Sample details: f23b59c7d0ecba3017c65c9e23a83fae --

Hashes
MD5: f23b59c7d0ecba3017c65c9e23a83fae
SHA1: 5cc3001189689b2644b5400485724fea0ad81b12
SHA256: 4e966a5612256846e43a23530a398887016ba1ebf05c8d46203e505c9d881f30
SSDEEP: 6144:MZBuNpUyd0ijcUtdWuOJT2H3FTpYAGPBf24FFfAE20iOzhGwkYky80JwzwIZSQ8t:MZSayd0ipruR8qjP1FFFOOzhEYknL8jB
Details
File Type: PE32
Yara Hits
YRP/VC8_Microsoft_Corporation | YRP/Microsoft_Visual_Cpp_8 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasOverlay | YRP/HasDigitalSignature | YRP/HasRichSignature | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/Browsers | YRP/anti_dbg | YRP/network_tcp_socket | YRP/network_dns | YRP/screenshot | YRP/win_mutex | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/Advapi_Hash_API | YRP/CRC32_poly_Constant | YRP/CRC32_table | YRP/BASE64_table | YRP/Str_Win32_Winsock2_Library |
Parent Files
0078a6bfbb124113e4d60d41fd3fc8dc
Strings
		!This program cannot be run in DOS mode.
J1FY11t
J1FY'1j
J1Richa
`.rdata
@.data
|$Pj7h
9|$Hwj
|$<j7h
L$0Qh$
u	_^]3
D$ +GD
D$$+GH+
W@_^][
FhQRj P
u-Vj"h
T$0RWj
T$4RVj
D$$Pj)h
T$4RVj
T$4RPj
T$tRVj
D$XPVj
T$pRVj
T$xRVj
D$4j	h
T$dRPj
?SWj h
t.j(h$
L$,VWQ
L$(PQP
T$$RSV
PQSUVW
t$4WVU
T$4RVU
D$4PVU
D$4PVj
L$,Qj*h
L$$Qj:h 
T$HSRSW
T$TRWQ
te+D$0x_
u*8F<t
D$,RPj
uFj'hh
L$$+L$
T$(+T$ ;
PVQRj)h0
9.tES3
D$L`.F
t$<Ph8
D$,`.F
T$ 	WP
D$(@;D$$
QRPj3h
RPjCh`
D$ 9D$,t
L$Hj\Q
VWxK;]
PQSUVW
PQSUVW
T$L;T$Pt
D$L;D$@
D$xRPh
D$PPQR
D$PPQR
T$`RPQ
L$PQRP
9_4tLj
W8RSWh
L$ j?Q
PQSUVW
PQRj&h
D$<+D$4
D$@+D$8
L$<+L$4+
L$@+L$8+
thV9=$%G
8tY9~dtk
QQSWWWj
T$8RRRR
QQWRRRj
^<9;u"
C Ph@$G
twf9s@
L$ QPV
<Z~$<a|
9|$\ub
9|$\uG
L$\j=Q
tYHtHHt7Ht&Ht
t_HtKHt7Ht&Ht
j	h$'F
Aj-hd'F
j	hP(F
QQSUVW
_^][YY
D$(	D$$
thj3hx*F
j2hx+F
Pj*h,-F
j,hX-F
}/j"h8.F
	$$$$$$$
 !"#$$$$$$
<*tX<?tTF;t$
<\t	F;t$
D$<PSS
D$$j\P
\$@SSSj
D$,j\P
t8< t4<	t0<=t$
<"t6<\u
4< t5<	t1<
Y<*t&:
j.h$5F
j'hT5F
PSSVSSS
}Lj	h$7F
PSh0\C
SSSj1hP7F
j:h(8F
EXPjZS
t$ VSSSSSSPQ
0j(hP<F
j,h|<F
PSSSSSS
QSSSSj
t$WPSSj
</te<\ta<.ue
_@^[=#
<\t	;}
n<@u49U
6</tG<?tC
SSSSSS
SSSSSS
Pj&h,@F
%Pj$hT@F
j"h|@F
)j0h$AF
tu9s<v
u4j%hXAF
F$9^$u
u'Pj5h BF
%Pj*hXBF
9>t*U3
<0r><9w:j
9~$~ S
0WWWWW
0WWWWW
^SSSSS
j"^SSSSS
^SSSSS
W95p,G
0SSSSS
0SSSSS
^SSSSS
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
^SSSSS
^SSSSS
^SSSSS
0A@@Ju
PPPPPPPP
t"SS9]
tNIt?It0It 
HHtXHHt
>If90t
HHtYHHt
uL9= 1G
PPPPPPPP
PPPPPPPP
t$<"u	3
>=Yt1j
< tK<	tG
j@j ^V
>:u8FV
v	N+D$
^SSSSS
^SSSSS
j"^SSSSS
URPQQh
0SSSSS
t+WWVPV
	X 9} 
^SSSSS
j"^SSSSS
<+t(<-t$:
+t HHt
_VVVVV
^WWWWW
;t$,v-
UQPXY]Y[
0SSSSS
v	N+D$
_VVVVV
QQSVWd
s[S;7|G;w
tR99u2
InterlockedPopEntrySList
InterlockedPushEntrySList
kernel32.dll
bad allocation
CorExitProcess
SetThreadStackGuarantee
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error 
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program: 
(null)
`h````
xpxxxx
`h`hhh
xppwpp
Unknown exception
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 Complete Object Locator'
 Class Hierarchy Descriptor'
 Base Class Array'
 Base Class Descriptor at (
 Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
 delete[]
 new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
 delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
_nextafter
_hypot
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
1#QNAN
1#SNAN
Invalid DateTime
\WS!G:?W
(9SW(S9
WSW!KS\W?8K?
\I.\+S
899	Z__
+_DS\W?8
[FDS\W?8
U<KS\W?8Q
) UU;YL;<* @U<  
U<QQ)Y<@
899	Z__
+_J\1:?
899	Z__\	:
PSWI[FDS\W?8
+\W&S9[F5\(TP\TS
:798[F:SZ+\]
8S:T89[F:SZW
4S:T89
(4S:T89[F:SZDS?9:
(4S:T89
KPTTSD9:
KS\W?8KPTTSD9:
7S	\TS
Version
*#U!G:?W
(9SW(S9
(9SW(S9
KS\W?8
Tahoma
Cancel
Resume
%03d,%s
G\(:JSD9
\7K9W:(TH\:
(J:TPW\9:
T(:ES7
?P+S(9U
S+S(9Z
\W9(SW4
(<(P+SW:?
\W9(SW
(9SW(\
S(P+SW\9:
\W9(SWK:T(\9PWS
W\?&S7U1S(9D
S9W\?&S7S1S(9D
DS9W\?&S7S1S(9D
9W\?&S7S1S(9DPW
9W\?&S7S1S(9D
*WTP+S(9D
?8\((S
(9S(9:7
\WS5:D9
DSU]:9K9\9PD
KP??SDD#S	
W(DS9P	B
	\W\+D
:B?D+\(:JSD9
+\(:JSD9
+\(:JSD9
:(9SW(\
G:DD:(T
G:DD:(T
S(P+SW\9:
S(P+SW\9:
:?D+\(:JSD9
proxy-authenticate
www-authenticate
/;^@>2
:(L;B<
/;^@>2
W\(7:7
ASW:JI
P	TW\7S
P	TW\7S
%s-%llu%03d
P?:SWW
S]?S	9:
P(\P98
W:ES7Z
color_btnface
color_btnhighlight
color_btnhilight
color_btnshadow
color_btntext
color_captiontext
/%s=#%02x%02x%02x
Mscoree.dll
W9+\(:JSD9
!+\(:JSD9
K+\W9D8
\9W:P+
K+\W9K8
	\WS(9	W
/;^>Y[6
+\(:JSD9
9D9W\	
5\P(?8
	\98&SI[
D9\9PD
\DDSD!899	!D8S
Update failed
S(SW\9S
S.\+S[
Downloading 
Installing 
WST:D9WI
?WS\9S	W
7P?9[R
W7SW[R
D-_4\D8
\I.\+S
\I.\+S
DSU]:9K9\9PD
DSU]:9K9\9PD
-KP??SDD#S	
D-_KP??SDD#S	
D-_H\:
?SDD.\+S
?SDD.\+S
5:D95:D9V
899	Z__:(D9\
DS?PWS
D:9S\??SDD
(J_:(D9\
$N=PSWI*		S(7K
$N=PSWI*		S(7K
=PSWI*		S(7K
=PSWI*		S(7K
^/@Y? 
YYY;L7Y>^Y^@)7;2)
;^2S\/
YYS)/@YL);7?S/7YJ2S?)\^J7J\YL 
&SI1SW
\WS!G:?W
$N-:(D9\
$N-DSDD:
(D9\W9
D-_DSDD:
(D9\W9
$N-?D?:7
D-_?D?:7
$N-87:7
D-_87:7
$N-	\TS
:(7S][R
-_	\TS
 -_	:]S
-+\(:JSD9:(J
$N-P?:&:(7
7-_P?:&:(7
D-_+\(:JSD9:(J
$N-(\+S
D-_(\+S
$N-?:7
$N-:(D9\
D-_:(D9\
$N-:(D9\
D-_:(D9\
-_:(D9\
$N-_WS
W9A;#S
W9KS(7#S
W9#SD	
W9#SD	
D9\9PD
?WS7:9?
D+\W9D8
899	Z__
S]?S	9:
WS\7:(T
98WS\7:(T
:S(9\WS\
S9KS99:(TV6
K\1SKS99:(TV6
#S\7#STV6
#S\7#STV6
#ST#S\7
height
center
horizontal
vertical
ASW:JI
ASW:JI
ASW:JI
++P(:?\9:
FHTMLWindow
F#32770
ATL:%p
AXWIN Frame Window
AXWIN UI Window
AtlAxWin90
WM_ATLGETHOST
WM_ATLGETCONTROL
{8856F961-340A-11D0-A96B-00C04FD705A2}
Content-Type: application/x-www-form-urlencoded
about:blank
S9KS99:(T
K\1SKS99:(T
K\1SKS99:(TD
9S+.\+S
TWSDDH\:
TWSDD,K
#S\7#ST
W:9S#ST
KS(7U1S(9
ASW:JI
\WTP+S(9
U]	S?9:(T
U]	S?9S7
\WTP+S(9X
*WTP+S(9
D9W:(T
U]?S	9:
:7\9:(T
S]?S	9:
AtlAxWinLic90
&apos;
&quot;
6071814
5517928
4807842
431299
9S	\W\+DS]
:?(\+S
:?1SWD:
D\:W(7
9W\?&S7S1S(9D+\(:JSD9\WTD
TWSDD:9S+(\+S
TWSDDJ\:
5\P(?8
*P98S(9:?
9*7+:(
WGP9S]U]:D9D
WS\9SGP9S]
WS\9SK9\9:?
	TW\7S
	TW\7S
	TW\7S
	TW\7S
W:9SUWW
	TW\7SK:T(\9PWSUWW
	TW\7S
	TW\7S5\P(?8
	TW\7S5\P(?8
	TW\7S5\P(?8UWW
	TW\7S5\P(?8H\:
G\(:JSD9
G\(:JSD9
G\(:JSD9H\:
ASW:JI
ASW:JI
ASW:JI
(J:TUWW
ASW:JI
(J:TH\:
ASW:JI
W:9SUWW
\TSK:T(\9PWSUWW
5\P(?8
DSW*??S	9
DSW#S3S?9
K:ESUWW
W:9SUWW
*		K:T(\9PWSUWW
U(7KSDD:
9KS\W?8
1:7SW#S	
S9S5\P(?8
S9S5\P(?8H\:
\D9SWW
DS?PW:9I
P?:&:(7
:(7:WS?9
7:D	+DS?
:SASWD:
:DKP??SDDJP
&%s=%d
http://
?D?:7[
P9?SWW[
KS(7U1S(9HW
+K?W:	9V
KS(7U1S(9HW
+K?W:	9Z
(<(P+SW:?
9W\?&S7
U]?S	9:
W9U1S(9
^/@Y? 
YY ;L7Y>^Y^@)7;2)
;^2S?/
Y;S)/@YL);J?S/7YJ2S?)\^J7J\Y\ 
D97\9\[
+DTD:ES[
KS(7#S
G\&S#S
KS(7#S
\(9:1:W
\1\D9%
:97SJS(7SW
SW7SJS(7SW
&\D	SWD&I
+?\JSS
7SJS(7SW
DI+\(9S?
DID9S+
:++P(S9
7SJS(7SW
7SJS(7SW
\W\+DZ
_SWSD	
ASW:JI
7S?WI	9
\\.\%s%d:
W\D?D:
(9\:(SW
Microsoft Base Cryptographic Provider v1.0
                
****&**QK
***U**=*]U@@
9P/A9+#.,
Y(I()LH1W=
@^PK:YT
O'O(J5
****&**QK
***U**=Q5
+]7,?.'=?
.:5 3\^	(O
TEDYISL
,8=IK2=W
1HD]1G#1
DSW#S9WI
DSW#S9WI
9SW+:(\9S7
98WS\7
DSW#S9WI
DSW#S9WI
DSW#S9WI
WS9PW(Z
W\WIVPW
URLDownloadToFileA
(9SW(\
?*77WSDDV
SCSIDISK
000000000000000000000000000000
5*KKUK
[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
U$?&b T_.pW]>}
CY)IqOlGoPK%|w#DZ1\,R
!k+n9AmJ<N0[v6jHL'dhti2-Q4c7V*	sz{MFyfS3@
XuB"egE(r;5:=ax8/%25
?WS\9S
	SW\9:(T
DID9S+
\7+:(:D9W\9
W:T89D
\7+:(:D9W\9
WP((:(T
(J:TPW\9:
W9P(\9S
(J:TPW\9:
W9P(\9S
7:T:9\
D:T(\9PWS
:(7:?\9SD
7:J:S7
WWP	9S7
W9P(\9S
++S(7S7
+	P9SW
DS99:(TD
R#S9WIR
:(:9:\
++S(7S7
+	P9SW
DS99:(TD
R#S9WIR
win2k3
S]:D9Z
U]S?P9SH:
SHGetFolderPathA
[Rename]
0#S(\+S
0WS(\+S
[Rename]
\WS!G:?W
KID9S+!
PWWS(9
!KSDD:
G\(\TSW
%d.%d.%d.%d
%s: %s
GetLastError:%ld
	L;K(\	D8
=PSWIHP
+\TS.\+S*
\DDSD!4
	S(!77SS]S?!*		
ProductId
HKLM\Software\Microsoft\Windows\CurrentVersion
\WS!G:?W
PWWS(9ASWD:
\WS!G:?W
PWWS(9ASWD:
AdvApi32
CreateProcessWithTokenW
9!KS?PW:9I
S(9SW;
9!KS?PW:9I
SJS(7SW
KSW1:?S
:ESKS?PW:9I
S+*7+:(:D9W\9:1S5
((S?9KSW1SW
*(9:A:WPD
U]S?=PSWI
\I.\+S
+	\(I.\+S
iexplore.exe
D\J\W:B
D\J\W:
D\J\W:89+
opera.html
*#U!G:?W
PWWS(9ASWD:
\DDSD!
EnableLUA
*#U!G:?W
PWWS(9ASWD:
:?:SD!KID9S+
???, * GMT
%A, %B %d, %Y %H:%M:%S
?WI	9L;
?WI	9L;
CryptQueryObject
GetProcAddress of CryptQueryObject
CryptMsgGetParam
GetProcAddress of CryptMsgGetParam
CryptMsgGetParam size
CertFindCertificateInStore
GetProcAddress of CertFindCertificateInStore
LocalAlloc of PCMSG_SIGNER_INFO
CertFreeCertificateContext
CertCloseStore
CryptMsgClose
CertGetNameStringA
GetProcAddress of CertGetNameString
JP(?9:
+SDD\TSZ
unknown error.
:(9WPD9
:(9WPD9
WinVerifyTrust
WinTrustVerify
mailto
gopher
Location
Connection
Content-Length
K:T(SW
\W\+DV
\		S(7
\W\+DV
<?\?8S"
KS(7#S
(\1:T\9SV
(DSD9\9PDZ
899	D9\9Z
(\1:T\9SV
(DSD9\9PDZ
899	D9\9Z
KS(7#S
KS(7#S
KS(7#S
ASW:JIK:T(\9PWS
KS(7#S
S]?S	9:
KP??SDD
*		S(7Q
*		S(7Q
keep-alive
 HTTP/1.1
Host: %s:%d
Host: %s
Content-Length: %d
Content-Type: 
User-Agent: Custom_56562_HttpClient/VER_STR_COMMA
Transfer-Encoding
chunked
Trailer
set-cookie
bad exception
KERNEL32.DLL
ADVAPI32.dll
GDI32.dll
IPHLPAPI.DLL
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
USER32.dll
VERSION.dll
WS2_32.dll
ReadFile
TerminateThread
CreateFileA
DeleteFileA
GetCurrentProcessId
CreateToolhelp32Snapshot
Process32Next
SetLastError
OpenProcess
Process32First
GetCurrentThreadId
DeleteCriticalSection
CreateMutexA
OpenMutexA
GetLastError
RaiseException
MultiByteToWideChar
GetModuleFileNameW
InitializeCriticalSection
GetCommandLineA
InterlockedDecrement
InterlockedIncrement
GlobalFree
GlobalUnlock
MulDiv
GlobalAlloc
GlobalLock
FindClose
FindFirstFileA
EnumResourceNamesA
SetEnvironmentVariableA
CompareStringW
CompareStringA
FlushFileBuffers
WriteConsoleW
GetConsoleOutputCP
SetStdHandle
GetConsoleMode
GetConsoleCP
EnumResourceLanguagesA
RtlUnwind
GetTimeZoneInformation
QueryPerformanceCounter
GetFileType
SetHandleCount
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetEnvironmentStrings
FreeEnvironmentStringsA
InitializeCriticalSectionAndSpinCount
GetStringTypeW
GetStringTypeA
HeapCreate
LCMapStringW
LCMapStringA
EnumResourceTypesA
lstrcpyA
CreateThread
CloseHandle
GetModuleHandleA
CreateEventA
GetTickCount
SetEvent
WaitForSingleObject
LockResource
SizeofResource
WideCharToMultiByte
FindResourceExA
LoadResource
TlsFree
TlsSetValue
TlsAlloc
TlsGetValue
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
IsDebuggerPresent
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetDateFormatA
GetTimeFormatA
VirtualQuery
GetSystemInfo
VirtualProtect
GetStartupInfoA
ExitProcess
GetModuleHandleW
GetSystemTimeAsFileTime
VirtualAlloc
VirtualFree
IsProcessorFeaturePresent
InterlockedCompareExchange
HeapSize
HeapDestroy
LocalAlloc
GetShortPathNameA
GetTempPathA
GetVersion
GetVersionExA
WriteConsoleA
GetTempFileNameA
AttachConsole
GetStdHandle
Module32First
CreateDirectoryA
GetSystemDirectoryA
TerminateProcess
CreateProcessA
GetComputerNameExA
GetExitCodeProcess
FreeConsole
GetVolumeInformationA
GetDriveTypeA
WriteFile
GetWindowsDirectoryA
SetErrorMode
SetFilePointer
FindResourceA
lstrcmpA
lstrlenA
GetCurrentProcess
LeaveCriticalSection
lstrlenW
FlushInstructionCache
EnterCriticalSection
GetModuleFileNameA
GetSystemTime
WaitForMultipleObjectsEx
ResumeThread
HeapReAlloc
HeapAlloc
HeapFree
GetProcessHeap
FreeLibrary
GetProcAddress
LoadLibraryA
GetExitCodeThread
DeviceIoControl
FormatMessageA
LocalFree
GetComputerNameA
DosDateTimeToFileTime
GetFileSize
GetLocaleInfoA
MoveFileExA
CryptCreateHash
CryptDestroyHash
CryptDestroyKey
OpenSCManagerA
QueryServiceStatus
DuplicateTokenEx
LookupAccountNameA
ConvertSidToStringSidA
OpenProcessToken
CloseServiceHandle
OpenServiceA
RegCloseKey
RegEnumValueA
RegQueryInfoKeyA
RegOpenKeyExA
RegCreateKeyExA
RegEnumKeyExA
CryptReleaseContext
CryptAcquireContextA
CryptImportKey
CryptVerifySignatureA
CryptHashData
RegSetValueExA
RegQueryValueExA
GetObjectA
GetStockObject
CreateSolidBrush
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
DeleteObject
SetBkMode
CreateFontIndirectA
DeleteDC
SetTextColor
PatBlt
BitBlt
GetDeviceCaps
GetAdaptersInfo
CoInitialize
CoInitializeSecurity
CoSetProxyBlanket
CoCreateGuid
CoTaskMemAlloc
CoGetClassObject
StringFromGUID2
CLSIDFromString
CLSIDFromProgID
OleLockRunning
OleUninitialize
OleInitialize
CoInitializeEx
CoUninitialize
CreateStreamOnHGlobal
CoCreateInstance
PathFindFileNameA
PathUnquoteSpacesA
PathAppendA
PathCombineA
PathAddExtensionA
UrlEscapeA
PathRemoveArgsA
PathRemoveExtensionA
PathFindExtensionA
PathFileExistsA
PathQuoteSpacesA
PathStripPathA
PathStripToRootA
SendMessageA
FindWindowExA
RegisterClassA
LoadCursorA
UpdateWindow
ReleaseCapture
SystemParametersInfoA
DispatchMessageA
GetFocus
GetParent
GetWindowInfo
GetDesktopWindow
GetSystemMetrics
EnableWindow
GetClassNameA
CreateDialogParamA
GetClientRect
EnumWindows
GetWindowThreadProcessId
PostThreadMessageA
RegisterClassExA
GetClassInfoExA
UnregisterClassA
GetSysColor
IsWindow
SetDlgItemTextA
EndPaint
DestroyWindow
SetCursor
GetMessageA
GetSystemMenu
SetTimer
ScreenToClient
GetWindowRect
FillRect
SetCapture
KillTimer
DrawTextA
SetForegroundWindow
MoveWindow
GetWindow
CallWindowProcA
LoadImageA
SetWindowTextA
GetDlgItem
CreateAcceleratorTableA
InvalidateRect
GetWindowTextA
RegisterWindowMessageA
GetWindowTextLengthA
SetFocus
CharNextA
InvalidateRgn
IsChild
DestroyAcceleratorTable
ClientToScreen
FindWindowA
GetForegroundWindow
AttachThreadInput
BeginPaint
PtInRect
TranslateMessage
InflateRect
SetRect
SetWindowLongA
MessageBoxA
BringWindowToTop
GetWindowLongA
CreateWindowExA
ReleaseDC
EnableMenuItem
DefWindowProcA
RedrawWindow
SetWindowPos
GetCursorPos
ShowWindow
GetSysColorBrush
FrameRect
PostMessageA
GetFileVersionInfoSizeA
GetFileVersionInfoA
VerQueryValueA
getaddrinfo
WSARecv
WSASend
WSASetEvent
WSAConnect
WSACloseEvent
WSAEventSelect
WSAGetOverlappedResult
freeaddrinfo
WSACreateEvent
WSAResetEvent
WSAEnumNetworkEvents
WSASocketA
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVCAtlException@ATL@@
Qkkbal
?456789:;<=
 !"#$%&'()*+,-./0123
.?AUHTMLWindowException@@
.?AVHTMLWindowObserver@@
.?AUIAxWinAmbientDispatch@@
.?AUIAxWinAmbientDispatchEx@@
.?AV?$IDispatchImpl@UIAxWinAmbientDispatchEx@@$1?_GUID_b2d0778b_ac99_4c58_a5c8_e7724e5316b5@@3U__s_GUID@@B$1?m_libid@CAtlModule@ATL@@2U_GUID@@A$0PPPP@$0PPPP@VCComTypeInfoHolder@ATL@@@ATL@@
.?AUIAdviseSink@@
.?AUIServiceProvider@@
.?AUIObjectWithSite@@
.?AV?$IObjectWithSiteImpl@VCAxHostWindow@ATL@@@ATL@@
.?AUIParseDisplayName@@
.?AUIOleContainer@@
.?AUIOleControlSite@@
.?AUIOleInPlaceSite@@
.?AUIOleInPlaceSiteEx@@
.?AUIOleInPlaceSiteWindowless@@
.?AUIOleClientSite@@
.?AUIAxWinHostWindow@@
.?AUIAxWinHostWindowLic@@
.?AV?$CWindowImpl@VCAxHostWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CComCoClass@VCAxHostWindow@ATL@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AVCAxHostWindow@ATL@@
.?AV?$CComContainedObject@VCAxHostWindow@ATL@@@ATL@@
.?AUIEnumUnknown@@
.?AV?$CComEnumImpl@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@@ATL@@
.?AV?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComMultiThreadModel@6@@ATL@@
.?AV?$CComObject@V?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComMultiThreadModel@6@@ATL@@@ATL@@
.?AV?$CWindowImpl@VCAxUIWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AVCAxUIWindow@ATL@@
.?AV?$CComObject@VCAxUIWindow@ATL@@@ATL@@
.?AUIOleWindow@@
.?AUIOleInPlaceUIWindow@@
.?AUIOleInPlaceFrame@@
.?AVCMessageMap@ATL@@
.?AVCWindow@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CWindowImpl@VCAxFrameWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CComObjectRootEx@VCComMultiThreadModel@ATL@@@ATL@@
.?AVCAxFrameWindow@ATL@@
.?AV?$CComObject@VCAxFrameWindow@ATL@@@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AV?$CComPolyObject@VCAxHostWindow@ATL@@@ATL@@
.?AUIDropTarget@@
.?AUIDocHostUIHandler@@
.?AUIDispatch@@
.?AUDWebBrowserEvents2@@
.?AUIUnknown@@
.?AVIWebBrowser2Observer@@
.?AVHTMLWindow@@
.?AVCSimpleHttpClient@LibHttp@@
.?AVCAppInternetRequest@SAI@@
.?AVZEvtSyncSocket@ATL@@
.?AV?$CAtlHttpClientT@VZEvtSyncSocket@ATL@@@ATL@@
.?AVCCustomHttpClient@LibHttp@@
.?AVCHttpClient@LibHttp@@
.?AVCSocketAddr@ATL@@
.?AVbad_exception@std@@
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
6xv=oB
VRp@`k
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
V_z~Bg
7T.x?ga
wpfV)7+
 0kZyf
~7DAOX
O*L<J~f
K:*q"l
"_FM;F
^Um66w
>Cd`{p
|]6YOL
;O&hzi
{U0lAt
aMPa*$
h1Pt=z
dOn>t7vt
@(>U!%"f
{/BuY[
rBo'%i
\d?V3%
{r2$YM
^`1H(+
,ZW7U%
Wx	!$8B
;h15e 0
C.)2?j
 z&1ak
z5N3"=
jR/=;y%.YkD
>{|u}7
v'\fx}
?P5m_1
&k~bVB}
qY 50"
Uk8z+.
lvOuCzAJ
*CIr+y
`}SVa^
4[oXV))
"[:7ZQ
^j\L^:
	"B`-n
B8T\ZT
hxusye;
?f(p<>RG
cdt!i:'
6s:wKr/v
!	LHdU
fY#I!Sg
Y,[*;w?U
/.p'PY@
/#*[JQ3
X DWRC
F[?,nQN
)za{qF
jd~L0b
wf2[nm
,hoVb?
yZU`zN
`S7T+=
gjH\z1
D{16F!@
^eY3=N
T"~z@WS+
$BeCjE
x/X[cQ
j1[9ir
0pw!3b
6>nWy7
D'F<y tnX
,b^WM}
'k)^5!WK
($Dq+C
~N8]E'w
+)F[~w'
>f}Os]
Y"Yz?R-
MWQ)c;Q
m.#?w+[
}j?#6Y
_y:Xz7
z;.,{'nz"SsP
&MA1*>
F39J4K
O#4rl(
5IB3F|bh
1|^ |*
KX[Y5FE
Tl\a,Q@
*JDx2q_N
D&B%md
$* /g`
-Sp35P
wxr""/p
wr""/p
ozR1ML
oLLLLL
wwwwwwwxp
"""""/
"""""/
wwwwwwww
zz1111MMM
^zz1111MM
^zz1111M
^zz1111
^zz111
0<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
    <application>
      <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
      <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
    </application>
  </compatibility></assembly>
VeriSign, Inc.1
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
110401000000Z
130519235959Z0
Washington1
Bellevue1
Pinball Corporation.1>0<
5Digital ID Class 3 - Microsoft Software Validation v21
Pinball Corporation.0
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
https://www.verisign.com/rpa0
http://ocsp.verisign.com0;
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
>cX?>g
VeriSign, Inc.1
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
100208000000Z
200207235959Z0
VeriSign, Inc.1
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0
[0Y0W0U
	image/gif0!0
#http://logo.verisign.com/vslogo.gif04
#http://crl.verisign.com/pca3-g5.crl04
http://ocsp.verisign.com0
VeriSignMPKI-2-80
VeriSign, Inc.1
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA