Static | ZeroBOX

PE Compile Time

2020-06-21 16:05:55

PDB Path

c:\Reply-quite\Cry_Country\523\Gave\Color\shape.pdb

PE Imphash

6507b1356328cc79bafe86c109deb6e0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004a297 0x0004a400 6.63817976219
.rdata 0x0004c000 0x00021a70 0x00021c00 5.99559143742
.data 0x0006e000 0x00098684 0x00000c00 2.39527131559
.reloc 0x00107000 0x000023e4 0x00002400 6.72128933027

Imports

Library KERNEL32.dll:
0x104c014 GetCommandLineA
0x104c01c GetTempPathA
0x104c020 GetWindowsDirectoryA
0x104c024 GetCurrentDirectoryA
0x104c028 SetFileAttributesA
0x104c02c SetSystemPowerState
0x104c030 SetConsoleCP
0x104c034 WriteConsoleW
0x104c038 HeapReAlloc
0x104c03c CreateProcessA
0x104c040 GetFileSizeEx
0x104c044 GetStringTypeW
0x104c048 FlushFileBuffers
0x104c04c GetProcessHeap
0x104c058 WideCharToMultiByte
0x104c05c GetCommandLineW
0x104c060 GetCPInfo
0x104c064 GetModuleFileNameA
0x104c068 FormatMessageA
0x104c070 HeapSize
0x104c074 VirtualProtect
0x104c078 GetOEMCP
0x104c07c GetACP
0x104c080 IsValidCodePage
0x104c084 FindNextFileW
0x104c088 FindFirstFileExW
0x104c08c FindClose
0x104c090 SetFilePointerEx
0x104c094 SetEndOfFile
0x104c098 MultiByteToWideChar
0x104c09c GetConsoleCP
0x104c0a8 GetCurrentProcess
0x104c0ac TerminateProcess
0x104c0b8 GetCurrentProcessId
0x104c0bc GetCurrentThreadId
0x104c0c0 InitializeSListHead
0x104c0c4 IsDebuggerPresent
0x104c0c8 GetStartupInfoW
0x104c0cc GetModuleHandleW
0x104c0d0 RaiseException
0x104c0d4 RtlUnwind
0x104c0d8 InterlockedFlushSList
0x104c0dc GetLastError
0x104c0e0 SetLastError
0x104c0e4 EncodePointer
0x104c0e8 EnterCriticalSection
0x104c0ec LeaveCriticalSection
0x104c0f0 DeleteCriticalSection
0x104c0f8 TlsAlloc
0x104c0fc TlsGetValue
0x104c100 TlsSetValue
0x104c104 TlsFree
0x104c108 FreeLibrary
0x104c10c GetProcAddress
0x104c110 LoadLibraryExW
0x104c114 CloseHandle
0x104c118 CreateFileW
0x104c11c GetFileType
0x104c120 ExitProcess
0x104c124 GetModuleHandleExW
0x104c128 GetModuleFileNameW
0x104c12c HeapAlloc
0x104c130 HeapFree
0x104c134 LCMapStringW
0x104c138 GetLocaleInfoW
0x104c13c IsValidLocale
0x104c140 GetUserDefaultLCID
0x104c144 EnumSystemLocalesW
0x104c148 GetStdHandle
0x104c14c ReadFile
0x104c150 GetConsoleMode
0x104c154 ReadConsoleW
0x104c158 SetStdHandle
0x104c15c WriteFile
0x104c160 DecodePointer
Library USER32.dll:
0x104c168 ValidateRect
0x104c16c MapWindowPoints
0x104c170 PostMessageW
0x104c174 EmptyClipboard
0x104c178 GetSystemMetrics
0x104c17c DestroyMenu
0x104c180 BeginPaint
0x104c184 InvalidateRect
Library ole32.dll:
0x104c1b4 CoTaskMemAlloc
0x104c1b8 CoTaskMemFree
0x104c1bc CoInitialize
0x104c1c0 CoUninitialize
Library ADVAPI32.dll:
0x104c000 RegOpenKeyExA
0x104c004 RegCreateKeyA
0x104c008 RegCloseKey
0x104c00c RegQueryValueExA
Library WS2_32.dll:
0x104c198 WSACloseEvent
0x104c19c WSASocketA
0x104c1a0 WSAConnect
0x104c1a4 WSACleanup
0x104c1a8 WSAStartup
Library UxTheme.dll:
0x104c18c GetThemeFont
0x104c190 CloseThemeData

Exports

Ordinal Address Name
1 0x102a030 Fatreply
2 0x1028d80 Periodwait
3 0x102a340 Seemprove
4 0x102a0f0 Which
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
@UVWATAUAVAWH
Dg\NDMW]
)%b]5A
Qgd'<I}
XB/NXG|L
0#USMW
MPHHtl
~TDWSu
XUEHL[
HHH @HL
A4``2uLp
V9.Dt:
`;HDXt
HHH@$=
u/[H\E
LAOH_HHH
J~y[eG2
if"]gQ
2^.*gK!
i.gP5e
19#K#
S}N=]ND
cI, YLo4M
H\%0_TTO
DyuM|S
d~myuc
HHtEHG
HjL$%L
LP*H;$
$ttHF@
PHH3IZ
sXDU`3HAx
B#kbpL
LXjw?/
YqEFzf
*EOQ@9Y%
PHtHHHg`$
0 A%$@H
y`JY[S-
}f?3}B
HHH8LT
B7dF</
4tRQGN
J4@wpn
3[l-OJ'j
eGSR)J
WRm9|E
8i{Y"E
~J\`9E
Hh2tHH
HH@=HM
H$&;H5t
qL9IT_
FYq9J;
/lKFr.
DZUp3HtHt
t3HExQ)8LH
M$PPmH
Ht8)V0.
P$HLH[30
GHMPHg$
HH@HS3
a1NO@JX
YhGaE{
ZE8TxB
u}r7MV+R?
/u)OEM
+[eo?Y
yncF}f
AH$H03Lx
_HH 'Wwu
LEcs$H
H@8$;hHH
GdpAKE
"f4GA'
MSEigJ
c&K6@I
0LpHUt
PDHL_4@
ItHWM$8
RHtxAH
DHDLGW
@zrVo\
@tHDf$
HH3HH3
EDim-Ry
4x+5eq
D~;cBM
HHH)SVCH
M$M$HI
H$OHHH
A $CYH
USH?;$N|
HC0\D$
@MHHAH
H2c HHi ^
}HW\HIK
;3`DHM$
D\pC$T<;H
3H2$A
H@HWCA
)HHAU8
HwfBT@
3WP#Xx
+LHPAEt$
HHH!
V%cpH`H
UtAGAH
EL@EHC
xL"YIfM
DHc HcXH
L )FtH
@HUHH3
dHtHH
I;HHt
LM88HHT
HZMKHI
`Hp`[B
1g`$HPT
0HHIuCH
_\HHH
DHE$ u
T$HHUM
)HHL$
\MHD3E
HL`HL(
[`H$$3
hkHtL$XH3
BHH$)MB
HD!$HH
HD&H(LP
{uH^$M
tH]tHH^
MtPH.s
$H+@t`
HO\=HHH?
IHLHHH
%HLLW
$HEAHHP
jHOpH%
cIMHHLA
\HL$$$
M/H@HH
H$"H0D
cHHHHH$
HUEHMv
WtHHDH
HHH"(L
HHDtHLL
$4HHHE
)H$Ix
WTL) K
8HHH$H
W8`$J0
H0$H H
8$HD|q
@0M$I
HPE/Ht
BAA~Hg$
H$H0AT
ECLPHHH
!`HZHH
HH\HAHHH
_{xpL$.
tI$@^HHH
>$>D(]
HMm$E8
PH$0kH
MHDP$Ot-0
2$tH+H
HHHy*_HH
DL!HH@H
HIIPLL
HPhL8d@
8HK[DH
0D5VLHH
2HHH%\K
KD-$ZH
HPuLW$
bEH@pH
\WHDHML
VH HH@
$\{EB$
Mt W[$
DHj$H(
tStDL0%QH
H[(AHH0
IIHMMH
HMH/ BI
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
ts;},sn
W8^(u<
W8^(u<
Tt5jh_f;
Ejl_f;
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
t#Vh<n
SWt@jU
_tqPVj@
<at.<rt!<wt
<=upG8
D8(Ht'
Wj0XPV
SPjdVQ
QQSVj8j@
zSSSSj
f9:t!V
ARPRQh
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
IEEEEE%
iEEExE8E
G}AK0M
D"}KBEEE1H
AEEEEEEEEE
@@@@FFFFEEEEEEEEEEEE
@@@@FFFFEEEEEEEEEEEE
@@@@FFFFEEEEEEEEEEEE
2BhEUEE
nU@@@F
e <<
c be
emept<
a y e
o 2 /e /t "-
m> ipmem
C>
a/ceT
te tcea
"inr se
.ComTypes.IMPLTYPEFLAGS.IMPLTYPEFLAG_FRESTRICTED">
<summary>
</summary>
</member>
<member name="F:System.Runtime.InteropServices.ComTypes.IMPLTYPEFLAGS.IMPLTYPEFLAG_FDEFAULTVTABLE">
<summary>
(VTBL).
</summary>
</member>
<member name="T:System.Runtime.InteropServices.ComTypes.INVOKEKIND">
<summary>
</exception>
<exception cref="T:System.ArgumentNullException">
<paramref name="value" />
<see langword="null" />.
</exception>
<exception cref="T:System.ArgumentOutOfRangeException">
<paramref name="startIndex" />
<paramref name="value" />
<see langword="null" />.
param name="beginMethod">
</param>
<param name
Ss M
FS "o
e.e< e
> G le
e< mr lS
u Fm=
e nsisbe"r-u
1
t>=. a"enn
< c jA
yy . oS
gS ma< u
b"i Pe
u.rir.
r io
m>me m - r
lC.o a
y .Sns e
e>< W <
mt a"s<
<m
= l yp S>y.
i Ta" s
r e <n
kW2>E$U
IxEx)I
Eh&)4)>
Fqj6<p
. rio
"/ yr
=e e it
r <"
rte# t
,ta.re>
mI u
m<
"" m<S
= pitf)
s t
pn"na
n c < Oi
rx< e
e ao
.>n>ne
oc .
.e n
Cm m"
<>pd,Su
eur- e
t:3/ s
x "
"s> ms o
ce>e
ET we
pi <
em) le
rt>tra
ur soy3
b tm r
Cm Cp:
btspse>
" o>>> >
a e
=>e ia
f mE .a
: i
tCn
24@m
>re,.>
fR gma
y mF">
i"a m
gyM ln >
dt r f smppye
i<8>cF
AYJVMiN
P9YoGP
lyuG(gh
dYUAXm
3Rp@cf
<3"]HE
+=eLON
M1+Q,`
XwnEKC~
N{ytPv~m
JNizum*N
!"#$#
!D-,/.)(+
7&^<vYtwvEqpsr}|
lrmc.T
ce .
n ng
r r. i>
ea,lerla
y l
a <f
Fg gme
2p=r
"ts> <
. r tn
m, tmt
) "/ue
om emr
tcso l
:iu me
g
tp"etm
y imE
e y..
or"y
i "aS
. yz:=x
c. m< T
n lr
aa T m
sxur
.earem
Snp e.r
i rb p
rma>/A
tmr
. t=
to p"Tn
S fA<
/. oa
g/; ,
Suc. Nt
mAp
<t ph>r
> t<d >pN
== te
Se n i
el 2s
tlt> ems
ntr I
f
/ u <cy e a<Se
.<e/ <e
eAT h
. s<t
/s ko"/
mn = u bl
tt. =E
aSBgc/e
nP.pP
S=EJ]265
&4F0,qn
A@[b6^
I&Y>}8
*9{d|F
}YeEr
bjVmYg
^\B^EF6
<e /
m s=
ne m
g Rct"<
a Sar
a P.3
smuRc
s t =emu.c
y.tc "
tt >
n>r a
r
Sy = rp
<m<
r aii
t t
e rpgr
rna. >
ec,
Inepr
tyc f. u
t xe ,
rytIr
"n nsT
) iseee
Q\~&(F
EAQ*bSF
U5seaZ
_G%zdF
}Q4z [d}
XEw%jb
T t,
rcb il
u /ef
sgmt "
>e >me
iyS:s. i
aygf m a
=e e
" M>",
r >e>
Pot y
o"i= > sems
< pmn>/ s
aet<
"TNnC
emyT
Ae m
" C c
pl
t fl
m, 2cms
p i:<amys me
ephg
s sm m
d< eS
uP> mlgenm
a <r
eu IE
SlestT
F <tI
etaam r
um.y
um Sads
y
G g" /cl
"ba F pu
y: ppU >
m,"saoat
: r.SF
r uc, oe
t emxn
seD
T co,
An
r .cgu
hteaca
an iembct
y l<
S ..ay, .b
y m> saa
rr r a Pa
feo
t t .t
Dv7LM1W
UG@}7x
+Er7S1n3p=Dv
"Ev=(-
FWg<BX
eM|JN5
@#+GKH1
8@Y")%
an=ge> y
dOcs
a=aa
ua u
ee <
e m eer:eroy.p
iaf m
u"yfe
trem C,m
yeeyl
tnD< c
s Pm=a
<tm
ee x
uSeSrh f l
reC e rs
so/ lT /
e"ro bM
rn r
`l
m iI S
c nona e
e >>
m tewv
< e
fc t
he
< x<
r emm-e
y mm
oe "yD
aeSA g
n<o ni
el
e/p>
S Br
St y<<d n
n>S < aeir
x ":e
OS> n
. g/ y
ey"<np
lodTts
By a x
. u
As"e
e ne "
r<i iT
<a" er
" l r
I ees
i "
rrd Aed
alsc2ep
"B s
s e >t
a t/
/ > e r
A p< u
/ean
ym <r
- >< C m
>> mD
r.mm .m D
Dm>L m
"n . i
nun. d
3 .mp
. rn
e .re
"B, <
D=di >
c F
<cm
e e
pa dtS
mlpRc
en=/r
,R e u
rms
= =
a ( y
xc n
p xe<
.rm u><y e"
r m
>> uem<
bS r
K s
. = .pSm
.,rm(t
en a
e.sC a
u ce
<s a
e nfuy
u =n
Dl = /
:y m
rd/ m
c> r-p
a : =l
tm t e<
, e>eeo
C /rP
r f T"ai
e csu re
t nc=
my .i
N<Ie
ncan g>
A =
eeip >
a H
sou
nm d>
>aX e(
: >tcym
r rcne
c a
tFa r
mkn> m> <,aei
R y
= u mn
yuy se
a x-on
nmS mn
<i: c
as .
<ntP
T s
n >iyra
Te/
f e
e, nn<rhp
<bn>n
xra
"dc l
eael/m
p g".G
:< > >
ramE .sp
sm
2
t cr<
> ra
<rm r
/tui m
:r ig
st= p a
y pi >m
xymnIy c
mt cm yt
a t>p
acr<"
r y>
> n mmra
f iS>
, t I.
m cme
m iTr
:o .l /
<oae r
r e =va
amc m <
snay e"m
S p>
l
a
pd taum>
/s6.ee iT
mamInf
t <
uFe
H/xu i
< .a d
S. apm
rim
r de>
Sv " r
> mm
m m:e
nt m
x
l> c>h>m
" e.T y
""mr o
xS-n`/
ptam g
s a er
uhEn .g
s>= un,
=reg f
"e n c
/a< asSA
t rkt
t"<t
. Tr r
tty by
/Netan se im"
>"e<r>
wr s
f + >r
ee< e s < >
e =m em y
/ie nr Ta
" us
uT
. O ht
t e>
py r
eo Cc )Srl
e iPy r
"/ a<rr
xcr em
Tr e :i>
:u o
ef. 2a m R
rxcN w
e/ an
siaepm
= a to
fe upEr
r/oiep:tunr
>Ft
en >m,
>Sn <
T e
to"n a <s mA
mr"tsm
n"ta,
D ,Iizeb.eS
a >Tt"
pm aemOT
om a
ebo3 o
1
r
f y nS
y :t
p pt/
l, .
stle i l"e
oaax)
<sa mwr
"e/
m e . =
l ru "
p"n
>, s
<rlCA<rma nyt
bt s >
r< "5
/mee f
t i , t
> <a t .
oy
Ifm<
a b r
z <t e
nM
m eam
ceTa s ae
e L
ene t
wm F Nn
a" m
< oxeP
eum e
) r Ps
Oa n
nnea
lee.
e a e
< A a
" m mu
m,t enr
e,e Q
e du<u
a et
ir "c
> >.TRm a
" ce
ie cac
fE e
nmer P.
Syci=
.h a/
/ >pf <
e s
<. Sk
m ri ae
/ w s
efp <
at ftL
a mfe
e <<
p< / e
i . a Nh>
m o at_
aa r n
<d ct.
c. em
.erne.
t/ oc
m " nu
o ti
c ..
:c >rp/
g eDa
tyn( < i
c nu
pc
iSnp mvMr
a mTm
u" e/tr
tn r/
.y <sme
a erSm
S3 ptv "o
tps ni <ReI
c"r.f
ruf=(f
t ..
r n [e
bim mu
t w>>S
r tmda
: t u.
>xtmen
>m a>" Vu
uiT< <
e e
hFw/e
" ye cee
lf wi
/yW rm
< ts
Mo<
a my<
Sne ua
ng <
t<rc s
.ne=em
>i."t m
S. =" e
(ySa> u
e yTat
r. l j
cs s
< .
"a" lSaye
, .em
/ iTsy
tda rb
ivta li>
h mme
mTrt p
Cr"e r
ccf agrr a
t kI /
"eep
m tn y
< p =
aa sn
tecLr"
o. C
[ac or<e=
m>l e
a/ac u
= "mP
a e t
<b .
oy" c
e b>o
/lrmTye"<
< p e -
o eyt
(e mTTd>
cmeOeCr
S (s
oSeho
ntne i T
yeAl
se <e n
/"<=tn
<> " kr
r
<mt r s
r ex
> n
sy I<ri
a//o.o n
aCe =so
hpP I
iana i
ip p >
s>" ".=
eG
cSe"ey "
he.E )
i /E.n
>)g t.
etVl .mcs
rusa le
elmg"
< e s
,e x"
yp r
a< sm/
m.te<"
.< =
. gscpx
ry Sco"
gn /
.l w
s tCl
n T m
TPC
r
eeE O n
c A:-
.x 1e
.m CE<
x "P I o>Scncs
e a e
oe c<c
e .are
r o m
n " t
eS ifea
s <
m n
f y<
snc" srn
t m<d
"orsy
ty/m
" lde
" S r r
e n"
P c
t =eA)b
e > l
>t<"m s
Si, sr
rt/
ug A
m pae=Ton
ar SE u<
cIlag r
.ma y
< < m
es"::r
ea c
md seu ee
e ,emre
<
iedo Ca
au"om t
er cy
.e. `
ca >
nle
" mme
"axc eo
ee
s>O P Rk
.sys ua
rttnmm
rmim
s gc
ce fat
Oo S e
x ee
y
u ecp
an"nt
p n
> m
l r.i
te>nco
t>e
San)
fy s l"P
r"lpoK
zm c e1/ =
<I =m
pe> o
fn o a
.ieim E
r u
y Gte n y
en. ms
md 4 eS
(lP.su
mem p
ec a>
Imse r
>e t. >u
IF f"> a
/"> =tye
te T
e/rf =
i i
"ypS
e l
x Racu
n ,a.
e.rn.
m Sa.<
z n e
.lfo/<
r I r
ymt T >
.L mca<
"p <=
S mn
Shey cm
e c m
e.tr p
ra imyr
eracr
p>urin
a .h"<m
<my"
t oSa
= r f/e
rv< .yT nl "/
rI u r >
t / OC
ppmT p
m pt :,
gu :min c
S-/ "e
l r "i
e/elrmp
" /nt/
gcrNt
Sspibt
<dSssM
ou /m
pr/s>
"S o /<
t m I
e a i
u tt<wl
n pe
xnm md. "
cC
c ce
c am
ya<m m
,h/ m
Bsm<r
ir .f
L<> x(e
ct
SyrS
smn raj".D
aoe e
> > e>i
t.a /A
uS C
emranwr
.g u
nnely m
tr e > g aa
rk?II
@=@FFFF
<paramref name="right" />;
<see langword="false" />.
</returns>
</member>
<member name="M:System.Reflection.ConstructorInfo.op_Inequality(System.Reflection.ConstructorInfo,System.Reflection.ConstructorInfo)">
<summary>
<see cref="T:System.Reflection.ConstructorInfo" />.
</summary>
<param name="left">
.Collections.IDictionary" />.
</param>
<returns>
<see langword="true" />,
<see cref="T:System.Collections.IDictionary" />
<see langword="false" />.
</returns>
<exception cref="T:System.ArgumentNullException">
<paramref name="key" />
<see langword="null" />.
</exception>
</member>
<member name="M:System.Collections.IDictionary.GetEnumerator">
<summary>
<see cref="T:System.Collections.IDictionaryEnumerator" />
<see cref="Treach %d Gran %d Bel
Unknown exception
bad array new length
string too long
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
[aOni*{
~ $s%r
@b;zO]
v2!L.2
`h````
xpxxxx
(null)
CorExitProcess
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UTF-16LEUNICODE
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
c:\Reply-quite\Cry_Country\523\Gave\Color\shape.pdb
.text$di
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
shape.dll
Fatreply
Periodwait
Seemprove
VirtualProtect
GetSystemTimeAsFileTime
FormatMessageA
GetModuleFileNameA
CreateProcessA
GetCommandLineA
GetEnvironmentVariableA
GetTempPathA
GetWindowsDirectoryA
GetCurrentDirectoryA
SetFileAttributesA
SetSystemPowerState
SetConsoleCP
KERNEL32.dll
PostMessageW
EmptyClipboard
GetSystemMetrics
DestroyMenu
BeginPaint
InvalidateRect
ValidateRect
MapWindowPoints
USER32.dll
CoInitialize
CoUninitialize
CoTaskMemAlloc
CoTaskMemFree
ole32.dll
RegCloseKey
RegCreateKeyA
RegOpenKeyExA
RegQueryValueExA
ADVAPI32.dll
WSACloseEvent
WSAConnect
WSASocketA
WSAWaitForMultipleEvents
WS2_32.dll
CloseThemeData
GetThemeFont
UxTheme.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RaiseException
RtlUnwind
InterlockedFlushSList
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
CloseHandle
CreateFileW
GetFileType
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetStdHandle
ReadFile
GetConsoleMode
ReadConsoleW
SetStdHandle
WriteFile
GetConsoleCP
MultiByteToWideChar
SetEndOfFile
SetFilePointerEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineW
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
FlushFileBuffers
GetStringTypeW
GetFileSizeEx
HeapSize
HeapReAlloc
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
0"0T0Y0_0e0k0q0v0{0
1!1'1+11151;1?1E1I1O1S1Y1]1c1g1m1q1w1{1
2#2)2/2\2b2s2y2
3(30383>3C3L3Q3X3_3e3k3q3v3
4!4-4>4I4R4W4]4f4l4q4
5(5=5C5I5P5U5_5
6#6*676<6I6Q6V6c6i6
7 7)7/777E7K7Y7`7j7p7x7
8 8.84898D8R8d8
9*92979<9X9i9o9
::.:3:9:[:o:
;';=;C;T;b;t;z;
<<2<?<L<R<d<i<
=3=9=H=M=W=h=p=v=|=
>$>,>l>
??2?7?B?N?T?a?h?t?y?
0!0'01070=0H0O0e0k0{0
1R1\1a1o1
3:3@3J3O3i3
?5J5R5X5k5}5
6*63696G6\6b6h6o6|6
8"82888D8J8R8^8{8
9/9>9D9L9Z9`9n9z9
:!:*:0:A:G:P:V:]:c:j:v:
;%;+;9;@;F;P;U;g;z;
<"<.<7<=<P<d<l<r<x<~<
=&=,=5=@=S=Y=c=i=s=y=
>#>,>;>C>I>O>U>[>a>
??%?*?7?_?r?z?
00,03090E0j0p0}0
11-141;1D1K1X1^1k1s1
2&2+202^2y2
313A3G3U3\3b3k3q3
4'464E4^4o4{4
55%53585E5K5T5\5h5
6#646=6P6l6r6
7!7'767?7H7a7
8*838C8M8S8[8g8n8w8
9*9=9C9H9O9U9^9r9
:":N:\:c:n:
;.;5;@;W;];k;q;w;
<"<-<D<J<X<^<d<t<
="=.===F=W=l=r=x=
>0>6>D>P>`>
?%?,?F?f?o?
0"040M0V0o0u0
1%1-161O1U1d1q1
2 2*2>2W2h2o2
3 3&343;3H3M3X3^3r3x3~3
4+41474H4_4e4s4|4
5"5,52585>5C5S5\5u5{5
6"6-6D6J6X6^6d6|6
7!7,7>7S7_7m7t7{7
8!848N8t8
9@9P9V9d9k9w9
::):/:9:>:V:\:p:
; ;:;@;M;Z;_;j;
<<;<B<I<R<^<d<m<
=&=-=:=G=L=[=c=
>#>(>.>5>;>@>G>M>e>k>p>y>
?,?2?<?D?Q?W?\?g?m?y?
I0Z0b0|0
1#1,1?1D1P1V1c1i1w1
22%2*212=2D2K2T2Y2f2l2
3(343A3G3L3W3
4"4'4-494F4L4b4h4v4
5+51565<5H5Q5\5d5k5x5
6'61666<6F6O6Z6d6l6{6
7'7:7C7W7k7
8$878I8U8]8c8i8o8u8{8
9#999D9`9i9u9
:):=:J:a:
;-;3;8;A;G;O;U;r;x;
< <%<+<9<?<M<S<X<d<j<p<v<{<
=(=B=K=x=
>%>I>O>\>g>m>s>y>~>
?!?1?7?<?F?L?X?]?c?i?u?{?
<0G0M0X0g0m0s0y0
1'10161G1M1V1\1c1i1o1x1~1
2$2/252;2C2Q2W2e2k2t2y2
3"3'3,3T3Z3i3o3z3
44%4*444<4F4N4Z4x4~4
:8:I:l:
0B0O0Z0l0s0y0
1+161?1E1L1R1f1p1|1
2-292?2E2K2Y2n2t2z2
3(353Q3W3a3g3r3y3
307D7T7G8M8l8
;!;T;^;l;
>#>*>2>:>B>N>W>\>b>l>v>
?!?(?/?7???G?R?W?]?g?q?
0&0-03090
2*20262<2B2H2N2c2x2
484B4[4d4i4|4
5%6/686A6V6_6
647G7e7s7!9X9_9d9h9l9p9
<$<L<Z<`<{<
=!=-=|=
6%6+6R6
:5;@;Z<a<
=$=0=?=W=
>6>@>L>Q>V>q>{>
F0c0o0
2<3V3e3s3
4#404>4L4W4m4
3>4G4_5h5
7"7&7*7.727J72868:8>8B8F8J8N8R8V8
`3h3o3Z5
5>;?=G=~=
99V9]9g<
>&>Q>X>
#0'0+0/03070;0?0C0G0T9[9x9|9
>=?B?I?o?
3=4\7{8
9p:t:x:|:
4$474A4_4j4
6)6A6_6w6
8&939B9W9a9t9{9
;#;4;F;U;
000@0E0O0T0_0j0~0
2#2=2v2
3$3)3U3f3k3
8+8C8J8k8
9?9T9d9q9
::8:I:S:u:
<9<@<F<M<R<
= =%=*=:=?=D=T=Y=^=n=s=x=
>!>->A>W>}>
?&?+?0?M?q?
00$0?0N0Y0^0c0~0
1-1?1U1Z1_1
3*363D3e3l3
/090\0f0
5E6^6c6l6
8C8N8X8g8o8w8n9
R0X0j0u0
<=6=_=z=
0*01070R0Y0
1X1g1u1
11282x2
2/3<3k3w3
<B<_<~<W=
<F=M=T=[=u=
0'1s1|1
30454;4@4O5
6777U7`7
72878<8A8S8
9L:T:l:z:
=)>?>c>
0u1p3u4
?)?;?M?_?q?
<)<><T<
022F243
3<;D;{;
246;6B6_6
2"3(3;3Z3f3
;-<G<T<
2*222O2_2k2z2
474T4h4s4
667V7f7
9m9x9~9
;Y<k<}<
>">3>a>
2e=i=m=q=u=y=}=
1!2D2a2
6 6$6(6,60686<6@6D6H6L6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
0P>X>`>d>h>l>p>t>x>|>
80<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0 0$0(0,0004080<0@0D0H0L0P0\0`0d0h0l0p0t0x0|0
5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
6(646@6L6X6d6p6|6
7$707<7H7T7`7l7x7
8 8,888D8P8\8h8t8
9 9,989D9P9\9h9t9
?$?,?4?<?D?L?T?\?d?l?t?|?
\1`1h1
2 2$2,2D2T2X2h2l2p2x2
3,3<3@3P3T3X3\3d3|3
8 848<8D8L8P8X8l8t8|8
9,909L9P9p9x9|9
:4:8:@:H:P:T:\:p:
;0;P;p;
<0<L<P<p<
=0=P=p=
>0>8>D>x>
?8?X?x?
282H2X2h2x2
9(9,9094989<9@9D9H9
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
IND)ind)
(null)
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
((((( H
((((( H
(
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
CrowdStrike Clean
BitDefender Trojan.GenericKD.46602191
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Win32/Spy.Ursnif.CG
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Sophos Clean
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Ursnif
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet PossibleThreat.MU
BitDefenderTheta Gen:NN.ZedlaF.34790.Bq4@a8prUll
AVG Win32:Malware-gen
Avast Win32:Malware-gen
Qihoo-360 Win32/Heur.Generic.Hx4CdcQA
No IRMA results available.