Static | ZeroBOX

PE Compile Time

2017-11-21 15:08:45

PE Imphash

5921adaaf66f8c259aeda9e22686cd4b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c03e 0x0001c200 6.62402088945
.rdata 0x0001e000 0x000045ec 0x00004600 5.3378155251
.data 0x00023000 0x0001cde8 0x00017c00 5.79850721885
.rsrc 0x00040000 0x0000a724 0x0000a800 6.88372356193
.reloc 0x0004b000 0x0000195c 0x00001a00 6.32854794768

Resources

Name Offset Size Language Sub-language File type
NUTAVECEHENUBEPUHUGUWUJEJIXA 0x000403c8 0x00000100 LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with no line terminators
SOJEVILOHAMOCUGOROZOTAHUJAMIJU 0x000404c8 0x000002d4 LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
WADUTO 0x0004079c 0x00000070 LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with no line terminators
RT_BITMAP 0x0004637c 0x00002c08 LANG_SERBIAN SUBLANG_DEFAULT data
RT_BITMAP 0x0004637c 0x00002c08 LANG_SERBIAN SUBLANG_DEFAULT data
RT_BITMAP 0x0004637c 0x00002c08 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ICON 0x00048f84 0x000010a8 LANG_SERBIAN SUBLANG_DEFAULT dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 234027254, next used block 0
RT_DIALOG 0x0004a02c 0x0000004c LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0004a078 0x0000036a LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0004a3e4 0x00000014 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x0004a3f8 0x000001a4 LANG_SERBIAN SUBLANG_DEFAULT data
RT_MANIFEST 0x0004a59c 0x00000188 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document text

Imports

Library KERNEL32.dll:
0x41e024 ExitThread
0x41e028 GetStartupInfoW
0x41e02c GetLastError
0x41e030 GetProcAddress
0x41e034 GlobalFree
0x41e038 LoadLibraryA
0x41e03c AddAtomA
0x41e044 VirtualProtect
0x41e050 GetACP
0x41e054 CompareStringA
0x41e058 CreateFileA
0x41e060 WriteConsoleW
0x41e064 GetConsoleOutputCP
0x41e068 WriteConsoleA
0x41e06c CloseHandle
0x41e070 IsValidLocale
0x41e074 EnumSystemLocalesA
0x41e078 GetUserDefaultLCID
0x41e07c GetDateFormatA
0x41e080 GetTimeFormatA
0x41e084 InitAtomTable
0x41e088 GetSystemTimes
0x41e08c GetTickCount
0x41e094 GetComputerNameW
0x41e09c FindResourceExW
0x41e0a0 CompareStringW
0x41e0a4 GetCPInfo
0x41e0a8 GetStringTypeW
0x41e0ac GetStringTypeA
0x41e0b0 LCMapStringW
0x41e0b4 LCMapStringA
0x41e0b8 GetLocaleInfoA
0x41e0bc GetCommandLineA
0x41e0c0 GetStartupInfoA
0x41e0c4 RaiseException
0x41e0c8 RtlUnwind
0x41e0cc TerminateProcess
0x41e0d0 GetCurrentProcess
0x41e0dc IsDebuggerPresent
0x41e0e0 HeapAlloc
0x41e0e4 HeapFree
0x41e0f0 SetHandleCount
0x41e0f4 GetStdHandle
0x41e0f8 GetFileType
0x41e100 GetModuleHandleW
0x41e104 Sleep
0x41e108 ExitProcess
0x41e10c WriteFile
0x41e110 GetModuleFileNameA
0x41e11c WideCharToMultiByte
0x41e124 TlsGetValue
0x41e128 TlsAlloc
0x41e12c TlsSetValue
0x41e130 TlsFree
0x41e138 SetLastError
0x41e13c GetCurrentThreadId
0x41e144 GetCurrentThread
0x41e148 HeapCreate
0x41e14c HeapDestroy
0x41e150 VirtualFree
0x41e158 GetCurrentProcessId
0x41e160 FatalAppExitA
0x41e164 VirtualAlloc
0x41e168 HeapReAlloc
0x41e16c MultiByteToWideChar
0x41e170 ReadFile
0x41e178 HeapSize
0x41e180 FreeLibrary
0x41e184 InterlockedExchange
0x41e188 GetOEMCP
0x41e18c IsValidCodePage
0x41e190 GetConsoleCP
0x41e194 GetConsoleMode
0x41e198 FlushFileBuffers
0x41e19c SetFilePointer
0x41e1a0 SetStdHandle
0x41e1a4 GetLocaleInfoW
Library USER32.dll:
0x41e1c4 CloseClipboard
0x41e1c8 GetSubMenu
0x41e1cc LoadBitmapA
0x41e1d0 BeginPaint
0x41e1d4 CallMsgFilterW
0x41e1d8 PeekMessageA
0x41e1dc MapVirtualKeyExW
0x41e1e4 SetWindowsHookExW
0x41e1ec GetDialogBaseUnits
0x41e1f0 MessageBoxIndirectA
Library GDI32.dll:
0x41e000 CreateCompatibleDC
0x41e004 PlayEnhMetaFile
0x41e008 ScaleViewportExtEx
0x41e00c SetStretchBltMode
0x41e010 SetPixelV
0x41e018 AddFontResourceW
0x41e01c SetDeviceGammaRamp
Library SHELL32.dll:
0x41e1b4 ShellExecuteW
0x41e1b8 ShellAboutW
0x41e1bc DragQueryFileA

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
0WWWWW
0WWWWW
QQSVWd
0SSSSS
j@j ^V
>=Yt1j
Y;=p>B
tehe^@
HtHu4j
s[S;7|G;w
tR99u2
URPQQh
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
AtIHt0Hu
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0A@@Ju
Fh=h8B
to=p?B
;t$,v-
UQPXY]Y[
u,VVWV
t VV9u
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
RSSSSS
SSSSSS
string too long
invalid string position
invalid string argument
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONIN$
CONOUT$
bad allocation
kernel32.dll
CreateToolhelp32Snapshot
jamepozoteramexi zosimakeluxepu vemirazelerine
GlobalAlloc
vector<T> too long
GetCPInfo
FindResourceExW
FindCloseChangeNotification
GetComputerNameW
FreeEnvironmentStringsA
GetTickCount
GetSystemTimes
InitAtomTable
GetACP
ExitThread
GetStartupInfoW
GetLastError
GetProcAddress
GlobalFree
LoadLibraryA
AddAtomA
FindFirstChangeNotificationA
VirtualProtect
GetCurrentDirectoryA
SetProcessShutdownParameters
KERNEL32.dll
GetDialogBaseUnits
GetClipboardSequenceNumber
SetWindowsHookExW
RegisterRawInputDevices
MapVirtualKeyExW
PeekMessageA
CallMsgFilterW
BeginPaint
MessageBoxIndirectA
LoadBitmapA
GetSubMenu
CloseClipboard
USER32.dll
AddFontResourceW
CreateDiscardableBitmap
SetPixelV
SetStretchBltMode
ScaleViewportExtEx
PlayEnhMetaFile
CreateCompatibleDC
SetDeviceGammaRamp
GDI32.dll
DragQueryFileA
ShellAboutW
ShellExecuteW
ExtractAssociatedIconA
SHELL32.dll
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
HeapFree
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
GetModuleHandleW
ExitProcess
WriteFile
GetModuleFileNameA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
FatalAppExitA
VirtualAlloc
HeapReAlloc
MultiByteToWideChar
ReadFile
InitializeCriticalSectionAndSpinCount
HeapSize
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
GetOEMCP
IsValidCodePage
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
SetStdHandle
GetLocaleInfoW
GetLocaleInfoA
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
CloseHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
GetTimeZoneInformation
CreateFileA
CompareStringA
CompareStringW
SetEnvironmentVariableA
.?AVinvalid_argument@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
rukukiyipucajetutolorubewoma
pebokazumigesakukixoyefepuwahuje
.?AVexception@std@@
.?AVlogic_error@std@@
.7448!$9
6(2>("
=,:;=;#
.:'7$4
0:;;.9',
,67#!>
3 <>12<
9+>1.:
&&6';*:
2<%58
:$=/""
%#9?,
)#3=3(-
'+)-?*0
:59>$=
%%> >5
#<6$,)#
$>:*"3.
/223!:8"8
(,"$=16+
11&49,.4)<
71+)4>
2!'3 !5
;?2:.?
>0++10
7527=463
-' &?2
22109!
=:=$3%
.7%%(&.
"-8%..!
$;#2.
#<!3<4
(89!"$
=57'7"
>*,&%5
)+8)2=
)#3(/"3
2=.739<
.+34*%0-7$ 5
"&?003
8(58#'
-'(72+7
&6*>14
51%.-?
?4>-0
3'31'5#
--(:,!
=/? &9
),12(=
8:<'>:"=?
#%/<,:
+#718<
412# 0
,&1(##
78%%3'!)(
'3-)35>
=>;7.#
&/:1139,
"46 0<
/#5:/
,7.(0%
$?2<#!
%-0:/%
,((#)+<(
,3/;+0-*
9+7>-
#/ !<,$
> &';
)("</4
&-0(<8?
"*:6<)
0#:#/
3?%- (5
/.::5
)&%:;0,%
<,&=2''
; %":1?
/"#=(&
9)$.,3/
</"!'1)(14
&3*76'$
??2+=
&%7?:'0
3!?;69
:7)0&3-
0#?>%5
0#,>&
49$;%?
(+/:1#(
3<4?,
%%84)"
6;"#(7,
%3.8!%"
8"<+1(
=<<9$;7.
61 ./*
0:833>
;0#;?(
80<:?4
#*811=
5 84'$)
>0%&%!
!4<(!1
<>%%,2:0$
6<,56'33
3#1;2:
519:34
5<':"7
"$9<8+
*4**-1-#
!%*>#0#=
.$&>:334+#"*:
$#:>/%>
".:1,-!
?23 $(*3
7?$ $-
8#42+)0
143"%
-*4+,/
3!:3(5
.2.?%
44#(<(
= +' '
;.%.=.
8%)956)
#%4>1
1*2&&?
314?"1
*60:.,
/) )1+ 9;
8/)4!%3
,5,864:
+#<,+4
/$3 &>.>
-)5;,
=;*5969;
#&50,82
>9-(81
=("7++#:
'04$70%
$449597
72 50
:&50(28"*
583+=&),
!98,="
()*>%
$21(+
2-%!,
!+0/-$
2 :./'?:
994$.7
#0;5(=
;"!?*7
'7"#00+
5=,=8&,9/
:#; '76
07<)3=4
6 7/."
<.9>9;<(
6'5!=5
3/;)<
*61=%+
(<%<3%
%?%436"%
8653;1
8==;6!3
86<.%!=
*#:!4
.">408.;#>
$#-!.?$
35;-<&
(9:<*75
5.51)+
2>:%7(:
4/(40<72(
#)</6>
(# >/7)
9<=<5'
06='4?
4*3><
33>#?!
7(9<;9(?>&
3=711
7650% 4
#"%> /
- 8(1 6
>3/ 4'
11$ *,
;'016*
6;8"8(<
>8'":!5
&;$./8
*=75"+
7 ) >3 *
:=12(:
,3:'<.)=>
&6?7,:
95!.3%6
0:<?78>
5<;$+2
?0))=$
>36)8/
0<!",9
;%#9+*
*>31
:+=#%4/")=,
:1"49;74
<6(< '3(
/*61"$
)+?=9"1
>>9/"
-?(/-#
<+-&9>1
(:!0(7
:?5?0/
(- ="46)
#(>"48
&47.1'+
6:=&(&
!56)8<78#
/:;"=-
12#->:2
2(2'*0&
./$3><.&5'
'60;(?
6<$:,&2<
0'?,7$??
#4-60/)
6#%=7>
<?=!-#-$
/>!"%01
-54->)
635$-(
<'1?668
7588'3(
5+3+.&)
9&29)0
5&6",4
6/9-924
8& 2.!
5-+!?4/,-
5&#9+=
,%#;2,#%)
0(!810
*5$0""
+)7%0&
<+((>2=
959-
+43((-.
+!,>?'
4!3(8/.
5, 90+
4#;0 4$%),'3
6><7': "
8-/*-7%6!1*
1*-&.6;;&<
5?*%>>
82('09>
/91,2+4"
3&;*5+#
?<94*&
$8"=)5:7
2%/6$3
83>=(
);4.4
5!*294
6&,3( ?0&+
&#6 "05
8(*1.=
97<(&(9
53,+0&
8<8= .
95*#&
'#21#
0='?#$2
+8% =*:,
/6"8;'3
%')$)#
'8'8(8
&"9(<6
.09-69
:#5(6*
?.1"'5
%'')4'64
$#*"
<.-,(!/,/'0
9;)!.7
##$>-(.7
(**=6,-
+%7.(
05-*0.
,>:%1*
%': -#
4&9&
."03!/
;>-;,0<3
552>:$
76'(<=
(:;->
5:'1#:
06276!<2+
&2,<3;?$
13)8!?8:
8=<%-#
)/"".(
423:2&!
,.'7%:+.
'"''+%?$<
)#5-",
8%=/%5
6% ;9:6
<.!.94$
2, 4<47>&=-*<9#
7/>-7
)1*&2
,$04#8
)'%<?'+74%5
11&2!
0;&-"
#-5/-;
48"1 4
9*+6+':
74#7'/
94;"!-.32
9!!%3!/
$:?#6,20$
,(&!99$%
9"5 &253
37!08>-
*':",'
97#05>'
->',43
?&43#;
??((>;
:'0/71=
9"#!5%4
"%3'8()!
#= %.<-
>/ =,.
'>225?
+-/=%>
!*,6(&
1/!"*.
9!)<4
%:#&#3
(/0,9?
234 9:
5?7*007*"
->=6?.
)<>2?
720'#-%
3)2<(!3=
:$0#7
8#-5<-
&,:7("
&*'.5!::
9-,961
"27"=.
(/79)&
"4;1,
?3>)#1
?(0<"59
#+:<,''
'13"/?43
;1.0"7
)0::+
84)1.
:/).47 
122)3:
<4)$8+
-6 '*!
#04/>/
*50)"(
>-77/#*5
5849
+-!#$.
2='*.
$5+<?'
#6<3>(*
667;)%8
0-$.81
'74##-
2),;<8
,)5?;,&
2>,-14;
<7<<1
(0.#8 
#&41 *
+"5+4$#
%'=;<?*7
'+,;<
-;>$23
4<%/<5
:48+1
#?%4,&
'>"'*<#
4"#'7?
.*6="%;+3.
2/23?2
/2-.=$
<3"3,*=
/;90*
.!/54$8<
%6 )-"*
2%1'+7
.1?766
% *1+4$
7$359=
;++&.9
-(97!()60(!
,,$*//
>2=;0%
!378>(/
2(-6 32
;8:9-&!3&9+
"12: #
;$/?&<
5"3<;;/
+-60+<
141'8)
3*"%0*(
,'*/8=$
0=,2 7;*
(%4?$2
?4&*%
=9-2<-0
5,6167;-
*>,-&-
8 =>%;
>&! $
'<'"7-9
4$18"*
./80%9;
"==3##"&
73'454
'>?<.;:
)'6+,
"9:/(#+
6<7$$&54
,%;#2#
=:*?'
'/'08.?5
),,.(7
&>?'" !
%'(7'*,'
1.,)"3
96369*
$*29%=?5+;
+)2)4
%">*2>,/)
/(":+=
22>*+(
:>?663
$#-3)"
<"<6&7;#
"56##)
0'##6)
%7'#6#
3""#$"
%4)3+!
=658?+(
/',';
6(6(0.98&
#35<:
0?#<(: ?1
-8>7,/:&"-::'#23"$6!
,2'-:!/15
&1-/&".;3
5(8"9=3
/'7$&6
/348):.
%:'0?$
93;$0
%4)4%3
/=!=109
$$>".#.
"'"61
---=67
:5)3*64.
<"37>5
$$5*> 
;3$(&+5
=::-8. 9
/*>(-;
8%5$5%
>=<$31
7$,?20
/.8+,8
&'5:"%
-:53/>;!
/:7<3,
-$727&
!7&26$?.3'
3;1%4!=+5
<"+/#'.
>9++9<67,
;9-+<$
(? ; #0
:9!9*.
9?"26,
,57)43=++<39<?
:2-!*5)
/$?%3?
',+&:"1>
?5 %?1
!5-<"
:(//' &
(:=$)'1.!
(1=!6<
2..601$*1
7*)6%9=+:+
<,/69'
,.( =*
,=,>'3
1=(3(,3-.
",213#! ?$
161)9+ (4#2
*,!10!
/+="+'
$=$(7,
6#$=%$
+8*?612
#8-';;=-
%&.:/316*
?'31<!
0?88,?
/,6>*
<#)9(6(
1+&.;
$8:(4)5
6!04$,#2>
=8>*:/0=
5&1?-$
:*9:0?099,
79>9!1
.$5789
%> ">(
#1"5!)#
'>4<'#+
;?9 .
!)& )/
-*)78'-?
">&.+
<""93
:5:99/-
2-<&6)
&2?*3!
, 2<83
(0'//)&
:6?/
/'5(&
-.82-9
'";#$$$
$*?$1$
%/4/"/
<*4/4
<)8:'-
'-*>"4
0!$0!%
$47/<% 5
("$9<5;
,((%39
+)<;1&-
$"8%.<6
#)6)$
%=#&;>$
!5)%2,*05
>)&>!-/&
?9-/<;
/$##$.:
=6?*;?
' 428:'5<+
3;-;6(
!*-+7+'
3-0;#!
6$+$&1
(1##:&5.
/0';6-&
:%.'=-
1">':,++
'(!6;"
<?#337
8%)3+-
(?) 418
+0,'9?/
'2:5% =
'0>2#.
!","./
5";7;/$
? ;0#
 , '
=")*3
6*==0+
. >$*//
?7?07376:%
/>37;
3'7,2:7
<'%',#
,"+-(?
>! /-
$:%"1$1
#!1 =1
--,:)4/+
253=?0
%+3 =2&4+3>
49:#"8-7
-((4>4--)
7>2);5
(8.702#%
-1> =
!)(-9/
&#*;=
0$1-/
7<6 )&
'-275
=43*).
.5/37+
961..:)
;8(&=$
>804
$2;">'
>$;$6:(
./=,);&)2-
"359,-
0(*&??28
;*825!
&>>!>$
?:7%,
"""'>&'
3#)+,'?%+
!4&#+
(!4#-+*
,;5,1;
8.037
!:,6"<
9; &3-
12-;:)52#508*/">!
/&'%7)
:)$0?;
&7'=32
$*("7+
*3<6&?
$/#20*%4
46,=74%*0;
2;.=&,
.1 &">
785&%%&
&%1!;&
/6%%55
* 0,"?
)27/2#5
4)35)6
;#((?/1%
:%)),$
*-/3-;4.
=2(*?>%"
"2#!-2'=
#!):?44<
($7(
;0 *>.1
&# *(.
37#)6224'
*$/<$(3"%8
;=3($)&
1<:;;&
%13'&49
?8+=-568
:',4,?2-#=7
5<8&7$=
><80"
*2;:9=!--"
-5:,=,
"'!719
/1'11>
4,)*4$
'<*?#1&
!6-29.%0
!+,.5/
94"<=3
/(&";4
0=$+<
2 163%
&/3>37=
(831+:
916<5);4$(6+
8#?2)$
>&52#$:/
,)7>8)
*62/0?
+/)3?3
3??81%
,?<8'"7
9%7*)&>
*+ $$-
=<--;8
/#.=6>)
$/'=>8
:*9,!/<
?(8;6-
#-/2"
-87,"4
*,9#4?032
%8>0;.
5'6+",
6 #0((+4
".7!*9%-%
?"==7(=&+$#5(
46;4:!?
24)%+1
<62,4><8
<(8?45
)>#7:0<*
< 63-&
5+*#$8' #
#.:/9=/
%>/?21
4'19;'3
',&69
074>9
6::%-+1
)4+" ;
63(,";)
><,&'
95+/0,7
21#(8-
9!1+1#1
5:>.)/5>
>5(2?#??
;?" '?"#
>=2=>91-
.)6,-#8/
=)"8-0
;3(;/.3
+7./5?63!
2536:-
4-:%90
-2$%&4
$>'44>#4
=%+%(050
3$-)54
3'71
*0"/5'
/$=*.#
.?AVlength_error@std@@
.?AVbad_alloc@std@@
Xaze payuwenesihuho. Sicefu lecu zidato bojoseya. Tutala. Su. Yidofe. Dapobuwona. Yaruta. Peraru pixo yowa. Hulepokikuwu cetumagikeza ca. Cudicuzodane cololarumali vuzawujuki gisunudo xefe. Sepexujeri vugelavomejuca lowoxuwu yele penadara. Juhojoji nupucayFupacelunuyifu nogacebora coye. Nusaluwaho. Zepumojuhogoru nufigunatoduho. Keje kayila. Kadolipowelile baxupe wurixazonanota lefebu hafucaye. Pecaxubofose rogatidife vice zakowuke. Wofejave hebajigiviha zifu yacizo. Gizanugipaya cucipiwe tewavasalo gejuxosidijoha. Ruxayogorayoci. Cene ho. Zogolehejosa zobilonozi wovazefabo. Favi sefunotu dovoza wesojimetasu. Jinefegeci panoluyifo zoberifezidawa zugeniyokuluye. Sepuhezimo safo didusepeja cuda gemuvafa. Lomise yi. Cuwati takoneyepijosu dotakupove temulavi. Fiposoxohiluju sucufususabo henihideya. Dizeruleviya hudejitafe. Pijiwagekuwi zu medelo cifucavo xilituvabuju. Pexo yixuhapikosihe mukuxabi kugikija. Beso gutu yozu konipihowuso cegu. Tosixuxacojofo. Dagoluhi tokihHaciceye yevaxudi zerafasumate. Vakuvoko gum
5B7hB7hB7hB7hB7hq
5B7hB7hB7hB7hB7hq
1B7hB7hq
}W6}W65)
8}W6}W6}W65)
5B7hB7hB7hB7hB7hq
5B7hB7hB7hB7hB7hq
1B7hB7hq
}W6}W65)
8}W6}W6}W65)
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
n,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
n,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI\
n,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI
n,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI,fI,fI
n,fI,fI
,fI,fI,fI,fI,fI,fI,fI,fI,fI
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI\
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI\
,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI\
#&,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI,fI
#&,fI,fI,fI,fI,fI,fI,fI
#&,fI,fI
#&,fI,fI,fI,fI,fI,fI,fI
#&,fI,fI,fI,fI,fI,fI)
#&,fI,fI,fI,fI
j,fI,fI,fI,}
#&,fI,fI
j,fI,fI,fI,fI,fI,}
j,fI,fI,fI,fI,fI,fI,fI,}
j,fI,fI,fI,fI,fI,fI,fI,fI,}
j,fI,fI,fI,fI,fI,fI
j,fI,fI,fI
3fF3fF3fF3fF3fF3fF3fF3fF3fF*
3fF3fF3fF3fF3fF3fF3fF3fF*
3fF3fF3fF3fF,}
3fF3fF3fF3fF3fF3fF3fF*
3fF3fF3fF3fF3fF3fF,}
3fF3fF3fF3fF3fF3fF*
3fF3fF3fF3fF3fF3fF*
3fF3fF3fF3fF3fF3fF,}
3fF3fF3fF3fF3fF*
3fF3fF3fF3fF3fF3fF
',3fF3fF3fF3fF3fF3fF
3fF3fF
3fF3fF3fF3fF3fF3fF
',3fF3fF3fF3fF3fF3fF
3fF3fF3fF3fF3fF3fF
',3fF3fF3fF3fF3fF3fF
3fF3fF3fF3fF3fF3fF
3fF3fF3fF3fF3fF3fF
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0"080F1n1
2%364|7
;!;V;m;{;
1$1*10161<1B1H1N1T1Z1`1f1l1r1x1~1
2+383K3k3u3
636@6\6y6
6&7M7m7
;9;?;G;T;h;};
<.<6<A<
4?4X4_4g4l4p4t4
5N5T5X5\5`5
6!6K6}6
6N7`728<8I8d8k8
9%9H9[9
;!;K;Q;n;t;
==+=8=\=n=|=
>0>_>$?:?
0+1[1m1
4*5_5x5
6 6$6n6t6x6|6
7 7A7k7
=1=Z=_=v=
0"0-020B0L0S0^0g0}0
1(1R1W1b1g1
162C2`2
273<3d3
5#5<5B5
6'6j6y6
7 717<7O7
;7;O;U;`;l;
<6<G<M<X<b<h<t<
=&=-=:=]=r=
>*>B>h>
050:0B0H0O0U0\0b0j0q0v0~0
11-131@1`1f1
22'21272=2D2R2u2
8B8t8*9
5 5K5V5
66+64696?6I6R6]6i6n6~6
8%93999\9c9|9
;D;L;e;k;p;
>">'>6>?>L>W>i>|>
?"?)?.?7?D?J?d?u?{?
4"4+4E4K4W4r4
6?7M7{7
;';3;j;s;
<<8<Y<e<
0q1{1/2>2
6I6U6a7(8-8?8]8q8w8
:2:V:f:u:
:;8;c<y<
?;???C?G?K?O?S?W?[?`?k?x?
0&090G0
032D2z2
3%3*31373=3B3H3N3W3]3g3l3r3|3
8G9t9i:
?,?G?S?~?
192`2e2l2s2z2
373Y3_3k3r3
3%4@4r4{4
5)5I5S5
758C8J8
9'9/999T9h9y9
=%=R=x=
=(>;>B>d>i>
?3?A?p?
2"2X2e2
3.4J4Z4g4
4!5P5W5`5j5q5}5
56*666<6B6k6u6
77(7-7E7U7z7
8B9c9x9
9.:3:I:n:
9%9m9}9
:5:D:|:
4$494F4L4V4d4
6$6*606W6
747j7q7v7
818E8f8p8z8
809M9T9[9b9
9P:b:v:
<G<T<d<t<
>5>;>Q>W>
0!0.0=0g0
1e2n2t2
3M3S3}3
6!6/686G6L6V6d6
6F8M8S8
>U>b>l>z>
252N2j2s2y2
:-;F;W;
;x<y=*>
4&505<5E5
8+848V8
:";(;4;{;
=o=#>C>3?\?
5.6;6T6r6
8,8G8g8
5%5-5:5A5
3313j3~4
4P5b5t5
"7i7q7B9X9
4)5<5k5z5F;
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;
X1\1`1d1h1l1p1t1x1|1
243>3V3
=$=Y=l=
2.2g2t2S3b3
4)5/555;5v5
6-6G6f6~6
7/797i7
:.:4:::F:L:t:|:
;&;.;7;@;L;X;e;l;w;
<<p<}<
3+434D4U4
5j6B7N9
9/:X;g;e<
191j1z1=2C2O2^2
3 6&6,62686>6D6J6P6V6\6b6h6n6t6z6
7"7(7.747:7@7F7L7R7X7^7d7j7p7v7|7
8#8/858
:):_:d:l:
;(;1;:;@;H;N;T;Z;d;n;w;
=,=:=@=F=L=
>$>*>/>5><>A>F>M>T>[>b>i>p>w>~>
?-?P?k?
!0,00050
2(2,2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
7l:p:x:|:
;,;<;@;P;T;d;h;l;t;
<(<8<<<L<P<X<p<
= =0=4=8=@=X=h=l=|=
=4>@>`>h>p>|>
?(?H?h?
000P0p0
1$1@1H1L1d1h1
2(202`2h2l2
3 3<3@3`3
4$4(4H4h4
5(5H5h5t5
606P6p6
787X7x7
888@8T8\8p8x8
9$989L9X9`9x9
:0:8:D:
0(0H0L0h0
5$5,545<5D5L5T5\5d5l5t5|5
5@8D8H8L8P8T8X8\8`8d8
> >0>T>`>d>h>l>p>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?h?p?t?x?|?
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
jojoxarukulurazapunekuce dolapedubojirehebetajedara
Su cugetutu nivileraluwafu
NUTAVECEHENUBEPUHUGUWUJEJIXA
SOJEVILOHAMOCUGOROZOTAHUJAMIJU
WADUTO
Dialog
MS Shell Dlg
SGiki vejoxegafuvemi daxazikeli zedoxirivi xavizozesafaca nemafi cavereni xadatebico
Futi wefogucubo hexu viyicaIYanemo yicehijetude xicawo mutegafefo piwoze mogigaxujazaji yanivoxa zowi
Wayepa xoliwuro6Piyenazizofoco nale seyimucayedu poxiyoni cemi be haha
Sepawudehuku sidadagaHRaterisovuhi hiculicoyami yobewijayeroso ro rerojufebusuyi yofakita wevi Leretixaha weraluzujice howodizo,Duremefule biti nekatixeba lewufevujoka gomi
VS_VERSION_INFO
StringFileInfo
457aa56b
FileVersion
5.3.7.82
InternalName
gigifaw.exe
LegalCopyright
Copyright (C) 2018, guvaxiz
VarFileInfo
Translation
Antivirus Signature
Bkav W32.WioesjeNWF.Trojan
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.AgentWDCR.SVC
FireEye Generic.mg.996ba35165bb6247
CAT-QuickHeal Ransom.Stop.S7866402
ALYac Trojan.Ransom.Stop
Cylance Unsafe
Zillya Trojan.Hosts2.Win32.3219
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00545a541 )
BitDefender Trojan.AgentWDCR.SVC
K7GW Trojan ( 00545a541 )
Cybereason malicious.165bb6
BitDefenderTheta Gen:NN.ZexaF.34688.ru0@aqo3V9lG
Cyren W32/Kryptik.PT.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 Win32/Qhost.PPC
Baidu Clean
APEX Malicious
Avast Win32:BotX-gen [Trj]
ClamAV Win.Packed.Agentwdcr-9819888-0
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:Win32/Qhost.9112e630
NANO-Antivirus Trojan.Win32.Encoder.fmcefj
ViRobot Trojan.Win32.S.Agent.281088.FA
Rising Trojan.Kryptik!1.B582 (KTSE)
Ad-Aware Trojan.AgentWDCR.SVC
TACHYON Trojan/W32.DNSChanger.281088
Emsisoft Trojan.Agent (A)
Comodo TrojWare.Win32.Ransom.GandCrypt.AA@82gsko
F-Secure Clean
DrWeb Trojan.Encoder.26667
VIPRE Trojan.Win32.Generic!BT
TrendMicro Trojan.Win32.STOP.AC
McAfee-GW-Edition BehavesLike.Win32.Trojan.dh
CMC Clean
Sophos Mal/Generic-R + Mal/GandCrab-G
Ikarus Trojan-Ransom.Downloader.Stop
GData Win32.Packed.Kryptik.BHC4MD
Jiangmin Trojan.Generic.dayql
MaxSecure Ransomeware.GandCrypt.JZ
Avira TR/Crypt.Agent.tbytt
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.vb
Arcabit Clean
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
ZoneAlarm Clean
Microsoft Trojan:Win32/Fareit.V!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/Gandcrab10.Exp
Acronis Clean
McAfee Generic.bto
MAX malware (ai score=100)
VBA32 Trojan.Encoder
Malwarebytes Trojan.MalPack.GS
Panda Trj/WLT.E
Zoner Trojan.Win32.80301
TrendMicro-HouseCall Trojan.Win32.STOP.AC
Tencent Malware.Win32.Gencirc.10b9bc2a
Yandex Trojan.GenAsa!4PBpAla5ciE
SentinelOne Clean
eGambit Unsafe.AI_Score_99%
Fortinet W32/Generic.PPC!tr
Webroot W32.Adware.Installcore
AVG Win32:BotX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.