Static | ZeroBOX

PE Compile Time

2021-04-09 04:44:13

PDB Path

C:\Users\W7H64\Desktop\VCSamples-master\VC2010Samples\ATL\General\commap\aggreg\informasionze.pdb

PE Imphash

4a781930090209c67b1a0398b1940cca

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00041dc6 0x00041e00 6.62765458464
.rdata 0x00043000 0x0000dd52 0x0000de00 5.36997541924
.data 0x00051000 0x0012afdc 0x00129c00 2.31268819376
.rsrc 0x0017c000 0x000001e0 0x00000200 4.71767883295
.reloc 0x0017d000 0x00002f0c 0x00003000 6.63026719391

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0017c060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x44309c TlsFree
0x4430a0 TlsGetValue
0x4430a4 TlsSetValue
0x4430a8 VirtualProtect
0x4430ac VirtualAlloc
0x4430b0 WaitForSingleObject
0x4430b4 GetCurrentThreadId
0x4430b8 GetCommandLineA
0x4430bc SetEvent
0x4430c0 CloseHandle
0x4430c4 CreateThread
0x4430c8 GetModuleHandleW
0x4430cc CreateEventA
0x4430d0 WriteConsoleW
0x4430d4 GetConsoleMode
0x4430d8 GetConsoleCP
0x4430dc FlushFileBuffers
0x4430e0 GetStringTypeW
0x4430e8 OutputDebugStringA
0x4430f0 TlsAlloc
0x443104 GetCommandLineW
0x443108 GetCPInfo
0x44310c GetOEMCP
0x443110 IsValidCodePage
0x443114 FindNextFileW
0x443118 FindNextFileA
0x44311c FindFirstFileExW
0x443120 FindFirstFileExA
0x443124 FindClose
0x443128 GetFileType
0x44312c HeapAlloc
0x443130 HeapFree
0x443134 GetCurrentThread
0x443138 HeapReAlloc
0x44313c HeapSize
0x443140 EnumSystemLocalesW
0x443144 TerminateProcess
0x443148 TerminateJobObject
0x443150 SwitchToThread
0x443154 SuspendThread
0x443158 SleepEx
0x443160 Sleep
0x443164 SignalObjectAndWait
0x44316c SetThreadPriority
0x443170 SetStdHandle
0x44317c SetLastError
0x443188 SetFilePointerEx
0x44318c SetFileAttributesW
0x443190 lstrcmpiA
0x443194 WideCharToMultiByte
0x443198 FreeLibrary
0x44319c GetModuleFileNameA
0x4431a4 GetProcAddress
0x4431a8 DecodePointer
0x4431ac LoadResource
0x4431b0 IsDBCSLeadByte
0x4431b4 RaiseException
0x4431b8 GetLastError
0x4431bc MultiByteToWideChar
0x4431c0 GetModuleHandleA
0x4431c4 FindResourceA
0x4431d0 LoadLibraryExA
0x4431d8 SizeofResource
0x4431dc GetProcessHeap
0x4431e0 GetUserDefaultLCID
0x4431e4 IsValidLocale
0x4431e8 GetLocaleInfoW
0x4431ec LCMapStringW
0x4431f0 CompareStringW
0x4431f4 GetTimeFormatW
0x4431f8 GetDateFormatW
0x4431fc GetACP
0x443200 WriteFile
0x443204 GetStdHandle
0x443208 GetModuleFileNameW
0x44320c GetModuleHandleExW
0x443210 ExitProcess
0x443214 VirtualQuery
0x443218 GetSystemInfo
0x44321c LoadLibraryExW
0x443224 EncodePointer
0x443230 RtlUnwind
0x443234 InitializeSListHead
0x44323c GetCurrentProcessId
0x443244 IsDebuggerPresent
0x443248 OutputDebugStringW
0x443250 GetCurrentProcess
0x443258 GetStartupInfoW
0x44325c CreateFileW
Library USER32.dll:
0x443298 CloseDesktop
0x44329c CloseWindowStation
0x4432a0 UnregisterClassA
0x4432a4 CreateWindowExW
0x4432ac DefWindowProcW
0x4432b0 DestroyWindow
0x4432b4 CharNextA
0x4432b8 CreateDesktopW
0x4432bc RegisterClassW
0x4432c0 DispatchMessageW
0x4432c4 GetMessageA
0x4432c8 FindWindowExW
0x4432cc PostThreadMessageA
0x4432d0 MessageBoxA
0x4432d4 CharNextW
0x4432d8 TranslateMessage
0x4432dc CharUpperA
0x4432e0 DispatchMessageA
0x4432e4 PostMessageW
0x4432e8 IsWindow
0x4432f4 GetThreadDesktop
0x4432fc GetMessageW
Library ADVAPI32.dll:
0x443000 FreeSid
0x443004 RegQueryInfoKeyA
0x443008 SystemFunction036
0x44300c SetTokenInformation
0x443010 SetThreadToken
0x443014 SetSecurityInfo
0x44301c SetEntriesInAclW
0x443020 RevertToSelf
0x443024 RegSetValueExW
0x443028 RegQueryValueExW
0x443034 GetLengthSid
0x44303c GetAce
0x443040 EventWrite
0x443044 EventUnregister
0x443048 EventRegister
0x44304c EqualSid
0x443050 DuplicateTokenEx
0x443054 DuplicateToken
0x443058 CreateWellKnownSid
0x443064 CopySid
0x443074 AccessCheck
0x443078 RegCloseKey
0x44307c RegQueryInfoKeyW
0x443080 RegDeleteKeyA
0x443084 RegCreateKeyExA
0x443088 RegSetValueExA
0x44308c RegOpenKeyExA
0x443090 RegDeleteValueA
0x443094 RegEnumKeyExA
Library SHELL32.dll:
0x443288 SHGetFolderPathW
Library ole32.dll:
0x443304 CoRevokeClassObject
0x443308 CoTaskMemAlloc
0x44330c CoTaskMemFree
0x443310 CoTaskMemRealloc
0x44331c CoInitialize
0x443320 StringFromGUID2
0x443324 CoUninitialize
0x443328 CoCreateInstance
Library OLEAUT32.dll:
0x443264 LoadRegTypeLib
0x443268 LoadTypeLib
0x44326c UnRegisterTypeLib
0x443270 SysAllocString
0x443274 SysStringLen
0x443278 VarUI4FromStr
0x44327c SysFreeString
0x443280 RegisterTypeLib

!This program cannot be run in DOS mode.
Richfr
`.rdata
@.data
@.reloc
D$ PQQQ
QQQQQQQPQQQ
HWhtQD
D$ x0k
Q(_][^
VWhtQD
9t(9^
uHSSSSSSS
uHSSSSSSS
u#8F<t
G,;w0|
QQSVWd
tH9] uC
u PWQR
URPQQh
tJ<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
t h ^D
t h(^D
<0|O<9
<A|2<P
uahh^D
9t2j(
t4<A|)<P
<0|*<9
<0|]<8
;t$,v-
UQPXY]Y[
Tt1jhZ;
Tt1jhZ;
Tt1jhZ;
Tt1jhZ;
Tt1jhZ;
Tt1jhZ;
^$+^8+
^$+^8+
^$+^8+
^$+^8+
^$+^8+
^$+^8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
t0jXXf
~$+~8+
F2jgYf;
F(jgYjGZ
F2jgYf;
F2jgYf;
F2jgYf;
F(jgYjGZ
F2jgYf;
F2jgYf;
<0|H<9
<0|H<9
x(j$Xf9
x(j$Xf9
j"^f91j\^u8
j"^f9q
t/j=[f;
QSSSSj
uGh|cD
tyPVj@W
_tcPVj@
u#j,Xf;
u0jAXf;
u0jAXf;
<xt"<Xt
u/jAXj
t.hlkD
aSh lD
uFVWhd
Wj0XPV
taj*Xf
WWWPWS
u-PWWS
VWj\^j:
WWWPWS
SSVWh
f9:t!V
|VWj=S
}VWj=S
tl9tX
t"k58bD
QQSWj0j@
<0|o<9
u^9^\t/
VX9^`tT
;N\u\W
u2Vj@hp
9C`u99C\t4
9C`u5Wj
jA[jZZ+
PPPPPWS
PP9E u:PPVWP
PPPPPPPP
mSjA[jZ^+
8jZZf;
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
Wj5_f;
f9/t"S
'+?2LF,
Unknown exception
bad allocation
bad array new length
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
template-parameter-
generic-type-
`anonymous namespace'
`non-type-template-parameter
`template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char16_t
char32_t
wchar_t
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
volatile
const
cli::array<
cli::pin_ptr<
{flat}
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetActiveWindow
GetCurrentPackageId
GetDateFormatEx
GetEnabledXStateFeatures
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
SetThreadStackGuarantee
SystemFunction036
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
atlTraceGeneral
atlTraceCOM
atlTraceQI
atlTraceRegistrar
atlTraceRefcount
atlTraceWindowing
atlTraceControls
atlTraceHosting
atlTraceDBClient
atlTraceDBProvider
atlTraceSnapin
atlTraceNotImpl
atlTraceAllocation
atlTraceException
atlTraceTime
atlTraceCache
atlTraceStencil
atlTraceString
atlTraceMap
atlTraceUtil
atlTraceSecurity
atlTraceSync
atlTraceISAPI
Advapi32.dll
RegOpenKeyTransactedA
RegCreateKeyTransactedA
RegDeleteKeyTransactedA
RegDeleteKeyExA
ForceRemove
NoRemove
Delete
Component Categories
FileType
Interface
Hardware
SECURITY
SYSTEM
Software
TypeLib
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
CLSID\
\Required Categories
\Implemented Categories
UnRegisterTypeLibForUser
RegisterTypeLibForUser
Mscoree.dll
UnregServer
RegServer
UnregServerPerUser
RegServerPerUser
RSDS23
C:\Users\W7H64\Desktop\VCSamples-master\VC2010Samples\ATL\General\commap\aggreg\informasionze.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
ATL$__a
ATL$__m
ATL$__z
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
GetModuleFileNameA
SizeofResource
EnterCriticalSection
LoadLibraryExA
LeaveCriticalSection
InitializeCriticalSectionEx
FindResourceA
GetModuleHandleA
MultiByteToWideChar
GetLastError
RaiseException
IsDBCSLeadByte
LoadResource
DecodePointer
GetProcAddress
DeleteCriticalSection
FreeLibrary
WideCharToMultiByte
lstrcmpiA
SetFileAttributesW
SetFilePointerEx
SetHandleInformation
SetInformationJobObject
SetLastError
SetNamedPipeHandleState
SetProcessShutdownParameters
SetStdHandle
SetThreadPriority
SetUnhandledExceptionFilter
SignalObjectAndWait
SleepConditionVariableSRW
SleepEx
SuspendThread
SwitchToThread
SystemTimeToTzSpecificLocalTime
TerminateJobObject
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
VirtualProtect
VirtualAlloc
WaitForSingleObject
GetCurrentThreadId
GetCommandLineA
SetEvent
CloseHandle
CreateThread
GetModuleHandleW
CreateEventA
KERNEL32.dll
UnregisterClassA
CharNextA
AllowSetForegroundWindow
CloseDesktop
CloseWindowStation
CreateDesktopW
CreateWindowExW
CreateWindowStationW
DefWindowProcW
DestroyWindow
DispatchMessageW
FindWindowExW
GetMessageW
GetProcessWindowStation
GetThreadDesktop
GetUserObjectInformationW
GetWindowThreadProcessId
IsWindow
PostMessageW
RegisterClassW
CharUpperA
TranslateMessage
CharNextW
MessageBoxA
PostThreadMessageA
DispatchMessageA
GetMessageA
USER32.dll
RegEnumKeyExA
RegDeleteValueA
RegOpenKeyExA
RegSetValueExA
RegCreateKeyExA
RegDeleteKeyA
RegQueryInfoKeyW
RegCloseKey
AccessCheck
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
ConvertStringSidToSidW
CopySid
CreateProcessAsUserW
CreateRestrictedToken
CreateWellKnownSid
DuplicateToken
DuplicateTokenEx
EqualSid
EventRegister
EventUnregister
EventWrite
FreeSid
GetAce
GetKernelObjectSecurity
GetLengthSid
GetNamedSecurityInfoW
GetSecurityDescriptorSacl
RegQueryValueExW
RegSetValueExW
RevertToSelf
SetEntriesInAclW
SetKernelObjectSecurity
SetSecurityInfo
SetThreadToken
SetTokenInformation
SystemFunction036
RegQueryInfoKeyA
ADVAPI32.dll
SHGetFolderPathW
SHGetKnownFolderPath
SHELL32.dll
CoTaskMemAlloc
CoTaskMemFree
CoTaskMemRealloc
CoAddRefServerProcess
CoReleaseServerProcess
CoInitialize
StringFromGUID2
CoUninitialize
CoCreateInstance
CoRegisterClassObject
CoResumeClassObjects
CoRevokeClassObject
ole32.dll
OLEAUT32.dll
IsDebuggerPresent
OutputDebugStringW
UnhandledExceptionFilter
GetCurrentProcess
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
InterlockedPushEntrySList
InterlockedFlushSList
EncodePointer
InitializeCriticalSectionAndSpinCount
LoadLibraryExW
GetSystemInfo
VirtualQuery
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
GetACP
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapSize
HeapReAlloc
GetCurrentThread
HeapFree
HeapAlloc
GetFileType
FindClose
FindFirstFileExA
FindFirstFileExW
FindNextFileA
FindNextFileW
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
SetEnvironmentVariableW
GetProcessHeap
SetConsoleCtrlHandler
OutputDebugStringA
WaitForSingleObjectEx
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
.?AUIClassFactory@@
.?AV?$CComContainedObject@VCAgg@@@ATL@@
.?AUIUnknown@@
.?AUIRegistrarBase@@
.?AVCAtlException@ATL@@
.?AV?$CComAggObject@VCAgg@@@ATL@@
.?AUIDispatch@@
.?AV?$CComObjectNoLock@VCComClassFactory@ATL@@@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AUISupportErrorInfo@@
.?AV?$CComObject@VCAgg@@@ATL@@
.?AV?$IDispatchImpl@UIAgg@@$1?IID_IAgg@@3U_GUID@@B$1?LIBID_AGGREGLib@@3U3@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$CComCoClass@VCAgg@@$1?CLSID_CAgg@@3U_GUID@@B@ATL@@
.?AVCAgg@@
.?AVCRegObject@ATL@@
.?AUIAgg@@
.?AVCComClassFactory@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AV?$CComObjectRootEx@VCComMultiThreadModel@ATL@@@ATL@@
.?AV?$IDispatchImpl@UIAggBlind@@$1?IID_IAggBlind@@3U_GUID@@B$1?LIBID_AGGREGLib@@3U3@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$CComCoClass@VCAggBlind@@$1?CLSID_CAggBlind@@3U_GUID@@B@ATL@@
.?AV?$CComObject@VCAggBlind@@@ATL@@
.?AVCAggBlind@@
.?AV?$CComContainedObject@VCAggBlind@@@ATL@@
.?AV?$CComAggObject@VCAggBlind@@@ATL@@
.?AUIAggBlind@@
.?AV?$IDispatchImpl@UIAutoAgg@@$1?IID_IAutoAgg@@3U_GUID@@B$1?LIBID_AGGREGLib@@3U3@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$IDispatchImpl@UIAutoAggB@@$1?IID_IAutoAggB@@3U_GUID@@B$1?LIBID_AGGREGLib@@3U3@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$CComContainedObject@VCAutoAgg@@@ATL@@
.?AV?$CAtlExeModuleT@VCAggregModule@@@ATL@@
.?AVCAggregModule@@
.?AV?$CComCoClass@VCAutoAgg@@$1?CLSID_CAutoAgg@@3U_GUID@@B@ATL@@
.?AUIAutoAgg@@
.?AV?$CComContainedObject@VCAutoAggB@@@ATL@@
.?AU?$CAtlValidateModuleConfiguration@$0A@VCAggregModule@@@ATL@@
.?AV?$CComCoClass@VCAutoAggB@@$1?CLSID_CAutoAggB@@3U_GUID@@B@ATL@@
.?AV?$CComObject@VCAutoAgg@@@ATL@@
.?AUIAutoAggB@@
.?AVCAutoAgg@@
.?AU_ATL_MODULE70@ATL@@
.?AVCAutoAggB@@
.?AV?$CComAggObject@VCAutoAggB@@@ATL@@
.?AV?$CComObject@VCAutoAggB@@@ATL@@
.?AVCAtlModule@ATL@@
.?AV?$CComAggObject@VCAutoAgg@@@ATL@@
.?AV?$CAtlModuleT@VCAggregModule@@@ATL@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0(040>0
0)1G1b1
2/3L3V3e3o3
5 5`5z5
6"6&656>6G6R6^6
7 7*757E7S7Y7^7d7k7v78'8-868=8B8I8O8W8v8
21383M3i3
<U=`=g=t=>&>D>K>
2(2=2X2t2
:.:;:L:
;1;j;p;
2G3c3}4
6'646Y6c6j6q6
7+7F7P7W7)808?8G8O8W8_8g8o8w8
9-9>9N9
='=3=E=R=w=
>#>5><>I>d>n>u>
0@0X0t0{0
01O1W1]1
8#929>9q9
9!:):/:8:?:H:e:
<0<7<=<G<e<j<|<
=,=5=F=^=o=z=
>5?B?G?L?
0)01090^0
091F1k1
3#303=3H3S3Y3c3z3
454L4h4
5%5<5X5
5"696P6l6
7)7@7\7
9$9-9?9
::%:+:1:7:=:C:I:O:U:[:a:g:m:s:y:
;!;';-;3;9;?;E;K;Q;W;];c;i;o;u;{;
<#<)</<5<;<A<G<M<S<Y<_<e<k<q<w<}<
=:=I=R=X=^=
1C1L1W1^1~1
2)292I2R2
3'3,3Q3W3]3c3i3o3v3}3
494@4Q4a4
8&878M8b8w8~8
9<9D9]9w9
<0=8=q=
?0?9?B?P?Y?j?
K0k0u0
2I2o2x2~2
3 3&3;3S3Y3i3
:P:X:j:w:
<(=/=4=8=<=@=
H0\0o0
1!1%1)1-1115191=1A1E1I1M1Q1U1Y1]1a1e1i1m1q1u1y1}1
?!?%?)?-?1?5?9?=?A?E?I?M?Q?U?Y?]?a?
1R2d3w3
5;6@6D6H6L6
:1;4<[<
=#=8=R=z=
> >1>B>L>Z>u>
6Q7i7o7
>3>e>q>
0%030:0@0Y0`0g0p0
1+10151E1J1O1r1
2,242j2
3'3=3Y3h3m3r3
4#4A4K4W4\4a4
88V8k8~8
8%9j;y;
<A=]=f=
1D2l2~2
4P56s6
9&:-:]:
<5<U<[<
=>=C=O=V=j=}=
0H0O0T0f0m0t0{0
1$131I1P1W1^1
242L2`2
2U3f3y3
4d4u4{4
=<>\>b>
1O1T1|1
1E2I2M2Q2U2Y2]2a2m2u2
343Q3b3
:?:N:g:w:
>]?m?t?
0!020?0O0v0
051Q1V1j1
2*2S2e2q2
3?3Y3f3n3
5N5\5j5
6%6X6p6y6
<R<]<k<w<
<+=P=v=
=F>K>e>r>
31383B3a3
3Y4d4o4w4
8L8W8m8
;";+;[;f;w;
<(<O<w<
1"151L1i1
3-4C4V4
6=6Z6e6
7+8>8:9C9K9
93;M;\;j;v;
<'<5<C<N<
7;7M7m7
8 8B8W8y8
4p5t5x5|5
9 9$9(9,9
9l:p:t:x:|:
> >$>(>,>0>4>
>8?<?@?D?H?L?P?T?
h0l0p0t0x0|0
1#1?1C1G1K1O1S1W1[1_1c1g1k152
3E3K3Q3W3]3c3i3o3u3{3
6"7L7_7n7
8'8,8=8
859G9O9Y9b9s9
1"1(1.1
2(262<2J2P2Z2y2
9!9'9-939
:,:2:@:r:
0 0+030>0D0O0U0c0
0 1%1E1J1
1$222<2Z2a2g2u2{2
3(363B3X3k3
4*4;4D4
=0>;>E>T>\>d>i?
8a9{9::
:A;Q;=z?
111:1@1R1]1s1
2:2U2`2
2Q3c3|3
0D0K0Q0X0j0o0
0-1H1M1S1Y1k1q1
2,21262F2K2P2`2e2j2z2
3 30353:3J3O3T3d3i3n3~3
44$44494>4N4S4X4h4m4r4
5#5_5o5
6R6i6s6
7(7E7j7
8#8-8I8T8Y8^8y8
8&9J9f9q9v9{9
: :;:E:a:
; ;%;C;g;r;w;|;
=*=L=p=
>2>T>_>d>i>
0'020?0U0`0e0j0
1#1E1S1b1
708A8]8
9N9_9z9
:?:P:j:s:
;#;.;<;E;l;r;
;L=V=y=
0]1-2f2
2#353k3
888K8e8x8
909J9]9w9
838:8X8b:
<=$=+=O=p=
>Y>k>q>
?1?^?e?p?~?
:f<?=^=
>">,>9>C>S>
2A2J2O2\2`2f2j2
<!<2<@<H<
=E>S>[>n>|>:?
2B3H3N3T3Z3`3
4(5>5Q5
5<6u6|6
6=7J7W7d7
:R;Y;_;t<
<M=_=z=
=#?5?Y?y?
1,1I1Q1z1
11282A2k2~2
2#3/3a3w3
7H:R:\:
;";4;F;X;j;|;
2"2*222~3[7
8!9r92:';q;c<
=4=y=!>v>~>
&3%8Y:
6)7P7[7k7
888N8X8w8
9-9V9t9
<!<X<_<
2B3J3y3
:N=U=\=c=
1(2<2g2
0A1K1u1
4M5g5t5
2V2i2x2
4*424O4_4k4z4~5
5(6E6Y6d6
9[9\:l:}:
;";(;1;s;
<(=4=9=?=
4*4@4H4
55%5+51575=5C5I5O5U5[5a5g5m5s5y5
6!6'6-63696?6E6K6Q6W6]6c6i6o6u6
414N4V4f4k4
5"6(6:6
7,7G7r7
999C9l9
:':H:c:~:
;%;@;[;v;
<-<7<X<s<
=0=K=f=
83@3D3H3L3P3\3`3d3h3l3x3|3
1$1@1X1l1p1x1|1
2 2$2(2H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
? ?$?(?,?8?D?P?\?
L2X2h2
4P5T5X5\5`5d5h5l5p5t5x5|5
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2
5$505<5H5T5`5l5x5
6 6,686D6P6\6h6t6
7(747@7L7X7d7p7
8(848@8L8X8d8p8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
4d>l>t>|>
?$?,?4?<?D?
t4x4|4
5(5@5D5H5L5P5T5X5
6 6(60686@6H6P6X6`6h6p6x6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$888<8@8D8H8L8P8T8X8\8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;
<(<`<d<h<l<p<t<x<|<
=4=8=<=@=D=h=l=p=t=x=|=
0 0(0@0P0T0d0h0l0p0x0
1$14181H1L1P1X1p1
2,20242<2T2d2h2x2|2
3(3,3034383<3@3D3H3L3P3T3X3`3x3
4044484@4D4H4L4P4T4X4\4`4d4h4p4
5$54585P5`5p5t5
6,6064686L6P6T6h6l6|6
7$74787<7@7H7P7h7l7
8$84888<8T8X8p8t8
9 9$9(9<9@9P9T9d9h9l9p9t9x9|9
:$:(:,:0:4:8:<:@:D:H:L:`:d:|:
; ;8;<;@;D;H;P;h;x;|;
<$<4<8<<<@<D<H<L<P<T<X<\<p<t<
=4=8=P=T=l=|=
> >$>(>,>0>4>8>@>D>H>L>P>T>X>\>`>d>h>p>
?$?(?,?D?H?L?P?T?\?`?d?h?l?p?t?x?|?
00040L0\0`0p0t0
1$14181P1T1l1|1
2 2$2(202H2X2\2`2t2x2
8$8D8P8p8|8
909<9D9\9t9|9
; ;P;X;x;
=8=T=d=p=
? ?@?\?l?x?
(0H0x0
1@1L1T1
2$282@2T2\2d2l2p2t2|2
383D3L3t3x3
484X4x4
5 5$5@5`5
6(6H6h6
7(7H7h7
808P8p8
909P9p9
:0:P:l:p:
1@1P1`1p1
1(7,787<7@7D7H7L7P7T7X7\7h7l7p7t7x7|7
P1T1p1t1
2(2@2X2p2
3(3H3h3
5D5X5x5
6 787p7
ERROR : Unable to initialize critical section in CAtlBaseModule
DForceRemove
DNoRemove
DDelete
Dapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
(null)
mscoree.dll
BRuntime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
CLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
msvcrt.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Dja-JP
((((( H
(
((((( H
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Software
Classes
Module
Module_Raw
REGISTRY
IAggBlind
sOLEAUT32.DLL
IAutoAgg
IAutoAggB
Antivirus Signature
Bkav Clean
Elastic Clean
ClamAV Clean
FireEye Trojan.GenericKD.46080143
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.3056743816
AegisLab Trojan.Win32.Bsymem.4!c
K7AntiVirus Trojan ( 0056ef3d1 )
BitDefender Trojan.GenericKD.46080143
K7GW Trojan ( 0056ef3d1 )
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/Kryptik.BKJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.GXKQ
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Alibaba Trojan:Win32/Kryptik.79a06946
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.46080143
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Trojan.GenericKD.46080143
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Agent.yaolx@0
F-Secure Clean
DrWeb Clean
VIPRE Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.tz
CMC Clean
Emsisoft Clean
SentinelOne Clean
Jiangmin Exploit.ShellCode.crg
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=80)
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Backdoor.AMRat.QXPVW3
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.Trojan.Wacatac
TACHYON Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
eGambit Clean
Fortinet W32/Kryptik.GXKQ!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike Clean
Qihoo-360 Win32/Trojan.Bsymem.HwoCiSgA
No IRMA results available.