUtils\nSystem.SysUtils\nIReadWriteSync\nSystem.SysUtils\nPThreadInfo\nTThreadInfo\nThreadID\nActive\nRecursionCount\nFHashTable\nTThreadLocalCounter'\nDestroy\nThread\nDelete\nThread\nThread\nTThreadLocalCounter\nSystem.SysUtils\nFSentinel\nFReadSignal\nFWriteSignal\nFWaitRecycle\nFWriteRecursionCount\nFWriterID\nFRevisionLevel\n$TMultiReadExclusiveWriteSynchronizer&\nCreate\nDestroy\nBeginRead\nEndRead\nBeginWrite\nEndWrite\n$TMultiReadExclusiveWriteSynchronizer\nSystem.SysUtils\nRevisionLevel\nFLength\nFMaxCapacity\nTStringBuilder&\nCreate\nCreate\naCapacity\nCreate\nCreate\naCapacity\naMaxCapacity\nCreate\naCapacity\nCreate\nStartIndex\nLength\naCapacity\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nAppend\nRepeatCount\nAppend\nStartIndex\nCharCount\nAppend\nStartIndex\nAppendFormat\nFormat\nAppendLine\nAppendLine\nCopyTo\nSourceIndex\nDestination\nDestinationIndex\nEnsureCapacity\naCapacity\nEquals\nStringBuilder\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nInsert\nstartIndex\ncharCount\nRemove\nStartIndex\nRemLength\nReplace\nOldChar\nNewChar\nReplace\nOldValue\nNewValue\nReplace\nOldChar\nNewChar\nStartIndex\nReplace\nOldValue\nNewValue\nStartIndex\nToString\nToString\nStartIndex\nStrLength\nGetChars\nSetChars\nTStringBuilder\nSystem.SysUtils\nCapacity\nLength\nMaxCapacity\nEEncodingError\nEEncodingError\nSystem.SysUtils\nIEnumerable<System.string>0!@\nSystem\nTArray<System.string>\nSystem\nFIsSingleByte\nFMaxCharSize\nTEncoding%\nConvert\nSource\nDestination\nConvert\nSource\nDestination\nConvert\nSource\nDestination\nStartIndex\nConvert\nSource\nDestination\nStartIndex\nFreeEncodings\nIsStandardEncoding\nAEncoding\nGetBufferEncoding\nBuffer\nAEncoding\nGetBufferEncoding\nBuffer\nAEncoding\nADefaultEncoding\nGetByteCount\nGetByteCount\nGetByteCount\nGetByteCount\nCharIndex\nCharCount\nGetByteCount\nCharIndex\nCharCount\nGetByteCount\nGetByteCount\nCharIndex\nCharCount\nGetBytes\nGetBytes\nGetBytes\nGetBytes\nCharIndex\nCharCount\nGetBytes\nCharIndex\nCharCount\nGetBytes\nCharIndex\nCharCount\nByteIndex\nGetBytes\nCharIndex\nCharCount\nByteIndex\nGetBytes\nGetBytes\nCharIndex\nCharCount\nByteIndex\nGetCharCount\nGetCharCount\nGetCharCount\nByteIndex\nByteCount\nGetCharCount\nByteIndex\nByteCount\nGetChars\nGetChars\nGetChars\nByteIndex\nByteCount\nGetChars\nByteIndex\nByteCount\nGetChars\nByteIndex\nByteCount\nCharIndex\nGetChars\nByteIndex\nByteCount\nCharIndex\nGetEncoding\nCodePage\nGetEncoding\nEncodingName\nGetMaxByteCount\nCharCount\nGetMaxCharCount\nByteCount\nGetPreamble\nGetString\nGetString\nByteIndex\nByteCount\nTEncoding$\nSystem.SysUtils\nCodePage\nEncodingName\nIsSingleByte\nFCodePage\nFMBToWCharFlags\nFWCharToMBFlags\nTMBCSEncoding&\nCreate\nCreate\nCodePage\nCreate\nCodePage\nMBToWCharFlags\nWCharToMBFlags\nGetMaxByteCount\nCharCount\nGetMaxCharCount\nByteCount\nGetPreamble\nTMBCSEncoding\nSystem.SysUtils\nTUTF7Encoding&\nCreate\nGetMaxByteCount\nCharCount\nGetMaxCharCount\nByteCount\nTUTF7Encoding\nSystem.SysUtils\nTUTF8Encoding&\nCreate\nGetMaxByteCount\nCharCount\nGetMaxCharCount\nByteCount\nGetPreamble\nTUTF8Encoding\nSystem.SysUtils\nTUnicodeEncoding&\nCreate\nGetMaxByteCount\nCharCount\nGetMaxCharCount\nByteCount\nGetPreamble\nTUnicodeEncoding\nSystem.SysUtils\nTBigEndianUnicodeEncoding%\nGetPreamble\nTBigEndianUnicodeEncoding\nSystem.SysUtils\nTMarshaller.PDisposeRec\nTMarshaller.TDisposeProc\nTMarshaller.TDisposeRec\nTMarshaller.IDisposer\nSystem.SysUtils\nFInline\nFOverflow\nFCount\nTMarshaller.TDisposer'\nDestroy\nTMarshaller.TDisposert\nSystem.SysUtils\nTMarshaller\nFDisposer\nInString\nMaxLen\nOutString\nInOutString\nMaxLen\nAsAnsi\nAsAnsi\nAsAnsi\nCodePage\nAsAnsi\nCodePage\nAsUtf8\nAsUtf8\nAllocMem\nReallocMem\nOldPtr\nNewSize\nFixString\nUnsafeFixString\nAllocStringAsAnsi\nAllocStringAsAnsi\nCodePage\nAllocStringAsUtf8\nAllocStringAsUnicode\n/TArray<System.SysUtils.TMarshaller.TDisposeRec>\nSystem\nSystem.SysUtils\n_^[YY]\nYZ]_^[\nYZ]_^[\nTStrData\nSystem.SysUtilsL\nSystem.SysUtilsL\nQQQQQQQQSV\nYZ]_^[\n$Z]_^[\n_^[YY]\n<@t!QS<$t\n$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)\n_^[YY]\n_^[YY]\n$YZ_^[\nSystem.SysUtilsL\nt,HtYH\n:TInternalEraInfoRecord.:1\nSystem.SysUtils,\nTInternalEraInfoRecord\nEraCount\nEraInfo\n_^[YY]\nSystem.SysUtils\n_^[YY]\n_^[YY]\n_^[YY]\n_^[YY]\n$Z]_^[\n_^[YY]\n$YZ_^[\n$Z]_^[\nPUnitHashEntryD\nTUnitHashEntry\nLibModule\nUnitName\nDupsAllowed\nFullHash\nTModuleInfo\nValidated\nUnitHashArray\n&TArray<System.SysUtils.TUnitHashEntry>\nSystemD\nYZ]_^[\nYZ]_^[\nYZ]_^[\n<pYZ_^[\n_^[YY]\n_^[YY]\nVariantChangeTypeEx\nVarNeg\nVarNot\nVarAdd\nVarSub\nVarMul\nVarDiv\nVarIdiv\nVarMod\nVarAnd\nVarXor\nVarCmp\nVarI4FromStr\nVarR4FromStr\nVarR8FromStr\nVarDateFromStr\nVarCyFromStr\nVarBoolFromStr\nVarBstrFromCy\nVarBstrFromDate\nVarBstrFromBool\nTVarCompareResult\ncrLessThan\ncrEqual\ncrGreaterThan\nSystem.Variants\nFVarType\nTCustomVariantType&\nCreate\nCreate\nRequestedVarType\nDestroy\nIsClear\nSource\nCastTo\nSource\nAVarType\nCastToOle\nSource\nSource\nIndirect\nBinaryOp\nOperator\nUnaryOp\nOperator\nCompareOp\nOperator\nCompare\nRelationship\nTCustomVariantTypep'C\nSystem.Variants\nVarType\nTVarDataArray\nSystem.Variants8&@\nEVariantInvalidOpError\nEVariantInvalidOpError\nSystem.Variants\nEVariantTypeCastError\nEVariantTypeCastError\nSystem.Variants\nEVariantOverflowErrorh.C\nEVariantOverflowError@.C\nSystem.Variants\nEVariantInvalidArgError\nEVariantInvalidArgError\nSystem.Variants\nEVariantBadVarTypeError\nEVariantBadVarTypeError\nSystem.Variants\nEVariantBadIndexError\nEVariantBadIndexError|0C\nSystem.Variants\nEVariantArrayLockedError\nEVariantArrayLockedError81C\nSystem.Variants\nEVariantArrayCreateError\nEVariantArrayCreateError\nSystem.Variants\nEVariantNotImplError\nEVariantNotImplError\nSystem.Variants\nEVariantOutOfMemoryError\nEVariantOutOfMemoryErrorp3C\nSystem.Variants\nEVariantUnexpectedError\nEVariantUnexpectedError04C\nSystem.Variants\nEVariantDispatchError\nEVariantDispatchError\nSystem.Variants\nEVariantInvalidNullOpError\nEVariantInvalidNullOpError\nSystem.Variants\nTStringRef\nUnicode\nFromAnsi\nFromUnicode\n@^[YY]\nQQQQQSV\n_^[YY]\nQQQQSV\nSystem.Variants\n_^[YY]\ntagSTATSTGH\npwcsName\ndwType\ncbSize\ngrfMode\ngrfLocksSupported\ngrfStateBits\nreserved\nISequentialStream\nWinapi.ActiveX\nIStream(\nWinapi.ActiveX\nPExcepInfo\nTFNDeferredFillIn\nExInfo\ntagEXCEPINFO \nwReserved\nbstrSource\nbstrDescription\nbstrHelpFile\ndwHelpContext\npvReserved\npfnDeferredFillIn\nTSingletonImplementation\nTSingletonImplementationt\nSystem.Generics.Defaults\nTStringComparer'\nOrdinal\nTStringComparer8\nSystem.Generics.Defaults\nTOrdinalIStringComparerD\nCompare\nEquals\nGetHashCode\nTOrdinalIStringComparer$\nSystem.Generics.Defaults\n IEqualityComparer<System.string>\nSystem.Generics.Defaults\nIComparer<System.string>\nSystem.Generics.Defaults\nTCustomComparer<System.string>\nTCustomComparer<System.string>D\nSystem.Generics.Defaults\n_^[YY]\nTOrdinalStringComparerD\nCompare\nEquals\nGetHashCode\nTOrdinalStringComparer\nSystem.Generics.Defaults\nTCollectionNotification\ncnAdded\ncnRemoved\ncnExtracted\nSystem.Generics.Collections\ndoOwnsKeys\ndoOwnsValues\nSystem.Generics.Collections\nTDictionaryOwnerships\nEInsufficientRtti@\nEInsufficientRtti\nSystem.Rtti\nEInvocationError\nEInvocationError\nSystem.Rtti\nENonPublicType\nENonPublicTypex\nSystem.Rtti\nIValueData\nSystem.Rtti\nTValueData\nFTypeInfo\nFValueData\nFAsUByte\nFAsUWord\nFAsULong\nFAsObject\nFAsClass\nFAsSByte\nFAsSWord\nFAsSLong\nFAsSingle\nFAsDouble\nFAsExtended\nFAsComp\nFAsCurr\nFAsUInt64\nFAsSInt64\nFAsMethod\nFAsPointer\nTValue\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\n&op_Implicit\nFromVariant\nFromOrdinal\nATypeInfo\nAValue\nFromArray\nArrayTypeInfo\nValues\nIsObject\nAsObject\nIsInstanceOf\nAClass\nIsClass\nAsClass\nIsOrdinal\nAsOrdinal\nTryAsOrdinal\nAResult\nIsType\nATypeInfo\nATypeInfo\nTryCast\nATypeInfo\nAResult\nAsInteger\nAsBoolean\nAsExtended\nAsInt64\nAsUInt64\nAsInterface\nAsString\nAsVariant\nAsCurrency\nIsArray\nGetArrayLength\nGetArrayElement\nSetArrayElement\nAValue\nABuffer\nATypeInfo\nResult\nAValue\nATypeInfo\nResult\nMakeWithoutCopy\nABuffer\nATypeInfo\nResult\nExtractRawData\nABuffer\nExtractRawDataNoCopy\nABuffer\nGetReferenceToRawData\nGetReferenceToRawArrayElement\nToString\nFHandle\nFRttiDataSize\nFPackage\nFParent\nFAttributeGetter\nTRttiObject'\nDestroy\nGetAttributes\nTRttiObject\nSystem.Rtti\nHandle\nRttiDataSize,\nParentx%D\nPackage\nTRttiNamedObject\nTRttiNamedObject\\nSystem.Rtti\nTRttiType3\nToString\nGetMethods\nGetFields\nGetProperties\nGetIndexedProperties\nGetMethod\nGetMethods\nGetField\nGetProperty\nGetIndexedProperty\nGetDeclaredMethods\nGetDeclaredProperties\nGetDeclaredFields\nGetDeclaredIndexedProperties\nTRttiType4\nSystem.Rtti\nHandle\nQualifiedName\nIsPublicType\nTypeKind\nTypeSize\nIsManaged@\nBaseType8\nAsInstance\nIsInstance\nAsOrdinal\nIsOrdinall\nAsRecord\nIsRecord\nTRttiMember\nTRttiMemberD\nSystem.Rtti\nParent\nVisibility\nTRttiStructuredType\nTRttiStructuredTypeD\nSystem.Rtti\nTRttiFieldE\nGetValue\nInstance\nSetValue\nInstance\nAValue\nToString\nTRttiField8\nSystem.Rtti\nFieldType\nOffset\nTRttiManagedFieldD\nTRttiManagedField \nSystem.Rtti\nFieldType\nFieldOffset\nFMethOfs\nTRttiRecordType<\nGetDeclaredFields\nGetDeclaredMethods\nGetAttributes\nTRttiRecordType(\nSystem.Rtti\nManagedFields\nTRttiPropertyE\nGetValue\nInstance\nSetValue\nInstance\nAValue\nTRttiProperty(\nSystem.Rtti\nPropertyType\nIsReadable\nIsWritable\nTRttiInstanceProperty3\nToString\nTRttiInstanceProperty\nSystem.Rtti\nPropertyType\nDefault\nNameIndex\nPropInfo\nTRttiParameter3\nToString\nTRttiParameter\nSystem.Rtti\nFlags@\nParamType\nTDispatchKind\ndkStatic\ndkVtable\ndkDynamic\ndkMessage\ndkInterface\nSystem.Rtti\nTMethodImplementationCallback\nSystem.Rtti\nTMethodImplementation.TFloatReg\nRegSingle\nRegDouble\nRegExtended\nRegComp\nRegCurr\nUnused1\nUnused2\nUnused3\n):TMethodImplementation.TInterceptFrame.:1\n%TMethodImplementation.TInterceptFrame(\nRegEAX\nRegEDX\nRegECX\nPreviousFrame\nRetAddr\n*TMethodImplementation.TFirstStageIntercept\nPushEBP_55\nMovEBP_ESP_1_89\nMovEBP_ESP_2_E5\nPush_68\nPushVal\nJmpRel_E9\nRelTarget\n%TMethodImplementation.PInterceptFrame\n*TMethodImplementation.PFirstStageIntercept\nTMethodImplementation.TParamLoc\nFTypeInfo\nFByRefParam\nFOffset\nCreate\nAByRef\nGetArgLoc\nAFrame\nGetArg\nAFrame\nSetArg\nAFrame\nFCallerPopsStack\nFResultFP\nFHasSelf\nFStackSize\nFParams\nFResultLoc\nFParamList\nFReturnType\nFCallConv\n!TMethodImplementation.TInvokeInfoK\nCreate\nACallConv\nAHasSelf\nDestroy\nGetParamLocs\nAddParameter\n!TMethodImplementation.TInvokeInfoX\nSystem.Rtti\nReturnType\nFUserData\nFCallback\nFInvokeInfo\nTMethodImplementation&\nCreate\nDestroy\nTMethodImplementation@\nSystem.Rtti\nCodeAddress\nFInvokeInfo\nTRttiMethod'\nDestroy\nInvoke\nInstance\nInvoke\nInstance\nInvoke\nInstance\nCreateImplementation\nAUserData\nACallback\nGetParameters\nToString\nTRttiMethod\nSystem.Rtti\nReturnType\nHasExtendedInfoLnH\nMethodKind\nDispatchKind\nIsConstructor\nIsDestructor\nIsClassMethod\nIsStatic\nVirtualIndex\qH\nCallingConvention\nCodeAddress\nFReadMethod\nFWriteMethod\nTRttiIndexedPropertyS\nGetValue\nInstance\nSetValue\nInstance\nToString\nTRttiIndexedProperty\nSystem.Rtti\nHandle@\nPropertyTypel\nReadMethodl\nWriteMethod\nIsReadable\nIsWritable\nIsDefault\nFProps\nFMeths\nFVirtCount\nFIndexedProps\nFClassTab\nFReadPropData\nFReadMethData\nTRttiInstanceType@\nGetDeclaredProperties\nGetDeclaredMethods\nGetDeclaredFields\nGetDeclaredIndexedProperties\n GetDeclaredImplementedInterfaces\nGetImplementedInterfaces\nGetAttributes\nTRttiInstanceType\nSystem.Rtti\nBaseType\nDeclaringUnitName\nMetaclassType\nVmtSize\nFMethods\nFTotalMethodCount\nTRttiInterfaceType=\nGetDeclaredMethods\nTRttiInterfaceType|\nSystem.Rtti\nBaseType,\nIntfFlags\nDeclaringUnitName\nTRttiOrdinalType\nTRttiOrdinalType\nSystem.Rtti\nOrdType\nMinValue\nMaxValue\nTRttiInt64Type\nTRttiInt64Type \nSystem.Rtti\nMinValue\nMaxValue\nFProcSig\nTRttiInvokableTypeS\nInvoke\nProcOrMeth\nGetParameters\nToString\nTRttiInvokableType`\nSystem.Rtti\nReturnType\qH\nCallingConvention\nTRttiMethodTypeQ\nInvoke\nCallable\nToString\nTRttiMethodType\nSystem.Rtti\nMethodKind 4e0d1edb76747fd945b87dd18299298f0df719edbea946119d91db59a9b6527a
1 Ransomware M !This program cannot be run in DOS mode.\n`.rdata\n@.data\n.mysec\n`.mysec3\n`.mysec2\n`.rcrs\n@.reloc\nPPPPPPP\n0WWWWW\n_VVVVV\n0WWWWW\njXh ?B\nQQSVWd\nHHtXHHt\n>If90t\ntM<it-<ot)<ut%<xt!<Xt\n<dty<itu<otq<utm<xti<Xte\nHIf98t\n0SSSSS\n<at9<rt,<wt\nURPQQh\n>=Yt1j\nQQSVWh\nj@j ^V\nj,hXBB\nHtHu4j\ns[S;7|G;w\ntR99u2\n0A@@Ju\n^SSSSS\nj"^SSSSS\nHHtYHHt\ntGHt.Ht&\n^SSSSS\n8VVVVV\n;t$,v-\nUQPXY]Y[\nHHt*HHt\n<0|<9\ntK<_t<<$t8<<t4<>t0<-t,<a|\n<z~$<A|\n<0|O<9\ntU<A|B<P\ntY<@tO<Zt\nt\<@tXj'\nNtFNt#NuV\nt.<@t5V\nTtUHtKHtAHt\n0t-HHt\nAtIHt0Hu\nj hhFB\n_VVVVV\n_VVVVV\n0SSSSS\n0SSSSS\n0WWWWW\nAAFFf;\nt"SS9]\nC PjPV\nC$PjQV\nC*PjTV\nC+PjUV\nC,PjVV\nC-PjWV\nC.PjRV\nC/PjSV\n.;1s(N\nHHt4HHt\nHt\Ht,\nteHtFHt&Hu\nty<%tA\nPPPPPPPP\ntNh<8B\nt=h88B\nVj@h`5B\nu%h@8B\nPPPPPPPP\n0WWWWW\nu,VVWV\nt VV9u\nt+WWVPV\n^SSSSS\n^SSSSS\n>:u8FV\nVVVVVQRSSj\n^SSSSS\n^SSSSS\n0SSSSS\n^SSSSS\n^WWWWW\n0SSSSS\n8VVVVV\nstring too long\ninvalid string position\ninvalid string argument\nUnknown exception\n(null)\n`h````\nxpxxxx\nUTF-16LE\nUNICODE\nCorExitProcess\nruntime error \nTLOSS error\nSING error\nDOMAIN error\nAn application has made an attempt to load the C runtime library incorrectly.\nPlease contact the application's support team for more information.\n- Attempt to use MSIL code from this assembly during native code initialization\nThis indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.\n- not enough space for locale information\n- Attempt to initialize the CRT more than once.\nThis indicates a bug in your application.\n- CRT not initialized\n- unable to initialize heap\n- not enough space for lowio initialization\n- not enough space for stdio initialization\n- pure virtual function call\n- not enough space for _onexit/atexit table\n- unable to open console device\n- unexpected heap error\n- unexpected multithread lock error\n- not enough space for thread data\nThis application has requested the Runtime to terminate it in an unusual way.\nPlease contact the application's support team for more information.\n- not enough space for environment\n- not enough space for arguments\n- floating point support not loaded\nMicrosoft Visual C++ Runtime Library\n<program name unknown>\nRuntime Error!\nProgram: \nEncodePointer\nDecodePointer\nFlsFree\nFlsSetValue\nFlsGetValue\nFlsAlloc\nbad exception\nLC_TIME\nLC_NUMERIC\nLC_MONETARY\nLC_CTYPE\nLC_COLLATE\nLC_ALL\n !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~\n`h`hhh\nxppwpp\n Complete Object Locator'\n Class Hierarchy Descriptor'\n Base Class Array'\n Base Class Descriptor at (\n Type Descriptor'\n`local static thread guard'\n`managed vector copy constructor iterator'\n`vector vbase copy constructor iterator'\n`vector copy constructor iterator'\n`dynamic atexit destructor for '\n`dynamic initializer for '\n`eh vector vbase copy constructor iterator'\n`eh vector copy constructor iterator'\n`managed vector destructor iterator'\n`managed vector constructor iterator'\n`placement delete[] closure'\n`placement delete closure'\n`omni callsig'\n delete[]\n new[]\n`local vftable constructor closure'\n`local vftable'\n`udt returning'\n`copy constructor closure'\n`eh vector vbase constructor iterator'\n`eh vector destructor iterator'\n`eh vector constructor iterator'\n`virtual displacement map'\n`vector vbase constructor iterator'\n`vector destructor iterator'\n`vector constructor iterator'\n`scalar deleting destructor'\n`default constructor closure'\n`vector deleting destructor'\n`vbase destructor'\n`string'\n`local static guard'\n`typeof'\n`vcall'\n`vbtable'\n`vftable'\noperator\n delete\n__unaligned\n__restrict\n__ptr64\n__clrcall\n__fastcall\n__thiscall\n__stdcall\n__pascal\n__cdecl\n__based(\n{flat}\n`non-type-template-parameter\nunsigned \nshort \n<ellipsis>\n,<ellipsis>\n throw(\n`template-parameter\ncli::pin_ptr<\ncli::array<\n`anonymous namespace'\ngeneric-type-\ntemplate-parameter-\n`unknown ecsu'\nunion \nstruct \nclass \ncoclass \ncointerface \nextern "C" \n[thunk]:\npublic: \nprotected: \nprivate: \nvirtual \nstatic \n`template static data member destructor helper'\n`template static data member constructor helper'\n`local static destructor helper'\n`adjustor{\n`vtordisp{\n`vtordispex{\nconst \nvolatile \nvolatile\n volatile\nsigned \ndouble\nUNKNOWN\n__int128\nwchar_t\n__int64\n__int16\n__int32\n__int8\n__w64 \nSystemFunction036\nADVAPI32.DLL\nGetProcessWindowStation\nGetUserObjectInformationA\nGetLastActivePopup\nGetActiveWindow\nMessageBoxA\nUSER32.DLL\n !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~\n !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\nHH:mm:ss\ndddd, MMMM dd, yyyy\nMM/dd/yy\nDecember\nNovember\nOctober\nSeptember\nAugust\nFebruary\nJanuary\nSaturday\nFriday\nThursday\nWednesday\nTuesday\nMonday\nSunday\nunited-states\nunited-kingdom\ntrinidad & tobago\nsouth-korea\nsouth-africa\nsouth korea\nsouth africa\nslovak\npuerto-rico\npr-china\npr china\nnew-zealand\nhong-kong\nholland\ngreat britain\nengland\nbritain\namerica\nswedish-finland\nspanish-venezuela\nspanish-uruguay\nspanish-puerto rico\nspanish-peru\nspanish-paraguay\nspanish-panama\nspanish-nicaragua\nspanish-modern\nspanish-mexican\nspanish-honduras\nspanish-guatemala\nspanish-el salvador\nspanish-ecuador\nspanish-dominican republic\nspanish-costa rica\nspanish-colombia\nspanish-chile\nspanish-bolivia\nspanish-argentina\nportuguese-brazilian\nnorwegian-nynorsk\nnorwegian-bokmal\nnorwegian\nitalian-swiss\nirish-english\ngerman-swiss\ngerman-luxembourg\ngerman-lichtenstein\ngerman-austrian\nfrench-swiss\nfrench-luxembourg\nfrench-canadian\nfrench-belgian\nenglish-usa\nenglish-us\nenglish-uk\nenglish-trinidad y tobago\nenglish-south africa\nenglish-nz\nenglish-jamaica\nenglish-ire\nenglish-caribbean\nenglish-can\nenglish-belize\nenglish-aus\nenglish-american\ndutch-belgian\nchinese-traditional\nchinese-singapore\nchinese-simplified\nchinese-hongkong\nchinese\ncanadian\nbelgian\naustralian\namerican-english\namerican english\namerican\nNorwegian-Nynorsk\nCONIN$\nCONOUT$\nSunMonTueWedThuFriSat\nJanFebMarAprMayJunJulAugSepOctNovDec\nbad allocation\npaluci begohicixezufemure wutatodebamaxokikedotezuno\ntelokagikavetitogone\nvukuxekewa %f\nruyejegomu\nLockFile\nGetFileAttributesExA\nGetTickCount\nLoadLibraryW\nlstrlenW\nCreateMailslotW\nGetLastError\nGetProcAddress\nLocalAlloc\nVirtualProtect\nDuplicateHandle\nCloseHandle\nKERNEL32.dll\nSetAclInformation\nOpenSCManagerA\nAreAnyAccessesGranted\nADVAPI32.dll\nGetStartupInfoW\nRaiseException\nRtlUnwind\nTerminateProcess\nGetCurrentProcess\nUnhandledExceptionFilter\nSetUnhandledExceptionFilter\nIsDebuggerPresent\nHeapAlloc\nHeapFree\nWriteFile\nWideCharToMultiByte\nGetConsoleCP\nGetConsoleMode\nFlushFileBuffers\nDeleteCriticalSection\nLeaveCriticalSection\nFatalAppExitA\nEnterCriticalSection\nGetModuleHandleW\nExitProcess\nGetStdHandle\nGetModuleFileNameA\nGetModuleFileNameW\nFreeEnvironmentStringsW\nGetEnvironmentStringsW\nGetCommandLineW\nSetHandleCount\nGetFileType\nGetStartupInfoA\nTlsGetValue\nTlsAlloc\nTlsSetValue\nTlsFree\nInterlockedIncrement\nSetLastError\nGetCurrentThreadId\nInterlockedDecrement\nGetCurrentThread\nHeapCreate\nHeapDestroy\nVirtualFree\nQueryPerformanceCounter\nGetCurrentProcessId\nGetSystemTimeAsFileTime\nSetFilePointer\nGetCPInfo\nGetACP\nGetOEMCP\nIsValidCodePage\nVirtualAlloc\nHeapReAlloc\nWriteConsoleA\nGetConsoleOutputCP\nWriteConsoleW\nMultiByteToWideChar\nSetStdHandle\nInitializeCriticalSectionAndSpinCount\nCreateFileA\nHeapSize\nSetConsoleCtrlHandler\nFreeLibrary\nInterlockedExchange\nLoadLibraryA\nLCMapStringA\nLCMapStringW\nGetStringTypeA\nGetStringTypeW\nGetTimeFormatA\nGetDateFormatA\nGetUserDefaultLCID\nGetLocaleInfoA\nEnumSystemLocalesA\nIsValidLocale\nSetEndOfFile\nGetProcessHeap\nReadFile\nGetLocaleInfoW\nGetTimeZoneInformation\nCompareStringA\nCompareStringW\nSetEnvironmentVariableA\n.?AVlogic_error@std@@\n.?AVinvalid_argument@std@@\n.?AVlength_error@std@@\n.?AVout_of_range@std@@\n.?AVbad_cast@std@@\n.?AVbad_typeid@std@@\n.?AV__non_rtti_object@std@@\n.?AVtype_info@@\n.?AVbad_exception@std@@\n \nabcdefghijklmnopqrstuvwxyz\nABCDEFGHIJKLMNOPQRSTUVWXYZ\n \nabcdefghijklmnopqrstuvwxyz\nABCDEFGHIJKLMNOPQRSTUVWXYZ\n.?AVexception@std@@\n.?AVbad_alloc@std@@\n3/9*"?8\n19-<-,9\n+04?21\n .--,,99\n' !>?=*3\n+042>1\n'<%3#?\n(5"#6((\n4)2052>><\n325"&7\n1663/.1\n&+#+.7\n*--9$%\n702;(!\n4?*<) \n*)*$=80=\n:(&&=$\n-'0'+$".:5\n*#<#-*\n+5$86!;'\n88#5**3"1# %\n":&<!,;\n66458)3\n*+!3(($\n';-(/:\n,')2052>><\n5)%&$8,\n,9<.&\n+0<'!;!\n?20753(69#\n8"(:1>.!\n: , =: \n(-*?1\n#9?;"&\n"0 /2$3\n8(6$$.\n(=)8 ":6\n<<("4.\n.=6-0-'\n899("+\n0',0*2\n);"#3)<\n'9&114.\n*1$//!\n(5=7)*\n/')/'&5\n97 ;8#\n<3$76<4:%\n;3736<:\n*,.,*'99\n*?/:,\n"4759+/9.\n4?&+3\n8 ))<>\n'3);,7$5$\n"'1&,7';\n:,300)<&?.)\n7'7'((.\n&352.:\n-*:>,#\n? -+ %\n/2%9;6\n#71*!#\n-,>$0#+*&<;\n9;+9:/\n176;916\n54>*#6\n)$<24<\n>.0;5!-\n602,.9/\n0>!*6%5\n?!1*"5>2\n)/?>(85\n"42)7$\n *-/2\n8#$>($\n79=&<9?\n/6),+:\n&??.(7\n 140;\n4:4'+<!\n,:*4/>\n8<<*+7\n+7::7:7(? ?\n64.7-0\n($/7<.+$8)77\n<%*;34<\n=* #-6\n9,44#(;.(\n1#0+%2\n>89<5'.$\n<9:0<'\n93(22/\n54?598\n%56;64127,0\n *$6<#8\n.6:182#<#/\n$1=9?8?\n#2%96,\n-)#7*#\n!/2 6: \n9$+757\n<#-+:*\n75:&.?\n042+$<;\n67 ";2\n7.?#:-+:&)\n=%/$+:\n!*023\n.%6".8 4\n990'*\n4(!>$9\n(,=8"28(0":\n!.<%#\n;9"-$$\n/ =55< \n>#6:7&&2\n732#$+--'()+9\n0>"&")\n#9( >#0!"0"\n5%?$)&;\n< ;251&\n:>)111\n>,6<3$4/34\n,$%;)"\n(8(-.#\n.94<);\n$-***2!\n26(4!'+="\n*6 :#*\n>$9? 3\n.5)<!/\n6+/,)/\n5)?1!=\n.-#$*%;\n7;#*\n2:1; *\n07#=(-\n%()>#0;#=1$ )\n$>8?>,\n$+=&.:\n98-=-=\n%?=-8"&*7.\n843,#3\n"!987?,4\n.&7-- ,\n>#, 2&;;2(\n-?5=&*\n:-$#57\n;:835\n%(%0#+\n/$:;'#\n3>*71'\n'!,*"%\n*=$,,)%%53\n-9)>=;&9/7(,\n"24.+9\n!88/5$\n!;9<53\n%&#=+<\n7*#';!4*'9\n&+938!\n)99%/30\n75' $*\n7=7%14\n36!;<3.\n8:49$/\n; 5%>\n85):>71#(\n5=%",#\n4"%<?-3\n&(/,/+8\n"8? #!\n2 #%2'\n9&7-(+\n=5%%>?\n,;7(<;\n7=<-3,?)\n+93#5\n'1-*??\n),*5#\n025'6$1:\n45-- .\n 11-=19\n;4! 3&(5'\n"760(\n(.:=%$\n50&(4??\n2*$$"?"\n29!5$ +7\n"4 <;-\n)+6(837\n?=1= <\n6:**:<2\n*;65=&4\n7%7=)4?\n!/283*<\n> !. ->5\n=,"#?1:,:\n1*)1-8\n5'/&6'\n?-0+-&\n.+2(6?\n/&#3<;\n!+/53(<4'<\n;""50'\n#&4"5\n7 4;-23\n5.923# 9(1\n!266!&9&>\n %<6,=\n--$+50>\n; 2<<\n<'5,(\n4!66\n85 06+\n=(1$1*\n$%728&--<%)\n;1=>08\n<2'6>4"+\n4+)64"1)%-\n3:<;? \n32>,?18\n:1%=9>\n0"/'/)!%\n>?'3*1\n3*2=9 \n8'92*7\n&+$?9\n6-.(;4\n/!:+& 35+4"\n2$$?,)+0\n+ 2( (-7\n#( 4 6%\n(,/7-((\n985 ;\n,&581$\n>63<->\n.-!4$:59/\n$-?30-:2*>\n* +-9328\n$08).)*\n%0394+\n;>)!98\n73,5?-\n>!/8+)*?.)(?33\n>0)1+;\n-;#2="\n%/0&8*\n!)1?/$\n>$)"&>3??\n'<9 '<\n,,>'9#\n,%4?8$899#3="\n?(;#*,\n(,:(%\n2+..73\n7$;1?4\n,;6)65\n8,0=>.\n%56;,3>\n0 5 0->\n.5#66.00*\n,??,$:\n-73=83%0\n%.:0"!\n?+4+#5'\n ($-:(\n-='8)<2\n#>734(?\n,"+#4%\n63$13:,\n/>-73%\n+% )75?-\n)#"=%6\n)6#)'+\n 20?25,0\n!'0%>*\n7'02\n2$>--=\n==!-*'?9\n+"-";!1984\n09>> 3?\n.&>,?+20\n#?-43"\n;;.?(0\n'>: +!\n,/0: 9\n$<%*.\n464,75\n966 #6\n;+?3$49\n,;1&,+:\n?!5&+\n?;4':=\n5&&5 1<\n/92..8 \n&># 710&\n .,$5)\n!!290'&\n'1,68,\n%6;/<=8 \n"*2/4+\n+(?;><\n:/*#,?:\n)"$;,:\n>#%1&=(\n"63" 8\n#339>.\n"?4#616.\n,*7-!5\n-$5(<=!!!;;\n!67>#"\n<7>(#/6\n11-;>-'1\n1!)4)7&\n"1:6'86\n!,7+ .\n#'+"6; \n"'$1.0"\n:48< %'\n>(!%619/\n(476#\n1-2%9>\n039;++\n!939:8.\n.-,276!\n;><83\n11-#474\n7/6:';"\n( 5# -5\n:!+1:?4!,\n0,6=\n*':;.>"*"\n#>/##\n=2226(3*.-"\n!-/--3\n(8!%'2\n8$'5>#\n-.'"$6#\n88$9<=<&9\n!!5'9:\n$#$+7'\n3=*7::\n= #,6>(\n%;4;'5<\n7.#1+:\n?#-8&2\n$%=+80/0\n0?819+<#\n850(9!\n83.(=\n(!33,8'\n%*'8!4\n+31/2\n<'!82!6\n52: 3 !;\n=-& ':%\n;9$&;13\n(50)+:\n>;591)\n$'2:#0\n+?.(=48\n(!-..'\n7'?-(5,+5%2\n#5?:7<\n$1 9(#;/\n<.(%$2?\n-6=)+"\n6$!7/6=<\n!2/','\n!3"&"513\n'9=974\n+7&%&%\n$<-"6\n' =#$$5\n 0*!?+4>)\n00#4?\n%'$%!(8<%,/1\n((*24#5\n$>4+,$\n$.!;&=&\n"$>4/9=\n+ 6'14\n#:0%7$#\n!6*;;.\n5$?4''=6)'\n(72:8!\n543:>+8/\n1$83578\n0&9/ &5\n:(&.0?\n(57+5\n33?7\n7936+!<%=\n"3?)89$%(\n!$32*=\n/(567<\n0=;*$,\n<%' &":2\n ;><=(\n(*?:">&1\n5#&?&,\n=;%!<9\n!%<5(24\n$!2'5!&\n082/7<\n0)4397?\n(?'76-9\n&$34*,\n0"30#&\n80$?)'3\n9(.5 >\n#!&9)\n%7/=?(#\n+/<7$\n5 -2/)\n,!44%)#\n4!;*-4\n?6-++) $\n2;5.5\n):.<6'7\n-1'%!1\n%570#464 \n(74&24\n&:%!9/ ?\n, '),+\n$&,;<%\n! %: ?!"2\n27')*\n"=-'&-\n01=9-/\n!'56=0$6\n05< ')(7.6%\n+/'#<%\n*'63"\n6&+!0.9.\n:6#*$ \n888-7?\n5*?4.!"\n?'&$6%>\n;2&"0"\n2<11-(-\n,"#(682\n:$:?"6 "\n3 9/<=**'3\n+77!$%\n5$!<96\n; (!416\n/:*0#\n-217:7\n:=#'%$0\n%7-,8+\n#;)?%.7\n:#+,#\n?825>-"\n- <-/:\n#+>;6:6-\n$/:6.%?8\n))9)#)(\n"&"!&4\n): ;10=\n#57,=:\n<=<9$-\n" ;,=?7\n2'&<5>\n=80'<*%8\n# :34"7\n2.2#, \n&,:+<=\n/%">""/6\n4'73>"\n&&? $\n("0,&9\n3/:2$=$\n(01.05\n#<>-.-\n#'% =5$9-,\n/&5;4:-2\n-13>?4\n=529<=\n=>=+9.$\n #8&;?(\n9;987$$$\n+ ";!(*:?\n+957&\n'&?883)\n'&19=?\n&&8+8<56"\n#4;(%;\n&181.\n<=7=2=$\n?-4:(.\n,>';%4\n.: 50>:\n!%7))8\n61.>5-\n4.'<:51\n;6(>06\n%+435\n>+( (.\n243=)-+\n$32-?8"\n+-)++;\n)*<>\n..52>$\n7*341,+>\n++#':%\n'%>(*/\n=<=++3?\n"+'306\n*.>!;=\n"+% +:(<\n5&#8?.\n;1&%("\n7)6!,,7\n; 4-=!9\n;,.8")==$\n5/2> \n9+ 80;.7\n< 4= 7--6\n<$3 ))3%38\n1#!9:;\n<,.%-6\n8+/'15>-\n !:!)?\n!&!6758\n!+65$7\n+!-,<$\n"+9/"5,\n9 )-;:3\n;(6/9\n6(.%(+&\n1"5<#<1\n7>8=$2($\n8*$,4-5\n0&<"9.3\n%1=%2#?\n%<"< :!\n<'9 7+\n5:""#\n'"26)1\n&-:0"/\n11,*$(4\n$);7',%1<:\n947>:7\n?<%5'2\n$ *.=()\n+;><'+2\n=4 *(.\n"&6#29,\n5<(?=-\n?/(99-9<(,33#(\n=,.8(9'!\n-+;;*\n8>6 =0%#93\n!2!!!#9\n,)9*91\n7=&.11\n1*/++90(\n266< *=+\n:/*1!5)\n-)=2(7\n;.,<!)\n!=<8#5\n''312"$\n.=%1+?\n&9%*)\n=9.6=62\n)4/27#\n0%->.,<9\n;#=3%<\n%-'<(2\n!>$%>2">\n!(;+8#+*\n85%>"%6.<\n%?*?3*=$\n3=7)-(\n#1#/4\n> %&,'>\n%1(?0+*1\n?,<+(1!\n$&-0<\n/)5*1+&\n55 #4?+=>\n#,*'7&\n#&2"&,\n" ;)?*\n "("%=1\n2".$;3\n;.+"#$0\n<$11'*\n706&<#.\n :4//'\n2/!"==(!-\n1;?/9;3\n$?!*+$$\n& %)6>\n7,*0:'\n,=*?>70&/92($\n 6%4)6\n:%*=7&'\n !1:%(\n;;$< \n4$4+5#=+\n##%%&"(/\n1.-*<19\n0( :"'\n"(?.6)4\n(=)$=#\n!6/2, &4\n-%(18:\n*9?%;9\n>? .;=\n:* $?0\n720)%)\n'!0$-$#\n;*"<&..91\n5$6")7:!\n8(%"* 6\n8-&4=#+\n;*#%&6*\n+?(->?\n%./#90!,&\n203#9 \n66<*750\n$<06,)9 \n/%!<&-\n!...#$:\n-7,2)3\n?3##=%1\n6&-<+/.\n;98%!/) \n>; 1;6\n56' #7\n-3$$?5+\n9..!-.\n!-0)$/\n2'3?02\n97:% "\n.39;,&:"\n4*!(.0% \n%'!=$0;\n33?5376\n<(2;?(\n72#%$9\n0:2)<%\n'7#3<(\n*"&3""\n"%5: 7933\n.2=,9,">00\n7>+*->.=\n'9+4( \n4%0.1<?$\n3!$,*8\n;,331$\n3%5:6"+,\n5-<67<\n*'61,??.\n;#.:=<\n'2& 98:\n92/0<&(\n4:%!878,\n<>%$>=\n-:$7%(-11\n70< 27$>0\n6*'(*(+\n"3/!74\n ;(++<!-0:;!"1\n;!+ :/\n6;:)1/"%\n%"! -0\n=/&,$?\n>9:>,4'%\n)$'%8&=;+\n46$)82\n#905 \n8-<$&>1!*14\n $,!&\n#,"'##\n9/9( .\n'$0%)$\n)! 3=62\n)!61>=\n0/7)62\n/:4-.\n.)#2,"\n:3)7$\n32; %'\n)!>8&6\n74 ./,\n$=;,'5 \n3076<4:%\n;3736<:\n5$5.>\n80995+\n136=20\n=*%9'28\n3,3"76\n62%?-:\n/)26>'2?\n,2/;5+/3\n.54)#8/\n3;65:'!;8.\n"1#&>*\n) 8-959%#>\n:/'9*0/8\n'+0$,?\n;&?>%0>\n9=7>-/\n"((2#+)( \n,+'-:&\n<2.18-7:?&*<-\n8'.%,\n*#+/3\n8,)506\n%6:"(*\n26-&'.\n#0)8:6 \n>09,)$\n-609:\n=$(# 9\n6=%<$'\n6,1*59\n,4$97*4\n6:+.68\n9#<2#=\n.3<30:'/+\n%0>%92'"\n/0*14:\n(09:3/\n:-4<+2)\n#/;,4\n:=4><6\n*&-'6:?\n?&%>0?\n;>$:)-82,\n4./>? 68\n6+7 5=#\n5;*/47\n7&8-25'-\n7!-=*=\n1/2$31\n361,!)- 33+\n7?/05.*0+\n-$;6;14'?'(\n?476#!\n9$448"*\n:>13>$'/#/\n443 )8"('3.\n;.;.=/\n5#2+/,\n!,)(!-\n/#:!;6)\n.#;#+*6\n65#%*+\n!,6=61?\n< /'5*<:<\n7(0?#;\n/!'0&)\n#3107-\n$'8 ;:\n>67!&(>(?,=\n=":=>&.-\n/86,)$\n+="##2=\n/??999<.1\n/?/<3!<\n,2 ;%/5\n/!<*<-\n ,3!8$+\n#/5.;39\n6(01%*\n2=("+2!0#4\n9:?+=9\n!.8$&-6=8\n.)8/7$\n'>!3 ('\n&$7:("\n'/->>4 =\n&"<'7'$\n435"+49\n*5&01=\n$4',<.?\n'/#&#;\n%7+-'1*\n*+>71\n5> ?-#-\n;2"!*&\n#%61/) \n':?7+?\n-!?967(\n)")<9?'?\n1?14#,\n4=964.:\n=32; 8\n8:+%2&\n7%*38&\n)3%56"\n +>*10 \n$>;55\n&;.<>,1\n,+4!$!56\n$>80>,\n-+':4:-\n)>'<8"$$\n'#-38';#\n>##+--\n4?83./!\n(,<+:'5\n##(*?,-2\n!8&%00\n:5?2>"\n!8(;%(\n *+# $5\n=7/:)$!\n67+;:05\n6!<"<4*\n0'&!!%'\n#7>5/\n5=:,3++&\n5'%5)6\n9:*-21/\n;!0jR;#4\n2z;=y6\n&k__k9\n0 0:0I0\n182=2c2h2p2x2\n5:6N6T6Z6`6e6q6w6}6\n7#7(7-737J7S7]7\n8&8.8;8E8\n>">(>.>4>:>@>F>L>R>^>}>\n?M?Z?m?\n0;0L0V0s0\n3:4R4j4\n;?;F;L;^;f;q;\n01X1}1\n3-3S3q3x3|3\n3V4a4|4\n5 5$5(5,505z5\n7*757R7\n9E:M:b:m:\n;'<:<U<\n2I2n2Q4M6Q6U6Y6]6a6e6i6\n:%;7;x;\n<'<^<o<\n==0=S=\n1l253f3|3\n6l6s6}6\n7&797L7p7\n8%8-838M8\8i8u8\n:\;d;|;\n>+?;?h?p?\n2?2X2_2g2l2p2t2\n3N3T3X3\3`3\n4!4K4}4\n9?:T:j:\n; ;M;h;n;w;~;\n;%<a<w<\n=&=6=K=\n??*?N?W?^?g?\n010I0[0q0\n3b3m3w3\n55$5*5\n66@6F6x6\n7!7I7b7\n778=8a8\n9)959J9Q9e9l9\n:!:+:1:=:L:R:g:x:\n;&;;;a;\n=d=t=z=\n>%>+>3>:>?>G>P>\>a>f>l>p>v>{>\n?)?/?K?{?\n0:0G0S0[0c0o0\n4)4.4>4C4I4O4e4l4\n;(;b;o;y;\n?#?+?B?[?w?\n4&4P4\4\n7:8S8d8\n232=2I2R2\n3.373C3z3\n4#4/4H4v5\n:":&:*:0:;:J:\n;0;5;x=\n>%>B>H>S>X>`>f>p>w>\n3.34393H3Q3^3i3{3\n6D7J7q7}7\n8U8(:3:;:V:d:l:y:\n1=1p1z1\n1=2Y2b2w2\n3#3(363\n4-4A4G4>6\n6)7<7X7j7}7\n:+;T;q;|;\n4,4;4S4r4\n9!9&919>9L9Z9h9v9\n=&=6===Y=:>@>Q>W>`>g>n>w>\n1"2C2T2\n6 777<7\n9f:x:~:\n<*<a<e<i<m<q<u<y<}<\n=%=+=7=>=G=L=c=v=\n282C2}2\n333k3u3~3H4S4X4x4\n4 515@5`526O6^6n6\n6*7H7d7\n838A8Q8h8\n>6>F>Y>\n60A0R0l0r0\n1#1b1q1\n393@3G3\n090A0V0p0\n1-1=1z1\n839r9w9\n=9=>=_=k=~=\n00%0+010X0\n2F3T3b3\n44#4'4@4\n7 7H7M7R7W7`7{7\n8$9W9a9g9t9\n:;$;+;0;7;<;\n??7?=?L?R?a?g?u?~?\n4!4,4\4\n0*0<0N0\n9(929]9e9\n192L2{2\n8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d82=\nh>l>p>t>x>|>\n1G2M2q2\n595V5r5\n3#404P4j4\n4X5=6C6y6\n(0O0j0t0{0\n202i2v2U3d3:4s4\n4$5\5b5h5n5\n546=6C6H6`6z6\n77.757B7b7l7\n94:=:a:g:m:y:\n:!;);5;B;I;Q;Y;a;j;s;\n123k6r6\n=*=3=?=I=U=`=\n3:3F3U3a3\n7$7*70767<7B7H7N7T7Z7`7f7l7r7x7~7\n8 8&8,82888>8D8J8P8V8\8b8h8n8t8z8\n979I9S9e9p9t9y9\n2T2X2\2t2x2|2\n2,:0:4:8:L:P:\n2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2\n3 3$3(3,3034383<3\n`5h5p5x5\n6 6(60686@6H6P6X6`6h6p6x6\n7 7(70787@7H7P7X7`7h7p7x7\n: :(:@:P:T:d:h:l:p:x:\n;0;@;D;T;X;h;l;p;x;\n<,<<<@<P<T<\<t<\n= =(=@=\n> >(>4>T>X>\>d>x>\n?4?8?@?D?`?\n0 0@0`0\n1(141P1X1\1t1x1\n2,282@2p2x2|2\n3,303L3P3p3\n4$4@4L4X4x4\n5 5<5@5`5|5\n6 6@6`6\n7 7@7`7\n8 8@8`8\n809@9T9h9t9|9\n0$0H0h0\n3@6P6\6d6l6t6|6\n=(=8=H=X=|=\n> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>\n(null)\nmscoree.dll\nKERNEL32.DLL\n ((((( H\n h(((( H\n H\nkernel32.dll\nAFX_DIALOG_LAYOUT bfb9db791b8250ffa8ebc48295c5dbbca757a5ed3bbb01de12a871b5cd9afd5a
... ... ... ... ...
2395 Ransomware M !This program cannot be run in DOS mode.\n`.rdata\n@.data\n@.reloc\nPj8h0XT\n j8h0XT\n+F(_^[;E\nF(@@;F,v\nF(;^ r\nF(;F0u\n^(_^[]\ntuhP[T\ntdh<[T\ntSh([T\nS\_^[]\nS\_^[]\nt39w u&\n_ 9w$u\nHt;O u\nu=j0^VP\nSVWj(3\nPjmhHjT\n jmhHjT\ntj9~8u@j\n9~8ucj\nF4_^[]\n0WWWWW\n0WWWWW\nQQSVWd\n0WWWWW\n@@BBf;\n@@BBf;\n0WWWWW\nAAFFf;\nuBh{"A\n0SSSSS\nHHtXHHt\n>If90t\n>=Yt1j\nj@j ^V\nHtHu4j\ns[S;7|G;w\ntR99u2\nURPQQh8:A\n_VVVVV\n^WWWWW\n0SSSSS\n0SSSSS\n0A@@Ju\n^SSSSS\nj"^SSSSS\n;t$,v-\nUQPXY]Y[\n0SSSSS\n_VVVVV\nt"SS9]\nPPPPPPPP\nPPPPPPPP\n<+t(<-t$:\n+t HHt\nt+WWVPV\n,L) _\\n(R^g_&\n>SZYw<`\nszl26Z\n8) dMU\nTOB3*q{\nc,[MthW\nlx12O?\nC-}y`X\n-' b}u\nuC,kj\\n}v yKx+B\n8Z;HDO@\nff1ynr+\n!HhJtC\n<O`mN\n^tYL3Y\n<X%LAgP\nJQ9{dj\ncvYYKX\nIUC!R<\nk~:7g}\n;`U~\ "M\ndtQPWD\nm[u$SX\n_EdSE5\nL'+?qs\n(6X9SQg\nx^q]te(T\nd'EppUEV\nin.1Hy\n0taL}M\naJ24)Y\nPjQJEv\n5tI\':5\n.y74pa5\nttam~S\nCe[ET'nR\nCpVSR9\n?JIho~`\nj@j6B2i\nvEd0VB@\nU$VPtd\n#K%WJ>WZ/c"\nfHK1OOs\nVT&t`\n_YfKzG\n(VU_Tj\n>NB.Ub\n)9e?pR\nIIQHxS\nd]6d3W\n,Op<0Ih\nEaEM$HP\nMK~AxL\n3)Iu(_\njPjEPM\n"XIPY(\n`m)=H*\njU^sN*V\nt0bx`M\nk1rfJ"\n5`W>k&\nAx5bsB\n/!NEdk:Fl\nMj!%[a\nlw&4TU\n(!G2?*S\nyq9Q`F,\nkt=W,,\n]QME9p.\nu<c]p3\nctbbvW$\nd0P9EvdW\niZ~2Lm\n"?WtLFFJ5\n7^NjLz<O\n8}|/CW\nf#k(wQ\nvd$<1\\nRdjdX<\nPQCpD'\n=L:>b{3\nO<ZR6:\nxSEP<8\nh4,;3W\n|HCB0Y\nl:gi `\nBvbnCj\n&1$mgQ\n')$PM[1\nlP09x7\nfV`^M]\nWEvJFMEjV~\n%!,/$A\njY*u_/F\nhjfONb\niE%vV@:\n;k,,[iA>\n2$D3| \ncDc#In\nY3_n(CS&\n9KD}R\nUxb{l5.a\n8f `RQ\nz@>gh>okA<\nc9@`g~\n>S{wpg\nWL5=0K#\nRj($.#g\n(,}0m`\nWX$Mfe\nVwSUdk1\nW_MdL]c\nrq{3L&\n}$[LnP\nFtFhS\nO8EE3F\nK1ui*^9\nr.`#QX\n]x<]dM\n>!w_\/m\nF':|gW\nmsJ|@I\n5N3K*%\nLMGy\Y\nY4o6M6\n#_4)|ePU\n7/`4DX\nF]mo4%\n'?\-47\n:W> <J*\n3$p-XXhH\nDYBG-qe\nj$-hh3\nQ]uEWP\n6#d<Eo*\n|*DgDj\n~,X{,}-h6\nHJ(@(q\njPu]Ed\nS>:,*c\n#^jY]D\nEEJttW\nIqAobl\n]KIXxl\nd$c4S5P%\nqBiUkQ\nFoQ9Yn\nT#/+53M\nHrs#||\n=xs#'2\nj]]~EuU\nq_Fr(.\nyN<4~e\nB4S&CXS\na\mHFH\nUUu,3d\nNuSPOoI%\n!yeMG"]9\n\Ng[=g\nGe@1.&\ngy.qC\\n5hGXhQ\n.(pO+AaX\n,u?F3i!\nSp;7Fc\na%UnZw\d\nmsaD,J\n&VF^GO\ndE]jt]\n@4QL?\\nE]abE^E\nPXTdVE\n^uVr*)%\n3Qd8PQ\nM^]EES\nKO}pjC\nE3EE{Ejf\nz<klf}\nEcaUEI\nP3EcdE\n@jE*,%P\nuE4j ;d\nMdM4]}\n]tVjME0\nW^v0]W\nEdCPEV\nPMEWFl`\nhjYh$V\nYuF6E5S\n9IM3d&\n_P@uEM\n>qBlFMd\n0~P^oQS\n]8$ddG\nk]JuP,.\n^@t_>h\nEh_PQd\nP ~8$h\nW\Q5fP\ndPjPPdP\n[} hdE\nGFMWj3\n}UPF~P\nE]E[b:\n0E3_0WE\nWhT@QM\nPtFQX;\n3Nj^gj\n$]aEjO\n3]tLbPE\n^3E5Jv\nM+udc@\n7_8UOc\n0_3MAjF\n]EQVthdj\n~\tF^E\n$]~Y0H\nPdW30]\n]9UMQW\nY]%Mue\n^EWuUJ \n~ cVME\\n[3G$3~\n;QY}M]M\nfu,t3\n3LFuMP\njEZ^PnF\nE`j)5R\nu]hhAhU\n8]QW3W\nPdtT^_\njFV@lN\nPU^xE}\n^SM,3v\nErWdtM\nM[c$\Y\nNWSu],\n]M_E][x\ndHdW]W\nS]uKEnpMEW\n5PQcMF,\nUWlD^5E\n^UY]VQ\nZaEa_MM\nM2MWh^\nXF,@;3\nB_EEVP\nE]thE8(\natP3x]\nWPE~jM\nYEjfMa\nhsEAuE3tE\nkP4_MO\nMEWdcMc\n ?XEhd\nVj4E}\\nEu%QW2*\nuJP~%R\nvEB6^d@\nVtjYtF\nP!2XuG\nWvM)Ut\ncVM8M2uf\nV3UE]~\ntX)Ep^\nppda@(u\nTPEAEvP\nE0Y]PW\nuQ@c~P\n8%uVtd\nME]8'EW\nV_3MMVQ\nE0tthK\nP,MPdE\n3PuXdP\nE^dEEU\nE<3jLP\nud15YW\nSWQUUF\n340FWP\n5}M.0\nY]EcFEx\nPPEE@PW\n^P&hF_P\nUAFY;]\n~tQQ0;M;0\nKFyYutP\nM3^;j`\n0/p u{\nFEapPf\n]jFE'cY\n~dE8]t\ntAeaY0\nPY3W3E\nu_Wvvh\n<AWYC$]]]\nFWW]_P\nHhWEEP\n~^MdW]\nQ3_Jzd\nt_ZPW6\n>@tWhn\nWtVMd:\n~0$du)\n<YEXu;\nEEuvRE\n3`M]^[\n[[G8]$\n_P~=3]\n|NuE`h\nvdj{3W\ntEv@d3\n^_]QS^\nEV'tdj\n0P^j$M\nPE}uE_\nucYE]I_G\nG^c]CU\nd3^]Mu\ntUEdEF\nOGEdU2\n`EEE^e\nEMVU8E\njsdcv]D\nVWcvauE5\n]M_PE0\nHGuFMM_F\n:+S$dd\n%W3jPV\nuhpHcd4\n;WMlF,E\nj]MBMM\njV]EHDh\ncxEjj~\nU@uIEu\nctMW#uZ\n @Qj]T\n]jEd]v\na:VG<t\n0jtP8$\n3VtuEE\nu?$rSd\nWFGbM~\nE^SPPu\nEE3uVs\nEEEd,j\nE~G(/K\nPFhY~V\naDAUeE\nVMUStf\nMt[PdU\nYRu^S~\n@hdM4P[\ncMBdePP\nEfcVMA\n+M[[fu\n^ut^Eh\nVhEthF\nNEwP&E\nEX]sQ]\nMP^EYE$\nkQ*]MEx\njSQ;]Q\n+P'_3O.]\nEAsU]E\nj2F_Vu\nGMrMP]\nuM]tMd\n^G~UcL\nc][\PD\n^-PSP0\nEdMME4\n@EP][Wj\ndPU;_Ed\nDVY]EN\nM3VVsEW]\nVQ0uP&EV\n]tdaMc3\nPjduWU\nhB@E^M\nQuE3EE\n]]AUW?U\nFEHP3R\nTA~pdE\nWu8Jcc#dE\nEP]UPU@\n0EEESj\njS]nE]P\n}uPjPx\n{vJhWK\nhYEt0c;\n3QCMPt\n, ]pdt\nutFt^EdcV\ndY~uH~\nMOV(cuE\n0_PEfE\nW3jMQh\nV}UEt-\nd43~M]\n:B$0UI\n;UEVh3\nPQd]Ph\n32(Eu~\n-EyOh(E\nz^EjWdW\nh~ud3Q\n]WuEWd\n'vG]PW\n YMEMF\nVd,EdF\nE.fVEz\nYMYcH\\nuddEdu\n!OJ4@WE\nM]d2E]\n^QhEV~h\nhcjV@Pl\nWMM~Ww\nPjd]M3\n]0EWdU\nPp>V{b~\nF]dMcE\nts@j,(\nd~LdHE\n,MjMH,F\ne^EWPP\ndB]uXdG\nESME;~\n^e~EUP\njjM_EZ~\nETeP]Y\n/-us.+\nf7uuu@\n%\^Wr,\nk{nnnn\n****////\nm?Bh@(\n{=sy2I\n:B@Ay5N\nNu4X+\n%%O%2~\nt <ruU\nt#<ruJ\nt><ru:\nD$ SVWh\nCObject\nCInvalidArgException\nCNotSupportedException\nCMemoryException\nCSimpleException\nCException\nCOleException\nCMapPtrToPtr\nCArchiveException\nCCmdTarget\nGetMonitorInfoA\nGetMonitorInfoW\nEnumDisplayDevicesW\nEnumDisplayMonitors\nMonitorFromPoint\nMonitorFromRect\nMonitorFromWindow\nGetSystemMetrics\nDISPLAY\nInitCommonControls\nInitCommonControlsEx\nHtmlHelpW\nhhctrl.ocx\nCByteArray\nCGdiObject\nCUserException\nCResourceException\nCPtrArray\nCObArray\nbad allocation\nUnknown exception\nHeapQueryInformation\nCorExitProcess\nruntime error \nTLOSS error\nSING error\nDOMAIN error\nAn application has made an attempt to load the C runtime library incorrectly.\nPlease contact the application's support team for more information.\n- Attempt to use MSIL code from this assembly during native code initialization\nThis indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.\n- not enough space for locale information\n- Attempt to initialize the CRT more than once.\nThis indicates a bug in your application.\n- CRT not initialized\n- unable to initialize heap\n- not enough space for lowio initialization\n- not enough space for stdio initialization\n- pure virtual function call\n- not enough space for _onexit/atexit table\n- unable to open console device\n- unexpected heap error\n- unexpected multithread lock error\n- not enough space for thread data\nThis application has requested the Runtime to terminate it in an unusual way.\nPlease contact the application's support team for more information.\n- not enough space for environment\n- not enough space for arguments\n- floating point support not loaded\nMicrosoft Visual C++ Runtime Library\n<program name unknown>\nRuntime Error!\nProgram: \n(null)\n`h````\nxpxxxx\nEncodePointer\nDecodePointer\nFlsFree\nFlsSetValue\nFlsGetValue\nFlsAlloc\nbad exception\nGAIsProcessorFeaturePresent\nKERNEL32\nSunMonTueWedThuFriSat\nJanFebMarAprMayJunJulAugSepOctNovDec\nGetProcessWindowStation\nGetUserObjectInformationA\nGetLastActivePopup\nGetActiveWindow\nMessageBoxA\nUSER32.DLL\n !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~\n`h`hhh\nxppwpp\n Complete Object Locator'\n Class Hierarchy Descriptor'\n Base Class Array'\n Base Class Descriptor at (\n Type Descriptor'\n`local static thread guard'\n`managed vector copy constructor iterator'\n`vector vbase copy constructor iterator'\n`vector copy constructor iterator'\n`dynamic atexit destructor for '\n`dynamic initializer for '\n`eh vector vbase copy constructor iterator'\n`eh vector copy constructor iterator'\n`managed vector destructor iterator'\n`managed vector constructor iterator'\n`placement delete[] closure'\n`placement delete closure'\n`omni callsig'\n delete[]\n new[]\n`local vftable constructor closure'\n`local vftable'\n`udt returning'\n`copy constructor closure'\n`eh vector vbase constructor iterator'\n`eh vector destructor iterator'\n`eh vector constructor iterator'\n`virtual displacement map'\n`vector vbase constructor iterator'\n`vector destructor iterator'\n`vector constructor iterator'\n`scalar deleting destructor'\n`default constructor closure'\n`vector deleting destructor'\n`vbase destructor'\n`string'\n`local static guard'\n`typeof'\n`vcall'\n`vbtable'\n`vftable'\noperator\n delete\n__unaligned\n__restrict\n__ptr64\n__clrcall\n__fastcall\n__thiscall\n__stdcall\n__pascal\n__cdecl\n__based(\n !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~\n !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~\nHH:mm:ss\ndddd, MMMM dd, yyyy\nMM/dd/yy\nDecember\nNovember\nOctober\nSeptember\nAugust\nFebruary\nJanuary\nSaturday\nFriday\nThursday\nWednesday\nTuesday\nMonday\nSunday\n1#QNAN\n1#SNAN\nCONOUT$\nstring too long\ninvalid string position\nbad allocation\nY'#v#LN\nLa8ayG\ni0H+i(H\nO0H+O(H\nA_A^A]A\_^][\n4?1n~p\n_x<<8t3[f\nipA-2Y\nwr4zR<4\n|7;Q$}2;A |-;A(}(\nIlAwtS~\nhlshsj\n~k@zrG\n|$ ;|$\nL$ #L$\nT$$#T$\n=lshsu0\n[OFF>*\nyAWH;fv\n_PTFZU\nle9B0IQ\nHuf;HL\nMHXVMM8I|\nBOB->(H\nK!M7-601\nbgba"N\n=Q3if6\n|&l>Os]\nb\^T~{\n0$$H $:\n$6d;+/vE\n.M$$@H\nAt[IPZ\n^tIH[%\nH9IH39s\n;Htu$C-l\nd$HAtP\n0PHuHh\nX$%ILH\n\HQ|S$+W,\nPpHtL<\nAd8Hf1\nQHrMpjB\ndj8^YH\nhdhuHP\nI]:uHH\n$HHH$HT\n+L$%9O\nH$)p j\n NuPPe\nS@0wI$\n0(EfHH\naHrPuh\nLtH8HB\nGMPU;\noE_LHH\nt4&Hu A\n93T$I0\n*9H$VP\n0ukt3;\nE5MHjj\nM$jubuH\n|3$f H$\n_HIHJ<\nP|HiTTf\nHgDd]$\nMH:tj7$\n$DH$TW\nMM8HHH\nW^H$$n\nS@;$$$\n@$$d$6\nDMOQHD\nEDD$E]\nT;DupL\nH8$/x3D\nRGH;P$\n$\Ax$j\nDZUALS\n%d DropHel %s NoCo\nd:\Glass\61\Bad\paragraph\Sat\29\Water\consider\62\Lie\22\27\CatchTire.pdb\nTlsGetValue\nHeapAlloc\nHeapFree\nGetSystemDirectoryW\nHeapCreate\nGetModuleFileNameW\nCreateFileW\nGetCurrentDirectoryW\nVirtualProtectEx\nGetLocalTime\nTlsAlloc\nKERNEL32.dll\nCallWindowProcW\nUnregisterHotKey\nBeginDeferWindowPos\nDeferWindowPos\nGetCursorPos\nAppendMenuW\nRegisterClassExW\nTranslateMessage\nGetClassInfoExW\nSetFocus\nCreateMenu\nUnhookWinEvent\nGetFocus\nRegisterWindowMessageW\nGetWindowTextLengthW\nUSER32.dll\nTextOutW\nEscape\nGDI32.dll\nCoUninitialize\nCoRegisterSurrogate\nCoInitialize\nCoTaskMemFree\nCoTaskMemAlloc\nole32.dll\nImageList_DragShowNolock\n_TrackMouseEvent\nCOMCTL32.dll\nOLEAUT32.dll\nAccessibleObjectFromEvent\nGetOleaccVersionInfo\nOLEACC.dll\nwaveInStart\ntimeEndPeriod\nwaveInOpen\nwaveInPrepareHeader\ntimeBeginPeriod\nwaveInClose\nWINMM.dll\nSetLastError\nGetLastError\nLocalAlloc\nLocalFree\nLeaveCriticalSection\nEnterCriticalSection\nGlobalLock\nGlobalReAlloc\nGlobalUnlock\nGlobalHandle\nGlobalAlloc\nInitializeCriticalSection\nTlsSetValue\nLocalReAlloc\nDeleteCriticalSection\nGlobalFree\nTlsFree\nGetProcAddress\nGetModuleHandleW\nInterlockedDecrement\nSizeofResource\nLockResource\nLoadResource\nFindResourceW\nFreeLibrary\nGetCurrentProcessId\nWideCharToMultiByte\nlstrlenW\nFormatMessageW\nMultiByteToWideChar\nCloseHandle\nGetCurrentThreadId\nInterlockedIncrement\nlstrcmpA\nlstrlenA\nGetVersionExA\nlstrcmpW\nLoadLibraryA\nLoadLibraryW\nGlobalDeleteAtom\nGlobalFindAtomW\nGlobalAddAtomW\nGlobalFlags\nWriteFile\nSetFilePointer\nFlushFileBuffers\nGetCurrentProcess\nGetModuleHandleA\nGetCommandLineA\nGetStartupInfoA\nRtlUnwind\nRaiseException\nHeapReAlloc\nHeapSize\nExitProcess\nTerminateProcess\nUnhandledExceptionFilter\nSetUnhandledExceptionFilter\nIsDebuggerPresent\nVirtualFree\nVirtualAlloc\nGetStdHandle\nGetModuleFileNameA\nFreeEnvironmentStringsA\nGetEnvironmentStrings\nFreeEnvironmentStringsW\nGetEnvironmentStringsW\nSetHandleCount\nGetFileType\nQueryPerformanceCounter\nGetTickCount\nGetSystemTimeAsFileTime\nInitializeCriticalSectionAndSpinCount\nGetCPInfo\nGetACP\nGetOEMCP\nIsValidCodePage\nGetLocaleInfoA\nGetConsoleCP\nGetConsoleMode\nLCMapStringA\nLCMapStringW\nGetStringTypeA\nGetStringTypeW\nSetStdHandle\nWriteConsoleA\nGetConsoleOutputCP\nWriteConsoleW\nCreateFileA\nUnhookWindowsHookEx\nMessageBoxW\nEnableWindow\nIsWindowEnabled\nGetLastActivePopup\nGetWindowLongW\nGetParent\nSendMessageW\nGetWindowThreadProcessId\nGetSubMenu\nGetMenuItemCount\nGetMenuItemID\nGetMenuState\nValidateRect\nPeekMessageW\nGetKeyState\nDispatchMessageW\nCallNextHookEx\nSetWindowsHookExW\nGetSysColorBrush\nGetSysColor\nReleaseDC\nGetSystemMetrics\nLoadCursorW\nGetWindowTextW\nCheckMenuItem\nEnableMenuItem\nModifyMenuW\nLoadBitmapW\nGetMenuCheckMarkDimensions\nSetMenuItemBitmaps\nGetWindow\nGetWindowRect\nGetWindowPlacement\nIsIconic\nSystemParametersInfoA\nSetWindowPos\nSetWindowLongW\nGetMenu\nDefWindowProcW\nGetDlgCtrlID\nPtInRect\nCopyRect\nAdjustWindowRectEx\nRegisterClassW\nGetClassInfoW\nCreateWindowExW\nPostMessageW\nGetClientRect\nSetForegroundWindow\nSetMenu\nMapWindowPoints\nGetMessagePos\nGetMessageTime\nDestroyWindow\nGetTopWindow\nGetDlgItem\nGetForegroundWindow\nIsWindow\nRemovePropW\nGetPropW\nSetPropW\nGetClassNameW\nGetClassLongW\nGetCapture\nWinHelpW\nLoadIconW\nSetWindowTextW\nClientToScreen\nDestroyMenu\nTabbedTextOutW\nDrawTextW\nDrawTextExW\nGrayStringW\nPostQuitMessage\nGetDeviceCaps\nCreateBitmap\nGetClipBox\nSetTextColor\nSetBkColor\nDeleteObject\nExtTextOutW\nSaveDC\nRestoreDC\nSetMapMode\nPtVisible\nRectVisible\nSelectObject\nSetViewportOrgEx\nOffsetViewportOrgEx\nSetViewportExtEx\nScaleViewportExtEx\nSetWindowExtEx\nScaleWindowExtEx\nDeleteDC\nGetStockObject\nClosePrinter\nDocumentPropertiesW\nOpenPrinterW\nWINSPOOL.DRV\nCreateStdAccessibleObject\nLresultFromObject\n.PAVCException@@\n.PAVCMemoryException@@\n.PAVCSimpleException@@\n.PAVCObject@@\n.PAVCNotSupportedException@@\n.PAVCInvalidArgException@@\n.?AVCSimpleException@@\n.?AVCException@@\n.?AVCObject@@\n.?AVCMemoryException@@\n.?AVCNotSupportedException@@\n.?AVCInvalidArgException@@\n.?AUCThreadData@@\n.?AVCNoTrackObject@@\n.?AV_AFX_THREAD_STATE@@\n.?AVAFX_MODULE_THREAD_STATE@@\n.?AVAFX_MODULE_STATE@@\n.?AVCDllIsolationWrapperBase@@\n.?AVCComCtlWrapper@@\n.?AVCCommDlgWrapper@@\n.?AVCShellWrapper@@\n.?AV_AFX_BASE_MODULE_STATE@@\n.?AVCOleException@@\n.PAVCOleException@@\n.?AVCMapPtrToPtr@@\n.?AVCAfxStringMgr@@\n.?AUIAtlStringMgr@ATL@@\n.?AVCCmdTarget@@\n.?AUIUnknown@@\n.PAVCArchiveException@@\n.?AVCArchiveException@@\n.?AVCCmdUI@@\n.?AVCHandleMap@@\n.?AVXAccessible@CWnd@@\n.?AVXAccessibleServer@CWnd@@\n.?AVCWnd@@\n.?AVCTestCmdUI@@\n.?AV_AFX_HTMLHELP_STATE@@\n.?AV?$IAccessibleProxyImpl@VCAccessibleProxy@ATL@@@ATL@@\n.?AUIAccessible@@\n.?AUIDispatch@@\n.?AUIAccessibleProxy@@\n.?AV?$CMFCComObject@VCAccessibleProxy@ATL@@@@\n.?AVCAccessibleProxy@ATL@@\n.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@\n.?AVCComObjectRootBase@ATL@@\n.?AUIOleWindow@@\n.?AVCByteArray@@\n.?AVCGdiObject@@\n.?AVCMenu@@\n.?AVCResourceException@@\n.?AVCUserException@@\n.?AVCDC@@\n.?AV?$CArray@W4LoadArrayObjType@CArchive@@ABW412@@@\n.?AVCPtrArray@@\n.?AVCObArray@@\n.?AVtype_info@@\n.?AVbad_exception@std@@\n \nabcdefghijklmnopqrstuvwxyz\nABCDEFGHIJKLMNOPQRSTUVWXYZ\n \nabcdefghijklmnopqrstuvwxyz\nABCDEFGHIJKLMNOPQRSTUVWXYZ\n.?AVlogic_error@std@@\n.?AVlength_error@std@@\n.?AVout_of_range@std@@\n@A_A^A]A\_\n@SUAVH\n7FOF}|e|\nx=C;)K\n'w?(h(\nwlw?(;(T[PV\nQZQRrMrI\n7p#v[p\nhNn{Q?\n]gUx0d<DH\n]-v,a \n/%ep3cT\nE$`t?Q)\nQtDH<\nUHkTW$\npH$H$H}$\nxHJhW0\n9NemK?\ne{PtF\\niZku@z\nSwS}4%'\n=O0]tK\nwmBdNx\nT,L8H \nrzEclf\nHH`DH$\n\#^'#|\nVxH$TP\n)L& Ykm\ndKy\x5\njWHUEA\nR-C*{{\nq(a Zuh\nBHHHP\nPGHhHMH\n$$LTS$RHcHU\nuM$HBIH\nRI$itS\nD#^$@0L\nEHHHHH\nPj(9C@;\nH$eHHH\nHLHHtL\nOEHj}H\n|W:u\M8\nXDE Q:i\nf2 $9\\nHLOh[h@\nED0HHV$\n}ZHPD}\n;VpHjU\n@u">tu\ntM"L(s\nH8O$$Lt\nH$HZ^@\n0yinh$s\nPDH3H](\n$Dd$TIuP\nd dtNH,I\nG#`/VuT\nAL$P90-\nH8D 52\nDHtH@H\n$MH$\j\n`^$LTM\nDZ$PH D\n;c0\L$\nd>w$A \n%f3$pHH\nHxR Xl\ntDR@^T\nY;<TE(\nz;`HHn0\n.?AVexception@std@@\n.?AVbad_alloc@std@@\n<?xml version='1.0' encoding='UTF-8' standalone='yes'?>\n<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>\n <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">\n <security>\n <requestedPrivileges>\n <requestedExecutionLevel level='asInvoker' uiAccess='false' />\n </requestedPrivileges>\n </security>\n </trustInfo>\n</assembly>\nupM?wrN\njfFAieF\nxsOwrN\nwrNywrN\ngbE|gbE\nxsOUwrN\ngcEWhcE\nwrN6xsO\nwrNqxsO\nfbDtgcE\nxsOLxsO\ngbEOhdE\nwrN&wrN\nwrNbxsO\ngcEegcE\nxsO?xsO\nwrN(wrN\nwrNZwrN\nhdE]hdE\nwrN8xsO\nhdE:hcE\nxsO!xsO\nxsNtwrN\ngcEwgcD\nxsOTxsO\nhdEWhcE\nxsO2xsN\nhdE5hdE\nxsOnxsO\nhdEqgcE\nxsOFxsO\nhdEHhdE\nytO%xsO\nvqM8wrN\nwrNuxsO\ngcEwgcE\nxsONxsO\ngcEPgcE\nwrN.xsO\nwrNjxsO\ngcElhdE\nxsOExsO\nhcEHgbD\nxsO#xsO\nxsO_xsO\nhdEahdE\nwrN<xsO\nxsO|wrN\nxsOTxsO\nhdEWhdE\nxsO1xsO\nxsOrxsO\nhdEthdE\n~W7xsO\nvqN0wrN\nxsOsxsO\nhcEuhcE\nxsOJxsO\nxsO(xsO\nxsOhxsO\nhdEjhcE\nxsO@xsO\nxsO xsO\nxsO]xsO\nhdE`gcD\nxsO7xsO\nxsOzxsO\nhdE|hdE\nxsOSxsO\nxsO.xsO\nwrN0wrN\nwrNowrN\ngcEqgcE\nxsOIxsO\ngcEJgcE\nxsO)wrN\nxsOexsO\nhcEghdE\nwrN@xsO\nxsNxsO\nxsOZxsO\nhdE\gcE\nxsO5xsO\nxsO,wrN\nxsOlxsO\ngcEnhcE\nxsOExsO\nxsO$xsO\nxsObxsO\nhdEchcE\nxsO;xsO\nwrN+wrN\nwrNk}xR\nhcEk^Z?\nwrNDzuP\nwrN#xsO\nfaC)zuQ\ngcDj=;)\n4:45,5O5\5b5t5z5\n7 7W7b7s7~7\n99/9Y:\n=,=V=y=\n>8>F>M>W>h>o>v>|>\n4+5N5q5|5\n9%:X:h:\n=7>K>U>m>\n0)1Q1j1\n5O67Y7\n:=;B;M;_;d;o;\n6#6.6^6v6\n6U7c7v7\n<M<p<z<\n=$=,=;=G=M=S=Y=_=e=k=\n>M>[>s>\n3h4w4{4\n475>5E5v5\n;+<E<M<\n>(>=>X>g>s>\n0A0F0K0-121[1m2v2\n989c9v9\n6B7i7q7x7\n8#83888i8\n:+:E:J:n:v:~:\n2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2\n5$5U5]5\n6"7=7E7\n;E;_;w;\n0-1"252S2^2{2\n2A3P3s3\n9/9L9q9v9{9\n: :E:J:O:\n;-;V;h;\n??&?,?>?F?Q?\n;3;V;i;\n=F=L=X=\n4 4$4(4,4\n5D6I6O6S6Y6]6c6g6m6q6v6|6\n8P9X9^9g9n9z9\n;G;b;h;q;x;\n<<$<4<><E<P<Y<o<z<\n=D=I=T=Y=w=(>5>\n?(?1?<?H?M?]?b?h?n?\n00'0,00040]0\n2=2D2H2L2P2T2X2\2`2\n4$4+4C4r5w5\n6$686>6G6Z6~6\n737A7F7\n:":(:-:6:S:Y:d:i:q:w:\n;"?.?a?\n6%6,6;6G6T6x6\n77(7L7{7\n9,:J:p:\n6!6(6,6064686<6@6D6\n7,73787<7@7a7\n7*8084888<8\n:@;M;V;\n;:<E<O<`<k<\n>/>7>=>B>H>\n090?0q0\n10262Y2^2\n2$3*353A3V3]3q3x3\n444C4J4W4z4\n4%5+5G5_5\n5"6,6d6l6\n7!7*767;7@7F7J7P7U7[7`7o7\n8%8G8j8w8\n7=7F7R7\n5?5e5M7{9\n1<1b1J3q5u5y5}5\n2(2o2t2\n2E3N3T3\n7"71767@7N7\n70979=9d9\n?7?A?T?x?\n2 2(2?2X2t2}2\n<m<!=A=1>Z>\n>G?Y?f?r?|?\n203:3R3Y3c3k3x3\n7"747F7X7j7|7b:i:\n; <1<l<\n=*=9=G=O=\=z=\n4)56'6\n060o0|0[1j1\n677D7W7\n9'909C9P9b9n9s9\n:":0:C:O:a:}:\n;";2;8;@;];i;z;\n<$<,<=<E<O<c<j<y<\n=$=F=e=k=t=~=\n>@>M>Y>a>n>t>\n?!?1?6?Y?a?o?\n0'02080A0K0V0]0l0s0y0\n1;1D1J1T1^1e1s1z1\n2!2*212;2@2G2l2w2\n3$3*3;3F3M3V3^3d3l3r3{3\n4#4/464=4F4L4R4W4b4i4\n5!5(51585?5a5|5\n6&6-6M6Z6c6n6z6\n3#3<3C3T3i3y3D>I>O>U>[>a>f>k>q>w>}>\n?#?)?.?3?9???E?K?P?U?[?a?g?m?r?w?}?\n0!0'0+0R0Y0d0o0\n1"161=1M1]1h1s1\n292E2P2_2i2\n3$353>3O3\3e3q3x3\n4(4J4U4^4h4\n535D5K5_5\n6 6'6/666C6K6Q6o6\n7%7,737@7G7T7o7u7\n868N8[8`8x8\n9/9R9Z9`9p9~9\n:":R:Y:h:q:|:\n;0;7;>;M;S;Z;`;t;~;\n<#<)<3<@<N<W<r<\n=='=-=3=D=O=b={=\n>'>J>Q>X>f>r>\n?%?=?P?[?n?t?z?\n0!0(030;0E0K0_0p0\n1 1%1G1O1^1x1\n2/262j2y2\n323?3K3]3c3\n4'4.4R4`4h4t4\n5 5<5X5c5o5|5\n6#6.6A6J6T6\6{6\n6&7-747V7e7s7|7\n8,838=8V8\8m8\n9+9@9N9T9Z9c9z9\n:/:>:H:O:\:r:}:\n;*;A;K;Q;b;m;\n<<-<F<T<[<f<l<v<}<\n=#=3=F=L=X=e=m=\n>&>->4>F>W>^>k>q>y>\n??%?+?0?7?D?K?Q?W?a?i?q?v?\n0 010B0H0X0`0k0s0y0\n1*12191C1I1[1f1\n2-3X3~3\n7/7R7\7h7t7\n8"8'8,818=8I8O8S8Y8]8c8g8m8v8{8\n9 9&9*90949:9>9D9M9R9W9\9a9f9k9p9u9\n:":&:-:1:8:<:B:L:V:`:j:t:~:\n4 4$4(44484<4@4D4P4T4\n6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6\n7,7<7H7L7P7T7X7\7`7t7\n9 9P9T9X9l9|9\n> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>\n? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?|?\n0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0|0\n0L1P1l1\n2,2D2\2t2\n343L3d3|3\n4T8X8\8`8d8h8l8p8t8x8\n9 9$9(9,90989<9D9H9L9P9X9\9`9h9l9p9t9x9|9\n: :$:(:,:0:4:8:<:@:\n; ;,;0;<;H;L;X;\;`;d;h;l;p;t;x;|;\n<(<,<0<4<D<T<`<d<h<l<|<\n< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<\n= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=\n<7@7D7H7L7P7T7X7\7`7d7h7\n8 8(8@8D8\8l8p8t8|8\n9$9(9,90949<9T9d9h9x9|9\n: :$:8:<:L:P:T:\:t:\n; ;0;4;8;@;X;h;l;|;\n< <$<(<0<H<X<\<l<p<t<x<\n=4=D=H=X=\=`=h=\n>0>4>D>H>L>P>X>p>\n?$?(?0?H?X?\?l?p?x?\n0,0<0@0P0T0X0`0x0\n1(1,10181P1T1l1|1\n24282P2`2d2h2l2p2t2x2|2\n34383P3`3d3h3p3\n4(4,4<4@4D4L4d4t4x4\n5(5,5054585@5X5h5l5|5\n6$6<6@6X6h6l6p6\n707@7D7T7X7\7d7|7\n8,808@8D8H8P8h8x8|8\n:8:T:x:\n;$;0;8;P;X;|;\n<4<@<`<h<|<\n< =0=8=<=@=D=L=h=p=\n>0><>d>l>x>\n?0?<?D?p?\n0$000P0\0\n1<1H1h1p1\n20282L2\2p2x2\n3(3H3P3t3\n4,444H4P4l4t4\n505P5p5\n686X6x6\n7$7@7L7h7p7t7\n8,808L8P8X8`8h8l8t8\n9(9H9T9p9\n:0:P:p:\n; ;4;<;D;L;P;T;\;p;x;\n; <0<D<X<d<l<\n0 0@0`0x0\n1(1H1p1\n606L6h6\n848\8p8\n:\:h:l:t:x:\n?$?,?4?<?D?L?T?\?d?l?t?|?\n 2$202\n: :$:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:\n; ;$;(;,;8;p?t?\ntDelete\nNoRemove\nForceRemove\n@comctl32.dll\n@comdlg32.dll\n@shell32.dll\n@%s (%s:%d)\n%s (%s:%d)\nException thrown in destructor\nf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp\nAfxWnd90su\nAfxControlBar90su\nAfxMDIFrame90su\nAfxFrameOrView90su\nAfxOleControl90su\nAfxOldWndProc423\nUSER32\nYaccParent\naccChildCount\naccChild\naccName\naccValue\naccDescription\naccRole\naccState\naccHelp\naccHelpTopic\naccKeyboardShortcut\naccFocus\naccSelection\naccDefaultAction\naccSelect\naccLocation\naccNavigate\naccHitTest\naccDoDefaultAction\n#32768\nf:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl\ncommctrl_DragListMsg\n%2\CLSID\n%2\Insertable\n%2\protocol\StdFileEditing\verb\0\n%2\protocol\StdFileEditing\server\nCLSID\%1\nCLSID\%1\ProgID\nCLSID\%1\InprocHandler32\nole32.dll\nCLSID\%1\LocalServer32\nCLSID\%1\Verb\0\n&Edit,0,2\nCLSID\%1\Verb\1\n&Open,0,2\nCLSID\%1\Insertable\nCLSID\%1\AuxUserType\2\nCLSID\%1\AuxUserType\3\nCLSID\%1\DefaultIcon\nCLSID\%1\MiscStatus\nCLSID\%1\InProcServer32\nCLSID\%1\DocObject\n%2\DocObject\nCLSID\%1\Printable\nCLSID\%1\DefaultExtension\n%9, %8\nf:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin1.inl\n@kernel32.dll\nmscoree.dll\n(null)\nKERNEL32.DLL\n ((((( H\n h(((( H\n H\nInvalid DateTime\nInvalid DateTimeSpan\nForceRemove\nNoRemove\nDelete\nComponent Categories\nFileType\nInterface\nHardware\nSECURITY\nSYSTEM\nSoftware\nTypeLib\nApartment\nVS_VERSION_INFO\nStringFileInfo\n0c0904b0\nCompanyName\nTheretire Great Quickown\nFileDescription\nTwenty Guide\nFileVersion\n2.3.78.74\nInternalName\nTwenty Guide\nLegalCopyright\nLicensed under the GNU GPL, v3.\nOriginalFilename\nTwenty Guide.exe\nProductName\nTwenty Guide\nProductVersion\n2.3.78.74\nVarFileInfo\nTranslation\nstrange\n&suggest 7d809e8c9b98c16647bbfac49854c28ecc3fe6d4345410deeaa79445cc50cf51
2396 Ransomware M This program must be run under Win32\n`.itext\n`.data\n.idata\n.rdata\n@.reloc\nB.rsrc\nCardinal\nstringX\nWideString\nTObject\nTObject\nSystem\nIInterface\nSystem\nTInterfacedObject\nFastMM Borland Edition \n 2004, 2005 Pierre le Riche / Professional Software Development\nAn unexpected memory leak has occurred. \nThe unexpected small block leaks are:\n bytes: \nUnknown\nString\nThe sizes of unexpected leaked medium and large blocks are: \nUnexpected Memory Leak\n~KxI[)\nSOFTWARE\Borland\Delphi\RTL\nFPUMaskValue\n_^[YY]\nVWUUh|@@\nZTUWVSPRTj\nYZ]_^[\ntChp^@\nkernel32.dll\nGetLongPathNameA\nSoftware\Borland\Locales\nSoftware\Borland\Delphi\Locales\n_^[YY]\nTStream|n@\nTHandleStream\nTFileStreamho@\nTCustomMemoryStream\nTMemoryStream\nException\nEHeapException\nEOutOfMemory\nEInOutError\nEExternal\nEExternalException\nEIntError\nEDivByZero\nERangeError\nEIntOverflow\nEMathError\nEInvalidOp\nEZeroDivide$~@\nEOverflow\nEUnderflow\nEInvalidPointer0\nEInvalidCast\nEConvertError\nEAccessViolation\nEPrivilege\nEStackOverflow\nEControlC\nEVariantError\nEAssertionFailed\nEAbstractError\nEIntfCastError\nEOSError\nESafecallException\nSysUtils\nSysUtils\nTThreadLocalCounter\n$TMultiReadExclusiveWriteSynchronizer\n-{{{{1\n-ffff!\n-{{{{1\n-ffff!\n-[[[[1\n-ffff!\n-[[[[1\n-ffff!\n_^[YY]\n_^[YY]\n<*t"<0r=<9w9i\nINFNAN\n$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)\n_^[YY]\nt%HtIHtm\n$Z]_^[\nQQQQQQSVW3\nQQQQQSVW\n_^[YY]\nTErrorRec\nTExceptRec\n$YZ_^[\nYZ]_^[\nm/d/yy\nmmmm d, yyyy\n:mm:ss\nTUnitHashArray\nSysUtils\nTModuleInfo\nkernel32.dll\nGetDiskFreeSpaceExA\n(Z]_^[\nYZ]_^[\nTFileName\nTSearchRecp\ntUI|RVS\nkernel32.dll\nCreateToolhelp32Snapshot\nHeap32ListFirst\nHeap32ListNext\nHeap32First\nHeap32Next\nToolhelp32ReadProcessMemory\nProcess32First\nProcess32Next\nProcess32FirstW\nProcess32NextW\nThread32First\nThread32Next\nModule32First\nModule32Next\nModule32FirstW\nModule32NextW\nQkkbal\n-Portions Copyright (c) 1999 by Hagen Reddmann\nQQQQSV\nQQQQQQQSVW\nQQQQQS\nYZ]_^[\n_^[YY]\n_^[YY]\nTByteArray\n_^[YY]\nR50qQ+\nR`}_ M]\n[;dMt>(\nTFGInt\n_^[YY]\n0_^[YY]\n_^[YY]\nYZ]_^[\nTDigits\nDigits4bA\nTInteger\nTInteger4bA\nDigits\nDigits\nYZ]_^[\n$Z]_^[\n_^[YY]\nYZ]_^[\n_^[YY]\nTKeyObj\nTZeppelinU\noleaut32.dll\nVariantChangeTypeEx\nVarNeg\nVarNot\nVarAdd\nVarSub\nVarMul\nVarDiv\nVarIdiv\nVarMod\nVarAnd\nVarXor\nVarCmp\nVarI4FromStr\nVarR4FromStr\nVarR8FromStr\nVarDateFromStr\nVarCyFromStr\nVarBoolFromStr\nVarBstrFromCy\nVarBstrFromDate\nVarBstrFromBool\nTCustomVariantType\nTCustomVariantTypeP\nVariants\nEVariantInvalidOpError\nEVariantTypeCastError\nEVariantOverflowError\nEVariantInvalidArgError\nEVariantBadVarTypeError\nEVariantBadIndexError\nEVariantArrayLockedError\nEVariantArrayCreateError\nEVariantNotImplError\nEVariantOutOfMemoryError\nEVariantUnexpectedErrort\nEVariantDispatchError\nQQQQSV\nSmallint\nInteger\nSingle\nDouble\nCurrency\nOleStr\nDispatch\nBoolean\nVariant\nUnknown\nDecimal\nShortInt\nLongWord\nString\nArray \nByRef \nVariants\n_^[YY]\nt~hDzC\nEStreamError\nEFileStreamError\nEFCreateError\nEFOpenError\nEFilerError \nEReadError\nEWriteError\nEListError\nEStringListError\nTThreadListD\nTPersistent\nTPersistentD\nClasses\nIStringsAdapter\nClasses\nTStrings\nTStrings\nClasses\nTStringItem\nTStringList\nTStringListP\nClasses\nTStream\nTHandleStream\nTFileStream\nTCustomMemoryStreamT\nTMemoryStream\nTStringStreamX\nEThread\nTThread\nTRegGroup\nTRegGroups\nStrings\nS$_^[Y]\n_^[YY]\nSd]_^[\n$Z]_^[\n_^[YY]\ntEh|zC\nIWideStringsAdapter\nWideStrings\nTWideStrings\nTWideStrings,&B\nWideStrings\nTWideStringItem\nTWideStringList((B\nTWideStringListx'B\nWideStrings\nQQQQQQSVW\nStrings\n_^[YY]\nS$_^[Y]\nSh]_^[\n$Z]_^[\nC ;C$u\n0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ_\nTRegExpr\nERegExpr\n^$.[()|?+*\{]}\nNo errors\nTRegExpr(comp): Null Argument\nTRegExpr(comp): Regexp Too Big\nTRegExpr(comp): ParseReg Too Many ()\nTRegExpr(comp): ParseReg Unmatched ()\nTRegExpr(comp): ParseReg Junk On End\nTRegExpr(comp): *+ Operand Could Be Empty\nTRegExpr(comp): Nested *?+\nTRegExpr(comp): Bad Hex Digit\nTRegExpr(comp): Invalid [] Range\nTRegExpr(comp): Parse Atom Trailing \\nTRegExpr(comp): No Hex Code After \x\nTRegExpr(comp): Hex Code After \x Is Too Big\nTRegExpr(comp): Unmatched []\nTRegExpr(comp): Internal Urp\nTRegExpr(comp): ?+*{ Follows Nothing\nTRegExpr(comp): Trailing \\nTRegExpr(comp): RarseAtom Internal Disaster\nTRegExpr(comp): BRACES Argument Too Big\nTRegExpr(comp): BRACE Min Param Greater then Max\nTRegExpr(comp): Unclosed (?#Comment)\nTRegExpr(comp): If you want take part in beta-testing BRACES '{min,max}' and non-greedy ops '*?', '+?', '??' for complex cases - remove '.' from {.$DEFINE ComplexBraces}\nTRegExpr(comp): Urecognized Modifier\nTRegExpr(comp): LinePairedSeparator must countain two different chars or no chars at all\nTRegExpr(exec): RegRepeat Called Inappropriately\nTRegExpr(exec): MatchPrim Memory Corruption\nTRegExpr(exec): MatchPrim Corrupted Pointers\nTRegExpr(exec): Not Assigned Expression Property\nTRegExpr(exec): Corrupted Program\nTRegExpr(exec): No Input String Specified\nTRegExpr(exec): Offset Must Be Greater Then 0\nTRegExpr(exec): ExecNext Without Exec[Pos]\nTRegExpr(exec): GetInputString Without InputString\nTRegExpr(dump): Corrupted Opcode\nTRegExpr(exec): Loop Stack Exceeded\nTRegExpr(exec): Loop Without LoopEntry !\nTRegExpr(misc): Bad p-code imported\nUnknown error\n0123456789\n0123456789\nQQQQSVW\n (pos \n+85GT`\n[_(OGb\nQQQQQS\n_^[YY]\nTPresenceU\nTExcludeFiles\nTExcludeFoldersU\nQQQQQQQSVW\nTDrivesAndShares\nQQQQQQQS3\nTReadme\nQQQQQQSVW\nTUnlockAndEncryptU\nTSearcherU\nTTaskKillerU\nQQQQQQQQSVW\n{Q.X6>\nQQQQQSVW3\nkernel32.dll\nQQQQSVW\nQQQQQQQQ3\n'FM52b\nQQQQQQ3\nZC.7D>8\n!!! D !!!\n!!! LOCALPUBKEY !!!\n!!! ENCLOCALPRIVKEY !!!\n"w{.y}|\n`"k[H6\n+K+v;w\nmm\Nc(9\n1(j.w_\nRuntime error at 00000000\n0123456789ABCDEF\nABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\n?456789:;<=\n !"#$%&'()*+,-./0123\nL&&jl66Z~??A\nOh44\Q\nsb11S*\nuB!!c \nD""fT**~;\n;d22Vt::N\nJ%%o\..r8\n0123456789ABCDEFW\n^$.[()|?+*\{\noleaut32.dll\nSysFreeString\nSysReAllocStringLen\nSysAllocStringLen\nadvapi32.dll\nRegQueryValueExA\nRegOpenKeyExA\nRegCloseKey\nuser32.dll\nGetKeyboardType\nDestroyWindow\nLoadStringA\nMessageBoxA\nCharNextA\nkernel32.dll\nGetACP\nVirtualFree\nVirtualAlloc\nGetTickCount\nQueryPerformanceCounter\nGetCurrentThreadId\nInterlockedDecrement\nInterlockedIncrement\nVirtualQuery\nWideCharToMultiByte\nMultiByteToWideChar\nlstrlenA\nlstrcpynA\nLoadLibraryExA\nGetThreadLocale\nGetStartupInfoA\nGetProcAddress\nGetModuleHandleA\nGetModuleFileNameA\nGetLocaleInfoA\nGetCommandLineA\nFreeLibrary\nFindFirstFileA\nFindClose\nExitProcess\nExitThread\nCreateThread\nWriteFile\nUnhandledExceptionFilter\nRtlUnwind\nRaiseException\nGetStdHandle\nkernel32.dll\nTlsSetValue\nTlsGetValue\nLocalAlloc\nGetModuleHandleA\nuser32.dll\nTranslateMessage\nPeekMessageA\nMsgWaitForMultipleObjects\nMessageBoxA\nLoadStringA\nGetSystemMetrics\nDispatchMessageA\nCharNextW\nCharLowerBuffW\nCharNextA\nCharLowerBuffA\nCharLowerA\nCharUpperA\nCharToOemA\nmpr.dll\nWNetOpenEnumW\nWNetEnumResourceW\nWNetCloseEnum\nkernel32.dll\nWriteProcessMemory\nWriteFile\nWaitForSingleObject\nVirtualQuery\nVirtualAllocEx\nTerminateThread\nTerminateProcess\nSetLastError\nSetFileTime\nSetFilePointer\nSetFileAttributesW\nSetEvent\nSetEndOfFile\nResumeThread\nResetEvent\nReadFile\nOpenProcess\nMoveFileW\nLoadLibraryA\nLeaveCriticalSection\nInitializeCriticalSection\nGlobalUnlock\nGlobalReAlloc\nGlobalHandle\nGlobalLock\nGlobalFree\nGlobalAlloc\nGetVersionExA\nGetUserDefaultLangID\nGetTickCount\nGetThreadLocale\nGetStdHandle\nGetProcAddress\nGetModuleHandleA\nGetModuleFileNameW\nGetModuleFileNameA\nGetLocaleInfoA\nGetLocalTime\nGetLastError\nGetFullPathNameA\nGetFileAttributesW\nGetFileAttributesA\nGetExitCodeThread\nGetEnvironmentVariableW\nGetEnvironmentVariableA\nGetDriveTypeA\nGetDiskFreeSpaceA\nGetDateFormatA\nGetCurrentThreadId\nGetCurrentProcess\nGetCommandLineW\nGetCPInfo\nInterlockedIncrement\nInterlockedExchange\nInterlockedDecrement\nFreeLibrary\nFormatMessageA\nFindNextFileW\nFindFirstFileW\nFindClose\nFileTimeToLocalFileTime\nFileTimeToDosDateTime\nExitThread\nExitProcess\nEnumCalendarInfoA\nEnterCriticalSection\nDuplicateHandle\nDeleteFileW\nDeleteCriticalSection\nCreateThread\nCreateRemoteThread\nCreateProcessW\nCreateProcessA\nCreatePipe\nCreateFileW\nCreateFileA\nCreateEventA\nCreateDirectoryW\nCopyFileW\nCompareStringW\nCompareStringA\nCloseHandle\nadvapi32.dll\nRegSetValueExW\nRegSetValueExA\nRegQueryValueExW\nRegQueryValueExA\nRegOpenKeyExW\nRegOpenKeyExA\nRegEnumKeyExA\nRegDeleteValueA\nRegDeleteKeyA\nRegCreateKeyExW\nRegCreateKeyExA\nRegCloseKey\nOpenProcessToken\nLookupPrivilegeValueA\nAdjustTokenPrivileges\nkernel32.dll\nwininet.dll\nInternetReadFile\nInternetOpenUrlA\nInternetOpenA\nInternetConnectA\nInternetCloseHandle\nHttpSendRequestA\nHttpOpenRequestA\nHttpAddRequestHeadersA\nshell32.dll\nShellExecuteW\nshell32.dll\nSHGetSpecialFolderLocation\nshell32.dll\nSHGetPathFromIDListW\nSHGetMalloc\noleaut32.dll\nSafeArrayPtrOfIndex\nSafeArrayGetUBound\nSafeArrayGetLBound\nSafeArrayCreate\nVariantChangeType\nVariantCopy\nVariantClear\nVariantInit\n0,0H0T0d0\n0)1-111I1X1\1x1\n2"2*222:2B2J2R2Z2b2j2r2z2\n3&3*5@5Q5t5\n6E6M6R6w6\n6 7&7,777\n7F9U9\9\n: :*:A:V:i:v:\n;*;e;o;\n< <5<A<^<g<\n0_1o1"2+2=2I2T2\n5)5<5W5]5u5\n7-898x8\n=!=%=5=:=_=\n>2>N>o>\n>&?;?H?h?\n-0T0X0\0`0d0h0l0p0t0#2\2\n263?3p3w3\n>,>:>n>\n>$?-?_?h?\n3/393D3U3\n5!5+53595G5b5w5\n6M6V6[6}6\n717<7y8\n0R4[4b5k5o<\n1,1<1C1\n2&22292Z5\n6b7o7{7\n848B8G8`8p8\n9 9*949>9H9R9\9f9p9z9\n:&:.:6:>:F:N:V:^:f:n:v:~:\n;&;.;6;>;F;N;V;^;f;n;v;~;\n<&<.<6<><F<N<V<^<f<n<v<~<\n> >$>0>P>X>\>`>d>h>l>p>t>x>|>\n?<?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?\n5d6l6t6|6\n7$7,747<7D7L7T7\7d7l7t7|7\n8$8,848<8D8L8T8\8d8l8t8|8\n9$9,949<9H9\9d9h9l9p9t9x9|9\n: :(:,:0:4:8:<:@:D:H:\:|:\n;,;4;8;<;@;D;H;L;P;T;l;\n<<<D<H<L<P<T<X<\<`<d<t<\n=(=H=P=T=X=\=`=d=h=l=p=\n> >0>P>X>\>`>d>h>l>p>t>x>\n? ?$?(?,?@?`?h?l?p?t?x?|?\n0$0(0,0004080<0@0D0T0t0|0\n1(1014181<1@1D1H1L1P1d1\n2 2@2H2L2P2T2X2\2`2d2h2|2\n343A3I3X3e3m3\n3(4,4044484<4@4X4d4h4\n>+?<?R?\n3155595=5A5E5I5M5Q5U5Y5]5a5e5i5m5q5u5A6H6\n:6<K<V=\n96:]:q:\n=+=^=q=\n>->=>P>\>|>\n20353C3g3\n465N5`5x5\n7.7E7W7\n:?:D:^:\n:;;;Z;l;\n=9=R=b={=\n?F?W?`?\n33+3k3\n5E6W6k6\n7%747P7~7\n88%8-868B8G8P8Y8b8k8t8\n8%9C9l9\n>R>W>e>n>\n>?-?H?Q?l?\n060?0S0a0u0\n1&161>1S1[1x1\n3/464E4L4j4\n: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:\n; ;(;,;4;8;@;D;L;P;X;\;d;h;p;t;|;\n<$<(<0<4<<<@<H<L<T<X<`<d<l<p<x<|<\n=!=+=5=?=I=S=]=g=q=|=\n>$>.>9>K>\>l>\n>0F0N0V0^0f0n0v0~0\n1*1/1<1A1N1S1`1e1r1w1\n3;3[3j3r3\n;@;~;Z<\n2(3B3T3\n7"7X7d7R9\n;.<V<h<\n>C>K>~>\n2!3-3:3B3O3V3j3v3\n8P8@9^9,:d:\n<<5<S<X<\n000<0P0\n7p7N8w8\n314?4M4[4h4\n3 3.3<3J3W3e3\n5$525?5M5\n8(8c8r8~8\n:9:V:w<\n4$434B4\n6/6@6z6\n7T7e7v7\n7.8?8P8a8\n9*9;9u9\n:O:`:q:\n:);:;K;\;\n<%<6<p<\n=J=[=l=}=\n=$>5>F>W>\n? ?1?k?|?\n0E0V0g0x0\n0101A1R1\n2/2l2}2\n3L3]3n3\n3,4=4N4_4\n5.5?5|5\n66\6m6~6\n6<7M7^7o7\n8-8>8O8\n9/9l9}9\n:L:]:n:\n:,;=;N;_;\n<.<?<|<\n==\=m=~=\n2 2$2(2,202>2P2^2b2t2\n2"3-343D3O3^3j3{3\n4!474R4a4f4l4\n5.5E5p5\n:K:S:d:\n8A9N9V9\n: ;T;];n;\n4$4(4,4044484<4@4D4R4\n4=5M5[5i5\n8W8k8y8\n:&:P:[:c:p:\n;8<V<t<*===Q=\n(050d0\n2.262>2F2}2\n33%3*353;3@3K3Q3V3a3g3l3w3}3\n4'4-424=4C4H4S4Y4^4i4\n6$6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6\n747T7\7`7d7h7l7p7t7x7|7\n8$8(8,8084888<8@8D8`8\n9(9H9P9T9X9\9`9d9h9l9p9\n: :$:(:,:0:4:8:<:@:\:|:\n;(;H;P;T;X;\;`;d;h;l;p;\n;7<F<]<\n<'=6=M=u=\n?%?4?K?Z?n?}?\n]0k0z0\n:$:<:F<J<N<R<V<Z<^<b<f<j<n<r<v<z<~<\n1!1%1)1-111C1[1X3\3`3d3h3l3p3t3x3|3\n9)9>9C9P9p9\n<&<G<]<u<z<\n= =(=0=8=@=H=P=X=`=h=p=x=\n>,>4>8><>@>D>H>L>P>T>h>\n?$?D?L?P?T?X?\?`?d?h?l?|?\n0,0L0T0X0\0`0d0h0l0p0t0\n1 1$1<1\1d1h1l1p1t1x1|1\n2 2$2(2,2024282<2@2D2H2L2V2Z2l2}2\n3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3\n4$4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4\n5<5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5\n6$6,6064686<6@6D6H6L6P6T6X6\6`6d6h6v6\n7(7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7\n8,84888<8@8D8H8L8P8T8`8\n949<9@9D9H9L9P9T9X9\9\n<$<1<C<H<\n5!6>6|6\n<;<c<u<\n=F>Q>[>\n1P2U2|2\n77#7'7+7/73777;7?7C7G7K7O7S7W7[7_7c7g7k7o7|8\n:+;e;o;\n<*<1<W<d<s<\n0+101\1\n2,222;2H2i2n2\n3&4+4=4[4g4n4x4\n6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6\n7!7,7<7L7T7X7\7`7d7h7l7p7t7x7|7\n8$898=8e8o8t8z8\n<=.=O=n==>d>\n)0V0m0\n1$2^2y2E3\n898X8h8\n=8>P><?u?\n4,44484<4@4D4H4L4P4T4\n55#5'5\n6#616?6M6[6i6w6\n77-7;7I7W7e7s7\n0'0:0M0e0v0\n2"3J3r3\n55#5'5+5\n3;4B4^4b4f4j4n4r4v4z4]6B8U9\n<(<5<`<y<\n99#9A9E9I9M9Q9U9Y9]9a9e9\n4L5P5T5X5\5`5d5h5l5p5t5x5|5\n>#>:>Y>\n?6?D?k?\nL0^0l0\n1"242H2\n40484<4@4D4H4L4P4T4X4\n9$9,9094989<9@9D9H9L9x9\n0N0\0i0y0\n5(555[5\n7!8/8c8\n;&;4;R;~;\n;Y<g<u<\n> >$>(>,>0>4>8>F>\n?%?H?n?\n171L1e1p1\n60686<6@6D6H6L6P6T6X6\6`6n6\n6(7H7P7T7X7\7`7d7h7l7p7t7x7\n1&161G1W1u1\n737F7\7o7\n7>8o8S9\n<%<@<Q<\n?#?1?X?\n"0T0a0}0\n3/3G3_3w3\n4%456\6x6\n8(8N8[9k9\n:/:9:>:J:`:\n: ;2;h;\n<%</<4<@<J<O<[<e<j<x<\n=+=8=G=T=c=p=\n>.>J>T>Y>c>m>|>\n?(?2?7?A?T?c?z?\n00090T0]0\n192@2F2O2Z2e2l2x2\n6+6>6P6\6`6l6p6\n00%0)0/060:0T0]0f0r0|0\n1 1%1/141>1C1M1R1\1a1k1p1z1\n64@4O4[4c4m4x4\n5#545?5U5f5{5\n6"6/6;6H6T6g6s6}6\n1(1H1,7074787<7@7D8L8P8t8x8\n9 9$9(9,909l9t9|9\n044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4\n5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5\n6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6\n7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7\njjjjjjjj\njjjjjjjj\njjjjjjjj eb920e0fc0c360abb901e04dce172459b63bbda3ab8152350885db4b44d63ce5

2397 rows × 4 columns

Created by: Avinash
Downloaded 2 times
Comments: 0

Version: 1
Date: Dec. 26, 2022, 4:53 p.m.
Created by: Avinash
Description: Only ransomware strings
Categories: Ransomware(2512)
Rows: 1826 | Cols: 4 | Reports Used: 2512   Download Version 1 (31.1 MB)