Static | ZeroBOX

PE Compile Time

2020-03-16 22:54:04

PDB Path

C:\gevokulagaba.pdb

PE Imphash

e4703f951d731209d4eda0f101cdb509

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00073c91 0x00073e00 7.96750151874
.rdata 0x00075000 0x0000481c 0x00004a00 4.39386132299
.data 0x0007a000 0x02837cc0 0x00004400 1.32658428834
.rsrc 0x028b2000 0x00019a60 0x00019c00 6.59029849622

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x028cb400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028cb400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028cad90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_DIALOG 0x028cb690 0x000000cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x028cb8d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_STRING 0x028cb8d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028cb2a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028cb2a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_CURSOR 0x028cb4b0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x028be198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028be198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028be198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028be198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_VERSION 0x028cb4d8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x475008 lstrlenA
0x47500c FindResourceExW
0x475010 LocalCompact
0x475014 UpdateResourceA
0x475018 MoveFileExW
0x475020 GetCurrentProcess
0x475024 GetUserDefaultLCID
0x47502c WriteConsoleInputA
0x475030 GetComputerNameW
0x475034 SetEvent
0x47503c GetProcessHeap
0x475040 IsBadReadPtr
0x475048 GetConsoleTitleA
0x47504c ReadConsoleW
0x475050 ReadConsoleOutputA
0x475054 WriteFile
0x475058 CreateActCtxW
0x47505c GetVolumePathNameW
0x475060 ActivateActCtx
0x475064 GetConsoleCP
0x475068 GlobalAlloc
0x47506c TerminateThread
0x475070 ReadConsoleInputA
0x475078 SetConsoleCP
0x475080 GetFileAttributesA
0x475088 lstrcpynW
0x47508c GetConsoleAliasW
0x475098 WriteConsoleW
0x47509c GetMailslotInfo
0x4750a0 CreateActCtxA
0x4750a4 GetCPInfoExW
0x4750a8 GetLastError
0x4750ac GetLongPathNameW
0x4750b0 SetLastError
0x4750b4 GetProcAddress
0x4750b8 EnumDateFormatsExA
0x4750c0 GlobalGetAtomNameA
0x4750c4 BuildCommDCBW
0x4750c8 LoadLibraryA
0x4750cc GetProfileStringA
0x4750d0 GlobalGetAtomNameW
0x4750d8 SetSystemTime
0x4750e0 SetConsoleTitleW
0x4750e4 GetModuleHandleA
0x4750e8 lstrcatW
0x4750ec EraseTape
0x4750f8 VirtualProtect
0x4750fc PeekConsoleInputA
0x475100 SetCalendarInfoA
0x475104 EndUpdateResourceA
0x475108 FindFirstVolumeW
0x47510c AreFileApisANSI
0x475110 VerifyVersionInfoA
0x47511c HeapReAlloc
0x475120 HeapAlloc
0x475124 GetCommandLineA
0x475128 GetStartupInfoA
0x47512c RaiseException
0x475130 RtlUnwind
0x475134 GetModuleHandleW
0x475138 Sleep
0x47513c ExitProcess
0x475140 GetStdHandle
0x475144 GetModuleFileNameA
0x475148 TerminateProcess
0x47514c IsDebuggerPresent
0x475150 HeapFree
0x47515c HeapCreate
0x475160 VirtualFree
0x475164 VirtualAlloc
0x475174 WideCharToMultiByte
0x47517c SetHandleCount
0x475180 GetFileType
0x475184 TlsGetValue
0x475188 TlsAlloc
0x47518c TlsSetValue
0x475190 TlsFree
0x475198 GetCurrentThreadId
0x4751a0 GetTickCount
0x4751a4 GetCurrentProcessId
0x4751b0 HeapSize
0x4751b4 GetCPInfo
0x4751b8 GetACP
0x4751bc GetOEMCP
0x4751c0 IsValidCodePage
0x4751c4 GetLocaleInfoA
0x4751c8 LCMapStringA
0x4751cc MultiByteToWideChar
0x4751d0 LCMapStringW
0x4751d4 GetStringTypeA
0x4751d8 GetStringTypeW
Library USER32.dll:
0x4751e0 GetAltTabInfoW
0x4751e4 RealGetWindowClassA
Library ADVAPI32.dll:
0x475000 BackupEventLogW

!This program cannot be run in DOS mode.
`.rdata
@.data
0WWWWW
0WWWWW
QQSVWd
uBhYe@
0SSSSS
tNIt?It0It
t h$[G
>=Yt1j
j@j ^V
F\=@ZG
teh`h@
HtHu4j
s[S;7|G;w
YYh4[G
tR99u2
0SSSSS
0SSSSS
tRHtCHt4Ht%HtFHHt
URPQQh
0A@@Ju
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
GWh(dG
t"SS9]
FVh(dG
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
)c2q'
I1i0wd
]TX6lN
\??3/.
q7<&&3c
eFt^V*
1IxyVu"<
i]lo?M
dOZ+LZ
;s<|+h2r^2Z
O&R~k<2
[O<eiP
)1!MW
\_qR[/
:q/)O0Ym#
LfRh,A
<lJqkC
@(Mm~<Iq
C_|y)/
T\+.{W
{u8~>F+c
FBVH'4
]9shSaO
bhNiig
wTPU6O
mR@!g'H
:MGco]
CWRy0C
*z9+/l
!R4||0
~bD"j"%k
v\fF^P
w6_k7D
t6/o\R
5$l"Wk
zv(99hK
It?o]~
/'khk\
ldv,db
WHO;4$
[mH,![w
\racO`c
r]HHM
:=f1Tm
FLR+s%A
5{V2tE
2??"38&
6oBuhj
F hOV@
>'pUni&\
8vDs(>
^zR^$=6
:{>;}_
]+{FD)
53I,@h
o+>nhX
6~yD'X
}v":y&9
XgG#QY
$ wRzD
|IeVGO
+!&GfA
|6IkRn
j$?yZ&
IpS=Q^ZE9
<NJ:rdO
"E!:5uV
xh^O.Y}g@
z^sut
X7gB4-
L0%+i$
f](OgP
0~Dk_ZET
HH}E@|}f
fFrX4^A
,lqzUh
rD^JI
VbpN&k
*e5{`+
_Wak+/
ZwaPhG
M)S8_
?'#36H
uaj 4}mz
_dR7e*
HsV%G;
'{ZPK
BH=p6*
3:Hs)I
7:(:eb
[PNxzN
,o`DN$
Yc87GA
]C|!s$%
A>hw}wy
<8,)$?T
m:0N<:Q
Zdflh1
L{>e`h
`JCiH[B1
4+C\[{
)W3~sU
UQN02D
,^nd`z
za:wEl7
[%/2EA
_O~P@(
x_Xtm?X
#*>7[,
X'Ki>
}zzFcg
yZi k+
Wqs6/)
%B?)W,+
f]A4N
e(Tp(U
7\QRZ
ggi]:+
{DKw+?
:?-Ith
.vvpr&
=V7X2Avc~
6;54]<
*Sw0J?,
' ##0E
E0r+lb
q8uREj
Me$Vz4
jA66rQ
w|oaLj
QP&m`w
e^Bo.l
IGVuk4
=ThD [
a*{shS
Wc>OH+X
d!vId01
Z.QYh
8 bXb2
f,7mN]y
}YSS/
Ay;T@'
dalJkR
j!w1<t
E`MS/07?/
^^dr1:
Tsz):
y,o{S5D"
\_eDiJ
QpC[M-
9%aq<m
/ wLr
IRR}0KnNOv
oCQFwSE
|<Y0/N
w|)0?C(
9Z!B,E
*X;=Rg
WhE)?Y
i8uqZ,
VHrfT
|]ibbp
+Poqi1q
<&mRUaU
.G:n&t%'I+
mIrh^}
v[Z(G*
wf0m^z
jb?(5m
AuoG"]
OVNbg~
#9OhPz
Q$9;+j1p
^^#|P.N
N5xqid&
zxjn0?v
8R1s]6&
`hFE!/
Box+5j
flie!<
Tuv_k&
`)JWu9
(@RqMX=
P~EoDR
l0,Fn?
1Fz0Cqp
vtleq[
{+2WAFY
4B@=]P)^
hZi3iW
^d?B<D
XA/lLC
$hMEv@
juN7X8FO
Ex^y(k
)==c8e
FB`5C_X
U8:~#H
>WaI#Y
L"n_paKg[
j*@I(
|l ER#
a3IMI.&v|
]ErM}0
xj9OE"
XA;$)!
'=^pyDxx
-Rj,qP
oJKph/K
t1:Ok
b.&j57
p*,v2[
'+?qEGe
@<7#kLz
:-t]O5_
&='xJPe
],#L<<
VDDT,uH5
eB[5w?
FNgz"|Q-Gx
HLL)T7
@UF~&i
~#/~v{B
Qn.ptf
]E 1&$%w4
x/(.4g
Vr]X]F
7g>otw
^9<EIl
&Fe[Qk
{2/\!s]
MKg9oi
4g.RZ'J
x{u^2"
YW$;PX
{/I]:^
L.mmin
Y6DQT(
&l3k/
*"hXt-
P0< MP
nU|n[N
6O1Z^Hq{
;q@.F|
<|.S^v
,pP{Ne1
ibM%|
ny~QZo
(b`$o{
*g ;??%
mHQE,E
.8.?d]
xR6qSIA
Y(k|lAO
\aM.:4
i3092$
s,4UE)
4X2+Mj
EJuL<j>G
|/TT%su
y<$]4^
oVDqv*2
e;VAz
11QdZ*
$&QEkP
C+|\o`
,<?{sV
dc3w@'
{v'5GMRNB
N3SzNC!F
JDqvJLw
h>&W8E?Hmrw
AE<FnS
3~Xe2j
A<:T.+k
lQY|nn
@4DnpCuK
LZpYNx
U&Ct;q
vNcjh.4
JD'q98
=Ovte;
Plf)Z-
N-U?,q
xr(Y|w
t<AtN-
|kl2^NX
u9{=651
cyN5KtN
lB?8/T
rT)okT<
m)dJ0t
NoT$U\M
V#?U{O
J>+m7|
Z|!+
Cv,aT?
&-:h{.
r:;6LZq
BI"v|b
B"9GG
;G,IwT
$A_1_f
bP@#U#
7^PoP6%
]aeyQ-R
v\aoM^
auLZ?)D
?n<!q=
1.RMNxdv
PmV;0,2
i.Z.VcR$y
Xm(4AY
D>i'!l!
^>I^zt
>u6;
9/Fa34
Jvg2~;
K)T>TGc
L\(KW_
wy:FA0
&G){h7Mj
03m+&L
C&6%fA
#2'mRh
7XEb4\
(b=.mG@
3H5*qxO
qr-60i:
N/eZ"!
$H_a07U
v]N>t"l
Y6_6yv
(LSb9kc
7}(+A*
aH"X7l
94URcO
ih}~Slrr
i5bs+J
na8.#!
a\UuZ0w
c8Z>,}L)
McC,]m
(ihgJX
wnOX2%
G.MOnyASC
1LLLV&;
<1+^R
kN2&"b4
|Z_K<c
ZeOk19
l|![$l
Fg39VC1
7wZr`
-!7.g)g
Xv7X8R
9ui0u7d
!Sp.|u
jzbNNT
U [NMt
e$WzG[
"ni{9UqV
;2-T)c
2DDr==\
~d\ $&
T46'(`%
HA%,0YUi
[8PAO
K2z}*Y
WXlzK
mom`5i
,VpXib;f
^:(1h ?=U
+@vHD$T2
7u({qk
FOKz y
PSac]M
j"*}9)
SkaBB'
0&H7c^Q
|XjsCv0
kwn$@~
Sla9/F
/1Tqr:
jc"tLb
Q4][f_!!
VYLlz-!C
R&R#1`p
-ix 0Ow
!C=e12:
d8Qki5
hn6e+#3Xb
9^j|aVm
"BCUe|
I&)X}pj
Ntc/`V
v~,.O+O
c%C5:+
GzP-W`,!|w
%X^dt_l
ST*v}r<
T jt4u
~-eO-9
IG_2"d
m)G&lDN}3
3(/?juD
ia!"r!
j22ZL9?#E
~$7@#N
;57E[Gw*:
(6o+kM`k
(MknkB
4HR,OB
H}goW-n|R+*
i_tp{-
j}S)7<s0s
&6-`]'nr
Qc@@kBP
zc@ipp
Iw?+iSi
m-LvsA
C$H{q6
s~%_O'V
J{f1uo
F>0,pw0#uV
MkH2l)
yHAPWU
3^=-"d}
ZXIfrc
[$0E-h
2|nieW
sJXs(%
dOd%$X
CZSY1p
$,N.d5N{slx
UN%11H
!rjaY@
nL=6B5}
qWk3{t
s2+}jj'
Q3^zs;
[@s+'.
s/8rfplV
i`pM *I
'T=BD?
}SqI|G
q%h!FxYe8
N;!d=0
5Sb*!d
M'=SXR
!aJ"p>?e)g?
pFz}/C
N]88zL
}7pN*-
}"LIvD5"zu^
w%47cO
Sg0|r})D
<gLX(W
pk06R,
84Dq7R
os>q)=
vx$2pG
+@@^[z
0}B">l
;/;+!:<
Eg,l+&k
cJUcK&
%`&4+.
lkw^k
kgrC)[
k#BMTr
YC!!|U
^oNV3c
QqB_TE
#=5FM v
pbwfH1
Qr@h Qj
5(u^0iF
9@A!8k4
8z O$b8X
WrZn0d)N
m5'Z8P
AYq2Ta
l'h>T[=!
$ry3%7
%^xjf]
"y,:1+
3~ _2R
)6pQ+-
Qv0"cF
hz5WGW
U'4/"x
pfSeje
WC& $:
N\tiwN
`FI#Dtl
un)!`5
GRha:x
qON40ln+{
7y<J p
aLphOK`
{|QfnD8
i.K>zo
lw+ZYp
.Y#q6~72
[g'{1B$bZ"p
H5bifZ
&Ja~on
6>?h+q
EFCUaZ
`lD#+#
EC(<c[W1
gwd`eH
4AV}'b;
!Vm&_k`
O3x\jb(
zBEcR7
n}spmD
e~7L5P
#Z&xsf
'l}u9R
yz($8C
!W})<Ty!
fZ,gCi
i~1+ 7
|psSbm\`
T.^zS[w
OV1%}P
Ph}<SUJ&
LB0p}
{}s>jV
j}He<j
<kz=fP
N<tJt/
XKS2,y
q&Y@wh
nVsz/t
#E@d@$
@EpF5xo`
}q]jdW
LL~O[sE$
9@)wOG
sC0P/U&G
rIDZNK
$_ru8\
y:(I0A
)6ZZ\4
5Ih\95
gL\sT;osb2Iv
L0QO+
g6'O<O
W=-}Qf
ZW7`@xT
)M1Fv@
7!,f7c-o
l&td1WHa
D'u_=&
";IzV}G
T3Ss6L
8ty<F%
DI4m*E
LK%MSV
6Ir@g[
&66D:z
wY^xOG
Fkz0cB
i\hWB5e
4ZOZ5
!-h36waBiO
*:SItF
D6)u*q
TB%Tiyc]hh
(J[Gj1
%lUwp/
2gmC0j5{
u"cMsB
(_/50i
cO7Z$,<
UMnNlv'
s9?n>
_fJ%X
~$OU!>)x
YRi(@~"
;OKx#P
w=N>n8
Lf?@P_
fO+jL_
uPTT?1
#|0/#/
B8`l}%
uN=%$&
)^2MV&
bsVIpR+)90
U)FY%n
m+jm'0
l+^}N'>
H~Uw`x
o6YmQ*
$FB(#9
br/FPi
|XMf]
l=Ze1,
~j3~bC)z9z
,n8m2#
^zB4Ks>
8;]$+J
qc!`U}
X`YEv}
v??V6Eo
Tl_-k+
R61@xd
3cSkPJno
6iy=v05
D?JM\2KV7
cN, *+HH
EN=@QQs
Js&0#1
Du*!g%2
lzO#,&
TLw.[_za]F
j5m?p3e
}7$$3p7l
tgWu*S
2GDGQf
&>!iW
]GHK7T
a+#tj:Y
7d[="v
q\?=e>
0f8PoNM%\,
7Z=G\.3
*V5?dW
2FcO.t
]wM~SZ
./|-|k
Kz3pA}
|?EZc6
sCOzKU
%AX,8J
RQf7
6!{D`+
?U`C>
nRAR'Y
F90P1G
/P9wRp
-67O_*
zb?/5/
z*BUYU
zQ rQ:
wOj[Q_=
cOM;Zj
d((^=O
;T3lJTTa'
:Jhit_
/J2w:1
!4.Xcp
zK&? $
<_>`5[
FALz{;+O
^LIgZ7u
`D*cn+
3(0UJ1
`JP\B<
"V9M3o
]&KOsz
|F.}*|k
0C.%a1
XKI?`O
"-{w#b
CKYlse
Q_X)481+
K26A0}
"j1\xb
}DJO61
IgS>Ls1
{A!jU{
w"~&;,
tde{u8
2!L{07
EV%*aI
}{H'Xm{
Vk{g;wf
b;tIvmuC
W\`sT<
h_YH}
Rg5{!C0
%izu5#
^'ZXP"
W5JlYC
@0sf3%z
"55(|zQ
.a$bmh
7$$N}5
j{+'V3
SrRCGO
8*O/<v3
F^kCx2n
uZ`I'\
5u3e<a
Awh`bN
.=TCY?x
`7&{<d
eCP1gT
>}G1qK
0JC H&
f~=;A"
{S}"Jl
(c\g"}
LbFf<u
`#E~TR|;
4]Vbew
O8YFea
K+&E>;v
xk4V@)
/xrG-?>
46sc<"aR
/"j`3k
|!AaC1f
dDu`y
<^K=g@
iUPF
0J_I8y
e@Wr$K
/c^qxO
"Gp|CYj86<
m6Kw3:l
N-AaRgn
>CCu80z
Nc+rse
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
Zab xeyilipawemeliyovadusekelu bevusibivi
pabewitoholezugi
mogujurocozesimajiraxoyumi soyuwiyaraxikuhepofakobe lonojekuvumo gilamepayixehud xusexutanadojezafezenisasoxo
nixifalonexedoco fej payaseyemecob vem gevayasoketicepiyiz
doruligiyuzujecedupuri hicacotayapitucajuf huzizuhelayupupewepuj yov fowugenititabivecah
logumenocox
lukekif gonezexebiveyoboporud javezadiliyijegasagemuvetec jevucisovowegiyabovoroxaxizamo
tagavorifa
kernel32.dll
LocalAlloc
C:\gevokulagaba.pdb
WriteConsoleOutputCharacterW
lstrlenA
FindResourceExW
LocalCompact
UpdateResourceA
MoveFileExW
InterlockedDecrement
GetCurrentProcess
GetUserDefaultLCID
SetConsoleScreenBufferSize
WriteConsoleInputA
GetComputerNameW
SetEvent
GetSystemDefaultLCID
GetProcessHeap
IsBadReadPtr
GetConsoleAliasesLengthA
GetConsoleTitleA
ReadConsoleW
ReadConsoleOutputA
WriteFile
CreateActCtxW
GetVolumePathNameW
ActivateActCtx
GetConsoleCP
GlobalAlloc
TerminateThread
ReadConsoleInputA
GetSystemWindowsDirectoryA
SetConsoleCP
InterlockedPopEntrySList
GetFileAttributesA
DnsHostnameToComputerNameW
lstrcpynW
GetConsoleAliasW
SetTimeZoneInformation
VerifyVersionInfoA
WriteConsoleW
GetMailslotInfo
CreateActCtxA
GetCPInfoExW
GetLastError
GetLongPathNameW
SetLastError
GetProcAddress
EnumDateFormatsExA
EnterCriticalSection
GlobalGetAtomNameA
BuildCommDCBW
LoadLibraryA
GetProfileStringA
GlobalGetAtomNameW
WaitForMultipleObjects
SetSystemTime
SetEnvironmentVariableA
SetConsoleTitleW
GetModuleHandleA
lstrcatW
EraseTape
CancelTimerQueueTimer
GetPrivateProfileSectionA
VirtualProtect
PeekConsoleInputA
SetCalendarInfoA
EndUpdateResourceA
FindFirstVolumeW
AreFileApisANSI
KERNEL32.dll
GetAltTabInfoW
RealGetWindowClassA
USER32.dll
BackupEventLogW
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapReAlloc
HeapAlloc
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
HeapCreate
VirtualFree
VirtualAlloc
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
#gzwg]
B5e 5e
4[e eB
2gZVe)
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQ
QQQQQQQQQQHu
bQQQQQQQQQ
QQQQQQQQQQ
PXN]QQQQQQQQQQQQQi
QQQQQQQQQQQQQ
|sQQQQQQQQQQQQQ0
QQQQQQQQQVkU lJ
QQQQQQQQQ
QQQQQQQQQC
QQQQQQQQQ{
:=|c#.~
12~s$3
O15~~)%
4OM}wE<
6RYrI1-
IOl8.=
SZ{wC=
==e__XTGc
g@Ch+4O
/Sf?$u
S{~:1~
&Bu~j*z
Ruz%1HpN
+:e='u
Co~;%}
G:e{t1^
KKKKKKKKKKKKKKKKKKKKKKK
nnnnnff|
laaaaaaaaaaaaaaaaaaaaaOl
aaaaaaaaaaaaaaaaa
lllllll
llllllll
JJJJJJ
LL{{{{
BBBBBBBBBBBBBB
wwwwwwwwwwwwwwwwwww
KKKKKKKKKKKKKKKKKKKKKKK
GGGGGGGGGGGGGGGGG
hhhhhhhhhhhhh
%hhhhhhhhhhhhhhhh%
hhhhhhhhhhhhhhhh
%hhhhhhhhhhhhhh
44444444444444
{{{{4o
;ooooo
GGGGGGGGGGGGGGGGGG
-----------
ccccccccc#
88FFF888
66666666
????#f##k#
--------------
VVVVVV
IIIIIII
IIIIIII
IIIIIII
IIIIIII
VVVVVV
VVVVVV
{ttpo{t
%!$bear~
3A6$^gd|}~
""""""
""""""""""""""
"""""""""
""""""""
"""""""
""""""
""""""
++J|EE
1111111112
lWWWWWWWWWWWWWWWWWWWWWWWWWWz
uuuuuuuuu
uuuuuuu
uuuuuuuuuuuuu
uuuuuu
uuuuuuuu
uuuuuuuu
uuuuuu
b=tuuuuu
b=tuuuuu
b=tuuuu
111QQOORR
p..VVF
pp..VVF
ppp.VVFF
111QQOORR
CCCCCCCCCCCCCCCCCC
C111111666
QQQQQQQQQQQQQQ
yyyyyyyyyyyy
yhhhhh
yhhhhhhh
%%%%%%%%%}
%%%%%%%%%%%
#P~m M
6C`V&R
ssi"L
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
yehofidahecuverocig fehicezizatatonirewudayuzofazene luvenixovilowilig rehijatuzeha
xutupixoxatimop fed xifiyidatisonugotewehonil gapasimocelev vicipotidahima
hawedev rolozacadatawavisoni buravabucihuc bazokudezacukuhogiturutudalux
fihedodutawixetazifedolekuj kulojefacelivazedajiligojoj buvikudicerenicezaxinasom payeyigumubowi
yevufunuzusalarekis yap
xcehewitakivahamobivupujezogo jocojobojupeloxid dutisobatibeduvodotumovigetoxasu
gaxivodimusipaduritixorofajemusu
ERRORDIALOG
VS_VERSION_INFO
StringFileInform
081564c6
InternalName
kogsmoadeke.exi
Copyright
Copyrighz (C) 2020, fodkagata
ProductVersion
9.21.22.12
VarFileInfo
Translation
Error!
Select One:
&Retry
&Abort
&Ignore
YMado gal robu pew gituhivisowef domete muyiyazi yinapuxar nadugusasetisey kisobuzakucelekLLekup zareluwiyoj jewuh bikuvocus cato wapa cuwitehuxi sifutaf jetuvajepifes
+Sogatide ziyariruh wabirejegit nakiwapikuke
6Jifihuzayigameg wuxew tuy yobizigorupodi visugip pijes
VGozokapiyuyemo yexoj yagisowapunam pefuvoriconuc rumatohefin vocogilekuvuto xezevumive
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.8472ae9fabd1a6ed
CAT-QuickHeal Clean
Qihoo-360 HEUR/QVM10.1.233B.Malware.Gen
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34058.Lq0@a87sMNw
Cyren Clean
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HLZW
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Ad-Aware Clean
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.SoftPulse.jc
CMC Clean
Emsisoft Clean
Ikarus Trojan-Banker.UrSnif
GData Win32.Trojan.BSE.SL2CMN
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult.FW!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!8472AE9FABD1
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_91%
Fortinet Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.