Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2019-Jun-23 09:20:02 |
Detected languages |
English - United States
|
Suspicious | The PE is possibly packed. |
Unusual section name found: .didata
Unusual section name found: .kyua0 Unusual section name found: .kyua1 |
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Suspicious | The PE header may have been manually modified. |
The resource timestamps differ from the PE header:
|
Malicious | VirusTotal score: 19/68 (Scanned on 2019-06-23 09:43:15) |
Bkav:
HW32.Packed.
FireEye: Generic.mg.26f38d53a07de98f Malwarebytes: Adware.DLAssistant.Generic Symantec: ML.Attribute.HighConfidence ESET-NOD32: a variant of Win32/DownloadAssistant.S potentially unwanted APEX: Malicious Kaspersky: not-a-virus:HEUR:Downloader.Win32.Generic Sophos: Download Assistant (PUA) Invincea: heuristic SentinelOne: DFI - Malicious PE Microsoft: PUA:Win32/Puwaders.B!ml Endgame: malicious (high confidence) ZoneAlarm: not-a-virus:HEUR:Downloader.Win32.Generic Acronis: suspicious Cylance: Unsafe Rising: PUA.DownloadAssistant!8.182 (TFE:dGZlOgVh8c8aN829IA) eGambit: PE.Heur.InvalidSig CrowdStrike: win/malicious_confidence_80% (D) Qihoo-360: HEUR/QVM19.1.0DBD.Malware.Gen |
e_magic | MZ |
---|---|
e_cblp | 0x50 |
e_cp | 0x2 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0xf |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0x1a |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0x80 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 10 |
TimeDateStamp | 2019-Jun-23 09:20:02 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x387000 |
SizeOfInitializedData | 0x3e200 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0075DECE (Section: .kyua1) |
BaseOfCode | 0x1000 |
BaseOfData | 0x388000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.0 |
ImageVersion | 0.0 |
SubsystemVersion | 5.0 |
Win32VersionValue | 0 |
SizeOfImage | 0xacb000 |
SizeOfHeaders | 0x600 |
Checksum | 0x4d7f3f |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x4000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
ADVAPI32.DLL |
ConvertSidToStringSidA
GetTokenInformation GetUserNameA OpenProcessToken RegCloseKey RegConnectRegistryW RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegFlushKey RegLoadKeyW RegOpenKeyExA RegOpenKeyExW RegQueryInfoKeyW RegQueryValueExA RegQueryValueExW RegReplaceKeyW RegRestoreKeyW RegSaveKeyW RegSetValueExW RegUnLoadKeyW |
---|---|
KERNEL32.DLL |
CloseHandle
CompareStringW CreateDirectoryA CreateEventW CreateFileA CreateFileW CreateMutexW CreateProcessW CreateThread DeleteCriticalSection DeleteFileA EnterCriticalSection EnumCalendarInfoW EnumResourceNamesW EnumSystemLocalesW ExitProcess ExitThread ExpandEnvironmentStringsA FileTimeToSystemTime FindClose FindFirstFileW FindResourceW FormatMessageW FreeLibrary FreeResource GetACP GetCPInfo GetCPInfoExW GetCommandLineW GetComputerNameW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDiskFreeSpaceW GetEnvironmentStringsW GetExitCodeThread GetFileAttributesA GetFileAttributesW GetFileSize GetFileType GetFullPathNameW GetLastError GetLocalTime GetLocaleInfoA GetLocaleInfoW GetLogicalDriveStringsA GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoA GetStartupInfoW GetStdHandle GetStringTypeA GetStringTypeW GetSystemDefaultLangID GetSystemDefaultUILanguage GetSystemInfo GetTempPathA GetThreadLocale GetThreadPriority GetTickCount GetTimeZoneInformation GetUserDefaultLCID GetUserDefaultUILanguage GetVersion GetVersionExA GetVersionExW GetVolumeInformationA GlobalAddAtomW GlobalAlloc GlobalDeleteAtom GlobalFindAtomW GlobalFree GlobalLock GlobalUnlock HeapAlloc HeapCreate HeapDestroy HeapFree HeapSize InitializeCriticalSection InterlockedDecrement InterlockedExchange InterlockedIncrement IsDBCSLeadByteEx IsDebuggerPresent IsValidLocale LCMapStringA LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadLibraryW LoadResource LocalAlloc LocalFree LockResource MulDiv MultiByteToWideChar OpenProcess OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadFile ReleaseMutex ResetEvent ResumeThread RtlUnwind SetConsoleCtrlHandler SetEndOfFile SetErrorMode SetEvent SetFilePointer SetHandleCount SetLastError SetThreadLocale SetThreadPriority SizeofResource Sleep SuspendThread SwitchToThread TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection UnhandledExceptionFilter VerSetConditionMask VerifyVersionInfoW VirtualAlloc VirtualFree VirtualProtect VirtualQuery VirtualQueryEx WaitForMultipleObjectsEx WaitForSingleObject WideCharToMultiByte WriteFile lstrcmpW lstrlenW |
NETAPI32.DLL |
NetApiBufferFree
NetWkstaGetInfo |
VERSION.DLL |
GetFileVersionInfoA
GetFileVersionInfoSizeA GetFileVersionInfoSizeW GetFileVersionInfoW VerQueryValueA VerQueryValueW |
WINSPOOL.DRV |
ClosePrinter
DocumentPropertiesW EnumPrintersW #203 OpenPrinterW |
COMCTL32.DLL |
FlatSB_GetScrollInfo
FlatSB_GetScrollPos FlatSB_SetScrollInfo FlatSB_SetScrollPos FlatSB_SetScrollProp ImageList_Add ImageList_BeginDrag ImageList_Copy ImageList_Create ImageList_Destroy ImageList_DragEnter ImageList_DragLeave ImageList_DragMove ImageList_DragShowNolock ImageList_Draw ImageList_DrawEx ImageList_EndDrag ImageList_GetBkColor ImageList_GetDragImage ImageList_GetIcon ImageList_GetIconSize ImageList_GetImageCount ImageList_GetImageInfo ImageList_LoadImageW ImageList_Read ImageList_Remove ImageList_Replace ImageList_ReplaceIcon ImageList_SetBkColor ImageList_SetIconSize ImageList_SetImageCount ImageList_SetOverlayImage ImageList_Write #17 InitializeFlatSB _TrackMouseEvent |
DWMAPI.DLL | (EMPTY) |
GDI32.DLL |
AbortDoc
AngleArc Arc ArcTo BitBlt Chord CombineRgn CopyEnhMetaFileW CreateBitmap CreateBrushIndirect CreateCompatibleBitmap CreateCompatibleDC CreateDCW CreateDIBSection CreateDIBitmap CreateFontIndirectW CreateHalftonePalette CreateICW CreatePalette CreatePenIndirect CreateRectRgn CreateSolidBrush DeleteDC DeleteEnhMetaFile DeleteObject Ellipse EndDoc EndPage EnumFontFamiliesExW EnumFontsW ExcludeClipRect ExtFloodFill ExtTextOutW FrameRgn GdiFlush GetBitmapBits GetBkMode GetBrushOrgEx GetClipBox GetCurrentPositionEx GetDIBColorTable GetDIBits GetDeviceCaps GetEnhMetaFileBits GetEnhMetaFileDescriptionW GetEnhMetaFileHeader GetEnhMetaFilePaletteEntries GetNearestPaletteIndex GetObjectW GetPaletteEntries GetPixel GetRgnBox GetStockObject GetStretchBltMode GetSystemPaletteEntries GetTextExtentPoint32W GetTextExtentPointW GetTextMetricsW GetWinMetaFileBits GetWindowOrgEx IntersectClipRect LineTo MaskBlt MoveToEx PatBlt Pie PlayEnhMetaFile PolyBezier PolyBezierTo Polygon Polyline RealizePalette RectVisible Rectangle ResizePalette RestoreDC RoundRect SaveDC SelectClipRgn SelectObject SelectPalette SetAbortProc SetBkColor SetBkMode SetBrushOrgEx SetDIBColorTable SetDIBits SetEnhMetaFileBits SetMapMode SetPixel SetROP2 SetRectRgn SetStretchBltMode SetTextColor SetViewportOrgEx SetWinMetaFileBits SetWindowOrgEx StartDocW StartPage StretchBlt StretchDIBits UnrealizeObject |
MSIMG32.DLL | (EMPTY) |
SHELL32.DLL |
ShellExecuteW
Shell_NotifyIconW #190 #155 SHOpenFolderAndSelectItems |
SHFOLDER.DLL |
SHGetFolderPathA
|
USER32.DLL |
ActivateKeyboardLayout
AdjustWindowRectEx BeginPaint CallNextHookEx CallWindowProcW CharLowerBuffW CharLowerW CharNextW CharUpperBuffW CharUpperW CheckMenuItem ChildWindowFromPoint ClientToScreen CloseClipboard CopyIcon CopyImage CreateAcceleratorTableW CreateIcon CreateMenu CreatePopupMenu CreateWindowExW DefFrameProcW DefMDIChildProcW DefWindowProcW DeleteMenu DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageA DispatchMessageW DrawEdge DrawFocusRect DrawFrameControl DrawIcon DrawIconEx DrawMenuBar DrawTextExW DrawTextW EmptyClipboard EnableMenuItem EnableScrollBar EnableWindow EndMenu EndPaint EnumChildWindows EnumDisplayDevicesW EnumDisplayMonitors EnumThreadWindows EnumWindows FillRect FindWindowExW FindWindowW FrameRect GetActiveWindow GetCapture GetClassInfoW GetClassLongW GetClassNameW GetClientRect GetClipboardData GetCursor GetCursorPos GetDC GetDCEx GetDesktopWindow GetDlgCtrlID GetFocus GetForegroundWindow GetIconInfo GetKeyNameTextW GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardLayoutNameW GetKeyboardState GetLastActivePopup GetMenu GetMenuItemCount GetMenuItemID GetMenuItemInfoW GetMenuState GetMenuStringW GetMessageExtraInfo GetMessagePos GetMonitorInfoW GetParent GetPropW GetScrollBarInfo GetScrollInfo GetScrollPos GetScrollRange GetShellWindow GetSubMenu GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTopWindow GetUpdateRect GetWindow GetWindowDC GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId HideCaret InsertMenuItemW InsertMenuW InvalidateRect IsChild IsDialogMessageA IsDialogMessageW IsIconic IsWindow IsWindowEnabled IsWindowUnicode IsWindowVisible IsZoomed KillTimer LoadBitmapW LoadCursorW LoadIconW LoadKeyboardLayoutW LoadStringW LockWindowUpdate MapVirtualKeyW MapWindowPoints MessageBeep MessageBoxW MonitorFromPoint MonitorFromRect MonitorFromWindow MoveWindow MsgWaitForMultipleObjects MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageA PeekMessageW PostMessageW PostQuitMessage RedrawWindow RegisterClassW RegisterClipboardFormatW RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu RemovePropW ScreenToClient ScrollWindow SendMessageA SendMessageW SetActiveWindow SetCapture SetClassLongW SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetMenu SetMenuItemInfoW SetParent SetPropW SetRect SetScrollInfo SetScrollPos SetScrollRange SetTimer SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowCaret ShowOwnedPopups ShowScrollBar ShowWindow SystemParametersInfoW TrackPopupMenu TranslateMDISysAccel TranslateMessage UnhookWindowsHookEx UnregisterClassW UpdateWindow WaitMessage WindowFromPoint wsprintfA |
IMM32.DLL | (EMPTY) |
OLE32.DLL |
CoCreateInstance
CoInitialize CoInitializeEx CoInitializeSecurity CoSetProxyBlanket CoTaskMemAlloc CoTaskMemFree CoUninitialize IsEqualGUID OleInitialize OleUninitialize |
OLEAUT32.DLL |
#200
#15 #20 #19 #148 #2 #4 #6 #5 #12 #9 #10 #8 |
SHLWAPI.DLL |
AssocQueryStringW
PathFileExistsA PathFindFileNameW #156 StrFormatByteSizeW |
IPHLPAPI.DLL |
GetAdaptersInfo
|
WTSAPI32.DLL |
WTSEnumerateProcessesW
WTSFreeMemory |
WINDOWSCODECS.DLL | (EMPTY) |
UXTHEME.DLL | (EMPTY) |
SHCORE.DLL | (EMPTY) |
WINHTTP.DLL |
WinHttpAddRequestHeaders
WinHttpCloseHandle WinHttpConnect WinHttpGetIEProxyConfigForCurrentUser WinHttpGetProxyForUrl WinHttpOpen WinHttpOpenRequest WinHttpQueryAuthSchemes WinHttpQueryDataAvailable WinHttpQueryHeaders WinHttpQueryOption WinHttpReadData WinHttpReceiveResponse WinHttpSendRequest WinHttpSetCredentials WinHttpSetOption WinHttpSetStatusCallback WinHttpSetTimeouts WinHttpWriteData |
CRYPT32.DLL | (EMPTY) |
WTSAPI32.DLL (#2) |
WTSEnumerateProcessesW
WTSFreeMemory |
KERNEL32.DLL (#2) |
CloseHandle
CompareStringW CreateDirectoryA CreateEventW CreateFileA CreateFileW CreateMutexW CreateProcessW CreateThread DeleteCriticalSection DeleteFileA EnterCriticalSection EnumCalendarInfoW EnumResourceNamesW EnumSystemLocalesW ExitProcess ExitThread ExpandEnvironmentStringsA FileTimeToSystemTime FindClose FindFirstFileW FindResourceW FormatMessageW FreeLibrary FreeResource GetACP GetCPInfo GetCPInfoExW GetCommandLineW GetComputerNameW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDiskFreeSpaceW GetEnvironmentStringsW GetExitCodeThread GetFileAttributesA GetFileAttributesW GetFileSize GetFileType GetFullPathNameW GetLastError GetLocalTime GetLocaleInfoA GetLocaleInfoW GetLogicalDriveStringsA GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoA GetStartupInfoW GetStdHandle GetStringTypeA GetStringTypeW GetSystemDefaultLangID GetSystemDefaultUILanguage GetSystemInfo GetTempPathA GetThreadLocale GetThreadPriority GetTickCount GetTimeZoneInformation GetUserDefaultLCID GetUserDefaultUILanguage GetVersion GetVersionExA GetVersionExW GetVolumeInformationA GlobalAddAtomW GlobalAlloc GlobalDeleteAtom GlobalFindAtomW GlobalFree GlobalLock GlobalUnlock HeapAlloc HeapCreate HeapDestroy HeapFree HeapSize InitializeCriticalSection InterlockedDecrement InterlockedExchange InterlockedIncrement IsDBCSLeadByteEx IsDebuggerPresent IsValidLocale LCMapStringA LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadLibraryW LoadResource LocalAlloc LocalFree LockResource MulDiv MultiByteToWideChar OpenProcess OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadFile ReleaseMutex ResetEvent ResumeThread RtlUnwind SetConsoleCtrlHandler SetEndOfFile SetErrorMode SetEvent SetFilePointer SetHandleCount SetLastError SetThreadLocale SetThreadPriority SizeofResource Sleep SuspendThread SwitchToThread TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection UnhandledExceptionFilter VerSetConditionMask VerifyVersionInfoW VirtualAlloc VirtualFree VirtualProtect VirtualQuery VirtualQueryEx WaitForMultipleObjectsEx WaitForSingleObject WideCharToMultiByte WriteFile lstrcmpW lstrlenW |
USER32.DLL (#2) |
ActivateKeyboardLayout
AdjustWindowRectEx BeginPaint CallNextHookEx CallWindowProcW CharLowerBuffW CharLowerW CharNextW CharUpperBuffW CharUpperW CheckMenuItem ChildWindowFromPoint ClientToScreen CloseClipboard CopyIcon CopyImage CreateAcceleratorTableW CreateIcon CreateMenu CreatePopupMenu CreateWindowExW DefFrameProcW DefMDIChildProcW DefWindowProcW DeleteMenu DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageA DispatchMessageW DrawEdge DrawFocusRect DrawFrameControl DrawIcon DrawIconEx DrawMenuBar DrawTextExW DrawTextW EmptyClipboard EnableMenuItem EnableScrollBar EnableWindow EndMenu EndPaint EnumChildWindows EnumDisplayDevicesW EnumDisplayMonitors EnumThreadWindows EnumWindows FillRect FindWindowExW FindWindowW FrameRect GetActiveWindow GetCapture GetClassInfoW GetClassLongW GetClassNameW GetClientRect GetClipboardData GetCursor GetCursorPos GetDC GetDCEx GetDesktopWindow GetDlgCtrlID GetFocus GetForegroundWindow GetIconInfo GetKeyNameTextW GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardLayoutNameW GetKeyboardState GetLastActivePopup GetMenu GetMenuItemCount GetMenuItemID GetMenuItemInfoW GetMenuState GetMenuStringW GetMessageExtraInfo GetMessagePos GetMonitorInfoW GetParent GetPropW GetScrollBarInfo GetScrollInfo GetScrollPos GetScrollRange GetShellWindow GetSubMenu GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTopWindow GetUpdateRect GetWindow GetWindowDC GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId HideCaret InsertMenuItemW InsertMenuW InvalidateRect IsChild IsDialogMessageA IsDialogMessageW IsIconic IsWindow IsWindowEnabled IsWindowUnicode IsWindowVisible IsZoomed KillTimer LoadBitmapW LoadCursorW LoadIconW LoadKeyboardLayoutW LoadStringW LockWindowUpdate MapVirtualKeyW MapWindowPoints MessageBeep MessageBoxW MonitorFromPoint MonitorFromRect MonitorFromWindow MoveWindow MsgWaitForMultipleObjects MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageA PeekMessageW PostMessageW PostQuitMessage RedrawWindow RegisterClassW RegisterClipboardFormatW RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu RemovePropW ScreenToClient ScrollWindow SendMessageA SendMessageW SetActiveWindow SetCapture SetClassLongW SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetMenu SetMenuItemInfoW SetParent SetPropW SetRect SetScrollInfo SetScrollPos SetScrollRange SetTimer SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowCaret ShowOwnedPopups ShowScrollBar ShowWindow SystemParametersInfoW TrackPopupMenu TranslateMDISysAccel TranslateMessage UnhookWindowsHookEx UnregisterClassW UpdateWindow WaitMessage WindowFromPoint wsprintfA |
KERNEL32.DLL (#3) |
CloseHandle
CompareStringW CreateDirectoryA CreateEventW CreateFileA CreateFileW CreateMutexW CreateProcessW CreateThread DeleteCriticalSection DeleteFileA EnterCriticalSection EnumCalendarInfoW EnumResourceNamesW EnumSystemLocalesW ExitProcess ExitThread ExpandEnvironmentStringsA FileTimeToSystemTime FindClose FindFirstFileW FindResourceW FormatMessageW FreeLibrary FreeResource GetACP GetCPInfo GetCPInfoExW GetCommandLineW GetComputerNameW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDiskFreeSpaceW GetEnvironmentStringsW GetExitCodeThread GetFileAttributesA GetFileAttributesW GetFileSize GetFileType GetFullPathNameW GetLastError GetLocalTime GetLocaleInfoA GetLocaleInfoW GetLogicalDriveStringsA GetModuleFileNameA GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetOEMCP GetProcAddress GetProcessHeap GetStartupInfoA GetStartupInfoW GetStdHandle GetStringTypeA GetStringTypeW GetSystemDefaultLangID GetSystemDefaultUILanguage GetSystemInfo GetTempPathA GetThreadLocale GetThreadPriority GetTickCount GetTimeZoneInformation GetUserDefaultLCID GetUserDefaultUILanguage GetVersion GetVersionExA GetVersionExW GetVolumeInformationA GlobalAddAtomW GlobalAlloc GlobalDeleteAtom GlobalFindAtomW GlobalFree GlobalLock GlobalUnlock HeapAlloc HeapCreate HeapDestroy HeapFree HeapSize InitializeCriticalSection InterlockedDecrement InterlockedExchange InterlockedIncrement IsDBCSLeadByteEx IsDebuggerPresent IsValidLocale LCMapStringA LCMapStringW LeaveCriticalSection LoadLibraryA LoadLibraryExW LoadLibraryW LoadResource LocalAlloc LocalFree LockResource MulDiv MultiByteToWideChar OpenProcess OutputDebugStringW QueryPerformanceCounter QueryPerformanceFrequency RaiseException ReadFile ReleaseMutex ResetEvent ResumeThread RtlUnwind SetConsoleCtrlHandler SetEndOfFile SetErrorMode SetEvent SetFilePointer SetHandleCount SetLastError SetThreadLocale SetThreadPriority SizeofResource Sleep SuspendThread SwitchToThread TerminateThread TlsAlloc TlsFree TlsGetValue TlsSetValue TryEnterCriticalSection UnhandledExceptionFilter VerSetConditionMask VerifyVersionInfoW VirtualAlloc VirtualFree VirtualProtect VirtualQuery VirtualQueryEx WaitForMultipleObjectsEx WaitForSingleObject WideCharToMultiByte WriteFile lstrcmpW lstrlenW |
USER32.DLL (#3) |
ActivateKeyboardLayout
AdjustWindowRectEx BeginPaint CallNextHookEx CallWindowProcW CharLowerBuffW CharLowerW CharNextW CharUpperBuffW CharUpperW CheckMenuItem ChildWindowFromPoint ClientToScreen CloseClipboard CopyIcon CopyImage CreateAcceleratorTableW CreateIcon CreateMenu CreatePopupMenu CreateWindowExW DefFrameProcW DefMDIChildProcW DefWindowProcW DeleteMenu DestroyCursor DestroyIcon DestroyMenu DestroyWindow DispatchMessageA DispatchMessageW DrawEdge DrawFocusRect DrawFrameControl DrawIcon DrawIconEx DrawMenuBar DrawTextExW DrawTextW EmptyClipboard EnableMenuItem EnableScrollBar EnableWindow EndMenu EndPaint EnumChildWindows EnumDisplayDevicesW EnumDisplayMonitors EnumThreadWindows EnumWindows FillRect FindWindowExW FindWindowW FrameRect GetActiveWindow GetCapture GetClassInfoW GetClassLongW GetClassNameW GetClientRect GetClipboardData GetCursor GetCursorPos GetDC GetDCEx GetDesktopWindow GetDlgCtrlID GetFocus GetForegroundWindow GetIconInfo GetKeyNameTextW GetKeyState GetKeyboardLayout GetKeyboardLayoutList GetKeyboardLayoutNameW GetKeyboardState GetLastActivePopup GetMenu GetMenuItemCount GetMenuItemID GetMenuItemInfoW GetMenuState GetMenuStringW GetMessageExtraInfo GetMessagePos GetMonitorInfoW GetParent GetPropW GetScrollBarInfo GetScrollInfo GetScrollPos GetScrollRange GetShellWindow GetSubMenu GetSysColor GetSysColorBrush GetSystemMenu GetSystemMetrics GetTopWindow GetUpdateRect GetWindow GetWindowDC GetWindowLongW GetWindowPlacement GetWindowRect GetWindowTextW GetWindowThreadProcessId HideCaret InsertMenuItemW InsertMenuW InvalidateRect IsChild IsDialogMessageA IsDialogMessageW IsIconic IsWindow IsWindowEnabled IsWindowUnicode IsWindowVisible IsZoomed KillTimer LoadBitmapW LoadCursorW LoadIconW LoadKeyboardLayoutW LoadStringW LockWindowUpdate MapVirtualKeyW MapWindowPoints MessageBeep MessageBoxW MonitorFromPoint MonitorFromRect MonitorFromWindow MoveWindow MsgWaitForMultipleObjects MsgWaitForMultipleObjectsEx OpenClipboard PeekMessageA PeekMessageW PostMessageW PostQuitMessage RedrawWindow RegisterClassW RegisterClipboardFormatW RegisterWindowMessageW ReleaseCapture ReleaseDC RemoveMenu RemovePropW ScreenToClient ScrollWindow SendMessageA SendMessageW SetActiveWindow SetCapture SetClassLongW SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetMenu SetMenuItemInfoW SetParent SetPropW SetRect SetScrollInfo SetScrollPos SetScrollRange SetTimer SetWindowLongW SetWindowPlacement SetWindowPos SetWindowRgn SetWindowTextW SetWindowsHookExW ShowCaret ShowOwnedPopups ShowScrollBar ShowWindow SystemParametersInfoW TrackPopupMenu TranslateMDISysAccel TranslateMessage UnhookWindowsHookEx UnregisterClassW UpdateWindow WaitMessage WindowFromPoint wsprintfA |
ADVAPI32.DLL (delay-loaded) |
ConvertSidToStringSidA
GetTokenInformation GetUserNameA OpenProcessToken RegCloseKey RegConnectRegistryW RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegEnumValueW RegFlushKey RegLoadKeyW RegOpenKeyExA RegOpenKeyExW RegQueryInfoKeyW RegQueryValueExA RegQueryValueExW RegReplaceKeyW RegRestoreKeyW RegSaveKeyW RegSetValueExW RegUnLoadKeyW |
Attributes | 0x1 |
---|---|
Name | ADVAPI32.DLL |
ModuleHandle | 0x3ce1a0 |
DelayImportAddressTable | 0x3ce1a4 |
DelayImportNameTable | 0x8a42a4 |
BoundDelayImportTable | 0x3ce1b4 |
UnloadDelayImportTable | 0x3ce1bc |
TimeStamp | 1970-Jan-01 00:00:00 |
Ordinal | 1 |
---|---|
Address | 0x2343 |
Ordinal | 2 |
---|---|
Address | 0x82380 |
Ordinal | 3 |
---|---|
Address | 0x3880ac |
Ordinal | 4 |
---|---|
Address | 0x3b8a1c |
It's not allowed to add a new chunk because the current image is invalid. |
The png image could not be loaded from the resource ID. |
Some operation could not be performed because the system is out of resources. Close some windows and try again. |
Setting bit transparency color is not allowed for png images containing alpha value for each pixel (COLOR_RGBALPHA and COLOR_GRAYSCALEALPHA) |
This operation is not valid because the current image contains no valid header. |
The new size provided for image resizing is invalid. |
The "Portable Network Graphics" could not be created because invalid image type parameters have being provided. |
The "Portable Network Graphics" image could not be loaded because it uses an invalid image bit depth. |
Error on call to Winsock2 library function %s |
Error on loading Winsock2 library (%s) |
The "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corrupted |
This "Portable Network Graphics" image is invalid because it has missing image parts. |
Could not decompress the image because it contains invalid compressed data. |
Description: |
The "Portable Network Graphics" image contains an invalid palette. |
The file being read is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corrupted, try obtaining it again |
This "Portable Network Graphics" image is not supported or it might be invalid. |
(IHDR chunk is not the first) |
This "Portable Network Graphics" image is not supported because either its width or height exceeds the maximum size of 65535 pixels. |
There is no such palette entry. |
This "Portable Network Graphics" image contains an unknown critical part which could not be decoded. |
This "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded. |
This "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded. |
This "Portable Network Graphics" image uses an unknown color type which could not be decoded. |
The chunks must be compatible to be assigned. |
This "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file. |
This "Portable Network Graphics" image contains no data. |
The program tried to add a existent critical chunk to the current image which is not allowed. |
Invalid index |
Unable to insert an item |
Invalid owner |
RichEdit line insertion error |
Failed to Load Stream |
Failed to Save Stream |
%s is already associated with %s |
This control requires version 4.70 or greater of COMCTL32.DLL |
Date exceeds maximum of %s |
Date is less than minimum of %s |
You must be in ShowCheckbox mode to set to this date |
Failed to set calendar date or time |
Failed to set maximum selection range |
Failed to set calendar min/max range |
Failed to set calendar selected range |
This "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error) |
Class '%s' is not registered for '%s' |
%s parameter cannot be nil |
Feature not supported by this style |
Style '%s' is not registered |
Cannot unregister the system style |
Style not registered |
Cannot call BeginInvoke on a control with no parent or window handle |
Failed to clear tab control |
Failed to delete tab at index %d |
Failed to retrieve tab at index %d |
Failed to get object at index %d |
Failed to set tab "%s" at index %d |
Failed to set object at index %d |
MultiLine must be True when TabPosition is tpLeft or tpRight |
Invalid item level assignment |
Invalid level (%d) for item "%s" |
Cannot remove shell notification icon |
%s requires Windows Vista or later |
Button%d |
RadioButton%d |
Caption cannot be empty |
CategoryPanel must have a CategoryPanelGroup as its parent |
Only CategoryPanels can be inserted into a CategoryPanelGroup |
Unable to load style '%s' |
Unable to load styles: %s |
Style '%s' already registered |
Style class '%s' already registered |
Style '%s' not found |
Style class '%s' not found |
Invalid style handle |
Invalid style format |
Class '%s' is already registered for '%s' |
Docked control must have a name |
Error removing control from dock tree |
- Dock zone not found |
- Dock zone has no control |
Error loading dock zone from the stream. Expecting version %d, but found %d. |
Multiselect mode must be on for this feature |
Length of value array must be >= length of prompt array |
Prompt array must not be empty |
&Username |
&Password |
&Domain |
Login |
Separator |
Error setting %s.Count |
Listbox (%s) style must be virtual in order to set Count |
No OnGetItem event handler assigned |
Right |
Down |
Ins |
Del |
Shift+ |
Ctrl+ |
Alt+ |
Value must be between %d and %d |
All |
Unable to insert a line |
Clipboard does not support Icons |
Cannot open clipboard: %s |
Text exceeds memo capacity |
Operation not supported on selected printer |
There is no default printer currently selected |
Menu '%s' is already being used by another form |
&Ignore |
&All |
N&o to All |
Yes to &All |
&Close |
BkSp |
Tab |
Esc |
Enter |
Space |
PgUp |
PgDn |
End |
Home |
Left |
Up |
Metafiles |
Enhanced Metafiles |
Icons |
Bitmaps |
TIFF Images |
Warning |
Error |
Information |
Confirm |
&Yes |
&No |
OK |
Cancel |
&Help |
&Abort |
&Retry |
Scrollbar property out of range |
%s property out of range |
Menu index out of range |
Menu inserted twice |
Sub-menu is not in menu |
Not enough timers available |
Printer is not currently printing |
Printing in progress |
Printer index out of range |
Printer selected is not valid |
%s on %s |
GroupIndex cannot be less than a previous menu item's GroupIndex |
Cannot create form. No MDI forms are currently active |
Can only modify an image if it contains a bitmap |
A control cannot have itself as its parent |
Cannot drag a form |
Invalid image size |
Invalid ImageList |
Unable to Replace Image |
Unable to Insert Image |
Invalid ImageList Index |
Failed to read ImageList data from stream |
Failed to write ImageList data to stream |
Error creating window device context |
Error creating window class |
Cannot focus a disabled or invisible window |
Control '%s' has no parent window |
. Path: |
%s |
Parent given is not a parent of '%s' |
Cannot hide an MDI Child Form |
Cannot change Visible in OnShow or OnHide |
Cannot make a visible window modal |
Tab position incompatible with current tab style |
Tab style incompatible with current tab position |
Bitmap image is not valid |
Icon image is not valid |
Metafile is not valid |
Invalid pixel format |
Invalid image |
Scan line index out of range |
Cannot change the size of an icon |
Cannot change the size of a WIC Image |
Unknown picture file extension (.%s) |
Unsupported clipboard format |
Unsupported stream format |
Out of system resources |
Canvas does not allow drawing |
Text format flag '%s' not supported |
Error querying headers: (%d) %s |
Error obtaining session handle |
Error sending data: (%d) %s |
Error receiving data: (%d) %s |
Error connecting to server: %s |
Error opening request: (%d) %s |
Error adding header: (%d) %s |
Error removing header: (%d) %s |
Error reading data: (%d) %s |
Error setting timeout for the request: (%d) %s |
Pair of extension and mime type already exists |
Mime type cannot be empty |
OLE error %.8x |
Method '%s' not supported by automation object |
Variant does not reference an automation object |
Dispatch methods do not support more than 64 parameters |
Credential without user and password |
Platform-dependant function not implemented |
Scheme-dependant function not implemented |
Method already assigned |
URL already assigned |
Parameter index (%d) out of range (%d..%d) |
Invalid URL: "%s" |
Parameter "%s" not found |
Maximum number of redirections (%d) exceeded |
Error getting Server Certificate |
Server Certificate Invalid or not present |
Server Certificate not accepted |
Empty certificate list |
Unspecified certificate from client |
Client rejected the certificate |
Execution of request terminated with unknown error |
UTF8: A start byte not followed by enough continuation bytes |
UTF8: An unexpected continuation byte in %d-byte UTF8 |
UTF8: Type cannot be determined out of header byte |
The input value is not a valid JSON |
. Path '%s', line %d, position %d (offset %d) |
The nesting level of JSON arrays / objects is greater than %d |
Value '%s' not found |
Value %s cannot be added to %s |
Unexpected char for root element: . |
Path ended with an open bracket |
Path ended with an open string |
Invalid index for array: %s |
Unexpected character while parsing indexer: %s |
Empty name not allowed in dot notation, use [''] |
Scheme "%s" already registered for %s |
Scheme "%s" is not registered |
Cannot construct an ITask in this manner |
List of tasks to Join method empty |
At least one task in array nil |
Cannot start a task that has already completed |
One or more tasks were cancelled |
One or more errors occurred |
Must wait on at least one event |
Cannot call BeginInvoke on a TComponent in the process of destruction |
A regular expression specified in RegEx is required |
Error in regular expression at offset %d: %s |
Error studying the regex: %s |
Successful match required |
Strings parameter cannot be nil |
Invalid index type |
Index out of bounds (%d) |
Invalid group name (%s) |
Windows 8 |
Windows 8.1 |
Windows 10 |
Observer is not supported |
Cannot have multiple single cast observers added to the observers collection |
The object does not implement the observer interface |
No single cast observer with ID %d was added to the observer collection |
No multi cast observer with ID %d was added to the observer collection |
Observer is not available |
Invalid date string: %s |
Invalid time string: %s |
Invalid time Offset string: %s |
Error decoding URL style (%%XX) encoded string at position %d |
Invalid URL encoded character (%s) at position %d |
The Break method was previously called. Break and Stop may not be used in combination in iterations of the same loop |
The Stop method was previously called. Break and Stop may not be used in combination in iterations of the same loop |
%s (Version %d.%d, Build %d, %5:s) |
%s Service Pack %4:d (Version %1:d.%2:d, Build %3:d, %5:s) |
32-bit Edition |
64-bit Edition |
Windows |
Windows Vista |
Windows Server 2008 |
Windows 7 |
Windows Server 2008 R2 |
Windows 2000 |
Windows XP |
Windows Server 2003 |
Windows Server 2003 R2 |
Windows Server 2012 |
Windows Server 2012 R2 |
Windows Server 2016 |
No help found for context %d |
Unable to open Index |
Unable to open Search |
Unable to find a Table of Contents |
No topic-based help system installed |
No help found for %s |
Argument out of range |
Argument must not be nil |
Unbalanced stack or queue operation |
Item not found |
Duplicates not allowed |
Insufficient RTTI available to support this operation |
Parameter count mismatch |
Type '%s' is not declared in the interface section of a unit |
VAR and OUT arguments must match parameter type exactly |
Specified Login Credential Service not found |
Invalid Timeout value: %s |
SpinCount out of range. Must be between 0 and %d |
Invalid Reset Count: %d |
Invalid Count: %d |
Invalid Decrement Count: %d |
Invalid Increment Count: %d |
Decrement amount will cause invalid results: Count: %d, CurCount: %d |
Count already max: Amount: %d, CurCount: %d |
Countdown already reached zero (0) |
Timespan too long |
The duration cannot be returned because the absolute value exceeds the value of TTimeSpan.MaxValue |
Value cannot be NaN |
Negating the minimum value of a Timespan is invalid |
Invalid Timespan format |
Timespan element too long |
No context-sensitive help installed |
Parameter %s cannot be nil |
Parameter %s cannot be a negative value |
Input buffer exceeded for %s = %d, %s = %d |
Invalid characters in path |
? |
The given "%s" local time is invalid (situated within the missing period prior to DST). |
No help viewer that supports filters |
Invalid argument |
Index out of range (%d). Must be >= 0 and < %d |
String index out of range (%d). Must be >= %d and <= %d |
Invalid UTF32 character value. Must be >= 0 and <= $10FFFF, excluding surrogate pair ranges |
High surrogate char without a following low surrogate char at index: %d. Check that the string is encoded properly |
Low surrogate char without a preceding high surrogate char at index: %d. Check that the string is encoded properly |
Length of Strings and Objects arrays must be equal |
Source and Destination arrays must not be the same |
Class %s is not intended to be constructed |
Failed to set data for '%s' |
Resource %s not found |
%s.Seek not implemented |
Operation not allowed on sorted list |
String expected |
%s expected |
%s not in a class registration group |
Property %s does not exist |
Stream write error |
Thread creation error: %s |
Thread Error: %s (%d) |
Cannot terminate an externally created thread |
Cannot wait for an externally created thread |
Cannot call Start on a running or suspended thread |
Cannot call CheckTerminated on an externally created thread |
Cannot call SetReturnValue on an externally create thread |
Invalid data type for '%s' |
Invalid string constant |
Line too long |
List capacity out of bounds (%d) |
List count out of bounds (%d) |
List index out of bounds (%d) |
Out of memory while expanding memory stream |
%s has not been registered as a COM class |
Number expected |
ANSI or UTF8 encoding expected |
%s on line %d |
Error reading %s%s%s: %s |
Stream read error |
Property is read-only |
Failed to create key %s |
Failed to get data for '%s' |
CheckSynchronize called from thread $%x, which is NOT the main thread |
Class %s not found |
A class named %s already exists |
List does not allow duplicates ($0%x) |
A component named %s already exists |
String list does not allow duplicates |
Cannot create file "%s". %s |
Cannot open file "%s". %s |
Identifier expected |
Invalid binary value |
Invalid stream format |
'%s' is an invalid mask at (%d) |
''%s'' is not a valid component name |
Invalid property value |
Invalid property path |
Invalid property value |
Invalid source array |
Invalid destination array |
Character index out of bounds (%d) |
Start index out of bounds (%d) |
Invalid count (%d) |
Invalid destination index (%d) |
Invalid code page |
Invalid encoding name |
No mapping for the Unicode character exists in the target multi-byte code page |
Invalid StringBaseIndex |
Operation Cancelled |
Ancestor for '%s' not found |
Cannot assign a %s to a %s |
Bits index out of range |
Can't write to a read-only resource stream |
''%s'' expected |
November |
December |
Sun |
Mon |
Tue |
Wed |
Thu |
Fri |
Sat |
Sunday |
Monday |
Tuesday |
Wednesday |
Thursday |
Friday |
Saturday |
Jul |
Aug |
Sep |
Oct |
Nov |
Dec |
January |
February |
March |
April |
May |
June |
July |
August |
September |
October |
Exception in safecall method |
Object lock not owned |
Monitor support function not initialized |
Feature not implemented |
Method called on disposed object |
%s (%s, line %d) |
Abstract Error |
Access violation at address %p in module '%s'. %s of address %p |
System Error. Code: %d. |
%s%s |
A call to an OS function failed |
Jan |
Feb |
Mar |
Apr |
May |
Jun |
Invalid NULL variant operation |
Invalid variant operation (%s%.8x) |
%s |
Custom variant type (%s%.4x) is out of range |
Custom variant type (%s%.4x) already used by %s |
Custom variant type (%s%.4x) is not usable |
Too many custom variant types have been registered |
Could not convert variant of type (%s) into type (%s) |
Overflow while converting variant of type (%s) into type (%s) |
Variant overflow |
Invalid argument |
Invalid variant type |
Operation not supported |
Unexpected variant error |
External exception %x |
Assertion failed |
Interface not supported |
Control-C hit |
Privileged instruction |
Exception %s in module %s at %p. |
%s%s |
Application Error |
Format '%s' invalid or incompatible with argument |
No argument for format '%s' |
Variant method calls not supported |
Read |
Write |
Execution |
Invalid access |
Error creating variant or safe array |
Variant or safe array index out of bounds |
Variant or safe array is locked |
Invalid variant type conversion |
Invalid variant operation |
File access denied |
Read beyond end of file |
Disk full |
Invalid numeric input |
Division by zero |
Range check error |
Integer overflow |
Invalid floating point operation |
Floating point division by zero |
Floating point overflow |
Floating point underflow |
Invalid pointer operation |
Invalid class typecast |
Access violation at address %p. %s of address %p |
Access violation |
Stack overflow |
<unknown> |
'%s' is not a valid integer value |
'%s' is not a valid integer value for %s type |
'%s' is not a valid floating point value |
'%s' is not a valid floating point value for %s type |
'%s' is not a valid date and time |
'%d.%d' is not a valid timestamp |
'%s' is not a valid GUID value |
'%s' is not a valid boolean value |
Invalid argument to time encode |
Invalid argument to date encode |
Out of memory |
I/O error %d |
File not found |
Invalid filename |
Too many open files |