Static | ZeroBOX

PE Compile Time

2009-07-01 01:00:15

PDB Path

c:\Post\806_Blood\Question\animal\four.pdb

PE Imphash

789fcca066875e59aafcb5a18bb50d1b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000462fd 0x00046400 6.60751707607
.rdata 0x00048000 0x00016691 0x00016800 6.06930496404
.data 0x0005f000 0x0009c208 0x00001800 3.97938828996
.rsrc 0x000fc000 0x00000f20 0x00001000 3.32902550096
.reloc 0x000fd000 0x00003508 0x00003600 5.1466661049

Resources

Name Offset Size Language Sub-language File type
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000fcce0 0x000000be LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000fcda0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x104801c GetProcAddress
0x1048020 LoadLibraryA
0x1048028 VirtualProtectEx
0x104802c GetModuleFileNameA
0x1048030 GetWindowsDirectoryA
0x1048034 SetConsoleCP
0x1048038 SetConsoleOutputCP
0x104803c GetModuleHandleA
0x1048040 Sleep
0x1048044 GetLocaleInfoW
0x1048048 WriteConsoleW
0x104804c GetConsoleOutputCP
0x1048050 WriteConsoleA
0x1048058 GetProcessHeap
0x104805c SetEndOfFile
0x1048060 GlobalLock
0x1048068 GlobalAlloc
0x1048070 CreatePipe
0x1048074 GlobalFree
0x1048078 InterlockedIncrement
0x104807c InterlockedDecrement
0x1048080 WideCharToMultiByte
0x1048084 InterlockedExchange
0x104808c DeleteCriticalSection
0x1048090 EnterCriticalSection
0x1048094 LeaveCriticalSection
0x1048098 MultiByteToWideChar
0x104809c GetLastError
0x10480a0 CloseHandle
0x10480a4 HeapAlloc
0x10480a8 RtlUnwind
0x10480ac RaiseException
0x10480b0 TerminateProcess
0x10480b4 GetCurrentProcess
0x10480bc IsDebuggerPresent
0x10480c0 GetCurrentThreadId
0x10480c4 GetCommandLineA
0x10480c8 HeapFree
0x10480cc GetCPInfo
0x10480d0 LCMapStringA
0x10480d4 LCMapStringW
0x10480d8 GetFileType
0x10480dc CreateFileA
0x10480e0 SetStdHandle
0x10480e4 SetHandleCount
0x10480e8 GetStdHandle
0x10480ec GetStartupInfoA
0x10480f0 VirtualFree
0x10480f4 VirtualAlloc
0x10480f8 HeapReAlloc
0x10480fc HeapCreate
0x1048100 HeapDestroy
0x1048104 GetModuleHandleW
0x1048108 ExitProcess
0x104810c WriteFile
0x1048110 TlsGetValue
0x1048114 TlsAlloc
0x1048118 TlsSetValue
0x104811c TlsFree
0x1048120 SetLastError
0x1048124 GetACP
0x1048128 GetOEMCP
0x104812c IsValidCodePage
0x1048130 GetUserDefaultLCID
0x1048134 GetLocaleInfoA
0x1048138 EnumSystemLocalesA
0x104813c IsValidLocale
0x1048140 GetStringTypeA
0x1048144 GetStringTypeW
0x104814c GetEnvironmentStrings
0x104815c GetTickCount
0x1048160 GetCurrentProcessId
0x1048168 HeapSize
0x104816c GetConsoleCP
0x1048170 GetConsoleMode
0x1048174 FlushFileBuffers
0x1048178 ReadFile
0x104817c SetFilePointer
Library USER32.dll:
0x1048184 SetForegroundWindow
0x1048188 CheckRadioButton
0x104818c SetClipboardData
0x1048190 DestroyWindow
0x1048194 SendMessageA
0x1048198 GetClipboardData
0x104819c SendDlgItemMessageA
Library ole32.dll:
0x10481a4 OleInitialize
0x10481a8 OleUninitialize
Library IMM32.dll:
0x1048000 ImmNotifyIME
0x1048008 ImmGetContext
0x1048014 ImmReleaseContext

Exports

Ordinal Address Name
1 0x102c6b0 Formweather
2 0x102c420 Piecehear
3 0x102b3f0 Stickregion
4 0x102c510 Would
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
WATAUAVAWH
tafffff
0A_A^A]A\_
H$EHDHH
(HdHZ8
EGdND#LW]^
AntLyX
k7!|$1
0Ig_qI
Q@P`%d
mJScm1s|
8!6VZ)tAJ
iN]7amF
0I200U
DDLLIL{
uHL%DH$
;MH$KI
K\S6\_
;K~|qt
AwFQgLa
61Y7*<P
AI"F8D:
uAd (%zH
WEq`ui=
mD\QJRC
Jg|Juz
M|{uC~
zE3"=+
"ILtG|
EL~7m1|3zE=
iVENq|
\#]EJY
gTQ5&DN
+VHHt;
H?E<.$
H`H?L
Egr,MF
~iAJrz
}1@G8E
f|PUR{
HHHTMu
%HH[CH
`$$`$TH
`$MAHH
0HH HF$(
EDY5T
?6;E3S
]ku(EB
/@F}-V
TFhvU.M
FyXu7A[Y
I3SJ!c
zHAMHH
$H@D3L0
Nl0^E_
EOhe@QB
rz9g}[
WDoaE{
/fiB_R
SyI/E\O
HLHD(L
HU0)S"U
DB tDS
HHLH'H
LHHP\A
aHMNi,;
M;B`KIY
gx}la>
$HH%HC
H\EM$
BUDt0CX
W|%k3E4
Y)h/G,k
uUHH3HI
=DcH=vP
$Pa!nHAK
[]1uxb
YV\]B#B
HHHLDHY
Lu9$LH
LHtLHHH=
=d\8m'
dBt`1O
u$.IHy
HHu7 X
0H$%IT
D$(~ITh
EM!U1g
jxaN3BE
HGDlH%
HhH$lU'I
tH3HT
H[@'H$t
`}Y6#L5E9
6>=E/W@
=GhEfS
At0>ZXJCE
1tcvCK
~/3ER-nO\
DH*$T\
$C3TDu
HL`DHD
(Hu%LD
0L39+E
`ODH9<
fzlJ]r
H ItHtd
U9.Et
uH+H$H
H\GH%f
ZW*oES"
.ECc_5
Ei|IDG#
|Ehu3s7
ETu8{
EA]u_w
8't'=DCHAt
$LPE0\
LsAHHEM
Hx0HH\
UH$yLH
z!3H8B
U!o$HH
*Hc\HL
D^TDHH3
WH\%HLH
$H3Hc[
TSH@c^
0HH0HH;
(HhHHM
LHH \W
;MAuH$
A(HcHT
C$N3L[
SN!t_`W
@HHMHT
\DH4HU
HDG3$C
HHS#1V
HhHLHI\
%HK9H[H
;HO8A
$1MHHGx S
@W$M@bH
HUD1HE
$HH(@H
L*hH$tH
7twL@H$03
LEI0`3
`HAHH$
H$H$$H
H8HLL$
CM`D)H
:HMHHH
Ht HH"
%$H~Lt^
LuHWPB
9u0$C(
H37gO
9e@DH%
MPHHH^A
HM:LH0
|P3$`H
$KVLLHH
H@AEM!D
Dm%l\L
\HMHoHD0HI
M HH'L$y
';HL40
HHl$\EH
[H~30H
tZ$%HS3
HLfM\@
$~MHC$%H
H0T@tT
>fH+HH
@$+M W
uHH*HbD
`EHHtt
H.UXH)HP;
H9H$`"H
c%HHPDH
HH$1Yu
H0Aut07
(#-$C$
HHxQHHHHM*
MH$H3
LHAHAH
N@j$$W
C@H$M
IItVH 4
L8`HSEH
8H@WDH
"E HUH
HHIH$H8
H$tHHH
()$0H $
HC@0H^%
L]K WE%$'u
\H'pHI
;fIMuH
MHpHcHHtH
$vM$M.
Up$HfH
HHT+@D
HL$HHH
HHJ|C`
c0$Ht?
0*HHU$$
`HIHEO
MAXN;H
TMtHg$
CH$:D3
$He$%KOM
%_DpH\
KQH3HH
$`tH\H
@tHCHU
E%MHiL3
8QHHH
H$HIh$H
`$HLLA
H$ LH(H
t}9>uyj
tz9uvj
F09^(u
QQSVWd
PPPPPPPP
0WWWWW
0WWWWW
HtHu4j
s[S;7|G;w
tR99u2
t"SS9]
^SSSSS
^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
j@j ^V
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0A@@Ju
0SSSSS
0SSSSS
0SSSSS
PPPPPPPP
_VVVVV
^WWWWW
>=Yt1j
t+WWVPV
URPQQh\'
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
HHtYHHt
0SSSSS
_VVVVV
u,VVWV
t VV9u
<+t(<-t$:
+t HHt
bad allocation
ETN) :q
JFFEEE%
!EEE6Y
iEEExE8EE6O
aVDJS/
|~8]8~
GhEuEED"
G}AK0M
${MDFFF2H
BFEEEEEEEEEEEE
@@@@FFFFEEEEEEEEEEEE
@@@@FFFFEEEEEEEEEEEE
@@@@FFFFEEEEEEEE
4AkFVEE
1]n^n[
/A-EUEE
S.T >y
l"e y
r o<
t tpaa/
</exception>
<exception cref="T:System.ObjectDisposedException">
</exception>
</member>
<member name="M:System.IO.UnmanagedMemoryAccessor.ReadSByte(System.Int64)">
<summary>
</summary>
<param name="position">
</param>
<returns>
</returns>
<exception cref="T:System.ArgumentException">
<paramref name="position" />
</exception>
<exception cref="T:System.ArgumentOutOfRangeException">
<paramref name="position" />
</exception>
<exception cref="T:Sys </exception>
</member>
<member name="M:System.Convert.ToInt16(System.Object)">
<summary>
n)xt.Uy:
<see cref="
</summary>
</member>
<member name="T:System
</summary>
<returns>
<see langword="true" />,
<see cref="T:System.Reflection.Emit.SignatureHelper" />
</param>
<param name="ca
"bi eA : r R
ei /i
mtmriGe
m m>e
foc le
ye a
e mT l
y psa
a u
/S rS
tT in
ei "
u=l i Pm
.c
.Tmml
e e
ea /es
ea "Xy D
]eYhav
yS2hYG
o;"pFw
8wC;;.F
vF<DM\
E0N;F%
4<F\%U
X[dEMP
(ETU+:
dU[G=g_
I.EGAv
7k1l/E
Tuatni
r c M
a te.eM
<s "
ia xu
It y
rme>s
l",faup<
q tR
js e/
eF py>
:.rnoe
r > r
m < m
1O3nEG
MGDW~=q
@E -:}
]mKCE~
@[}.UG
($[" E
rm rn
>taem"r i
. pb
TnaPs
:e:wdgit
t
u"metm
maeeer
>mc> <
/xy tty
Sxs
<acme
tmh y
e: <
p. b=c
G o = s
" h<ry e
mbnb Sm
-n
errn/<
a e
r reeg
D a .
r c oerm
er t.Xm
uPp sa
t/c<
lb se
> ys te
6" . >
<.ip/ (y
rame
p ra>X
EcGk{1(aw2
EK}W<lE
\V'[Cx!
cN5%'DM
;=ND*i
Epv0B\
IOJvE[3
b ue,
Td.3e
pr "la3
) ee V
r"re"m
a n aas
< ) ftS
nn P"a
oa ene
py >r<
c"<r<.
a oa s
".su1e
d" e
ei/ t
e rSp c
.mbscr>
n e
E , >
da mt ce
gd mc <
emc3 /
e na rsm
m Ce S
c /msi
ADx N
n b mn
t /ng
mt L
m n(, "
cw ="t
a" r r
l i
t rw
e =tSe
ps T
pbefo/ .
x t
e.yct
frnn.ja mR
celrp
e">e t
> =
i,s by
G$RZ^`
]G]`K^%E
X9iPE%
e
<E e
aey m
e a aa
y
au.n i
sPmne
cau cs
.= a
<a>mte
texRgr
p> b
h.yCy
ca= n
7@XO(E
Bm t >m S
xl)=
e=<ot
w s<.
I t
y #
a m
p
ir ia
S p=Sr
c re
m .<e
Se <r g
S mR
bptu >
""er
" ==e,ma
".t yt a
ei CDt
geV|i\Z
E#o[]n
nsEB"t
235NN
Q",&#D+
EON\#K
pYE\K
m<k.lis
ybna >
rf"
. e t "
rn ee
y m w
T/d
ce e rt
a/ ricc y
tme ts <
ty>t ma
m re
eb rr
c. a e
<E n nC
nm sx tdcp
n s
e<mt :
o = .
l2p
ho> ec
l: t
eA .nx
re
,"s
t
tePy/
n<tmulm
,S e>ei
tamcr r
:c rn a
>n:
>m" p
st rm.me
n:t..a
e :lea
e >
fcpe
, r r
.m x<
a>>FR>Tu.
pm I
<yaaoc
ms yea
I. p
e ta.VT
Pb a
.y
=ee>a=P
e> /pF
< I sobyde"
3s hic
an s.tuj1
etns mn
>s /s
i"n.Ss
ueie.e
.iana
<atm
t enbe
I w"
eLngaic
s bs
hcrr m
sn rm
ty.a xm
ew
c any nee
>L"r
rs y(t
>a2 =m m
e ce;ed
GtSeme
u"o ie
an r S<f
rc. p
o>s ie .
m/< myn. r
frmr
=: rm
< me
y 3
ic t.u
/ >ypi
y a>
els">
Mc sr f
/,ye ne
s 3t
" (m
r r a
f .A i
,( o/
t m# >n
Hms n.
nr " .
n m
st Fn
a<.p
nf me
a,t y t
a .
m e.m mmr
/r A =mm
t "i/ r
b /S ef cam
e edw<r
y a"O r
y a/a r
. rm
<e am y
t -/yu<
t n .
ay lm
y ti F.a
=>Sn
tierm
e mn e
@ae@pm
rt p fs
c >
n E b
= souu
n i m
a<u
Sottt
<"eAeum
>"
2"(utx
Tu as
brtrm a
ysee o
nsy o m
< m< "ws N s
t mIt
ay t
D
.=nM <, " I a
mpm n
n< o"
tt>c
aml
> eel > o
o y
a>r <i
s ee
}= :a .
m as m
tte
L . a>A
nB S o i> )/
r u< S
u p i
e < ze
S>e e> I
r mv> cnt t
n pr
lnM
/r
sm y
sS :r>
rt c 2c=
"t< , o
s e o
S i r<c,
yt b .t
ig r b
s n.mr
Be = a
ga o
m t
TG,=e
eeccer
p<d> "r
smsm .
."a=met n
a. rr
ee. .p
o eneld
eu t:"
lD ar<
mn
utea<<
h> f#
et, io
i Sir
m/x m
tS.pla
m:S rs
p T e
zaI
x<mg"l
.ge<Se
e o/v:
ese x
io /l :
t. u
< e, :s
t=.
mS r bo
e l>ce
g m se
idraa
n o A
pr f
Sa a .
E sa
/o
p mfSrne
t.c m e
y eu a
a t r.my
c t lp
"stfFe
<a. u
E//r
a .le
Sr
asn
".rnt
a"r:ms
l . eos
aei u t
a / i
czX S
s =
e nsae<
t >""P
aaae
emP-.b"a
e , p
gt x>
l"l rr
< m <
mse, nm
tr
< aAo
lt g t
c .TosS
s = ve
c. mp
txts >
>
sa:cm
b m D
) aMi f
y tj
p. o .
et>ya
."s< Ts=
mC<e
Hep =m
,a, e
=t" d>
er iD
aMS / e".
r t R e
y" um
rea
p.=meg
cfd t
lSts/n
h iu u
r cliD
S s
"an
p=S cen <p
rnt nP.
<g ""
yam, s
re rS
a >(Tg:
c t
rr .i .
(p r>
i"din
mi e>C
sc o
n>.>
s a ber
im w
rs = mtA
S>en s
eame .
o Lg bLC ,Cc a
/oe> y
g aw<
=l eeeo i
<mxfr
a<ea ms
s/e t.
cmeI3
/ptr
x . fM
yePs
m i /n
esd r
n/<s
brsnv
p mj>Dm.el
rc ra"
<mii
>a< ,>
m= I n
t seMt
a os.ei
a rn
yr a a
=1rC
yag
cm < im.
nSt
.n/ee,
ts"e u
e <.(txn
t nby
m ep.y
t<D t
e rat
r :
"e eM
Oot,r
> t men
9"< n
h m uc V
Rtc ><=n.
mgn r i
." <
aa: os
is . p
a l t
me t /.r
Ir9NGD
.FFFFame="M:System.Runtime.Remoting.Metadata.W3cXsd2001.SoapNcName.#ctor(System.String)">
<summary>
<see cref="T:System.Runtime.Remoting.Metadata.W3cXsd2001.SoapNcName" />
XML- <see langword="NcName" />
</summary>
<param name="value">
<see cref="T:System.String" />
XML <see langword="NcName" />
</param>
</member>
<member name="M:System.Runtime.Remoting.Metadata.W3cXsd2001.SoapNcName.GetXsdType">
<summary>
XML (XSD)
</param>
<param name="bytes">
</param>
<param name="byteIndex">
</param>
<returns>
ios_base::eofbit set
ios_base::failbit set
ios_base::badbit set
bad cast
bad allocation
string too long
invalid string position
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Unknown exception
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
(null)
`h````
xpxxxx
GAIsProcessorFeaturePresent
KERNEL32
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
`h`hhh
xppwpp
1#QNAN
1#SNAN
CONOUT$
c:\Post\806_Blood\Question\animal\four.pdb
GlobalFree
CreatePipe
SetUnhandledExceptionFilter
GlobalAlloc
QueryPerformanceFrequency
GlobalLock
GetProcAddress
LoadLibraryA
GetEnvironmentVariableA
VirtualProtectEx
GetModuleFileNameA
GetWindowsDirectoryA
SetConsoleCP
SetConsoleOutputCP
GetModuleHandleA
KERNEL32.dll
SetForegroundWindow
CheckRadioButton
SendDlgItemMessageA
GetClipboardData
SendMessageA
DestroyWindow
SetClipboardData
USER32.dll
OleUninitialize
OleInitialize
ole32.dll
ImmSetCompositionWindow
ImmGetCompositionStringA
ImmGetContext
ImmSetCompositionFontA
ImmNotifyIME
ImmReleaseContext
IMM32.dll
InterlockedIncrement
InterlockedDecrement
WideCharToMultiByte
InterlockedExchange
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
MultiByteToWideChar
GetLastError
CloseHandle
HeapAlloc
RtlUnwind
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
GetCurrentThreadId
GetCommandLineA
HeapFree
GetCPInfo
LCMapStringA
LCMapStringW
GetFileType
CreateFileA
SetStdHandle
SetHandleCount
GetStdHandle
GetStartupInfoA
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
HeapDestroy
GetModuleHandleW
ExitProcess
WriteFile
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
GetStringTypeW
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapSize
GetConsoleCP
GetConsoleMode
FlushFileBuffers
ReadFile
SetFilePointer
SetEndOfFile
GetProcessHeap
InitializeCriticalSectionAndSpinCount
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
GetLocaleInfoW
four.dll
Formweather
Piecehear
Stickregion
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$numpunct@D@std@@
.?AV_Locimp@locale@std@@
.?AUctype_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDH@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
%0)0/03090=0C0G0M0Q0W0[0`0e0k0q0w0}0
11$1)1/151;1A1F1K1Q1W1]1c1
2!2-262<2F2M2Z2f2n2s2{2
3!3*353<3E3J3Q3`3g3n3t3~3
4%41484B4K4U4[4`4i4n4u4
5#5*595B5I5Q5X5e5l5|5
6"6'646<6A6O6X6`6f6o6u6}6
7#7.767<7E7V7c7j7z7
8"8)8:8D8T8_8f8l8r8
9(9.959A9L9V9\9h9n9v9
::':-:2:;:B:H:T:\:d:l:r:w:
;!;';,;5;<;B;H;Q;Y;^;d;m;
<&<0<6<B<H<P<\<a<l<r<z<
=!=)=2=8=C=J=O=
>0>7>R>W>`>
? ?(?2?G?N?^?n?~?
0)0/060O0W0^0e0t0{0
1#1(161<1B1H1O1c1|1
22*202A2G2M2S2c2i2z2
3=3K3\3b3
1 1*131=1C1H1Q1X1`1f1r1x1
2%2,262=2J2P2U2[2g2m2u2{2
323@3F3V3\3b3q3w3
4+444:4D4Q4]4k4t4}4
5&5,525A5G5V5[5a5i5r5x5
6-666=6D6\6t6|6
7"7(747=7C7M7Z7b7y7
88,84898G8P8X8^8g8m8u8z8
99%9,979=9L9R9q9
::':/:::@:K:S:Y:c:p:x:
;";(;/;6;\;g;n;
<&<.<M<l<r<z<
= =%=.=G=M=[=`=
>!>/>5>=>I>N>T>X>l>
?%?5?K?S?j?s?
0+070>0N0U0k0q0w0|0
1"1.1M1S1b1o1{1
2%232<2E2K2T2[2b2r2z2
363<3F3O3b3h3s3x3~3
44&464;4B4Q4X4f4t4
5"5.5<5D5[5d5q5
6 686?6E6X6h6n6w6~6
7#7*797G7S7]7y7
8,828@8I8Q8X8_8s8
9&9I9a9l9{9
:*:2:9:O:`:i:r:y:
;$;4;M;^;v;
<+<3<B<Q<h<y<
=%=>=Z=b=z=
>(><>J>P>`>f>x>
?!?*?G?\?
0#0-0F0Y0f0m0}0
061B1R1Z1a1t1
2!252@2F2R2^2d2k2t2y2
33$3-3=3G3M3S3X3h3m3x3
44+41474?4H4N4U4[4`4f4l4v4{4
5'5-52585@5I5O5V5\5c5h5n5x5~5
6,62696I6O6U6Z6a6h6w6
7(7.757;7B7N7U7d7j7o7z7
88%8.868<8A8N8V8`8f8r8}8
9(989C9J9P9V9a9i9o9w9
:!:):.:7:>:D:K:T:Z:a:n:u:
;$;-;3;R;Y;f;q;x;
<!<'<2<9<@<F<O<[<b<k<r<
=,=3=9=A=G=L=R=p=v={=
>+>6>?>F>O>Y>_>f>l>q>
?!?'?6?<?[?z?
0'0-0:0Q0\0h0m0t0z0
1G1X1_1f1m1
292D2K2Z2`2h2t2z2
3 3)363c3i3x3
3<4A4G4R4_4f4l4r4z4
5"5.555<5K5T5Z5d5q5}5
66(6.686@6J6a6g6|6
7 7&7;7V7`7j7r7
8b8g8n8}8
939f9r9~9
:D:J:O:U:
;K;V;\;b;t;};
<"<)<H<S<f<y<V>i>
333U3~3
5p6f7s7
6'6/6v6
&050~4
1R2\2u2}2
3 303P3~3
3=4`4u4}4
8&898H8R8a8u8
5$595B5y5
7C7X7a7
7N8h8o8
8:9G9Z9
:(:9:]:
;,;3;>;D;O;T;h;x;
=#?,?S?^?
0P0Z0r0
22?2v2
6"6+676C6O6[6f6n6
8@9F9c9h9
3G4_4d4
8L9d9|9
:E:K:S:`:t:
;7<?<N<
=@>Z?_?i?
0*0Z0v0
303Y3^3u3
3)4/4@4k4
8;9^9i9
0&050B0N0^0e0t0
1I1X1a1
2I3Q3f3q3
9#:A:H:L:P:T:X:\:`:d:
:&;1;L;S;X;\;`;
<J<P<T<X<\<
= =Y=b=n=
161H1[1m1
525O5Z5q5
6*7:7U7u7
N1U1m1t1~1
2"252Y2
3!3d5r5x5
6.646?6D6L6R6\6c6w6~6
>'>:>D>P>Y>a>k>q>w>
0"020G0
2%2.252>2~2
3 323V3}3
:B:V;a;j;
<+<=<O<a<
>B?H?S?_?t?{?
0)050;0G0V0\0e0q0
3Q3a3g3s3y3
4 4(414=4B4G4M4Q4W4\4b4g4v4
7%808:8S8]8p8
;4;<;D;[;t;
>&?6?H?\?
4;5N5}5
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<|<
0h0n0t0z0
1.13191?1U1\1e1
1!1(1,1014181<1@1D1
2,23282<2@2a2
2*3034383<3
3v4+545C5{5
7O8U8k8v8
839F9x9
<'<V<d<
<B=O=o=
1A1N1S1a1
3#323O3{3
788>8J8
:M:S:_:
<J<^=e=
4}5R6f6o6
:):.:8:F:
>!?;?D?
7#7+787?7
8M9C:K:
<!='=7=
1e2k2{2
6!:%:):-:1:5:9:=:A:E:I:M:Z:5;M;\;
;#<J<z<
?%?H?v?
011T1w1
2$2.2C2M2]2b2l2x2
? ?$?(?,?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0@1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
1@2D2H2L2P2h2l2p2t2x2|2
87@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3
3P4T4d4h4l4t4
5 5$54585<5D5\5l5p5
6$6<6L6P6`6d6h6p6
7(787<7D7\7l7p7
8$8(8@8P8T8d8h8x8|8
9 989H9L9P9X9p9
: :0:4:8:<:D:\:l:p:
;,;0;4;<;T;d;h;x;|;
;\<d<p<
=$=D=H=L=T=h=p=
>,>8>@>`>p>
?$?,?D?L?T?X?`?t?|?
0$0,040<0D0L0T0\0d0p0
1,181`1
2<2D2P2p2|2
3 3(303<3\3h3
4(4H4L4P4X4l4t4
505P5p5|5
606P6p6
787X7`7d7|7
8 8<8@8H8P8X8\8d8x8
9 9@9`9l9
:0:L:P:p:
;0;P;p;
2,3L3l3p3
3<4P4`4d4|4
8d:l:t:|:
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
2 2$2(2,2024282<2@2
((((( H
h(((( H
H
mscoree.dll
KERNEL32.DLL
(null)
captain
MS Shell Dlg
second
written
MS Shell Dlg
record
MS Shell Dlg
MS Shell Dlg
soldier
rather
temperature
MS Shell Dlg
MS Shell Dlg
through
necessary
motion
MS Shell Dlg
property
MS Shell Dlg
probable
sister
MS Shell Dlg
surprise
MS Shell Dlg
family
MS Shell Dlg
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.37200498
FireEye Trojan.GenericKD.37200498
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Riskware.Win32.Agent.ky
CrowdStrike Clean
BitDefender Trojan.GenericKD.37200498
K7GW Trojan ( 0057f0651 )
K7AntiVirus Trojan ( 0057f0651 )
BitDefenderTheta Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/Spy.Ursnif.DJ
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37200498
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Agent.cnfss@0
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic PWS.y
CMC Clean
Emsisoft Trojan.GenericKD.37200498 (B)
SentinelOne Clean
GData Trojan.GenericKD.37200498
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/AD.UrsnifDropper.uytnr
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic PWS.y
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Clean
Fortinet W32/Ursnif.DJ!tr.spy
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
Qihoo-360 Win32/TrojanPSW.Gozi.HgkASX8A
No IRMA results available.