Static | ZeroBOX

PE Compile Time

2020-12-12 00:06:17

PDB Path

C:\ruwacepajazo\ga.pdb

PE Imphash

e4703f951d731209d4eda0f101cdb509

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005bf41 0x0005c000 7.95130872799
.rdata 0x0005d000 0x0000481c 0x00004a00 4.42060738988
.data 0x00062000 0x02837cc0 0x00004400 1.33435925383
.rsrc 0x0289a000 0x00019a60 0x00019c00 6.59089277397

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x028b3400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028b3400 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_ICON 0x028b2d90 0x00000468 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG GLS_BINARY_LSB_FIRST
RT_DIALOG 0x028b3690 0x000000cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x028b38d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_STRING 0x028b38d0 0x0000018e LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028b32a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_ACCELERATOR 0x028b32a8 0x00000028 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_CURSOR 0x028b34b0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x028a6198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a6198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a6198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_GROUP_ICON 0x028a6198 0x00000068 LANG_GERMAN SUBLANG_GERMAN_LUXEMBOURG data
RT_VERSION 0x028b34d8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x45d008 lstrlenA
0x45d00c FindResourceExW
0x45d010 LocalCompact
0x45d014 UpdateResourceA
0x45d018 MoveFileExW
0x45d020 GetCurrentProcess
0x45d024 GetUserDefaultLCID
0x45d02c WriteConsoleInputA
0x45d030 GetComputerNameW
0x45d034 SetEvent
0x45d03c GetProcessHeap
0x45d040 IsBadReadPtr
0x45d048 GetConsoleTitleA
0x45d04c ReadConsoleW
0x45d050 ReadConsoleOutputA
0x45d054 WriteFile
0x45d058 CreateActCtxW
0x45d05c GetVolumePathNameW
0x45d060 ActivateActCtx
0x45d064 GetConsoleCP
0x45d068 GlobalAlloc
0x45d06c TerminateThread
0x45d070 ReadConsoleInputA
0x45d078 SetConsoleCP
0x45d080 GetFileAttributesA
0x45d088 lstrcpynW
0x45d08c GetConsoleAliasW
0x45d098 WriteConsoleW
0x45d09c GetMailslotInfo
0x45d0a0 CreateActCtxA
0x45d0a4 GetCPInfoExW
0x45d0a8 GetLastError
0x45d0ac GetLongPathNameW
0x45d0b0 SetLastError
0x45d0b4 GetProcAddress
0x45d0b8 EnumDateFormatsExA
0x45d0c0 GlobalGetAtomNameA
0x45d0c4 BuildCommDCBW
0x45d0c8 LoadLibraryA
0x45d0cc GetProfileStringA
0x45d0d0 GlobalGetAtomNameW
0x45d0d8 SetSystemTime
0x45d0e0 SetConsoleTitleW
0x45d0e4 GetModuleHandleA
0x45d0e8 lstrcatW
0x45d0ec EraseTape
0x45d0f8 VirtualProtect
0x45d0fc PeekConsoleInputA
0x45d100 SetCalendarInfoA
0x45d104 EndUpdateResourceA
0x45d108 FindFirstVolumeW
0x45d10c AreFileApisANSI
0x45d110 VerifyVersionInfoA
0x45d11c HeapReAlloc
0x45d120 HeapAlloc
0x45d124 GetCommandLineA
0x45d128 GetStartupInfoA
0x45d12c RaiseException
0x45d130 RtlUnwind
0x45d134 GetModuleHandleW
0x45d138 Sleep
0x45d13c ExitProcess
0x45d140 GetStdHandle
0x45d144 GetModuleFileNameA
0x45d148 TerminateProcess
0x45d14c IsDebuggerPresent
0x45d150 HeapFree
0x45d15c HeapCreate
0x45d160 VirtualFree
0x45d164 VirtualAlloc
0x45d174 WideCharToMultiByte
0x45d17c SetHandleCount
0x45d180 GetFileType
0x45d184 TlsGetValue
0x45d188 TlsAlloc
0x45d18c TlsSetValue
0x45d190 TlsFree
0x45d198 GetCurrentThreadId
0x45d1a0 GetTickCount
0x45d1a4 GetCurrentProcessId
0x45d1b0 HeapSize
0x45d1b4 GetCPInfo
0x45d1b8 GetACP
0x45d1bc GetOEMCP
0x45d1c0 IsValidCodePage
0x45d1c4 GetLocaleInfoA
0x45d1c8 LCMapStringA
0x45d1cc MultiByteToWideChar
0x45d1d0 LCMapStringW
0x45d1d4 GetStringTypeA
0x45d1d8 GetStringTypeW
Library USER32.dll:
0x45d1e0 GetAltTabInfoW
0x45d1e4 RealGetWindowClassA
Library ADVAPI32.dll:
0x45d000 BackupEventLogW

!This program cannot be run in DOS mode.
`.rdata
@.data
0WWWWW
0WWWWW
QQSVWd
uBhYe@
0SSSSS
tNIt?It0It
>=Yt1j
j@j ^V
teh`h@
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
tRHtCHt4Ht%HtFHHt
URPQQh
0A@@Ju
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
^p!XN9
}-"%a?Y
OX0a {
<u.WtK
,Kj<EU
rVlrU2)(h
3_-Q#a
G!i-UwAR
>5,/hu
#%1E?LW
5t1Q9be
{S<Iy y
NrerUJ
1tN!d7^
?twlfP
V!W*L{
xYSs0x
c~`+B4
X#\{y6
0|I|pz:[TT
g(v53a
FQ4=HS
>"alG:%
O6{S?%
eJb.Fk
||!40\
Ebh6Qor
Yb/_K3
;a8_n:
96aS*(z
CQS\a
.Y_mkEv
&7t(T?
VJ:uzO
[JiC_A
ob7Md
lAQbXz
AN<1^z
;MMu0C
6\K Be;
Aot{T8i
YSE0F]D
A!R7sZ
~/ulVH{
6? wt)
|>(=u
vU!l-<
%w7Ic~e
3{^}sz
H?()")
@a?JEL1
X*fk:]
9|)!Q
z^_g1&G:u
u&mz+-@
Z4h$y{
PmfcVn
.ls:_*
2mg,t,
H11gl-
*rr`f\
Y*WNbia
<a_lm^
~},.6,
e>P>=]]el
YXgCy4
0A$x#Dbg
smMCuM
&ZZ.IT
[tX/?g
g;j696
aW)r+@
JhjZE=
=o)rU}%L
V)wV7
rDTG;83
sSp/%"K
MBik]k
WF EzbV
!PRP7]
%sP1}PTCc
D76@mBv>
<O(i`M
ac5MmU
5r4>%I
0[!0["
:y#HsI:
|?C?nF_W$L
SkNcF59e
"D`?<$
1c`KqAz_
y[n:/7
w671.v
lw!x0r
<DOU$mDH
iqoVz?
&oj(nlE
2J5J]Ru
^u+;]Hr
:l0_q'AS
i=:{P,8
H:2ZEi
b2uS6w:G
}7Epx\
Q%2?B{&
WF%JD}=H
L];H|0
u=LGe,~|d
86>.f};+
hHv$g9
fb.t6&
:sWW'Z
=2#ie
u9D,b7
EO[$6w\
KEG`k
]'^SE<y9
=bvpS&
P7.] S-X
$,2dK3
a_71^f
]aA(S$T
*5[VatB
9TEG5-]
Y|k,Q3L
o"b)+-
rLJiW)
qlp[i~x
nHn9tB
HR#hQA
{uCoLk6
f)K#)h
b!Yz(J
%BSZ=
:\cc+'
mo(C-m
fNLYa]
j%i^&V
qshS`Z
QeRvq,
~~e*wE
'x9P1s
;0UiP,
)uKe^z
n+FVLq
.4IT]f
o(;'|D:8
RT.{9\2
)G^9qk
=?J&6!
g,tf\v
,d{~8X
M`jN/X9
D$}aO
0:z`Ab;"W
"tu7tH
r0\tZJ
4\1S@
q+5f@!l
w#R\fP
X%:7H^
vVH`8V
I`rEk<
n@:HG
(0]d03
JU@.y{s
)f[`z
^l,mF$
dRprn}
WxJYpK
rEEf)d
JXj\QG
Mi'2Id
}Dkdw;OM
{s]9'R.}dI
+g#},_k
W(x3rBD
/tHn*m%
lLv}J6y)
V1-|3[
EHGjZ%
a|DD2*
WH+QRZ1H4
5U69D{
R]WEXd
&59QpjW_M
:YxwQ-
V&[f
gpjNW4
jI2I4tg
jv.`3u
lGO>/2e
~/@)QS
Rg#|]}=
e1kVqj
/yDG5t
'fqe5n
.J2gT3
%4bnE{_Z
_[UG"7
v`K>Q<
`:5Z5m
_u_+VWS
]5 OzA
0er0d=
4n|8w~
We7#ds
`dr{r=
rJ8^9\
n>Wqb(.
*`Ue|o.
.MTxn>l[
yu?ID
KAoxA6_
CFy2#K
U>Kzu
j-(KX2
`e5*SX
hicc6w
pN%+=a
j:b,i1
%+|y,e
,KD9H9e
+5R5p1
q5\P|,
sMI^B?
o3n.X\+>N
UqW*Pq
v!5,`#
w'lJns
~TeMjd
<VDqi
VB3:=)
C.[l*S
~;I/OI[ET
2W[*hZ
G$Pb&p^
?6o(x:
z"_)|]
X.a{F1
pKT;Yd-R2
Xd[.bJ
s?Es!V
XGW)'u
yS^jIk
2y;S+k
2iB2S
Rg)9W3
<Y}%CeZF8k
PZ2G3/
t&lop4
DG%eal
M65[TB
\B76}x6b
$V{.e7;n
x4n18a
c6_q]~
yjtM=Fp
&@l1h}J
-PA1di
Ys!8$X
KC}ghG
@~M nF
mO?j8W
pRr}>.
(Jy#9s
I>6Gbt
wfp=c,
sc/]a^F
.R!PBVd\i
2lqq<*
I4JV'g
ISgnP3w
%>D)bG
D98^JX
e+QM$A
`{mL@-
A?&|lp
6RMkOQ4
_c*3a&*
TqP{`2
:4#6E
?jE4e`
XdL&L2
PXRkSk
E)7MS$l
r1e+<?<>
+}PxwM
]0<w~Z"
1zqODc`vo
Q2hAdm
:Ea_[P
k:Yt^z
8cbx*~$r
9"eb/q
~&~PC
}jl7f]
>]Jj^hCz
-+6~*UT
k8 ':yI
-aG@Mq
K}ua E
YbpRCa
SA[?C4
zci?=P
J)1*02`x
kM&2.X
d_ah4
[n[%g]'
EGYvx5'
!*%Wm)
Mr %`{w'
uX'y=b
$AYA;*F
PJaw$6'
2p>K!q
BIlzxH
$TLAys)Iodx
#B8QX`B
N<~I:Y
K}"heu]
PTCuTp
O/O#k?
X'(c
V:*xc'
gSm;LT)r
@!wmfA
A:-pjZ
i n<T;P
%@#P~RH
|d(o{Q$D
T5j\#]fs
Q.xqKo
a5/(R,
ft5%h;
)b|8)J
5&:Czp
,R@b:MQ=
`,]u^%
OD'C1*F
S^j,YVS
t;v_cG
:8{N{*
)qn#<G
Hd?QFe'z
=d`:]
]gySUj
j9l'X"s
roKW!;*J
}WP[=]
b2H^xgj"%
m}&4ZmH
n7"T/=+
|E0fx<.
KH}70"
! Cj%V
9ax8X&;
<zAwpL
WKbK[0
$(z5p!
4V{sN?+
oJ.^=~8
DNVO,(
W>c"\=8:
T23I9D
KO</{`5M
1.AA?-
_gsDz8
HeSPBP
S>kB{|Aiz
[tT{e{
b2@Oi`
hK/1Y3W
,QMtNv
Hh.Dp+
r_4WE_
smi8wR
\@corw
Y4T0B
?n{UG_
^!RosS
jpCwOJ
++b;io
`9zJ+U
(9&+5/
~>(3~]
;z.#t$n$
:JUIA.
Z[G C5
Tw)Ewh
d]otg^`
C6aJ[}
+cH)2\
4T>3g-
`[Gw-:
[&4MGh
xq6hyY*.`
Cq3H_
OC:8C:3K:0,6M?
>OvNz\2U
ZYH$\#9
8; U,}
-eo_cz 6<~
SO#@pr
7F]>V5
/0ITf2
M%0gb>
x_v.4~
20,v#jIW
jnOg"h
|k(EKX"4
Sxk_-)x
qMCC~%
SE0N\+
|QV.I@
(7k-{A
<B$G9>
sZ&M;S
,kUO 3_
_{ \P'-+
#So#Z0
WQB*e^
$Cd4vkyH
3HC='
* oL"t#
)2QtS\RI
2x2r+*[
&'oP[@
Bt$=-[
{z{Zm5
<d=5Yx
F~wCC:_
zYq< *
yik9/3
YzCkA
dI+QI)
rpLq{=
w%Ud8b
:Fvez8g
phqYj7
U9#jZ<
;42uk
]wjiC,
J^2x'Fd
"GgQo
xWF@9)
zSm$fH
.d2**7
j|CAjE
'O@yb'=3
a|9NHBb
>6;?j#
a?bYkV;
|<ZYzF
RoVf"IoX
2><[GP-
%64XWQ
e]U@liM
ul~Y'4|+d
mj\C473
Ab<\,k
;^5'ZQ:
A:P@qQ;
tOISw$
1'zdf@
}Q@NM`
f2(0|e
6>]\B8e
A(q5Y-k
>?sP*y
d]7D@`
f)g|NNj
,'"OtQ.
;6)D,]
1@$0 t{yx
0R)7R$
MHS+[
qn>6_Y
@W:xwY|h0
nQ*3mk
BZ#vo0#n
+^Y4Gm
.o#FlT
D\ZsBT
C?"dvU
;vG''o
F,I@^5"Jw
U+4B-4
1 xyT1
Nn"8,K
TBUXU.G
#tRW]=G
PlRarF<
4'Wc-Y
MiFUk{
&}#=%E=
Y:D.gWR
gjmLNaG
B{'9/;s
?n]-',
ch]$RN
H7q&E2
.i@5"U
vy,ya=
p>ce'
gyz?eL"
^C4S,$
m[`WKv
wo_=#7O}
"RZhe&
'D"S}Q
<%U6wJ
-|eF?a
yD$2V#C
?Br \#
+:aI&
gAQi1eQ
TvD[|T
+8_<!7
d'*G4[
Bok}HY
N4"NaT3
b<Tdg\
"BPcux
``uI|{
ed")i$
x6lV$0
6-r`{m
6*uW~i
U>8tE:&f
IzA!QL
o8NI#Oo
~p]94s
/q/xdm
B[J- {
rN&#v
2'r6_J
j(=:6'9A
598(={j
y<4^C{D
)#!e+L?h2yhl
00P+_`a
UbgFl9
2"Vhh
PUfxALJ
+?uF`k)
Gu#J!w
ddzHPR2[
F#~)DqF
}CB~x_
TQlP\&E
rl~Eau9P{mQ
Ud4J-"
m,-|Nw`{[
dh{r0
[D:~z
<PBN_1
kZ*Htf(;
B,cx)3bQ/$
fea;`= m
'm\}>{
wiTd8(
("W)g(y
bJ?x'e<1
L6'IHe
t}eT"/x
,}[s{
uF>45D
-s&@tb
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
Zab xeyilipawemeliyovadusekelu bevusibivi
pabewitoholezugi
mogujurocozesimajiraxoyumi soyuwiyaraxikuhepofakobe lonojekuvumo gilamepayixehud xusexutanadojezafezenisasoxo
nixifalonexedoco fej payaseyemecob vem gevayasoketicepiyiz
doruligiyuzujecedupuri hicacotayapitucajuf huzizuhelayupupewepuj yov fowugenititabivecah
logumenocox
lukekif gonezexebiveyoboporud javezadiliyijegasagemuvetec jevucisovowegiyabovoroxaxizamo
tagavorifa
kernel32.dll
LocalAlloc
C:\ruwacepajazo\ga.pdb
WriteConsoleOutputCharacterW
lstrlenA
FindResourceExW
LocalCompact
UpdateResourceA
MoveFileExW
InterlockedDecrement
GetCurrentProcess
GetUserDefaultLCID
SetConsoleScreenBufferSize
WriteConsoleInputA
GetComputerNameW
SetEvent
GetSystemDefaultLCID
GetProcessHeap
IsBadReadPtr
GetConsoleAliasesLengthA
GetConsoleTitleA
ReadConsoleW
ReadConsoleOutputA
WriteFile
CreateActCtxW
GetVolumePathNameW
ActivateActCtx
GetConsoleCP
GlobalAlloc
TerminateThread
ReadConsoleInputA
GetSystemWindowsDirectoryA
SetConsoleCP
InterlockedPopEntrySList
GetFileAttributesA
DnsHostnameToComputerNameW
lstrcpynW
GetConsoleAliasW
SetTimeZoneInformation
VerifyVersionInfoA
WriteConsoleW
GetMailslotInfo
CreateActCtxA
GetCPInfoExW
GetLastError
GetLongPathNameW
SetLastError
GetProcAddress
EnumDateFormatsExA
EnterCriticalSection
GlobalGetAtomNameA
BuildCommDCBW
LoadLibraryA
GetProfileStringA
GlobalGetAtomNameW
WaitForMultipleObjects
SetSystemTime
SetEnvironmentVariableA
SetConsoleTitleW
GetModuleHandleA
lstrcatW
EraseTape
CancelTimerQueueTimer
GetPrivateProfileSectionA
VirtualProtect
PeekConsoleInputA
SetCalendarInfoA
EndUpdateResourceA
FindFirstVolumeW
AreFileApisANSI
KERNEL32.dll
GetAltTabInfoW
RealGetWindowClassA
USER32.dll
BackupEventLogW
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapReAlloc
HeapAlloc
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
HeapCreate
VirtualFree
VirtualAlloc
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
#gzwg]
B5e 5e
4[e eB
2gZVe)
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQ
QQQQQQQQQQHu
bQQQQQQQQQ
QQQQQQQQQQ
PXN]QQQQQQQQQQQQQi
QQQQQQQQQQQQQ
|sQQQQQQQQQQQQQ0
QQQQQQQQQVkU lJ
QQQQQQQQQ
QQQQQQQQQC
QQQQQQQQQ{
:=|c#.~
12~s$3
O15~~)%
4OM}wE<
6RYrI1-
IOl8.=
SZ{wC=
==e__XTGc
g@Ch+4O
/Sf?$u
S{~:1~
&Bu~j*z
Ruz%1HpN
+:e='u
Co~;%}
G:e{t1^
=NNNNNNNNNNNNNNNNNNNNNNN=
.....................
^^j**/
:..[[[
``F`F`FF
]]\\\]]]
yyyyyyy\
@@@@@@@@@@@@@@@@:
-)))))))))))))))))))
....................
=NNNNNNNNNNNNNNNNNNNNNNN=
KKKK"""
88888F88F8888
))))))
???????
FFFFF88
pppVVVp
eeeeeeKKe
\*E*E*E*E
E\\*YY
(((((((
(((((((
(((((((
(((((((
~}ye}z~
xvsst{z
~|{|||
%_b`t}
;H6!Yj_x{
""""""
""""""""""""""
"""""""""
""""""""
"""""""
""""""
""""""
++J|EE
1111111112
lWWWWWWWWWWWWWWWWWWWWWWWWWWz
uuuuuuuuu
uuuuuuu
uuuuuuuuuuuuu
uuuuuu
uuuuuuuu
uuuuuuuu
uuuuuu
b=tuuuuu
b=tuuuuu
b=tuuuu
111QQOORR
p..VVF
pp..VVF
ppp.VVFF
111QQOORR
CCCCCCCCCCCCCCCCCC
C111111666
QQQQQQQQQQQQQQ
yyyyyyyyyyyy
yhhhhh
yhhhhhhh
%%%%%%%%%}
%%%%%%%%%%%
#P~m M
6C`V&R
ssi"L
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
yehofidahecuverocig fehicezizatatonirewudayuzofazene luvenixovilowilig rehijatuzeha
xutupixoxatimop fed xifiyidatisonugotewehonil gapasimocelev vicipotidahima
hawedev rolozacadatawavisoni buravabucihuc bazokudezacukuhogiturutudalux
fihedodutawixetazifedolekuj kulojefacelivazedajiligojoj buvikudicerenicezaxinasom payeyigumubowi
yevufunuzusalarekis yap
xcehewitakivahamobivupujezogo jocojobojupeloxid dutisobatibeduvodotumovigetoxasu
gaxivodimusipaduritixorofajemusu
ERRORDIALOG
VS_VERSION_INFO
StringFileInform
081564c6
InternalName
kogsmoadeke.exi
Copyright
Copyrighz (C) 2020, fodkagata
ProductVersion
9.21.22.12
VarFileInfo
Translation
Error!
Select One:
&Retry
&Abort
&Ignore
YMado gal robu pew gituhivisowef domete muyiyazi yinapuxar nadugusasetisey kisobuzakucelekLLekup zareluwiyoj jewuh bikuvocus cato wapa cuwitehuxi sifutaf jetuvajepifes
+Sogatide ziyariruh wabirejegit nakiwapikuke
6Jifihuzayigameg wuxew tuy yobizigorupodi visugip pijes
VGozokapiyuyemo yexoj yagisowapunam pefuvoriconuc rumatohefin vocogilekuvuto xezevumive
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
Alibaba Clean
K7GW Trojan ( 0056f9be1 )
CrowdStrike win/malicious_confidence_100% (D)
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34058.Fq0@a8xDM5r
Cyren Clean
Symantec Packed.Generic.525
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Backdoor.MSIL.Convagent.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Clean
Tencent Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.SoftPulse.hc
FireEye Generic.mg.bcaf1c7dc97e9cf1
Emsisoft Clean
APEX Malicious
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Ransom:Win32/Wacatac.B!ml
ViRobot Clean
ZoneAlarm Clean
GData Win32.Trojan.BSE.SL2CMN
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Ikarus Trojan-Banker.UrSnif
Zoner Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
Qihoo-360 HEUR/QVM10.1.2197.Malware.Gen
Cybereason Clean
Panda Clean
MaxSecure Clean
No IRMA results available.