Static | ZeroBOX

PE Compile Time

2021-06-19 01:45:10

PE Imphash

a044253673528dd98a9dd008f2a6b058

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000bfe7 0x0000c000 6.62372387341
.rdata 0x0000d000 0x00005a02 0x00005c00 4.8085811075
.data 0x00013000 0x0000163c 0x00000800 2.3842249168
.gfids 0x00015000 0x000000dc 0x00000200 1.61728008178
.rsrc 0x00016000 0x00001000 0x00000600 3.81689048248
.reloc 0x00017000 0x00000ed8 0x00001000 6.3501203186

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000160a0 0x000002dc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0001637c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x40d000 LoadLibraryA
0x40d004 GetProcAddress
0x40d008 DecodePointer
0x40d00c WriteConsoleW
0x40d010 SetFilePointerEx
0x40d014 GetConsoleMode
0x40d018 GetConsoleCP
0x40d024 GetCurrentProcess
0x40d028 TerminateProcess
0x40d034 GetCurrentProcessId
0x40d038 GetCurrentThreadId
0x40d040 InitializeSListHead
0x40d044 IsDebuggerPresent
0x40d048 GetStartupInfoW
0x40d04c GetModuleHandleW
0x40d050 RaiseException
0x40d054 RtlUnwind
0x40d058 GetLastError
0x40d05c SetLastError
0x40d070 TlsAlloc
0x40d074 TlsGetValue
0x40d078 TlsSetValue
0x40d07c TlsFree
0x40d080 FreeLibrary
0x40d084 LoadLibraryExW
0x40d088 GetStdHandle
0x40d08c WriteFile
0x40d090 GetModuleFileNameA
0x40d094 MultiByteToWideChar
0x40d098 WideCharToMultiByte
0x40d09c ExitProcess
0x40d0a0 GetModuleHandleExW
0x40d0a4 GetCommandLineA
0x40d0a8 GetCommandLineW
0x40d0ac GetACP
0x40d0b0 HeapFree
0x40d0b4 HeapAlloc
0x40d0b8 CloseHandle
0x40d0bc FindClose
0x40d0c0 FindFirstFileExA
0x40d0c4 FindNextFileA
0x40d0c8 IsValidCodePage
0x40d0cc GetOEMCP
0x40d0d0 GetCPInfo
0x40d0e0 CompareStringW
0x40d0e4 LCMapStringW
0x40d0e8 SetStdHandle
0x40d0ec GetFileType
0x40d0f0 GetStringTypeW
0x40d0f4 GetProcessHeap
0x40d0f8 HeapSize
0x40d0fc HeapReAlloc
0x40d100 FlushFileBuffers
0x40d104 CreateFileW
Library USER32.dll:
0x40d10c wsprintfW
Library ole32.dll:
0x40d114 CoInitialize
0x40d118 CoUninitialize
0x40d11c CoCreateInstance

!This program cannot be run in DOS mode.
`.rdata
@.data
.gfids
@.rsrc
@.reloc
t.h0FA
URPQQh@/@
;t$,v-
UQPXY]Y[
QSSSSj
35h=A
WWWPWS
u-PWWS
PQhH1A
PQhP2A
SSVWh
f9:t!V
|VWj=S
QQSWj0j@
tl=H6A
j,h "A
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
Unknown exception
bad allocation
bad array new length
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
CompareStringEx
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
LoadLibraryA
GetProcAddress
KERNEL32.dll
wsprintfW
USER32.dll
CoInitialize
CoUninitialize
CoCreateInstance
ole32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RaiseException
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
GetACP
HeapFree
HeapAlloc
CloseHandle
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
CompareStringW
LCMapStringW
SetStdHandle
GetFileType
GetStringTypeW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
WriteConsoleW
DecodePointer
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
010J0S0Y0
2]3j3o3v3
:;&;:;A;
<=&=+=w=
?&?+?0?Q?V?c?
d0m0x0
1 1&101:1J1Z1j1s1
31383>3P3Z3
4G4b4n4}4
595B5H5y5$6C6M6^6l6r6
8)8Z8w8
8S9\9d9
:!:0:R:
:G;O;a;
0+050C0^0o0{0
091I1`1h1
2:2C2H2M2q2}2
3@3R3^3h3z3
7C7M7S7Y7
:.:5:h:m:
<*<W<r<
=9=S=}=
>.>5>A>T>Y>e>j>{>
?O?a?i?s?|?
6;6@6M6Y6r6
7&7/747A7F7
;S;O<c<
>4>@>Q>Z>
0&0Y0k0
4/5V5_6
7(7F7P7a7f7{7
;(;-;8;L;W;n;
0G0R0_0p0~0
2)303;3I3P3V3q3x3
4@4Y4h4t4
5*555:5?5Z5d5
6,676<6A6_6i6
6/7S7o7z7
8=8K8Z8~8
:':.:E:[:
;3<E<{<
=Y=k=}=
>>1>R>d>v>
5#525V5
7!7.7E7
20<0_0i0
1(1?1b1}1
<,=]=c=
151<1R1h1u1z1
5!6T6i6z6
1 121z1
2,252>2
2_3H4W4v4
5 6J6R6o6
8H8e8y8
;k;l<|<
='=2=8=A=
0(1e1o1
3"5\6w6
>;>O>U>
;;<@<D<H<L<
$1,181<1@1D1H1T1X1\1
2024282<2H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
;P=T=X=\=
<$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
l9t9|9
:$:,:4:<:D:L:$;(;0;P;T;d;h;p;
<$<4<8<H<L<T<l<|?
000P0X0\0x0
181X1x1
282X2x2
3 3@3\3`3
60646H6L6P6T6X6\6`6d6h6l6x6|6
!This program cannot be run in DOS mode.
RichRX
`.rdata
@.data
.reloc
B.rsrc
D$4CreaP
D$<teFi
D$@leW
D$DClos
D$HeHan
D$Ldle
D$,GetF
D$0ileS
D$4ize
D$ Read
D$$File
D$TileP
D$PSetF
D$Xoint
Heaph0p
D$ odul
D$$eFil
D$(eNam
D$0RPV
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
VWuBhhd
t.;t$$t(
VC20XC00U
"WWShtd
PPPPPPPP
PPPPPPPP
tFGQPS
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcAddress
ReadFile
LoadLibraryA
KERNEL32.dll
GetCommandLineA
GetVersion
ExitProcess
TerminateProcess
GetCurrentProcess
GetCurrentThreadId
TlsSetValue
TlsAlloc
TlsFree
SetLastError
TlsGetValue
GetLastError
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
GetModuleHandleA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
HeapFree
WriteFile
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapAlloc
GetCPInfo
GetACP
GetOEMCP
VirtualAlloc
HeapReAlloc
RtlUnwind
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedDecrement
InterlockedIncrement
axhub.dll
kernel32
22373R3
4(4.444>4V4[4e4
4L5g5v5
6!6+6D6L6Q6]6b6
7#707@7F7N7l7r7
7878=8g8m8
8#9-9N9c9
:$:I:X:g:
;$;1;6;<;
='=\=d=~=
=)><>z>
0)0L0R0^0n0u0|0
1'1M1Z1h1s1
202<2X2m2
30383e3
9*999Z9`9
:*:4:?:I:S:Y:
:C;I;g;x;
<(<6<E<V<
=5=<=@=D=H=L=P=T=X=
>%>@>G>L>P>T>q>
>:?@?D?H?L?
3 6.646N6S6b6h6x6
7"7(7l7
:%:+:A:H:N:X:^:c:i:y:
<:<D<L<R<Z<c<l<
=%=+=5=;=U=[=c=r=
2#2*22282?2D2U2q2
6 6(666T6q6
8"8>8Q8X8j8r8
849F9n9
:$:8:y:
:X;p;w;
<b<h<l<p<t<
0&1;2s2
0<0t0|0
1$141D1P3T3X3\3
4 8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8v,)cml
)U]bc[
';VHw~{
Q&t0ik
8$ COW
IGkn){
3=ekjO
FEGq|%3
n[Ba6cf
jtRQi}JW
+iffCPvf
rU3|XX
YU72*/
f,0 kN
\1M,T5M
#PA;"/
*x:128
z?%)c>Fm
:.fs;,
}s)&-oi
ln{{^.
dc([8B
nd)c>
"/9;12
%yv%.*
Eo)$ww
fkq7j<:
}G1k}X
oku^si
b59)5L
b (!.
M3ke)l
)-h8[cfF
bFXOZ^
U+$ I@
TQ7jebNd
k1}("i
z2wm[%
_g)c/6
u%,lU8
/gj+"'
izDg/n
5H`(c*7
eMIY"f
/72bjmW
D.?G*u
}.cs8'
Aqa.5{`l:
if,'R9
i~>v2N{m
e-o'l*
fCKjb'.
SH!k3o
LMh~:h*
Adkic)
7Y[B2,d
!2|-cn\
P0@9{/
gA<b%
QQ"Ji9
a'o&k%
m4+``X
Xd*d+dV
a#dEJ)d
od'jPx
AW']e!
n*- &!/
a&V^)/
+(6g6Y
"\]FH
f$a7v
4p7;fTl
h '>5
Ko+VS*
D4/Yrx
N}a1O]&
Fa_xNc$
typjX5
;h$h|a
BZ}q!Y
5Ee!v2^X
pVbLo$
[oNi-G
64BVbIj
`/F.^r
(h8>==
5Z%E:ZP
Z;8YM}
g<*x&tY
Z;1PZt9
yGy@~w
bN<cUc
;vXCqo+
mE@"t$>
juoC/L6
hlgchhh'
TAHES>
'//-,K
Dg9<Bl
;1.%j"
k'aj02
z</}q,
L"G(&-G
<|"/ci
&%5W*j
Y<)CS
Mkb\oY
';{s7J
;n *eo
>J?9ea`
TAIt|)
h<<a`9:
)2s'?$
]RmBE6
A</}qE
vT%y;7
BQe#x0k
"$c#c
K$/cg
=&5,?>%
l=8 '
8cMZk{J
ldlf4s
^</i:
EH-$ELg
wc}szc;
z<Fz,d
<E7+.<9+
^2/ge-m%j
$\E$s1
5EJ!_k
<jXDN(
=&z?WB6n
R|rF j
A_>'fK
R;I)e;
v^sONi
4<\]*
c9#>#~>
Ka-{3i
.!d/Me
.mQ6Re
l&j+jN
j;zQE?zS&]H
i1X2I$
#j*) <4
8z*87.
'/5=b/
!+l/iAD
kr"?14
?K#F1?-g
sin+-P
w!wmjy
(.h`i#o
]g,ma-
./MkBI
o9?elm
a72&l?
OHn,(ao:
%[Tm'!
i(.HxQ
hU1~@
u'k#'m
zFr&>N
jOviny
`noq='
.4#:<>
d*;0+.>
YV`.`k"l
f-px+a
!z|`,.
832`q~$
~7gYM4
YI\] 4
_YTAYLT
1({a+Y}dsv
e] ^O
XjXjX"
Ve fANi
"c/~SOAT
@:ouz
,Q][gj
n9}i%$
:j\]-*
*ed,/g$
.CdesRe
)54--
WYT))6W
YgHGI:
Ru*f
z8j>s"
JNQFy&
e-qi3i
kA.;7X
ObCO}xq
[)ly~AJ
',-kb,
UY}BMr}Q
p)e$b&*e
>kuCJI
^Z%8GZ
yI$iZ4
TXn .e
2j8rAEB
k7e`."
aO].pB
XiZq?D
@FAz'
8o$?k)g
CVTzw:
HKAgm
VkWySD.
e,v>g3
Xa-5}h.
_lbx~&
le@N[T
& ^F)A
MOk(j,
d#tvQ8
h=ZM2c'O
Xe-q9j
q7Y-f
3`ekj
v8qq$'
wxHIi
YTmc|"
=z!2{nHV
)g.bkd
P9KFp.
')bDZ5
.+e`lBM
y3$lo.
NN[]GKc
#s*xg1
7HM05H<
lbNDz7
~$)a+i
}B+(^PL
{=T DO
3.p~ /e}
JbX|"4
FFhIgF
)cCVD
DBLhT<
=/IF*kl
hj`XB
y%}_I4
o!oBMj
V@nz.&Sl
Wg!~~#,
hM-H/s
z4W)[p
an,`5Y
-n_6I%
a'Vh.
m-+#//
LiCfiE
7vMCCr
s4.{fh
vsi(n&
v 'lq/
!c*h'l
./Y4Fc-
l`b-Nz|
o]3_7" "
(i-Q\f
p-i\G#
WC9#YF|
jjPoCg
i/CHajX
Sv*c.g
?{$(d f
Yu2m.'.
9+}Y]0<7
mTE_@.
GnTG}[
JCln+y/
^o,)n.
$.PR&f
P=};H
/+$-{I]
/5"~+v
}JDPHD
g!l ;uj
cEM"m*
wv0/(b~:c
!i&fm,q98
#4_S95{
fI@lt1
s>gj,m
nKlHwS
[`e+.T
[Z,PZk7
u'*t~(
Wcme{P>
a't=o!
%#NIhD
jO$8S%
*wYTrL
/1w83F
,*FR?Bd
Uide(Q\@
Cojb\V
a/Z[<G]g
PsIH$<
xTWc2~
,"OCb-X
:0Fg!cPb'
C+=PFG
/ha'd-B
3}/an"
YO8.7.
L& 9? (4
P22;/ng
,'&/f*
(h")GO
iYOQs_
b&9Mv-
Y](q;(-{z,
ELv9e{
C{|kFl
?N94C>
Z/9eml
|{{k|j
Tz.lOQ5$b
]{=?:A&
su-)O#)'hF
j jCD`
Yg#h(*
KR<2b][
'$cYj'
uAi)k*
YQwEQG
TVEcmdk
h%'r#mB
-zRhNl
maKE8z
.t;nell
C_:| 6i
FQzJn&
EEi`QeUi
;)Q_7x
MU]EMh
k")D_"8E>2
29st-*
+u#nkz
5-kbzV
jVRBUk
e-m%nz]
f\X"$,.
k-S\`V]
Z(jg*.;
`KGnTMD
vm*c+.=U3
7HT+&S
5fKNY
--!)48
!Y"1,f
zbXks#?3>
hYiL:P
~bowE/
MZmJ}ZY
wLIhNL
3hMYyZ
-Lv85
2xa=k2S`
ncl'*V1
;?ESL=
'MPMWz
%9Ub#G
Gx0>7a
/)7p!'
6("}8&
oF=%,;[
$,X{"R
uhh(][
jl.B7^d
eepGW/)
6L1,4;
{Bh6y5
m>X1&?B
*u,szF
jF~Wom:
3~']riF
P@-oRW
jVoPyMgS
jGcLNk<$
VG~OF`_eU
zkvfKG
ffOkF~/
k=1gex
`@<M0u
:Z:7W^
[fZW<5
y3[SrA
*i|3&i
k"g" e
P1`US<[$
SK%l+g
nlzgKJ`
YH'-kJf
(J;rg[
NQ(5gZS
h$j*bk
o;0a+e
oo>v#p7
iW(Edqg)
$h*d*b
,'"+ ,l/e
>WnY;1>m
ZfZ_63Z
bVD2-a
$XFiqM
i-_?V>
.`liXn
SZPf$&
9UW+TXe(
$)xufS\
33Pu \
xi~oHS)}0
(%i@}TQW
+^"HuO|
o(aLFs
R<&H".
e9-q:N
)X4iDO
Q-OZM!
PQ*j++
] }a4h
ljok.2
4&#72)
!"OD!`)
{6UWXT
D!<or1
*]3GZ
H{DH4}My
zAJD`Z:
g"Wr`L
Q6bE'TM
`&h*bj
J8}d8:.,#V
0dd#l@
Y]C|Q2>
p+uRgX"
~ulG_
gV\V[Iw
w?!ZT4
[.&S["
R*i)IJ
f=C-Sq
*j/ha'
]lyFSOx
;sdqdW
i)nJrn
^2V{OV!Dy
7Swn2!
E(Ck+j
KA_p9F3
mXe=?T
zWMkec
y=0#*E
XSq]2'
p*<drQ;
/&'++na\H
d*$2>W7
tF\tXL
nW!g*c
k (aiMRvk
Sg+NX}
;/C"M,D
a"t3B"
AF5d \
n,;9ff
.h"d"d4;
\6HOqv
GR.#d
bmex4)
{d /3?
"+n,)'
8WLa.bIMi
'+fkk"
q|svhi
yS&h3u
>qam$K
&edvr&
$(bm/
|_]e<
,*#.&=za'R
P:2t'o/
!h!/!r
&!mau<
)PaM0Tg
/z;YEw"d
*d;072=
e&,"- f
fg#]FxE
%im81FK
K-d*& o
F9't9%
&(lfo"
iccfPV
#hb71o
_yG)d*
.kP^d
z71i,9{S
vdd[SfF:
Qk*KD,
Y]\M?c
.JEm*`%'
aVv$2r
+&*m,"B
$/'%<9
iU hE(
ge28oa6\
TIu[F1cP
Y<6qc
^>/czr
'RFGMn
pOPZt9
1l+a&l
.(mwHt
}JW)NJh*}
%`|6wW
jj=}m,
/KnDvj
9TA3>r~
WRl-3e;HQ=
*d869JcM
)zk%%>
;yrFFL
j/om,:
U;/ k
#*Gj"/
)yxuh3
/JvQK5
i"/ge-
d,"#&$
rrr3!,
.'\QO!
qd#l+/
$f{o-
}qR/RN
O^9-JIg
i"/RXg
&ghHGh
m% &`e=?
5L.'%=
)oft{i
`)_i%*
P(dHTz
4bdF"#
F(V%;5
fWw*;R%
jm-bg{>
J'_sw:
+XR$-\
5nsTI
K6q,~m
*oLLli
;3q/to
2.S]mb
/#*e,S
^_x=:
2FY-"'
_xgj5.?
j{k_RY
'Ggt8+
?[OWV$
:ww==Io
/om-W
7=e|R
nKOk9U
?>,M{04K&
"Bmi=(V
l$=JM$
'3&`%:
3^*WZg
Z4u"j
%=8("*
\6o&"e
.TW-"XU
~aw94#j,j
(I%ph[
//i)(p
aL#~.|
&`.g
:<-#y\
/h!"@|FD
p|#kUO
k*djmJ
5;nj,:
A5Z.A5
]*e96/
ge,B*Nk
E6L%(P
~Vd7l@(
&h$a((
#)`&SYu
R*bl.@
^Md/XS
U<;/Gd
2eq9)a'e
DV<`.I
,RCP,c
F>x'6n
;p,"T_
j>2<dQ
rK'|5l(
#^35XN
m1;p9"f
rOA&(d
<Ca>y#$
nLH#'O#
MjfJDQ
)ja%.h
"(g{<j
/!fpu:
9h,j&f
#!dfCG
Mc>7k5
;h!g"b
k/,P7_
lU6f?P
h"4=$<x
*m97S]Q
EVt]^
kd@dn[*
l$-3d:A
X!RU(N
j&aa'S
f#63_e
Qth,>:
BWSUy/
FTs X_
#&v3*f
0x.'',^
:f;:`'M
@b{-cyZ
8?`)v?+kl
=h*,ga"-
28'az<A
3Qo&^:%f,
i_|4/
dFrl^a;
+c #{7
\{TLg.h.,
0;aa<>
LC-d2t
hWXg~[
/o=<k%`h*a
jh+m.h34
,o}bsi
+$!kKr
e1rq7Z
jn&&n;
b&EmF#
+f_?Lejf
*$:x&(
A]0d>6
+$#,78 mK;v
!+'KWz&
IO!487
PrCO[^
LZG~co
D5oQcL
4G.h1x
6KWyt3
h9nj07
Z'(ghC
6:ocFB
S4fb'"
Cdan3<
6(jnv8
Ae0r{!
a'npYG_
h(]lpA
7jkj+}
[S/s,-
uO-Cj$
oXT!l$
WZh]mQ
,Z}wPi
_h,na
'a$ 1|
^v(&p}+l
_bhHgkk
B/i")$a
9eXjW'4
7#m+u(
!r*)')
/3e:|".@I'
YV9I.65
N!j~} fe
sm$b".KE
'`#t;&
"$/ck|
e*dz<"
^(&-',)#
>Quo9B
-+#fUQ
Fy1=,#)E
%S{}R|
-`DnCG
Ap_'r5
*$,g/h
E1"l@2
N&;b:
3Hjk?z
%"g,(o
,e#, d
ASWe"(
e)#&,'(
dK."nlk
MN@@Gc
90*;y
0n-,u6
;l+l+b
dKSq<
5Jr~fb
qpE4jX
<vh"d.
\Fwz1&
./( e|1-K
kl&aIm
x?wsL1
eK]seO
7%pVJ{d
YcOh,*l
Qm-?VN
l0xf=!&
q{=&(*
.h'a+e
l]]ii;=
)M"$*l*
#e0v.n
AXU. t9
>#:u$g
zgAXV7
"$)e f
zZC$4Y
Li+,el+
_d-!)-
=(T 6p'
YLTkd)&eh
.&O//I
hY0d-@J%
.c)igN
}jr_&k
XeYDBUSDZ
>qAOi$!
<rm*KU
A.e+$,
_M]:}`
e'q6f{o
%@}@f`
"$)e f
i)de&m"+a$
FC'`U7L5z84m
2'<^oP
"fL`I~
`n&.jg
f`')!o
d<8#l&
i/%&,16
b"*fnCo
0m '/.
o|ymh)d#n
V;r;`!
}E!5},
"*.&CoJ
g/ge,(`k
zm(lFZu
jDA/JD
&of.'L
/a#5Zfh
,;gIXN
\&2>O/v?
H'!\rE
X`'w5j
F(da'j
one",
FNCOn*
Nd,9um7a=k
(&vp-*
kj"c7n:
-n&YFP
rfBL)b!
d. AD:
]bZ$~8e
rn*dp4
</\`Yw:
'te+y4
!F|90<
mgTiO"
/&ZWc!
o,u}r}+eh
w3_$r3
EP]KkN+
('"ts%
R<d"ai
')j&OK>p
GHLiu6c&
,i()wl;RFP
CRrg'oJ
+' .`r
jQD2<C
}`U=&dM
e-^6o2
IBGN[T/
"l*l*n
YTAB,d*
B(h*/.
mD`U{
ZTi,tH
"a/i&b
PEdpu8
%#nb)(n
b \\ok
_] X2
/kQo0tP
e3>#-e
D/kbS:
Oh"DB.
l/f%.EKk4
m;!t(jhn
sJb/3(
zg)/q:
G&bO/ne
A%.CLit[
/iTJ2Muf
' jfY_`
%aY_fI
#e/,/.
m*-+t[
zN`.J5Y
4xKE[D
La+\i
V<`!GV
r@Nyww
+dm2Z'
e:8g"b
i'(#fKE,j
*x<)!|SZ
d v2.SY
FW0^B0m
g-esuI
H#l)l*f
T $3>@
-l.`xL
i&(",79
m?rCBg
iO@)<5*
]rN#7S/
b.C{tE
\E]Ge,6_y
%d`)'*
k` NwH}h.$
MLb.'*
p2"8or'
bf+/e n#
bdNAjE
CENlg
6-!d" O
\"wD`k
:7iz%6#d
fptKGoC
y-FN68
XMTUwe
$i /*
!lIO!d
TQLXf^
E7r`$~
?i${wC
hQ2(IYc
TB?j4Y
2C@_\C
y*c&*G
w'3S@W
$`\KZf6;pd
}H)]sFYwq
F~xql|
|Q$Hr_Tbp
1aEFOg/6eeD
$e2rH'
8{OJ|N
sr?x7Gb
mepn4/B3
2L*FEN
LXV8>5T
.2}sY0
oSkPX
U@_=%w
qwYtw$G
UGx0>7a
/)7p!'
6("}8&
:o*UN-
r$yQP?
|JOx'?/
o$9prMh
6L1,41
{Bh6y]
8<=T?t
WZGydZ
Ym;_`V
Bt$V:V
jF~Wom:
CRJ[C*
B9-VBj
0Vz'wT
LH7)Vz
ZZ_W+7
I~4olN+gK
{rRC&1
1#sZm^g
rV]O`d
pkw1h3
`V iUD3
iU#8jh4
TTSh$
P4G*W>
(/#T:L
bA}^bkc
\m)[)
4i1owzg
rn.bp8*
jtyg>3
MuuC1_"
3!l7>cj
TrIoj?
f+]#CD
kj'&#
k[Vgdy~m
|FqK|G
mZgZ]A
:hz+9o
jDhvZM
Uo|`m@
ThSj>"v
IV?6\E
2C@_\C
j'+6vk
n.R5+R
M(6 V}J
!o5y#AJ
G&B#@%
$W4E&R
d&(ko/
<4kjMU!
ckj&VY
Dld)"ob
6m16fg
;j1I"Z
fR+/h%
=@jKFe
gL0E9kKFe
VzGx]b
#soWZf
"=uj$3
{}"}"fV%
:'eiFHla
n0}"frva
v_#JB/E
eJGZ`y2B
_]*8o}
ErXOep
@advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
@ja-JP
@api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
"%s",%s
%s.lnk
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Logitech, Inc.
FileDescription
LGHUB Crashpad Handler
FileVersion
2021.6.4851
InternalName
Logitech G HUB
LegalCopyright
Copyright
Logitech, Inc. 2021
ProductName
LGHUB Crashpad Handler
ProductVersion
2021.6.4851
VarFileInfo
Translation
((((( H
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Intel Corporation
FileDescription
Hardware VP9 Decoder MFT
FileVersion
7.16.8.4
InternalName
mfx_mft_vp9vd.dll
LegalCopyright
Copyright
2008-2016 Intel Corporation
LegalTrademarks
Intel Corporation
OriginalFilename
mfx_mft_vp9vd.dll
ProductName
Media SDK
ProductVersion
7.0.1540.4116
VarFileInfo
Translation
axhub.dll
axhub.dat
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37141241
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37141241
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Zenlod.a!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.37141241
K7GW Riskware ( 0040eff71 )
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/Trojan.OAML-5751
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDropper.Agent.SNN
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.Win32.Zenlod.gen
Alibaba TrojanDropper:Win32/Zenlod.6fcba1f1
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37141241
Emsisoft Trojan.GenericKD.37141241 (B)
Comodo Malware@#1w0ix92xqhrt4
F-Secure Clean
DrWeb Trojan.Inject4.12781
Zillya Clean
TrendMicro TROJ_GEN.R06BC0WFL21
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
FireEye Generic.mg.41c69a7f93fbe7ed
Sophos Generic ML PUA (PUA)
SentinelOne Clean
GData Trojan.GenericKD.37141241
Jiangmin TrojanDownloader.Zenlod.be
eGambit Clean
Avira TR/AD.Inject.jwrep
MAX malware (ai score=99)
Antiy-AVL Trojan/Generic.ASMalwS.339A813
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Generic.D236BAF9
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R426623
Acronis Clean
McAfee RDN/Generic Downloader.x
TACHYON Clean
VBA32 TrojanDownloader.Zenlod
Malwarebytes Trojan.Dropper
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06BC0WFL21
Tencent Clean
Yandex Clean
Ikarus Trojan.Inject
MaxSecure Trojan.Malware.101153295.susgen
Fortinet W32/PossibleThreat
Webroot W32.Trojan.Gen
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
Qihoo-360 Clean
No IRMA results available.