Analysis Details
Category Package Started Completed Duration Logs
FILE exe 2026-03-08 09:34:31 2026-03-08 09:36:28 117s
Reports JSON
Analysis Log
2026-03-05 20:34:38,257 [root] INFO: Date set to: 20260308T09:35:18, timeout set to: 60
2026-03-08 09:35:18,131 [root] DEBUG: Starting analyzer from: C:\vdyc7mjt
2026-03-08 09:35:18,194 [root] DEBUG: Storing results at: C:\pFgSGb
2026-03-08 09:35:18,209 [root] DEBUG: Pipe server name: \\.\PIPE\iRkbqMIcVR
2026-03-08 09:35:18,240 [root] DEBUG: Python path: C:\Python310
2026-03-08 09:35:18,256 [root] INFO: analysis running as an admin
2026-03-08 09:35:18,272 [root] INFO: analysis package specified: "exe"
2026-03-08 09:35:18,272 [root] DEBUG: importing analysis package module: "modules.packages.exe"...
2026-03-08 09:35:18,287 [root] DEBUG: imported analysis package "exe"
2026-03-08 09:35:18,287 [root] DEBUG: initializing analysis package "exe"...
2026-03-08 09:35:18,287 [lib.common.common] INFO: wrapping
2026-03-08 09:35:18,287 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-03-08 09:35:18,287 [root] DEBUG: New location of moved file: C:\Users\cape\AppData\Local\Temp\strings.exe
2026-03-08 09:35:18,303 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL option
2026-03-08 09:35:18,303 [root] INFO: Analyzer: Package modules.packages.exe does not specify a DLL_64 option
2026-03-08 09:35:18,303 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader option
2026-03-08 09:35:18,319 [root] INFO: Analyzer: Package modules.packages.exe does not specify a loader_64 option
2026-03-08 09:35:18,631 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-03-08 09:35:18,725 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-03-08 09:35:18,740 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-03-08 09:35:18,756 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-03-08 09:35:18,803 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-03-08 09:35:18,834 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2026-03-08 09:35:18,928 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2026-03-08 09:35:20,100 [lib.api.screenshot] INFO: Please upgrade Pillow to >= 5.4.1 for best performance
2026-03-08 09:35:20,147 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-03-08 09:35:20,225 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-03-08 09:35:20,240 [root] DEBUG: Initialized auxiliary module "Browser"
2026-03-08 09:35:20,240 [root] DEBUG: attempting to configure 'Browser' from data
2026-03-08 09:35:20,256 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-03-08 09:35:20,256 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-03-08 09:35:20,256 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-03-08 09:35:20,256 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-03-08 09:35:20,256 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-03-08 09:35:20,256 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-03-08 09:35:20,272 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-03-08 09:35:20,272 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-03-08 09:35:21,256 [modules.auxiliary.digisig] DEBUG: File has a valid signature
2026-03-08 09:35:21,256 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-03-08 09:35:21,272 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-03-08 09:35:21,272 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-03-08 09:35:21,272 [root] DEBUG: attempting to configure 'Disguise' from data
2026-03-08 09:35:21,272 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-03-08 09:35:21,272 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-03-08 09:35:21,287 [modules.auxiliary.disguise] INFO: Disguising GUID to 339d92a4-c255-4420-97b0-5631bd58867a
2026-03-08 09:35:21,287 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-03-08 09:35:21,287 [root] DEBUG: Initialized auxiliary module "Human"
2026-03-08 09:35:21,287 [root] DEBUG: attempting to configure 'Human' from data
2026-03-08 09:35:21,287 [root] DEBUG: module Human does not support data configuration, ignoring
2026-03-08 09:35:21,287 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-03-08 09:35:21,303 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-03-08 09:35:21,303 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-03-08 09:35:21,303 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-03-08 09:35:21,303 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-03-08 09:35:21,303 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-03-08 09:35:21,459 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-03-08 09:35:21,459 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-03-08 09:35:21,459 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-03-08 09:35:21,459 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-03-08 09:35:21,459 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-03-08 09:35:21,522 [modules.auxiliary.tlsdump] INFO: lsass.exe found, pid 644
2026-03-08 09:35:21,584 [lib.api.process] INFO: Monitor config for <Process 644 lsass.exe>: C:\vdyc7mjt\dll\644.ini
2026-03-08 09:35:21,584 [lib.api.process] INFO: Option 'tlsdump' with value '1' sent to monitor
2026-03-08 09:35:21,662 [lib.api.process] INFO: 64-bit DLL to inject is C:\vdyc7mjt\dll\agsEkyC.dll, loader C:\vdyc7mjt\bin\HLnLkMTh.exe
2026-03-08 09:35:21,772 [root] DEBUG: Loader: Injecting process 644 with C:\vdyc7mjt\dll\agsEkyC.dll.
2026-03-08 09:35:51,584 [root] DEBUG: 644: Python path set to 'C:\Python310'.
2026-03-08 09:35:51,631 [root] DEBUG: 644: Disabling sleep skipping.
2026-03-08 09:35:51,662 [root] DEBUG: 644: TLS secret dump mode enabled.
2026-03-08 09:35:52,928 [root] DEBUG: 644: Yara error: Scanning timed out
2026-03-08 09:35:52,928 [root] DEBUG: 644: Monitor initialised: 64-bit capemon loaded in process 644 at 0x00007FFEABE90000, thread 1956, image base 0x00007FF7C23E0000, stack from 0x0000008E4CA71000-0x0000008E4CA80000
2026-03-08 09:35:52,928 [root] DEBUG: 644: Commandline: C:\Windows\system32\lsass.exe
2026-03-08 09:35:52,959 [root] DEBUG: 644: Hooked 5 out of 5 functions
2026-03-08 09:35:52,975 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-03-08 09:35:52,990 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\agsEkyC.dll.
2026-03-08 09:35:53,006 [lib.api.process] INFO: Injected into 64-bit <Process 644 lsass.exe>
2026-03-08 09:35:53,006 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-03-08 09:35:53,459 [root] DEBUG: 644: TLS 1.2 secrets logged to: C:\pFgSGb\tlsdump\tlsdump.log
2026-03-08 09:36:01,366 [root] INFO: Restarting WMI Service
2026-03-08 09:36:01,428 [root] DEBUG: package modules.packages.exe does not support configure, ignoring
2026-03-08 09:36:01,444 [root] WARNING: configuration error for package modules.packages.exe: error importing data.packages.exe: No module named 'data.packages'
2026-03-08 09:36:01,444 [lib.core.compound] INFO: C:\Users\cape\AppData\Local\Temp already exists, skipping creation
2026-03-08 09:36:01,538 [lib.api.process] INFO: Successfully executed process from path "C:\Users\cape\AppData\Local\Temp\strings.exe" with arguments "" with pid 6132
2026-03-08 09:36:01,538 [lib.api.process] INFO: Monitor config for <Process 6132 strings.exe>: C:\vdyc7mjt\dll\6132.ini
2026-03-08 09:36:01,553 [lib.api.process] INFO: 32-bit DLL to inject is C:\vdyc7mjt\dll\hizPnd.dll, loader C:\vdyc7mjt\bin\fyLUmkl.exe
2026-03-08 09:36:01,678 [root] DEBUG: Loader: Injecting process 6132 (thread 6036) with C:\vdyc7mjt\dll\hizPnd.dll.
2026-03-08 09:36:01,694 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-03-08 09:36:01,694 [root] DEBUG: Successfully injected DLL C:\vdyc7mjt\dll\hizPnd.dll.
2026-03-08 09:36:01,709 [lib.api.process] INFO: Injected into 32-bit <Process 6132 strings.exe>
2026-03-08 09:36:03,725 [lib.api.process] INFO: Successfully resumed <Process 6132 strings.exe>
2026-03-08 09:36:04,537 [root] DEBUG: 6132: Python path set to 'C:\Python310'.
2026-03-08 09:36:04,553 [root] DEBUG: 6132: Disabling sleep skipping.
2026-03-08 09:36:04,553 [root] DEBUG: 6132: Dropped file limit defaulting to 100.
2026-03-08 09:36:04,600 [root] DEBUG: 6132: YaraInit: Compiled 44 rule files
2026-03-08 09:36:04,600 [root] DEBUG: 6132: YaraInit: Compiled rules saved to file C:\vdyc7mjt\data\yara\capemon.yac
2026-03-08 09:36:04,615 [root] DEBUG: 6132: YaraScan: Scanning 0x00300000, size 0x5b6c0
2026-03-08 09:36:04,615 [root] DEBUG: 6132: Monitor initialised: 32-bit capemon loaded in process 6132 at 0x73f00000, thread 6036, image base 0x300000, stack from 0x282000-0x290000
2026-03-08 09:36:04,631 [root] DEBUG: 6132: Commandline: "C:\Users\cape\AppData\Local\Temp\strings.exe"
2026-03-08 09:36:04,866 [root] DEBUG: 6132: hook_api: LdrpCallInitRoutine export address 0x77EB2A40 obtained via GetFunctionAddress
2026-03-08 09:36:04,991 [root] DEBUG: 6132: hook_api: Warning - SetWindowLongW export address 0x75D45420 differs from GetProcAddress -> 0x750E59E0 (apphelp.dll::0xff3d59e0)
2026-03-08 09:36:04,991 [root] DEBUG: 6132: hook_api: Warning - EnumDisplayDevicesA export address 0x75D395A0 differs from GetProcAddress -> 0x750E6780 (apphelp.dll::0xff3d6780)
2026-03-08 09:36:05,006 [root] DEBUG: 6132: hook_api: Warning - EnumDisplayDevicesW export address 0x75D4FB70 differs from GetProcAddress -> 0x7510E4D0 (apphelp.dll::0xff3fe4d0)
2026-03-08 09:36:05,022 [root] WARNING: b'Unable to place hook on GetCommandLineA'
2026-03-08 09:36:05,022 [root] DEBUG: 6132: set_hooks: Unable to hook GetCommandLineA
2026-03-08 09:36:05,022 [root] WARNING: b'Unable to place hook on GetCommandLineW'
2026-03-08 09:36:05,037 [root] DEBUG: 6132: set_hooks: Unable to hook GetCommandLineW
2026-03-08 09:36:05,131 [root] DEBUG: 6132: Hooked 630 out of 632 functions
2026-03-08 09:36:05,147 [root] DEBUG: 6132: Syscall hook installed, syscall logging level 1
2026-03-08 09:36:05,147 [root] DEBUG: 6132: RestoreHeaders: Restored original import table.
2026-03-08 09:36:05,147 [root] INFO: Loaded monitor into process with pid 6132
2026-03-08 09:36:05,162 [root] DEBUG: 6132: caller_dispatch: Added region at 0x00300000 to tracked regions list (kernel32::LoadLibraryExW returns to 0x0030D07E, thread 6036).
2026-03-08 09:36:05,178 [root] DEBUG: 6132: YaraScan: Scanning 0x00300000, size 0x5b6c0
2026-03-08 09:36:05,178 [root] DEBUG: 6132: ProcessImageBase: Main module image at 0x00300000 unmodified (entropy change 0.000000e+00)
2026-03-08 09:36:05,240 [root] DEBUG: 6132: DLL loaded at 0x73DC0000: C:\Windows\SYSTEM32\USP10 (0x17000 bytes).
2026-03-08 09:36:05,256 [root] DEBUG: 6132: DLL loaded at 0x73D80000: C:\Windows\SYSTEM32\msls31 (0x31000 bytes).
2026-03-08 09:36:05,256 [root] DEBUG: 6132: DLL loaded at 0x73DE0000: C:\Windows\SYSTEM32\RICHED20 (0x7a000 bytes).
2026-03-08 09:36:05,256 [root] DEBUG: 6132: DLL loaded at 0x73E60000: C:\Windows\SYSTEM32\Riched32 (0x6000 bytes).
2026-03-08 09:36:05,350 [root] DEBUG: 6132: InstrumentationCallback: Added region at 0x772833EC (base 0x77150000) to tracked regions list (thread 6036).
2026-03-08 09:36:05,350 [root] DEBUG: 6132: ProcessTrackedRegion: Region at 0x77150000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\KernelBase.dll is in known range, skipping
2026-03-08 09:36:05,397 [root] DEBUG: 6132: DLL loaded at 0x745D0000: C:\Windows\system32\uxtheme (0x74000 bytes).
2026-03-08 09:36:05,412 [root] DEBUG: 6132: DLL loaded at 0x76BA0000: C:\Windows\System32\MSCTF (0xd4000 bytes).
2026-03-08 09:36:05,709 [root] DEBUG: 6132: InstrumentationCallback: Added region at 0x76AD24AC (base 0x76AB0000) to tracked regions list (thread 6036).
2026-03-08 09:36:05,709 [root] DEBUG: 6132: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-03-08 09:36:05,819 [root] DEBUG: 6132: DLL loaded at 0x73B70000: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984\comctl32 (0x210000 bytes).
2026-03-08 09:36:05,897 [root] DEBUG: 6132: ProcessTrackedRegion: Region at 0x76AB0000 mapped as \Device\HarddiskVolume1\Windows\SysWOW64\kernel32.dll is in known range, skipping
2026-03-08 09:36:06,053 [root] DEBUG: 6132: set_hooks_by_export_directory: Hooked 0 out of 632 functions
2026-03-08 09:36:06,053 [root] DEBUG: 6132: DLL loaded at 0x75250000: C:\Windows\SYSTEM32\kernel.appcore (0xf000 bytes).
2026-03-08 09:36:06,069 [root] DEBUG: 6132: DLL loaded at 0x76D80000: C:\Windows\System32\bcryptPrimitives (0x5f000 bytes).
2026-03-08 09:36:06,256 [root] DEBUG: 6132: DLL loaded at 0x73760000: C:\Windows\SYSTEM32\ntmarta (0x29000 bytes).
2026-03-08 09:36:06,272 [root] DEBUG: 6132: DLL loaded at 0x73790000: C:\Windows\System32\CoreMessaging (0x9b000 bytes).
2026-03-08 09:36:06,272 [root] DEBUG: 6132: DLL loaded at 0x73680000: C:\Windows\SYSTEM32\wintypes (0xdb000 bytes).
2026-03-08 09:36:06,272 [root] DEBUG: 6132: DLL loaded at 0x73830000: C:\Windows\System32\CoreUIComponents (0x27e000 bytes).
2026-03-08 09:36:06,287 [root] DEBUG: 6132: DLL loaded at 0x73AB0000: C:\Windows\SYSTEM32\textinputframework (0xb9000 bytes).
2026-03-08 09:36:06,631 [root] DEBUG: 6132: DLL loaded at 0x735E0000: C:\Windows\SYSTEM32\TextShaping (0x94000 bytes).
2026-03-08 09:36:08,569 [modules.auxiliary.human] INFO: Found button "agree", clicking it
2026-03-08 09:36:11,428 [root] DEBUG: 6132: NtTerminateProcess hook: Attempting to dump process 6132
2026-03-08 09:36:11,428 [root] DEBUG: 6132: DoProcessDump: Skipping process dump as code is identical on disk.
2026-03-08 09:36:11,850 [root] INFO: Process with pid 6132 appears to have terminated
2026-03-08 09:36:12,022 [root] INFO: Process with pid 6132 has terminated
2026-03-08 09:36:16,959 [root] INFO: Process list is empty, terminating analysis
2026-03-08 09:36:17,990 [root] INFO: Created shutdown mutex
2026-03-08 09:36:19,006 [root] INFO: Shutting down package
2026-03-08 09:36:19,006 [root] INFO: Stopping auxiliary modules
2026-03-08 09:36:19,006 [root] INFO: Stopping auxiliary module: Browser
2026-03-08 09:36:19,006 [root] INFO: Stopping auxiliary module: Human
2026-03-08 09:36:21,631 [root] INFO: Stopping auxiliary module: Screenshots
2026-03-08 09:36:22,459 [root] INFO: Finishing auxiliary modules
2026-03-08 09:36:22,490 [root] INFO: Shutting down pipe server and dumping dropped files
2026-03-08 09:36:22,490 [root] WARNING: Folder at path "C:\pFgSGb\debugger" does not exist, skipping
2026-03-08 09:36:22,490 [root] INFO: Uploading files at path "C:\pFgSGb\tlsdump"
2026-03-08 09:36:22,490 [lib.common.results] INFO: Uploading file C:\pFgSGb\tlsdump\tlsdump.log to tlsdump\tlsdump.log; Size is 8494; Max size: 100000000
2026-03-08 09:36:22,490 [root] INFO: Analysis completed
Process Log

        
Pre-Script Log

        
During-Script Log

        
Machine Information
Name Label Manager Started On Shutdown On Route
win10x64 win10x64 KVM 2026-03-08 09:34:31 2026-03-08 09:36:27 none
File Details
File Information
File Name
strings.exe
File Type PE32 executable (console) Intel 80386, for MS Windows
File Size 370056 bytes
MD5 818a6b4770d7090cfa60d53e4fcb854a
SHA1 9efc50edf5a7c92d51503c78efbe755313871e7b
SHA256 a7553d77edca85bec980e38e69bf0e9f36962f20be0ee759e9a96030d519c5a0 VT MWDB Bazaar
SHA3-384 393cdcf37e1564c442e7c761db8e2b42d4a85da20c76746e0c4a57dca26cbe4be467d3a3d5ea7b215e75cd7501446773
CRC32 2063D15D
TLSH T1F1745B11B9C0C032D6B33D304AB8E2B15D7E79706D349A9FA39815795F34A81EA35B2F
Ssdeep 6144:EopCpgg69QIEXbryg1A1KJ7zMKBRyXtghOkm5xKXoulo8+jbjFOuBRlwa:TIpgg69QIEXbrygK1KJ7zMKL7ouloDsB
Yara
Strings
-0D0m0
ar-IQ
0@0U0k0x0
:(:@:\:|:
ms-bn
ru-ru
`default constructor closure'
1 1@1`1
quz-ec
8+9Y9u9
UNKNOWN
l/accepteula
tel quel
0'1t1
uz-uz-cyrl
.rsrc
?@?[?
jdh(?E
GetModuleHandleExW
de-at
FlushFileBuffers
\'b7\tab Internet-based services, and \par
DOCUMENTATION
tlj*Yf
EndDialog
5"595?5E5K5Q5W5]5r5
dddd, MMMM dd, yyyy
un usage particulier et d'absence de contrefa
NX9^`t1
SPSVQ
ar-jo
4(4H4h4
hi-IN
10h0o0t0x0|0
QQSVWd
bf&!D
License Agreement
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
united-kingdom
The software is licensed, not sold.This agreement only gives you some rights to use the software.Sysinternals reserves all other rights.Unless applicable law gives you more rights despite this limitation, you may use the software only as expressly permitted in this agreement.In doing so, you must comply with any technical limitations in the software that only allow you to use it in certain ways.You may not
az-AZ-Cyrl
ka-ge
norwegian-bokmal
EndPage
cs-CZ
Legal_policy_statement
0/090
\StringFileInfo\%04X%04X\%s
norwegian-nynorsk
iotuap
protected:
eu-es
4!4V4g4
S0Q0O
<!<j=q=
February
EnumSystemLocalesEx
uz-UZ-Latn
5 5>5I5
<unknown>
short
\pard\fi-363\li720\sb120\sa120\tx720\'b7\tab les r\'e9clamations au titre de violation de contrat ou de garantie, ou au titre de responsabilit\'e9 stricte, de n\'e9gligence ou d'une autre faute dans la limite autoris\'e9e par la loi en vigueur.\par
swedish-finland
tEJ!U*
4(444
0?1\1
111J1l1
cy-gb
< t3<
QQSVj8j@
__clrcall
ml-IN
No strings found.
;9;i;
swiss
GetStringTypeW
api-ms-win-core-string-l1-1-0
cs-cz
EnumSystemLocalesW
Microsoft Code Signing PCA 20110
strings.exe
zh-mo
DeleteCriticalSection
sr-ba-cyrl
j$Yf9
9C`u99C\t4
GetNumberOfConsoleInputEvents
tant distribu
2$2,242<2D2L2T2\2d2l2t2|2
\fs20 11.\tab\fs19 Disclaimer of Warranty.\caps0 \caps The software is licensed "as - is." You bear the risk of using it. SYSINTERNALS gives no express warranties, guarantees or conditions. You may have additional consumer rights under your local laws which this agreement cannot change. To the extent permitted under your local laws, SYSINTERNALS excludes the implied warranties of merchantability, fitness for a particular purpose and non-infringement.\par
ft&9q
50666B6`6f6
es-NI
de-DE
te-IN
PuO'a
GetUserObjectInformationW
en-ca
InternalName
__int8
>B>$?
\caps\fs20 8.\tab\fs19 Entire Agreement.\b0\caps0 This agreement, and the terms for supplements, updates, Internet-based services and support services that you use, are the entire agreement for the software and support services.\par
votre
Wow64DisableWow64FsRedirection
.?AVDNameStatusNode@@
.CRT$XTZ
az-AZ-Latn
This agreement describes certain legal rights.You may have other rights under the laws of your country.You may also have rights with respect to the party from whom you acquired the software.This agreement does not change your rights under the laws of your country if the laws of your country do not permit it to do so.
0,000L0P0X0`0h0l0t0

ta-in
*tI=+
\pard\sb120\sa120\b0\fs19 These license terms are an agreement between Sysinternals (a wholly owned subsidiary of Microsoft Corporation) and you. Please read them. They apply to the software you are downloading from Systinternals.com, which includes the media on which you received it, if any. The terms also apply to any Sysinternals\par
5ineI
950nE
GetStdHandle
es-cl
it-ch
RaiseException
'0<0Q0
CONIN$
:);/;A;R;r;
GetConsoleMode
jXXf;
-a Ascii-only search (Unicode and Ascii is default)
portuguese-brazilian
smj-no
5,6 7`7l8
WriteConsoleW
GetCommandLineA
-s Recurse subdirectories
HPjPW
ms-MY
frexp
435D5U5
2#2(2-2H2R2^2c2h2
america
?@s-f
GetLastError
usage: %s [-a] [-f offset] [-b bytes] [-n length] [-o] [-s] [-u] <file or directory>
mn-mn
DialogBoxIndirectParamA
`vftable'
pt-br
{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fswiss\fprq2\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}}
1<2i2
bn-in
MessageBoxW
spanish-mexican
SYSINTERNALS SOFTWARE LICENSE TERMS
5a6~6"9
POUR LES DOMMAGES.Vous pouvez obtenir de Sysinternals et de ses fournisseurs une indemnisation en cas de dommages directs uniquement
sr-sp-latn
\'b7\tab support services\par
.CRT$XCA
const
;(<I<d</=5=;=A=G=M=
lt-LT
ntdll
.rtc$IZZ
fr-ca
-o Print offset in file string was located
mn-MN
Microsoft Time-Stamp PCA 2010
tendre
444a4
he-IL
kk-KZ
sma-no
Use -accepteula to accept EULA.
-n Minimum string length (default is 3)
rent les lois de votre pays si celles-ci ne le permettent pas.
__ptr64
GetFileVersionInfoA
889v9
:O;Z;d;i;
GetSystemTimeAsFileTime
RoUninitialize
PjPW
GetSysColorBrush
\pard\li357\sb120\sa120\b0\caps0 This limitation applies to\par
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
gligence ou d'une autre faute dans la limite autoris
es-SV
3 3(30383@3H3P3X3`3h3p3x3
mWQO)
;%<E<K<w<
zh-chs
_tqPVj@
JRich
hr-ba
advapi32
Unknown exception
bg-BG
*publish the software for others to copy;
GetModuleFileNameA
SWj=V
:%:Y:
de-LI
;:;T;c;s;
2H2X2h2x2
`dynamic atexit destructor for '
el-GR
SVWUj
-u Unicode-only search (Unicode and Ascii is default)
FlsGetValue
sma-se
wIPS3
.rdata
6O6S6W6[6_6c6g6k6o6
GetFileVersionInfoSizeW
LC_CTYPE
sk-SK
nullptr
gl-ES
Because this software is "as is, " we may not provide support services for it.
Vt-h0
unsigned
5#515@5
pr china
6%6M6_6z6
2+3_3
?-?^?
EulaAccepted
j"_f9y
$PjQW
rnf;u
ar-sa
ro-ro
-jd_;
InterlockedPushEntrySList
LC_COLLATE
ExitProcess
`template-parameter
PVj@W
ar-TN
`anonymous namespace'
`copy constructor closure'
InterlockedFlushSList
RegOpenKeyA
StringFileInfo
INSTALLATION AND USER RIGHTS
es-es
pour les dommages indirects, accessoires ou de quelque nature que ce soit, il se peut que la limitation ou l'exclusion ci - dessus ne s'appliquera pas
hr-hr
|hK,_
DecodePointer
j;Xf9
LegalCopyright
2#3*3
_cabs
.PjRW
au logiciel, aux services ou au contenu(y compris le code) figurant sur des sites Internet tiers ou dans des programmes tiers; et
211202213145Z0t1
english-american
667;7B7h7
String
=)=K=_=
8@uW@
;';8;=;X;e;j;
de-lu
%S#[k
OriginalFilename
D8(Ht'
0 1/1A1c1
2!363b3w3
sr-ba-latn
es-ve
`RTTI
vi-VN
user32
uk-UA
Microsoft Code Signing PCA 2011
0+00050U0i0z0
.idata$5
35,}E
0$0)0/0
`managed vector copy constructor iterator'
\pard\b0\fs20\lang1033\par
de-de
2"2+2S2^2w2
IsWow64Process
`vtordisp{
(
*transfer the software or this agreement to any third party; or
.?AVDNameNode@@
r;f;u
quz-bo
Jjl^f;
7G7R7
j5Zf;
div-mv
fo-fo
FindNextFileA
af-za
u+GkW
040904b0
F _^[
bec, Canada, certaines des clauses dans ce contrat sont fournies ci - dessous en fran
SetCursor
0,131s1z1
6.7C7Y7s7
norwegian
*?*kXIc
GetConsoleCP
2 2(20282@2H2P2X2`2h2p2x2
Translation
Software\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels
7!808<8K8^8}8
.CRT$XPA
tr-tr
volatile
jAZjX
german-swiss
?"?4?A?Z?s?
.data$r
1'2l2
`vector constructor iterator'
nan(snan)
$uf8Q
atan2
.CRT$XIC
fr-FR
?$?@?
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
SVWh
GetUserDefaultLCID
9A:U:
80999R9b9
_nextafter
[aOni*{
3M3l3
gu-in
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-core-localization-obsolete-l1-2-0
Software\Sysinternals\%s
ar-JO
IsValidCodePage
You can also use the /accepteula command-line switch to accept the EULA.
united-states
LocateXStateFeature
3,4A4L4T4_4e4p4v4
information, files saved by Sysinternals tools may include personally identifiable or other sensitive information(such as usernames, passwords, paths to files accessed, and paths to registry accessed).By using this software, you acknowledge that you are aware of this and take sole responsibility for any personally identifiable or other sensitive information provided to Microsoft or any other party through your use of the software.
GetFileVersionInfoW
\b BY USING THE SOFTWARE, YOU ACCEPT THESE TERMS. IF YOU DO NOT ACCEPT THEM, DO NOT USE THE SOFTWARE.\par
private:
api-ms-
* updates,
364A4M4
es-cr
<&<:<E<x<
Microsoft Corporation0
455<5
!This program cannot be run in DOS mode.
ar-qa
676L6W6b6m6x6
south korea
NanoServer
es-hn
uz-uz-latn
*and support services
slovak
January
; ;.;=;N;\;g;u;
>\>k>
spanish-puerto rico
Y_^[]
=d>}>
on sont exclues.
`managed vector destructor iterator'
GetModuleHandleW
>#>+>?>`>e>k>q>w>
j.Yf;
.CRT$XCAA
const
%04u:
smn-fi
ar-lb
Thales TSS ESN:897A-E356-17011%0#
%s License Agreement
3$3,343<3D3L3T3\3d3l3t3|3
VarFileInfo
te-in
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
220411190220Z0
>4>:>F>c>i>
1#SNAN
<r=}=
chinese-simplified
az-az-cyrl
australian
holland
smn-FI
?P?x?
SystemFunction036
GetCurrentThreadId
extern "C"
8"9|9
October
api-ms-win-core-winrt-l1-1-0
ventualit
zu-za
mr-IN
SetEnvironmentVariableW
ko-KR
en-TT
he-il
sa-in
5&626w6
mt-MT
Af;:u
CompareStringW
SetThreadStackGuarantee
UQPXY]Y[
F1<at
QSj W
mscoree.dll
<!=(=.=5=:=
LPjQW
signed
\caps\fs20 7.\tab\fs19 SUPPORT SERVICES.\caps0 \b0 Because this software is "as is, " we may not provide support services for it.\b\par
12<3D3{3
LCIDToLocaleName
LEGAL EFFECT
@b;zO]
F1<gt
nl-NL
gl-es
1!111:1^1l1r1x1~1
fr-be
728M8
:5;K;^;q;
j0Yf;
RegCreateKeyA
7 848G8_8r8~8
sms-fi
WideCharToMultiByte
SetStdHandle
jg[BjG_
IsWow64Process2
2T2d2r2
american-english
american english
9~8~Q
RICHEDIT
ar-QA
<@t A
PPPPPPPP
ReadConsoleInputW
ReadFile
;V\uYW
GetACP
`omni callsig'
:G;}<
{flat}
et-ee
j"Xf;
sms-FI
ml-in
static
3 3@3`3
`eh vector destructor iterator'
GetConsoleOutputCP
PrintDlgA
EnterCriticalSection
id-ID
30373V3]3d3
2+373
ficier de droits additionnels en vertu du droit local sur la protection dues consommateurs, que ce contrat ne peut modifier. La ou elles sont permises par le droit locale, les garanties implicites de qualit
spanish-nicaragua
ar-KW
spanish-uruguay
es-MX
es-GT
IsProcessorFeaturePresent
Microsoft Operations Puerto Rico1
api-ms-win-core-localization-l1-2-1
`vector vbase copy constructor iterator'
spanish-guatemala
.rtc$TAA
M0K0I
en-CA
delete
=%=+=1=
GetXStateFeaturesMask
8#9C9W9l9
e_.,>
5#5@5d5
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
r}f;u
gard.
91:7:
en-zw
south-korea
cli::array<
March
api-ms-win-appmodel-runtime-l1-1-2
y9SVW
1S1^1
GetLocaleInfoEx
> >(>0>8>@>H>P>X>
char16_t
.rdata$CastGuardVftablesC
G;~8u
Base Class Array'
chinese-hongkong
5W6l6u6~6
*make more copies of the software than specified in this agreement or allowed by applicable law, despite this limitation;
415B5V9
j,Yf;
ar-LY
zh-cht
es-HN
RegCloseKey
CONOUT$
.CRT$XCZ
ar-tn
)Microsoft Root Certificate Authority 20100
ar-SY
$u;8H
=6>e>
syr-sy
zh-sg
;g<`=
1 1$1(1,1
u,PQRS
zh-CHT
u,f9F
operator<=>
\'b7\tab transfer the software or this agreement to any third party; or\par
324=4q4
LoadLibraryExW
rkf;u
__stdcall
`template-parameter-
/accepteula
sma-NO
Y_[^]
3.4?4H4t7X>`>
[thunk]:
r\f;u
ext-ms-
@.reloc
iu+-,
vus par les lois de votre pays. Le pr
Microsoft Corporation1&0$
RegQueryValueExA
Tuesday
virtual
w>t6;
pt-PT
GetFileType
9?:E:
tHSVWP
0$0)0.0>0C0H0X0]0b0r0w0|0
Rhu]@
5X5a5q5
hr-BA
italian-swiss
1(1.1J1P1\1z1
j"Xf9
en-ZA
cli::pin_ptr<
>%>7>I>[>m>
fa-IR
4$5H5S5`5r5
Accept Eula (Y/N)?
QueryPerformanceCounter
<security>
>[>y>
german-austrian
VERSION.dll
SCOPE OF LICENSE
CompareStringEx
6(6E6W6]6f6l6
<#<)</<5<;<A<G<M<S<Y<_<e<k<q<w<}<
spanish-honduras
7K7o7|7
8@t4V
YYhdRD
This is the first run of this program. You must accept EULA to continue.
GetProcAddress
9$u?A
454@4M4Z4k4
div-MV
*tL=+
MS Shell Dlg
volatile
f9<H}
CommandLineToArgvW
\pard\fi-363\li720\sb120\sa120\fs20 b.\tab\fs19 Outside the United States.\b0 If you acquired the software in any other country, the laws of that country apply.\b\par
Legal_Policy_Statement
1!161d1
__int32
en-gb
>D>K>s>
t"h|RD
%04d:
354}E
zSSSSj
4 4(40484@4H4P4X4`4h4p4x4
nl-nl
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
th-TH
/PjSW
`managed vector constructor iterator'
bs-ba-latn
puerto-rico
0B1\1l1
VS_VERSION_INFO
.CRT$XIAC
eu-ES
fr-fr
20210623125524Z0w0=
9!9d9
az-az-latn
AppPolicyGetWindowingModel
j:Xf;
Microsoft Operations Puerto Rico1&0$
EXPORT RESTRICTIONS
Washington1
tout ce qui est reli
de-LU
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
sl-si
@.data
fr-MC
Any person that has valid access to your computer or internal network may copy and use the documentation for your internal, reference purposes.
tt-RU
es-pa
`typeof'
`template static data member destructor helper'
)Microsoft Root Certificate Authority 20110
\pard\sb120\sa120 for this software, unless other terms accompany those items. If so, those terms apply.\par
4(4D4Y4^4c4
sv-fi
PPPPP
6>9s9
8!898Q8i8
english-jamaica
ar-MA
ar-eg
ms-my
zu-ZA
`udt returning'
GetProcessHeap
r_f;u
wchar_t
<$=(=,=0=4=8=<=W=a=t=y=
3U3}3l5
`eh vector vbase copy constructor iterator'
.rdata$sxdata
GetCurrentProcess
class
December
LoadLibraryExA
URPQQh
floor
IsDebuggerPresent
:&;J;U;c;
sent contrat d
1 1(10181@1H1P1X1`1h1p1x1
TS ET EXCLUSION DE RESPONSABILIT
ar-ly

==>h>}>
es-CO
english-can
VWj=S
InflateRect
35<}E
t3SVj
cointerface
=>=D=P=m=s=
ar-ma
is-is
3o4@54617
-PjWW
"B <1=
2*323@3N3_3
d'un tel dommage. Si votre pays n'autorise pas l'exclusion ou la limitation de responsabilit
BY USING THE SOFTWARE, YOU ACCEPT THESE TERMS.IF YOU DO NOT ACCEPT THEM, DO NOT USE THE SOFTWARE.
se-NO
FindFirstFileA
7!7;7h7o7P:
pwMt?
sw-KE
Saturday
spanish-panama
>^?d?s?y?
obwQ4
Sysinternals Strings
<ellipsis>
PPPPj
Microsoft Corporation1
ril.Sysinternals n'accorde aucune autre garantie expresse. Vous pouvez b
WSVPP
?5Wg4p
\caps\fs20 2.\tab\fs19 Scope of License\caps0 .\b0 The software is licensed, not sold. This agreement only gives you some rights to use the software. Sysinternals reserves all other rights. Unless applicable law gives you more rights despite this limitation, you may use the software only as expressly permitted in this agreement. In doing so, you must comply with any technical limitations in the software that only allow you to use it in certain ways. You may not\b\par
\pard\li360\sb120\sa120 It also applies even if Sysinternals knew or should have known about the possibility of the damages. The above limitation or exclusion may not apply to you because your country may not allow the exclusion or limitation of incidental, consequential or other damages.\par
EndDoc
0G1'4
__swift_1
ky-KG
?.?8?R?`?
4k4r4
StartPage
tre l'
Sysinternals - www.sysinternals.com
AppPolicyGetThreadInitializationType
?r?{?
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
english-uk
;F<s<
Y__^[
8*9U9`9k9s9|9
es-co
`generic-type-
ns-ZA
china
`template static data member constructor helper'
new-zealand
InitializeSListHead
RegOpenKeyExA
D:\a\1\s\Win32\Release\strings.pdb
EFFET JURIDIQUE.Le pr
7%7D7J7%8
Do not display the startup banner and copyright message.
=D>W>u>
.rtc$IAA
?>?S?i?
<(<S<
Please be aware that, similar to other debug tools that capture
ar-bh
__int16
9~8~R
:(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<
nl-be
sw-ke
United States.If you acquired the software in the United States, Washington state law governs the interpretation of this agreement and applies to claims for breach of it, regardless of conflict of laws principles.The laws of the state where you live govern all other claims, including claims under state consumer protection laws, unfair competition laws, and in tort.
__unaligned
spanish-argentina
generic-type-
7,7=7E7U7f7
\pard\fi-363\li720\sb120\sa120\'b7\tab supplements,\par
`local static destructor helper'
8Q8(9X9l9
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
mk-mk
.?AVtype_info@@
rJf;u
* claims for breach of contract, breach of warranty, guarantee or condition, strict liability, negligence, or other tort to the extent permitted by applicable law.
97:<:
GetCurrentThread
Microsoft Corporation1(0&
es-ec
pt-pt
PRPQh
LIMITATION DES DOMMAGES - INT
DLYwh
-b Bytes of file to scan
ar-DZ
quz-PE
GetCommandLineW
sma-SE
8(8.848:8@8F8L8R8X8^8d8j8
9!:(:W:^:
747S7e7
9(9,9<9@9D9L9d9t9x9
de-ch
char
SetFilePointerEx
se-se
sq-AL
#0.030K0[0u0
stricte, de n
FileDescription
u29K\t-
SSSSj
es-ES
2(2J2d2
5#515=5X5l5
__swift_2
NAN(IND)
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
operator co_await
;S<p<|<
3c3k4
https://www.sysinternals.com0
\pard\keepn\sb120\sa120\b LIMITATION DES DOMMAGES-INT\'c9R\'caTS ET EXCLUSION DE RESPONSABILIT\'c9 POUR LES DOMMAGES.\b0 Vous pouvez obtenir de Sysinternals et de ses fournisseurs une indemnisation en cas de dommages directs uniquement \'e0 hauteur de 5,00 $ US. Vous ne pouvez pr\'e9tendre \'e0 aucune indemnisation pour les autres dommages, y compris les dommages sp\'e9ciaux, indirects ou accessoires et pertes de b\'e9n\'e9fices.\par
UnhandledExceptionFilter
.?AVpairNode@@
GetActiveWindow
1#QNAN
SVWf9
7M:m:
.rtc$TZZ
it-it
=A>X>
GetLastActivePopup
AppPolicyGetShowDeveloperDiagnostic
lv-LV
es-do
{\*\generator Riched20 10.0.10240}\viewkind4\uc1
api-ms-win-security-systemfunctions-l1-1-0
\pard\keepn\fi-360\li720\sb120\sa120\tx720\lang1036\'b7\tab tout ce qui est reli\'e9 au logiciel, aux services ou au contenu (y compris le code) figurant sur des sites Internet tiers ou dans des programmes tiers ; et\par
If you comply with these license terms, you have the rights below.
ABCDEFGHIJKLMNOPQRSTUVWXYZ
xh-za
en-jm
QQSVW
1^2s2
NAN(SNAN)
*030>0E0X0f0l0r0x0~0
>@s5f
GetCPInfo
e par la loi en vigueur.
%s v%s - %s
operator ""
RegSetValueExA
oK0D$"<
great britain
1$1,141<1D1L1T1\1d1l1t1|1
5. \tab\fs19 DOCUMENTATION.\b0 Any person that has valid access to your computer or internal network may copy and use the documentation for your internal, reference purposes.\b\par
>G?Y?
pl-pl
.Toute utilisation de ce logiciel est
volatile
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
tn-ZA
be-by
USER32.dll
:V;Z;^;b;f;j;n;r;
Microsoft Visual C++ Runtime Library
LIMITATION ON AND EXCLUSION OF REMEDIES AND DAMAGES
english-trinidad y tobago
`template-type-parameter-
9$9C9
english-belize
zh-cn
r5f;u
__fastcall
4L5}5
es-pr
en-bz
5"5-545<6
std::nullptr_t
v2!L.2
.idata$6
@hX*E
ar-ye
kok-in
SPjdVQ
#.X'=
2$3A3`3
x!j$Xf9
9F:O:
1N1\1c1j1t1{1
SetFilePointer
fr-lu
english-usa
`adjustor{
english-us
Type Descriptor'
8K9T9l9
F2jgYf;
R0P0N
fr-CA
es-PR
>">0>8>P>i>
<*<4<=<
hu-hu
SetUnhandledExceptionFilter
xh-ZA
(Ht5F
`vbase destructor'
.?AVbad_exception@std@@
th-th
`string'
GetOEMCP
8(8H8d8h8
909p9v9
sk-sk
bn-IN
6%7>7j7
german-luxembourg
votre seule risque et p
ca-es
\pard\sa200\sl276\slmult1\f1\fs22\lang9\par
InitializeCriticalSectionAndSpinCount
trinidad & tobago
9E WW
t4<A|)<P
en-au
german-lichtenstein
south-africa
~ $s%r
484N4w4
3@3X3h3
GDI32.dll
<0| <9
el-gr
smj-SE
fices.
fi-fi
Microsoft Corporation1)0'
hy-am
ur-pk
api-ms-win-rtcore-ntuser-window-l1-1-0
Microsoft Time-Stamp Service
sr-BA-Cyrl
.CRT$XIA
8 8$8(8,80848@8D8H8L8P8T8X8\8`8
es-CL
.CRT$XIAA
V@j0P
3P4[5
it-IT
333j3
.00cfg
D=xz#
es-AR
\pard\b Please note: As this software is distributed in Quebec, Canada, some of the clauses in this agreement are provided below in French.\par
marchande, d'ad
ar-iq
Failed to open %s:
ar-sy
en-PH
VerQueryValueW
en-tt
425;5
es-PY
ca-ES
u2Vj@h
091_1
abcdefghijklmnopqrstuvwxyz
ms-BN
*tD=+
french-canadian
en-NZ
Outside the United States.If you acquired the software in any other country, the laws of that country apply.
uz-UZ-Cyrl
\pard\brdrb\brdrs\brdrw10\brsp20 \sb120\sa120\b\f0\fs24 SYSINTERNALS SOFTWARE LICENSE TERMS\fs28\par
__eabi
\pard\fi-363\li720\sb120\sa120\tx720\'b7\tab updates,\par
230012+4630090
api-ms-win-core-xstate-l2-1-0
2,3w3
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
dutch-belgian
InitializeCriticalSectionEx
1L1h1
^<V7w
V2jx_f;
TlsGetValue
`placement delete[] closure'
ProductVersion
RtlUnwind
1(1-121B1G1L1\1a1f1v1{1
__vectorcall
sa-IN
user32.dll
.CRT$XPZ
south africa
:C;Y;
Redmond1
english-ire
fo-FO
PSj W
england
Riched32.dll
8/8u8
__cdecl
.idata$3
aucune indemnisation pour les autres dommages, y compris les dommages sp
__int64
Friday
smj-se
spanish-paraguay
210114190220Z
TerminateProcess
de-AT
313F3Y3 474
<program name unknown>
long
0"080>0J0b0h0u0
tR<0|
Class Hierarchy Descriptor'
char8_t
HH:mm:ss
SendMessageA
3 3-3:3K3u3
sent contrat ne modifie pas les droits que vous conf
es-DO
s\StringFileInfo\%04X%04X\%s
C;^8u
<,=D=w=
<requestedPrivileges>
* work around any technical limitations in the software;
@_^[]
.rsrc$01
162d2k2w2
.CRT$XPX
5Genu
rYf;u
8&8Q8f8
(HtMf
9=0nE
0;0d0y0
-nobanner
jjjjj
9 :c:q:
ReadConsoleW
1/0-0
9'9R9t9
kernel32
GetFullPathNameA
1#IND
sr-sp-cyrl
StartDocA
FFG;}
</assembly>
zh-MO
nn-no
?!?)?G?O?
nb-NO
\pard\fi-363\li720\sb120\sa120\tx720\b0\'b7\tab work around any technical limitations in the binary versions of the software;\par
~1WPQ
`eh vector constructor iterator'
pt-BR
kn-IN
EncodePointer
110708205909Z
\pard\fi-360\li360\sb120\sa120\tx360\fs20 12.\tab\fs19 Limitation on and Exclusion of Remedies and Damages. You can recover from SYSINTERNALS and its suppliers only direct damages up to U.S. $5.00. You cannot recover any other damages, including consequential, lost profits, special, indirect or incidental damages.\par
Dapi-ms-win-core-datetime-l1-1-1
\caps\fs20 6.\tab\fs19 Export Restrictions\caps0 .\b0 The software is subject to United States export laws and regulations. You must comply with all domestic and international export laws and regulations that apply to the software. These laws include restrictions on destinations, end users and end use. For additional information, see {\cf1\ul{\field{\*\fldinst{HYPERLINK www.microsoft.com/exporting }}{\fldrslt{www.microsoft.com/exporting}}}}\cf1\ul\f0\fs19 <{{\field{\*\fldinst{HYPERLINK "http://www.microsoft.com/exporting"}}{\fldrslt{http://www.microsoft.com/exporting}}}}\f0\fs19 >\cf0\ulnone .\b\par
GetUserDefaultLocaleName
U0S0Q
tr-TR
1*272f2r2
<ItC<Lt3<Tt#<h
3H9P9T9X9\9`9d9h9l9p9t9x9|9
en-us
.?AVcharNode@@
7T8c8
bs-BA-Latn
l1p1t1x1
ky-kg
american
union
en-BZ
GetTimeFormatEx
zh-tw
&Decline
se-FI
\pard\fi-363\li720\sb120\sa120\tx720\'b7\tab anything related to the software, services, content (including code) on third party Internet sites, or third party programs; and\par
GetDeviceCaps
spanish-chile
ar-AE
english-nz
f9:t!V
uk-ua
.data$rs
lt-lt
sr-BA-Latn
__pascal
FreeLibrary
: :':,:3:b:
britain
.CRT$XPXA
CompanyName
This agreement, and the terms for supplements, updates, Internet - based services and support services that you use, are the entire agreement for the software and support services.
template-parameter-
struct
.CRT$XIZ
ru-RU
.text$x
LC_TIME
/nobanner
HeapFree
`non-type-template-parameter
; ;$;(;,;0;4;8;B;
ldexp
les r
No matching files were found.
Tt)jhZf;
par une licence est offert
Wj0XPV
kk-kz
en-GB
<$u.V
:#:A:^:
WqVNHE
vi-vn
sq-al
tjj_S
kn-in
9p u"
SWj P
Wednesday
; ;(;0;8;@;H;P;X;`;h;p;x;
de-li
? ?%?*?:???D?T?Y?^?n?s?x?
fr-CH
=!=9=?=k>w>(?4?l?
{for
April
LocaleNameToLCID
8?8^8y8
;7<J<
be-BY
9+:h:
quz-pe
GetProcessWindowStation
t^WjU
\pard\sb240\lang1036 Remarque : Ce logiciel \'e9tant distribu\'e9 au Qu\'e9bec, Canada, certaines des clauses dans ce contrat sont fournies ci-dessous en fran\'e7ais.\par
* use the software for commercial software hosting services.
MessageBoxA
FlsFree
chinese-traditional
;,;c;
AreFileApisANSI
9j:%;
KERNEL32.dll
es-UY
nan(ind)
e+000
english-aus
float
RegQueryValueExW
sv-FI
Dja-JP
9-9N9e9
bad exception
Software\Sysinternals
zh-hk
>,?S?c?
585=5i5z5
202;2U2w2
mi-nz
GetTimeFormatW
ukWj<
id-id
687z7
GetDateFormatEx
es-sv
delete[]
se-SE
425C5T5l5
__restrict
sr-SP-Latn
enum
1(0&0
Complete Object Locator'
rMf;u
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
November
.rdata$r
5 5$5(5,5054585<5@5L5P5T5X5\5`5d5h5l5p5t5x5|5
ext-ms-win-ntuser-windowstation-l1-1-0
\b EFFET JURIDIQUE.\b0 Le pr\'e9sent contrat d\'e9crit certains droits juridiques. Vous pourriez avoir d'autres droits pr\'e9vus par les lois de votre pays. Le pr\'e9sent contrat ne modifie pas les droits que vous conf\'e8rent les lois de votre pays si celles-ci ne le permettent pas.\b\par
&Print
: :$:(:0:H:X:\:l:p:x:
es-VE
6,6Z6d6
?L?a?r?
LocalAlloc
LC_MONETARY
ka-GE
\pard\keepn\fi-360\li360\sb120\sa120\tx360\cf2\b\caps\fs20 9.\tab\fs19 Applicable Law\caps0 .\par
GetCurrentDirectoryA
\0.F;
$`2X`F
;6<|<
\VarFileInfo\Translation
*supplements,
pa-in
quz-BO
belgian
mt-mt
`.rdata
ar-om
C WVP
\pard\fi-363\li720\sb120\sa120\'b7\tab reverse engineer, decompile or disassemble the binary versions of the software, except and only to the extent that applicable law expressly permits, despite this limitation;\par
`vector copy constructor iterator'
<#=5=A=c=j=
;/;>;C;H;f;~;
F4_^[
ja-jp
`vector destructor iterator'
GetEnvironmentStringsW
9(:4:@:L:X:\:`:p;t;x;
HeapSize
zh-CHS
rqf;u
french-swiss
\pard\fi-357\li357\sb120\sa120\tx360\b\fs20 3.\tab SENSITIVE INFORMATION. \b0 Please be aware that, similar to other debug tools that capture \ldblquote process state\rdblquote information, files saved by Sysinternals tools may include personally identifiable or other sensitive information (such as usernames, passwords, paths to files accessed, and paths to registry accessed). By using this software, you acknowledge that you are aware of this and take sole responsibility for any personally identifiable or other sensitive information provided to Microsoft or any other party through your use of the software.\b\par
EXON
BVj(j
PPPPPWS
5(5H5h5
clamations au titre de violation de contrat ou de garantie, ou au titre de responsabilit
5 5,585D5P5\5h5t5
english-south africa
da-DK
GetFileVersionInfoSizeA
__based(
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
es-mx
6$6,646<6D6L6T6\6d6l6t6|6
it-CH
9F:W:b:
`placement delete closure'
fr-ch
LCMapStringW
383A3L3
et-EE
api-ms-win-core-sysinfo-l1-2-1
uf_^[
\'b7\tab use the software for commercial software hosting services.\par
syr-SY
nl-BE
se-fi
ro-RO
818q9
HeapAlloc
0:1S4d4c5i5o5u5?6N6g6u6{6
\'b7\tab make more copies of the software than specified in this agreement or allowed by applicable law, despite this limitation;\par
spanish-peru
IsValidLocaleName
This limitation applies to
kok-IN
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
FileVersion
.rdata$zzzdbg
<$<.<A<H<T<l<q<}<
SSSSS
Please note : As this software is distributed in Quebec, Canada, some of the clauses in this agreement are provided below in French.
91::;
en-AU
7!8+888
GetFileSizeEx
af-ZA
Cette limitation concerne :
7 7(70787@7H7P7X7`7h7p7x7
nb-no
`generic-method-parameter-
.xdata$x
.?AVpDNameNode@@
tt-ru
french-luxembourg
CreateFileA
en-za
WriteFile
t<j\V
8'9D9M9X9
es-uy
*t`=+
GetCurrentProcessId
Program:
<(=T=Z=c=x=
< <(<0<8<@<H<P<X<`<h<p<x<
.?AVexception@std@@
api-ms-win-core-synch-l1-2-0
0.0j0}0
7;1u"3
((((( H
en-cb
5)6.636N6X6h6m6r6
\pard\sb120\sa120 EXON\'c9RATION DE GARANTIE.\b0 Le logiciel vis\'e9 par une licence est offert \'ab tel quel \'bb. Toute utilisation de ce logiciel est \'e0 votre seule risque et p\'e9ril. Sysinternals n'accorde aucune autre garantie expresse. Vous pouvez b\'e9n\'e9ficier de droits additionnels en vertu du droit local sur la protection dues consommateurs, que ce contrat ne peut modifier. La ou elles sont permises par le droit locale, les garanties implicites de qualit\'e9 marchande, d'ad\'e9quation \'e0 un usage particulier et d'absence de contrefa\'e7on sont exclues.\par
7(7H7h7
zh-HK
`eh vector vbase constructor iterator'
SetWindowTextA
smj-NO
7'7+7/73777;7?7[7_7c7g7}7
0~1-2|2
ar-EG
decltype(auto)
(null)
</security>
1/191Q1m1
\pard\brdrt\brdrs\brdrw10\brsp20 \sb120\sa120 If you comply with these license terms, you have the rights below.\par
ciaux, indirects ou accessoires et pertes de b
t1RWV
2(242@2L2X2d2p2|2
en-US
french-belgian
SetConsoleCtrlHandler
\'b7\tab publish the software for others to copy;\par
fi-FI
ar-kw
`vbtable'
6;6`6
void
FlsSetValue
GetModuleFileNameW
SUPPORT SERVICES
-f File offset at which to start scanning.
These license terms are an agreement between Sysinternals(a wholly owned subsidiary of Microsoft Corporation) and you.Please read them.They apply to the software you are downloading from technet.microsoft.com / sysinternals, which includes the media on which you received it, if any.The terms also apply to any Sysinternals
es-py
short
uX9^\
5!8Y8
api-ms-win-core-processthreads-l1-1-2
F4_^[]
es-CR
2!2'2
GetVersionExA
You can recover from sysinternals and its suppliers only direct damages up to U.S.$5.00.You cannot recover any other damages, including consequential, lost profits, special, indirect or incidental damages.
2 2,2024282<2@2L2P2T2X2
Microsoft Time-Stamp PCA 20100
quz-EC
1#INF
\'b7\tab rent, lease or lend the software;\par
GetLocaleInfoW
__thiscall
hong-kong
hu-HU
Base Class Descriptor at (
GetModuleHandleA
LCMapStringEx
.CRT$XTA
{\colortbl ;\red0\green0\blue255;\red0\green0\blue0;}
nn-NO
<:<N<q<
ARPRQh
Monday
RoInitialize
spanish-costa rica
log10
9@:H:P:T:X:\:`:d:h:l:t:x:|:
es-PA
I1Q1X1
GetDlgItem
97:R:
V<0|Z<9
Thursday
8@u/@
es-pe
uQPVj
eLK(w
en-IE
ur-PK
es-gt
45<5D5L5T5\5d5l5t5|5
es-BO
en-ph
\pard\fi-363\li720\sb120\sa120\tx720\cf0\fs20 a.\tab\fs19 United States.\b0 If you acquired the software in the United States, Washington state law governs the interpretation of this agreement and applies to claims for breach of it, regardless of conflict of laws principles. The laws of the state where you live govern all other claims, including claims under state consumer protection laws, unfair competition laws, and in tort.\b\par
768d8l8
4/5M5m5
api-ms-win-core-file-l1-2-2
616>6`6z7
2 2@2\2`2
coclass
ar-OM
20210622125524Z
en-ie
SWt@jU
Sysinternals License
201215213145Z
jAXf;
chinese
=3=e=w=
1$1B1J1k1q1y1
ENTIRE AGREEMENT
es-EC
BC .=
tn-za
3'3W3
da-dk
8*9u9
6!7C7p7
TlsAlloc
ar-ae
,<ellipsis>
</requestedPrivileges>
*Internet - based services,
9':<:V:h:
F0a0w0
.?AVpcharNode@@
`scalar deleting destructor'
r8f;u
czech
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
sl-SI
SENSITIVE INFORMATION
crit certains droits juridiques.Vous pourriez avoir d'autres droits pr
Kernel32.dll
\pard\sb120\sa120 Elle s'applique \'e9galement, m\'eame si Sysinternals connaissait ou devrait conna\'eetre l'\'e9ventualit\'e9 d'un tel dommage. Si votre pays n'autorise pas l'exclusion ou la limitation de responsabilit\'e9 pour les dommages indirects, accessoires ou de quelque nature que ce soit, il se peut que la limitation ou l'exclusion ci-dessus ne s'appliquera pas \'e0 votre \'e9gard.\par
260708210909Z0~1
TlsFree
;+<0<5<M<Z<_<d<
\pard\fi-357\li357\sb120\sa120\tx360\fs20 1.\tab\fs19 INSTALLATION AND USE RIGHTS. \b0 You may install and use any number of copies of the software on your devices.\b\par
TlsSetValue
es-ni
6"cN"
es-bo
r~akow
sv-SE
5 6'6L6P6T6X6\6,7
pr-china
english-caribbean
SetMapMode
LC_NUMERIC
9^\ty
2L3`3
LoadCursorA
`virtual displacement map'
t f;E
Runtime Error!
:f;>u
0S0b0p0
Microsoft Time-Stamp Service0
;W;^;
FindClose
464]455~5
8@u(@
5$5,545<5D5L5T5\5d5l5t5|5
ar-LB
GetSystemTimePreciseAsFileTime
gu-IN
`dynamic initializer for '
fr-mc
`unknown ecsu'
ar-BH
358uE
7:8I8)9V;
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
de-CH
i1s1}1
<$=J=O=b=r=
>R?d?
spanish-modern
1,2024282<2@2D2H2
ns-za
11x<|<
CloseHandle
100701213655Z
6 696H6e6>7P7i7t7h8~8
0-090U0z0
6(6H6h6
8$u V
chinese-singapore
>!?/?5?P?x?
=/===\=o=~=
spanish-ecuador
hi-in
jg[jG
en-JM
operator
sv-se
`local vftable'
The software is licensed "as - is." You bear the risk of using it.Sysinternals gives no express warranties, guarantees or conditions.You may have additional consumer rights under your local laws which this agreement cannot change.To the extent permitted under your local laws, sysinternals excludes the implied warranties of merchantability, fitness for a particular purpose and non - infringement.
5 5(50585@5H5P5X5`5h5p5x5
mr-in
DISCLAIMER OF WARRANTY
2-2;2A2G2M2S2Y2`2g2n2u2|2
&Agree
hauteur de 5, 00 $ US.Vous ne pouvez pr
GetDateFormatW
en-CB
< <v<
rGf;u
:=>p>
;T^h<U_i=V`j>Wak?Xbl@YcmAZdnB[eoC\fpD]gq
3$303<3H3T3`3l3x3
8$u-9
_hypot
.rsrc$02
2A2]2k2w2
ar-SA
The software is subject to United States export laws and regulations.You must comply with all domestic and international export laws and regulations that apply to the software.These laws include restrictions on destinations, end users and end use.For additional information, see www.microsoft.com / exporting .
Strings
7h7w7
+PjUW
AppPolicyGetProcessTerminationMethod
1!2s2
3#3)3
for this software, unless other terms accompany those items.If so, those terms apply.
%s\%s
Software\Microsoft\windows nt\currentversion
restrict(
spanish-el salvador
`local static thread guard'
FreeEnvironmentStringsW
LocalFree
Microsoft Corporation1200
public:
`vector deleting destructor'
358}E
QEX82q'
en-ZW
zh-TW
process state
fr-LU
ProductName
Remarque : Ce logiciel
2!2'2-23292?2E2K2Q2W2]2c2i2o2u2{2
A<lt'<tt
SetConsoleMode
es-PE
`vtordispex{
:5;I;N;S;Y;a;};
It also applies even if Sysinternals knew or should have known about the possibility of the damages.The above limitation or exclusion may not apply to you because your country may not allow the exclusion or limitation of incidental, consequential or other damages.
j.Xf;
6=7N7T7d7r7y7
F950nE
6-686U6`6{6
ar-dz
4 4,484D4P4\4h4t4
6 6(60686@6H6P6X6`6h6p6x6
=J>R>\>e>v>
mi-NZ
quation
6Q7w7
*rent, lease or lend the software;
MM/dd/yy
`2Dk\
char32_t
SetLastError
_logb
pl-PL
,PjVW
1,232:2A2a2p2z2
O0M0K
VerQueryValueA
spanish-bolivia
.idata$2
Search for ANSI and Unicode strings in binary images.
E0C1)0'
1&1?1I1l1v1
IsValidLocale
FormatMessageA
j0Zf;
</trustInfo>
FindNextFileW
384R4^4j4r4
2`3d3h3l3p3t3x3|3
;%;+;5;E;f;
jA[f;
`vector vbase constructor iterator'
ko-kr
250701214655Z0|1
mk-MK
ar-YE
au Qu
0*0A0b0
es-ar
std::nullptr_t
*PjTW
A1<Fu
galement, m
spanish-venezuela
4J6f6
9):E:q:~:
8?u'@
4 4$4(4,4044484<4@4D4H4L4
hr-HR
MultiByteToWideChar
YYj,Z
Dapi-ms-win-core-fibers-l1-1-1
.data
0^_[]
zh-SG
Elle s'applique
= =(=0=8=@=H=P=X=`=h=p=x=
4j5H6o6
__w64
ADVAPI32.dll
= =J=
IsCharAlphaNumericW
%s\*.*
pa-IN
fa-ir
9):7:
N0L0J
PP9E u:PPVWP
1I1[1
<0|]<8
?/?q?
me si Sysinternals connaissait ou devrait conna
>V?c?
.text
jGYf;
Shell32.dll
VVVVV
\lang1033 Cette limitation concerne :\par
spanish-colombia
HeapReAlloc
z.9Wv
\pard\fi-363\li720\sb120\sa120\'b7\tab claims for breach of contract, breach of warranty, guarantee or condition, strict liability, negligence, or other tort to the extent permitted by applicable law.\par
jj^f;
\pard\fi-357\li357\sb120\sa120\tx360\caps\fs20 10.\tab\fs19 Legal Effect.\b0\caps0 This agreement describes certain legal rights. You may have other rights under the laws of your country. You may also have rights with respect to the party from whom you acquired the software. This agreement does not change your rights under the laws of your country if the laws of your country do not permit it to do so.\b\caps\par
FlsAlloc
<h=#>/>7>?>H>u>~>
__int128
Copyright (C) 1999-2021 Mark Russinovich
CorExitProcess
4$4,444<4D4L4T4\4d4l4t4|4
1)1H1
August
* anything related to the software, services, content(including code) on third party Internet sites, or third party programs; and
4<4T4o4z4
canadian
<0=:=C=L=a=j=
*reverse engineer, decompile or disassemble the software, except and only to the extent that applicable law expressly permits, despite this limitation;
APPLICABLE LAW
CreateFileW
September
en-nz
>!>/>5>C>
RATION DE GARANTIE.Le logiciel vis
122O2
zh-CN
spanish-dominican republic
;E<\<~<
20210622112508.213Z0
OutputDebugStringW
PWjUR
You may install and use any number of copies of the software on your devices.
utf-8
.text$mn
COMDLG32.dll
PeekConsoleInputA
`local vftable constructor closure'
6?7E7K7Q7W7]7
CLC_ALL
`vcall'
GetStartupInfoW
hy-AM
irish-english
>#>7>
se-no
Sunday
lv-lv
FindFirstFileExW
is-IS
-accepteula
667?7\7b7h7
2%3B3
0P0z0
0$0,040<0D0L0T0\0d0l0t0|0
`local static guard'
.?AVbad_alloc@std@@
? ?@?H?T?
;4<;<C<X=
new[]
WWWWW
1A1o1
687<7
;8;=;c;
6!6*6K6
bg-bg
cy-GB
sr-SP-Cyrl
double
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
GetEnabledXStateFeatures
`generic-class-parameter-
.rdata$CastGuardVftablesA
noexcept
ta-IN
`eh vector copy constructor iterator'
=6=i=@>|>
LeaveCriticalSection
fr-BE
.idata$4
Archive: overlay
Subfile Information
Filename
32a9b4fae77dc182ce634c321b6bf2102a9fe53313678e25821d2078e94f62ce
File Type data
Associated Filenames
overlay
File Size 9096 bytes
MD5 3b382f6507fd9d8c12a9e719b3e4d5ff
SHA1 548041242648655740967a19dd1214aaba25f73e
SHA256 32a9b4fae77dc182ce634c321b6bf2102a9fe53313678e25821d2078e94f62ce VT MWDB Bazaar
SHA3-384 312113f74e60a85ae1260a51cc71581f2d22e69aca5f4280a85e3cf0477ffb30c02b9067ad353df9bee8a3999bad7a50
CRC32 4A650080
TLSH T1181229D28D6C5843DE9B7C8053ACE853BD3C83D738009066295EFA991DD37C6EB2856D
Ssdeep 192:eWULwu0Sc2HnhWgN7aQWFgoqnajKsXcq:wD/HRN7unlGsXc
PE Information
Image Base
0x00400000
Entry Point
0x00004019
Min OS
6.0
Compile Time
2021-06-22 11:24:59
Import Hash
03a0e8da139a5eed63cd002618eb6590
PDB Path
D:\a\1\s\Win32\Release\strings.pdb

CompanyName Sysinternals - www.sysinternals.com
FileDescription Search for ANSI and Unicode strings in binary images.
FileVersion 2.54
InternalName Strings
LegalCopyright Copyright (C) 1999-2021 Mark Russinovich
OriginalFilename strings.exe
ProductName Sysinternals Strings
ProductVersion 2.54
Translation 0x0409 0x04b0

Name RAW Addr Virt Addr Virt Size Raw Size Characteristics Entropy
.text 0x00000400 0x00001000 0x00043df1 0x00043e00 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.61
.rdata 0x00044200 0x00045000 0x00010468 0x00010600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.89
.data 0x00054800 0x00056000 0x00001d8c 0x00000c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2.61
.rsrc 0x00055400 0x00058000 0x00000588 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3.91
.reloc 0x00055a00 0x00059000 0x000026c0 0x00002800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 6.61

Name Offset Size Language Entropy Type
RT_VERSION 0x000580a0 0x00000368 LANG_ENGLISH 3.41 None
RT_MANIFEST 0x00058408 0x0000017d LANG_ENGLISH 4.91 None

Address Name
0x445044 GetVersionExA
0x445048 LoadLibraryExA
0x44504c GetCurrentDirectoryA
0x445050 CreateFileA
0x445054 FindClose
0x445058 FindFirstFileA
0x44505c FindNextFileA
0x445060 GetFullPathNameA
0x445064 ReadFile
0x445068 SetFilePointer
0x44506c CloseHandle
0x445070 GetLastError
0x445074 SetLastError
0x445078 FormatMessageA
0x44507c FreeEnvironmentStringsW
0x445080 GetEnvironmentStringsW
0x445084 MultiByteToWideChar
0x445088 GetCPInfo
0x44508c GetOEMCP
0x445090 GetACP
0x445094 IsValidCodePage
0x445098 FindNextFileW
0x44509c FindFirstFileExW
0x4450a0 OutputDebugStringW
0x4450a4 SetFilePointerEx
0x4450a8 LocalFree
0x4450ac LocalAlloc
0x4450b0 GetProcAddress
0x4450b4 GetModuleHandleA
0x4450b8 GetCommandLineW
0x4450bc GetModuleFileNameW
0x4450c0 GetStdHandle
0x4450c4 GetFileType
0x4450c8 GetModuleFileNameA
0x4450cc SetEnvironmentVariableW
0x4450d0 GetProcessHeap
0x4450d4 SetConsoleCtrlHandler
0x4450d8 HeapSize
0x4450dc HeapReAlloc
0x4450e0 WriteConsoleW
0x4450e4 GetCurrentProcess
0x4450e8 GetSystemTimeAsFileTime
0x4450ec UnhandledExceptionFilter
0x4450f0 SetUnhandledExceptionFilter
0x4450f4 TerminateProcess
0x4450f8 IsProcessorFeaturePresent
0x4450fc QueryPerformanceCounter
0x445100 GetCurrentProcessId
0x445104 GetCurrentThreadId
0x445108 DecodePointer
0x44510c InitializeSListHead
0x445110 IsDebuggerPresent
0x445114 GetStartupInfoW
0x445118 GetModuleHandleW
0x44511c InterlockedPushEntrySList
0x445120 InterlockedFlushSList
0x445124 RtlUnwind
0x445128 EnterCriticalSection
0x44512c LeaveCriticalSection
0x445130 DeleteCriticalSection
0x445134 InitializeCriticalSectionAndSpinCount
0x445138 TlsAlloc
0x44513c TlsGetValue
0x445140 TlsSetValue
0x445144 TlsFree
0x445148 FreeLibrary
0x44514c LoadLibraryExW
0x445150 EncodePointer
0x445154 RaiseException
0x445158 SetStdHandle
0x44515c ExitProcess
0x445160 GetModuleHandleExW
0x445164 GetConsoleCP
0x445168 WriteFile
0x44516c GetCommandLineA
0x445170 HeapAlloc
0x445174 HeapFree
0x445178 GetDateFormatW
0x44517c GetTimeFormatW
0x445180 CompareStringW
0x445184 LCMapStringW
0x445188 GetLocaleInfoW
0x44518c IsValidLocale
0x445190 GetUserDefaultLCID
0x445194 EnumSystemLocalesW
0x445198 GetCurrentThread
0x44519c FlushFileBuffers
0x4451a0 GetConsoleOutputCP
0x4451a4 GetConsoleMode
0x4451a8 WideCharToMultiByte
0x4451ac CreateFileW
0x4451b0 SetConsoleMode
0x4451b4 GetNumberOfConsoleInputEvents
0x4451b8 ReadConsoleInputW
0x4451bc PeekConsoleInputA
0x4451c0 ReadConsoleW
0x4451c4 GetStringTypeW
0x4451c8 GetFileSizeEx

Address Name
0x4451d0 LoadCursorA
0x4451d4 InflateRect
0x4451d8 GetSysColorBrush
0x4451dc SetCursor
0x4451e0 SetWindowTextA
0x4451e4 GetDlgItem
0x4451e8 EndDialog
0x4451ec DialogBoxIndirectParamA
0x4451f0 SendMessageA

Address Name
0x445028 StartPage
0x44502c EndDoc
0x445030 StartDocA
0x445034 SetMapMode
0x445038 GetDeviceCaps
0x44503c EndPage

Address Name
0x445020 PrintDlgA

Address Name
0x445000 RegQueryValueExW
0x445004 RegQueryValueExA
0x445008 RegOpenKeyExA
0x44500c RegOpenKeyA
0x445010 RegCreateKeyA
0x445014 RegCloseKey
0x445018 RegSetValueExA
Processing 5.10s
  • 4.95s CAPE
  • 0.106s BehaviorAnalysis
  • 0.046s AnalysisInfo
  • 0.001s Debug
Signatures 0.20s
  • 0.05s antiav_detectreg
  • 0.019s infostealer_ftp
  • 0.014s territorial_disputes_sigs
  • 0.011s antianalysis_detectreg
  • 0.011s infostealer_im
  • 0.007s antiav_detectfile
  • 0.006s antivm_vbox_keys
  • 0.006s ransomware_files
  • 0.005s infostealer_mail
  • 0.005s ransomware_extensions_known
  • 0.004s antianalysis_detectfile
  • 0.004s antivm_vmware_keys
  • 0.004s infostealer_bitcoin
  • 0.004s masquerade_process_name
  • 0.003s antivm_parallels_keys
  • 0.003s antivm_vbox_files
  • 0.003s antivm_xen_keys
  • 0.002s antivm_generic_diskreg
  • 0.002s antivm_vpc_keys
  • 0.002s geodo_banking_trojan
  • 0.002s browser_security
  • 0.002s disables_backups
  • 0.002s poullight_files
  • 0.001s antidebug_devices
  • 0.001s antivm_bochs_keys
  • 0.001s antivm_generic_bios
  • 0.001s antivm_hyperv_keys
  • 0.001s antivm_vbox_devices
  • 0.001s antivm_vmware_files
  • 0.001s ketrican_regkeys
  • 0.001s banker_zeus_mutex
  • 0.001s bypass_firewall
  • 0.001s file_credential_store_access
  • 0.001s registry_credential_store_access
  • 0.001s darkcomet_regkeys
  • 0.001s disables_browser_warn
  • 0.001s disables_power_options
  • 0.001s disables_startmenu_search
  • 0.001s azorult_mutexes
  • 0.001s cryptbot_files
  • 0.001s echelon_files
  • 0.001s qulab_files
  • 0.001s revil_mutexes
  • 0.001s satan_mutexes
  • 0.001s limerat_regkeys
  • 0.001s modirat_behavior
  • 0.001s rat_pcclient
  • 0.001s warzonerat_regkeys
  • 0.001s recon_fingerprint
  • 0.001s language_check_registry
  • 0.001s tampers_etw
  • 0.001s lokibot_mutexes
  • 0.001s ursnif_behavior
Reporting 0.00s
  • 0.003s JsonDump
Signatures
pdbpath: D:\a\1\s\Win32\Release\strings.pdb
overlay: Contains overlay at offset 0x00058200 with size: 9096 bytes
Binary triggered YARA rule: IsPE32
Binary triggered YARA rule: IsConsole
Binary triggered YARA rule: HasOverlay
Binary triggered YARA rule: HasDebugData
Binary triggered YARA rule: HasRichSignature
Binary triggered YARA rule: VC8_Microsoft_Corporation
Binary triggered YARA rule: Microsoft_Visual_Cpp_8
Summary
  • C:\Users\cape\AppData\Local\Temp\strings.exe
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\System32\msctf.dll
  • C:\Program Files\WindowsApps\Microsoft.LanguageExperiencePackru-RU_19041.80.272.0_neutral__8wekyb3d8bbwe\Windows\System32\ru-RU\USER32.dll.mui
  • C:\Windows\win.ini
  • C:\Windows\System32\uxtheme.dll.Config
  • C:\Windows\System32\uxtheme.dll
  • C:\Users\cape\AppData\Local\Temp\strings.exe.Local\
  • C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984
  • C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.1110_none_a8625c1886757984\comctl32.dll
  • C:\Windows\WindowsShell.Manifest
  • C:\Windows\System32\kernel.appcore.dll
  • C:\Windows\System32\bcryptPrimitives.dll
  • \Device\CNG
  • C:\Windows\System32\textinputframework.dll
  • C:\Windows\System32\CoreUIComponents.dll
  • C:\Windows\System32\CoreMessaging.dll
  • C:\Windows\System32\ntmarta.dll
  • C:\Windows\System32\WinTypes.dll
  • C:\Windows\SystemResources\USER32.dll.mun
  • C:\Users\cape\AppData\Local\Temp\TextShaping.dll
  • C:\Windows\System32\TextShaping.dll
  • C:\Windows\Fonts\staticcache.dat
  • HKEY_CURRENT_USER
  • HKEY_LOCAL_MACHINE\Software\Sysinternals
  • HKEY_CURRENT_USER\Software\Sysinternals
  • HKEY_CURRENT_USER\Software\Sysinternals\Strings
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Sorting\Ids
  • HKEY_LOCAL_MACHINE\Software\Microsoft\windows nt\currentversion
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Server\ServerLevels
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\StateSeparation\RedirectionMap\Keys
  • HKEY_LOCAL_MACHINE\Software\Microsoft\LanguageOverlay\OverlayPackages\ru-RU
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\ru-RU\Latest
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\System,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixedsys,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Small Fonts,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Serif,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Sans Serif,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\strings.exe
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\AppCompatClassName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\MS Shell Dlg
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Input
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\ResyncResetTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\MaxResyncAttempts
  • HKEY_CURRENT_USER\Software
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals\Strings
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals\Strings\EulaAccepted
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableUmpdBufferSizeCheck
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions\000603xx
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ProductName
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize\AppsUseLightTheme
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\LanguageOverlay\OverlayPackages\ru-RU\Latest
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\ResourcePolicies
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent Bold,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arabic Transparent,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helvetica
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg 2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tahoma Armenian
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Baltic,186
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CE,238
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman CYR,204
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Greek,161
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman TUR,162
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Shell Dlg
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\System,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Fixedsys,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Small Fonts,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Serif,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\MS Sans Serif,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Arial Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Courier New Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Times New Roman Cyr,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Helv,0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\Tms Rmn,0
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\STE
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\MDMEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\OOBE\LaunchUserOOBE
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\TurnOffSPIAnimations
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\IsVailContainer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\ResyncResetTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\MaxResyncAttempts
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableUmpdBufferSizeCheck
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals\Strings
  • HKEY_CURRENT_USER\SOFTWARE\Sysinternals\Strings\EulaAccepted
  • Local\SM0:6132:168:WilStaging_02
  • Local\MSCTF.Asm.MutexDefault1
  • CicLoadWinStaWinSta0
  • Local\MSCTF.CtfMonitorInstMutexDefault1
  • Local\SM0:6132:64:WilError_03

No results found.

No behavioral analysis data available.

Sorry! No strace.
Sorry! No tracee.
Hosts
No hosts contacted.
TCP Connections
No TCP connections recorded.
UDP Connections
No UDP connections recorded.
DNS Requests
No domains contacted.
HTTP Requests
No HTTP(s) requests performed.
SMTP Traffic
No SMTP traffic performed.
IRC Traffic
No IRC requests performed.
ICMP Traffic
No ICMP traffic performed.
CIF Results
No CIF Results
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Suricata HTTP
No Suricata HTTP
Sorry! No Suricata Extracted files.

No dropped files found.

Sorry! No process dumps.