Static | ZeroBOX

PE Compile Time

2020-03-21 02:38:48

PDB Path

C:\zosokikivugah-jagi\jigu-peziv77\fifekewuzifi-pa.pdb

PE Imphash

21f8cbe210ac78e50bb44fcc94551c73

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0006ea50 0x0006ec00 7.97308496873
.rdata 0x00070000 0x0000373c 0x00003800 4.26165165895
.data 0x00074000 0x02837b64 0x00004200 1.25236491765
.rsrc 0x028ac000 0x00011610 0x00011800 6.39339413081

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x028bcfa8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028bcfa8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028bcfa8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028bcfa8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028bb1d0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_DIALOG 0x028bd238 0x000000cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x028bd478 0x00000198 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_STRING 0x028bd478 0x00000198 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_ACCELERATOR 0x028bb6d8 0x00000028 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_ACCELERATOR 0x028bb6d8 0x00000028 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_CURSOR 0x028bd058 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x028bd058 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x028bb638 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_ICON 0x028bb638 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_ICON 0x028bb638 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_VERSION 0x028bd080 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x470000 GetComputerNameA
0x470004 lstrlenA
0x47000c MoveFileExA
0x470018 GetUserDefaultLCID
0x47001c WaitForSingleObject
0x470024 SetEvent
0x470028 IsBadReadPtr
0x470030 GetVolumePathNameW
0x470034 GetConsoleCP
0x470038 LocalShrink
0x470040 ReadConsoleOutputW
0x470044 GetFileAttributesA
0x470048 lstrcpynW
0x47004c GetConsoleAliasW
0x470050 VerifyVersionInfoA
0x470054 WriteConsoleW
0x47005c ReadFile
0x470064 GetSystemDirectoryA
0x470068 CreateFileW
0x47006c CreateActCtxA
0x470070 lstrcatA
0x470074 GetACP
0x470078 VerifyVersionInfoW
0x47007c SetLastError
0x470080 GetProcAddress
0x470084 PeekConsoleInputW
0x470088 EnumDateFormatsExA
0x470094 BuildCommDCBW
0x470098 GetLocalTime
0x47009c GetProcessId
0x4700a0 LocalAlloc
0x4700a4 DeleteTimerQueue
0x4700a8 SetCalendarInfoW
0x4700b0 CreateTapePartition
0x4700b4 SetFileApisToANSI
0x4700b8 GlobalGetAtomNameW
0x4700c0 SetConsoleTitleW
0x4700c4 GetModuleHandleA
0x4700c8 UpdateResourceW
0x4700cc GetConsoleTitleW
0x4700d0 VirtualProtect
0x4700d4 EndUpdateResourceA
0x4700d8 GetVersionExA
0x4700dc FindFirstVolumeW
0x4700e8 GetCommandLineA
0x4700ec GetStartupInfoA
0x4700f0 GetModuleHandleW
0x4700f4 Sleep
0x4700f8 ExitProcess
0x4700fc GetLastError
0x470100 WriteFile
0x470104 GetStdHandle
0x470108 GetModuleFileNameA
0x47010c HeapAlloc
0x47011c WideCharToMultiByte
0x470124 SetHandleCount
0x470128 GetFileType
0x470130 TlsGetValue
0x470134 TlsAlloc
0x470138 TlsSetValue
0x47013c TlsFree
0x470144 GetCurrentThreadId
0x470148 HeapCreate
0x47014c VirtualFree
0x470150 HeapFree
0x470158 GetTickCount
0x47015c GetCurrentProcessId
0x470168 TerminateProcess
0x47016c GetCurrentProcess
0x470170 IsDebuggerPresent
0x470174 LoadLibraryA
0x47017c RaiseException
0x470180 VirtualAlloc
0x470184 HeapReAlloc
0x470188 GetCPInfo
0x47018c GetOEMCP
0x470190 IsValidCodePage
0x470194 RtlUnwind
0x470198 HeapSize
0x47019c GetLocaleInfoA
0x4701a0 LCMapStringA
0x4701a4 MultiByteToWideChar
0x4701a8 LCMapStringW
0x4701ac GetStringTypeA
0x4701b0 GetStringTypeW
Library USER32.dll:
0x4701b8 RealGetWindowClassW

Exports

Ordinal Address Name
1 0x401000 @GetOtherVice@16
!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVVh
"unVVV
j h(*G
tNIt?It0It
>=Yt1j
jThh*G
j@j ^V
0SSSSS
0SSSSS
0SSSSS
tRHtCHt4Ht%HtFHHt
0A@@Ju
URPQQh
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
-gJM.~
N5hq0OO
<[Sb]J
`A#8tJW
2nL=2R
;4IW)!
{jn_18mI
k"'XdL
j(}A:|
r hQo.
O[zUIA
^,6S[2
>;064`
F}_O+1
W,t);@
Ng9H1t
~p5p.d
JZYQ3&
XEO;5X
z.}XYV
+zH+Y@
^,CF.k
>sbwFj
${3e,MJ
G@7CIj
5o9MvF
0%'K=z
[MA-7h
JE]s%W
3@|#8a
~b $<b
7I1Z2
0rs _s
|h}W)V
1f65=m|dq
Q&&@z
BS$sH/i
a=TeBN
?\:KFL
#\7CFT
\`?NO<
iXdXDyo,
+8#51&
recpR)
Jda%6n
g)av#5f
p/I`~t
bf|XUc
s`WR>
nRgG"Cx
>D;a`f
a3o!ykf~
~FE)B^?
%r7MRE
:<7"'n
h4{7X'
c CKH7
=3K-2z
)4(SDRg
o^Ih6I
\}gJa5NQ
5(KdrfC'
[Ro"JN
fVHj|n
]7@*_=K
}BAX:*7oK
-)lYey6
pzhq\Y7:
ys;}n7Y
i}3+=l
462Cim
cr|s#H~r
I{yBZ
7=gW>I
r<KyuL
^%ve'r
s0AmpW
<zikO.;q
H(93c#
T5,z
7%38_Y
e3?~y.V
8^Ejuw
"vmjtjw
1U14j-
r!/%<f
+|3'fHtd
`NS,BD(
5nuEuE~
H'kHL=
t[V]qz
hg"a5q
f?'Q;'
A@T9AG>wQx
v!MbL\
su"}.l
0Luq>of
A]^\n.
aA'wD5%
w2}klfb
,CL|,=3
ckX$X
h:DUI$?
`m!?>7
f_rlsJ
Z"d=yX
]jGy?6
X^K%|=&
%yMs=a9rb
S{\`U|
Zwf&Rf&
29SqlN"
fK4X-?
MKFg~k
VECXc>
ceH&*Jh
U\/n_+
lba`h!
99meZ{Z9
h IRR>
DcT\^8
`f-~$_
Eo$~](3
nC7#`=
`%kA
nyz6sw^/
K0OMKFC
iG/V0KRN
~V-DUG
e4dJm2
[`[dH!
Az$UJ.
N$0pp}
Q"fC>d
"09a?9
99 C)M
wSMPa*
q(f$"Ps%
g{o\3(
X,:DNc
HC<~u)
.`%[PdN8-
A1Vg7
qyMLg_
3(nR&h
<2`&-5
[42U"n
veAYnm
0=,`Ov
-h$hW,
GbBnQ@+
9+EQd%
kNMo*E
pZ&AC@
ml5aHo
T6QC\`
V:'<FEk
W0{$]K
F2acD,
m[j}<rm
y.Th9A
eiMy1;\
%#1kk^
(n1b25
3SSuEa_+
A?*8O#
l"]s(g
\F~G$1
'HeAii
kfsGn$&
-$n&SK
@&pP^F
=H3<-d
Jdn*=`
QA:Axv6T
G?D[KWDI
Y\D\09
q)eP~mx
y/cq=p
}w{CcC
|dU|0c
`(h$P;
?E=80a
qk9XHv
da@kz^D\
7%La=zN
g%=;">
A.LGX`
Eu#B+/
}(GBU!b:^]
k#S/}V|)
^TE.0`
7As$]N
P\MY$h
J#)LP} J
GcGm(,
a BC@
?Ph=K'
0I^{4U
*L^h[ W
TlEy^K7
-{c>Ff
WE;:ie
LDd4qq
\-~`MJ
+yg1l)I\
'LrDEs
8j-"Z&^d
(S(]NP
+#ir~Y
qSv:HL
8cxb%X
[C3v+RF
Hh#!fn7
cLg8Ec
-F<@/(
S;dy(}
,OnAz
R](]'#s
G.d_V}
CGT=r8
B),:]R
CeCF2*
q648udBj
WRz+|)u
7,22`/8
K(Nu#Y
?TPwOZ
TFE+\y
(@|<n0IW
f1FD'^X
"t[^X;
_Sd^3g
-e$&-j
82&Uq3L7
nw[6a{)
/fKnb&
!d{U['
lJz6~p|d
Qh#NI-
\qpL^0gS
F3F1<x
lpRq$s
l;3mSo
={/z'"
[:g^R1
J"k%1PRo
N'h*F%
<9w%r"n
jV-g<XS
/CWHdP
<U.dzq_
|6[ZyH
9"P3o@u
rXyQk\#
J=Hbo
t0xMpZ
4U_D9sJ
/ge{.7)
1(ennmR
K^&ltN
Q=$aP/
j*VaV4
\TI*/H
,wSK1G
vtT,orao
3ojt('
@U Z
Ks(F.[c
NI48\
PbXcP\
,Ham}>
3`p)@E
Z,}X|\I6I
M/]x21XGJY:k
V%X9TXu
Xx) )kG)
V5^-es!
3vG!Su
E5F6xM
g~@x7<
-d !Sz
~aQEVo
DE(Qs<^
rw|.;h
qCk-8TJ%X
jjc]oA
6z=g5#
:P*f[a
1Zqly
9rm!0%)
@:W-Z>J
U%<Ee/6
p30\L>
LF]F1_
PR<OlZ5
gb!'-s
wo\j\
0)}&y9t
x7P/"q
@NhWz%feO
NIdp;c
16}+g>
FW,`}u
._tt!7C`c
KabAVWS
?9:@pR
33@vi7K
Ro>,#h
#aQFuV
dXyQs
$j=$>d
cRQGE9e/
3Dge)D
dUe[0O
v+h"`qhy
_U|+Ry
/%"n2J
`'~awBz
+256S3
XO<e=.
,^8S{)
tZYskN
+@9xgtx
\2`Ja'
; 9,zK
x )eI-
lzWW#c
lm3C9@
<DsVc<n
$p'Mz]
t"kI!{
!Wc8JKX5
R"u(*K
ni6Yi
dTY:g]
>tAcc>
~NbQhF
5XZB 
=~Ev$m
Q2{A`i
T(s62s
z"X4sk
*5jk>X
}8WeA4*
H$:=VX
z#5q7C
3q${*o
x^\9-`
7 km@&l
&ZBZ^E
m%o/k6
!oMM]}`s
G'U?!'
#Ex;c{
tmBL#=k
<vBt<\VG
Cy|BV-
v?:Q!u
/dGT=4
%2yeiE
eNegF-B
%^c7lF3G
.UVf_mT
EuR4^2
Oi^fd(
e\1#dCX
]z;B@w
30liv3
ZtJW*|UR~
O1JyWD
)P?@%B]
vuA!l&W
G*RYi$
pST?B[&
(2)~9Q
TT"uJP&
B2q5L=?
g2'$N_v
;xggT(
3D`xA+[
?'3&G?
fYHEq:
WCXwM[
\3?O?4ap
4G<l&Z
~I?$}@s@;
WDSFBj
L`#[s9
{9x-50
#_q!lL}&YD
:]wOh
|{ypp[Y
Pk)f2)
[$yw-qL
W>6nle
L%c8 JDN
5k8>(*
iEF^)|,
Bp,y5KY
`IV=7
$D-=&z
IA0+%
*|S9-V
jYibEh
"y?;]t'
v^ A&:
!GKmYy
Bx\'1>
^}}@+t
,"8y&Z
B-hO?}
q0':<c
uJzKsp&&
dRM;88Y
R+oypS
erwR;;
k8CFk'|
o_X'zAO
KY)ajI
6B$=G
43_o1X1
|LCK|j
5U@'6A!
;seCJR0w
j"e.l
$cC:c`
Ef3;T\
61[%G
]muPeg
GnEUGBQ
<6yTyf
2EY7"Q
F}5=FB
_k>3I~
%10b=~
%p b4f
SHf-ps
,>w[aW")
G9yYlrM
^E=Z~D
mBJ^Y?
<$V','
4C`YZH
Vm<!~]
k|L&]=
LS{\8N
l1{0o3
a%HH0q
Jnz* )4[
iG4ER2
D7A|(N
(RM-d>%l
kZ4;n+
)/cT}K
v4;8S#
rpKm[IAY
(>@mJd
zT>aMP
?aGSw@u
_X1T|j
9kj,<}te\f0
O#i^U/
v4S3^`
1)!?$QH]
a&0jMTMx
=#Q`K.o
$?OOtT?
Z}W9A|
2mb?Xx=
Chf2<3
Y6ChDI
:!bD<L
@cZR_h
1#oJD;
]uzCu.np
2k[%vD
w2M%LY
~^>IDE
b]'8-]
Jb)Xow
nCFK,
fp26V8N
v5A5Gn
X\]c;r
2 r3e@
yMxEP
baJYK(
GR@!kM
Uf-xa_s&
vLu<;`
CZQNMk
x1zG^:N
/wp:\?
<OOyoZ
\t! 9*
GAXV v
fnPK};
#QpsA1
+]"Kz9c
s1Ml9YV
3z"6:!
!BR(KDH`&IQJ
2[ x_U
hW3K(e
1B3H*8
g#x3p8Z
uzxfR
9kd5XdC
<mwL^:
&$u<%K=')
G\mRzA
1V4ds#
vBAg81
=&2"3ksm
w]yPj
cHrmj#;o
O 5'uN
_>eMvT6
VQ&`a[LC[
op62W9
)| a`X
[O~@<,
_v^^yq
6sA:b*
AJMVZ;w
O2J=Z/
{DpwQ^
d&YQQ2
,2pwZF~&l
]7/]1
)c[4J#
o|R=sD
;8D1ZP
M%gZb~
T[rb@m
)Lw]%!R
eeb'H,
CC~KqLE
~{FzS\
X`?v]n
Z*MU-=J
]|vh$;
QnQ%qK
ep1-!Roh
|avxB4
u6kfd]
5!Cf]w
2?_a6SW
oR.&snClG
&8Pv++78
~yPw>Z~
7?"zYQ]
n("wt`
kYWrC9
RJ(Y>$
<IC.3zV
:/-=W#
xru~2D
-GGQqb
xPaW,B$$v0
iQq @f
"? 9"n
2S?;F\]
E=\~B8
y$e:y3
BOF1Tk
"KlXnOB8
!Oa+&]i
7!j&/
G?z\C9
trS|cJQ
>|kvx=
]F(CJ/
8"XXg;
>&lwY)
2cJVrp*`
_Uy`NG%
SFR$q6e
>%MC0"
Vv#2rs
\Wnjv.z
r'r9qS
=(^i5,
6K4s[D
.l>D|5
<m:*=S
6ek}JD
>i2o.(r
P>gP![,
e|s<PBc
M@'!Gi
!J]@"5
\gKwhq~
UM^Vw
B/4zl&
%Sx5'N'
:]UR6
@C6wO>
`7`b)O6L
{>q<S`xE
N5<4PgB
K\TG]C
T1{Rz#5
,{M1CV
r]yZE$
UkwC!N
Y[ c6
^lv6Ic
:LFIuw
!H2Uze
lRr_TE
1Q&qc`
e81e5]
|(Zfc
U7OJ.h
wR~F9"
"8m+((/
}@5/w,
eeu$jwK
dAj:9Y
h 5/TR
4(7tx1
n;*{2]
NGq;rq/80%
qr$5?cW(
N+gaU]x<
E4kGRzf
. YHZL
-(T13!Su
cQB,;T
6e==+_)
7bwWU~X
,"}ZD:
/#ii=wx
"t'A\9
>1Y?xb
E@dL{5U
]=qy\I
N^X5,,
GaP@(~q
r{s|H#6
Y~WXv\
"Y}L7/F0
0>rKDa
P0'7\f0?0
?o52s6
-94Ag]]
J]G:15
T8@&}lP
FdSEMe||9
[M\rm<&
%Mb-_E
6-^n&#
f:T/(~
J*U54+
`Hx}my
s]%Dxm
7>vbbV
#nq)W;
nAg{"v
#QE2F[
5PGT~b
sUkO/a
w0D7BK
gaW2YK
uD0x"%
'Jb]$U
h&&`tP
HEh,ee|+>K
&o`JI$<T G
V=P(I7R
L;8uLP
^kbc9#
AY(^hk
V{8>hj
k}5kii
Tq7*2>
Dq^8hH
xh]s-,
:L\Ci1
a/nd-i
8+:l'>j
H<-/wk
:hG#_6
ZD6Z>*6
N6:'RB
@ w-:S
7:C22I):
z-alU-rL
\Olxf5@
gMdy'l
b%"i>F$;{
dOxTu0
U.8YOT
$Zs0aqY|us
Bmsz;V
o@SCq$
qxO#_Si
}Yh?R9s
bx1\sis
%&}a92
-L #mq
bqM3;s
tTys>m7
fW>2ou
=9En#Tj%mx
@.fvN)ilm
G|QT8F
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
jafabazigixuloci totujaru cijelib cisedihumamomoruca
xudofosedolufa
zulerezoted
kernel32.dll
LocalAlloc
lafolirukamelefujujelihetiyutal sowuyiyacuruxavamucuvija wejutafulicubo
C:\zosokikivugah-jagi\jigu-peziv77\fifekewuzifi-pa.pdb
GetComputerNameA
lstrlenA
GetConsoleAliasesLengthW
MoveFileExA
InterlockedDecrement
ReadConsoleOutputAttribute
GetUserDefaultLCID
WaitForSingleObject
SetConsoleScreenBufferSize
SetEvent
IsBadReadPtr
GetUserDefaultLangID
GetVolumePathNameW
GetConsoleCP
LocalShrink
GetSystemWindowsDirectoryA
ReadConsoleOutputW
GetFileAttributesA
lstrcpynW
GetConsoleAliasW
VerifyVersionInfoA
WriteConsoleW
WritePrivateProfileSectionW
ReadFile
GetCompressedFileSizeA
GetSystemDirectoryA
CreateFileW
CreateActCtxA
lstrcatA
GetACP
VerifyVersionInfoW
SetLastError
GetProcAddress
PeekConsoleInputW
EnumDateFormatsExA
GetConsoleDisplayMode
EnterCriticalSection
BuildCommDCBW
GetLocalTime
GetProcessId
LocalAlloc
DeleteTimerQueue
SetCalendarInfoW
DnsHostnameToComputerNameA
CreateTapePartition
SetFileApisToANSI
GlobalGetAtomNameW
SetEnvironmentVariableA
SetConsoleTitleW
GetModuleHandleA
UpdateResourceW
GetConsoleTitleW
VirtualProtect
EndUpdateResourceA
GetVersionExA
FindFirstVolumeW
KERNEL32.dll
RealGetWindowClassW
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCommandLineA
GetStartupInfoA
GetModuleHandleW
ExitProcess
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
LoadLibraryA
InitializeCriticalSectionAndSpinCount
RaiseException
VirtualAlloc
HeapReAlloc
GetCPInfo
GetOEMCP
IsValidCodePage
RtlUnwind
HeapSize
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
loka.exe
@GetOtherVice@16
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
95~e#
:U\tJ2/
!LQm;/?
((((((((((((((((((((((((((((((((((((((((((B
((((((((((((((((((((
((((((((((((((((((N
((((((((((((((((;
FS%(((((((((((((((
((((((((((((((w
?(((((((((((((((
(((((((((((((((`
(((((((((((.
((((((((((
((((((((((
((((((((((((
((((((((((((
(((((((((((((+z
((((((((((((4
$((((((((((((
M(((((
C((((((((((((((((((
((((((((((((((((((I
$((((((((((((((((((
(((((((((((((((((($}8
((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((((
yyyyyyyyyyyyyyyyyyyyyyyyyyy
yyyyyyyyyyyy&
yyyyyyyyyyy
yyyyyyyyyy
yyyyyyyyy$
Zyyyyyy
yyyyyyyr;4
yyyyyyy9gO
yyyyyyyyru
yyyyyyyy9
lyyyyyyyyyyyy
yyyyyyyyyyy
(6yyyyyyyyyyyyr9#yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
Zk!{__.
Ho{7|bo!
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ}j-w/
cQQQQQQQQQQQQQQQQQ
~QQQQQQQQQ
{HQQQQQQQQQQQQQQ
%QQQQQQQQQQQQQj
8QQQQQQQQQQH
QQQQQQQQQ;
8QQQQQQc"?
xx5&R9T
@&8QQQQQQu
8QQQQQQ]-
QQQQQQQ
QQQQQQQu>$
QQQQQQQ
QQQQQQQ
XQQQQQQQ"Jg
kUrI I
QQQQQQQQQj?
QQQQQQQQQ
"QQQQQQQQQQ
QQQQQQQQQQQQQX
QQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQ
U~QQQQQQQQQQQQQQQ
!&-rUV
%QQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQ~
QQQQQQQQQQQQQQQQcbb
%QQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQQQQ>
QQQQQQQQQQQQQQQQQQQQQQI
QQQQQQQQQQQQQQQQQQQQQ8
#v`pev
QQQQQQQQQQQQQQQQQQQQQ8&
QQQQQQQQQQQQQQQQQQQQQ8
2F'ppp
8QQQQQQQQQQQQQQQQQQQQQ8
XQQQQQQQQQQQQQQQQQQQQQQ
8QQQQQQQQQQQQQQQQQQQQQQQc
-XQQQQQQQQQQQQQQQQQQQQQQQQQ~-
bXQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
8QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
IR{"QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
iBFi.8Q
0Uj@&u
Swz%4KrO
,;g>)w
I=h}v3`
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
sopixuy pakozijimew tetivijejiyejofifucurutowefomu nexumoxaga
vaduhavopenozumabucogijageguhu
fecikafofolekiperay fekanezidaberowexapayet
gixiheciwicuwanorif roboleyatecuvejasamewowupe califeyul
rigifebasekocuhonikofigi vos
luyevarajebosayuhuzururavo
dgulamuweve
yidediniluhahitizukexodun
ERRORDIALOG
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
081564c6
InternalName
sigsmoegeke.emi
Copyright
Copyrighz (C) 2020, fodkageta
ProductVersion
29.51.22.12
VarFileInfo
Translation
Error!
Select One:
&Retry
&Abort
&Ignore
Gahojaxoxixomol-Gujufivefawijem suh positapazutucuk pafemufucRJonuwa dususegidigazaw tusotacuwafutek honolaben dohegen jidileraca bezamatujuhuvo
Gijijiw genofe doseheyux
UYageya sucumowi magomo higomogoro kesozaruboya velenofuy sela hipikin riwoxag wiwacec&Cipumece cewugexixudideg yukavutocarat.Rafelexa jijefomoginaru wohovohih wegetoyonuno
Tasozaf wez cuvadus
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.a945644533a405a1
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056d2f81 )
BitDefender Clean
K7GW Trojan ( 0056d2f81 )
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren W32/Kryptik.EUY.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Chapak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Azorult.RW!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!A945644533A4
TACHYON Clean
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34058.Iq0@aCKYV4gG
Avast Clean
Qihoo-360 HEUR/QVM10.1.3A6F.Malware.Gen
No IRMA results available.