Static | ZeroBOX

PE Compile Time

2020-03-16 20:52:35

PDB Path

C:\hox joxab\mahehabel\xatelibu69 wotuvudejuz\xol-yocufanukec.pdb

PE Imphash

e4703f951d731209d4eda0f101cdb509

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005cfb1 0x0005d000 7.9530073927
.rdata 0x0005e000 0x0000480c 0x00004a00 4.42689738713
.data 0x00063000 0x02837cc0 0x00004400 1.33357948747
.rsrc 0x0289b000 0x00019a60 0x00019c00 6.58336007706

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x028b4400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028b4400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_DIALOG 0x028b4690 0x000000cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x028b48d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_STRING 0x028b48d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028b42a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028b42a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_CURSOR 0x028b44b0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x028a7198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a7198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a7198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a7198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_VERSION 0x028b44d8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x45e008 lstrlenA
0x45e00c FindResourceExW
0x45e010 LocalCompact
0x45e014 UpdateResourceA
0x45e018 MoveFileExW
0x45e020 GetCurrentProcess
0x45e024 GetUserDefaultLCID
0x45e02c WriteConsoleInputA
0x45e030 GetComputerNameW
0x45e034 SetEvent
0x45e03c GetProcessHeap
0x45e040 IsBadReadPtr
0x45e048 GetConsoleTitleA
0x45e04c ReadConsoleW
0x45e050 ReadConsoleOutputA
0x45e054 WriteFile
0x45e058 CreateActCtxW
0x45e05c GetVolumePathNameW
0x45e060 ActivateActCtx
0x45e064 GetConsoleCP
0x45e068 GlobalAlloc
0x45e06c TerminateThread
0x45e070 ReadConsoleInputA
0x45e078 SetConsoleCP
0x45e080 GetFileAttributesA
0x45e088 lstrcpynW
0x45e08c GetConsoleAliasW
0x45e098 WriteConsoleW
0x45e09c GetMailslotInfo
0x45e0a0 CreateActCtxA
0x45e0a4 GetCPInfoExW
0x45e0a8 GetLastError
0x45e0ac GetLongPathNameW
0x45e0b0 SetLastError
0x45e0b4 GetProcAddress
0x45e0b8 EnumDateFormatsExA
0x45e0c0 GlobalGetAtomNameA
0x45e0c4 BuildCommDCBW
0x45e0c8 LoadLibraryA
0x45e0cc GetProfileStringA
0x45e0d0 GlobalGetAtomNameW
0x45e0d8 SetSystemTime
0x45e0e0 SetConsoleTitleW
0x45e0e4 GetModuleHandleA
0x45e0e8 lstrcatW
0x45e0ec EraseTape
0x45e0f8 VirtualProtect
0x45e0fc PeekConsoleInputA
0x45e100 SetCalendarInfoA
0x45e104 EndUpdateResourceA
0x45e108 FindFirstVolumeW
0x45e10c AreFileApisANSI
0x45e110 VerifyVersionInfoA
0x45e11c HeapReAlloc
0x45e120 HeapAlloc
0x45e124 GetCommandLineA
0x45e128 GetStartupInfoA
0x45e12c RaiseException
0x45e130 RtlUnwind
0x45e134 GetModuleHandleW
0x45e138 Sleep
0x45e13c ExitProcess
0x45e140 GetStdHandle
0x45e144 GetModuleFileNameA
0x45e148 TerminateProcess
0x45e14c IsDebuggerPresent
0x45e150 HeapFree
0x45e15c HeapCreate
0x45e160 VirtualFree
0x45e164 VirtualAlloc
0x45e174 WideCharToMultiByte
0x45e17c SetHandleCount
0x45e180 GetFileType
0x45e184 TlsGetValue
0x45e188 TlsAlloc
0x45e18c TlsSetValue
0x45e190 TlsFree
0x45e198 GetCurrentThreadId
0x45e1a0 GetTickCount
0x45e1a4 GetCurrentProcessId
0x45e1b0 HeapSize
0x45e1b4 GetCPInfo
0x45e1b8 GetACP
0x45e1bc GetOEMCP
0x45e1c0 IsValidCodePage
0x45e1c4 GetLocaleInfoA
0x45e1c8 LCMapStringA
0x45e1cc MultiByteToWideChar
0x45e1d0 LCMapStringW
0x45e1d4 GetStringTypeA
0x45e1d8 GetStringTypeW
Library USER32.dll:
0x45e1e0 GetAltTabInfoW
0x45e1e4 RealGetWindowClassA
Library ADVAPI32.dll:
0x45e000 BackupEventLogW

!This program cannot be run in DOS mode.
`.rdata
@.data
0WWWWW
0WWWWW
QQSVWd
uBhYe@
0SSSSS
tNIt?It0It
>=Yt1j
j@j ^V
teh`h@
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
tRHtCHt4Ht%HtFHHt
URPQQh
0A@@Ju
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
2Z{^w|
L=Cit{
($4x
b|WB}M
!/6t4S
"=OieH
BgcSf"
jT_M].
GHpP"e
Bc)*J+R
\.T?h;
:}C~?3
;ySi8W
0>R-3G
q~}2)R
`~"?eI
W5@+=?
mdR,;R
,8Dq=_g
AX(R#W
l1/5^o
G# Gzk
5C%4q5
_oG#ePL
~_7@2/M
R)%?K7|
?3y7GU
pq0Fumg&.
{s`8lp$
<wgYGM|
I0<ar;u
{8iVtP/<
(zIp|#n
y $)<&S
^'#Em^i}|S
e`hGoi>
EhMW[}
4l>yR#
o{K??u
0,v<vB
T@lZm
oDON\:
nb~i]K.
&[gYH_R'
v&:1uC
CLs5!Guo[
HLD572
T{67Yn
8'I"wX;x
2\*5*=b)PB
jRUv/4D{,
{F&{d,Z
:NRM{
CSdpx2uTO
=KHX|x
rgK`Z
pHs?8X
AnS:5-.
=B!9WDp
7kZSvo_T
]H6%)#9:.
5#4Jn-
fwi!E^
z2*c)5*!9bd
8"Kr-f
5,lO^V
0<-R%>
>7cwNj
6]PI8E
{9`4.y
F`+A@]
H}l)@=
pQt"<W
{{.S_?
@7mqj|
H8k1.F
|?k8z;4
_0V1Z&
I-u}0v
`-5QXw
P2NU3GU
+!{Ir0A
FqCmxn
;`1Oi1
jcjt|?
4P*RJ/o
GxYNIo
%d<4Ig
}kR57/v
yJA>W:
z]&%q,
,odj9U7
IL3y4E
DvvO)V
j@iYL]
un&V_2#
F3?n8
y7TQ$k
hOH j{
0IlZmN
eN5uGZ#
4/jt1yjBX@
~VJc=)
{e#)T %
n57NU.
h;QZK6
KdF?t
|IS<+f
O#/$|K0
#_^o`,
,yBn65
g1,PnP
Vp)8CI~
F@@fbl3
6]?wTd
@R%mLT
O7 KJ}
=Oz7uZ$g
1>>N'b%r
8/e$W7
X'oG|I
@pQ}&1|
0K&dvl-
FA2mi<
vV{w6e-g
YH"|]%
(v|r(c
:NL:dL
-2dI7
I/0j'/]r
u3Q!4*R
,_0aQEy
M/h)_K
Afc^Vq
nq3\@&
<<g6
[2.H.J
B.s*XN
( #p\W
92%_zm
kT([DRv
/7`;b.~
rO7p4C
A8~Lg5
gKu57'
c<D)9r
? r]%~
%a!)VWB
hY&]_n67;p
adT,T3
+9tS4]i
KHn|S+B
v@=t'_
g4BT*v
hXQ1M7[
7OVuj\9
a0BtV'
0Q;fT*h.
AmE(Go
!Jm=,/
#Ri"R{
s@/.eS
7nquy9L
3W"PZr
<6pB(n
vH,DNy%'
#t3<5$
Ky-8CQw6
Dz$>>(
%^!rIx?H
q64m;8
5{,@A<P
y*p,ryc
,P_,M5
OQ"Dbl
xj{Q)D
G"+vbs
lUFh38
!jj<)B
^~(=lg
n3RS\;X
>2*]Fz
~L8T<RPJ
:^A$b3
Q~O[aiF>h
bT^'S[
~6R$A
Tm9Lr%
u<W}LA
Z-?kb<>
f#g:gN
WT.ej1
;@T?eK
iOZEZw
mh+vbE
Aqyfv&pG
5]Z:t\
Z'fTsR
M)!hv^
^>z*CP}&W
F@IIvWcb
#3@uU`z
_a6zms
92xCEM
6W+1LB_
d(['/s-
cwW?(_$rB
c3b?!I8
d={4;3
\%WrYhT
HbT ch{
:Zxakw
Y2~g?!
c'Bkcy
t8ihio
av(j4o+
[iU3HV
Zp%8IL
$_QYiTgP_
-bN"vn
S+gftE,
])&PD/|
^7t*H F
{c%xlW,
HG*+2d
8|^HY3
8S <JV
CTrfPWZ
["1z`;
'q>3.F
(q&_J<
f-bN,Y
R_\$}0
*A}yj@
Bga(-"
6(jP#q
T,}I;!
hBVm)6
Owz]@h
^s8&,
R=6mTjG
N9BH>`
.%H:)'Z!
Af>WQF-
XRmYbO
cjo*Ut
tonV[m
~:Df1CW
M]a=<5`
^4*In'
,LMBpa"
G^yNuNU#Q
.]}Ovi
/_}!o8
~AjsxIj
I`n,WDn
y7Qs<z&
r!`v#5
T'?Lcll
o0{Lr>
~a%V*"
c]2;yH
D6>W:6
YLb5EJ
rofw|]M
spV[v?
9@ikaY
6pIccM
@E IBF
%_)nWoZ%o
kFH(`"
.dT&?R(
#Z]2KO
qbQ9|Q
/N~e`3
3h'NVa
M+Cc\+!
_7b5(
m^*0vH
'Caz'
4ZodNQQ
wM&Wfz
y9u#i]U
NUmrM_
P+,S!c
+mQWHa
FW(mMRZ
P*y3iU!
F{PH;A-
0-$+f6
UTeEaX2
+;%dWX
Wg_r,I
]R}%]*
vjv!]~
ge+m[H~
o!e:3dbP
xB}hjO
A*@/~ZGu
YQwI$a
C>p>)
V-\) 4
),`x/~
tU=%($
Aj{E[!6{S
1"B[0re-_
2n=];8
g=L1z"
>*=X}L
j~E}dSB
BN*103=$
Ol[iNb
.5p(aO
:|b`]N
/G>iHh
~ZGgE,
(GL(#0n
Kf&*<"
A\!vYB
k,f#j*
,C)H)`
QvazOM
ZRqde-
@AC4}zG%#
ohUUiW
M=hj4Z
&2rL"p
ml8%bL
`d.k:8
18{;JW
G(.A&W
D,]ws'
9A%,eF\
|dWdPKOc
UV3vId
~B R=P
FGR(7g
<3AqEW
N`>hl
l^SYs]4
)AN{>{
jXP5ogF
};r9ru
fJySUoSQ
=6~CG0
kJkj,A18
^\["lJ
;I90j(
_ZTBR2
:zq!2A
7S>I*'|2
jw=_N|
Zd:\,I=
J{+reR{@
h\KBb1
H_ztOHf
{wu,6v
!!s1DU
3}L.[c
5t+!/M
vPz:o
{\cKS=
1:))me
ohouoo#3
W&RXPH=
q=]FUT">~
]aKVdH\;V
X8yC'~{P
\6yWm1W
cu+j &
:5?[tBb
rr<*7R
!17dk#|
#O|02
6MGD2<
)?&&Xv
Q)*.H$
:2>115
MrIJt`
4Du?Ws
d:R*e
@@[<P'
Ao#uXj
!WWc4
*mP$EE
a.SZOM
*is9tHC
s;xF')
|B=6~'
+9;Lz)
zcASS
i]6#Gnn&
GlpCZ\\
aIZM.o
l?DrJtw
OsIg>}
ENR:.\>
3Nc^aV
@OW9rz
r>(o3B
T}#%JA'
L#F:6OrK
Otg!W(
rx9^Yp-
ZcIS'*
mU:'Tu
#I_=<m
e&#'$CK
\@Q.nOdX
?0|uX
MjbAy6
XK2s4P
7|y48z
q'qf:W
\aVXLg+V
Sa$}tO
F;]T1]
NdPLie
q*?~dBL
m[~sU
d0rztc
y\"t:#
~};(F?
=5\)O-a
HyaAf+
NVPNzS
C >$<.$
1+$?%i7
t+j3uJ[V
hnAOA}
g(88J4
?&?JS^
H 2XF2Fgff
Q!;Yb%r
qfQ$UR5
UZl(Wfz
g<VP[m
wke&V-
|'k`mM
e5u.Le
.+BZ*<
lM!9]C
ZsT*J
2y7-aQ
`!TZY{
{-3z}
v,'+1X'
C2T]EB
?&soZv
fUET1p
y@O!Ga
"BBb>,
+~!x}^
!yal >&}/;
K'yq,A
T52+RaR
0mFwI~
Az2b3D
+XT[($h
vlEk`(J
)Z&aMI
Hk&W6w
G0Sx^`|/n
0vS|jJC
Jj{H50
OX;NOS
wu3HZ<U
oaB*d^@
W$ZBlq
'K9L<\
r!D]\ajL
&{Oloq
J;`kDO
%P7-WF
2&5=I9Sw
[p"*ak&W
kkuwjE
xqfF L
&wgMq>
y nY@M
XXw&II
]HX9b:y
n836I2|
a_"CkHf,
_QZ7fSC
4e+u.G
ZjI'"$JqP
{0x,d!o
[XbJV}S
=a<&NN
Ux+)i@(
bR"F@Y7
L=y7HSC
wu7{s%y
JmSBqqY
gA6oNW
[nXRiS
n+"0;Z
-|x,R}
NTR7l!
7{ 8fj
%$I@~u
9bUSn]j
JR`2oR
6/?WdL
X6u@,<>6w=5
(TB_;!
ti|fCa;
t9Sd$
p,\dz_O
37E5n]
6KO$=E
iXy}XD
F;Fyh!
dTs,~M
QFttdu
+A}rr9
2.!}4;
s;E5pc
d]\G&c+/
k`_jT8W
^/4KcY
@`2M0]
W9+g7|
`6[pm=
t&|y$#^
9!?bjA
SgKWJz
?"^#iN^
q$2u#"
m[)uD28
mvaBp
<ON^Ll
c'JRkH
I1^@Jwg^`
[Xkrv:
P;Pg]-
rwh@@<
~L$e&fP;
|m(nO`
A\KT\|
u&?h4KR
uOZy*6
:Nl=rv
g]jfQ+
GQrqE-
2fvKvR
A"<5S|m
\^'NS^
I1b@pA
UT)ZU^
}9PmG@t
qI ~.s
3A;f1=)
\B~Q6E9
9["c%+
n;;^?,~y
.RP59d
<<Gt<>
V0\9y;
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
Zab xeyilipawemeliyovadusekelu bevusibivi
pabewitoholezugi
mogujurocozesimajiraxoyumi soyuwiyaraxikuhepofakobe lonojekuvumo gilamepayixehud xusexutanadojezafezenisasoxo
nixifalonexedoco fej payaseyemecob vem gevayasoketicepiyiz
doruligiyuzujecedupuri hicacotayapitucajuf huzizuhelayupupewepuj yov fowugenititabivecah
logumenocox
lukekif gonezexebiveyoboporud javezadiliyijegasagemuvetec jevucisovowegiyabovoroxaxizamo
tagavorifa
kernel32.dll
LocalAlloc
RSDS<:
C:\hox joxab\mahehabel\xatelibu69 wotuvudejuz\xol-yocufanukec.pdb
WriteConsoleOutputCharacterW
lstrlenA
FindResourceExW
LocalCompact
UpdateResourceA
MoveFileExW
InterlockedDecrement
GetCurrentProcess
GetUserDefaultLCID
SetConsoleScreenBufferSize
WriteConsoleInputA
GetComputerNameW
SetEvent
GetSystemDefaultLCID
GetProcessHeap
IsBadReadPtr
GetConsoleAliasesLengthA
GetConsoleTitleA
ReadConsoleW
ReadConsoleOutputA
WriteFile
CreateActCtxW
GetVolumePathNameW
ActivateActCtx
GetConsoleCP
GlobalAlloc
TerminateThread
ReadConsoleInputA
GetSystemWindowsDirectoryA
SetConsoleCP
InterlockedPopEntrySList
GetFileAttributesA
DnsHostnameToComputerNameW
lstrcpynW
GetConsoleAliasW
SetTimeZoneInformation
VerifyVersionInfoA
WriteConsoleW
GetMailslotInfo
CreateActCtxA
GetCPInfoExW
GetLastError
GetLongPathNameW
SetLastError
GetProcAddress
EnumDateFormatsExA
EnterCriticalSection
GlobalGetAtomNameA
BuildCommDCBW
LoadLibraryA
GetProfileStringA
GlobalGetAtomNameW
WaitForMultipleObjects
SetSystemTime
SetEnvironmentVariableA
SetConsoleTitleW
GetModuleHandleA
lstrcatW
EraseTape
CancelTimerQueueTimer
GetPrivateProfileSectionA
VirtualProtect
PeekConsoleInputA
SetCalendarInfoA
EndUpdateResourceA
FindFirstVolumeW
AreFileApisANSI
KERNEL32.dll
GetAltTabInfoW
RealGetWindowClassA
USER32.dll
BackupEventLogW
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapReAlloc
HeapAlloc
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
HeapCreate
VirtualFree
VirtualAlloc
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
#gzwg]
B5e 5e
4[e eB
2gZVe)
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQ
QQQQQQQQQQHu
bQQQQQQQQQ
QQQQQQQQQQ
PXN]QQQQQQQQQQQQQi
QQQQQQQQQQQQQ
|sQQQQQQQQQQQQQ0
QQQQQQQQQVkU lJ
QQQQQQQQQ
QQQQQQQQQC
QQQQQQQQQ{
:=|c#.~
12~s$3
O15~~)%
4OM}wE<
6RYrI1-
IOl8.=
SZ{wC=
==e__XTGc
g@Ch+4O
/Sf?$u
S{~:1~
&Bu~j*z
Ruz%1HpN
+:e='u
Co~;%}
G:e{t1^
:q---------------------q:
)-)-)-)-)-)-)-)-)
C4qqqq4CNNNNN
NN}}++
]]i]i]ii
KKdddddddd
uL!L!!!!uuu
LLLLLLLLLLLLLL
:q--------------------0q:
iiiiiiiiiiiii
WiiiiiiiiiiiiiiiiW
iiiiiiiiiiiiiiii
Wiiiiiiiiiiiiii
}}}}}}
uu<<u)<<<
VVVVVVWWV
qqqqqqqqqqqq
dqqdqqd
zzzzzzzzz
bbbbbbbbbb
qzbwwUUUwwwbzq
qzbDDDDDDDDbzq
q1bbbbbbbbbb1q
SSSSSSSSS
QQQQQQQS
SQQQQQQQS
SSSSSSSSS
yxvwusy
)Z`\q}
:I="^je|{
""""""
""""""""""""""
"""""""""
""""""""
"""""""
""""""
""""""
++J|EE
1111111112
lWWWWWWWWWWWWWWWWWWWWWWWWWWz
uuuuuuuuu
uuuuuuu
uuuuuuuuuuuuu
uuuuuu
uuuuuuuu
uuuuuuuu
uuuuuu
b=tuuuuu
b=tuuuuu
b=tuuuu
111QQOORR
p..VVF
pp..VVF
ppp.VVFF
111QQOORR
CCCCCCCCCCCCCCCCCC
C111111666
QQQQQQQQQQQQQQ
yyyyyyyyyyyy
yhhhhh
yhhhhhhh
%%%%%%%%%}
%%%%%%%%%%%
#P~m M
6C`V&R
ssi"L
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
yehofidahecuverocig fehicezizatatonirewudayuzofazene luvenixovilowilig rehijatuzeha
xutupixoxatimop fed xifiyidatisonugotewehonil gapasimocelev vicipotidahima
hawedev rolozacadatawavisoni buravabucihuc bazokudezacukuhogiturutudalux
fihedodutawixetazifedolekuj kulojefacelivazedajiligojoj buvikudicerenicezaxinasom payeyigumubowi
yevufunuzusalarekis yap
xcehewitakivahamobivupujezogo jocojobojupeloxid dutisobatibeduvodotumovigetoxasu
gaxivodimusipaduritixorofajemusu
ERRORDIALOG
VS_VERSION_INFO
StringFileInform
081564c6
InternalName
kogsmoadeke.exi
Copyright
Copyrighz (C) 2020, fodkagata
ProductVersion
9.21.22.12
VarFileInfo
Translation
Error!
Select One:
&Retry
&Abort
&Ignore
YMado gal robu pew gituhivisowef domete muyiyazi yinapuxar nadugusasetisey kisobuzakucelekLLekup zareluwiyoj jewuh bikuvocus cato wapa cuwitehuxi sifutaf jetuvajepifes
+Sogatide ziyariruh wabirejegit nakiwapikuke
6Jifihuzayigameg wuxew tuy yobizigorupodi visugip pijes
VGozokapiyuyemo yexoj yagisowapunam pefuvoriconuc rumatohefin vocogilekuvuto xezevumive
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Racealer.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46759742
FireEye Generic.mg.cc350161b58a017e
CAT-QuickHeal Clean
McAfee GenericRXAA-AA!CC350161B58A
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46759742
K7GW Trojan ( 0056f9be1 )
K7AntiVirus Trojan ( 0056f9be1 )
Baidu Clean
Cyren W32/Kryptik.EWB.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HLZW
APEX Malicious
Avast Win32:RansomX-gen [Ransom]
ClamAV Win.Packed.Filerepmalware-9884745-0
Kaspersky HEUR:Trojan-PSW.Win32.Racealer.gen
Alibaba Trojan:Win32/Kryptik.4bd99d30
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.46759742
Emsisoft Trojan.GenericKD.46759742 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.BSE.SL2CMN
Jiangmin Clean
Webroot Clean
Avira TR/AD.StellarStealer.rluer
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/Aicat.A!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R436231
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34058.Fq0@ayqzJmD
ALYac Clean
MAX malware (ai score=99)
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Yandex Clean
TACHYON Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HLZT!tr
AVG Win32:RansomX-gen [Ransom]
Cybereason malicious.f63d1f
Paloalto generic.ml
Qihoo-360 Win32/Heur.Generic.HwoCueAA
No IRMA results available.