Et voilà (mais c'est grave docteur ??) :
Fichier explorer.exe reçu le 2009.02.05 23:24:06 (CET)
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.02.05 -
AhnLab-V3 5.0.0.2 2009.02.05 -
AntiVir 7.9.0.74 2009.02.05 -
Authentium 5.1.0.4 2009.02.05 -
Avast 4.8.1281.0 2009.02.05 -
AVG 8.0.0.229 2009.02.05 -
BitDefender 7.2 2009.02.05 -
CAT-QuickHeal 10.00 2009.02.05 -
ClamAV 0.94.1 2009.02.05 -
Comodo 965 2009.02.05 -
DrWeb 4.44.0.09170 2009.02.05 -
eSafe 7.0.17.0 2009.02.05 -
eTrust-Vet 31.6.6343 2009.02.05 -
F-Prot 4.4.4.56 2009.02.05 -
F-Secure 8.0.14470.0 2009.02.05 -
Fortinet 3.117.0.0 2009.02.05 -
GData 19 2009.02.05 -
Ikarus T3.1.1.45.0 2009.02.05 -
K7AntiVirus 7.10.620 2009.02.05 -
Kaspersky 7.0.0.125 2009.02.05 -
McAfee 5516 2009.02.04 -
McAfee+Artemis 5516 2009.02.04 -
Microsoft 1.4306 2009.02.05 -
NOD32 3831 2009.02.05 -
Norman 6.00.02 2009.02.05 -
nProtect 2009.1.8.0 2009.02.05 -
Panda 9.5.1.2 2009.02.05 -
PCTools 4.4.2.0 2009.02.05 -
Prevx1 V2 2009.02.05 -
Rising 21.15.30.00 2009.02.05 -
SecureWeb-Gateway 6.7.6 2009.02.05 -
Sophos 4.38.0 2009.02.05 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.02.05 -
TheHacker 6.3.1.5.247 2009.02.05 -
TrendMicro 8.700.0.1004 2009.02.05 -
VBA32 3.12.8.12 2009.02.05 -
ViRobot 2009.2.5.1591 2009.02.05 -
VirusBuster 4.5.11.0 2009.02.05 -
Information additionnelle
File size: 3080704 bytes
MD5...: bbd8e74f23d7605cb0cdb57a1b25d826
SHA1..: d84af003a6a9dcf6ca9bd68bb66f2b96dcd1fce8
SHA256: 2e5e05f85aa53789a88cccb98dc6a52864492cf92f259ed24f4ffd894e91d096
SHA512: 1ad2a4c92ff062234a42ddb9029a0587c770036c5f1868291494d8b8c695ddc3<br>dd8ca800fec0b30b8931ca61ca62281e8023f8baab20a2defc1f7cae63dd1642<br>
ssdeep: 24576:F3/xDOesUVC38HDINpGYCW5uXSA7jTeFadRsxKb/g/J/ulZ:FPxDOesUVP<br>HDIvLC8A7/eFw33l<br>
PEiD..: -
TrID..: File type identification<br>Win64 Executable Generic (95.5%)<br>Generic Win/DOS Executable (2.2%)<br>DOS Executable Generic (2.2%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x23550<br>timedatestamp.....: 0x4907e791 (Wed Oct 29 04:33:21 2008)<br>machinetype.......: 0x8664 (AMD64)<br><br>( 6 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x731b9 0x73200 6.29 035ef792c6c677dda650715b324ea77b<br>.rdata 0x75000 0x19a64 0x19c00 4.63 a948cba1882a42bc64d94d561990b7e3<br>.data 0x8f000 0x2ffa 0x2e00 0.86 2db36e4ae57f1a7f36ba150aab05b050<br>.pdata 0x92000 0x858c 0x8600 5.97 5e3de5edca57db3504ae375153bbbfa9<br>.rsrc 0x9b000 0x2566a0 0x256800 7.04 4c8ed0154caccb7d6d39343edc8c8e27<br>.reloc 0x2f2000 0x1188 0x1200 5.39 7a0d23ff7ebf06fd655b80e02cb2ae13<br><br>( 19 imports ) <br>> ADVAPI32.dll: RegCreateKeyW, RegCloseKey, RegOpenKeyExW, RegGetValueW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, GetLengthSid, GetTokenInformation, OpenProcessToken, EventEnabled, EventWrite, EventRegister, EventUnregister, GetUserNameW, RegDeleteValueW, RegQueryInfoKeyW, RegEnumKeyExW, TraceMessage, RegOpenKeyW, RegEnumKeyW, RegEnumValueW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, QueryServiceStatus, CheckTokenMembership, ConvertStringSecurityDescriptorToSecurityDescriptorW, OpenThreadToken, ConvertSidToStringSidW, StartServiceW, CreateWellKnownSid<br>> KERNEL32.dll: GetCurrentProcessId, MultiByteToWideChar, GetLocalTime, GetTimeFormatW, GetDateFormatW, GetLocaleInfoW, GetSystemWindowsDirectoryW, FlushInstructionCache, SetLastError, RaiseException, CreateFileW, GetFileSize, ReadFile, LoadLibraryA, GetModuleHandleW, OpenEventW, FindClose, FindNextFileW, FindFirstFileW, GetFileAttributesW, GlobalGetAtomNameW, ExpandEnvironmentStringsW, GetUserDefaultUILanguage, SystemTimeToFileTime, GetSystemTime, SetEvent, LeaveCriticalSection, EnterCriticalSection, GlobalFree, GetUserDefaultLangID, GetPrivateProfileIntW, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetBinaryTypeW, CompareFileTime, GetSystemTimeAsFileTime, MulDiv, GetTickCount, CompareStringOrdinal, lstrcmpiW, ExitProcess, GetTimeZoneInformation, SetFilePointer, DeleteCriticalSection, HeapDestroy, RegisterApplicationRestart, SetTermsrvAppInstallMode, CreateEventW, GetSystemDirectoryW, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, InitializeCriticalSection, GetCurrentProcess, SetErrorMode, FreeLibrary, GetProcAddress, GetEnvironmentVariableW, QueryPerformanceFrequency, GetFileAttributesExW, GetLongPathNameW, QueueUserWorkItem, GetProcessTimes, GetProcessId, TerminateThread, CreateIoCompletionPort, GetQueuedCompletionStatus, GetModuleHandleA, GetWindowsDirectoryW, FormatMessageW, QueryFullProcessImageNameW, DuplicateHandle, GetCurrentDirectoryW, WideCharToMultiByte, GlobalAlloc, WriteFile, DeactivateActCtx, ActivateActCtx, ReleaseActCtx, CreateActCtxW, LockResource, LoadResource, FindResourceExW, WaitForSingleObject, HeapAlloc, HeapFree, GetProcessHeap, GetPrivateProfileStringW, GetModuleFileNameW, CreateProcessW, lstrlenW, GetCommandLineW, GetStartupInfoW, OpenProcess, LocalFree, LocalAlloc, GetLastError, QueryInformationJobObject, Sleep, CreateThread, SetPriorityClass, GetPriorityClass, ResumeThread, AssignProcessToJobObject, SetInformationJobObject, CreateJobObjectW, CloseHandle, LoadLibraryW, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, SetUnhandledExceptionFilter, InterlockedPushEntrySList, VirtualAlloc, InterlockedPopEntrySList, VirtualFree, DelayLoadFailureHook<br>> GDI32.dll: GetStockObject, OffsetViewportOrgEx, GetLayout, CombineRgn, SetWindowOrgEx, GdiAlphaBlend, GetTextExtentPoint32W, ExtTextOutW, CreatePatternBrush, GetTextMetricsW, SelectClipRgn, SetViewportOrgEx, GetViewportOrgEx, IntersectClipRect, GetClipRgn, CreateRectRgn, PatBlt, GetBkColor, SetBkColor, OffsetWindowOrgEx, CreateCompatibleBitmap, GetTextExtentPointW, GetClipBox, CreateDIBSection, CreateRectRgnIndirect, CreateFontIndirectW, CreateSolidBrush, SetBkMode, SetTextColor, GetObjectW, DeleteObject, GetPixel, DeleteDC, BitBlt, SelectObject, CreateCompatibleDC, GetDeviceCaps<br>> USER32.dll: GetScrollInfo, SetScrollInfo, SendMessageCallbackW, GetWindowLongPtrW, SwitchToThisWindow, EnableMenuItem, IsZoomed, IsIconic, GetSystemMenu, IsWindowVisible, GetWindowInfo, GetMonitorInfoW, MonitorFromWindow, GetWindowThreadProcessId, IsRectEmpty, KillTimer, SetTimer, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, IsWindow, SetFocus, GetFocus, GetMenuItemCount, LoadImageW, TrackPopupMenuEx, GetSubMenu, SetMenuDefaultItem, SetMenuInfo, LoadMenuW, InsertMenuItemW, SetForegroundWindow, DestroyIcon, SetMenuItemInfoW, GetMenuItemInfoW, DeleteMenu, CharUpperBuffW, GetWindowLongPtrA, PostQuitMessage, SetWindowLongPtrW, ShutdownBlockReasonCreate, LoadStringW, UnregisterDeviceNotification, RegisterDeviceNotificationW, RegisterWindowMessageW, SetWindowPos, UnregisterClassW, DestroyWindow, UpdateWindow, GetDesktopWindow, RegisterClassExW, EndPaint, SetLayeredWindowAttributes, LoadBitmapW, BeginPaint, InvalidateRect, DefWindowProcW, ShowWindow, MoveWindow, PostMessageW, PeekMessageW, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, ActivateKeyboardLayout, GetKeyboardLayout, IsProcessDPIAware, SetClassLongW, GetDCEx, PrintWindow, SetWindowLongW, GetPropW, GetGUIThreadInfo, GetCapture, GetNextDlgGroupItem, GetDlgCtrlID, GetNextDlgTabItem, ChildWindowFromPointEx, GetWindowDC, CharUpperW, SetWindowLongPtrA, RegisterClipboardFormatW, ReleaseCapture, SetWinEventHook, UnhookWinEvent, GetUserObjectInformationW, GetProcessWindowStation, LoadIconW, GetClassLongPtrW, GetIconInfo, InternalGetWindowText, GetShellWindow, SetProcessDPIAware, ReleaseDC, GetKeyState, GetForegroundWindow, IsWindowEnabled, GetAncestor, ShowWindowAsync, BringWindowToTop, MsgWaitForMultipleObjectsEx, AllowSetForegroundWindow, RemoveMenu, CallWindowProcW, EnableWindow, SetDlgItemInt, GetDlgItemInt, CheckDlgButton, SetParent, CopyIcon, DrawFocusRect, NotifyWinEvent, LockWorkStation, RegisterClassW, LoadCursorW, CascadeWindows, TileWindows, GetClassInfoExW, GetMenuItemID, TrackPopupMenu, FillRect, GetParent, CloseDesktop, OpenInputDesktop, GetThreadDesktop, EndTask, SetThreadDesktop, GetWindowLongW, EnumChildWindows, SendMessageW, MonitorFromRect, MapWindowPoints, AdjustWindowRectEx, SetRectEmpty, SetActiveWindow, DeregisterShellHookWindow, SetScrollPos, GetDlgItem, FlashWindowEx, GetClientRect, SetClassLongPtrW, GetClassLongW, GetClassInfoW, DrawTextW, GetSysColor, ScreenToClient, ClientToScreen, GetWindowRect, PtInRect, GetWindow, GetAsyncKeyState, HungWindowFromGhostWindow, GhostWindowFromHungWindow, IsDlgButtonChecked, EndDialog, GetSysColorBrush, UnionRect, EqualRect, IsHungAppWindow, GetLastActivePopup, AppendMenuW, WindowFromPoint, CheckMenuItem, ExitWindowsEx, DrawEdge, GetMessagePos, SetCursorPos, ChildWindowFromPoint, SendDlgItemMessageW, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, GetActiveWindow, MessageBeep, RemovePropW, GetLastInputInfo, GetWindowPlacement, GetWindowRgnBox, UpdateLayeredWindow, SetWindowRgn, SendMessageTimeoutW, OffsetRect, RedrawWindow, SubtractRect, WaitMessage, TranslateAcceleratorW, GetClassNameW, EnumDisplayMonitors, IntersectRect, LoadAcceleratorsW, SendNotifyMessageW, InflateRect, SetWindowPlacement, GetDoubleClickTime, SetCapture, TrackMouseEvent, LockSetForegroundWindow, CopyRect, SetRect, MonitorFromPoint, SetPropW, ModifyMenuW, InsertMenuW, GetMenuState, GetMessageW, TranslateMessage, DispatchMessageW, CharNextW, CharPrevW, CreatePopupMenu, GetMenuDefaultItem, EnumWindows, RegisterShellHookWindow, IsChild, GetCursorPos, GetDC, FindWindowW, GetSystemMetrics, DestroyMenu, SystemParametersInfoW, SetWindowTextW<br>> msvcrt.dll: free, _vsnwprintf, memset, memcpy, memcmp, _terminate@@YAXXZ, _onexit, realloc, memmove, malloc, __wgetmainargs, __C_specific_handler, _XcptFilter, _exit, _lock, __dllonexit, _unlock, __set_app_type, _fmode, _cexit, exit, _wcmdln, _initterm, _amsg_exit, __setusermatherr, _commode<br>> ntdll.dll: NtClose, NtOpenThreadToken, NtQueryInformationToken, RtlGetProductInfo, NtOpenProcessToken, NtQueryInformationProcess, NtSetInformationProcess, WinSqmAddToStream, NtSetSystemInformation<br>> SHLWAPI.dll: PathGetDriveNumberW, -, StrChrIW, SHRegGetUSValueW, -, StrDupW, PathQuoteSpacesW, -, -, -, PathRemoveFileSpecW, PathIsDirectoryW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, -, AssocQueryStringW, StrCmpW, -, PathParseIconLocationW, AssocQueryKeyW, PathIsPrefixW, -, -, -, -, SHOpenRegStream2W, -, -, PathFileExistsW, PathFindExtensionW, PathRemoveExtensionW, -, -, -, -, -, -, -, -, -, -, SHDeleteKeyW, PathAppendW, SHDeleteValueW, SHSetValueW, -, -, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, SHGetValueW, PathFindFileNameW, -, PathGetArgsW, SHSetThreadRef, SHCreateThreadRef, PathCombineW, -, -, -, -, -, StrChrW, StrToIntW, SHRegGetValueW, -, SHStrDupW, -, -, -, -, -, -, -, -, StrCmpNW, -, -, -, -, -, -, -, PathMatchSpecW, SHQueryValueExW, AssocCreate, StrCmpIW, -, PathIsRootW, PathIsNetworkPathW, -, SHQueryInfoKeyW, StrRetToBufW, -, -, -, -, -, StrStrIW, -, StrPBrkW, -, -, -, -, StrRetToStrW, PathStripToRootW<br>> SHELL32.dll: SHGetDesktopFolder, -, -, -, -, SHGetIDListFromObject, SHBindToFolderIDListParent, -, -, -, -, -, -, SHGetFolderPathW, -, -, -, SHBindToFolderIDListParentEx, -, -, SHCreateItemFromIDList, SHCreateShellItemArrayFromShellItem, -, -, -, -, -, -, -, SHCreateShellItemArrayFromIDLists, -, -, -, SHChangeNotify, SHAddToRecentDocs, DuplicateIcon, -, -, ShellExecuteW, -, -, -, SHGetPathFromIDListA, -, -, -, SHUpdateRecycleBinIcon, SHGetKnownFolderIDList, SHGetFolderPathEx, SHFileOperationW, -, -, SHGetPathFromIDListW, -, -, -, -, -, -, -, -, -, Shell_NotifyIconW, -, -, -, SHGetFolderPathAndSubDirW, ExtractIconExW, Shell_GetCachedImageIndexW, -, -, SHGetSpecialFolderLocation, -, SHBindToParent, -, -, -, SHEvaluateSystemCommandTemplate, -, -, -, -, -, -, -, -, ShellExecuteExW, -, -, -, -, -, SHBindToObject, -, SHGetSpecialFolderPathW, -, SHGetFolderLocation, -, -, SHParseDisplayName, -, -, -<br>> ole32.dll: CoRegisterClassObject, CoCreateInstance, CoTaskMemFree, CoRevokeClassObject, CoGetClassObject, OleInitialize, OleUninitialize, StringFromGUID2, CoGetObject, RegisterDragDrop, RevokeDragDrop, CoInitialize, CoUninitialize, CoRegisterMessageFilter, CoFreeUnusedLibraries, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoTaskMemAlloc, CoCreateFreeThreadedMarshaler, PropVariantClear, DoDragDrop, CoInitializeEx, CreateBindCtx<br>> OLEAUT32.dll: -, -, -, -, -, -<br>> SHDOCVW.dll: -, -<br>> UxTheme.dll: GetThemeColor, DrawThemeTextEx, GetThemeFont, GetThemeBackgroundRegion, GetThemeBool, IsCompositionActive, IsAppThemed, SetWindowTheme, GetThemeTextExtent, DrawThemeText, DrawThemeBackground, GetThemeRect, GetThemeMargins, GetThemeInt, CloseThemeData, OpenThemeData, DrawThemeParentBackground, GetThemeMetric, GetThemePartSize, GetThemeBackgroundContentRect, IsThemePartDefined<br>> POWRPROF.dll: GetPwrCapabilities<br>> dwmapi.dll: -, DwmSetWindowAttribute, DwmEnableBlurBehindWindow, DwmQueryThumbnailSourceSize, DwmUpdateThumbnailProperties, DwmGetColorizationColor, DwmIsCompositionEnabled, DwmUnregisterThumbnail, DwmRegisterThumbnail<br>> gdiplus.dll: GdiplusShutdown, GdiplusStartup, GdipGetImageHeight, GdipGetImageWidth, GdipCloneImage, GdipLoadImageFromFile, GdipDrawImageRectI, GdipSetInterpolationMode, GdipSetCompositingMode, GdipDeleteGraphics, GdipCreateFromHDC, GdipDisposeImage, GdipAlloc, GdipFree, GdipCreateBitmapFromStream<br>> slc.dll: SLGetWindowsInformationDWORD<br>> RPCRT4.dll: RpcStringFreeW, RpcBindingSetAuthInfoExW, RpcBindingFree, RpcStringBindingComposeW, I_RpcExceptionFilter, RpcBindingFromStringBindingW, NdrClientCall3<br>> PROPSYS.dll: VariantToInt32WithDefault, VariantToStringAlloc, PSCreateMemoryPropertyStore, VariantToStringWithDefault, VariantToBooleanWithDefault, PSGetPropertyDescription, PropVariantToStringAlloc, PSPropertyKeyFromString, PSGetNameFromPropertyKey, PSGetPropertyKeyFromName<br>> BROWSEUI.dll: -, -<br><br>( 0 exports ) <br>
Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.93 2009.02.05 -
AhnLab-V3 5.0.0.2 2009.02.05 -
AntiVir 7.9.0.74 2009.02.05 -
Authentium 5.1.0.4 2009.02.05 -
Avast 4.8.1281.0 2009.02.05 -
AVG 8.0.0.229 2009.02.05 -
BitDefender 7.2 2009.02.05 -
CAT-QuickHeal 10.00 2009.02.05 -
ClamAV 0.94.1 2009.02.05 -
Comodo 965 2009.02.05 -
DrWeb 4.44.0.09170 2009.02.05 -
eSafe 7.0.17.0 2009.02.05 -
eTrust-Vet 31.6.6343 2009.02.05 -
F-Prot 4.4.4.56 2009.02.05 -
F-Secure 8.0.14470.0 2009.02.05 -
Fortinet 3.117.0.0 2009.02.05 -
GData 19 2009.02.05 -
Ikarus T3.1.1.45.0 2009.02.05 -
K7AntiVirus 7.10.620 2009.02.05 -
Kaspersky 7.0.0.125 2009.02.05 -
McAfee 5516 2009.02.04 -
McAfee+Artemis 5516 2009.02.04 -
Microsoft 1.4306 2009.02.05 -
NOD32 3831 2009.02.05 -
Norman 6.00.02 2009.02.05 -
nProtect 2009.1.8.0 2009.02.05 -
Panda 9.5.1.2 2009.02.05 -
PCTools 4.4.2.0 2009.02.05 -
Prevx1 V2 2009.02.05 -
Rising 21.15.30.00 2009.02.05 -
SecureWeb-Gateway 6.7.6 2009.02.05 -
Sophos 4.38.0 2009.02.05 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.02.05 -
TheHacker 6.3.1.5.247 2009.02.05 -
TrendMicro 8.700.0.1004 2009.02.05 -
VBA32 3.12.8.12 2009.02.05 -
ViRobot 2009.2.5.1591 2009.02.05 -
VirusBuster 4.5.11.0 2009.02.05 -
Information additionnelle
File size: 3080704 bytes
MD5...: bbd8e74f23d7605cb0cdb57a1b25d826
SHA1..: d84af003a6a9dcf6ca9bd68bb66f2b96dcd1fce8
SHA256: 2e5e05f85aa53789a88cccb98dc6a52864492cf92f259ed24f4ffd894e91d096
SHA512: 1ad2a4c92ff062234a42ddb9029a0587c770036c5f1868291494d8b8c695ddc3<br>dd8ca800fec0b30b8931ca61ca62281e8023f8baab20a2defc1f7cae63dd1642<br>
ssdeep: 24576:F3/xDOesUVC38HDINpGYCW5uXSA7jTeFadRsxKb/g/J/ulZ:FPxDOesUVP<br>HDIvLC8A7/eFw33l<br>
PEiD..: -
TrID..: File type identification<br>Win64 Executable Generic (95.5%)<br>Generic Win/DOS Executable (2.2%)<br>DOS Executable Generic (2.2%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x23550<br>timedatestamp.....: 0x4907e791 (Wed Oct 29 04:33:21 2008)<br>machinetype.......: 0x8664 (AMD64)<br><br>( 6 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x731b9 0x73200 6.29 035ef792c6c677dda650715b324ea77b<br>.rdata 0x75000 0x19a64 0x19c00 4.63 a948cba1882a42bc64d94d561990b7e3<br>.data 0x8f000 0x2ffa 0x2e00 0.86 2db36e4ae57f1a7f36ba150aab05b050<br>.pdata 0x92000 0x858c 0x8600 5.97 5e3de5edca57db3504ae375153bbbfa9<br>.rsrc 0x9b000 0x2566a0 0x256800 7.04 4c8ed0154caccb7d6d39343edc8c8e27<br>.reloc 0x2f2000 0x1188 0x1200 5.39 7a0d23ff7ebf06fd655b80e02cb2ae13<br><br>( 19 imports ) <br>> ADVAPI32.dll: RegCreateKeyW, RegCloseKey, RegOpenKeyExW, RegGetValueW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, GetLengthSid, GetTokenInformation, OpenProcessToken, EventEnabled, EventWrite, EventRegister, EventUnregister, GetUserNameW, RegDeleteValueW, RegQueryInfoKeyW, RegEnumKeyExW, TraceMessage, RegOpenKeyW, RegEnumKeyW, RegEnumValueW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, QueryServiceStatus, CheckTokenMembership, ConvertStringSecurityDescriptorToSecurityDescriptorW, OpenThreadToken, ConvertSidToStringSidW, StartServiceW, CreateWellKnownSid<br>> KERNEL32.dll: GetCurrentProcessId, MultiByteToWideChar, GetLocalTime, GetTimeFormatW, GetDateFormatW, GetLocaleInfoW, GetSystemWindowsDirectoryW, FlushInstructionCache, SetLastError, RaiseException, CreateFileW, GetFileSize, ReadFile, LoadLibraryA, GetModuleHandleW, OpenEventW, FindClose, FindNextFileW, FindFirstFileW, GetFileAttributesW, GlobalGetAtomNameW, ExpandEnvironmentStringsW, GetUserDefaultUILanguage, SystemTimeToFileTime, GetSystemTime, SetEvent, LeaveCriticalSection, EnterCriticalSection, GlobalFree, GetUserDefaultLangID, GetPrivateProfileIntW, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetBinaryTypeW, CompareFileTime, GetSystemTimeAsFileTime, MulDiv, GetTickCount, CompareStringOrdinal, lstrcmpiW, ExitProcess, GetTimeZoneInformation, SetFilePointer, DeleteCriticalSection, HeapDestroy, RegisterApplicationRestart, SetTermsrvAppInstallMode, CreateEventW, GetSystemDirectoryW, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, InitializeCriticalSection, GetCurrentProcess, SetErrorMode, FreeLibrary, GetProcAddress, GetEnvironmentVariableW, QueryPerformanceFrequency, GetFileAttributesExW, GetLongPathNameW, QueueUserWorkItem, GetProcessTimes, GetProcessId, TerminateThread, CreateIoCompletionPort, GetQueuedCompletionStatus, GetModuleHandleA, GetWindowsDirectoryW, FormatMessageW, QueryFullProcessImageNameW, DuplicateHandle, GetCurrentDirectoryW, WideCharToMultiByte, GlobalAlloc, WriteFile, DeactivateActCtx, ActivateActCtx, ReleaseActCtx, CreateActCtxW, LockResource, LoadResource, FindResourceExW, WaitForSingleObject, HeapAlloc, HeapFree, GetProcessHeap, GetPrivateProfileStringW, GetModuleFileNameW, CreateProcessW, lstrlenW, GetCommandLineW, GetStartupInfoW, OpenProcess, LocalFree, LocalAlloc, GetLastError, QueryInformationJobObject, Sleep, CreateThread, SetPriorityClass, GetPriorityClass, ResumeThread, AssignProcessToJobObject, SetInformationJobObject, CreateJobObjectW, CloseHandle, LoadLibraryW, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, SetUnhandledExceptionFilter, InterlockedPushEntrySList, VirtualAlloc, InterlockedPopEntrySList, VirtualFree, DelayLoadFailureHook<br>> GDI32.dll: GetStockObject, OffsetViewportOrgEx, GetLayout, CombineRgn, SetWindowOrgEx, GdiAlphaBlend, GetTextExtentPoint32W, ExtTextOutW, CreatePatternBrush, GetTextMetricsW, SelectClipRgn, SetViewportOrgEx, GetViewportOrgEx, IntersectClipRect, GetClipRgn, CreateRectRgn, PatBlt, GetBkColor, SetBkColor, OffsetWindowOrgEx, CreateCompatibleBitmap, GetTextExtentPointW, GetClipBox, CreateDIBSection, CreateRectRgnIndirect, CreateFontIndirectW, CreateSolidBrush, SetBkMode, SetTextColor, GetObjectW, DeleteObject, GetPixel, DeleteDC, BitBlt, SelectObject, CreateCompatibleDC, GetDeviceCaps<br>> USER32.dll: GetScrollInfo, SetScrollInfo, SendMessageCallbackW, GetWindowLongPtrW, SwitchToThisWindow, EnableMenuItem, IsZoomed, IsIconic, GetSystemMenu, IsWindowVisible, GetWindowInfo, GetMonitorInfoW, MonitorFromWindow, GetWindowThreadProcessId, IsRectEmpty, KillTimer, SetTimer, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, IsWindow, SetFocus, GetFocus, GetMenuItemCount, LoadImageW, TrackPopupMenuEx, GetSubMenu, SetMenuDefaultItem, SetMenuInfo, LoadMenuW, InsertMenuItemW, SetForegroundWindow, DestroyIcon, SetMenuItemInfoW, GetMenuItemInfoW, DeleteMenu, CharUpperBuffW, GetWindowLongPtrA, PostQuitMessage, SetWindowLongPtrW, ShutdownBlockReasonCreate, LoadStringW, UnregisterDeviceNotification, RegisterDeviceNotificationW, RegisterWindowMessageW, SetWindowPos, UnregisterClassW, DestroyWindow, UpdateWindow, GetDesktopWindow, RegisterClassExW, EndPaint, SetLayeredWindowAttributes, LoadBitmapW, BeginPaint, InvalidateRect, DefWindowProcW, ShowWindow, MoveWindow, PostMessageW, PeekMessageW, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, ActivateKeyboardLayout, GetKeyboardLayout, IsProcessDPIAware, SetClassLongW, GetDCEx, PrintWindow, SetWindowLongW, GetPropW, GetGUIThreadInfo, GetCapture, GetNextDlgGroupItem, GetDlgCtrlID, GetNextDlgTabItem, ChildWindowFromPointEx, GetWindowDC, CharUpperW, SetWindowLongPtrA, RegisterClipboardFormatW, ReleaseCapture, SetWinEventHook, UnhookWinEvent, GetUserObjectInformationW, GetProcessWindowStation, LoadIconW, GetClassLongPtrW, GetIconInfo, InternalGetWindowText, GetShellWindow, SetProcessDPIAware, ReleaseDC, GetKeyState, GetForegroundWindow, IsWindowEnabled, GetAncestor, ShowWindowAsync, BringWindowToTop, MsgWaitForMultipleObjectsEx, AllowSetForegroundWindow, RemoveMenu, CallWindowProcW, EnableWindow, SetDlgItemInt, GetDlgItemInt, CheckDlgButton, SetParent, CopyIcon, DrawFocusRect, NotifyWinEvent, LockWorkStation, RegisterClassW, LoadCursorW, CascadeWindows, TileWindows, GetClassInfoExW, GetMenuItemID, TrackPopupMenu, FillRect, GetParent, CloseDesktop, OpenInputDesktop, GetThreadDesktop, EndTask, SetThreadDesktop, GetWindowLongW, EnumChildWindows, SendMessageW, MonitorFromRect, MapWindowPoints, AdjustWindowRectEx, SetRectEmpty, SetActiveWindow, DeregisterShellHookWindow, SetScrollPos, GetDlgItem, FlashWindowEx, GetClientRect, SetClassLongPtrW, GetClassLongW, GetClassInfoW, DrawTextW, GetSysColor, ScreenToClient, ClientToScreen, GetWindowRect, PtInRect, GetWindow, GetAsyncKeyState, HungWindowFromGhostWindow, GhostWindowFromHungWindow, IsDlgButtonChecked, EndDialog, GetSysColorBrush, UnionRect, EqualRect, IsHungAppWindow, GetLastActivePopup, AppendMenuW, WindowFromPoint, CheckMenuItem, ExitWindowsEx, DrawEdge, GetMessagePos, SetCursorPos, ChildWindowFromPoint, SendDlgItemMessageW, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, GetActiveWindow, MessageBeep, RemovePropW, GetLastInputInfo, GetWindowPlacement, GetWindowRgnBox, UpdateLayeredWindow, SetWindowRgn, SendMessageTimeoutW, OffsetRect, RedrawWindow, SubtractRect, WaitMessage, TranslateAcceleratorW, GetClassNameW, EnumDisplayMonitors, IntersectRect, LoadAcceleratorsW, SendNotifyMessageW, InflateRect, SetWindowPlacement, GetDoubleClickTime, SetCapture, TrackMouseEvent, LockSetForegroundWindow, CopyRect, SetRect, MonitorFromPoint, SetPropW, ModifyMenuW, InsertMenuW, GetMenuState, GetMessageW, TranslateMessage, DispatchMessageW, CharNextW, CharPrevW, CreatePopupMenu, GetMenuDefaultItem, EnumWindows, RegisterShellHookWindow, IsChild, GetCursorPos, GetDC, FindWindowW, GetSystemMetrics, DestroyMenu, SystemParametersInfoW, SetWindowTextW<br>> msvcrt.dll: free, _vsnwprintf, memset, memcpy, memcmp, _terminate@@YAXXZ, _onexit, realloc, memmove, malloc, __wgetmainargs, __C_specific_handler, _XcptFilter, _exit, _lock, __dllonexit, _unlock, __set_app_type, _fmode, _cexit, exit, _wcmdln, _initterm, _amsg_exit, __setusermatherr, _commode<br>> ntdll.dll: NtClose, NtOpenThreadToken, NtQueryInformationToken, RtlGetProductInfo, NtOpenProcessToken, NtQueryInformationProcess, NtSetInformationProcess, WinSqmAddToStream, NtSetSystemInformation<br>> SHLWAPI.dll: PathGetDriveNumberW, -, StrChrIW, SHRegGetUSValueW, -, StrDupW, PathQuoteSpacesW, -, -, -, PathRemoveFileSpecW, PathIsDirectoryW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, -, AssocQueryStringW, StrCmpW, -, PathParseIconLocationW, AssocQueryKeyW, PathIsPrefixW, -, -, -, -, SHOpenRegStream2W, -, -, PathFileExistsW, PathFindExtensionW, PathRemoveExtensionW, -, -, -, -, -, -, -, -, -, -, SHDeleteKeyW, PathAppendW, SHDeleteValueW, SHSetValueW, -, -, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, SHGetValueW, PathFindFileNameW, -, PathGetArgsW, SHSetThreadRef, SHCreateThreadRef, PathCombineW, -, -, -, -, -, StrChrW, StrToIntW, SHRegGetValueW, -, SHStrDupW, -, -, -, -, -, -, -, -, StrCmpNW, -, -, -, -, -, -, -, PathMatchSpecW, SHQueryValueExW, AssocCreate, StrCmpIW, -, PathIsRootW, PathIsNetworkPathW, -, SHQueryInfoKeyW, StrRetToBufW, -, -, -, -, -, StrStrIW, -, StrPBrkW, -, -, -, -, StrRetToStrW, PathStripToRootW<br>> SHELL32.dll: SHGetDesktopFolder, -, -, -, -, SHGetIDListFromObject, SHBindToFolderIDListParent, -, -, -, -, -, -, SHGetFolderPathW, -, -, -, SHBindToFolderIDListParentEx, -, -, SHCreateItemFromIDList, SHCreateShellItemArrayFromShellItem, -, -, -, -, -, -, -, SHCreateShellItemArrayFromIDLists, -, -, -, SHChangeNotify, SHAddToRecentDocs, DuplicateIcon, -, -, ShellExecuteW, -, -, -, SHGetPathFromIDListA, -, -, -, SHUpdateRecycleBinIcon, SHGetKnownFolderIDList, SHGetFolderPathEx, SHFileOperationW, -, -, SHGetPathFromIDListW, -, -, -, -, -, -, -, -, -, Shell_NotifyIconW, -, -, -, SHGetFolderPathAndSubDirW, ExtractIconExW, Shell_GetCachedImageIndexW, -, -, SHGetSpecialFolderLocation, -, SHBindToParent, -, -, -, SHEvaluateSystemCommandTemplate, -, -, -, -, -, -, -, -, ShellExecuteExW, -, -, -, -, -, SHBindToObject, -, SHGetSpecialFolderPathW, -, SHGetFolderLocation, -, -, SHParseDisplayName, -, -, -<br>> ole32.dll: CoRegisterClassObject, CoCreateInstance, CoTaskMemFree, CoRevokeClassObject, CoGetClassObject, OleInitialize, OleUninitialize, StringFromGUID2, CoGetObject, RegisterDragDrop, RevokeDragDrop, CoInitialize, CoUninitialize, CoRegisterMessageFilter, CoFreeUnusedLibraries, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoTaskMemAlloc, CoCreateFreeThreadedMarshaler, PropVariantClear, DoDragDrop, CoInitializeEx, CreateBindCtx<br>> OLEAUT32.dll: -, -, -, -, -, -<br>> SHDOCVW.dll: -, -<br>> UxTheme.dll: GetThemeColor, DrawThemeTextEx, GetThemeFont, GetThemeBackgroundRegion, GetThemeBool, IsCompositionActive, IsAppThemed, SetWindowTheme, GetThemeTextExtent, DrawThemeText, DrawThemeBackground, GetThemeRect, GetThemeMargins, GetThemeInt, CloseThemeData, OpenThemeData, DrawThemeParentBackground, GetThemeMetric, GetThemePartSize, GetThemeBackgroundContentRect, IsThemePartDefined<br>> POWRPROF.dll: GetPwrCapabilities<br>> dwmapi.dll: -, DwmSetWindowAttribute, DwmEnableBlurBehindWindow, DwmQueryThumbnailSourceSize, DwmUpdateThumbnailProperties, DwmGetColorizationColor, DwmIsCompositionEnabled, DwmUnregisterThumbnail, DwmRegisterThumbnail<br>> gdiplus.dll: GdiplusShutdown, GdiplusStartup, GdipGetImageHeight, GdipGetImageWidth, GdipCloneImage, GdipLoadImageFromFile, GdipDrawImageRectI, GdipSetInterpolationMode, GdipSetCompositingMode, GdipDeleteGraphics, GdipCreateFromHDC, GdipDisposeImage, GdipAlloc, GdipFree, GdipCreateBitmapFromStream<br>> slc.dll: SLGetWindowsInformationDWORD<br>> RPCRT4.dll: RpcStringFreeW, RpcBindingSetAuthInfoExW, RpcBindingFree, RpcStringBindingComposeW, I_RpcExceptionFilter, RpcBindingFromStringBindingW, NdrClientCall3<br>> PROPSYS.dll: VariantToInt32WithDefault, VariantToStringAlloc, PSCreateMemoryPropertyStore, VariantToStringWithDefault, VariantToBooleanWithDefault, PSGetPropertyDescription, PropVariantToStringAlloc, PSPropertyKeyFromString, PSGetNameFromPropertyKey, PSGetPropertyKeyFromName<br>> BROWSEUI.dll: -, -<br><br>( 0 exports ) <br>